The file's text, extracted by GovTribe without its formatting.
Appendix A Cloud Security
Include the following as part of the procurement and contract for systems hosted in a Vendor cloud environment.
State of Illinois Security Requirements:
1. Vendor will notify the State of Illinois’ Chief Information Security Officer within 24 hours of knowledge of any information breach or other security incident which impacts State of Illinois data. Email notification to: DoIT.Security@illinois.gov and Subject Line should state “Breach Notification.”
2. Vendor shall have a documented security incident policy and plan. Vendor must supply a copy at the request of the State of Illinois.
3. Vendor must comply with all United States Federal and State of Illinois laws, rules, and regulations.
4. Vendor must comply with all of the State of Illinois Enterprise Security Policies (https://www2.illinois.gov/sites/doit/support/policies/Pages/default.aspx).
5. Vendor must ensure that all information technology, including electronic information, software, systems and equipment, developed or provided under this contract complies with the applicable requirements of the Illinois Information Technology Accessibility Act Standards as published at (www.dhs.state.il.us/iitaa). 30 ILCS 587. If available, Vendor must provide the State of Illinois their most recent Voluntary Product Accessibility Template (VPAT).
6. Vendor program and project management personnel must ensure coordination of activities with the State of Illinois governance program. Vendor must comply with all policies, standards, and procedures defined by the State of Illinois Department of Innovation and Technology’s Enterprise Portfolio Management Office.
7. Vendor’s system must interface with the State of Illinois’ identity and access management solutions if authentication is required for access to the system.
8. Vendor’s system must log activity within the system and have capacity to forward log information to the State of Illinois’ security incident and event management system (SIEM). Vendor must meet the State of Illinois’ Minimum Logging Requirements for the term of the Contract.
8.1. (See Security Appendix S1)
9. Vendor certifies it has undertaken independent third-party audit Statement on Standards for Attestation Engagements (SSAE-18) certifications and must provide the State of Illinois with a System Operation Controls report (SOC 1) annually and applicable bridge/gap letter when vendor is hosting State of Illinois financial information.
10. Vendor certifies it can comply with at least one of the following requirements listed in order of preference.
10.1 Vendor certifies it has undertaken independent third-party audit Statement on Standards for Attestation Engagements (SSAE-18) certifications and must provide the State of Illinois with a System Operation Controls report (SOC 2 type 2) annually and applicable bridge/gap letter.
10.2 Vendor must provide the State of Illinois with a 3rd party risk assessment of the Vendor’s system conducted within the last year including a 3rd party penetration test.
10.3 Vendor must provide the State of Illinois with a 3rd party risk assessment of the Vendor’s system conducted within the last year.
10.4 Vendor must provide the State of Illinois with a 3rd party penetration test conducted within the last year.
10.5 Vendor must perform an internal security controls assessment to demonstrate compliance with the State of Illinois Vendor Security Controls, based on the current revision of NIST 800-53 security controls for a moderate system. (See Security Appendix S2)
11. Vendor must participate in an annual risk assessment and data classification and system categorization process. The formal risk assessment will be administered by the State of Illinois.
If Vendor cannot provide the SOC 1 and/or 2 report required above and any necessary bridge/gap letter or another appropriate third-party risk assessment as determined by the State of Illinois, then Vendor must perform an internal security controls assessment to demonstrate compliance with the State of Illinois Vendor Security Controls, based on the current revision of NIST 800-53 security controls for a moderate system. Vendor must provide attestation of compliance along with the results of this assessment documented in a Security Assessment Report (SAR) to the State of Illinois. This does not relieve the Vendor of the above requirement to submit a required SOC 1 and/or SOC 2.
11.1. (See Security Appendix S2)
12. Vendor must provide a Plan of Action and Milestones (POA&M) to the State of Illinois that addresses any control deficiencies identified during the State of Illinois’ risk assessment, review of Vendor’s SOC report(s), third-party assessment, and internal security controls assessment. The POA&M should describe the deficiencies in the security controls, address the residual risk, and detail plans for remediation. Vendor must provide the State of Illinois monthly updates regarding progress toward remediation of identified deficiencies.
12.1. (See Security Appendix S3)
13. Vendor must complete and provide the State of Illinois an Authority to Operate (ATO) or Authority to Connect (ATC) packet at the State of Illinois’ request. This packet must be renewed annually.
13.1. (See Security Appendix S4)
14. Vendor must ensure all hosted data pertinent to this contract shall remain located within the contiguous United States.
15. Vendor must ensure encryption of State of Illinois data at rest and in motion. This encryption must comply with encryption security controls as defined in the most current version of the Federal Information Processing Standard (FIPS) 140 using Advanced Encryption Standard (AES) encryption with a minimum key length of 256 bits. Vendor must provide proof of encryption. Vendor must provide the State of Illinois with the capabilities to manage encryption keys for data at rest.
16. Vendor must store data in a non-proprietary, readily accessible format, or Vendor must provide a solution, at no additional cost to the State of Illinois, to extract any State of Illinois data stored in Vendor’s solution.
17. Vendor must only use State of Illinois data, for the purposes stated in this contract.
18. Vendor must maintain a robust and reliable data backup system. Vendor must supply a description of backup methodology, and this methodology must meet defined Maximum Tolerable Downtime (MTD) and Return to Operations (RPO) requirements.
19. Vendor must provide a written disaster recovery mythology and provide proof of annual disaster recovery testing, including issues discovered and remediation plans for the issues discovered.
20. Vendor may not use any State of Illinois data in any non-production system or in any other system outside the application/service procured under this contract.
21. Vendor must provide a copy of all State of Illinois data (in a non-proprietary format) to the State of Illinois without delay upon request by the State of Illinois.
22. Vendor must provide a copy of all State of Illinois data (in a non-proprietary format) to the State of Illinois prior to termination of contract.
23. Vendor must sanitize all media that contains or contained State of Illinois data. Vendor must use the more current revision of NIST Special Publication 800-88; Guidelines for Media Sanitization. Vendor must provide the State of Illinois with a written certification of media sanitization including the method, date and time.
24. Vendor must use a form of “crypto shredding” acceptable to the State of Illinois for rendering all State of Illinois data hosted by the Vendor inaccessible after a copy of all data has been provided to the State of Illinois.
25. Vendor and/or its agents must not resell nor otherwise redistribute information gained from its access to the State of Illinois data.
26. Vendor must not engage in nor permit its agents to push adware, software, or marketing not explicitly authorized by the State of Illinois.
27. Vendor must allow the State of Illinois to perform vulnerability assessments.
27.1. (See Security Appendix S5)
28. Vendor must immediately remediate critical, high, and medium vulnerabilities within the application that are detected during the security assessments and are determined by the State of Illinois to pose an unacceptable risk.
29. Vendor must secure independent third-party penetration testing at regular intervals, in accordance with Cloud Security Alliance (CSA) and Open Web Application Security Project (OWASP) recommendations. Vendor must supply the results of the testing to the State of Illinois upon request.
30. Vendor must supply a list of all non-proprietary/open source software used in their solution. Vendor must also include the version and Open Source Initiative (OSI) approved license type used for any open source software. If Open Source uses non-OSI approved licensing Vendor must include licensing terms and conditions.
Security Appendix S1 – Minimum Logging Requirements
· Input validation failures (e.g., protocol violations, unacceptable encodings, invalid parameter names and values)
· Output validation failures (e.g., database record set mismatch, invalid data encoding)
· Authentication successes and failures
· Authorization (access control) failures
· Session management failures (e.g., cookie session identification value modification)
· Application errors and system events (e.g., syntax and runtime errors, connectivity problems, performance issues, third-party service error messages, file system errors, file upload virus detection, configuration changes)
· Application and related systems start-ups and shut downs, and logging initialization (starting, stopping, or pausing)
· Use of higher-risk functionality (e.g., network connections, addition or deletion of users, changes to privileges, assigning users to tokens, adding or deleting tokens, use of systems administrative privileges, access by application administrators, all actions by users with administrative privileges, access to payment cardholder data, use of data encrypting keys, key changes, creation and deletion of system-level objects, data import and export including screen-based reports, submission of user-generated content - especially file uploads)
· Legal and other opt-ins (e.g., permissions for mobile phone capabilities, terms of use, terms & conditions, personal data usage consent, permission to receive marketing communications)
Security Appendix S2: Security Controls for Vendors Authoritative Document NIST 800-53 v4 – Security and Privacy Controls Access and Control (AC) Organizations must limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems) and to the types of transactions and functions that authorized users are permitted to exercise.
AC Security Controls and Control Enhancements (for Moderate Security Categorization):
| Security Control Summary |
| Control # |
| Enhancement #’s |
| · Access Control Policy and Procedures |
| AC-1 |
| · Account Management |
| AC-2 |
| (1), (2), (3), (4) |
| · Access Enforcement |
| AC-3 |
| · Information Flow Enforcement |
| AC-4 |
| · Separation of Duties |
| AC-5 |
| · Least Privilege |
| AC-6 |
| (1), (2), (5), (9), (10) |
| · Unsuccessful Logon Attempts |
| AC-7 |
| · System Use Notification |
| AC-8 |
| · Session Termination |
| AC-12 |
| · Permitted Actions without Identification or Authentication |
| AC-14 |
| · Remote Access |
| AC-17 |
| (1), (2), (3), (4) |
| · Wireless Access |
| AC-18 |
| (1) |
| · Access Control for Mobile Devices |
| AC-19 |
| (5) |
| · Use of External Information Systems |
| AC-20 |
| (1), (2) |
| · Information Sharing |
| AC-21 |
| · Publicly Accessible Content |
| AC-22 |
Authority
| CFR |
| HIPAA 45 CFR - 160, 162, 164 |
| NIST |
| SP 800-53 Security and Privacy Controls |
| FIPS |
| 200 Minimum Security Controls |
| IRS |
| 1075 Tax Information Security Guidelines |
| DoIT |
| DoIT Policies and Associated Standards and Guidelines |
Awareness and Training (AT) Organizations must (i) ensure that managers and users of organizational information systems are made aware of the security risks associated with their activities and of the applicable laws, executive orders, directives, policies, standards, instructions, regulations, or procedures related to the security of organizational information systems; and (ii) ensure that organizational personnel are adequately trained to carry out their assigned information security-related duties and responsibilities.
AT - NIST Security Controls and Control Enhancements (for Moderate Security Categorization):
| Security Control Summary |
| Control # |
| Enhancement #’s |
| · Security Awareness and Training Policy and Procedures |
| AT-1 |
| · Security Awareness Training |
| AT-2 |
| (2) |
| · Role-Based Security Training |
| AT-3 |
| · Security Training Records |
| AT-4 |
Authority
| NIST |
| SP 800-53 Security and Privacy Controls |
| FIPS |
| 200 Minimum Security Controls |
| IRS |
| 1075 Tax Information Security Guidelines |
| DoIT |
| DoIT Policies and Associated Standards and Guidelines |
Audit and Accountability (AU) Organizations must: (i) create, protect, and retain information system audit records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful, unauthorized, or inappropriate information system activity; and (ii) ensure that the actions of individual information system users can be uniquely traced to those users, so they can be held accountable for their actions.
AU - NIST Security Controls and Control Enhancements (for Moderate Security Categorization):
| Security Control Summary |
| Control # |
| Enhancement #’s |
| · Audit and Accountability Policy and Procedure |
| AU-1 |
| · Content of Audit Records |
| AU-3 |
| (1) |
| · Audit Storage Capacity |
| AU-4 |
| · Response to Audit Processing Failures |
| AU-5 |
| · Audit Review, Analysis, and Reporting |
| AU-6 |
| (1), (3) |
| · Audit Reduction and Report Generation |
| AU-7 |
| (1) |
| · Protection of Audit Information |
| AU-9 |
| (4) |
| · Audit Record Retention |
| AU-11 |
Authority
| CFR |
| HIPAA 45 CFR - 160, 162, 164 |
| NIST |
| SP 800-53 Security and Privacy Controls |
| FIPS |
| 200 Minimum Security Controls |
| IRS |
| 1075 Tax Information Security Guidelines |
| DoIT |
| DoIT Policies and Associated Standards and Guidelines |
Certification, Accreditation, and Security Assessments (CA) Organizations must: (i) periodically assess the security controls in organizational information systems to determine if the controls are effective in their application; (ii) develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organization information systems; (iii) authorize the operation of organizational information systems and any associated information system connections; and (iv) monitor information system security controls on an ongoing basis to ensure the continued effectiveness of the controls.
CA - NIST Security Controls and Control Enhancements (for Moderate Security Categorization):
| Security Control Summary |
| Control # |
| Enhancement #’s |
| · Security Assessment and Authorization Policy and Procedures |
| CA-1 |
| · Security Assessments |
| CA-2 |
| (1) |
| · System Interconnections |
| CA-3 |
| (5) |
| · Plan of Action and Milestones |
| CA-5 |
| · Security Authorization |
| CA-6 |
| · Continuous Monitoring |
| CA-7 |
| (1) |
| · Internal System Connections |
| CA-9 |
Authority
| NIST |
| SP 800-53 Security and Privacy Controls |
| NIST |
| SP 800-53A Assessing Security Controls |
| FIPS |
| 200 Minimum Security Controls |
| IRS |
| 1075 Tax Information Security Guidelines |
| DoIT |
| DoIT Policies and Associated Standards and Guidelines |
Configuration Management (CM) Vendors must: (i) establish and maintain baseline configurations and inventories of organizational information systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; and (ii) establish and enforce security configuration settings for information technology products employed in organizational information systems.
CM - NIST Security Controls and Control Enhancements (for Moderate Security Categorization):
| Security Control Summary |
| Control # |
| Enhancement #’s |
| · Configuration Management Policy and Procedures |
| CM-1 |
| · Baseline Configuration |
| CM-2 |
| (1), (3), (7) |
| · Configuration Change Control |
| CM-3 |
| (2) |
| · Security Impact Analysis |
| CM-4 |
| · Access Restrictions for Change |
| CM-5 |
| · Configuration Settings |
| CM-6 |
| · Least Functionality |
| CM-7 |
| (1), (2), (4) |
| · Information System Component Inventory |
| CM-8 |
| (1), (3), (5) |
| · Configuration Management Plan |
| CM-9 |
| · Software Usage Restrictions |
| CM-10 |
| · User-Installed Software |
| CM-11 |
Authority
| NIST |
| SP 800-53 Security and Privacy Controls |
| FIPS |
| 200 Minimum Security Controls |
| IRS |
| 1075 Tax Information Security Guidelines |
| DoIT |
| DoIT Policies and Associated Standards and Guidelines |
Contingency Planning (CP) Organizations must establish, maintain, and effectively implement plans for emergency response, backup operations, and post-disaster recovery for organizational information systems to ensure the availability of critical information resources and continuity of operations in emergency situations.
CP - NIST Security Controls and Control Enhancements (for Moderate Security Categorization):
| Security Control Summary |
| Control # |
| Enhancement #’s |
| · Contingency Planning Policy and Procedures |
| CP-1 |
| · Contingency Plan |
| CP-2 |
| (1), (3), (8) |
| · Contingency Training |
| CP-3 |
| · Contingency Plan Testing |
| CP-4 |
| (1) |
| · Alternate Storage Site |
| CP-6 |
| (1), (3) |
| · Alternate Processing Site |
| CP-7 |
| (1), (2), (3) |
| · Telecommunications Services |
| CP-8 |
| (1), (2) |
| · Information System Backup |
| CP-9 |
| (1) |
| · Information System Recovery and Reconstitution |
| CP-10 |
| (2) |
Authority
| CFR |
| HIPAA 45 CFR - 160, 162, 164 |
| NIST |
| SP 800-53 Security and Privacy Controls |
| FIPS |
| 200 Minimum Security Controls |
| IRS |
| 1075 Tax Information Security Guidelines |
| DoIT |
| DoIT Policies and Associated Standards and Guidelines |
Identification and Authentication (IA) Organizations must identify information system users, processes acting on behalf of users, or devices and authenticate (or verify) the identities of those users, processes, or devices as a prerequisite to allowing access to organizational information systems.
IA - NIST Security Controls and Control Enhancements (for Moderate Security Categorization):
| Security Control Summary |
| Control # |
| Enhancement #’s |
| · Identification and Authentication Policy and Procedures |
| IA-1 |
| · Identification and Authentication (Organizational Users) |
| IA-2 |
| (1), (2), (3), (8), (11), (12) |
| · Device Identification and Authentication |
| IA-3 |
| · Identifier Management |
| IA-4 |
| · Authentication Management |
| IA-5 |
| (1), (2), (3), (11) |
| · Authenticator Feedback |
| IA-6 |
| · Cryptographic Module Authentication |
| IA-7 |
| · Identification and Authentication (Non-Organizational Users) |
| IA-8 |
| (1), (2), (3), (4) |
Authority
| CFR |
| HIPAA 45 CFR - 160, 162, 164 |
| NIST |
| SP 800-53 Security and Privacy Controls |
| FIPS |
| 200 Minimum Security Controls |
| IRS |
| 1075 Tax Information Security Guidelines |
| DoIT |
| DoIT Policies and Associated Standards and Guidelines |
Incident Response (IR) Organizations must: (i) establish an operational incident handling capability for organizational information systems that includes adequate preparation, detection, analysis, containment, recovery, and user response activities; and (ii) track, document, and report incidents to appropriate organizational officials and/or authorities.
IR - NIST Security Controls and Control Enhancements (for Moderate Security Categorization):
| Security Control Summary |
| Control # |
| Enhancement #’s |
| · Incident Response Policy and Procedures |
| IR-1 |
| · Incident Response Training |
| IR-2 |
| · Incident Response Testing |
| IR-3 |
| (2) |
| · Incident Handling |
| IR-4 |
| (1) |
| · Incident Monitoring |
| IR-5 |
| · Incident Reporting |
| IR-6 |
| (1) |
| · Incident Response Assistance |
| IR-7 |
| (1) |
| · Incident Response Plan |
| IR-8 |
Authority
| CFR |
| HIPAA 45 CFR - 160, 162, 164 |
| NIST |
| SP 800-53 Security and Privacy Controls |
| FIPS |
| 200 Minimum Security Controls |
| IRS |
| 1075 Tax Information Security Guidelines |
| DoIT |
| DoIT Policies and Associated Standards and Guidelines |
Maintenance (MA) Organizations must: (i) perform periodic and timely maintenance on organizational information systems; and (ii) provide effective controls on the tools, techniques, mechanisms, and personnel used to conduct information system maintenance.
MA - NIST Security Controls and Control Enhancements (for Moderate Security Categorization):
| Security Control Summary |
| Control # |
| Enhancement #’s |
| · System Maintenance Policy and Procedures |
| MA-1 |
| · Controlled Maintenance |
| MA-2 |
| · Maintenance Tools |
| MA-3 |
| (1), (2) |
| · Nonlocal Maintenance |
| MA-4 |
| (2) |
| · Maintenance Personnel |
| MA-5 |
| · Timely Maintenance |
| MA-6 |
Authority
| NIST |
| SP 800-53 Security and Privacy Controls |
| FIPS |
| 200 Minimum Security Controls |
| IRS |
| 1075 Tax Information Security Guidelines |
| DoIT |
| DoIT Policies and Associated Standards and Guidelines |
Media Protection (MP) Organizations must: (i) protect information system media, both paper and digital; (ii) limit access to information on information system media to authorized users; and (iii) sanitize or destroy information system media before disposal or release for reuse.
MP - NIST Security Controls and Control Enhancements (for Moderate Security Categorization):
| Security Control Summary |
| Control # |
| Enhancement #’s |
| · Media Protection Policy and Procedures |
| MP-1 |
| · Media Transport |
| MP-5 |
| (4) |
| · Media Sanitization |
| MP-6 |
Authority
| CFR |
| HIPAA 45 CFR - 160, 162, 164 |
| NIST |
| SP 800-53 Security and Privacy Controls |
| FIPS |
| 200 Minimum Security Controls |
| IRS |
| 1075 Tax Information Security Guidelines |
| DoIT |
| DoIT Policies and Associated Standards and Guidelines |
Physical and Environmental Protection (PE) Organizations must: (i) limit physical access to information systems, equipment, and the respective operating environments to authorized individuals; (ii) protect the physical plant and support infrastructure for information systems; (iii) provide supporting utilities for information systems; (iv) protect information systems against environmental hazards; and (v) provide appropriate environmental controls in facilities containing information systems.
PE - NIST Security Controls and Control Enhancements (for Moderate Security Categorization):
| Security Control Summary |
| Control # |
| Enhancement #’s |
| · Physical and Environmental Protection Policy and Procedures |
| PE-1 |
| · Physical Access Authorizations |
| PE-2 |
| · Physical Access Control |
| PE-3 |
| · Access Control for Transmission Medium |
| PE-4 |
| · Access Control for Output Devices |
| PE-5 |
| · Monitoring Physical Access |
| PE-6 |
| (1) |
| · Visitor Access Records |
| PE-8 |
| · Power Equipment and Cabling |
| PE-9 |
| · Emergency Shutoff |
| PE-10 |
| · Emergency Lighting |
| PE-12 |
| · Fire Protection |
| PE-13 |
| (3) |
| · Temperature and Humidity Controls |
| PE-14 |
| · Water Damage Protection |
| PE-15 |
| · Delivery and Removal |
| PE-16 |
| · Alternate Work Site |
| PE-17 |
Authority
| NIST |
| SP 800-53 Security and Privacy Controls |
| FIPS |
| 200 Minimum Security Controls |
| IRS |
| 1075 Tax Information Security Guidelines |
| DoIT |
| DoIT Policies and Associated Standards and Guidelines |
Planning (PL) Organizations must develop, document, periodically update, and implement security plans for organizational information systems that describe the security controls in place or planned for the information systems and the rules of behavior for individuals accessing the information systems.
PL - NIST Security Controls and Control Enhancements (for Moderate Security Categorization):
| Security Control Summary |
| Control # |
| Enhancement #’s |
| · Security Planning Policy and Procedures |
| PL-1 |
| · System Security Plan |
| PL-2 |
| (3) |
| · Rules of Behavior |
| PL-4 |
| (1) |
| · Information Security Architecture |
| PL-8 |
Authority
| NIST |
| SP 800-53 Security and Privacy Controls |
| FIPS |
| 200 Minimum Security Controls |
| IRS |
| 1075 Tax Information Security Guidelines |
| DoIT |
| DoIT Policies and Associated Standards and Guidelines |
Personnel Security (PS) Organizations must: (i) ensure that individuals occupying positions of responsibility within organizations (including third-party service providers) are trustworthy and meet established security criteria for those positions; (ii) ensure that organizational information and information systems are protected during and after personnel actions, such as terminations and transfers; and (iii) employ formal sanctions for personnel failing to comply with organizational security policies and procedures.
PS - NIST Security Controls and Control Enhancements (for Moderate Security Categorization):
| Security Control Summary |
| Control # |
| Enhancement #’s |
| · Personnel Security Policy and Procedures |
| PS-1 |
| · Position Risk Designation |
| PS-2 |
| · Personnel Screening |
| PS-3 |
| · Personnel Termination |
| PS-4 |
| · Personnel Transfer |
| PS-5 |
| · Third-Party Personnel Security |
| PS-7 |
| · Personnel Sanctions |
| PS-8 |
Authority
| NIST |
| SP 800-53 Security and Privacy Controls |
| FIPS |
| 200 Minimum Security Controls |
| IRS |
| 1075 Tax Information Security Guidelines |
| DoIT |
| DoIT Policies and Associated Standards and Guidelines |
Risk Assessment (RA) Organizations must periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals resulting from the operation of organizational information systems and the associated processing, storage, or transmission of organizational information.
RA - NIST Security Controls and Control Enhancements (for Moderate Security Categorization):
| Security Control Summary |
| Control # |
| Enhancement #’s |
| · Risk Assessment Policy and Procedures |
| RA-1 |
| · Security Categorization |
| RA-2 |
| · Vulnerability Scanning |
| RA-5 |
| (1), (2), (5) |
Authority
| CFR |
| HIPAA 45 CFR - 160, 162, 164 |
| NIST |
| SP 800-53 Security and Privacy Controls |
| FIPS |
| 200 Minimum Security Controls |
| IRS |
| 1075 Tax Information Security Guidelines |
| DoIT |
| DoIT Policies and Associated Standards and Guidelines |
System and Services Acquisition (SA) Organizations must: (i) allocate sufficient resources to adequately protect organizational information systems; (ii) employ system development life cycle processes that incorporate information security considerations; (iii) employ software usage and installation restrictions; and (iv) ensure that third-party providers employ adequate security measures to protect information, applications, and or services outsourced from the organizations.
SA - NIST Security Controls and Control Enhancements (for Moderate Security Categorization):
| Security Control Summary |
| Control # |
| Enhancement #’s |
| · System and Services Acquisition Policy and Procedures |
| SA-1 |
| · Allocation of Resources |
| SA-2 |
| · System Development Life Cycle |
| SA-3 |
| · Acquisition Process |
| SA-4 |
| (1), (2), (9), (10) |
| · Information System Documentation |
| SA-5 |
| · Security Engineering Principles |
| SA-8 |
| · External Information System Services |
| SA-9 |
| (2) |
| · Developer Configuration Management |
| SA-10 |
| · Developer Security Testing and Evaluation |
| SA-11 |
Authority
| NIST |
| SP 800-53 Security and Privacy Controls |
| FIPS |
| 200 Minimum Security Controls |
| IRS |
| 1075 Tax Information Security Guidelines |
| DoIT |
| DoIT Policies and Associated Standards and Guidelines |
System and Communications Protection (SC) Organizations must: (i) monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries for the information systems; and (ii) employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational information systems.
SC - NIST Security Controls and Control Enhancements (for Moderate Security Categorization):
| Security Control Summary |
| Control # |
| Enhancement #’s |
| · System and Communication Protection Policy and Procedures |
| SC-1 |
| · Application Partitioning |
| SC-2 |
| · Information in Shared Resources |
| SC-4 |
| · Denial of Service Protection |
| SC-5 |
| · Boundary Protection |
| SC-7 |
| (3), (4), (5), (7) |
| · Transmission Confidentiality and Integrity |
| SC-8 |
| (1) |
| · Network Disconnect |
| SC-10 |
| · Cryptographic Key Establishment and Management |
| SC-12 |
| · Cryptographic Protection |
| SC-13 |
| · Collaborative Computing Devices |
| SC-15 |
| · Public Key Infrastructure Certificates |
| SC-17 |
| · Voice Over Internet Protocol |
| SC-19 |
| · Secure Name/Address Resolution Service (Authoritative Source) |
| SC-20 |
| · Secure Name/Address Resolution Service (Recursive or Caching Resolver) |
| SC-21 |
| · Architecture and Provisioning for Name/Address Resolution Service |
| SC-22 |
| · Session Authenticity |
| SC-23 |
| · Protection of Information at Rest |
| SC-28 |
| · Process Isolation |
| SC-39 |
Authority
| CFR |
| HIPAA 45 CFR - 160, 162, 164 |
| NIST |
| SP 800-53 Security and Privacy Controls |
| FIPS |
| 200 Minimum Security Controls |
| IRS |
| 1075 Tax Information Security Guidelines |
| DoIT |
| DoIT Policies and Associated Standards and Guidelines |
System and Information Integrity (SI) Organizations must: (i) identify, report, and correct information and information systems flaws in a timely manner; (ii) provide protection from malicious code at appropriate locations within organizational information systems, and (iii) monitor information system security alerts and advisories and take appropriate actions in response.
SI - NIST Security Controls and Control Enhancements (for Moderate Security Categorization):
| Security Control Summary |
| Control # |
| Enhancement #’s |
| · System and Information Integrity Policy and Procedures |
| SI-1 |
| · Flaw Remediation |
| SI-2 |
| (2) |
| · Malicious Code Protection |
| SI-3 |
| (1), (2) |
| · Information System Monitoring |
| SI-4 |
| (2), (4), (5) |
| · Security Alerts, Advisories and Directives |
| SI-5 |
| · Software, Firmware, and Information Integrity |
| SI-7 |
| (1), (7) |
| · Spam Protection |
| SI-8 |
| (1), (2) |
| · Information Input Validation |
| SI-10 |
| · Information Handling and Retention |
| SI-12 |
| · Memory Protection |
| SI-16 |
Authority
| CFR |
| HIPAA 45 CFR - 160, 162, 164 |
| NIST |
| SP 800-53 Security and Privacy Controls |
| FIPS |
| 200 Minimum Security Controls |
| IRS |
| 1075 Tax Information Security Guidelines |
| DoIT |
| DoIT Policies and Associated Standards and Guidelines |
Security Appendix S3 - Plan of Actions and Milestones Template
| Identified Deficiency |
| Residual Risk |
| Detailed Remediation Plan with Timeline |
| Expected Completion Date |
Security Appendix 4 – Authority to Operate / Authority to Connect Packet
Security Appendix S5 – Authority Packet STATE OF ILLINOIS NIST and FISMA Compliance Document Project Name:
Date:
Duration of Project:
Vendor Name:
Vendor Contact Information:
A. The departments and agencies within all branches of the Federal Government are required by Federal Information Security Modernization Act (FISMA) of 2014 to comply with OMB E-GOV guidance to provide information security for the information and information systems that support the operations and assets under their control. The Federal Office of Management and Budget (OMB) has published guidance for the executive branch in OMB Circulars A-123, Appendix D and A-130.
B. STATE OF ILLINOIS recognizes that FISMA compliance, effective information security management, and continuous monitoring of information systems are paramount to the success of information technology (IT) systems. In order to establish an information security program in accordance with FISMA, Vendor must follow the National Institute for Standards and Technology (NIST) Guidelines of the NIST Risk Management Framework (RMF), as amended.
C. Requirements
(1) Each requirement in the table below is understood to contain the implied prefix, " Vendor shall..."
| Area |
| Requirement ID |
| Description |
| NIST and FISMA Compliance |
| 1 |
| Describe in detail how Vendor will meet all NIST and FISMA requirements before the solution or projects approved for production. |
VENDOR RESPONSE:
| NIST and FISMA Compliance |
| 2 |
| Describe in detail how Vendor will define information system boundaries for authorization. |
VENDOR RESPONSE:
| NIST and FISMA Compliance |
| 3 |
| Describe in detail how Vendor will assess, review, and evaluate the information systems to be implemented based upon security categorization in accordance with Federal Information Processing Standards (FIPS) Publication 199 Standards for Security Categorization of Federal Information and Information Systems. Additional guidance on defining the information type can be obtained from National Institute Technological Standards (NIST) SP 800-60. |
VENDOR RESPONSE:
| NIST and FISMA Compliance |
| 4 |
| Describe in detail how Vendor will select the baseline controls described in FIPS 200 and NIST SP 800-53 to develop a System Security Plan (SSP). |
VENDOR RESPONSE:
| NIST and FISMA Compliance |
| 5 |
| Describe in detail how Vendor will meet security requirements with regard to protecting the confidentiality, integrity, and availability of the system and the information processed, stored, and transmitted by the system. |
VENDOR RESPONSE:
| NIST and FISMA Compliance |
| 6 |
| Describe in detail how Vendor will perform continuous monitoring of the system in compliance with NIST SP 800-137. |
VENDOR RESPONSE:
| (2) Vendor shall provide the following System Security Plan (SSP): |
| The Vendor must develop a SSP using the guidance from NIST Risk Management Framework (RMF) (NIST SP 800-18) to establish an information security program in accordance with the Federal Information Security Management Act (FISMA) and demonstrate compliance. |
This SSP must be approved by an authorizing official within the STATE OF ILLINOIS. The SSP must include, but shall not be limited to, the following:
i. Description of how the system is to be compliant with all the United States Federal and State of Illinois laws regarding the security and privacy of medical data and records and of all protected health information (PHI), including:
a) The Code of Federal Regulations (at 45 CFR 95.621), which provides that State of Illinois agencies are responsible for the security of all automated data processing systems involved in the administration of Department of Health and Human Services’ programs, and which includes the establishment of a security plan that outlines how software and data security will be maintained. This section further requires that State of Illinois agencies conduct a review and evaluation of physical and data security operating procedures and personnel practices on a biennial basis.
b) The security and privacy standards contained in Pub. L. 104–191, the Health Insurance Portability and Accountability Act of 1996 (HIPAA), and adopted in 45 CFR Part 164, Subparts C and E, as follows: The security standards require that measures be taken to secure protected heath information that is transmitted or stored in electronic format. The privacy standards apply to protected health information that may be in electronic, oral, and paper form.
c) The requirements in section 1902(a)(7) of the Social Security Act (the Act), as further interpreted in Federal regulations at 42 CFR 431.300 to 307.
ii. Description of measures to secure data and software;
iii. Description of how data is encrypted in transit and in storage;
iv. Description of physical and equipment security measures;
v. Description of personnel security;
vi. Description of software used for security;
vii. Description of the user roles and the access capabilities of each role;
viii. Description of how users are assigned certain roles;
ix. Identification of the staff responsible for controlling the system security;
x. Description of contingency security procedures during a disaster recovery event;
xi. Description of how Vendor works with Office of the Statewide Chief Information Security Officer to conduct annual security review;
xii. Description of how Vendor will ensure password security
xiii. Audit trails for all data access;
xiv. Acknowledgement that Vendor will be responsible for all costs associated with Identify theft, resulting from security breach.
D. Security Risk Assessment. STATE OF ILLINOIS or an independent entity will perform a security control assessment. STATE OF ILLINOIS will provide Vendor a copy of the approved security control assessment. Once Vendor receives the approved assessment, Vendor must then develop a Security Risk Assessment based on the applicable security controls. Guidance on conducting and documenting the Security Risk Assessment can be obtained in NIST SP 800-30.
E. Plan of Action and Milestones (POA&M). After STATE OF ILLINOIS reviews and approves the Security Risk Assessment, Vendor should begin to develop a POA&M. The POA&M should be a living document that is based on the findings and recommendations of the security assessment report. The POA&M should describe the deficiencies in the security controls, address the residual risk, and detail plans for remediation and identify timeline for such remediation.
F. Authorization Approval Package.
(a) After STATE OF ILLINOIS reviews and approves the POA&M, Vendor must prepare a transmittal letter to request approval of the entire authorization package. The authorization package must include at a minimum the following documents:
i. Transmittal Letter
ii. Updated System Security Plan
iii. Security Assessment Plan (include the STATE OF ILLINOIS/independent security assessment)
iv. Security Assessment Report (include the STATE OF ILLINOIS/independent security assessment)
v. Security Risk Assessment
vi. Plan of Action and Milestones
vii. Supporting Documentation including but not limited to design documentation, “As Built” documentation, operational documentation, validation documentation, prior authorization documentation, and other artifacts associated with the implementation and monitoring of the security controls.
(b) The authorizing official will determine the risk to the organizational operation and determine if the system is authorized to proceed. The authorizing official will deliver to Vendor a letter of authorization specifying any limitations or restriction placed on the operation of the system. Additionally, this letter should establish an end date for the security authorization.
(c) If the authorizing official denies the authorization, STATE OF ILLINOIS will continue to work with Vendor until an acceptable level of residual risk for the system is achieved. This work should include the continued remediation listed in the POA&M.
G Life-Cycle Management Vendor shall perform security system reviews and reauthorization of the system at the direction of STATE OF ILLINOIS. Vendor shall be responsible for meeting the following requirements:
(a) Performing continuous monitoring of the security system. Vendor’s continuous monitoring must include periodically selecting a subset of the baseline controls for assessment. Based on assessment of these controls, subsequent remediation actions must be identified and implemented. The ongoing remediation process should include updating key documents such as the SSP, SAR, and POA&M.
(b) Prior to any system or environmental modifications, Vendor must perform a security impact analysis. This must be included as a part of any change management or configuration management process. If the results of the modification indicate changes to the security posture of the system, corrective actions should be initiated and appropriate documents revised and updated. The updating of the documentation and continuous monitoring should provide near real-time risk management.
(c) A monthly Security Status Report must be produced by Vendor for STATE OF ILLINOIS. The Security Status Report should provide essential information regarding the security posture of the system as well as the effectiveness of the controls deployed. Ongoing monitoring activities should be detailed as well as ongoing remediation efforts to address known vulnerabilities. Additional guidance for the monitoring of system security can be obtained in NIST SP 800-137.
Security Appendix S5 – Vulnerability Assessment
· Vendor must obtain approval on behalf of the State of Illinois to perform vulnerability assessments on the cloud-hosting vendor’s website(s).
· Vendor must execute the State of Illinois Vulnerability Scanning Agreement prior to the vulnerability assessment.
(See DoIT Scanning Agreement)
· State of Illinois may, with reasonable notice to Vendor, conduct a security assessment of Vendor’s solution, which may include the following:
· Prior to initial “official” production role out of the application,
· Whitelisted scanning and manual testing of the application only, with application credentials equal to the least privileged role within the application
· Manual verification of scan results with the same credentials
· Manual testing of the application for vulnerabilities
· State of Illinois will not conduct any Denial of Service (DOS) attacks
· State of Illinois will not scan or test any infrastructure devices (servers, switches, routers, intrusion protection system, firewalls, etc.)
· On a quarterly basis for the for the first year after initial production deployment,
· Whitelisted scanning and manual testing of the application only, with application credentials equal to the least privileged role within the application
· Manual verification of scan results with the same credentials
· Manual testing of the application for vulnerabilities
· State of Illinois will not conduct any DOS attacks
· State of Illinois will not scan or test any infrastructure devices (servers, switches, routers, intrusion protection system, firewalls, etc.)
· Prior to any enhancements or upgrades being deployed to production after the initial “official” production role out of the application,
· Whitelisted scanning and manual testing of the application only, with application credentials equal to the least privileged role within the application
· Manual verification of scan results with the same credentials
· Manual testing of the application for vulnerabilities
· State of Illinois will not conduct any DOS attacks
· State of Illinois will not scan or test any infrastructure devices (servers, switches, routers, intrusion protection system, firewalls, etc.)
· Monthly vulnerability scan – no whitelisting, non-credentialed scan (same day every month) DoIT Scanning Agreement DDDDddd State of Illinois IFB Contract: State Supplemental Provisions V.23.3 DoIT Legal – May 2023 image1.jpg