---
documentation_complete: false
name: Verizon Intelligent API
schema_version: 3.0.0
satisfies:
##
## BEGINNING OF:
## ACCESS CONTROL
##
## Reminder of "implementation_status" codes:
##  - implementation_status: unsatisfied
##  - implementation_status: unknown
##  - implementation_status: planned
##  - implementation_status: partial
##  - implementation_status: complete
##  - implementation_status: none

- control_key: AC-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Development, documentation, and dissemination of an organization-level, mission/business
        process-level, or a system-level access control policy, is outside the scope of the
        Verizon Intelligent API.
    - key: b
      text: |
        Designation of an organization-defined official to manage the development,
        documentation, and dissemination of access control policy and procedures
        is outside the scope of the configuration of the Verizon Intelligent API.

- control_key: AC-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        AC-2(a) is an organizational control outside the scope of configuring the Verizon Intelligent API.
    - key: b
      text: |
        AC-2(b) is an organizational control outside the scope of configuring the Verizon Intelligent API.
    - key: c
      text: |
        AC-2(c) is an organizational control outside the scope of configuring the Verizon Intelligent API.
    - key: d
      text: |
        AC-2(d) is an organizational control outside the scope of configuring the Verizon Intelligent API.
    - key: e
      text: |
        AC-2(e) is an organizational control outside the scope of configuring the Verizon Intelligent API.
    - key: f
      text: |
        AC-2(f) is an organizational control outside the scope of configuring the Verizon Intelligent API.
    - key: g
      text: |
        AC-2(g) is an organizational control outside the scope of configuring the Verizon Intelligent API.
    - key: h
      text: |
        AC-2(h) is an organizational control outside the scope of configuring the Verizon Intelligent API.
    - key: i
      text: |
        AC-2(i) is an organizational control outside the scope of configuring the Verizon Intelligent API.
    - key: j
      text: |
        AC-2(j) is an organizational control outside the scope of configuring the Verizon Intelligent API.
    - key: k
      text: |
        AC-2(k) is an organizational control outside the scope of configuring the Verizon Intelligent API.
    - key: l
      text: |
        AC-2(l) is an organizationla control outside the scope of configuring the Verizon Intelligent API.

- control_key: AC-2 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |-
       Application-level access to the Verizon Intelligent API is established through
       the Verizon Intelligent API Management Console.

       Currently this process cannot be automated. An administrator must login
       to the Verizon Intelligent API Management Console and add/modify API keys.

# AC-2(2) NOTES:
#       The customer will be responsible for automatically removing or
#       disabling emergency and temporary accounts within the required
#       timeframe. A successful control response will need to address
#       all of the procedures and mechanisms involved in disabling these
#       accounts.
#
- control_key: AC-2 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |-
        Currently, the Verizon Intelligent API does not have the capability to automatically remove or
        disable access. An Administrator must login to the Management Console and add/remove/modify API keys.
        
# AC-2(3) NOTES:
#       The customer will be responsible for automatically disabling user
#       accounts after the specified period of inactivity. A successful
#       control response will need to address all automated mechanisms
#       involved in disabling inactive accounts.
#
# ADMIN NOTE:
#       AC-2(2) disables temp/emergency accounts after period of time.
#       AC-2(3) differs by disabling *every other* account type
#
- control_key: AC-2 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - key: a
      text: |
        Disabling accounts to the Verizon Intelligent API
        within an organization-defined time period
        when the accounts have expired requires manual intervention
        by a Verizon Intelligent API Administrator.
    - key: b
      text: |-
        Disabling accounts within an organization-defined time period when the accounts
        are no longer associated with a user or individual currently requires manual
        intervention by a Verizon Intelligent API Administrator.
    - key: c
      text: |
        Disabling accounts within an organization-defined time period when the accounts are in
        violation of organizational policy requires manual intervention by a Verizon Intelligent API
        Administrator.
    - key: d
      text: |-
        Disabling accounts within an organization-defined time period when the accounts
        have been inactive for an organization-defined time period currently requires manual
        intervention by a Verizon Intelligent API Administrator.
        

- control_key: AC-2 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |-
        The Verizon Intelligent API automatically audits account creation, modification, enabling,
        disabling, and removal actions. 
        
        This is default, non-configurable, behavior. The Verizon Intelligent API cannot be configured
        to be out of compliance with this control.

- control_key: AC-2 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |-
        The Verizon Intelligent API currently does not have the capability to require that
        users log out after an organization-defined
        time period of expected inactivity or description of when to log out.

        This is currently a permanent finding.

- control_key: AC-2 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |-
        The Verizon Intelligent API Role-Based Access Control (RBAC) subsystem allows 
        administrators to dynamically change privilege management of users.

- control_key: AC-2 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - key: a
      text: |-
        Establishing and administration of privileged user accounts in accordance with a role-based access scheme or
        an attribute-access scheme is supported. Available roles are defined in AC-2(2).
    - key: b
      text: |-
        The Verizon Intelligent API auditing subsystem monitors privileged role and attribute assignments.

        This is default, non-configurable, behavior. The Verizon Intelligent API cannot be configured to be
        out of compliance with this control.
    - key: c
      text: |-
        The Verizon Intelligent API auditing subsystem monitors changes to roles and attributes.

        This is default, non-configurable, behavior. The Verizon Intelligent API cannot be configured
        to be out of compliance with this control.
    - key: d
      text: |-
        Not Applicable.

        Revoking access when privileged role or attribute assignments are no longer appropriate
        is an organizational control outside the scope of configuring the Verizon Intelligent API.

- control_key: AC-2 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |-
        Currently, Verizon Intelligent API access is controlled by an Administrator. Controlling access through
        a dynamic API is planned for  a future release.

- control_key: AC-2 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |-
        The Verizon Intelligent API provides mechanisms for unique accounts.
        Usage of shared or group accounts reflects an organizational
        control outside the scope of Verizon Intelligent API configuration. 

- control_key: AC-2 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        As of NIST 800-53 rev5, this control was withdrawn and incorporated
        into AC-2.

- control_key: AC-2 (11)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        Enforcement of organization-defined circumstances and/or usage
        conditions for organization-defined system accounts is an organizational
        control outside the scope of Verizon Intelligent API configuration.

- control_key: AC-2 (12)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |-
        Monitoring system accounts for organization-defined atypical usage
        is the responsibility of the organization's security
        operations center, and outside the scope of Verizon Intelligent API configuration.
    - key: b
      text: |-
        Reporting atypical usage of system accounts to organization-defined
        personnel or roles is the responsibility of the organization's security
        operations center, and is outside the scope of Verizon Intelligent API configuration.

- control_key: AC-2 (13)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        Disabling accounts of individuals within an organization-defined time
        period of discovery of organization-defined significant risks is the
        responsibility of the organization, and outside the scope of Verizon Intelligent API
        configuration.

- control_key: AC-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |-
        The Verizon Intelligent implements a Role-Based Access Control (RBAC) subsystem. The
        RBAC subsystem enforces approved authorizations for logical access to
        information and system resources in accordance with applicable access
        control policies.

        This is default, non-configurable, behavior. The Verizon Intelligent API cannot be configured
        to be out of compliance with this control as there is no way to disable the
        RBAC subsystem. Its usage is mandatory.

- control_key: AC-3 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        As of NIST 800-53 rev5, this control was withdrawn by NIST and incorporated into
        AC-6.

- control_key: AC-3 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |-
        The Verizon Intelligent API does not have a mechanism to enforce dual-authorization for
        organization-defined privileged commands.

        This is a permanent finding.

- control_key: AC-3 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: inherited
  narrative:
    - key: a
      text: |-
        Access to the Verizon Intelligent API is brokered through an external
        identity service, such as an organization's OAuth2 provider.

        Enforcing organization-defined mandatory access control policy overrides
        the set of covered subjects and objects specified in the policy, and where the
        policy is uniformly enforced across the covered subjects and objects within
        the system, is the responsibility of the organization's identity management
        subsystem.
    - key: b
      text: |-
        Access to the Verizon Intelligent API is brokered through an external
        identity service, such as an organization's OAuth2 provider.

        It is the responsibility of the organizations identity management
        subsystem to enforce organization-defined mandatory access control policy over the
        set of covered subjects and objects specified in the policy, and where the
        policy specifies that a subject has been granted access to information is
        constrained from doing any of the following:
          
           (1) Passing the information to unauthorized subjects or objects;
           (2) Granting its privilege to other subjects;
           (3) Changing one or more security attributes (specified by the policy)
           on subjects, objects, the system, or system components;
           (4) Chosing the security attributes and attribute values (specified by the policy)
           to be associated with newly created or modified objects; and
           (5) Changing the rules governing access control
        
    - key: c
      text: |-
        Access to the Verizon Intelligent API is brokered through an external
        identity service, such as an organization's OAuth2 provider.

        Enforcing organization-defined mandatory access control policy over the set
        of covered subjects and objects specified in the policy, and where the policy
        specifies that organization-defined subjects may explicity be granted
        organization-defined privilgees such that they are not limited by any
        defined subset (or all) of the above constraints, is the responsibility of the
        organization's identity management subsytem.

- control_key: AC-3 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: inherited
  narrative:
    - key: a
      text: |-
        Access to the Verizon Intelligent API is brokered through an external
        identity service, such as an organization's OAuth2 provider.

        Enforcement of organization-defined discretionary access control
        policy over the set of covered subjects and objects specified in the
        policy, and where the policy specifies that a subject that has been granted
        access to information can pass the information to any other subjects
        or objects, is the responsibility of the organization's identity
        management subsystem.
    - key: b
      text: |-
        Access to the Verizon Intelligent API is brokered through an external
        identity service, such as an organization's OAuth2 provider.

        Enforcement of organization-defined discretionary access control
        policy over the set of covered subjects and objects specified in the
        policy, and where the policy specifies that a subject that has been granted
        access to information can grant its privileges to other subjects,
        is the responsibility of the organization's management subsystem.
    - key: c
      text: |-
        Access to the Verizon Intelligent API is brokered through an external
        identity service, such as an organization's OAuth2 provider.

        Enforcement of organization-defined discretionary access control
        policy over the set of covered subjects and objects specified in the
        policy, and where the policy specifies that a subject that has been granted
        access to information can change security attributes on subjects,
        objects, the system, or the system's components, is the
        responsibility of the organization's identity management system.
    - key: d
      text: |-
        Access to the Verizon Intelligent API is brokered through an external
        identity service, such as an organization's OAuth2 provider.

        Enforcement of organization-defined discretionary access control
        policy over the set of covered subjects and objects specified in the
        policy, and where the policy specifies that a subject that has been granted
        access to information can chose the security attributes to be associated
        with newly created or revised objects, is the responsibility of the
        organization's identity management system.
    - key: e
      text: |-
        Access to the Verizon Intelligent API is brokered through an external
        identity service, such as an organization's OAuth2 provider.

        Enforcement of organization-defined discretionary access control
        policy over the set of covered subjects and objects specified in the
        policy, and where the policy specifies that a subject that has been granted
        access to information can change the rules governing access control, is
        the responsibility of the organization's identity management subsystem.

- control_key: AC-3 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        The Verizon Intelligent API provides a real-time connection to Private 5G
        telecommunication core networks through machine-to-machine communication
        protocols.

        The system uses persistent configuration files which are loaded into the
        Verizon Intelligent API during subsystem initialization. This allows
        for privileged users to modify security-relevant information, such as
        PKI certificates or encryption secrets, without requiring the Verizon Intelligent
        API be placed in a non-operable state.

- control_key: AC-3 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev5, this control was withdrawn by NIST
        and incorporated into MP-4 and SC-28.

- control_key: AC-3 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        As a requirement of accessing the Verizon Intelligent API, it is assumed that
        all authorized users (or system services acting on their behalf) have authorization
        to read all defined subjects and objects that are presented by the Verizon
        Intelligent API.

- control_key: AC-3 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: inherited
  narrative:
    - text: |-
        Access to the Verizon Intelligent API is brokered through an external
        identity service, such as an organization's OAuth2 provider.

        Enforcing revocations of access authorizations resulting from changes
        to the security attributes of subjects and objects based on
        organization-defined rules governing the timing of revocations of
        access authorizations is the responsibility of the organization's
        identity management subsystem.

- control_key: AC-3 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |-
        Releasing information outside of the Verizon Intelligent API only if
        the the recieving organization-defined system or system component provides
        organization-defined controls is a procedural requirement outside the
        scope of configuring the Verizon Intelligent API.

        It is assumed that any user, system, or system component, with access
        to the Verizon Intelligent API has an approved interconnection agreement.
    - key: b
      text: |-
        Releasing information outside of the Verizon Intelligent API only if
        organization-defined controls are used to validate the appropriateness of
        the information designated for release is an organizaitonal control
        outside the scope of configuring the Verizon Intelligent API.

- control_key: AC-3 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: inherited
  narrative:
    - text: |-
        Access to the Verizon Intelligent API is brokered through an external
        identity service, such as an organization's OAuth2 provider.

        Employment of an audited override of automated access control mechanisms
        under organization-defined conditions by organization-defined roles is the
        responsibiltiy of the organization's identity management system.

        The Verizon Intelligent API does not have the ability to override its
        authentication controls. There are no hard coded passwords or API keys.

- control_key: AC-3 (11)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: inherited
  narrative:
    - text: |-
        Access to the Verizon Intelligent API is brokered through an external
        identity service, such as an organization's OAuth2 provider.

        By integrating with the organization's identity management system,
        the Verizon Intelligent API will only allow access to data repositories
        once a user or process has received explicit access to the Verizon
        Intelligent API.

- control_key: AC-3 (12)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - key: a
      text: |-
        The Verizon Intelligent API installs into Kubernetes environments through
        the use of Helm Charts, Kustomize, and custom resource definitions. These
        installation components explicitly assert, as part of the installation process,
        the access needed to system applications and functions.
    - key: b
      text: |-
        Access to the Verizon Intelligent API is brokered through an external
        identity service, such as an organization's OAuth2 provider.

        Enforcement of an approved identity is an intrinsic property of the
        Verizon Intelligent API and cannot be configured to be out of compliance.
    - key: c
      text: |-
        The Verizon Intelligent API is installed and configured into Kubernetes
        environments through the use of Helm Charts, Kustomize, and custom resource
        definitions. Modification of these files, and further reloading of the
        Verizon Intelligent API to use the modified values, requires administrative
        access to the Kubernetes namespace that the Verizon Intelligent API
        is deployed into. This is default, non-configurable behavior.

- control_key: AC-3 (13)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        The Verizon Intelligent API queries Private 5G telecommunication
        networks for real-time information/metrics. A requirement for
        having access to the Verizon Intelligent API is approval
        for a user or system to receive all attributes of the data which the
        Verizon Intelligent API exposes.

- control_key: AC-3 (14)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        The Verizon Intelligent API does not handle personally identifiable
        information.

- control_key: AC-3 (15)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - key: a
      text: |-
        The Verizon Intelligent API assumes that all users and services
        accessing the API have full access to all data.

        The Verizon Intelligent API currently cannot be configured to
        enforce organizatin-defined mandatory access control policies over
        the set of covered subjects and objects specified in the policy.
    - key: b
      text: |-
        The Verizon Intelligent API assumes that all users and services
        accessing the API have full access to all data.

        The Verizon Intelligent API currently cannot be configured to
        enforce organizatin-defined discretionary access control policies over
        the set of covered subjects and objects specified in the policy.

- control_key: AC-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |-
        Access to the Verizon Intelligent API is broked through external identity
        services, such as an organization's OAuth2 provider.

        The Verizon Intelligent API uses the OAuth2 token to enforce approved
        authorizations for controlling the flow of information within the
        system and between connected systems.

- control_key: AC-4 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |-
        Access to the Verizon Intelligent API is broked through external identity
        services, such as an organization's OAuth2 provider.

        Further use of organization-defined security and privacy attributes associated
        with organization-defined information, source, and destination objects to enforce
        organizatin-defined information flow control policies as a basis for flow control
        decisions is not supported.
        

- control_key: AC-4 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        Access to the Verizon Intelligent API is broked through external identity
        services, such as an organization's OAuth2 provider.

        Further use of protected processing domains to enforce organization-defined
        information flow control policies as a basis for flow control decisions
        is not supported.

        If such capabilities are a requirement, it is recommended to instantiate
        an instance of the Verizon Intelligent API in a security context (e.g. SELinux
        label) aligning to your needs.

- control_key: AC-4 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        The Verizon Intelligent API does not have the capability to enforce
        organization-defined information flow control policies.

- control_key: AC-4 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        The Verizon Intelligent API is not an information flow enforcement
        capability.

- control_key: AC-4 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        The Verizon Intelligent API reads information from Private 5G telecommunication
        cores, standardizes the data, and exposes it to downstream consumers.

        The Verizon Intelligent API does not embed data types within other data types.
        This is default, non-configurable behavior.

- control_key: AC-4 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        The Verizon Intelligent API is not an information flow enforcement
        capability. 

- control_key: AC-4 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        The Verizon Intelligent API is not an information flow enforcement capability.

- control_key: AC-4 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |-
        The Verizon Intelligent API is not a flow enforcement capability.
    - key: b
      text: |-
        The Verizon Intelligent API is not a flow enforcement capability.

- control_key: AC-4 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        The Verizon Intelligent API is not an information flow enforcement capability.

- control_key: AC-4 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        The Verizon Intelligent API is not an information flow enforcement capability.

- control_key: AC-4 (11)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        The Verizon Intelligent API is not an information flow enforcement capability.

- control_key: AC-4 (12)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        The Verizon Intelligent API is not an information flow enforcement capability.

- control_key: AC-4 (13)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        The Verizon Intelligent API is not an information flow enforcement capability.

- control_key: AC-4 (14)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        The Verizon Intelligent API is not an information flow control capability.

- control_key: AC-4 (15)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        The Verizon Intelligent API is not an information flow control capability.

- control_key: AC-4 (16)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev5, this control was withdrawn by NIST
        and incorporated into AC-4.

- control_key: AC-4 (17)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        The Verizon Intelligent API authenticates to source Private 5G endpoints
        through the 3GPP and O-RAN xApp API specifications.

        Downstream destination points authenticate to the Verizon Intelligent
        API through enterprise credentials, such as OAuth2 tokens.

        The session established between the source data (Private 5G Endpoint)
        and the downstream API consumer recieves a unique session ID.

        This is default, non-configurable behavior.


- control_key: AC-4 (18)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev5, this control was incorporated into AC-16 by NIST.

- control_key: AC-4 (19)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        The Verizon Intelligent API is not an information flow enforcement capability.

- control_key: AC-4 (20)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        The Verizon Intelligent API is not an information flow enforcement capability.

- control_key: AC-4 (21)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        The Verizon Intellient API is not an information flow enforcement capability.

- control_key: AC-4 (22)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        The Verizon Intelligent API is not an information flow enforcement capability.

- control_key: AC-4 (23)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        The Verizon Intelligent API is not an information flow enforcement capability.

- control_key: AC-4 (24)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        The Verizon Intelligent API is not an information flow enforcement capability.


- control_key: AC-4 (25)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        The Verizon Intelligent API is not an information flow enforcement capability.

- control_key: AC-4 (26)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        The Verizon Intelligent API is not an information flow enforcement capability.

- control_key: AC-4 (27)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        The Verizon Intelligent API is not an information flow enforcement capability.

- control_key: AC-4 (28)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        The Verizon Intelligent API is not an information flow enforcement capability.

- control_key: AC-4 (29)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |-
        The Verizon Intelligent API is not an information flow enforcement capability.
    - key: b
      text: |-
        The Verizon Intelligent API is not an information flow enforcement capability.

- control_key: AC-4 (30)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        The Verizon Intelligent API is not an information flow enforcement capability.

- control_key: AC-4 (31)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        The Verizon Intelligent API is not an information flow enforcement capability.

- control_key: AC-4 (32)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |-
        The Verizon Intelligent API is not an information flow enforcement capability.
    - key: b
      text: |-
        The Verizon Intelligent API is not an information flow enforcement capability.
    - key: c
      text: |-
        The Verizon Intelligent API is not an information flow enforcement capability.
    - key: d
      text: |-
        The Verizon Intelligent API is not an information flow enforcement capability.

- control_key: AC-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: partial
  narrative:
    - key: a
      text: |
        It is recommended that a new organization-defined duty of
        "Verizon Intelligent API Administrator" be created.
    - key: b
      text: |
        The "Verizon Intelligent API Administrator" will need sufficient
        permissions to install, modify, and remove, the Verizon Intelligent
        API from your Kubernetes environment.

        Further elaboration of required access authorizations is forthcoming.

- control_key: AC-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        Authenticated users, or processes acting on behalf of users, only
        have access to the Verizon Intelligent API data. Privileged user accesses,
        such as administrative access to the infrastructure hosting the Verizon
        Intelligent API, is not provided.

- control_key: AC-6 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        The Verizon Intelligent API utilizes enterprise authentication mechanisms,
        such as an OAuth2 provider, to authenticate users or processes acting on their
        behalf.

        To authorize access for organization-defined individuals or roles to
        organizatio-defined security functions (deployed in hardware, software,
        and firmware), users must be added to the enterprise authentication
        and identity management systems.
    - key: b
      text: |
        The Verizon Intelligent API utilizes enterprise authentication mechanisms,
        such as an OAuth2 provider, to authenticate users or processes acting on their
        behalf.

        To authorize access for organization-defined individuals or roles To
        organization-defined security-relevant information contained within
        the Verizon Intelligent API, users must be added to the enterprise
        authentication and identity management systems.

- control_key: AC-6 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        The Verizon Intelligent API utilizes enterprise authentication mechanisms,
        such as an OAuth2 provider. To require that users of system accounts (or roles)
        with access to organization-defined security functions or security-relevant information
        use non-privileged accounts or roles, when accessing non-security functions, the
        users must have a non-privileged account in the enterprise authentication or
        identity management system.

        Creation and management of such accounts is outside the scope of configuring
        the Verizon Intelligent API.

- control_key: AC-6 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        The Verizon Intelligent API is a software application that is installed
        in a hosting platform, such as Kubernetes. 

        As the Verizon Intelligent API does not contain privileged commands,
        nor offers network access to privileged commands, this control is delegated
        to the hosting platform upon which the Verizon Intelligent API resides.

- control_key: AC-6 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        Upon authentication to the Verizon Intelligent API, users, or processes
        acting on their behalf, are isolated into a dedicated communication and
        data access session. Users are unable to access data, or communicate
        with other users, in separate sessions.

        This is default behavior and the Verizon Intelligent API cannot
        be configured to be out of compliance with this control.

- control_key: AC-6 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Restricting privileged accounts on the system to organization-defined personnel
        or roles reflects a procedural control outside the scope of configuring
        the Verizon Intelligent API.

- control_key: AC-6 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Prohibiting privileged access to the system by non-organizational users
        reflects a procedural control outside the scope of the Verizon Intelligent API.
        
        Also note that the Verizon Intelligent API utilizes enterprise authentication
        mechanisms, such as an OAuth2 provider, and does not perform user
        management itself. In order to prohibit privileged access to the system
        by non-organizational users, it is suggested to not give non-organizational
        users accounts in the enterprise authentication service.

- control_key: AC-6 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        The Verizon Intelligent API only has one class of user, which can query
        the Verizon Intelligent API and receive data. 

        Periodic reviews to validate the need for such access is a procedural control
        outside the scope of configuring the Verizon Intelligent API.
    - key: b
      text: |
        This is an organizational/procedural control outside the scope of
        configuring the Verizon Intelligent API. It is up to the organization
        to review and validate users permissions and privileges.

- control_key: AC-6 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        By design, the Verizon Intelligent API has only one class of user
        (read only data access) and only one privilege level (read only data
        access). There is no ability for users, or processes acting on their behalf,
        to elevate permissions.

        This is default, non-configurable, behavior and the Verizon Intelligent
        API cannot be configured to be out of compliance with this control.

- control_key: AC-6 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        The Verizon Intelligent API has only one class of user,
        which has read-only access to data. There are no privileged functions
        available to users or processes acting on their behalf. This is default,
        non-configurable behavior, and the Verizon Intelligent API cannot be
        configured to be out of compliance with this control.

        Note that privileged functions which could impact the Verizon
        Intelligent API, such as starting or reconfiguring the service,
        is handled by the administrators of the hosting platform upon
        which the Verizon Intelligent API is hosted. This control
        is appropriately scoped to the administration of that platform,
        and not to the Verizon Intelligent API itself.

- control_key: AC-6 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The Verizon Intelligent API has only one class of user,
        which has read-only access to data. There are no privileged functions
        available to users or processes acting on their behalf. This is default,
        non-configurable behavior, and the Verizon Intelligent API cannot be
        configured to be out of compliance with this control.

        Note that privileged functions which could impact the Verizon
        Intelligent API, such as starting or reconfiguring the service,
        is handled by the administrators of the hosting platform upon
        which the Verizon Intelligent API is hosted. This control
        is appropriately scoped to the administration of that platform,
        and not to the Verizon Intelligent API itself.

- control_key: AC-7
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: inherited
  narrative:
    - key: a
      text: |-
        The Verizon Intelligent API integrates with enterprise authentication
        mechanisms, such as enterprise OAuth2 services, to logon users or
        processes acting on their behalf.

        It is the responsibility of the enterprise authentication or
        identity management system to enforce a limit of an organization-defined
        number of consecutive invalid logon attempts by a user during a
        organization-defined time period.
    - key: b
      text: |-
        The Verizon Intelligent API integrates with enterprise authentication
        mechanisms, such as enterprise OAuth2 services, to logon users or
        processes acting on their behalf.

        It is the responsibility of the enterprise authentication or
        identity management system to address this control.

- control_key: AC-7 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev5, this control was withdrawn and incorporated
        into AC-7.

- control_key: AC-7 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Management of mobile devices is outside the scope
        of configuring the Verizon Intelligent API.

- control_key: AC-7 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: inherited
  narrative:
    - text: |
        The Verizon Intelligent API inherits user management from an
        enterprise authentication system, such as an OAuth2 provider,
        and does not natively perform any user management or authentication
        functions. This is default, non-configurable, behavior and
        the Verizon Intelligent API cannot be configured to be out
        of compliance with this control.

- control_key: AC-7 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: inherited
  narrative:
    - key: a
      text: |-
        The Verizon Intelligent API inherits user management from an
        enterprise authentication system, such as an OAuth2 provider,
        and does not natively perform any user management or authentication
        functions. This is default, non-configurable, behavior and
        the Verizon Intelligent API cannot be configured to be out
        of compliance with this control.
    - key: b
      text: |-
        The Verizon Intelligent API inherits user management from an
        enterprise authentication system, such as an OAuth2 provider,
        and does not natively perform any user management or authentication
        functions. This is default, non-configurable, behavior and
        the Verizon Intelligent API cannot be configured to be out
        of compliance with this control.

- control_key: AC-8
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        The Verizon Intelligent API currently does not disaply an
        organization-defined system use notification message or banner to users
        before granting access to the system.

        This functionality is planned for a future version.
    - key: b
      text: |
        The Verizon Intelligent API currently does not display an
        organizatin-defined system use notification message or banner to users
        before granting access to the system.

        This functionality is planned for a future version.
    - key: c
      text: |
        The Verizon Intelligent API currently does not display an
        organizatin-defined system use notification message or banner to users
        before granting access to the system.
        
        This functionality is planned for a future version.

- control_key: AC-9
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The Verizon Intelligent API currently does not have the capability to
        notify the user, upon successful logon to the system, of the date and time
        of the last logon.

        This functionality is planned for a future version.

- control_key: AC-9 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The Verizon Intelligent API does not currently notify the user, upon
        successful logon, of the number of unsuccessful logon attempts since the
        last successful logon.

        This functionality is planned for a future version.

- control_key: AC-9 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The Verizon Intelligent API currently does not notify the user, upon
        successful logon, of the number of succesful logons, unsuccessful logon
        attempts, or both, during an organization-defined time period.

        This functionality is planned for a future version.

- control_key: AC-9 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The Verizon Intelligent API currently does not notify the user, upon successful
        logon, of changes to organization-defined security-related characteristics or
        parameters of the user's account during an organization-defined time period.
        
        This functionality is planned for a future version.

- control_key: AC-9 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The Verizon Intelligent API currently does not notify the user, upon successful
        logon, of additional organization-defined additional information.
        
        This functionality is planned for a future version.

- control_key: AC-10
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        Currently, an authenticated user, or process acting on their behalf,
        can issue API calls to the Verizon Intelligent API in any order
        their mission requires, to include simultanious sessions.

        As an API, this control negatively impacts the mission purpose
        of the Verizon Intelligent API and is not implemented.

- control_key: AC-11
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Device management is outside the scope of the operation
        and configuration of the Verizon Intelligent API.
    - key: b
      text: |
        Device management is outside the scope of the operation and configuration
        of the Verizon Intelligent API.

- control_key: AC-11 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        Device management is outside the scope of the operation and configuration
        of the Verizon Intelligent API.

- control_key: AC-12
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The Verizon Intelligent API currently does not automatically terminate
        a user session after organization-defined conditions or trigger events
        requiring session disconnect.

        This capability will be incorporated into a future version of the
        Verizon Intelligent API.

- control_key: AC-12 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |-
        The Verizon Intelligent API currently does not provide a logout capability
        for user-initiated communication sessions whenever authentication is used to
        gain access to organization-defined information resources.

        This capability will be incorporated into a future version of the
        Verizon Intelligent API.

- control_key: AC-12 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |-
        The Verizon Intelligent API currently does not display an explicit logout message
        to users indicating the termination of authenticated communications sessions.

        This functionality is planned for a future version of the
        Verizon Intelligent API.

- control_key: AC-12 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |-
        The Verizon Intelligent API currently does not display an explicity message to users
        inidcating that the session will end in an organization-defined time until
        end of session.

        This functionality is planned for a future version of the
        Verizon Intelligent API.

      
- control_key: AC-13
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev5, this control was withdrawn and incorporated into
        AC-2 and AU-6 by NIST.

- control_key: AC-14
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - key: a
      text: |-
        There are no user actions that can be performed on the Verizon Intelligent API
        without identification or authentication. This is default, non-configurable
        behavior and the Verizon Intelligent API cannot be configured to be
        out of compliance with this control.
    - key: b
      text: |-
        There are no user actions that can be performed on the Verizon Intelligent API
        without identification or authentication. This is default, non-configurable
        behavior and the Verizon Intelligent API cannot be configured to be
        out of compliance with this controls.
    
- control_key: AC-14 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        As of NIST 800-53 rev5, this control was withdrawn and incorporated into
        AC-14 by NIST.

- control_key: AC-15
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        As of NIST 80053 rev5, this control was withdrawn and incorporated into
        MP-3 by NIST.

- control_key: AC-16
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |-
        The Verizon Intelligent API queries data and exposes it on an API. If the source
        data provides data fields that associate organization-defined types of security
        and privacy attributes with organization-defined security and privacy attribute
        values for information, then those fields will be exposed in the API
        for downstream consumers to utilize.
    - key: b
      text: |-
        The Verizon Intelligent API queries data and exposes it on an API. If the source
        data ensures that the attribute associations are made and retained with the inforation,
        e.g. through data schema, then those attribute associations will be exposed in the
        API for downstream consumers to utilize.
    - key: c
      text: |-
        The Verizon Intelligent API queries data and exposes it on an API. If the source
        data provided established the foloowing permitted security and privacy attributes
        from the attributes defined in AC-16a for organization-defined systems, to include
        organization-defined security and privacy attributes, then those attributes will be
        exposed in the API for downstream consumers to utilize.
    - key: d
      text: |-
        The Verizon Intelligent API queries data and exposes it on an API. If the source
        data provider determined the following permitted attribute values or ranges for each
        of the established attributes in an organization-defined attribute values or ranges
        for established attributes, then that data will be exposed in the API for
        downstream consumers to utilize.
    - key: e
      text: |-
        The Verizon Intelligent API queries data and exposes it on an API. There is no
        capability to change source data, and the Verizon Intelligent API cannot
        be configured to be out of compliance with this control.

        Auditing changes to attributes of source data is the responsibility of the source
        data provider/owner.
    - key: f
      text: |-
        The Verizon Intelligent API queries data and exposes it on an API.

        The review of organization-defined security and privacy attributes of that
        data for applicability on an organization-defined frequency is the responsibility
        of the source data provider/owner.

- control_key: AC-16 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        The Verizon Intelligent API queries and displays information from
        a data source, however cannot manipulate the data in any way. This is
        default, non-configurable, behavior which cannot be modified.

        Dynamic attribute association is the responsibility of the data
        source/data owner, and outside the scope of the Verizon Intelligent API.

- control_key: AC-16 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        The Verizon Intelligent API queries and displays information from
        a data source, however cannot manipulate the data in any way. This is
        default, non-configurable, behavior that cannot be modified.

        Providing authorized individuals (or processes acting on their behalf of
        individuals) the capability to define or change the value of associated
        security and privacy attributes is outside the scope of the operation
        and configuration of the Verizon Intelligent API.

- control_key: AC-16 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: inherited
  narrative:
    - text: |
        The Verizon Intelligent API queries and displays information from
        a data source, however cannot manipulate the data in any way. This is
        default, non-configurable, behavior that cannot be modified. The
        Verizon Intelligent API cannot be configured to be out of compliance
        with this control.

        In practice, this ensures that the Verizon Intelligent API maintains
        the association and integrity of organization-defined security and
        privacy attributes to organization-defined subjects and objects, as
        long as the association is provided natively in the data of which the
        Verizon Intelligent API is querying and displaying.

- control_key: AC-16 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: inherited
  narrative:
    - text: |
        The Verizon Intelligent API queries and displays information from a data source,
        however cannot manipulate the data in any way. This is default, non-configurable,
        behavior that cannot be modified. The Verizon Intelligent API cannot be configured
        to be out of compliance with this control.

        In practice, this means that as long as the source data associates organization-defined
        security and privacy attributes with organization-defined subjects and objects by
        authorized individuals (or processes acting on behalf of individuals), then that
        association data will be available through the Verizon Intelligent API.

- control_key: AC-16 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: inherited
  narrative:
    - text: |
        The Verizon Intelligent API queries and displays information from a data source.

        As long as the data source exposes security and privacy attributes, the
        Verizon Intelligent API will include that information (eg data schema fields).

- control_key: AC-16 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Requiring personnel to associate and maintain the association of organization-defined
        security and privacy attributes with organization-defined subjects and objects
        in accordance with organization-defined seucrity and privacy policies, is a procedural
        control outside the scope of configuring and operating the Verizon Intelligent API.

- control_key: AC-16 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        The Verizon Intelligent API queries and forwards data from a data source. If the
        data source provides consistent interpretation of security and privacy attributes, such
        as throgh a standardized data schema/data fields of which the Verizon Intelligent API
        can query, then those attributes will be transmitted with API responses automatically.

- control_key: AC-16 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Implementation of organization-defined techniques and technologies in associating
        security and privacy attributes is an organizational control outside the scope of
        operating and configuring the Verizon Intelligent API.

- control_key: AC-16 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Attribute reassignment is outside the scope of configuring and operating the
        Verizon Intelligent API. The Verizon Intelligent API can only query source data,
        and provides no mechanisms to manipulate data. This is default, non-configurable,
        behavior and the Verizon Intelligent API cannot be configured to be out of compliance
        with this control.

- control_key: AC-16 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Attribute configuration by authorized individuals is outside the scope
        of the Verizon Intelligent API.

        Note the Verizon Intelligent API queries data from a data source and provides
        no mechanism to modify the data. This is default, non-configurable, behavior and
        the Verizon Intelligent API cannot be configured to provide a mechanism to
        modify the data.

- control_key: AC-17
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: in process
  narrative:
    - key: a
      text: |
        Documentation on the usage restrictions, configuration/connection requirements,
        and implementation guidance for remote access to the Verizon Intelligent API
        is under development.
    - key: b
      text: |
        This is an organizational control outside the scope of configuring
        or operating the Verizon Intelligent API.

- control_key: AC-17 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Employment of automated mechanisms to monitor and control remote
        access methods is outside the scope of the configuration and operation
        of the Verizon Intelligent API.

        This is typically provided by network monitoring services, such as
        a Network Operatins Center (NOC) or a Security Operations Center (SOC).

- control_key: AC-17 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        The Verizon Intelligent API utilizes FIPS 140 validated SSL, provided
        by the host compute platform, to implement crypographic mechanisms to protect
        the confidentiality and integrity of remote access sessions.

        There are no non-encrypted access mechanisms to the Verizon Intelligent API.

        This is default, non-configurable, behavior and the Verizon Intelligent API cannot
        be configured to be out of compliance with this control.

- control_key: AC-17 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Managed access control points are outside the scope of the configuration
        and operation of the Verizon Intelligent API.

- control_key: AC-17 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: inherited
  narrative:
    - key: a
      text: |
        The Verizon Intelligent API does not have privileged commands. The
        Verizon Intelligent API queries data sources, on a read-only basis, and passes
        the data to the end user of the API. 

        Typical privileged commands, such as starting or stopping the Verizon Intelligent API,
        or reconfiguring it, are provided through the host compute platform. 
    - key: b
      text: |
        The Verizon Intelligent API queries data sources, typically a Private 5G network
        core, and exposes that data in a read-only manner to downstream users (or processes
        acting on behalf of a user). The existance of the Verizon Intelligent API ensures that
        users are not directly accessing the Private 5G core directly, and instead, have read-only
        access through the Verizon Intelligent API.

- control_key: AC-17 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev5, this control was withdrawn and incorporated into SI-4
        by NIST.

- control_key: AC-17 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Ensuring users protect information from unauthorized use and disclosure
        is an organizational control outside the scope of the configuration
        and operation of the Verizon Intelligent API.

- control_key: AC-17 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev5, this control was withdrawn and incorporated into
        AC-3 (10) by NIST.

- control_key: AC-17 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev5, this control was withdrawn and incorporated into
        CM-7 by NIST.

- control_key: AC-17 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: inherited
  narrative:
    - text: |
        The Verizon Intelligent API is a software application deployed upon a compute
        hosting environment, such as Kubernetes. It is the responsibility of the underlying
        platform to provide the capability to disconnect or disable remote access to the
        Verizon Intelligent API within an organization-defined time period.

- control_key: AC-17 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        The Verizon Intelligent API utilizes an enteprise authentication provider,
        such as an OAuth2 provider, to authenticate all remote connections and commands.
        
- control_key: AC-18
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational processes regarding the establishment of wireless
        access usage restrictions are outside the scope of configuring the Verizon Intelligent API.
    - key: b
      text: |
        Organizational processes regarding wireless access to the information
        system are outside the scope of configuring the Verizon Intelligent API.

- control_key: AC-18 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Configuration of wireless networking is outside the scope of
        configuring the Verizon Intelligent API.

- control_key: AC-18 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev5, this control was withdrawn and incorporated
        into SI-4 by NIST.

- control_key: AC-18 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        Configuration of wireless networking is outside the scope of
        configuring the Verizon Intelligent API.

- control_key: AC-18 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        Configuration of wireless networking is outside the scope of
        configuring the Verizon Intelligent API.

- control_key: AC-18 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Radio antenna selection and calibration is outside the scope
        of configuring the Verizon Intelligent API.

- control_key: AC-19
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Establishing organizational usage restrictions for mobile devices is outside
        the scope of configuring the Verizon Intelligent API.
    - key: b
      text: |
        Authorization of mobile devices is outside the scope of configuring the
        Verizon Intelligent API.

- control_key: AC-19 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev5, this control was withdrawn and incorporated into
        MP-7 by NIST.

- control_key: AC-19 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev5, this control was withdrawn and incorporated into
        MP-7 by NIST.

- control_key: AC-19 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev5, this control was withdrawn and incorporated into
        MP-7 by NIST.

- control_key: AC-19 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational restrictions on the use of mobile devices is outside
        the scope of configuring the Verizon Intelligent API.
    - key: b
      text: |
        Enforcement of organizational restrictions of mobile devices is
        outside the scope of configuring the Verizon Intelligent API.
    - key: c
      text: |
        Restricting the connection of classified mobile devices to
        classified information systems is outside the scope of This control was withdrawn by NIST.
        the Verizon Intelligent API configuration.

- control_key: AC-19 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Encryption strategies for mobile devices is outside
        the scope of configuring the Verizon Intelligent API.

- control_key: AC-20
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational processes for establishing terms and conditions
        for accessing the information system from external information
        systems is outside the scope of configuring the Verizon Intelligent API.
    - key: b
      text: |
        Organizational processes for establishing terms and conditions
        for the processing, storage, or transmission of organization-controlled
        information using external information systems is outside the scope
        of configuring the Verizon Intelligent API.

- control_key: AC-20 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Verification of security control implementation on external systems
        is outside the scope of configuring the Verizon Intelligent API.
    - key: b
      text: |
        Retention of approved information system connection or processing
        agreements with organizational entities hosting the external
        information system is outside the scope of configuring the Verizon Intelligent API.

- control_key: AC-20 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational processes regarding the restriction or
        prohibiting of the use of organization-controlled portable
        storage devices by authorized individuals on external information
        systems is outside the scope of configuring the Verizon Intelligent API.

- control_key: AC-20 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational processes regarding the restriction or
        prohibiting of the use of non-organizationally owned
        information systems, system components, or devices to process,
        store, or transmit organizational information, is
        outside the scope of configuring the Verizon Intelligent API.

- control_key: AC-20 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational processes regarding prohibiting the use of
        organization-defined network accessible storage devices in
        external information systems is beyond the scope of
        the Verizon Intelligent API configuration.

- control_key: AC-20 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational processes that prohibit the use of organization-defined network
        accessible storage devices in external systems are outside the scope of
        the configuration and operation of the Verizon Intelligent API.

- control_key: AC-21
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Facilitation of information sharing is outside the scope
        of configuring the Verizon Intelligent API.
    - key: b
      text: |
        Employment of technology or processes to assist users in making
        information sharing/collaboration decisions is outside
        the scope of configuring the Verizon Intelligent API.

- control_key: AC-21 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Enforcement of information-sharing decisions is outside
        the scope of configuring the Verizon Intelligent API.

- control_key: AC-21 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Implementation of information search and retrieval services
        that enforce organization-defined information sharing restrictions
        is outside the scope of configuring the Verizon Intelligent API.

- control_key: AC-22
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational processes regarding the designation of individuals
        authorized to post information onto a publicly accessible information
        system is outside the scope of configuring the Verizon Intelligent API.
    - key: b
      text: |
        Training authorized individuals to ensure that publicly accessible
        information does not contain nonpublic information is outside the
        scope of configuring the Verizon Intelligent API.
    - key: c
      text: |
        Reviewing the proposed content of information prior to posting onto
        the publicly accessible information system to ensure that nonpublic
        information is not included is outside the scope of Red Hat Virtualization Manager (RHVM)
        configuration.
    - key: d
      text: |
        Reviewing content on the publicly accessible information system
        for nonpublic information at an organization-defined frequency and
        removal of such information, if discovered, is outside the scope of
        configuring the Verizon Intelligent API.

- control_key: AC-23
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        The Verizon Intelligent API integrates with enterprise authentication
        and identity mangement systems, such as OAuth2 providers. The
        Verizon Intelligent API will not reply to any requests prior to
        successfully authenticating users.

        This is default, non-configurable, behavior that cannot be modified.

- control_key: AC-24
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        The establishment of organizational procedures or implementation mechanisms to ensure
        organization-defined access control decisions are applied to each access request prior to
        access enforcement is outside the scope of the configuration and operation of the
        Verizon Intelligent API.

- control_key: AC-24 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        The Verizon Intelligent API integrates with enterprise authentication
        and identity management systems, such as an OAuth2 provider. The connection
        between the Verizon Intelligent API is always encrypted, and this is
        default, non-configurable, behavior which cannot be modified.

- control_key: AC-24 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: inherited
  narrative:
    - text: |
        The Verizon Intelligent API integrates with enterprise authentication
        and identity management systems, such as an OAuth2 provider.

        It is the responsibility of the enterprise authentication or identity
        management system to enforce access control decisions based on organization-defined
        security or privacy attributes that do not include the identity of the user or process
        acting on behalf of the user.

- control_key: AC-25
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Implementation of a reference monitor is outside the scope of the
        configuration and operation of the Verizon Intelligent API.##
## BEGINNING OF:
## AWARENESS AND TRAINING CONTROLS
##

- control_key: AT-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.

- control_key: AT-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.
    - key: d
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.

- control_key: AT-2 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.

- control_key: AT-2 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.

- control_key: AT-2 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.

- control_key: AT-2 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.

- control_key: AT-2 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.

- control_key: AT-2 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.

- control_key: AT-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.

- control_key: AT-3 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.

- control_key: AT-3 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.

- control_key: AT-3 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.

- control_key: AT-3 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.

- control_key: AT-3 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.

- control_key: AT-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.

- control_key: AT-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev4 this control was withdrawn
        and incorporated into PM-15.

- control_key: AT-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.
##
## BEGINNING OF:
## AUDIT AND ACCOUNTABILITY
##
## Reminder of "implementation_status" codes:
##  - implementation_status: unsatisfied
##  - implementation_status: unknown
##  - implementation_status: planned
##  - implementation_status: partial
##  - implementation_status: complete
##  - implementation_status: none

- control_key: AU-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Developing an organization-level audit and accountability
        policy is outside the scope of Verizon Intelligent API configuration.
    - key: b
      text: |
        Designating an official to manage the development, documentation,
        and dissemination of the audit 
    - key: c
      text: |
        Review and updating an organizational-level audit and
        accountability policy is outside the scope of Verizon Intelligent API
        configuration.

- control_key: AU-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: partial
  narrative:
    - key: a
      text: |-
        The selection of organization-defined auditable events is not applicable
        to the configuration of Verizon Intelligent API.

        However, as supplementary information, the Verizon Intelligent API
        was designed to audit a relevant events identified in Intelligence
        Community Standard Number 500-27 (ICS 500-27).

        The following set of auditable events represent a minimal set of events
        suggested to be audited:

            - Authentication Events
              * API Session Creation (Success/Failure)
              * API Session Termination (Success/Failure)
  
            - Reboot, Restart & Shutdown of the Verizon Intelligent API (Success/Failure)
              * NOTE: These audit events will likely have to be performed at the
                compute host layer.
    - key: b
      text: |
        Coordinating the security audit function with other
        organizational entities is outside the scope of
        system configuration.
    - key: c
      text: |
        For rationale regarding why the auditable events are deemed to be
        adequate to support after-the-fact investigations of security incidents,
        please contact your countries Common Criteria representative:
        https://www.commoncriteriaportal.org/ccra/members/
    - key: d
      text: |
        The frequency (or situation requiring) the audit of events identified
        in AU-2(a) is not applicable to the configuration of Red Hat
        Virtualization Host (RHVH).

        As supplementary information, RHVH is capable of auditing the success and
        failure, in realtime, of events identified in AU-2(a).

- control_key: AU-2 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST.

- control_key: AU-2 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST.

- control_key: AU-2 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational review and updates to the audited events are
        outside the scope of Verizon Intelligent API configuration.

- control_key: AU-2 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST.

- control_key: AU-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |-
        Verizon Intelligent API audit records contain
        the required information and cannot be configured to be out of
        compliance with this control.

- control_key: AU-3 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: AU-3 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: partial
  narrative:
    - text: |
        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: AU-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20419

- control_key: AU-4 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: AU-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - key: a
      text: |-
        The audit subsystem was designed to uniquely identify multiple causes
        of audit processing failures. Configuring the audit subsystem to alert,
        or take alternative actions such as shutdown, is detailed in AC-5(b).

        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20421
    - key: b
      text: |-
        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20421

- control_key: AU-5 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20422

- control_key: AU-5 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20423

- control_key: AU-5 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: partial
  narrative:
    - text: |
        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: AU-5 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: AU-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational review and analysis of information system
        audit records for indications of organization-defined
        inappropriate or unusual activity is outside the scope
        of Verizon Intelligent API configuration.
    - key: b
      text: |
        Reporting findings of organization-defined inappropriate or
        unusual activity to organization-defined personnel or roles is
        outside the scope of Verizon Intelligent API configuration.

- control_key: AU-6 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational use of automated mechanisms to integrate audit review,
        analysis, and reporting processes to support organizational processes for
        investigation and response to suspicious activities is outside the scope
        of Verizon Intelligent API configuration.

- control_key: AU-6 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST.

- control_key: AU-6 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational analysis and correlation of audit records across
        different repositories to gain organization-wide
        situational awareness is outside the scope
        of Verizon Intelligent API configuration.

        To aide in such organizational processes, note that Verizon Intelligent API's
        cluster loggging "Log Forward" feature enables Verizon Intelligent API
        administrators to configure custom pipelines to send container
        logs to remote destinations. These remote destinations, such as
        Elastic or Splunk endpoints, could be used for information
        system-wide correlation.

- control_key: AU-6 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational capability to centrally review and analyze
        audit records from multiple components within the system
        is outside the scope of Verizon Intelligent API configuration.
        Note: When AU-4 (1) is enforced Verizon Intelligent API will be configured
        to off-load audit records onto a different system
        or media than the system being audited. In practice this correlates
        to offloading audit records to a SIEM (e.g. Elastic). However,
        this control is specifically about centralized review and analysis,
        and not offloading records, thus AU-6 (4) is marked as not
        applicable.

- control_key: AU-6 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational capability to integrate analysis or audit
        records with analysis of additional organization-defined
        data/information collected from other sources to further
        enhance the ability to identify inappropriate or unusual
        activity is outside the scope of Verizon Intelligent API configuration.

        To aide in such organizational processes, note that Verizon Intelligent API's
        cluster loggging "Log Forward" feature enables Verizon Intelligent API
        administrators to configure custom pipelines to send container
        logs to remote destinations. These remote destinations, such as
        Elastic or Splunk endpoints, could be used for information
        system-wide correlation.

- control_key: AU-6 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational capability to correlate information from
        Verizon Intelligent API audit records with information obtained from monitoring
        physical access to further enhanced the ability to identify
        suspicious, inappropriate, unusual, or malevolent activity
        is outside the scope of Verizon Intelligent API configuration.

        To aide in such organizational processes, note that Verizon Intelligent API's
        cluster loggging "Log Forward" feature enables Verizon Intelligent API
        administrators to configure custom pipelines to send container
        logs to remote destinations. These remote destinations, such as
        Elastic or Splunk endpoints, could be used to correlate Verizon Intelligent API
        logs with physical access data.

- control_key: AU-6 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational specification of permitted actions for
        information system processes, roles, and/or users, associated
        with the review, analysis, and reporting of audit
        information is outside the scope of Verizon Intelligent API configuration.

- control_key: AU-6 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational processes to perform full text analysis or audited
        privileged commands in a physically distinct component or subsystem
        of the information system, or other information system that is
        dedicated to that analysis, is outside the scope of Verizon Intelligent API
        configuration.

- control_key: AU-6 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational processes to correlate information
        from nontechnical sources with audit information to enhance
        organization-wide situational awareness is outside
        the scope of Verizon Intelligent API configuration.

- control_key: AU-6 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational adjustment of the level of audit review, analysis, and
        reporting within the information system when there is a change in risk
        based on law enforcement information, intelligence information, or other
        credible sources of information, is outside the scope of Verizon Intelligent API
        configuration.

- control_key: AU-7
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20424
    - key: b
      text: |
        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20424

- control_key: AU-7 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20425

- control_key: AU-7 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: AU-8
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - key: a
      text: |
        By default the audit subsystem utilizes the system clock and cannot be
        configured to be out of compliance with this control.
    - key: b
      text: |
        The audit subsystem is hard coded to only accept internationally recognized
        timezone settings. This ensures audit log timestamps can be mapped to
        Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT).

        To ensure the underlying system clocks are accurate within an
        organization-defined granularity of time measurement, the system must be
        configured to synchronize with an authoritative time source. Such
        configuration is detailed in AU-8(1).

- control_key: AU-8 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |-
        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: b
      text: |
        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: AU-8 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: AU-9
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |-
        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: AU-9 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Writing audit trails to hardware enforced, write-once media,
        is outside the scope of Verizon Intelligent API configuration.

- control_key: AU-9 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Backup of audit records onto a physically different system or
        system component than the component being audited is the
        responsibility of the centralized audit facility defined in
        AU-4 (1), "Transfer to Alternate Storage," and outside
        the scope of Verizon Intelligent API configuration.

- control_key: AU-9 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: partial
  narrative:
    - text: |
        Enforcement of cryptographic protectionm is the responsibility of the centralized audit
        facility, and outside the scope of Verizon Intelligent API configuration.

- control_key: AU-9 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        A control response is planned. Engineering progress can be tracked
        via:

        https://projects.engineering.redhat.com/browse/RHV-20506

- control_key: AU-9 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        Per AU-4 (1), Verizon Intelligent API will be configured to offload audit records
        to a centralized audit facility. Enforcement of dual authorization
        for movement and/or deletion of organization-defined audit
        information is the responsibility of the centralized audit
        facility, and outside the scope of Verizon Intelligent API configuration.

- control_key: AU-9 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: partial
  narrative:
    - text: |
        A control response is planned. Engineering progress can be tracked
        via:

        https://projects.engineering.redhat.com/browse/RHV-22656

- control_key: AU-10
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned. Engineering progress can be tracked
        via:

        https://projects.engineering.redhat.com/browse/RHV-20507

- control_key: AU-10 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A control response is planned. Engineering progress can be tracked
        via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: b
      text: |
        A control response is planned. Engineering progress can be tracked
        via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: AU-10 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A control response is planned. Engineering progress can be tracked
        via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: b
      text: |
        A control response is planned. Engineering progress can be tracked
        via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: AU-10 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned. Engineering progress can be tracked
        via:

        https://projects.engineering.redhat.com/browse/RHV-1

- control_key: AU-10 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A control response is planned. Engineering progress can be tracked
        via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: b
      text: |
        A control response is planned. Engineering progress can be tracked
        via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: AU-10 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST.

- control_key: AU-11
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |-
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Verizon Intelligent API.

        However, once an organization-defined time period record retention is
        created, and audit logs are being kept locally on the system, it
        is important to ensure the audit logs will not automatically be rotated
        or discarded after exceeding a certain file size.

        A control response is planned. Engineering progress can be tracked
        via:

        https://projects.engineering.redhat.com/browse/RHV-20509

- control_key: AU-11 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned. Engineering progress can be tracked
        via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: AU-12
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |-
        A control response is planned. Engineering progress can be tracked
        via:

        https://projects.engineering.redhat.com/browse/RHV-20513
    - key: b
      text: |-
        A control response is planned. Engineering progress can be tracked
        via:

        https://projects.engineering.redhat.com/browse/RHV-20513
    - key: c
      text: |-
        A control response is planned. Engineering progress can be tracked
        via:

        https://projects.engineering.redhat.com/browse/RHV-20513

- control_key: AU-12 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned. Engineering progress can be tracked
        via:

        https://projects.engineering.redhat.com/browse/RHV-20514

- control_key: AU-12 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned. Engineering progress can be tracked
        via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: AU-12 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned. Engineering progress can be tracked
        via:

        https://projects.engineering.redhat.com/browse/RHV-20515

- control_key: AU-13
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Monitoring of organization-defined open source information
        and/or information sites at an organization-defined frequency for
        evidence of unauthorized disclosure of organizational information
        is outside the scope of Verizon Intelligent API configuration.

- control_key: AU-13 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Employment of automated mechanisms to determine if
        organizational information has been disclosed in an
        unauthorized manner is outside the scope of
        Verizon Intelligent API configuration.

- control_key: AU-13 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Reviews of the open source information sites being monitored
        at an organization-defined frequency is outside the scope
        of Verizon Intelligent API configuration.

- control_key: AU-14
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned. Engineering progress can be tracked
        via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: AU-14 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned. Engineering progress can be tracked
        via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: AU-14 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        A control response is planned. Engineering progress can be tracked
        via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: AU-14 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned. Engineering progress can be tracked
        via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: AU-15
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Providing an alternate audit capability in the event of a failure in primary audit
        capability is an organizational control outside of Verizon Intelligent API.

- control_key: AU-16
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Employment of organization-defined methods for coordinating
        organization-defined audit information among external
        organizations when audit information is transmitted
        across organizational boundaries is outside the scope
        of Verizon Intelligent API configuration.

- control_key: AU-16 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned. Engineering progress can be tracked
        via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: AU-16 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Providing cross-organizational audit information to
        organization-defined organizations based on
        organization-defined cross-organizational sharing
        agreements is outside the scope of Verizon Intelligent API
        configuration.
##
## BEGINNING OF:
## SECURITY ASSESSMENT AND AUTHORIZATION
##

- control_key: CA-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Establishing organizational security assessment and
        authorization policy and procedures is outside
        the scope of Red Hat Virtualization Manager (RHVM) configuration guidance.
    - key: b
      text: |
        Establishing organizational security assessment and
        authorization policy and procedures is outside
        the scope of Red Hat Virtualization Manager (RHVM) configuration guidance.

- control_key: CA-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Development of an organizational security assessment plan
        is outside the scope of Red Hat Virtualization Manager (RHVM) configuration guidance.
    - key: b
      text: |
        Development of an organizational security assessment plan
        is outside the scope of Red Hat Virtualization Manager (RHVM) configuration guidance.
    - key: c
      text: |
        Development of an organizational security assessment plan
        is outside the scope of Red Hat Virtualization Manager (RHVM) configuration guidance.
    - key: d
      text: |
        Development of an organizational security assessment plan
        is outside the scope of Red Hat Virtualization Manager (RHVM) configuration guidance.

- control_key: CA-2 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Employment of independent assessors or assessment teams
        is outside the scope of Red Hat Virtualization Manager (RHVM) configuration guidance.

- control_key: CA-2 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Specialized security assessments are outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration guidance.

- control_key: CA-2 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational acceptance of the results of an assessment
        is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CA-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Establishment of organizational system interconnection
        agreements is outside the scope of Red Hat Virtualization Manager (RHVM) configuration
        guidance.
    - key: b
      text: |
        Establishment of organizational system interconnection
        agreements is outside the scope of Red Hat Virtualization Manager (RHVM) configuration
        guidance.

        Red Hat Virtualization Manager (RHVM) requires a number of ports to be
        opened to allow network traffic through the system firewall. The firewall
        rules are automatically configured by default when adding a new host to
        the Manager, overwriting any pre-existing firewall configuration.

        Documentation on RHVM interconnections is available in the
        Red Hat Virtualization Installation Guide available at:

        https://access.redhat.com/documentation/en-us/red_hat_virtualization/
    - key: c
      text: |
        Establishment of organizational system interconnection
        agreements is outside the scope of Red Hat Virtualization Manager (RHVM) configuration
        guidance.

- control_key: CA-3 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration guidance.

- control_key: CA-3 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration guidance.

- control_key: CA-3 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration guidance.

- control_key: CA-3 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration guidance.

- control_key: CA-3 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        This control is applicable to Red Hat Virtualization Manager (RHVM) and applicable
        through host-level firewall rules.

        Engineering progress can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-20516

- control_key: CA-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST.

- control_key: CA-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Creating an information system-level Plan of Action
        and Milestones (POA&M) is outside the scope of Red Hat Virtualization Manager (RHVM)
        configuration processes.
    - key: b
      text: |
        Organizational processes relating to updating and the maintenance
        of an information system-level Plan of Action and Milestones (POA&M)
        is outside the scope of Red Hat Virtualization Manager (RHVM) configuration processes.

- control_key: CA-5 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Updates and maintenance of an information system-level
        Plan of Action and Milestones (POA&M) document outside the
        scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CA-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational processes outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration guidance.
    - key: b
      text: |
        This control reflects organizational processes outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration guidance.
    - key: c
      text: |
        This control reflects organizational processes outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration guidance.

- control_key: CA-7
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        Engineering progress can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-20517
    - key: b
      text: |
        Engineering progress can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-20517
    - key: c
      text: |
        Engineering progress can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-20517
    - key: d
      text: |
        Engineering progress can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-20517
    - key: e
      text: |
        Engineering progress can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-20517
    - key: f
      text: |
        Engineering progress can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-20517
    - key: g
      text: |
        Engineering progress can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-20517

- control_key: CA-7 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Employment of assessors or assessment teams is outside the
        scope of Red Hat Virtualization Manager (RHVM) configuration guidance.

- control_key: CA-7 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST.

- control_key: CA-7 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational trend analyses processes are
        outside the scope of Red Hat Virtualization Manager (RHVM) configuration guidance.

- control_key: CA-8
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Penetration testing is outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration guidance.

- control_key: CA-8 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Employment of independent penetration testers
        is out of scope for Red Hat Virtualization Manager (RHVM) configuration
        guidance.

- control_key: CA-8 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Red Team Exercises are out of scope for
        Red Hat Virtualization Manager (RHVM) configuration guidance.

- control_key: CA-9
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |-
        Red Hat Virtualization Manager (RHVM) requires
        a number of ports to be opened to allow network traffic through
        the system firewall. The firewall rules are automatically configured
        by default when adding a new host to the Manager, overwriting any
        pre-existing firewall configuration.

        Documentation on RHVM interconnections is available in the
        Red Hat Virtualization Installation Guide available at:

        https://access.redhat.com/documentation/en-us/red_hat_virtualization/

        Engineering progress can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-20518
    - key: b
      text: |
        Red Hat Virtualization Manager (RHVM) requires
        a number of ports to be opened to allow network traffic through
        the system firewall. The firewall rules are automatically configured
        by default when adding a new host to the Manager, overwriting any
        pre-existing firewall configuration.

        Documentation on RHVM interconnections is available in the
        Red Hat Virtualization Installation Guide available at:

        https://access.redhat.com/documentation/en-us/red_hat_virtualization/

        Engineering progress can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-20518

- control_key: CA-9 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        CA-9 (1) reflects organizational processes outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration guidance.
##
## BEGINNING OF:
## CONFIGURATION MANAGEMENT
##
## Reminder of "implementation_status" codes:
##  - implementation_status: unsatisfied
##  - implementation_status: unknown
##  - implementation_status: planned
##  - implementation_status: partial
##  - implementation_status: complete
##  - implementation_status: none

- control_key: CM-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Developing, documenting, and disseminating an organizational configuration
        management policy is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Review and update procedures to the organizational configuration
        management policy is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CM-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20519

- control_key: CM-2 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20520
    - key: b
      text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20520
    - key: c
      text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20520

- control_key: CM-2 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20521

- control_key: CM-2 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20522

- control_key: CM-2 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST.

- control_key: CM-2 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST.

- control_key: CM-2 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: partial
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20523

- control_key: CM-2 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational issuance of organization-defined information
        systems, system components, or devices with organizational-defined
        configurations to individuals traveling to locations that the
        organization deems to be of significant risk is outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Organizational processes to apply organization-defined security
        safeguards to the devices when the individuals return is
        outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CM-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: partial
  narrative:
    - key: a
      text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: b
      text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: c
      text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: d
      text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: e
      text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: f
      text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: g
      text: |
        This control reflects organizational processes outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration guidance.

- control_key: CM-3 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational processes outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration guidance.
    - key: b
      text: |
        This control reflects organizational processes outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration guidance.
    - key: c
      text: |
        This control reflects organizational processes outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration guidance.
    - key: d
      text: |
        This control reflects organizational processes outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration guidance.
    - key: e
      text: |
        This control reflects organizational processes outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration guidance.
    - key: f
      text: |
        This control reflects organizational processes outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration guidance.

- control_key: CM-3 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational processes outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration guidance.

- control_key: CM-3 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: partial
  narrative:
    - text: |
        This control reflects organizational processes outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration guidance.

- control_key: CM-3 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        The requirement for an information security representative to be
        a member of the organization-defined configuration change
        control element is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CM-3 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: partial
  narrative:
    - text: |
        This control reflects organizational processes outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration guidance.

- control_key: CM-3 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: partial
  narrative:
    - text: |
        This control reflects organizational processes outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration guidance.

- control_key: CM-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational analysis of changes to the information system to
        determine potential security impacts prior to change implementation
        is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CM-4 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: partial
  narrative:
    - text: |
        This control reflects organizational processes outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration guidance.

- control_key: CM-4 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: partial
  narrative:
    - text: |
        This control reflects organizational processes outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration guidance.

- control_key: CM-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        This control reflects organizational processes outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration guidance.

- control_key: CM-5 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        A complete control response is planned. Progress can be
        tracked via:

        https://github.com/ComplianceAsCode/redhat/issues/897

- control_key: CM-5 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational processes outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration guidance.

- control_key: CM-5 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20591

- control_key: CM-5 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-22701

- control_key: CM-5 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: partial
  narrative:
    - key: a
      text: |
        A complete control response is planned. Progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-22703
    - key: b
      text: |
        This control reflects organizational processes outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration guidance.

- control_key: CM-5 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational processes outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration guidance.

- control_key: CM-5 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST.

- control_key: CM-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: partial
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of configuring
        this system component. Use of the NIST National Checklist
        for this system component is suggested as a supported,
        US Government recognized, vendor supported, baseline.

        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20523
    - key: b
      text: |
        The customer will be responsible for implementing configuration
        settings as defined in CM-6(a). A successful control response will
        describe how mandatory configuration settings are implemented. This can
        include the process or documentation followed.

        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20523
    - key: c
      text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20523
    - key: d
      text: |
        The customer will be responsible for monitoring and controlling
        changes to the configuration settings in accordance with organization
        policies and procedures. A successful control response will describe
        how changes are controlled and monitored. This can include limitations
        to privileges, how these changes are audited, and any tools in place to
        track and approve changes.

        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20523

- control_key: CM-6 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20524

- control_key: CM-6 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational processes outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration guidance.

- control_key: CM-6 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST.

- control_key: CM-6 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST.

- control_key: CM-7
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Red Hat Virtualization Manager (RHVM) is a purpose-built operating
        system baseline which only provides minimal/required functionality.
        No additional configuration is required for this control.

        This control reflects organizational processes outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration guidance.
    - key: b
      text: |
        The default firewall configuration is a deny-all allow-by-exception
        policy. No additional configuration is required for this control.

        This control reflects organizational processes outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration guidance.

- control_key: CM-7 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20525
    - key: b
      text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20525

- control_key: CM-7 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20592

- control_key: CM-7 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational processes outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration guidance.

- control_key: CM-7 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20593
    - key: b
      text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20593
    - key: c
      text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20593

- control_key: CM-7 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20594
    - key: b
      text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20594
    - key: c
      text: |
        This control reflects organizational processes outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration guidance.

- control_key: CM-8
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20779
    - key: b
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20779

- control_key: CM-8 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20780

- control_key: CM-8 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: CM-8 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20595
    - key: b
      text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20595

- control_key: CM-8 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational processes to include in the information system
        component inventory information, a means for identifying
        by name, position, and/or role, individuals responsible/accountable
        for administering those components, is outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CM-8 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational verification that all components within the
        authorization boundary of the information system are not
        duplicated in other information system component
        inventories is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CM-8 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-22704

- control_key: CM-8 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: partial
  narrative:
    - text: |
        A complete control response is planned. Progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: CM-8 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational processes outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration guidance.

- control_key: CM-8 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational assignment of organization-defined acquired information
        system components to an information system is outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Organizational processes to receive an acknowledgement from the
        information system owner of the assignment in CM-8(8)(a) is outside
        the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CM-9
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational processes outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration guidance.
    - key: b
      text: |
        This control reflects organizational processes outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration guidance.
    - key: c
      text: |
        This control reflects organizational processes outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration guidance.
    - key: d
      text: |
        This control reflects organizational processes outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration guidance.

- control_key: CM-9 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational processes to assign responsibility for developing the
        configuration management process to organizational personnel that are
        not directly involved in information system development are outside
        the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CM-10
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A complete control response is planned. Progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20596
    - key: b
      text: |
        A complete control response is planned. Progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20596
    - key: c
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: CM-10 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Establishment of organizational restrictions on open source software
        is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CM-11
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: partial
  narrative:
    - key: a
      text: |
        It is highly uncommon to deploy additional software on Red Hat
        Virtualization Manager (RHVM) nodes. The following are suggested
        policies to govern the installation of software by users:

        - All software packages must be cryptographically signed
        by a third party the organization trusts (such as
        Red Hat GPG keys);

        - All software repositories configured on the system
        must enforce GPG key verification prior to software
        installation;

        - Previous versions of software should be removed after newer
        versions have been installed.
    - key: b
      text: |
        The following configuration checks enforce the policies identified
        in CM-11(a):

        - CCE-26957-1: Ensure Red Hat GPG Key Installed

        - CCE-26876-3: Ensure gpgcheck Enabled for All YUM Package Repositories

        - CCE-26989-4: Ensure gpgcheck Enabled In Main YUM Configuration

        - CCE-80347-8: Ensure gpgcheck Enabled for Local Packages

        - CCE-80346-0: Ensure YUM Removes Previous Package Versions
    - key: c
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: CM-11 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        A complete control response is planned. Progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-222709

- control_key: CM-11 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        By default, Red Hat Virtualization Manager (RHVM) nodes only allow software
        installation with privileged access through the usage of sudo or the root user.
##
## BEGINNING OF:
## CONTINGENCY PLANNING
##

- control_key: CP-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Developing an organization-level contingency planning policy is
        outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Review and updating an organizational-level contingency planning
        policy is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CP-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Developing an organization-level contingency planning policy is
        outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Distribution of an organizational-level contingency planning
        policy is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: c
      text: |
        Coordinating contingency planning activities with incident handling
        activities is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: d
      text: |
        Reviewing organizational contingency plans for the information system
        at an organization-defined frequency is outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration.
    - key: e
      text: |
        Organizational processes to update the contingency plan are outside the
        scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: f
      text: |
        Organizational communication plans regarding the contingency plan are outside
        the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: g
      text: |
        Protection of the contingency plan from unauthorized disclosure and
        modification is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CP-2 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Coordinating contingency plan development with organizational elements
        responsible for related plans is outside the scope of Red Hat Virtualization Manager (RHVM)
        configuration.

- control_key: CP-2 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        To assist with this organizational control, documentation is being
        planned. Progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20781

- control_key: CP-2 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Planning for the resumption of essential missions and business
        functions within an organization-defined time period of contingency
        plan activation is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CP-2 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Planning for the resumption of all missions and business
        functions within an organization-defined time period of contingency
        plan activation is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CP-2 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Planning for the continuance of essential missions and business
        functions with little or no loss of operational continuity and
        sustainment of that continuity until full information system
        restoration at primary processing and/or storage sites
        is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CP-2 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        To assist with this organizational control, documentation is being
        planned. Progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20781

- control_key: CP-2 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Coordination of organizational contingency plans with the
        contingency plans of external service providers to ensure that
        contingency requirements can be satisfied is outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CP-2 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: CP-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Providing contingency training to information system users consistent
        with assigned roles and responsibilities within an organization-defined
        time period of assuming a contingency role or responsibility is outside
        the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Providing contingency training to information system users consistent
        with assigned roles and responsibilities when required by information
        system changes is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: c
      text: |
        Providing contingency training to information system users consistent
        with assigned roles and responsibilities at an organization-defined
        frequency is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CP-3 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Incorporating simulated events into contingency training to
        facilitate effective response by personnel in crisis
        situations is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CP-3 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Employment of automated mechanisms to provide a more thorough and
        realistic contingency training environment is outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CP-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Testing the contingency plan for the information system at an
        organization-defined frequency using organization-defined tests
        to determine the effectiveness of the plan and the organizational
        readiness to execute the plan is outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Organizational reviews of the contingency plan test results is outside
        the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: c
      text: |
        Organizational process to initiate corrective actions, if needed,
        are outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CP-4 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Coordinating contingency plan testing with organizational
        elements responsible for related plans is outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CP-4 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational testing of the contingency plan at the alternate
        processing site to familiarize contingency personnel with the
        facility and available resources is outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Organizational testing of the contingency plan at the alternate
        processing site to evaluate the capabilities of the alternate
        processing site to support contingency operations is outside
        the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CP-4 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: CP-4 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: CP-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST.

- control_key: CP-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Establishment of an alternative storage site including
        necessary agreements to permit the storage and retrieval
        of information system backup information is outside
        the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Ensuring that the alternative storage site provides information
        security safeguards equivalent to that of the primary site
        is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CP-6 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Identification of an alternate storage site that is
        separated from the primary storage site to reduce
        susceptibility to the same threats is outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CP-6 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: CP-6 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Identification of potential accessibility problems to the alternate
        storage site in an event of an area-wide disruption or disaster and
        the outline of explicit mitigation actions is outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CP-7
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b
      text: |
        To assist with this organizational control, documentation is being
        planned. Progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20598
    - key: c
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: CP-7 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Identification of an alternate processing site that is
        separated from the primary processing site to reduce
        susceptibility to the same threats is outside the
        scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CP-7 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Identification of potential accessibility problems to the
        alternate processing site in the event of an area-wide
        disruption or disaster and outline of explicit mitigation
        actions is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CP-7 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Development of alternate processing site agreements that contain
        priority-of-service provisions in accordance with organizational
        availability requirements (including recovery time objectives)
        is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CP-7 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: CP-7 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST.

- control_key: CP-7 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational planning and preparation for circumstances
        that preclude returning to the primary processing site
        is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CP-8
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Establishment of alternate telecommunications services
        is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CP-8 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Development of primary and alternate telecommunications service
        agreements that contain priority-of-service provisions in accordance
        with organizational availability requirements (including recovery
        time objectives) is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Requests for Telecommunications Service Priority for all
        telecommunucations services used for national security emergency
        preparedness in the event that the primary and/or alternate
        telecommunications services are provided by a common carrier
        are outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CP-8 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Obtaining alternate telecommunications services to reduce
        the likelihood of sharing a single point of failure with
        primary telecommunications services is outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CP-8 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Obtaining alternate telecommunications services from providers
        that are separated from primary service providers to reduce
        susceptibility to the same threats is outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CP-8 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Requiring primary and alternate telecommunications service
        providers to have contingency plans is outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Reviewing provider contingency plans to ensure that the plans
        meet organizational contingecny requirements is outside
        the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: c
      text: |
        Obtaining evidence of contingency testing/training by providers
        at an organization-defined frequency is outside the plannedscope
        of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CP-8 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Testing alternate telecommunication services at
        an organization-defined frequency is outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CP-9
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        The customer will be responsible for conducting daily incremental and
        weekly full backups of user-level information contained in the
        information system. Additional requirements and guidance include
        maintaining at least three backup copies of user-level information (at
        least one of which is available online) or provides an equivalent
        alternative. A successful control response will detail how backups of
        user-level information occurs, and how three backup copies are
        maintained.

        To assist with this organizational control, documentation is being
        planned. Progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20600
    - key: b
      text: |
        The customer will be responsible for conducting daily incremental and
        weekly full backups of system-level information contained in the
        information system. Additional requirements and guidance include
        maintaining at least three backup copies of user-level information (at
        least one of which is available online) or provides an equivalent
        alternative. A successful control response will detail how backups of
        user-level information occurs, and how three backup copies are
        maintained.

        To assist with this organizational control, documentation is being
        planned. Progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20600
    - key: c
      text: |
        The customer will be responsible for conducting daily incremental and
        weekly full backups of information system documentation including
        security-related documentation. Additional requirements and
        guidance include maintaining at least three backup copies of user-level
        information (at least one of which is available online) or provides an
        equivalent alternative. A successful control response will detail how
        backups of user-level information occurs, and how three backup copies
        are maintained.

        To assist with this organizational control, documentation is being
        planned. Progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20600
    - key: d
      text: |
        The customer will be responsible for protecting the confidentiality,
        integrity, and available of backup information at storage locations.
        Additional requirements and guidance include determining
        what elements of the cloud environment require the Information System
        Backup control. The customer will determine how Information System
        Backup is going to be verified and appropriate periodicity of the
        check.

        To assist with this organizational control, documentation is being
        planned. Progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20600

- control_key: CP-9 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Testing backup information for reliability and information integrity
        is an organizational control outside the scope of Red Hat Virtualization Manager (RHVM)
        configuration.

- control_key: CP-9 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Testing backup information for reliability and information integrity
        using sampling data is an organizational control outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: CP-9 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Storing backup copies of organization-defined critical information
        system software and other security-related information in a separate
        facility or in a fire-rated container that is not collocated with the
        operational system is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

        To assist with this organizational control, documentation is being
        planned. Progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20782

- control_key: CP-9 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST.

- control_key: CP-9 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: CP-9 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

        To assist with this organizational control, documentation is being
        planned. Progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: CP-9 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: CP-10
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        The customer will be responsible for documenting how to reconstitute
        their Red Hat Virtualization Manager (RHVM) environment. A successful control response will detail
        processes used to fully recover/restore the Red Hat Virtualization Manager (RHVM) environment.

        To assist with this organizational control, documentation is being
        planned. Progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20601

- control_key: CP-10 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST.

- control_key: CP-10 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: CP-10 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST.

- control_key: CP-10 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: CP-10 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST.

- control_key: CP-10 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: CP-11
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: CP-12
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: CP-13
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        Employment of organization-defined alternative or
        supplemental security mechanisms for satisfying
        organization-defined security functions when the primary
        means of implementing Red Hat Virtualization Manager (RHVM) security function is
        unavailable or compromised is outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration guidance.

        A complete control response is planned. Progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-
##
## BEGINNING OF:
## IDENTIFICATION AND AUTHENTICATION
##
## Reminder of "implementation_status" codes:
##  - implementation_status: unsatisfied
##  - implementation_status: unknown
##  - implementation_status: planned
##  - implementation_status: partial
##  - implementation_status: complete
##  - implementation_status: none

- control_key: IA-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Developing organization-level identification and authentication
        policy and procedures are outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Review and updating an organizational-level identification and authentication
        policy and procedures are outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IA-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20602

- control_key: IA-2 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20672

- control_key: IA-2 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20682

- control_key: IA-2 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20683

- control_key: IA-2 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20684

- control_key: IA-2 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        By default, Red Hat Virtualization Manager (RHVM) does not support or allow group authentication.

- control_key: IA-2 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-22707

- control_key: IA-2 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-22711

- control_key: IA-2 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20685

- control_key: IA-2 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20686

- control_key: IA-2 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-22712

- control_key: IA-2 (11)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20687

- control_key: IA-2 (12)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20688

- control_key: IA-2 (13)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Implementing out-of-band authentication methods is an organizational
        control outside the configuration guidance of Red Hat Virtualization Manager (RHVM).

- control_key: IA-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20689

- control_key: IA-3 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-22713

- control_key: IA-3 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST.

- control_key: IA-3 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-22714
    - key: b
      text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-22714

- control_key: IA-3 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-22715

- control_key: IA-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: partial
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: c
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: d
      text: |
        Red Hat Virtualization Manager (RHVM) is not capable of preventing
        the reuse of identifiers for an organization-defined time period.

        To satisfy this control, an external identity provider must be
        used (e.g. Red Hat Identity Management or Microsoft Active Directory).
    - key: e
      text: |
        To disable identifiers after an organization-defined time period
        of inactivity, the following configuration checks must be enforced
        for any local accounts:

        - CCE-27355-7: Set Account Expiration Following Inactivity

        When Red Hat Virtualization Manager (RHVM) is configured to an external
        identity provider (e.g. Red Hat Identity Management or Microsoft Active Directory),
        it is the responsibility of the identity provider to satisfy this control.

- control_key: IA-4 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: IA-4 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational procedural requirement
        outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IA-4 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational procedural requirement
        outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IA-4 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational procedural requirement
        outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IA-4 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Red Hat Virtualization Manager (RHVM) is not capable of dynamically managing
        authenticators as authenticators are passed through from an external
        identity provider.

        To satisfy this control, an external identity provider must be
        used (e.g. Red Hat Identity Management or Microsoft Active Directory).

- control_key: IA-4 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Coordination with organization-defined external
        organizations for cross-organization management
        of identifiers is outside the scope of Red Hat Virtualization Manager (RHVM)
        configuration.

- control_key: IA-4 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational requirements that the user registration
        process to receive an individual identifier be conducted
        in person before a designated registration authority
        is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IA-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        This is an organizational procedural requirement
        outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20783
    - key: c
      text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20783
    - key: d
      text: |
        This is an organizational procedural requirement
        outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: e
      text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20783
    - key: f
      text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20783
    - key: g
      text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20783
    - key: h
      text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20783
    - key: i
      text: |
        This is an organizational procedural requirement
        outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: j
      text: |
        This is an organizational procedural requirement
        outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IA-5 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: partial
  narrative:
    - key: a
      text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20784
    - key: b
      text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20784
    - key: c
      text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20784
    - key: d
      text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20784
    - key: e
      text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20784
    - key: f
      text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-20784

- control_key: IA-5 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-21004
    - key: b
      text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-21004
    - key: c
      text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-21004
    - key: d
      text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-21004

- control_key: IA-5 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational requirements that the registration process to
        receive organization-defined types of and/or specific authenticators
        be conducted either in person and/or by a trusted third party before
        organization-defined registration authority with authorization by
        organization-defined personnel or roles is outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IA-5 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-21004

- control_key: IA-5 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational procedural requirement
        outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
        By default, Red Hat Virtualization Manager (RHVM) does not configure or deliver
        default passwords or authenticators.

- control_key: IA-5 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational procedural requirement
        outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IA-5 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: IA-5 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational implementation of organization-defined security
        safeguards to manage the risk of compromise due to individuals having
        accounts on multiple information systems is outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IA-5 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational coordination with organization-defined
        external organizations for cross-organization management
        of credentials is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IA-5 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        To satisfy this control, an external identity provider must be
        used (e.g. Red Hat Identity Management or Microsoft Active Directory).

- control_key: IA-5 (11)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-21005

- control_key: IA-5 (12)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Employment of mechanisms that satisfy organization-defined
        biometric quality requirements is outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IA-5 (13)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: IA-5 (14)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: IA-5 (15)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: IA-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        Red Hat Virtualization Manager (RHVM) automatically obscures
        feedback of authentication information and cannot be configured
        to be out of compliance with this control.

        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-21006

- control_key: IA-7
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-21008

- control_key: IA-8
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        All information system users, regardless of organizational
        or non-organizational, receive unique system identifiers. This is
        non-configurable default behavior. Any attempts to alter
        user identifiers is audited through events defined in AU-2.

- control_key: IA-8 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-21009

- control_key: IA-8 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-21010

- control_key: IA-8 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-21011

- control_key: IA-8 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-21012

- control_key: IA-8 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: partial
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: IA-9
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Since Red Hat Virtualization Manager (RHVM) is not a service-oriented architecture,
        it is up to the organization to ensure that service identification
        and authentication is implemented.

- control_key: IA-9 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Ensuring that service providers receive, validate, and transmit
        identification and authentication information is an organizational
        control outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IA-9 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Ensureing that identification and authentication decisions are transmitted
        between organizationally defined services consistent with organizational
        policies is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IA-10
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Requiring that individuals accessing the information system employ
        organization-defined supplemental authentication techniques or
        mechanisms under specific organization-defined circumstances or
        situations is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IA-11
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-
##
## BEGINNING OF:
## INCIDENT RESPONSE
##
- control_key: IR-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: a.1
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: a.2
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b.1
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b.2
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: IR-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: c
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

##
## Note to content authors:
##  IR-2 (1) relates to creating simulated events/scenarios
##  relating to incident response. While this is an organizational
##  control, consider creating component-specific incident
##  response simulations as appropriate (e.g. if a virtualization
##  product, what happens after a VM escape?).
##
- control_key: IR-2 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IR-2 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IR-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IR-3 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IR-3 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IR-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: c
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: IR-4 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

##
## Note to content authors:
##  IR-4 (2) is *technically* an organizational control, however
##  many accreditors/auditors will want to understand how the
##  system component integrates with dynamic reconfiguration capabilities.
##  Lacking formal guidance from the government, some auditors expect a
##  response to this control at the component level.
##
- control_key: IR-4 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IR-4 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IR-4 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IR-4 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IR-4 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IR-4 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IR-4 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IR-4 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IR-4 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IR-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

##
## Note to content authors:
##  Often 3rd party auditors will incorrectly state satisfaction of IR-5 (1)
##  relates to centralized audit logging of security events.
##
##  Central audit logging is covered under other controls, namely:
##  - AU-6 (3) - Correlate Audit Repositories
##  - AU-6 (4) - Central Review and Analysis
##  - AU-12 - Audit Generation
##
- control_key: IR-5 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IR-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: IR-6 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IR-6 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IR-6 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IR-7
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: IR-7 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IR-7 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: IR-8
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: a.1
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: a.2
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: a.3
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: a.4
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: a.5
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: a.6
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: a.7
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: a.8
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: c
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: d
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: e
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: f
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: IR-9
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: c
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: d
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: e
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: f
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: IR-9 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IR-9 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IR-9 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IR-9 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: IR-10
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
##
## BEGINNING OF:
## MAINTENANCE
##
## Reminder of "implementation_status" codes:
##  - implementation_status: unsatisfied
##  - implementation_status: unknown
##  - implementation_status: planned
##  - implementation_status: partial
##  - implementation_status: complete
##  - implementation_status: none

- control_key: MA-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: MA-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: c
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: d
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: e
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: f
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
- control_key: MA-2 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST.

- control_key: MA-2 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: MA-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: MA-3 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: MA-3 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Checking media containing diagnostic and test programs for
        malicious code before the media are used in the information
        system is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: MA-3 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Preventing the unauthorized removal of maintenance equipment containing
        organizational information by verifying that there is no organizational
        information contained on the equipment is outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Preventing the unauthorized removal of maintenance equipment containing
        organizational information by sanitizing or destroying the equipment is
        outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: c
      text: |
        Preventing the unauthorized removal of maintenance equipment containing
        organizational information by retaining the equipment within the
        facility is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: d
      text: |
        Preventing the unauthorized removal of maintenance equipment containing
        organizational information by obtaining an exception from
        organization-defined personnel or roles explicity authorizing removal
        of the equipment from the facility is outside the scope of Red Hat Virtualization Manager (RHVM)
        configuration.

- control_key: MA-3 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: MA-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        From the perspective of Red Hat Virtualization Manager (RHVM), all
        maintenance and diagnostic activities are monitored regardless
        of local (e.g. physical console) or nonlocal (e.g. over SSH)
        access mechanism.
    - key: b
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: c
      text: |
        From the perspective of Red Hat Virtualization Manager (RHVM), both
        local and nonlocal maintenance and diagnostic sessions will require
        the same authenticators (as configured to controls in the AC section).

        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-21013
    - key: d
      text: |
        From the perspective of Red Hat Virtualization Manager (RHVM), session
        and network connections terminate in the same manner (e.g. once user logs out)
        regardless of local or nonlocal access mechanism used.

        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-21013
    - key: e
      text: |
        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-21013

- control_key: MA-4 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: b
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: MA-4 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-21014

- control_key: MA-4 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b
      text: |
        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-21015

- control_key: MA-4 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: b
      text: |
        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: MA-4 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Approval of each nonlocal maintenance session by
        organization-defined personnel or roles is outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Notification of organization-defined personnel or roles of
        the date and time of planned nonlocal maintenance is outside
        the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: MA-4 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: MA-4 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: MA-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Establishing a process for maintenance personnel authorization and
        maintaining a list of authorized maintenance organizations or personnel
        is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Ensuring that non-escorted personnel performing maintenance on
        the information system have required access authorizations is
        outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: c
      text: |
        Designating organizational personnel with required access
        authorizations and technical competence to supervise the
        maintenance activities of personnel who do not possess
        the required access authorizations is outside the
        scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: MA-5 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Implementing organizational procedures for the use of maintenance
        personnel that lack appropriate security clearances or are not U.S.
        citizens is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Development and implementation of alternate security safeguards
        in the event an information system component cannot be sanitized,
        removed, or disconnected from the system, is outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: MA-5 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational processes ensuring that personnel performing
        maintenance and diagnostic activities on an information system
        processing, storing, or transmitting classified information
        possess security clearances and formal access approvals for at
        least the highest classification level and for all compartments
        of information on the system, is outside the scope of Red Hat Virtualization Manager (RHVM)
        configuration.

- control_key: MA-5 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational processes ensuring that personnel performing
        maintenance and diagnostic activities on an information system
        processing, storing, or transmitting classified information are
        U.S. citizens, is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: MA-5 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational processes that ensure cleared foreign nationals (i.e.
        foreign nationals with appropriate security clearances), are used
        to conduct maintenance and diagnostic activities on classified
        information systems only when the systems are jointly owned and
        operated by the United States and foreign allied governments, or
        owned and operated solely by foreign allied governments, is outside
        the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Organizational processes that ensure approvals, consents, and detailed
        operational conditions regarding the use of foreign nationals to
        conduct maintenance and diagnostic activities on classified information
        systems are fully documented within Memoranda of Agreements, is outside
        the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: MA-5 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational processes ensuring that non-escorted personnel
        performing maintenance activities not directly associated with
        the information system but in the physical proximity of the
        system, have required access authorizations, is outside the
        scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: MA-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-21052

- control_key: MA-6 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-21052

- control_key: MA-6 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-21052

- control_key: MA-6 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        A control response is planned. Engineering progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-21052
##
## BEGINNING OF:
## MEDIA PROTECTION
##

- control_key: MP-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: MP-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |-
        A control response is planned. Engineering
        progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-21053

- control_key: MP-2 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control was withdrawn by NIST.

- control_key: MP-2 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control was withdrawn by NIST.

- control_key: MP-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: MP-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A control response is planned. Engineering
        progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-21054
    - key: b
      text: |
        A control response is planned. Engineering
        progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-21054

- control_key: MP-4 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control was withdrawn by NIST.

- control_key: MP-4 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: MP-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: d
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: MP-5 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control was withdrawn by NIST.

- control_key: MP-5 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control was withdrawn by NIST.

- control_key: MP-5 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: MP-5 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: MP-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: MP-6 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: MP-6 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: MP-6 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: MP-6 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control was withdrawn by NIST.

- control_key: MP-6 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control was withdrawn by NIST.

- control_key: MP-6 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control was withdrawn by NIST.

- control_key: MP-6 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: MP-6 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: MP-7
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |-
        To prohibit the use of USB storage devices on Red Hat Virtualization
        Manager (RHVM) nodes, the following configuration check must be enabled:

        - CCE-27277-3: Disable Modprobe Loading of USB Storage Driver

        To disable support for bluetooth connections, the following
        configuration checks must be enabled:

        - CCE-27327-6: Disable Bluetooth Kenrel Modules

        - CCE-27328-4: Disable Bluetooth Service

        A complete control response is planned. Engineering
        progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-21055

- control_key: MP-7 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: MP-7 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: MP-8
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: d
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: MP-8 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: MP-8 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: MP-8 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: MP-8 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
##
## BEGINNING OF:
## PHYSICAL AND ENVIRONMENTAL PROTECTION
##

- control_key: PE-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Development, documentation, and dissemination of a physical
        and environmental protection policy reflects organizational
        procedure/policy and is not applicable to component-level
        configuration.
    - key: b
      text: |
        Organizational review and updates to the physical and
        environmental protection policy reflects organizational
        procedure/policy and is not applicable to component-level
        configuration.

- control_key: PE-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Development, approval, and maintenance of a list
        of individuals with authorized access to the facility
        where the information system resides reflects organizational
        procedure/policy and is not applicable to component-level
        configuration.
    - key: b
      text: |
        Issuing authorization credentials for facility access
        reflects organizational procedure/policy and is not
        applicable to component-level configuration.
    - key: c
      text: |
        Reviewing the access list detailing authorized facility
        access by individuals at an organization-defined frequency
        reflects organizational procedure/policy and is not
        applicable to component-level configuration.
    - key: d
      text: |
        Removal of individuals from the facility access list when access
        is no longer required reflects organizational procedure/policy
        and is not applicable to component-level configuration.

- control_key: PE-2 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Authorizing physical access to the facility where the information
        system resides based on position or role reflects organizational
        procedures/policy and is not applicable to component-level
        configuration.

- control_key: PE-2 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Requiring two forms of identification from an organization-defined
        list of acceptable forms of identification for visitor access to
        the facility where the information system resides reflects
        organizational procedure/policy and is not applicable to
        component-level configuration.

- control_key: PE-2 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Restricting unescorted access to the facility where the
        information system resides reflects organizational
        procedure/policy and is not applicable to component-level
        configuration.

- control_key: PE-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Enforcing physical access authorizations at organization-defined
        entry/exit points to the facility where the information system resides
        reflects organizational procedure/policy and is not applicable to
        component-level configuration.
    - key: b
      text: |
        Maintaining physical access audit logs for organization-defined
        entry/exit points reflects organizational procedure/policy and
        is not applicable to component-level configuration.
    - key: c
      text: |
        Providing organization-defined security safeguards to control access
        to areas within the facility officially designated as publicly
        accessible reflects organizational procedure/policy and
        is not applicable to component-level configuration.
    - key: d
      text: |
        Escorting visitors and monitoring visitor activity during
        organization-defined circumstances requiring visitor escorts
        and monitoring reflects organizational procedure/policy and
        is not applicable to component-level configuration.
    - key: e
      text: |
        Securing keys, combinations, and other physical access devices
        reflects organizational procedure/policy and
        is not applicable to component-level configuration.
    - key: f
      text: |
        Inventory of organization-defined physical access devices
        at an organization-defined frequency reflects organizational
        procedure/policy and is not applicable to component-level
        configuration.
    - key: g
      text: |
        Changing combinations and keys at an organization-defined frequency
        and/or when keys are lost, combinations are compromised, or individuals
        are transferred or terminated, reflects organizational procedure/policy
        and is not applicable to component-level configuration.

- control_key: PE-3 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Enforcing physical access authorizations to the information system
        in addition to the physical access controls for the facility at
        organization-defined physical spaces containing one or more components
        of the information system reflects organizational procedure/policy
        and is not applicable to component-level configuration.

- control_key: PE-3 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Performing security checks at an organization-defined
        frequency at the physical boundary of the facility or information
        system for unauthorized exfiltration of information or removal
        of information system components reflects organizational
        procedure/policy and is not applicable to
        component-level configuration.

- control_key: PE-3 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Employing guards and/or alarms to monitor every physical access
        point to the facility where the information system resides 24 hours
        per day, 7 days per week, reflects organizational procedure/policy and
        is not applicable to component-level configuration.

- control_key: PE-3 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Using lockable physical casings to protect organization-defined
        information system components from unauthorized physical access
        reflects organizational procedure/policy and is not
        applicable to component-level configuration.

- control_key: PE-3 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Employing organization-defined security safeguards to
        detect and/or prevent physical tampering or alteration of
        organization-defined hardware components within the information
        system reflects organizational procedure/policy and is not
        applicable to component-level configuration.

- control_key: PE-3 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Employing a penetration testing process that includes, at an
        organization-defined frequency, unannounced attempts to bypass or
        circumvent security controls associated with physical access points
        to the facility reflects organizational procedure/policy and is
        not applicable to component-level configuration.

- control_key: PE-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Controlling physical access to organization-defined information
        system distribution and transmission lines within organizational
        facilities using organizaiton-defined security safeguards reflects
        organizational procedure/policy and is not applicable to
        component-level configuration.

- control_key: PE-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Controlling physical access to information system output devices to
        prevent unauthorized individuals from obtaining the output reflects
        organizational policy/procedures and is not applicable to
        component-level configuration.

- control_key: PE-5 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Controlling physical access to output from organization-defined
        output devices reflects organizational procedures/policy and
        is outside the scope of component-level configuration.
    - key: b
      text: |
        Ensuring that only authorized individuals receive output
        from the device reflects organizational
        procedure/policy and is not applicable to component-level
        configuration.

- control_key: PE-5 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Controlling physical access to output from organization-defined
        output devices reflects organizational
        procedure/policy and is not applicable to component-level
        configuration.
    - key: b
      text: |
        Linking individual identity to receipt of the output
        from the device reflects organizational
        procedure/policy and is not applicable to component-level
        configuration.

- control_key: PE-5 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Marking organization-defined information system output devices
        indicating the appropriate security marking of the information
        permitted to be output from the device reflects organizational
        procedure/policy and is outside the scope of component-level
        configuration.

- control_key: PE-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Monitoring physical access to the facility where the information
        system resides to detect and respond to physical security incidents
        reflects organizational procedure/policy and is outside the scope
        of component-level configuration.
    - key: b
      text: |
        Reviewing physical access logs at an organization-defined
        frequency and upon occurence of organization-defined events
        or potential indications of events, reflects organizational
        procedure/policy and is not applicable to component-level
        configuration.
    - key: c
      text: |
        Coordinating results of reviews and investigations with
        the organizational incident response capability reflects
        organizational procedure/policy and is not applicable to
        component-level configuration.

- control_key: PE-6 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Monitoring physical intrusion alarms and surveillance
        equipment reflects organizational procedure/policy and is
        not applicable to component-level configuration.

- control_key: PE-6 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-6 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-6 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-7
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-8
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-8 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-8 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-9
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-9 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-9 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-10
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: c
      text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-10 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-11
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-11 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-11 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: c
      text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-12
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-12 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-13
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-13 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-13 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-13 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-13 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-14
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-14 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-14 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-15
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-15 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-16
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-17
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: c
      text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-18
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-18 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-19
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-19 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PE-20
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        This control is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
##
## BEGINNING OF:
## PLANNING
##

- control_key: PL-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        'This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.'

- control_key: PL-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        'This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.'

- control_key: PL-2 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        'As of NIST 800-53 rev4 this control was withdrawn
        and incorporated into PL-7.'

- control_key: PL-2 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        'As of NIST 800-53 rev4 this control was withdrawn
        and incorporated into PL-8.'

- control_key: PL-2 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        'This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.'

- control_key: PL-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        'As of NIST 800-53 rev4 this control was withdrawn
        and incorporated into PL-2.'

- control_key: PL-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        'This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.'

- control_key: PL-4 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        'This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.'

- control_key: PL-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        'As of NIST 800-53 rev4 this control was withdrawn
        and incorporated into Appendix J, AR-2.'

- control_key: PL-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        'As of NIST 800-53 rev4 this control was withdrawn
        and incorporated into PL-2.'

- control_key: PL-7
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        'This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.'

- control_key: PL-8
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        'This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.'

- control_key: PL-8 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        'This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.'

- control_key: PL-8 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        'This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.'

- control_key: PL-9
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        'This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.'
##
## BEGINNING OF:
## PROGRAM MANAGEMENT
##

- control_key: PM-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: d
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PM-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PM-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PM-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PM-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PM-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PM-7
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PM-8
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PM-9
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PM-10
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PM-11
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PM-12
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PM-13
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PM-14
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PM-15
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PM-16
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
##
## BEGINNING OF:
## PERSONNEL SECURITY
##
## Reminder of "implementation_status" codes:
##  - implementation_status: unsatisfied
##  - implementation_status: unknown
##  - implementation_status: planned
##  - implementation_status: partial
##  - implementation_status: complete
##  - implementation_status: none

- control_key: PS-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational development, documentation, and dissemination of
        a personnel security policy to organization-defined personnel
        is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: a.1
      text: |
        Organizational development, documentation, and dissemination of
        a personnel security policy to organization-defined personnel
        is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: a.2
      text: |
        Organizational development, documentation, and dissemination of
        a personnel security policy to organization-defined personnel
        is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Organizational reviews and updates to the personnel security policy
        and personnel security procedures at an organization-defined frequency
        is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b.1
      text: |
        Organizational development, documentation, and dissemination of
        a personnel security policy to organization-defined personnel
        is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b.2
      text: |
        Organizational development, documentation, and dissemination of
        a personnel security policy to organization-defined personnel
        is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PS-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational assignment of a risk designation to all organizational
        positions is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Organizational establishment of screening criteria for individuals
        filling those positions is outside the scope of Red Hat Virtualization Manager (RHVM)
        configuration.
    - key: c
      text: |
        Organizational review and updating of position risk
        designations at an organization-defined frequency is outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PS-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational screening of individuals prior to authorizing access
        to the information system is outside the scope of Red Hat Virtualization Manager (RHVM)
        configuration.
    - key: b
      text: |
        Organizational processes to rescreen individuals according to
        organization-defined conditions requiring rescreening and,
        where rescreening is so indicated, the frequency of such
        rescreening, is outside the scope of Red Hat Virtualization Manager (RHVM)
        configuration.

- control_key: PS-3 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational processes ensuring that individuals accessing an
        information system processing, storing, or transmitting classified
        information are cleared and indoctrinated to the highest classification
        level of the information to which they have access on the system,
        are outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PS-3 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational processes ensuring that individuals accessing an
        information system processing, storing, or transmitting types of
        classified information which require formal indoctrination, are
        formally indoctrinated for all of the relevant types of information
        to which they have access on the system, are outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PS-3 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational processes ensuring that individuals accessing an
        information system processing, storing, or transmitting information
        requiring special protection have valid access authorizations that are
        demonstrated by assigned official government dutues, are outside the
        scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Organizational processes ensuring that individuals accessing an
        information system processing, storing, or transmitting information
        requiring special protection satisgy organization-defined additional
        personnel screening criteria, are outside the scope of Red Hat Virtualization Manager (RHVM)
        configuration.

- control_key: PS-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational processes ensuring that, upon termination of individual
        employment, information system access is disabled within an
        organization-defined time period, are outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Organizational processes ensuring that, upon termination of individual
        employment, any authenticators/credentials associated with the individual
        are terminated/revoked, are outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration.
    - key: c
      text: |
        Organizational processes ensuring that, upon termination of individual
        employment, exit interviews are conducted that include a discussion of
        organization-defined information security topics, are outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration.
    - key: d
      text: |
        Organizational processes ensuring that, upon termination of individual
        employment, all security-related organizational information
        system-related property is retrieved, are outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration.
    - key: e
      text: |
        Organizational processes ensuring that, upon termination of individual
        employment, the organization retains access to organizational
        information systems formerly controlled by the terminated individual,
        are outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: f
      text: |
        Organizational processes ensuring that, upon termination of individual
        employment, the organization notifies organization-defined personnel
        or roles within an organization-defined time period, are outside
        the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PS-4 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational processes which notify terminated individuals of
        applicable, legally binding post-employment requirements for
        the protection of organizational information are outside
        the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Organizational processes requiring terminated individuals
        to sign an acknowledgement of post-employment requirements
        as part of the organizational termination process
        are outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PS-4 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational employment of automated mechanisms to notify
        organization-defined personnel or roles upon termination of
        an individual, is outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PS-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational processes to review and confirm ongoing operational
        need for current logical and physical access authorizations to
        information systems/facilities when individuals are reassigned or
        transferred to other positions within the organization are
        outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Organizational processes to initiate organization-defined transfer
        or reassignment actions within organization-defined time period
        following the formal transfer action are outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration.
    - key: c
      text: |
        Organizational processes to modify access authorizations as needed to
        correspond with any changes in oeprational need due to reassignment
        or transfer are outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: d
      text: |
        Organizational notifications of organization-defined personnel
        or roles within an organization-defined time period are outside
        the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PS-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational process to develop and document access agreements for
        organizational information systems are outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Organizational reviews and updates to the access agreements at an
        organization-defined frequency are outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration.
    - key: c
      text: |
        Organizational processes that ensure individuals requiring access to
        organizational information and information systems sign and re-sign
        access agreements are outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: c.1
      text: |
        Organizational processes that ensure individuals requiring access to
        organizational information and information systems sign and re-sign
        access agreements are outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: c.2
      text: |
        Organizational processes that ensure individuals requiring access to
        organizational information and information systems sign and re-sign
        access agreements are outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PS-6 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST.

- control_key: PS-6 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational processes that ensure access to classified information
        requiring special protection is granted only to individuals who
        have a valid access authorization that is demonstrated by assigned
        official government duties are outside the scope of Red Hat Virtualization Manager (RHVM)
        configuration.
    - key: b
      text: |
        Organizational processes that ensure access to classified information
        requiring special protection is granted only to individuals who
        satisfy associated personnel security criteria are outside
        the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: c
      text: |
        Organizational processes that ensure access to classified information
        requiring special protection is granted only to individuals who
        have read, understood, and signed a nondisclosure agreement are
        outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PS-6 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational processes to notify individuals of applicable, legally
        binding post-employment requirements for protection of organizational
        information are outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Organizational processes which require individuals to sign
        an acknowledgement of these requirements, if applicable, as
        part of granting initial access to covered information, are
        outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PS-7
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational processes to establish security requirements including
        security roles and responsibilities for third-party providers are
        outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Organizational processes requiring third-party providers to comply
        with personnel security polocies and procedures established by
        the organization are outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: c
      text: |
        Organizational processes to document presonnel security requirements
        are outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: d
      text: |
        Organizational processes to require third-party providers to notify
        organization-defined personnel or roles of any personnel transfers or
        terminations of third-party personnel who possess organizational
        credentials and/or badges, or who have information system privileges
        within an organization-defined time period, are outside the
        scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: e
      text: |
        Organizational monitoring of provider compliance is outside
        the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: PS-8
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational employment of a formal sanctions process for individuals
        failing to comply with established information security policies
        and procedures is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Organizational notification of organization-defined personnel
        or roles within an organization-defined time period when a formal
        employee santions process is initiated, identifying the individual
        sanctioned and the reason for the sanction.
##
## BEGINNING OF:
## RISK ASSESSMENT
##

- control_key: RA-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational development, documentation, and dissemination to
        organization-defined personnel or roles a risk assessment policy
        and procedures is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: a.1
      text: |
        Organizational development, documentation, and dissemination to
        organization-defined personnel or roles a risk assessment policy
        and procedures is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: a.2
      text: |
        Organizational development, documentation, and dissemination to
        organization-defined personnel or roles a risk assessment policy
        and procedures is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Organizational review and updates to the risk assessment policy
        and risk assessment procedures is outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration.
    - key: b.1
      text: |
        Organizational review and updates to the risk assessment policy
        and risk assessment procedures is outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration.
    - key: b.2
      text: |
        Organizational review and updates to the risk assessment policy
        and risk assessment procedures is outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration.

- control_key: RA-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational processes to categorize information and information
        systems in accordance with applicable federal laws, Executive
        Orders, directives, policies, regulations, standards, and
        guidance, are outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Organizational processes to document the security categorization
        results (including supporting rationale) in the security plan for
        the information system are outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration.
    - key: c
      text: |
        Organizational processes to ensure that the authorizing official
        or authorizing official designated representative reviews and
        approved the security categorization decision are outside
        the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: RA-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational processes to conduct an assessment of risk,
        including the likelihood and magnitude of harm, from the unauthorized
        access, use, disclosure, disruption, modification, or desctruction of
        the information system and the information it processes, stores, or
        transmits, are outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Organizational processes to document risk assessment results in
        security plans, risk assessment reports, or organization-defined
        documents, are outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: c
      text: |
        Organizational processes to review risk assessment results at
        an organization-defined frequency are outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration.
    - key: d
      text: |
        Organizational processes to disseminate risk assessment results to
        organization-defined personnel or roles are outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration.
    - key: e
      text: |
        Organizational processes to update the risk assessment at an
        organization-defined frequency or whenever there are significant
        changes to the information system or environment of operation
        (including the identification of new threats and vulnerabilities),
        or other conditions that may impact the security state of the system,
        are outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: RA-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST.

- control_key: RA-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: partial
  narrative:
    - key: a
      text: |
        A control response is planned. Progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: b
      text: |
        A control response is planned. Progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: c
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: d
      text: |
        A control response is planned. Progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: e
      text: |
        Organizational processes to share information obtained from the
        vulnerability scanning process and security control assessments
        with organization-defined personnel or roles to help eliminate
        similar vulnerabilities in other information systems (i.e.,
        systemic weaknesses or deficiences) are outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: RA-5 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned. Progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: RA-5 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: RA-5 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: RA-5 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned. Progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-21056

- control_key: RA-5 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned. Progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: RA-5 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: partial
  narrative:
    - text: |
        A control response is planned. Progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: RA-5 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST.

- control_key: RA-5 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational review of historic audit logs to determine if a
        vulnerability identified in the information system has been
        previously exploited is outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration.

- control_key: RA-5 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST.

- control_key: RA-5 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational processes to correlate the output from vulnerability
        scanning tools to determine the presence of
        multi-vulnerability/multi-hop attack vectors are outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: RA-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational employment of a technical surveillance countermeasures
        survey at organization-defined locations at an organization-defined
        frequency or when organization-defeined events or indicators
        occur is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
##
## BEGINNING OF:
## SYSTEM AND SERVICES ACQUISITION
##

- control_key: SA-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational processes to develop, document, and disseminate to
        organization-defined personnel or roles a system and services
        acquisition policy is outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration.
    - key: a.1
      text: |
        Organizational processes to develop, document, and disseminate to
        organization-defined personnel or roles a system and services
        acquisition policy is outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration.
    - key: a.2
      text: |
        Organizational processes to develop, document, and disseminate to
        organization-defined personnel or roles a system and services
        acquisition policy is outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Organizational review and updates to the current system and services
        acquisition policy and procedures at an organization-defined frequency
        is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b.1
      text: |
        Organizational review and updates to the current system and services
        acquisition policy and procedures at an organization-defined frequency
        is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b.2
      text: |
        Organizational review and updates to the current system and services
        acquisition policy and procedures at an organization-defined frequency
        is outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational processes to determine information security requirements
        for the information system or information system service in
        mission/business process planning are outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Organizational processes to determine, document, and allocate the
        resources required to protect the information system or information
        system service as part of its capital planning and investment
        control process are outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration.
    - key: c
      text: |
        Organizational processes to establish a discrete line item for
        information security in organizational programming and budgeting
        documentation are outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational processes to manage the information system using
        organization-defined system development life cycle that incorporates
        information security considerations are outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Organizational processes to define and document information security
        roles and responsibilities throughout the system development
        life cycle are outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: c
      text: |
        Organizational processes to identify individuals having information
        security roles and responsibilities are outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration.
    - key: d
      text: |
        Organizational processes to integrate the organizational information
        security risk management process into system development life cycle
        activities are outside the scope of Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational processes to include security functional requirements
        in acquisition contracts are outside the scope of Red Hat Virtualization Manager (RHVM)
        configuration.
    - key: b
      text: |
        Organizational processes to include security strength requirements
        in acquisition contracts are outside the scope of Red Hat Virtualization Manager (RHVM)
        configuration.
    - key: c
      text: |
        Organizational processes to include security assurance requirements
        in acquisition contracts are outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration.
    - key: d
      text: |
        Organizational processes to include security-related documentation
        requirements in acquisition contracts are outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration.
    - key: e
      text: |
        Organizational processes to include requirements for protecting
        security-related documentation in acquisition contracts
        are outside the scope of Red Hat Virtualization Manager (RHVM) configuration.
    - key: f
      text: |
        Organizational processes to include a description of the information
        system development environment and environment in which the system is
        intended to operate in acqusition contracts are outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration.
    - key: g
      text: |
        Organizational processes to include acceptance criteria in
        acqusition contracts are outside the scope of Red Hat Virtualization Manager (RHVM)
        configuration.

##
## Developers note on SA-4 (1):
##  This control requires that developers of system components, e.g.
##  application servers, to provide a description of the functional
##  properties of the security controls to be deployed.
##
##  A a generally accepted control response is to provide a security
##  configuration guide, such as a NIST National Checklist or DoD
##  STIG, for the component.
##
##  In absence of an approved government configuration baseline,
##  note this requirement is satisfied by a *description* of
##  functional properties. Implementation details are offered in
##  SA-4(2).
##
- control_key: SA-4 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response to SA-4 (1) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-22638

##
## Developers note on SA-4 (2):
##  This control differs from SA-4 (1) in that implementation
##  details are now required.
##
##  The majority of FedRAMP and FISMA Moderate systems refine this control
##  with the following:
##    - Provide design and implementation regarding security-relevant
##      external system interfaces and high-level design;
##    - Provide design and implementation information required by the
##      SDL process;
##    - Above should be provided with a level of detail sufficient for
##      secure deployment.
##
- control_key: SA-4 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response to SA-4 (2) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-22639

##
## Developers note on SA-4 (3):
##  This is most frequently satisfied by demonstrating common criteria
##  certification.
##
##  Lacking Common Criteria certification a detailed outline of SDLC practices
##  is required.
##
- control_key: SA-4 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response to SA-4 (3) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SA-4 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev4 this control was withdrawn
        and incorporated into CM-8 (9).

##
## Developers note on SA-4 (4):
##  Note: For software components, such as operating systems, NIST considers it
##  sufficient to provide install-time configuration. For example in RHEL7 a
##  "Security Profile" menu is presented that installs Linux into known government
##  baselines.
##
- control_key: SA-4 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A control response to SA-4(5)(a) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: b
      text: |
        A control response to SA-4(5)(b) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-

##
## Developers note on SA-4 (6):
##  Note this is only applicable "when the networks used to transmit
##  the information are at a lower classification than the information
##  being transmitted."
##
##  If this component is not intended to enable cross domain infrastructure,
##  this control potentially could be 'not applicable'.
##
- control_key: SA-4 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational employment of only government off-the-shelf
        (GOTS) or commercial off-the-shelf (COTS) information assurance
        (IA) and IA-enabled information technology products that compose
        an NSA-approved solution to protect classified information when
        the networks used to transmit the information are at a lower
        classificiation level than the information transmitted, is
        an organizational control outside the scope of
        Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        Organizational assurance that these products have been evaluated
        and/or validated by NSA or in accordance with NSA-approved
        procedures is an organizational control outside the scope
        of Red Hat Virtualization Manager (RHVM) configuration.

        NOTE: As of September 2019, Red Hat Virtualization Manager (RHVM) has not undergone formal NSA
        evaluation for the inclusion in cross domain information
        systems.

##
## Developers note on SA-4 (7):
##  As of 2018, protection profiles recognized by NIAP and those recognized
##  by the broader Common Criteria effort have diverged. A listing of NIAP-
##  recognized protection profiles can be found here:
##
##  https://www.niap-ccevs.org/Profile/PP.cfm
##
- control_key: SA-4 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A control response to SA-4(7)(a) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: b
      text: |
        A control response to SA-4(7)(b) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-

##
## Developers note on SA-4 (8):
##  A successful control response will document how to achieve continuous
##  monitoring of control/standards as identified in CA-7.
##
- control_key: SA-4 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response to SA-4(8) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-

##
## Developers note on SA-4 (9):
##  A successful control response will document all network
##  information. Take care to document internal network usage,
##  including loopback devices, as it is customary to block all
##  traffic not explicitly outlined in this control.
##
- control_key: SA-4 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response to SA-4(9) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SA-4 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: a.1
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: a.2
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: a.3
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: b.1
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: b.2
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: b.3
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: d
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: e
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-5 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev4 this control was withdrawn
        and incorporated into SA-4 (1).

- control_key: SA-5 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev4 this control was withdrawn
        and incorporated into SA-4 (2).

- control_key: SA-5 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev4 this control was withdrawn
        and incorporated into SA-4 (3).

- control_key: SA-5 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev4 this control was withdrawn
        and incorporated into SA-4 (4).

- control_key: SA-5 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev4 this control was withdrawn
        and incorporated into SA-4 (5).

- control_key: SA-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev4 this control was withdrawn
        and incorporated into CM-10 and SI-7.

- control_key: SA-7
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev4 this control was withdrawn
        and incorporated into CM-11 and SI-7.

- control_key: SA-8
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-9
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-9 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-9 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-9 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-9 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-9 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response to SA-9(5) is planned. Progress
        can be tracked at:

        https://issues.redhat.com/browse/CMP-368

##
## Developers note on SA-10
##  A successful control response will document all network
##  information. Take care to document internal network usage,
##  including loopback devices, as it is customary to block all
##  traffic not explicitly outlined in this control.
##
- control_key: SA-10
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    ## A successful control response will document performance of configuration
    ## management. Processes and mechanisms involved in configuration management
    ## will need to be addressed.
    - key: a
      text: |
        A control response to SA-10(a) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-21061

    ## A successful control response will need to address the processes
    ## and mechanisms involved in documenting, managing, and controlling the
    ## integrity of chances.
    - key: b
      text: |
        A control response to SA-10(b) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-21061

    ## A successful control response will need to address the approval process
    ## and safeguards in place to ensure only approved changes are implemented.
    - key: c
      text: |
        A control response to SA-10(c) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-21061

    ## A successful control response will need to discuss the process for
    ## documentation.
    - key: d
      text: |
        A control response to SA-10(d) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-21061

    ## A successful control response will need to discuss the process
    ## and tools used for tracking, resolution, and reporting.
    - key: e
      text: |
        A control response to SA-10(e) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-21061

##
## Developers note on SA-10 (1)
##  A successful control response will need to address the process and
##  mechanisms involved in integrity verification.
##
##  For example, TPM+TXT for hardware and operating systems.
##
- control_key: SA-10 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response to SA-10(1) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SA-10 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

##
## Developers note on SA-10 (3)
##  This control differs from SA-10 (1) by focusing on hardware
##  (vs software and firmware).
##
##  This control may not be applicable if the component being documented
##  is not involved in the system boot process.
##
- control_key: SA-10 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

##
## Developers note on SA-10 (4)
##  This control may not be applicable if the component being documented
##  is not involved in the system boot process.
##
- control_key: SA-10 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SA-10 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SA-10 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SA-11
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    ## A successful control response will need to outline the security
    ## assessment plan.
    - key: a
      text: |
        A control response to SA-11(a) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-21062
    - key: b
      text: |
        A control response to SA-11(b) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-21062

    ## A successful control response will need to address the process by
    ## which the customer obtains and reviews the evidence and results of
    ## testing.
    - key: c
      text: |
        A control response to SA-11(c) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-21062

    ## A successful control response will need to outline the means by which
    ## flaws are identified and addressed.
    - key: d
      text: |
        A control response to SA-11(d) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-21062

    ## A successful control response will need to discuss the procedure for
    ## identifying flaws, alerting appropriate personnel to correct flaws, and
    ## verifying the success of the correction.
    - key: e
      text: |
        A control response to SA-11(e) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-21062

##
## Developers note on SA-11 (1)
##  A successful control response will document how static code analysis
##  tools are used on this compont to identify of common flaws,
##  and how the results of the analysis are integrated into actions.
##
- control_key: SA-11 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response to SA-11(1) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-

##
## Developers note on SA-11 (2)
##  A successful control response will need to address the analysis
##  of how the as-built system differs from the initial design, as well
##  as how any new vulnerabilities created as a result of these differences
##  are reviewed and mitigated.
##
- control_key: SA-11 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response to SA-11(2) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SA-11 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A control response to SA-11(3)(a) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: b
      text: |
        A control response to SA-11(3)(b) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SA-11 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SA-11 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SA-11 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SA-11 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SA-11 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SA-12
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-12 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-12 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-12 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev4 this control was withdrawn
        and incorporated into SA-12(1).

- control_key: SA-12 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev4 this control was withdrawn
        and incorporated into SA-12(13).

- control_key: SA-12 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-12 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev4 this control was withdrawn
        and incorporated into SA-12(1).

- control_key: SA-12 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-12 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-12 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

##
## Developers note on SA-12:
##  While this is an organizational control and not applicable
##  to component configuration, consider how customers may validate
##  the system component. For example, in software, usage of gpg keys
##  on installation media.
##
- control_key: SA-12 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response to SA-12(10) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SA-12 (11)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-12 (12)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-12 (13)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-12 (14)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-12 (15)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-13
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-14
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-14 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev4 this control was withdrawn
        and incorporated into SA-20.

- control_key: SA-15
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A control response to SA-15(a) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-21063
    - key: a.1
      text: |
        A control response to SA-15(a)(1) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-21063
    - key: a.2
      text: |
        A control response to SA-15(a)(2) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-21063
    - key: a.3
      text: |
        A control response to SA-15(a)(3) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-21063
    - key: a.4
      text: |
        A control response to SA-15(a)(4) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-21063
    - key: b
      text: |
        A control response to SA-15(b) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV-21063

- control_key: SA-15 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A control response to SA-15(1)(a) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV
    - key: b
      text: |
        A control response to SA-15(1)(b) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV

- control_key: SA-15 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response to SA-15(2) is planned.

- control_key: SA-15 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
         A control response to SA-15(3) is planned.

- control_key: SA-15 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-15 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV

- control_key: SA-15 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response to SA-15(6) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV

- control_key: SA-15 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A complete control response is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV
    - key: b
      text: |
        A complete control response is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV
    - key: c
      text: |
        A complete control response is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV
    - key: d
      text: |
        A complete control response is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV

- control_key: SA-15 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response to SA-15(8) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV

- control_key: SA-15 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-15 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response to SA-15(10) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV

- control_key: SA-15 (11)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response to SA-15(11) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV

- control_key: SA-16
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response to SA-16 is planned.

- control_key: SA-17
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A control response to SA-17(a) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV
    - key: b
      text: |
        A control response to SA-17(b) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV
    - key: c
      text: |
        A control response to SA-17(c) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV

- control_key: SA-17 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-17 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A control response to SA-17(2)(a) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV
    - key: b
      text: |
        A control response to SA-17(2)(b) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV

- control_key: SA-17 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A control response to SA-17(3)(a) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV
    - key: b
      text: |
        A control response to SA-17(3)(b) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV
    - key: c
      text: |
        A control response to SA-17(3)(c) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV
    - key: d
      text: |
        A control response to SA-17(3)(d) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV
    - key: e
      text: |
        A control response to SA-17(3)(e) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV

- control_key: SA-17 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A control response to SA-17(4)(a) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV
    - key: b
      text: |
        A control response to SA-17(4)(b) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV
    - key: c
      text: |
        A control response to SA-17(4)(c) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV
    - key: d
      text: |
        A control response to SA-17(4)(d) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV
    - key: e
      text: |
        A control response to SA-17(4)(e) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV

- control_key: SA-17 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A control response to SA-17(5)(a) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV
    - key: b
      text: |
        A control response to SA-17(5)(b) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV

- control_key: SA-17 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response to SA-17(6) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV

- control_key: SA-17 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response to SA-17(7) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV

- control_key: SA-18
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response to SA-18 is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV

- control_key: SA-18 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response to SA-18(1) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV

- control_key: SA-18 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response to SA-18(2) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV

- control_key: SA-19
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-19 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-19 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-19 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-19 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV

- control_key: SA-20
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-21
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A control response to SA-21(a) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV
    - key: b
      text: |
        A control response to SA-21(b) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV

- control_key: SA-21 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-22
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        Red Hat provides a published product life cycle for Red Hat
        Virtalization. The product life cycle for Red Hat
        Red Hat Virtalization 4.x can be viewed at:

        https://access.redhat.com/support/policy/updates/rhev

        A control response to SA-22(a) is planned. Progress
        can be tracked at:

        https://projects.engineering.redhat.com/browse/RHV
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.

- control_key: SA-22 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to Red Hat Virtualization Manager (RHVM) configuration.
##
## BEGINNING OF:
## SYSTEMS AND COMMUNICATIONS PROTECTION
##

- control_key: SC-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The customer is responsible for separating user functionality
        including user interface services) from information system management
        functionality. A successful control response will indicate how user
        and management functionality access is separated.

        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-2 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The customer is responsible for deployment utilizing namespaces,
        host roles and other features as well as policies and procedures
        to implement and ensure continued isolation of security functions
        from non-security functions.

        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-3 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The customer is responsible for deployment utilizing namespaces,
        host roles and other features as well as policies and procedures
        to implement and ensure continued isolation of security functions
        from non-security functions.

        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-3 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The customer is responsible for deployment utilizing namespaces,
        host roles and other features as well as policies and procedures
        to implement and ensure continued isolation of security functions
        from non-security functions.

        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-3 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        To assist with this organizational control, documentation is being
        planned. Progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-3 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        To assist with this organizational control, documentation is being
        planned. Progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-3 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        To assist with this organizational control, documentation is being
        planned. Progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The customer is responsible for preventing unauthorized and
        unintended information transfer via shared system resources. A
        successful control response will discuss how this is prevented.

        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-4 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST, and incorporated into SC-4.

- control_key: SC-4 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        This control is met when SELinux is enabled and enforced and through
        the use of SELinux MCS Levels.

        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-5 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-5 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-5 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The customer is responsible for the protection and availability of
        resources by allocating processor and memory resources by process
        priority and resource availability. A successful control response will
        discuss how resource availability is protected.

        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-7
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: b
      text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: c
      text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-7 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST, and incorporated into SC-7.

- control_key: SC-7 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST, and incorporated into SC-7.

- control_key: SC-7 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The customer is responsible for limiting the number of external
        network connetions to the information system. A successful control
        response will indicate the rate limiting procedures and technical
        enforcement.

        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-7 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: c
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: d
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: e
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-7 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The customer will be responsible for ensuring managed interfaces deny
        network traffic by default and allow network communications traffic
        by exception (i.e. deny all, permit by exception).

        To assist with this organizational control, documentation is being
        planned. Progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-7 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST, and incorporated into SC-7(18).

- control_key: SC-7 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        The customer will be responsible for implementing mechanisms to
        ensure Red Hat Virtualization Manager (RHVM) nodes do not act as proxy or relay servers between
        internal and external networks.

- control_key: SC-7 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-7 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: partial
  narrative:
    - key: a
      text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: b
      text: |
        Auditing users associated with denied communications is the responsibility
        of the organization and is outside the scope of Red Hat Virtualization Manager (RHVM) configuration

- control_key: SC-7 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-7 (11)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        To assist with this organizational control, documentation is being
        planned. Progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-7 (12)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The customer will be responsible for implementing host-based
        boundary protection mechanisms. This is often through configuration of
        local firewalld and SELinux policies.

        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-7 (13)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The customer will be responsible for ensuring that Red Hat Virtualization Manager (RHVM) is
        isolated from other internal information system components by
        implementing physically separate subnetworks with managed
        interfaces to other components of the system. A successful control
        response will discuss the networking configuration to satisfy this
        control.

        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-7 (14)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-7 (15)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-7 (16)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-7 (17)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-7 (18)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-7 (19)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-7 (20)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-7 (21)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-7 (22)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-7 (23)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-8
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-8 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-8 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-8 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-8 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-9
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST, and incorporated into SC-8.

- control_key: SC-10
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The customer will be responsible for terminating network connections
        at the end of the session or after no longer than 30 minutes of
        inactivity. A successful control response will document the technical
        means on how this is established.

        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-11
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-11 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-12
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        Red Hat Virtualization Manager (RHVM) utilizes FIPS 140 evaluated
        OpenSSL libraries for the generation of cryptographic keys. This
        behavior is coded into RHVH and cannot be misconfigured by users
        or system administrators.

        Management of cryptographic keys (e.g. rotation) reflects
        organizational procedures/policies, and is not applicable to
        the configuration of Red Hat Virtualization Manager (RHVM).

        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-12 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-12 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-12 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-12 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST, and incorporated into SC-12.

- control_key: SC-12 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST, and incorporated into SC-12.

- control_key: SC-13
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The Federal Information Security Management
        Act (FISMA) requires the use of FIPS 140 evaluated cryptography.
        Red Hat Virtualization Manager (RHVM) carries several FIPS validations,
        however it is imperitive the system have FIPS enabled.

        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-13 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST, and incorporated into SC-13.

- control_key: SC-13 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST, and incorporated into SC-13.

- control_key: SC-13 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST, and incorporated into SC-13.

- control_key: SC-13 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST, and incorporated into SC-13.

- control_key: SC-14
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST, and incorporated into AC-2,
        AC-3, AC-5, AC-6, SI-3, SI-4, SI-5, SI-7, SI-10.

- control_key: SC-15
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Examples of collaborative computing devices include networked white
        boards, TV conference cameras, and remote video systems. This control
        is not applicable because Red Hat Red Hat Virtualization Manager (RHVM) Container Platform is not
        a collaborative computing device.
    - key: b
      text: |
        Examples of collaborative computing devices include networked white
        boards, TV conference cameras, and remote video systems. This control
        is not applicable because Red Hat Red Hat Virtualization Manager (RHVM) Container Platform is not
        a collaborative computing device.

- control_key: SC-15 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-15 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-15 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-15 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-16
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-16 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-17
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://issues.redhat.com/browse/CMP-419

- control_key: SC-18
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        The customer will be responsible for defining acceptable and
        unacceptable mobile code and mobile code technologies.
    - key: b
      text: |
        The customer will be responsible for establishing usage restrictions
        and implementation guidance for acceptable mobile code and mobile
        code technologies.
    - key: c
      text: |
        The customer will be responsible for authorizing, monitoring, and
        controlling the use of mobile code within the system in accordance
        with organizational policies defined in SC-18(a) and SC-18(b).

- control_key: SC-18 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-18 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-18 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-18 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-18 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-19
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b
      text: |
        The customer will be responsible for authorizing, monitoring, and
        controlling the use of VoIP within the system in accordance with
        organizational policies defined in SC-19(a).

- control_key: SC-20
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        Red Hat Virtualization Manager (RHVM) administrators are responsible for providing
        origin authentication and integrity verification artifacts along
        with authoritative name resolution data returns in response. A
        successful control response will discuss the technical means used to
        accomplish this.

        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: b
      text: |
        Red Hat Virtualization Manager (RHVM) administrators are responsible for
        providing means to indicate the security status of child zones and
        enable verification of a chain of trust among parent and child domains.
        A successful control response will discuss the technical means used to
        accomplish this.

        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-20 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST, and incorporated into SC-20.

- control_key: SC-20 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-21
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        Documentation to configure DNSSEC is provided in the Red Hat
        Security Guide:

        https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/security_guide/sec-securing_dns_traffic_with_dnssec#sec-Security_Guide-Installing_DNSSEC

        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-21 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST, and incorporated into SC-21.

- control_key: SC-22
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        The organization is responsible for ensuring that the information systems
        that function as nameservers are fault-tolerant and implement internal/external role
        separation.

- control_key: SC-23
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The customer will be responsible for guarding against, for
        example, man in the middle or session hijacking attacks for
        connections to the customer application, for example via the
        use of TLS. A successful control response will address the
        various types of attacks against session authenticity and the
        mechanisms used to protect against those attacks.

        Red Hat Virtualization Manager (RHVM) uses various TLS algorithms and ciphers to protect
        the authenticity of communications sessions.

        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-23 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-23 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST, and incorporated into AC-12 (1).

- control_key: SC-23 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-23 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST, and incorporated into SC-23 (3).

- control_key: SC-23 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-24
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-25
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-26
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-26 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-27
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-28
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-28 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The customer is responsible for implementing cryptographic
        mechanisms to prevent unauthorzed disclosure and modification of
        customer data. A successful control response will outline how
        cryptography is used to ensure integrity of data in rest and
        transport.

        When running on Red Hat Enterprise Linux, full disk encryption
        is possible for data at rest on the Red Hat Virtualization Manager (RHVM) nodes. For data
        in transport, Red Hat Virtualization Manager (RHVM) uses cryptographic algorithms and ciphers to
        protect confidentiality and integrity of data in transport.

        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-28 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        To assist with this organizational control, documentation is being
        planned. Progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-29
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        To assist with this organizational control, documentation is being
        planned. Progress can be tracked via:

            https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-29 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        To assist with this organizational control, documentation is being
        planned. Progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-30
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        To assist with this organizational control, documentation is being
        planned. Progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-30 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-30 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-30 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-30 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-30 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-31
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-31 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-31 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        To assist with this organizational control, documentation is being
        planned. Progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-31 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-32
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-33
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST, and incorporated into SC-8.

- control_key: SC-34
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: b
      text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-34 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-34 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-34 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: b
      text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-35
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-36
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-36 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        To assist with this organizational control, documentation is being
        planned. Progress can be tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-37
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-37 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-38
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-39
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-39 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-39 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-40
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-40 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-40 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-40 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-40 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-41
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SC-42
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-42 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-42 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-42 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-43
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SC-44
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
##
## BEGINNING OF:
## SYSTEM AND INFORMATION INTEGRITY
##

- control_key: SI-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of the Verizon Intelligent API.
    - key: a.1
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: a.2
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b.1
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b.2
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SI-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        The customer will be responsible for analyzing their Red Hat Virtualization Manager (RHVM) deployment for
        flaws, reporting on those flaws, and correcting them. A successful
        control response will include a discussion of the process by which
        flaws are discovered and remediated, as well as tools that are used to
        assist in detection and remediation.
    - key: b
      text: |
        The customer will be responsible for testing Red Hat Virtualization Manager (RHVM) updates
        related to flaw remediation prior to installation. A successful
        control response will discuss the testing process (e.g. the
        nature of the test environment, the types of testing performed,
        the tools in testing, etc.).
    - key: c
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: d
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SI-2 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-2(1) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

##
## Developers note on SI-2 (2):
##  Some auditors will request documentation outlining how the component
##  is configured to connect with organizational automated systems for
##  flaw remediation.
##
- control_key: SI-2 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The customer will be required to employ automated mechanisms on a
        monthly basis to determine the state of information system components
        with regard to flaw remediation on their information systems as
        required by their organizations policy. A successful control response
        will address the customers use of automated tools such as Nessus, OpenSCAP, etc. to
        perform periodic and on-demand scans through their system to determine
        the state of system components with regard to flaw remediation.

        A control response for SI-2(2) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-2 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        The customer is responsible for scanning for flaws in their
        information systems and for measuring the time between flaw
        identification and flaw remediation. A successful control response
        will need to address the time between flaw identification and
        remediation using timestamps and calculates the time elapsed
        difference.
    - key: b
      text: |
        The customer will be responsible for scanning for flaws in their
        information systems and for establishing benchmarks for taking
        correctie actions according to their organizational policies. A
        successful control response will need to address the use of
        benchmarks to remediate high, and moderate risk flaws within a
        customer defined period after a flaws discovery.

- control_key: SI-2 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST, and incorporated into SI-2.

##
## Developers note on SI-2 (5):
##  Some auditors will request documentation outlining how the component
##  is configured to connect with organizational automated systems for
##  software updates.
##
##  For example, managing softare through Red Hat Satellite and configuring
##  host operating systems to automatically update components as needed.
##
- control_key: SI-2 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-2(5) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

##
## Developers note on SI-2 (6):
##  Some auditors will request documentation outlining how the component
##  is configured to remove old software/firmware versions.
##
##  For example, software installed on Enterprise Linux distributions
##  generally use the package management of the operating system (e.g. RPM).
##  In such cases, removal of outdated software is handled by the operating
##  system and not the software component itself.
##
- control_key: SI-2 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-2(6) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        The customer is responsible for ensuring that they employ malicious
        code protection at information system entry, and exit points to detect
        and eradicate malicious code. A successful control response will need
        to address use of code protection mechanisms to protect assets from
        malicious software (i.e. Viruses, malware, rootkits, worms, and
        scripts).

        A control response for SI-3 is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: b
      text: |
        A control response for SI-3 is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: c
      text: |
        A control response for SI-3 is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: c.1
      text: |
        A control response for SI-3 is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: c.2
      text: |
        A control response for SI-3 is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: d
      text: |
        A control response for SI-3 is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-3 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
       The customer is responsible for ensuring that their malicious code
       protection mechanisms are centrally managed. A successful control
       response will need to address that the planning, implementing,
       assessing, authorizing and monitoring of their malicious code
       protection mechanism is centered in one location.

       A control response for SI-3(1) is planned. Engineering progress can be
       tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-3 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The customer is responsible for ensuring that they update their
        malicious code protection mechanisms automatically when new versions/
        definitions become available. A successful control response will need
        to address that the employed malicious code protection
        mechanisms definitions are configured to be updated automatically.

        A control response for SI-3(2) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-3 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST, and incorporated into AC-6(10).

- control_key: SI-3 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-3(4) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-3 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SI-3 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SI-3 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        The customer is responsible for ensuring that they implement a
        nonsignature-based malicious code detection mechanism on their
        information system. A successful control response will need to address
        a nonsignature based detection mechanism that can detect, analyze and
        describe the characteristics or behavior of malicious code and
        could provide safeguards against malicious code for which signatures
        do not yet exist.

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-3 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-3(4) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-3 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-3(4) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-3 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SI-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: a.1
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: a.2
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: c
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: c.1
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: c.2
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: d
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: e
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: f
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: g
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SI-4 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The customer will be responsible for integrating intrusion detection
        tools into the Red Hat Virtualization Manager (RHVM) environment, and documenting how this
        capability is integrated into enterprise-wide intrusion detection
        systems when applicable. A successful control response will address
        the workflow between local and enterprise intrusion detection
        systems.

        A control response for SI-4(1) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-4 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The customer will be responsible for deploying automated tools to
        support near real-time analysis of events in their infrastructure.
        This is frequently provided by corporate services outside the
        information system, e.g. centralized security operation centers may
        host an enterprise logging solution. A successful control response
        will indicate who is responsible for hosting such capabilities, and
        what technology and processes are in place to support near-realtime
        analysis of events.

        A control response for SI-4(2) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-4 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-4(3) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-4 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The customer will be responsible for identifying how and where
        network traffic is continuously monitored.

        A control response for SI-4(4) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-4 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The customer will be responsible for automatic notification of
        appropriate staff when indicators of compromise are detected.
        Frequently this is accomplished by automatic alerting to Security
        Operations Center staff. A successful control response will indicate
        who is notified, by name or position title(s), and the mechanism of
        the notification.

        A control response for SI-4(4) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-4 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST, and incorporated into AC-6(10).

- control_key: SI-4 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-4(7) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-4 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SI-4 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SI-4 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-4(9) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-4 (11)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SI-4 (12)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SI-4 (13)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: c
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SI-4 (14)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        An Red Hat Virtualization Manager (RHVM) infrastructure does not have wireless capabilities.

- control_key: SI-4 (15)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        An Red Hat Virtualization Manager (RHVM) infrastructure does not have wireless capabilities.

- control_key: SI-4 (16)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The customer will be responsible for aggregating and correlating
        information from monitoring tools, for multiple system components.
        This is frequently accomplished with centralized audit reduction
        tools.

        A control response for SI-4(16) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-4 (17)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SI-4 (18)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-4(18) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-4 (19)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SI-4 (20)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-4(20) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-4 (21)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SI-4 (22)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-4(20) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-4 (23)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The customer will be responsible for installing host-based monitoring
        mechanisms. A successful control response will need to discuss how
        various elements of the Red Hat Virtualization Manager (RHVM) infrastructure are monitored.

        A control response for SI-4(20) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-4 (24)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-4(20) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        A control response for SI-5(a) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: b
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: c
      text: |
        A control response for SI-5(c) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: d
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SI-5 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SI-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        The customer will be responsible for verifying the correct operation
        of security functions within customer-controlled operating systems and
        software. A successful control response will need to discuss the
        security functions deemed necessary to verify, as well as the means
        for testing the correct operation and resolving any issues found.

        A control response for SI-6 is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: b
      text: |
        A control response for SI-6 is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: c
      text: |
        A control response for SI-6 is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: d
      text: |
        A control response for SI-6 is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-6 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SI-6 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-6(2) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-6 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-6(3) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-7
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The customer will be responsible for employing integrity verification
        tools for customer-controlled operating systems and software. A
        successful control response will need to discuss the tools in use and
        the integrity-checking mechanisms these tools employ.

        A control response for SI-7 is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-7 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The customer will be responsible for performing integrity checks at
        customer-specific frequencies and under customer-specified
        circumstances. A successful control response will need to identify the
        criteria for performing integrity checking, as well as the rationale
        for selecting those criteria.

        A control response for SI-7(1) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-7 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-7(2) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-7 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-7(4) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-7 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST, and incorporated into AC-6(10).

- control_key: SI-7 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-7(5) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-7 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-7(2) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-7 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        The customer will be responsible for incorporating the detection of
        customer-defined security-relevant changes into the customers incident
        response capability. A successful control response will need to
        outline the process for deeming particular changes as
        security-relevant and the means by which the incident response
        capability is invoked when needed.

- control_key: SI-7 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-7(8) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

##
## Note: This control regards the boot of *devices*, not
## initialization of software (e.g. Middleware server on
## an operating system).
##
- control_key: SI-7 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-7(9) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-7 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-7(10) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-7 (11)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SI-7 (12)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-7(12) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-7 (13)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SI-7 (14)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SI-7 (15)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-7(15) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-7 (16)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-7(16) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-8
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies that
        are not applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b
      text: |
        This control reflects organizational procedures/policies that
        are not applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SI-8 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies that
        are not applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SI-8 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies that
        are not applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SI-8 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedures/policies that
        are not applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SI-9
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST, and incorporated into AC-2,
        AC-3, AC-5 and AC-6.

- control_key: SI-10
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The customer will be responsible for checking the validity of
        information inputs to customer-controlled operating systems and
        software. A successful control response will need to discuss the
        specific inputs for which the validity is checked, the rationale
        for selecting those inputs for validity checking, and the response
        taken by the system to invalid inputs.

        A control response for SI-10 is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-10 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies that
        are not applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: d
      text: |
        This control reflects organizational procedures/policies that
        are not applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: c
      text: |
        This control reflects organizational procedures/policies that
        are not applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SI-10 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-10(2) is planned. Engineering progress can be
        tracked via:

        https://issues.redhat.com/browse/CMP-555

- control_key: SI-10 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-10(3) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-10 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-10(4) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-10 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        A control response for SI-10(5) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-11
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        The customer will be responsible for generating error messages in
        cusomer-controlled operating systems and software that provide
        information necessary for corrective actions without revealing
        information that could be exploited by adversaries. A successful
        control response will need to discuss the process by which error
        messages are created, analyzed, and corrected when necessary.

        A control response for SI-11(a) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: b
      text: |
        The customer will be responsible for revealing error messages only to
        authorized personnel. A successful control response will need to
        address how error messages are displayed and the means by which access
        to error messages is controlled.

        A control response for SI-11(b) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-12
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The customer will be responsible for handling and retaining
        information within, or hosted by, Red Hat Virtualization Manager (RHVM) in
        accordance with applicable federal laws, Executive Orders,
        directives, policies, regulations, standards, and operational
        requirements. A successful control response will need to outline
        the specific requirements applicable to customer information
        handling and retention, and the means by which those requirements
        are met.

- control_key: SI-13
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A control response for SI-13(a) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-
    - key: b
      text: |
        A control response for SI-13(b) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-13 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        A control response for SI-13(1) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-13 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST, and incorporated into SI-7(16).

- control_key: SI-13 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-13(3) is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-13 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies that
        are not applicable to the configuration of Red Hat Virtualization Manager (RHVM).
    - key: b
      text: |
        This control reflects organizational procedures/policies that
        are not applicable to the configuration of Red Hat Virtualization Manager (RHVM).

- control_key: SI-13 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        A control response for SI-13(5) is planned. Engineering progress can be
        tracked via:

        https://issues.redhat.com/browse/CMP-560

- control_key: SI-14
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-15 is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-14 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-15 is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-15
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-15 is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

##
##  Developers note on SI-15:
##    This control most frequently is applicable to to
##    operating systems and virtualization platforms. If the component falls
##    into such categories a control response is likely required.
##
- control_key: SI-16
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        A control response for SI-16 is planned. Engineering progress can be
        tracked via:

        https://projects.engineering.redhat.com/browse/RHV-

- control_key: SI-17
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response for SI-17 is planned.
