Amendment 0003 SOW Attachment 8C Information Technology Security.pdf
PDF 3 MB Posted
- Attached to
- Next Generation Credential Authentication Technology (CAT2) Federal contract opportunity
- Solicitation number
- 70T04022R7672N007
About this file
This is a request for proposal from the Transportation Security Administration seeking offers for a next generation credential authentication technology system and related support services. Offerors must submit requests for access to pre-award sensitive security information by September 1st and submit any questions by September 9th. Proposals for Phase 1 are due by September 30th. The solicitation seeks design, manufacture, testing, maintenance, installation, program management, training, engineering support, delivery, and logistics services to support the credential authentication technology system. The associated NAICS code is 334511 with a small business size standard of 1,250 employees.
View the file
Other files for this federal contract opportunity
Show all 34
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
INFORMATION TECHNOLOGY
TSA MANAGEMENT DIRECTIVE No. 1400.3
INFORMATION TECHNOLOGY SECURITY
To enhance mission performance, TSA is committed to promoting a culture founded on its values of Integrity, Respect and Commitment.
REVISION:
This revised directive supersedes TSA MD 1400.3, Information Technology Security dated April 8, 2014.
SUMMARY OF CHANGES:
Section 1, Purpose, updated; Section 2, Scope, updated; Section 3, Authorities, updated; Section 4, Definitions, updated; Section 5, Responsibilities, updated; Section 6, Policy, updated; Section 7, Procedures, updated; and Section 8, Approval and Effective Date, updated.
1. PURPOSE:
This directive provides TSA information assurance and cybersecurity policy and procedures for the secure use, development, maintenance, and continuous monitoring of authorized TSA information systems including prototypes and telecommunications.
2. SCOPE:
This directive and its Attachment 1, TSA Information Assurance (IA) Handbook, shall apply to all TSA employees and contractors, as well as TSA-owned, or TSA-controlled information systems that collects, generates, processes, stores, displays, transmits, continuously monitor, backup, dispositions or receives TSA data. This includes prototypes, telecommunications systems, cloud environment, and all systems in all phases of the System Engineering Life Cycle (SELC).
3. AUTHORITIES:
A. 44 United States Code (USC) Chapter 33, Disposal of Records
B. 14 Code of Federal Regulations (CFR), Part 191, Protection of Sensitive Security Information
C. E.O. 13526, Classified National Security Information
D. DHS 140-01, Information Technology Security Program
E. DHS Sensitive Systems Policy Directive 4300A F. DHS National Security Systems Policy Directive 4300B
G. Homeland Security Presidential Directive (HSPD) 7, Critical Infrastructure Identification, Prioritization, and Protection
H. HSPD 12, Policy for a Common Identification Standard for Federal Employees and Contractors
I. DHS Secure Cloud Computing Guidance
J. DHS IT Strategic Plan
K. TSA Management Directive (MD) 1400.20, IT Governance https://office.ishare.tsa.dhs.gov/sites/ITSEC/CP/PC/policy/Internal%20Shared%20Documents/Projects/TSA%20IA%20HB%20v14.1%20Final.pdf https://www.archives.gov/isoo/policy-documents/cnsi-eo.html http://dhsconnect.dhs.gov/org/comp/mgmt/policies/Directives/140-01.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/policies/Directives/140-01.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/ocio/ciso/Pages/sspolicy.aspx http://dhsconnect.dhs.gov/org/comp/mgmt/ocio/ciso/Pages/sspolicy.aspx http://dhsconnect.dhs.gov/org/comp/mgmt/policies/Directives/4300B.pdf#search=DHS%204300B http://dhsconnect.dhs.gov/org/comp/mgmt/policies/Directives/4300B.pdf#search=DHS%204300B http://www.dhs.gov/homeland-security-presidential-directive-7 http://www.dhs.gov/homeland-security-presidential-directive-7 http://www.dhs.gov/homeland-security-presidential-directive-12 http://www.dhs.gov/homeland-security-presidential-directive-12 http://dhsconnect.dhs.gov/org/comp/mgmt/ocio/ciso/CISO%20ALL%20Documents/Cloud%20Computing%20Appendix.pdf#search=DHS%20Secure%20cloud%20computing%20guidance http://dhsconnect.dhs.gov/org/comp/mgmt/ocio/ciso/CISO%20ALL%20Documents/Cloud%20Computing%20Appendix.pdf#search=DHS%20Secure%20cloud%20computing%20guidance https://ishare.tsa.dhs.gov/Offices/OCRO/ReadingRoom/DHS%20Strategic%20Plan%20FY14-18.pdf#search=DHS%20IT%20Strategic%20Plan https://ishare.tsa.dhs.gov/PoliciesAndForms/Policies/Policies%20Library/TSA%20MD%201400.20,%20508%20Compliance%20v,%20170403.pdf#zoom=100
L. TSA Information Assurance (IA) Handbook M. TSA MD 2810.1, SSI Program
N. SSI Policies and Procedures Handbook
O. TSA MD 1400.24 Enterprise Information Sharing
P. TSA MD 1400.25 Enterprise Information and Data Governance Q. TSA IT Strategic Plan
R. OMB M-17-25, Reporting Guidance for Executive Order on Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure
S. PL 113-283, Federal Information Security Modernization Act (FISMA) of 2014 (Amendment to FISMA 2002)
T. PL 107-347, E-Government Act of 2002, Federal Information Security Management Act (FISMA) of 2002
U. Office of Management and Budget (OMB) M-17-27, Assessment and Enforcement of Domestic Preferences in Accordance with Buy American Laws
V. OMB M-17-09, Management of Federal High Value Assets (HVAs)
W. OMB M-16-17 Circulate A-123, Management’s Responsibility for Enterprise Risk Management and Internal Control
X. OMB M-16-04, Cybersecurity Strategy and Implementation Plan (CSIP) for the Federal Civilian Government
Y. OMB M-15-14, Management and Oversight of Federal Information Technology (on
FITARA)
Z. OMB M-14-04, FY 2013 Reporting Instructions for the Federal Information Security Management Act (FISMA) and Agency Privacy Management
AA. OMB M-14-03, Enhancing the Security of Federal Information and Information Systems
BB. OMB Circular A-130 Revision, Managing Information as a Strategic Resource CC. Information Technology (IT) Cloud Computing Security Handbook
DD. National Institute of Standards and Technology (NIST) Special Publication 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems:
A Security Life Cycle Approach
EE. NIST SP 800-137, Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations
FF. NIST Supplemental Guidance on Ongoing Authorization: Transitioning to Near Real- Time Risk Management
GG. NIST Special Publication 800-55, Security Metrics Guide for Information Security
HH. Sensitive Security Information (SSI) Policies and Procedures Handbook https://office.ishare.tsa.dhs.gov/sites/ITSEC/CP/PC/policy/Internal%20Shared%20Documents/Projects/TSA%20IA%20HB%20v14.1%20Final.pdf https://ishare.tsa.dhs.gov/PoliciesAndForms/Policies/Policies%20Library/TSA%20MD%202810.1,%20FINAL,%20151104.pdf#zoom=100 https://ishare.tsa.dhs.gov/Offices/LawEnforcementFAMS/SecuritySvcAssessments/SSIBranch/Policies%20%20Procedures%20PPs/Forms/AllItems.aspx https://ishare.tsa.dhs.gov/PoliciesAndForms/Policies/Policies%20Library/TSA%20MD%201400-24,%20FINAL,%20210812.pdf https://ishare.tsa.dhs.gov/PoliciesAndForms/Policies/Policies%20Library/TSA%20MD%201400-25,%20FINAL,%20210810.pdf https://ishare.tsa.dhs.gov/Offices/OIT/Documents/Strategy/IT%20Strategic%20Plan%20FY1720.pdf https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/memoranda/2017/M-17-25.pdf https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/memoranda/2017/M-17-25.pdf https://www.congress.gov/113/plaws/publ283/PLAW-113publ283.pdf https://www.gpo.gov/fdsys/pkg/PLAW-107publ347/pdf/PLAW-107publ347.pdf https://www.gpo.gov/fdsys/pkg/PLAW-107publ347/pdf/PLAW-107publ347.pdf https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/memoranda/2017/M-17-27_assessment_enforcement_domestic_preference_buy_american_laws.pdf https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/memoranda/2017/M-17-27_assessment_enforcement_domestic_preference_buy_american_laws.pdf https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/memoranda/2017/m-17-09.pdf https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/memoranda/2016/m-16-17.pdf https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/memoranda/2016/m-16-17.pdf https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/memoranda/2016/m-16-04.pdf https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/memoranda/2016/m-16-04.pdf https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/memoranda/2015/m-15-14.pdf https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/memoranda/2015/m-15-14.pdf https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/memoranda/2014/m-14-04.pdf https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/memoranda/2014/m-14-04.pdf https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/memoranda/2014/m-14-03.pdf https://a130.cio.gov/ https://office.ishare.tsa.dhs.gov/sites/ITSEC/CP/PC/policy/Internal%20Shared%20Documents/Projects/Cloud%20Computing%20Security%20Handbook%20(CCSH),%20V2/TSA%20CCSH%20Main%20v2%20Final%20Signed.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r1.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r1.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r1.pdf http://csrc.nist.gov/publications/nistpubs/800-137/SP800-137-Final.pdf http://csrc.nist.gov/publications/nistpubs/800-137/SP800-137-Final.pdf http://csrc.nist.gov/publications/nistpubs/800-37-rev1/nist_oa_guidance.pdf http://csrc.nist.gov/publications/nistpubs/800-37-rev1/nist_oa_guidance.pdf http://csrc.nist.gov/publications/nistpubs/800-55-Rev1/SP800-55-rev1.pdf https://ishare.tsa.dhs.gov/Offices/LawEnforcementFAMS/SecuritySvcAssessments/SSIBranch/Policies%20%20Procedures%20PPs/Forms/AllItems.aspx
4. DEFINITIONS:
A. Authorizing Official (AO): TSA official with the authority to formally assume accountability for operating an information system at an acceptable level of risk to the agency and is empowered to grant and oversee approval for a system to operate.
B. Chief Information Officer (CIO): TSA official with oversight authority for information systems and the effectiveness and completeness of each system’s Information Security including FISMA compliance within the Agency.
C. Chief Information Security Officer (CISO) and Executive Director for Information Assurance and Cybersecurity Division (IAD): TSA official with assigned authority and oversight for implementing and organizing information security program under the direction of the CIO. This position may also be known as the Senior Information Security Officer.
D. Cloud Computing: A model for enabling on-demand network access to a shared pool of configurable IT capabilities/resources (e.g. networks, servers, storage, applications and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction. It allows users to access technology-based services from the network cloud without knowledge of, expertise with, or control over the technology infrastructure that supports them. This cloud model is composed of five essential characteristics (on-demand self-service, ubiquitous network access, location independent resource pooling, rapid elasticity, and measured service); three service delivery models (Cloud Software as a Service (SaaS), Cloud Platform as a Service (PaaS), and Cloud Infrastructure as a Service (IaaS)); and four models for enterprise access (Private cloud, Community cloud, Public cloud and Hybrid cloud). Both the user's data and essential security services may reside in and be managed within the network cloud.
E. Continuous Diagnostics and Mitigation (CDM): Dynamic approach to fortifying the cybersecurity of government networks and systems; it provides federal departments and agencies with capabilities and tools that identify cybersecurity risks on an ongoing basis, prioritizes these risks based upon potential impacts, and enable cybersecurity personnel to mitigate the most significant problems first. The CDM process implements and maintains current security status for one or more information systems or for the entire suite of information systems on which the operational mission of the enterprise depends.
The process includes: 1) The development of a strategy to regularly evaluate selected information assurance (IA) controls/metrics; 2) Recording and evaluating IA relevant events, incidents and the effectiveness of the enterprise in dealing with those events; 3) Recording changes to IA controls or changes that affect IA risks; and 4) Publishing the current security status to enable information-sharing decisions involving the enterprise.
F. Continuous Monitoring as a Service (CMaaS): A service that provides the ability to maintain ongoing awareness of information security vulnerabilities and threats to support organizational risk management decisions in real-time. The terms “continuous” and “ongoing” in this context imply that security controls and organizational risks are assessed and analyzed at a frequency sufficient to support risk-based security decisions to adequately protect organization information.
G. Cyber Attack: An attack, via cyberspace, targeting an enterprise’s use of cyberspace for the purpose of disrupting, disabling, destroying, or maliciously controlling a computing environment/infrastructure; or destroying the integrity of the data or stealing controlled information.
H. Cybersecurity: Prevention of damage to, protection of, and restoration of computers, electronic communications systems, electronic communications services, wire communication, and electronic communication, including information contained therein, to ensure its availability, integrity, authentication, confidentiality and nonrepudiation.
I. Cyberspace: A global domain within the information environment consisting of the interdependent network of information systems infrastructures including the Internet, telecommunications networks, computer systems, and embedded processors and controllers.
J. Cyber Incident: Actions taken through the use of an information system or network that result in an actual or potentially adverse effect on an information system, network, and/or the information residing therein. See incidents, events, security-relevant event, and/or intrusion.
K. DHS and GSA CDM Program: The DHS, in partnership with the General Services Administration (GSA), has established a CDM Program. This DHS/GSA partnership established a government-wide acquisition vehicle for continuous monitoring capabilities.
L. Information Owner (IO): TSA official with statutory or operational authority for specified information and oversight on establishing controls for its generation, collection, processing, dissemination, and disposal. With some systems the Information Owner may also be the Program Manager, Business Owner, System Owner or Data Stewards.
M. Information System (IS): A discrete set of information resources, either in stand-alone or networked configurations, which is organized for the collection, processing, maintenance, transmission, and dissemination of information in accordance with defined procedures, whether automated or manual.
N. Information System Security Officer (ISSO): The security official, either government or contractor, responsible for the security posture of an assigned set of information systems.
O. Ongoing Authorization (OA): The OA methodology has been adopted from DHS and involves shifting from periodic to ongoing assessments and facilitating a continual state of compliance awareness. OA procedures provide guidance for the implementation and transition of ongoing authorizations at TSA.
http://dhsconnect.dhs.gov/org/comp/mgmt/ocio/ciso/CISO%20ALL%20Documents/DHS%20Info%20Security%20Continuous%20Monitoring%20Strategy.pdf#search=CDM https://office.ishare.tsa.dhs.gov/sites/ITSEC/CP/CRM/Compliance/OA/default.aspx?PageView=Shared
P. Security Authorization Package: The package that is transmitted from the System Owner (SO) to the AO seeking an official management decision to authorize operation of an information system for all offices in a specified environment at an acceptable level of risk, based on the implementation of an approved set of technical, managerial, and operational safeguards.
Q. Security Authorization Process (SAP): The combination of documentation, test and evaluation activities required to ensure that adequate information security controls are in place to reduce the information security risks of operating a system to an acceptable level and acknowledgement that the level of residual risk is acceptable to management.
R. Security Control Assessor (SCA): The individual, group, or organization with the authority and oversight for conducting the security control assessment.
S. System Engineering Life Cycle (SELC): The set of processes used by a systems analyst to develop an information system, including requirements, validation, training, and user ownership.
T. System Owner (SO): The Government official responsible for implementing and maintaining the security posture of an assigned set of information systems.
U. Sensitive Security Information (SSI): As defined in the SSI Regulation at § 1520.5, information obtained or developed in the conduct of security activities, including research and development, the disclosure of which DHS/TSA has determined would, among other things, be detrimental to the security of transportation. For detailed categories of SSI, see the SSI Regulation, 49 C.F.R. § 1520.5(b)(1) through (16)). For additional guidance on how to identify SSI, see SSI Policies and Procedures Handbook, Section 3.0, Identifying
SSI.
V. Technical Solutions Portfolio (Tech SP): A database that is an authoritative source of technology solutions for TSA, which was designed to assist TSA personnel to search and identify software and hardware products that are currently in use and approved at TSA. It categorizes the standards and technologies to support and enable the delivery of service components and capabilities. All IT hardware and software shall be compliant with TSA standards and products profile and shall be subject to TSA and DHS Enterprise Architectural approval. No products shall be utilized in any production environment that is not included in the solutions portfolio.
5. RESPONSIBILITIES:
A. The CIO is responsible for:
(1) Ensuring the planning, development, maintenance, and management of the TSA Information Security/Information Assurance Program is performed;
(2) Appointing an AO for every TSA information system or serving as the AO for an information system where one has not been appointed, or where a vacancy exists;
https://apps2013.ishare.tsa.dhs.gov/sites/EAD-TRM/SitePages/Home.aspx
(3) Appointing a CISO and Executive Director for IAD; and
(4) Ensuring that information security and assurance requirements and policies are addressed early in the acquisition and contracting process prior to award.
B. The AO is responsible for:
(1) Ensuring the secure operation of an information system is at an acceptable level of risk for the agency;
(2) Granting or withholding authorization of security controls prescribed for a system;
and
(3) Signing an authorization/approval memorandum that documents the authorization decision determined by the adequacy of system safeguards.
C. The CISO/Executive Director for IAD is responsible for:
(1) Ensuring the implementation and management of the TSA-wide information security/information assurance program in accordance with IT and IAD strategic plans;
(2) Issuing TSA-wide information security strategy, policy, guidance, and coordinating enterprise architectural requirements with the Chief Enterprise Architect (CEA), for all TSA information systems and networks;
(3) Serving as the principal department liaison with organizations outside TSA in matters relating to information security, information assurance, and cybersecurity;
(4) Arbitrating a conflicting information security/assurance policy or guidance;
(5) Ensuring that directives such as the TSA MD 1400.3 Information Technology Security and its Attachment 1, TSA Information Assurance (IA) Handbook, are updated and maintained;
(6) Coordinating and working with the Sensitive Security Information (SSI) Office to ensure that SSI is protected and is disclosed to vetted and covered persons with a need-to-know; and
(7) Cyber risk assessments for all TSA data, information, and systems and serving as TSA’s Cyber Risk Executive and Cyber Workforce Lead.
D. The SCA is responsible for:
(1) Ensuring that risk analysis is performed to identify IT or IA security risks;
(2) Determining risk magnitude; and
(3) Identifying what areas need additional safeguards.
E. The Information Assurance and Cybersecurity Division (IAD) is responsible for:
(1) Protecting information, data source codes, and information systems against unauthorized access, unauthorized use, disclosure, disruption, unauthorized modification, or destruction;
(2) Implementing and providing IT centric security programs for classified and sensitive but unclassified (SBU)-level IT systems and communications security management;
(3) Preserving, maintaining, and updating this TSA MD 1400.3 ITS and serving as contact point for all inquiries pertaining to the IAD;
(4) Providing Federal Information Security Management Act (FISMA) compliance;
managing IT procurement requests; developing TSA IT related security policy, technical standards, and standard operating procedures; providing critical infrastructure protection oversight; and assessing information security risks within
TSA;
(5) Reviewing, testing and approving the security of all TSA IT systems; and
(6) Ensuring that all cybersecurity assessment packages that are performed for TSA data/information systems are routed via the CISO for review and approval.
F. The Governance, Risk, and Compliance (GRC) Branch is responsible for:
(1) Ensuring that TSA is in compliance with FISMA mandate in support of the security of TSA information systems through development, implementation, and maintenance of the Security Authorization (SA) process, Ongoing Authorization (OA), Continuous Monitoring and CDM Program requirements in addition to the DHS Information Security Performance Plan;
(2) Ensuring and validating that TSA information systems comply with Federal mandates, DHS policies and directive, and NIST guidelines via collaboration efforts with System Owners and ISSOs;
(3) Overseeing and supporting management of cybersecurity risk which supports TSA by assessing and performing continuous monitoring to determine overall risk within the TSA systems infrastructure and environments; and
(4) Enhancing TSA's security posture by ensuring that Federal, DHS and TSA IT and information assurance (IA) security mandates, management directives, policies, technical standards, and procedures are accurate, accessible and communicated to TSA employees and coordinate with System Owners and ISSOs to provide Compliance support.
G. The Focused Operations (FO) Branch is responsible for:
(1) Providing the IAD with advanced analysis capabilities for the detection of cyber threats within the environment in order to ensure the confidentiality, integrity and availability of the data is maintained;
(2) Providing and implementing three distinct programs that manage and conduct advanced cyber threat detection and protection operations; these programs are the:
Cyber Threat, Advanced Network Operations and Advanced Data Discovery and Analysis;
(3) Providing programs that leverage the capabilities of other IAD programs including GRC, CSAO, SIVM, and CND creating an endless loop that results in protection from cyber threats; and
(4) Challenging the effectiveness of TSA’s compliance with Federal mandates including, but not limited to: FISMA, SA, OA and RMF by performing and implementing countermeasures to improve TSA’s stance against cyber threats.
H. The Computer Network Defense (CND) Branch is responsible for:
(1) Monitoring, detecting, and analyzing potential intrusions in real time;
(2) Responding to confirmed incidents by coordinating resources and directing use of timely and appropriate countermeasures;
(3) Serving as the 24x7 Incident Commander for all TSA-related incidents, spills and/or security events; requires leadership to support and report all incidents to the Security Operations Center (SOC) for review and resolution;
(4) Providing situational awareness and reporting on cybersecurity status, incidents, and trends;
(5) Protecting TSA sensitive data during classified, SSI, or PII spills; and
(6) Operations, maintenance and engineering for the Computer Network Defense System (CNDS) and data collection/analysis systems.
I. The Cybersecurity Awareness and Operational Support (CAOS) Branch is responsible for:
(1) Providing administrative, contractual, management, and procurement services to satisfy the operational and acquisition needs of the Information Assurance Division
(IAD);
(2) Supporting the execution of IAD’s budget and IAD’s software, hardware, and support service cost. Additionally, supporting the ad-hoc operational needs of the Chief Information Security Officer (CISO);
(3) Developing all IAD-related security awareness training, training content, communication, risk reduction and management, and outreach activities related to cybersecurity. CAOS also collaborates with several other TSA training partners to provide security related training; and
(4) Ensuring Operational Support (OS) provides Contract Officer Representative (COR) support for all of IAD contracts to ensure timely execution of contract deliverables, successful execution of contract resources and accurate management of contract funds.
J. The Secure Infrastructure and Vulnerability Management (SIVM) Branch is responsible for:
(1) Performing security testing and evaluation (ST&E) for TSA and non-TSA (contractor managed) systems to ensure vulnerabilities are remediated before systems goes live in the TSA enterprise;
(2) Providing TSA enterprise-wide security oversight, security engineering, infrastructure support, guidance, and reviews for the TSA IT environment;
(3) Ensuring all areas in the enterprise such as software, devices, networks, database, Microsoft and Linux/UNIX infrastructure, and web applications meet TSA requirements;
(4) Supporting large technology integration projects, enterprise-wide change control (SCCB), new enterprise-wide technology deployments, DHS PKI functions, and the evaluation of new and existing IT Security products to enhance TSA’s security posture; and
(5) Ensuring the proper tracking, COMSEC and custodial activities are taking place in accordance with National Security Agency (NSA) and DHS communication security policies.
K. The SO is responsible for:
(1) Planning, procuring, developing, integrating, modifying, operating, maintaining, continuously monitoring, retiring, and disposing of an information system;
(2) Ensuring that information security requirements are included very early-on in the acquisition and contracts process and considered throughout the lifecycle of the IT system prior to award to any prime, sub or third-party contracting firm;
(3) Supporting and aiding in the Security Authorization process and ensuring that IAD receives all requested information to obtain a system Authority to Operate;
(4) Enforcing and ensuring that non-GFE software, hardware, and/or applications are not installed on any TSA information systems by users since such actions are prohibited;
and
(5) Ensuring that security requirements identified in the System Owner Notification Appointment Letter are complied with in efforts to provide overall security, procurement, development, integration, modification, or operation and maintenance of an information system.
L. The ISSO is responsible for:
(1) Performing all specific tasking as defined in the DHS Information System Security Officer (ISSO) Guide and the TSA ISSO appointment letter;
(2) Maintaining the security posture of a specific information system in TSA, including POA&M management, security authorization responsibilities, providing training for information system users, and ensuring continuous monitoring in accordance with Federal security policies, directives, mandates, and laws;
(3) Complying with all IAD requirements to ensure system security implementation and adherence to all cybersecurity related requirements; and
(4) Reporting to the CISO via the appropriate IAD Branch Managers.
M. TSA offices that procure, acquire, develop, own, operate, conduct pilots, participate in bailment agreements, and/or replace information system components are responsible for:
(1) Participating in the formulation and approval of TSA IT security policies, information assurance, requirements, procedures, and IT security risk mitigation strategies prior to any contract award;
(2) Ensuring FISMA requirement security initiative is cost effective and technically efficient; and
(3) Ensuring information security requirements are addressed very early in the procurement effort and are properly budgeted as part of the overall acquisitions process prior to award. These requirements shall consider costs pertaining to the procurement, operations, maintenance, ongoing authorizations, monitoring, licensing, retirement and disposition of IT systems and/or products in accordance with applicable TSA and DHS policies.
N. All TSA employees, contractors, detailees, users of TSA information systems, and all others working on behalf of DHS are responsible for supporting and complying with IT security and information assurance program requirements stated herein.
O. The Contracting Officer (CO) is responsible for ensuring the use of information security, cybersecurity and information assurance verbiage is considered and incorporated into applicable contracts in accordance with the TSA IA HB and other relevant documents.
6. POLICY:
A. TSA employees, contractors and information systems covered under the scope of this directive shall uphold the security requirements in accordance with the TSA IA HB and all applicable DHS policies to ensure that all TSA information systems, high value assets (HVAs), general assets, applications, and information are completely secured.
B. TSA employees, contractor, and information systems covered under the scope of this directive shall support the secure development, approval, access, use, storage, maintenance, monitoring, retirement, and disposal of TSA information systems, information and networks, including prototypes and telecommunications systems.
C. The DHS Sensitive Systems Policy Directive 4300A shall take precedence in instances where there is conflict with TSA MD 1400.3 IT Security and its supporting TSA IA HB, unless otherwise indicated in TSA policy.
D. Each TSA office reporting to the Administrator shall obtain formal security authorization for its information systems from the appropriate AO in accordance with the TSA IA HB.
E. All TSA employees and contractors shall receive and complete annual information technology security awareness and privileged user training, when applicable.
F. All policy and supporting documentation established as a result of this directive shall be maintained on both the Management Policy and IAD’s TSA IA Policy iShare sites.
7. PROCEDURES:
Refer to the Management Policy and TSA IA Policy iShare sites to access establishment and maintenance procedures as outlined by the TSA IA HB, technical standards, standard operating procedures, the Online Learning Center (OLC), and additional publications that provide the foundation to ensure confidentiality, integrity, availability and non-repudiation within the TSA IT enterprise, IT infrastructure, and operations.
8. APPROVAL AND EFFECTIVE DATE:
This policy is approved and effective the date of signature unless otherwise specified.
APPROVAL
Signed January 31, 2022 Russell Roberts Date Assistant Administrator Chief Information Officer for Information Technology
EFFECTIVE
Date
Distribution: All TSA employees and contract personnel Point-of-Contact: IT, Information Assurance and Cybersecurity Division (IAD)
TSAIADPolicy@tsa.dhs.gov https://office.ishare.tsa.dhs.gov/sites/oit/bmo/pages/ManagementPolicy.aspx https://office.ishare.tsa.dhs.gov/sites/ITSEC/CP/PC/policy/default.aspx https://office.ishare.tsa.dhs.gov/sites/ITSEC/CP/PC/policy/Internal%20Shared%20Documents/Projects/TSA%20IA%20HB%20v14.1%20Final.pdf mailto:TSAIADPolicy@tsa.dhs.gov
TRANSPORTATION SECURITY ADMINISTRATION
INFORMATION ASSURANCE AND CYBERSECURITY DIVISION
TSA Information Assurance Handbook
Attachment 1 to TSA MD 1400.3 IT Security
Date Signed: 12/27/2019
Version 14.1
Records Disposition Schedule (RDS)
Policy Records Code and Item #: 2000.4.1 Cut off at end of calendar year in which superseded or obsolete.
Transfer to NARA 10 years after cut off [ Authority N1-560-04-10, Item 5b ] https://ishare.tsa.dhs.gov/Offices/OIT/Documents/TSA%20MD%201400.3,%20FINAL,%20140408.pdf https://ishare.tsa.dhs.gov/PoliciesAndForms/recmgt/Pages/Records%20Disposition%20Schedules/2000-OperationsPolicy.aspx https://ishare.tsa.dhs.gov/PoliciesAndForms/recmgt/Pages/Records%20Disposition%20Schedules/2000-OperationsPolicy.aspx https://ishare.tsa.dhs.gov/PoliciesAndForms/recmgt/Pages/Records%20Disposition%20Schedules/2000-OperationsPolicy.aspx https://ishare.tsa.dhs.gov/PoliciesAndForms/recmgt/Pages/Records%20Disposition%20Schedules/2000-OperationsPolicy.aspx
INFORMATION ASSURANCE HANDBOOK
This Page Intentionally Left Blank
Table of Contents TSA Information Assurance Handbook
Table of Contents
1. Purpose
2. Scope
3. Policy
4. Roles and Responsibilities
5. Definitions
6. Abbreviations
7. Acknowledgements
8. Authorities
9. Document Change History
10. Document Control Information
11. Effective Date and Implementation
12. Appendix A - References (Federal Information Assurance (IA) Policy Mandate -- Top- Down Alignment Diagram, Detailed Authorities and SOPs):
List of Relevant Mandates and Links
List of Relevant SOPs and Applicable Security Controls
1. Purpose This handbook implements the policies and requirements of the Transportation Security Administration (TSA) Management Directive (MD) 1400.3, Information Technology Security by establishing guidance applicable to the use, development, and maintenance of TSA Information Technology (IT) assets, networks, and systems. The guidance contained herein is designed to ensure the Confidentiality, Integrity, Availability, and overall assurance of TSA information. This handbook is supplemented by published extension documents, TSA Technical Standards (TSs), and Standard Operating Procedures (SOPs). The IA HB, TSs, SOPs and other relevant documents are published in the IA Policy Outreach page. This document is used to identify responsibilities by educating and increasing awareness of TSA information assurance (IA) policy. An accountability matrix containing roles and responsibilities of key personnel mentioned in this Handbook can be found in an Information Assurance (IA) Roles and Responsibilities spreadsheet located in our IA Policy Outreach site. References to the specific areas and authorities to enable successful execution of tasks and job requirements are identified herein. Appendix A (References) located in the back of this Handbook contains a Figure 1 diagram, which illustrates a top-down approval and alignment order as derived IAW federal policy mandates.
2. Scope The policies within this handbook apply to all TSA employees, contractors, vendors, detailees, others working on behalf of TSA, and to non-TSA individuals authorized to access TSA information systems, software and/or applications. It also applies to all TSA information systems, software and/or applications that collect, generate, process, store, display, transmit, or receive TSA data, including prototypes and telecommunications systems, in all phases of the Systems Engineering Life Cycle (SELC) unless an approved waiver has been granted using the proper waiver form. The above assets shall be collectively referred to as "IT assets" throughout the document. As required by the Department of Homeland Security (DHS), the Federal Chief Information Officer (CIO) and Office of Management and Budget (OMB) guidance, program and project managers shall be provided with guidance to support the implementation of Agile Information Technology (IT) Development.
Requirements shall reference the DHS “Carwash” User Guide, the DHS Directive System Instruction Number 102-01-004: Agile Development and Delivery for Information Technology and the DHS Agile Center of Excellence - Tools. These guides enhance understanding as to why Agile is a preferred approach to federal IT development, how it provides a starting point for increasing DHS-wide application of Agile methodologies, and helps managers and other key stakeholders identify options for tailoring the SELC for Agile. The private sector uses Agile as an effective and efficient method to deliver software faster, better, and cheaper compared to other methods. Important note for System Owners (SOs) and Information Systems Security Officers (ISSOs) – In the context of this IA Handbook, the term “System” is synonymous with “Application” and “Software”, and the expectation for adherence is the same.
The structure of this document is based on the controls contained in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 Revision 4, Security and Privacy Controls for Federal Information Systems and Organizations. Information on privacy controls and related privacy overlays can be found here. Furthermore, the controls identified are mapped to Federal Information Processing Standards (FIPS) Publication 199, Standards for Security Categorization of https://office.ishare.tsa.dhs.gov/sites/ITSEC/CP/PC/policy/Internal%20Shared%20Documents/Projects/Privacy_Overlay_Final_Approved.pdf
Federal Information and Information Systems, which establishes the foundation for categorizing systems based on three security objectives: Confidentiality, Integrity, and Availability (C, I, A).
These publications, and other relevant NIST guidance, are available online at http://csrc.nist.gov/.
Security objectives are assigned a potential impact level, also known as “impact level” throughout this handbook, of Low, Moderate, or High. Within the tables of requirements in this document, the applicability of each control statement is provided in the “Category” column with the following abbreviations: Low (L), Moderate (M), High (H), Privacy System (P), or Chief Financial Officer (CFO) Designated Financial System (F).
Definitions for terms are located in Section 5 Definitions. For definitions not identified, the NIST Glossary of Key Information Security Terms shall be used as a baseline for reference.
The DHS Sensitive Systems Policy Directive 4300A, and its supporting Handbook, shall take precedence in instances where there is conflict with TSA MD 1400.3 ITS and this supporting handbook, unless otherwise identified in TSA policy.
The DHS Trusted Internet Connection (TIC) infrastructure initiative (see OMB M-08-05) was originally introduced to optimize and standardize the security of individual external network connections (extranet services) used by TSA and other agencies. More recently, new TIC policy was introduced, see OMB M-19-26 Update to the Trusted Internet Connections (TIC) Initiative, to enhance an approach for implementing this new TIC initiative to further provide agencies with increased flexibility to use modern security capabilities. It also establishes a process for ensuring the TIC initiative is agile and responsive to advancements in technology and rapidly evolving threats.
Regarding vulnerabilities, weaknesses and mitigations, and based on directions from the DHS USM Memo titled “Strengthening DHS Cyber Defenses” (July 22, 2015), a unique type of high impact level category classified as “Critical” are used under certain circumstances and in response to escalation in cyber related attacks. This Critical impact is also supported by the DHS Binding Operational Directive (BOD) 19-02 or BOD 19-02: “Vulnerability Remediation Requirements for Internet-Accessible Systems”, which is only applicable to internet-accessible systems in the Federal agencies.. In these special cases, Critical vulnerabilities must be remediated within 15 calendar days of initial detection and High vulnerabilities must be remediated within 30 calendar days of initial detection.
The CISO has the flexibility and the resources to work with DHS with the presumption that TSA has the full and complete trust in DHS from an architectural perspective to serve as the provider and management of TSA’s current Semi-Trusted zone. Additional details may be found in the TSA TIC Migration Plan of Action and Milestones Agreement and Approval document, dated August 31, 2011, under VPN Service (p. 7) in that, “DHS OneNet network infrastructure is a Department managed service to the DHS Component and should be considered trusted.”
In cases where current TSA policy is conflicting, the policy identified in this Handbook shall take precedence. The TSA Chief Information Security Officer (CISO) shall make the final arbitration decision in the case of any conflicting guidance in policy documents. In addition, in cases where this http://csrc.nist.gov/ http://nvlpubs.nist.gov/nistpubs/ir/2013/NIST.IR.7298r2.pdf http://nvlpubs.nist.gov/nistpubs/ir/2013/NIST.IR.7298r2.pdf https://www.whitehouse.gov/omb/information-for-agencies/memoranda/ https://www.whitehouse.gov/wp-content/uploads/2019/09/M-19-26.pdf https://office.ishare.tsa.dhs.gov/sites/ITSEC/CP/PC/policy/Internal%20Shared%20Documents/Projects/DHS%20Memos/DHS%20Memo%20Strengthening%20DHS%20Cyber%20Defenses.pdf https://office.ishare.tsa.dhs.gov/sites/ITSEC/CP/PC/policy/Internal%20Shared%20Documents/Projects/DHS%20Memos/DHS%20Memo%20Strengthening%20DHS%20Cyber%20Defenses.pdf https://office.ishare.tsa.dhs.gov/sites/ITSEC/CP/PC/policy/Internal%20Shared%20Documents/Projects/CISA%20BOD%2019-02%20-%20Vuln%20Remediation%20Requirements%20-%2029APR19.pdf https://office.ishare.tsa.dhs.gov/sites/ITSEC/CP/PC/policy/Internal%20Shared%20Documents/Projects/CISA%20BOD%2019-02%20-%20Vuln%20Remediation%20Requirements%20-%2029APR19.pdf handbook conflicts with SSI Program Office or Privacy Office policy and procedures, the appropriate SSI and Privacy office’s guidance shall take precedence.
3. Policy
3.1 Access Control (AC)
The implementation of proper access control is a critical element of the information assurance (IA) solution. TSA and DHS-trusted IT related assets provide an environment that allows active network use by authorized individuals in the performance of their assigned tasks, while also ensuring appropriate measures are in place to maintain the integrity of network information through limited and controlled access. This control supports the logical access control measures of TSA and DHS-trusted IT assets, and is applicable to all TSA IT assets whenever a claim of identity is made. Where applicable, specific detailed guidance of the cybersecurity requirements on access control is contained in several TSs including: TS-001 Passwords/PINs, TS-002 Encryption, TS-003 Wi-Fi, TS- 008 End User Assets, TS-010 Network Interconnections, TS-012 Port Security, TS-015 Network Logical Access Control, TS-016 Remote Access and TS-049 Information Systems Logging.
Other guidance: OMB Memorandum 04-04, 08-05, and 08-27; FIPS Publications 140-2, 199, and 201; NIST Special Publications 800-12, 800-16, 800-46, 800-63, 800-73, 800-77, 800-78, 800-98, 800-94, 800-100, 800-113, 800-114, 800-121, and 800-124.
3.1.1 Access Control Policy and Procedures (AC-1)
Policy ID Policy Statements DHS
4300A
NIST
SP
800-53 Category
1.1.1 The CISO shall develop, disseminate, and annually
review/update a formal, documented access control policy that addresses purpose, scope, roles, responsibilities, management commitment, and coordination among TSA and DHS trusted entities. The CISO shall also ensure documented procedures are established at the system level and each system needs to develop their own procedures in order to facilitate the implementation of access control policies and associated controls that provide protection from unauthorized alteration, loss, unavailability, or disclosure of information.
5.2.a 5.4.3.a
AC-1 LMH
F
1.1.2 The System Owner (SO) shall be responsible for the
management of access controls for IT assets for the information system, including oversight and agreements as needed for IT assets outside of direct control by TSA personnel.
5.2.a 5.4.3.a
AC-1
AC-2
LMH
1.1.3 For the purpose of maintenance, a cleared and authorized vendor/ individual shall sign-in, provide credentials, and be escorted for access to a designated area for the purpose of maintaining TSA or DHS equipment; an authorized federal manager or designee with knowledge of the maintenance task shall be present to escort and monitor the individual at all times.
1.4.25 4.8.3.h 5.2.a
5.4.3.a
1.1.4 Reserved
1.1.5 All privileged access control shall be in compliance with the TSA policy.
5.2.a
5.4.3.a
AC-1 LMH
F
1.1.6 In the very rare instance where emergency access is
needed to an account by an authorized individual other than the account owner, this shall be strictly controlled and approved by the CISO, Deputy CISO, or other designee prior to being granted. This type of access is normally on a temporary basis and whose time frame is determined by the authorized individual or designee.
5.2.a 5.2.d
5.4.3.a
AC-1
AC-2
1.1.7 The ISSO shall provide on-going supervision and review
of the actions of personnel who enforce access controls and those who are subject to this enforcement.
5.2.a 5.4.3.a
1.1.8 The ISSO shall ensure the SOC routinely reviews activity logs for signs of inappropriate actions and response action shall be taken as required.
5.2.a 5.4.3.a
1.1.9 Changes to user access rights shall be regularly reviewed by the user’s supervisor independent of the cybersecurity function.
5.2.a 5.4.3.a
1.1.10 The user’s supervisor shall notify the system ISSO of any abnormal activity and support investigation activities upon request.
5.2.a 5.4.3.a
3.1.2 Account Management (AC-2)
General user accounts are established by the TSA after the completion of the TSA Form 1403, Computer and Wireless Mobile Device Access Agreement (CAA), available via the Online Learning Center (OLC). The data and applications available to the specific user are defined by an evaluation of that user’s needs to perform his or her duties. A properly completed TSA Form 1403 is used to identify the user and the user’s privileges, in order to create a profile. Account management is a critical element in the defense-in-depth approach and provides protection from unauthorized system access. All data, applications, and IT assets of the TSA network are accessed through defined accounts. The establishment of these accounts is rigorously controlled throughout the life cycle.
Policy ID Policy Statements DHS
4300A
NIST
SP
800-53 Category
1.2.1 The SO shall be responsible for management and oversight of all accounts used to access the information system.
5.2 4.1.3.a
AC-2 LMH
F
1.2.2 The ISSO shall support the SO in account management by:
a. Identifying account types (to include individual, group, system, application, service, guest/anonymous, and temporary); see TS-033 Application/Service Accounts for additional information and guidance;
b. Establishing conditions for group membership;
c. Enacting processes to identify authorized users of the information system and specify access privileges;
d. Requiring appropriate approvals for requests to establish accounts;
e. Enacting processes to establish, activate, modify, disable, and remove accounts;
f. Enacting processes to specifically authorize and monitor the use of guest/anonymous or temporary accounts;
g. Notifying account managers when temporary accounts are no longer required and when information system users are terminated, transferred, or have their information system usage or need to know/need to share status change;
h. Enacting processes to deactivate temporary accounts that are no longer required and the accounts of terminated or transferred users;
i. Enacting processes to grant access to the system based on a valid access authorization, intended system usage, and other attributes as required by the TSA or associated missions’/business functions;
j. Ensuring/confirming the use of unique group access and group passwords, which shall be approved by the appropriate AO, is very limited to situations dictated by operational necessity or criticality for mission accomplishment. Shared and group accounts are prohibited for all systems categorized as High Value Assets (HVAs); and
k. Enacting processes to review accounts on an annual basis.
5.2 4.1.6.d 5.1.1.e
AC-2 LMH
ID Policy Statements DHS
4300A
NIST
SP
800-53 Category
1.2.3 The ISSO shall ensure that access control implementations follow the principles of least privilege and separation of duties and shall require users to use unique identifiers.
Privileged users shall have separate accounts from their general user accounts in order to perform privileged access. Privileged users are authorized and therefore, trusted to perform security-relevant functions that general users are not authorized to perform.
4.1.4.c 5.2.b
AC-2 LMH
F
1.2.4 Social Security Numbers (SSN) shall not be part of any:
authentication process, identifier, or as an authenticator.
Click on DHS Privacy Policy Guidance Memorandum PD 140-11, Use of Social Security Numbers at the Department of Homeland Security by the Chief Privacy Officer (CPO) for additional information on not collecting or using an SSN as a unique identifier but rather creating a unique identifier to identify or link information concerning an individual.
5.2.b AC-2 LMH F
1.2.5 The Authorizing Official (AO) or the CISO shall review, delegate and approve in writing an individual requiring administrator privileges. This individual may be an appropriate SO, IAD SME or Program Manager.
2.1.6.d
AC-2 LMH
1.2.6 Reserved 5.2.d AC-2 LMHF
1.2.7 Systems that are part of the Critical DHS Assets Program shall have provisions to allow the CISO to approve new user accounts as part of a Continuity of Operations (COOP) scenario.
3.5 AC-2 LMH
F
1.2.8 The SOs shall propose, and AOs shall approve, separation of duties and responsibilities for critical information system functions among different individuals to minimize the possibility of any one individual having the necessary authority or system access to be able to engage in fraudulent or criminal activity.
4.1.4.a AC-2
AC-5
LMH
F
1.2.9 Reserved
1.2.10 The SO shall implement procedures to ensure system
access is suspended for personnel on extended absences for the duration of the absence.
4.1.6.c AC-2
IA-4
LMH
F https://www.dhs.gov/sites/default/files/publications/privacy-policy-guidance-memorandum-2007-02.pdf https://www.dhs.gov/sites/default/files/publications/privacy-policy-guidance-memorandum-2007-02.pdf https://www.dhs.gov/sites/default/files/publications/privacy-policy-guidance-memorandum-2007-02.pdf
ID Policy…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .