-
The DIDO-TE identifies each Configuration Value requiring protection.
-
Each Sensitive Configuration Value has an applicable Classification and handling rule.
-
-
Only identified and authorised actors, Nodes, processes, and services have access to a Sensitive Configuration Value.
-
Access remains limited to the Sensitive Configuration Value and operation required by the authorised activity.
-
The DIDO-TE protects Sensitive Configuration Values during storage and transfer.
-
The DIDO-TE protects Sensitive Configuration Values from unauthorised disclosure, alteration, substitution, duplication, extraction, and reuse.
-
The DIDO-TE prevents Sensitive Configuration Values from appearing in unprotected configuration files, command histories, process arguments, logs, error messages, Test Results, or Evidence.
-
The DIDO-TE uses protected references, Identifiers, digests, or redacted representations when records require identification without disclosure.
-
Protection does not prevent verification of the Sensitive Configuration Value’s identity, source, authority, integrity, applicability, or use.
-
The DIDO-TE detects an expired, revoked, altered, substituted, exposed, or unauthorised Sensitive Configuration Value.
-
The DIDO-TE prevents use of a Sensitive Configuration Value that fails an applicable validity or protection criterion.
-
The DIDO-TE records access to and material use of Sensitive Configuration Values without recording the exposed values.
-
The DIDO-TE rotates, revokes, replaces, archives, or disposes of Sensitive Configuration Values in accordance with applicable Security Controls.
-
A change to a Sensitive Configuration Value produces a distinguishable configuration revision and triggers applicable
Configuration Validation.
-
The DIDO-TE maintains Traceability among the Sensitive Configuration Value, its Classification, protected reference, authorised Configuration Source, authorised users, Node Configuration, Node instance, Security Controls, access records, findings, exceptions, and resulting Evidence.
-
A missing, exposed, altered, unprotected, unauthorised, improperly retained, or untraceable Sensitive Configuration Value constitutes nonconformance with this requirement.
-
Inspection of Sensitive Configuration Value identification and Classification
-
Inspection of applicable handling rules and Security Controls
-
Inspection of Access Control assignments
-
Inspection of storage and transfer protections
-
Inspection of configuration files, command histories, process arguments, logs, error messages, Test Results, and Evidence for exposed values
-
Confirmation that protected references preserve identity and Traceability without disclosing Sensitive Configuration Values
-
A negative assessment involving unauthorised access
-
A negative assessment involving an altered, expired, or revoked Sensitive Configuration Value
-
A negative assessment involving attempted disclosure through a log or error message
-
Confirmation that an invalid Sensitive Configuration Value prevents the applicable configuration or execution activity
-
Inspection of access, rotation, revocation, retention, and disposal records
-
Inspection of findings, exceptions, Evidence, and Traceability