Attachment 7_Security Program Plan
452 KB Posted
- Attached to
- Test and Evaluation Support Services (TESS) - Synopsis Federal contract opportunity
- Solicitation number
- 2109209CT4005
About this file
Attachment 7_Security Program Plan (SPP) Template
Text of this file
SENSITIVE SECURITY INFORMATION
Proprietary information for Program use only.
WARNING: This record contains Sensitive Security Information that is controlled under 49 CFR parts 15 and 1520. No part of this record may be disclosed to persons without a “need to know”, as defined in 49 CFR parts 15 and 1520, except with the written permission of the Administrator of the Transportation Security Administration or the Secretary of Transportation. Unauthorized release may result in civil penalty or other action. For U.S. government agencies, public disclosure is governed by 5 U.S.C. 552 and 49
CFR parts 15 and 1520.
Transportation Security Administration
XXXX Program
Security Program Plan
Deliverable Name
Version X.X
Date
Contract Number xxxxxxxx
WARNING: This record contains Sensitive Security Information that is controlled under 49 CFR parts 15 and 1520. No part of this record may be disclosed to persons without a “need to know”, as defined in 49 CFR parts 15 and 1520, except with the written permission of the Administrator of the Transportation Security Administration or the Secretary of Transportation. Unauthorized release may result in civil penalty or other action. For U.S. government agencies, public disclosure is governed by 5 U.S.C. 552 and 49
Note to Contractors: This document is a template to be used by the potential contractor in preparation for their submittals to Transportation Security Agency proposals. It is to be filled out by the contractor and submitted along with all other proposal artifacts.
WARNING: This record contains Sensitive Security Information that is controlled under 49 CFR parts 15 and 1520. No part of this record may be disclosed to persons without a “need to know”, as defined in 49 CFR parts 15 and 1520, except with the written permission of the Administrator of the Transportation Security Administration or the Secretary of Transportation. Unauthorized release may result in civil penalty or other action. For U.S. government agencies, public disclosure is governed by 5 U.S.C. 552 and 49
CFR parts 15 and 1520.
Title: Security Program Plan
Identifier:
Issued:
Recertified:
Supersedes:
Contact:
Approved:
Trademark Information
Product names mentioned in this document may be copyrighted, trademarked, registered trademarked, or service marked by their respective companies and are hereby acknowledged.
For Program Use Only: Make no distribution of this document outside of the XYZ Program without the prior consent of an authorized representative of the originating organization.
Revision History
CONTROLLED COPIES ISSUED BY:
Version Revision Description Approver Date
1.0 Initial Delivery
WARNING: This record contains Sensitive Security Information that is controlled under 49 CFR parts 15 and 1520. No part of this record may be disclosed to persons without a “need to know”, as defined in 49 CFR parts 15 and 1520, except with the written permission of the Administrator of the Transportation Security Administration or the Secretary of Transportation. Unauthorized release may result in civil penalty or other action. For U.S. government agencies, public disclosure is governed by 5 U.S.C. 552 and 49
CFR parts 15 and 1520.
Table of Contents
1 INTRODUCTION
1.1 Purpose
1.2 Scope
1.3 Authorities
1.4 Definitions and Acronyms
1.5 Roles and Responsibilities
1.6 Organization of the Remaining Sections of the Security Program Plan
1.6.1 Overview of the Security Program
1.6.2 Security Control Functions
1.6.3 Appendices of the SPP
1.6.4 Security Plan Documentation
2 SECURITY PROGRAM OVERVIEW
2.1 Objectives
2.2 Approach
2.3 Services and Functions
2.4 Security Events Monitoring (SEM) Guide
3 ACCESS AND LOGICAL CONTROL PROTECTION
3.1 Access Control Policy and Procedures (AC-1)
3.2 Account Management (AC-2)
3.3 Access Enforcement (AC-3)
3.4 Information Flow Enforcement (AC-4)
3.5 Separation of Duties (AC-5)
3.6 Least Privilege (AC-6)
3.7 Unsuccessful Login Attempts (AC-7)
3.8 System Use Notification (AC-8)
3.9 Previous Logon Notification (AC-9)
3.10 Concurrent Session Control (AC-10)
3.11 Session Lock (AC-11)
3.12 Session Termination (AC-12)
3.13 Supervision and Review – Access Control (AC-13)
WARNING: This record contains Sensitive Security Information that is controlled under 49 CFR parts 15 and 1520. No part of this record may be disclosed to persons without a “need to know”, as defined in 49 CFR parts 15 and 1520, except with the written permission of the Administrator of the Transportation Security Administration or the Secretary of Transportation. Unauthorized release may result in civil penalty or other action. For U.S. government agencies, public disclosure is governed by 5 U.S.C. 552 and 49
CFR parts 15 and 1520.
3.14 Permitted Actions without Identification or Authentication (AC-14)
3.15 Automated Marking (AC-15)
3.16 Automated Labeling (AC-16)
3.17 Remote Access (AC-17)
3.18 Wireless Access Restrictions (AC-18)
3.19 Access Control for Portable and Mobile Systems (AC-19)
3.20 Use of External Information Systems (AC-20)
4 AWARENESS AND TRAINING
4.1 Security Awareness and Role-Based Training Policy and Procedures (AT-1)
4.2 Security Awareness (AT-2)
4.3 Security Training (AT-3)
4.4 Security Training Records (AT-4)
4.5 Contacts with Security Groups and Associations (AT-5)
5 AUDIT AND ACCOUNTABILITY
5.1 Audit and Accountability Policy and Procedures (AU-1)
5.2 Auditable Events (AU-2)
5.3 Content of Audit Records (AU-3)
5.4 Audit Storage Capacity (AU-4)
5.5 Response to Audit Processing Failures (AU-5)
5.6 Audit Monitoring, Analysis, and Reporting (AU-6)
5.7 Audit Reduction and Report Generation (AU-7)
5.8 Time Stamps (AU-8)
5.9 Protection of Audit Information (AU-9)
5.10 Non-Repudiation (AU-10)
5.11 Audit Record Retention (AU-11)
6 CERTIFICATION, ACCREDITATION, AND SECURITY ASSESSMENTS
6.1 Certification, Accreditation, and Security Assessment Policies and Procedures (CA-1)
6.2 Security Assessments (CA-2)
6.3 Information System Connections (CA-3)
6.4 Security Certification (CA-4)
6.5 Plan of Action and Milestones (CA-5)
WARNING: This record contains Sensitive Security Information that is controlled under 49 CFR parts 15 and 1520. No part of this record may be disclosed to persons without a “need to know”, as defined in 49 CFR parts 15 and 1520, except with the written permission of the Administrator of the Transportation Security Administration or the Secretary of Transportation. Unauthorized release may result in civil penalty or other action. For U.S. government agencies, public disclosure is governed by 5 U.S.C. 552 and 49
CFR parts 15 and 1520.
6.6 Security Accreditation (CA-6)
6.7 Continuous Monitoring (CA-7)
7 CONFIGURATION MANAGEMENT
7.1 Configuration Management Policy and Procedures (CM-1)
7.2 Baseline Configuration (CM-2)
7.3 Configuration Change Control (CM-3)
7.4 Monitoring Configuration Changes (CM-4)
7.5 Access Restrictions for Change (CM-5)
7.6 Configuration Settings (CM-6)
7.7 Least Functionality (CM-7)
7.8 Information System Component Inventory (CM-8)
8 CONTINGENCY PLANNING
8.1 Contingency Planning Policy and Procedures (CP-1)
8.2 Contingency Plan (CP-2), Training (CP-3), Testing (CP-4), and Updating (CP-5)
8.3 Contingency Training (CP-3)
8.4 Contingency Plan Testing and Exercises (CP-4)
8.5 Contingency Plan Update (CP-5)
8.6 Alternate Storage Sites (CP-6)
8.7 Alternate Processing Sites (CP-7)
8.8 Telecommunications Services (CP-8)
8.9 Information System Backup (CP-9)
8.10 Information System Recovery and Reconstitution (CP-10)
9 IDENTIFICATION AND AUTHENTIFICATION, IT ASSET IDENTIFICATION AND
ASSESSMENT
9.1 Identification and Authentication Policy and Procedures (IA-1)
9.2 User Identification and Authentication (IA-2)
9.3 Device Identification and Authentication (IA-3)
9.4 Identifier Management (IA-4)
9.5 Authenticator Management (IA-5)
9.6 Authenticator Feedback (IA-6)
9.7 Cryptographic Module Authentication (IA-7)
WARNING: This record contains Sensitive Security Information that is controlled under 49 CFR parts 15 and 1520. No part of this record may be disclosed to persons without a “need to know”, as defined in 49 CFR parts 15 and 1520, except with the written permission of the Administrator of the Transportation Security Administration or the Secretary of Transportation. Unauthorized release may result in civil penalty or other action. For U.S. government agencies, public disclosure is governed by 5 U.S.C. 552 and 49
CFR parts 15 and 1520.
10 INCIDENT RESPONSE AND INFORMATION SECURITY INCIDENT HANDLING
10.1 Incident Response Policy and Procedure (IR-1)
10.2 Incident Response Training (IR-2)
10.3 Incident Response Testing and Exercises (IR-3)
10.4 Incident Handling (IR-4)
10.5 Incident Monitoring (IR-5)
10.6 Incident Reporting (IR-6)
10.7 Incident Response Assistance (IR-7)
11 MAINTENANCE
11.1 System Maintenance Policy and Procedures (MA-1)
11.2 Controlled Maintenance (MA-2)
11.3 Maintenance Tools (MA-3)
11.4 Remote Maintenance (MA-4)
11.5 Maintenance Personnel (MA-5)
11.6 Timely Maintenance (MA-6)
12 MEDIA PROTECTION
12.1 Media Protection Policy and Procedures (MP-1)
12.2 Media Access (MP-2)
12.3 Media Labeling (MP-3)
12.4 Media Storage (MP-4)
12.5 Media Transport (MP-5)
12.6 Media Sanitization and Disposal (MP-6)
13 PHYSICAL AND ENVIRONMENTAL PROTECTION
13.1 Physical and Environmental Protection Policy and Procedures (PE-1)
13.2 Physical Access Authorizations (PE-2)
13.3 Physical Access Control (PE-3)
13.4 Access Control for Transmission Medium (PE-4)
13.5 Access Control for Display Medium (PE-5)
13.6 Monitoring Physical Access (PE-6)
13.7 Visitor Control (PE-7)
13.8 Access Records (PE-8)
WARNING: This record contains Sensitive Security Information that is controlled under 49 CFR parts 15 and 1520. No part of this record may be disclosed to persons without a “need to know”, as defined in 49 CFR parts 15 and 1520, except with the written permission of the Administrator of the Transportation Security Administration or the Secretary of Transportation. Unauthorized release may result in civil penalty or other action. For U.S. government agencies, public disclosure is governed by 5 U.S.C. 552 and 49
CFR parts 15 and 1520.
13.9 Power Equipment and Power Cabling (PE-9)
13.10 Emergency Shutoff (PE-10)
13.11 Emergency Power (PE-11)
13.12 Emergency Lighting (PE-12)
13.13 Fire Protection (PE-13)
13.14 Temperature and Humidity Controls (PE-14)
13.15 Water Damage Protection (PE-15)
13.16 Delivery and Removal (PE-16)
13.17 Alternate Work Site (PE-17)
13.18 Location of Information System Components (PE-18)
13.19 Information Leakage (PE-19)
14 PLANNING
14.1 Security Planning Policy and Procedures (PL-1)
14.2 System Security Plan (PL-2)
14.3 System Security Plan Update (PL-3)
14.4 Rules of Behavior (PL-4)
14.5 Privacy Impact Assessment (PL-5)
14.6 Security-Related Activity Planning (PL-6)
15 PERSONNEL SECURITY
15.1 Personnel Security Policy and Procedures (PS-1)
15.2 Position Categorization (PS-2)
15.3 Personnel Screening (PS-3)
15.4 Personnel Termination (PS-4)
15.5 Personnel Transfer (PS-5)
15.6 Access Agreements (PS-6)
15.7 Third-Party Personnel Security (PS-7)
15.8 Personnel Sanctions (PS-8)
16 RISK ASSESSMENT
16.1 Risk Assessment Policy and Procedures (RA-1)
16.2 Security Categorization (RA-2)
16.3 Risk Assessment (RA-3)
WARNING: This record contains Sensitive Security Information that is controlled under 49 CFR parts 15 and 1520. No part of this record may be disclosed to persons without a “need to know”, as defined in 49 CFR parts 15 and 1520, except with the written permission of the Administrator of the Transportation Security Administration or the Secretary of Transportation. Unauthorized release may result in civil penalty or other action. For U.S. government agencies, public disclosure is governed by 5 U.S.C. 552 and 49
CFR parts 15 and 1520.
16.4 Risk Assessment Update (RA-4)
16.5 Vulnerability Scanning (RA-5)
17 SYSTEM AND SERVICES ACQUISITION
17.1 System and Services Acquisition Policy and Procedures (SA-1)
17.2 Allocation of Resources (SA-2)
17.3 Life Cycle Support (SA-3)
17.4 Acquisitions (SA-4)
17.5 Information System Documentation (SA-5)
17.6 Software Usage Restrictions (SA-6)
17.7 User Installed Software (SA-7)
17.8 Security Engineering Principles (SA-8)
17.9 External Information System Services (SA-9)
17.10 Developer Configuration Management (SA-10)
17.11 Developer Security Testing (SA-11)
18 SYSTEM AND COMMUNICATIONS PROTECTION
18.1 System and Communications Protection Policy (SC-1)
18.2 Application Partitioning (SC-2)
18.3 Security Function Isolation (SC-3)
18.4 Information Remnance (SC-4)
18.5 Denial of Service Protection (SC-5)
18.6 Resource Priority (SC-6)
18.7 Boundary Protection (SC-7)
18.8 Transmission Integrity (SC-8)
18.9 Transmission Confidentiality (SC-9)
18.10 Network Disconnect (SC-10)
18.11 Trusted Path (SC-11)
18.12 Cryptographic Key Establishment and Management (SC-12)
18.13 Use of Cryptography (SC-13)
18.14 Public Access Protections (SC-14)
18.15 Collaborative Computing (SC-15)
18.16 Transmission of Security Parameters (SC-16)
18.17 Public Key Infrastructure Certificates (SC-17)
WARNING: This record contains Sensitive Security Information that is controlled under 49 CFR parts 15 and 1520. No part of this record may be disclosed to persons without a “need to know”, as defined in 49 CFR parts 15 and 1520, except with the written permission of the Administrator of the Transportation Security Administration or the Secretary of Transportation. Unauthorized release may result in civil penalty or other action. For U.S. government agencies, public disclosure is governed by 5 U.S.C. 552 and 49
CFR parts 15 and 1520.
18.18 Mobile Code (SC-18)
18.19 Voice Over Internet Protocol (SC-19)
18.20 Secure Name/Address Resolution Service (Authoritative Source) (SC-20)
18.21 Secure Name/Address Resolution Service (Recursive or Caching Resolver) (SC-21) ... 45
18.22 Architecture and Provisioning for Secure Name/Address Resolution Service (SC-22) .. 45
18.23 Session Authenticity (SC-23)
19 SYSTEM AND INFORMATION INTEGRITY
19.1 System and Information Integrity Policy and Procedures (SI-1)
19.2 Flaw Remediation (SI-2)
19.3 Malicious Code Protection (SI-3)
19.4 Information System Monitoring Tools and Techniques (SI-4)
19.5 Security Alerts and Advisories (SI-5)
19.6 Security Functionality Verification (SI-6)
19.7 Software and Information Integrity (SI-7)
19.8 Spam Protection (SI-8)
19.9 Information Input Restrictions (SI-9)
19.10 Information Input Accuracy, Completeness, Validity and Authenticity (SI-10)
19.11 Error Handling (SI-11)
19.12 Information Output Handling and Retention (SI-12)
APPENDIX A - DEFINITIONS AND ACRONYMS
APPENDIX B - ACCESS CONTROL PROCEDURE
APPENDIX C - MEDIA PROTECTION PROCEDURE
APPENDIX D - SECURITY AWARENESS AND ROLE-BASED TRAINING
ATTACHMENT 1 – INFORMATION SECURITY CONCEPT OF OPERATIONS
ATTACHMENT 2 – AUDIT AND ACCOUNTABILITY PROCEDURE
ATTACHMENT 3 – CERTIFICATION AND ACCREDITATION (C&A) PROCEDURE
ATTACHMENT 4 – INCIDENT RESPONSE PROCESS
WARNING: This record contains Sensitive Security Information that is controlled under 49 CFR parts 15 and 1520. No part of this record may be disclosed to persons without a “need to know”, as defined in 49 CFR parts 15 and 1520, except with the written permission of the Administrator of the Transportation Security Administration or the Secretary of Transportation. Unauthorized release may result in civil penalty or other action. For U.S. government agencies, public disclosure is governed by 5 U.S.C. 552 and 49
CFR parts 15 and 1520.
ATTACHMENT 5 – PERSONNEL AND PHYSICAL SECURITY
ENCLOSURE – PERSONNEL TERMINATION CHECKLIST
List of Tables
TABLE 1-1 SECURITY PROGRAM ROLES AND RESPONSIBILITIES
TABLE 1-2 SECURITY CONTROLS
TABLE 2-1 INFORMATION SECURITY SERVICES AND FUNCTIONS
1 INTRODUCTION
The Introduction should provide the following information:
Purpose and scope of the SPP.
High-level description of IT resources deployed.
High-level summary of major business units within the organization impacted by the
SPP.
High-level review of interoperability factors associated with individual business units and how these impact the security of information processed within each business unit.
Assessment of interoperability between business units and the impact on data exchange.
Assessment of interoperability between external trading partners and internal business units.
Roles and responsibilities of IT personnel in the implementation of the SPP and its subcomponents.
1.1 Purpose
1.2 Scope
1.3 Authorities
1.4 Definitions and Acronyms
1.5 Roles and Responsibilities
WARNING: This record contains Sensitive Security Information that is controlled under 49 CFR parts 15 and 1520. No part of this record may be disclosed to persons without a “need to know”, as defined in 49 CFR parts 15 and 1520, except with the written permission of the Administrator of the Transportation Security Administration or the Secretary of Transportation. Unauthorized release may result in civil penalty or other action. For U.S. government agencies, public disclosure is governed by 5 U.S.C. 552 and 49
Table 1-1 Security Program Roles and Responsibilities
Role Responsibilities
Information Systems
Security Manager
(ISSM)
Administers the provisions of the SPP and associated contract documentation, as a component of the HSAR and TSA Information
Security (IS) Program.
Advises the Department of Homeland Security (DHS) Chief Information
Security Officer (CISO) on the security of contractor IT systems.
Certification
Agent/Certification
Authority (CA)
Certifies that adequate security controls are in place.
Designated
Approving Authority
(DAA)
A senior management official or executive with the authority to formally assume responsibility for operating an information system at an acceptable level of risk to agency operations, assets, and individuals.
Contractor Validate that the provisions of this SPP are in place and enforced.
1.6 Organization of the Remaining Sections of the Security Program Plan
1.6.1 Overview of the Security Program
1.6.2 Security Control Functions
Table 1-2 Security Controls
Identifier Family SPP
Section
AC Access Control 3
AT Awareness and Training 4
AU Audit and Accountability 5
CA Certification, Accreditation, and Security Assessments 6
CM Configurations Management 7
WARNING: This record contains Sensitive Security Information that is controlled under 49 CFR parts 15 and 1520. No part of this record may be disclosed to persons without a “need to know”, as defined in 49 CFR parts 15 and 1520, except with the written permission of the Administrator of the Transportation Security Administration or the Secretary of Transportation. Unauthorized release may result in civil penalty or other action. For U.S. government agencies, public disclosure is governed by 5 U.S.C. 552 and 49
CFR parts 15 and 1520.
Identifier Family SPP
Section
CP Contingency Planning 8
IA Identification and Authentication 9
IR Incident Response 10
MA Maintenance 11
ME Media Protection 12
PE Physical and Environmental Protection 13
PL Planning 14
PS Personnel Security 15
RA Risk Assessment 16
SA System and Services Acquisition 17
SC System and Communications Protection 18
SI System and Information Integrity 19
1.6.3 Appendices of the SPP
Appendix A contains the list of definitions and acronyms. Appendices B through D describe the procedures established by the program for accomplishing Access Control, Media Protection, and
Security Awareness/Role Based Training.
1.6.4 Security Plan Documentation
2 SECURITY PROGRAM OVERVIEW
2.1 Objectives
2.2 Approach
2.3 Services and Functions
2.4 Security Events Monitoring (SEM) Guide
Table 2-1 Information Security Services and Functions
WARNING: This record contains Sensitive Security Information that is controlled under 49 CFR parts 15 and 1520. No part of this record may be disclosed to persons without a “need to know”, as defined in 49 CFR parts 15 and 1520, except with the written permission of the Administrator of the Transportation Security Administration or the Secretary of Transportation. Unauthorized release may result in civil penalty or other action. For U.S. government agencies, public disclosure is governed by 5 U.S.C. 552 and 49
CFR parts 15 and 1520.
Service Function
3 ACCESS AND LOGICAL CONTROL PROTECTION
A) Access Control:
Describe how your organization limits information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems) and to the types of transactions and functions that authorized users are permitted to exercise.
B) Logical and Physical Protection:
Per Chapter 4 of the TSA Security Policy Handbook, describe the logical and physical controls that apply to all information processing systems deployed throughout the networked environment. Provide a summary of all applicable physical, procedural, personnel and environmental controls.
Describe the organizational processes and procedures for ensuring the application of technical controls over information processing systems. Identify roles, individuals, and business sub-units, within the Managed Service Provider, that are responsible for implementing, administering, maintaining, using, and testing information security controls.
3.1 Access Control Policy and Procedures (AC-1)
Demonstrate how the organization will develop, disseminate, and periodically review/update: (i) a formal, documented, access control policy that addresses purpose, scope, roles, responsibilities, and compliance; and (ii) formal, documented procedures to facilitate the implementation of the access control policy and associated access controls.
WARNING: This record contains Sensitive Security Information that is controlled under 49 CFR parts 15 and 1520. No part of this record may be disclosed to persons without a “need to know”, as defined in 49 CFR parts 15 and 1520, except with the written permission of the Administrator of the Transportation Security Administration or the Secretary of Transportation. Unauthorized release may result in civil penalty or other action. For U.S. government agencies, public disclosure is governed by 5 U.S.C. 552 and 49
3.2 Account Management (AC-2)
Describe how the organization will manage information system accounts, including establishing, activating, modifying, reviewing, disabling, and removing accounts.
3.3 Access Enforcement (AC-3)
Describe how assigned authorizations for controlling access to the system are enforced in accordance with applicable policy.
3.4 Information Flow Enforcement (AC-4)
Describe how the information system will enforce assigned authorizations for controlling the flow of information within the system and between interconnected systems in accordance with applicable policy.
3.5 Separation of Duties (AC-5)
Describe how the information system will enforce separation of duties through assigned access authorizations.
3.6 Least Privilege (AC-6)
Describe how the information system will enforce the most restrictive set of rights/privileges or accesses needed by users (or processes acting on behalf of users) for the performance of specified tasks.
3.7 Unsuccessful Login Attempts (AC-7)
Describe how the information system will enforce a limit of consecutive invalid access attempts by a user during a time period. The information system automatically locks the account/node when the maximum number of unsuccessful attempts is exceeded.
WARNING: This record contains Sensitive Security Information that is controlled under 49 CFR parts 15 and 1520. No part of this record may be disclosed to persons without a “need to know”, as defined in 49 CFR parts 15 and 1520, except with the written permission of the Administrator of the Transportation Security Administration or the Secretary of Transportation. Unauthorized release may result in civil penalty or other action. For U.S. government agencies, public disclosure is governed by 5 U.S.C. 552 and 49
3.8 System Use Notification (AC-8)
Describe how the information system will display an approved, system use notification message before granting system access informing potential users: (i) that the user is accessing a U.S.
Government information system; (ii) that system usage may be monitored, recorded, and subject to audit; (iii) that unauthorized use of the system is prohibited and subject to criminal and civil penalties; and (iv) that use of the system indicates consent to monitoring and recording.
3.9 Previous Logon Notification (AC-9)
Describe how the information system will notify the user, upon successful logon, of the date and time of the last logon, and the number of unsuccessful logon attempts since the last successful logon.
3.10 Concurrent Session Control (AC-10)
Describe how the information system will limit the number of concurrent sessions for any user to an organization-defined number of sessions.
3.11 Session Lock (AC-11)
Describe how the information system will prevent further access to the system by initiating a session lock that remains in effect until the user reestablishes access using appropriate identification and authentication procedures.
3.12 Session Termination (AC-12)
Describe how the information system will automatically terminate a session after a specified period of inactivity.
WARNING: This record contains Sensitive Security Information that is controlled under 49 CFR parts 15 and 1520. No part of this record may be disclosed to persons without a “need to know”, as defined in 49 CFR parts 15 and 1520, except with the written permission of the Administrator of the Transportation Security Administration or the Secretary of Transportation. Unauthorized release may result in civil penalty or other action. For U.S. government agencies, public disclosure is governed by 5 U.S.C. 552 and 49
3.13 Supervision and Review – Access Control (AC-13)
Describe how the organization will supervise and review the activities of users with respect to the enforcement and usage of information system access controls.
3.14 Permitted Actions without Identification or Authentication (AC-14)
Describe how the organization will identify specific user actions that can be performed on the information system without identification or authentication.
3.15 Automated Marking (AC-15)
Describe how the information system will mark output using standard naming conventions to identify any special dissemination, handling, or distribution instructions.
3.16 Automated Labeling (AC-16)
Describe how the information system will appropriately label information in storage, in process, and in transmission.
3.17 Remote Access (AC-17)
Describe how the organization will document, monitor, and control all methods of remote access
(e.g., dial-up, Internet) to the information system including remote access for privileged functions. Also describe how appropriate organization officials will authorize each remote access method for the information system and authorize only the necessary users for each access method.
3.18 Wireless Access Restrictions (AC-18)
Describe how the organization will: (i) establish usage restrictions and implementation guidance for wireless technologies; and (ii) document, monitor, and control wireless access to the
WARNING: This record contains Sensitive Security Information that is controlled under 49 CFR parts 15 and 1520. No part of this record may be disclosed to persons without a “need to know”, as defined in 49 CFR parts 15 and 1520, except with the written permission of the Administrator of the Transportation Security Administration or the Secretary of Transportation. Unauthorized release may result in civil penalty or other action. For U.S. government agencies, public disclosure is governed by 5 U.S.C. 552 and 49
CFR parts 15 and 1520.
information system. Also describe how the appropriate organizational officials will authorize the use of wireless technologies.
3.19 Access Control for Portable and Mobile Systems (AC-19)
for portable and mobile devices; and (ii) document, monitor, and control device access to organizational networks. Appropriate organizational officials authorize the use of portable and mobile devices.
3.20 Use of External Information Systems (AC-20)
Describe how the organization will establish terms and conditions for authorized individuals to access the information system from an external information system and process, store, and/or transmit organization-controlled information using an external information system.
4 AWARENESS AND TRAINING
Describe how your organization will:
Ensure that managers and users of organizational information systems are made aware of the security risks associated with their activities and of the applicable laws, Executive
Orders, directives, policies, standards, instructions, regulations, or procedures related to the security of organizational information systems
Ensure that organizational personnel are adequately trained to carry out their assigned information security-related duties and responsibilities.
Provide details about the Managed Service Provider’s development and implementation of security awareness training programs for the end user population and specific programs for technical security training provided to IT network and security management personnel.
4.1 Security Awareness and Role-Based Training Policy and Procedures (AT-1)
WARNING: This record contains Sensitive Security Information that is controlled under 49 CFR parts 15 and 1520. No part of this record may be disclosed to persons without a “need to know”, as defined in 49 CFR parts 15 and 1520, except with the written permission of the Administrator of the Transportation Security Administration or the Secretary of Transportation. Unauthorized release may result in civil penalty or other action. For U.S. government agencies, public disclosure is governed by 5 U.S.C. 552 and 49
CFR parts 15 and 1520.
Describe how the organization will develop, disseminate, and periodically review/update: (i) a formal, documented, security awareness and training policy that addresses purpose, scope, roles, responsibilities, and compliance; and (ii) formal, documented procedures to facilitate the implementation of the security awareness and training policy and associated security awareness and training controls.
4.2 Security Awareness (AT-2)
Describe how the organization will ensure all users (including managers and senior executives) are exposed to basic information system security awareness materials before authorizing access to the system and, at least, annually thereafter.
4.3 Security Training (AT-3)
Describe how the organization will identify personnel with significant information system security roles and responsibilities, document those roles and responsibilities, and provide appropriate information system security training before authorizing access to the system and on a regular basis thereafter.
4.4 Security Training Records (AT-4)
Describe how the organization will document and monitor individual information system security training activities including basic security awareness training and specific information system security training.
4.5 Contacts with Security Groups and Associations (AT-5)
Describe how the organization will establish and maintain contacts with special interest groups, specialized forums, professional associations, news groups, and/or peer groups of security professionals in similar organizations to stay up to date with the latest recommended security practices, techniques, and technologies and to share the latest security-related information including threats, vulnerabilities, and incidents.
WARNING: This record contains Sensitive Security Information that is controlled under 49 CFR parts 15 and 1520. No part of this record may be disclosed to persons without a “need to know”, as defined in 49 CFR parts 15 and 1520, except with the written permission of the Administrator of the Transportation Security Administration or the Secretary of Transportation. Unauthorized release may result in civil penalty or other action. For U.S. government agencies, public disclosure is governed by 5 U.S.C. 552 and 49
5 AUDIT AND ACCOUNTABILITY
5.1 Audit and Accountability Policy and Procedures (AU-1)
Describe how the organization will develop, disseminate, and periodically review/update: (i) a formal, documented, audit and accountability policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (ii) formal, documented procedures to facilitate the implementation of the audit and accountability policy and associated audit and accountability controls.
5.2 Auditable Events (AU-2)
Describe how the organization will generate audit records for events that are significant and relevant to the security of the system.
5.3 Content of Audit Records (AU-3)
Describe how the organization will capture sufficient information in audit records to establish what events occurred, the sources of the events, and the outcomes of the events.
5.4 Audit Storage Capacity (AU-4)
Describe how the organization will allocate sufficient audit record storage capacity and configure auditing to prevent such capacity being exceeded.
5.5 Response to Audit Processing Failures (AU-5)
Describe how the organization will alert appropriate organizational officials in the event of an audit processing failure and takes the following additional actions including: shutdown information system, overwrite oldest audit records, stop generating audit records.
WARNING: This record contains Sensitive Security Information that is controlled under 49 CFR parts 15 and 1520. No part of this record may be disclosed to persons without a “need to know”, as defined in 49 CFR parts 15 and 1520, except with the written permission of the Administrator of the Transportation Security Administration or the Secretary of Transportation. Unauthorized release may result in civil penalty or other action. For U.S. government agencies, public disclosure is governed by 5 U.S.C. 552 and 49
CFR parts 15 and 1520.
5.6 Audit Monitoring, Analysis, and Reporting (AU-6)
Describe how the organization will regularly review/analyze audit records for indications of inappropriate or unusual activity, investigates suspicious activity or suspected violations, reports findings to appropriate officials, and takes necessary actions.
5.7 Audit Reduction and Report Generation (AU-7)
Describe how the organization will provide an audit reduction and report generation capability.
5.8 Time Stamps (AU-8)
Describe how time stamps will be implemented for use in audit record generation.
5.9 Protection of Audit Information (AU-9)
Describe how audit information and audit tools will be protected from unauthorized access, modification, and deletion.
5.10 Non-Repudiation (AU-10)
Describe how the capability to determine whether an individual took a particular action will be provided.
5.11 Audit Record Retention (AU-11)
Describe how, and for how long, the organization will retain audit records to provide support for after-the-fact investigations of security incidents and to meet regulatory and organizational information retention requirements.
6 CERTIFICATION, ACCREDITATION, AND SECURITY ASSESSMENTS
Security accreditation is about the acceptance and management of risk—the risk to agency operations, agency assets, or individuals that results from the operation of an information system.
WARNING: This record contains Sensitive Security Information that is controlled under 49 CFR parts 15 and 1520. No part of this record may be disclosed to persons without a “need to know”, as defined in 49 CFR parts 15 and 1520, except with the written permission of the Administrator of the Transportation Security Administration or the Secretary of Transportation. Unauthorized release may result in civil penalty or other action. For U.S. government agencies, public disclosure is governed by 5 U.S.C. 552 and 49
CFR parts 15 and 1520.
Security certification directly supports security accreditation by providing authorizing officials with important information necessary to make credible, risk-based decisions on whether to place information systems into operation or continue their current operation.
6.1 Certification, Accreditation, and Security Assessment Policies and Procedures (CA-1)
Describe how the organization will develop, disseminate, and periodically review/update: (i) formal, documented, security assessment and certification and accreditation policies that address purpose, scope, roles, responsibilities, and compliance; and (ii) formal, documented procedures to facilitate the implementation of the security assessment and certification and accreditation policies and associated assessment, certification, and accreditation controls.
6.2 Security Assessments (CA-2)
Describe how the organization will conduct an assessment of the security controls in the information system to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system.
6.3 Information System Connections (CA-3)
Describe how the organization will authorize all connections from the information system to other information systems outside of the accreditation boundary and monitors/controls the system interconnections on an ongoing basis. Also describe how the appropriate organizational officials will approve information system interconnection agreements.
6.4 Security Certification (CA-4)
WARNING: This record contains Sensitive Security Information that is controlled under 49 CFR parts 15 and 1520. No part of this record may be disclosed to persons without a “need to know”, as defined in 49 CFR parts 15 and 1520, except with the written permission of the Administrator of the Transportation Security Administration or the Secretary of Transportation. Unauthorized release may result in civil penalty or other action. For U.S. government agencies, public disclosure is governed by 5 U.S.C. 552 and 49
CFR parts 15 and 1520.
Describe how the organization will conduct an assessment of the security controls in the information system to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system.
6.5 Plan of Action and Milestones (CA-5)
Describe how the organization will develop and update, on a periodic basis, a plan of action and milestones for the information system that documents the organization’s planned, implemented, and evaluated remedial actions to correct any deficiencies noted during the assessment of the security controls and to reduce or eliminate known vulnerabilities in the system.
6.6 Security Accreditation (CA-6)
Describe how the organization will authorize (i.e., accredit) the information system for processing before operations and updates the authorization. Also describe how senior organizational officials will sign and approve the security accreditation.
6.7 Continuous Monitoring (CA-7)
Describe how the organization will monitor the security controls in the information system on an ongoing basis.
7 CONFIGURATION MANAGEMENT
This section describes the implementation of the seven security controls comprising the
Configuration Management control family.
7.1 Configuration Management Policy and Procedures (CM-1)
Describe how the organization will develop, disseminate, and periodically review/update: (i) a formal, documented, configuration management policy that addresses purpose, scope, roles, responsibilities, and compliance; and (ii) formal, documented procedures to facilitate the
WARNING: This record contains Sensitive Security Information that is controlled under 49 CFR parts 15 and 1520. No part of this record may be disclosed to persons without a “need to know”, as defined in 49 CFR parts 15 and 1520, except with the written permission of the Administrator of the Transportation Security Administration or the Secretary of Transportation. Unauthorized release may result in civil penalty or other action. For U.S. government agencies, public disclosure is governed by 5 U.S.C. 552 and 49
CFR parts 15 and 1520.
implementation of the configuration management policy and associated configuration management controls.
7.2 Baseline Configuration (CM-2)
Describe how the organization will develop, document, and maintain a current, baseline configuration of the information system and an inventory of the system’s constituent components.
7.3 Configuration Change Control (CM-3)
Describe how the organization will document and control changes to the information system.
Appropriate organizational officials approve information system changes in accordance with organizational policies and procedures.
7.4 Monitoring Configuration Changes (CM-4)
Describe how the organization will monitor changes to the information system and conducts security impact analyses to determine the effects of the changes.
7.5 Access Restrictions for Change (CM-5)
Describe how the organization will enforce access restrictions associated with changes to the information system.
7.6 Configuration Settings (CM-6)
Describe how the organization will configure the security settings of information technology products to the most restrictive mode consistent with information system operational requirements.
7.7 Least Functionality (CM-7)
WARNING: This record contains Sensitive Security Information that is controlled under 49 CFR parts 15 and 1520. No part of this record may be disclosed to persons without a “need to know”, as defined in 49 CFR parts 15 and 1520, except with the written permission of the Administrator of the Transportation Security Administration or the Secretary of Transportation. Unauthorized release may result in civil penalty or other action. For U.S. government agencies, public disclosure is governed by 5 U.S.C. 552 and 49
CFR parts 15 and 1520.
Describe how the organization will configure the information system to provide only essential capabilities and specifically prohibits and/or restricts the use of the following functions, ports, protocols, and/or services.
7.8 Information System Component Inventory (CM-8)
Describe how the organization will develop, document, and maintain a current inventory of the components of the information system and relevant ownership information.
8 CONTINGENCY PLANNING
This section describes the implementation of the ten security controls comprising the
Contingency Planning control family.
8.1 Contingency Planning Policy and Procedures (CP-1)
formal, documented, contingency planning policy that addresses purpose, scope, roles, responsibilities, and compliance; and (ii) formal, documented procedures to facilitate the implementation of the contingency planning policy and associated contingency planning controls.
8.2 Contingency Plan (CP-2), Training (CP-3), Testing (CP-4), and Updating (CP-5)
Describe how the organization will develop and implement a contingency plan for the information system addressing contingency roles, responsibilities, assigned individuals with contact information, and activities associated with restoring the system after a disruption or failure. Also describe how designated officials within the organization will review and approve the contingency plan and distribute copies of the plan to key contingency personnel.
8.3 Contingency Training (CP-3)
WARNING: This record contains Sensitive Security Information that is controlled under 49 CFR parts 15 and 1520. No part of this record may be disclosed to persons without a “need to know”, as defined in 49 CFR parts 15 and 1520, except with the written permission of the Administrator of the Transportation Security Administration or the Secretary of Transportation. Unauthorized release may result in civil penalty or other action. For U.S. government agencies, public disclosure is governed by 5 U.S.C. 552 and 49
CFR parts 15 and 1520.
Describe how the organization will train personnel in their contingency roles and responsibilities with respect to the information system and provides refresher.
8.4 Contingency Plan Testing and Exercises (CP-4)
Describe how the organization will test and/or exercises the contingency plan for the information system to determine the plan’s effectiveness and the organization’s readiness to execute the plan.
Include how appropriate officials within the organization review the contingency plan test results and initiate corrective actions.
8.5 Contingency Plan Update (CP-5)
Describe how the organization will review the contingency plan for the information system and revises the plan to address system/organizational changes or problems encountered during plan implementation, execution, or testing.
8.6 Alternate Storage Sites (CP-6)
Describe how the organization will identify an alternate storage site and initiates necessary agreements to permit the storage of information system backup information.
8.7 Alternate Processing Sites (CP-7)
Describe how the organization will identify an alternate processing site and initiates necessary agreements to permit the resumption of information system operations for critical mission/business functions within a defined timeframe when the primary processing capabilities are unavailable.
8.8 Telecommunications Services (CP-8)
WARNING: This record contains Sensitive Security Information that is controlled under 49 CFR parts 15 and 1520. No part of this record may be disclosed to persons without a “need to know”, as defined in 49 CFR parts 15 and 1520, except with the written permission of the Administrator of the Transportation Security Administration or the Secretary of Transportation. Unauthorized release may result in civil penalty or other action. For U.S. government agencies, public disclosure is governed by 5 U.S.C. 552 and 49
CFR parts 15 and 1520.
Describe how the organization will identify primary and alternate telecommunications services to support the information system and initiates necessary agreements to permit the resumption of system operations for critical mission/business when the primary telecommunications capabilities are unavailable.
8.9 Information System Backup (CP-9)
Describe how the organization will conduct backups of user-level and system-level information
(including system state information) contained in the information and stores backup information at an appropriately secured location.
8.10 Information System Recovery and Reconstitution (CP-10)
Describe how the organization will employ mechanisms with supporting procedures to allow the information system to be recovered and reconstituted to the system’s original state after a disruption or failure.
9 IDENTIFICATION AND AUTHENTIFICATION, IT ASSET IDENTIFICATION AND
ASSESSMENT
This section describes the implementation of the seven security controls comprising the
Identification and Authentication control family.
9.1 Identification and Authentication Policy and Procedures (IA-1) formal, documented, identification and authentication policy that addresses purpose, scope, roles, responsibilities, and compliance; and (ii) formal, documented procedures to facilitate the implementation of the identification and authentication policy and associated identification and authentication controls.
9.2 User Identification and Authentication (IA-2)
WARNING: This record contains Sensitive Security Information that is controlled under 49 CFR parts 15 and 1520. No part of this record may be disclosed to persons without a “need to know”, as defined in 49 CFR parts 15 and 1520, except with the written permission of the Administrator of the Transportation Security Administration or the Secretary of Transportation. Unauthorized release may result in civil penalty or other action. For U.S. government agencies, public disclosure is governed by 5 U.S.C. 552 and 49
CFR parts 15 and 1520.
Describe how the information system will uniquely identify and authenticate users (or processes acting on behalf of users).
9.3 Device Identification and Authentication (IA-3)
Describe how the information system will identify and authenticate specific devices before establishing a connection.
9.4 Identifier Management (IA-4)
Describe how the organization will manage user identifiers by: (i) uniquely identifying each user; (ii) verifying the identity of each user; (iii) receiving authorization to issue a user identifier from an appropriate organization official; (iv) ensuring that the user identifier is issued to the intended party; (v) disabling user identifier after a defined time period of inactivity; and (vi) archiving user identifiers.
9.5 Authenticator Management (IA-5)
Describe how the organization will manage information system authenticators (e.g., tokens, PKI certificates, biometrics, passwords, key cards) by: (i) defining initial authenticator content; (ii) establishing administrative procedures for initial authenticator distribution, for lost/compromised, or damaged authenticators, and for revoking authenticators; and (iii) changing default authenticators upon information system installation.
9.6 Authenticator Feedback (IA-6)
Describe how the information system will provide feedback to a user during an attempted authentication and how that feedback will not compromise the authentication mechanism.
9.7 Cryptographic Module Authentication (IA-7)
WARNING: This record contains Sensitive Security Information that is controlled under 49 CFR parts 15 and 1520. No part of this record may be disclosed to persons without a “need to know”, as defined in 49 CFR parts 15 and 1520, except with the written permission of the Administrator of the Transportation Security Administration or the Secretary of Transportation. Unauthorized release may result in civil penalty or other action. For U.S. government agencies, public disclosure is governed by 5 U.S.C. 552 and 49
CFR parts 15 and 1520.
Describe how, for authentication to a cryptographic module, the information system will employ authentication methods that meet the requirements of FIPS 140-2.
10 INCIDENT RESPONSE AND INFORMATION SECURITY INCIDENT HANDLING
This section describes the implementation of the seven security controls comprising the Incident
Response control family.
10.1 Incident Response Policy and Procedure (IR-1)
Describe how the organization will develop, disseminate, and periodically review/update: (i) a formal, documented, incident response policy that addresses purpose, scope, roles, implementation of the incident…
This is the start of the file's text. The full file is on GovTribe.
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| HSTS04-09-R-CT4005 Amendment 004.pdf | ||
| Attachment_ 3 Labor Category Descriptions.pdf | ||
| HSTS04-09-R-CT4005 Amendment 003.pdf | ||
| Attachment 2_Task Order 001.pdf | ||
| Attachment 1_ CDRLs-DIDs.pdf | ||
| Attachment 6_Test and Evaluation Directive 026-06.pdf | ||
| Attachment 3_Labor Category Descriptions.pdf | ||
| TESS HSTS04-09-R-CT4005 Amendment 002.pdf | ||
| TESS HSTS04-09-R-CT4005 Amendment 001.pdf | ||
| Attachment 3 Labor Category Descriptions.pdf | ||
| TESS RFP HSTS04-09-R-CT4005 6.09.09.pdf | ||
| Attachment 1 CDRLs-DIDs.pdf | ||
| Attachment 2 Task Order 001.pdf | ||
| Attachment 4 DD 254 - Contract Security Classification Specification.pdf | ||
| Attachment 5 Past Performance Questionnaire.pdf |
Show all 15
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
File details come from the government source that posted it. Updated .