11 - ED CSF Risk Scorecard Overview_July 2020.pdf
PDF 3 MB Posted
- Attached to
- Request for Information: Award Eligibility Determination Federal contract opportunity
- Solicitation number
- Not on record
- Issued by
- Department of Education
About this file
This document provides an overview of the U.S. Department of Education's Cybersecurity Framework Risk Scorecard. The scorecard integrates the NIST Cybersecurity Framework to assess cybersecurity risk across the Department's systems. It utilizes the Framework's functions, categories, and additional risk factors to calculate risk scores. These scores are visualized through customizable dashboards in Power BI. The dashboards are accessible to authorized users and provide filtering and reporting capabilities. They include consolidated views of the Department's risk register, system-level scorecards, and dashboards for authorizing officials. The scorecard aims to inform cybersecurity planning, provide a methodology for managing risk, and help prioritize resources. Since launching in 2017, the Department has used the scorecard successfully to improve its overall security posture by quantifying and reducing risk.
The related federal contract opportunity is a Request for Information regarding the Department of Education's plans to modernize its Central Processing System for processing Federal Student Aid applications. The new Award Eligibility Determination system will replace the existing CPS. Interested parties are sought to provide information on capabilities for developing and implementing a total system solution. However, this RFI does not constitute a request for proposal and the government is not currently seeking proposals. All costs associated with responding are the responsibility of interested parties.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 10 - AED Draft SLAs.xlsx | XLSX spreadsheet | |
| 12 - CPS 101 with FA impacts 09102020.pdf | ||
| 09 - FSA Current State.pdf | ||
| AED RFI Final.pdf | ||
| 03 - Security Technical Requirements.xlsx | XLSX spreadsheet | |
| 08 - FSA Identity Access Mgt Solution Overview.docx | DOCX document | |
| 01 - Award Eligibility Determination Requirements_REVISED PER CE.pdf | ||
| 02 - Pricing Template.xlsx | XLSX spreadsheet | |
| 07 - Hosting Environments w Approved ATOs.pdf | ||
| 06 - FSA NARA Universal Electronic Records Management Requirements v2.03.xlsx | XLSX spreadsheet | |
| 05 - Hosting Environments with Approved Agency ATOs.pdf | ||
| 04 - Additional Current State Technical Constraints.xlsx | XLSX spreadsheet |
Show all 12
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ED Cybersecurity Framework Risk Scorecard Overview U.S. Department of Education
July 2020
Overview
Benefits Dashboard Overview
Risk Factors
System Weighting CSF Category Scoring
Consolidated Risk Register
System Level Scorecards Authorizing Official Dashboards
CSAM Data Discrepancies Reporting
Quantifiable Risk Reduction at ED
Agenda
NIST Cybersecurity Framework fully integrated Powered by Microsoft Power BI Accessible through your
Office365/Power BI Pro account Fully customizable Capabilities
Fast/Near real-time delivery Dynamic filtering Advanced POA&M reporting Customizable dashboards
Cybersecurity Framework (CSF) Risk Scorecard
Overview of Framework Core Functions
NIST Framework for Improving Critical Infrastructure Cybersecurity, v1.1, April 16, Aimed at reducing and better managing cybersecurity risks.
₋ Implementation of the practices in the Framework may vary across organizations.
₋ Organizations can determine activities that are important to critical service delivery and can prioritize investments to maximize the impact of each dollar spent.
Benefits of CSF Risk Scorecard
Informs overall cybersecurity strategic planning at the Department-level
Provides a methodology for strategic planners to view, understand, and manage cybersecurity risk
Allows quantifiable prioritization of risks as an input to the annual cybersecurity budget planning/formulation process
Helps to align cybersecurity activities with business requirements, risk tolerances, and resources
Dashboard Features
Incremental Scoring
Scores all systems
Fully filterable Principal Office High Value Assets FISMA Reportable System Status
Column sorting
Power BI CSF Risk Scorecard: Dashboard
Report filtering
Office of Sample Office 1 Office of Sample Office 2 Office of Sample Office 3 Office of Sample Office 4 Office of Sample Office 5 Office of Sample Office 6 Office of Sample Office 7 Office of Sample Office 8 Office of Sample Office 9 Office of Sample Office 10 Office of Sample Office 11 Office of Sample Office 12 Office of Sample Office 13
The overall purpose of the CSF Risk Scorecard is to allow the Department’s security professionals the ability to visual risk and prioritize risk management activities appropriately.
Each CSF Function, including the addition of Privacy within the scorecard utilizes various risk factors in calculating risk scores. These factors are independently calculated based upon scoring criteria consistent with the defined risk levels (0,1,2,3)
CSF Scorecard - Risk Factors
Privacy Score
Open POA&M Totals
Privacy Threshold Analysis
Date
Privacy Impact
Analysis Date
ATO
Document
Status
Incident Response Test Date
Overview of Framework Core Categories and Control Mapping
Framework Core is broken down into categories and subcategories
NIST controls are mapped to one or more Framework categories or subcategories
Scoring Constructs
CSF Risk Scorecard Risk Weights and Factors
To emphasize the specific significance various factors have on overall risk, additional weighted system-level risk factors are used within the calculated risk score.
For each risk factor, a response is given indicating a weight to be calculated against the risk factor value to determine the overall weight and the scale to which a framework completion percentage is represented.
Systems with higher weights represent a greater risk to ED should that system be compromised.
Each system is given a weight based on factors that cannot be mitigated but are attributes that determine the value of the system. The system weight is used to set the scoring thresholds that the system must obtain to limit risk based on the system's value.
System Weighting
Weight 0 1 2 3 50-65 0% 92% 96% 100% 35-49 0% 88% 94% 100% 20-34 0% 84% 92% 100% 0-19 0% 80% 90% 100%
# of POA&Ms (% passing)
Scores calculated for all Functions and Categories based upon compliance to the Framework’s subcategory ‘objectives’ and additional custom risk factors
CSF Function and Category Scoring
Consolidated Risk Register
Consolidated View within Department Scorecard Prioritized by impact to CSF objectives Lists all
POA&Ms/Risk Factors and Future Issues by system Filterable by PO and System
Most Valuable Progress
System-level CSF Risk Scorecards
System Level Report Features
Filterable by System Synced to all pages within the system scorecard section
Currently Tracking Department Level Configuration Management Plan Contingency Date Contingency Plan Test Date Incident Response Plan Privacy Threshold Analysis Privacy Impact Assessment
Only systems that contain PII System Security Plan Hardware List Software List
Future Version in Development Technical Description System Description MOU’s Date Completed (Where Required) Business Impact Analysis Date Completed
Required Authorization Documentation Dashboard
System 1 System 2 System 3 System 4 System 5 System 6 System 7 System 8 System 9 System 10 System 11 System 12 System 13 System 14 System 15 System 16
Office 1
Dashboard for Authorizing Officials Filterable by AO, PO, System, FISMA & Operational Status
Dashboard tab contains:
Total Systems Total PO’s Open POA&Ms Expired ATO
Documents CSF Risk Scores ATO Status POA&M Trending
Authorizing Official Dashboard: Dashboard
Info System 1 Info System 2 Info System 3 Info System 4 Info System 5 Info System 6 Info System 7
New Dashboard for Authorizing Officials Filterable by AO, PO, System, FISMA & Operational Status
Actionable Items Tab Contains:
Systems w/Open
POA&Ms Past Due POA&Ms Expired ATO
Documents Prioritized List of
Actions/Risks ATO Document
Statuses
Authorizing Official Dashboard: Actionable Items
PO 1 PO 2 PO 3 PO 4 PO 5 PO 6 PO 7 PO 8 PO 9 PO 10 PO 11 PO 12 PO 13 PO 14 PO 15
Info System 1 Info System 2 Info System 3 Info System 4 Info System 5 Info System 6 Info System 7 Info System 8 Info System 9 Info System 10 Info System 11 Info System 12 Info System 13 Info System 14 Info System 15 Info System 16
CSAM Data Discrepancies Reporting
Quantifiable Risk Reduction at ED
Principal Office 1 Principal Office 2 Principal Office 3 Principal Office 4 Principal Office 5 Principal Office 6 Principal Office 7 Principal Office 8 Principal Office 9 Principal Office 10 Principal Office 11 Principal Office 12
Since its launch in 2017, the Department has embraced the ED CSF Risk Scorecard consistently to help prioritize risk remediation activities improve the overall security posture of the organization.
QUESTIONS?
| ED Cybersecurity Framework �Risk Scorecard�Overview |
| Agenda |
| Cybersecurity Framework (CSF) Risk Scorecard |
| NIST Cybersecurity Framework�Overview of Framework Core Functions |
| Benefits of CSF Risk Scorecard |
| Power BI CSF Risk Scorecard: Dashboard |
| CSF Scorecard - Risk Factors |
| NIST Cybersecurity Framework�Overview of Framework Core Categories and Control Mapping |
| Scoring Constructs |
| CSF Risk Scorecard�Risk Weights and Factors |
| Slide Number 11 |
| CSF Function and Category Scoring |
| Consolidated Risk Register |
| System-level CSF Risk Scorecards |
| Required Authorization Documentation Dashboard� |
| Authorizing Official Dashboard: Dashboard� |
| Authorizing Official Dashboard: Actionable Items |
| Slide Number 18 |
| Quantifiable Risk Reduction at ED |
| Slide Number 20 |
File details come from the government source that posted it. Updated .