JMD AFMS RFP 15JPSS26R00000037.pdf
PDF 17 MB Posted
- Attached to
- Asset Forfeiture Administrative Support Services Federal contract opportunity
- Solicitation number
- 15JPSS26R00000037
About this file
This document is a PDF viewer error message, not a federal contract opportunity file. The document contains only technical instructions for upgrading Adobe Reader software and does not include any solicitation, proposal request, statement of work, or other contract-related content. No contract information, requirements, timelines, pricing terms, or agency details are present in this file.
View the file
Other files for this federal contract opportunity
Show all 35
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Please wait...
If this message is not eventually replaced by the proper contents of the document, your PDF viewer may not be able to display this type of document.
You can upgrade to the latest version of Adobe Reader for Windows®, Mac, or Linux® by visiting http://www.adobe.com/go/reader_download.
For more assistance with Adobe Reader visit http://www.adobe.com/go/acrreader.
Windows is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or other countries. Mac is a trademark of Apple Inc., registered in the United States and other countries. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries.
DOJ 2620.7 CONTROL AND PROTECTION OF LIMITED OFFICIAL USE INFORMATION
http://dojnet.doj.gov/dojorders/DOJ2620.7.htm[4/20/2012 2:34:58 PM]
DOJ 2620.7
CONTROL AND PROTECTION OF LIMITED OFFICIAL USE INFORMATION
Approval Date: September 1, 1982 Approved By: KEVIN D. ROONEY
Assistant Attorney General for Administration
Distribution: BUR/H-1; OBD/H-1; OBD/F-1 Initiated By: Justice Management Division
Security Staff
1. PURPOSE . This order establishes Department of Justice (DOJ) regulations requiring the identification, with the marking "Limited Official Use", and the safeguarding of unclassified but sensitive information which must be protected against unauthorized disclosure. The order includes minimum protection requirements and recommends additional security safeguards to be applied where warranted by the sensitivity of the information.
2. SCOPE. This order applies to all organizations within the Department of Justice.
3. REFERENCES.
a. 26 U.S.C. Section 6103, Publicity of returns and disclosure of information as to persons filing income tax returns.
b. Federal Rules of Criminal Procedure, Rule 6(e), Grand Jury Secrecy of Proceedings and Disclosure.
4. BACKGROUND. In contrast with many government agencies, the Department of Justice has not previously issued a published policy for protecting unclassified information which is considered sensitive. Within the Department, a number of bureaus, offices, boards and divisions have issued directives or established procedures to protect sensitive information within their purview. The lack of a Department order specifying a single term to identify sensitive information throughout the Department and setting minimum protection requirements decreases the effectiveness of the individual directives or procedures when the information is released to other organizations within the Department. Additionally, the protection of sensitive information on Department wide facilities such as the Justice Data Management Service or the Justice Telecommunications System is more difficult to effect without uniform Department policy.
5. DEFINITION OF LIMITED OFFICIAL USE.
a. Limited Official Use information is unclassified information of a sensitive, proprietary or personally private nature which must be protected against release to unauthorized individuals, and this term is prescribed for use within the Department to signify such information. Information which impacts on the national security of the United States and is classified Confidential, Secret or Top Secret under Executive Order 12356 is not to be considered as Limited Official Use.
b. The determination of categories or types of information within an organization of the Department which are considered as Limited Official Use will be the responsibility of the heads of Offices, Boards, Divisions and Bureaus (hereinafter referred to as Departmental organizations). Information must not be designated as Limited Official Use to conceal inefficiency, misdeeds or mismanagement.
c. The following categories are provided for illustrative purposes only as examples of the types of information that Departmental organizations may want to include as Limited Official Use information:
(1) Informant and witness information;
(2) Grand Jury information subject to paragraph 3b;
(3) Investigative material;
(4) Tax information subject to paragraph 3a;
(5) Information that could be sold for profit;
(6) Personal information subject to the Privacy Act of 1974;
(7) Reports that disclose security vulnerabilities;
(8) Information that could result in physical risk to individuals;
(9) Company proprietary information.
(10) Deliberative information relating to internal DOJ or Executive Branch policy and decision making.
6. POLICY.
a. The Department of Justice has access to a considerable amount of unclassified information which must be safeguarded to comply with existing laws and regulations or to protect individual rights or critical operations of the Department or the integrity of the policy making process. It is the policy of the Department to comply with these laws and regulations and provide adequate protection to safeguard sensitive information.
b. It is the policy of the Department to comply with requests for public access to information in accordance with existing laws and regulations.
7. RESPONSIBILITIES.
a. Heads of Departmental organizations are responsible for ensuring compliance with this Order, specifically including:
(1) Issuing directives, if needed, establishing criteria for identifying Limited Official Use information within their organization in accordance with paragraph 5.
(2) Ensuring that adequate security measures and procedures are implemented to protect Limited Official Use information.
(3) Protecting material identified as Limited Official Use received from other organizations within the Department.
(4) Ensuring that employees of their organization are aware of their responsibility to protect Limited Official Use information.
(5) Providing the Assistant Attorney General for Administration with a copy of any implementing directive which lists the categories of information included under Limited Official Use to ensure that the categories are consistent with DOJ policy.
b. The Department Security Officer is responsible for reviewing compliance with this order and for providing guidance to Departmental organizations regarding identification and protection of Limited Official Use information.
8. CROSS REFERENCES. Departmental personnel should contact their Security Programs Manager or the Department Security Officer if copies of the non-DOJ references are needed to comply with the requirements of paragraph 13c. Field office personnel should contact their Security Programs Manager or the Department Security Officer if copies of paragraph 8a or 8f are needed.
a. Order DOJ 2640.1, Privacy Act Security Regulations for Systems of Records.
b. Order DOJ 2640.2, Automated Data Processing (ADP) Security.
c. Order DOJ 2620.5A, Safeguarding Tax Returns and Tax Return Information.
d. National Bureau of Standards Federal Information Processing Standards Publication 46, Data Encryption Standard.
e. Federal Telecommunications Standard 1027, General Security Requirements for Equipments Using the Data Encryption Standard.
f. Order DOJ 2710. 9A, Records Disposition Program.
g. 28 C.F.R. 45.735-10, Improper Use of Official Information.
h. 28 C.F.R. 16.56, Employee Standards of Conduct With Regard to Privacy.
i. 28 C.F.R. 50.2, Release of Information to Personnel of the Department of Justice Relating to Criminal and Civil Proceedings.
j. 28 C.F.R. 22.1, Confidentiality of Identifiable Research and Statistical Information.
9. FREEDOM OF INFORMATION ACT (FOIA) AND PRIVACY ACT OF 1974. The identification of material as Limited Official Use information has no connection with the Freedom of Information Act (5 U.S.C.
552) and cannot be used as a reason for approving or denying FOIA requests. Requests for access to Limited Official Use material will be considered in a similar manner as requests for any other Department information.
Information subject to the Privacy Act (5 U.S.C. 552a) is required to be protected in accordance with paragraph 8a and may be included as Limited Official Use by the head of the organization concerned.
10. DESIGNATING AUTHORITIES.
a. Heads of Departmental organizations have the authority to specify the categories or types of information, which originate in their organization or are prepared for the use of their organization, that are designated as Limited Official Use. If the sensitivity of the information requires protection in excess of the minimum levels established in this order, they should ensure that such criteria are known to all offices who have custody of the information.
b. Heads of departmental organizations shall identify those subordinate officials who have authority to determine which information originating under their supervision or cognizance requires protection against unauthorized disclosure. The officials so designated are responsible for ensuring that personnel under their direction are aware of information that is considered Limited Official Use.
11. IDENTIFICATION AND MARKING. Department material which contains information that the head of the Departmental organization has determined requires protection against unauthorized disclosure must be identified as Limited Official Use to ensure that all persons having access to the information are aware of the protection requirement. The identification of Limited Official Use may be done by a marking of Limited Official Use on the first page of the material, by a notation in a covering memo, by inclusion in a category identified as Limited Official Use in an organization directive and known to all personnel handling the information, or any other method authorized by the head of the departmental organization. The purpose of identifying Limited Official Use information is to ensure that all recipients of the material are aware that the information requires protection. The identification method selected should have a minimal effect on the operational efficiency of the organization.
12. CUSTODY AND STORAGE.
a. Personnel who have custody of material designated as Limited Official Use shall exercise due caution to ensure that the information is not available to individuals who have no requirement for it. At a minimum, unauthorized individuals must not be able to enter areas unobserved and have visual access to Limited Official Use information.
b. During non-duty hours, Limited Official Use material shall be afforded minimum protection of storage in a locked desk or file cabinet, or storage in a facility or area using physical access control measures which afford adequate protection to prevent unauthorized access. The sensitivity of some Limited Official Use material may require a higher level of protection such as a safe with a combination lock.
c. Limited Official Use information stored and processed by an ADP facility shall have adequate physical, administrative and technical safeguards in accordance with paragraph 8b. Tax information must be protected in accordance with paragraph 8c.
13. DISSEMINATION AND TRANSMISSION.
a. Information which has been identified and is known by the recipient as Limited Official Use shall be safeguarded from disclosure to unauthorized individuals whether or not the material is physically marked.
Safeguarding from disclosure includes precautions against oral disclosure, prevention of visual access to the information and precautions against release of the material to unauthorized personnel.
b. Limited Official Use information leaving the control of the originating organization must be transmitted in a single opaque envelope or in a wrapping properly sealed and addressed.
c. Electronically transmitted messages or data containing Limited Official Use information shall be preceded by the term Limited Official Use at the beginning of the text. If data encryption techniques are employed, the equipment must use the Data Encryption Standard algorithm (paragraph 8d) and meet the Federal Telecommunications Standard 1027 (paragraph 8e), or be approved for National Security Information.
d. An ADP facility handling Limited Official Use information or a remote facility used to access Limited Official Use information from an ADP system via communications links shall implement procedures to protect the information in accordance with paragraph 8b. The managers of sensitive systems accessed via communications links must consider the threats to the data in determining whether security measures such as data encryption, use of dedicated lines, terminal or user identifiers, or control and marking of output should be implemented.
e. Limited Official Use information may be discussed on the telephone; however, the ease of interception of telephone conversations dictates that discretion be used where the threat of interception exists. In the latter case, the use of voice privacy equipment or secure telephones should be considered.
14. CONTRACTOR PERSONNEL. If Limited Official Use information must be released to nongovernment personnel as part of a contract or grant, the head of the Departmental organization shall determine if the sensitivity of the information justifies a requirement for an investigation of contractor personnel handling the sensitive information. The procurement document must include the contractor background investigation requirements and other security requirements of the contract. The Security Programs Manager of the Departmental organization requesting the contract shall (1) determine the extent of the investigation required, ranging from FBI name and fingerprint checks to full-field background investigations, and (2) develop the mandatory security requirements for the contract. The contractual security requirements shall be forwarded to the Departmental organization's Security Programs Manager for concurrence prior to submitting the solicitation document to the procurement office.
15. DESTRUCTION.
a. Record material may not be destroyed without appropriate disposition authority. (See paragraph 8f.) When such authority exists, physical destruction may be accomplished in the manner described in the succeeding paragraphs.
b. Where appropriate, Limited Official Use material may be destroyed by tearing it into small pieces and discarding with other waste material. Material of higher sensitivity must be destroyed by shredding or other methods such as burning or pulping. Small segments of microfiche and microfilm may be readable;
therefore, destruction into very small particles or strips is necessary.
c. ADP storage media containing Limited Official Use data should be overwritten with nonsensitive data prior to release of the storage media. Storage media containing data of greater sensitivity should be degaussed, sanitized and/or destroyed.
16. ADDITIONAL PROTECTION REQUIREMENTS. The safeguards prescribed in this order are minimum requirements except where otherwise noted. The sensitivity of the information and threats to it should be considered in determining the adequacy of existing safeguards and the need for additional security protection.
17. MATERIAL PROM OTHER DEPARTMENTS. A number of government agencies have issued regulations for protecting sensitive information using designations such as For Official Use Only or Limited Official Use.
Sensitive material from other government agencies or proprietary information from private concerns should be safeguarded from unauthorized disclosure in accordance with this order or provided additional protection in accordance with the specific requirements of the agency providing the sensitive information.
18. UNAUTHORIZED DISCLOSURE. Heads of Departmental organizations shall ensure that prompt and appropriate administrative action is taken against personnel responsible for disclosure of Limited Official Use material to unauthorized individuals and issue appropriate directives, if needed, to effect this action.
/s/KEVIN D. ROONEY Assistant Attorney General for Administration doj.gov
DOJ 2620.7 CONTROL AND PROTECTION OF LIMITED OFFICIAL USE INFORMATION
® U.S. Department of Justice 0904
Approved On:
DOJOrder
CYBERSECURITY PROGRAM
PURPOSE: Maintains and enhances the Department of Justice (Department or DOJ) Cybersecurity Program as established in previous DOJ Orders; provides the governance framework for uniform policy; ensures appropriate privacy protections for DOJ information and information system security; confirms authorities; and assigns responsibilities for protecting information and information systems that store, process, or transmit DOJ electronic information from cyber intrusions.
SCOPE: All DOJ components, personnel, and information systems that process, store, or transmit DOJ national security or unclassified information;
contractors and other users and operators of information systems that support the operations and assets of DOJ, including any non-DOJ organizations and their representatives who are granted access to DOJ information resources, such as other federal agencies and cloud providers.
ORIGINATOR: Justice Management Division (JMD), Office of the Chief Information Officer
CATEGORY: (I) Administrative, (II) Information Technology; Information and Privacy
AUTHORITY: Federal Information Security Modernization Act of 2014, Pub. L. 107- 347, 116 Stat. 2899 (Dec. 18, 2014) (primarily codified at 44 United States Code (U.S.C.) chapter 35, subchapter II); Office of Management and Budget Circular A-130, Managing Information as a Strategic Resource, July 28, 2016, reference Appendix A for additional authorities
CANCELLATION: DOJ Order 2640.2F
DISTRIBUTION: Electronically distributed to those referenced in the "SCOPE" section and posted on the DOJ directives electronic repository (SharePoint) at https://doj365.sharepoint.us/sites/jmd-dm/dm/SitePages/Home.aspx
APPROVED BY: Lisa Monaco ~ ,~ -~ ~ Deputy Attorney General
U.S. Department of Justice DOJ Order 0904
ACTION LOG
The issuing component must review its DOJ directives at least every five years and make revisions as necessary. The action log records dates of approval, recertification, and cancellation, as well as major and minor modifications to this directive, and provides a brief summary ofall revisions. In the event this directive is cancelled, superseded, or supersedes another directive, that will also be noted in the action log.
Action Reissuance
Authorized by
Lee J. Lofthus Assistant Attorney General for Administration
Date
9/15/2016 Summ.lr}
Reflected updated security requirements for DOJ information and information systems.
Updated to align with new federal mandates, directives, and guidance.
Update Lisa Monaco Deputy Attorney
General
,1/1t1/2oz~
/4~ ·1r1~
U.S. Department ofJustice
TABLE OF CONTENTS
ACTION LOG
DEFINITIONS
ACRONYMS
I. Policy
A. Maintains Staff to Serve as the Central Focal Point for Cybersecurity
B. Deploys and Manages a Department-Wide Common Security Strategy
C. Identifies New and Emerging Technologies
D. Develops Cybersecurity Policies, Standards, Procedures, and Templates
E. Promotes Awareness of Security and Privacy Risks and Policies
F. Develops Standards for and Performs Security and Privacy Control Monitoring and Evaluation
G. Develops and Manages a Comprehensive Risk Management Program
H. Maintain System Inventory and Security and Privacy Authorization Documentation
I. Manage Supply Chain Risk Management Program
J. Maintain Enterprise High Value Asset Governance
K. Protects the Privacy oflndividuals
II. Information System Security and Privacy Requirements
A. Security and Privacy Control Families
B. Contractor Access to Information Systems
C. Use of DOI IT Resources Outside the United States
D. Classified Information
E. Cloud Computing
F. Protection ofMobile Devices and Removable Media
G. External Information Systems
H. Wireless Communication Platforms
III. Roles and Responsibilities
A. DOI Chief Information Officer
B. DOI Chieflnformation Security Officer
C. Department Security Officer
D. Head of Component or Designee(s)
E. Chief Privacy and Civil Liberties Officer
APPENDIX A: AUTHORITIES
Term Definition
Access, Internal Either local access or internal network access to DOJ information systems. Local access is access to information systems by users ( or processes acting on behalf ofusers) where such access is obtained by direct connections without the use of networks. Network access is access to information systems by users (or processes acting on behalf of users) where such access is obtained through network connections (e.g., non-local accesses). Internal networks include local area networks and wide area networks.
Access, Public Limited to non-DOJ users of DOJ information systems. In accordance with the E-Authentication E-Govemment initiative, authentication of non-DOJ users accessing federal information systems may be required to protect federal, proprietary, or privacy-related information (with exceptions noted for national security systems). Components must use risk assessments to determine authentication needs and consider scalability, practicality, and security in balancing the need to ensure ease of use for access to federal information and information systems with the need to protect and adequately mitigate risk.
Components may allow a limited number of user actions without identification or authentication, including access to public websites or other publicly accessible federal information systems.
Access,Remote Any access to a DOJ non-public information system by a DOJ employee or contractor operating outside the authorization boundary of the organizational system and communicating through an external, non-DOJ-controlled network. Remote access presents additional security concerns as the component has no direct control over the application of required security and privacy controls or the assessment of security control effectiveness of the connecting devices and network. The goal of these requirements is to ensure that components can safely use remote access to better accomplish their missions.
Access, General Authorized general information system access that is approved access and that is not privileged access.
Access, Privileged Authorized privileged information system access that is approved access with elevated roles or functions - especially security-relevant functions (e.g., account management, system administration, and application configuration) - and specifically restricts access to email and internet services.
DEFINITIONS
Authorization to Operate
The official management decision is given by an Authorizing Official or other designated senior DOJ official to authorize the operation of an information system and to explicitly accept the risk to DOJ operations, assets, individuals, other organizations, and the Nation.
Authorizing Official
A senior Federal official or executive with authority to assume formal responsibility for operating an information system at an acceptable level of risk to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation.
Breach The loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence in which (1) a person other than an authorized user accesses or potentially accesses Personally Identifiable Information (PII) or (2) an authorized user accesses or potentially accesses PII for an unauthorized purpose.
Cloud Computing A model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction. This cloud model is composed of five essential characteristics, three service models, and four deployment models in accordance with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-145, The NIST Definition ofCloud Computing.
Component An office, board, division, or bureau of the Department ofJustice as defined in 28 C.F.R. Part OSubpart A, Paragraph 0.1 .
Continuous Monitoring
Maintaining ongoing awareness to support organizational risk decisions.
Critical Sofhvare Any software that has, or has direct software dependencies upon, one or more components with at least one of these attributes: is designed to run with elevated privilege or manage privileges; has direct or privileged access to networking or computing resources; is designed to control access to data or operational technology; performs a function critical to trust; or operates outside of normal trust boundaries with privileged access.
Cybersecurity Prevention of damage to, protection of, and restoration ofcomputers, electronic communications systems, electronic communications services, wire communication, and electronic communication, including information contained therein, to ensure its availability, integrity, authentication, confidentiality, and nonrepudiation.
Term
Data Information in an electronic format that allows it to be retrieved or transmitted.
External An information system or component of an information system that is Information System outside of the authorization boundary established by the organization and for which the organization typically has no direct control over the application of required security and privacy controls or the assessment of security control effectiveness.
Government- Any device that exists within the authorization boundary of a DOJ Authorized Device information system with an Authorization to Operate. This includes, but is not limited to, equipment furnished by the government.
Head of The Director or Administrator of a bureau or the Assistant Attorney Component General or equivalent of the offices, boards, and divisions.
Incident An occurrence that (1) actually or imminently jeopardizes, without lawful authority, the availability, integrity, authentication, confidentiality, or nonrepudiation1 of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.
Information Any communication or representation of knowledge, such as facts, data, or opinions, in any form or medium, including textual, numerical, graphic, cartographic, narrative, or audio-visual. This includes communication or representation of knowledge in an electronic format that allows it to be stored, retrieved, or transmitted.
Information, DOJ Information that is owned, produced, controlled, protected by, or otherwise within the custody or responsibility ofDOJ, including information related to DOJ programs or personnel. It includes information (1) provided by, generated by, or generated for DOJ, (2) provided to DOJ and in DOJ custody, or (3) managed or acquired by a DOJ contractor in connection with the performance of a contract regardless of format.
Information System A discrete set of information resources organized for collecting, processing, maintaining, using, sharing, disseminating, or disposing of information. Information systems include specialized systems such as industrial/process control systems, telephone switching and private branch exchange systems, and environmental control systems.
Definition
1 Protection against an individual who falsely denies having performed a certain action and provides the capability to determine whether an individual took a certain action, such as creating information, sending a message, approving information, or receiving a message. NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations, Appendix A.
Information System Security Officer
An individual with assigned responsibility for maintaining the appropriate operational security level for an information system or program.
Insider Any person with authorized access to any U.S. Government resource including personnel, facilities, information, equipment, networks, or systems.
Insider Threat The threat that an insider will use their authorized access, wittingly or unwittingly, to do harm to the security of the U.S. This threat can include damage to the U.S. through espionage, terrorism, unauthorized disclosure o:
information, or the loss or degradation of departmental resources or capabilities.
Least Functionality The security concept in which information systems are configured to provide only essential capabilities and specifically prohibit or restrict the use of non-essential functions, such as ports, protocols, and/or services that are not integral to the operation of that information system.
Least Privilege The security concept in which a user or process is given the minimum levels of access or permissions needed to perform their job or intended function.
Multifactor Authentication
Authentication using two or more factors to achieve authentication. Factors include: (i) something the user knows ( e.g., password/personal identification number [PIN]); (ii) something the user has ( e.g., cryptographic identification device, token); or (iii) something the user is (e.g., biometric).2
National Security Information
Information that has been determined (pursuant to Executive Order 13526, Classified National Security Information, December 29, 2009, or any successor order, or by the Atomic Energy Act of1954) to require protection against unauthorized disclosure and is marked to indicate its classified status.
2 The Department's default multifactor authentication is using Personal Identity Verification (PIV) as the second form factor.
Term
Policy Enforcement Point
Personally Identifiable Information (PII)
Risk
Risk Management
Definition
As described and used within NIST SP 800-207, Zero Trust Architecture; a system responsible for enabling, monitoring, and eventually terminating connections between end users, applications or other non- human entities, and enterprise resources.
Information that can be used to distinguish or trace an individual's identity, such as name, social security number, or biometric records, alone or when combined with other personal or identifying information that is linked or linkable to a specific individual, such as date and place of birth or mother's maiden name.
To determine whether the information is PII, the agency must perform an assessment ofthe specific risk that an individual can be identified using the information with other information that is linked or linkable to the individual. When performing this assessment, it is important to recognize that information that is not PII can become PII whenever additional information becomes available - in any medium and from any source -that would make it possible to identify an individual.3
A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically it is a function of (1) the adverse impact or magnitude of the harm that would arise if the circumstance or event occurs; and (2) the likelihood ofoccurrence. Risk can include both information security and privacy risks.
The process of managing risks to DOJ operations (including mission, functions, image, or reputation), DOJ assets, data, individuals, and other organizations that result from the operation of an information system.
The process includes: (1) the conduct of a risk assessment; (2) the implementation of a risk mitigation strategy; and (3) the employment of techniques and procedures for the continuous monitoring of the security state of the information system.
3 0MB Circular A-130, Managing Information as a Strategic Resource, (July 28, 2016), 11-1 to 11-2.
Security and Privacy Continuous Monitoring Strategy
A formal document that catalogs the available security and privacy controls implemented at DOJ across the DOJ risk management tiers. It supports the effective monitoring of controls on an ongoing basis by assigning a DOJ-defined assessment frequency to each control that is sufficient to ensure compliance with applicable security and privacy requirements and to maintain an ongoing awareness of information security and privacy vulnerabilities and threats to support organizational risk management decisions.
Senior Component Official for Privacy
The Senior Component Official for Privacy (SCOP) role and responsibilities are defined in DOJ Order 0601, Privacy and Civil Liberties, or a successor order. Generally, a component's SCOP holds primary responsibility for the applicable component' s privacy and civil liberties activities, including compliance with applicable privacy laws, regulations, directives, and policies.
System Security and Privacy Plan
A formal document that details (1) the security and privacy controls selected for an information system or environment of operation that are in place, or planned, for meeting applicable security and privacy requirements and managing security and privacy risks; (2) how the controls have been implemented; and (3) the methodologies and metrics that will be used to assess the controls.
Terminal Services A multi-user, thin client environment. The user's machine functions like an input/output terminal to the central server.
United States Includes the land area, internal waters, territorial sea, and airspace of the United States, including: (1) United States territories; and (2) other areas over which the U.S. Government has complete jurisdiction and control or has exclusive authority or defense responsibility.
Virtual Private Network
Enables users to send and receive data across shared or public networks as if their computing devices were directly connected to the private network. A virtual private network is created by establishing a virtual point-to-point connection using dedicated connections, virtual tunneling protocols, and traffic encryption.
Acronym Meaning
AAG/A Assistant Attorney General for Administration
AG Attorney General
AO Authorizing Official
APN Acquisition Policy Notice
ATO Authorization to Operate
BIA Business Impact Analysis
CD Compact Disc
CIO Chief Information Officer
CISA Cybersecurity and Infrastructure Security Agency
CISO Chief Information Security Officer
CMT Core Management Team
CNSS Committee on National Security Systems
COR Contracting Officer' s Representative
CPCLO ChiefPrivacy and Civil Liberties Officer
CSAT Cybersecurity Awareness and Training
CSP Cloud Service Provider css Cybersecurity Services Staff
DAAG/IRM Deputy Assistant Attorney General/Information Resources Management
DAG Deputy Attorney General
DAR Data at Rest
DIT Data in Transit
DNI Director ofNational Intelligence
DNS Domain Name System
DOJ Department ofJustice
DSO Department Security Officer
DVD Digital Video Disc
ACRONYMS
EDR Endpoint Detection and Response
ERM Enterprise Risk Management
FBI Federal Bureau oflnvestigation
FedRAMP Federal Risk and Authorization Management Program
FIPS Federal Information Processing Standards
FITARA Federal Information Technology Acquisition Reform Act
GAO Government Accountability Office
HTTPS Hypertext Transfer Protocol Secure
HVA High Value Asset
ICAM Identity, Credential, and Access Management
ICD Intelligence Community Directive
ICTS Information and Communication Technology Services
IG Inspector General
IPA Initial Privacy Assessment
ISCM Information Security Continuous Monitoring
ISCP Information System Contingency Plan
IT Information Technology
ITPDP Insider Threat Prevention and Detection Program
JAR Justice Acquisition Regulations
JCAM Joint Cybersecurity Authorization Management
JCOTS Justice Cloud Optimized TIC Service
JEFS Justice Enterprise File Sharing
JSOC Justice Security Operations Center
MFA Multifactor Authentication
NIST National Institute of Standards and Technology
NSA National Security Agency
NSI National Security Information
NSS National Security Systems
OCIO Office of the Chief Information Officer
ODNI Office of the Director ofNational Intelligence
0MB Office ofManagement and Budget
OPCL Office of Privacy and Civil Liberties
PIA Privacy Impact Assessment
PU Personally Identifiable Information
POA&M Plan ofAction and Milestones
PTA Privacy Threshold Analysis
RMF Risk Management Framework
SCI Sensitive Compartmented Information
SCOP Senior Component Official for Privacy
SCRM Supply Chain Risk Management
SDLC Systems Development Lifecycle
SORN System or Records Notice
SP Special Publication
SPAA Security and Privacy Assessment and Authorization Handbook
SPDR Security Posture Dashboard Report
SPE Senior Procurement Executive
SPOM Security Program Operating Manual
SSN Social Security Number
TIC Trusted Internet Connection
UAS Unmanned Aircraft System
USB Universal Serial Bus
VPN Virtual Private Network u.s.c. United States Code
I. Policy
The Federal Information Security Modernization Act of2014 (FISMA) and the Office of Management and Budget (0MB) Circular A-130 require the Department of Justice to maintain a DOJ-wide Cybersecurity Program that protects DOJ information systems and operations; maximizes resources; and establishes the governance framework, policy requirements, and standards for managing the security and privacy of departmental electronic information, information systems, and associated assets.
In accordance with these requirements, this Order establishes and explicates the DOJ Cybersecurity Program (formerly established by DOJ Order 2640.2F, Information
Technology Security). Through this Cybersecurity Program, DOJ must continue to safeguard the Department against malicious unauthorized access, use, disclosure, disruption, modification, or damage or destruction of its information systems and resources in support ofDOJ's mission. FISMA directs agency heads to delegate authority to the agency Chief Information Officer (CIO), who is required to designate a senior agency information security officer to carry out the CIO's responsibilities under FISMA.4 The DOJ CIO has designated the DOJ Chief Information Security Officer (CISO) under this authority, and the CIO maintains the authority to further designate cybersecurity responsibilities as necessary within the Office of the CIO (OCIO) or to other qualified and appropriate DOJ officials.
The Chief Privacy and Civil Liberties Officer (CPCLO), supported by the Office of Privacy and Civil Liberties (OPCL), serves as the central focal point for privacy in DOJ.
The DOJ CIO, CISO, and cybersecurity personnel must coordinate with the CPCLO, OPCL, and the relevant Senior Component Official for Privacy (SCOP) on privacy risks.
The DOJ CISO manages and oversees the Cybersecurity Program. In that capacity, the CISO is responsible for ensuring that DOJ complies with the following Cybersecurity Program requirements:
A. Maintains Staff to Serve as the Central Focal Point for Cybersecurity
The Cybersecurity Services Staff (CSS) serves as DOJ's central focal point for cybersecurity. CSS provides DOJ-wide management and implementation of the DOJ Cybersecurity Program. CSS and the components work collaboratively to manage the priorities for achieving business objectives and complying with the required laws, rules, and regulations, including those listed in Appendix A; Directives; Presidential Decision Directives/Presidential Directives; Presidential Executive Orders; 0MB circulars and memoranda; National Institute of Standards and Technology (NIST) requirements; Committee on National Security Systems (CNSS) requirements;
4 44 U.S.C. § 3554(a)(3).
Director ofNational Intelligence (DNI) directives; and DOJ cybersecurity requirements.
B. Deploys and Manages a Department-Wide Common Security Strategy
The DOJ CIO sets and implements the Department's common security strategy that defines security goals for the components in alignment with applicable federal laws, regulations, and guidance. These goals outline DOJ's security posture, both internally and externally, while considering each component's respective business needs and missions. DOJ's common security strategy is strengthened by adopting an enterprise security architecture to ensure that information technology (IT) and supporting infrastructure remain secure throughout the entire lifecycle. Components must align information system security requirements to the strategy and security architecture at the beginning of the system's development lifecycle (SDLC) and appropriately fund such security requirements.
C. Identifies New and Emerging Technologies
The increase in the volume of departmental electronic information is so substantial and dynamic that DOJ is constantly identifying new and emerging technologies to assist in accomplishing its evolving national and global mission. Components must coordinate with CSS before implementing new or emerging technologies that will or may impact the DOJ enterprise architecture. 5 To deviate from the DOJ enterprise architecture or have overlapping enterprise security services provided by OCIO, components must obtain a waiver from the DOJ CIO.
D. Develops Cybersecurity Policies, Standards, Procedures, and Templates
DOJ's cybersecurity policies, standards, procedures, and templates address DOJ's information system security and privacy needs and serve as the foundation for DOJ's Cybersecurity Program. The cybersecurity policies, standards, procedures, and templates are the primary mechanism for CSS senior management to communicate its cybersecurity requirements to the components. The DOJ CISO revises these cybersecurity policies, standards, procedures, and templates as necessary to align with federal mandates, directives, and guidance while allowing components to execute their missions.
E. Promotes Awareness of Security and Privacy Risks and Policies
The DOJ CISO must continually educate DOJ information system users on security and privacy risks and related policy. CSS will continually work with components to educate and provide resources to promote cybersecurity awareness training to users
5 See DOJ Policy Statement 0903.02, Information Technology EnterpriseArchitecture Oversight.
through its enterprise awareness and training materials and applications.
F. Develops Standards for and Performs Security and Privacy Control Monitoring and Evaluation
The DOJ CISO and CPCLO must continually monitor and assess DOJ's cybersecurity and privacy programs to validate the security and privacy controls implemented to ensure effectiveness in safeguarding DOJ information systems and information and in conforming with applicable federal laws, regulations, and guidance. They must incorporate the monitoring of control effectiveness and compliance with policy within the Information Security Continuous Monitoring (ISCM) program, including using automated tools when possible.
G. Develops and Manages a Comprehensive Risk Management Program
The DOJ CISO and components must develop, implement, and manage information systems based on a thorough examination of the risks identified in security and privacy control assessments and the potential impact the information system has on DOJ operations. FISMA, 0MB Circular A-130, NIST Special Publication (SP) 800-
37, Risk Management Framework for Information Systems and Organizations, and other federal guidance concepts are incorporated in the DOJ risk management program. It presents a formal, structured approach for developing risk assessments for information systems and provides a uniform standard for evaluating security and privacy risks affecting the availability, integrity, authentication, confidentiality, or nonrepudiation of DOJ information or information systems.
DOJ information system owners and cybersecurity managers must adhere to the DOJ risk management program when assessing risks, framing risks, and prioritizing resources for the security and privacy assessment and authorization of information systems. Effective risk management must include risk identification and prioritization, categorization ofrecommended safeguards, feasibility of implementation, and other risk management processes as defined in the DOJSecurity and Privacy Assessment and Authorization (SPAA) Handbook. The DOJ CISO must continually evaluate the DOJ risk management strategy to address the current threats to DOJ information systems and information.
DOJ components must use the iterative NIST SP 800-37 Revision 1, Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle
Approach, Risk Management Framework (RMF) steps zero through six as defined in the DOJSPAA Handbook to enforce the risk management process where security and privacy risks are assessed, responded to, and monitored in support of DOJ's ISCM activities. DOJ implements a three-tier ISCM approach to assess, analyze, prioritize, monitor, and report security and privacy risks at the information system, component, and DOJ levels. For contractor-managed information systems, such as hosting providers and Cloud Service
Providers (CSPs), components must ensure that all contracts include security and privacy clauses specifying the DOJ risk management and assessment and authorization requirements.
DOJ components must develop, monitor, and implement Plan ofActions and Milestones (POA&Ms) to correct information system deficiencies and reduce or eliminate vulnerabilities per the DOJPOA&MManagement Guide. DOJ component information system owners must use a POA&M to track and resolve vulnerabilities within an information system, component, or DOJ.
DOJ components must incorporate security and privacy system risks into the larger scope ofDOJ's Enterprise Risk Management (ERM).6 Effective ERM balances achieving security and privacy objectives with optimizing limited resources to manage risks, rather than addressing risks in silos.
H. Maintain System Inventory and Security and Privacy Authorization Documentation
The DOJ CISO must ensure that components identify and document each information system inventory in DOJ's Joint Cybersecurity Authorization Management (JCAM) application, the Department's enterprise record for security assessment and authorization. To effectively manage DOJ's FISMA inventory and automate reporting, components must associate information system assets to an information system authorization boundary. The components must certify the completeness and accuracy of their system inventory as stored in JCAM as part of the quarterly FIS MA CIO metrics data call submission.
I. Manage Supply Chain Risk Management Program
The DOJ CISO must ensure that components conduct supply chain risk assessments consistent with federal mandates, directives, and guidance. The DOJ Information and
Communication Technology Services (ICTS) Supply Chain Risk Management
(SCRM) Strategy7 documents the organization, resources, responsibilities, processes, and artifacts that guide the secure procurement, deployment, and implementation of
IT software, hardware, and services throughout the ICTS life cycle. The SCRM process must be a cooperative effort among procurement, cybersecurity, legal, IT operations, system stakeholders, and risk management officials.
J. Maintain Enterprise High Value Asset Governance
6 The DOJ Strategic Planning and Performance Staff manages the implementation of the ERM Program and leads the Department in the identification and management of enterprise risks that may have a significant impact on the performance and achievement of the Department' s strategic objectives and strategies.
7 The Department has two ICTS SCRM programs; one operated by CSS within JMD that supports all non-FBI components, and a second operated solely by the FBI (because of its status as a member ofthe U.S. Intelligence Community).
The DOJ CISO must ensure that components identify and maintain an inventory of all designated High Value Assets (HV As).8 DOJ components must complete security and privacy security control assessments for the information systems per the DOJ HV A Program to ensure the accuracy of information pertaining to the HV As' security and privacy posture. DOJ components must develop and prioritize remediation of vulnerabilities associated with HV As in accordance with the DOJ POA&M process.
K. Protects the Privacy of Individuals
While security and privacy are distinct disciplines, they are closely related.
Therefore, the DOJ CISO and CPCLO must ensure that DOJ components take a coordinated approach to identifying and managing security and privacy risks while complying with security and privacy requirements.
In implementing the Cybersecurity Program, components and DOJ as a whole must ensure that they identify privacy needs and requirements at the beginning of the SDLC and fund them appropriately. Further, DOJ components must integrate the NIST RMF with DOJ's privacy program requirements under DOJ Order 0601 , Privacy and Civil Liberties, May 14, 2020 (or its successor order), including the selection, implementation, assessment, and monitoring ofprivacy controls.
II. Information System Security and Privacy Requirements
The Justice Management Division's CSS has designed security and privacy controls to be technology neutral, focusing on the fundamental countermeasures needed to protect DOJ information and information systems. The security and privacy controls described in this Order apply to all DOJ information systems, information systems managed by contractors on behalfof DOJ, national security systems (NSS),9 and cloud services used by the Department.
DOJ information systems that process National Security Information (NSI) must meet additional requirements specified by the CNSS. DOJ information systems that process Sensitive Compartmented Information (SCI) must meet additional requirements established by the Office of the Director ofNational Intelligence (ODNI). If there is a
8 The HVA designation is not applicable to national security systems (NSS) as defined in FISMA (44 U.S.C.
§ 3552). Owners and operators ofNSS, which includes those systems critical to the execution ofmilitary, intelligence, and cryptologic operations, shall follow all CNSS issuances, as well as Department of Defense (DoD) or IC guidance regarding the protection of sensitive information and systems with respect to NSS. If a situation arises whereby designating a system satisfies the conditions of both an NSS and HV A, the system shall be designated an
NSS.
9 NSS shall include those systems defined as NSS in 44 U.S.C. § 3552(b)(6) as well as all other Department of Defense and Intelligence Community systems, as described in 44 U.S.C.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .