
**************************************************************************
USACE / NAVFAC / AFCEC / NASA UFGS-25 08 11.00 20 (November 2020)
------------------------------------
Preparing Activity: NAVFAC
UNIFIED FACILITIES GUIDE SPECIFICATIONS
References are in agreement with UMRL dated October 2022
**************************************************************************
SECTION TABLE OF CONTENTS
DIVISION 25 - INTEGRATED AUTOMATION
SECTION 25 08 11.00 20
RISK MANAGEMENT FRAMEWORK FOR FACILITY-RELATED CONTROL SYSTEMS
11/20
PART 1 GENERAL
1.1 CONTROL SYSTEM APPLICABILITY
1.2 RELATED REQUIREMENTS
1.3 REFERENCES
1.4 DEFINITIONS
1.4.1 Assured Compliance Assessment Solution (ACAS) Scans
1.4.2 Authority To Operate (ATO)
1.4.3 Control Correlation Identifier (CCI) or Security Control
1.4.4 Enterprise Mission Assurance Support Service (eMASS)
1.4.5 Functional Authorizing Official (FAO) or Authorizing Official
(AO)
1.4.6 Information System Owner (ISO) or System Owner (SO)
1.4.7 Information System Security Manager (ISSM)
1.4.8 Information System Security Engineer (ISSE)
1.4.9 Risk Management Framework (RMF)
1.4.10 Security Assessment Plan (SAP)
1.4.11 Security Assessment Report (SAR)
1.4.12 Security Content Automation Protocol (SCAP)
1.4.13 Security Control Accessor - Validator (SCA-V)
1.4.14 Security Plan (SP)
1.4.15 Security Technical Implementation Guidance (STIG)
1.5 ADMINISTRATIVE REQUIREMENTS
1.5.1 Coordination
1.6 SUBMITTALS
1.7 QUALITY CONTROL
1.7.1 Certifications
1.8 CYBERSECURITY DOCUMENTATION
1.8.1 Authorization Strategy Plan
PART 2 PRODUCTS
2.1 SPARE PARTS
SECTION 25 08 11.00 20 Page 1