Attachment__D_Information_Security_Program__1-17_IT_security.pdf
PDF 312 KB Posted
- Attached to
- Digital Asset Management System Federal contract opportunity
- Solicitation number
- 1145PC19Q0001
- Issued by
- Peace Corps
About this file
Attachment D
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Intellectual_Property_Inquiry.pdf | ||
| DAM_RFP_questions_document_2_of_2.pdf | ||
| DAM_RFP-QUESTIONS_1_of_2.pdf | ||
| Att_A-9-20-2018.xlsx | XLSX spreadsheet | |
| Attachment_C__Sample_Call_Order_SOW.docx | DOCX document | |
| Att_B-9-20-2018.xlsx | XLSX spreadsheet | |
| REQUEST_FOR_PROPOSAL_-_1145PC19Q0001.pdf | ||
| Attachment_E_MS_899_Breach_Notification_Response_Plan.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment 6 – Interim Policy Statement (IPS) 1-17 Information Security Program
Peace Corps | IPS 1-17 Information Security Program Page 1
IPS 1-17 Information Security Program
Effective Date: June 16, 2017
Responsible Office: Office of the Chief Information Officer (OCIO)
Supersedes: MS 542 1/7/13; 7/19/12; 1/26/06; 05/21/02; 06/16/88
Transmittal Memo MS 542
Issuance Memo (07/19/2012)
Issuance Memo (01/07/2013)
Issuance Memo (06/16/2017)
Rules of Behavior - General
Rules of Behavior - Privileged
1.0 Purpose
This Manual Section sets forth the Peace Corps Information Security Program (Program), which addresses information security for the Peace Corps information systems.
2.0 Authorities
The Freedom of Information Act (FOIA), 5 U.S.C. 552; Presidential Memorandum on the FOIA, January 21, 2009; Records Management Act, 44 U.S.C. 31; E-Government Act of 2002, 44
U.S.C. 101; Federal Information Security Modernization Act of 2014 (FISMA); National
Institute of Standards and Technology (NIST) Special Publications; Office of Management and
Budget (OMB) Circulars and Memoranda, and Federal Information Processing Standards (FIPS)
Publications, including FIPS Publication 200.
3.0 Applicability
This Manual Section applies to all users of a Peace Corps information system and to all components of the Peace Corps information systems. It does not apply to information systems of the Office of Inspector General.
4.0 Definitions
(a) General user is any person accessing a Peace Corps information system or application either from the Peace Corps domain (internal user) or from the Internet (external user).
The general user is the consumer of any Peace Corps products or services provided by a
Peace Corps information system and are only granted privileges required to access the product or service provided by the Peace Corps information system.
http://inside.peacecorps.gov/index.cfm?viewDocument&document_id=2526&filetype=htm http://inside.peacecorps.gov/index.cfm?viewDocument&document_id=46793&filetype=htm http://inside.peacecorps.gov/index.cfm?viewDocument&document_id=49683&filetype=htm http://inside.peacecorps.gov/index.cfm?viewDocument&document_id=46795&filetype=doc http://inside.peacecorps.gov/index.cfm?viewDocument&document_id=46796&filetype=doc
Peace Corps | IPS 1-17 Information Security Program Page 2
(b) Privileged user is any person accessing a Peace Corps information system with access privileges which exceed those imposed on a general user. Roles with elevated privileges are typically, but are not limited to, system administrators, application administrators, security administrators, system or application developer, or managers/supervisors. The elevated privileges will allow the privileged user to circumvent, in full or in part, the restriction imposed by general users’ access privileges.
(c) Sensitive Information is information that if obtained, exposed or distributed by unauthorized individuals can cause harm to the Peace Corps’ workforce, assets or reputation. Examples of sensitive data are, but are not limited to: Personally Identifiable
Information (PII); electronic Personal Health Information (ePHI); financial information;
and information labeled For Official Use Only (FOUO), Internal Use, or Sensitive But
Unclassified (SBU).
(d) Publicly Accessible Websites and Services are online resources and services available over HTTP or HTTPS over the public internet that are operated and maintained in whole or in part by the Peace Corps, contractor, or other organization on behalf of the Peace
Corps. They present government information or provide services to the public or a specific user group and support the performance of an agency's mission. This definition includes all web interactions, whether a visitor is logged-in or anonymous.
(e) Information System is a discrete set of information resources, hardware and/or software, owned and operated by or on the behalf of the Peace Corps, which are organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of Peace
Corps information.
(f) Information Security Program (Program) provides information and assurance and prevents harm to the Peace Corps information technology organization, workforce, assets, and reputation. It is designed to support the mission and business process needs while assuring that an acceptable security posture is maintained for the information systems of the Peace Corps.
(g) Common Control Provider is an individual, group, or organization responsible for the development, implementation, assessment, and monitoring of common controls (i.e., security controls inherited by information systems. Common control providers are responsible for: (i) documenting the organizational-identified common controls in a security plan; (ii) ensuring that required assessments of common controls are carried out by qualified assessors with an appropriate level of independence defined by the organization; (iii) documenting assessment findings in a security assessment report; and
(iv) producing a plan of action and milestones for all controls having weaknesses or deficiencies.
(h) Availability is ensuring timely and reliable access to and use of information.
(i) Confidentiality is preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary or sensitive information.
Peace Corps | IPS 1-17 Information Security Program Page 3
(j) Integrity is guarding against improper information modification or destruction, and includes ensuring information non-repudiation and authenticity.
(k) Cloud Services are any service made available to users on demand via the Internet from a cloud computing provider’s servers as opposed to being provided from a Peace Corps owned on-premises server(s).
(l) Third Party Collaboration Tool is a cloud service used to support a group of two or more individuals to accomplish a common goal or objective they have set themselves.
(m) Encryption is the process of converting plaintext into ciphertext for the purpose of security or privacy.
5.0 Policies
(a) The Program will operate in compliance with FIPS Publication 200, NIST SP800-53 and other laws and regulations governing federal information and information systems. The
Chief Information Officer is continuing to develop procedures (IPS 1-17 Information
Security Program Procedures) to implement the requirements of such laws and regulations.
(b) The Program will be reviewed, at a minimum, every three years or as required by change to the mission and business needs governance, technologies, or threats to the agency or agency workforce.
6.0 Roles and Responsibilities
6.1 Peace Corps Director
The Director has the overall responsibility, in accordance with provisions of NIST and FISMA, to provide information security protections commensurate with the risk and magnitude or impact of harm to organizational operations and assets, individuals, other organizations that may result from unauthorized access, use, disclosure, disruption, modification, or destruction of: (i) information collected or maintained by or on behalf of the Peace Corps; and (ii) information systems used or operated by an agency or by a contractor of an agency or other organization on behalf of an agency.
6.2 Authorizing Official
The Chief Information Officer (CIO) is the Authorizing Official for Peace Corps information systems. The Authorizing Official has the authority to formally assume responsibility for operating an information system at an acceptable level of risk to agency operations, assets, or individuals. Through the security authorization process, the authorizing official is accountable for the security risks associated with information system operations. Accordingly, the authorizing official is a in management position with a level of authority commensurate with understanding and accepting such information system-related security risks The Authorizing
Official cannot also be the System Owner for a system operating under his/her authority.
Peace Corps | IPS 1-17 Information Security Program Page 4
The Authorizing Official must complete role based security training prior to executing any signatory responsibilities as the Authorizing Official.
The Authorizing Official may approve or deny authorization to operate (ATO) for an information system. If the system is operational, the Authorizing Official may halt operations when unacceptable risks exist. The Authorizing Official coordinates activities with the risk executive (function), Chief Information Security Officer, System Owners, Information System
Security Managers, security control assessors, and other interested parties during the security authorization process.
6.3 Chief Information Officer
The Chief Information Officer (CIO) promotes and coordinates the agency-wide information security program; assigns a Chief Information Security Officer to develop and implement the
Program; and manages the OCIO, which is the agency’s common control provider for information security policies and procedures. Note: the Office of Safety and Security is the common control provider for physical, environmental, and personnel security controls.
6.4 Chief Information Security Officer
The Chief Information Security Officer (CISO) is an OCIO official responsible for: (i) carrying out the CIO’s security responsibilities under FISMA; and (ii) serving as the primary liaison for the CIO, information system owners, common control providers, and information system security officers. The CISO is responsible for the implementation and maintenance of the
Program; will develop and disseminate the Peace Corps Information Security Program Plan
(Plan); and provide oversight and performance metrics for the Plan, which will address:
(a) The provision and identification of security resources.
(b) Plan of action and milestones for the Program.
(c) The creation and maintenance of an information system inventory.
(d) Metrics for implementation and operation of the Plan.
(e) A risk management strategy and security authorization process.
(f) Appropriate guides and instructions for operation of the Plan.
6.5 Associate Director of the Office of Safety and Security
The Associate Director of the Office of Safety and Security coordinates continuity of operations and insider threat planning and activities with the OCIO to ensure that business processes and information systems used to support business processes are documented as required to support each individual plan.
Peace Corps | IPS 1-17 Information Security Program Page 5
6.6 Risk Executive
The Chief of Staff serves as Risk Executive and provides comprehensive, organization wide approach to risk management; serves as the common risk management resource for senior leaders/executives, system owners, CIO, CISO, information security officer, information system owners, common control providers; information system security managers, and stakeholders in the system success of the agency.
6.7 Information Owner
The information owner is an organizational official with statutory, management, or operational authority for specified information and the responsibility for establishing the policies and procedures governing its generation, collection, processing, dissemination, storage, and disposal.
The information owner is responsible for establishing the rules for appropriate use and protection of the subject information and retains that responsibility even when the information is shared outside the agency. The owner of the information processed, stored, or transmitted by an information system may or may not be the same as the system owner. A single information system may contain information from multiple information owners. Information owners provide input to information system owners regarding the security requirements and security controls for the systems where the information is processed, stored, or transmitted. The information owner may work in concert with the system owner or information system owner, and the ISSM or the
Privacy Office to complete the FIPS 199 categorization and/or the Privacy Threshold Analysis and Privacy Impact Assessment as required for the Risk Management Framework process.
6.8 System Owner
Each Peace Corp information system must have a System Owner (SO) throughout the information system’s lifecycle. The designation should be made by the leadership within the information system’s sponsoring business unit. The SO is responsible, in full or in part, for the planning, development, operation, maintenance and disposition of information systems used to support Peace Corps business processes. The SO will support the implementation and function of information system security controls throughout the information system’s lifecycle. With the
Information System Security Manager, the SO is accountable for the development and maintenance of the security plan and ensures that the system is deployed and operated in accordance with the agreed-upon security controls.
SOs must complete Peace Corps role based security training prior to executing any signatory responsibilities as the System Owner.
6.9 Information System Security Manager
The Information System Security Manager (ISSM) is responsible for ensuring the appropriate security posture is established and maintained throughout the information system’s lifecycle. The
ISSM is selected by and reports to the CISO. The information system security manager works in close collaboration with the information system owner and stakeholders and serves as a principal advisor on all matters, technical and otherwise, involving the security of an information system.
The information system security manager must have detailed knowledge and expertise required to manage the security aspects of an information system and is assigned the responsibility for the
Peace Corps | IPS 1-17 Information Security Program Page 6 day-to-day security operations of a system. Such positions are assigned by and report directly to the CISO.
6.10 Security Control Assessor
The security control assessor (SCA) is an individual, group, or organization responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an information system to determine the overall effectiveness of the controls. The SCA is selected by and reports to the CISO. SCAs are additionally responsible for:
(a) Providing an assessment of the severity of weaknesses and recommend corrective actions to address identified vulnerabilities; and
(b) Preparing the final security assessment report containing the results and findings from the assessment.
6.11 General Users
General Users must:
(a) Comply with this Manual Section, MS 542 Rules of Behavior for General Users and other Peace Corps requirements on the use of Peace Corps information technology resources, data, and information systems.
(b) Review the MS 542 Rules of Behavior for General Users as a condition of access to the
Peace Corps network and sign the New User’s Verification Form (PC-1780).
(c) Be knowledgeable in, and follow, Peace Corps security policies and procedures, as well as related Federal policy contained in the Privacy Act and Freedom of Information Act
(FOIA).
(d) Immediately report any of the following incidents to the Service Desk, local IT
Specialist, or supervisor:
(1) Breaches involving sensitive agency data (in electronic or paper format) that may have been lost, stolen, or compromised;
(2) Lost or stolen IT equipment furnished by the Peace Corps;
(3) Suspicious emails (phishing); or
(4) Activities in violation of the Rules of Behavior.
(e) Complete required information security and functional training.
Peace Corps | IPS 1-17 Information Security Program Page 7
6.12 Privileged Users
Privileged users include individuals with system administrator, system development, or system engineering responsibilities. In addition to the responsibilities identified for General Users, Privileged Users must:
(a) Review the Peace Corps MS 542 Rules of Behavior for Privileged Users and sign and get the required authorized signatures on the Privileged User Account Request Form (PC-
2076-e);
(b) Complete required information security and functional training before using their privileged account;
(c) Develop and implement the information security requirements throughout the system development life cycle up to and including archiving and disposition;
(d) Verify the system security requirements of the information systems to which they have privileged access are being met;
(e) Establish, maintain, review, and communicate the security safeguards required to protect the availability, integrity and confidentiality of information systems based on the information’s security characterization;
(f) Plan and implement the on-going maintenance of the information system, including updates, upgrades, and patches in accordance with the system development life cycle and the change control board (CCB) process.
(g) Comply with the OCIO Standards of Practice and Governance and Standard Operating
Procedures;
(h) System Administrators will periodically review and verify that all users of their systems are authorized and are using the required systems security safeguards, in compliance with the Peace Corps Information Security Program and all related standards, guidelines, and procedures; and
(i) Implement only information system changes approved by the Agency’s Change Control
Board.
7.0 Information Security Controls
The information security policies and procedures address the protection of the Agency’s workforce, business processes, and digital content through the implementation of management, operational, and technical controls that provide a framework to protect Peace Corps information and information systems. These controls protect the confidentiality, availability, integrity, authenticity, and non-repudiation of information created, collected, processed, aggregated, transmitted, stored, or disposed of, by or on behalf of Peace Corps information systems and business processes.
Peace Corps | IPS 1-17 Information Security Program Page 8
7.1 Information and Information System Security Categorization
Security categorization is the first step in determining the security controls required to protect
Peace Corps information, information technologies, information systems and digital content.
The categorization process is used to determine the impact to the Peace Corps workforce, assets, business processes, and reputation in the event of a breach of confidentiality, integrity or availability occurs.
The impact levels are described as low impact, moderate, and high impact. Impact categories are described below:
(a) Information is considered to be low impact if loss of confidentiality, integrity, or availability could be expected to have a limited adverse effect on organizational operations, organizational assets, or individuals.
(b) Information is considered to be moderate impact if loss of confidentiality, integrity, or availability could be expected to have a serious adverse effect on organizational operations, organizational assets, or individuals.
(c) Information is considered to be high risk if loss of confidentiality, integrity, or availability could be expected to have a severe or catastrophic adverse effect on organizational operations, organizational assets, or individuals.
The information owner or information system owner is responsible for completing the security categorization process in accordance with FIPS 199 and establishing a security control baseline.
The information system owner must provide written justification, referencing control tailoring techniques defined in NIST publications, for all changes, increased or decreased, to the provisional impact levels provided in NIST SP800-60.
7.2 Encryption Requirements
(a) All agency website and service available over the Hypertext Transfer Protocol (HTTP) connections must enable and utilize the HTTP Strict Transport Security (HSTS).
(b) There are no encryption requirements for low impact information, as defined in section
7.1(a).
(c) Moderate and high impact information is considered sensitive information, as defined in
4.0(c), and must be encrypted in accordance with FIPS 140-2.
(d) High impact information must be encrypted while at rest or in storage in accordance with
FIPS 140-2.
(e) Agency furnished and Bring Your Own Device (BYOD) mobile devices must have FIPS
140-2 encryption and containerization capabilities.
Peace Corps | IPS 1-17 Information Security Program Page 9
7.3 Cloud Services
The acquisition of cloud services must be authorized by the Office of Chief Information Office
(OCIO). OCIO will ensure that any contract or other agreement with a cloud service provider is fully documented and addresses key cloud service terms, including provisions for ownership of data, data retention, data sanitization upon contract termination, data dissemination, access to
Peace Corps data, data security, data preservation, and any access requirements. Further, all subsequent changes to contracts or agreements must be approved by the OCIO.
7.4 Third Party Collaboration Tools
Peace Corps staff may use OCIO approved third party collaboration tools to enable work directly with external partners, contacts or Peace Corps Volunteers only in circumstances in which there is low impact information. All third party collaboration tools must be approved by the OCIO prior to being used to conduct Peace Corps related business. These tools cannot be used to transmit, aggregate, share or store moderate or high impact, or sensitive information.
All staff created, maintained or retained content on third party a collaboration tools are subject to
FOIA disclosure and must follow Federal records management laws and requirements as is done with all agency records. Federal records must also be stored in an appropriate location within the
Peace Corps environment by staff users who must export documents or media from the third party collaboration tools until the process can be automated.
8.0 Procedures
All procedures required under law to implement information security policies are continuing to be developed by the OCIO and reviewed and approved by both the Office of General Counsel and the Office of Compliance. Country Directors may issue additional country-specific procedures for information technology, provided they are consistent with this Manual Section.
9.0 Effective Date
The effective date is the date of issuance.
File details come from the government source that posted it.