HHS Information Security and Privacy Policy - 2014 Edition.pdf
PDF 2 MB Posted
- Attached to
- Health Center Loan Guarantee Program Support Federal contract opportunity
- Solicitation number
- 75R60220Q00040
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 75R60220Q00040-0001.pdf | ||
| HRSA Information Security Policy.pdf | ||
| Amendment 1 75R60220Q00040.pdf | ||
| Questions and Answers - RFQ 75R60220Q00040 - Health Center Loan Guarantee Program Support 2.14.2020.pdf | ||
| SOW Attachment B LGP BPA Call Order Form 01282020.xlsx | XLSX spreadsheet | |
| Attachment B Technical Evaluation Criteria.pdf | ||
| RFQ LGP 75R60220Q00040.pdf | ||
| Attachment D LGP Labor Category-loading Matrix.xlsx | XLSX spreadsheet | |
| Attachment E Past Performance Questionnaire.pdf | ||
| SOW Attachment A LGP BPA Price Catalog 01282020.pdf | ||
| Attachment C LGP Call Order 1 - 01282020.xlsx | XLSX spreadsheet | |
| SOW Attachment C Contractor Non-Disclosure Agreement 01282020.pdf | ||
| Attachment A SOW LGP 01282020 (002).pdf |
Show all 13
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Office of the Chief Information Officer Office of the Assistant Secretary for Administration
Department of Health and Human Services
HHS Information Systems Security and Privacy Policy
July 30, 2014
Project: HHS OCIO Policy Document Number: HHS-OCIO-2014-0001
Table of Contents
Table of Contents
1. Purpose
2. Background
3. Scope
4. Policy
4.1. Department-Mandated Controls
4.2. OpDiv/StaffDiv Controls
5. Information and Assistance
6. Effective Date/Implementation
7. Approved
Appendix A: Roles and Responsibilities
Appendix B: Security Control Section
Access Control (AC)
Awareness and Training (AT)
Audit and Accountability (AU)
Security Assessment and Authorization (CA)
Configurat ion Management (CM)
Contingency Planning (CP)
Identificat ion and Authentication (IA)
Incident Response (IR)
Maintenance (MA)
Media Protection (MP)
Physical and Environmental Protection (PE)
Planning (PL)
Program Management (PM)
Personnel Security (PS)
Risk Assessment (RA)
Systems and Services Acquisition (SA)
Systems and Communication Protection (SC)
System and Informat ion Integrity (SI)
Appendix C: Privacy Control Sect ion
Authority and Purpose (AP)
Accountability, Audit, and Risk Management (AR)
Data Quality and Integrity (DI)
Data Minimizat ion and Retention (DM)
Individual Participation and Redress (IP)
Security (SE)
Transparency (TR)
Use Limitation (UL)
Appendix D: Glossary
Appendix E: Acronyms
Appendix F: Authorities
1. Federal Directives and Policies
2. Statutes
3. HHS Policy
4. OMB Policy and Memoranda
5. NIST Guidance
Appendix G: Min imum Set of HHS Roles Assigned Significant Responsibilit ies for Informat ion Security
Appendix H: System Component Inventory Requirements
Appendix I: Informat ion System Media
Information Systems Security and Privacy Policy
1. Purpose
The Department of Health and Human Services (HHS), Office of the Chief Information Officer (OCIO), HHS-OCIO Information Systems Security and Privacy Policy (henceforth “the Policy”) provides direction to the information technology (IT) security programs of Operating Divisions (OpDivs) and Staff Divisions (StaffDivs) for the security and privacy of HHS data in accordance with the Federal Information Security Management Act of 2002
(FISMA).
The Policy is a reissuance in order to comply with the updated requirements of the National Institute of Standards and Technology’s (NIST) Special Publication (SP) 800-53, Revision 4, as amended. This Policy establishes comprehensive IT security and privacy requirements for the IT security programs and information systems of OpDivs and StaffDivs. For the controls that are to be applied without needing any specific OpDiv parameters, this Policy will be the authoritative source. OpDivs do not have to develop internal policies to supplement the stated requirements. The Policy also includes the complementary HHS- OCIO Information Systems Security and Privacy Policy Control Section (henceforth the “Control Section”), which replaces the previous Information Security and Privacy Policy Handbook. The Control Section outlines IT security and privacy policy requirements for IT security and privacy programs and information systems in more detail, and is organized according to information assurance (IA) control families (as defined by NIST SP 800-53) to make the document easy to use and scalable for the future.
This Policy supersedes the HHS-OCIO-2011-0003, Policy for Information Systems Security and Privacy, dated July 7, 2011, and incorporates retired policies HHS-OCIO-2009-0003, Policy for Information Systems Security and Privacy, HHS-OCIO-2007-0002.001, Policy for Department-wide Information Security. This document does not supersede any other applicable law or higher level agency directive, policy, or guidance. All references noted below are subject to periodic revision, update, and reissuance.
The Policy codifies the Department’s authority to develop, document, implement, and oversee a Department-wide IT security and privacy program to provide IT security and privacy for the information and information systems that support the operations and assets of the Department, including those provided or managed by another Federal agency, contractor, or other source. OpDivs and StaffDivs must comply with and support the implementation of a Department-wide IT security and privacy program, to include compliance with Federal requirements and programmatic policies, standards, procedures, and IT security controls.
2. Background
The HHS Cybersecurity Program (henceforth “the Program”) has evolved and matured over the last several years as new Federal requirements have been published, as advances in technology have been made, and as new threats to the Department’s infrastructure have emerged. Additionally, concerns over the unauthorized disclosure of protected health information (PHI) and personally identifiable information (PII) have placed IT security and privacy issues at the forefront of the national dialogue, positively impacting the way in which public, private, and government organizations provide services and protect information.
To better serve IT security and privacy stakeholders, the Department recognized the need to appropriately incorporate, cross-reference, and organize its IT security and privacy policy requirements in a manner that clearly explains the scope and applicability of the requirements. The format in which those requirements are presented should be scalable to accommodate the modification or addition of new requirements over time. As a result, this Policy was developed to incorporate privacy requirements as well as other requirements cross-referenced in individually-released Department policies, standards, and memoranda.
3. Scope
This Policy applies to all HHS organizational components (OpDivs and StaffDivs), and all personnel conducting business for, and on behalf of, the Department, whether directly or through contractual relationships. This Policy does not supersede any other applicable law, higher level agency directive, or existing labor management agreement in place as of the effective date of this Policy.
Department officials must apply this Policy to employees, contractor personnel, interns and other non-government employees conducting business for the Department, or on its behalf through contractual relationships or memoranda of agreement, when using HHS information systems or resources. All organizations collecting or maintaining information, or using or operating information systems on behalf of the Department, are also subject to the stipulations of this Policy. The content of and compliance with this Policy must be incorporated into applicable contract language, as appropriate.
Agencies shall use this Policy or may create a more restrictive OpDiv/StaffDiv policy which is in no way less restrictive, less comprehensive, or less compliant with, this Policy.
The Policy does not apply to any network or system that processes, stores, or transmits foreign intelligence or national security information under the cognizance of the Special Assistant to the Secretary (National Security) pursuant to Executive Order (E.O.) 12333, United States Intelligence Activities, or subsequent orders. The Special Assistant to the Secretary (National Security) is the point of contact (POC) for issuing IT security and privacy policy and guidance for these systems. Questions about the Health Information Technology Economic and Clinical Health (HITECH) Act or the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule and the HIPAA Privacy Rule should be directed to the HHS Office for Civil Rights (OCR).
The Department acknowledges that OpDivs/StaffDivs require flexibility in implementing this Policy. Variations in terminology may currently exist across the OpDivs/StaffDivs, and there may be variations in the titles of roles. These variations are acceptable.
For cases in which an OpDiv/StaffDiv cannot comply with these requirements, justification for noncompliance must be documented using the Department Information Security Policy/Standard Waiver.
Justification may also be documented in security artifacts, such as security plans drafted pursuant to the NIST SP 800-37, which are subject to approval by the Authorizing Official (AO) (formerly known as the Designated Approving Authority) or Authorizing Official Designated Representative as part of an OpDiv/StaffDiv security authorization process.
4. Policy
4.1. Department-Mandated Controls
This section addresses mandates for the secure development, operations, and maintenance of information systems.
4.1.1 OpDivs/StaffDivs must use NIST SP 800-37, Guide for Applying the Risk
Management Framework to Federal Information Systems: A Security Life Cycle Approach, as the methodology for the security assessment and authorization (SA&A) of information systems (formerly known as “certification and accreditation” or “C&A”), in accordance with FISMA and direction from the Office of Management and Budget (OMB).
4.1.2 OpDivs/StaffDivs must ensure that information systems provide adequate, risk-based protection in the control areas defined in the Federal Information Processing Standard (FIPS) 200, Minimum Security Requirements for Federal Information and Information Systems, by using the appropriate baseline security controls as established in NIST SP 800-53, Recommended Security Controls for Federal Information Systems, in accordance with the impact level for the system as defined in FIPS 199, Standards for Security Categorization of Federal Information and Information Systems.
4.1.2.1 For instances in which NIST directs agencies to make assignments and selections within the confines of NIST SP 800-53 controls, the Program created standard parameters which OpDivs/StaffDivs must utilize for systems categorized as Low, Moderate, or High. The term “the organization” is used throughout these controls to make clear that, unless a component is specifically mentioned, these are a baseline regardless of organizational component or system, and may be enhanced as necessary based on that component’s mission.
4.1.2.2 Deviations from the HHS assignments and selections within the Control Section are permitted, providing the resulting parameters are consistent with NIST SP 800-53 or minimum government-wide parameters.
Exceptions cannot be granted to the controls themselves as they are Federal Government-wide standards; however, the compensating security control policy applies (see Section 4.1.6).
4.1.2.3 OpDivs/StaffDivs may exercise flexibility in the solutions used to meet the control requirement, so long as the baseline requirement is met.
4.1.3 Information assurance and privacy activities conducted within the Department must be consistent with the guidance, methodologies, and intent prescribed by the NIST SP series, in particular NIST SP 800-53, and other relevant Federal laws and guidance documents. It is incumbent upon each OpDiv to appropriately follow the steps in the NIST SP 800-37 Risk Management Framework (RMF) to select, implement, assess, authorize, and monitor such controls commensurate with a system’s FIPS 199 categorization.
4.1.4 As new Federal requirements are published, OpDivs/StaffDivs must ensure that systems that are in development comply with those newly published requirements before those systems are granted a security authorization, and that existing (i.e., operational) systems comply with the new requirements within one year.
4.1.4.1 If any issues are identified that would prevent the implementation of a new Federal requirement on a development system, the Information System Security Officer (ISSO) or System Owner must bring this issue to the attention of the AO or Authorizing Official Designated Representative as soon as the issue is identified so that a plan can be developed to implement or mitigate the requirement, or the risk can be accepted. When the final security authorization package is delivered, and it has been agreed that the requirement would not be implemented, the AO or Authorizing Official Designated Representative must acknowledge the gap in the form of a Plan of Action and Milestones (POA&M), and must indicate an anticipated time period when the requirement will be met or explicitly accept the risk to organizational operations and assets, individuals, other organizations, and the Nation based on the implementation of an agreed-upon set of security controls.
4.1.4.2 If a new Federal requirement cannot be implemented on an operational system, the ISSO or System Owner must bring this to the attention of the AO or Authorizing Official Designated Representative. The AO or Authorizing Official Designated Representative must acknowledge the gap in the form of a Plan of Action and Milestones (POA&M), and must either indicate an anticipated time period when the requirement will be met or document the risk-based decision not to comply with the requirement.
4.1.5 OpDivs/StaffDivs may employ compensating security controls only after the following conditions are met:
4.1.5.1 The OpDiv/StaffDiv selects the compensating security control(s) from the security control catalog in NIST SP 800-53, when applicable;
4.1.5.2 The OpDiv/StaffDiv develops a complete and convincing rationale and justification for how the chosen compensating security control(s) provide an equivalent security capability or level of protection for the information system; and
4.1.5.3 The OpDiv/StaffDiv assesses and formally accepts (i.e., in writing) the risk associated with employing the compensating security control(s) in the information system.
4.1.6 OpDivs/StaffDivs must review the use of compensating security controls, document those controls in the security plan and other appropriate security documentation for the information system, and request approval of those controls from the AO or Authorizing Official Designated Representative for the information system.
4.1.7 OpDivs/StaffDivs must apply the controls in the updated Control Section to their IT security and privacy programs and to their information systems as appropriate.
The Program changed the IS2P and accompanying Handbook by integrating the HHS minimum requirements into a copy of Revision 4, establishing the HHS minimum requirements for IT security and privacy programs within the OpDivs/StaffDivs and to address common system security control questions that fall outside the scope of NIST SP 800-53.
4.2. OpDiv/StaffDiv Controls
This section establishes the authority of the OpDivs/StaffDivs to develop their own security controls for information systems.
4.2.1 OpDivs/StaffDivs may decide whether to issue any additional OpDiv/StaffDiv-wide security controls for OpDiv/StaffDiv information systems to augment the government and Department-wide controls specified herein. OpDivs/StaffDivs must ensure that parameters are established and documented for each parameterized control, unless set by the Department.
4.2.2 OpDivs/StaffDivs may develop system-specific security controls and parameters.
When needed and/or appropriate, it is an OpDiv/StaffDiv decision whether to set parameters OpDiv/StaffDiv-wide, on a system-by-system basis, or some combination thereof.
5. Information and Assistance
HHS OCIO policies and standards are posted on the following website:
http://www.hhs.gov/ocio/policy/index.html.
Direct any questions, comments, suggestions, or requests for further information to the HHS Cybersecurity Program at HHS.Cybersecurity@hhs.gov or (202) 205-9581.
http://www.hhs.gov/ocio/policy/index.html mailto:HHS.Cybersecurity@hhs.gov
6. Effective Date/Implementation
The effective date of this Policy is the date the Policy is approved.
These policies and procedures will not be implemented in any recognized bargaining unit until the union has been provided notice of the proposed changes and given an opportunity to fully exercise its representational rights.
The HHS policies contained in this issuance must be exercised in accordance with Public Law 93-638, the Indian Self-Determination and Education Assistance Act, as amended, and the Secretary’s policy statement dated December 14, 2010, as amended, titled U. S.
Department of Health and Human Services Tribal Consultation Policy. It is HHS policy to consult with Indian people to the greatest practicable extent and to the extent permitted by law before taking actions that affect these governments and people; to assess the impact of the Department’s plans, projects, programs, and activities on tribal and other available resources; and to remove any procedural impediments to working directly with tribal governments or Indian people.
7. Approved
/s/ July 30, 2014 Frank Baitman DATE HHS Chief Information Officer
Appendix A: Roles and Responsibilities
1. Secretary of HHS
2. OpDiv Heads
3. Office of Finance (OF)/Assistant Secretary for Financial Resources (ASFR)/Chief
Financial Officer (CFO)
4. ASFR/Office of Grants and Acquisition Policy and Accountability (OGAPA)/Division of
Acquisition (DA)
5. Office of Security and Strategic Information (OSSI)
6. ASA/Deputy Assistant Secretary for Human Resources (DASHR)
7. ASA/Deputy Assistant Secretary for Information Technology (DASIT)/HHS Chief
Information Officer (CIO)
8. HHS Senior Agency Official for Privacy (SAOP)
9. Office of Information Security (OIS)/HHS Chief Information Security Officer (CISO)
10. OpDiv CIOs
11. OpDiv CISOs
12. HHS Computer Security Incident Response Center (CSIRC)
13. OpDiv Computer Security Incident Response Team (CSIRT)
14. HHS Privacy Incident Response Team (PIRT)
15. OpDiv Senior Official for Privacy (SOP)
16. OpDiv Privacy Act Contact
17. Authorizing Official (AO) or Authorizing Official Designated Representative
18. Security Control Assessor
19. Information System Security Officer (ISSO)
20. Program Executive
21. System Owner
22. Data Owner/Business Owner
23. Website Owner/Administrator
24. Contingency Planning Coordinator
25. System Developer and Maintainer
26. System/Network Administrator
27. Contracting Officers and Contracting Officer’s Representative
28. Project/Program Manager
29. Human Resource Officer
30. Supervisor
31. All Users
32. HHS Records Officer
33. HHS Privacy Act Officer
1. Secretary of HHS
The responsibilities of the Secretary of HHS include, but are not limited to:
1.1 Ensuring that a Department-wide IT security and privacy program is developed, documented, and implemented to provide security for all systems, networks, and data that support Department operations;
1.2 Ensuring that IT security and privacy management processes are integrated with HHS strategic and operational planning processes;
1.3 Ensuring the provision of resources necessary to administer the Program;
1.4 Protecting information systems and data by allocating resources commensurate with the risk and magnitude of harm posed by unauthorized access, modification, disclosure, disruption, use, and/or destruction; or as recommended by law;
1.5 Ensuring that senior HHS officials provide IT security and privacy for operations and IT resources under their control;
1.5.1 Delegating to the HHS CIO the authority to ensure compliance with the
Program;
1.5.2 Ensuring that HHS has trained Federal and contractor personnel to support compliance with the Program; and
1.5.3 Ensuring that the HHS CIO, in coordination with the OpDiv CIOs, reports annually on the effectiveness of the Program and on any required remedial actions.
1.6 Establishing, through the development and implementation of policies, the organizational commitment to information security and privacy, and the actions required to effectively manage risk and protect the core missions and business functions being carried out by the organization; and
1.7 Establishing appropriate accountability for information security and privacy, and providing active support and oversight of monitoring and improvement for the information security and privacy program.
2. OpDiv Heads
The responsibilities of each OpDiv Head include, but are not limited to:
2.1 Providing IT security and privacy protections commensurate with the risk and magnitude of harm resulting from unauthorized access, use, disclosure, disruption, modification, or destruction of the following:
2.1.1 Information collected or maintained by or on behalf of the OpDiv; and
2.1.2 Information systems used or operated by the OpDiv, a contractor of the
OpDiv, or another organization on behalf of the OpDiv.
2.2 Complying with the requirements of FISMA (Title III of the E-Government Act) and Department-related policies, procedures, standards, and guidelines, including:
2.2.1 IT security and privacy requirements promulgated under OMB Circular A-130, Appendix III; and
2.2.2 IT security and privacy standards and guidelines issued by OMB in accordance with NIST guidance, including Presidential Directives such as Homeland Security Presidential Directive 12 (HSPD-12), Policy for a Common Identification Standards for Federal Employees and Contractors.
2.3 Ensuring that IT security and privacy management processes are integrated with
OpDiv strategic and operational planning processes;
2.4 Ensuring that senior OpDiv officials provide IT security and privacy for the information and information systems that support the operations and assets under their control;
2.5 Designating a senior OpDiv official as the OpDiv CIO, and delegating to the
OpDiv CIO the authority to ensure compliance with the security requirements imposed on the OpDiv under FISMA;
2.6 Delegating responsibility and authority for management of OpDiv IT security and privacy programs to the OpDiv CIOs;
2.7 Ensuring that the OpDiv has trained personnel sufficiently to assist the OpDiv in complying with the security and privacy requirements under FISMA and Department policies; and
2.8 Ensuring that the OpDiv CIO, in coordination with other senior OpDiv officials, reports annually to the OpDiv Head on the effectiveness of the OpDiv IT security and privacy program, including the progress of any remedial actions.
3. OF/ASFR/CFO
The responsibilities of the OF/ASFR/CFO include, but are not limited to:
3.1 Coordinating the Department’s internal controls program to ensure comprehensiveness and to establish responsibility for uniform security level designations for the financial management system according to the guidelines of OMB Circular A-127, Financial Management Systems; and
3.2 Targeting/selecting entities to be reviewed per OMB Circular A-123, Management's Responsibility for Internal Control, applying risk-based, business-driven logic to maximize the effectiveness of the evaluations.
4. ASFR/OGAPA/DA
The responsibilities of the ASFR/OGAPA/DA include, but are not limited to:
4.1 Partnering with the HHS CIO and the Program to develop and implement IT security and privacy-related contract clauses for incorporation in all current and future contracts; and
4.2 Ensuring that contracting officers (COs) enforce the requirements of IT security and privacy clauses.
5. OSSI
The responsibilities of OSSI include, but are not limited to:
5.1 Providing overall leadership for the development, coordination, application, and evaluation of all policies and activities within the Department that relate to physical and personnel security, the security of classified information, and the exchange and coordination of national security-related strategic information with other Federal agencies and the national security community, including national security-related relationships with law enforcement organizations and public safety agencies;
5.2 Providing current and timely intelligence or national security information to the HHS CSIRC and OpDiv CSIRCs and other key personnel responsible for incident response;
5.3 Ensuring the implementation of communications security, including the use of secure telecommunications equipment and classified information systems, for the discussion and handling of classified information in support of the detection, defense, and response to security and privacy vulnerabilities, threats, and incidents;
5.4 Protecting employees and visitors and Department-owned and -occupied critical infrastructure;
5.5 Assuring the integration of strategic medical, public health, biomedical, and national security information;
5.6 Managing and administering the flow of classified information;
5.7 Providing national security information services to all components within the Office of the Secretary (OS); and
5.8 Approving visits by a foreign national to any HHS laboratory or other facility designated as Critical Infrastructure.
6. ASA/DASHR
The responsibilities of the ASA/DASHR include, but are not limited to:
6.1 Partnering with the HHS CIO, OpDivs, and system administrators who operate critical systems to develop, implement, and oversee personnel security controls for access to sensitive information (as defined by the HHS Standard for the Definition of Sensitive Information); and
6.2 Ensuring that personnel officers notify the OpDiv ISSO, or designated POC for physical and logical access controls, of an employee’s separation within one business day.
7. ASA/DASIT/HHS CIO
The responsibilities of the HHS CIO include, but are not limited to:
7.1 Primary responsibility and authority for management of the Department’s IT security program;
7.2 Ensuring HHS compliance with Federal regulations and FISMA IT security and privacy program implementation requirements;
7.3 Ensuring the development and maintenance of a Department-wide IT security and privacy program to include the development and implementation of policies, standards, procedures, and IT security controls resulting in adequate security for all organizational information systems and environments of operation for those systems;
7.4 Requiring the development and implementation of protections for HHS information and information systems commensurate with the risk and magnitude of harm posed by unauthorized access, modification, disclosure, disruption, use, and/or destruction, or as recommended by law;
7.5 Ensuring the dissemination of Department-wide IT security and privacy policy for OpDiv review and comment;
7.6 Reporting annually, in coordination with OpDiv/StaffDiv Heads, to the Secretary of HHS on the effectiveness of the Program, including progress of remedial actions;
7.7 Appointing the HHS CISO to fulfill the responsibilities of the CIO in developing and maintaining a Department-wide IT security and privacy program;
7.8 Defining and establishing the minimum security control requirements in accordance with data sensitivity and system criticality;
7.9 Preparing any report that may be required of HHS to satisfy the reporting requirements of OMB Circular A-130 and FISMA;
7.10 Coordinating with the Secretary of HHS to ensure the provision of resources necessary to administer the Program;
7.11 Providing advice and assistance to OS and other senior management personnel to ensure that information resources are acquired and managed for the Department in accordance with the goals of the Capital Planning and Investment Control (CPIC) process;
7.12 Determining, based on organizational priorities, the appropriate allocation of resources dedicated to the protection of the information systems supporting the organization's missions and business functions;
7.13 Providing leadership for developing, promulgating, and enforcing agency information resource management policies, standards, and guidelines, and for procedures on data management, enterprise performance life cycle (EPLC) management, security, telecommunications, IT reviews, and other related areas;
7.14 Establishing, implementing, and enforcing a Department-wide framework to facilitate an incident response program, ensuring proper and timely reporting to the United States Computer Emergency Readiness Team (US-CERT);
7.15 Establishing a Department-wide framework to facilitate the development of
Privacy Impact Assessment (PIA) Summaries for all Department systems, as instructed by OMB;
7.16 Primary authority to resolve any disputes from Office of Inspector General
(OIG) reviews and audits that cannot be resolved at the OpDiv level;
7.17 Overseeing personnel with significant responsibilities for information security and ensuring that the personnel are adequately trained;
7.18 Assisting senior organizational officials concerning their security responsibilities;
7.19 Performing the Risk Executive function for the Department;
As the Department’s Risk Executive, with the support of the HHS CISO, the HHS CIO also works closely with AOs across the OpDivs/StaffDivs and their designated representatives to execute the following responsibilities:
7.20 Ensuring information security considerations are integrated into programming/planning/budgeting cycles, enterprise architectures, and acquisition/system development life cycles;
7.21 Ensuring information systems are covered by approved security plans and are authorized to operate;
7.22 Ensuring information security-related activities required across the organization are accomplished in an efficient, cost-effective, and timely manner;
7.23 Ensuring a centralized reporting process is in place for appropriate information security-related activities; and
7.24 Executing the RMF tasks as outlined in NIST SP 800-37.
8. HHS SAOP
Within HHS, the CIO serves in the role of SAOP. The responsibilities of the SAOP include, but are not limited to:
8.1 Ensuring the proper implementation of information privacy protections, including full compliance with Federal laws, regulations, and policies relating to information privacy, such as the Privacy Act of 1974 (henceforth, “Privacy Act”) 5 U.S.C. Section 552a, and the E-Government Act of 2002;
8.2 Maintaining appropriate documentation regarding compliance with information privacy laws, regulations, and HHS policies;
8.3 Overseeing, coordinating, and facilitating the Department’s privacy compliance efforts, including reviewing documented information privacy procedures to ensure comprehensiveness and currency, and coordinating any necessary revisions;
8.4 Coordinating privacy-related reporting activities as mandated by Federal legislation and OMB guidance;
8.5 Approving the Department’s submission of the Privacy Management portion of the annual FISMA report;
8.6 Maintaining a central policy-making role in the Department’s development and evaluation of legislative, regulatory, and other policy proposals pertaining to information privacy issues, including those relating to the agency’s collection, use, sharing, and disclosure of personal information;
8.7 Ensuring that data sharing activities occur within applicable privacy laws and with appropriate safeguards;
8.8 Designating responsibility for oversight of the PIA process to the OpDiv SOP;
8.9 Establishing a framework to facilitate the development of PIA Summaries for all OpDiv systems, as instructed by OMB;
8.10 Ensuring PIAs are conducted for information systems and online collections, and coordinating submission of all Department PIA Summaries to OMB;
8.11 Reviewing and acknowledging the completion and accuracy of PIAs by designating PIAs as approved for Web publishing via the Department’s PIA reporting tool;
8.12 Allocating proper resources to permit identification and remediation of privacy weaknesses;
8.13 Ensuring the Department’s employees, contractors, and stakeholders receive appropriate privacy training;
8.14 Providing education programs regarding information privacy laws, regulations, policies, and procedures governing the Department’s handling of PII;
8.15 Serving as the Chair of the Privacy Incident Response Team (PIRT);
8.16 Reviewing and approving any use of a multi-session Web measurement and customization technology that collects PII;
8.17 Providing the public with notice of proposed use of a multi-session Web measurement and customization technology that collects PII, and an opportunity to comment on the proposed use;
8.18 Reviewing the Department’s practices related to the use of Web measurement and customization technologies annually and making the results of the review available to the public;
8.19 Consulting with OpDivs during the planning, implementation, and post-implementation review of a third-party Website or application; and
8.20 Designating responsibility to the HHS CISO for the management and oversight of the privacy components of FISMA and related OMB guidance.
9. OIS/HHS CISO
The responsibilities of the HHS CISO include but are not limited to:
9.1 Providing leadership in IT security and privacy policy, guidance, and expert advice among OpDivs and the StaffDivs in developing, promoting, and maintaining IT security and privacy measures to adequately and cost effectively protect and ensure the confidentiality, integrity and timely availability of all information in the custody of the Department, as well as the information systems required to meet the Department’s current and future business needs;
9.2 Assisting and advising the HHS CIO in the development, documentation, and implementation of the Program (e.g., issuing policy, maintaining situational awareness, and performing compliance oversight) in order to provide IT security and privacy safeguards for the electronic information and information systems that support the operations and assets of the Department, including those provided or managed by another Federal organization or bureau, contractor, or other source;
9.3 Ensuring that all IT resources are reviewed for compliance with established
Department and external policies, standards, and regulations;
9.4 Monitoring OpDiv/StaffDiv IT security and privacy program activities;
9.5 Fostering communication and collaboration among the Department’s security and privacy stakeholders to share knowledge and to better understand threats to Department information;
9.6 Carrying out the CIO security and SAOP responsibilities under FISMA and overseeing the preparation of quarterly and annual FISMA reports;
9.7 Developing and implementing an IT security performance measurement program to evaluate the effectiveness of technical and non-technical IT security safeguards used to protect the Department’s information;
9.8 Coordinating OSSI requirements for personnel clearances, position sensitivity, and access to information systems with the appropriate office;
9.9 Ensuring that all HHS-owned telephony equipment is provided with system and physical protection;
9.10 Implementing a security incident monitoring program for all Department systems and networks;
9.11 Disseminating information on potential security threats and recommended safeguards;
9.12 Ensuring the Department-wide implementation of Federal policies and procedures related to IT security and privacy incident response;
9.13 Overseeing the HHS CSIRC and managing the resources that support HHS
CSIRC operations;
9.14 Ensuring, in coordination with the HHS CIO and ASFR/OGAPA/DA, that all IT acquisitions include Department security and privacy considerations;
9.15 Serving as the primary liaison for the CIO to AOs, System Owners, primary operational IT infrastructure managers1 , ISSOs, and SOPs;
9.16 Providing management and oversight of activities under IT critical information protection (CIP);
9.17 Serving, as necessary, as an Authorizing Official Designated Representative or
Security Control Assessor;
9.18 Executing the RMF tasks as listed in NIST SP 800-37.
10. OpDiv CIOs
The responsibilities of each OpDiv CIO2 are to provide leadership to activities including, but not limited to:
10.1 Reporting quarterly to the HHS CIO on the effectiveness of the OpDiv’s IT security and privacy program, including the progress of any remedial actions;
10.2 Appointing an OpDiv CISO to fulfill the responsibilities of the OpDiv CIO in maintaining the OpDiv IT security program;
10.3 Managing internal security reviews of the program business cases, alternatives analyses, and other specific investment documents;
10.4 Managing and certifying an inventory of all current and proposed investments containing an IT component in accordance with the HHS CPIC process;
1 The HHS role of the Primary Operational IT Infrastructure Manager maps to the NIST SP 800-37 role of Common Control Providers.
2 The OpDiv CIOs perform the OpDiv Risk Executive (function) on behalf of the OpDiv Heads.
10.5 Ensuring that policies, procedures, and practices are consistent with Department requirements in order to ensure that programs, systems, and data are secure and protected from unauthorized access that might lead to the alteration, damage, or destruction of automated resources, unintended release of HHS data, or denial of service (DoS);
10.6 Ensuring that all employees and contractors comply with Department and
OpDiv IT security and privacy policies;
10.7 Ensuring the establishment of a computer security incident response team
(CSIRT) to participate in the investigation and resolution of incidents within the OpDiv;
10.8 Establishing, implementing, and enforcing an OpDiv-wide framework to facilitate an incident response program (including PII and PHI breaches) that ensures proper and timely reporting to HHS;
10.9 Managing an inventory of all major information systems, devices and other items per FISMA requirements and as required by OMB;
10.10 Ensuring mandatory security training, education, and awareness activities are undertaken by all personnel using, operating, supervising, or managing information systems;
10.11 Exercising primary responsibility and authority for management of the OpDiv’s
IT security program;
10.12 Serving as one of six Primary Operational IT Infrastructure Managers3 (applies to the CIO for the Centers for Disease Control and Prevention (CDC), Food and Drug Administration (FDA), Indian Health Service (IHS), Centers for Medicare and Medicaid Services (CMS), National Institutes of Health (NIH), and OS).
When an OpDiv CIO performs as a Primary Operational IT Infrastructure Manager, he/she is responsible for performing IT risk-management duties.
Where an information system relies (or partially relies) on one of the six Primary Operational IT infrastructures, the associated Primary Operational IT Infrastructure Manager(s) must concur with the risk acceptance by also signing the security authorization package as the AO;
10.13 Resolving any disputes from OIG reviews and audits at the OpDiv level, where possible. If disputes cannot be resolved, the disputes must be escalated to the
HHS CIO;
3 Reference HHS Secretary Memorandum: Security of Information Technology Systems, and HHS OCIO Memorandum: Process Guidance for Security Risk-Based Decisions Involving the Primary Operational Information Technology Infrastructure Managers. The ASA internal realignment abolished the OS CIO position; those duties are now performed by the HHS CIO who serves as the Primary Operational IT Infrastructure Manager for OS.
10.14 Developing a strategy for the continuous monitoring4 of security control effectiveness and any proposed or actual changes to the information system and its environment of operation5; and
10.15 Executing the RMF tasks as listed in NIST SP 800-37.
11. OpDiv CISOs
The responsibilities of each OpDiv CISO include, but are not limited to:
11.1 Leading OpDiv IT security and privacy programs and promoting proper IT security and privacy practices;
11.2 Supporting the HHS CISO in the implementation of the Program;
11.3 Fostering communication and collaboration among the OpDiv’s security and privacy stakeholders to share knowledge and to better understand threats to OpDiv information;
11.4 Providing information about the OpDiv IT security and privacy policies to management and throughout the OpDiv;
11.5 Providing advice and assistance to other organizational personnel concerning the security of sensitive information and of critical data processing capabilities;
11.6 Advising the OpDiv CIO about security-related incidents in accordance with the security breach reporting procedures developed and implemented by the Department and/or OpDiv;
11.7 Disseminating information on potential security threats and recommended safeguards;
11.8 Ensuring OpDiv-wide implementation of Department and OpDiv policies and procedures that relate to IT security and privacy incident response;
11.9 Collaborating with the PIRT Coordinator when the PIRT Coordinator is engaging the OpDiv POC for information collection and clarification, and sitting on the HHS PIRT while the breach is under investigation;
11.10 Coordinating with OpDiv Senior Official for Privacy to ensure privacy implications are addressed when PII incident response activities occur within the OpDiv;
4 The monitoring strategy may be included in the security plan to support the concept of near real-time risk management and ongoing authorization. The approval of the monitoring strategy may be obtained in conjunction with the security plan approval. The monitoring of security controls continues throughout the EPLC.
5 This is the responsibility of the System Owner or the Primary Operational IT Infrastructure Manager.
11.11 Ensuring that roles with significant security responsibilities are identified and documented per the HHS Memorandum: Role-Based Training of Personnel with Significant Security Responsibilities;
11.12 Conducting security education and awareness training needs assessments to determine appropriate training resources and to coordinate training activities for target populations;
11.13 Supporting general privacy awareness and role-based training activities for all personnel using, operating, supervising, or managing information systems;
11.14 Assisting System Owners in establishing and implementing the required security safeguards to protect computer hardware, software, and data from improper use or abuse;
11.15 Coordinating requirements for personnel clearances, position sensitivity, and access to information systems with the appropriate office;
11.16 Establishing, documenting, and enforcing requirements and processes for granting and terminating all administrative privileges including, but not limited to, ser vers, security domains, and local workstations;
11.17 Auditing the processes above for effectiveness; and
11.18 Executing the RMF tasks as listed in NIST SP 800-37.
12. HHS CSIRC
The responsibilities of the HHS CSIRC include, but are not limited to:
12.1 Establishing and maintaining a partnership with OpDiv CSIRTs to ensure the
HHS CSIRC is aware of security and privacy vulnerabilities, threats, and incidents that may negatively impact the ability of the OpDiv and/or the Department to fulfill its mission and functions;
12.2 Serving as the primary entity in the Department responsible for maintaining
Department-wide operational IT security situational awareness and determining the overall IT security risk posture of HHS;
12.3 Serving as the lead organization for coordinating Department-wide cybersecurity information sharing, analysis, and response activities;
12.4 Reporting HHS IT security and privacy incidents to US-CERT; and
12.5 Serving as the Department's primary POC with US-CERT.
13. OpDiv CSIRT
The responsibilities of the OpDiv CSIRT include, but are not limited to:
13.1 Serving as the primary entity in the OpDiv responsible for maintaining OpDiv-wide operational IT security situational awareness and determining the overall IT security risk posture of the OpDiv;
13.2 Serving as the lead organization for coordinating OpDiv-wide cybersecurity information sharing, analysis, and response activities;
13.3 Reporting OpDiv IT security and privacy incidents to HHS CSIRC6; and
13.4 Serving as the OpDiv's primary POC with HHS CSIRC.
14. HHS PIRT
The responsibilities of the HHS PIRT include, but are not limited to:
14.1 Evaluating breaches or suspected breaches of PII and deciding which actions should be taken;
14.2 Providing input to and approving breach response activities for breaches involving PII;
14.3 Assessing the responsible organization’s proposed course of action, risk assessments, response plan, and proposed notification activities; providing feedback; and making recommendations for improvement or course corrections in a timely manner;
14.4 Ensuring proper reporting, notification, and follow-up actions to stakeholders across relevant HHS organizational components when a breach involving PII occurs;
14.5 Working closely with the Program to coordinate Department response activities and data collection;
14.6 Referring HIPAA compliance breaches to HHS OCR, as appropriate;
14.7 Notifying appropriate internal HHS stakeholders, including the following:
OpDiv Security Offices; HHS Records Officer; building physical security; the HHS Assistant Secretary for Preparedness and Response (ASPR); the OIG;
HHS OCR; as well as appropriate external entities such as the US-CERT and law enforcement; and
6 OpDivs should share events and analysis with the CSIRC in near real-time.
14.8 Providing notification and assessments of information breaches to the HHS Risk
Management and Financial Oversight Board (RMFOB).
15. OpDiv SOP
The SOP title and position was extended by the Department to each OpDiv to effectively meet the reporting requirements outlined in OMB M-08-21, FY 2008 Reporting Instructions for the Federal Information Security Management Act and Agency Privacy Management. The agency requirement for the title and position is outlined in OMB M- 05-08, Designation of Senior Agency Officials for Privacy.
The responsibilities of the OpDiv SOP include, but are not limited to:
15.1 Supporting the HHS SAOP in ad-hoc privacy reporting activities as necessary, including the maintenance of and compliance with Presidential mandates and quarterly and annual FISMA reporting activities;
15.2 Reviewing and approving the OpDiv FISMA and Privacy Management Report for submission to the Department;
15.3 Developing and supporting the integration of Department privacy program initiatives into IT security practices, where applicable;
15.4 Establishing and implementing privacy policies, procedures, and practices consistent with Department privacy requirements, in coordination with the OpDiv CISO;
15.5 Coordinating OpDiv policy, guidance, and system-level documentation to ensure that Department management, operational, and technical privacy requirements are addressed;
15.6 Approving written requests to process, access, or store PII on personally owned or non-Department equipment in accordance with Control Section AC-17:
Remote Access;
15.7 Coordinating with the OpDiv CISO to obtain contractual assurances from third parties to ensure that the third party will protect PII in a manner consistent with the privacy practices of the Department and the OpDiv;
15.8 Reporting, in coordination with the OpDiv CISO, to the HHS SAOP the effectiveness of the OpDiv privacy program, including weaknesses and the progress of remedial actions, as identified;
15.9 Establishing an OpDiv policy framework to facilitate the development and maintenance of PIAs for all systems based on Department and Federal legislative requirements;
15.10 Tracking and maintaining all OpDiv PIA activities in the Department’s PIA reporting tool;
15.11 Reviewing completed OpDiv PIAs and attesting that PIAs are adequately and accurately completed;
15.12 Promoting (i.e., escalating) OpDiv PIAs to the Department, and submitting completed OpDiv PIAs to the HHS SAOP, and/or seeking revisions from the PIA author if errors are found;
15.13 Coordinating activities to regularly review PII holdings, assessing the PII confidentiality impact level of the PII holdings, recommending controls to protect the confidentiality of the PII, and eliminating the unnecessary use or collection of PII (including social security numbers);
15.14 Coordinating and ensuring that privacy education and awareness activities, specific to the OpDiv privacy culture, are established for all personnel using, operating, supervising, or managing information systems;
15.15 Coordinating with OpDiv budgetary offices to ensure PIA and System of
Records Notice (SORN) activities are included as part of Exhibit 300 development;
15.16 Making recommendations to the HHS SAOP and senior level officials with budgetary authority in order to allocate proper resources to identify and mitigate privacy weaknesses found in system PIAs;
15.17 Coordinating with the OpDiv Privacy Act Contact to:
15.17.1 Ensure that all required SORNs are completed and published in the Federal Register, and also on the HHS.gov Website;
15.17.2 Keep track of the location of Privacy Act records;
15.17.3 Approve/deny/track access to and amendments of records;
15.17.4 Ensure records are complete, accurate, timely and relevant;
15.17.5 Ensure that system users are made aware of their privacy responsibilities when accessing systems that contain PII;
15.17.6 Ensure that data collection forms include a Privacy Act Notification Statement;
15.17.7 Complete biannual SORN updates in accordance with OMB Circular
A-130; and
15.17.8 Coordinate completion of Privacy Act reviews, as defined by OMB
Circular A-130.
15.18 Coordinating reviews of data sharing activities to ensure that reviews occur according to applicable privacy laws and with appropriate safeguards;
15.19 Coordinating with HHS Website owners/administrators to ensure that Web-based privacy compliance requirements are met across the OpDiv; and
15.20 Coordinating with the OpDiv CSIRT and/or HHS PIRT concerning reports of the loss of control of PII.
16. OpDiv Privacy Act Contact
The responsibilities of the OpDiv Privacy Act Contact include, but are not limited to:
16.1 Serving as a POC for issues related to the Privacy Act within the OpDiv;
16.2 Coordinating with the OpDiv SOP on the development, publishing, and maintenance of OpDiv SORNs;
16.3 Maintaining an OpDiv SORN Website to post current SORNs per the guidance of the HHS Privacy Act Officer;
16.4 Supporting the OpDiv SOP and OpDiv CISO in completing required Privacy
Act reviews, as defined by OMB Circular A-130; and
16.5 Supporting completion of the OpDiv FISMA and Privacy Management Report for submission to the Department.
17. AO or Authorizing Official Designated Representative
The responsibilities of the AO or Authorizing Official Designated Representative7 for systems and networks under his or her authority include, but are not limited to, the following:
Note: AOs or Authorizing Official Designated Representatives typically…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .