Attachment_D.1_-_In_and_Out_Processing.pdf

PDF 577 KB Posted

Attached to
Compressor Air System Federal contract opportunity
Solicitation number
2017-Q-66803
Issued by
Department of Health and Human Services Centers for Disease Control and Prevention Pittsburgh

About this file

Attachment D.1 - In and Out Processing

View the file

Other files for this federal contract opportunity

Other files attached to Compressor Air System, newest first.
File Type Posted
Air_Compressor_System_Site_Visit_-_Q&As.pdf PDF
2017-Q-66803_-_RFP.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

The Centers for Disease Control and Prevention (CDC)1 has revised the

“In- and Out -Processing of CDC Employees, Non-employees, and Affiliates” Policy.

1. Reason for Revisions: This Operational Policy has been revised to include the requirements of the Homeland Security Presidential Directive 12 (HSPD-12) of August 27, 2004 that calls for a mandatory, government-wide standard of identification. The policy updates requirements for in- and out -processing of staff and provides more information on key issues CIOs must consider

2. Summary Of Policy: This revised policy covers the general requirements to achieve the following:

• Accountability for security, property, and financial issues as related to in-and out-processing

• Compliance with records management laws and regulations

• Proper management of logical access to CDC networks

• Proper and secure physical access to CDC campuses, buildings and facilities and other assets

• Accountability for CDC property

• Timely information transfer

3. Related Issuances: None

4. Responsible Officials: The Management Information Systems Office (MISO)

5. Material Superseded: In- and Out -Processing of CDC FTE’s, PSCs, Contractors, and

Other Non-FTEs Policy, dated June 1999

6. Recertification: This document is scheduled for recertification on or before the last working day of July 2018

7. Points of Contact: Teresa Kinley, Management Information Systems Office (MISO) 770-

488-5933 and Tonya R. Johnson, Policy Analyst, Management Analysis Services and Office, 770-488-4771

To go directly to the policy, click on the link below or enter the following URL into the location line of your browser.

http://aops-mas-iis.cdc.gov/Policy/Doc/policy510.pdf

Sherri A. Berger, M.S.P.H.

Chief Operating Officer

1 References to CDC also apply to the Agency for Toxic Substances and Disease Registry (ATSDR) http://www.whitehouse.gov/omb/e-gov/hspd12_reports/ http://aops-mas-iis.cdc.gov/Policy/Doc/policy510.pdf

CATEGORY: General Administration

CDC-GA-2007-01

DATE OF ISSUE 3/2/2007; REVISED:9/17/2007; REVISED 07/10/2013

PROPONENTS: Office of the Chief Information Security Officer, Management Information Systems Office (MISO)

IN- AND OUT-PROCESSING OF CDC EMPLOYEES, NON-EMPLOYEES AND

AFFILIATES

SECTIONS: 1. PURPOSE AND SCOPE

2. BACKGROUND

3.

4.

POLICY

RESPONSIBILITIES

5. REFERENCES

6. ABBREVIATIONS AND ACRONYMS

7. DEFINITIONS

ATTACHMENTS: A. CDC DEPARTING EMPLOYEE REQUEST FOR

DOCUMENTARY MATERIALS

B. GUIDANCE ON ELECTRONIC COMMUNICATIONS1

C. HHS EMPLOYEE EXIT SURVEY

D. IN- AND OUT-PROCESSING PROCEDURES & CHECKLISTS

1. PURPOSE AND SCOPE

This policy provides general guidance for the in- and out -processing of employees, non-employees and affiliates (referred to in their entirety as “staff”) at the Centers for Disease Control and Prevention (CDC)2. The policy covers the general requirements to achieve the following:

Accountability for security, property, and financial issues as related to in- and out-processing

Information transfer objectives

Compliance with records management laws and regulations

Proper management of logical access to CDC networks

Proper and secure physical access to CDC campuses, buildings and facilities, systems and other assets

Accountability for CDC property

The policy applies to all CDC staff (employees, non-employees [contractors] and affiliates) within the United States (US) and assigned abroad, but does not apply to Locally-Employed Staff (LES) who are employed exclusively overseas and do not have access to CDC domestic sites or computer and communications networks. The in- and out -processing requirements for LES staff falls under security requirements established by the servicing U.S. Embassy.

1 Guidance on Electronic Communications was developed from various National Archives and Records Administration (NARA) publications 2 References to CDC also apply to the Agency Toxic Substances and Disease Registry (ATSDR) https://www.kamtm.com/url/u.aspx?58C64B1F514941650

2. BACKGROUND

This policy will help ensure that staff are properly processed and managed when they come into and leave CDC and will guide Centers, Institute, and Offices (CIOs), CDC managers and others regarding the major focus of in- and out -processing requirements. This will protect CDC staff, records, facilities, and systems, and ensure consistency in operational requirements. Detailed in- and out -processing procedures are contained in Attachment D In- and Out -Processing Guide and Checklist, and are guided by the major requirements of this policy. Subsequent changes to, and approval of specific revised procedures, may be made separately from this policy as long as they do not impact the purpose, scope, requirements and responsibilities outlined in this policy.

3. POLICY

CDC will implement the requirements prescribed in this policy and its attachments to enhance security, improve in- and out -processing efficiency, reduce non-compliance, and protect government property, systems and records. Executive and management officials from CDC CIOs will ensure all requirements are met to complete the in- and out-processing procedures prior to staff coming into and leaving the organization.

Responsible staff and officials, as appointed by each CIO, are required to complete and verify all applicable tasks related to the in- or out -processing of staff. Tasks include those related to change in duty station, employment status, or any other employment change affecting logical (network) or physical access (buildings and facilities) to CDC or other government resources and facilities. In- and out -processing activities will be performed according to the laws, regulations, standards, and procedures pertaining to the oversight and administration of government property and records, access to facilities and information systems, and security-related activities and requirements.

Non-employees and affiliates are required to adhere to all applicable CDC policies and agreements outlined in their service contract and this policy. Please see the CDC Operational Policy, Identification of Contractors' Employees Safeguarding Government Information for additional guidance.

A. General Requirements

The general requirements of this policy outlined below address the five general objectives of in-and out -processing: Security (access to physical or logical resources), Property Accountability (assignment and return of government-furnished equipment), Financial Accountability (reconciling accounts), Information Transfer (proper transfer of information and responsibilities to authorized staff), and Records Management (appropriate review, storage, and disposition of federal records). Additional information regarding the General In- and Out -processing Requirements can be found in Section 3B and 3C of this of the policy, related attachments and policies.

CIOs may develop detailed procedures which focus on these five requirements. They may vary by CIO, and/or geographic location, to accommodate special circumstances and unique characteristics of organizations. In some cases, the task owners may be identified for a particular CIO. This guidance may be developed in supplemental standard operating procedures or internal guidance; however, CIOs must comply with the general requirements described in this policy. If CIOs are unsure that their internal guidance complies with the http://aops-mas-iis.cdc.gov/Policy/Doc/policy481.pdf requirements of this policy, they must forward the proposed guidance directly to the Management Information Systems Office (MISO) and Management Analysis and Services Office (MASO) for review before implementation.

1) Security

Physical and logical access will be limited to staff who have legitimate business with CDC. Changes in organizational affiliation within the agency, employment status, or non-employee contract status will be managed, tracked, and adjudicated in a timely manner.

Staff will not be issued Personal Identification Verification (PIV) Credentials, or granted access to the CDC network until in-processing procedures are complete. All staff who separate from CDC are required to complete out-processing procedures in accordance with the Homeland Security Presidential Directive 12 (HSPD-12) of August 27, 20043.

2) Property Accountability

Government-Furnished Equipment (GFE) assigned to staff will be tracked and accounted for while a person is actively working at CDC. These activities promote the proper stewardship of CDC assets and supports control of GFE when staff separates from CDC. Appropriate planning and timing of property turn in requirements must be considered by CIO Management and responsible officials to prevent issues including the unauthorized removal of CDC property. Property assigned to staff must be collected and accounted for prior to the end of a staff member’s last day with CDC.

3) Financial Accountability

Departing staff are responsible for settling outstanding balances related to any government-issued credit card (e.g. the Government Travel Credit Card (GovCC), the GSA Smartpay® 2 Government Purchase Card, and phone cards). In addition, all Government-issued credit cards must be destroyed prior to the employee separating from the agency or CIO. It is recommended that all card activity be discontinued at least 30 days prior to the employee’s departure, or as soon as the employee gives notice of separation if less than 30 days, this will allow any trailing charges to be posted on the account and the remaining balance to be cleared prior to the cancellation of the card.

4) Information Transfer

CIOs must ensure that only cleared and authorized incoming staff review security classified or sensitive records and are trained accordingly with regards to how this information is properly managed and stored. CIOs and Supervisors are responsible to facilitate the transition of work related information, records, and responsibilities to incoming staff. CIOs are responsible to ensure that the data managed by departing employees is accessible and readable to staff who inherit their responsibilities. They

3 The act indicates: “Wide variations in the quality and security of forms of identification used to gain access to secure Federal and other facilities where there is potential for terrorist attacks need to be eliminated. Therefore, it is the policy of the United States to enhance security, increase Government efficiency, reduce identity fraud, and protect personal privacy by establishing a mandatory, Government-wide standard for secure and reliable forms of identification issued by the Federal Government to its employees and contractors (including contractor employees).”

http://www.whitehouse.gov/omb/e-gov/hspd12_reports/ must also ensure that proprietary data remains in the possession of CDC and that sensitive data is not released as the result of departing staff. This includes the protection of data covered under various Federal Laws and regulations including (but not limited to) the Public Health Service Act, Privacy Act and the American Health Insurance Portability and Accountability Act.

5) Records Management

The requirements for the effective management of Federal records are outlined in 36 CFR Subpart B.1222: Creation and Maintenance of Federal Records. CDC records4 must be:

Managed effectively and efficiently throughout their lifecycle to document the programmatic and administrative accomplishments of CDC CIOs

Preserved in accordance with applicable statutory and regulatory requirements

Managed to allow the promotion of access to information by CDC staff, affiliates, contractors and the public, as appropriate

CDC must ensure that incoming staff:

Understand the unique requirements of managing Federal Records

Create adequate and proper documentation of CDC’s actions, decisions and functions

Ensure that records are stored in official files and managed appropriately

Complete the appropriate mandatory records management training (created and maintained by CDC Records Management program) within their first thirty days of employment. The training provides an overview of federal records management and the obligations of federal employees to adequately document agency business

CDC must ensure that outgoing staff not remove records from the possession of CDC or destroy them inappropriately. Responsible officials must:

Make efforts to transfer records managed by departing staff to current staff

Ensure that records are managed appropriately if there are pending litigation holds, discovery actions, Freedom of Information Act and Privacy Act requests, and/or audits

Keep Federal Records in the official recordkeeping system maintained by the applicable office

B. General In-Processing Requirements (For more specific information see Attachment

D, In -and Out -Processing Procedures and Checklist)

1) Establish a User Profile and Enable a Network Account

4 Federal records are created in various formats, which include, but not limited to paper, electronic communications, electronic systems, databases, audio-visual records and other recording media.

http://www.ecfr.gov/cgi-bin/text-idx?rgn=div5&node=36:3.0.10.2.11#36:3.0.10.2.11.2

All new staff must create a user profile by entering required information in the PeopleProcessing System and subsequently creating a user ID. Staff that requires logical (network) or physical access (buildings and facilities) to CDC resources, or who are assigned as a CDC affiliate, must have a valid profile. A profile and user ID must be created to complete In-processing.

2) Complete Security Requirements

Security-related activities for in-processing are conducted by the Office of Safety, Security and Asset Management (OSSAM). In-processing requires completion of security activities including: fingerprinting, background checks, and/or security clearances. Upon completion of security activities, OSSAM provides the sponsorship, enrollment, adjudication, and issuance of a Smart Card Personal Identification Verification (PIV) which will allow access to the central point of logical (network) access and physical (buildings and facilities) control. All new staff must complete the following security-related activities prior to their official start date:

a. Fingerprinting

b. Logical access related security training

c. Safety Survival Skills training

d. Security documents (National Agency Check with Written Inquiries [NACI], public trust and/or security clearance documents)

e. Security Level determination assigned (CDC-HR-2006-01)

f. Sensitivity level designation (The Human Capital and Resource Management Office

[HCRMO] will ensure that positions are designated with the appropriate sensitivity level)

g. Smart Card (PIV) sponsorship, enrollment, adjudication, and issuance (see the Utilization and Issuance of PIV Credentials Operational Policy)

Note: Newly employed non-U.S. citizens must have an approved visit request in the CDC Visitor’s Management System (VMS) before a Personal Identification Verification (PIV) Credential will be issued. For non-U.S. citizens, a valid country passport, Employment Authorization Document (EAD) card, or Lawful Permanent Residence card (LPR or “green card”) indicating permanent U.S. residency is required. United Nations laissez-passer passports are invalid identification for security purposes

A U.S. government issued common access card with Smart Card (PIV) credentials is a FIPS-201 compliant Smart Card (PIV) credential and is acceptable for access to CDC with an approved access request (for both U.S. and non-U.S. citizens)

3) Issue Logical (network) and Physical Access (buildings and facilities) using Smart Card (PIV) Credentials, which include:

a. Establish a user profile (user ID creation)

b. Conduct a security background investigation

c. Complete Security Awareness Training (SAT) (if applicable)

d. Safety Survival Skills training

e. Complete Smart Card (PIV) process

f. Submit New User Request form for logical access

g. Receive government-furnish equipment from sponsored organization http://peopleprocessing.cdc.gov/ http://isp-v-maso-apps.cdc.gov/Policy/Doc/policy560.pdf

4) Annual Security Awareness Training

Each year CDC users with access to logical (network) resources are required to complete the Security Awareness Training.

5) Changes in Employment Status, Transfers, Changes in Duty Station, Details, and

Promotions

Changes in employment status, including but not limited to, reassignment, promotion, changes in duty station, details, or temporary promotions that require changes in staff’s logical (network) or physical (buildings and facilities) access to government resources require that all applicable in- or out -processing activities be completed. Procedures for a change in employment status are the same as those required to out-process staff permanently separated from CDC. NOTE: After initial fingerprinting, additional fingerprinting will not be required however, a review of the need and type of access and property required must be conducted.

6) Records Management Training. All new employees must complete records management training within 30 days of their arrival.

7) Applicable Policies

PIV (Smart Card) Policy

National Security Information Records Management Policy

C. General Out-Processing Requirements

1) Records Management

Before departing CDC, every individual must:

Sort records into groups if records were not kept in accordance to official file plan o Federal records o Non-record material o Personal material

Collaborate with supervisor or senior records liaison to determine the best method for managing records before departure

Seek permission to retain extra copies of records kept for convenience or reference.

It is possible to take copies of records during departure if a “Request for Removal of Documentary Materials” (see Attachment A) form receives appropriate approval and signatures.

Remove all personal records and delete non-records For assistance to determine the records status of e-mails (see Attachment B).

“Guidance of Electronic Communications”

Applicable policies:

CDC Records Management Policy – includes guidance on electronic records and email HHS Records Management Policy HHS Litigation Hold Policy http://isp-v-maso-apps.cdc.gov/Policy/Doc/policy560.pdf http://aops-mas-iis.cdc.gov/policy/Doc/policy302.pdf http://isp-v-maso-apps.cdc.gov/Policy/Doc/policy449.pdf http://aops-mas-iis.cdc.gov/Policy/Doc/policy449.pdf http://www.hhs.gov/ocio/policy/2007-0004.001.html http://www.hhs.gov/ocio/policy/policydocs/policy-2010-0008.doc

2) Information Transfer

CIOs are responsible for facilitating the transition of work-related information/data, records and responsibilities from departing staff to individuals identified as successors and ensure that the records are accessible and readable.

3) Security

a. Disabling Accounts

All staff is required to exercise common sense, good judgment, and propriety in the use of government-provided resources. The designated authority must ensure that all user accounts are disabled prior to an individual’s last day of work. In the event of an immediate separation, the designated authority must terminate account access immediately and notify OSSAM for additional guidance.

b. Security Clearance Debriefings

Anyone who holds a security clearance must complete a debriefing with Personnel Security or the CDC Special Security Officer SSO, as applicable, prior to their departure.

4) Property Accountability

a. Return of Government Property

All government furnished equipment (GFE), both at home and at work, must be accounted for and returned prior to the permanent separation or transfer of any staff from the CDC.

b. Personal Identification Verification (PIV) Credentials

CDC policy requires departing staff to turn in their Smart Card (PIV) credential on or before their last day. If the person also holds a radiation badge, it must also be returned before the last day at CDC.

Note: Staff, in the field or in locations where there is no responsible authority or agent to physically collect the badge or card key, should contact the Field Security Officer in advance for instructions. In these circumstances, it will also be necessary to coordinate with OSSAM and review the Issuance and Utilization of PIV Credentials Policy for details.

c. Door Keys

Door keys (government property) must be returned to OSSAM prior to the departing staff’s separation.

d. Key Fobs

All key fobs (RSA Secure ID tokens) must be accounted for prior to the staff member’s departure.

http://aops-mas-iis.cdc.gov/Policy/Doc/policy560.pdf

e. Auto Decals

Departing staff must remove and destroy all government-issued decals from personally owned vehicles and notify OSSAM once completed. Please refer to the Parking and Vehicle Operation Policy, CDC-GA-2002-07.

f. Government-Issued Passports

All U.S. government passports are government property and must be stored in the CDC Center for Global Health (CGH) or approved field site (except when checked out by individuals for official international travel). The responsible authority or agent must notify the appropriate official in CGH of the departure and collect and return the passport to

CGH.

5) Financial Accountability

All Government-issued charge cards (including GSA SmartPay 2® Government Purchase Card, travel credit cards (GovCC) and Phone cards) must be destroyed prior to departure. As previously stated, it is strongly recommended that all government credit card activity be discontinued at least 30 days prior to departure. This will allow any trailing charges to be posted on the account and the remaining balance to clear prior to cancellation of the card.

a. Government Travel Card (GovCC)

All GovCCs must be returned to CDC and destroyed prior to the employee leaving the agency. When properly notified of an employee’s separation from the agency, OCFO will collect and destroy any government travel credit cards issued to the employee and will review the employee’s credit card and other account balances to determine whether a balance is owed.

Departing CDC staff in the field may need to retain the GovCC until they are out-processed if they return from travel or from overseas. In these cases, the departing staff member must notify their supervisor and Agency/Organization Program Coordinator (A/OPC) in advance. The supervisor must ensure that the GovCC card is retrieved and DESTROYED immediately and the account cancelled upon notification.

If the GovCC cannot be returned and destroyed, a written statement signed by the responsible authority and the CIO or executive leadership must be prepared to identify and record the reason. The corresponding administrators or responsible parties in OCFO need to cancel or deactivate the account upon notification. The CIO or office representative must contact the OCFO Service Desk at 404-718-8100 to request cancellation of accounts.

b. Government Purchase Cards

The Cardholder Approving Official must contact the CDC Purchase Card Staff to request cancellation of the purchase card, and the cardholder, approving official and supervisors must follow all procedures in the CDC Purchase Card Guide.

http://aops-mas-iis.cdc.gov/Policy/Doc/policy345.pdf http://aops-mas-iis.cdc.gov/Policy/Doc/policy345.pdf http://pgo.cdc.gov/pgo/ost/_ost_visa_home.shtm

The CDC Purchase Card Guide provides the following guidance related to separating employees:

Cardholders leaving their current positions must:

1) Stop using card(s) 30-45 days prior to leaving

2) Ensure all transactions have “cleared the bank” and are logged, matched, registered, received, and approved in MACCS

3) Shred unused checks, destroy card(s), and return content to your approving official. Approving officials will coordinate with the Program Coordinator to cancel the account

Approving Officials leaving their positions must:

1) Ensure a valid alternate approving official, equal to or higher grade than the cardholders, is in place

2) Advise the Program Coordinator of the new approving official

c. Phone Card

The responsible authority or agent should contact the ITSO Service Desk at (404) 639-6000 to request cancellation of phone cards.

6) Involuntary Removals

All logical (network) and physical (buildings and facilities) access accounts must be deactivated within 23 hours of an individual’s departure, or immediately on those occasions when the terms of departure (including involuntary separation) may cause an immediate security risk. If the person’s departure is involuntary or takes place under unfavorable circumstances, the responsible authority must notify the appropriate (ISSO) and Physical Security immediately. If the ISSO is not available they must contact the Chief Information Security Officer (CISO).

7) Exit Interviews

Exit Interviews: All CIOs must allow employees the option to participate in an exit interview before they depart. The departing employee is strongly encouraged to participate so that their opinions, ideas, and experiences are considered in future human capital decision making.

These interviews can provide a tool to ensure that employees transition out of CDC in an organized and structured manner, and can be used to base future human resources and management policies and activities. They can:

o Provide an overview of the requirements of their position o Provide a summary of issues in current work assignments o Ensure an orderly transition for customers o Ensure that work on projects is transferred in a timely and orderly manner o Provide information to CIO management on current management practices o Promote staff morale o Resolve any pending or outstanding issues

An HHS interview tool is provided in the link contained in Attachment C and this data is provided monthly to the HCRMO office

CIOs can also develop internal exit interview processes in addition to the one provided.

4. RESPONSIBILITIES

In- and out- processing is a collaborative effort involving CDC staff and CIOs and must be performed consistent with the directives outlined in this policy and other federal policies, laws, regulations, standards, and procedures. Specific responsibilities are provided below:

A. CDC staff including Employees, Non-Employees, and Affiliates

1) Comply with the tasks, standards, and procedures outlined in this policy, provided in Attachment D

2) Demonstrate understanding of the requirements and responsibilities of in- and out -processing and perform tasks in a timely and conscientious manner. If a person is uncertain about this policy, its requirements, or performing in- and out -processing tasks, they should seek guidance from the responsible authority

3) Apply the appropriate use and processing of government property and resources and exercise common sense, good judgment, and propriety in the use of government-provided resources

4) Report any change in status by immediately confirming the change to their responsible authority and assist in recording the change in the proper CDC-wide system (PeopleProcessing)

5) Complete all assigned or required in- or out -processing tasks for which they are responsible. Example includes the return of Smart Cards, Smart Card Readers, Purchase Cards and other GFE prior to the end of the their last day of service

6) Ensure that official records are properly retained and disposed of in accordance with an approved records control schedule. Ensure that the Request for Removal of Documentary Materials Form (See Attachment A), is completed if copies of records are made and removed from CDC. Ensure that email communications are managed in accordance with federal records requirements (See Attachment B) -- Guidance on Electronic Communications – to determine if an email communication constitutes a Federal record)

7) Comply with the HHS Information Security Program Rules of Behavior and CDC system-specific rules of behavior before gaining access to the CDC’s systems and networks

8) Complete required privacy, records and information security training

B. Responsible Authority

The Responsible Authority is the supervisor, project officer, and/or Cardholder Approving Official with primary responsibility to ensure that in- or out -processing tasks have been performed and completed for any person for whom the responsible authority is accountable.

A responsible authority has the following in- and out -processing responsibilities under his or her authority:

1) Ensure that employment status for employees, contractors and affiliates are communicated in a timely manner, and initiated

2) Supervise and ensure in- and out-processing task compliance from all persons under their direction and provide the education, awareness, and resources necessary to ensure the process is followed

3) Appoint the appropriate persons as in-and-out processing task owners. The task owner is then responsible for completing the in- and out -processing tasks that they own. The in- and out -processing task owner is also responsible to ensure that the tasks comply with this policy, attachments, and standards and procedures

4) Ensure that any departure, resignation, retirement, removal, or change of duty station or employment status is reflected in the user’s profile in the directory and that any access to IT or physical resources is deactivated upon notification of the separation. Ensure that all logical (network) and physical (buildings and facilities) access accounts are deactivated within 23 hours of an individual’s departure, or immediately upon those occasions when the terms of departure (including involuntary separation) may cause an immediate security risk. In the case of an involuntary departure, under unfavorable circumstances, the responsible authority must immediately notify the appropriate Information Systems Security Officer (ISSO) and Physical Security immediately. If the ISSO is not available, they must contact the Chief Information Security Officer (CISO).

5) Ensure CDC issued credit and purchase cards of any departing staff (whether departing voluntarily or involuntarily) be destroyed and the appropriate CDC offices are notified to cancel the accounts

6) Ensure that all applicable in- or out -processing tasks have been completed and verified

7) Ensure that official records are managed in accordance with approved records schedules and are properly disposed of according with the CDC Records Management Policy and legal requirements. They also ensure that original CDC records are not removed. The responsible authority ensures that the departing person has deleted, transferred, or disposed of any e-mails, electronic files, folders, or documents not deemed official records prior to departure or separation. Finally, the official ensures that requests to remove copies of records are reviewed and approved

8) If government property has not been recovered prior to a person’s departure, notify the organization’s property management officer. Notify the departing staff that they risk further government action if they do not comply with the return/collection of Government Funded Equipment (GFE)

9) In consultation with the Human Capital and Resource Management Office (HCRMO) and the organization’s Information Systems Security Officer (ISSO):

a. Determine and assign the level of position sensitivity for all supervised staff and ensure position designations are correct http://aops-mas-iis.cdc.gov/Policy/Doc/policy449.pdf http://aops-mas-iis.cdc.gov/Policy/Doc/policy449.pdf

b. Ensure that background checks of incoming personnel match the security level required by contracted tasks

c. Identify and document personnel with significant system security responsibilities (SSR) and ensure that personnel with SSR receive required security role based training (see the National Security Information Operational Policy)

10) Ensure that their employees complete all required information security training within the mandated time frame

11) Notify system owners of new users in a timely manner and authorize access privileges for individuals that identifies the level of authorization and any restrictions

12) Notify system owners to revoke access privileges of a present user in a timely manner when a user under their supervision or oversight no longer requires access privileges

13) Ensure that departing employees have the option of completing an exit interview

C. CIO or Executive Leadership

CIO or Executive Leadership is required to ensure that the resources are available to administer the provisions of this policy. CIO or Executive Leadership should designate specific individuals, or groups within their organization, to serve as task owners to perform specific functions associated with in- and out -processing.

A CIO Director or Executive Leadership has the following in- and out -processing responsibilities under their authority:

1) Ensure that all persons comply with this policy, and understand in- and out -processing responsibilities

2) Ensure that training and resources are made available to assist in complying with and administering this policy

3) Ensure that all supervisors, responsible authorities, agents, and task owners in their organization complete and verify all applicable in- or out -processing tasks for which they are responsible

4) Assign and communicate with the designated task owners within your organization for each task associated with in-or out -processing activities. The CIO and Executive Leadership are responsible to ensure that every person in their organization knows the appropriate task owners designated for a given task. Make sure that staff understands that a failure to communicate the proper procedures may result in noncompliance and will put CDC security at risk

5) Develop, promote, and coordinate CDC in- and out -processing training and initiatives

6) Develop, promote, and coordinate in- and out -processing implementation plans with key affected parties

7) Serve as a focal point for incident reporting and subsequent resolution http://aops-mas-iis.cdc.gov/policy/Doc/policy302.pdf

8) Ensure that in- and out -processing incident response procedures are established to investigate and resolve incidents

9) Initiate and pursue appropriate disciplinary or adverse action for violations of this policy

D. Task Owner

A task owner is the person designated to accomplish or complete a given in- and out -processing task(s) and will be assigned by varying officials within an organization. A task owner is responsible to ensure that the tasks comply with this policy. Task owners may include the incoming or departing individual, designated administrative staff, IT staff, security personnel, property officers, organizational managers, Senior Records Liaisons, or any other persons responsible for a given task. For many tasks, the CIO or Executive Leadership within a CIO will designate the appropriate responsible task owner. The designated task owner may be an individual or a group of individuals (e.g. administrative staff) within an organization.

A task owner has the following in- and out -processing responsibilities under his or her authority:

1) Ensure that all in- and out -processing tasks are performed in compliance with the standards and procedures identified in or associated with this policy

2) Perform given tasks as directed by CIO or Executive Leadership in a timely manner in accordance with the policy requirements

3) When the task owner completes all assigned tasks, or identifies issues with non-compliance, he or she will notify the responsible authority immediately

E. Business Stewards

A business steward is a management official to whom responsibility for an agency mission objective is assigned, typically a Branch Chief or Division Director, and who directs or controls the budget, personnel, and information resources to accomplish that mission. Only a CDC employee can fulfill the role of a business steward.

A business steward has the following in- and out -processing responsibilities under his or her authority:

1) Establish, as appropriate, system-specific rules of behavior for all systems that apply to all personnel that manage, administer, or have access to CDC IT systems

2) Grant individuals only those privileges necessary for job performance (access to any privileges not specifically granted must be denied) so that privileges are based on a legitimate need to have system access

3) Ensure users and support personnel receive required system-specific training

4) Revoke access when personnel are transferred or terminated in a timely manner

F. CDC Information Systems Security Officers (CDC ISSOs)

1) Ensure that all users complete HHS and CDC security based training to fulfill their information security responsibilities. This training is required for executives; program and functional managers; IT management, operations and security personnel; and other security-oriented personnel such as IT administrators (e.g., network, system, or database)

2) Assist supervisors in identifying personnel with significant security responsibilities

3) Ensure that system owners establish processes for timely revocation of access privileges when a user’s system access is no longer necessary (e.g., transfer, resignation, retirement, change of job description, etc.). This includes immediate revocation for individuals being separated for adverse reasons on, or just prior to, the effective date of their separation

4) Assist the CISO in coordinating with Human Resource management to develop reporting procedures regarding personnel departures from the Department of Health and Human Services (DHHS)

G. Contracting Officers (COs), Contracting Officer Representatives (COR), Project Officers (PO), and Technical Monitors (TM)

The Contracting Officer has authority to enter into, administer, and/or terminate contracts and make related determinations and findings. The term includes certain authorized representatives of the Contracting Officer acting within the limits of their authority as delegated by the contracting regulation (FAR 2.101, Subpart 2.1 – Definitions; JFMIP 2003, p.76).

The Project Officer (PO) is a federal employee designated to provide guidance, information, and assistance to the Contracting Officer for all technical aspects of a proposed project. Project Officers may be delegated authority to also act as the COR on a contract or order. The PO is responsible for the in- and out-processing of non-employees. In some cases, a non-employee will also have a technical monitor (TM). Either the TM or the PO is ultimately responsible for ensuring proper processing of non-employee staff assigned to a given project/task order. The PO or TM can delegate in- and out -processing responsibility and tasks to other staff as directed by Executive Leadership but ultimate responsibility for ensuring policy compliance remains with the PO or TM.

Contracting Officers, Contracting Officer Representative (COR), Project Officers, and Technical Monitors have the following in- and out -processing responsibilities under his or her authority:

1) Ensure that contracts, Request for Proposals, Request for Task Order Proposals include language that requires contracting firms to identify personnel that meet the criteria as having Significant Security Responsibilities (SSR) and require those personnel take appropriate Role Base Training (RBT)

2) Ensure that contracts, Request for Proposals, Request for Task Order Proposals include language requiring contracting firms to report compliance of SSR classification and role based training of personnel via monthly reports to OCISO http://farsite.hill.af.mil/reghtml/regs/far2afmcfars/fardfars/far/02.htm#P10_604

H. MASO Records Management Program/CDC Records Officer

The MASO Records Management program and CDC Records Officer, has primary responsibility for the management and oversight of the CDC Records Management Policies. Additionally, all CDC staff and CIOs are responsible for ensuring that Records Management issues are addressed during in- and out -processing. Records Management responsibilities are to ensure that adequate and proper documentation of CDC’s activities and programs are preserved to allow future use for administrative, scientific, audit, legal, and historic records. The Records Management Program/CDC Records Officer should direct departing staff to submit a Request for Removal of Documentary Materials (See Attachment A) prior to removing or destroying documents. Departing staff must show an understanding that document removal must comply with Federal FOIA regulations and confidentiality requirements. In addition, departing staff should be directed to CDC policy regarding email management to determine which communications should be retained as a Federal record (See Attachment B – Guidance on Electronic Communications).

I. Human Capital and Resources Management Office (HCRMO)

The Human Capital and Resources Management Office (HCRMO) is responsible for the processing of new CDC employees. Prior to in-processing a new employee, HCRMO facilitates the communication between CDC and potential candidates. Once official employment offer has been accepted, HCRMO assists with employee on-boarding requirements (e.g., creation of UserID, pre-vet identity, forms, etc.). Additionally, HCRMO oversees exiting interviews. CDC is required to offer Exit Interviews and encourages participation. The departing staff has the option to participate in the optional out-processing activity (See Attachment C).

J. Office of the Chief Financial Officer (OCFO)

When properly notified of an employee’s separation from the agency, OCFO will collect and destroy any government travel credit cards issued to the employee and will review the employee’s credit card and other account balances to determine whether a balance is owed.

Note: Departing CDC staff in the field may need to retain the GovCC until they are out-processed if they return from travel or from overseas. In these cases, the departing staff member must notify their supervisor and Agency/Organization Program Coordinator (A/OPC) in advance. The supervisor must ensure that the GovCC card is retrieved and DESTROYED immediately and the account cancelled upon notification.

If the GovCC cannot be returned and destroyed, a written statement signed by the responsible authority and the CIO or Executive Leadership must be prepared to identify and record the reason. The corresponding administrators or responsible parties in OCFO need to cancel or deactivate the account upon notification. The CIO or office representative must contact the OCFO Service Desk at 404-718-8100 to request cancellation of accounts.

5. REFERENCES

A. HHS

HHS Records Management Policy.

HHS Rules of Behavior (For Use of Technology Resources and Information), February 12, 2008

Appendix III to OMB Circular No. A-130: Security of Federal Automated Information Resources.

OMB Memorandum M-04-04: E-Authentication Guidance for Federal Agencies.

B. Security

Physical Access to CDC Facilities. CDC, revised June 2011.

Issuance and Utilization of PIV Credentials. CDC, March 2011. (pending)

FIPS 201-1: March 2006, Personal Identity Verification (PIV) of Federal Employees and Contractors

National Security Information

HHS-OCIO Policy for Information System Security and Privacy. June 2009.

Homeland Security Presidential Directive (HSPD) 12. August 27, 2004.

National Agency Check and Inquiry Procedures. CDC, June 1999

The In- and Out -Processing Checklists contain the tasks and instructions that must be completed in order for any CDC employees, Personal Services Contractors (PSC) or other non-employees to officially arrive, transfer or depart from a CDC facility, or to access government-provided resources and information.

PeopleProcessing. Last updated October 2010.

C. Financial

Government Charge Card Abuse Prevention Act of 2012 http://www.hhs.gov/ocio/policy/2007-0004.001.html http://intranet.hhs.gov/infosec/docs/policies_guides/ROB/Information_Security_Program_Rules_of_Behavior.htm http://www.whitehouse.gov/omb/circulars/a130/appendix_iii.pdf http://www.whitehouse.gov/omb/circulars/a130/appendix_iii.pdf http://www.whitehouse.gov/omb/memoranda/fy04/m04-04.pdf http://aops-mas-iis.cdc.gov/Policy/Doc/policy334.pdf http://csrc.nist.gov/publications/fips/fips201-1/FIPS-201-1-chng1.pdf http://csrc.nist.gov/publications/fips/fips201-1/FIPS-201-1-chng1.pdf http://aops-mas-iis.cdc.gov/policy/Doc/policy302.pdf http://intranet.hhs.gov/infosec/docs/policies_guides/PISSP/Policy%20for%20Information%20Systems%20Security%20and%20Privacy_toc.html http://www.whitehouse.gov/omb/e-gov/hspd12_reports/ http://aops-mas-iis.cdc.gov/Policy/Doc/policy95.htm http://www.gpo.gov/fdsys/pkg/BILLS-112s300enr/pdf/BILLS-112s300enr.pdf

6. ABBREVIATIONS AND ACRONYMS

For the purposes of this policy, the following abbreviations and acronyms apply:

AO Administrative Officer

APCO Alternate Property Custodial Officer

ATSDR Agency for Toxic Substances and Disease Registry

CDC Centers for Disease Control and Prevention

C.F.R. Code of Federal Regulations

CIO Centers, Institute, Offices

CISO Chief Information Security Officer

CGH Center for Global Health

FAR Federal Acquisition Regulation

FEO Facilities Engineering Office

FISMA Federal Information Security Management Act

OCFO Office of the Chief Financial Officer

Employee Full-Time Equivalent

GFE Government Furnished Equipment(s)

GovCC Government Travel Credit Card

GRS General Records Schedule

HHS Department of Health and Human Services

ISSO Information Systems Security Officer

IT Information Technology

ITSO Information Technology Services Office

JMFIP Joint Financial Management Improvement Program

LAN Local-Area Network

LES Locally-Employed Staff

LSB Laboratory Safety Branch

MASO Management Analysis and Services Office

NACI National Agency Check with Inquiries

NIST National Institute of Standards and Technology

OCISO Office of the Chief Information Security Officer

HCRMO Human Capital and Resource Management Office

OSHE Office of Safety Health and Environment

OSSAM Office of Safety, Security and Asset Management

PCO Property Custodial Officer

PDA Personal Digital Assistant

PGO Procurement and Grants Office

PIV Personal Identification Verification

PMO Property Management Officer

PO Project Officer

PSC Personal Services Contractor

SSR Significant Security Responsibilities

TM Technical Monitor

USB Universal Serial Bus

WAN Wide-Area Network

7. DEFINITIONS

For the purposes of this policy, the following definitions apply:

Affiliates – individuals associated with CDC who are not considered employees or non-employees. Affiliates are typically not funded by CDC. They may be involved in an ongoing collaboration, be in a special training or educational program, provide employee services, or may be traveled by CDC for a special one-time purpose.

Agent – An entity designated and approved by CIO or Executive Leadership to perform many in

- or out -processing tasks as necessary or as assigned by the responsible authority. The agent can act on behalf of the responsible authority, but the responsible authority is ultimately accountable for ensuring policy compliance and completion of all required tasks.

Alternate Property Custodial Officer – A non-employee can be an alternate property custodial officer when designated by the contract by which they are employed. However, non-employees filling this position are specifically precluded from final authorization of any action that affects the financial standing of the government (see CDC policy, CDC Use of Contractors as Alternate Property Custodial Officers, CDC-MM-2006-01).

Employees – An officer or individual who is appointed or hired to federal service, engaged in the performance of a Federal function, subject to the supervision of an officer or employee of the Federal Government, funded by CDC managed appropriations and under authority of law or an executive act as defined by 5 U.S.C. § 2105. This includes all staff regardless of the appointment type, hiring method, pay plan, tour of duty (part-time and full-time), duration (temporary, term, permanent), or location (domestic or international).

In-Processing – In-processing tasks can include assignment of property, assets, and/or access to information or facilities that may occur at any time during the lifecycle of association with CDC. In-processing refers to all activities and tasks required to validate a user’s identity and their need for specific access to physical and/or logical resources associated with CDC.

Mobile Device – Any computer or other apparatus that can store and process data and is designed to be mobile; examples include: laptop computers, iPods, Blackberries, Treos, Palm Pilots and other Personal Digital Assistants (PDAs). Cameras and cell phones, with built-in or plug-in memory (e.g. SD cards) are also included.

Non-Employees – Individuals providing consistent services to CDC and/or who maintain a regular presence on a CDC facility or require access to the CDC internal network, are issued a CDC badge (physical and/or logical access credential), and are funded by CDC managed appropriations.

Onboarding – On-boarding is defined as the activities that encompass the hiring process.

Out-Processing – Out-processing tasks can include removal of property, assets, and/or access to information or facilities that may occur at any time during the lifecycle of association with CDC. Out-processing refers to all activities and tasks required to transfer ownership, remove logical (network) and physical (buildings and facilities) access when no longer required due to separation, and ensure proper disposal or traceability of any assets, resources, access, or information for given staff associated with CDC.

http://aops-mas-iis.od.cdc.gov/Policy/Doc/policy482.htm

Portable Media – Any device that can store data electronically and is portable, such as portable hard drives, Universal Serial Bus (USB) drives, CD-ROMs, and DVDs.

Property Custodial Officer or Property Custodian – The individual designated in writing and located at the field operating unit level with physical custody and control over property (see CDC policy, CDC Use of Contractors as Alternate Property Custodial Officers, CDC-MM-2006-01).

Property Management Officer – This individual is responsible for directing an effective personal property system, including: property accountability, inventory, utilization and…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .