Appendix E - System Security Plan Requirements.pdf
PDF 98 KB Posted
- Attached to
- Agency Digital Asset Management System Federal contract opportunity
- Solicitation number
- 88310321Q00056
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Amendment 002.docx | DOCX document | |
| Appendix B - Contingency Plan Template.pdf | ||
| Appendix F - Configuration Management Database (CMDB) Template.pdf | ||
| Appendix C - Incident Response Plan Template.pdf | ||
| 88310321Q00056 ADAMS.docx | DOCX document | |
| Appendix D - Quality_Assurance_Cloud_CMDB_Template.xlsx | XLSX spreadsheet | |
| Appendix G - Interface Control Document (ICD) Template.pdf | ||
| Amendment 001 Extension.docx | DOCX document | |
| 88310321Q00056 ADAMS.pdf | ||
| Volume 1 Requirements Matrix.xlsx | XLSX spreadsheet | |
| Appendix A - IT Security Requirements.pdf |
Show all 11
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SSP System Application Level Controls.xlsx Project: Physical Access Control System
Page 1 of
Paragraph/ReqI D
Title Requirement Statement Class Type Status Priority Responsible Entities Implementation Estimated Completion
Date
Notes
AC-2 Account Management AC-2. For all data, the NARA System Owner shall:
AC-2a. Identify account types (i.e., individual, group, system, application, guest/anonymous, and temporary);
AC-2b. Assign account managers for information system accounts;
AC-2c. Establish conditions for group and role membership;
AC-2d. Specify authorized users of the information system, group and role membership, and access authorizations (i.e., privileges) and other attributes (as required) for each account;
AC-2e. Require approvals by ISSO and system owner for requests to create information system accounts;
AC-2f. Create, enable, modify, disable, and remove information system accounts in accordance with NARA 804, Information Technology (IT) Systems Security;
AC-2g. Monitor the use of, information system accounts;
AC-2h. Notify account managers:
1. When accounts are no longer required;
2. When users are terminated or transferred; and
3. When individual information system usage or need-to-know changes;
AC-2i. Authorize access to the information system based on:
1. A valid access authorization;
2. Intended system usage; and
3. Other attributes as required by the system functions;
AC-2j. Review accounts compliance with account management requirements [at least annually].
AC-2k. Establish a process for reissuing shared/group account credentials (if deployed) when individuals are removed from the group.
Technical Hybrid P1
AC-2 (1) Automated System Account Management
AC-2(1) For data requiring moderate or high confidentiality, the NARA System Owner shall employ automated mechanisms to support the management of information system accounts.
Technical Hybrid P1
AC-2 (2) Removal Of Temporary / Emergency Accounts
AC-2(2) For data requiring moderate or high confidentiality, the information system shall automatically disable temporary and emergency accounts after [a period not to exceed 15 days for unclassified information systems or 72 hours for classified information systems].
Technical Hybrid P1
AC-2 (3) Disable Inactive Accounts
AC-2(3) For data requiring moderate or high confidentiality, the information system shall automatically disable inactive accounts after [a period not to exceed 365 days for unclassified information systems or 30 days for classified information systems].
Technical Hybrid P1
AC-2 (4) Automated Audit Actions
AC-2(4) For data requiring moderate or high confidentiality, the information system shall automatically audit account creation, modification, disabling, and removal actions and shall notify, as required, appropriate individuals.
Technical Hybrid P1
AC-3 Access Enforcement AC-3. For all data, the information system shall enforce approved authorizations for logical access to the system and system resources in accordance with NARA applicable access control policy.
The NARAnet GSS shall provide multifactor access control as a common control for remote and local access to the network. The authentication capability shall be available to externally hosted systems which restrict access to NARA account holders.
Multifactor access mechanisms shall include credentials from HSPD 12 compliant PIV cards.
Users with elevated security privileges shall access the system using a multi factor authentication mechanism that complies with applicable federal directives and NARA policy.
Minor applications receive access enforcement as a service from the General Support System of which they are a part.
If the security plan of a minor application requires auditing of the actions of users with elevated security privileges, those users shall authenticate using multi-factor mechanisms.
Minor applications which contain PII enforce assigned authorizations for controlling access to the system in accordance with applicable policy
Technical Hybrid P1
AC-4 Information Flow Enforcement
AC-4. For data requiring moderate or high confidentiality, the information system shall enforce approved authorizations for controlling the flow of information within the system and between interconnected systems in accordance with applicable policy.
Technical Hybrid P1
AC-5 Separation of Duties AC-5. For data requiring moderate or high confidentiality, the NARA System Owner shall:
AC-5a. Separate [SSP-defined duties of individuals];
AC-5b. Document separation of duties of individuals; and AC-5c. Define information system access authorizations to support separation of duties.
Technical Hybrid P1
AC-6 Least Privilege AC-6. For data requiring moderate or high confidentiality, the NARA System Owner shall employ the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with NARA missions and business functions.
Technical Hybrid P1
AC-6 (1) Authorize Access To Security Functions
AC-6 (1) For data requiring moderate or high confidentiality, the NARA System Owner shall explicitly authorize access to [SSP-defined list of security functions (deployed in hardware, software, and firmware) and security-relevant information].
Technical Hybrid P1
AC-6 (2) Non-Privileged Access For Nonsecurity Functions
AC-6 (2) For data requiring moderate or high confidentiality, the NARA System Owner shall require that users of information system accounts, or roles, with access to [SSP-defined list of security functions or security-relevant information], use non-privileged accounts, or roles, when accessing other system functions, and, if feasible, audits any use of privileged accounts or roles for such functions.
Technical Hybrid P1
AC-6 (5) Privileged Accounts AC-6 (5) For data requiring moderate or high confidentiality, the NARA System Owner shall restrict privileged accounts on the information system to [SPP-defined personnel or roles].
Technical Hybrid P1
AC-6 (9) Auditing Use Of Privileged Functions
AC-6 (9) For data requiring moderate or high confidentiality, the information system shall audit the execution of privileged functions.
Technical Hybrid P1
AC-6 (10) Prohibit Non-Privileged Users From Executing Privileged Functions
AC-6 (10) For data requiring moderate or high confidentiality, the information system shall prevent non-privileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures.
Technical Hybrid P1
AC-7 Unsuccessful Logon Attempts
AC-7. For all data, the information system shall:
AC-7a. Enforce a limit of [a maximum of 5 for unclassified information systems or 3 for classified information systems] consecutive invalid login attempts by a user during a [15 minute period]; and AC-7b. Automatically [lock the account/node for at least 15 minutes for unclassified information systems or 10 minutes for classified information systems] when the maximum number of unsuccessful attempts is exceeded.
Technical Hybrid P2
Page 2 of
Paragraph/ReqI D
Title Requirement Statement Class Type Status Priority Responsible Entities Implementation Estimated Completion
Date
Notes
AC-8 System Use Notification
AC-8. For all data, the information system shall:
AC-8a. Display to users [an approved system use notification message or banner] before granting access to the system that provides privacy and security notices consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance and states that:
Users are accessing a U.S. Government information system;
Information system usage may be monitored, recorded, and subject to audit;
Unauthorized use of the system is prohibited and subject to criminal and civil penalties; and Use of the information system indicates consent to monitoring and recording;
AC-8b. Retain the notification message or banner on the screen until users acknowledge the usage conditions and take explicit actions to log on to or further access the information system; and AC-8c. For publicly accessible systems:
1. Display the system use information when appropriate, before granting further access;
2. Display references, if any, to monitoring, recording, or auditing that are consistent with privacy accommodations for such systems that generally prohibit those activities; and
3. Include a description of the authorized uses of the system.
Technical Hybrid P1
AC-11 Session Lock AC-11. For data requiring moderate or high confidentiality, the information system shall:
AC-11a. Prevent further access to the system by initiating a session lock after [30 minutes] of inactivity or upon receiving a request from a user; and AC-11b. Retain the session lock until the user reestablishes access using established identification and authentication procedures.
Technical Hybrid P3
AC-12 Session Termination AC-12 . For data requiring moderate or high confidentiality, the information system automatically terminates a user session after [SSP-defined conditions or trigger events requiring session disconnect].
Technical Hybrid P2
AC-14 Permitted Actions without Identification or Authentication
AC-14. For all data, the NARA System Owner shall:
AC-14a. Identify [SSP-defined user actions] that can be performed on the information system without identification or authentication consistent with NARA missions/business functions; and AC-14b. Document and provide supporting rationale in the security plan for the information system, user actions not requiring identification and authentication.
Technical System-specific P1
AC-17 Remote Access AC-17. For all data, the NARA Office of Information Services (I) shall:
AC-17a. Establish and document usage restrictions, configuration/connection requirements, and implementation guidance for each type of remote access allowed; and AC-17b. Authorize remote access to the information system prior to allowing such connections.
Technical
AC-18 Wireless Access AC-18. For all data, the NARA Office of Information Services (I) shall:
AC-18a. Establish usage restrictions, configuration/connection requirements, and implementation guidance for wireless access;
AC-18b. Authorize wireless access to the information system prior to connection
Technical
AC-19 Access Control for Mobil Devices
AC-19. For all data, the NARA Office of Information Services (I) shall:
AC-19a. Establish usage restrictions, configuration requirements, and implementation guidance for NARA-controlled mobile devices; and AC-19b. Authorize the connection of mobile devices to NARA information systems
Technical
AC-20 Use of External Information Systems
AC-20. For all data, the NARA Office of Information Services (I) shall establish terms and conditions, consistent with any trust relationships established with other organizations owning, operating, and/or maintaining external information systems, allowing authorized individuals to:
AC-20a. Access the information system from the external information systems; and AC-20b. Process, store
Technical
AC-22 Publicly Accessible Content
AC-22. For all data, the NARA Office of Information Services (I) shall:
AC-22a. Designate individuals authorized to post information onto a publicly accessible information system;
AC-22b. Train authorized individuals to ensure that publicly accessible information does not contain nonpublic information;
AC-22c. Review the proposed content of information prior to posting onto the publicly accessible information system to ensure that nonpublic information is not included; and AC-22d. Review the content on the publicly accessible NARA information system for nonpublic information [annually]; and removes such information, if discovered.
Technical System-specific P2
AU-2 Audit Events AU-2. For all data, the NARA System Owner shall:
AU-2a. Determine that the information system is capable of auditing the following events:
1. Successful and unsuccessful attempts to access, modify, or delete security objects,
2. Successful and unsuccessful logon attempts,
3. Privileged activities or other system level access,
4. Starting and ending time for user access to the system,
5. Concurrent logons from different workstations,
6. Successful and unsuccessful accesses to objects,
7. All program initiations,
8. All direct access to the information system.
AU-2b. Coordinate the security audit function with other NARA entities requiring audit-related information to enhance mutual support and to help guide the selection of auditable events;
AU-2c. Provide a rationale for why the list of auditable events are deemed to be adequate to support after-the-fact investigations of security incidents; and AU-2d. Determine that the following events are to be audited within the information system: [SSP-defined audited events (the subset of the auditable events defined in AU-2 a.) along with the frequency of (or situation requiring) auditing for each identified event]
Technical Hybrid P1
AU-2(3) List of Audible Events Update
AU-2(3) For data requiring moderate or high integrity, the NARA Office of Information Services (I) shall review and update the list of auditable events [annually].
AU-3 Content of Audit Records
AU-3. For all data, the information system shall generate audit records containing information that establishes what type of event occurred, when the event occurred, where the event occurred, the source of the event, the outcome of the event, and the identity of any individuals or subjects associated with the event.
Technical Hybrid P1
AU-3 (1) Additional Audit Information
AU-3(1) For data requiring moderate or high integrity, the information system shall generate audit records containing the following additional information: [Audit record content shall include, for most audit records date and time of the event; the component of the information system (e.g., software component, hardware component) where the event occurred; type of event; subject identity; and the outcome (success or failure) of the event].
Technical Hybrid P1
AU-4 Audit Storage Capacity AU-4. For all data, the NARA Office of Information Services (I) and System Owner shall allocate audit record storage capacity in accordance with [SSP-defined audit storage requirements].
Technical
Page 3 of
Paragraph/ReqI D
Title Requirement Statement Class Type Status Priority Responsible Entities Implementation Estimated Completion
Date
Notes
AU-5 Response to Audit Processing Failures
AU-5. For all data, the information system shall:
AU-5a. Alert designated NARA officials in the event of an audit processing failure; and AU-5b. Take the following additional actions: [For low or moderate integrity information systems, each information system shall overwrite the oldest audit records after an audit processing failure.
Technical Hybrid P1
AU-6 Audit Review, Analys, and Reporting
AU-6. For all data, the NARA Office of Information Services (I) shall:
AU-6a. Review and analyze information system audit records [at least on a weekly basis] for indications of [SSP-defined inappropriate or unusual activity]; and AU-6b. Report findings to [SSP-defined designated NARA officials].
AU-6(1) For data requiring moderate or high integrity, the information system shall integrate audit review, analysis, and reporting processes to support NARA processes for investigation and response to suspicious activities.
AU-6(3) For data requiring moderate or high integrity, the NARA Office of Information Services (I) shall analyze and correlate audit records across different repositories to gain NARA-wide situational awareness.
Technical
AU-7 Audit Reduction and Report Generation
AU-7. For data requiring moderate or high integrity, the information system shall provide an audit reduction and report generation capability that:
AU-7a. Supports on-demand audit review, analysis, and reporting requirements and after-the-fact investigations of security incidents; and AU-7b. Does not alter the original content or time ordering of audit records.
Technical Hybrid P2
AU-7 (1) Automatic Processing AU-7(1) For data requiring moderate or high integrity, the information system shall provide the capability to process audit records for events of interest based [SSP-defined audit fields within audit records].
Technical Hybrid P2
AU-8 Time Stamps AU-8. For all data, the information system shall:
AU-8a. Use internal system clocks to generate time stamps for audit records; and AU-8b. Records time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT) and meets [SSP-defined granularity of time measurement].
Technical Hybrid P1
AU-8 (1) Synchronization With Authoritative Time Source
AU-8(1) For data requiring moderate or high integrity, the information system shall:
(a) Compare the internal information system clocks [at least every 24 hours] with [NARA’s authoritative time source]; and
(b) Synchronize internal information system clocks to the authoritative time source when the time difference is greater than [5 minutes].
Technical Hybrid P1
AU-9 Protection of Audit Information
AU-9. For all data, the information system shall protect audit information and audit tools from unauthorized access, modification, and deletion.
Technical Hybrid P1
AU-9 (4) Access By Subset Of Privileged Users
AU-9(4) For data requiring moderate or high integrity, the NARA Office of Information Services (I) shall authorize access to management of audit functionality to only [a limited subset of NARA-defined privileged users].
Technical Hybrid P1
AU-11 Audit Record Retention
AU-11. For all data, the NARA Office of Information Services (I) shall retain audit records for [a minimum of 1 year for unclassified information, a minimum of 5 years for Sensitive Compartmented Information, a minimum of 5 years for Sources And Methods Intelligence information] to provide support for after-the-fact investigations of security incidents and to meet regulatory and NARA information retention requirements.
Technical Hybrid P3
AU-12 Audit Generation AU-12. For all data, the information system shall:
AU-12a. Provide audit record generation capability for the list of auditable events defined in AU-2a. at [the NARA Office of Information Services (I) SIM];
AU-12b. Allow [designated NARA personnel] to select which auditable events are to be audited by specific components of the information system; and AU-12c. Generate audit records for the list of audited events defined in AU-2d. with the content as defined in AU-3.
Technical Hybrid P1
CM-2 Baseline Configuration CM-2. For all data, the NARA System Owner shall develop, document, and maintain under configuration control, a current baseline configuration of the information system.
Operational
CM-2(1) Baseline Configuration Update review
CM-2(1) For data requiring moderate or high integrity, the NARA System Owner shall review and update the baseline configuration of the information system:
[At least annually.];
When required due to [changes to baseline configuration requiring change control approval and at weekly CCB meetings]; and As an integral part of information system component installations and upgrades.
CM-3 Configuration Change
Control CM-3. For data requiring moderate or high integrity, the NARA System Owner or the system CCB shall:
CM-3a. Determine the types of changes to the information system that are configuration-controlled;
CM-3b. Review proposed configuration-controlled changes to the information system and approve or disapprove such changes with explicit consideration for security impact analyses;
CM-3c. Document configuration change decisions associated with the information system;
CM-3d. Implement approved configuration-controlled changes to the information system;
CM-3e. Retain records of configuration-controlled changes to the information system for [SSP-defined time period];
CM-3f. Audit and review activities associated with configuration-controlled changes to the information system; and CM-3g. Coordinate and provide oversight for configuration change control activities through [Configuration Control Board] that convenes [that convenes weekly and when emergency changes need to be approved for GSS systems and other systems are SSP-defined].
CM-4 Security Impact Analysis
CM-4. For all data, the NARA Change Control Board in consultation with the IT Security Management Division (IS) shall analyze changes to the information system to determine potential security impacts prior to change implementation.
CM-5 Access Restriction for Change
CM-5. For data requiring moderate or high integrity, the NARA System Owner shall define, document, approve, and enforce physical and logical access restrictions associated with changes to the information system
CM-6 Configuration Settings CM-6. For all data, the NARA Office of Information Services (I) shall:
CM-6a. Establish and document configuration settings for information technology products employed within the information system using [Security Architecture security configuration checklists approved and published by IT Security Management Division (IS)] that reflect the most restrictive mode consistent with operational requirements;
CM-6b. Implement the configuration settings;
CM-6c. Identify, document, and approve deviations from the established configuration settings for [individual components within the information system] based on [information system operational requirements]; and CM-6d. Monitor and control changes to the configuration settings in accordance with NARA policies and procedures
Page 4 of
Paragraph/ReqI D
Title Requirement Statement Class Type Status Priority Responsible Entities Implementation Estimated Completion
Date
Notes
CM-7 Least Functionality CM-7. For all data, the NARA System Owner shall:
CM-7a. Configure the information system to provide only essential capabilities; and CM-7b. Prohibit or restrict the use of the following functions, ports, protocols, and/or services: [SSP-defined functions, ports, protocols and/or services].
CM-7(1) Least Functionality Information Review
For data requiring moderate or high integrity, the NARA System Owner shall:
(a) Review the information system [at least annually] to identify and eliminate unnecessary and/or nonsecure functions, ports, protocols, and services; and
(b) Disable [SSP-defined functions, ports, protocols and services within the information system deemed to be unnecessary and/or nonsecure].
CM-7(4) Least Functionality CM-7(4) For data requiring moderate integrity, the NARA information system shall:
(a) Identify [SSP-defined software programs not authorized to execute on the information system];
(b) Employ an allow-all, deny-by-exception policy to prohibit the execution of unauthorized software programs on the information system; and
(c) Review and update the list of unauthorized software programs [at least annually].
CM-8 Information System Component Inventory
CM-8a. Develop and document an inventory of information system components that:
1. Accurately reflects the current information system;
2. Includes all components within the authorization boundary of the information system;
3. Is at the level of granularity deemed necessary for tracking and reporting; and
4. Includes [SSP-defined ports, protocols, and services, IP address, FIPS-rating, etc. (including other columns being added to the Master System List]; and
Operational System-specific P1
CM-8(3) Information System Component Inventory
CM-8(3) For data requiring moderate or high integrity, the NARA information system shall:
(a) Employ automated mechanisms [on a continuous basis] to detect the presence of unauthorized hardware, software, and firmware components within the information system; and
(b) Take the following actions when unauthorized components are detected [disables network access by such components; or notifies [designated NARA officials]].
Operational
CM-8(5) Information System Component Inventory
CM-8(5) For data requiring moderate or high integrity, the NARA System Owner shall verify that all components within the authorization boundary of the information system are either inventoried as a part of the system or recognized by another system as a component within that system.
Operational
CM-9 Configurate Management Plan
CM-9. For data requiring moderate or high integrity, the NARA System Owner shall develop, document, and implement a configuration management plan for the information system that:
CM-9a. Addresses roles, responsibilities, and configuration management processes and procedures;
CM-9b. Establishes a process for identifying configuration items throughout the system development life cycle and for managing the configuration of the configuration items CM-9c. Defines the configuration items for the information system and under configuration management; and CM-9d. Protects the configuration management plan from unauthorized disclosure and modification.
Operational
CM-10 Software Usage Restriction
CM-10. For all data, the NARA System Owner shall:
CM-10a. Use software and associated documentation in accordance with contract agreements and copyright laws;
CM-10b. Track the use of software and associated documentation protected by quantity licenses to control copying and distribution; and CM-10c. Control and document the use of peer-to-peer file sharing technology to ensure that this capability is not used for the unauthorized distribution, display, performance, or reproduction of copyrighted work.
Operational
CM-11 User-Installed Software
CM-11. For all data, the NARA System Owner shall:
CM-11a. Establish [SSP-defined policies] governing the installation of software by users;
CM-11b. Enforce software installation policies through [SSP-defined methods]; and CM-11c. Monitor policy compliance at [SSP-defined frequency].
Operational System-specific P1
CP-2 Contingency Plan CP-2. For all data, the NARA System Owner shall:
CP-2a. Develop a contingency plan for the information system that:
1. Identifies essential missions and business functions and associated contingency requirements;
2. Provides recovery objectives, restoration priorities, and metrics;
3. Addresses contingency roles, responsibilities, assigned individuals with contact information;
4. Addresses maintaining essential missions and business functions despite an information system disruption, compromise, or failure;
5. Addresses eventual, full information system restoration without deterioration of the security measures originally planned and implemented; and
6. Is reviewed and approved by [designated officials within the NARA Security Staff];
CP-2b. Distribute copies of the contingency plan to [SSP-defined list of key contingency personnel and assessment personnel];
CP-2c. Coordinate contingency planning activities with incident handling activities;
CP-2d. Review the contingency plan for the information system [at least yearly];CP-2e. Update the contingency plan to address changes to the NARA organizational chart, information system, or environment of operation and problems encountered during contingency plan implementation, execution, or testing.
CP-2f. Communicate contingency plan changes to [SSP-defined list of key contingency personnel and assessment personnel]; and CP-2g. Protect the contingency plan from unauthorized disclosure and modification
Operational
CP-9 Information System Backup
CP-9. For all data, the NARA System Owner shall:
CP-9a. Conduct backups of user-level information contained in the information system [SSP as per BIA for unclassified information systems or at least weekly for classified information systems];
CP-9b. Conduct backups of system-level information contained in the information system [SSP as per BIA for unclassified information systems or at least weekly for classified information systems];
CP-9c. Conduct backups of information system documentation including security-related documentation [SSP as per BIA or annually at COOP vital records server]; and CP-9d. Protect the confidentiality and integrity of backup information at the storage location.
Operational System-specific P1
CP-10 Information System Recovery and Reconstitution
CP-10. For all data, the NARA System Owner shall provide for the recovery and reconstitution of the information system to a known state after a disruption, compromise, or failure.
Operational System-specific P1
CP-10 (2) Transaction Recovery CP-10(2) For data requiring moderate or high availability, the information system shall implement transaction recovery for systems that are transaction-based.
Operational System-specific P1
Page 5 of
Paragraph/ReqI D
Title Requirement Statement Class Type Status Priority Responsible Entities Implementation Estimated Completion
Date
Notes
IA-2 Identification and Authentication (Organizational Users)
IA-2. For all data, the information system shall uniquely identify and authenticate NARA users (or processes acting on behalf of NARA users).
Technical Hybrid P1
IA-2(1) Identification and Authentication Multifactor Authentication
IA-2(1) For all data, the information system shall implement multifactor authentication for network access to privileged accounts.
IA-3 Device Identification and Authentication
IA-3. For data requiring moderate or high confidentiality, the information system shall uniquely identify and authenticate [SSP-defined list of specific and/or types of devices] before establishing a [local; remote; network] connection.
Technical Hybrid P1
IA-4 Identifier Management IA-4. For all data, the NARA Office of Information Services (I) shall manage information system identifiers by:
IA-4a. Receiving authorization from a designated [NARA official] to assign a user or device identifier;
IA-4b. Selecting an identifier that identifies an individual, group, role or device;
IA-4c. Assigning the user identifier to the intended individual, group, role or the device;
IA-4d. Preventing reuse of identifiers for [at least one year]; and IA-4e. Disabling the identifier after [not to exceed 90 days for unclassified information systems or 30 days for classified information systems].
Technical Hybrid P1
IA-5 Authenticator Management
IA-5. For all data, the NARA Office of Information Services (I) shall manage information system authenticators by:
IA-5a. Verifying, as part of the initial authenticator distribution, the identity of the individual, group, role or device receiving the authenticator;
IA-5b. Establishing initial authenticator content for authenticators defined by the NARA Office of Information Services (I);
IA-5c. Ensuring that authenticators have sufficient strength of mechanism for their intended use;
IA-5d. Establishing and implementing administrative procedures for initial authenticator distribution, for lost/compromised or damaged authenticators, and for revoking authenticators;
IA-5e. Changing default content of authenticators prior to information system installation;
IA-5f. Establishing minimum and maximum lifetime restrictions and reuse conditions for authenticators;
IA-5g. Changing/refreshing authenticators [not to exceed 90 days for unclassified information systems or 180 days for classified information systems];
IA-5h. Protecting authenticator content from unauthorized disclosure and modification;
IA-5i. Requiring individuals to take, and having devices implement, specific security safeguards to protect authenticators; and IA-5j. Changing authenticators for group/role accounts when membership to those accounts changes
Technical Hybrid P1
IA-5 (1) Password-Based Authentication
IA-5(1) For all data, the information system, shall, for password-based authentication:
(a) Enforces minimum password complexity of [a case sensitive, 8-character mix of upper case letters, lower case letters, numbers, and special characters, including at least one of each];
(b) Enforce at least the following number of changed characters when new passwords are created: [four character change];
(c) Stores and transmits only encrypted representations of passwords;
(d) Enforce password minimum and maximum lifetime restrictions of [1 day minimum, 90 day maximum];
(e) Prohibit password reuse for [a minimum of 5 for unclassified information systems or 10 for classified information systems] generations; and
(f) Allows the use of a temporary password for system logons with an immediate change to a permanent password.
Technical Hybrid P1
IA-5 (3) In-Person Or Trusted Third-Party Registration
IA-5(3) For data requiring moderate or high confidentiality, the NARA Office of Information Services (I) shall require that the registration process to receive [user ID and password] be conducted [in person] before [Security Architecture adds: A NARA badge presented to a help desk representative] with authorization by [a designated NARA official (e.g., a supervisor)].
Technical Hybrid P1
IA-6 Authenticator Feedback
IA-6. For all data, the information system shall obscure feedback of authentication information during the authentication process to protect the information from possible exploitation/use by unauthorized individuals.
Technical Hybrid P1
IA-7 Cryptographic Module Authentication
IA-7. For all data, the information system shall implement mechanisms for authentication to a cryptographic module that meet the requirements of applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance for such authentication.
Technical Hybrid P1
IA-8 Identification and Authorization (non- Nara users)
IA-8. For all data, the information system shall uniquely identify and authenticates non-NARA users (or processes acting on behalf of non- NARA users).
IA-8(1) Identification and Authorization (non- Nara users)
IA-8(1) For all data, the information system shall accept and electronically verify Personal Identity Verification (PIV) credentials from other federal agencies.
IA8(2) Identification and Authorization (non- Nara users)
IA-8(2) For all data, the information system shall accept only FICAM-approved third-party credentials.
SA-5 Information System Documentation
SA-5. For all data, the NARA System Owner shall:
SA-5a. Obtain administrator documentation for the information system, system component, or information system service that describes:
1. Secure configuration, installation, and operation of the information system;
2. Effective use and maintenance of security features/functions; and
3. Known vulnerabilities regarding configuration and use of administrative (i.e., privileged) functions; and SA-5b. Obtain user documentation for the information system, system component, or information system service that describes:
1. User-accessible security features/functions and how to effectively use those security features/functions;
2. Methods for user interaction, which enables individuals to use the system, components, or service in a more secure manner; and
3. User responsibilities in maintaining the security of the system, component, or service;
SA-5c. Document attempts to obtain information system , system component, or information system service documentation when such documentation is either unavailable or nonexistent and [SSP-defined actions] in response;
SA-5d. Protect documentation as required, in accordance with the risk management strategy; and SA-5e. Distribute documentation to [SSP-defined personnel or roles].
Management Hybrid P2
SA-8 Security Engineering Principles
SA-8. For data requiring moderate or high integrity, the NARA System Owner shall apply information system security engineering principles in the specification, design, development, implementation, and modification of the information system.
Management Hybrid P1
Page 6 of
Paragraph/ReqI D
Title Requirement Statement Class Type Status Priority Responsible Entities Implementation Estimated Completion
Date
Notes
SA-9 External Information System Services
SA-9. For all data, the NARA System Owner shall:
SA-9a. Require that providers of external information system services comply with NARA information security requirements and employ [SSP-defined security controls] in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance;
SA-9b. Define and document government oversight and user roles and responsibilities with regard to external information system services;
and SA-9c. Employ (SSP-defined processes, methods, and techniques] to monitor security control compliance by external service providers on an ongoing basis.
Management
SA-9(2) External Information System Services (identification of functions, ports, protocols
SA-9(2) For data requiring moderate or high integrity, the NARA System Owner shall require providers of [SSP-defined external information system services] to identify the functions, ports, protocols, and other services required for the use of such services
SA-10 Developer Configuration Management
SA-10. For data requiring moderate or high integrity, the NARA System Owner shall require that information system developers of the information system, system component, or information system service to:
SA-10a. Perform configuration management during system, component, or service [design; development; implementation;
operation];
SA-10b. Document, manage, and control the integrity of changes to [SSP-defined configuration items under configuration management];
SA-10c. Implement only SSP-approved changes to the system, component, or service;
SA-10d. Document approved changes to the system, component, or service and the potential security impacts of such changes; and SA-10e. Track security flaws and flaw resolution within the system, component, or service and report findings to [SSP-defined personnel].
SA-11 Developer Security Testing
SA-11. For data requiring moderate or high integrity, the NARA System Owner shall require that information system developers/integrators, in consultation with associated security personnel (including security engineers):
SA-11a. Create and implement a security assessment plan;SecA.
Requirements.docx 106 March 22, 2017 SA-11b. Perform [unit; integration; system; or regression] testing/evaluation at [SSP-defined depth and coverage];
SA-11c. Produce evidence of the execution of the security assessment plan and the results of the security testing/evaluation;
SA-11d. Implement a verifiable flaw remediation process; and SA-11e. Correct flaws identified during security testing/evaluation.
SC-2 Application Partitioning SC-2. For data requiring moderate or high confidentiality, the information system shall separate user functionality (including user interface services) from information system management functionality.
Technical System-specific P1
SC-4 Information in Shared Resources
SC-4. For data requiring moderate or high confidentiality, the information system shall prevent unauthorized and unintended information transfer via shared system resources.
Technical Hybrid P1
SC-5 Denial of Service Protection
SC-5. For all data, the information system shall protect against or limit the effects of the following types of denial of service attacks: [Denial of service attacks identified in US CERT advisories] by employing [SSP-defined security safeguards].
Technical Hybrid P1
SC-7 Boundary Protection SC-7. For all data, the information system shall:
SC-7a. Monitor and control communications at the external boundary of the system and at key internal boundaries within the system;
SC-7b. Implement subnetworks for publicly accessible system components that are [physically] separated from internal organizational networks; and SC-7c. Connect to external networks or information systems only through managed interfaces consisting of boundary protection devices arranged in accordance with the NARA security architecture.
Technical
SC-7(3) Boundary Protection limit number of external connections
SC-7(3) For data requiring moderate or high integrity, the NARA Office of Information Services (I) shall limit the number of external network connections to the information system.
SC-7(4) Boundary Protection limit number of external connections
SC-7(4) For data requiring moderate or high integrity, the NARA Office of Information Services (I) shall:
(a) Implement a managed interface for each external telecommunication service;
(b) Establish a traffic flow policy for each managed interface;
(c) Protect the confidentiality and integrity of the information being transmitted across each interface;
(d) Document each exception to the traffic flow policy with a supporting mission/business need and duration of that need; and
(e) Review exceptions to the traffic flow policy [SSP-defined frequency POA&M review process and frequency].
SC-7(5) Boundary Protection (deny by exeption)
SC-7(5) For data requiring moderate or high integrity, the information system at managed interfaces, shall deny network communications traffic by default and allows network communications traffic by exception (i.e., deny all, permit by exception).
SC-7(7) Boundary Protection SC-7(7) For data requiring moderate or high integrity, the information system shall in conjunction with a remote device, prevents the device from simultaneously establishing non-remote connections with the system and communicating via some other connection to resources in external networks.
SC-8 Transmission Confidentiality and Integrity
SC-8. For data requiring moderate or high confidentiality and/or integrity, the information system shall protect the [confidentiality and integrity] of transmitted information.
Technical System-specific P1
SC-8 (1) Cryptographic Or Alternate Physical Protection
SC-8(1) For data requiring moderate or high confidentiality and/or integrity, the NARA Office of Information Services (I) shall employ cryptographic mechanisms to [detect changes to information] during transmission unless otherwise protected by [SSP-defined alternative physical safeguards].
Technical System-specific P1
SC-10 Network Disconnect SC-10. For data requiring moderate or high confidentiality, the information system shall terminate the network connection associated with a communications session at the end of the session or after [no more than 15 minutes for unclassified information systems or no more than 48 hours for classified information systems] of inactivity.
Technical Hybrid P2
SC-12 Cryptographic Key Establishment and Management
SC-12. For all data, the NARA Office of Information Services (I) shall establish and manage cryptographic keys for required cryptography employed within the information system in accordance with [NARA-defined requirements for generation, distribution, storage, access, and destruction].
Technical System-specific P1
SC-13 Cryptographic Protection
SC-13. For all data, the information system shall implement [SSP-defined cryptographic uses and type of cryptography required for each use] in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.
Technical System-specific P1
SC-15 Collaborative Computing Devices
SC-15. For all data, the information system shall:
SC-15a. Prohibit remote activation of collaborative computing devices with the following exceptions: [SSP-defined exceptions where remote activation is to be allowed]; and SC-15b. Provide an explicit indication of use to users physically present at the devices.
Technical System-specific P1
SC-17 Public Key Certificate SC-17. For data requiring moderate or high confidentiality or integrity, the NARA Office of Information Services (I) shall issue public key certificates under a [NARA certificate policy] or shall obtain public key certificates from an approved service provider.
Page 7 of
Paragraph/ReqI D
Title Requirement Statement Class Type Status Priority Responsible Entities Implementation Estimated Completion
Date
Notes
SC-18 Mobile Code SC-18. For data requiring moderate or high confidentiality, the NARA System Owner shall:
SC-18a. Define acceptable and unacceptable mobile code and mobile code technologies;
SC-18b. Establish usage restrictions and implementation guidance for acceptable mobile code and mobile code technologies; and SC-18c. Authorize, monitor, and control the use of mobile code within the information system.
Technical System-specific P2
SC-23 Session Authentication SC-23. For data requiring moderate or high integrity, the information system shall protect the authenticity of communications sessions.
Technical
SC-28 Protection of Information at Rest
SC-28. For data requiring moderate or high confidentiality or integrity, the information system shall protect the [confidentiality and integrity] of [SSP-defined information at rest].
Technical System-specific P1
SC-28(1) Protection of Information at Rest
SC-28(1) For data requiring moderate or high confidentiality or integrity protection, the NARA Office of Information Services (I) shall implement cryptographic mechanisms to prevent unauthorized disclosure and modification of [SSP-defined information at rest unless otherwise protected by alternative physical measures].SC
SC-32 Information System Partitioning
SC-32. For data requiring moderate or high confidentiality or integrity, the NARA System Owner shall partition the information system into [SSP-defined components] residing in separate physical domains or environments based on [SSP-defined circumstances for physical separation of components].
SC-39 Process Isolation SC-39. For all data, the NARA System Owner shall maintain a separate execution domain for each executing process.
Technical System-specific P1
SI-2 Flaw Remediation SI-2. For all data, the NARA Office of Information Services (I) shall:
SI-2a. Identify, report, and correct information system flaws;
SI-2b. Test software updates related to flaw remediation for effectiveness and potential side effects on NARA information systems before installation;
SI-2c. Installs security-relevant software and firmware updates within [Define timeframes of critical(30 days), high(30 days), medium and low (60 days) vulnerabilities or stricter SSP-defined time period] of the release of the updates; and SI-2d. Incorporate flaw remediation into the NARA configuration management process.
Operational
SI-2(2) Flaw Reemediation SI-2(2) For data requiring moderate or high integrity, the NARA information system shall employ automated mechanisms [SSP-defined frequency] to determine the state of information system components with regard to flaw remediation.
SI-3 Malicious Code Protection
SI-3. For all data, the NARA Office of Information Services (I) shall:
SI-3a. Employ malicious code protection mechanisms at information system entry and exit points to detect and eradicate malicious code:
• Transported by electronic mail, electronic mail attachments, web accesses, removable media, or other common means; or
• Inserted through the exploitation of information system vulnerabilities;
SI-3b. Update malicious code protection mechanisms (including signature definitions) whenever new releases are available in accordance with NARA configuration management policy and procedures;
SI-3c. Configure malicious code protection mechanisms to:
1. Perform periodic scans of the information system [SSP-defined frequency] and real-time scans of files from external sources at [endpoint] as the files are downloaded, opened, or executed in accordance with NARA security policy; and
2. [block malicious code; quarantine malicious code; send alert to administrator] in response to malicious code detection; and SI-3d. Address the receipt of false positives during malicious code detection and eradication and the resulting potential impact on the availability of the information system.
SI-3(1) Malicious Code Protection
SI-3(1) For data requiring moderate or high integrity, the NARA Office of Information Services (I) shall centrally manage malicious code protection mechanisms.
SI-3(2) Malicious Code Protection
SI-3(2) For data requiring moderate or high integrity, the information system shall automatically update malicious code protection mechanisms
SI-4 Information System Monitoring
SI-4. For all data, the NARA Office of Information Services (I) shall:
SI-4a. Monitors the information system to detect:
1. Attacks and indicators of potential attacks in accordance with [SSP-defined monitoring objectives]; and
2. Unauthorized local, network, and remote connections;
SI-4b. Identify unauthorized use of the information system through [SSP-defined techniques and methods];
SI-4c. Deploy monitoring devices: (i) strategically within the information system to collect organization-determined essential information; and (ii) at ad hoc locations within the system to track specific types of transactions of interest to the organization;
SI-4d. Protect information obtained from intrusion-monitoring tools from unauthorized access, modification, and deletion;
SI-4e. Heighten the level of information system monitoring activity whenever there is an indication of increased risk to NARA operations and assets, individuals, other organizations, or the Nation based on law enforcement information, intelligence information, or other credible sources of information; and SI-4f. Obtain legal opinion with regard to information system monitoring activities in accordance with applicable federal laws, Executive Orders, directives, policies, or regulations.
SI-4g. Provide [SSP-defined information system monitoring information] to [SSP-defined personnel] [as needed; and [SSP-defined frequency]].
SI-4(2) Information System Monitoring
SI-4(2) For data requiring moderate or high integrity, the NARA Office of Information Services (I) shall employ automated tools to support near real-time analysis of events.
SI-4(4) Information System Monitoring
SI-4(4) For data requiring moderate or high integrity, the information system shall monitor inbound and outbound communications traffic [SSP-defined frequency] for unusual or unauthorized activities or conditions.
SI-4(5) Information System Monitoring
SI-4(5) For data requiring moderate or high integrity, the information system shall alert [SSP-defined list of incident response personnel (identified by name and/or by role), and NARA IT HELP] when the following indications of compromise or potential compromise occur:
[SSP-defined compromise indicators].
SI-5 Security Alerts SI-5. For all data, the IT Security Management Division (IS) shall:
SI-5a. Receive information system security alerts, advisories, and…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .