17 GSA Control Tailoring Workbook 2023 07 11.xlsx
XLSX spreadsheet 217 KB Posted
- Attached to
- Unified User Interface (UUI) Federal contract opportunity
- Solicitation number
- 47PM0024R0003
About this file
This is a solicitation notice for a Unified User Interface (UUI) contract opportunity from the General Services Administration Public Buildings Service. The solicitation requests proposals to provide a unified user interface in accordance with the RFP, attachments, and links provided. Key details include: a single award contract will be made; the acquisition is not set aside for small business; the Service Contract Labor Standards wage determination is incorporated; the pre-proposal conference will be held on February 6, 2024 with a limit of three attendees per offeror; questions are due by February 5 and 8, 2024; proposals are due by February 26, 2024; the period of acceptance is 120 days; the government will award to the best value offeror. The 16 attachments include the RFP cover letter, solicitation, solicitation attachments, and questions and answers from the draft RFP.
View the file
Other files for this federal contract opportunity
Show all 20
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Instructions
| Overview | The General Services Administration (GSA) Control Tailoring Workbook (CTW) provides a listing of the values for parameters associated with assignment and selection statements in the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, Revision 5 controls. The parameters listed provide designers, developers, and assessors the values the controls must adhere to in order to meet the GSA's security policies and procedures. The phrase "GSA S/SO or Contractor recommended and GSA CISO and AO approved" (or similar wording) is used when GSA has determined an enterprise parameter should not be set and has left the parameter setting to be established on a system-by-system basis. The GSA IT Security InSite page (https://insite.gsa.gov/topics/information-technology/security-and-privacy/it-security/it-security-procedural-guides) provides links to GSA security guides mentioned in this workbook. |
| Instructions Tab | Provides an overview of the CTW. |
| GSA Defined Settings Tab | Provides a listing of NIST controls with GSA parameter settings, including applicability to the NIST Privacy Baseline, the Federal Information Processing Standard (FIPS) 199 Low, Moderate, and High levels, and the various GSA Assessment and Authorization (A&A) processes. |
| Notes: | (1) Shading of controls/control enhancements is as follows: |
(a) Dark gray - withdrawn controls
(b) Gray - controls not applicable at any FIPS 199 Level or any GSA A&A process
(c) Light Green - controls that are in the Privacy baseline, but not applicable at this time.
(2) Control applicability markings are as follows:
X - control is applicable at the FIPS 199 Level or GSA A&A process in the column heading X* - control is applicable per the GSA Office of the Chief Information Security Officer (OCISO), conditional text may follow the marking X** - control is applicable per the GSA OCISO Tailored Moderate Baseline (also included in High controls if not already selected), conditional text may follow the marking X^ - control is applicable if PII is stored, processed, or transmitted
| (3) Parameters are delineated by brackets--[] and are in blue, italicized text. Typically, acronyms are not spelled out in the CTW. | |
| Column - Name | Description |
| Column A - N/A | A hidden, protected column used to apply shading to controls. |
| Column B - Control ID | NIST security control identifier. |
| Column C - Control Name | NIST security control/enhancement name. |
| Column D - Control Statement | Control statement with GSA parameters included in the statement delineated by brackets [] and are in blue, italicized text. |
| Columns E-J - Control Baselines | For each column, an "X" denotes the security control/control enhancement is applicable for the following baselines/GSA A&A Processes. |
Conditional applicability information may be included.
E - Privacy Baseline F - FIPS 199 Low Baseline G - FIPS 199 Moderate Baseline H - FIPS 199 High Baseline I - Lightweight Security Authorization Process (LATO) control set J - Moderate Impact Software-as-a-Service (MiSaaS) control set Column K - Vendor/Contractor Defined Values To be used to enter vendor/contractor recommended settings for the NIST security controls/enhancements where the specific parameter/settings is reserved for the system to define (or if the setting differs from the GSA defined value). Cells where information is required (or may be required in a few instances) are highlighted in light yellow.
Column L - GSA Approval of Vendor/Contractor Defined Values To be used by GSA to indicate that the GSA CISO and AO have approved the vendor/contactor recommended setting. Cells where approval must be noted (or may be required in a few instances) are highlighted in light yellow.
GSA Defined Settings
| Control | Baselines | |||||||||||
| Control ID | Control Name | Control Statement | Privacy | Low | Moderate | High | LATO | MiSaaS | Vendor/Contractor Defined Values | GSA Approval of Vendor/Contractor Defined Values | ||
| AC-1 | (Access Control) | |||||||||||
| Policy and Procedures | a. Develop, document, and disseminate to [personnel with IT security responsibilities as defined in GSA Order CIO 2100.1]: |
1. [Organization-level] access control policy that:
(a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
(b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and
2. Procedures to facilitate the implementation of the access control policy and the associated access controls;
b. Designate an [CISO] to manage the development, documentation, and dissemination of the access control policy and procedures; and
c. Review and update the current access control:
1. Policy [annually, as part of CIO 2100.1 update] and following [changes to Federal or GSA policies, requirements, or guidance]; and
| 2. Procedures [at least every three (3) years] and following [changes to Federal or GSA policies, requirements, or guidance]. | X | X | X | X |
| AC-2 | Account Management | a. Define and document the types of accounts allowed and specifically prohibited for use within the system; |
b. Assign account managers;
c. Require [GSA SSO or Contractor recommended prerequisites and criteria (based on defined user role(s) matrix in GSA SSPP Template Section 9: Types of Users) as approved by the CISO and AO] for group and role membership;
d. Specify:
1. Authorized users of the system;
2. Group and role membership; and
3. Access authorizations (i.e., privileges) and [the following attributes as defined in the user role(s) matrix in GSA SSPP Template Section 9: Types of Users - Internal or External; Privileged (P), Non-Privileged (NP), or No Logical Access (NLA); Sensitivity Level; Authorized Privileges; Functions Performed; MFA Authentication Method] for each account;
e. Require approvals by [designated account managers as specified in AC-2.b] for requests to create accounts;
f. Create, enable, modify, disable, and remove accounts in accordance with [CIO-IT Security-01-01, Identification and Authentication, CIO-IT Security-01-07, Access Control, and GSA-defined procedures or conditions (as applicable)];
g. Monitor the use of accounts;
h. Notify account managers and [System Owner, System/Network Administrator, and/or ISSO] within:
1. [14 days] when accounts are no longer required;
2. [14 days] when users are terminated or transferred; and
3. [14 days] when system usage or need-to-know changes for an individual;
i. Authorize access to the system based on:
1. A valid access authorization;
2. Intended system usage; and
3. [Role privileges identified in GSA SSP Section 9: Types of Users];
j. Review accounts for compliance with account management requirements [annually];
k. Establish and implement a process for changing shared or group account authenticators (if deployed) when individuals are removed from the group; and
| l. Align account management processes with personnel termination and transfer processes. | X | X | X | X | X | |||
| AC-2(1) | Account Management | Automated System Account Management | Support the management of system accounts using [GSA SSO or Contractor recommended automated mechanisms as approved by the GSA CISO and AO]. | X | X | ||||
| AC-2(2) | Account Management | Automated Temporary and Emergency Account Management | Automatically [disable] temporary and emergency accounts after [no more than 90 days]. | X | X | ||||
| AC-2(3) | Account Management | Disable Accounts | |||||||
| Disable accounts within [30 days for GSA users; for non-GSA users as determined by the System Owner and approved by the GSA CISO and AO] when the accounts: |
(a) Have expired;
(b) Are no longer associated with a user or individual;
(c) Are in violation of organizational policy; or
| (d) Have been inactive for [90 days for GSA users; for non-GSA users as determined by the System Owner and approved by the GSA CISO and AO]. | X | X | |||
| AC-2(4) | Account Management | Automated Audit Actions | Automatically audit account creation, modification, enabling, disabling, and removal actions. | X | X | |
| AC-2(5) | Account Management | Inactivity Logout | Require that users log out when [they have completed their workday]. | X | X | |
| AC-2(6) | Account Management | Dynamic Privilege Management | Implement [dynamic privilege management capabilities provided by enterprise endpoint and network security tools]. | |||
| AC-2(7) | Account Management | Privileged User Accounts | (a) Establish and administer privileged user accounts in accordance with [a role-based or attribute-based schema]; |
(b) Monitor privileged role or attribute assignments;
(c) Monitor changes to roles or attributes; and
| (d) Revoke access when privileged role or attribute assignments are no longer appropriate. | X | ||||||||
| NA | AC-2(8) | Account Management | Dynamic Account Management | Create, activate, manage, and deactivate [Assignment: organization-defined system accounts] dynamically. | ||||||
| NA | AC-2(9) | Account Management | Restrictions On Use of Shared and Group Accounts | Only permit the use of shared and group accounts that meet [Assignment: organization-defined conditions for establishing shared and group accounts]. | ||||||
| Withdrawn | AC-2(10) | Account Management | Shared and Group Account Credential Change | |||||||
| AC-2(11) | Account Management | Usage Conditions | Enforce [GSA SSO or Contractor recommended circumstances and/or usage conditions to be approved by the GSA CISO and AO] for [GSA SSO or Contractor recommended information system accounts to be approved by the GSA CISO and AO]. | X | ||||||
| AC-2(12) | Account Management | Account Monitoring for Atypical Usage | (a) Monitor system accounts for [atypical times of day and originating IP address for a known privileged account user that are inconsistent with normal usage patterns]; and | |||||||
| (b) Report atypical usage of system accounts to [the ISSO and the GSA OCISO]. | X | ||||||||
| AC-2(13) | Account Management | Disable Accounts for High-Risk Individuals | Disable accounts of individuals within [24 hours] of discovery of [account compromise relating to an incident or Insider Threat event (per the OMA Insider Threat Program] as directed by the GSA CISO, AO, and/or GSA Incident Response Team]. | X | X | |||||
| AC-3 | Access Enforcement | Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies. | X | X | X | X | X | ||
| NA | AC-3(1) | Access Enforcement | Restricted Access to Privileged Functions | |||||||
| NA | AC-3(2) | Access Enforcement | Dual Authorization | Enforce dual authorization for [Assignment: organization-defined privileged commands and/or other organization-defined actions]. | ||||||
| NA | AC-3(3) | Access Enforcement | Mandatory Access Control | Enforce [Assignment: organization-defined mandatory access control policy] over the set of covered subjects and objects specified in the policy, and where the policy: |
(a) Is uniformly enforced across the covered subjects and objects within the system;
(b) Specifies that a subject that has been granted access to information is constrained from doing any of the following;
(1) Passing the information to unauthorized subjects or objects;
(2) Granting its privileges to other subjects;
(3) Changing one or more security attributes (specified by the policy) on subjects, objects, the system, or system components;
(4) Choosing the security attributes and attribute values (specified by the policy) to be associated with newly created or modified objects; and
(5) Changing the rules governing access control; and
(c) Specifies that [Assignment: organization-defined subjects] may explicitly be granted [Assignment: organization-defined privileges] such that they are not limited by any defined subset (or all) of the above constraints.
NA AC-3(4) Access Enforcement | Discretionary Access Control Enforce [Assignment: organization-defined discretionary access control policy] over the set of covered subjects and objects specified in the policy, and where the policy specifies that a subject that has been granted access to information can do one or more of the following:
(a) Pass the information to any other subjects or objects;
(b) Grant its privileges to other subjects;
(c) Change security attributes on subjects, objects, the system, or the system’s components;
(d) Choose the security attributes to be associated with newly created or revised objects; or
(e) Change the rules governing access control.
| NA | AC-3(5) | Access Enforcement | Security-Relevant Information | Prevent access to [Assignment: organization-defined security-relevant information] except during secure, non-operable system states. |
| NA | AC-3(6) | Access Enforcement | Protection of User and System Information | |
| NA | AC-3(7) | Access Enforcement | Role-Based Access Control | Enforce a role-based access control policy over defined subjects and objects and control access based upon [Assignment: organization-defined roles and users authorized to assume such roles]. |
| NA | AC-3(8) | Access Enforcement | Revocation of Access Authorizations | Enforce the revocation of access authorizations resulting from changes to the security attributes of subjects and objects based on [Assignment: organization-defined rules governing the timing of revocations of access authorizations]. |
| NA | AC-3(9) | Access Enforcement | Controlled Release | Release information outside of the system only if: |
(a) The receiving [Assignment: organization-defined system or system component] provides [Assignment: organization-defined controls]; and
(b) [Assignment: organization-defined controls] are used to validate the appropriateness of the information designated for release.
| NA | AC-3(10) | Access Enforcement | Audited Override of Access Control Mechanisms | Employ an audited override of automated access control mechanisms under [Assignment: organization-defined conditions] by [Assignment: organization-defined roles]. |
| NA | AC-3(11) | Access Enforcement | Restrict Access to Specific Information Types | Restrict access to data repositories containing [Assignment: organization-defined information types]. |
| NA | AC-3(12) | Access Enforcement | Assert and Enforce Application Access | (a) Require applications to assert, as part of the installation process, the access needed to the following system applications and functions: [Assignment: organization-defined system applications and functions]; |
(b) Provide an enforcement mechanism to prevent unauthorized access; and
(c) Approve access changes after initial installation of the application.
| NA | AC-3(13) | Access Enforcement | Attribute-Based Access Control | Enforce attribute-based access control policy over defined subjects and objects and control access based upon [Assignment: organization-defined attributes to assume access permissions]. | ||||
| AC-3(14) | Access Enforcement | Individual Access | Provide [a self service mechanism or use GSA's Privacy Act Request for Access process] to enable individuals to have access to the following elements of their personally identifiable information: [as defined in the GSA PII Rules Matrix (https://docs.google.com/spreadsheets/d/1Yb9I9C3qCee8dnkVIIUqIZgrWsA1DoW0xYF2yPjgz0I/edit#gid=1521803081)]. | X | X^ | X^ | X^ | |
| NA | AC-3(15) | Access Enforcement | Discretionary and Mandatory Access Control | (a) Enforce [Assignment: organization-defined mandatory access control policy] over the set of covered subjects and objects specified in the policy; and |
(b) Enforce [Assignment: organization-defined discretionary access control policy] over the set of covered subjects and objects specified in the policy.
| AC-4 | Information Flow Enforcement | Enforce approved authorizations for controlling the flow of information within the system and between connected systems based on [Web Service Security (WS Security), WS-Security Policy, WS Trust, WS Policy Framework, Security Assertion Markup Language (SAML), extensible Access Control Markup Language (XACML)]. | X | X | |
| NA | AC-4(1) | Information Flow Enforcement | Object Security and Privacy Attributes | Use [Assignment: organization-defined security and privacy attributes] associated with [Assignment: organization-defined information, source, and destination objects] to enforce [Assignment: organization-defined information flow control policies] as a basis for flow control decisions. | ||
| NA | AC-4(2) | Information Flow Enforcement | Processing Domains | Use protected processing domains to enforce [Assignment: organization-defined information flow control policies] as a basis for flow control decisions. | ||
| NA | AC-4(3) | Information Flow Enforcement | Dynamic Information Flow Control | Enforce [Assignment: organization-defined information flow control policies]. | ||
| AC-4(4) | Information Flow Enforcement | Flow Control of Encrypted Information | Prevent encrypted information from bypassing [any information flow control mechanisms] by [decrypting the information, blocking the flow of the encrypted information, or by terminating communications sessions attempting to pass encrypted information]. | X | ||
| NA | AC-4(5) | Information Flow Enforcement | Embedded Data Types | Enforce [Assignment: organization-defined limitations] on embedding data types within other data types. | ||
| NA | AC-4(6) | Information Flow Enforcement | Metadata | Enforce information flow control based on [Assignment: organization-defined metadata]. | ||
| NA | AC-4(7) | Information Flow Enforcement | One-Way Flow Mechanisms | Enforce one-way information flows through hardware-based flow control mechanisms. | ||
| NA | AC-4(8) | Information Flow Enforcement | Security and Privacy Policy Filters | (a) Enforce information flow control using [Assignment: organization-defined security or privacy policy filters] as a basis for flow control decisions for [Assignment: organization-defined information flows]; and |
(b) [Selection (one or more): Block; Strip; Modify; Quarantine] data after a filter processing failure in accordance with [Assignment: organization-defined security or privacy policy].
| NA | AC-4(9) | Information Flow Enforcement | Human Reviews | Enforce the use of human reviews for [Assignment: organization-defined information flows] under the following conditions: [Assignment: organization-defined conditions]. |
| NA | AC-4(10) | Information Flow Enforcement | Enable and Disable Security or Privacy Policy Filters | Provide the capability for privileged administrators to enable and disable [Assignment: organization-defined security or privacy policy filters] under the following conditions: [Assignment: organization-defined conditions]. |
| NA | AC-4(11) | Information Flow Enforcement | Configuration of Security or Privacy Policy Filters | Provide the capability for privileged administrators to configure [Assignment: organization-defined security or privacy policy filters] to support different security or privacy policies. |
| NA | AC-4(12) | Information Flow Enforcement | Data Type Identifiers | When transferring information between different security domains, use [Assignment: organization-defined data type identifiers] to validate data essential for information flow decisions. |
| NA | AC-4(13) | Information Flow Enforcement | Decomposition Into Policy-Relevant Subcomponents | When transferring information between different security domains, decompose information into [Assignment: organization-defined policy-relevant subcomponents] for submission to policy enforcement mechanisms. |
| NA | AC-4(14) | Information Flow Enforcement | Security or Privacy Policy Filter Constraints | When transferring information between different security domains, implement [Assignment: organization-defined security or privacy policy filters] requiring fully enumerated formats that restrict data structure and content. |
| NA | AC-4(15) | Information Flow Enforcement | Detection of Unsanctioned Information | When transferring information between different security domains, examine the information for the presence of [Assignment: organization-defined unsanctioned information] and prohibit the transfer of such information in accordance with the [Assignment: organization-defined security or privacy policy]. |
| Withdrawn | AC-4(16) | Information Flow Enforcement | Information Transfers On Interconnected Systems | |
| NA | AC-4(17) | Information Flow Enforcement | Domain Authentication | Uniquely identify and authenticate source and destination points by [Selection (one or more): organization; system; |
application; service; individual] for information transfer.
| Withdrawn | AC-4(18) | Information Flow Enforcement | Security Attribute Binding | |
| NA | AC-4(19) | Information Flow Enforcement | Validation of Metadata | When transferring information between different security domains, implement [Assignment: organization-defined security or privacy policy filters] on metadata. |
| NA | AC-4(20) | Information Flow Enforcement | Approved Solutions | Employ [Assignment: organization-defined solutions in approved configurations] to control the flow of [Assignment: organization-defined information] across security domains. |
| NA | AC-4(21) | Information Flow Enforcement | Physical or Logical Separation of Information Flows | Separate information flows logically or physically using [Assignment: organization-defined mechanisms and/or techniques] to accomplish [Assignment: organization-defined required separations by types of information]. |
| NA | AC-4(22) | Information Flow Enforcement | Access Only | Provide access from a single device to computing platforms, applications, or data residing in multiple different security domains, while preventing information flow between the different security domains. |
| NA | AC-4(23) | Information Flow Enforcement | Modify Non-Releasable Information | When transferring information between different security domains, modify non-releasable information by implementing [Assignment: organization-defined modification action]. |
| NA | AC-4(24) | Information Flow Enforcement | Internal Normalized Format | When transferring information between different security domains, parse incoming data into an internal normalized format and regenerate the data to be consistent with its intended specification. |
| NA | AC-4(25) | Information Flow Enforcement | Data Sanitization | When transferring information between different security domains, sanitize data to minimize [Selection (one or more): delivery of malicious content, command and control of malicious code, malicious code augmentation, and steganography encoded data; spillage of sensitive information] in accordance with [Assignment: organization-defined policy]]. |
| NA | AC-4(26) | Information Flow Enforcement | Audit Filtering Actions | When transferring information between different security domains, record and audit content filtering actions and results for the information being filtered. |
| NA | AC-4(27) | Information Flow Enforcement | Redundant/Independent Filtering Mechanisms | When transferring information between different security domains, implement content filtering solutions that provide redundant and independent filtering mechanisms for each data type. |
| NA | AC-4(28) | Information Flow Enforcement | Linear Filter Pipelines | When transferring information between different security domains, implement a linear content filter pipeline that is enforced with discretionary and mandatory access controls. |
| NA | AC-4(29) | Information Flow Enforcement | Filter Orchestration Engines | When transferring information between different security domains, employ content filter orchestration engines to ensure that: |
(a) Content filtering mechanisms successfully complete execution without errors; and
(b) Content filtering actions occur in the correct order and comply with [Assignment: organization-defined policy].
| NA | AC-4(30) | Information Flow Enforcement | Filter Mechanisms Using Multiple Processes | When transferring information between different security domains, implement content filtering mechanisms using multiple processes. |
| NA | AC-4(31) | Information Flow Enforcement | Failed Content Transfer Prevention | When transferring information between different security domains, prevent the transfer of failed content to the receiving domain. |
| NA | AC-4(32) | Information Flow Enforcement | Process Requirements for Information Transfer | When transferring information between different security domains, the process that transfers information between filter pipelines: |
(a) Does not filter message content;
(b) Validates filtering metadata;
(c) Ensures the content associated with the filtering metadata has successfully completed filtering; and
(d) Transfers the content to the destination filter pipeline.
AC-5 Separation of Duties a. Identify and document [GSA SSO or Contractor recommended duties of individuals requiring separation, to be approved by the GSA CISO and AO];
b. Define system access authorizations to support separation of duties.
| X | X | X | ||||
| AC-6 | Least Privilege | Employ the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) that are necessary to accomplish assigned organizational tasks. | X | X | X | |
| AC-6(1) | Least Privilege | Authorize Access to Security Functions | Authorize access for [any individual or role] to: |
(a) [GSA SSO or Contractor recommended security functions (deployed in hardware, software, and firmware) approved by the GSA CISO and AO]; and
| (b) [security-relevant information as approved by the GSA CISO and AO]. | X | X | ||||||
| AC-6(2) | Least Privilege | Non-Privileged Access for Non-Security Functions | Require that users of system accounts (or roles) with access to [all security functions (examples of security functions include but are not limited to: establishing system accounts, configuring access authorizations (i.e., permissions, privileges), setting events to be audited, and setting intrusion detection parameters, system programming, system and security administration, other privileged functions)] use non-privileged accounts or roles, when accessing nonsecurity functions. | X | X | X | |||
| AC-6(3) | Least Privilege | Network Access to Privileged Commands | Authorize network access to [all privileged commands (i.e., any command requiring privileges above a standard user)] only for [GSA SSO or Contractor recommended compelling operational needs as approved by the GSA CISO and AO] and document the rationale for such access in the security plan for the system. | X | |||||
| NA | AC-6(4) | Least Privilege | Separate Processing Domains | Provide separate processing domains to enable finer-grained allocation of user privileges. | |||||
| AC-6(5) | Least Privilege | Privileged Accounts | Restrict privileged accounts on the system to [GSA SSO or Contractor recommended employees and contractors as approved by the GSA CISO and AO]. | X | X | X | |||
| NA | AC-6(6) | Least Privilege | Privileged Access By Non-Organizational Users | Prohibit privileged access to the system by non-organizational users. | |||||
| AC-6(7) | Least Privilege | Review of User Privileges | (a) Review [annually as part of the annual account review (per AC-2j)] the privileges assigned to [all roles and users] to validate the need for such privileges; and | ||||||
| (b) Reassign or remove privileges, if necessary, to correctly reflect organizational mission and business needs. | X | X | ||||||
| NA | AC-6(8) | Least Privilege | Privilege Levels for Code Execution | Prevent the following software from executing at higher privilege levels than users executing the software: [Assignment: organization-defined software]. | |||||
| AC-6(9) | Least Privilege | Log Use of Privileged Functions | Log the execution of privileged functions. | X | X | X | X | ||
| AC-6(10) | Least Privilege | Prohibit Non-Privileged Users From Executing Privileged Functions | Prevent non-privileged users from executing privileged functions. | X | X | ||||
| AC-7 | Unsuccessful Logon Attempts | a. Enforce a limit of [not more than ten (10) failed access attempts] consecutive invalid logon attempts by a user during a [30 minute time period]; and | ||||||
| b. Automatically [locks the account/node for 30 minutes] when the maximum number of unsuccessful attempts is exceeded. | X | X | X | |||||
| NA | AC-7(1) | Unsuccessful Logon Attempts | Automatic Account Lock | ||||||
| NA | AC-7(2) | Unsuccessful Logon Attempts | Purge or Wipe Mobile Device | Purge or wipe information from [Assignment: organization-defined mobile devices] based on [Assignment: organization-defined purging or wiping requirements and techniques] after [Assignment: organization-defined number] consecutive, unsuccessful device logon attempts. | |||||
| NA | AC-7(3) | Unsuccessful Logon Attempts | Biometric Attempt Limiting | Limit the number of unsuccessful biometric logon attempts to [Assignment: organization-defined number]. | |||||
| NA | AC-7(4) | Unsuccessful Logon Attempts | Use of Alternate Authentication Factor | (a) Allow the use of [Assignment: organization-defined authentication factors] that are different from the primary authentication factors after the number of organization-defined consecutive invalid logon attempts have been exceeded; and |
(b) Enforce a limit of [Assignment: organization-defined number] consecutive invalid logon attempts through use of the alternative factors by a user during a [Assignment: organization-defined time period].
AC-8 System Use Notification a. Display [a system use notification message or banner as defined in GSA Order CIO 2100.1] to users before granting access to the system that provides privacy and security notices consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines and state that:
1. Users are accessing a U.S. Government system;
2. System usage may be monitored, recorded, and subject to audit;
3. Unauthorized use of the system is prohibited and subject to criminal and civil penalties; and
4. Use of the system indicates consent to monitoring and recording;
b. Retain the notification message or banner on the screen until users acknowledge the usage conditions and take explicit actions to log on to or further access the system; and
c. For publicly accessible systems:
1. Display system use information [when accessed via logon interfaces with human users], before granting further access to the publicly accessible system;
2. Display references, if any, to monitoring, recording, or auditing that are consistent with privacy accommodations for such systems that generally prohibit those activities; and
| 3. Include a description of the authorized uses of the system. | X | X | X | X | |||
| NA | AC-9 | Previous Logon Notification | Notify the user, upon successful logon to the system, of the date and time of the last logon. | ||||
| NA | AC-9(1) | Previous Logon Notification | Unsuccessful Logons | Notify the user, upon successful logon, of the number of unsuccessful logon attempts since the last successful logon. | ||||
| NA | AC-9(2) | Previous Logon Notification | Successful and Unsuccessful Logons | Notify the user, upon successful logon, of the number of [Selection: successful logons; unsuccessful logon attempts; both] during [Assignment: organization-defined time period]. | ||||
| NA | AC-9(3) | Previous Logon Notification | Notification of Account Changes | Notify the user, upon successful logon, of changes to [Assignment: organization-defined security-related characteristics or parameters of the user’s account] during [Assignment: organization-defined time period]. | ||||
| NA | AC-9(4) | Previous Logon Notification | Additional Logon Information | Notify the user, upon successful logon, of the following additional information: [Assignment: organization-defined additional information]. | ||||
| AC-10 | Concurrent Session Control | Limit the number of concurrent sessions for each [user] to [GSA SSO or Contractor recommended number to be approved by the GSA CISO and AO]. | X | ||||
| AC-11 | Device Lock | a. Prevent further access to the system by [initiating a device lock after 15 minutes of inactivity; requiring the user to initiate a device lock before leaving the system unattended]; and | |||||
| b. Retain the device lock until the user reestablishes access using established identification and authentication procedures. | X | X | |||||
| AC-11(1) | Device Lock | Pattern-Hiding Displays | Conceal, via the device lock, information previously visible on the display with a publicly viewable image. | X | X | |||
| AC-12 | Session Termination | Automatically terminate a user session after [ |
(1) 30 minutes of inactivity,
(2) the following timeframes, regardless of user activity:
a. Thirty (30) days for systems at AAL1
| b. Twelve (12) hours for systems at AAL2 and AAL3]. | X | X | X | ||
| NA | AC-12(1) | Session Termination | User-Initiated Logouts | Provide a logout capability for user-initiated communications sessions whenever authentication is used to gain access to [Assignment: organization-defined information resources]. | ||
| NA | AC-12(2) | Session Termination | Termination Message | Display an explicit logout message to users indicating the termination of authenticated communications sessions. | ||
| NA | AC-12(3) | Session Termination | Timeout Warning Message | Display an explicit message to users indicating that the session will end in [Assignment: organization-defined time until end of session]. | ||
| NA | AC-13 | Supervision and Review — Access Control | |||
| AC-14 | Permitted Actions Without Identification or Authentication | a. Identify [no user actions] that can be performed on the system without identification or authentication consistent with organizational mission and business functions; and | |||
| b. Document and provide supporting rationale in the security plan for the system, user actions not requiring identification or authentication. | X | X | X | ||
| NA | AC-14(1) | Permitted Actions Without Identification or Authentication | Necessary Uses | |||
| NA | AC-15 | Automated Marking | |||
| NA | AC-16 | Security and Privacy Attributes | a. Provide the means to associate [Assignment: organization-defined types of security and privacy attributes] with [Assignment: organization-defined security and privacy attribute values] for information in storage, in process, and/or in transmission; |
b. Ensure that the attribute associations are made and retained with the information;
c. Establish the following permitted security and privacy attributes from the attributes defined in AC-16a for [Assignment: organization-defined systems]: [Assignment: organization-defined security and privacy attributes];
d. Determine the following permitted attribute values or ranges for each of the established attributes: [Assignment: organization-defined attribute values or ranges for established attributes];
e. Audit changes to attributes; and
f. Review [Assignment: organization-defined security and privacy attributes] for applicability [Assignment: organization-defined frequency].
| NA | AC-16(1) | Security and Privacy Attributes | Dynamic Attribute Association | Dynamically associate security and privacy attributes with [Assignment: organization-defined subjects and objects] in accordance with the following security and privacy policies as information is created and combined: [Assignment: organization-defined security and privacy policies]. | |||
| NA | AC-16(2) | Security and Privacy Attributes | Attribute Value Changes By Authorized Individuals | Provide authorized individuals (or processes acting on behalf of individuals) the capability to define or change the value of associated security and privacy attributes. | |||
| NA | AC-16(3) | Security and Privacy Attributes | Maintenance of Attribute Associations By System | Maintain the association and integrity of [Assignment: organization-defined security and privacy attributes] to [Assignment: organization-defined subjects and objects]. | |||
| NA | AC-16(4) | Security and Privacy Attributes | Association of Attributes By Authorized Individuals | Provide the capability to associate [Assignment: organization-defined security and privacy attributes] with [Assignment: organization-defined subjects and objects] by authorized individuals (or processes acting on behalf of individuals). | |||
| NA | AC-16(5) | Security and Privacy Attributes | Attribute Displays on Objects to be Output | Display security and privacy attributes in human-readable form on each object that the system transmits to output devices to identify [Assignment: organization-defined special dissemination, handling, or distribution instructions] using [Assignment: organization-defined human-readable, standard naming conventions]. | |||
| NA | AC-16(6) | Security and Privacy Attributes | Maintenance of Attribute Association | Require personnel to associate and maintain the association of [Assignment: organization-defined security and privacy attributes] with [Assignment: organization-defined subjects and objects] in accordance with [Assignment: organization-defined security and privacy policies]. | |||
| NA | AC-16(7) | Security and Privacy Attributes | Consistent Attribute Interpretation | Provide a consistent interpretation of security and privacy attributes transmitted between distributed system components. | |||
| NA | AC-16(8) | Security and Privacy Attributes | Association Techniques and Technologies | Implement [Assignment: organization-defined techniques and technologies] in associating security and privacy attributes to information. | |||
| NA | AC-16(9) | Security and Privacy Attributes | Attribute Reassignment - Regrading Mechanism | Change security and privacy attributes associated with information only via regrading mechanisms validated using [Assignment: organization-defined techniques or procedures]. | |||
| NA | AC-16(10) | Security and Privacy Attributes | Attribute Configuration By Authorized Individuals | Provide authorized individuals the capability to define or change the type and value of security and privacy attributes available for association with subjects and objects. | |||
| AC-17 | Remote Access | a. Establish and document usage restrictions, configuration/connection requirements, and implementation guidance for each type of remote access allowed; and | ||||
| b. Authorize each type of remote access to the system prior to allowing such connections. | X | X | X | |||
| AC-17(1) | Remote Access | Monitoring and Control | Employ automated mechanisms to monitor and control remote access methods. | X | X | ||
| AC-17(2) | Remote Access | Protection of Confidentiality and Integrity Using Encryption | Implement cryptographic mechanisms to protect the confidentiality and integrity of remote access sessions. | X | X | ||
| AC-17(3) | Remote Access | Managed Access Control Points | Route remote accesses through authorized and managed network access control points. | X | X | ||
| AC-17(4) | Remote Access | Privileged Commands and Access | (a) Authorize the execution of privileged commands and access to security-relevant information via remote access only in a format that provides assessable evidence and for the following needs: [GSA SSO or contractor recommended and GSA CISO and AO approved special cases for remote administration and maintenance tasks]; and | ||||
| (b) Document the rationale for remote access in the security plan for the system. | X | X | ||||
| NA | AC-17(5) | Remote Access | Monitoring for Unauthorized Connections | ||||
| NA | AC-17(6) | Remote Access | Protection of Mechanism Information | Protect information about remote access mechanisms from unauthorized use and disclosure. | |||
| NA | AC-17(7) | Remote Access | Additional Protection for Security Function Access | ||||
| NA | AC-17(8) | Remote Access | Disable Nonsecure Network Protocols | ||||
| NA | AC-17(9) | Remote Access | Disconnect or Disable Access | Provide the capability to disconnect or disable remote access to the system within [Assignment: organization-defined time period]. | |||
| NA | AC-17(10) | Remote Access | Authenticate Remote Commands | Implement [Assignment: organization-defined mechanisms] to authenticate [Assignment: organization-defined remote commands]. | |||
| AC-18 | Wireless Access | a. Establish configuration requirements, connection requirements, and implementation guidance for each type of wireless access; and | ||||
| b. Authorize each type of wireless access to the system prior to allowing such connections. | X | X | X | |||
| AC-18(1) | Wireless Access | Authentication and Encryption | Protect wireless access to the system using authentication of [users and devices] and encryption. | X | X | ||
| NA | AC-18(2) | Wireless Access | Monitoring Unauthorized Connections | ||||
| AC-18(3) | Wireless Access | Disable Wireless Networking | Disable, when not intended for use, wireless networking capabilities embedded within system components prior to issuance and deployment. | X | X | ||
| AC-18(4) | Wireless Access | Restrict Configurations By Users | Identify and explicitly authorize users allowed to independently configure wireless networking capabilities. | X | |||
| AC-18(5) | Wireless Access | Antennas and Transmission Power Levels | Select radio antennas and calibrate transmission power levels to reduce the probability that signals from wireless access points can be received outside of organization-controlled boundaries. | X | |||
| AC-19 | Access Control for Mobile Devices | a. Establish configuration requirements, connection requirements, and implementation guidance for organization-controlled mobile devices, to include when such devices are outside of controlled areas; and | ||||
| b. Authorize the connection of mobile devices to organizational systems. | X | X | X | |||
| NA | AC-19(1) | Access Control for Mobile Devices | Use of Writable and Portable Storage Devices | ||||
| NA | AC-19(2) | Access Control for Mobile Devices | Use of Personally Owned Portable Storage Devices | ||||
| NA | AC-19(3) | Access Control for Mobile Devices | Use of Portable Storage Devices With No Identifiable Owner | ||||
| NA | AC-19(4) | Access Control for Mobile Devices | Restrictions for Classified Information | (a) Prohibit the use of unclassified mobile devices in facilities containing systems processing, storing, or transmitting classified information unless specifically permitted by the authorizing official; and |
(b) Enforce the following restrictions on individuals permitted by the authorizing official to use unclassified mobile devices in facilities containing systems processing, storing, or transmitting classified information:
(1) Connection of unclassified mobile devices to classified systems is prohibited;
(2) Connection of unclassified mobile devices to unclassified systems requires approval from the authorizing official;
(3) Use of internal or external modems or wireless interfaces within the unclassified mobile devices is prohibited; and
(4) Unclassified mobile devices and the information stored on those devices are subject to random reviews and inspections by [Assignment: organization-defined security officials], and if classified information is found, the incident handling policy is followed.
(c) Restrict the connection of classified mobile devices to classified systems in accordance with [Assignment: organization-defined security policies].
| AC-19(5) | Access Control for Mobile Devices | Full Device or Container-Based Encryption | Employ [at a minimum full device encryption, preferred container encryption] to protect the confidentiality and integrity of information on [GSA approved and authorized mobile devices]. | X | X |
| AC-20 | Use of External Systems | a. Establish [terms and conditions per agreements established by CA-3; and identify controls asserted to be implemented on external systems per agreements established by CA-3], consistent with the trust relationships established with other organizations owning, operating, and/or maintaining external systems, allowing authorized individuals to: |
1. Access the system from external systems; and
2. Process, store, or transmit organization-controlled information using external systems; or
| b. Prohibit the use of [external systems not covered by an approved ISA, per CA-3]. | X | X | X |
| AC-20(1) | Use of External Systems | Limits On Authorized Use | Permit authorized individuals to use an external system to access the system or to process, store, or transmit organization-controlled information only after: |
(a) Verification of the implementation of controls on the external system as specified in the organization’s security and privacy policies and security and privacy plans; or
| (b) Retention of approved system connection or processing agreements with the organizational entity hosting the external system. | X | X | |
| AC-20(2) | Use of External Systems | Portable Storage Devices – Restricted Use | Restrict the use of organization-controlled portable storage devices by authorized individuals on external systems using [prohibits the use on any external system that is not GSA owned incuding the use of personally-owned systems]. |
GSA Additional Guidance: Portable Storage Devices include digital media such as flash drives, diskettes, magnetic tapes, external or removable hard disk drives (e.g., solid state, magnetic), compact discs, and digital versatile discs.
| External systems are systems that are used by but not part of organizational systems, and for which the organization has no direct control over the implementation of required controls or the assessment of control effectiveness. External systems include personally owned systems, components, or devices; privately owned computing and communications devices in commercial or public facilities; systems owned or controlled by nonfederal organizations; systems managed by contractors; and federal information systems that are not owned by, operated by, or under the direct supervision or authority of the organization. External systems also include systems owned or operated by other components within the same organization and systems within the organization with different authorization boundaries. | X | X | |||
| NA | AC-20(3) | Use of External Systems | Non-Organizationally Owned Systems — Restricted Use | Restrict the use of non-organizationally owned systems or system components to process, store, or transmit organizational information using [Assignment: organization-defined restrictions]. | ||
| NA | AC-20(4) | Use of External Systems | Network Accessible Storage Devices — Prohibited Use | Prohibit the use of [Assignment: organization-defined network accessible storage devices] in external systems. | ||
| NA | AC-20(5) | Use of External Systems | Portable Storage Devices – Prohibited Use | Prohibit the use of organization-controlled portable storage devices by authorized individuals on external systems. | ||
| AC-21 | Information Sharing | a. Enable authorized users to determine whether access authorizations assigned to a sharing partner match the information’s access and use restrictions for [GSA SSO or Contractor recommended information sharing circumstances where user discretion is required to be approved by the GSA CISO and AO]; and | |||
| b. Employ [GSA SSO or Contractor recommended automated mechanisms or manual processes to be approved by the GSA CISO and AO] to assist users in making information sharing and collaboration decisions. | X | X | X | ||
| NA | AC-21(1) | Information Sharing | Automated Decision Support | Employ [Assignment: organization-defined automated mechanisms] to enforce information-sharing decisions by authorized users based on access authorizations of sharing partners and access restrictions on information to be shared. | ||
| NA | AC-21(2) | Information Search and Information Sharing | Retrieval | Implement information search and retrieval services that enforce [Assignment: organization-defined information sharing restrictions]. | ||
| AC-22 | Publicly Accessible Content | a. Designate individuals authorized to make information publicly accessible; |
b. Train authorized individuals to ensure that publicly accessible information does not contain nonpublic information;
c. Review the proposed content of information prior to posting onto the publicly accessible system to ensure that nonpublic information is not included; and
| d. Review the content on the publicly accessible system for nonpublic information [quarterly] and remove such information, if discovered. | X | X | X | |
| NA | AC-23 | Data Mining Protection | Employ [Assignment: organization-defined data mining prevention and detection techniques] for [Assignment: organization-defined data storage objects] to detect and protect against unauthorized data mining. | |
| NA | AC-24 | Access Control Decisions | [Selection: Establish procedures; Implement mechanisms] to ensure [Assignment: organization-defined access control decisions] are applied to each access request prior to access enforcement. | |
| NA | AC-24(1) | Access Control Decisions | Transmit Access Authorization Information | Transmit [Assignment: organization-defined access authorization information] using [Assignment: organization-defined controls] to [Assignment: organization-defined systems] that enforce access control decisions. | |
| NA | AC-24(2) | Access Control Decisions | No User or Process Identity | Enforce access control decisions based on [Assignment: organization-defined security or privacy attributes] that do not include the identity of the user or process acting on behalf of the user. | |
| NA | AC-25 | Reference Monitor | Implement a reference monitor for [Assignment: organization-defined access control policies] that is tamperproof, always invoked, and small enough to be subject to analysis and testing, the completeness of which can be assured. | |
| AT-1 | (Awareness and Training) | |||
| Policy and Procedures | a. Develop, document, and disseminate to [personnel with IT security responsibilities as defined in GSA Order CIO 2100.1]: |
1. [Organization-level] awareness and training policy that:
(a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
(b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and
2. Procedures to facilitate the implementation of the awareness and training policy and the associated awareness and training controls;
b. Designate an [CISO] to manage the development, documentation, and dissemination of the awareness and training policy and procedures; and
c. Review and update the current awareness and training:
1. Policy [annually, as part of CIO 2100.1 update] and following [changes to Federal or GSA policies, requirements, or guidance]; and
| 2. Procedures [at least every three (3) years] and following [changes to Federal or GSA policies, requirements, or guidance]. | X | X | X | X |
| AT-2 | Literacy Training and Awareness | a. Provide security and privacy literacy training to system users (including managers, senior executives, and contractors): |
1. As part of initial training for new users and [annually] thereafter; and
2. When required by system changes or following [the analysis of security trends, signficant events, and user feedback];
b. Employ the following techniques to increase the security and privacy awareness of system users [by frequent phishing, security vignettes via emails];
c. Update literacy training and awareness content [annually] and following [the analysis of security and privacy trends, signficant events, and user feedbacks]; and
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .