A19_RFP Amendment 2_Computer Security Handbook.docx
DOCX document 33 KB Posted
- Attached to
- Site Exposure Matrices (SEM) Scientific and Technical Services Federal contract opportunity
- Solicitation number
- 1605C3-25-R-00002
About this file
This document is a Department of Labor (DOL) Computer Security Handbook detailing comprehensive policies and procedures for safeguarding sensitive data, particularly Personally Identifiable Information (PII). The handbook establishes rigorous protocols for protecting sensitive information across DOL agencies, including requirements for encryption, remote access, media transportation, authentication, and incident response. Key provisions include mandating two-factor authentication for remote system access, full device encryption for portable systems, strict guidelines for transmitting sensitive data, and annual reporting requirements for agency heads to certify PII protection measures.
The document outlines specific responsibilities for various DOL officials, including the Senior Agency Official for Privacy, Chief Information Officer, Chief Information Security Officer, and individual users. It emphasizes a multi-layered approach to data protection, covering technological safeguards, personnel training, access controls, and incident management. The handbook applies to all DOL information systems, external hosted systems, and encompasses data from federal, state, local government partners, and private sector entities, with penalties for non-compliance and clear guidelines for handling sensitive information throughout its lifecycle.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| A19_RFP_Attachment 3 - Pricing Template Updated.xlsx | XLSX spreadsheet | |
| A19_RFP_Amendment 2_Vendor_Questions and Answers.xlsx | XLSX spreadsheet | |
| A19_RFP_Amendment 2.pdf | ||
| A19_RFP_Amendment 1.pdf | ||
| A19_RFP_Attachment 4 - Wage Determination.pdf | ||
| A19_RFP_Attachment 3 - Pricing Template.xlsx | XLSX spreadsheet | |
| A19_RFP_Attachment 1 - Vendor Questions Template.xlsx | XLSX spreadsheet | |
| A19_RFP_Attachment 5 - Subcontract Plan Template.docx | DOCX document | |
| A19_RFP_Attachment 2 - PPQ.pdf | ||
| A19_RFP_1605C3-25-R-00002.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
1100 Safeguarding Sensitive Data Including Personally Identifiable Information
1101 Purpose This chapter establishes policy guidance and responsibilities for the safeguarding of agency sensitive data including, but not limited to personally identifiable information (PII) that is accessed, processed, transported, or stored on end-user computing devices and portable media.
1102 Scope
1. The policy guidance and responsibilities contained in this chapter apply to:
0. All data held, used, or owned by the Department of Labor (DOL), including data that has been provided to, or supplied by, federal, state and local government partners and the private sector in the conduct of DOL business;
0. All DOL information systems
0. All information systems that store DOL externally hosted information pursuant to a contract, subcontract, or other agreement;
0. All DOL agencies, bureaus, offices, and users as defined in Section 1207.
This chapter is solely intended to prescribe safeguards for protecting sensitive information. It is not intended to set policy regarding the withholding or disclosure of sensitive data in litigation, under various statutes, or in response to court/tribunal requirements or orders, or congressional requests.
Nothing in this chapter shall limit in any way or otherwise contravene the authority or independence of the Office of Inspector General as set forth in the Inspector General Act of 1978, as amended.
1103 Policy It is DOL policy to ensure consistent, department-wide compliance with the Office of Management and Budget (OMB) mandates and all Federal legislation applicable to the protection of sensitive data and implementing regulations. OMB has established requirements for Federal agencies that inform and are supplemented by this chapter.
1104 Penalties and Remedies The Privacy Act of 1974 provides for both criminal penalties against individuals and civil remedies against agencies.
1105 Background Federal Agencies are required to take aggressive measures to mitigate the risks associated with the collection, storage and dissemination of sensitive data including PII. In today's information-driven economy, Federal agencies create, collect, use, process, store, maintain, disseminate, disclose, and dispose of unprecedented volumes of sensitive data including PII. Agencies increasing rely on information technology to more efficiently collect and process information and to make informed decisions. Federal information systems are increasingly the targets of sophisticated attacks by actors who want to sell or trade stolen sensitive information including PII on criminal exchanges or use the information for other malicious purposes. This has the potential to place sensitive information at risk and to pose serious threats to individuals and Federal operations and assets and privacy.
1106 Authorities and References
1. 2014 (35 U.S.C. 3541)
1. Civil Rights Act of 1964 (42 U.S.C. § 21) as amended
1. Rehabilitation Act of 1973 (29 U.S.C. § 701) as amended
1. Privacy Act of 1974 (5 U.S.C. § 552a)
1. Paperwork Reduction Act of 1995. (44 U.S.C. §§ 3501-3520)
1. E-Government Act of 2002 (P.L. 107-347, 44 U.S.C. Chapter 36)
1. Federal IT Acquisition Reform Act, December 19, 2014.
1. H.R.624 - Social Security Number Fraud Prevention Act of 2017 - 115th Congress (2017-2018)
1. Procurement Integrity Act, 41 U.S.C. § 2102
1. Trade Secrets Act is 18 U.S.C. § 1905
1. Executive Order 13719 – Establishment of the Federal Privacy Council, February 20, 2016OMB Circular No. A-108, Federal Agency Responsibilities for Review, Reporting, and Publication under the Privacy Act, December 23, 2016
1. OMB Circular No. A-130, Managing Information as a Strategic Resource, July 28, 2016
1. OMB Memorandum M-17-12, Preparing for and Responding to a Breach of Personally Identifiable Information, January 3, 2017
1. OMB Memorandum M-16-24, Role and Designation of Senior Agency Officials for Privacy, September 15, 2016
1. OMB Memorandum M-03-22, Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002, September 30, 2003
1. OMB Memorandum M-01-05, Guidance on Inter-Agency Sharing of Personal Data - Protecting Personal Privacy, December 20, 2000
1. OMB Memorandum M-00-13, Privacy Policies and Data Collection on Federal Web Sites, June 22, 2000
1. OMB Memorandum M-99-05, Instructions on Complying with President's Memorandum of May 14, 1998, "Privacy and Personal Information in Federal Records,” January 7, 1999
1. President’s Memorandum on Privacy and Personal Information in Federal Records, May 14, 1998
1. National Institute of Standards and Technology (NIST) Special Publication 800-53 Rev 4,Security and Privacy Controls for Federal Information Systems and Organizations, April 2013
1. National Institute of Standards and Technology (NIST) Special Publication 800-122, Guide to Protecting the Confidentiality of Personally Identifiable Information, April 2010
1. DOL Cybersecurity Policy Portfolio (CPP)
1. DOL Computer Security Incident Response Capability Guide
1. DLMS 3 – Chapter 400 —DOL Property Management
1. DLMS 1 – Chapter 1000 – The Privacy Act of 1974 and Invasion of Privacy
1. DLMS 7 – Chapter 400 – Information Technology Security
1. DLMS 7 – Chapter 900 – Appropriate Use of DOL Information Technology
1. DLMS 7 – Chapter 1200 – Privacy Policy on Data Collection Over DOL Web Sites 1107 Definitions
1. Authentication. The process of verifying the authorization of a user, process, or device, usually as a prerequisite for granting access to resources in an IT system.
1. Authentication Token. A security device or object given to authorized users who keep them in their possession. The security device also referred to as a “card” or “token” is used to log in to the network, the security device or token may be read directly like a credit card, or it may display a changing number code that is typed in as the password or in addition to a primary password. USB-based tokens plug directly into the computer.
1. Authorizing Official (AO). The senior agency management official who is responsible for ensuring that all agency systems are authorized to operate in accordance with policies and procedures established by the Chief Information Officer (CIO). The AO is the senior agency official or an official designee appointed in writing with direct succession authority.
1. Encryption. The process of changing plain text into cipher text for the purpose of security or privacy.
1. FIPS 140-2 Compliance. Refers to products with cryptographic modules that have been tested and validated as meeting the requirements of FIPS 140-2. The cryptographic validation program was established by NIST and the Communications Security Establishment in 1995. U.S. Federal organizations must use validated cryptographic modules.
1. Information System. A discrete set of information resources organized for the collection, processing, maintenance, transmission, and dissemination of information, in accordance with defined procedures, whether automated or manual.
1. The Mission Owner (MO) also known as the business owner, is a senior official or executive within an organization with specific mission or line of business responsibilities. The MO establishes mission and business processes and the security and privacy protection needs for successful conduct.
1. Mobile Access. The ability to access an information system without being physically connected to a network, usually with a portable device that has a wireless interface.
1. Personally Identifiable Information (PII). As defined by OMB in Memorandum M-1717-12, “information which can be used to distinguish or trace an individual’s identity, such as their name, social security number, biometric records, etc. alone, or when combined with other personal or identifying information which is linked or linkable to a specific individual, such as date and place of birth, mother’s maiden name, etc..”. For purposes of this chapter, DOL makes these distinctions.
1. Non-Sensitive PII. PII whose disclosure cannot reasonably be expected to result in personal harm. Examples include first/last name; e-mail address; business address; business telephone; and general education credentials that are not linked to or associated with any protected PII.
1. Protected PII. PII whose disclosure could result in harm to the individual whose name or identity is linked to that information. Examples include, but are not limited to, social security number; credit card number; bank account number; residential address; residential or personal telephone; biometric identifier (image, fingerprint, iris, etc.); date of birth; place of birth; mother’s maiden name; criminal records; medical records; and financial records. The conjunction of one data element with one or more additional elements, increases the level of sensitivity and/or propensity to cause harm in the event of compromise.
1. Portable Media. Transportable devices that are capable of storing information but do not employ their own operating system. Examples of portable media are USB drives, external hard drives, optical drives, CDs, and DVDs. Portable Media could also be referred to as mobile devices.
1. Portable System. Transportable devices employing an operating system and capable of storing information. Laptops, cell phones, smartphones, and tablets are examples of portable systems.
1. Remote Access. The ability to access network resources from external locations outside the authorization boundary. Generally, this applies to the use of a computer, a modem or other communication link, and remote access software to connect to the network.
1. Sensitive Data. Information that requires protection due to the risk and magnitude of loss or harm that could result from inadvertent or deliberate disclosure, alteration, or destruction of the information. The term includes information whose improper use or disclosure could adversely affect the ability of DOL to accomplish its mission; proprietary information; records about individuals requiring protection under the Privacy Act; and information not releasable under the Freedom of Information Act. This definition is not intended to extend to all electronic documents (e.g. email messages, electronic media, digital copies, etc.) generated or received by DOL system users. Sensitive data contained in electronic documents must be protected in accordance with the level of risk posed, as documented in the system’s risk assessment.
1. Two-factor Authentication. Authentication protocols that require two independent methods for establishing identity and privileges. Common implementations of two-factor authentication are “something you know” (usually a password or Personal Identification Number (PIN)) as one of the two factors, and either “something you have” (a token) or “something you are” (a biometric) as the other factor.
1. Users. Persons who have been authorized to access DOL information, DOL information systems, or information systems provided for DOL use under contract, subcontract, or other agreement.
1108 Authorization to Access Sensitive Data Users are authorized to access sensitive data to the extent necessary to perform their duties and assigned job responsibilities. This chapter does not prohibit the Office of the Solicitor or the Office of the Inspector General from accessing sensitive data in order to carry out their responsibilities. Furthermore, the AO must authorize all data sharing of protected PII that is governed by Memorandums of Understanding (MOUs), Interagency Agreements (IAs), associated Interconnection Security Agreements (ISAs), and similar agreements.
1109 Usage of Sensitive Data on DOL Equipment
1. Information technology devices used to access or store protected PII and other sensitive data must either be the property of the government or government-authorized or leased, and must be configured to meet the requirements of this and other applicable policies. Written authorization from the agency AO is required in cases where use of government-owned equipment is not practical or possible. Cases requiring AO authorization include, but are not limited to:
0. Use of contractor-owned network devices for storage or remote/mobile access to a DOL system containing protected PII and other sensitive data;
0. Use of personally owned or public computers to access, handle, or store such data in mobile workforce arrangements;
0. Use of personally owned or public computers to access, handle, or store such data in emergencies such as pandemic and contingency operations.
1. The AO authorization of non-government equipment must:
1. Acknowledge the AO’s awareness of and acceptance of the risks inherent in using such equipment;
1. Describe how the agency intends to mitigate those risks and
1. Impose appropriate stipulations and rules of behavior.
The AO cannot authorize access to a system or application (e.g., universal applications) owned by another DOL agency, without the express approval of the owning agency.
1110 Usage of Sensitive Data on Portable Media Protected PII or other sensitive data must only be stored on portable media when necessary to meet business requirements as determined by the system owner and only for the duration of the specific business assignment for which the data is required. Storage media is affixed with a label and cover sheets detailing distribution limitations, handling caveats, and applicable security markings. Media labeling exemptions are identified in CPP Volume 10: Media Protection (MP).
1111 Protection of Media Devices and Their Data Protected PII and other sensitive data on portable media, also known as mobile devices, and portable systems issued by DOL must be protected with encryption. Portable systems, such as laptops, require full device encryption, preferably at Basic Integrated Operating System (BIOS) or Extensible Firmware Interface (EFI) level (i.e., activated during boot-up). All portable media, such as flash drives, CDs, DVDs, writable optical media, and external hard drives that will store protected PII or other sensitive data, must be encrypted. All selected encryption products at DOL must use FIPS 140-2-validated cryptographic modules in approved modes of operation.
Use of any portable system or media without encryption must be approved in writing by the Deputy Secretary of Labor or an official designee. In accordance with the process outlined in the DOL CPP, data on the portable system or media must be determined, in writing, to be non-sensitive before approval will be granted by the Deputy Secretary or the official designee. Agencies seeking an exemption to the encryption requirement must follow the process contained in the DOL CPP.
All reasonable measures will be taken to ensure that portable media containing protected PII and other sensitive data are stored inside a secured area during periods when the media is not in transit or in active use.
1112 Transportation of Portable Media Containing Sensitive Data Portable media containing protected PII or other sensitive data may be transmitted by the United States Postal Service or another DOL-authorized delivery service if media is encrypted to DOL standards and packaged in a container that is sufficiently sealed to prevent inadvertent opening and to show signs of tampering. The decryption key must not be included in the same package, but transmitted via a separate or alternate channel. The package must be sent via an authorized delivery service with an ability to track pickup, receipt, transfer, and delivery. Consult the DOL CPP for additional protections that may be required depending on data sensitivity.
In addition, such media may be transmitted by DOL interoffice mail provided it be packaged to afford sufficient protection against inadvertent access.
1113 Use of E-mail and File Transfer Protocol (FTP) Agencies are required to establish and enforce risk-based policies pertaining to the use of electronic mail or network transfer protocols to transmit protected PII or other sensitive data outside of DOL network boundaries. Appropriate technologies such as cryptography and Secure transfer protocols must be considered in cases where there is a documented business need to handle sensitive data via e-mail or transfer protocols. Electronic transfers of protected PII and other sensitive data outside of DOL network boundaries must be encrypted.
Agencies are encouraged to append a standard disclaimer notice to outgoing e-mail messages to notify recipients that the message, and any files transmitted with it, are confidential and intended solely for the use of the individual or entity to whom they are addressed; that the DOL sender should be notified if a message is received by mistake; and that the unintended recipient is prohibited from disclosing, copying, or disseminating a message that is received in error. Example for an email disclaimer: The information transmitted is intended only for the person or entity to which it is addressed and may contain confidential and/or privileged material. Any review, retransmission, dissemination or other use of, or taking of any action in reliance upon, this information by persons or entities other than the intended recipient is prohibited. Notify sender if this email was received in error.
Users are prohibited from using e-mail to send protected PII outside of DOL without encrypting it within an attachment or insecure transfer protocols to circumvent the safeguards in this chapter pertaining to the transmission, use, and storage of protected PII and other sensitive data.
1114 Sanitization or Destruction of Portable Media Containing Sensitive Agency Data Media containing protected PII or other sensitive data must be sanitized or destroyed before disposal or release for reuse, in accordance with the DOL CPP.
1115 Logging and Verification of Data Extracts Computer-readable database extracts containing protected PII or other sensitive information must be logged following the procedures established in the DOL CPP. Each data extract found in a database containing PII or other sensitive information must be verified to ensure sanitization or destruction within 90 days unless it is still required for use.
1116 Remote Access to DOL Systems Remote access to protected PII and other sensitive data must be safeguarded using a secure encrypted channel that is FIPS 140-2 compliant.
DOL remote access systems must be configured to prevent caching of protected PII and sensitive information. In addition, all implementations that allow remote access must be configured to prevent copying and downloading of such data unless authorized in writing by the AO and required for business reasons.
All implementations of remote access and mobile devices must employ a “time-out” function requiring user re-authentication after 30 minutes of inactivity.
1117 Two-Factor Authentication Remote access to DOL systems must be authenticated using two factors. One of the two factors must be separate from the computing device.
1118 Annual PII Report from Agency Heads DOL senior agency officials are required to provide an annual report to the Senior Agency Official for Privacy certifying that they have conducted a review of their processes, procedures, and systems to ensure that PII is protected by adequate security safeguards. Senior Agency Officials must conduct a review of the agency’s inventory of systems that contain such information and confirm that security controls for its protection are properly implemented. This annual report must also include a review of the agency’s access to and management of PII. The templates and schedule for the report will be provided to the agencies by the OCIO.
1119 Collection and Use of Social Security Numbers (SSNs) For new information systems initiated subsequent to the issuance of this Chapter, agency programs shall collect, use, maintain, and disseminate SSNs only when required by law (e.g., statute, regulation, or upon approval of the SAOP or designated SAOP designee). In the absence of this SAOP approval of or a law authorizing the use of an SSN, agency programs shall not collect or use an SSN as a unique identifier; rather, programs shall work to create their own unique identifiers to distinguish or link information concerning an individual.
1120 Responsibilities
1. The protection of PII and other sensitive data depends on the involvement of all DOL agencies and departmental offices that acquire, develop, operate, or replace information systems components. Agencies and offices must participate in the formulation and approval of DOL policies, implementation directives, requirements, procedures, and controls. Agencies, offices, and personnel must carry out responsibilities as follows:
0. The Secretary is responsible for ensuring that privacy interests are protected and that PII is managed responsibly within DOL. The Secretary designates the Senior Agency Official for Privacy (SAOP) who is responsible and accountable for ensuring compliance with applicable privacy requirements, managing privacy risk, and DOL’s Privacy Program.
0. The Senior Agency Official for Privacy (SAOP) has the following responsibilities with respect to the Department’s Information Privacy Program:
1. Manage DOL implementation of information privacy protections, including full compliance with federal laws, regulations, and policies relating to information privacy, to include requirements under the Privacy Act.
1. Oversight, coordination, and facilitation of DOL privacy compliance efforts.
1. Require that all DOL employees and contractors receive appropriate training and education programs regarding the information privacy laws, regulations, policies, and procedures governing the handling of personal information.
1. Approves the Information Privacy controls contained within the system security plans as part of the Security Assessment and Authorization process.
1. Engage in close collaboration internally with key offices to ensure that the privacy program’s mission is integrated into the organization’s efforts to protect and secure PII.
1. Coordinates with the CIO, CISO, the Solicitor’s Office, records management, and other organization officials who have a role in protecting and safeguarding PII.
0. The Chief Information Officer (CIO) must develop and implement the department-wide program for protecting PII and other sensitive data and ensure that agencies develop and implement agency-specific programs for protecting PII. The CIO must issue additional policies, procedures, and guidance through other documents such as, but not limited to, the DOL CPP. The CIO must carry out the following responsibilities:
2. Incorporate safeguards for the protection for PII and other sensitive data into DOL’s Security Program.
2. In a collaborative manner with DOL agencies, develop and/or oversee development of the following as they relate to protected PII and other sensitive data:
1. Information technology policies;
1. Standards, plans, and guidance;
1. Architectures and concepts of operation;
1. Procedures, processes, and methodologies to ensure information that is stored, disseminated, or transmitted by DOL-owned information systems or by other systems provided for DOL use under contract or subcontract is properly safeguarded against unauthorized access, use, modification, or destruction, through the integration of management, operational, and technical controls; and
1. Independent verification and validation of the Senior Agency Official’s annual PII report to ensure the protection of sensitive information (e.g., personal health information, financial information, etc.).
0. Ensure issuance of implementation directives in support of this chapter and in concert with DOL agencies.
0. Manage all DOL protected PII and other sensitive data program elements, including policy formulation, policy compliance, program evaluation, awareness, and threat analysis.
0. Require that agency officials provide an annual report certifying that the agency has conducted a review of processes, procedures, systems, inventory, security controls and access management to ensure that PII is protected by adequate security safeguards.
0. Ensure that all information system acquisition and contracting actions, including service life extension and decommissioning activities, comply with DOL policy as it pertains to protected PII and other sensitive data protection.
0. Ensure that protected PII and other sensitive data requirements and cost estimates are addressed in the DOL capital investment planning process throughout each system's life cycle.
0. In consultation with the Office of the Solicitor, oversee development of DOL procedures for managing access to protected PII or other information determined to be sensitive, including procedures that require:
8. Review of the sensitivity of information entered, accessed, processed, transmitted, or stored on DOL information systems;
8. Approval of new information systems, initiated subsequent to the issuance of this Chapter, which propose to collect, use, maintain, and disseminate SSNs;
8. Issuance of guidelines regarding access to sensitive systems-based information;
8. Issuance of guidance about how to apply personnel security requirements in accordance with federal laws and regulations;
8. Consultation, as appropriate, with the Office of the Solicitor prior to the release of sensitive information.
0. Ensure risks and other implications resulting from technology or budget changes are communicated to DOL agencies and offices.
0. Ensure that DOL personnel receive adequate training in their responsibilities for protecting PII and other sensitive data for general awareness and privacy training to include role-based training requirements.
1. The responsibilities of Senior Agency Officials are as follows:
1. Comply with the requirements of the DOL CPP as they pertain to protected PII and other sensitive data.
1. Develop and implement information security procedures and mitigating controls sufficient to afford security protections commensurate with the risk and magnitude of harm resulting from unauthorized disclosure, disruption, modification, or destruction of protected PII and sensitive information.
1. Assign duties to safeguard protected PII and other sensitive data to qualified agency personnel.
1. Include security requirements for protected PII and other sensitive data in the agency’s IT capital investment planning and management process as required by the DOL Guide to IT Capital Investment Management.
1. Ensure that the requirements of the Privacy Act and other laws protecting sensitive information are incorporated into the Agency Cyber Security Program.
1. Ensure that IT personnel, new employees and system users receive general awareness role based training in protecting PII and other sensitive data.
1. Grant access to protected PII and sensitive information only to appropriate personnel (in accordance with applicable law or regulation, or DOL policies and procedures) who meet the requirements of the Agency’s System Security Plans and comply with guidance provided by the CIO.
1. Address security requirements for protected PII and other sensitive data, and their associated cost estimates, in any DOL acquisition management system and throughout the life cycle for systems and services, including service-life extension and decommissioning activities.
1. Ensure that computer incident response capability is implemented for handling incidents involving the compromise or loss of protected PII and other sensitive data, in accordance with DOL policy, the DOL CPP, and NIST Special Publication 800-61, Computer Security Incident Handling Guide.
1. Ensure that all agency personnel, contractors, and subcontractors at any tier working for, or on behalf of, the agency take security measures commensurate with the sensitivity level of the data and the risk management required and in compliance with applicable regulations and terms of DOL contracts.
1. Apply measures to assure the confidentiality of protected PII and other sensitive information that is transmitted between geographically separated facilities.
1. Ensure that all remote access to systems employs two-factor authentication in accordance with this chapter and the DOL CPP.
1. Ensure that all portable systems and media are equipped with the appropriate encryption technology in accordance with this chapter and the DOL CPP. Where need exists to issue equipment without encryption, ensure that the affected data is non-sensitive, and that justification for the exception is appropriately documented and forwarded to the Deputy Secretary of Labor or designee for approval.
1. Ensure that the agency identifies, inventories, and reports to the CIO all portable systems within its control. An inventory and reconciliation of all portable systems should be done at least annually as part of the Agency’s requirement to inventory and reconcile accountable property in accordance with Section 110 of DLMS 3-400, DOL Property Management.
1. Maintain and update the inventory of agency information technology systems that contain sensitive data.
1. Certify in an Annual Report to the CIO that the Agency has:
15. Reviewed its processes, procedures, and systems to ensure that PII and sensitive information is protected by adequate security safeguards.
15. Reviewed its inventory of systems that contain PII and sensitive information and confirmed that security controls for the protection of this information are properly implemented.
15. Reviewed its access and management of PII and sensitive information.
1. The Solicitor of Labor is responsible for providing legal advice and assistance for activities under this chapter.
1. The Chief Information Security Officer (CISO) is responsible for leading DOL Security Incident Response and managing all incident-related activities. These activities are as follows:
3. Respond immediately to a reported incident of the theft or loss of PII (both protected and, as appropriate, non-sensitive PII such as first/last name) or other sensitive data and report to US-CERT within one hour of incident discovery.
3. Coordinate with Office of the Inspector General, Department Senior Management, Office of the Solicitor, or other DOL or Federal agencies for the identification and investigation of any reported incident involving the loss or theft of PII or other sensitive data as described in the DOL CPP.
3. Provide support as required to assist in reporting, tracking and resolving incidents that involve the loss or theft of PII.
3. Coordinate DOL technical resources required for the identification and development of mitigations strategies to appropriately address incidents and vulnerabilities involving loss or theft of PII.
3. Document and maintain all incidents and vulnerabilities involving loss or theft of PII that are reported under Departmental procedures and guidance.
3. Develop, maintain and publish procedures required for handling incidents that involve portable media.
3. Disseminate to all DOL agencies the lessons learned from specific incidents involving loss or theft of PII.
3. Develop, maintain, update, and publish a template for annual reporting by Senior Agency Officials on privacy and security information as outlined in Section 1218.
3. Maintain and update the inventory of all DOL IT systems that contain sensitive data.
3. Facilitate, coordinate, and track computer security awareness and training for users as well as role-based training relative to PII usage and responsibilities.
3. Carry out any other duties designated by DOL policy.
1. The designated agency Information Security Officers are responsible for implementing and maintaining their agencies’ information security program, applying DOL information security policy, leading their respective agency’s Computer Security Incident Response Team (CSIRT) activities, and managing all incident activities at their agency’s level, as follows:
4. Respond immediately to a reported incident involving PII (both protected and, as appropriate, non-sensitive PII such as first/last name) or other sensitive data and report to DOL CSIRC immediately or within an hour of incident discovery.
4. Coordinate with the DOL Chief Information Security Officer (CISO), the Office of the Inspector General and Agency Senior Management, and as directed by the CISO, coordinate with the Office of the Solicitor, or other Federal agencies for the identification and investigation of any reported security incident or of an individual or group of individuals responsible for compromising PII and other sensitive data.
4. Provide support to their agencies, as required, in reporting, tracking and resolving such incidents.
4. Coordinate their agencies’ technical resources required for the identification/development of mitigations to incidents and vulnerabilities involving loss of theft of PII.
4. Document and maintain all security incidents and vulnerabilities involving loss or theft of PII that are reported under Departmental procedures and guidance.
4. Develop, maintain, and publish procedures required for their respective agencies in regards to reporting and handling portable system and portable media incidents.
4. Forward Security Incident Advisories to individuals responsible for affected systems, and report actions to the DOL Computer Security Incident Response Capability.
4. Carry out any other duties designated by DOL policy and DOL-approved agency policy.
1. The Component Privacy Officer (CPO) SAOP:
5. Agency-wide responsibility for information privacy issues.
5. Identifying agency information systems that contain Personally Identifiable Information (PII), and ensure the confidentiality of PII.
5. Ensuring agency implementation of DOL information privacy protections, including full compliance with federal laws, regulations, and policies relating to information privacy, including the Privacy Act.
5. Ensure agency implementation of DOL information privacy protections, including full compliance with federal laws, regulations, and policies relating to information privacy, including the Privacy Act.
5. Agency oversight, coordination, and facilitation of DOL privacy compliance efforts.
5. Ensure agency employees and contractors receive appropriate training and education programs regarding the information privacy laws, regulations, policies, and procedures governing the handling of personal information.
1. The Director, Civil Rights Center, OASAM, must:
6. Apply the necessary internal controls and safeguards defined by applicable law to DOL sufficient to afford security protections to preclude unauthorized disclosure, modification, or destruction of protected PII and other sensitive information.
6. Require DOL grantees to establish policies and procedures that provide a reasonable guarantee of compliance to protect and safeguard PII and confidential information.
6. Ensure that the requirements of the Privacy Act and other laws protecting PII and sensitive information are incorporated into Equal Employment Opportunity training courses for DOL managers and supervisors.
1. The Director, Human Resources Center, OASAM, must:
7. Apply personnel program security procedures defined by applicable law to DOL personnel accessing information systems and sensitive data.
1. Contracting Officers must:
8. As prescribed or permitted by the Federal Acquisition Regulation, include a provision in all solicitations and contracts indicating that, in addition to systems and information at DOL facilities, chapter DLMS 7-1100 applies to all non-DOL equipment and systems (including equipment and systems of contractors and subcontractors at any tier) that store, process, or transmit DOL sensitive information. Similar provisions shall be flowed down to subcontracts at any tier.
8. Incorporate functional and assurance requirements for PII and other sensitive data in information system procurement documents (solicitation and contracts) in accordance with this chapter and as prescribed or permitted by the Federal Acquisition Regulation.
8. In accordance with Federal procurement laws and regulations, require prime contractors, subcontractors at any tier, to comply with requirements of the DOL personnel security program as defined by applicable law, regulation, or policy, prior to accessing information systems or other assets determined to be sensitive.
8. Ensure that contractors working under existing and future DOL contracts involving IT information resources and portable media subject to this chapter comply with provisions of the Privacy Act and other legal requirements governing sensitive information and the terms of DOL contracts.
8. Ensure that PII for contract employees is protected during the “enter on duty” and separation processes.
1. Users must comply with this chapter and those of the following subordinate guides Cybersecurity Strategic Program Plan (CSSP), Agency Security Program Plans, System Security Plans, and the DOL CPP. They must also apply the following DOL security practices to daily work activities:
9. It is the responsibility of individual users to protect the PII and other sensitive data to which they have access.
9. Users must adhere to the rules of behavior defined in applicable System Security Plans, DOL and agency guidance, and DLMS 7-900, Appropriate Use of DOL Information Technology.
9. Users are prohibited from the unauthorized uploading, downloading, access, use, transmittal, copying, reproduction, erasure, or modification of information the Federal government deems to be sensitive or containing PII.
9. Users must protect their passwords against unauthorized access.
9. Users must not allow anyone else to use or share their:
4. User ID;
4. Password;
4. Cryptographic key;
4. Digital certificate;
4. Authentication token.
9. Users are responsible for complying with DOL computer security policies at all off-site locations such as residences when working in a Flexi-place arrangement.
9. In the event of the loss or theft of portable media or portable system containing PII (both protected and, as appropriate, non-sensitive PII such as first/last name) or other sensitive data, the user must immediately report the incident to the applicable ISO and take any additional steps as instructed by the ISO.
1. The Mission Owner (MO) also known as the business owner, is a senior official or executive within an organization with specific mission or line of business responsibilities. The MO establishes mission and business processes and the security and privacy protection needs for successful conduct.
1. System Owners are the individuals or entities responsible for establishing the rules for appropriate use and protection of the data and information within a system. They must take appropriate actions to:
11. Ensure that their systems, technical personnel, and users comply with all applicable legal requirements, including the Privacy Act, as well as their Agency’s Computer Security Program Plan, the System Security Plan, and the DOL CPP.
11. Report portable media and portable system incidents in accordance with the System Security Plan, the Agency Computer Security Program Plan, and the DOL CPP. In addition, system owners must cooperate with incident response team members as guided by the Agency ISO and the AO.
Last updated: February 15, 2023
File details come from the government source that posted it. Updated .