Appendix A - IT Security Requirements.pdf
PDF 2 MB Posted
- Attached to
- Agency Digital Asset Management System Federal contract opportunity
- Solicitation number
- 88310321Q00056
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Appendix F - Configuration Management Database (CMDB) Template.pdf | ||
| Appendix E - System Security Plan Requirements.pdf | ||
| Appendix C - Incident Response Plan Template.pdf | ||
| 88310321Q00056 ADAMS.docx | DOCX document | |
| Appendix D - Quality_Assurance_Cloud_CMDB_Template.xlsx | XLSX spreadsheet | |
| Appendix G - Interface Control Document (ICD) Template.pdf | ||
| Amendment 002.docx | DOCX document | |
| Appendix B - Contingency Plan Template.pdf | ||
| Amendment 001 Extension.docx | DOCX document | |
| 88310321Q00056 ADAMS.pdf | ||
| Volume 1 Requirements Matrix.xlsx | XLSX spreadsheet |
Show all 11
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
NARA
IT Security Requirements
NATIONAL ARCHIVES AND RECORDS ADMINISTRATION
September 12, 2019
Version 6.18
Enterprise Architecture IT Security Requirement Version 6.18
SecA.Requirements.docx i September 12, 2019
Version Control
Document version
Description of contents/revisions
Editor
Date
6.0 Revised entire document to
reflect new NIST SP800-
53Rev4 guidance
J. Appleman 11/10/14
6.1 Updated mistyped reference
names in AC, CA and CM sections
J. Appleman 07/16/16
6.2 Update CA-6 requirement for
continuous authorization
J. Appleman 09/22/16
6.3 Update AC-2e to reflect NARA
policy
J Appleman 12/29/16
6.4 Updated PL-4, PL-4c, and PL-
4(1) to reflect NARA policy
J Appleman 01/19/17
6.5 Updated SI-2c to reflect
requirement established in the SI
Methodology
J Appleman 01/25/17
6.6 Updated AC-2j, AC-2(3), RA-
5d, SC-28, AP-2, AR-2, AR-8, DI-1, DI-1c
J Appleman 03/22/17
6.7 MP-3a, CP-8, PE-11, PL-9, SA-
11, SA-12(1), SA-15, SA-34,
SI-3, DI-1
J Appleman 04/20/17
6.8 SC-28 J Appleman 05/09/17
6.9 CA-5 changed “yearly” to
“monthly”
J Appleman 01/09/18
6.10 PE-8 changed “SSP-defined” to
“annually”, AU-11(1) removed
“a minimum of 5 years for
Sources And Methods
Intelligence information”, AC-
12 changed “SSP-defined conditions or trigger events requiring session disconnect” to
“within 30 minutes of inactivity”.
J Appleman 03/20/18
6.11 Updated RA-5 and SI-2
remediation timeframes
J Appleman 07/09/18
6.12 Updated AT-3 J Appleman 09/14/18
SecA.Requirements.docx ii September 12, 2019
Document version
Description of contents/revisions
Editor
Date
6.13 RA-5(5) J. Appleman 10/01/18
6.14 IA-5 J Appleman 11/01/18
6.15 IA-5 J Appleman 11/01/18
6.16 RA-5d and SI-2c: incorporated
BOD 19-02 requirements
J Appleman 05/06/19
6.17 PL-2(3) added moderate J Appleman 06/18/19
6.18 RA-5d and SI-2c: updated the
critical requirement
J Appleman 09/12/19
SecA.Requirements.docx iii September 12, 2019
Table of Contents
1. Introduction _____________________________________________________________ 1
2. NARA IT Security Requirements ____________________________________________ 2
2.1 Access Control Requirements __________________________________________________ 2
2.2 Awareness and Training Requirements _________________________________________ 21
2.3 Audit and Accountability Requirements ________________________________________ 23
2.4 Security Assessment and Authorization Requirements ____________________________ 32
2.5 Configuration Management Requirements ______________________________________ 36
2.6 Contingency Planning Requirements ___________________________________________ 45
2.7 Identification and Authentication Requirements _________________________________ 52
2.8 Incident Response Requirements ______________________________________________ 60
2.9 Maintenance Requirements __________________________________________________ 66
2.10 Media Protection Requirements ______________________________________________ 71
2.11 Physical and Environmental Protection Requirements _____________________________ 75
2.12 Security Planning Requirements ______________________________________________ 84
2.13 Security Program Requirements ______________________________________________ 88
2.14 Personnel Security Requirements _____________________________________________ 91
2.15 Risk Assessment Requirements _______________________________________________ 95
2.16 System and Services Acquisition Requirements __________________________________ 99
2.17 System and Communications Protection Requirements ___________________________ 116
2.18 System and Information Integrity Requirements ________________________________ 133
3. NARA Privacy Controls __________________________________________________ 146
3.1 Authority and Purpose _____________________________________________________ 146
3.2 Accountability, Audit, and Risk Management ___________________________________ 147
3.3 Data Quality and Integrity __________________________________________________ 149
3.4 Data Minimization and Retention ____________________________________________ 150
3.5 Individual Participation and Redress __________________________________________ 151
3.6 Security _________________________________________________________________ 153
3.7 Transparency _____________________________________________________________ 153
SecA.Requirements.docx iv September 12, 2019
3.8 Use Limitation ____________________________________________________________ 154
Appendix A: Requirements Traceability _________________________________________ 156
A.1 NIST Requirements for Federal Information _______________________________________ 156
A.2 OMB Requirements for Privacy within Federal Information ___________________________ 156
A.3 ISOO Requirements for Safeguarding Classified Information __________________________ 157
A.4 GAO Requirements for Resources Management ____________________________________ 159
A.5 FISMA Requirements for Information Security Management __________________________ 160
A.6 ISO Requirements for IT Security Operations _______________________________________ 161
SecA.Requirements.docx 1 September 12, 2019
1. Introduction
As expressed in the IT Security Domain Model, NARA has the following three major sources of
IT security requirements:
Needs for IT Security determined by NARA’s risk profile and based upon an analysis of
NARA’s business and IT risk assessments;
Needs for IT security specifically mandated by or implied by Federal laws, directives and guidelines; and
Needs for IT security specifically stated by or implied by NARA’s IT Security Policies.
This release of NARA’s IT Security Architecture documents security requirements mandated by
FIPS 200, Minimum Security Requirements for Federal Information Systems. The security controls expressed in this publication represents NISTS’s specification for minimum security requirements that must be met by Federal Agencies. The NIST 800 Series of computer security guidelines are published under the authority of the Federal Information Security Management
Act (FISMA) of 2002. The security controls specified by NIST Special Publication 800-53 are intended to safeguard the confidentiality, integrity and availability of information as required under FISMA.
It is important to recognize OMB and NIST documents referenced in the IT Security
Architecture are guidance documents or templates to be used by agencies to develop their own security architectures. They are not final products tailored for NARA and should not be directly utilized by NARA developers.
For example, NIST Special Publication 800-53 describes the following access controls on unsuccessful login attempts:
“The information system enforces a limit of [Assignment: organization-defined number] consecutive invalid access attempts by a user during a [Assignment: organization-defined time period] time period; and automatically [Selection: locks the account/node for an [Assignment:
organization-defined time period], delays next login prompt according to [Assignment:
organization-denied delay algorithm.]] when the maximum number of unsuccessful attempts is exceeded.”
The IT Security Architecture uses the above criteria to develop NARA’s own control objectives.
These are then used to develop policies, requirements, mechanisms, and specifications used to implement the control. This provides a single, consistent source of NARA-wide policy and prevents each organization form developing individual interpretations of Federal guidance.
NARA system developers should utilize NARA’s IT Security Architecture for their security
SecA.Requirements.docx 2 September 12, 2019 requirements. NARA system developers should not independently develop their own security requirements based on their individual interpretations of federal guidance.
For reference purposes, all of NARA’s tailoring to the NIST controls are maintained in square brackets (e.g., “[“ and “]”).
2. NARA IT Security Requirements
The IT Security Requirements are derived from the controls identified in NIST Special
Publication (SP) 800-53 for unclassified information systems and classified information systems.
The requirements for classified information systems were formerly derived from Director of
Central Intelligence Directive (DCID) 6/3, but have since been merged into the Rev. 4 version of the NIST SP 800-53. NIST SP 800-53 represents the specific requirements that must be met to implement the control to the required level for confidentiality, integrity, and availability.
Most of the requirements apply to all of NARA or to all information systems. These will be stated as “NARA shall…” or “Each information system shall…” as appropriate. Other requirements only apply to information systems at a moderate or high level of confidentiality, integrity or availability. These requirements will be qualified as being “For high availability information systems” or “For moderate integrity information systems” or something similar. A few of the requirements are not mandated for any particular system, but can be implemented where data is “deemed by the NARA System Owner to require additional protection” to enhance a particular security control. While no information system is required to enhance security beyond the minimum required levels, if stronger security is desired, it may be enhanced using these controls and control enhancements. Additional requirements that apply to classified systems will be noted as such.
2.1 Access Control Requirements
AC-1. Access Control Policy and Procedures
P1 LOW AC-1 MOD AC-1 HIGH AC-1
AC-1. For all data, the NARA Office of Information Services (I) shall:
AC-1a. Develop, document and disseminate:
1. An access control policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among NARA entities, and compliance; and
2. Procedures to facilitate the implementation of the access control policy and associated access controls; and
AC-1b. Review and update the current:
SecA.Requirements.docx 3 September 12, 2019
1. Access control policy [at least annually]; and
2. Access control procedures [at least annually].
AC-2. Account Management
P1 LOW AC-2 MOD AC-2 (1) (2) (3) (4) HIGH AC-2 (1) (2) (3) (4) (5) (11) (12) (13)
AC-2. For all data, the NARA System Owner shall:
AC-2a. Identify account types (i.e., individual, group, system, application, guest/anonymous, and temporary);
AC-2b. Assign account managers for information system accounts;
AC-2c. Establish conditions for group and role membership;
AC-2d. Specify authorized users of the information system, group and role membership, and access authorizations (i.e., privileges) and other attributes (as required) for each account;
AC-2e. Require approvals by system owner or the system's designated approving official for requests to create information system accounts;
AC-2f. Create, enable, modify, disable, and remove information system accounts in accordance with NARA 804, Information Technology (IT) Systems Security;
AC-2g. Monitor the use of, information system accounts;
AC-2h. Notify account managers:
1. When accounts are no longer required;
2. When users are terminated or transferred; and
3. When individual information system usage or need-to-know changes;
AC-2i. Authorize access to the information system based on:
1. A valid access authorization;
2. Intended system usage; and
3. Other attributes as required by the system functions;
AC-2j. Review accounts compliance with account management requirements [monthly for privileged users; and at least annually for all others].
SecA.Requirements.docx 4 September 12, 2019
AC-2k. Establish a process for reissuing shared/group account credentials (if deployed) when individuals are removed from the group.
AC-2(1) For data requiring moderate or high confidentiality, the NARA System Owner shall employ automated mechanisms to support the management of information system accounts.
AC-2(2) For data requiring moderate or high confidentiality, the information system shall automatically disable temporary and emergency accounts after [a period not to exceed 15 days for unclassified information systems or 72 hours for classified information systems].
AC-2(3) For data requiring moderate or high confidentiality, the information system shall automatically disable inactive accounts after [a period not to exceed 90 days for unclassified information systems or 30 days for classified information systems].
AC-2(4) For data requiring moderate or high confidentiality, the information system shall automatically audit account creation, modification, disabling, and removal actions and shall notify, as required, appropriate individuals.
AC-2 (5) For data requiring high confidentiality, the NARA System Owner shall:
Require that users log out when [15 minutes of inactivity have occurred]
Determine normal time-of-day and duration usage for information system accounts;
Monitor for atypical usage of information system accounts; and
Report atypical usage to designated NARA officials.
AC-2(6) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall dynamically manage user privileges and associated access authorizations.
AC-2(7) For data deemed by the NARA System Owner to require this additional confidentiality protection, the NARA System Owner shall:
(a) Establish and administer privileged user accounts in accordance with a role-based access scheme that organizes information system and network privileges into roles;
(b) Monitor privileged role assignments; and
(c) Disable account when privileged role assignments are no longer appropriate.
AC-2(8) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall create [SSP-defined information system accounts] dynamically.
SecA.Requirements.docx 5 September 12, 2019
AC-2(9) For data deemed by the NARA System Owner to require this additional confidentiality protection, NARA shall only permit the use of shared/group accounts that meet [SSP-defined conditions for establishing shared/group accounts].
AC-2(10) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall terminate shared/group account credentials when members leave the group.
AC-2(11) For data requiring high confidentiality, the information system shall enforce [SSP-defined circumstances and/or usage conditions] for [SSP-defined information system accounts].
AC-2 (12) For data requiring high confidentiality, the NARA System Owner shall:
(a) Monitor information system accounts for [SSP-defined atypical use]; and
(b) Reports atypical usage of information system accounts to system operators, ISSO and IS.
AC-2 (13) For data requiring high confidentiality, the NARA System Owner shall disable accounts of users posing a significant risk within [SSP defined time period] of discovery of the risk.
AC-3. Access Enforcement
LOW AC-3 MOD AC-3 HIGH AC-3
AC-3. For all data, the information system shall enforce approved authorizations for logical access to the system and system resources in accordance with NARA applicable access control policy.
The NARAnet GSS shall provide multifactor access control as a common control for remote and local access to the network. The authentication capability shall be available to externally hosted systems which restrict access to NARA account holders.
Multifactor access mechanisms shall include credentials from HSPD 12 compliant PIV cards.
Users with elevated security privileges shall access the system using a multi factor authentication mechanism that complies with applicable federal directives and NARA policy.
Minor applications receive access enforcement as a service from the General Support
System of which they are a part.
If the security plan of a minor application requires auditing of the actions of users with elevated security privileges, those users shall authenticate using multi-factor mechanisms.
SecA.Requirements.docx 6 September 12, 2019
Minor applications which contain PII enforce assigned authorizations for controlling access to the system in accordance with applicable policy
AC-3(1) [Withdrawn: Incorporated into AC-6].
AC-3(2) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall enforce dual authorization for [SSP defined privileged commands and/or other SSP-defined actions].
AC-3(3) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall enforce [SSP-defined mandatory access control policies] over all subjects and objects where the policy specifies that:
(a) The policy is uniformly enforced across all subjects and objects within the boundary of the information system;
(b) A subject that has been granted access to information is constrained from doing any of the following;
(1) Passing the information to unauthorized subjects or objects;
(2) Granting its privileges to other subjects;
(3) Changing one or more security attributes on subjects, objects, the information system, or information system components;
(4) Choosing the security attributes and attribute values to be associated with newly created or modified objects; or
(5) Changing the rules governing access control; and
(c) [SSP-defined subjects] may explicitly be granted [SSP-defined privileges (i.e., they are trusted subjects)] such that they are not limited by some or all of the above constraints.
AC-3(4) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall enforce a Discretionary Access Control (DAC) over defined subjects and objects where the policy specifies that a subject who has been granted access to information can do one or more of the following:
(a) Pass the information to any other subjects or objects;
(b) Grant its privileges to other subjects;
(c) Change security attributes on subjects, objects, the information system, or the information system’s components;
SecA.Requirements.docx 7 September 12, 2019
(d) Choose the security attributes to be associated with newly created or revised objects; or
(e) Change the rules governing access control.
AC-3(5) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall prevent access to [SSP defined Information] except during secure, non-operable system states.
AC-3(6) [Withdrawn: Incorporated into MP-4 and SC-28].
AC-3 (7) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall enforce a role-based access control policy over defined subjects and objects and controls access based upon [SSP-defined roles and users authorized to assume such roles].
AC-3 (8) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall enforce the revocation of access authorizations resulting from changes to the security attributes of subjects and objects based on [SSP-defined rules governing the timing of revocations of access authorizations].
AC-3 (9) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall not release information outside of the established system boundary unless:
(a) The receiving [SSP-defined information system or system component] provides
[SSP-defined security safeguards]; and
(b) [SSP-defined security safeguards] are used to validate the appropriateness of the information designated for release.
AC-3 (10) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall employ an audited override of automated access control mechanisms under [SSP-defined conditions].
AC-4. Information Flow Enforcement
P1 LOW Not Selected MOD AC-4 HIGH AC-4
AC-4. For data requiring moderate or high confidentiality, the information system shall enforce approved authorizations for controlling the flow of information within the system and between interconnected systems in accordance with applicable policy.
AC-4 (1) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall enforce information flow control using explicit security attributes on information, source, and destination objects as a basis for flow control decisions.
SecA.Requirements.docx 8 September 12, 2019
AC-4 (2) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall enforce information flow control using protected processing domains (e.g., domain type-enforcement) as a basis for flow control decisions.
AC-4 (3) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall enforce dynamic information flow control based on policy that allows or disallows information flows based on changing conditions or operational considerations.
AC-4 (4) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall prevent encrypted data from bypassing content-checking mechanisms.
AC-4 (5) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall enforce [SSP-defined limitations] on embedding data types within other data types.
AC-4 (6) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall enforce information flow control [on SSP-defined metadata].
AC-4 (7) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall enforce [SSP-defined one-way flows] using hardware mechanisms.
AC-4 (8) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall enforce information flow control using [SSP-defined security policy filters] as a basis for flow control decisions for [SSP-defined information flows].
AC-4 (9) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall enforce the use of human review for [SSP-defined security policy filters] when the system is not capable of making an information flow control decision.
AC-4 (10) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall provide the capability for a privileged administrator to enable/disable [SSP-defined security policy filters] under [SSP-defined conditions].
AC-4 (11) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall provide the capability for a privileged administrator to configure [SSP-defined security policy filters] to support different security policies.
SecA.Requirements.docx 9 September 12, 2019
AC-4 (12) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system, when transferring information between different security domains, shall use [SSP-defined data type identifiers] to validate data essential for information flows decisions.
AC-4 (13) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system, when transferring information between different security domains, shall decompose information into [SSP-defined policy-relevant subcomponents] for submission to policy enforcement mechanisms.
AC-4 (14) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system, when transferring information between different security domains, shall implement [SSP-defined security policy filters] requiring fully enumerated formats that restrict data structure and content.
AC-4 (15) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system, when transferring information between different security domains, examines the information for the presence of [SSP-defined unsanctioned information] and prohibits the transfer of such information in accordance with the
[NARA security policy].
AC-4 (16) [Withdrawn: Incorporated into AC-4].
AC-4 (17) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall uniquely identify and authenticate source and destination points by [SSP-defined: organization, system, application, individual] for information transfer.
AC-4 (18) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall bind security attributes to information using [SSP-defined binding techniques] to facilitate information flow policy enforcement.
AC-4 (19) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system, when transferring information between different security domains, shall apply the same security policy filtering to metadata as it applies to data payloads.
AC-4 (20) For data deemed by the NARA System Owner to require this additional confidentiality protection, the system owner shall employ [NARA-defined solutions in approved configurations] to control the flow of [SSP-defined information] across security domains.
AC-4 (21) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall separate information flows logically or
SecA.Requirements.docx 10 September 12, 2019 physically using [SSP-defined mechanisms and/or techniques] to accomplish [SSP-defined required separations by types of information].
AC-4 (22) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall provide access from a single device to computing platforms, applications, or data residing on multiple different security domains, while preventing any information flow between the different security domains.
AC-5. Separation of Duties
P1 LOW Not Selected MOD AC-5 HIGH AC-5
AC-5. For data requiring moderate or high confidentiality, the NARA System Owner shall:
AC-5a. Separate [SSP-defined duties of individuals];
AC-5b. Document separation of duties of individuals; and
AC-5c. Define information system access authorizations to support separation of duties.
AC-6. Least Privilege
P1 LOW Not Selected MOD AC-6 (1) (2) (5) (9) (10) HIGH AC-6 (1) (2) (3) (5) (9) (10)
AC-6. For data requiring moderate or high confidentiality, the NARA System Owner shall employ the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with
NARA missions and business functions.
AC-6 (1) For data requiring moderate or high confidentiality, the NARA System Owner shall explicitly authorize access to [SSP-defined list of security functions (deployed in hardware, software, and firmware) and security-relevant information].
AC-6 (2) For data requiring moderate or high confidentiality, the NARA System Owner shall require that users of information system accounts, or roles, with access to [SSP-defined list of security functions or security-relevant information], use non-privileged accounts, or roles, when accessing other system functions, and, if feasible, audits any use of privileged accounts or roles for such functions.
AC-6 (3) For data requiring high confidentiality, the NARA System Owner shall authorize network access to [SSP-defined privileged commands] only for compelling operational needs and documents the rationale for such access in the security plan for the information system.
AC-6(4) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall provide separate processing domains to enable finer-grained allocation of user privileges.
SecA.Requirements.docx 11 September 12, 2019
AC-6 (5) For data requiring moderate or high confidentiality, the NARA System Owner shall restrict privileged accounts on the information system to [SPP-defined personnel or roles].
AC-6 (6) For data deemed by the NARA System Owner to require this additional confidentiality protection, the NARA System Owner shall prohibit privileged access to the information system by non-NARA users.
AC-6 (7) For data deemed by the NARA System Owner to require this additional confidentiality protection, the System Owner shall:
(a) Review at [SSP-defined frequency] the privileges assigned to [SSP-defined roles or classes of users] to validate the need for such privileges; and
(b) Reassign or remove privileges, if necessary, to correctly reflect NARA mission/business needs.
AC-6 (8) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall prevent [SSP-defined software] from executing at higher privilege levels than users executing the software.
AC-6 (9) For data requiring moderate or high confidentiality, the information system shall audit the execution of privileged functions.
AC-6 (10) For data requiring moderate or high confidentiality, the information system shall prevent non-privileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures.
AC-7. Unsuccessful Login Attempts
P2 LOW AC-7 MOD AC-7 HIGH AC-7
AC-7. For all data, the information system shall:
AC-7a. Enforce a limit of [a maximum of 5 for unclassified information systems or 3 for classified information systems] consecutive invalid login attempts by a user during a [15 minute period]; and
AC-7b. Automatically [lock the account/node for at least 15 minutes for unclassified information systems or 10 minutes for classified information systems] when the maximum number of unsuccessful attempts is exceeded.
AC-7(1) [Withdrawn: Incorporated into AC-7].
AC-7(2) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall purges/wipes information from [NARA defined mobile
SecA.Requirements.docx 12 September 12, 2019 devices] based on [SSP-defined purging/wiping requirements/techniques] after [5] consecutive, unsuccessful device logon attempts.
AC-8. System Use Notification
P1 LOW AC-8 MOD AC-8 HIGH AC-8
AC-8. For all data, the information system shall:
AC-8a. Display to users [a NARA approved system use notification message or banner as documented in NARA Directive 802] before granting access to the system that provides privacy and security notices consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance and states that:
Users are accessing a U.S. Government information system;
Information system usage may be monitored, recorded, and subject to audit;
Unauthorized use of the system is prohibited and subject to criminal and civil penalties;
and
Use of the information system indicates consent to monitoring and recording;
AC-8b. Retain the notification message or banner on the screen until users acknowledge the usage conditions and take explicit actions to log on to or further access the information system;
and
AC-8c. For publicly accessible systems:
1. Display the system use information when appropriate, before granting further access;
2. Display references, if any, to monitoring, recording, or auditing that are consistent with privacy accommodations for such systems that generally prohibit those activities; and
3. Include a description of the authorized uses of the system.
AC-9. Previous Logon (Access) Notification
P0 LOW Not Selected MOD Not Selected HIGH Not Selected
AC-9. For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall notify the user, upon successful logon (access) to the system, of the date and time of the last logon (access).
SecA.Requirements.docx 13 September 12, 2019
AC-9 (1) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall notify the user, upon successful logon/access, of the number of unsuccessful logon/access attempts since the last successful logon/access.
AC-9 (2) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall notify the user of the number of [unsuccessful login attempts] during [the period since the last successful login/access attempt].
AC-9 (3) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall notify the user of change to [SSP-defined set of security-related changes to the user’s account] during [SSP-defined time period].
AC-9 (4) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall notify the user, upon successful logon (access), of the following additional information: [SSP-defined information to be included in addition to the date and time of the last logon (access)].
AC-10. Concurrent Session Control
P3 LOW Not Selected MOD Not Selected HIGH AC-10
AC-10. For data requiring high confidentiality, the information system shall limit the number of concurrent sessions for each system account to [a maximum of three (3) sessions].
AC-11. Session Lock
P3 LOW Not Selected MOD AC-11 (1) HIGH AC-11 (1)
AC-11. For data requiring moderate or high confidentiality, the information system shall:
AC-11a. Prevent further access to the system by initiating a session lock after [30 minutes] of inactivity or upon receiving a request from a user; and
AC-11b. Retain the session lock until the user reestablishes access using established identification and authentication procedures.
AC-11(1) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system conceals, via the session lock, information previously visible on the display with a publicly viewable image.
AC-12. Session Termination
P2 LOW Not Selected MOD AC-12 HIGH AC-12
AC-12 . For data requiring moderate or high confidentiality, the information system automatically terminates a user session after [within 30 minutes of inactivity].
SecA.Requirements.docx 14 September 12, 2019
AC-12 (1) The information system shall:
(a) Provide a logout capability for user-initiated communications sessions whenever authentication is used to gain access to [SSP-defined information resources]; and
(b) Displays an explicit logout message to users indicating the reliable termination of authenticated communications sessions.
AC-13. Supervision and Review — Access Control
AC-13 . [Withdrawn: Incorporated into AC-2 and AU-6].
AC-14. Permitted Actions without Identification or Authentication
P3 LOW AC-14 MOD AC-14 HIGH AC-14
AC-14. For all data, the NARA System Owner shall:
AC-14a. Identify [SSP-defined user actions] that can be performed on the information system without identification or authentication consistent with NARA missions/business functions; and
AC-14b. Document and provide supporting rationale in the security plan for the information system, user actions not requiring identification and authentication.
AC-14(1) [Withdrawn: Incorporated into AC-14].
AC-15. Automated Marking
AC-15 . [Withdrawn: Incorporated into MP-3].
AC-16. Security Attributes
P0 LOW Not Selected MOD Not Selected HIGH Not Selected
AC-16. For data deemed by the NARA System Owner to require this additional confidentiality protection, the System Owner shall:
AC-16a. Provide the means to associate [SSP-defined types of security attributes] having [SSP-defined security attribute values] with information in storage, in process, and/or in transmission;
AC-16b. Ensure that the security attribute associations are made and retained with the information;
AC-16c. Establish the permitted [SSP-defined security attributes] for [SSP-defined information systems]; and
AC-16d. Determines the permitted [SSP-defined values or ranges] for each of the established security attributes.
SecA.Requirements.docx 15 September 12, 2019
AC-16 (1) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall dynamically associates security attributes with [SSP-defined subjects and objects] in accordance with [SSP-defined security policies] as information is created and combined.
AC-16 (2) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall provide authorized individuals (or processes acting on behalf of individuals) the capability to define or change the value of associated security attributes.
AC-16 (3) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall maintain the association and integrity of
[SSP-defined security attributes] to [SSP-defined subjects and objects].
AC-16(4) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall support the association of [SSP-defined security attributes] with [SSP-defined subjects and objects] by authorized individuals (or processes acting on behalf of individuals).
AC-16 (5) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall displays security attributes in human-readable form on each object that the system transmits to output devices to identify [SSP-identified special dissemination, handling, or distribution instructions] using [SSP-identified human-readable, standard naming conventions].
AC-16 (6) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall allow personnel to associate, and maintain the association of [SSP-defined security attributes] with [SSP-defined subjects and objects] in accordance with [SSP-defined security policies].
AC-16 (7) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall provides a consistent interpretation of security attributes transmitted between distributed information system components.
AC-16 (8) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall implements [SSP-defined techniques or technologies] with [SSP-defined level of assurance] in associating security attributes to information.
AC-16 (9) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall ensures that security attributes associated
SecA.Requirements.docx 16 September 12, 2019 with information are reassigned only via re-grading mechanisms validated using [SSP-defined techniques or procedures].
AC-16 (10) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall provides authorized individuals the capability to define or change the type and value of security attributes available for association with subjects and objects.
AC-17. Remote Access
P1 LOW AC-17 MOD AC-17 (1) (2) (3) (4) HIGH AC-17 (1) (2) (3) (4)
AC-17. For all data, the NARA Office of Information Services (I) shall:
AC-17a. Establish and document usage restrictions, configuration/connection requirements, and implementation guidance for each type of remote access allowed; and
AC-17b. Authorize remote access to the information system prior to allowing such connections.
AC-17 (1) For data requiring moderate or high confidentiality, the information system shall monitor and control remote access methods.
AC-17 (2) For data requiring moderate or high confidentiality, the information system shall implement cryptographic mechanisms to protect the confidentiality and integrity of remote access sessions.
AC-17 (3) For data requiring moderate or high confidentiality, the information system shall route all remote accesses through a [SSP-defined number] managed access control points.
AC-17 (4) For data requiring moderate or high confidentiality, the NARA Office of Information
Services (I) shall:
(a) authorize the execution of privileged commands and access to security-relevant information via remote access only for [SSP-defined needs]; and
(b) document the rationale for such access in the security plan for the information system.
AC-17 (5) [Withdrawn: Incorporated into AC-17].
AC-17(6) For data deemed by the NARA System Owner to require this additional confidentiality protection, the NARA Office of Information Services (I) shall ensure that users protect information about remote access mechanisms from unauthorized use and disclosure.
AC-17(7) [Withdrawn: Incorporated into AC-3 ].
AC-17(8) [Withdrawn: Incorporated into CM-7 ].
SecA.Requirements.docx 17 September 12, 2019
AC-17 (9) For data deemed by the NARA System Owner to require this additional confidentiality protection, the System Owner shall provide the capability to expeditiously disconnect or disable remote access to the information system within [SSP-defined time period].
AC-18. Wireless Access
P1 LOW AC-18 MOD AC-18 (1) HIGH AC-18 (1) (4) (5)
AC-18. For all data, the NARA Office of Information Services (I) shall:
AC-18a. Establish usage restrictions, configuration/connection requirements, and implementation guidance for wireless access;
AC-18b. Authorize wireless access to the information system prior to connection
AC-18 (1) For data requiring moderate or high confidentiality, the information system shall protect wireless access to the system using authentication of [Selection (one or more): users;
devices] and encryption.
AC-18(2) [Withdrawn: Incorporated into SI-4 ].
AC-18(3) For data deemed by the NARA System Owner to require this additional confidentiality protection, the NARA System Owner shall disable, when not intended for use, wireless networking capabilities internally embedded within information system components prior to issuance and deployment.
AC-18(4) For data requiring high confidentiality, the NARA Office of Information Services (I) shall identify and explicitly authorize users allowed to independently configure wireless networking capabilities.
AC-18(5) For data requiring high confidentiality, the NARA Office of Information Services (I) shall select radio antennas and calibrate transmission power levels to reduce the probability that usable signals can be received outside of NARA-controlled boundaries..
AC-19. Access Control for Mobile Devices
P1 LOW AC-19 MOD AC-19 (5) HIGH AC-19 (5)
AC-19. For all data, the NARA Office of Information Services (I) shall:
AC-19a. Establish usage restrictions, configuration requirements, and implementation guidance for NARA-controlled mobile devices; and
AC-19b. Authorize the connection of mobile devices to NARA information systems;
AC-19(1) [Withdrawn: Incorporated into MP-7].
SecA.Requirements.docx 18 September 12, 2019
AC-19(2) [Withdrawn: Incorporated into MP-7].
AC-19(3) [Withdrawn: Incorporated into MP-7].
AC-19(4) For data deemed by the NARA System Owner to require this additional confidentiality protection, the NARA Office of Information Services (I) shall:
(a) Prohibit the use of unclassified mobile devices in facilities containing information systems processing, storing, or transmitting classified information unless specifically permitted by the authorizing official; and
(b) Enforce the following restrictions on individuals permitted by the authorizing official to use unclassified mobile devices in facilities containing information systems processing, storing, or transmitting classified information:
(1) Connection of unclassified mobile devices to classified information systems is prohibited;
(2) Connection of unclassified mobile devices to unclassified information systems requires approval from the authorizing official;
(3) Use of internal or external modems or wireless interfaces within the unclassified mobile devices is prohibited; and
(4) Unclassified mobile devices and the information stored on those devices are subject to random reviews and inspections by [Office of Information Services (I)], and if classified information is found, the incident handling policy is followed.
(c) Restrict the connection of classified mobile devices to classified information systems in accordance with [NARA-defined security policies].
AC-19 (5) For data requiring moderate high confidentiality, NARA employs [Selection: full-device encryption; container encryption] to protect the confidentiality and integrity of information on [SSP-defined mobile devices].
AC-20. Use of External Information Systems
P1 LOW AC-20 MOD AC-20 (1) (2) HIGH AC-20 (1) (2)
AC-20. For all data, the NARA Office of Information Services (I) shall establish terms and conditions, consistent with any trust relationships established with other organizations owning, operating, and/or maintaining external information systems, allowing authorized individuals to:
AC-20a. Access the information system from the external information systems; and
SecA.Requirements.docx 19 September 12, 2019
AC-20b. Process, store, and/or transmit NARA-controlled information using the external information systems.
AC-20 (1) For data requiring moderate or high confidentiality, the NARA Office of Information
Services (I) shall permit authorized individuals to use an external information system to access the information system or to process, store, or transmit NARA-controlled information only when the NARA Office of Information Services (I) has:
(a) Verified the implementation of required security controls on the external system as specified in the NARA Office of Information Services (I)’s information security policy and security plan; or
(b) Retained approved information system connection or processing agreements with the
NARA entity hosting the external information system.
AC-20 (2) For data requiring moderate or high confidentiality, the NARA Office of Information
Services (I) shall [restrict] the use of NARA-controlled portable storage media by authorized individuals on external information systems.
AC-20 (3) For data deemed by the NARA System Owner to require this additional confidentiality protection, the NARA Office of Information Services (I) shall [restrict] the use of non-NARA owned information systems, system components, or devices to process, store, or transmit NARA information.
AC-20 (4) For data deemed by the NARA System Owner to require this additional confidentiality protection, the NARA Office of Information Services (I) shall prohibit the use of
[NARA-defined network accessible storage devises] in external information systems.
AC-21. Information Sharing
P2 LOW Not Selected MOD AC-21 HIGH AC-21
AC-21. For data requiring moderate or high confidentiality, the NARA System Owner shall:
AC-21a. Facilitate information sharing by enabling authorized users to determine whether access authorizations assigned to the sharing partner match the access restrictions on the information for
[SSP-defined information sharing circumstances where user discretion is required]; and
AC-21b. Employ [SSP-defined automated mechanisms or manual processes] to assist users in making information sharing/collaboration decisions.
AC-21 (1) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall enforce information-sharing decisions by
SecA.Requirements.docx 20 September 12, 2019 authorized users based on access authorizations of sharing partners and access restrictions on information to be shared.
AC-21 (2) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall implement information search and retrieval services that enforce [SSP-defined information sharing restrictions].
AC-22. Publicly Accessible Content
P3 LOW AC-22 MOD AC-22 HIGH AC-22
AC-22. For all data, the NARA Office of Information Services (I) shall:
AC-22a. Designate individuals authorized to post information onto a publicly accessible information system;
AC-22b. Train authorized individuals to ensure that publicly accessible information does not contain nonpublic information;
AC-22c. Review the proposed content of information prior to posting onto the publicly accessible information system to ensure that nonpublic information is not included; and
AC-22d. Review the content on the publicly accessible NARA information system for nonpublic information [annually]; and removes such information, if discovered.
AC-23. Data Mining Protection
P0 LOW Not Selected MOD Not Selected HIGH Not Selected
AC-23. For data deemed by the NARA System Owner to require this additional confidentiality protection, the System Owner shall employ [SSP-defined data mining prevention and detection techniques] for [SSP-defined data storage objects] to adequately detect and protect against data mining.
AC-24 ACCESS CONTROL DECISIONS
P0 LOW Not Selected MOD Not Selected HIGH Not Selected
AC-24. For data deemed by the NARA System Owner to require this additional confidentiality protection, the System Owner shall establish procedures to ensure [SSP-defined access control decisions] are applied to each access request prior to access enforcement.
AC-24 (1) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall transmit [SSP-defined access authorization information] using [SSP-defined security safeguards] to [SSP-defined information systems] that enforce access control decisions.
SecA.Requirements.docx 21 September 12, 2019
AC-24 (2) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall enforce access control decisions based on
[SSP-defined security attributes] that do not include the identity of the user or process acting on behalf of the user.
AC-25 REFERENCE MONITOR
P0 LOW Not Selected MOD Not Selected HIGH Not Selected
AC-25. For data deemed by the NARA System Owner to require this additional confidentiality…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .