CIS608 - RMF Assignment: Step 3 - Implement
Prepared by: _________________________
Date: _________________________
Categorization for: ______________________________
Briefly describe system operation and purpose: (include general purpose, level/source of
maintenance support, physical environment, sensitivity of information, access by public users)
List roles of authorized users: (include basic and privileged users, any public/client access, etc.)
Using NIST SP 800-60 Vii, list 3-5 information types created, processed, or stored on this system:
Number Name Impact: C I A (L, M, or H)
_______ _________________________________________ ____ ____ _____
_______ _________________________________________ ____ ____ _____
_______ _________________________________________ ____ ____ _____
_______ _________________________________________ ____ ____ _____
_______ _________________________________________ ____ ____ _____
- Date: 09/14/2019
- Your Name:
- System name: ABC University Administration Office
- System Operations and Purpose: The purpose of the University Administration Office is for managing and coordinating all its administrative function. The office has an Admin website to manage Admissions, Degree Programs, University Events, and Financing Options of ABC University. This office is also responsible for answering any administrative related questions, safety & security of the university campus, storing & protecting all financial documents and students records. The University IT department provides the maintenance support to this portal, and the sensitivity of the data is protected. Only authorized admin personals can access the admin office and the admin portal.
- Authorized Roles: 5 Full-time employees can access University Administration Office, including the Admin portal. They can able to create, update, and delete any content from the admin portal. There are 2 system administrator from the IT department who has full access for any system maintenance activities. Other than 5 full-time employees and 2 IT staffs, public have read access to this ABC Admin portal.
- Information Type 1: Facilities, Fleet, and Equipment Management Information Type
- Information Type 2: Help Desk Services Information Type
- Information Type 3: Security Management Information Type
- Information Type 4: System Maintenance Information Type
- Information Type 5: IT Infrastructure Maintenance Information Type
- Information Type Number 1: C.3.1.1
- Information Type Number 2: C.3.1.2
- Information Type Number 3: C.3.1.3
- Information Type Number 4: C.3.5.3
- Information Type Number 5: C.3.5.4
- C1: L
- C2: L
- C3: M
- C4: L
- C5: L
- I1: L
- I2: L
- I3: M
- I4: M
- I5: L
- A1: L
- A2: L
- A3: L
- A4: L
- A5: L