PlumbTrackLive demoGRC Risk System

← internal audit

Audit — SC-24 — Fail in Known State

Framework: NIST SP 800-53 Rev.5 SC-24 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 6 checked
Examine Review the SSP/design documentation to confirm the defined 'known state' the system fails to for each defined failure condition and what state information is preserved on failure.
Interview Ask engineers which failure conditions trigger fail-to-known-state behavior (e.g., firewall fails closed, application enters safe mode) and how the availability vs. confidentiality/integrity tradeoff was decided.
Test Induce or observe a controlled failure (e.g., failover test, killing a dependency) and verify the system transitions to the documented known state without exposing data or losing integrity.
Examine Confirm boundary and security-enforcing devices are configured to fail closed (deny) rather than fail open when a component fails.
Examine Review failover, redundancy, and disaster-recovery test records demonstrating that state information is preserved and recovery is predictable after a failure.
Interview Ask operations personnel how failure events and fail-state transitions are detected, alerted, and logged so that the transition to a known state is verifiable.