11 - ED CSF Risk Scorecard Overview_July 2020.pdf

PDF 3 MB Posted

Attached to
Request for Information: Award Eligibility Determination Federal contract opportunity
Solicitation number
Not on record
Issued by
Department of Education

About this file

This document provides an overview of the U.S. Department of Education's Cybersecurity Framework Risk Scorecard. The scorecard integrates the NIST Cybersecurity Framework to assess cybersecurity risk across the Department's systems. It utilizes the Framework's functions, categories, and additional risk factors to calculate risk scores. These scores are visualized through customizable dashboards in Power BI. The dashboards are accessible to authorized users and provide filtering and reporting capabilities. They include consolidated views of the Department's risk register, system-level scorecards, and dashboards for authorizing officials. The scorecard aims to inform cybersecurity planning, provide a methodology for managing risk, and help prioritize resources. Since launching in 2017, the Department has used the scorecard successfully to improve its overall security posture by quantifying and reducing risk.

The related federal contract opportunity is a Request for Information regarding the Department of Education's plans to modernize its Central Processing System for processing Federal Student Aid applications. The new Award Eligibility Determination system will replace the existing CPS. Interested parties are sought to provide information on capabilities for developing and implementing a total system solution. However, this RFI does not constitute a request for proposal and the government is not currently seeking proposals. All costs associated with responding are the responsibility of interested parties.

View the file

Other files for this federal contract opportunity

Other files attached to Request for Information: Award Eligibility Determination, newest first.
File Type Posted
10 - AED Draft SLAs.xlsx XLSX spreadsheet
12 - CPS 101 with FA impacts 09102020.pdf PDF
09 - FSA Current State.pdf PDF
AED RFI Final.pdf PDF
03 - Security Technical Requirements.xlsx XLSX spreadsheet
08 - FSA Identity Access Mgt Solution Overview.docx DOCX document
01 - Award Eligibility Determination Requirements_REVISED PER CE.pdf PDF
02 - Pricing Template.xlsx XLSX spreadsheet
07 - Hosting Environments w Approved ATOs.pdf PDF
06 - FSA NARA Universal Electronic Records Management Requirements v2.03.xlsx XLSX spreadsheet
05 - Hosting Environments with Approved Agency ATOs.pdf PDF
04 - Additional Current State Technical Constraints.xlsx XLSX spreadsheet
Show all 12

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ED Cybersecurity Framework Risk Scorecard Overview U.S. Department of Education

July 2020

Overview

Benefits Dashboard Overview

Risk Factors

System Weighting CSF Category Scoring

Consolidated Risk Register

System Level Scorecards Authorizing Official Dashboards

CSAM Data Discrepancies Reporting

Quantifiable Risk Reduction at ED

Agenda

NIST Cybersecurity Framework fully integrated Powered by Microsoft Power BI Accessible through your

Office365/Power BI Pro account Fully customizable Capabilities

Fast/Near real-time delivery Dynamic filtering Advanced POA&M reporting Customizable dashboards

Cybersecurity Framework (CSF) Risk Scorecard

Overview of Framework Core Functions

NIST Framework for Improving Critical Infrastructure Cybersecurity, v1.1, April 16, Aimed at reducing and better managing cybersecurity risks.

₋ Implementation of the practices in the Framework may vary across organizations.

₋ Organizations can determine activities that are important to critical service delivery and can prioritize investments to maximize the impact of each dollar spent.

Benefits of CSF Risk Scorecard

Informs overall cybersecurity strategic planning at the Department-level

Provides a methodology for strategic planners to view, understand, and manage cybersecurity risk

Allows quantifiable prioritization of risks as an input to the annual cybersecurity budget planning/formulation process

Helps to align cybersecurity activities with business requirements, risk tolerances, and resources

Dashboard Features

Incremental Scoring

Scores all systems

Fully filterable Principal Office High Value Assets FISMA Reportable System Status

Column sorting

Power BI CSF Risk Scorecard: Dashboard

Report filtering

Office of Sample Office 1 Office of Sample Office 2 Office of Sample Office 3 Office of Sample Office 4 Office of Sample Office 5 Office of Sample Office 6 Office of Sample Office 7 Office of Sample Office 8 Office of Sample Office 9 Office of Sample Office 10 Office of Sample Office 11 Office of Sample Office 12 Office of Sample Office 13

The overall purpose of the CSF Risk Scorecard is to allow the Department’s security professionals the ability to visual risk and prioritize risk management activities appropriately.

Each CSF Function, including the addition of Privacy within the scorecard utilizes various risk factors in calculating risk scores. These factors are independently calculated based upon scoring criteria consistent with the defined risk levels (0,1,2,3)

CSF Scorecard - Risk Factors

Privacy Score

Open POA&M Totals

Privacy Threshold Analysis

Date

Privacy Impact

Analysis Date

ATO

Document

Status

Incident Response Test Date

Overview of Framework Core Categories and Control Mapping

Framework Core is broken down into categories and subcategories

NIST controls are mapped to one or more Framework categories or subcategories

Scoring Constructs

CSF Risk Scorecard Risk Weights and Factors

To emphasize the specific significance various factors have on overall risk, additional weighted system-level risk factors are used within the calculated risk score.

For each risk factor, a response is given indicating a weight to be calculated against the risk factor value to determine the overall weight and the scale to which a framework completion percentage is represented.

Systems with higher weights represent a greater risk to ED should that system be compromised.

Each system is given a weight based on factors that cannot be mitigated but are attributes that determine the value of the system. The system weight is used to set the scoring thresholds that the system must obtain to limit risk based on the system's value.

System Weighting

Weight 0 1 2 3 50-65 0% 92% 96% 100% 35-49 0% 88% 94% 100% 20-34 0% 84% 92% 100% 0-19 0% 80% 90% 100%

# of POA&Ms (% passing)

Scores calculated for all Functions and Categories based upon compliance to the Framework’s subcategory ‘objectives’ and additional custom risk factors

CSF Function and Category Scoring

Consolidated Risk Register

Consolidated View within Department Scorecard Prioritized by impact to CSF objectives Lists all

POA&Ms/Risk Factors and Future Issues by system Filterable by PO and System

Most Valuable Progress

System-level CSF Risk Scorecards

System Level Report Features

Filterable by System Synced to all pages within the system scorecard section

Currently Tracking Department Level Configuration Management Plan Contingency Date Contingency Plan Test Date Incident Response Plan Privacy Threshold Analysis Privacy Impact Assessment

Only systems that contain PII System Security Plan Hardware List Software List

Future Version in Development Technical Description System Description MOU’s Date Completed (Where Required) Business Impact Analysis Date Completed

Required Authorization Documentation Dashboard

System 1 System 2 System 3 System 4 System 5 System 6 System 7 System 8 System 9 System 10 System 11 System 12 System 13 System 14 System 15 System 16

Office 1

Dashboard for Authorizing Officials Filterable by AO, PO, System, FISMA & Operational Status

Dashboard tab contains:

Total Systems Total PO’s Open POA&Ms Expired ATO

Documents CSF Risk Scores ATO Status POA&M Trending

Authorizing Official Dashboard: Dashboard

Info System 1 Info System 2 Info System 3 Info System 4 Info System 5 Info System 6 Info System 7

New Dashboard for Authorizing Officials Filterable by AO, PO, System, FISMA & Operational Status

Actionable Items Tab Contains:

Systems w/Open

POA&Ms Past Due POA&Ms Expired ATO

Documents Prioritized List of

Actions/Risks ATO Document

Statuses

Authorizing Official Dashboard: Actionable Items

PO 1 PO 2 PO 3 PO 4 PO 5 PO 6 PO 7 PO 8 PO 9 PO 10 PO 11 PO 12 PO 13 PO 14 PO 15

Info System 1 Info System 2 Info System 3 Info System 4 Info System 5 Info System 6 Info System 7 Info System 8 Info System 9 Info System 10 Info System 11 Info System 12 Info System 13 Info System 14 Info System 15 Info System 16

CSAM Data Discrepancies Reporting

Quantifiable Risk Reduction at ED

Principal Office 1 Principal Office 2 Principal Office 3 Principal Office 4 Principal Office 5 Principal Office 6 Principal Office 7 Principal Office 8 Principal Office 9 Principal Office 10 Principal Office 11 Principal Office 12

Since its launch in 2017, the Department has embraced the ED CSF Risk Scorecard consistently to help prioritize risk remediation activities improve the overall security posture of the organization.

QUESTIONS?

ED Cybersecurity Framework �Risk Scorecard�Overview
Agenda
Cybersecurity Framework (CSF) Risk Scorecard
NIST Cybersecurity Framework�Overview of Framework Core Functions
Benefits of CSF Risk Scorecard
Power BI CSF Risk Scorecard: Dashboard
CSF Scorecard - Risk Factors
NIST Cybersecurity Framework�Overview of Framework Core Categories and Control Mapping
Scoring Constructs
CSF Risk Scorecard�Risk Weights and Factors
Slide Number 11
CSF Function and Category Scoring
Consolidated Risk Register
System-level CSF Risk Scorecards
Required Authorization Documentation Dashboard�
Authorizing Official Dashboard: Dashboard�
Authorizing Official Dashboard: Actionable Items
Slide Number 18
Quantifiable Risk Reduction at ED
Slide Number 20

File details come from the government source that posted it. Updated .