Dayforce

Controls

We take security, compliance, and privacy seriously. Explore our certifications, reports, and policies in one place.
⌘K

AC-11(1)

Pass
Conceal, via the device lock, information previously visible on the display with a publicly viewable image.

AC-11 Part a

Pass
Prevent further access to the system by [ initiating a device lock after [time period] of inactivity | requiring the user to initiate a device lock before leaving the system unattended ].

AC-11 Part b

Pass
Retain the device lock until the user reestablishes access using established identification and authentication procedures.

AC-12

Pass
Automatically terminate a user session after Eight (8) hours or when a session has been logged out after fifteen (15) minutes of idle time.

AC-14 Part a

Pass
Identify No actions that can be performed on the system without identification or authentication consistent with organizational mission and business functions.

AC-14 Part b

Pass
Document and provide supporting rationale in the security plan for the system, user actions not requiring identification or authentication.

AC-17(1)

Pass
Employ automated mechanisms to monitor and control remote access methods.

AC-17(2)

Pass
Implement cryptographic mechanisms to protect the confidentiality and integrity of remote access sessions.

AC-17(3)

Pass
Route remote accesses through authorized and managed network access control points.

AC-17(4) Part a

Pass
Authorize the execution of privileged commands and access to security-relevant information via remote access only in a format that provides assessable evidence and for the following needs: All needs.

AC-17(4) Part b

Pass
Document the rationale for remote access in the security plan for the system.

AC-17 Part a

Pass
Establish and document usage restrictions, configuration/connection requirements, and implementation guidance for each type of remote access allowed.

AC-17 Part b

Pass
Authorize each type of remote access to the system prior to allowing such connections.

AC-18(1)

Pass
Protect wireless access to the system using authentication of [ users | devices ] and encryption.

AC-18(3)

Pass
Disable, when not intended for use, wireless networking capabilities embedded within system components prior to issuance and deployment.

AC-18 Part a

Pass
Establish configuration requirements, connection requirements, and implementation guidance for each type of wireless access.

AC-18 Part b

Pass
Authorize each type of wireless access to the system prior to allowing such connections.

AC-19(5)

Pass
Employ [ full-device encryption | container-based encryption ] to protect the confidentiality and integrity of information on Organization-Controlled Mobile Devices.

AC-19 Part a

Pass
Establish configuration requirements, connection requirements, and implementation guidance for organization-controlled mobile devices, to include when such devices are outside of controlled areas.

AC-19 Part b

Pass
Authorize the connection of mobile devices to organizational systems.

AC-1 Part a1

Pending
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment system-level access control policy that: (a) addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

AC-1 Part a2

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment procedures to facilitate the implementation of the access control policy and the associated access controls.

AC-1 Part b

Pass
Designate an Chief Information Security Officer (CISO) to manage the development, documentation, and dissemination of the access control policy and procedures.

AC-1 Part c1

Pass
Review and update the current access control policy At least every 3 years and following Significant changes.

AC-1 Part c2

Pass
Review and update the current access control procedures At least annually and following Significant changes.

AC-20(1) Part a

Pass
Permit authorized individuals to use an external system to access the system or to process, store, or transmit organization-controlled information only after verification of the implementation of controls on the external system as specified in the organization’s security and privacy policies and security and privacy plans.

AC-20(1) Part b

Pass
Permit authorized individuals to use an external system to access the system or to process, store, or transmit organization-controlled information only after retention of approved system connection or processing agreements with the organizational entity hosting the external system.

AC-20(2)

Pass
Restrict the use of organization-controlled portable storage devices by authorized individuals on external systems using Acceptable use policies, endpoint security controls, and organizational security requirements.

AC-20 Part a

Pass
[ establish [terms and conditions] | identify [controls asserted] ] , consistent with the trust relationships established with other organizations owning, operating, and/or maintaining external systems, allowing authorized individuals to: 1. access the system from external systems; and 2. process, store, or transmit organization-controlled information using external systems.

AC-20 Part b

Pass
Prohibit the use of [ prohibited types of external systems ].

AC-2(1)

Pass
Support the management of system accounts using ServiceNow, One Identity IGA, Microsoft Entra ID, Azure RBAC.

AC-2(12) Part a

Pass
Monitor system accounts for Unusual authentication activity, excessive failed login attempts, anomalous geographic access patterns, privilege escalation events, abnormal administrative activity, unusual access times, and suspicious account behavior.

AC-2(12) Part b

Pass
Report atypical usage of system accounts to Information System Security Officer (ISSO), PubSec Cybersecurity Operations team, and Cybersecurity Management.

AC-2(13)

Pass
Disable accounts of individuals within One (1) Hour of discovery of Insider threat indicators, suspected malicious activity, policy violations, security incidents, compromised credentials, legal or HR-directed actions, or other significant security risks.

AC-21 Part a

Pass
Enable authorized users to determine whether access authorizations assigned to a sharing partner match the information’s access and use restrictions for Specifying authorized users, group/role membership, access authorizations, and role-based access for each account; based on valid authorization, intended system usage, role, and job function.

AC-21 Part b

Pass
Employ Role-based assignment and least-privilege access using automated tools such as Microsoft Purview, Wiz, Enterprise, and Microsoft Sentinel to assist users in making information sharing and collaboration decisions.

AC-2(2)

Pass
Automatically disable temporary and emergency accounts after Ninety-Six (96) Hours.

AC-22 Part a

Pass
Designate individuals authorized to make information publicly accessible.

AC-22 Part b

Pass
Train authorized individuals to ensure that publicly accessible information does not contain nonpublic information.

AC-22 Part c

Pass
Review the proposed content of information prior to posting onto the publicly accessible system to ensure that nonpublic information is not included.

AC-22 Part d

Pass
Review the content on the publicly accessible system for nonpublic information Quarterly and remove such information, if discovered.

AC-2(3) Part a

Pass
Disable accounts within Twenty-Four (24) Hours when the accounts have expired.

AC-2(3) Part b

Pass
Disable accounts within Twenty-Four (24) Hours when the accounts are no longer associated with a user or individual.

AC-2(3) Part c

Pass
Disable accounts within Twenty-Four (24) Hours when the accounts are in violation of organizational policy.

AC-2(3) Part d

Pass
Disable accounts within Twenty-Four (24) Hours when the accounts have been inactive for Sixty (60) Days.

AC-2(4)

Pass
Automatically audit account creation, modification, enabling, disabling, and removal actions.

AC-2(5)

Pass
Require that users log out when For privileged users, at the end of the user's standard work period.

AC-2(7) Part a

Pass
Establish and administer privileged user accounts in accordance with a role-based access scheme.

AC-2(7) Part b

Pass
Monitor privileged role or attribute assignments.

AC-2(7) Part c

Pass
Monitor changes to roles or attributes.

AC-2(7) Part d

Pass
Revoke access when privileged role or attribute assignments are no longer appropriate.

AC-2(9)

Pass
Only permit the use of shared and group accounts that meet Shared and group accounts are permitted only when a documented business need exists, and a justification demonstrates why individual accounts cannot reasonably support the required function.

AC-2 Part a

Pass
Define and document the types of accounts allowed and specifically prohibited for use within the system.

AC-2 Part b

Pass
Assign account managers.

AC-2 Part c

Pass
Require U.S. person validation, manager approval, completion of required trainings, signed Rules of Behavior (RoB), business justification for group and role membership.

AC-2 Part d

Pass
Specify: 1. authorized users of the system; 2. group and role membership; and 3. access authorizations (i.e., privileges) and Role-based access for each account.

AC-2 Part e

Pass
Require approvals by Managers and Resource Owners for requests to create accounts.

AC-2 Part f

Pass
Create, enable, modify, disable, and remove accounts in accordance with Access Control Policy, Identity & Access Management Plan, Human Resources onboarding and offboarding procedures, and established identity governance workflows.

AC-2 Part g

Pass
Monitor the use of accounts.

AC-2 Part h

Pass
Notify account managers and PubSec Enterprise Identity and Access Management (IAM) Team, and Human Resources (HR) Department within: 1. Twenty-four (24) hours when accounts are no longer required; 2. Eight (8) hours when users are terminated or transferred; and 3. Eight (8) hours when system usage or need-to-know changes for an individual.

AC-2 Part i

Pass
Authorize access to the system based on: 1. a valid access authorization; 2. intended system usage; and 3. Role and job function.

AC-2 Part j

Pass
Review accounts for compliance with account management requirements Quarterly for privileged users, annually for non-privileged users.

AC-2 Part k

Pass
Establish and implement a process for changing shared or group account authenticators (if deployed) when individuals are removed from the group.

AC-2 Part l

Pass
Align account management processes with personnel termination and transfer processes.

AC-3

Pass
Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.

AC-4

Pass
Enforce approved authorizations for controlling the flow of information within the system and between connected systems based on Azure RBAC, Microsoft Entra ID, Network Security Groups, Azure Firewall, Application Security Controls, and ServiceNow Approval Workflows.

AC-4(21)

Pass
Separate information flows logically or physically using Separate FedRAMP Azure Tenant, Separate Microsoft Entra ID Environment, Network Segmentation, and Role-Based Access Controls to accomplish FedRAMP and Corporate Information Flows.

AC-5 Part a

Pass
Identify and document Separation of administrative, operational, and security functions.

AC-5 Part b

Pass
Define system access authorizations to support separation of duties.

AC-6

Pass
Employ the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) that are necessary to accomplish assigned organizational tasks.

AC-6(10)

Pass
Prevent non-privileged users from executing privileged functions.

AC-6(1) Part a

Pass
Authorize access for PubSec Enterprise Security Identity and Access Management (IAM) team, PubSec Cybersecurity Operations team, PubSec Cloud Operations Team, PubSec Security Engineering Team, System Administrators, and other authorized personnel with approved administrative responsibilities to Microsoft Entra ID Administration, Azure Administration, Microsoft Sentinel Administration, CrowdStrike Administration, Wiz Administration, ServiceNow Security Administration, Identity Governance Administration, Security Configuration Management, Security Monitoring and Alerting, and Privileged Access Management.

AC-6(1) Part b

Pass
Authorize access for PubSec Enterprise Security Identity and Access Management (IAM) team, PubSec Cybersecurity Operations team, PubSec Cloud Operations Team, PubSec Security Engineering Team, System Administrators, and other authorized personnel with approved administrative responsibilities to Audit Logs, Security Event Data, Security Configurations, Vulnerability Information, Threat Intelligence Data, Access Control Configurations, Identity and Authentication Data, and Incident Response Information.

AC-6(2)

Pass
Require that users of system accounts (or roles) with access to All Security Functions use non-privileged accounts or roles, when accessing nonsecurity functions.

AC-6(5)

Pass
Restrict privileged accounts on the system to PubSec Enterprise Security Identity and Access Management (IAM) team, PubSec Cloud Operations team, PubSec Security Engineering team, PubSec Cybersecurity Operations personnel, System Administrators, Database Administrators, Authorized DevOps Personnel, and other personnel with approved administrative responsibilities.

AC-6(7) Part a

Pass
Review At least Annually the privileges assigned to All Users with Privileges to validate the need for such privileges.

AC-6(7) Part b

Pass
Reassign or remove privileges, if necessary, to correctly reflect organizational mission and business needs.

AC-6(9)

Pass
Log the execution of privileged functions.

AC-7 Part a

Pass
Enforce a limit of [ number ] consecutive invalid logon attempts by a user during a [ time period ].

AC-7 Part b

Pass
Automatically [ lock the account or node for [time period] | lock the account or node until released by an administrator | delay next logon prompt per [delay algorithm] | notify system administrator | take other [action] ] when the maximum number of unsuccessful attempts is exceeded.

AC-8 Part a

Pass
Display Approved FedRAMP System Use Banner to users before granting access to the system that provides privacy and security notices consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines and state that: 1. users are accessing a U.S. Government system; 2. system usage may be monitored, recorded, and subject to audit; 3. unauthorized use of the system is prohibited and subject to criminal and civil penalties; and 4. use of the system indicates consent to monitoring and recording.

AC-8 Part b

Pass
Retain the notification message or banner on the screen until users acknowledge the usage conditions and take explicit actions to log on to or further access the system.

AC-8 Part c

Pass
For publicly accessible systems: 1. display system use information Approved Public Access Notice (if applicable) , before granting further access to the publicly accessible system; 2. display references, if any, to monitoring, recording, or auditing that are consistent with privacy accommodations for such systems that generally prohibit those activities; and 3. include a description of the authorized uses of the system.

AT-1 Part a1

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment system-level awareness and training policy that: (a) addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

AT-1 Part a2

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment procedures to facilitate the implementation of the awareness and training policy and the associated awareness and training controls.

AT-1 Part b

Pass
Designate an Chief Information Security Officer (CISO) to manage the development, documentation, and dissemination of the awareness and training policy and procedures.

AT-1 Part c1

Pass
Review and update the current awareness and training policy At least every three (3) years and following Significant changes.

AT-1 Part c2

Pass
Review and update the current awareness and training procedures At least annually and following Significant changes.

AT-2(2)

Pass
Provide literacy training on recognizing and reporting potential indicators of insider threat.

AT-2(3)

Pass
Provide literacy training on recognizing and reporting potential and actual instances of social engineering and social mining.

AT-2 Part a

Pass
Provide security and privacy literacy training to system users (including managers, senior executives, and contractors): 1. as part of initial training for new users and At least annually thereafter; and 2. when required by system changes or following Security events prompting updates.

AT-2 Part b

Pass
Employ the following techniques to increase the security and privacy awareness of system users Phishing simulations, email advisories.

AT-2 Part c

Pass
Update literacy training and awareness content At least annually and following Identification of new types of security risks or events and as necessary to address changes in the technology environment, organizational policies, and applicable regulatory requirements.

AT-2 Part d

Pass
Incorporate lessons learned from internal or external security incidents or breaches into literacy training and awareness techniques.

AT-3 Part a

Pass
Provide role-based security and privacy training to personnel with the following roles and responsibilities: System Administrators, Security Administrators, Developers, Cloud Engineers, Cybersecurity Operations Personnel, and Privileged Users: 1. before authorizing access to the system, information, or performing assigned duties, and At least annually thereafter; and 2. when required by system changes.

AT-3 Part b

Pass
Update role-based training content At least annually and following Changes to technologies, security responsibilities, threat conditions, and organizational requirements.

AT-3 Part c

Pass
Incorporate lessons learned from internal or external security incidents or breaches into role-based training.

AT-4 Part a

Pass
Document and monitor information security and privacy training activities, including security and privacy awareness training and specific role-based security and privacy training.

AT-4 Part b

Pass
Retain individual training records for At least one (1) year or one (1) year after completion of a specific training program.

AU-11

Pass
Retain audit records for Ninety (90) days online, fifteen (15) months offline to provide support for after-the-fact investigations of incidents and to meet regulatory and organizational information retention requirements.

AU-12 Part a

Pass
Provide audit record generation capability for the event types the system is capable of auditing as defined in [AU-2a](#au-2_smt.a) on All information system and network components where audit capability is deployed/available.

AU-12 Part b

Pass
Allow PubSec Cybersecurity Operations Team, PubSec Cloud Engineering Team to select the event types that are to be logged by specific components of the system.

AU-12 Part c

Pass
Generate audit records for the event types defined in [AU-2c](#au-2_smt.c) that include the audit record content defined in [AU-3](#au-3).

AU-1 Part a1

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment system-level audit and accountability policy that: (a) addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

AU-1 Part a2

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment procedures to facilitate the implementation of the audit and accountability policy and the associated audit and accountability controls.

AU-1 Part b

Pass
Designate an Chief Information Security Officer (CISO) to manage the development, documentation, and dissemination of the audit and accountability policy and procedures.

AU-1 Part c1

Pass
Review and update the current audit and accountability policy At least every three (3) years and following Significant changes.

AU-1 Part c2

Pass
Review and update the current audit and accountability procedures At least annually and following Significant changes.

AU-2 Part a

Pass
Identify the types of events that the system is capable of logging in support of the audit function: Successful and unsuccessful account logon events, account management events, object access, policy change, privilege functions, process tracking, and system events. For Web applications: All administrator activity, authentication checks, authorization checks, data deletions, data access, data changes, and permission changes.

AU-2 Part b

Pass
Coordinate the event logging function with other organizational entities requiring audit-related information to guide and inform the selection criteria for events to be logged.

AU-2 Part c

Pass
Specify the following event types for logging within the system: Organization-defined subset of the auditable events defined in a to be audited continually for each identified event.

AU-2 Part d

Pass
Provide a rationale for why the event types selected for logging are deemed to be adequate to support after-the-fact investigations of incidents.

AU-2 Part e

Pass
Review and update the event types selected for logging Annually and whenever there is a change in the threat environment.

AU-3(1)

Pass
Generate audit records containing the following additional information: Session, connection, transaction, or activity duration ; For client-server transactions, the number of bytes received and sent; Additional informational messages to diagnose or identify the event; Characteristics the describe or identify the object or resource being acted upon; Individual identities of group account users; Full-text of privileged commands.

AU-3 Part a

Pass
Ensure that audit records contain information that establishes the following what type of event occurred.

AU-3 Part b

Pass
Ensure that audit records contain information that establishes the following when the event occurred.

AU-3 Part c

Pass
Ensure that audit records contain information that establishes the following where the event occurred.

AU-3 Part d

Pass
Ensure that audit records contain information that establishes the following source of the event.

AU-3 Part e

Pass
Ensure that audit records contain information that establishes the following outcome of the event.

AU-3 Part f

Pass
Ensure that audit records contain information that establishes the following identity of any individuals, subjects, or objects/entities associated with the event.

AU-4

Pass
Allocate audit log storage capacity to accommodate Ninety (90) days hot/online, fifteen (15) months cold storage.

AU-5 Part a

Pass
Alert PubSec Cybersecurity Operations Team within Near real-time in the event of an audit logging process failure.

AU-5 Part b

Pass
Take the following additional actions: Overwrite oldest record.

AU-6(1)

Pass
Integrate audit record review, analysis, and reporting processes using Microsoft Sentinel Azure Monitor Log Analytics.

AU-6(3)

Pass
Analyze and correlate audit records across different repositories to gain organization-wide situational awareness.

AU-6 Part a

Pass
Review and analyze system audit records At least weekly for indications of Inappropriate or unusual activity per the established baseline and the potential impact of the inappropriate or unusual activity.

AU-6 Part b

Pass
Report findings to CISO, PubSec Cybersecurity Operations Team.

AU-6 Part c

Pass
Adjust the level of audit record review, analysis, and reporting within the system when there is a change in risk based on law enforcement information, intelligence information, or other credible sources of information.

AU-7(1)

Pass
Provide and implement the capability to process, sort, and search audit records for events of interest based on the following content: All events and details per AU-2 and AU-3 and threat intelligence.

AU-7 Part a

Pass
Provide and implement an audit record reduction and report generation capability that supports on-demand audit record review, analysis, and reporting requirements and after-the-fact investigations of incidents.

AU-7 Part b

Pass
Provide and implement an audit record reduction and report generation capability that does not alter the original content or time ordering of audit records.

AU-8 Part a

Pass
Use internal system clocks to generate time stamps for audit records.

AU-8 Part b

Pass
Record time stamps for audit records that meet One second granularity of time measurement and that use Coordinated Universal Time, have a fixed local time offset from Coordinated Universal Time, or that include the local time offset as part of the time stamp.

AU-9(4)

Pass
Authorize access to management of audit logging functionality to only Site Reliability Engineering (SRE) Team or PubSec Cybersecurity Operations Team.

AU-9 Part a

Pass
Protect audit information and audit logging tools from unauthorized access, modification, and deletion.

AU-9 Part b

Pass
Alert PubSec Cybersecurity Operations Team upon detection of unauthorized access, modification, or deletion of audit information.

CA-1 Part a1

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment system-level assessment, authorization, and monitoring policy that: (a) addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

CA-1 Part a2

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment procedures to facilitate the implementation of the assessment, authorization, and monitoring policy and the associated assessment, authorization, and monitoring controls.

CA-1 Part b

Pass
Designate an Chief Information Security Officer (CISO) to manage the development, documentation, and dissemination of the assessment, authorization, and monitoring policy and procedures.

CA-1 Part c1

Pass
Review and update the current assessment, authorization, and monitoring policy At least every three (3) years and following Significant changes.

CA-1 Part c2

Pass
Review and update the current assessment, authorization, and monitoring procedures At least annually and following Significant changes.

CA-2(1)

Pass
Employ independent assessors or assessment teams to conduct control assessments.

CA-2(3)

Pass
Leverage the results of control assessments performed by Any FedRAMP-Accredited 3PAO on Dayforce PubSec HCM when the assessment meets FedRAMP Moderate baseline for systems with sensitive federal data/system data.

CA-2 Part a

Pass
Select the appropriate assessor or assessment team for the type of assessment to be conducted.

CA-2 Part b

Pass
Develop a control assessment plan that describes the scope of the assessment including: 1. controls and control enhancements under assessment; 2. assessment procedures to be used to determine control effectiveness; and 3. assessment environment, assessment team, and assessment roles and responsibilities.

CA-2 Part c

Pass
Ensure the control assessment plan is reviewed and approved by the authorizing official or designated representative prior to conducting the assessment.

CA-2 Part d

Pass
Assess the controls in the system and its environment of operation At least annually to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting established security and privacy requirements.

CA-2 Part e

Pass
Produce a control assessment report that document the results of the assessment.

CA-2 Part f

Pass
Provide the results of the control assessment to System Stakeholders, PubSec Governance & Assurance Personnel, Executive Leadership, Authorizing Officials (AO), 3PAO.

CA-3 Part a

Pass
Approve and manage the exchange of information between the system and other systems using [ interconnection security agreements | information exchange security agreements | memoranda of understanding or agreement | service level agreements | user agreements | non-disclosure agreements | [type of agreement] ].

CA-3 Part b

Pass
Document, as part of each exchange agreement, the interface characteristics, security and privacy requirements, controls, and responsibilities for each system, and the impact level of the information communicated.

CA-3 Part c

Pass
Review and update the agreements [ frequency ].

CA-5 Part a

Pass
Develop a plan of action and milestones for the system to document the planned remediation actions of the organization to correct weaknesses or deficiencies noted during the assessment of the controls and to reduce or eliminate known vulnerabilities in the system.

CA-5 Part b

Pass
Update existing plan of action and milestones At least monthly based on the findings from control assessments, independent audits or reviews, and continuous monitoring activities.

CA-6 Part a

Pass
Assign a senior official as the authorizing official for the system.

CA-6 Part b

Pass
Assign a senior official as the authorizing official for common controls available for inheritance by organizational systems.

CA-6 Part c

Pass
Ensure that the authorizing official for the system, before commencing operations: 1. accepts the use of common controls inherited by the system; and 2. authorizes the system to operate.

CA-6 Part d

Pass
Ensure that the authorizing official for common controls authorizes the use of those controls for inheritance by organizational systems.

CA-6 Part e

Pass
Update the authorizations In accordance with OMB A-130 requirements (every three (3) years) or when a significant change occurs.

CA-7(1)

Pass
Employ independent assessors or assessment teams to monitor the controls in the system on an ongoing basis.

CA-7(4) Part a

Pass
Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following effectiveness monitoring.

CA-7(4) Part b

Pass
Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following compliance monitoring.

CA-7(4) Part c

Pass
Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following change monitoring.

CA-7 Part a

Pass
Develop a system-level continuous monitoring strategy and implement continuous monitoring in accordance with the organization-level continuous monitoring strategy that includes establishing the following system-level metrics to be monitored: Metrics as noted in SSP Appendix N: Continuous Monitoring.

CA-7 Part b

Pass
Develop a system-level continuous monitoring strategy and implement continuous monitoring in accordance with the organization-level continuous monitoring strategy that includes establishing Frequencies as noted in SSP Appendix N: Continuous Monitoring for monitoring and Frequencies as noted in SSP Appendix N: Continuous Monitoring for assessment of control effectiveness.

CA-7 Part c

Pass
Develop a system-level continuous monitoring strategy and implement continuous monitoring in accordance with the organization-level continuous monitoring strategy that includes ongoing control assessments in accordance with the continuous monitoring strategy.

CA-7 Part d

Pass
Develop a system-level continuous monitoring strategy and implement continuous monitoring in accordance with the organization-level continuous monitoring strategy that includes ongoing monitoring of system and organization-defined metrics in accordance with the continuous monitoring strategy.

CA-7 Part e

Pass
Develop a system-level continuous monitoring strategy and implement continuous monitoring in accordance with the organization-level continuous monitoring strategy that includes correlation and analysis of information generated by control assessments and monitoring.

CA-7 Part f

Pass
Develop a system-level continuous monitoring strategy and implement continuous monitoring in accordance with the organization-level continuous monitoring strategy that includes response actions to address results of the analysis of control assessment and monitoring information.

CA-7 Part g

Pass
Develop a system-level continuous monitoring strategy and implement continuous monitoring in accordance with the organization-level continuous monitoring strategy that includes reporting the security and privacy status of the system to Organizational Leadership, PubSec Governance & Assurance Team, AO, Risk Owners Monthly.

CA-8

Pass
Conduct penetration testing At least annually on All components within the Dayforce PubSec HCM federal authorization boundary.

CA-8(1)

Pass
Employ an independent penetration testing agent or team to perform penetration testing on the system or system components.

CA-8(2)

Pass
Employ the following red-team exercises to simulate attempts by adversaries to compromise organizational systems in accordance with applicable rules of engagement: Red team exercises.

CA-9 Part a

Pass
Authorize internal connections of Components used for communication between the corporate network and Dayforce PubSec HCM platform to the system.

CA-9 Part b

Pass
Document, for each internal connection, the interface characteristics, security and privacy requirements, and the nature of the information communicated.

CA-9 Part c

Pass
Terminate internal system connections after When a connection is no longer required or authorized; when the supporting system, component, service, or agreement is retired or terminated; when required security or privacy protections are not maintained; when the connection creates unacceptable risk; or when a change to the connection has not received required approval..

CA-9 Part d

Pass
Review At least annually the continued need for each internal connection.

CM-10 Part a

Pass
Use software and associated documentation in accordance with contract agreements and copyright laws.

CM-10 Part b

Pass
Track the use of software and associated documentation protected by quantity licenses to control copying and distribution.

CM-10 Part c

Pass
Control and document the use of peer-to-peer file sharing technology to ensure that this capability is not used for the unauthorized distribution, display, performance, or reproduction of copyrighted work.

CM-11 Part a

Pass
Establish Access Control Policy, Configuration Management Policy, and approved change-management requirements governing the installation of software by users.

CM-11 Part b

Pass
Enforce software installation policies through the following methods: Restricted AVD permissions, prohibition of local software installation, approved change requests, controlled system images, privileged-access restrictions, and the CM-8(3) unauthorized-component detection mechanisms.

CM-11 Part c

Pass
Monitor policy compliance Continuously through CM-7(5).

CM-12(1)

Pass
Use automated tools to identify Federal data and system data that must be protected at the Moderate impact level on Data stores for customer and system data to ensure controls are in place to protect organizational information and individual privacy.

CM-12 Part a

Pass
Identify and document the location of Federal information and system data processed or stored within Dayforce PubSec HCM and the specific system components on which the information is processed and stored.

CM-12 Part b

Pass
Identify and document the users who have access to the system and system components where the information is processed and stored.

CM-12 Part c

Pass
Document changes to the location (i.e., system or system components) where the information is processed and stored.

CM-1 Part a1

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment system-level configuration management policy that: (a) addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

CM-1 Part a2

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment procedures to facilitate the implementation of the configuration management policy and the associated configuration management controls.

CM-1 Part b

Pass
Designate an Chief Information Security Officer (CISO) to manage the development, documentation, and dissemination of the configuration management policy and procedures.

CM-1 Part c1

Pass
Review and update the current configuration management policy At least every three (3) years and following Significant changes.

CM-1 Part c2

Pass
Review and update the current configuration management procedures At least annually and following Significant changes.

CM-2(2)

Pass
Maintain the currency, completeness, accuracy, and availability of the baseline configuration of the system using Terraform, Terraform Cloud, and Artifactory.

CM-2(3)

Pass
Retain At least one previous approved baseline configuration for each applicable infrastructure and application configuration item of previous versions of baseline configurations of the system to support rollback.

CM-2(7) Part a

Pass
Issue No systems or system components are permitted to travel to locations deemed to be of significant risk with No systems or system components are permitted to travel to locations deemed to be of significant risk to individuals traveling to locations that the organization deems to be of significant risk.

CM-2(7) Part b

Pass
Apply the following controls to the systems or components when the individuals return from travel: No systems or system components are permitted to travel to locations deemed to be of significant risk.

CM-2 Part a

Pass
Develop, document, and maintain under configuration control, a current baseline configuration of the system.

CM-2 Part b

Pass
Review and update the baseline configuration of the system: 1. At least annually and when a significant change occurs; 2. when required due to Significant changes, major releases, infrastructure changes, security incidents, newly identified vulnerabilities, government-directed actions, platform updates, or other security-relevant events ; and 3. when system components are installed or upgraded.

CM-3(2)

Pass
Test, validate, and document changes to the system before finalizing the implementation of the changes.

CM-3(4)

Pass
Require PubSec Product Security Personnel, Privacy Officers, PubSec Change Management Personnel to be members of the Change Advisory Board (CAB) (as defined in CM-3).

CM-3 Part a

Pass
Determine and document the types of changes to the system that are configuration-controlled.

CM-3 Part b

Pass
Review proposed configuration-controlled changes to the system and approve or disapprove such changes with explicit consideration for security and privacy impact analyses.

CM-3 Part c

Pass
Document configuration change decisions associated with the system.

CM-3 Part d

Pass
Implement approved configuration-controlled changes to the system.

CM-3 Part e

Pass
Retain records of configuration-controlled changes to the system for [ time period ].

CM-3 Part f

Pass
Monitor and review activities associated with configuration-controlled changes to the system.

CM-3 Part g

Pass
Coordinate and provide oversight for configuration change control activities through [ configuration change control element ] that convenes [ [frequency] | when [configuration change conditions] ].

CM-4

Pass
Analyze changes to the system to determine potential security and privacy impacts prior to change implementation.

CM-4(2)

Pass
After system changes, verify that the impacted controls are implemented correctly, operating as intended, and producing the desired outcome with regard to meeting the security and privacy requirements for the system.

CM-5

Pass
Define, document, approve, and enforce physical and logical access restrictions associated with changes to the system.

CM-5(1) Part a

Pass
Enforce access restrictions using Microsoft Entra ID, Azure RBAC, ServiceNow, GitHub Enterprise, and Privileged Access Management mechanisms.

CM-5(1) Part b

Pass
Automatically generate audit records of the enforcement actions.

CM-5(5) Part a

Pass
Limit privileges to change system components and system-related information within a production or operational environment.

CM-5(5) Part b

Pass
Review and reevaluate privileges At least quarterly.

CM-6(1)

Pass
Manage, apply, and verify configuration settings for Wiz, Group Policy Objects (GPOs), Intune, Infrastructure-as-Code (IaC), and Packer using CIS Level 2 Benchmarks and Dayforce Security Standards.

CM-6 Part a

Pass
Establish and document configuration settings for components employed within the system that reflect the most restrictive mode consistent with operational requirements using CIS Level 2 Benchmarks, vendor hardening guidance, and approved Dayforce security standards.

CM-6 Part b

Pass
Implement the configuration settings.

CM-6 Part c

Pass
Identify, document, and approve any deviations from established configuration settings for Windows servers, Linux servers, Azure resources, databases, containers, and application platforms based on Documented operational, business, compatibility, or technical requirements.

CM-6 Part d

Pass
Monitor and control changes to the configuration settings in accordance with organizational policies and procedures.

CM-7(1) Part a

Pass
Review the system At least annually to identify unnecessary and/or nonsecure functions, ports, protocols, software, and services.

CM-7(1) Part b

Pass
Disable or remove Unapproved functions, ports, protocols, and services.

CM-7(2)

Pass
Prevent program execution in accordance with [ [policies, rules of behavior, and/or access agreements regarding software program usage and restrictions] | rules authorizing the terms and conditions of software program usage ].

CM-7(5) Part a

Pass
Identify Exception Approval Authorities: Architecture Review Board (ARB), Security Team, Change Management Authority.

CM-7(5) Part b

Pass
Employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs on the system.

CM-7(5) Part c

Pass
Review and update the list of authorized software programs At least quarterly or when there is a change.

CM-7 Part a

Pass
Configure the system to provide only Only essential capabilities required to support Dayforce PubSec HCM business and security requirements.

CM-7 Part b

Pass
Prohibit or restrict the use of the following functions, ports, protocols, software, and/or services: Non-secure and unnecessary functions, ports, protocols, and services.

CM-8(1)

Pass
Update the inventory of system components as part of component installations, removals, and system updates.

CM-8(3) Part a

Pass
Detect the presence of unauthorized hardware, software, and firmware components within the system using [ organization-defined automated mechanisms ] [ frequency ].

CM-8(3) Part b

Pass
Take the following actions when unauthorized components are detected: [ disable network access by unauthorized components | isolate unauthorized components | notify [personnel or roles] ].

CM-8 Part a

Pass
Develop and document an inventory of system components that: 1. accurately reflects the system; 2. includes all components within the system; 3. does not include duplicate accounting of components or components assigned to any other system; 4. is at the level of granularity deemed necessary for tracking and reporting; and 5. includes the following information to achieve system component accountability: Virtual machines, Azure resources, databases, containers, applications, network components, and security tooling.

CM-8 Part b

Pass
Review and update the system component inventory At least monthly.

CM-9 Part a

Pass
Develop, document, and implement a configuration management plan for the system that addresses roles, responsibilities, and configuration management processes and procedures.

CM-9 Part b

Pass
Develop, document, and implement a configuration management plan for the system that establishes a process for identifying configuration items throughout the system development life cycle and for managing the configuration of the configuration items.

CM-9 Part c

Pass
Develop, document, and implement a configuration management plan for the system that defines the configuration items for the system and places the configuration items under configuration management.

CM-9 Part d

Pass
Develop, document, and implement a configuration management plan for the system that is reviewed and approved by Chief Information Security Officer (CISO), System Owner, PubSec Cloud Engineering leadership, and PubSec Change Management leadership.

CM-9 Part e

Pass
Develop, document, and implement a configuration management plan for the system that protects the configuration management plan from unauthorized disclosure and modification.

CP-10

Pass
Provide for the recovery and reconstitution of the system to a known state within RTO Four (4) hours; RPO one (1) hour after a disruption, compromise, or failure.

CP-10(2)

Pass
Implement transaction recovery for systems that are transaction-based.

CP-1 Part a1

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment system-level contingency planning policy that: (a) addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

CP-1 Part a2

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment procedures to facilitate the implementation of the contingency planning policy and the associated contingency planning controls.

CP-1 Part b

Pass
Designate an Chief Information Security Officer (CISO) to manage the development, documentation, and dissemination of the contingency planning policy and procedures.

CP-1 Part c1

Pass
Review and update the current contingency planning policy At least every three (3) years and following Significant changes.

CP-1 Part c2

Pass
Review and update the current contingency planning procedures At least annually and following Significant changes.

CP-2(1)

Pass
Coordinate contingency plan development with organizational elements responsible for related plans.

CP-2(3)

Pass
Plan for the resumption of [ all | essential ] mission and business functions within Recovery Time Objective (RTO) Four (4) Hours of contingency plan activation.

CP-2(8)

Pass
Identify critical system assets supporting [ all | essential ] mission and business functions.

CP-2 Part a

Pass
Develop a contingency plan for the system that: 1. identifies essential mission and business functions and associated contingency requirements; 2. provides recovery objectives, restoration priorities, and metrics; 3. addresses contingency roles, responsibilities, assigned individuals with contact information; 4. addresses maintaining essential mission and business functions despite a system disruption, compromise, or failure; 5. addresses eventual, full system restoration without deterioration of the controls originally planned and implemented; 6. addresses the sharing of contingency information; and 7. is reviewed and approved by Contingency Planning Directors.

CP-2 Part b

Pass
Distribute copies of the contingency plan to Contingency Planning Directors, Contingency Planning Coordinators, Outage and Damage Assessment Leads, Hardware Recovery Team, Software Recovery Team, Telecommunications Team, Procurement and Logistics Coordinators, Security Coordinators, and Technical Recovery Guide (TRG) Owners.

CP-2 Part c

Pass
Coordinate contingency planning activities with incident handling activities.

CP-2 Part d

Pass
Review the contingency plan for the system At least annually.

CP-2 Part e

Pass
Update the contingency plan to address changes to the organization, system, or environment of operation and problems encountered during contingency plan implementation, execution, or testing.

CP-2 Part f

Pass
Communicate contingency plan changes to Contingency Planning Directors, Contingency Planning Coordinators, Outage and Damage Assessment Leads, Hardware Recovery Team, Software Recovery Team, Telecommunications Team, Procurement and Logistics Coordinators, Security Coordinators, and Technical Recovery Guide (TRG) Owners.

CP-2 Part g

Pass
Incorporate lessons learned from contingency plan testing, training, or actual contingency activities into contingency testing and training.

CP-2 Part h

Pass
Protect the contingency plan from unauthorized disclosure and modification.

CP-3 Part a

Pass
Provide contingency training to system users consistent with assigned roles and responsibilities: 1. within Ten (10) days for privileged admins and engineers, sixty (60) days of hire date of assuming a contingency role or responsibility; 2. when required by system changes; and 3. At least annually thereafter.

CP-3 Part b

Pass
Review and update contingency training content At least annually and following Contingency testing, exercises, and actual recovery events.

CP-4(1)

Pass
Coordinate contingency plan testing with organizational elements responsible for related plans.

CP-4 Part a

Pass
Test the contingency plan for the system At least annually using the following tests to determine the effectiveness of the plan and the readiness to execute the plan: Functional exercises.

CP-4 Part b

Pass
Review the contingency plan test results.

CP-4 Part c

Pass
Initiate corrective actions, if needed.

CP-6(1)

Pass
Identify an alternate storage site that is sufficiently separated from the primary storage site to reduce susceptibility to the same threats.

CP-6(3)

Pass
Identify potential accessibility problems to the alternate storage site in the event of an area-wide disruption or disaster and outline explicit mitigation actions.

CP-6 Part a

Pass
Establish an alternate storage site, including necessary agreements to permit the storage and retrieval of system backup information.

CP-6 Part b

Pass
Ensure that the alternate storage site provides controls equivalent to that of the primary site.

CP-7(1)

Pass
Identify an alternate processing site that is sufficiently separated from the primary processing site to reduce susceptibility to the same threats.

CP-7(2)

Pass
Identify potential accessibility problems to alternate processing sites in the event of an area-wide disruption or disaster and outlines explicit mitigation actions.

CP-7(3)

Pass
Develop alternate processing site agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives).

CP-7 Part a

Pass
Establish an alternate processing site, including necessary agreements to permit the transfer and resumption of Dayforce PubSec HCM system operations for essential mission and business functions within RTO: Four (4) hours, RPO: One (1) hour when the primary processing capabilities are unavailable.

CP-7 Part b

Pass
Make available at the alternate processing site, the equipment and supplies required to transfer and resume operations or put contracts in place to support delivery to the site within the organization-defined time period for transfer and resumption.

CP-7 Part c

Pass
Provide controls at the alternate processing site that are equivalent to those at the primary site.

CP-8

Pass
Establish alternate telecommunications services, including necessary agreements to permit the resumption of Dayforce PubSec HCM system operations for essential mission and business functions within RTO: Four (4) hours when the primary telecommunications capabilities are unavailable at either the primary or alternate processing or storage sites.

CP-8(1) Part a

Pass
Develop primary and alternate telecommunications service agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives).

CP-8(1) Part b

Pass
Request Telecommunications Service Priority for all telecommunications services used for national security emergency preparedness if the primary and/or alternate telecommunications services are provided by a common carrier.

CP-8(2)

Pass
Obtain alternate telecommunications services to reduce the likelihood of sharing a single point of failure with primary telecommunications services.

CP-9(1)

Pass
Test backup information At least weekly to verify media reliability and information integrity.

CP-9(8)

Pass
Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of All backup files.

CP-9 Part a

Pass
Conduct backups of user-level information contained in All Dayforce PubSec HCM components that contain user-level information Daily incremental; weekly full.

CP-9 Part b

Pass
Conduct backups of system-level information contained in the system Daily incremental; weekly full.

CP-9 Part c

Pass
Conduct backups of system documentation, including security- and privacy-related documentation Daily incremental; weekly full.

CP-9 Part d

Pass
Protect the confidentiality, integrity, and availability of backup information.

IA-11

Pass
Require users to re-authenticate when Every twelve (12) hours or after thirty (30) minutes of inactivity.

IA-12(2)

Pass
Require evidence of individual identification be presented to the registration authority.

IA-12(3)

Pass
Require that the presented identity evidence be validated and verified through Visual inspection.

IA-12(5)

Pass
Require that a [ registration code | notice of proofing ] be delivered through an out-of-band channel to verify the users address (physical or digital) of record.

IA-12 Part a

Pass
Identity proof users that require accounts for logical access to systems based on appropriate identity assurance level requirements as specified in applicable standards and guidelines.

IA-12 Part b

Pass
Resolve user identities to a unique individual.

IA-12 Part c

Pass
Collect, validate, and verify identity evidence.

IA-1 Part a1

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment system-level identification and authentication policy that: (a) addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

IA-1 Part a2

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment procedures to facilitate the implementation of the identification and authentication policy and the associated identification and authentication controls.

IA-1 Part b

Pass
Designate an Chief Information Security Officer (CISO) to manage the development, documentation, and dissemination of the identification and authentication policy and procedures.

IA-1 Part c1

Pass
Review and update the current identification and authentication policy At least every three (3) years and following Significant changes.

IA-1 Part c2

Pass
Review and update the current identification and authentication procedures At least annually and following Significant changes.

IA-2

Pass
Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users.

IA-2(1)

Pass
Implement multi-factor authentication for access to privileged accounts.

IA-2(12)

Pass
Accept and electronically verify Personal Identity Verification-compliant credentials.

IA-2(2)

Pass
Implement multi-factor authentication for access to non-privileged accounts.

IA-2(5)

Pass
When shared accounts or authenticators are employed, require users to be individually authenticated before granting access to the shared accounts or resources.

IA-2(6) Part a

Pass
Implement multi-factor authentication for [ local | network | remote ] access to [ privileged accounts | non-privileged accounts ] such that one of the factors is provided by a device separate from the system gaining access.

IA-2(6) Part b

Pass
Implement multi-factor authentication for [ local | network | remote ] access to [ privileged accounts | non-privileged accounts ] such that the device meets FIPS-validated.

IA-2(8)

Pass
Implement replay-resistant authentication mechanisms for access to [ privileged accounts | non-privileged accounts ].

IA-3

Pass
Uniquely identify and authenticate Organizational devices, administrative workstations, Azure Virtual Desktop (AVD) session hosts, managed servers, virtual machines, Kubernetes worker nodes, and other managed infrastructure components operating within Dayforce PubSec HCM before establishing a [ local | remote | network ] connection.

IA-4(4)

Pass
Manage individual identifiers by uniquely identifying each individual as Contractors, foreign nationals.

IA-4 Part a

Pass
Manage system identifiers by receiving authorization from User’s manager and ISSO to assign an individual, group, role, service, or device identifier.

IA-4 Part b

Pass
Manage system identifiers by selecting an identifier that identifies an individual, group, role, service, or device.

IA-4 Part c

Pass
Manage system identifiers by assigning the identifier to the intended individual, group, role, service, or device.

IA-4 Part d

Pass
Manage system identifiers by preventing reuse of identifiers for At least two (2) years.

IA-5(1) Part a

Pass
For password-based authentication maintain a list of commonly-used, expected, or compromised passwords and update the list Monthly through Microsoft Entra ID password-protection services and when organizational passwords are suspected to have been compromised directly or indirectly and when organizational passwords are suspected to have been compromised directly or indirectly.

IA-5(1) Part b

Pass
For password-based authentication verify, when users create or update passwords, that the passwords are not found on the list of commonly-used, expected, or compromised passwords in IA-5(1)(a).

IA-5(1) Part c

Pass
For password-based authentication transmit passwords only over cryptographically-protected channels.

IA-5(1) Part d

Pass
For password-based authentication store passwords using an approved salted key derivation function, preferably using a keyed hash.

IA-5(1) Part e

Pass
For password-based authentication require immediate selection of a new password upon account recovery.

IA-5(1) Part f

Pass
For password-based authentication allow user selection of long passwords and passphrases, including spaces and all printable characters.

IA-5(1) Part g

Pass
For password-based authentication employ automated tools to assist the user in selecting strong password authenticators.

IA-5(1) Part h

Pass
For password-based authentication enforce the following composition and complexity rules: If there is an instance where a password is needed: Minimum length of 14 characters and support for all printable ASCII characters. For emergency-use accounts: minimum length of 14 characters, support for all printable ASCII characters, and mandatory password change after each use.

IA-5(2) Part a

Pass
For public key-based authentication: (1) enforce authorized access to the corresponding private key; and (2) map the authenticated identity to the account of the individual or group.

IA-5(2) Part b

Pass
When public key infrastructure (PKI) is used: (1) validate certificates by constructing and verifying a certification path to an accepted trust anchor, including checking certificate status information; and (2) implement a local cache of revocation data to support path discovery and validation.

IA-5(6)

Pass
Protect authenticators commensurate with the security category of the information to which use of the authenticator permits access.

IA-5(7)

Pass
Ensure that unencrypted static authenticators are not embedded in applications or other forms of static storage.

IA-5 Part a

Pass
Manage system authenticators by verifying, as part of the initial authenticator distribution, the identity of the individual, group, role, service, or device receiving the authenticator.

IA-5 Part b

Pass
Manage system authenticators by establishing initial authenticator content for any authenticators issued by the organization.

IA-5 Part c

Pass
Manage system authenticators by ensuring that authenticators have sufficient strength of mechanism for their intended use.

IA-5 Part d

Pass
Manage system authenticators by establishing and implementing administrative procedures for initial authenticator distribution, for lost or compromised or damaged authenticators, and for revoking authenticators.

IA-5 Part e

Pass
Manage system authenticators by changing default authenticators prior to first use.

IA-5 Part f

Pass
Manage system authenticators by changing or refreshing authenticators At least annually for organization-issued certificates and immediately upon compromise, personnel separation, role change, loss, theft, cryptographic weakness, or administrative direction or when Suspected or confirmed compromise, loss, theft, personnel termination, role change, certificate expiration, cryptographic weakness, or other security events requiring authenticator replacement occur.

IA-5 Part g

Pass
Manage system authenticators by protecting authenticator content from unauthorized disclosure and modification.

IA-5 Part h

Pass
Manage system authenticators by requiring individuals to take, and having devices implement, specific controls to protect authenticators.

IA-5 Part i

Pass
Manage system authenticators by changing authenticators for group or role accounts when membership to those accounts changes.

IA-6

Pass
Obscure feedback of authentication information during the authentication process to protect the information from possible exploitation and use by unauthorized individuals.

IA-7

Pass
Implement mechanisms for authentication to a cryptographic module that meet the requirements of applicable laws, executive orders, directives, policies, regulations, standards, and guidelines for such authentication.

IA-8

Pass
Uniquely identify and authenticate non-organizational users or processes acting on behalf of non-organizational users.

IA-8(1)

Pass
Accept and electronically verify Personal Identity Verification-compliant credentials from other federal agencies.

IA-8(2) Part a

Pass
Accept only external authenticators that are NIST-compliant.

IA-8(2) Part b

Pass
Document and maintain a list of accepted external authenticators.

IA-8(4)

Pass
Conform to the following profiles for identity management Microsoft Entra ID, OpenID Connect, SAML.

IR-1 Part a1

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment system-level incident response policy that: (a) addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

IR-1 Part a2

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment procedures to facilitate the implementation of the incident response policy and the associated incident response controls.

IR-1 Part b

Pass
Designate an Chief Information Security Officer (CISO) to manage the development, documentation, and dissemination of the incident response policy and procedures.

IR-1 Part c1

Pass
Review and update the current incident response policy At least every three (3) years and following Significiant changes.

IR-1 Part c2

Pass
Review and update the current incident response procedures At least annually and following Significiant changes.

IR-2 Part a

Pass
Provide incident response training to system users consistent with assigned roles and responsibilities: 1. within Ten (10) days for privileged users, thirty (30) days for Incident Response Roles of assuming an incident response role or responsibility or acquiring system access; 2. when required by system changes; and 3. At least annually thereafter.

IR-2 Part b

Pass
Review and update incident response training content At least annually and following Significant organizational or system changes, updates to incident response procedures, functional exercises, security incidents, privacy incidents, non-security incidents, lessons learned activities, and root cause analyses.

IR-3

Pass
Test the effectiveness of the incident response capability for the system Functional, at least annually using the following tests: Tabletop exercises and simulated incident scenarios.

IR-3(2)

Pass
Coordinate incident response testing with organizational elements responsible for related plans.

IR-4(1)

Pass
Support the incident handling process using Microsoft Sentinel, ServiceNow, PagerDuty.

IR-4 Part a

Pass
Implement an incident handling capability for incidents that is consistent with the incident response plan and includes preparation, detection and analysis, containment, eradication, and recovery.

IR-4 Part b

Pass
Coordinate incident handling activities with contingency planning activities.

IR-4 Part c

Pass
Incorporate lessons learned from ongoing incident handling activities into incident response procedures, training, and testing, and implement the resulting changes accordingly.

IR-4 Part d

Pass
Ensure the rigor, intensity, scope, and results of incident handling activities are comparable and predictable across the organization.

IR-5

Pass
Track and document incidents.

IR-6(1)

Pass
Report incidents using Microsoft Sentinel, ServiceNow, and PagerDuty.

IR-6(3)

Pass
Provide incident information to the provider of the product or service and other organizations involved in the supply chain or supply chain governance for systems or system components related to the incident.

IR-6 Part a

Pass
Require personnel to report suspected incidents to the organizational incident response capability within US-CERT incident reporting timelines as specified in NIST SP 800-61(as amended).

IR-6 Part b

Pass
Report incident information to Designated Dayforce incident-response and legal personnel, affected federal customer contacts and Authorizing Officials, designated FedRAMP contacts, and other required federal reporting authorities.

IR-7

Pass
Provide an incident response support resource, integral to the organizational incident response capability, that offers advice and assistance to users of the system for the handling and reporting of incidents.

IR-7(1)

Pass
Increase the availability of incident response information and support using ServiceNow, PagerDuty, Microsoft Sentinel, and security monitoring platforms.

IR-8 Part a

Pass
Develop an incident response plan that: 1. provides the organization with a roadmap for implementing its incident response capability; 2. describes the structure and organization of the incident response capability; 3. provides a high-level approach for how the incident response capability fits into the overall organization; 4. meets the unique requirements of the organization, which relate to mission, size, structure, and functions; 5. defines reportable incidents; 6. provides metrics for measuring the incident response capability within the organization; 7. defines the resources and management support needed to effectively maintain and mature an incident response capability; 8. addresses the sharing of incident information; 9. is reviewed and approved by Chief Information Security Officer and designated incident-response leadership At least annually ; and 10. explicitly designates responsibility for incident response to PubSec Cybersecurity Operations personnel, supported by Incident Management, Legal, Privacy, Product Security, Cloud Operations, Cloud Engineering, executive leadership, and other applicable response stakeholders.

IR-8 Part b

Pass
Distribute copies of the incident response plan to Designated incident-response personnel and organizational elements including designated FedRAMP personnel.

IR-8 Part c

Pass
Update the incident response plan to address system and organizational changes or problems encountered during plan implementation, execution, or testing.

IR-8 Part d

Pass
Communicate incident response plan changes to Designated incident-response personnel and organizational elements including designated FedRAMP personnel.

IR-8 Part e

Pass
Protect the incident response plan from unauthorized disclosure and modification.

IR-9(2)

Pass
Provide information spillage response training At least annually.

IR-9(3)

Pass
Implement the following procedures to ensure that organizational personnel impacted by information spills can continue to carry out assigned tasks while contaminated systems are undergoing corrective actions: Dayforce incident response process.

IR-9(4)

Pass
Employ the following controls for personnel exposed to information not within assigned access authorizations: Restrict further access, preserve evidence, identify exposed personnel, notify Legal/Privacy Counsel, assess disclosure obligations, obtain nondisclosure or handling instructions where appropriate, monitor for further dissemination, and document the exposure and corrective actions.

IR-9 Part a

Pass
Respond to information spills by assigning PubSec Cybersecurity Operations Personnel, Privacy Personnel, PubSec Legal Personnel with responsibility for responding to information spills.

IR-9 Part b

Pass
Respond to information spills by identifying the specific information involved in the system contamination.

IR-9 Part c

Pass
Respond to information spills by alerting PubSec Cybersecurity Operations Personnel, Privacy Personnel, PubSec Legal Personnel, Management Personnel of the information spill using a method of communication not associated with the spill.

IR-9 Part d

Pass
Respond to information spills by isolating the contaminated system or system component.

IR-9 Part e

Pass
Respond to information spills by eradicating the information from the contaminated system or component.

IR-9 Part f

Pass
Respond to information spills by identifying other systems or system components that may have been subsequently contaminated.

IR-9 Part g

Pass
Respond to information spills by performing the following additional actions: Preserve evidence, determine the scope and impact of the spill, assess notification obligations, document response activities, track corrective actions, and perform lessons-learned review.

MA-1 Part a1

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment system-level maintenance policy that: (a) addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

MA-1 Part a2

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment procedures to facilitate the implementation of the maintenance policy and the associated maintenance controls.

MA-1 Part b

Pass
Designate an Chief Information Security Officer (CISO) to manage the development, documentation, and dissemination of the maintenance policy and procedures.

MA-1 Part c1

Pass
Review and update the current maintenance policy At least every three (3) years and following Significant changes.

MA-1 Part c2

Pass
Review and update the current maintenance procedures At least annually and following Significant changes.

MA-2 Part a

Pass
Schedule, document, and review records of maintenance, repair, and replacement on system components in accordance with manufacturer or vendor specifications and/or organizational requirements.

MA-2 Part b

Pass
Approve and monitor all maintenance activities, whether performed on site or remotely and whether the system or system components are serviced on site or removed to another location.

MA-2 Part c

Pass
Require that Data center technicians explicitly approve the removal of the system or system components from organizational facilities for off-site maintenance, repair, or replacement.

MA-2 Part d

Pass
Sanitize equipment to remove the following information from associated media prior to removal from organizational facilities for off-site maintenance, repair, or replacement: All information.

MA-2 Part e

Pass
Check all potentially impacted controls to verify that the controls are still functioning properly following maintenance, repair, or replacement actions.

MA-2 Part f

Pass
Include the following information in organizational maintenance records: Maintenance-related information.

MA-3(1)

Pass
Inspect the maintenance tools used by maintenance personnel for improper or unauthorized modifications.

MA-3(2)

Pass
Check media containing diagnostic and test programs for malicious code before the media are used in the system.

MA-3(3) Part a

Pass
Prevent the removal of maintenance equipment containing organizational information by verifying that there is no organizational information contained on the equipment.

MA-3(3) Part b

Pass
Prevent the removal of maintenance equipment containing organizational information by sanitizing or destroying the equipment.

MA-3(3) Part c

Pass
Prevent the removal of maintenance equipment containing organizational information by retaining the equipment within the facility.

MA-3(3) Part d

Pass
Prevent the removal of maintenance equipment containing organizational information by obtaining an exemption from The information owner explicitly authorizing removal of the equipment from the facility.

MA-3 Part a

Pass
Approve, control, and monitor the use of system maintenance tools.

MA-3 Part b

Pass
Review previously approved system maintenance tools At least annually.

MA-4 Part a

Pass
Approve and monitor nonlocal maintenance and diagnostic activities.

MA-4 Part b

Pass
Allow the use of nonlocal maintenance and diagnostic tools only as consistent with organizational policy and documented in the security plan for the system.

MA-4 Part c

Pass
Employ strong authentication in the establishment of nonlocal maintenance and diagnostic sessions.

MA-4 Part d

Pass
Maintain records for nonlocal maintenance and diagnostic activities.

MA-4 Part e

Pass
Terminate session and network connections when nonlocal maintenance is completed.

MA-5(1) Part a

Pass
Implement procedures for the use of maintenance personnel that lack appropriate security clearances or are not U.S. citizens, that include the following requirements: (1) maintenance personnel who do not have needed access authorizations, clearances, or formal access approvals are escorted and supervised during the performance of maintenance and diagnostic activities on the system by approved organizational personnel who are fully cleared, have appropriate access authorizations, and are technically qualified; and (2) prior to initiating maintenance or diagnostic activities by personnel who do not have needed access authorizations, clearances or formal access approvals, all volatile information storage components within the system are sanitized and all nonvolatile storage media are removed or physically disconnected from the system and secured.

MA-5(1) Part b

Pass
Develop and implement Alternate security safeguards in the event a system component cannot be sanitized, removed, or disconnected from the system.

MA-5 Part a

Pass
Establish a process for maintenance personnel authorization and maintain a list of authorized maintenance organizations or personnel.

MA-5 Part b

Pass
Verify that non-escorted personnel performing maintenance on the system possess the required access authorizations.

MA-5 Part c

Pass
Designate organizational personnel with required access authorizations and technical competence to supervise the maintenance activities of personnel who do not possess the required access authorizations.

MA-6

Pass
Obtain maintenance support and/or spare parts for Infrastructure components within A timeframe to support advertised uptime and availability of failure.

MP-1 Part a1

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment system-level media protection policy that: (a) addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

MP-1 Part a2

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment procedures to facilitate the implementation of the media protection policy and the associated media protection controls.

MP-1 Part b

Pass
Designate an Chief Information Security Officer (CISO) to manage the development, documentation, and dissemination of the media protection policy and procedures.

MP-1 Part c1

Pass
Review and update the current media protection policy At least every three (3) years and following Significant changes.

MP-1 Part c2

Pass
Review and update the current media protection procedures At least annually and following Significant changes.

MP-2

Pass
Restrict access to All types of digital and/or non-digital media containing sensitive information to Personnel granted access to Azure Commercial Cloud data center facilities (via a badge swipe and personal identification number (PIN) combination) after screening against a pre-authorized list of those needing access to perform their duties or those who are fully escorted, as appropriate.

MP-3 Part a

Pass
Mark system media indicating the distribution limitations, handling caveats, and applicable security markings (if any) of the information.

MP-3 Part b

Pass
Exempt No removable media types from marking if the media remain within Not applicable.

MP-4 Part a

Pass
Physically control and securely store All types of digital and non-digital media with sensitive information within Defined controlled areas where the information and information system reside..

MP-4 Part b

Pass
Protect system media types defined in MP-4a until the media are destroyed or sanitized using approved equipment, techniques, and procedures.

MP-5 Part a

Pass
Protect and control All media with sensitive information during transport outside of controlled areas using Prior to leaving secure/controlled environment: For digital media, encryption in compliance with Federal requirements and utilizes FIPS validated or NSA approved cryptography (See SC-13); For non-digital media, secured in a locked container.

MP-5 Part b

Pass
Maintain accountability for system media during transport outside of controlled areas.

MP-5 Part c

Pass
Document activities associated with the transport of system media.

MP-5 Part d

Pass
Restrict the activities associated with the transport of system media to authorized personnel.

MP-6 Part a

Pass
Sanitize Techniques and procedures IAW NIST SP 800-88 Section 4: Reuse and Disposal of Storage Media and Hardware prior to disposal, release out of organizational control, or release for reuse using Organization-defined sanitization techniques and procedures.

MP-6 Part b

Pass
Employ sanitization mechanisms with the strength and integrity commensurate with the security category or classification of the information.

MP-7 Part a

Pass
[ restrict | prohibit ] the use of Azure-defined types of system media on Azure-defined systems or system components using Azure-defined controls.

MP-7 Part b

Pass
Prohibit the use of portable storage devices in organizational systems when such devices have no identifiable owner.

PE-10 Part a

Pending
Provide the capability of shutting off power to The information system or individual system components in emergency situations.

PE-10 Part b

Pending
Place emergency shutoff switches or devices in Near more than one egress point of the IT area and ensure it is labeled and protected by a cover to prevent accidental shut-off to facilitate access for authorized personnel.

PE-10 Part c

Pending
Protect emergency power shutoff capability from unauthorized activation.

PE-11

Pass
Provide an uninterruptible power supply to facilitate [ an orderly shutdown of the system | transition of the system to long-term alternate power ] in the event of a primary power source loss.

PE-12

Pending
Employ and maintain automatic emergency lighting for the system that activates in the event of a power outage or disruption and that covers emergency exits and evacuation routes within the facility.

PE-13

Pass
Employ and maintain fire detection and suppression systems that are supported by an independent energy source.

PE-13(1)

Pass
Employ fire detection systems that activate automatically and notify Service provider building maintenance/physical security personnel and Service provider emergency responders with incident response responsibilities in the event of a fire.

PE-13(2) Part a

Pass
Employ fire suppression systems that activate automatically and notify Azure ISSO and Emergency Responders.

PE-13(2) Part b

Pass
Employ an automatic fire suppression capability when the facility is not staffed on a continuous basis.

PE-14 Part a

Pass
Maintain [ temperature | humidity | pressure | radiation | [environmental control] ] levels within the facility where the system resides at [ acceptable levels ].

PE-14 Part b

Pass
Monitor environmental control levels [ frequency ].

PE-15

Pass
Protect the system from damage resulting from water leakage by providing master shutoff or isolation valves that are accessible, working properly, and known to key personnel.

PE-16 Part a

Pass
Authorize and control All information system components entering and exiting the facility.

PE-16 Part b

Pass
Maintain records of the system components.

PE-17 Part a

Pass
Determine and document the Remote/work-from-home allowed for use by employees.

PE-17 Part b

Pass
Employ the following controls at alternate work sites: Use of company laptop to connect to the Dayforce PubSec HCM.

PE-17 Part c

Pass
Assess the effectiveness of controls at alternate work sites.

PE-17 Part d

Pass
Provide a means for employees to communicate with information security and privacy personnel in case of incidents.

PE-1 Part a1

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment system-level physical and environmental protection policy that: (a) addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

PE-1 Part a2

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment procedures to facilitate the implementation of the physical and environmental protection policy and the associated physical and environmental protection controls.

PE-1 Part b

Pass
Designate an Chief Information Security Officer (CISO) to manage the development, documentation, and dissemination of the physical and environmental protection policy and procedures.

PE-1 Part c1

Pass
Review and update the current physical and environmental protection policy At least every three (3) years and following Significant changes.

PE-1 Part c2

Pass
Review and update the current physical and environmental protection procedures At least annually and following Significant changes.

PE-2 Part a

Pass
Develop, approve, and maintain a list of individuals with authorized access to the facility where the system resides.

PE-2 Part b

Pass
Issue authorization credentials for facility access.

PE-2 Part c

Pass
Review the access list detailing authorized facility access by individuals At least annually.

PE-2 Part d

Pass
Remove individuals from the facility access list when access is no longer required.

PE-3 Part a

Pass
Enforce physical access authorizations at [ entry and exit points ] by: 1. verifying individual access authorizations before granting access to the facility; and 2. controlling ingress and egress to the facility using [ [systems or devices] | guards ].

PE-3 Part b

Pass
Maintain physical access audit logs for [ entry or exit points ].

PE-3 Part c

Pass
Control access to areas within the facility designated as publicly accessible by implementing the following controls: [ physical access controls ].

PE-3 Part d

Pass
Escort visitors and control visitor activity [ circumstances ].

PE-3 Part e

Pass
Secure keys, combinations, and other physical access devices.

PE-3 Part f

Pass
Inventory [ physical access devices ] every [ frequency ].

PE-3 Part g

Pass
Change combinations and keys [ organization-defined frequency ] and/or when keys are lost, combinations are compromised, or when individuals possessing the keys or combinations are transferred or terminated.

PE-4

Pass
Control physical access to Data center system distribution and transmission lines within organizational facilities using Physical access restrictions.

PE-5

Pass
Control physical access to output from Information system output devices to prevent unauthorized individuals from obtaining the output.

PE-6(1)

Pass
Monitor physical access to the facility where the system resides using physical intrusion alarms and surveillance equipment.

PE-6 Part a

Pass
Monitor physical access to the facility where the system resides to detect and respond to physical security incidents.

PE-6 Part b

Pass
Review physical access logs At least monthly and upon occurrence of Events or potential indications of events.

PE-6 Part c

Pass
Coordinate results of reviews and investigations with the organizational incident response capability.

PE-8 Part a

Pass
Maintain visitor access records to the facility where the system resides for For a minimum of one (1) year.

PE-8 Part b

Pass
Review visitor access records At least monthly.

PE-8 Part c

Pass
Report anomalies in visitor access records to Azure ISSO.

PE-9

Pass
Protect power equipment and power cabling for the system from damage and destruction.

PL-10

Pass
Select a control baseline for the system.

PL-11

Pass
Tailor the selected control baseline by applying specified tailoring actions.

PL-1 Part a1

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment system-level planning policy that: (a) addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

PL-1 Part a2

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment procedures to facilitate the implementation of the planning policy and the associated planning controls.

PL-1 Part b

Pass
Designate an Chief Information Security Officer (CISO) to manage the development, documentation, and dissemination of the planning policy and procedures.

PL-1 Part c1

Pass
Review and update the current planning policy At least every three (3) years and following Significant changes.

PL-1 Part c2

Pass
Review and update the current planning procedures At least annually and following Significant changes.

PL-2 Part a

Pass
Develop security and privacy plans for the system that: 1. are consistent with the organization’s enterprise architecture; 2. explicitly define the constituent system components; 3. describe the operational context of the system in terms of mission and business processes; 4. identify the individuals that fulfill system roles and responsibilities; 5. identify the information types processed, stored, and transmitted by the system; 6. provide the security categorization of the system, including supporting rationale; 7. describe any specific threats to the system that are of concern to the organization; 8. provide the results of a privacy risk assessment for systems processing personally identifiable information; 9. describe the operational environment for the system and any dependencies on or connections to other systems or system components; 10. provide an overview of the security and privacy requirements for the system; 11. identify any relevant control baselines or overlays, if applicable; 12. describe the controls in place or planned for meeting the security and privacy requirements, including a rationale for any tailoring decisions; 13. include risk determinations for security and privacy architecture and design decisions; 14. include security- and privacy-related activities affecting the system that require planning and coordination with Chief Information Security Officer (CISO) ; and 15. are reviewed and approved by the authorizing official or designated representative prior to plan implementation.

PL-2 Part b

Pass
Distribute copies of the plans and communicate subsequent changes to the plans to Chief Information Security Officer (CISO).

PL-2 Part c

Pass
Review the plans At least annually.

PL-2 Part d

Pass
Update the plans to address changes to the system and environment of operation or problems identified during plan implementation or control assessments.

PL-2 Part e

Pass
Protect the plans from unauthorized disclosure and modification.

PL-4(1) Part a

Pass
Include in the rules of behavior, restrictions on use of social media, social networking sites, and external sites/applications.

PL-4(1) Part b

Pass
Include in the rules of behavior, restrictions on posting organizational information on public websites.

PL-4(1) Part c

Pass
Include in the rules of behavior, restrictions on use of organization-provided identifiers (e.g., email addresses) and authentication secrets (e.g., passwords) for creating accounts on external sites/applications.

PL-4 Part a

Pass
Establish and provide to individuals requiring access to the system, the rules that describe their responsibilities and expected behavior for information and system usage, security, and privacy.

PL-4 Part b

Pass
Receive a documented acknowledgment from such individuals, indicating that they have read, understand, and agree to abide by the rules of behavior, before authorizing access to information and the system.

PL-4 Part c

Pass
Review and update the rules of behavior [ frequency ].

PL-4 Part d

Pass
Require individuals who have acknowledged a previous version of the rules of behavior to read and re-acknowledge [ [frequency] | when the rules are revised or updated ].

PL-8 Part a

Pass
Develop security and privacy architectures for the system that: 1. describe the requirements and approach to be taken for protecting the confidentiality, integrity, and availability of organizational information; 2. describe the requirements and approach to be taken for processing personally identifiable information to minimize privacy risk to individuals; 3. describe how the architectures are integrated into and support the enterprise architecture; and 4. describe any assumptions about, and dependencies on, external systems and services.

PL-8 Part b

Pass
Review and update the architectures At least annually and when a significant change occurs to reflect changes in the enterprise architecture.

PL-8 Part c

Pass
Reflect planned architecture changes in security and privacy plans, Concept of Operations (CONOPS), criticality analysis, organizational procedures, and procurements and acquisitions.

PS-1 Part a1

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment system-level personnel security policy that: (a) addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

PS-1 Part a2

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment procedures to facilitate the implementation of the personnel security policy and the associated personnel security controls.

PS-1 Part b

Pass
Designate an Chief Information Security Officer (CISO) to manage the development, documentation, and dissemination of the personnel security policy and procedures.

PS-1 Part c1

Pass
Review and update the current personnel security policy At least every three (3) years and following Significant changes.

PS-1 Part c2

Pass
Review and update the current personnel security procedures At least annually and following Significant changes.

PS-2 Part a

Pass
Assign a risk designation to all organizational positions.

PS-2 Part b

Pass
Establish screening criteria for individuals filling those positions.

PS-2 Part c

Pass
Review and update position risk designations At least every ninety (90) days.

PS-3(3) Part a

Pass
Verify that individuals accessing a system processing, storing, or transmitting information requiring special protection have valid access authorizations that are demonstrated by assigned official government duties.

PS-3(3) Part b

Pass
Verify that individuals accessing a system processing, storing, or transmitting information requiring special protection satisfy Personnel screening criteria as required by specific information that will be stored, transmitted, or processed through the system.

PS-3 Part a

Pass
Screen individuals prior to authorizing access to the system.

PS-3 Part b

Pass
Rescreen individuals in accordance with For national security clearances; A reinvestigation is required during the fifth (5th) year for top secret security clearance, the tenth (10th) year for secret security clearance, and fifteenth (15th) year for confidential security clearance. For moderate risk law enforcement and high impact public trust level, a reinvestigation is required during the fifth (5th) year. There is no reinvestigation for other moderate risk positions or any low-risk positions.

PS-4 Part a

Pass
Upon termination of individual employment disable system access within Four (4) hours.

PS-4 Part b

Pass
Upon termination of individual employment terminate or revoke any authenticators and credentials associated with the individual.

PS-4 Part c

Pass
Upon termination of individual employment conduct exit interviews that include a discussion of Return of equipment, Confidentiality Obligations.

PS-4 Part d

Pass
Upon termination of individual employment retrieve all security-related organizational system-related property.

PS-4 Part e

Pass
Upon termination of individual employment retain access to organizational information and systems formerly controlled by terminated individual.

PS-5 Part a

Pass
Review and confirm ongoing operational need for current logical and physical access authorizations to systems and facilities when individuals are reassigned or transferred to other positions within the organization.

PS-5 Part b

Pass
Initiate Transfer Actions – Role/Permission/Access Updates within Twenty-four (24) hours.

PS-5 Part c

Pass
Modify access authorization as needed to correspond with any changes in operational need due to reassignment or transfer.

PS-5 Part d

Pass
Notify PubSec Enterprise Security Team within Twenty-four (24) hours.

PS-6 Part a

Pass
Develop and document access agreements for organizational systems.

PS-6 Part b

Pass
Review and update the access agreements At least annually.

PS-6 Part c

Pass
Verify that individuals requiring access to organizational information and systems: 1. sign appropriate access agreements prior to being granted access; and 2. re-sign access agreements to maintain access to organizational systems when access agreements have been updated or At least annually and any time there is a change to the user’s level of access.

PS-7 Part a

Pass
Establish personnel security requirements, including security roles and responsibilities for external providers.

PS-7 Part b

Pass
Require external providers to comply with personnel security policies and procedures established by the organization.

PS-7 Part c

Pass
Document personnel security requirements.

PS-7 Part d

Pass
Require external providers to notify PubSec Enterprise Security team of any personnel transfers or terminations of external personnel who possess organizational credentials and/or badges, or who have system privileges within Within twenty-four (24) hours.

PS-7 Part e

Pass
Monitor provider compliance with personnel security requirements.

PS-8 Part a

Pass
Employ a formal sanctions process for individuals failing to comply with established information security and privacy policies and procedures.

PS-8 Part b

Pass
Notify To include the ISSO and/or similar role within the organization within Twenty-four (24) hours when a formal employee sanctions process is initiated, identifying the individual sanctioned and the reason for the sanction.

PS-9

Pass
Incorporate security and privacy roles and responsibilities into organizational position descriptions.

RA-1 Part a1

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment system-level risk assessment policy that: (a) addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

RA-1 Part a2

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment procedures to facilitate the implementation of the risk assessment policy and the associated risk assessment controls.

RA-1 Part b

Pass
Designate an Chief Information Security Officer (CISO) to manage the development, documentation, and dissemination of the risk assessment policy and procedures.

RA-1 Part c1

Pass
Review and update the current risk assessment policy At least every three (3) years and following Significant changes.

RA-1 Part c2

Pass
Review and update the current risk assessment procedures At least annually and following Significant changes.

RA-2 Part a

Pass
Categorize the system and information it processes, stores, and transmits.

RA-2 Part b

Pass
Document the security categorization results, including supporting rationale, in the security plan for the system.

RA-2 Part c

Pass
Verify that the authorizing official or authorizing official designated representative reviews and approves the security categorization decision.

RA-3(1) Part a

Pass
Assess supply chain risks associated with All system components and services associated with the Dayforce PubSec HCM environment.

RA-3(1) Part b

Pass
Update the supply chain risk assessment Annually for high-risk vendors; at least every three (3) years for moderate-risk vendors , when there are significant changes to the relevant supply chain, or when changes to the system, environments of operation, or other conditions may necessitate a change in the supply chain.

RA-3 Part a

Pass
Conduct a risk assessment, including: 1. identifying threats to and vulnerabilities in the system; 2. determining the likelihood and magnitude of harm from unauthorized access, use, disclosure, disruption, modification, or destruction of the system, the information it processes, stores, or transmits, and any related information; and 3. determining the likelihood and impact of adverse effects on individuals arising from the processing of personally identifiable information.

RA-3 Part b

Pass
Integrate risk assessment results and risk management decisions from the organization and mission or business process perspectives with system-level risk assessments.

RA-3 Part c

Pass
Document risk assessment results in [ security and privacy plans | risk assessment report | [document] ].

RA-3 Part d

Pass
Review risk assessment results [ frequency ].

RA-3 Part e

Pass
Disseminate risk assessment results to [ personnel or roles ].

RA-3 Part f

Pass
Update the risk assessment [ frequency ] or when there are significant changes to the system, its environment of operation, or other conditions that may impact the security or privacy state of the system.

RA-5(11)

Pass
Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components.

RA-5(2)

Pass
Update the system vulnerabilities to be scanned [ [frequency] | prior to a new scan | when new vulnerabilities are identified and reported ].

RA-5(3)

Pass
Define the breadth and depth of vulnerability scanning coverage.

RA-5(5)

Pass
Implement privileged access authorization to All components that support authentication for All scans.

RA-5 Part a

Pass
Monitor and scan for vulnerabilities in the system and hosted applications Authenticated vulnerability scans are performed whenever technically feasible to provide comprehensive visibility into system vulnerabilities and configuration weaknesses. and when new vulnerabilities potentially affecting the system are identified and reported.

RA-5 Part b

Pass
Employ vulnerability monitoring tools and techniques that facilitate interoperability among tools and automate parts of the vulnerability management process by using standards for: 1. enumerating platforms, software flaws, and improper configurations; 2. formatting checklists and test procedures; and 3. measuring vulnerability impact.

RA-5 Part c

Pass
Analyze vulnerability scan reports and results from vulnerability monitoring.

RA-5 Part d

Pass
Remediate legitimate vulnerabilities High-risk vulnerabilities mitigated within thirty (30) days from date of discovery; moderate-risk vulnerabilities mitigated within ninety (90) days from date of discovery; low risk vulnerabilities mitigated within one hundred and eighty (180) days from date of discovery in accordance with an organizational assessment of risk.

RA-5 Part e

Pass
Share information obtained from the vulnerability monitoring process and control assessments with PubSec Product Security Team, AO to help eliminate similar vulnerabilities in other systems.

RA-5 Part f

Pass
Employ vulnerability monitoring tools that include the capability to readily update the vulnerabilities to be scanned.

RA-7

Pass
Respond to findings from security and privacy assessments, monitoring, and audits in accordance with organizational risk tolerance.

RA-9

Pass
Identify critical system components and functions by performing a criticality analysis for All Dayforce systems, system components, and system services at Architecture/design time, Development.

SA-10 Part a

Pass
Require the developer of the system, system component, or system service to perform configuration management during system, component, or service [ design | development | implementation | operation | disposal ].

SA-10 Part b

Pass
Require the developer of the system, system component, or system service to document, manage, and control the integrity of changes to Dayforce PubSec HCM applications.

SA-10 Part c

Pass
Require the developer of the system, system component, or system service to implement only organization-approved changes to the system, component, or service.

SA-10 Part d

Pass
Require the developer of the system, system component, or system service to document approved changes to the system, component, or service and the potential security and privacy impacts of such changes.

SA-10 Part e

Pass
Require the developer of the system, system component, or system service to track security flaws and flaw resolution within the system, component, or service and report findings to PubSec Product Security Team.

SA-11(1)

Pass
Require the developer of the system, system component, or system service to employ static code analysis tools to identify common flaws and document the results of the analysis.

SA-11(2) Part a

Pass
Require the developer of the system, system component, or system service to perform threat modeling and vulnerability analyses during development and the subsequent testing and evaluation of the system, component, or service that uses the following contextual information: Architecture reviews, system design activities, and significant system changes.

SA-11(2) Part b

Pass
Require the developer of the system, system component, or system service to perform threat modeling and vulnerability analyses during development and the subsequent testing and evaluation of the system, component, or service that employs the following tools and methods: AI Threat Modeling using STRIDE and PASTA methodologies.

SA-11(2) Part c

Pass
Require the developer of the system, system component, or system service to perform threat modeling and vulnerability analyses during development and the subsequent testing and evaluation of the system, component, or service that conducts the modeling and analyses at the following level of rigor: At both the application-level and component-level.

SA-11(2) Part d

Pass
Require the developer of the system, system component, or system service to perform threat modeling and vulnerability analyses during development and the subsequent testing and evaluation of the system, component, or service that produces evidence that meets the following acceptance criteria: Identifies the system, component, service, or release evaluated; Identifies the scope and exclusions; Documents the threat-modeling method used; Identifies threats, vulnerabilities, mitigations, and residual risks; Records responsible owners and disposition dates; Includes the applicable automated and manual test results; Identifies the reviewers and approval date..

SA-11 Part a

Pass
Require the developer of the system, system component, or system service, at all post-design stages of the system development life cycle, to develop and implement a plan for ongoing security and privacy control assessments.

SA-11 Part b

Pass
Require the developer of the system, system component, or system service, at all post-design stages of the system development life cycle, to perform [ unit | integration | system | regression ] testing/evaluation During deployment and prior to promotion into production environments at Development and integration test environments.

SA-11 Part c

Pass
Require the developer of the system, system component, or system service, at all post-design stages of the system development life cycle, to produce evidence of the execution of the assessment plan and the results of the testing and evaluation.

SA-11 Part d

Pass
Require the developer of the system, system component, or system service, at all post-design stages of the system development life cycle, to implement a verifiable flaw remediation process.

SA-11 Part e

Pass
Require the developer of the system, system component, or system service, at all post-design stages of the system development life cycle, to correct flaws identified during testing and evaluation.

SA-15(3) Part a

Pass
Require the developer of the system, system component, or system service to perform a criticality analysis at the following decision points in the system development life cycle: During initial system or software design, architecture review, onboarding into the CyberHub Asset Register, acquisition or introduction of significant components or dependencies, and following significant changes affecting system criticality or risk.

SA-15(3) Part b

Pass
Require the developer of the system, system component, or system service to perform a criticality analysis at the following level of rigor: Analysis sufficient to identify the business and security criticality of applicable software assets, components, dependencies, interfaces, and supporting services using inherent and residual risk scoring.

SA-15 Part a

Pass
Require the developer of the system, system component, or system service to follow a documented development process that: 1. explicitly addresses security and privacy requirements; 2. identifies the standards and tools used in the development process; 3. documents the specific tool options and tool configurations used in the development process; and 4. documents, manages, and ensures the integrity of changes to the process and/or tools used in development.

SA-15 Part b

Pass
Review the development process, standards, tools, tool options, and tool configurations At least annually to determine if the process, standards, tools, tool options and tool configurations selected and employed can satisfy the following security and privacy requirements: FedRAMP Security Authorization requirements.

SA-1 Part a1

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment system-level system and services acquisition policy that: (a) addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

SA-1 Part a2

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment procedures to facilitate the implementation of the system and services acquisition policy and the associated system and services acquisition controls.

SA-1 Part b

Pass
Designate an Chief Information Security Officer (CISO) to manage the development, documentation, and dissemination of the system and services acquisition policy and procedures.

SA-1 Part c1

Pass
Review and update the current system and services acquisition policy At least every three (3) years and following Significant changes.

SA-1 Part c2

Pass
Review and update the current system and services acquisition procedures At least annually and following Significant changes.

SA-22 Part a

Pass
Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer.

SA-22 Part b

Pass
Provide the following options for alternative sources for continued support for unsupported components [ in-house support | [support from external providers] ].

SA-2 Part a

Pass
Determine the high-level information security and privacy requirements for the system or system service in mission and business process planning.

SA-2 Part b

Pass
Determine, document, and allocate the resources required to protect the system or system service as part of the organizational capital planning and investment control process.

SA-2 Part c

Pass
Establish a discrete line item for information security and privacy in organizational programming and budgeting documentation.

SA-3 Part a

Pass
Acquire, develop, and manage the system using Dayforce Software Development Lifecycle (SDLC) that incorporates information security and privacy considerations.

SA-3 Part b

Pass
Define and document information security and privacy roles and responsibilities throughout the system development life cycle.

SA-3 Part c

Pass
Identify individuals having information security and privacy roles and responsibilities.

SA-3 Part d

Pass
Integrate the organizational information security and privacy risk management process into system development life cycle activities.

SA-4(1)

Pass
Require the developer of the system, system component, or system service to provide a description of the functional properties of the controls to be implemented.

SA-4(10)

Pass
Employ only information technology products on the FIPS 201-approved products list for Personal Identity Verification (PIV) capability implemented within organizational systems.

SA-4(2)

Pass
Require the developer of the system, system component, or system service to provide design and implementation information for the controls that includes: [ security-relevant external system interfaces | high-level design | low-level design | source code or hardware schematics | [design and implementation information] ] at [ level of detail ].

SA-4(9)

Pass
Require the developer of the system, system component, or system service to identify the functions, ports, protocols, and services intended for organizational use.

SA-4 Part a

Pass
Include the following requirements, descriptions, and criteria, explicitly or by reference, using [ standardized contract language | [contract language] ] in the acquisition contract for the system, system component, or system service security and privacy functional requirements.

SA-4 Part b

Pass
Include the following requirements, descriptions, and criteria, explicitly or by reference, using [ standardized contract language | [contract language] ] in the acquisition contract for the system, system component, or system service strength of mechanism requirements.

SA-4 Part c

Pass
Include the following requirements, descriptions, and criteria, explicitly or by reference, using [ standardized contract language | [contract language] ] in the acquisition contract for the system, system component, or system service security and privacy assurance requirements.

SA-4 Part d

Pass
Include the following requirements, descriptions, and criteria, explicitly or by reference, using [ standardized contract language | [contract language] ] in the acquisition contract for the system, system component, or system service controls needed to satisfy the security and privacy requirements.

SA-4 Part e

Pass
Include the following requirements, descriptions, and criteria, explicitly or by reference, using [ standardized contract language | [contract language] ] in the acquisition contract for the system, system component, or system service security and privacy documentation requirements.

SA-4 Part f

Pass
Include the following requirements, descriptions, and criteria, explicitly or by reference, using [ standardized contract language | [contract language] ] in the acquisition contract for the system, system component, or system service requirements for protecting security and privacy documentation.

SA-4 Part g

Pass
Include the following requirements, descriptions, and criteria, explicitly or by reference, using [ standardized contract language | [contract language] ] in the acquisition contract for the system, system component, or system service description of the system development environment and environment in which the system is intended to operate.

SA-4 Part h

Pass
Include the following requirements, descriptions, and criteria, explicitly or by reference, using [ standardized contract language | [contract language] ] in the acquisition contract for the system, system component, or system service allocation of responsibility or identification of parties responsible for information security, privacy, and supply chain risk management.

SA-4 Part i

Pass
Include the following requirements, descriptions, and criteria, explicitly or by reference, using [ standardized contract language | [contract language] ] in the acquisition contract for the system, system component, or system service acceptance criteria.

SA-5 Part a

Pass
Obtain or develop administrator documentation for the system, system component, or system service that describes: 1. secure configuration, installation, and operation of the system, component, or service; 2. effective use and maintenance of security and privacy functions and mechanisms; and 3. known vulnerabilities regarding configuration and use of administrative or privileged functions.

SA-5 Part b

Pass
Obtain or develop user documentation for the system, system component, or system service that describes: 1. user-accessible security and privacy functions and mechanisms and how to effectively use those functions and mechanisms; 2. methods for user interaction, which enables individuals to use the system, component, or service in a more secure manner and protect individual privacy; and 3. user responsibilities in maintaining the security of the system, component, or service and privacy of individuals.

SA-5 Part c

Pass
Document attempts to obtain system, system component, or system service documentation when such documentation is either unavailable or nonexistent and take Actions to create documentation with knowledge available from existing SME's in response.

SA-5 Part d

Pass
Distribute documentation to ISSO, documented control owners, and personnel requesting the acquisition.

SA-8

Pass
Apply the following systems security and privacy engineering principles in the specification, design, development, implementation, and modification of the system and system components: NIST SP 800-53.

SA-9(1) Part a

Pass
Conduct an organizational assessment of risk prior to the acquisition or outsourcing of information security services.

SA-9(1) Part b

Pass
Verify that the acquisition or outsourcing of dedicated information security services is approved by PubSec Cybersecurity Operations personnel and PubSec Legal personnel.

SA-9(2)

Pass
Require providers of the following external system services to identify the functions, ports, protocols, and other services required for the use of such services: All external systems where federal customer data is processed or stored.

SA-9(5)

Pass
Restrict the location of [ information processing | information or data | system services ] to Contiguous United States based on FedRAMP and agency requirements.

SA-9 Part a

Pass
Require that providers of external system services comply with organizational security and privacy requirements and employ the following controls: FedRAMP Moderate Security Controls Baseline if federal information is processed or stored within the external system.

SA-9 Part b

Pass
Define and document organizational oversight and user roles and responsibilities with regard to external system services.

SA-9 Part c

Pass
Employ the following processes, methods, and techniques to monitor control compliance by external service providers on an ongoing basis: FedRAMP Continuous Monitoring requirements for external systems where federal information is processed or stored.

SC-10

Pass
Terminate the network connection associated with a communications session at the end of the session or after No longer than ten (10) minutes for privileged sessions and no longer than fifteen (15) minutes for user sessions of inactivity.

SC-12

Pass
Establish and manage cryptographic keys when cryptography is employed within the system in accordance with the following key management requirements: In accordance with Federal requirements.

SC-13 Part a

Pass
Determine the Cryptographic uses within PubSec HCM.

SC-13 Part b

Pass
Implement the following types of cryptography required for each specified cryptographic use: FIPS-validated.

SC-15 Part a

Pass
Prohibit remote activation of collaborative computing devices and applications with the following exceptions: No exceptions for computing devices.

SC-15 Part b

Pass
Provide an explicit indication of use to users physically present at the devices.

SC-17 Part a

Pass
Issue public key certificates under an DigiCert, a Dayforce-approved certificate authority and certificate service provider or obtain public key certificates from an approved service provider.

SC-17 Part b

Pass
Include only approved trust anchors in trust stores or certificate stores managed by the organization.

SC-18 Part a

Pending
Define acceptable and unacceptable mobile code and mobile code technologies.

SC-18 Part b

Pending
Authorize, monitor, and control the use of mobile code within the system.

SC-1 Part a1

Pass
Develop, document, and disseminate to [ organization-defined personnel or roles ] [ organization-level | mission/business-process-level | system-level ] system and communications protection policy that: (a) addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

SC-1 Part a2

Pass
Develop, document, and disseminate to [ organization-defined personnel or roles ] procedures to facilitate the implementation of the system and communications protection policy and the associated system and communications protection controls.

SC-1 Part b

Pass
Designate an [ official ] to manage the development, documentation, and dissemination of the system and communications protection policy and procedures.

SC-1 Part c1

Pass
Review and update the current system and communications protection policy [ frequency ] and following [ events ].

SC-1 Part c2

Pass
Review and update the current system and communications protection procedures [ frequency ] and following [ events ].

SC-2

Pass
Separate user functionality, including user interface services, from system management functionality.

SC-20 Part a

Pass
Provide additional data origin authentication and integrity verification artifacts along with the authoritative name resolution data the system returns in response to external name/address resolution queries.

SC-20 Part b

Pass
Provide the means to indicate the security status of child zones and (if the child supports secure resolution services) to enable verification of a chain of trust among parent and child domains, when operating as part of a distributed, hierarchical namespace.

SC-21

Pass
Request and perform data origin authentication and data integrity verification on the name/address resolution responses the system receives from authoritative sources.

SC-22

Pass
Ensure the systems that collectively provide name/address resolution service for an organization are fault-tolerant and implement internal and external role separation.

SC-23

Pass
Protect the authenticity of communications sessions.

SC-28

Pass
Protect the [ confidentiality | integrity ] of the following information at rest: All information at rest.

SC-28(1)

Pass
Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of the following information at rest on All information system components storing federal customer data or system data that must be protected at the High or Moderate impact levels: All information.

SC-39

Pass
Maintain a separate execution domain for each executing system process.

SC-4

Pass
Prevent unauthorized and unintended information transfer via shared system resources.

SC-45

Pass
Synchronize system clocks within and between systems and system components.

SC-45(1) Part a

Pass
Compare the internal system clocks At least hourly with http://tf.nist.gov/tf-cgi/servers.cgi.

SC-45(1) Part b

Pass
Synchronize the internal system clocks to the authoritative time source when the time difference is greater than Any difference.

SC-5 Part a

Pass
[ protect against | limit ] the effects of the following types of denial-of-service events: At a minimum: ICMP (ping) flood, SYN flood, slowloris, buffer overflow attack, and volume attack.

SC-5 Part b

Pass
Employ the following controls to achieve the denial-of-service objective: ICMP (ping) flood — Azure DDoS Protection, Azure Firewall, network access control lists, security groups, ICMP filtering, rate limiting, and blocking of unnecessary ICMP message types; SYN flood — Azure DDoS Protection, Azure Firewall, load balancing, Cloudflare Advanced Network Firewall, TCP connection-rate limiting, backlog settings, and connection thresholds; Slowloris attack — Cloudflare WAF, load balancing, reverse proxy or API Gateway protections, request-header and idle-connection timeouts, concurrent-connection thresholds, and rate limiting; Buffer-overflow attack — Secure coding standards, bounds and input validation, Microsoft Defender, Cloudflare WAF, flaw remediation, security patching, and process isolation; Volume attack — Azure DDoS Protection, Cloudflare WAF, Azure Firewall, load balancing, traffic filtering, rate limiting, autoscaling, and deployment across multiple availability zones or regions; Application-layer request flooding — Azure DNS redundant DNS infrastructure, DNS query-rate limiting, health checks, and DNS failover capability; DNS denial-of-service — Azure DNS redundant DNS infrastrucute, DNS query-rate limiting, health checks, and DNS failover capability; Resource-exhaustion attack — Application quotas, per-user and per-tenant resource limits, connection-pool limits, request-size limits, execution timeouts, circuit breakers, workload isolation, container resource limits, autoscaling capability, and automated recovery; Malformed traffic or protocol abuse — Azure firewall, Cloudflare WAF, Cloudflare Advanced Network Firewall, Azure Firewall Premium IDPS, protocol validation, malformed-packet filtering, request-size restrictions, input validation, and connection termination; Distributed denial-of-service attack — Azure DDoS protection, Cloudflare WAF, Azure firewall, geographic or reputation-based filtering, CrowdStrike, CyberINT, ThreatConnect, upstream traffic scrubbing, rate limiting, load balancing, and automated scaling.

SC-7(12)

Pass
Implement CrowdStrike Falcon at All PubSec HCM system components.

SC-7(18)

Pass
Prevent systems from entering unsecure states in the event of an operational failure of a boundary protection device.

SC-7(3)

Pass
Limit the number of external network connections to the system.

SC-7(4) Part a

Pass
Implement a managed interface for each external telecommunication service.

SC-7(4) Part b

Pass
Establish a traffic flow policy for each managed interface.

SC-7(4) Part c

Pass
Protect the confidentiality and integrity of the information being transmitted across each interface.

SC-7(4) Part d

Pass
Document each exception to the traffic flow policy with a supporting mission or business need and duration of that need.

SC-7(4) Part e

Pass
Review exceptions to the traffic flow policy At least every one hundred and eighty (180) days or whenever there is a change in the threat environment that warrants a review of the exceptions and remove exceptions that are no longer supported by an explicit mission or business need.

SC-7(4) Part f

Pass
Prevent unauthorized exchange of control plane traffic with external networks.

SC-7(4) Part g

Pass
Publish information to enable remote networks to detect unauthorized control plane traffic from internal networks.

SC-7(4) Part h

Pass
Filter unauthorized control plane traffic from external networks.

SC-7(5)

Pass
Deny network communications traffic by default and allow network communications traffic by exception [ at managed interfaces | for [systems] ].

SC-7(7)

Pass
Prevent split tunneling for remote devices connecting to organizational systems unless the split tunnel is securely provisioned using Zscaler Web Proxy.

SC-7(8)

Pass
Route All internal communications traffic to Any network outside of organizational control and any network outside the authorization boundary through authenticated proxy servers at managed interfaces.

SC-7 Part a

Pass
Monitor and control communications at the external managed interfaces to the system and at key internal managed interfaces within the system.

SC-7 Part b

Pass
Implement subnetworks for publicly accessible system components that are [ physically | logically ] separated from internal organizational networks.

SC-7 Part c

Pass
Connect to external networks or systems only through managed interfaces consisting of boundary protection devices arranged in accordance with an organizational security and privacy architecture.

SC-8

Pass
Protect the [ confidentiality | integrity ] of transmitted information.

SC-8(1)

Pass
Implement cryptographic mechanisms to [ prevent unauthorized disclosure of information | detect changes to information ] during transmission.

SI-10

Pass
Check the validity of the following information inputs: All user-supplied input fields, application requests, API requests, uploaded content, authentication requests, administrative requests, and system-generated input processed by Dayforce PubSec HCM.

SI-11 Part a

Pass
Generate error messages that provide information necessary for corrective actions without revealing information that could be exploited.

SI-11 Part b

Pass
Reveal error messages only to ISSO, PubSec Cybersecurity Operations personnel, System Administrators, and authorized support personnel.

SI-12

Pass
Manage and retain information within the system and information output from the system in accordance with applicable laws, executive orders, directives, regulations, policies, standards, guidelines and operational requirements.

SI-16

Pass
Implement the following controls to protect the system memory from unauthorized code execution: Operating system memory protections, Azure platform security features, CIS benchmark configurations, Microsoft security baselines, Group Policy Objects (GPOs), Intune policies, secure boot capabilities, virtualization-based security controls, and host operating system protections.

SI-1 Part a1

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment system-level system and information integrity policy that: (a) addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

SI-1 Part a2

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment procedures to facilitate the implementation of the system and information integrity policy and the associated system and information integrity controls.

SI-1 Part b

Pass
Designate an Chief Information Security Officer (CISO) to manage the development, documentation, and dissemination of the system and information integrity policy and procedures.

SI-1 Part c1

Pass
Review and update the current system and information integrity policy At least every three (3) years and following Signifiant changes.

SI-1 Part c2

Pass
Review and update the current system and information integrity procedures At least annually and following Signifiant changes.

SI-2(2)

Pass
Determine if system components have applicable security-relevant software and firmware updates installed using Wiz and BurpSuite At least monthly.

SI-2(3) Part a

Pass
Measure the time between flaw identification and flaw remediation.

SI-2(3) Part b

Pass
Establish the following benchmarks for taking corrective actions: High: Thirty (30) days, Moderate: Ninety (90) days,and Low: One hundred and eighty (180) days.

SI-2 Part a

Pass
Identify, report, and correct system flaws.

SI-2 Part b

Pass
Test software and firmware updates related to flaw remediation for effectiveness and potential side effects before installation.

SI-2 Part c

Pass
Install security-relevant software and firmware updates within Within thirty (30) days of release of updates of the release of the updates.

SI-2 Part d

Pass
Incorporate flaw remediation into the organizational configuration management process.

SI-3 Part a

Pass
Implement [ signature-based | non-signature-based ] malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code.

SI-3 Part b

Pass
Automatically update malicious code protection mechanisms as new releases are available in accordance with organizational configuration management policy and procedures.

SI-3 Part c

Pass
Configure malicious code protection mechanisms to: 1. perform periodic scans of the system [ frequency ] and real-time scans of files from external sources at [ endpoint | network entry and exit points ] as the files are downloaded, opened, or executed in accordance with organizational policy; and 2. [ block malicious code | quarantine malicious code | take [action] ] ; and send alert to [ personnel or roles ] in response to malicious code detection.

SI-3 Part d

Pass
Address the receipt of false positives during malicious code detection and eradication and the resulting potential impact on the availability of the system.

SI-4(1)

Pass
Connect and configure individual intrusion detection tools into a system-wide intrusion detection system.

SI-4(16)

Pass
Correlate information from monitoring tools and mechanisms employed throughout the system.

SI-4(18)

Pass
Analyze outbound communications traffic at external interfaces to the system and at the following interior points to detect covert exfiltration of information: External interfaces, Azure workloads, Kubernetes workloads, and monitored system components within the authorization boundary.

SI-4(2)

Pass
Employ automated tools and mechanisms to support near real-time analysis of events.

SI-4(23)

Pass
Implement the following host-based monitoring mechanisms at Virtual machines and supported workloads within the authorization boundary: CrowdStrike Falcon endpoint detection and response monitoring.

SI-4(4) Part a

Pass
Determine criteria for unusual or unauthorized activities or conditions for inbound and outbound communications traffic.

SI-4(4) Part b

Pass
Monitor inbound and outbound communications traffic Continuously for Unauthorized communications, malicious communications, indicators of compromise, anomalous network activity, data exfiltration attempts, unauthorized protocol usage, unauthorized external connections, and suspicious inbound or outbound traffic patterns..

SI-4(5)

Pass
Alert PubSec Cybersecurity Operations Personnel, PubSec Product Security Personnel, Incident Responders, System Administrators when the following system-generated indications of compromise or potential compromise occur: Malware detections, indicators of compromise, unauthorized access attempts, suspicious network activity, integrity monitoring alerts, vulnerability exploitation attempts, anomalous behavior, and security monitoring alerts.

SI-4 Part a

Pass
Monitor the system to detect: 1. attacks and indicators of potential attacks in accordance with the following monitoring objectives: [ monitoring objectives ] ; and 2. unauthorized local, network, and remote connections.

SI-4 Part b

Pass
Identify unauthorized use of the system through the following techniques and methods: [ techniques and methods ].

SI-4 Part c

Pass
Invoke internal monitoring capabilities or deploy monitoring devices: 1. strategically within the system to collect organization-determined essential information; and 2. at ad hoc locations within the system to track specific types of transactions of interest to the organization.

SI-4 Part d

Pass
Analyze detected events and anomalies.

SI-4 Part e

Pass
Adjust the level of system monitoring activity when there is a change in risk to organizational operations and assets, individuals, other organizations, or the Nation.

SI-4 Part f

Pass
Obtain legal opinion regarding system monitoring activities.

SI-4 Part g

Pass
Provide [ system monitoring information ] to [ personnel or roles ] [ as needed | [frequency] ].

SI-5 Part a

Pass
Receive system security alerts, advisories, and directives from [ external organizations ] on an ongoing basis.

SI-5 Part b

Pass
Generate internal security alerts, advisories, and directives as deemed necessary.

SI-5 Part c

Pass
Disseminate security alerts, advisories, and directives to: [ [personnel or roles] | [elements] | [external organizations] ].

SI-5 Part d

Pass
Implement security directives in accordance with established time frames, or notify the issuing organization of the degree of noncompliance.

SI-6 Part a

Pass
Verify the correct operation of [ organization-defined security and privacy functions ].

SI-6 Part b

Pass
Perform the verification of the functions specified in SI-6a [ [system transitional states] | upon command by user with appropriate privilege | [frequency] ].

SI-6 Part c

Pass
Alert [ personnel or roles ] to failed security and privacy verification tests.

SI-6 Part d

Pass
[ shut the system down | restart the system | [alternative action(s)] ] when anomalies are discovered.

SI-7(1)

Pass
Perform an integrity check of [ organization-defined software, firmware, and information ] [ at startup | at [organization-defined transitional states or security-relevant events] | [organization-defined frequency] ].

SI-7(7)

Pass
Incorporate the detection of the following unauthorized changes into the organizational incident response capability: Unauthorized changes to operating system files, security configurations, application files, audit configurations, configuration baselines, privileged access settings, and security monitoring configurations.

SI-7 Part a

Pass
Employ integrity verification tools to detect unauthorized changes to the following software, firmware, and information: Operating system files, security configurations, application files, configuration baselines, audit configurations, critical system files, and security-relevant information within the authorization boundary.

SI-7 Part b

Pass
Take the following actions when unauthorized changes to the software, firmware, and information are detected: Generate alerts, initiate investigations, create incident records, perform root cause analysis, restore approved configurations, implement corrective actions, and escalate incidents in accordance with incident response procedures.

SI-8(2)

Pass
Automatically update spam protection mechanisms Automatically as vendor updates become available.

SI-8 Part a

Pass
Employ spam protection mechanisms at system entry and exit points to detect and act on unsolicited messages.

SI-8 Part b

Pass
Update spam protection mechanisms when new releases are available in accordance with organizational configuration management policy and procedures.

SR-10

Pass
Inspect the following systems or system components [ at random | at [frequency] | upon [indications of need for inspection] ] to detect tampering: [ systems or system components ].

SR-11(1)

Pass
Train PubSec Cybersecurity Operations Team to detect counterfeit system components (including hardware, software, and firmware).

SR-11(2)

Pass
Maintain configuration control over the following system components awaiting service or repair and serviced or repaired components awaiting return to service: All system components.

SR-11 Part a

Pass
Develop and implement anti-counterfeit policy and procedures that include the means to detect and prevent counterfeit components from entering the system.

SR-11 Part b

Pass
Report counterfeit system components to [ source of counterfeit component | [external reporting organizations] | [personnel or roles] ].

SR-12

Pass
Dispose of All Dayforce PubSec HCM data, documentation tools, or system components using the following techniques and methods: Disposal methods built into each of the associated services (i.e., terminate instance, delete database, etc.).

SR-1 Part a1

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment system-level supply chain risk management policy that: (a) addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

SR-1 Part a2

Pass
Develop, document, and disseminate to All Dayforce PubSec HCM personnel with access to the FedRAMP environment procedures to facilitate the implementation of the supply chain risk management policy and the associated supply chain risk management controls.

SR-1 Part b

Pass
Designate an Chief Information Security Officer (CISO) to manage the development, documentation, and dissemination of the supply chain risk management policy and procedures.

SR-1 Part c1

Pass
Review and update the current supply chain risk management policy At least every three (3) years and following Significant changes.

SR-1 Part c2

Pass
Review and update the current supply chain risk management procedures At least annually and following Significant changes.

SR-2(1)

Pass
Establish a supply chain risk management team consisting of PubSec Enterprise Security Team and PubSec Legal Team to lead and support the following SCRM activities: Vendor assessment, security assessment, and annual reviews.

SR-2 Part a

Pass
Develop a plan for managing supply chain risks associated with the research and development, design, manufacturing, acquisition, delivery, integration, operations and maintenance, and disposal of the following systems, system components or system services: All Dayforce PubSec HCM systems, system components, and system services.

SR-2 Part b

Pass
Review and update the supply chain risk management plan At least annually or as required, to address threat, organizational or environmental changes.

SR-2 Part c

Pass
Protect the supply chain risk management plan from unauthorized disclosure and modification.

SR-3 Part a

Pass
Establish a process or processes to identify and address weaknesses or deficiencies in the supply chain elements and processes of [ system or system component ] in coordination with [ supply chain personnel ].

SR-3 Part b

Pass
Employ the following controls to protect against supply chain risks to the system, system component, or system service and to limit the harm or consequences from supply chain-related events: [ supply chain controls ].

SR-3 Part c

Pass
Document the selected and implemented supply chain processes and controls in [ security and privacy plans | supply chain risk management plan | [document] ].

SR-5

Pass
Employ the following acquisition strategies, contract tools, and procurement methods to protect against, identify, and mitigate supply chain risks: Security Review, CyberGrX, Process Unity, Risk Recon.

SR-6

Pass
Assess and review the supply chain-related risks associated with suppliers or contractors and the system, system component, or system service they provide At least annually.

SR-8

Pass
Establish agreements and procedures with entities involved in the supply chain for the system, system component, or system service for the [ notification of supply chain compromises | [results of assessments or audits] ].