28. DRAFT - Template_Program of Record_DHA Info Sys Contingency Plan.docx
DOCX document 592 KB Posted
- Attached to
- Charleston Consolidated Storage Distribution Center Federal contract opportunity
- Solicitation number
- Not on record
About this file
This document provides details for an upcoming federal contract opportunity for initial outfitting services at a consolidated storage and distribution center. The U.S. Army Corps of Engineers Little Rock District intends to issue a request for quote for outfitting work at the Charleston Consolidated Storage and Distribution Center with an estimated contract value between $1.5-2 million. The solicitation will use simplified acquisition procedures under FAR Part 13 in conjunction with commercial item procedures under FAR Part 12. The requirement is set aside for small businesses with a NAICS code of 337127 and size standard of 500 employees. The anticipated proposal due date is September 2nd, 2022, with a site visit scheduled for August 23rd and questions accepted through August 25th. Potential dates for the notice of award and start of performance are January 19th and March 19th, 2023, respectively.
View the file
Other files for this federal contract opportunity
Show all 37
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
INSERT PROGRAM OFFICE NAME
Contingency Plan Insert eMASS System Name
Insert eMASS SYSTEM ACRONYM
DD MM YYYY
Version 1.1
UNCLASSIFIED
Insert POR Name IS Contingency Plan
FOR OFFICIAL USE ONLY
vi
DOCUMENT HISTORY
| Version |
| Date |
| Topic |
| Section/ |
Paragraph Page
| 1.0 |
| 5/17/2018 |
| Draft Template for RMF ISCP |
CSD COOP Team
| 1.2 | Comment by Windows User: Insert new change control information |
| 4/23/2019 | |
| Revised Annex L ref to NIST SP 800 53r4, eMASS, and overall pagination. |
CSD COOP Team
DISTRIBUTION STATEMENT: Distribution authorized to DoD and U.S. DoD contractors only.
Other requests for this document shall be referred to:
ATTN: POR PMO
DESTRUCTION NOTICE: Non-record Controlled Unclassified Information (CUI) documents may be destroyed by shredding or tearing into pieces and discarding the pieces in regular trash containers.
NOTE: The Department of Defense (DoD) defines an Information System (IS) as: a set of information resources organized for the collection, storage, processing, maintenance, use, sharing, dissemination, disposition, display, or transmission of information. An IS includes AIS applications, enclaves, outsourced IT-based processes, and platform IT interconnections. This term IS is used interchangeably as defined above by DoD.
The Program Office (PO) Name completing this Contingency Plan (CP) must state within Section 1.4, Scope, if the IS confidentiality, integrity, and availability categorization is deemed a to be high, moderate, or low. It must be stated in those sections how that determination was made and by whom it was made. This determination should be consistent with the information provided in Security Design Document.
The PO Name must indicate how they will fulfill their business requirement (i.e., use a manual process, etc.) if the IS is down due to an extraordinary event. Additionally, the PO Name is to indicate the amount of time that they can function with the IS being unavailable. If the PO Name references a corporate/hosting IS, the PO Name must ensure that the corporate/hosting IS’ CP incorporates the PO Name IS’ production requirements. The PO Name completing this CP should reference/provide, where applicable, the hosting IS’ CP; Service Level Agreement (SLA); and/or Interconnection Memorandum of Agreement (MOA), which shows responsibility for and compliance with the contingency planning requirement. Ensure that you are referencing the latest “approved” corporate/hosting IS CP, SLA, and/or Interconnection MOA.
Additionally, this CP must be customized to your IS’s CP practices, ensuring that the requirements shown here are addressed accordingly.
Agreement and Approval of the Contingency Plan for Insert POR Name (SP 800-34 Rev.1 A; [CP-2] [CCI-000457]) This signature page certifies agreement between the system’s Information System Security Manager (ISSM) and the system’s Information System Security Officer (ISSO) regarding the contingency plan for Insert POR Name. It affirms that the Contingency Plan contains or references all information required by National Institute for Standards and Technology (NIST) Special Publication SP 800-34 Rev.1 and NIST SP 800-53, Rev. 4.
The undersigned concur with the information contained in this contingency plan and agree that it accurately describes the efforts to be implemented to maintain the operation of the Insert POR Name.
The undersigned certify that the Contingency Plan is complete and that the information contained in this Contingency Plan provides an accurate representation of the system, its hardware, software, and telecommunication components. The undersigned further certify that this document identifies the criticality of the Program of Record (POR) as it relates to the mission of Insert POR Name, and that the recovery strategies identified will provide the ability to recover the functionality of Insert POR Name and any supported enclaves in the most expedient and cost beneficial method in keeping with its level of criticality.
The undersigned attest that this Insert POR Name Contingency Plan will be reviewed and tested at least annually. This Contingency Plan was last reviewed on Insert Date Here and last tested on Insert Date Here.
The undersigned acknowledge this Contingency Plan is a living document and will be modified based on the review process, lessons learned from Tests, Training, and Exercise (TT&E) activities, and/or as changes occur to the system and will remain under strict version control; a copy will be provided to the Defense Health Agency (DHA) as well as to those persons and sites responsible for the plan’s implementation and operation, as identified in the point of contact list found in Annex A.
/s/
| _________________________ | ||
| Name, Insert POR Name ISSM | Date |
/s/
| _________________________ | ||
| Name, Insert POR Name ISSO | Date |
TABLE OF CONTENTS
| Agreement and Approval of the Contingency Plan for Insert POR Name | iv | |
| 1 | INTRODUCTION | 1 |
| 1.1 | Contingency Planning Controls | 1 |
| 1.2 | Background | 2 |
| 1.3 | Background Objectives | 2 |
| 1.4 | Scope | 4 |
| 1.4.1 | Security Categorization and Control Baseline Compliance | 4 |
| 1.5 | Policy | 6 |
| 1.6 | Assumptions | 6 |
| 1.7 | Applicable Provisions and Directives | 7 |
| 1.8 | Threat Events Included | 8 |
| 1.9 | Preventive Measures | 9 |
| 2 | CONCEPT OF OPERATIONS | 11 |
| 2.1 | System Description | 11 |
| 2.2 | Overview of the Three COOP Phases | 11 |
| 2.2.1 | Activation and Notification Phase | 11 |
| 2.2.2 | Recovery Phase | 12 |
| 2.2.3 | Reconstitution Phase | 12 |
| 2.3 | Roles and Responsibilities | 12 |
| 2.3.1 | COOP Roles Organizational Chart | 14 |
| 2.3.2 | COOP Roles Point of Contact (POC) Information | 16 |
| 2.4 | Supplies | 16 |
| 2.5 | Transportation | 16 |
| 2.6 | Cost Considerations | 16 |
| 2.7 | Documentation | 17 |
| 3 | BUSINESS IMPACT ANALYSIS | 18 |
| 3.1 | Identification of Primary and Secondary Systems | 19 |
| 3.2 | Key Components Supporting Identified Systems | 21 |
| 3.3 | Threat Identification and Categorization | 23 |
| 3.4 | Risk Severity Determination | 27 |
| 3.5 | Primary Contingency Strategies for Risk Profiles | 28 |
| 3.5.1 | Strategies for Severity 1 Risks | 30 |
| 3.5.2 | Strategies for Severity 2 Risks | 30 |
| 3.5.3 | Strategies for Severity 3 Risks | 31 |
| 3.6 | Strategy Development in Response to Severity Risks | 31 |
| 3.7 | Scenario Driven Contingency Strategy Variations | 32 |
| 4 | ACTIVATION AND NOTIFICATION | 39 |
| 4.1 | Activation Criteria and Procedure | 39 |
| 4.2 | Notification | 40 |
| 4.3 | Outage Assessment | 40 |
| 5 | RECOVERY | 42 |
| 5.1 | Sequence of Recovery Activities | 42 |
| 5.2 | Recovery Procedures | 43 |
| 5.3 | Recovery Escalation Notices/Awareness | 43 |
| 6 | RECONSTITUTION | 44 |
| 6.1 | Validation Data Testing | 45 |
| 6.2 | Validation Functionality Testing | 45 |
| 6.3 | Recovery Declaration | 45 |
| 6.4 | Notifications | 45 |
| 6.5 | Cleanup | 45 |
| 6.6 | Offsite Data Storage | 45 |
| 6.7 | Data Backup | 46 |
| 6.8 | Event Documentation | 46 |
| 6.9 | Deactivation | 47 |
| 7 | ALTERNATE STORAGE, SITE AND TELECOMMUNICATIONS | 48 |
| 8 | HARDWARE AND SOFTWARE INVENTORY | 51 |
| 8.1 | Hardware/Software Inventory | 51 |
| 8.2 | Key Component Specifications and Vendor Contact Tables | 52 |
| 9 | ASSOCIATED PLANS, CONTRACTS AND/OR AGREEMENTS | 56 |
| 10 | AFTER ACTION REPORT AND DOCUMENT MANAGEMENT | 57 |
TABLE OF FIGURES
| Figure 1: Insert POR Name Contingency Plan Organizational Chart | 15 |
| Figure 2: Primary and Alternate Site Routing Picture | 49 |
| Figure 3: Insert POR Name Authorization Boundary Diagram | 68 |
| Figure 4: Insert POR Name Data Flow Diagram | 68 |
| Figure 5: Insert POR Name Interconnectivity Diagram | 68 |
TABLE OF TABLES
| Table 1: Summary of NIST SP 800-53 r4: Contingency Planning Controls | 2 |
| Table 2: Insert POR Name Continuity Compliance – Inheritance Mapping | 5 |
| Table 3: Contingency Plan Roles and Responsibilities | 14 |
| Table 4: Primary and Secondary System Identification | 20 |
| Table 5: Key Components Supporting Primary and Secondary System | 22 |
| Table 6: Threat Identification and Categorization | 25 |
| Table 7: Threat Categorization | 27 |
| Table 8: Risk Severity Matrix | 28 |
| Table 9: Threat Categorization and Severity | 30 |
| Table 10: Contingency Strategies and Implementation Variants | 34 |
| Table 11: Contingency Strategy Variation A | 35 |
| Table 12: Contingency Strategy Variation B | 36 |
| Table 13: Contingency Strategy Variation C | 36 |
| Table 14: Contingency Strategy Variation D | 37 |
| Table 15: Contingency Strategy Variation E | 37 |
| Table 16: Contingency Strategy Variation F | 38 |
| Table 17: Contingency Strategy Variation G | 38 |
| Table 18: Contingency Notification Procedures | 40 |
| Table 19: Recovery Sequence for Key Components | 43 |
| Table 20: Insert POR Name Hardware Inventory | 51 |
| Table 21: Insert POR Name Software Inventory | 51 |
| Table 22: Key Component Specifications and Vendor Contact Table | 53 |
| Table 23: Key Component Specifications and Vendor Contact Table | 54 |
| Table 24: Key Component Specifications and Vendor Contact Table | 55 |
| Table 25: Associated Plans, Contracts And/Or Agreements | 56 |
| Table 26: Key COOP Personnel Contact Information | 61 |
| Table 27: Personnel Successions | 62 |
| Table 28: System Validation Test Plan | 67 |
| Table 29: Interconnections Table | 69 |
| Table 30: Test and Maintenance Schedule | 70 |
| Table 31: Insert POR Name Contingency Control Implementations Table | 102 |
| Table 32: COOP Security Controls Baseline | 107 |
| Table 33: Incident Security Controls Baseline: | 109 |
TABLE OF ANNEXES
| Annex A: | Key COOP Personnel Contact Information | 59 |
| Annex B: | Succession Order | 62 |
| 1.0 | Overview | 62 |
| 2.0 | Approvals | 62 |
| Annex C: | ISCP Delegation of Authority | 64 |
| Annex D: | Detailed Recovery Procedures | 65 |
| Annex E: | Alternate Processing Procedures | 66 |
| Annex F: | System Validation Test Plan | 67 |
| Annex G: | Diagrams | 68 |
| Annex H: | Interconnections Table | 69 |
| Annex I: | Test and Maintenance Schedule | 70 |
| Annex J: | Glossary | 71 |
| Annex K: | Acronym List | 73 |
| Annex L: | Quarterly Readiness Checklist | 74 |
| Annex M: | Damage Assessment Procedures Report | 79 |
| 1.0 | Overview | 79 |
| 2.0 | Damage Assessment Report | 80 |
| Annex N: | Incident After Action Report | 81 |
| Annex O: | ISCP Activities Checklist | 82 |
| Annex P: | Incident Communications Report | 85 |
| 1.0 | Overview | 85 |
| 2.0 | Incident Communications Report | 87 |
| Annex Q: | Information System Shutdown Procedures | 89 |
| 1.0 | Primary System | 89 |
| 3.0 | Secondary Systems | 89 |
| Annex R: | Information System Startup Procedures | 90 |
| 1.0 | Primary System | 90 |
| 2.0 | Secondary Systems | 90 |
| Annex S: | Insert POR Name Contingency Control Implementations Table | 91 |
| Annex T: | COOP Related CNSSI 1253 Security Control Baselines | 103 |
| 4.0 | COOP Security Controls Baseline | 103 |
| 5.0 | Incident Security Controls Baseline | 107 |
| Annex U: | NIST SP 800-53 r4 COOP Related Controls | 110 |
| 1.0 | NIST SP 800-53 Rev.4 COOP Security Controls | 110 |
| 2.0 | NIST SP 800-53 r4 Incident Response Controls | 125 |
| 3.0 | NIST SP 800-53 r4 Other COOP Related Controls | 136 |
| Annex V: | Contingency Planning and Incident Response Common Controls | 142 |
| 1.0 | Contingency Planning Common Controls | 142 |
| 2.0 | Incident Response Common Controls | 196 |
| 3.0 | Contingency Planning Common Controls | 213 |
Insert POR Name
Insert POR Name
1. INTRODUCTION
(SP 800-34 Rev.1 A [CP-2], [CP-2(3)]) Information systems are vital to the Defense Health Agency’s mission/business processes; therefore, it is critical that services provided by Insert POR Name are able to operate effectively without excessive interruption. This Information System (IS) Contingency Plan (CP) establishes comprehensive procedures to recover quickly and effectively following a service disruption. This CP document is adapted from the National Institute for Standards and Technology (NIST) Special Publication (SP) 800-34, Rev. 1 template and guide available from the NIST website at:
http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-34r1.pdf. The template provided is a guide and may be customized and adapted as necessary to best fit the system or organizational requirements for contingency planning.
The Insert POR Name Program of Record (POR) Information System Contingency Plan (ISCP) is a plan of action designed to reduce to an acceptable level, the consequences of any loss of Automated Information System (AIS) resources or capabilities. The purpose of the ISCP is to mitigate the damaging consequences of unexpected and undesirable events of any magnitude, not just major catastrophes.
This ISCP is different from an Enterprise Business Continuity Plan (BCP). While there is some overlap between an ISCP and a BCP, a BCP covers a broader range of incidents, including those not necessarily affecting AISs. The purpose of a BCP is to ensure the safety of employees, to protect and restore facilities and capabilities, to reduce the damaging consequences of any unexpected or undesirable event, and to keep the organization in operation. This ISCP can be considered an important component of an Enterprise BCP; however, its focus is on Primary and Secondary AIS resources within the Insert POR Name Authorization boundary.
Contingency Planning Controls
([CP-2] [CCI-000445])
The Security Control table, Table 1 below identifies NIST SP 800-53, Rev. 4 contingency planning controls applicable to Insert POR Name.
NOTE: The following Contingency Plan controls below are from NIST SP 800-53, Rev. 4.
This table will assist you in identifying controls that are applicable to your system.
Do not delete any rows in the Table 1 below. NOTE: The following Contingency Plan controls below are from NIST SP 800-53, Rev. 4.
This table will assist you in identifying controls that are applicable to your system.
Do not delete any rows in the Table 1-1 below.
If any controls are identified as “Not applicable”, please state “Not applicable” in the section within this document. Do not delete any section within this document.
Delete this notational text box before submitting to DHA CSD for approval.
If any controls are identified as “Not applicable”, please state “Not applicable” in the section within this document. Do not delete any section within this document.
Delete this notational text box before submitting to DHA CSD for approval.
| Control No. |
| Control Name |
| Applicability |
Select Yes or No; then change to black font
| CP-1 |
| Contingency Planning Policy and Procedures |
| No (Tier 1) |
| CP-2 |
| Contingency Plan |
| Yes No |
| CP-3 |
| Contingency Training (IAW CP-2, CCI 449) |
| Yes No |
| CP-4 |
| Contingency Plan Testing and Exercise |
| Yes No |
| CP-5 |
| Contingency Plan Update (Withdrawn) |
| ------ |
| CP-6 |
| Alternate Storage Site |
| Yes No |
| CP-7 |
| Alternate Processing Site |
| Yes No |
| CP-8 |
| Telecommunications Services |
| Yes No |
| CP-9 |
| Information System Backup |
| Yes No |
| CP-10 |
| Information System Recovery and Reconstitution |
| Yes No |
| CP-11 |
| Alternate Communications Protocols |
| No (per CNSSI 1253) |
| CP-12 |
| Safe Mode |
| No (per CNSSI 1253) |
| CP-13 |
| Alternative Security Mechanisms |
| No (per CNSSI 1253) |
Table 1: Summary of NIST SP 800-53 r4: Contingency Planning Controls Background (SP 800-34 Rev.1 4.1, A.2.1; [CCI-000446]) This document contains the ISCP for the Insert POR Name. This Plan serves as a centralized repository for information, tasks, and procedures necessary to facilitate the Insert POR Name management’s, and that of the gaining Enclave(s), decision-making process in response to any disruptive or extended interruption of the site's normal business operations and services. This is especially important if the cause of the interruption is such that a prompt resumption of operations cannot be accomplished by employing only normal daily operating procedures.
Insert POR Name is a POR that has been accredited via the NIST Risk Management Framework (RMF) and is maintained within the Defense Health Agency (DHA) Enterprise. Therefore, execution and compliance responsibility to various security measures such as Continuity controls identified within NIST SP 800-53 r.4, shall be delineated between the POR Information Systems Security Manager (ISSM) and the enclave (i.e., via concept of inheritance) ISSM as applicable.
It is incumbent upon every individual who is in receipt of the Insert POR Name ISCP, or any parts thereof, or who has a role and responsibility for any information or materials contained in the document, to ensure that adequate and sufficient attention and resources are committed to the maintenance and security of the document and its contents.
Plan Objectives The Insert POR Name management team is committed to maintaining the needs of the Insert POR Name POR System Administrators (SAs) and staff by providing them formal practices for responding to any emergency or non-emergency occurrence. The primary concern is to ensure the resumption of time-sensitive operations of primary information systems which contain electronic Protected Health Information (PHI) as defined by the Health Insurance Portability and Accountability Act (HIPAA), Controlled Unclassified Information, Privacy Act information, and provide operational capability to the Medical Treatment Facilities (MTFs) that comprise the Insert POR Name system area of operations (AOR).
The Insert POR Name ISCP establishes procedures to recover Insert POR Name following a disruption and serves to:
· Provide a complete description of the POR along with its boundaries and interdependencies as well as a description of the roles and responsibilities of key personnel
· Maximize the effectiveness of contingency operations through an established plan and methodology
· Ensure that all systems required to support Insert POR Name Mission Essential Functions (MEFs) are identified along with the procedures for Activation and Notification, Recovery, and Reconstitution within their expected recovery timeframes.
· Identify the activities, resources, and procedures needed to fulfill system processing requirements during prolonged interruptions of normal operations
· Assign responsibilities to designated Insert POR Name personnel and provide guidance for Primary System and Key Component recovery during prolonged periods of interruption of normal operations
· Ensure coordination with the Insert POR Name staff or other DHA personnel that participate in contingency planning strategies
· Ensure coordination with external Points of Contact (POC) such as contractors or vendors who participate in the contingency planning strategies.
Supplemental information referred to in this plan will be found in the Annexes. Such information includes:
· Key COOP Personnel Contact Information
· Alternate Facility and Processing Information
· Detailed Recovery Procedures
· Validation Testing Procedures
· Alternate Mission/Business Processing Procedures
· System Interconnections Information
· Key Component Hardware Software Specifications and Vendor Contact Information
· ISCP Testing and Maintenance Procedures and Schedule
· Document Management Approach
· Associated Plans and Procedures
· Activity and Evaluation Checklists
· Damage Assessment Reports
· Post-Incident After Action Reports
Scope (SP 800-34 Rev.1 3.1, 3.2.2, 4.1, A.1.2; [CCI-000443] [CCI-000444] [CCI00475]) Provide the scope which identifies the Federal Information Processing Standard (FIPS) 199, Standards for Security Categorization of Federal Information and Information Systems, impact level and associated RTOs, the alternate site and data storage capabilities (if applicable).
Although the system cannot completely avoid disruption, by following the defined ISCP and procedures, the risk and impact of unforeseen disasters can be significantly reduced. Implementation of best practices can minimize the risk associated with hardware and software failures, human error, and natural disasters as they relate to the Insert POR Name environment.
This document addresses only those areas pertaining to the reconstitution of AIS operations for facilities identified as a part of the Insert POR Name Authorization Boundary. Figure 3 – Insert POR Name Accreditation Boundary Diagram identifies the basic system configuration and accreditation boundary within the enclave.
For information concerning the Insert POR Name alternate processing site and offsite data storage location please reference Section 7 of this document.
The Insert POR Name System Security Categorization is documented in Table 2 below. The Insert POR Name Recovery Time Objective (RTO) is documented in Table 4 of this document.
Security Categorization and Control Baseline Compliance
([CCI-000445])
Table 2 below identifies the Insert POR Name security categorization, control baseline, control inheritance determinations and compliance approach. For applicable contingency requirements for the system at the Control Correlation Identifier (CCI) level please see Annex S of this document.
| IA Control Number |
| IA Control Name |
| System Security Categorization |
(C,I,A)
| Applicable Control Enhancements |
| Assessed as N/A for System |
| Compliance Approach (1-2 Sentence) |
| CP-1 | |
| Contingency Planning Policy and Procedures |
M/M/M
| Y/N |
| This control is assigned to Tier 1 – the DoD. It is not applicable to this plan. |
| CP-2 |
| Contingency Plan |
| M/M/M |
| CP-2(1), CP-2(3), CP-2(8) |
| Y/N |
| The system will ensure compliance with both the base control and applicable enhancements |
| CP-3 |
| Contingency Training |
| M/M/M |
| Y/N |
| The system will ensure compliance with both the base control and applicable enhancements |
| CP-4 |
| Contingency Plan Testing |
| M/M/M |
| CP-4(1) |
| Y/N |
| The system will ensure compliance with both the base control and applicable enhancements |
| CP-6 |
| Alternate Storage Site |
| M/M/M |
| CP-6(1), CP-6(3) |
| Y/N |
| The system will ensure compliance with both the base control and applicable enhancements |
| CP-7 |
| Alternate Processing Site |
| M/M/M |
| CP-7(1), CP-7(2), CP-7(3) |
| Y/N |
| The system will ensure compliance with both the base control and applicable enhancements |
| CP-8 |
| Telecommunications Services |
| M/M/M |
| CP-8(1), CP-8(2) |
| Y/N |
| The system will ensure compliance with both the base control and applicable enhancements |
| CP-9 |
| Information System Backup |
| M/M/M |
| CP-9(1), CP-9(5) |
| Y/N |
| The system will ensure compliance with both the base control and applicable enhancements |
| CP-10 |
| Information System Recovery and Reconstitution |
| M/M/M |
| CP-10(2) |
| Y/N |
| The system will ensure compliance with both the base control and applicable enhancements |
| IR-8 |
| Incident Response Plan |
| M/M/M |
| Y/N |
| The system will ensure compliance with both the base control and applicable enhancements |
Table 2: Insert POR Name Continuity Compliance – Inheritance Mapping Policy (SP 800-34 Rev.1 3.1) Policy Statement: All DHA enclaves, systems, and major applications (e.g., Programs of Record [PORs]) must develop Contingency Plans for each accredited environment within the collective Enterprise in order to meet and sustain the needs of corresponding Mission Essential Functions (MEFs) in the event of a disruption. The procedures for execution of such a capability shall be documented in a formal Contingency Plan by the cognizant Program Manager, Contingency Plan Coordinator (CPC), Information Systems Security Manager (ISSM), and User Representative, and must be reviewed annually and updated as necessary by the CPC. The plan must comply with the appropriate, corresponding security controls (e.g., NIST SP 800-53, Rev.4). The Contingency Plan must assign specific responsibilities to designated personnel or positions to facilitate the recovery and/or continuity of MEFs. Resources necessary to ensure viability of the procedures must be acquired and maintained. Personnel responsible for target enclaves, systems, and/or applications must be trained to execute contingency procedures. The Contingency Plan recovery capabilities and personnel shall be tested annually to identify weaknesses and propose responsive solutions. The results and subsequent recommendations for Contingency Plan maturation shall be reviewed and signed by the assigned Authorizing Official (AO), Program Manager, and User Representative.
Assumptions (SP 800-34 Rev.1 4.1, A.2) Provide the assumptions that were used in developing the CP as well as the list of situations that are not applicable. Please see NIST Special Publication 800-34, Appendix A for a sample of assumptions and situations.
· A Disaster Recovery Plan (DRP) exists for the gaining Enclave(s) and will be activated along with the ISCP if the damage is beyond the scope of the ISCP and relocation is required
· Appropriate preparatory activities will be performed when there is adequate notice of an event (e.g., hurricane warning)
· Key personnel have been identified and trained in their emergency response and recovery roles and are available to activate this ISCP
· Subject matter experts are available during all system shutdown and startup events
· The Insert POR Name ISCP is up-to-date and accessible to key personnel responsible for executing the plan
· Preventive controls (e.g., generators, environmental controls, waterproof tarps, sprinkler systems, fire extinguishers, and fire department assistance) are fully operational at the time of the disaster or other significant event that impacts long-term operations
· The Insert POR Name has sound and practiced Configuration Management (CM) processes in place which track with (i.e., account for) and communicate ISCP implications to those responsible for ISCP updates and activities.
· Information System infrastructure and network equipment are connected to an uninterruptible power supply (UPS) that provides a minimum of fifteen minutes of operating capacity to allow for the transfer to the backup alternate power in the event of a facilities power outage
· Infrastructure and network equipment are connected through electrical circuit panels which are automatically powered by the generator if the primary power source fails
· The equipment, connections, and capabilities required to operate Insert POR Name systems are available at the alternate site
· Current backups of the system software and data are intact, available and protected.
· Equipment warranty service agreements are maintained with hardware, software, and communication providers to support the emergency system recovery Applicable Provisions and Directives
([CP-2])
This CP complies with IS contingency planning policy as follows:
The development of the Insert POR Name CP is required by both executive decision and regulatory mandates. The Insert POR Name management and host sites must maintain a Cyber Security (CS) infrastructure that will ensure that information resources maintain availability, confidentiality, and integrity of their data. Furthermore, Insert POR Name management must ensure their strategic information resources management capabilities. Therefore, the Insert POR Name CP is developed in accordance with the following executive decisions, regulatory mandates, provisions, and directives:
“Federal Information Security Modernization Act of 2014” (PLAW 113-283), 18 December 2014 Office of Management and Budget Circular A–130, “Management of Federal Information Resources.” 24 December 1985. Revised, Transmittal Memorandum No. 4, Appendix III, “Security of Federal Automated Information Resources.” 28 November 2000 Department of Homeland Security “Federal Continuity Directive 2”, June 2017 Department of Homeland Security “Federal Continuity Directive 1”, January 2017 Homeland Security Presidential Directive (HSPD) 7 “Critical Infrastructure Identification, Prioritization, and Protection”, December 17, 2003 National Security Presidential Directive (NSPD) 51/ Homeland Security Presidential Directive (HSPD) 20 “National Continuity Policy”, May 2007 Federal Information Processing Standard (FIPS) 199, “Standards for Security Categorization of Federal Information and Information Systems”, February 2004 National Institute of Standards and Technology Special Publication 800-53 “Security and Privacy Controls for Federal Information Systems and Organizations”, Revision 4, December 2014 National Institute of Standards and Technology (NIST) Special Publication 800-34, “Contingency Planning Guide for Federal Information Systems.” Revision 1. May 2010 Homeland Security “Nation Response Framework” 3rd Edition, August 2016 Homeland Security Council “National Continuity Policy Implementation Plan” (NCPIP), August 2007, updated December 1, 2013 CNSSI No.1253, “Security Categorization And Control Selection For National Security Systems”, 27 March 2014 DoD Instruction 8500.01, “Cybersecurity”, 14 March 2014 DoD Instruction 8510.01, “Risk Management Framework (RMF) for DoD Information Technology (IT)”, 12 March 2014 DOD Continuity Policy DoDD 3020.26, February 14, 2018.
DHA “Common Control Workbook Ver.5”, August 24, 2016 Any other applicable departmental policies should be added.
The Insert POR Name ISSM will continually assess potential risks and vulnerabilities to classified or sensitive data in its possession and develop, implement, and maintain appropriate administrative, physical, and technical security measures in accordance with this policy, instruction, and guidance.
Guidance for development of this ISCP was extracted from NIST SP 800-34 Rev.1, which defines the following seven-step contingency process that may be applied to develop and maintain a viable contingency planning program for IS. These seven progressive steps are designed to be integrated into each stage of the system development life cycle.
· Step 1: Develop contingency planning policy statement. A formal department policy provides the authority and guidance necessary to develop an effective ISCP
· Step 2: Conduct the Business Impact Analysis (BIA). The BIA helps to identify and prioritize Primary/Secondary IT systems and components
· Step 3: Identify preventive controls. Measures taken to reduce the effects of system disruptions can increase system availability and reduce contingency life cycle costs
· Step 4: Develop recovery strategies. Thorough recovery strategies ensure that the system may be recovered quickly and effectively following a disruption
· Step 5: Develop an IS contingency plan. The ISCP should contain detailed guidance and procedures for restoring a damaged system
· Step 6: Plan testing, training, and exercises. Testing the plan identifies planning gaps, whereas training prepares recovery personnel for plan activation; both activities improve plan effectiveness and overall agency preparedness
· Step 7: Plan maintenance. The plan should be a living document that is updated regularly to remain current with system enhancements.
Threat Events Included (SP 800-34 Rev.1 3.2; Federal Continuity Directive 2 Appendix A) The following list describes the broad categories of events which could result in an interruption of service or loss/destruction of equipment or information. Examples of threats which could result in an included event are included where appropriate; however, a more comprehensive list of threats and associated impacts is contained in the RMF Package (e.g., Risk Assessment).
· Network-based events with a human actor, accidental or malicious (e.g., malicious outsider/hacker causes denial of service; accidental misconfiguration causes network interruption)
· Physical events with a human actor, accidental or malicious (e.g., acts of vandalism)
· System Events not directly caused by a human factor (e.g., software defects, widespread virus propagation, hardware defects, system problems)
· Environmental Events (e.g., power supply issues, telecommunications issues, third party system dependencies, natural disasters).
Threats determined to have a potential impact on availability have been grouped into these 4 broad categories and are discussed further in Section 3.3. While threats related to data integrity are addressed elsewhere, it should be noted that the steps necessary to remediate a significant data integrity incident are often similar to those necessary for remediating an incident which results in loss of data.
This Insert POR Name ISCP is limited to enabling the continuity of operations in cases where an incident may result in a loss of availability of the Insert POR Name services. Threats which may result in disclosure of protected information are discussed in the RMF Assessment and Authorization Package and are therefore not included in this ISCP. Further, this contingency plan does not describe actions which may be necessary to prevent further losses or ensure the safety of individuals (such as evacuation procedures). Application or system specific recovery procedures for secondary systems are not contained within this ISCP; however, these procedures are part of the system documentation for each secondary AIS.
Preventive Measures (SP 800-34 Rev.1 3.3) In some cases, the outage impacts identified in the BIA may be mitigated or eliminated through preventive measures that deter, detect, and/or reduce impacts to the system. Where feasible and cost-effective, preventive methods are preferable to actions that may be necessary to recover the system after a disruption. Step 2 of the RMF includes the identification of effective contingency planning preventive controls and maintaining these controls on an ongoing basis. A variety of preventive controls are identified in NIST SP 800-53, Rev.4, depending on system type and configuration; some common measures are listed below:
· Appropriately sized uninterruptible power supplies (UPS) to provide short-term backup power to all system components (including environmental and safety controls);
· Gasoline- or diesel-powered generators to provide long-term backup power;
· Air-conditioning systems with adequate excess capacity to prevent failure of certain components, such as a compressor;
· Fire suppression systems;
· Fire and smoke detectors;
· Water sensors in the computer room ceiling and floor;
· Heat-resistant and waterproof containers for backup media and vital non electronic records;
· Emergency master system shutdown switch;
· Offsite storage of backup media, non-electronic records, and system documentation;
· Technical security controls, such as cryptographic key management; and
· Frequent scheduled backups including where the backups are stored (onsite or offsite) and how often they are recirculated and moved to storage
FOR OFFICIAL USE ONLY 11
CONCEPT OF OPERATIONS
(SP 800-34 Rev.1, SP 800-18 Rev.1) Per NIST Special Publication 800-34 Rev.1, Section 4.1, the Concept of Operations section provides details about Insert POR Name, an overview of the three phases of the ISCP (Activation and Notification, Recovery, and Reconstitution), and a description of roles and responsibilities of Insert POR Name personnel during a contingency activation.
System Description
([CP-2(8)] [CCI-002828])
Provide a general description of system architecture and functionality.
Include a general description of the information system addressed by the contingency plan. The description should include the information system architecture, location(s), and any other important technical considerations. An input/output (I/O) diagram and system architecture diagram, including security devices (e.g., firewalls, internal and external connections) are useful. The content for the system description can usually be taken from the Security Plan (SP).
Overview of the Three COOP Phases ([CP-2], [CP-10], [CCI-000447] [CCI-000454] [CCI-000455] [CCI-000456] [CCI-000550] [CCI-000551] ) This CP has been developed to recover and reconstitute the Insert POR Name system using a three-phased approach. This approach ensures that system recovery and reconstitution efforts are performed in a methodical sequence to maximize the effectiveness of the recovery and reconstitution efforts and minimize system outage time due to errors and omissions.
The three system recovery phases are:
Activation and Notification Phase Activation of the CP occurs after a disruption or outage that may reasonably extend beyond the RTO established for a system (see Table 4 of this document for system RTO information). The outage event may result in severe damage to the facility that houses the system, severe damage or loss of equipment, or other damage that typically results in long-term loss.
Once the CP is activated, system owners and users are notified of a possible long-term outage, and a thorough outage assessment is performed for the system. Information from the outage assessment is presented to system owners and may be used to modify recovery procedures specific to the cause of the outage.
The focus of the Insert POR Name operations will shift from the current structure and function of “business as usual” to the structure and function of a contingency mode working towards the resumption of time-sensitive business operations.
The primary contingency responsibilities are to:
· Protect information assets until normal business operations are resumed
· Ensure that a viable capability exists to respond to an incident
· Identify an alternate location/resources within the MTF (or consistent with, and in support of MTF relocation if deemed necessary during disaster recovery event) to re-establish the system should the computer room or main server room experience an event
· Manage all activation and notification, recovery, and reconstitution activities
· Support and communicate with employees, system administrators, security officers, and managers
· Accomplish rapid and efficient resumption of time-sensitive business operations, technology, and functional support areas
· Ensure regulatory requirements are satisfied
· Exercise recovery and reconstitution expenditure decisions
· Streamline the reporting among teams and management.
Recovery Phase The Recovery phase details the activities and procedures for recovery of the affected system. Activities and procedures are written at a level that an appropriately skilled technician can recover the system without intimate system knowledge. This phase includes notification and awareness escalation procedures for communication of recovery status to system owners and users.
Reconstitution Phase The Reconstitution phase defines the actions taken to test and validate system capability and functionality at the original or new permanent location. This phase consists of two major activities: validating successful reconstitution and deactivation of the plan.
During validation, the system is tested and validated as operational prior to returning operation to its normal state. Validation procedures may include functionality or regression testing, concurrent processing, and/or data validation. The system is declared recovered and operational by system owners upon successful completion of validation testing.
Deactivation includes activities to notify users of system operational status. This phase also addresses recovery effort documentation, activity log finalization, incorporation of lessons learned into plan updates, and readying resources for any future events.
Roles and Responsibilities (SP 800-34 Rev.1 3.4.6, A; [CP-2] [CCI-000449]) Describe each team and role responsible for executing or supporting system recovery and reconstitution. Include responsibilities for each team/role, leadership roles, and coordination with other recovery and reconstitution teams, as applicable. At a minimum, a role should be established for a system owner or business unit point of contact, a recovery coordinator, and a technical recovery point of contact. The organization being inspected/assessed must clearly and accurately document contingency roles, responsibilities, assigned individuals with contact information for its information system(s).
This section discusses key Insert POR Name personnel and teams responsible for recovering Insert POR Name and its main components. All personnel within the Insert POR Name POR have an assigned responsibility during a crisis and should know their roles and responsibilities during an emergency. Personnel should be trained to respond without hesitation during an emergency and this training should be reinforced with mock disasters on a regularly scheduled basis.
This plan designates specific individuals and teams for directing and managing the contingency plan during both emergency and non-emergency periods. Direction and management of the contingency plan is pushed top-down through the Insert POR Name organizational structure. Key Insert POR Name individuals identified in the plan are: Contingency Plan Coordinator, ISSM, and System Administrators. The roles and responsibilities outlined in the Contingency Plan will ensure that the plan is activated and normal operations are restored in the most efficient manner possible. Figure 1 provides a graphical depiction of the plan’s organizational chart and hierarchy of roles.
The following sections describe the roles and responsibilities of personnel involved in carrying out the Contingency Plan. Table 3 below provides a summary of the plan’s key roles, the corresponding role, and the responsibilities associated with each position. Contact information for all Contingency Plan personnel is contained within Annex A.
Contingency Plan Role Responsibilities
| POR Contingency Plan Coordinator |
| The Contingency Plan Coordinator (CPC) manages the POR’s ISCP and develops, promotes, tracks, and coordinates ISCP activities. The CPC further ensures the effectiveness and survivability of the POR’s ISCP capability by: (1) working with Enterprise leadership to manage day-to-day continuity programs at any applicable POR-managed central facilities, and (2) reporting to, and coordinating with the Enterprise COOP PM as appropriate. |
Supports Business Impact Analysis (BIA), Risk Management (RM) analysis, and reconstitution and recovery activity pertaining to business processes. Provides insight into (1) critical IS assets, (2) system, network, and other technology based interdependencies, and (3) requirements for alternate site and/or service level agreements and resources.
Enclave Contingency Plan Coordinator
MTF Enclave CPC develops, manages, promotes, and tracks POR ISCP measures the enclave has inherited responsibility for (e.g., backup power, alternate site for locally maintained POR key components). The MTF Enclave CPC further ensures the effectiveness and survivability of the POR and Enclave’s collective ISCP capability by: (1) working with site leadership to manage day-to-day continuity programs at the local facility (e.g., Facility), and (2) reporting to, and coordinating with the Enterprise COOP PM as appropriate. The MTF Enclave CPC serves as the primary interface with the POR CPC and ISSM.
| Business Continuity Lead |
| Supports Business Impact Analysis (BIA), Risk Management (RM) analysis, and reconstitution and recovery activity pertaining to business processes. |
| IS Disaster Recovery (ISDR) Lead |
| Provides insight into (1) critical IS assets, (2) system, network, and other technology based interdependencies, and (3) requirements for alternate site and/or service level agreements and resources. |
| Tests, Training, and Exercises (TT&E) Lead |
| Coordinates activity necessary to raise awareness, and validate plans against operational constraints through education, testing, and reporting. |
| POR ISSM |
| Responsible for implementing security requirements for IS, networks, and/or AIS programs under his or her control and ensures that Enterprise deployment of the POR is in conformance with pertinent information security policies. POR ISSMs are responsible for facilitating a consistent approach to COOP parameters, resources and information distributed via the Strategic Plan. The POR ISSM works closely with MTF enclave IS and SC officials to ensure a complete understanding of risks and evaluates information security controls and techniques to ensure each are cost effective and enable, but do not adversely affect or unnecessarily impede business operations. |
| Enclave ISSM |
| Responsible for implementing security requirements for IS, networks, and/or AIS programs under his or her control and ensures that Enterprise enclaves and sites are in conformance with pertinent information security policies. ISSMs are responsible for facilitating a consistent approach to COOP parameters, resources and information distributed via the Strategic Plan. ISSMs participate in identifying regional Strategic Plan requirements and communicate with the Commands COOP PM to ensure Enterprise compliance. The ISSM works closely with POR IS and CS officials to ensure a complete understanding of risks and evaluates information security controls and techniques to ensure each are cost effective and enable, but do not adversely affect or unnecessarily impede business operations. The MTF Enclave ISSM serves as the secondary interface to the POR CPC and ISSM (CPC is primary POC). |
| Program Managers and System Owners |
| Implement policy, provide direction, and control funding for an information system and are liable for the continuity of systems supporting primary and mission-essential functions. The System Owner ensures that COOP and ISCP considerations for each information system are planned for, documented, and tested throughout the system life cycle (SLC) from the information system’s initiation/acquisition phase to the system’s disposal phase. |
| System and Network Administrators |
| Ensure that appropriate COOP and ISCP requirements are implemented and enforced for systems or networks and ensure that the information security posture of the network is maintained during all network maintenance, monitoring activities, interconnections, installations or upgrades, and day-to-day operations. |
| User Representatives |
| Participate in annual CS Awareness training and ongoing information security awareness program; understand and be willing to perform their duties in ISCP situations (e.g., reporting incidents that may trigger ISCP activation to help desk) to ensure the Enterprise can continue its essential functions; participate in COOP test and exercise activity as appropriate for their security role; and ensuring that family members are prepared for and taken care of in an emergency situation. |
| DHA |
| Provides regional level IS security direction to specific sites. Coordinates COOP and ISCP execution and management for a specific region. Participates in ISCP test and exercise activity as appropriate for their security role. |
Table 3: Contingency Plan Roles and Responsibilities COOP Roles Organizational Chart (SP 800-34 Rev.1 3.4.6; [CP-2] [CCI-000449]) The following Figure 1 Insert POR Name Contingency Plan Organizational Chart outlines the key COOP roles, the individuals filling those roles and the immediate successors for each role.
Incident Commander Alt
TBD
Incident Commander
TBD
Chief, A&A Execution Section, CS Division LCDR A. McLean
DHA
LT A. McLean
NAVMISSA
IS CPC
IS CPC (Alt)
ISSM
ISSM (Alt)
TBD
ISDR Lead
TBD
ISDR Lead (Alt)
PM/Owner
PM/Owner (Alt)
TBD
System Admin (Alt)
TBD
System Admin
User Rep (Alt)
User Rep
Figure 1: Insert POR Name Contingency Plan Organizational Chart COOP Roles Point of Contact (POC) Information (SP 800-34 Rev.1 A.2.3, A; [CP-2]) Contact information is documented for Insert POR Name recovery personnel, as well as for each application associated with the Insert POR Name Contingency Plan. POC information for individuals filling Insert POR Name contingency roles is located within Annex A. For component support and vendor POC information refer to each component’s Key Component Specification and Vendor Contact Table located in Section 8.2.
All key employees are issued recall rosters that are the size of their identification badges and should be carried with them next to their identification badges.
Supplies (SP 800-34 Rev.1 3.3; [CP-7] [CCI-000515] [CCI-002839]) A list of critical supply items and locations will be maintained by the ISSM and the Information Systems Security Officer (ISSO) at each host site. Once incident preparations have been initiated, supplies should be distributed immediately. Protective supplies for equipment such as plastic sheeting, plastic bags, and tape will be issued when there is warning of weather-related or other impending potential disastrous conditions (see Section 1.9 Preventative Measures). Supplies will be managed by the ISSM and the ISSO at Insert POR Name host facilities.
Office equipment, furniture, and supplies will be procured on an “emergency as required” basis at the time of the disaster. If space and funds permit, it is recommended that management review supply needs and coordinate with the local procurement office to consider implementing a revolving emergency inventory of workspace and survival supplies for immediate use in the event of a disaster. Additionally, a revolving inventory of survival supplies should be maintained, including bottled drinking water, personal products, and food rations. These provisions could be utilized in the event personnel cannot be evacuated or are temporarily prevented from leaving the confines of the building due to weather conditions.
An inventory of Insert POR Name equipment and supplies available at the alternate site is documented. Insert POR Name equipment and supplies which will be transported or otherwise acquired for use at the alternate site within required time windows are also identified and documented.
Insert a reference/link to the repository containing documentation of the Insert POR Name equipment and supplies available at the alternate site and Insert POR Name equipment and supplies which are to be transported to the alternate site.
Transportation
([MP-5])
All transportation of equipment must be in accordance with classification standards for all hardware, software, and associated materials utilizing normal supply channels for transportation of replacement equipment.
Cost Considerations (SP 800-34 Rev.1 3.2.1, 3.4.5) The Contingency Planning Coordinator (CPC) shall ensure the contingency strategy developed can be implemented effectively with available personnel and financial resources. The cost of alternate site location, equipment replacement, and storage options should be considered and weighed against budget limitations. Contingency planning expenses, including less obvious costs (including contingency awareness program or contractor support), should be considered and determined. The budget should also be sufficient to include:
· Software
· Hardware
· Travel
· Shipping
· Testing
· Plan awareness/training programs
· Labor hours
· Additional contracted services
· Administrative overhead (e.g., desks, telephones, etc.).
Documentation
([CP-9] [CCI-000539])
All documentation for Insert POR Name components is provided within the operators and maintenance manuals, and Commercial-Off-The-Shelf (COTS) manuals. For key component specifications see Section 8.2. Documentation of maintenance and backup procedures are detailed in Section 6.7 of the ISCP.
Detailed rebuild and restore instructions for the Primary System (or the system’s components) are maintained, reviewed, tested regularly, and updated as needed. This information and instruction is detailed in Annex D.
BUSINESS IMPACT ANALYSIS
(SP 800-34 Rev.1 3.2, 4.5, A; [CP-2 (3)] [CP-2(4)] [CP-2(5)] [SP-2(6)] [SP-2(8)]; Federal Continuity Directive 2 Appendix A) The organization identifies essential missions and business functions and associated contingency requirements; Provides recovery objectives,…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .