Cybersecurity and Infrastructure Security Agency – Guidance on Consent Banners
3.1 3.1.9
https://www.cisa.gov/resources-tools/resources/guidance-consent-banners
CISA has identified nine factors that entities should consider as they develop banners that provide notice to employees of network monitoring and seek their consent. There is one set of guidance for state, local, tribal and territorial governments, and another set of guidance for private sector entities.
DoD – Consent Banner with FAQ
3.1 3.1.9
https://dl.dod.cyber.mil/hidden/home/unclass-consent_banner.zip
This link provides the standard banner language used within the Department of Defense along with a list of FAQs.
Five Golden Rules for Contractors to Meet New DoD Cyber Mandate
3.1 3.1.7 Access Control
https://federalnewsnetwork.com/all-news/2018/01/five-golden-rules-for-contractors-to-meet-new-dod-cyber-mandate/
This article from Federal News Network provides an overview of key controls that are essential to NIST SP 800-171 compliance: access controls, awareness and training, audit and accountability, configuration management, and identification and authentication.
https://www.tripwire.com/state-of-security/report-usb-threats-to-ics-systems-have-nearly-doubled?_gl=1*17h2dr2*_up*MQ..*_ga*NTE0Nzg5ODUwLjE3NTU4OTEzMzQ.*_ga_CM76E0XMNW*czE3NTU4OTEzMzQkbzEkZzEkdDE3NTU4OTE0MDYkajYwJGwwJGgw*_ga_NHMHGJWX49*czE3NTU4OTEzMzMkbzEkZzEkdDE3NTU4OTE0MDYkajYwJGwwJGgw
This article provides an overview of the risks associated with removable media for industrial facilities based on a 2020 Honeywell report.
https://www.gartner.com/reviews/market/privileged-access-management
This website from Gartner provides reviews and rating for PAM Tools.
Groovy Post – How to Make Windows 11 Lock Automatically After a Set Amount of Inactivity
3.1 3.1.10 Access Control
https://www.groovypost.com/howto/make-windows-10-lock-automatically-after-a-set-amount-of-inactivity/
When you walk away from your computer, you want to make sure to lock it so other people can’t access your machine and its data. You can, of course, manually lock your Windows 11 PC down by hitting Windows Key + L or Ctrl + Alt + Del. But sometimes you forget. The cool thing is you can make Windows 11 lock automatically after a set time of inactivity. Here is a look at a few ways you can set this up.
Indiana State University – Standard for Screen Locking
3.1 3.1.10 Access Control
https://indstate.teamdynamix.com/TDClient/1851/Portal/KB/ArticleDet?ID=85670
An example of a screenlocking standard, used by academia.
Information Security Oversight Office – CUI Presentation
3.1 3.1.3 Access Control
https://www.nist.gov/system/files/documents/2018/10/18/cui18oct2018-0930-1030-cui_overview-casey.pdf
This ISOO presentation describes CUI program and what it is that needs to be protected.
https://www.infosecinstitute.com/resources/security-awareness/security-awareness-hazards-removable-media/
This article provides an overview of removable media including the risks associated with this technology and how to implement a control policy.
InfoWorld – Manage those Macs: A guide for Windows admins / Set your Mac to log out when not in use
3.1 3.1.11 Access Control
https://www.infoworld.com/article/2249814/manage-those-macs-a-guide-for-windows-admins-2.html
This article describes techniques for automating the management of Apple iOS devices that will allow an admin to push polices such as “Idle-time logoff” to a MAC instead of touching each machine. NIST 800-171 Control: 3.1.11