HRSA Information Security Policy.pdf

PDF 984 KB Posted

Attached to
Health Center Loan Guarantee Program Support Federal contract opportunity
Solicitation number
75R60220Q00040
Issued by
Department of Health and Human Services Health Resources and Services Administration Headquarters

View the file

Other files for this federal contract opportunity

Show all 13

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Office of Information Security and Privacy

HRSA INFORMATION

SECURITY POLICY

May 24, 2019

HRSA Information Security Policy

Change Log

Date Update Updated By 5/9/2019 Draft OISP 5/17/2019 Reviewed and approved by CISO N/A 5/24/2019 Reviewed and approved by CIO N/A

Document Approvals

Adriane Burton Date

HRSA Chief Information Officer

Contents Introduction

Purpose

Structure

Scope

Policy

Access Control (AC)

Audit and Accountability (AU)

Awareness and Training (AT)

Configuration Management (CM)

Contingency Planning (CP)

Identification and Authentication (IA)

Incident Response (IR)

Maintenance (MA)

Media Protection (MP)

Personnel Security (PS)

Physical and Environmental Security (PE)

Planning (PL)

Program Management (PM)

Risk Assessment (RA)

Security Assessment and Authorization (CA)

System and Communications Protection (SC)

System and Information Integrity (SI)

System and Services Acquisition (SA)

Privacy Controls

Appendix A: References

Appendix B: HRSA-Defined Values Mapping to NIST and HHS IS2P

Introduction

Purpose

The Health Research Services Administration (HRSA) Information Security Policy (Policy), in conjunction with the Health and Human Services Information Systems Security Policy (HHS IS2P), provides direction to the information technology (IT) security program for the security and privacy of HRSA data and HRSA information systems. This policy supports the risk management framework for securing HRSA information and information systems.

Structure

The only controls listed in this Policy are HRSA-specific IT security and privacy requirements, organized according to information assurance (IA) control families (as defined by NIST SP 800-53) for easy reference. The HRSA-Defined Values section outlines these requirements in more detail.

For the controls that are to be applied without specific HRSA parameters, the HHS IS2P is the authoritative source. Together, this Policy and the HHS IS2P establish comprehensive IT security and privacy requirements that reflect applicable federal laws, Executive Orders, directives, regulations, policies, standards, and guidance.

A policy conveys:

• What is to be done,

• Who is to do it, and

• When it is to be done.

Scope

This policy is implemented in HRSA IT environments and applies to

• all management, users, system owners, information owners, information system security officers, system maintainers, system developers, system operators, and system administrators, including contractors and third parties, of HRSA information systems, facilities, networks, and information.

• all organizations collecting or maintaining information, or using or operating information systems on behalf of HRSA, are also subject to the stipulations of this policy.

This policy does not apply to and shall not alter requirements pertaining to the protection of classified information and national security information systems such as those identified in FISMA and policies, directives, instructions, and standards issued by The Office of Management and Budget or the intelligence community.

https://nvd.nist.gov/800-53/Rev4

Policy

Access Control (AC)

AC-1 Access Control Policy and Procedures

Applies to: LOW MODERATE HIGH

• This policy shall be made available to all HRSA organizational users via the HRSA OISP

SharePoint site and to non-organizational users as needed. This policy shall be developed, reviewed, and updated in accordance with NIST standards and HHS policy.

• HRSA information systems shall develop Access Control procedures to ensure Access Control policies and controls are properly implemented.

• Access Control procedures shall be developed, reviewed, and updated in accordance with NIST standards and HHS policy.

• Access Control procedures shall be disseminated to relevant system stakeholders as needed at the discretion of the system owner.

AC-2 Account Management

• HRSA information systems shall implement account management activities in accordance with NIST standards and HHS policy.

• HRSA information systems shall identify and select from the following information system account types to support organizational mission/business functions: Individual, shared, group, system, guest/anonymous, emergency, developer/manufacturer/vendor, temporary, and service.

• HRSA information systems shall require approvals by HRSA information system owners for requests to create information system accounts.

• HRSA information systems create, enable, modify, disable, and remove information system accounts in accordance with HRSA IT security procedures and HRSA Account Lifecycle and Password Policy for Active Directory accounts and system-specific procedures for all other accounts.

AC-2(4) Account Management | Automated Audit Actions

Applies to: MODERATE HIGH

• HRSA information systems shall automatically audit account actions in accordance with NIST standards and HHS policy, and notifies appropriate personnel as defined by the system owner.

AC-2(11) Account Management | Usage Conditions

Applies to: HIGH

• HRSA information systems shall enforce appropriate circumstances and usage conditions for accessing the system based on account type, as defined by the system owner.

AC-2(12) Account Management | Account Monitoring / Atypical Usage

• HRSA information systems shall monitor for atypical usage, as defined by the system owner, of information system accounts and shall report to the information system security officer in accordance with NIST standards and HHS policy.

AC-4 Information Flow Enforcement

• HRSA information systems shall enforce approved authorizations for controlling the flow of information in accordance with NIST standards, HHS policy and the following HRSA information flow control policies:

o HRSA network and system administrators will configure systems to prevent information from flowing to a user or system not authorized to receive such information in order to preserve data confidentiality and integrity.

o Flow control restrictions will include: keeping export-controlled information from being transmitted in the clear to the Internet, blocking outside traffic that claims to be from within the organization, restricting web requests to the Internet that are not from the internal web proxy server, and limiting information transfers between organizations based on data structures and content.

o Flow control enforcement will be implemented in boundary protection devices (e.g., gateways, routers, guards, encrypted tunnels, firewalls) that employ rule sets or establish configuration settings that restrict information system services, provide a packet-filtering capability based on header information, or message-filtering capability based on message content (e.g., implementing key word searches or using document characteristics). The trustworthiness of filtering/inspection mechanisms (i.e., hardware, firmware, and software components) that are critical to information flow enforcement will also be considered.

AC-5 Separation of Duties

• HRSA information systems shall separate duties of system administration and security administration and audit, system development and system change management, and other duties as defined by the system owner in accordance with NIST standards and HHS policy.

AC-6(1) Least Privilege | Authorize Access to Security Functions

• HRSA information systems shall explicitly authorize access to the following security functions, as well as those defined in NIST standards and HHS policy:

o Establishing system accounts, o Filtering rules for routers/firewalls, o Cryptographic key management information, o Configuration parameters for security services, and o Access control lists.

AC-6(2) Least Privilege | Non-Privileged Access for Non-Security Functions

• HRSA information systems shall require that users of information system accounts, or roles, with access to the information system security functions defined in AC-6(1) will use non-privileged accounts or roles in accordance with NIST standards and HHS policy.

AC-6(3) Least Privilege | Network Access to Privileged Commands

• HRSA information systems shall authorize network access to any privileged commands only when authorized by the system owner in accordance with NIST standards and HHS policy.

AC-6(5) Least Privilege | Privileged Accounts

• HRSA information systems shall restrict privileged accounts on the information system to system and network administrators in accordance with NIST standards and HHS policy.

AC-8 System Use Notification

• HRSA information systems shall implement system use notification in accordance with NIST standards and HHS policy.

• For publicly accessible systems requiring user authentication, the system use notification is displayed before granting further access.

AC-10 Concurrent Session Control

• HRSA information systems shall limit the number of concurrent sessions to 0 sessions for general accounts and in accordance with NIST standards and HHS policy.

AC-12 Session Termination

• HRSA information systems shall automatically terminate a user session after 30 minutes of inactivity in accordance with NIST standards and HHS policy.

AC-14 Permitted Actions without Identification or Authentication

• HRSA system owners or designated representative shall identify, document, and provide supporting rational in the associated SSP any specific user actions that can be performed without identification and/or authentication (e.g., public web sites or other publicly available information systems), consistent with HRSA Programs’ missions and business functions, and in accordance with NIST standards and HHS policy.

AC-17(3) Remote Access | Managed Access Control Points

• HRSA information systems shall route all remote accesses through the HHS Trusted Internet

Connection (TIC) for the HRSA network and as defined by the system owner for external systems, in accordance with NIST standards and HHS policy.

AC-17(4) Remote Access | Privileged Commands / Access

• HRSA shall authorize the execution of privileged commands and access to security-relevant information via remote access only for compelling operational needs as determined by the system owner or designated representative, and shall document the rationale in accordance

AC-19(5) Access Control for Mobile Devices | Full Device / Container-Based Encryption

• HRSA shall employ full-device encryption to protect the confidentiality and integrity of information on HRSA-issued mobile devices.

AC-21 Information Sharing

• HRSA shall facilitate information sharing by enabling authorized users to determine whether access authorizations assigned to the sharing partner match the access restrictions on the information for authorized users, in accordance with NIST standards and HHS policy.

• HRSA shall employ system owner-defined mechanisms or processes to assist users in making information sharing/collaboration decisions.

Audit and Accountability (AU)

AU-1 Audit and Accountability Policy reviewed, and updated in accordance with NIST standards and HHS policy.

• HRSA information systems shall develop Audit and Accountability procedures to ensure Audit and Accountability policies and controls are properly implemented.

• Audit and Accountability procedures shall be developed, reviewed, and updated in accordance with NIST standards and HHS policy.

• Audit and Accountability procedures shall be disseminated to relevant system stakeholders as needed at the discretion of the system owner.

AU-3(2) Content of Audit Records | Centralized Management of Planned Audit Record Content

• HRSA information systems shall provide centralized management and configuration of the content to be captured in audit records for the following:

o Firewalls;

o Security devices/appliances;

o Core and border routers;

o Domain controllers;

o DNS servers; and o Critical servers (as identified in the Business Impact Assessment (BIA)).

AU-4 Audit Storage Capacity

• HRSA information systems shall define audit record storage capacity requirements within audit and accountability procedures and allocate audit record storage capacity accordingly.

AU-5 Response to Audit Processing Failures

• In the event of an audit processing failure, HRSA information systems shall:

o Alerts appropriate system administrator(s); and o Takes the following action:

For low information systems: overwrite oldest audit records.

For moderate and high information systems: actions defined by HHS policy.

AU-5(1) Response to Audit Processing Failures | Audit Storage Capacity

• HRSA information systems shall provide a warning to the appropriate system administrator(s) immediately when allocated audit record storage volume reaches 90% of repository maximum audit record storage capacity.

AU-5(2) Response to Audit Processing Failures | Real-Time Alerts

• HRSA information systems shall provide an alert to the system administrator(s) immediately when the following audit failure events occur:

o When 80% of maximum audit storage (and every additional 10% thereafter) is achieved;

o When the audit file is deleted; and o When the audit file permissions are modified.

AU-6 Audit Review, Analysis, and Reporting

• HRSA information systems shall review and analyze information system audit records in accordance with HHS policy for indications of inappropriate or unusual activity (as identified by the system administrator or ISSO), and report findings to the system owner and ISSO.

AU-6(5) Audit Review, Analysis, and Reporting | Integration / Scanning and Monitoring Capabilities

• HRSA shall integrate analysis of audit records with analysis of data collected from vulnerability scanning information, performance data, and information system monitoring information, where applicable, in accordance with NIST standards and HHS policy.

AU-7(1) Audit Reduction and Report Generation | Automatic Processing

• HRSA information systems shall provide the capability to process audit records for events of interest based on specific audit fields identified by the ISSO or system administrator and documented within the audit and accountability procedures.

AU-8 Time Stamps

• HRSA information systems shall use internal system clocks to generate and record time stamps for audit records in accordance with NIST standards and HHS policy.

• HRSA information systems shall record time stamps for audit records that meet a granularity within tens of milliseconds.

AU-8(1) Time Stamps | Synchronization with Authoritative Time Source

• HRSA information systems shall compare the internal information system clocks to the authoritative time source in accordance with HHS policy and NIST standards.

• HRSA information systems shall synchronize to the authoritative time source when the time difference is greater than +/- 5 minutes.

AU-9(2) Protection of Audit Information | Audit Backup on Separate Physical Systems / Components

• HRSA information systems shall back up audit records weekly onto a physically different system or system component than the system or component being audited.

AU-9(4) Protection of Audit Information | Access by Subset of Privileged Users

• HRSA information systems shall authorize access to management of audit functionality to only system owner or designated representative.

AU-10 Non-Repudiation

• HRSA information systems shall protect against an individual or process acting on behalf of an individual falsely denying having performed actions such as creating information, sending and receiving messages, and approving information (e.g., indicating concurrence or signing a contract).

AU-11 Audit Record Retention

• HRSA shall retain audit records in accordance with Records Management retention requirements.

AU-12 Audit Generation

• HRSA information systems shall provide audit record generation capability for the auditable events defined in AU-2 for the following information system components:

o firewalls;

o domain controllers;

o workstations (desktop PCs and laptops);

o servers;

o security devices;

o network devices (routers, switches); and o VPN devices,

• and shall allow the system owner or designated representative to select which auditable events are to be audited, and generates audit records in accordance with NIST standards and HHS policy.

AU-12(1) Audit Generation | Time-Correlated Audit Trail

• HRSA information systems shall compile audit records from the information system components in AU-12 into a system-wide logical or physical audit trail that is time-correlated to +/- 5 minutes.

AU-12(3) Audit Generation | Changes by Authorized Individuals

• HRSA information systems shall provide the capability for system administrators to change the auditing to be performed on the information system components in AU-12 Audit Generation based on criteria defined by the system owner or designated representative in near real-time.

Awareness and Training (AT)

AT-1 Security Awareness and Training Policy and Procedures

• This policy shall be made available to all HRSA organizational users via the HRSA Office of

Information Security and Privacy (OISP) SharePoint and to non-organizational users as needed. This policy shall be developed, reviewed, and updated in accordance with NIST standards and HHS policy.

• The HRSA OISP is responsible for developing Security Awareness and Training procedures in accordance with NIST standards and HHS policy.

• Security Awareness and Training procedures shall be disseminated to relevant stakeholders as needed at the discretion of the HRSA OISP.

Configuration Management (CM)

CM-1 Configuration Management Policy reviewed, and updated in accordance with NIST standards and HHS policy.

• HRSA information systems are responsible for developing Configuration Management procedures to ensure Configuration Management policies and controls are properly implemented.

• Configuration Management procedures shall be developed, reviewed, and updated in accordance with NIST standards and HHS policy.

• Configuration Management procedures shall be disseminated to relevant system stakeholders as needed at the discretion of the system owner.

CM-2(3) Baseline Configuration | Retention of Previous Configurations

• HRSA information systems shall retain previous versions of the baseline configuration of the information system in accordance with Records Management, NIST standards, and HHS

CM-2(7) Baseline Configuration | Configure Systems, Components, or Devices for High-Risk Areas

• HRSA shall issue devices to individuals traveling to locations deemed to be of significant risk

• HRSA information systems shall sanitize and wipe devices when individuals return from locations deemed to be of significant risk.

CM-3 Configuration Change Control

• HRSA information systems shall control configuration changes in accordance with NIST

• HRSA information systems shall employ a configuration change control board that meets, at a minimum, weekly in accordance with NIST standards and HHS policy.

CM-3(1) Configuration Change Control | Automated Document / Notification / Prohibition of Changes

• HRSA information systems shall employ automated mechanisms to appropriately control configuration changes, and shall notify the ISSO and system owner of proposed changes and completed changes to the system in accordance with NIST standards and HHS policy.

CM-5(2) Access Restrictions for Change | Review System Changes

• HRSA information systems shall review information system changes in accordance with NIST standards and HHS policy, and when there are indications of unusual or suspicious activities.

CM-5(3) Access Restrictions for Change | Signed Components

• HRSA information systems shall prevent the installation of unauthorized and unapproved software and firmware component(s) without verification that the component(s) has been digitally signed in accordance with NIST standards and HHS policy.

CM-6 Configuration Settings

• HRSA information systems shall establish, document, and implement configuration settings using in accordance with NIST standards and HHS policy.

o In situations where HHS, USGCB, and NCP guidance does not exist, system owner and

ISSO shall establish baselines based on industry and vendor best practices.

• HRSA information systems identify, document, and approve any deviations in accordance with NIST standards and HHS policy, based on documented, approved business justification.

CM-6(2) Configuration Settings | Respond to Unauthorized Changes

• HRSA information systems shall alert system administrators to respond to unauthorized changes to information system components defined by the system owner in accordance with NIST standards and HHS policy.

CM-7 Least Functionality

• HRSA information systems shall configure information systems to provide only essential capabilities and to prohibit or restrict high-risk functions ports, protocols, and services as defined by the HRSA Enterprise Architecture office.

CM-7(2) Least Functionality | Prevent Program Execution

• HRSA information systems shall prevent program execution in accordance with policies defined by the HRSA Enterprise Architecture office.

CM-7(4) Least Functionality | Unauthorized Software / Blacklisting

Applies to: MODERATE

• HRSA Enterprise Architecture office shall identify and maintain a list of software programs not authorized to execute on HRSA information systems.

• HRSA information systems shall employ an allow-all, deny-by-exception policy in accordance

CM-7(5) Least Functionality | Authorized Software / Whitelisting

• HRSA Enterprise Architecture office shall identify and maintain a list of software programs authorized to execute on HRSA information systems.

• HRSA information systems shall employ a deny-all, permit-by-exception policy in accordance

CM-8(3) Information System Component Inventory | Automated Unauthorized Component Detection

• HRSA information systems shall employ automated mechanisms to detect the presence of unauthorized components within the information system, and shall notify designated system administrator of the presence of unauthorized component, in accordance with NIST standards and

CM-11 User-Installed Software

• HRSA information systems shall prohibit the installation of software by users on all government-furnished equipment, enforce software prohibition policies through automated methods (restricting end users from installing software), and monitor compliance in

Contingency Planning (CP)

CP-1 Contingency Planning Policy reviewed, and updated in accordance with NIST standards and HHS policy.

• HRSA information systems shall ensure Contingency Planning policies and controls are properly implemented.

• Contingency Planning procedures shall be developed, reviewed, and updated in accordance with NIST standards and HHS policy.

• Contingency Planning procedures shall be disseminated to relevant system stakeholders as needed at the discretion of the system owner.

CP-2(3) Contingency Plan | Resume Essential Mission / Business Functions

• HRSA information systems shall plan for the resumption of essential mission and business functions within a time period identified in the information system’s ITCP.

CP-2(4) Contingency Plan | Resume All Mission / Business Functions

• HRSA information systems shall plan for the resumption of all mission and business functions within timeframes identified in the information system’s ITCP.

CP-7 Alternate Processing Site

• HRSA information systems shall identify an alternate processing site in accordance with NIST standards and HHS policy that ensures resumption of information system operations for HRSA critical mission/business functions.

CP-7(1) Alternate Processing Site | Separation from Primary Site

• HRSA information systems shall identify an alternate processing site that has separate telecommunications and power services, regardless of distance, from the primary processing site in accordance with NIST standards and HHS policy.

CP-8 Telecommunication Services

• HRSA shall establish alternate telecommunications services and necessary agreements to permit resumption of information system operations for HRSA critical mission/business functions within a time period identified in the information system’s ITCP and in accordance

CP-9 Information System Backup

• HRSA information systems shall conduct weekly full backups of Low and Moderate systems, and daily incremental backups of High systems, and shall protect the confidentiality, integrity, and availability of backup information in accordance with NIST standards and HHS

CP-9(3) Information System Backup | Separate Storage for Critical Information

• HRSA information systems shall store backup copies of the operating system on which the information systems reside, as well as other critical information system software, in a separate facility in accordance with NIST standards and HHS policy.

CP-9(5) Information System Backup | Transfer to Alternate Storage Site

• HRSA information systems shall encrypt and transfer information system backup information to the alternate storage site in accordance with the information system’s return time objectives (RTO) and recovery point objectives (RPO) defined in the information system’s ITCP, and in accordance with NIST standards and HHS policy.

CP-10(4) Information System Recovery and Reconstitution | Restore within Time Period

• HRSA information systems shall provide the capability to reimage information system components within a time period identified in the information system’s ITCP, in accordance

Identification and Authentication (IA)

IA-1 Identification and Authentication Policy and Procedures

SharePoint site and to non-organizational users as needed. This policy shall be developed, reviewed, and updated in accordance with NIST standards and HHS policy.

• HRSA information systems shall develop Identification and Authentication procedures to ensure Identification and Authentication policies and controls are properly implemented.

• Identification and Authentication procedures shall be developed, reviewed, and updated in accordance with NIST standards and HHS policy.

• Identification and Authentication procedures shall be disseminated to relevant system

IA-2(11) Identification and Authentication (Organizational Users) | Remote Access – Separate Device

• HRSA information systems shall implement multifactor authentication for remote access to privileged and non-privileged accounts such that one of the factors is provided by a device separate from the system gaining access and the device meets strength requirements documented in HRSA Active Directory Standards in accordance with NIST

IA-4 Identifier Management

• HRSA information systems shall manage information system identifiers in accordance

• HRSA information systems shall receive authorization from the system owner or designated representative to assign an individual, group, role, or device identifier.

IA-5(3) Authenticator Management | In-Person or Trusted Third-Party Registration

• HRSA shall require the registration process to receive PIV cards be conducted in

IA-5(11) Authenticator Management | Hardware Token-Based Authentication

• HRSA information systems shall employ mechanisms that satisfy HRSA token quality requirements as defined in the HRSA Account Life Cycle and Password Policy in

IA-8(3) Identification and Authentication (Non-Organizational Users) | Use of FICAM-Approved Products

• HRSA general public-accessible systems, such as the public-facing websites, shall employ only FICAM-approved information system components to accept third-party credentials, in with accordance with NIST standards and HHS policy.

Incident Response (IR)

IR-1 Incident Response Policy reviewed, and updated in accordance with NIST standards and HHS policy.

• The HRSA Office of Information Security and Privacy (OISP) is responsible for developing baseline Incident Response procedures. HRSA information systems are responsible for developing supplemental Incident Response procedures to ensure Incident Response policies and controls are properly implemented.

• Incident Response procedures shall be developed, reviewed, and updated in accordance with NIST standards and HHS policy.

• Incident Response procedures shall be disseminated to relevant system stakeholders as

IR-3 Incident Response Testing

• HRSA information systems shall test the incident response capability in accordance with NIST standards and HHS policy, using tests defined in the HRSA Incident Response plan.

IR-6 Incident Reporting

• HRSA personnel shall report suspected security incidents to the HRSA Security Operations

Center (SOC) within 1 hour.

• HRSA shall report security incidents in accordance with NIST standards and HHS policy.

IR-8 Incident Response Plan

• HRSA shall develop and maintain an incident response plan in accordance with NIST

• The incident response plan shall be reviewed and approved by the HRSA Chief Information Security Officer (CISO).

• The incident response plan shall be distributed, and any changes communicated, to HRSA personnel with incident response responsibilities.

Maintenance (MA)

MA-1 System Maintenance Policy reviewed, and updated in accordance with NIST standards and HHS policy.

• HRSA information systems are responsible for developing Maintenance procedures to ensure Maintenance policies and controls are properly implemented.

• Maintenance procedures shall be developed, reviewed, and updated in accordance with NIST standards and HHS policy.

• Maintenance procedures shall be disseminated to relevant system stakeholders as needed at the discretion of the system owner.

MA-2 Controlled Maintenance

• HRSA Information systems shall schedule, perform, document, and review records of maintenance and repairs on information system components in accordance with NIST standards and HHS policy.

• HRSA information systems shall require the system owner or designated representative to explicitly approve the removal of the system or components from organizational facilities for off-site maintenance.

• HRSA information system maintenance records shall include the following:

o date and time of maintenance, o name of individual performing the maintenance, o name of escort, if necessary, o description of the maintenance performed, o list of equipment removed and replaced (including identification numbers, if applicable)

MA-3(3) Maintenance Tools | Prevent Unauthorized Removal

• HRSA information systems shall prevent unauthorized removal of maintenance equipment containing organizational information in accordance with NIST standards and HHS policy.

o HRSA information systems shall obtain an exemption from the system owner or designated representative explicitly authorizing removal of the equipment from the facility.

MA-4(1) Nonlocal Maintenance | Auditing and Review

• HRSA information systems shall audit all nonlocal maintenance and diagnostic sessions in

MA-6 Timely Maintenance

• HRSA information systems shall obtain timely maintenance support for system components designated within the system’s maintenance procedures within a time period of failure defined in system’s maintenance procedures.

Media Protection (MP)

MP-1 Media Protection Policy and Procedures reviewed, and updated in accordance with NIST standards and HHS policy.

• HRSA information systems shall define, develop, review, and update the appropriate media protection procedures and mechanisms in accordance with NIST standards and HHS policy.

• Media Protection procedures shall be disseminated to relevant system stakeholders as

MP-2 Media Access

• HRSA information systems shall restrict access to media to authorized users, as identified by the system owner, in accordance with NIST standards and HHS policy.

MP-3 Media Marking

• HRSA information systems shall mark information system media in accordance with HHS policy and NIST standards. Media containing information that is determined to be publicly releasable is exempted from media marking. Any additional exemptions shall be approved by HRSA Records Management.

MP-7 Media Use

• HRSA prohibits the use of personally-owned USB removable media (e.g., thumb drives, memory sticks) to store or process HRSA data or connect to HRSA information systems or system components in accordance with NIST standards and HHS policy.

o Government-furnished USB storage devices that store or process sensitive HRSA information shall be encrypted.

Personnel Security (PS)

PS-1 Personnel Security Policy reviewed, and updated in accordance with NIST standards and HHS policy.

• HRSA information systems shall establish and apply Personnel Security procedures to ensure Personnel Security policies and controls are properly implemented.

• Personnel Security procedures shall be developed, reviewed, and updated in accordance with NIST standards and HHS policy.

• Personnel Security procedures shall be disseminated to relevant system stakeholders as

PS-4 Personnel Termination

• HRSA shall notify Human Resources and ensure personnel termination processes are implemented for all departing individuals in accordance with NIST standards and HHS policy.

o Supervisors shall conduct exit interviews that include a discussion of information security topics including, but not limited to, reminding terminated individuals of nondisclosure agreements and potential limitations on future employment.

PS-4(2) Personnel Termination | Automated Notification

• HRSA shall employ automated mechanisms to notify Human Resources upon termination of an individual in accordance with NIST standards and HHS policy.

PS-5 Personnel Transfer

• HRSA shall notify Human Resources and ensure personnel transfers are implemented in

PS-7 Third-Party Personnel Security

• HRSA shall ensure third-party personnel security is implemented in accordance with NIST

• HRSA shall require third-party providers to notify the Contracting Office Representative of any personnel transfers or terminations of third-party personnel who possess organizational credentials and/or badges, or who have information system privileges in accordance with

PS-8 Personnel Sanctions

• HRSA shall employ a formal sanctions process in accordance with NIST standards and HHS

• HRSA shall notify Human Resources when a formal employee sanctions process is initiated, in

Physical and Environmental Security (PE)

PE-1 Physical and Environmental Protection Policy and Procedures reviewed, and updated in accordance with NIST standards and HHS policy.

• HRSA information systems shall develop Physical and Environmental Protection procedures to ensure Physical and Environmental Protection policies and controls are properly implemented.

• Physical and Environmental Protection procedures shall be developed, reviewed, and updated in accordance with NIST standards and HHS policy.

• Physical and Environmental Protection procedures shall be disseminated to relevant system

PE-3 Physical Access Control

• HRSA information systems shall enforce physical access authorizations at entry/exit points of

HRSA facilities where information systems reside by controlling ingress/egress to the facility using physical access devices (e.g., keys, locks, combinations, card readers) and/or security guards to control entries into the facility, and in accordance with NIST standards and HHS policy.

• HRSA information systems shall maintain physical access audit logs for HRSA facilities where information systems reside.

• HRSA information systems shall provide monitoring (cameras and/or security guards) to control access to areas within the facilities officially designated as publicly accessible:

• HRSA information systems shall ensure all visitors are escorted and their activities monitored while on HRSA premises and on facilities where external HRSA systems reside.

o Government employees, contractors, and others with permanent authorization credentials are not considered visitors.

• HRSA information systems shall secure keys, combinations, and other physical access devices in accordance with NIST standards and HHS policy.

• HRSA information systems shall inventory keys and other physical access devices and shall change combinations and keys in accordance with NIST standards and HHS policy.

• HRSA information systems shall change combinations and keys in accordance with NIST

PE-3(1) Physical Access Control | Information System Access

• HRSA information systems shall enforce physical access authorizations to the information system at HRSA facilities where information systems reside.

PE-4 Access Control for Transmission Medium

• HRSA information systems shall control physical access to system distribution and transmission lines within HRSA facilities using o locked wiring closets;

o disconnected or locked spare jacks; and/or o protection of cabling by conduit or cable trays.

PE-6 Monitoring Physical Access

• HRSA information systems shall monitor physical access to the facility where the information system resides in accordance with HHS policy and NIST standards.

o HRSA information systems shall perform additional reviews physical access logs when there is indication of potential events.

PE-6(4) Monitoring Physical Access | Monitoring Physical Access to Information Systems

• HRSA information systems shall monitor physical access to the information system where there is a concentration of information system components (server rooms, media storage areas, etc.) in accordance with NIST standards and HHS policy.

PE-8 Visitor Access Records

• HRSA information systems shall maintain visitor access records to the facility where the information system resides for a time period defined by Records Management and reviews visitor access records in accordance with HHS policy and NIST requirements.

PE-10 Emergency Shutoff

• HRSA information systems shall provide the capability for shutting off power, place emergency shutoff switches or devices in all facilities housing information systems, such as data centers and server rooms, and protect emergency power shutoff capability from unauthorized activation in accordance with NIST standards and HHS policy.

PE-13(1) Fire Protection | Detection Devices / Systems

• Facilities housing HRSA information systems shall employ fire detection devices/systems for the information system in accordance with NIST standards and HHS policy that notify the system administrator and designated emergency responders in the event of a fire.

PE-13(2) Fire Protection | Suppression Devices / Systems

• Facilities housing HRSA information systems shall employ fire suppression devices/systems for the information system in accordance with NIST standards and HHS policy that notify the system administrator and designated emergency responders in the event of a fire.

PE-14 Temperature and Humidity Controls

• Facilities housing HRSA information systems shall ensure temperate and humidity levels remain at an acceptable level per equipment specification, and shall monitor temperature and humidity levels on an ongoing basis.

PE-15(1) Water Damage Protection | Automation Support

• Facilities housing HRSA information systems shall employ automated mechanisms to detect the presence of water and alert the system administrator or designated representative.

PE-16 Delivery and Removal

• HRSA information systems shall authorize, monitor, and control all information system components entering and exiting the facility in accordance with NIST standards and HHS

PE-17 Alternate Work Site

• HRSA information systems shall employ HRSA’s Telework Policy at alternate work sites in

PE-18 Water Damage Protection

• HRSA information systems shall ensure the information system components are positioned in the facility to minimize potential damage from flooding, vandalism, electrical interference, and electromagnetic radiation, in accordance with NIST standards and HHS policy.

Planning (PL)

PL-1 Security Planning Policy and Procedures

SharePoint and to non-organizational users as needed. This policy shall be developed, reviewed, and updated in accordance with NIST standards and HHS policy.

• The HRSA Office of Information Security and Privacy (OISP) is responsible for developing baseline Security Planning procedures. HRSA information systems are responsible for developing supplemental Security Planning procedures to ensure Security Planning policies and controls are properly implemented.

• Security Planning procedures shall be developed, reviewed, and updated in accordance with NIST standards and HHS policy.

• Security Planning procedures shall be disseminated to relevant system stakeholders as

PL-2 System Security Plan

• All HRSA information systems shall develop and maintain a system security plan in accordance with NIST requirements and HHS policy.

• The system security plan shall be reviewed by the system owner, information system security officer, and other key stakeholders.

• System security plans shall be stored in the HRSA eGRC tool to allow appropriate stakeholders to access the system security plan.

• Additionally, system security plans should be disseminated as needed to additional stakeholders that do not have access to the HRSA eGRC tool.

Program Management (PM)

There are no HRSA-specific policies for the PM control family.

Risk Assessment (RA)

RA-1 Risk Assessment Policy and Procedures

SharePoint and to non-organizational users as needed. This policy shall be developed, reviewed, and updated in accordance with NIST standards and HHS policy.

• The HRSA Office of Information Security and Privacy (OISP) shall develop, review, and update Risk Assessment procedures in accordance with NIST standards and HHS policy. HRSA information systems shall develop supplemental Risk Assessment procedures to ensure Risk Assessment policies and controls are properly implemented.

• Risk Assessment procedures shall be disseminated to relevant system stakeholders as

RA-3 Risk Assessment

• HRSA information systems shall perform and maintain risk assessments in accordance with

• HRSA shall document risk assessment results in Risk Assessment Reports. Risk assessment reports shall be stored in the HRSA eGRC tool to allow appropriate stakeholders to access the risk assessment results.

• Additionally, system security plans should be disseminated as needed to additional stakeholders that do not have access to the HRSA eGRC tool.

RA-5 Vulnerability Scanning

• HRSA shall implement vulnerability scanning of information systems and hosted applications

• Information obtained from the vulnerability scanning process shall be distributed to ISSOs.

ISSOs shall disseminate vulnerability scanning information to additional stakeholders as needed.

RA-5(4) Vulnerability Scanning | Discoverable Information

• If information about a HRSA information system is determined to be discoverable by adversaries, HRSA information systems shall take appropriate corrective actions as outlined in the HRSA Incident Response Plan.

RA-5(5) Vulnerability Scanning | Privileged Access

• HRSA information systems shall implement privileged access authorizations for all vulnerability scans, where feasible.

Security Assessment and Authorization (CA)

CA-1 Security Assessment and Authorization Policy and Procedures reviewed, and updated in accordance with NIST standards and HHS policy.

• The HRSA Office of Information Security and Privacy (OISP) is responsible for developing baseline Security Assessment and Authorization procedures. HRSA information systems are responsible for developing supplemental Security Assessment and Authorization procedures to ensure Security Assessment and Authorization policies and controls are properly implemented.

• Security Assessment and Authorization procedures shall be developed, reviewed, and updated in accordance with NIST standards and HHS policy.

• Security Assessment and Authorization procedures shall be disseminated to relevant system

CA-2 Security Assessments

• HRSA information systems shall perform security assessments in accordance with NIST

• HRSA information systems shall ensure all controls are assessed prior to commencing operations. Once operational, a subset of controls shall be selected by OISP to be assessed annually.

• Security control assessment results shall be provided to the information system’s ISSO and system owner.

CA-2(1) Security Assessments | Independent Assessors

• Security control assessments shall be conducted by independent security control assessors.

o OISP employs independent security control assessors that should perform information system’s security control assessments. If an information system selects their own security control assessors, their level of independence shall be approved by OISP prior to conducting an assessment.

CA-2(2) Security Assessments | Specialized Assessments

• HRSA security controls assessments shall include announced vulnerability scanning.

CA-2(3) Security Assessments | External Organizations

• HRSA shall accept the results of assessments of information systems performed by independent assessors when the assessment meets the requirements identified in section CA-2(1) Security Assessments | Independent Assessors.

CA-3(5) System Interconnections | Restrictions on External System Connections

• HRSA information systems shall restrict connections to external information systems in

CA-5 Plan of Action and Milestones

• HRSA information systems shall develop a plan of action and milestones (POA&M) and shall update all POA&Ms at least monthly, in accordance with NIST standards and HHS policy.

CA-7 Continuous Monitoring

• HRSA shall develop a continuous monitoring strategy and implement a continuous monitoring program in accordance with NIST standards and HHS policy.

o HRSA shall document an annual continuous monitoring methodology which establishes specific metrics to monitor, monitoring frequencies, and assessment frequencies.

• The security status of the organization shall be reported to HHS. The security status of information systems shall be reported to the ISSO, system owner, and other system stakeholders as determined by the system owner.

CA-7(1) Continuous Monitoring | Independent Assessment

• See section CA-2(1) Security Assessments | Independent Assessors.

CA-9 Internal System Connections

• HRSA information systems shall authorize and document internal connections of information system components defined by the system owner, in accordance with NIST standards and

System and Communications Protection (SC)

SC-1 Systems and Communication Protection Policy and Procedures reviewed, and updated in accordance with NIST standards and HHS policy.

• HRSA information systems shall develop Systems and Communication Protection procedures to ensure Systems and Communication Protection policies and controls are properly implemented.

• Systems and Communication Protection procedures shall be developed, reviewed, and updated in accordance with NIST standards and HHS policy.

• Systems and Communication Protection procedures shall be disseminated to relevant system

SC-5 Denial of Service

• HRSA information systems shall protect against/limit the effects of denial of service attacks in

• HRSA information systems shall identify and implement the security safeguards (e.g. rate limiting on public facing DNS servers, blocking access to common attack vectors such as pings from external systems, host-based firewalls on desktops, TCP SYN flood attack protection on firewalls) to protect the system against denial of service attacks.

SC-7(8) Boundary Protection | Route Traffic to Authenticated Proxy Servers

• HRSA information systems shall route any user-initiated traffic and any external, untrusted network traffic through authenticated proxy servers at managed interfaces.

SC-7(21) Boundary Protection | Isolation of Information System Components

• HRSA information systems shall employ boundary protection mechanisms to separate information system components performing different missions and/or business functions in

SC-8(1) Transmission Confidentiality and Integrity | Cryptographic or Alternate Physical Protection

• HRSA information systems shall implement cryptographic mechanisms in accordance with

NIST standards and HHS policy, unless otherwise physically protected by a controlled boundary.

SC-17 Public Key Infrastructure Certificates

• HRSA information systems shall issue public key certificates under the approved HRSA certificate authority in accordance with NIST standards and HHS policy.

SC-28 Protection of Information at Rest

• HRSA information systems shall protect sensitive information, as defined by the HRSA Guide for Identifying and Handling Sensitive Information, at rest, in accordance with NIST standards and HHS policy.

System and Information Integrity (SI)

SI-1 System and Information Integrity Policy reviewed, and updated in accordance with NIST standards and HHS policy.

• HRSA information systems shall develop System and Information Integrity procedures to ensure System and Information Integrity policies and controls are properly implemented.

• System and Information Integrity procedures shall be developed, reviewed, and updated in accordance with NIST standards and HHS policy.

• System and Information Integrity procedures shall be disseminated to relevant system

SI-2 Flaw Remediation

• HRSA information systems shall remediate flaws in accordance with NIST standards and HHS

• HRSA information systems shall install security-relevant software and firmware updates promptly, the time period being determined based on the criticality of the update (severity of the vulnerability related to the discovered flaw).

SI-4 Information System Monitoring

• HRSA information systems shall perform information system monitoring in accordance with

• HRSA information systems shall monitor for attacks and indicators of potential attacks in accordance with the following objectives:

o Detection of unauthorized use of government information technology assets;

o Detection of unauthorized disclosure of government data;

o Identification of information technology vulnerabilities;

o Identification of cybersecurity threats that threaten the confidentiality, integrity, and availability of government information technology assets.

• HRSA information systems shall identify unauthorized use of the information system through techniques and methods including, but not limited to: intrusion detection systems, intrusion prevention systems, malicious code protection software, scanning tools, audit record monitoring software, network monitoring software.

• HRSA information systems shall provide relevant information system monitoring information to system stakeholders as…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .