Appendix E - System Security Plan Requirements.pdf

PDF 98 KB Posted

Attached to
Agency Digital Asset Management System Federal contract opportunity
Solicitation number
88310321Q00056
Issued by
National Archives and Records Administration

View the file

Other files for this federal contract opportunity

Other files attached to Agency Digital Asset Management System, newest first.
File Type Posted
Amendment 002.docx DOCX document
Appendix B - Contingency Plan Template.pdf PDF
Appendix F - Configuration Management Database (CMDB) Template.pdf PDF
Appendix C - Incident Response Plan Template.pdf PDF
88310321Q00056 ADAMS.docx DOCX document
Appendix D - Quality_Assurance_Cloud_CMDB_Template.xlsx XLSX spreadsheet
Appendix G - Interface Control Document (ICD) Template.pdf PDF
Amendment 001 Extension.docx DOCX document
88310321Q00056 ADAMS.pdf PDF
Volume 1 Requirements Matrix.xlsx XLSX spreadsheet
Appendix A - IT Security Requirements.pdf PDF
Show all 11

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SSP System Application Level Controls.xlsx Project: Physical Access Control System

Page 1 of

Paragraph/ReqI D

Title Requirement Statement Class Type Status Priority Responsible Entities Implementation Estimated Completion

Date

Notes

AC-2 Account Management AC-2. For all data, the NARA System Owner shall:

AC-2a. Identify account types (i.e., individual, group, system, application, guest/anonymous, and temporary);

AC-2b. Assign account managers for information system accounts;

AC-2c. Establish conditions for group and role membership;

AC-2d. Specify authorized users of the information system, group and role membership, and access authorizations (i.e., privileges) and other attributes (as required) for each account;

AC-2e. Require approvals by ISSO and system owner for requests to create information system accounts;

AC-2f. Create, enable, modify, disable, and remove information system accounts in accordance with NARA 804, Information Technology (IT) Systems Security;

AC-2g. Monitor the use of, information system accounts;

AC-2h. Notify account managers:

1. When accounts are no longer required;

2. When users are terminated or transferred; and

3. When individual information system usage or need-to-know changes;

AC-2i. Authorize access to the information system based on:

1. A valid access authorization;

2. Intended system usage; and

3. Other attributes as required by the system functions;

AC-2j. Review accounts compliance with account management requirements [at least annually].

AC-2k. Establish a process for reissuing shared/group account credentials (if deployed) when individuals are removed from the group.

Technical Hybrid P1

AC-2 (1) Automated System Account Management

AC-2(1) For data requiring moderate or high confidentiality, the NARA System Owner shall employ automated mechanisms to support the management of information system accounts.

Technical Hybrid P1

AC-2 (2) Removal Of Temporary / Emergency Accounts

AC-2(2) For data requiring moderate or high confidentiality, the information system shall automatically disable temporary and emergency accounts after [a period not to exceed 15 days for unclassified information systems or 72 hours for classified information systems].

Technical Hybrid P1

AC-2 (3) Disable Inactive Accounts

AC-2(3) For data requiring moderate or high confidentiality, the information system shall automatically disable inactive accounts after [a period not to exceed 365 days for unclassified information systems or 30 days for classified information systems].

Technical Hybrid P1

AC-2 (4) Automated Audit Actions

AC-2(4) For data requiring moderate or high confidentiality, the information system shall automatically audit account creation, modification, disabling, and removal actions and shall notify, as required, appropriate individuals.

Technical Hybrid P1

AC-3 Access Enforcement AC-3. For all data, the information system shall enforce approved authorizations for logical access to the system and system resources in accordance with NARA applicable access control policy.

The NARAnet GSS shall provide multifactor access control as a common control for remote and local access to the network. The authentication capability shall be available to externally hosted systems which restrict access to NARA account holders.

Multifactor access mechanisms shall include credentials from HSPD 12 compliant PIV cards.

Users with elevated security privileges shall access the system using a multi factor authentication mechanism that complies with applicable federal directives and NARA policy.

Minor applications receive access enforcement as a service from the General Support System of which they are a part.

If the security plan of a minor application requires auditing of the actions of users with elevated security privileges, those users shall authenticate using multi-factor mechanisms.

Minor applications which contain PII enforce assigned authorizations for controlling access to the system in accordance with applicable policy

Technical Hybrid P1

AC-4 Information Flow Enforcement

AC-4. For data requiring moderate or high confidentiality, the information system shall enforce approved authorizations for controlling the flow of information within the system and between interconnected systems in accordance with applicable policy.

Technical Hybrid P1

AC-5 Separation of Duties AC-5. For data requiring moderate or high confidentiality, the NARA System Owner shall:

AC-5a. Separate [SSP-defined duties of individuals];

AC-5b. Document separation of duties of individuals; and AC-5c. Define information system access authorizations to support separation of duties.

Technical Hybrid P1

AC-6 Least Privilege AC-6. For data requiring moderate or high confidentiality, the NARA System Owner shall employ the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with NARA missions and business functions.

Technical Hybrid P1

AC-6 (1) Authorize Access To Security Functions

AC-6 (1) For data requiring moderate or high confidentiality, the NARA System Owner shall explicitly authorize access to [SSP-defined list of security functions (deployed in hardware, software, and firmware) and security-relevant information].

Technical Hybrid P1

AC-6 (2) Non-Privileged Access For Nonsecurity Functions

AC-6 (2) For data requiring moderate or high confidentiality, the NARA System Owner shall require that users of information system accounts, or roles, with access to [SSP-defined list of security functions or security-relevant information], use non-privileged accounts, or roles, when accessing other system functions, and, if feasible, audits any use of privileged accounts or roles for such functions.

Technical Hybrid P1

AC-6 (5) Privileged Accounts AC-6 (5) For data requiring moderate or high confidentiality, the NARA System Owner shall restrict privileged accounts on the information system to [SPP-defined personnel or roles].

Technical Hybrid P1

AC-6 (9) Auditing Use Of Privileged Functions

AC-6 (9) For data requiring moderate or high confidentiality, the information system shall audit the execution of privileged functions.

Technical Hybrid P1

AC-6 (10) Prohibit Non-Privileged Users From Executing Privileged Functions

AC-6 (10) For data requiring moderate or high confidentiality, the information system shall prevent non-privileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures.

Technical Hybrid P1

AC-7 Unsuccessful Logon Attempts

AC-7. For all data, the information system shall:

AC-7a. Enforce a limit of [a maximum of 5 for unclassified information systems or 3 for classified information systems] consecutive invalid login attempts by a user during a [15 minute period]; and AC-7b. Automatically [lock the account/node for at least 15 minutes for unclassified information systems or 10 minutes for classified information systems] when the maximum number of unsuccessful attempts is exceeded.

Technical Hybrid P2

Page 2 of

Paragraph/ReqI D

Title Requirement Statement Class Type Status Priority Responsible Entities Implementation Estimated Completion

Date

Notes

AC-8 System Use Notification

AC-8. For all data, the information system shall:

AC-8a. Display to users [an approved system use notification message or banner] before granting access to the system that provides privacy and security notices consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance and states that:

Users are accessing a U.S. Government information system;

Information system usage may be monitored, recorded, and subject to audit;

Unauthorized use of the system is prohibited and subject to criminal and civil penalties; and Use of the information system indicates consent to monitoring and recording;

AC-8b. Retain the notification message or banner on the screen until users acknowledge the usage conditions and take explicit actions to log on to or further access the information system; and AC-8c. For publicly accessible systems:

1. Display the system use information when appropriate, before granting further access;

2. Display references, if any, to monitoring, recording, or auditing that are consistent with privacy accommodations for such systems that generally prohibit those activities; and

3. Include a description of the authorized uses of the system.

Technical Hybrid P1

AC-11 Session Lock AC-11. For data requiring moderate or high confidentiality, the information system shall:

AC-11a. Prevent further access to the system by initiating a session lock after [30 minutes] of inactivity or upon receiving a request from a user; and AC-11b. Retain the session lock until the user reestablishes access using established identification and authentication procedures.

Technical Hybrid P3

AC-12 Session Termination AC-12 . For data requiring moderate or high confidentiality, the information system automatically terminates a user session after [SSP-defined conditions or trigger events requiring session disconnect].

Technical Hybrid P2

AC-14 Permitted Actions without Identification or Authentication

AC-14. For all data, the NARA System Owner shall:

AC-14a. Identify [SSP-defined user actions] that can be performed on the information system without identification or authentication consistent with NARA missions/business functions; and AC-14b. Document and provide supporting rationale in the security plan for the information system, user actions not requiring identification and authentication.

Technical System-specific P1

AC-17 Remote Access AC-17. For all data, the NARA Office of Information Services (I) shall:

AC-17a. Establish and document usage restrictions, configuration/connection requirements, and implementation guidance for each type of remote access allowed; and AC-17b. Authorize remote access to the information system prior to allowing such connections.

Technical

AC-18 Wireless Access AC-18. For all data, the NARA Office of Information Services (I) shall:

AC-18a. Establish usage restrictions, configuration/connection requirements, and implementation guidance for wireless access;

AC-18b. Authorize wireless access to the information system prior to connection

Technical

AC-19 Access Control for Mobil Devices

AC-19. For all data, the NARA Office of Information Services (I) shall:

AC-19a. Establish usage restrictions, configuration requirements, and implementation guidance for NARA-controlled mobile devices; and AC-19b. Authorize the connection of mobile devices to NARA information systems

Technical

AC-20 Use of External Information Systems

AC-20. For all data, the NARA Office of Information Services (I) shall establish terms and conditions, consistent with any trust relationships established with other organizations owning, operating, and/or maintaining external information systems, allowing authorized individuals to:

AC-20a. Access the information system from the external information systems; and AC-20b. Process, store

Technical

AC-22 Publicly Accessible Content

AC-22. For all data, the NARA Office of Information Services (I) shall:

AC-22a. Designate individuals authorized to post information onto a publicly accessible information system;

AC-22b. Train authorized individuals to ensure that publicly accessible information does not contain nonpublic information;

AC-22c. Review the proposed content of information prior to posting onto the publicly accessible information system to ensure that nonpublic information is not included; and AC-22d. Review the content on the publicly accessible NARA information system for nonpublic information [annually]; and removes such information, if discovered.

Technical System-specific P2

AU-2 Audit Events AU-2. For all data, the NARA System Owner shall:

AU-2a. Determine that the information system is capable of auditing the following events:

1. Successful and unsuccessful attempts to access, modify, or delete security objects,

2. Successful and unsuccessful logon attempts,

3. Privileged activities or other system level access,

4. Starting and ending time for user access to the system,

5. Concurrent logons from different workstations,

6. Successful and unsuccessful accesses to objects,

7. All program initiations,

8. All direct access to the information system.

AU-2b. Coordinate the security audit function with other NARA entities requiring audit-related information to enhance mutual support and to help guide the selection of auditable events;

AU-2c. Provide a rationale for why the list of auditable events are deemed to be adequate to support after-the-fact investigations of security incidents; and AU-2d. Determine that the following events are to be audited within the information system: [SSP-defined audited events (the subset of the auditable events defined in AU-2 a.) along with the frequency of (or situation requiring) auditing for each identified event]

Technical Hybrid P1

AU-2(3) List of Audible Events Update

AU-2(3) For data requiring moderate or high integrity, the NARA Office of Information Services (I) shall review and update the list of auditable events [annually].

AU-3 Content of Audit Records

AU-3. For all data, the information system shall generate audit records containing information that establishes what type of event occurred, when the event occurred, where the event occurred, the source of the event, the outcome of the event, and the identity of any individuals or subjects associated with the event.

Technical Hybrid P1

AU-3 (1) Additional Audit Information

AU-3(1) For data requiring moderate or high integrity, the information system shall generate audit records containing the following additional information: [Audit record content shall include, for most audit records date and time of the event; the component of the information system (e.g., software component, hardware component) where the event occurred; type of event; subject identity; and the outcome (success or failure) of the event].

Technical Hybrid P1

AU-4 Audit Storage Capacity AU-4. For all data, the NARA Office of Information Services (I) and System Owner shall allocate audit record storage capacity in accordance with [SSP-defined audit storage requirements].

Technical

Page 3 of

Paragraph/ReqI D

Title Requirement Statement Class Type Status Priority Responsible Entities Implementation Estimated Completion

Date

Notes

AU-5 Response to Audit Processing Failures

AU-5. For all data, the information system shall:

AU-5a. Alert designated NARA officials in the event of an audit processing failure; and AU-5b. Take the following additional actions: [For low or moderate integrity information systems, each information system shall overwrite the oldest audit records after an audit processing failure.

Technical Hybrid P1

AU-6 Audit Review, Analys, and Reporting

AU-6. For all data, the NARA Office of Information Services (I) shall:

AU-6a. Review and analyze information system audit records [at least on a weekly basis] for indications of [SSP-defined inappropriate or unusual activity]; and AU-6b. Report findings to [SSP-defined designated NARA officials].

AU-6(1) For data requiring moderate or high integrity, the information system shall integrate audit review, analysis, and reporting processes to support NARA processes for investigation and response to suspicious activities.

AU-6(3) For data requiring moderate or high integrity, the NARA Office of Information Services (I) shall analyze and correlate audit records across different repositories to gain NARA-wide situational awareness.

Technical

AU-7 Audit Reduction and Report Generation

AU-7. For data requiring moderate or high integrity, the information system shall provide an audit reduction and report generation capability that:

AU-7a. Supports on-demand audit review, analysis, and reporting requirements and after-the-fact investigations of security incidents; and AU-7b. Does not alter the original content or time ordering of audit records.

Technical Hybrid P2

AU-7 (1) Automatic Processing AU-7(1) For data requiring moderate or high integrity, the information system shall provide the capability to process audit records for events of interest based [SSP-defined audit fields within audit records].

Technical Hybrid P2

AU-8 Time Stamps AU-8. For all data, the information system shall:

AU-8a. Use internal system clocks to generate time stamps for audit records; and AU-8b. Records time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT) and meets [SSP-defined granularity of time measurement].

Technical Hybrid P1

AU-8 (1) Synchronization With Authoritative Time Source

AU-8(1) For data requiring moderate or high integrity, the information system shall:

(a) Compare the internal information system clocks [at least every 24 hours] with [NARA’s authoritative time source]; and

(b) Synchronize internal information system clocks to the authoritative time source when the time difference is greater than [5 minutes].

Technical Hybrid P1

AU-9 Protection of Audit Information

AU-9. For all data, the information system shall protect audit information and audit tools from unauthorized access, modification, and deletion.

Technical Hybrid P1

AU-9 (4) Access By Subset Of Privileged Users

AU-9(4) For data requiring moderate or high integrity, the NARA Office of Information Services (I) shall authorize access to management of audit functionality to only [a limited subset of NARA-defined privileged users].

Technical Hybrid P1

AU-11 Audit Record Retention

AU-11. For all data, the NARA Office of Information Services (I) shall retain audit records for [a minimum of 1 year for unclassified information, a minimum of 5 years for Sensitive Compartmented Information, a minimum of 5 years for Sources And Methods Intelligence information] to provide support for after-the-fact investigations of security incidents and to meet regulatory and NARA information retention requirements.

Technical Hybrid P3

AU-12 Audit Generation AU-12. For all data, the information system shall:

AU-12a. Provide audit record generation capability for the list of auditable events defined in AU-2a. at [the NARA Office of Information Services (I) SIM];

AU-12b. Allow [designated NARA personnel] to select which auditable events are to be audited by specific components of the information system; and AU-12c. Generate audit records for the list of audited events defined in AU-2d. with the content as defined in AU-3.

Technical Hybrid P1

CM-2 Baseline Configuration CM-2. For all data, the NARA System Owner shall develop, document, and maintain under configuration control, a current baseline configuration of the information system.

Operational

CM-2(1) Baseline Configuration Update review

CM-2(1) For data requiring moderate or high integrity, the NARA System Owner shall review and update the baseline configuration of the information system:

[At least annually.];

When required due to [changes to baseline configuration requiring change control approval and at weekly CCB meetings]; and As an integral part of information system component installations and upgrades.

CM-3 Configuration Change

Control CM-3. For data requiring moderate or high integrity, the NARA System Owner or the system CCB shall:

CM-3a. Determine the types of changes to the information system that are configuration-controlled;

CM-3b. Review proposed configuration-controlled changes to the information system and approve or disapprove such changes with explicit consideration for security impact analyses;

CM-3c. Document configuration change decisions associated with the information system;

CM-3d. Implement approved configuration-controlled changes to the information system;

CM-3e. Retain records of configuration-controlled changes to the information system for [SSP-defined time period];

CM-3f. Audit and review activities associated with configuration-controlled changes to the information system; and CM-3g. Coordinate and provide oversight for configuration change control activities through [Configuration Control Board] that convenes [that convenes weekly and when emergency changes need to be approved for GSS systems and other systems are SSP-defined].

CM-4 Security Impact Analysis

CM-4. For all data, the NARA Change Control Board in consultation with the IT Security Management Division (IS) shall analyze changes to the information system to determine potential security impacts prior to change implementation.

CM-5 Access Restriction for Change

CM-5. For data requiring moderate or high integrity, the NARA System Owner shall define, document, approve, and enforce physical and logical access restrictions associated with changes to the information system

CM-6 Configuration Settings CM-6. For all data, the NARA Office of Information Services (I) shall:

CM-6a. Establish and document configuration settings for information technology products employed within the information system using [Security Architecture security configuration checklists approved and published by IT Security Management Division (IS)] that reflect the most restrictive mode consistent with operational requirements;

CM-6b. Implement the configuration settings;

CM-6c. Identify, document, and approve deviations from the established configuration settings for [individual components within the information system] based on [information system operational requirements]; and CM-6d. Monitor and control changes to the configuration settings in accordance with NARA policies and procedures

Page 4 of

Paragraph/ReqI D

Title Requirement Statement Class Type Status Priority Responsible Entities Implementation Estimated Completion

Date

Notes

CM-7 Least Functionality CM-7. For all data, the NARA System Owner shall:

CM-7a. Configure the information system to provide only essential capabilities; and CM-7b. Prohibit or restrict the use of the following functions, ports, protocols, and/or services: [SSP-defined functions, ports, protocols and/or services].

CM-7(1) Least Functionality Information Review

For data requiring moderate or high integrity, the NARA System Owner shall:

(a) Review the information system [at least annually] to identify and eliminate unnecessary and/or nonsecure functions, ports, protocols, and services; and

(b) Disable [SSP-defined functions, ports, protocols and services within the information system deemed to be unnecessary and/or nonsecure].

CM-7(4) Least Functionality CM-7(4) For data requiring moderate integrity, the NARA information system shall:

(a) Identify [SSP-defined software programs not authorized to execute on the information system];

(b) Employ an allow-all, deny-by-exception policy to prohibit the execution of unauthorized software programs on the information system; and

(c) Review and update the list of unauthorized software programs [at least annually].

CM-8 Information System Component Inventory

CM-8a. Develop and document an inventory of information system components that:

1. Accurately reflects the current information system;

2. Includes all components within the authorization boundary of the information system;

3. Is at the level of granularity deemed necessary for tracking and reporting; and

4. Includes [SSP-defined ports, protocols, and services, IP address, FIPS-rating, etc. (including other columns being added to the Master System List]; and

Operational System-specific P1

CM-8(3) Information System Component Inventory

CM-8(3) For data requiring moderate or high integrity, the NARA information system shall:

(a) Employ automated mechanisms [on a continuous basis] to detect the presence of unauthorized hardware, software, and firmware components within the information system; and

(b) Take the following actions when unauthorized components are detected [disables network access by such components; or notifies [designated NARA officials]].

Operational

CM-8(5) Information System Component Inventory

CM-8(5) For data requiring moderate or high integrity, the NARA System Owner shall verify that all components within the authorization boundary of the information system are either inventoried as a part of the system or recognized by another system as a component within that system.

Operational

CM-9 Configurate Management Plan

CM-9. For data requiring moderate or high integrity, the NARA System Owner shall develop, document, and implement a configuration management plan for the information system that:

CM-9a. Addresses roles, responsibilities, and configuration management processes and procedures;

CM-9b. Establishes a process for identifying configuration items throughout the system development life cycle and for managing the configuration of the configuration items CM-9c. Defines the configuration items for the information system and under configuration management; and CM-9d. Protects the configuration management plan from unauthorized disclosure and modification.

Operational

CM-10 Software Usage Restriction

CM-10. For all data, the NARA System Owner shall:

CM-10a. Use software and associated documentation in accordance with contract agreements and copyright laws;

CM-10b. Track the use of software and associated documentation protected by quantity licenses to control copying and distribution; and CM-10c. Control and document the use of peer-to-peer file sharing technology to ensure that this capability is not used for the unauthorized distribution, display, performance, or reproduction of copyrighted work.

Operational

CM-11 User-Installed Software

CM-11. For all data, the NARA System Owner shall:

CM-11a. Establish [SSP-defined policies] governing the installation of software by users;

CM-11b. Enforce software installation policies through [SSP-defined methods]; and CM-11c. Monitor policy compliance at [SSP-defined frequency].

Operational System-specific P1

CP-2 Contingency Plan CP-2. For all data, the NARA System Owner shall:

CP-2a. Develop a contingency plan for the information system that:

1. Identifies essential missions and business functions and associated contingency requirements;

2. Provides recovery objectives, restoration priorities, and metrics;

3. Addresses contingency roles, responsibilities, assigned individuals with contact information;

4. Addresses maintaining essential missions and business functions despite an information system disruption, compromise, or failure;

5. Addresses eventual, full information system restoration without deterioration of the security measures originally planned and implemented; and

6. Is reviewed and approved by [designated officials within the NARA Security Staff];

CP-2b. Distribute copies of the contingency plan to [SSP-defined list of key contingency personnel and assessment personnel];

CP-2c. Coordinate contingency planning activities with incident handling activities;

CP-2d. Review the contingency plan for the information system [at least yearly];CP-2e. Update the contingency plan to address changes to the NARA organizational chart, information system, or environment of operation and problems encountered during contingency plan implementation, execution, or testing.

CP-2f. Communicate contingency plan changes to [SSP-defined list of key contingency personnel and assessment personnel]; and CP-2g. Protect the contingency plan from unauthorized disclosure and modification

Operational

CP-9 Information System Backup

CP-9. For all data, the NARA System Owner shall:

CP-9a. Conduct backups of user-level information contained in the information system [SSP as per BIA for unclassified information systems or at least weekly for classified information systems];

CP-9b. Conduct backups of system-level information contained in the information system [SSP as per BIA for unclassified information systems or at least weekly for classified information systems];

CP-9c. Conduct backups of information system documentation including security-related documentation [SSP as per BIA or annually at COOP vital records server]; and CP-9d. Protect the confidentiality and integrity of backup information at the storage location.

Operational System-specific P1

CP-10 Information System Recovery and Reconstitution

CP-10. For all data, the NARA System Owner shall provide for the recovery and reconstitution of the information system to a known state after a disruption, compromise, or failure.

Operational System-specific P1

CP-10 (2) Transaction Recovery CP-10(2) For data requiring moderate or high availability, the information system shall implement transaction recovery for systems that are transaction-based.

Operational System-specific P1

Page 5 of

Paragraph/ReqI D

Title Requirement Statement Class Type Status Priority Responsible Entities Implementation Estimated Completion

Date

Notes

IA-2 Identification and Authentication (Organizational Users)

IA-2. For all data, the information system shall uniquely identify and authenticate NARA users (or processes acting on behalf of NARA users).

Technical Hybrid P1

IA-2(1) Identification and Authentication Multifactor Authentication

IA-2(1) For all data, the information system shall implement multifactor authentication for network access to privileged accounts.

IA-3 Device Identification and Authentication

IA-3. For data requiring moderate or high confidentiality, the information system shall uniquely identify and authenticate [SSP-defined list of specific and/or types of devices] before establishing a [local; remote; network] connection.

Technical Hybrid P1

IA-4 Identifier Management IA-4. For all data, the NARA Office of Information Services (I) shall manage information system identifiers by:

IA-4a. Receiving authorization from a designated [NARA official] to assign a user or device identifier;

IA-4b. Selecting an identifier that identifies an individual, group, role or device;

IA-4c. Assigning the user identifier to the intended individual, group, role or the device;

IA-4d. Preventing reuse of identifiers for [at least one year]; and IA-4e. Disabling the identifier after [not to exceed 90 days for unclassified information systems or 30 days for classified information systems].

Technical Hybrid P1

IA-5 Authenticator Management

IA-5. For all data, the NARA Office of Information Services (I) shall manage information system authenticators by:

IA-5a. Verifying, as part of the initial authenticator distribution, the identity of the individual, group, role or device receiving the authenticator;

IA-5b. Establishing initial authenticator content for authenticators defined by the NARA Office of Information Services (I);

IA-5c. Ensuring that authenticators have sufficient strength of mechanism for their intended use;

IA-5d. Establishing and implementing administrative procedures for initial authenticator distribution, for lost/compromised or damaged authenticators, and for revoking authenticators;

IA-5e. Changing default content of authenticators prior to information system installation;

IA-5f. Establishing minimum and maximum lifetime restrictions and reuse conditions for authenticators;

IA-5g. Changing/refreshing authenticators [not to exceed 90 days for unclassified information systems or 180 days for classified information systems];

IA-5h. Protecting authenticator content from unauthorized disclosure and modification;

IA-5i. Requiring individuals to take, and having devices implement, specific security safeguards to protect authenticators; and IA-5j. Changing authenticators for group/role accounts when membership to those accounts changes

Technical Hybrid P1

IA-5 (1) Password-Based Authentication

IA-5(1) For all data, the information system, shall, for password-based authentication:

(a) Enforces minimum password complexity of [a case sensitive, 8-character mix of upper case letters, lower case letters, numbers, and special characters, including at least one of each];

(b) Enforce at least the following number of changed characters when new passwords are created: [four character change];

(c) Stores and transmits only encrypted representations of passwords;

(d) Enforce password minimum and maximum lifetime restrictions of [1 day minimum, 90 day maximum];

(e) Prohibit password reuse for [a minimum of 5 for unclassified information systems or 10 for classified information systems] generations; and

(f) Allows the use of a temporary password for system logons with an immediate change to a permanent password.

Technical Hybrid P1

IA-5 (3) In-Person Or Trusted Third-Party Registration

IA-5(3) For data requiring moderate or high confidentiality, the NARA Office of Information Services (I) shall require that the registration process to receive [user ID and password] be conducted [in person] before [Security Architecture adds: A NARA badge presented to a help desk representative] with authorization by [a designated NARA official (e.g., a supervisor)].

Technical Hybrid P1

IA-6 Authenticator Feedback

IA-6. For all data, the information system shall obscure feedback of authentication information during the authentication process to protect the information from possible exploitation/use by unauthorized individuals.

Technical Hybrid P1

IA-7 Cryptographic Module Authentication

IA-7. For all data, the information system shall implement mechanisms for authentication to a cryptographic module that meet the requirements of applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance for such authentication.

Technical Hybrid P1

IA-8 Identification and Authorization (non- Nara users)

IA-8. For all data, the information system shall uniquely identify and authenticates non-NARA users (or processes acting on behalf of non- NARA users).

IA-8(1) Identification and Authorization (non- Nara users)

IA-8(1) For all data, the information system shall accept and electronically verify Personal Identity Verification (PIV) credentials from other federal agencies.

IA8(2) Identification and Authorization (non- Nara users)

IA-8(2) For all data, the information system shall accept only FICAM-approved third-party credentials.

SA-5 Information System Documentation

SA-5. For all data, the NARA System Owner shall:

SA-5a. Obtain administrator documentation for the information system, system component, or information system service that describes:

1. Secure configuration, installation, and operation of the information system;

2. Effective use and maintenance of security features/functions; and

3. Known vulnerabilities regarding configuration and use of administrative (i.e., privileged) functions; and SA-5b. Obtain user documentation for the information system, system component, or information system service that describes:

1. User-accessible security features/functions and how to effectively use those security features/functions;

2. Methods for user interaction, which enables individuals to use the system, components, or service in a more secure manner; and

3. User responsibilities in maintaining the security of the system, component, or service;

SA-5c. Document attempts to obtain information system , system component, or information system service documentation when such documentation is either unavailable or nonexistent and [SSP-defined actions] in response;

SA-5d. Protect documentation as required, in accordance with the risk management strategy; and SA-5e. Distribute documentation to [SSP-defined personnel or roles].

Management Hybrid P2

SA-8 Security Engineering Principles

SA-8. For data requiring moderate or high integrity, the NARA System Owner shall apply information system security engineering principles in the specification, design, development, implementation, and modification of the information system.

Management Hybrid P1

Page 6 of

Paragraph/ReqI D

Title Requirement Statement Class Type Status Priority Responsible Entities Implementation Estimated Completion

Date

Notes

SA-9 External Information System Services

SA-9. For all data, the NARA System Owner shall:

SA-9a. Require that providers of external information system services comply with NARA information security requirements and employ [SSP-defined security controls] in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance;

SA-9b. Define and document government oversight and user roles and responsibilities with regard to external information system services;

and SA-9c. Employ (SSP-defined processes, methods, and techniques] to monitor security control compliance by external service providers on an ongoing basis.

Management

SA-9(2) External Information System Services (identification of functions, ports, protocols

SA-9(2) For data requiring moderate or high integrity, the NARA System Owner shall require providers of [SSP-defined external information system services] to identify the functions, ports, protocols, and other services required for the use of such services

SA-10 Developer Configuration Management

SA-10. For data requiring moderate or high integrity, the NARA System Owner shall require that information system developers of the information system, system component, or information system service to:

SA-10a. Perform configuration management during system, component, or service [design; development; implementation;

operation];

SA-10b. Document, manage, and control the integrity of changes to [SSP-defined configuration items under configuration management];

SA-10c. Implement only SSP-approved changes to the system, component, or service;

SA-10d. Document approved changes to the system, component, or service and the potential security impacts of such changes; and SA-10e. Track security flaws and flaw resolution within the system, component, or service and report findings to [SSP-defined personnel].

SA-11 Developer Security Testing

SA-11. For data requiring moderate or high integrity, the NARA System Owner shall require that information system developers/integrators, in consultation with associated security personnel (including security engineers):

SA-11a. Create and implement a security assessment plan;SecA.

Requirements.docx 106 March 22, 2017 SA-11b. Perform [unit; integration; system; or regression] testing/evaluation at [SSP-defined depth and coverage];

SA-11c. Produce evidence of the execution of the security assessment plan and the results of the security testing/evaluation;

SA-11d. Implement a verifiable flaw remediation process; and SA-11e. Correct flaws identified during security testing/evaluation.

SC-2 Application Partitioning SC-2. For data requiring moderate or high confidentiality, the information system shall separate user functionality (including user interface services) from information system management functionality.

Technical System-specific P1

SC-4 Information in Shared Resources

SC-4. For data requiring moderate or high confidentiality, the information system shall prevent unauthorized and unintended information transfer via shared system resources.

Technical Hybrid P1

SC-5 Denial of Service Protection

SC-5. For all data, the information system shall protect against or limit the effects of the following types of denial of service attacks: [Denial of service attacks identified in US CERT advisories] by employing [SSP-defined security safeguards].

Technical Hybrid P1

SC-7 Boundary Protection SC-7. For all data, the information system shall:

SC-7a. Monitor and control communications at the external boundary of the system and at key internal boundaries within the system;

SC-7b. Implement subnetworks for publicly accessible system components that are [physically] separated from internal organizational networks; and SC-7c. Connect to external networks or information systems only through managed interfaces consisting of boundary protection devices arranged in accordance with the NARA security architecture.

Technical

SC-7(3) Boundary Protection limit number of external connections

SC-7(3) For data requiring moderate or high integrity, the NARA Office of Information Services (I) shall limit the number of external network connections to the information system.

SC-7(4) Boundary Protection limit number of external connections

SC-7(4) For data requiring moderate or high integrity, the NARA Office of Information Services (I) shall:

(a) Implement a managed interface for each external telecommunication service;

(b) Establish a traffic flow policy for each managed interface;

(c) Protect the confidentiality and integrity of the information being transmitted across each interface;

(d) Document each exception to the traffic flow policy with a supporting mission/business need and duration of that need; and

(e) Review exceptions to the traffic flow policy [SSP-defined frequency POA&M review process and frequency].

SC-7(5) Boundary Protection (deny by exeption)

SC-7(5) For data requiring moderate or high integrity, the information system at managed interfaces, shall deny network communications traffic by default and allows network communications traffic by exception (i.e., deny all, permit by exception).

SC-7(7) Boundary Protection SC-7(7) For data requiring moderate or high integrity, the information system shall in conjunction with a remote device, prevents the device from simultaneously establishing non-remote connections with the system and communicating via some other connection to resources in external networks.

SC-8 Transmission Confidentiality and Integrity

SC-8. For data requiring moderate or high confidentiality and/or integrity, the information system shall protect the [confidentiality and integrity] of transmitted information.

Technical System-specific P1

SC-8 (1) Cryptographic Or Alternate Physical Protection

SC-8(1) For data requiring moderate or high confidentiality and/or integrity, the NARA Office of Information Services (I) shall employ cryptographic mechanisms to [detect changes to information] during transmission unless otherwise protected by [SSP-defined alternative physical safeguards].

Technical System-specific P1

SC-10 Network Disconnect SC-10. For data requiring moderate or high confidentiality, the information system shall terminate the network connection associated with a communications session at the end of the session or after [no more than 15 minutes for unclassified information systems or no more than 48 hours for classified information systems] of inactivity.

Technical Hybrid P2

SC-12 Cryptographic Key Establishment and Management

SC-12. For all data, the NARA Office of Information Services (I) shall establish and manage cryptographic keys for required cryptography employed within the information system in accordance with [NARA-defined requirements for generation, distribution, storage, access, and destruction].

Technical System-specific P1

SC-13 Cryptographic Protection

SC-13. For all data, the information system shall implement [SSP-defined cryptographic uses and type of cryptography required for each use] in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.

Technical System-specific P1

SC-15 Collaborative Computing Devices

SC-15. For all data, the information system shall:

SC-15a. Prohibit remote activation of collaborative computing devices with the following exceptions: [SSP-defined exceptions where remote activation is to be allowed]; and SC-15b. Provide an explicit indication of use to users physically present at the devices.

Technical System-specific P1

SC-17 Public Key Certificate SC-17. For data requiring moderate or high confidentiality or integrity, the NARA Office of Information Services (I) shall issue public key certificates under a [NARA certificate policy] or shall obtain public key certificates from an approved service provider.

Page 7 of

Paragraph/ReqI D

Title Requirement Statement Class Type Status Priority Responsible Entities Implementation Estimated Completion

Date

Notes

SC-18 Mobile Code SC-18. For data requiring moderate or high confidentiality, the NARA System Owner shall:

SC-18a. Define acceptable and unacceptable mobile code and mobile code technologies;

SC-18b. Establish usage restrictions and implementation guidance for acceptable mobile code and mobile code technologies; and SC-18c. Authorize, monitor, and control the use of mobile code within the information system.

Technical System-specific P2

SC-23 Session Authentication SC-23. For data requiring moderate or high integrity, the information system shall protect the authenticity of communications sessions.

Technical

SC-28 Protection of Information at Rest

SC-28. For data requiring moderate or high confidentiality or integrity, the information system shall protect the [confidentiality and integrity] of [SSP-defined information at rest].

Technical System-specific P1

SC-28(1) Protection of Information at Rest

SC-28(1) For data requiring moderate or high confidentiality or integrity protection, the NARA Office of Information Services (I) shall implement cryptographic mechanisms to prevent unauthorized disclosure and modification of [SSP-defined information at rest unless otherwise protected by alternative physical measures].SC

SC-32 Information System Partitioning

SC-32. For data requiring moderate or high confidentiality or integrity, the NARA System Owner shall partition the information system into [SSP-defined components] residing in separate physical domains or environments based on [SSP-defined circumstances for physical separation of components].

SC-39 Process Isolation SC-39. For all data, the NARA System Owner shall maintain a separate execution domain for each executing process.

Technical System-specific P1

SI-2 Flaw Remediation SI-2. For all data, the NARA Office of Information Services (I) shall:

SI-2a. Identify, report, and correct information system flaws;

SI-2b. Test software updates related to flaw remediation for effectiveness and potential side effects on NARA information systems before installation;

SI-2c. Installs security-relevant software and firmware updates within [Define timeframes of critical(30 days), high(30 days), medium and low (60 days) vulnerabilities or stricter SSP-defined time period] of the release of the updates; and SI-2d. Incorporate flaw remediation into the NARA configuration management process.

Operational

SI-2(2) Flaw Reemediation SI-2(2) For data requiring moderate or high integrity, the NARA information system shall employ automated mechanisms [SSP-defined frequency] to determine the state of information system components with regard to flaw remediation.

SI-3 Malicious Code Protection

SI-3. For all data, the NARA Office of Information Services (I) shall:

SI-3a. Employ malicious code protection mechanisms at information system entry and exit points to detect and eradicate malicious code:

• Transported by electronic mail, electronic mail attachments, web accesses, removable media, or other common means; or

• Inserted through the exploitation of information system vulnerabilities;

SI-3b. Update malicious code protection mechanisms (including signature definitions) whenever new releases are available in accordance with NARA configuration management policy and procedures;

SI-3c. Configure malicious code protection mechanisms to:

1. Perform periodic scans of the information system [SSP-defined frequency] and real-time scans of files from external sources at [endpoint] as the files are downloaded, opened, or executed in accordance with NARA security policy; and

2. [block malicious code; quarantine malicious code; send alert to administrator] in response to malicious code detection; and SI-3d. Address the receipt of false positives during malicious code detection and eradication and the resulting potential impact on the availability of the information system.

SI-3(1) Malicious Code Protection

SI-3(1) For data requiring moderate or high integrity, the NARA Office of Information Services (I) shall centrally manage malicious code protection mechanisms.

SI-3(2) Malicious Code Protection

SI-3(2) For data requiring moderate or high integrity, the information system shall automatically update malicious code protection mechanisms

SI-4 Information System Monitoring

SI-4. For all data, the NARA Office of Information Services (I) shall:

SI-4a. Monitors the information system to detect:

1. Attacks and indicators of potential attacks in accordance with [SSP-defined monitoring objectives]; and

2. Unauthorized local, network, and remote connections;

SI-4b. Identify unauthorized use of the information system through [SSP-defined techniques and methods];

SI-4c. Deploy monitoring devices: (i) strategically within the information system to collect organization-determined essential information; and (ii) at ad hoc locations within the system to track specific types of transactions of interest to the organization;

SI-4d. Protect information obtained from intrusion-monitoring tools from unauthorized access, modification, and deletion;

SI-4e. Heighten the level of information system monitoring activity whenever there is an indication of increased risk to NARA operations and assets, individuals, other organizations, or the Nation based on law enforcement information, intelligence information, or other credible sources of information; and SI-4f. Obtain legal opinion with regard to information system monitoring activities in accordance with applicable federal laws, Executive Orders, directives, policies, or regulations.

SI-4g. Provide [SSP-defined information system monitoring information] to [SSP-defined personnel] [as needed; and [SSP-defined frequency]].

SI-4(2) Information System Monitoring

SI-4(2) For data requiring moderate or high integrity, the NARA Office of Information Services (I) shall employ automated tools to support near real-time analysis of events.

SI-4(4) Information System Monitoring

SI-4(4) For data requiring moderate or high integrity, the information system shall monitor inbound and outbound communications traffic [SSP-defined frequency] for unusual or unauthorized activities or conditions.

SI-4(5) Information System Monitoring

SI-4(5) For data requiring moderate or high integrity, the information system shall alert [SSP-defined list of incident response personnel (identified by name and/or by role), and NARA IT HELP] when the following indications of compromise or potential compromise occur:

[SSP-defined compromise indicators].

SI-5 Security Alerts SI-5. For all data, the IT Security Management Division (IS) shall:

SI-5a. Receive information system security alerts, advisories, and…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .