2.2.1 Attachment H FEMA IT Security Directive_FD 140-1.pdf

PDF 618 KB Posted

Attached to
CONUS Vehicle & Equipment Maintenance Federal contract opportunity
Solicitation number
70FB7023R00000012
Issued by
Federal Emergency Management Agency

About this file

This document outlines the Federal Emergency Management Agency's Information Technology Security Policy Directive 140-1. The directive establishes policies and assigns responsibilities to ensure the confidentiality, integrity and availability of FEMA's IT resources and sensitive data. It applies to all FEMA employees, contractors and IT systems owned, operated or leased by FEMA.

The directive requires all individuals to acknowledge and comply with rules of behavior for system access and use. It also mandates security training, reporting of incidents, removal of system access for separated employees and contractors, and more. Specific responsibilities are outlined for employees, supervisors, senior leadership, the CIO, CISO, system owners, administrators and other roles to implement controls around access management, configuration management, incident response and more. The directive references related DHS policies and directives and supersedes prior FEMA directives and instructions on related topics.

View the file

Other files for this federal contract opportunity

Other files attached to CONUS Vehicle & Equipment Maintenance, newest first.
File Type Posted
RFP No.- 70FB7023R00000012 Q&A.xlsx XLSX spreadsheet
2.2.1 Attachment M Service Contract Wage Determination (2023-06-30)_DC Atlanta.pdf PDF
2.2.1 Attachment F Facility Access Directive_FD 121-3.pdf PDF
2.2.1 Attachment C Equipment List (Fort Worth)_2023-06-01.xlsx XLSX spreadsheet
2.2.1 Attachment C Equipment List (Atlanta)_2023-06-01.xlsx XLSX spreadsheet
2.2.1 Attachment M Service Contract Wage Determination (2022-12-27)_DC Tracy.pdf PDF
2.2.1 Attachment I Personal Identification and Verification Guidance_ FEMA Directive 121-1.pdf PDF
2.2.1 Attachment G Contractor Fitness Security Screening Request Form_DHS Form 11000-25.pdf PDF
2.2.1 Attachment C Equipment List (Tracy)_2023-06-01.xlsx XLSX spreadsheet
2.2.1 Attachment C Equipment List (Greencastle)_2023-06-01.xlsx XLSX spreadsheet
2.2.1 Attachment A Performance Work Statement_2023-07-18 Final.pdf PDF
2.2.1 Attachment M Service Contract Wage Determination (2023-06-30)_DC Greencastle.pdf PDF
2.2.1 Attachment L Motor Vehicle Accident Report_SF-91.pdf PDF
2.2.1 Attachment K Quality Assurance Monitoring Form_2023-03-13.pdf PDF
2.2.1 Attachment E Past Performance Questionnaire.docx DOCX document
2.2.1 Attachment B Quality Assurance Surveillance Plan_2023-07-18.pdf PDF
2.2.1 70FB7023R00000012 7-18-2023.pdf PDF
2.2.1 Attachment M Service Contract Wage Determination (2022-12-27)_DC Fort Worth.pdf PDF
2.2.1 Attachment J QASP Customer Compliant Investigation Form_2023-03-13.pdf PDF
2.2.1 Attachment D Pricing Template 2023-07-08.xlsx XLSX spreadsheet
Show all 20

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Federal Emergency Management Agency (FEMA) Directives System Directive Number: FD 140-1

Issue Date: 01/14/2012

FEMA INFORMATION TECHNOLOGY SECURITY POLICY

I. Purpose

The Federal Emergency Management Agency (FEMA) recognizes the need to balance operational requirements with putting in place controls to protect data and Information Technology (IT) resources. These controls are designed to ensure the confidentiality, availability and integrity of the FEMA Enterprise Network (FEN), sensitive data and IT resources in support of FEMA's mission. This need for balance, however, is especially crucial as the Agency assimilates new technologies and employees use these technologies in innovative ways to address the demands of a dynamic mission environment. FEMA IT Security recognizes that traditional cyber security practices can neither keep pace with a rapidly evolving technological environment, nor should they be allowed to stifle innovation. And most importantly, this directive recognizes that individual employees are the most important control factor in protecting data and IT resources. Supervisors, senior leadership, and technical controls are important, but every FEMA employee or contractor can be targeted at any given time by cyber threats. For this reason we all have a shared responsibility in protecting FEMA's network. The FEMA IT Security Directive 140-1, Version 2, complements the Department of Homeland Security (DHS) Sensitive Systems Policy Directive 4300A.

For intelligence systems, refer to DHS 4300C, Sensitive Compartmented Information (SCI) Systems. For National Security Systems (NSS) refer to the DHS National Security Systems Policy Directive 4300B. This Directive 140-1 requires implementation of the DHS Information Security Program through detailed standard operating procedures.

II. Scope

Personnel: This directive applies to all FEMA employees and contractors.

Systems: This directive applies to all IT resources whether owned, operated or leased by or on behalf of FEMA and whether located in a FEMA facility or at another site.

III. Policy and Procedures

The Responsibilities Section below constitutes the individual employee, supervisory and senior leadership controls and responsibilities for confidentiality, availability and integrity of all FEMA data and IT resources.

DIRECTIVE 140-1

IV. Responsibilities

A. Individual Employees and FEMA Contractors

1. Signing and acknowledging DHS/FEMA Rules of Behavior (RoB) for system access and use of IT resources.

are responsible for:

2. Using IT resources and protecting sensitive data as prescribed in the DHS Rules of Behavior (RoB), FEMA Email Policy and Guidance (located at http://on.fema.net/employee_tools/forms/Pages/Directives.aspx) and the FEMA Electronic and Hard Copy Media Sanitization and Release Standard Operating Procedure (SOP) (located at http://on.fema.net/components/msb/ocio/governance/Pages/OCIOSOPs.aspx).

This includes using encryption to send sensitive information via email and not using remote desktop connections, such as Microsoft’s Remote Desktop Protocol (RDP), without the use of an authentication method that employs secure authentication (two-factor, encrypted, key exchange, etc.).

3. Attending training as required for their level of privilege, access, and use of IT resources.

4. As a contractor, signing a Non-Disclosure Agreement promising to protect DHS and FEMA information.

5. Reporting known or suspected violations of RoB, or other security incidents, as specified in the IT Security Incident Management SOP located at http://on.fema.net/components/msb/ocio/governance/Pages/OCIOSOPs.aspx.

6. Taking prudent actions to minimize the negative impact of known or suspected violations of RoB, or other security incidents.

7. Reporting as soon as practicable to their supervisor their plan to separate from

FEMA.

8. Recommending innovations to their supervisor and to the FEMA Enterprise Architecture Board (EAB) in accordance with the New Technology Insertion SOP.

B. Supervisors and Contracting Officer’s Representatives (COR

1. Ensuring employees are scheduled for and attend training as required by their level of privilege, access, and use of IT resources.

) are responsible for:

2. Obtaining a signed Non-Disclosure Agreement (NDA) from all contractors.

3. Taking prudent actions to minimize the negative impact of known or suspected violations of RoB, or other security incidents.

4. Enforcing security policies and assessing employee adherence to security policies in annual performance evaluations.

5. Reporting information regarding employees and contractors who plan to separate from FEMA in accordance with the Employee and Non-Employee IT Access Removal Standard Operating Procedure (SOP) located at http://on.fema.net/components/msb/ocio/governance/Pages/OCIOSOPs.aspx.

6. Supporting, as necessary, recommendations to the EAB for innovation and for expanding them to an enterprise best practice or standard. Refer to the New Technology Insertion SOP.

http://on.fema.net/employee_tools/forms/Pages/Directives.aspx� http://on.fema.net/components/msb/ocio/governance/Pages/OCIOSOPs.aspx� http://on.fema.net/components/msb/ocio/governance/Pages/OCIOSOPs.aspx.�

C. Senior Leadership (directly or through delegation)

1. Promoting security awareness, education, themes, best practices, and policies to create an active security climate at FEMA.

is responsible for:

2. Ensuring that IT investments support security standards and controls to prevent the loss of data or IT resources.

3. Assessing in annual evaluations supervisory performance with regard to security policies.

D. Chief Information Officer (CIO) (directly or through delegation)

1. Ensuring FEMA RoB and SOPs related to protecting data and IT resources are relevant and up-to-date.

is responsible for:

2. Overseeing FEMA’s IT security-related training.

3. Acting as the Authorizing Official (AO) for FEMA information systems or designate one in writing. Serve as the AO for any system where an AO has not been appointed or where a vacancy exists.

4. Reviewing and approving FEMA-level information system contingency plans.

5. Chairing the EAB.

E. Chief Information Security Officer (CISO)

1. Developing and maintaining a FEMA-wide information security program in accordance with Department policies and guidance.

(directly or through delegation) is responsible for:

2. Conducting an inventory and review of classified equipment and storage processes and procedures with the Program Offices to verify that appropriate security controls are in place.

3. Completing the reconciliation of the inventory results against the consolidated classified equipment listing.

4. Establishing, maintaining, and updating as needed FEMA RoB, security related SOPs, and other IT security governance processes to ensure that they support FEMA mission requirements and address implementation of the information security program.

5. Reviewing and approving ISSO appointments and ensuring their appointment for each information system managed by FEMA.

6. Ensuring that ISSOs and System Administrators and System Owners fulfill their security-related responsibilities.

7. Establishing a program of instruction for training that addresses level of privilege, access, and use of IT resources.

8. Ensuring that information security-related decisions and information, including updates to the 4300 series of information security publications, are distributed to the Information System Security Officers (ISSOs) and other appropriate persons within FEMA in a timely manner.

9. Providing “Threat-Vulnerability-Risk” analytic products, reports, and recommendations to Senior Leadership, Program Offices, and other operational entities within FEMA, such as the Network Operations Center (NOC) and Security Operations Center (SOC).

10. Exercising oversight over all FEMA information technology security operations functions, to include the FEMA Security Operations Center (SOC) and the FEMA firewall rule sets.

11. Ensuring prompt follow-up with FEMA Program Office stakeholders to convey the status and resolution of any security violation involving that office.

12. Ensuring that Interconnection Security Agreements (ISAs) are maintained for all connections between systems that do not have the same security policy.

13. Ensuring execution of the DHS Logging Strategy detailed in the DHS 4300A Sensitive Systems Handbook.

14. Maintaining an independent FEMA-wide Assessment Program to ensure a consistent approach to testing the effectiveness of controls and periodically testing the security of implemented systems.

15. Overseeing FEMA’s POA&M process for remediating known vulnerabilities.

16. Conducting periodic surveys to ensure RoB, security related SOPs, training, and analytic products are protecting FEMA data and IT resources, and are keeping pace with innovation and technological changes, and that enterprise security tools are utilized.

17. Validating and approving all FEMA information system security reporting and ensuring that weekly incident reports are submitted to the DHS Emergency Operations Center (EOC).

18. Overseeing the Security Authorization process for General Support Systems (GSSs) and Major Applications (MAs) in use within FEMA.

19. Keeping the CIO apprised of all pertinent matters involving the security of information systems.

F. System Owners (directly or through delegation)

1. Ensuring that key duties and responsibilities in authorizing, processing, recording, and reviewing official agency transactions are separated among individuals. See Annex A, Page 4, definition of Separation of Duties.

are responsible for:

2. Assessing risk to, and vulnerabilities of, agency IT resources under their purview periodically, and coordinating resolution of vulnerabilities with appropriate officials to control risk exposure.

3. Establishing, maintaining, and updating as needed, a Security Plan (SP), contingency plan, disaster recovery plan, and continuity of operations plan (COOP) and personally accrediting and authorizing the plans and the establishment, operation, change, and retirement of the IT resource if delegated by the Authorizing Official. Documenting the initial system configuration in detail and controlling all subsequent changes in accordance with the system’s Configuration Management Plan (CMP).

4. Ensuring funding and human capital to protect data and IT resources are included in the system life cycle budget.

5. Planning, designing, testing, implementing, and operating systems and technologies, whether new or updated, and ensuring the systems and technologies are incorporated into the IT strategy that supports the Agency’s Strategic Plan.

G. Information System Security Officers (ISSO)

1. Serving as the principal point of contact for all IT security aspects pertaining to their systems and the liaison between System Owners and the FEMA IT Security Branch.

are responsible for:

2. Adhering to the DHS Secure Baseline Configuration Guides.

3. Verifying that security controls are effectively implemented and that SOPs are documented, completed, maintained, and followed.

4. Ensuring compensating controls are in place where strict separation of duties cannot be fully implemented.

5. Validating that employee and contractor access is removed by System

Administrators upon notification in accordance with FEMA Employee and Non-employee IT Access Removal SOP located at http://on.fema.net/components/msb/ocio/governance/Pages/OCIOSOPs.aspx.

6. Working closely with FEMA’s IT Security Branch to apply IT security policies and implement procedures and document security weaknesses in Plans of Action and Milestones (POA&Ms).

7. Initiating and ensuring completion of corrective actions in POA&Ms.

8. Identifying actions to be audited and reviewing audit trail logs to identify un-authorized or suspicious activities, especially for administrator accounts and CFO Designated Systems at least monthly.

H. System and Database Administrators

1. Controlling access to sensitive software, utilities, and processes.

are responsible for:

2. Ensuring user access controls are in place and functioning.

3. Reviewing and updating access control lists after validation of access privileges by system owners and supervisors at least annually.

4. Removing or reducing an employee or contractor’s access to an IT system, as appropriate, when notified of separations (within the 10 business days or 48 hours with heightened risk as determined by the CISO).

I. Chief, Independent Verification and Validation Branch, OCIO

1. Ensuring and approving the development and maintenance of the FEMA Enterprise Configuration Management Plan (ECMP) located at

, (directly or through delegation) is responsible for:

http://on.fema.net/components/msb/ocio/governance/Pages/OCIOSOPs.aspx.

2. Ensuring the controlling, approving, documenting and tracking subsequent changes into the production environment in accordance with the ECMP.

3. Receiving and managing software and system changes through release management processes in conformance with the FEMA ECMP.

J. FEMA Security Operations Center (SOC) is responsible for:

1. Serving, within the DHS IT security incident response capability structure, as the primary FEMA IT security incident response, investigation, coordination, and reporting authority to the DHS SOC, as required in Authorities E., F., and G. and successor documents. See the Security Operations Center (SOC) SOP ver. 2.0, located at http://on.fema.net/components/msb/ocio/governance/Pages/OCIOSOPs.aspx for further responsibilities.

2. Distributing advisories on vulnerabilities received from the DHS SOC to the appropriate individuals within FEMA and alerting the FEMA Computer Security Incident Response Center (CSIRC), FEMA CISO, and DHS SOC to the possible existence of new vulnerabilities or incidents. Submitting weekly security incident reports to the DHS SOC. If the FEMA SOC has no incidents to report for a given week, a weekly “NO Incidents” report will be sent to the DHS SOC.

3. Consulting with the FEMA Privacy Office for reporting and handling of privacy incidents.

4. Consulting with the Chief Security Officer on reporting and handling of security incidents involving suspected/potential data spillage.

5. Reporting of vulnerability scanning activities to the DHS Emergency Operations Center as detailed in Attachment O, Vulnerability Management Program, of DHS 4300A Sensitive Systems Handbook.

6. Developing and maintaining a vulnerability assessment scan schedule.

7. Establishing and maintaining configuration baseline for firewall hardware and devices through the artifacts deposited in the Federated Configuration Management Database in conformance with the FEMA ECMP.

K. Chief, Operations Services Branch, OCIO, (directly or through delegation) is responsible for:

1. Establishing and maintaining a FEMA IT security incident management capability.

2. Developing written SOPs governing the duties, responsibilities, and activities of the FEMA SOC and the Enterprise Service Desk.

3. Ensuring that the CISO is informed on all reported IT security incidents.

4. Designating and training individuals to sanitize electronic media in accordance with FEMA Electronic and Hard Copy Media Sanitization and Release SOP located at http://on.fema.net/components/msb/ocio/governance/Pages/OCIOSOPs.aspx.

5. Resetting service account passwords biannually. Service accounts must be reset immediately if a user becomes separated from FEMA.

6. Implementing patches in a timely manner in accordance with DHS 4300A timeframes.

7. Establishing and maintaining configuration baseline for network and systems hardware and devices in conformance with the FEMA ECMP.

L. Chief Component Human Capital Officer (CCHCO) (directly or through delegation) is responsible for:

1. Completing and submitting a Separation Notice when it is determined that no

Separation Notice was received by the Office of the CCHCO. The Separation Notice will be submitted prior to notifying the National Finance Center of the separation.

2. Verifying with supervisors the dates of separation of employees when needed.

M. Assistant Administrator, National Continuity Programs (NCP), (directly or through delegation) is responsible for:

1. Controlling the official listing of classified equipment provided by the Chief Security Officer within the FEMA Headquarters’ Document Control facility, located in NCP. The following information will be provided on this official listing: name of the person accountable for the equipment, the make, model, serial number, US Government Bar Code, and general location of the item.

2. Collecting Business Process Analyses in the continuity planning process periodically from each Program Office so OCIO can update the critical systems identified by program offices.

N. Chief Procurement Officer (directly or through delegation) is responsible for:

1. Including in all contracts a requirement for the contractors to notify the CORs of any individual on the contract who is leaving the FEMA contract prior to his or her separation.

2. Including in all contracts language that requires a signed NDA (DHS 11000-6 Standard Non-Disclosure Agreement Form) from each of the contractor’s employees working under the contract. The contractor shall provide this signed NDA form each time a new employee is assigned to the contract.

3. Including requirements in contracts to address personnel, IT resource, and facility security in accordance with FEMA SOPs, e.g. FEMA Electronic and Hard Copy Media Sanitization and Release SOP and FEMA Employee and Non-employee IT Access Removal SOP.

4. Including in contracts a clause that requires the removal of hard drives from copiers and other IT equipment, leased or purchased, before return to the vendor.

O. Property Management Officers, Accountable Property Officers (APO), Custodial Officers (CO) are responsible for:

Coordinating the appropriate disposal of IT resources in accordance with FEMA Electronic and Hard Copy Media Sanitization and Release SOP located at http://on.fema.net/components/msb/ocio/governance/Pages/OCIOSOPs.aspx.

VI. Authorities

A. Public Law 104-106, Clinger-Cohen Act of 1996 [formerly, Information Technology Management Reform Act (ITMRA)], February 10, 1996.

B. Federal Information Security Management Act (FISMA) of 2002, November 25, 2002.

C. Office of Management and Budget (OMB) Circular A-130, Management of Federal Information Resources, revised November 28, 2000.

D. DHS Management Directive (MD) 0007.1 Information Technology Integration and Management, March 15, 2007.

E. DHS Sensitive Systems Policy Directive 4300A.

F. DHS MD 4300A, Sensitive Systems Handbook.

G. DHS MD 4300A, Attachment F, Incident Response and Reporting.

H. DHS MD 4300A, Attachment H, Plan of Action and Milestones Process Guide.

I. DHS MD 4300B, National Security Systems Handbook.

J. DHS MD 4300C, Sensitive Compartmented Information (SCI) Systems.

K. Privacy Act of 1974.

L. OMB M-06-15, Safeguarding Personally Identifiable Information, May 22, 2006.

M. OMB M-06-19, Reporting Incidents Involving Personally Identifiable Information and

Incorporating the Cost for Security in Agency Information Technology Investments, July 12, 2006.

N. General Accounting Office (GAO), Federal Information System Controls Audit Manual (FISCAM), January 1999, http://www.gao.gov/special.pubs/ai12.19.6.pdf.

O. DHS MD 4400.1, DHS Web (Internet, Intranet and Extranet Information) and Information Systems, March 1, 2003.

P. DHS MD 4900, Individual Use and Operations of DHS Information Systems/Computers.

Q. DHS MD 11042, Safeguarding Sensitive But Unclassified (For Official Use Only) Information, January 6, 2005.

R. DHS MD 11049, Protection of Classified National Security Information: Security Violations and Infractions, April 19, 2006.

S. DHS MD 4500.1, DHS EMail Usage, March 1, 2003.

T. FEMA Manual 1230.1, Safeguarding National Security Information, January 1992, rev. July 31, 2001, http://on.fema.net/employee_tools/forms/Pages/Directives.aspx.

V. Responsible Office:

Office of the Chief Information Officer

VIII. Supersession

A. FEMA Directive 140-1, IT Security Policy, 2008.

B. FEMA Instruction 1540.4, Sanitization and Release of Electronic Storage Media, October 7, 2006.

C. FEMA Instruction 1540.1, Management of Information Technology Security

Incidents, October 15, 2006.

D. FEMA Directive 136-1, Configuration Management for Projects with Information

Technology Content, March 26, 2008.

E. FEMA Manual 1500.1, FEMA Information Resources Management Policy and

Procedural Directive (FIRMPD), December 1999.

IX. References

A. DHS Sensitive Systems Policy Handbook 4300A, Attachment G, Rules of Behavior, version 7.0, August 7, 2009.

B. FEMA Email Policy and Guidance, November 29, 2010, http://on.fema.net/employee_tools/forms/Pages/Directives.aspx.

C. FEMA Electronic and Hard Copy Media Sanitization and Release SOP, June 30, 2011, http://on.fema.net/components/msb/ocio/governance/Pages/OCIOSOPs.aspx.

D. FEMA Employee and Non-employee IT Access Removal SOP, June 14, 2011 http://on.fema.net/components/msb/ocio/governance/Pages/OCIOSOPs.aspx.

E. Enterprise Architecture Technical Reference Model (TRM), http://on.fema.net/components/msb/ocio/aees/Pages/EnterpriseArchitecture.aspx.

F. FEMA Enterprise Configuration Management Plan, March 2011, http://on.fema.net/components/msb/ocio/governance/Pages/OCIOSOPs.aspx.

G. FEMA New Technology Insertion SOP.

H. FEMA Security Operations Center (SOC) SOP Ver. 2.0, September 26, 2011, http://on.fema.net/components/msb/ocio/governance/Pages/OCIOSOPs.aspx.

XI. Attachments

Annex A – Definitions

VI. Questions

Direct questions regarding this guidance to the OCIO, Attn: IT Security Branch.

http://on.fema.net/employee_tools/forms/Pages/Directives.aspx.� http://on.fema.net/components/msb/ocio/governance/Pages/OCIOSOPs.aspx.� http://on.fema.net/components/msb/ocio/aees/Pages/EnterpriseArchitecture.aspx� http://on.fema.net/components/msb/ocio/governance/Pages/OCIOSOPs.aspx.�

Annex A - Definitions

A. Authorizing Official (AO) - An official within a Federal Government agency who can grant approval for a system to operate.

B. Classified National Security Information - Information that has been determined, pursuant to Executive Order 12958, Classified National Security Information, as amended, or any predecessor order, to require protection against unauthorized disclosure and is marked to indicate its classified status.

C. DHS Chief Financial Officer (CFO) Designated Financial Systems - DHS CFO designated financial systems are systems that require additional management accountability and effective internal control over financial reporting.

D. Electronic Media - Electronic (or soft copy) media are the bits and bytes contained in hard drives, random access memory (RAM), read-only memory (ROM), disks, memory devices, phones, mobile computing devices, networking equipment, and many other types listed in NIST 800-88, Appendix A. Various types of media are magnetic media such as hard disk drives and diskettes; optical media such as CDs and DVDs; and solid-state storage media, including USB drives and cellular or smartphones. These media can have both primary storage (memory) as found in smartphones, copiers, and computers, and secondary storage such as on a hard disk or tape, as found in copiers, servers, laptops, and other devices.

E. Information Systems Security Officer (ISSO) - An ISSO may either be a Federal employee or an appropriately cleared contractor who is assigned to serve as the point of contact for IT security for their assigned systems and who implements and/or monitors security for a particular system. The ISSO works closely with the Chief Information Security Officer (CISO) to interpret and apply IT security policies. While the ISSO performs security functions, the system steward is always responsible for information system security.

F. IT System - FEMA IT systems include general support systems and major applications that are (1) owned, leased, or operated by or for FEMA, (2) operated by a contractor on behalf of FEMA, or (3) operated by another Federal, state, or local government agency on behalf of FEMA.

1. General Support System (GSS) - A GSS is an interconnected set of information resources under the same direct management control that share common functionality. A system normally includes hardware, software, information, data, applications, communications, and people. A GSS can be, for example, a local area network (LAN) including smart terminals that support a branch office, an agency-wide area backbone, a communications network, a departmental data processing center and its operating system and utilities, a tactical radio network, or a shared information processing service organization.

2. Major Application (MA) - A major application (MA) is an automated information system (AIS) that “requires special attention to security due to the risk and magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of the information in the application.” Note: All Federal applications require some level of protection. Certain applications, because of the information in them, however, require special management oversight and should be treated as major. An MA is distinguishable from a GSS by the fact that it is a discrete application, whereas a GSS may support multiple applications. Each MA must be under the direct oversight of the FEMA CISO/ISSM, and must have one or more Information Systems Security Officers (ISSO) assigned.

G. Personally Identifiable Information (PII) - Any information that permits the identity of an individual to be directly or indirectly inferred, including any information which is linked or linkable to that individual regardless of whether the individual is a U.S. citizen, lawful permanent resident, visitor to the U.S., or employee or contractor to the Agency.

Examples of PII include: office phone lists, colleague’s business cards, personal mailing addresses, personal telephone numbers.

H. Privacy Incident - The DHS Privacy Office defines a privacy incident as the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, unauthorized access, or any similar situation in which persons who are not authorized users have access or potential access to PII in usable form, whether physical or electronic, for a purpose that is not authorized.

I. Remote Access - Access to a DHS information system by a user (or an information system) communicating through an external, non-DHS-controlled network (e.g., the Internet).

J. Sensitive Information – Information, not otherwise categorized by statute or regulation (Sensitive Security Information and Critical Infrastructure Information), that if disclosed could have an adverse impact on the welfare or privacy of individuals or on the welfare or conduct of Federal programs or other programs or operations essential to the national interest. Examples of sensitive information include sensitive personal data such as social security number; system and computer security vulnerability and deficiency information; pre-solicitation procurement documents; and law enforcement investigative methods. All sensitive information must be protected from loss, misuse, modification, and unauthorized access. Each individual Federal agency designates its own terminology for sensitive information. “For Official Use Only” (FOUO) is the term used within DHS to identify unclassified information of a sensitive nature that is not otherwise categorized by statute or regulation. DHS is adopting the term “Controlled Unclassified Information” (CUI) in a phased implementation in 2012 under direction of the Executive Agent at the National Archives.

K. Sensitive Personally Identifiable Information (SPII) - Personally Identifiable Information, which if lost, compromised, or disclosed without authorization, could result in substantial in harm, embarrassment, inconvenience, or unfairness to an individual. The DHS standard for information that is always considered Sensitive PII even if not coupled with additional PII or contextual information includes: complete social security number (SSN), alien registration number (A-Number), and biometric identifiers (e.g., fingerprint, iris scan, voice print). The following information is considered Sensitive PII when coupled with the person’s name or other unique identifier, such as address or telephone number: citizenship or immigration status, medical information, driver’s license number, passport number, full date of birth, authentication information such as mother’s maiden name or passwords, portions of SSNs such as last four digits, and financial information such as account numbers.

L. Separation of Duties - A principle for dividing and separating duties and responsibilities of critical information system functions among different individuals to minimize the possibility that any one individual would have the necessary authority or system access to be able to engage in fraudulent or criminal activity.

M. System Owner - System Owner use information technology to help achieve the mission needs within their program area of responsibility. They are responsible for the successful operation of the information systems and programs within their program area and are ultimately accountable for their security. All systems require a System Owner designated in writing for proper administration of security. While the ISSO performs security functions, the System Owner is always responsible for information system security. There can be business and technical system stewards or the System Owner covers both areas. A business stewards is a management official to whom responsibility for an agency mission objective is assigned, typically a Branch Chief or Division Director, and who directs or controls the budget, personnel, and information resources to accomplish that mission. A technical steward is someone, other than the business steward, who performs as either a principal investigator or principal user of an information system or as the principal information technology professional responsible for the system, ensuring that the specified functional characteristics of the system are produced as authorized by the business steward. The technical steward is responsible for ensuring that systems and applications function in compliance with all appropriate IT laws, policies, and standards and in accordance with her or his organization’s protocols and procedures, as established in the applicable system Security Plan (SP).

N. Two-Factor Authentication - Authentication can involve something the user knows (e.g., a password), something the user has (e.g., a smart card), or something the user “is” (e.g., a fingerprint or voice pattern). Single-factor authentication uses only one of the three forms of authentication, while two-factor authentication uses any two of the three forms. Three-factor authentication uses all three forms.

I. Purpose
II. Scope
III. Policy and Procedures
IV. Responsibilities
VI. Authorities
V. Responsible Office:
Office of the Chief Information Officer
VIII. Supersession
VI. Questions

File details come from the government source that posted it. Updated .