When an emanation security threat assessment is required, it is sought as early as possible in a system’s life cycle.
Topic
Emanation security threat assessments
Applicable to
Official, Protected, Secret, Top Secret
History
Priority
should
Dec 2023
When an emanation security threat assessment is required, it is sought as early as possible in a system’s life cycle.
The existing control relating to seeking emanation security threat assessments as early as possible in a system’s life cycle was reworded.
Jun 2022
An emanation security threat assessment is sought as early as possible in a system’s life cycle as implementing emanation security can have significant cost implications.
Miscellaneous changes were made to rationale and recommendations throughout the publication to clarify content. This included the adoption of ‘control’ terminology, in preference to ‘security control’ terminology, to allow for the capture of other types of controls in the future, such as privacy controls, in addition to security controls.
In addition, formatting changes were made to the system security plan annex template and the cloud controls matrix template in order to increase their alignment, such as the inclusion of an ‘implementation status’ column within the system security plan annex template. Furthermore, a new ‘responsible entity’ column was added to both templates in order to capture information on the responsible system (in the case of inherited controls) or responsible vendor (in the case of multi-vendor systems) that are responsible for the implementation of controls. Note, this column can also be used to capture information on teams or individuals that are responsible for the implementation of controls if desired.
2017
Agencies needing an emanation security threat assessment should seek one as early as possiblein project life cycles as emanation security controls can have significant cost implications.
Control Text Changed. No public explaination.
2015
Agencies needing an emanation security threat assessment should do so as early as possiblein project life cycles as emanation security controls can have significant cost implications.
2010
Agencies needing an emanation security threat assessment should do so as early as possible in projectlifecycles as emanation security controls can have significant cost implications.