Att-17_SBIWTP_SSP_042020.pdf
PDF 850 KB Posted
- Attached to
- O&M Services SBIWTP Federal contract opportunity
- Solicitation number
- 191BWC20R0002
About this file
This solicitation is for operation and maintenance services for the South Bay International Wastewater Treatment Plant located in San Diego County, California. The contractor shall provide full-service O&M including day-to-day management, supervision, personnel, sampling, testing, equipment operation and maintenance, monitoring, reporting, supplies, and other services. The contract is for a base year plus four option years with a 30-day transition period ending September 30, 2020. The treatment plant processes an average of 25 million gallons per day under the authority of the International Boundary and Water Commission United States-Mexico Section.
View the file
Other files for this federal contract opportunity
Show all 43
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
International Boundary and Water Commission
South Bay International Wastewater Treatment Plant (SIWTP) Supervisory Control and Data Acquisition (SCADA) System
System Security Plan
Submitted to The Information Management Division, U.S. Section El Paso, TX 79902
SBIWTP SCADA System - System Security Plan
Version Control
Date Author Version
09/013/2016 Corey Lancaster 1.0 – Initial Draft
09/22/2016 R. Smith Updated diagram.
10/15/18 WachField Industries Updated Controlls
04/10/20 Z. Mora 2.0 Updated
1 SIGNATURES AND APPROVAL
I have read and understand the security controls that are defined in this document. The signature below signifies an approval for the SBIWTP SCADA System (System) to remain in operation.
__________________ ___4/10/20__________
Zenon Mora Supervisory, IT Specialist / ISSM Date
Table of Contents
1 SIGNATURES AND APPROVAL .............................................. ii
1 SYSTEM CHARACTERIZATION
1.1 System Name and Unique Project Identifier
1.2 System Type
1.3 System Categorization
1.4 System Status
1.5 Responsible Organization
1.6 Information Contacts
1.7 General Description / Purpose
1.8 System Environment
1.9 System Interconnection / Information Sharing
1.9.1 System Dependencies
1.9.2 System Component Inventory
1.10 Applicable Laws or Regulations Affecting the System
1.11 FIPS 199 Levels
1.11.1 Security Categorization/Information Type(s)
1.11.2 Protection Requirements
1.11.3 Protection Requirement Findings
2 MANAGEMENT CONTROLS
2.1 (CA) Security Assessment and Authorization
2.1.1 (CA-1) Security Assessment and Authorization Policies and Procedures ... 10
2.1.2 (CA-2) Security Assessments
2.1.3 (CA-3) Information System Connections
2.1.4 (CA-5) Plan of Action and Milestones
2.1.5 (CA-6) Security Authorization
2.1.6 (CA-7) Continuous Monitoring
2.2 (PL) Planning
2.2.1 (PL-1) Security Planning Policy and Procedures
2.2.2 (PL-2) System Security Plan
2.2.3 (PL-4) Rules of Behavior
2.2.4 (PL-8) Information Security Architecture
2.3 (RA) Risk Assessment
2.3.1 (RA-1) Risk Assessment Policy and Procedures
2.3.2 (RA-2) Security Categorization
2.3.3 (RA-3) Risk Assessment
2.3.4 (RA-5) Vulnerability Scanning
2.4 (SA) System and Services Acquisition
2.4.1 (SA-1) System and Services Acquisition Policy and Procedures
2.4.2 (SA-2) Allocation of Resources
2.4.3 (SA-3) Life Cycle Support
2.4.4 (SA-4) Acquisitions
2.4.5 (SA-5) Information System Documentation
2.4.6 (SA-8) Security Engineering Principles
2.4.7 (SA-9) External Information System Services
2.4.8 (SA-10) Developer Configuration Management
2.4.9 (SA-11) Developer Security Testing
2.4.10 (SA-12) Supply Chain Protection
2.4.11 (SA-15) Development Process, Standards, and Tools
2.4.12 (SA-16) Developer Provided Training
2.4.13 (SA-17) Developer Security Architecture and Design
3 OPERATIONAL CONTROLS
3.1 (AT) Awareness and Training
3.1.1 (AT-1) Security Awareness and Training Policy and Procedures
3.1.2 (AT-2) Security Awareness
3.1.3 (AT-3) Role-Based Security Training
3.1.4 (AT-4) Security Training Records
3.2 (CM) Configuration Management
3.2.1 (CM-1) Configuration Management Policy and Procedures
3.2.2 (CM-2) Baseline Configuration
3.2.3 (CM-3) Configuration Change Control
3.2.4 (CM-4) Monitoring Configuration Changes
3.2.5 (CM-5) Access Restrictions for Change
3.2.6 (CM-6) Configuration Settings
3.2.7 (CM-7) Least Functionality
3.2.8 (CM-8) Information System Component Inventory
3.2.9 (CM-9) Configuration Management Plan
3.2.10 (CM-10) Software Usage Restrictions
3.2.11 . (CM-11) User Installed Software
3.3 (CP) Contingency Planning
3.3.1 (CP-1) Contingency Planning Policy and Procedures
3.3.2 (CP-2) Contingency Plan
3.3.3 (CP-3) Contingency Training
3.3.4 (CP-4) Contingency Plan Testing
3.3.5 (CP-6) Alternate Storage Site
3.3.6 (CP-7) Alternate Processing Site ................... Error! Bookmark not defined.
3.3.7 (CP-8) Telecommunications Services ........... Error! Bookmark not defined.
3.3.8 (CP-9) Information System Backup
3.3.9 (CP-10) Information System Recovery and Reconstitution
3.4 (IR) Incident Response
3.4.1 (IR-1) Incident Response Policy and Procedures
3.4.2 (IR-2) Incident Response Training
3.4.3 (IR-3) Incident Response Testing and Exercises
3.4.4 (IR-4) Incident Handling
3.4.5 (IR-5) Incident Monitoring
3.4.6 (IR-6) Incident Reporting
3.4.7 (IR-7) Incident Response Assistance
3.4.8 (IR-8) Incident Response Plan
3.5 (MA) Maintenance
3.5.1 (MA-1) System Maintenance Policy and Procedures
3.5.2 (MA-2) Controlled Maintenance
3.5.3 (MA-3) Maintenance Tools
3.5.4 (MA-4) Remote Maintenance
3.5.5 (MA-5) Maintenance Personnel
3.5.6 (MA-6) Timely Maintenance
3.6 (MP) Media Protection
3.6.1 (MP-1) Media Protection Policy and Procedures
3.6.2 (MP-2) Media Access
3.6.3 (MP-3) Media Labeling
3.6.4 (MP-4) Media Storage
3.6.5 (MP-5) Media Transport
3.6.6 (MP-6) Media Sanitization and Disposal
3.6.7 (MP-7) Media Use
3.7 (PE) Physical and Environmental Protection
3.7.1 (PE-1) Physical and Environmental Protection Policy and Procedures
3.7.2 (PE-2) Physical Access Authorizations
3.7.3 (PE-3) Physical Access Control
3.7.4 (PE-4) Access Control for Transmission Medium
3.7.5 (PE-5) Access Control for Output Devices
3.7.6 (PE-6) Monitoring Physical Access
3.7.7 (PE-8) Access Records
3.7.8 (PE-9) Power Equipment and Power Cabling
3.7.9 (PE-10) Emergency Shutoff
3.7.10 (PE-11) Emergency Power
3.7.11 (PE-12) Emergency Lighting
3.7.12 (PE-13) Fire Protection
3.7.13 (PE-14) Temperature and Humidity Controls
3.7.14 (PE-15) Water Damage Protection
3.7.15 (PE-16) Delivery & Removal
3.7.16 (PE-17) Alternate Work Site .......................... Error! Bookmark not defined.
3.7.17 (PE-18) Location of Information System Components
3.8 (PS) Personnel Security
3.8.1 (PS-1) Personnel Security Policy and Procedures
3.8.2 (PS-2) Position Categorization
3.8.3 (PS-3) Personnel Screening
3.8.4 (PS-4) Personnel Termination
3.8.5 (PS-5) Personnel Transfer
3.8.6 (PS-6) Access Agreements
3.8.7 (PS-7) Third-Party Personnel Security
3.8.8 (PS-8) Personnel Sanctions
3.9 (SI) System and Information Integrity
3.9.1 (SI-1) System and Information Integrity Policy and Procedures
3.9.2 (SI-2) Flaw Remediation
3.9.3 (SI-3) Malicious Code Protection
3.9.4 (SI-4) Information System Monitoring Tools and Techniques
3.9.5 (SI-5) Security Alerts and Advisories
3.9.6 (SI-6) Security Functionality Verification
3.9.7 (SI-7) Software and Information Integrity
3.9.8 (SI-8) Spam Protection
3.9.9 (SI-10) Information Accuracy, Completeness, Validity, and Authenticity
3.9.10 (SI-11) Error Handling
3.9.11 (SI-12) Information Output Handling and Retention
3.9.12 (SI-16) Memory Protection
4 TECHNICAL CONTROLS
4.1 (AC) Access Control
4.1.1 (AC-1) Access Control Policy and Procedures
4.1.2 (AC-2) Account Management
4.1.3 (AC-3) Access Enforcement
4.1.4 (AC-4) Information Flow Enforcement
4.1.5 (AC-5) Separation of Duties
4.1.6 (AC-6) Least Privilege
4.1.7 (AC-7) Unsuccessful Login Attempts
4.1.8 (AC-8) System Use Notification
4.1.9 (AC-10) Concurrent Session Control
4.1.10 (AC-11) Session Lock
4.1.11 (AC-12) Session Termination
4.1.12 (AC-14) Permitted Actions w/o Identification or Authentication
4.1.13 (AC-17) Remote Access
4.1.14 (AC-18) Wireless Access Restrictions Control: The organization:
4.1.15 (AC-19) Access Control for Portable and Mobile Devices
4.1.16 (AC-20) Use of External Information Systems
4.1.17 (AC-21) Information Sharing
4.1.18 (AC-22) Publicly Accessible Content
4.2 (AU) Audit and Accountability
4.2.1 (AU-1) Audit and Accountability Policy and Procedures
4.2.2 (AU-2) Auditable Events
4.2.3 (AU-3) Content of Audit Records
4.2.4 (AU-4) Audit Storage Capacity
4.2.5 (AU-5) Response to Audit Processing Failures
4.2.6 (AU-6) Audit Monitoring, Analysis, and Reporting
4.2.7 (AU-7) Audit Reduction and Report Generation
4.2.8 (AU-8) Time Stamps
4.2.9 (AU-9) Protection of Audit Information
4.2.10 (AU-10) Non-Repudiation
4.2.11 (AU-11) Audit Record Retention
4.2.12 (AU-12) Audit Generation
4.3 (IA)Identification and Authentication
4.3.1 (IA-1) Identification and Authentication Policy and Procedures
4.3.2 (IA-2) User Identification and Authentication
4.3.3 (IA-3) Device Identification and Authentication
4.3.4 (IA-4) Identifier Management
4.3.5 (IA-5) Authenticator Management
4.3.6 (IA-6) Authenticator Feedback
4.3.7 (IA-7) Cryptographic Module Authentication
4.3.8 (IA-8) Cryptographic Module Authentication
4.4 (SC) System and Communications Protection
4.4.1 (SC-1) System and Communications Protection Policy and Procedures
4.4.2 (SC-2) Application Partitioning
4.4.3 (SC-3) Security Function Isolation
4.4.4 (SC-4) Information Remnants
4.4.5 (SC-5) Denial of Service Protection
4.4.6 (SC-7) Boundary Protection
4.4.7 (SC-8) Transmission Confidentiality and Integrity
4.4.8 (SC-10) Network Disconnect
4.4.9 (SC-12) Cryptographic Key Establishment and Management
4.4.10 (SC-13) Use of Cryptography
4.4.11 (SC-15) Collaborative Computing Control: The information system:
4.4.12 (SC-17) Public Key Infrastructure Certificates
4.4.13 (SC-19) Voice Over Internet Protocol
4.4.14 (SC-20) Secure Name/Address Resolution Service (Authoritative Source) . 98
4.4.15 (SC-21) Secure Name/Address Resolution Service (Recursive or Caching Resolver)
4.4.16 (SC-22) Architecture and Provisioning for Name/Address Resolution Service
4.4.17 (SC-23) Session Authenticity
4.4.18 (SC-28) Protection of Information at Rest
4.5 (PM) Program Management
4.5.1 (PM-1) Program Management Policy and Procedures
4.5.2 (PM-2) Senior Information Security Officer
4.5.3 (PM-3) Information Security Resources
4.5.4 (PM-4) Plan of Action and Milestones
4.5.5 (PM-5) Information System Inventory
4.5.6 (PM-6) Information Security Measures of Performance
4.5.7 (PM-7) Enterprise Architecture
4.5.8 (PM-8) Critical Infrastructure Plan
4.5.9 (PM-9) Risk Management Strategy
4.5.10 (PM-10) Security Authorization Process
4.5.11 (PM-11) Mission/Business Process Definition
4.5.12 (PM-12) Insider Threat Program
4.5.13 (PM-13) Information Security Workforce
4.5.14 (PM-14) Testing, Training, and Monitoring
4.5.15 (PM-15) Contacts With Security Groups and Organizations
4.5.16 (PM-16) Threat Awareness Program
APPENDIX A SYSTEM STEWARD AND AO RESPONSIBILITIES .. 1
1 SYSTEM CHARACTERIZATION
1.1 System Name and Unique Project Identifier
The system name is South Bay International Water Treatment Plant (SBIWTP) SCADA.
1.2 System Type
The System is a General Support System (GSS). The SCADA Network governs all processes of the wastewater treatment plant.
1.3 System Categorization
The System is categorized with a FIPS 199 Criticality Watermark of High. The Information Types that were selected are taken from the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-60 Volume 2. The selected information types are listed in the table below with a supporting rationale for the Availability, Integrity, and Confidentiality security services in that order.
1.4 System Status
The System has completed a major modification and upgrade and is in full operation.
1.5 Responsible Organization
The organization that is responsible for the System is the International Boundary and Water Commission
(IBWC).
1.6 Information Contacts1
The following is contact information for the System points of contact System Stewards and the Authorizing Official (AO).
Table 1- 1: Point of Contact List
Business Steward Security Steward Authorizing Official
Name Nicolas Chapa Zenon Mora Jayne Harkins
Title System Owner ISSM Commissioner
Address 2995 Clearwater Way, in San Diego, CA, 92173
4191 N. Mesa, El Paso, TX 79902
4191 N. Mesa, El Paso, TX 79902
Phone (619) 662-7600 (915) 832-4755 (915) 832-4101
E-mail Nicolas.Chapa@ibwc.gov> z.mora@ibwc.gov Jayne.Harkins@ibwc.gov
1.7 General Description / Purpose
The SBIWTP is a 25 million gallons per day advanced primary treatment plant located in San Diego County, California, about 2 miles west of the San Ysidro Port of Entry. The physical - chemical plant treats sewage
1 System Stewards and AO responsibilities are in Appendix A.
originating in Tijuana, Mexico and discharges it to the Pacific Ocean through the South Bay Ocean Outfall, a four and one-half mile long 11foot diameter pipe completed in January 1999.
The South Bay International Wastewater Treatment Plant (SBIWTP) was designed to deal with the growing demand for the treatment of wastewater resulting in the contamination of the Tijuana River in the United States. It has been an ongoing concern since 1934 when the International Boundary Commission (IBC) was instructed by the United States and Mexican governments to cooperate in the preparation of a report on the Tijuana sewage problem. The SBIWTP is capable of providing secondary treatment for 25 million gallons per day (mgd) average daily flows of sewage in excess of the Tijuana sewage system capacity but has expansion capability of up to 100 mgd. The SBIWTP was built on a 75-acre site near the international boundary in the U.S.
The purpose of the SCADA Network is to monitor and control the industrial processes that comprise the entire wastewater treatment plant. Every industrial process has modifiers with established set-points that the processes cannot exceed (i.e. chlorine content must have certain potency levels. The SCADA Network ensures that all of the established industrial processes within the SBIWTP Industrial Control System (ICS) operate within these defined set-points.
The facility’s Arizona Department of Environmental Quality (ADEQ) Aquifer Protection Permit (APP) requires maintaining an A+ effluent water quality rating for reuse. This rating minimizes the possibility of human exposure to potential pathogens in the effluent water. It also stipulates a lower total effluent nitrogen concentration in order to minimize nitrate contamination of groundwater at recharge sites. Water quality must be monitored and reported in order to comply with the APP.
The USIBWC is a federal government agency and is headquartered in El Paso, Texas. The IBWC operates under the foreign policy guidance of the Department of State (DoS).
1.8 System Environment
Figure 1-1: IBWC - SBIWTP Network Diagram
1.9 System Interconnection / Information Sharing
Table 1- 2: System Interconnection/Information Sharing
System Name
Responsible
Organization
Type (e.g.
TCP/IP)
SIA/MOU/
MOA
Date FIPS 199 Rating
(Low, Moderate, High)
ATO
(Yes/No)
CDM GovPlace Security Monitoring
MOU 2020 High No
1.9.1 System Dependencies
The following is a list of dependencies for the System:
Bioreactor Mixer
Bioreactor #1 - #3 Valve
Bioreactor #1 - #3 Mixed Liquor
Grit Pump #1 - #2
Air Blower #1 - #5
Secondary Clarifier #1 - #3
RAS Pump #1 - #5
WAS Valves
WAS Pumps
Digestion Pond Aerators
Rotary Drum Thickener #1 and #2
Digestion Mixing Pump
Polymer System Station
Aerobic Digester Aerator System
SE Pump Station #1 - #3
WSSP Aerator #1-4
Generator and ATS Station
MDT Auto-save
Alarm System
1.9.2 System Component Inventory
Below is a table of the SCADA Network Component Inventory
Table 1-3: SCADA Network Inventory
Host Name Description IP Address Subnet Mask
Default Gateway DNS
DMZ
Status
ESX Host ESX Host 192.198.2.2
255.255.2 55.0
192.198.0.
192.168.20 0.10
IDRAC
192.168.2.2
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
SAND-IBWC-
DC-01
Domain Controller
192.168.2.3
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
SAND-IBWC-
DC-01
Domain Controller
192.168.1.3
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
Host Name Description IP Address Subnet Mask
Default Gateway DNS
DMZ
Status
SAND-IBWC-
AP-01
SAND-IBWC-
AP-01
192.168.2.3
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
SAND-IBWC-
AP-01
SAND-IBWC-
AP-01
192.168.1.3
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
SAND-IBWC-
AP-02
SAND-IBWC-
AP-02
192.168.2.4
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
SAND-IBWC-
AP-02
SAND-IBWC-
AP-02
192.168.1.4
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
SD-VSHERE SD-VSHERE
192.168.2.4
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
ESX Host ESX Host 192.198.2.2
255.255.2 55.0
192.198.0.
192.168.20 0.10
Inside Zone
IDRAC
192.168.2.2
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
SAND-IBWC-
IG-01
SAND-IBWC-
IG-01
192.168.2.4
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
SAND-IBWC-
DB-01 Database
192.168.2.4
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
SAND-IBWC-
TST-01
SAND-IBWC-
TST-01
192.168.2.4
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
SAND-IBWC-
CT-01
SAND-IBWC-
CT-01
192.168.2.4
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
ESX Host ESX Host 192.198.2.2
255.255.2 55.0
192.198.0.
192.168.20 0.10
Inside Zone
IDRAC
192.168.2.2
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
SAND-IBWC-
DC-02
Domain Controller
192.168.2.4
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
SAND-IBWC-
DC-02
Domain Controller
192.168.1.4
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
SAND-IBWC-
DB-02 Database
192.168.2.4
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
SAND-IBWC-
IG-02
SAND-IBWC-
IG-02
192.168.2.4
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
SWITCH 1 SWITCH 1
192.168.2.1
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
SWITCH 2 SWITCH 2
192.168.2.1
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
THIN CLIENTS
192.168.2.8
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
THIN CLIENTS
192.168.2.8
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
THIN CLIENTS
192.168.2.8
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
THIN CLIENTS
192.168.2.8
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
THIN CLIENTS
192.168.2.8
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
THIN CLIENTS
192.168.2.8
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
THIN CLIENTS
192.168.2.8
255.255.2 55.0
192.168.0.
192.168.20 0.10
Host Name Description IP Address Subnet Mask
Default Gateway DNS
DMZ
Status
THIN CLIENTS
192.168.2.8
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
THIN CLIENTS
192.168.2.8
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
THIN CLIENTS
192.168.2.8
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
THIN CLIENTS
192.168.2.9
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
THIN CLIENTS
192.168.2.9
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
THIN CLIENTS
192.168.2.9
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
THIN CLIENTS
192.168.2.9
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
THIN CLIENTS
192.168.2.9
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
THIN CLIENTS
192.168.2.9
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
THIN CLIENTS
192.168.2.9
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
RESERVED
ESX ESX
192.168.2.2
255.255.2 55.0
192.168.0.
192.168.20 0.10
Inside Zone
RESERVED
IDRAC IDRAC
192.168.2.2
255.255.2 55.0
192.168.0.
192.168.20 0.10
GovPlace Sensor
152.180.135 .236
255.255.2 55.0
152.180.1.
192.168.20 0.10
Outside
1.10 Applicable Laws or Regulations Affecting the System
The U.S. IBWC is responsible for implementing and administering a security program to protect its information resources in compliance with federal laws and regulations. The following section denotes applicable laws and regulations, standards, and guidelines from which USIBWC system security requirements are derived.
Executive Orders (EO)
EO 10450 Security Requirements for Government Employment
EO 10310 Critical Infrastructure Protection
EO 13011 Federal Information Technology
EO 13103 Computer Software Piracy
Homeland Security Presidential Directive 7
Federal Laws
Title II of the E-Government Act of 2002, Section 208
Privacy Act of 1974 (P.L. 93-579)
Freedom of Information Act of 1974
Federal Records Management Acts
Computer Fraud and Abuse Act of 1986 (P.L. 99-474)
Clinger-Cohen Act of 1996
Defense Authorization Act (P.L. 106-398)
Health Insurance Portability and Accountability Act (HIPAA) of 1996 (P.L. 104-191)
Federal Information Security Management Act of 2002 (FISMA)
National Institute of Standards and Technology (NIST) Special Publication (SP) and Guidelines
NIST SP 800-12, An Introduction to Computer Security: The NIST Handbook
NIST SP 800-14, Generally Accepted Principles and Practices for Security Information Technology Systems
NIST SP 800-18, Guide for Developing Security Plans for Information Technology Systems
NIST SP 800-26, Security Self-Assessment Guide for Information Technology Systems
NIST SP 800-30, Risk Management Guide for Information Technology Systems
NIST SP 800-34, Contingency Planning Guide for IT Systems
NIST SP 800-47, Security Guide for Interconnecting Information Technology Systems
NIST SP 800-53 Revision 2, Recommended Security Controls for Federal Information Systems
NIST SP 800-60 Vol. 1 & 2, Guide for Mapping Types of Information and Information Systems to Security Categories
NIST SP 800-63, Electronic Authentication Guideline: Recommendation of the National Institute of Standards and Technology
NIST SP 70, The NIST Security Configuration Checklists Program
NIST SP 800-82 Revision 2, Guide to Industrial Control Systems (ICS) Security
NIST SP 800-83, Guide to Malware Incident Prevention and Handling
NIST SP 800-86, Guide to Integrating Forensic Techniques Into Incident Response
NIST SP 800-92, Guide for Computer Security Log Management
NIST SP 800-97, Guide to IEEE 802.111: Establishing Robust Security Networks (this is related to wireless network deployment)
Federal Information Processing Standards Publications (FIPS)
FIPS PUB 199, Standards for Security Categorization of Federal Information and Information Systems
Office of Management and Budget (OMB) Circulars and Government Accounting Office (GAO) Requirements
OMB Circular No. A-130, Appendix III
OMB Circular No. A-123, Management Accountability and Control
OMB M-02-01, Guideline for Preparing and Submitting Security Plans of Action and Milestones
1.11 FIPS 199 Levels
FIPS 199 establishes three potential impact levels (Low, Moderate, High) for each of the security objectives (confidentiality, integrity, and availability). For any ICS/SCADA system, these security services are generally prioritized as availability, integrity, and confidentiality (A/I.C) in that order. The impact levels focus on the potential impact and magnitude of harm that the loss of these security services would have on
SBIWTP’s operations, assets, or individuals. FIPS 199 recognizes that an information system may contain more than one type of information (e.g., privacy information, medical information, financial information), each of which is subject to security categorization.
The following table provides the definitions for the A/I/C ratings for the System.
Table 1-4: Security Objectives
Security Objective Low Moderate High
Availability
Ensuring timely and reliable access to and use of information.
[44 USC, SEC. 3542]
The disruption of access to or use of information or an information system could be expected to have a limited adverse effect on organizational operations, organizational assets, or individuals.
The disruption of access to or use of information or an information system could be expected to have a serious adverse effect on organizational operations, organizational assets, or individuals.
The disruption of access to or use of information or an information system could be expected to have a severe or catastrophic adverse effect on organizational operations, organizational assets, or individuals.
Integrity
Guarding against improper information modification or destruction, and includes ensuring information non-repudiation and authenticity.
[44 USC, SEC. 3542]
The unauthorized modification or destruction of information could be expected to have a limited adverse effect on organizational operations, organizational assets, or individuals.
The unauthorized modification or destruction of information could be expected to have a serious adverse effect on organizational operations, organizational assets, or individuals.
The unauthorized modification or destruction of information could be expected to have a severe or catastrophic adverse effect on organizational operations, organizational assets, or individuals.
Confidentiality
Preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information
[44 USC, SEC. 3542]
The unauthorized disclosure of information could be expected to have a limited adverse effect on organizational operations, organizational assets, or individuals.
The unauthorized disclosure of information could be expected to have a serious adverse effect on organizational operations, organizational assets, or individuals.
The unauthorized disclosure of information could be expected to have a severe or catastrophic adverse effect on organizational operations, organizational assets, or individuals.
1.11.1 Security Categorization/Information Type(s)
The security category of an information system that processes, stores, or transmits multiple types of information should be at least the highest impact level that has been determined for each type of information for each security objective of A/I/C. The following table depicts the security category/information type for The System as identified in the System Risk Assessment Report.
Table 1- 5: System Information Types
Information Type / Rationale NIST SP 800-60
Referenc e
Availabilit y
Low/ Moderate/
High
Integrity Low/
Moderate/ High
Confidentialit y
Low/Moderat e/ High
Service Recovery
Service recovery involves the internal actions necessary to develop a plan for resuming operations after a catastrophe occurs, such as a fire or an earthquake.
The System generates alarms of what actions must be done to restore any part of wastewater treatment
C.2.4.3 High Moderate Low
Water Resource Management
Water Resource Management includes all activities that promote the effective use and management of the nation’s water resources. The System controls all activities for wastewater treatment for the City Arizona.
D.6.1 High High Low
Pollution Prevention and Control
Pollution prevention and control includes activities associated with the establishment of environmental standards to control the levels of harmful substances emitted into the soil, water, and atmosphere. The System controls the levels of harmful substances injected into the water supply of the City, Arizona.
D.8.3 High High Low
Public Resources, Facility, and Infrastructure Management
Public Resources, Facility, and Infrastructure Management involve the management and maintenance of government-owned capital goods and resources (natural or otherwise) on behalf of the public. The SBIWTP treats the wastewater of the City Arizona on behalf of the public.
D.22.3 High High Low
Overall Rating High High High Low
Based on the information types listed in the table provided above, the criticality watermark for the System is High.
1.11.2 Protection Requirements
Both information and information systems have distinct life cycles. It is important that the degree of sensitivity of information be assessed by considering the requirements for the A/I/C of the information:
Availability relates to the impact to the organization should the system be unavailable for use. Integrity ensures that the system’s information remains unaltered during transit. The goal of Confidentiality is to ensure that the data can only be disclosed to those to whom the data is intended.
1.11.3 Protection Requirement Findings2
Confidentiality: The System contains information that could identify information about the City’s water supply. This data requires a minimal level of protection from unauthorized disclosure because it is generally made publicly available. If the certain information contained in the System were released to the public it could result in a loss of public confidence in the city’s resource management.
However, the consequences are evaluated as minimal. Therefore, the unauthorized disclosure of the System information could be expected to have a minimal effect on organizational operations, SBIWTP assets, or individuals and the information. The protection measures are rated as Low.
Integrity: The System collects and processes information regarding natural resource management.
Because the wastewater treatment and chemical levels depend on the accuracy of the data collected, the unauthorized and unanticipated modification could seriously impact the health of the community population at large. Therefore, the unauthorized modification of the System information could be expected to have a severe effect on SBIWTP operations, organizational assets, or individuals and the information and protection measures are rated as High.
Availability: If the System were unavailable for even a short period of time, it would have an immediate impact and would affect the ability of the City to have access to a safe water supply.
Therefore, the unavailability of the System information could be expected to have a severe effect on organizational operations, organizational assets, or individuals and the information and protection measures are rated as High.
2Low – a limited adverse effect Moderate – a serious adverse effect High – a severe or catastrophic adverse effect
2 MANAGEMENT CONTROLS
2.1 (CA) Security Assessment and Authorization
2.1.1 (CA-1) Security Assessment and Authorization Policies and Procedures
Control: The organization:
a. Develops, documents, and disseminates to SBITWP operations and SCADA maintenance contractors :
1. A security assessment and authorization policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
2. Procedures to facilitate the implementation of the security assessment and authorization policy and associated security assessment and authorization controls;
and
b. Reviews and updates the current:
1. Security assessment and authorization policy annually; and
2. Security assessment and authorization procedures annually.
Implementation:
Inherited Control
The SBIWTP follows the IBWC Security Assessment and Authorization policies and procedures that are established for all IBWC information systems. IBWC has developed, documented and disseminated the following:
a. A security assessment and authorization policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among IBWC entities, and compliance with the appropriate standards for all IBWC information systems. IBWC has developed procedures to facilitate the implementation of the security authorization policy and associated controls for all IBWC-owned information systems.
b. IBWC reviews and updates the security assessment and authorization policy annually. Security assessment and authorization procedures for all IBWC information systems are also updated annually.
2.1.2 (CA-2) Security Assessments
Control: The organization:
a. Develops a security assessment plan that describes the scope of the assessment including:
1. Security controls and control enhancements under assessment;
2. Assessment procedures to be used to determine security control effectiveness; and
3. Assessment environment, assessment team, and assessment roles and responsibilities;
b. Assesses the security controls in the information system and its environment of operation annually to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting established security requirements;
c. Produces a security assessment report that documents the results of the assessment; and
d. Provides the results of the security control assessment SBITWP operations and SCADA system maintenance contractors.
System Specific Control
The SBIWTP has implemented the following to address security assessments:
a. A security assessment plan that describes the scope of the assessment. The plan discusses the scope of the security controls and the security control enhancements that are involved in the assessment. The plan also details the assessment procedures that are to be used to determine the security control effectiveness. Further, the security assessment plan also discusses the assessment environment, the assessment team, along with the assessment roles and responsibilities.
b. Security controls are assessed annually in the SCADA Network to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to the established security requirements.
c. A security assessment report is provided that documents the results of the assessment.
d. The results of the security control assessment are currently provided to the IBWC ISSM.
CA-2(1) SECURITY ASSESSMENTS | INDEPENDENT ASSESSORS
The organization employs assessors or assessment teams to conduct security control assessments.
The SBIWTP has employed a team of assessors to conduct security control assessments. This team is employed by IBWC but is independent of IBWC operations.
CA-2(2) SECURITY ASSESSMENTS | SPECIALIZED ASSESSMENTS
The organization includes as part of security control assessments, specialized, in-depth monitoring; vulnerability scanning; malicious user testing; insider threat assessment;
performance/load testing.
The SBIWTP has implemented the following to address specialized security assessments. The SBIWTP has deployed a Continuous Security Monitoring (CDM) solution that provides in-depth monitoring and analysis as part of its security control assessments. IBWC uses an independent team to perform quarterly vulnerability assessments of the System to include all support equipment and system.
2.1.3 (CA-3) Information System Connections
Control: The organization:
a. Authorizes connections from the information system to other information systems through the use of Interconnection Security Agreements;
b. Documents, for each interconnection, the interface characteristics, security requirements, and the nature of the information communicated; and
c. Reviews and updates Interconnection Security Agreements annually.
The SBIWTP has taken the following actions to address information system connections:
a. All appropriate connections have been authorized from the SCADA Network to other information systems through the use of Interconnection Security Agreements (ISA)s
b. The interface characteristics, security requirements, and the information communicated are documented for each defined interconnection.
c. The ISAs are reviewed and updated annually. An ISA is currently in place with the vendor which perform the 24/7 security monitoring of the SCADA Network.
CA-3(5) SYSTEM INTERCONNECTIONS | RESTRICTIONS ON EXTERNAL SYSTEM CONNECTIONS
The organization employs deny-all policy for allowing SCADA system components to connect to external information systems.
The SBIWTP employs a deny-all and no direct internet connects to the core layer of the SCADA system, in extreme emergencies SBIWTP may permit an exception to the policy to allow connections to the SCADA Network.
2.1.4 (CA-5) Plan of Action and Milestones
Control: The organization:
a. Develops a plan of action and milestones for the information system to document the organization’s planned remedial actions to correct weaknesses or deficiencies noted during the assessment of the security controls and to reduce or eliminate known vulnerabilities in the system; and
b. Updates existing plan of action and milestones annually based on the findings from security controls assessments, security impact analyses, and continuous monitoring activities.
The SBIWTP has taken the following actions to create a Plan of Action and Milestones (POA&M):
a. SBIWTP has developed a POA&M for the System to document the planned remedial actions to correct weaknesses and deficiencies noted during the assessment of the security controls. Known vulnerabilities are reduced and/or eliminated via the POA&M.
b. The POA&M is updated after every security assessment or when anomalies are detected by the monitoring services. The POA&M is based on any findings from security control assessments, security impact analyses, and continuous monitoring activities.
2.1.5 (CA-6) Security Authorization
Control: The organization:
a. Assigns a senior-level executive or manager as the authorizing official for the information system;
b. Ensures that the authorizing official authorizes the information system for processing before commencing operations; and
c. Updates the security authorization annually
The SBIWTP completes the following activities for security authorization of the System:
a. The IBWC Commissioner is the senior level executive who is assigned as the authorizing official for the SCADA Network.
b. The authorizing official always authorizes the SCADA Network before commencing operations of any system upgrades.
c. The security authorization package is updated on an ongoing basis.
2.1.6 (CA-7) Continuous Monitoring
Control: The organization develops a continuous monitoring strategy and implements a continuous monitoring program that includes:
a. Establishment of SCADA components to be monitored;
b. Establishment of continuos monitoring assessments supporting such monitoring;
c. Ongoing security control assessments in accordance with the organizational continuous monitoring strategy;
d. Ongoing security status monitoring of organization-defined metrics in accordance with the organizational continuous monitoring strategy;
e. Correlation and analysis of security-related information generated by assessments and monitoring;
f. Response actions to address results of the analysis of security-related information; and
g. Reporting the security status of the organization and the information system to SBITWP operations and SCADA maintenance contractors annually.
The SBIWTP has taken the following actions to address continuous monitoring:
The SBIWTP has developed a continuous monitoring solution and has implemented a continuous monitoring program using the Continuous Diagnostics and Monitoring (CDM) Services provided by GovPlace Solutions. This solution includes the following:
a. A clearly defined set of metrics to be monitored by the CDM service.
b. CDM establishes a continuous frequency for assessments that support each monitoring activity.
c. CDM supports ongoing security control assessments that occur on an annual basis in accordance with the continuous monitoring solution.
d. CDM provides continuous security status monitoring of a set of defined metrics in accordance with the SBIWTP continuous monitoring solution.
e. CDM provides correlation services for analysis of security-related information that is generated by security assessments and continuous monitoring activities.
f. CDM provides response actions to address the results of the analysis of security related information.
g. The security status of the SCADA Network and other related SBIWTP assets is provided to GovPlace Security staff and the appropriate IBWC personnel on a continuous basis.
CA-7(1) CONTINUOUS MONITORING | INDEPENDENT ASSESSMENT
The organization employs 3rd party assessors or assessment teams to monitor the security controls in the information system on an ongoing basis.
The SBIWTP employs the GovPlace Security Solutions CDM security staff to monitor the security controls of the SCADA Network on an ongoing basis. GovPlace Security Solutions operates independently from SBIWTP and IBWC.
2.2 (PL) Planning
2.2.1 (PL-1) Security Planning Policy and Procedures
Control: The organization:
a. Develops, documents, and disseminates to IBWC personnel and CDM services providers:
1. A security planning policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
2. Procedures to facilitate the implementation of the security planning policy and associated security planning controls; and
b. Reviews and updates the current:
1. Security planning policy annually; and
2. Security planning procedures annually.
SBIWTP has developed documentation for security planning policies and procedures.
a. The security planning policy is disseminated to the System Owner and the SBIWTP
ISSM. The policy addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. The policy includes and associated security planning controls necessary for implementation as well as procedures to facilitate the implementation.
b. The security planning policy and its associated procedures are reviewed and updated annually.
2.2.2 (PL-2) System Security Plan
Control: The organization:
a. Develops a security plan for the information system that:
1. Is consistent with the organization’s enterprise architecture;
2. Explicitly defines the authorization boundary for the system;
3. Describes the operational context of the information system in terms of missions and business processes; connections to other information systems;
4. Provides the security categorization of the information system including supporting rationale;
5. Describes the operational environment for the information system and relationships with or
6. Provides an overview of the security requirements for the system;
7. Identifies any relevant overlays, if applicable;
8. Describes the security controls in place or planned for meeting those requirements including a rationale for the tailoring decisions; and
9. Is reviewed and approved by the authorizing official or designated representative prior to planning implementation;
b. Distributes copies of the security plan and communicates subsequent changes to the plan to SBITWP operations and SCADA maintenance contractors ;
c. Reviews the security plan for the information system annually;
d. Updates the plan to address changes to the information system/environment of operation or problems identified during plan implementation or security control assessments; and
e. Protects the security plan from unauthorized disclosure and modification.
a. The IBWC’s IMD has developed a system security plan for this SCADA System. This document serves as the SBIWTP System Security Plan (SSP). The SSP is consistent with the SBIWTP ICS architecture. It explicitly defines Layer 2 of the SBIWTP ICS as the proper security authorization boundary. It describes the operational context of the System in terms of the mission, business processes, and connections to other information systems. The security categorization information and its supporting rationale are provided in Section
1.11.1 of this document. This SSP describes the operational environment in relation to all other connected information systems. It also describes all security requirements of the System and the security controls that are in place and planned to meet these requirements, including any tailored controls with their supporting rationale. It has been reviewed by the designated approving authority prior to implementation.
b. Copies of this SSP have been distributed to the System Owner and the ISSM.
c. The SSP for the System is reviewed and updated annually.
d. The SSP will be updated to address changes to the SCADA Network environment of operation. Any problems identified during implementation or during security control assessments will be documented in this SSP.
e. This SSP is protected from unauthorized disclosure or modification by only distributing it in areas that can be accessed by authorized personnel such as protected SharePoint sites.
PL-2(3) SYSTEM SECURITY PLAN | PLAN / COORDINATE WITH OTHER ORGANIZATIONAL
ENTITIES
The organization plans and coordinates security-related activities affecting the information system with the SBIWTP operations contractor before conducting such activities in order to reduce the impact on other organizational entities.
The SBIWTP plans and coordinates security-related activities that affect the System with the SCADA Network senior level executives. These activities are coordinated prior to executing these activities in order to reduce the impact on other entities that are related to IBWC.
2.2.3 (PL-4) Rules of Behavior
Control: The organization:
a. Establishes and makes readily available to individuals requiring access to the information system, the rules that describe their responsibilities and expected behavior with regard to information and information system usage;
b. Receives a signed acknowledgment from such individuals, indicating that they have read, understand, and agree to abide by the rules of behavior, before authorizing access to information and the information system;
c. Reviews and updates the rules of behavior bi-annually; and
d. Requires individuals who have signed a previous version of the rules of behavior to read and re-sign when the rules of behavior are revised/updated.
The SBIWTP has created a Rules of Behavior (ROB) document that addresses the following:
a. The ROB is made readily available to employees who require access to the System. The ROB defines rules that describe the employee’s responsibilities and the expected behavior when accessing the System and its associated information.
b. The System Owner receives a signed acknowledgment from all employees indicating that they have read, understand, and agree to abide by the ROB before access is authorized to an employee.
c. The ROB is reviewed and updated annually at a minimum.
d. All employees who are granted access to the SCADA Network who have signed a previous version of the ROB are required to read and re-sign the ROB when it is revised and/or updated.
e. The ROB is also incorporated in the annual security awareness training program to ensure all employees are well versed in policy requirements.
PL-4(1) RULES OF BEHAVIOR | SOCIAL MEDIA AND NETWORKING RESTRICTIONS
The organization includes in the rules of behavior, explicit restrictions on the use of social media/networking sites and posting organizational information on public websites.
Not Applicable
The SBIWTP does not need to include explicit restrictions on the use of social media and posting SBIWTP information on public websites because internet browsing is not enabled on the SCADA Network.
2.2.4 (PL-8) Information Security Architecture
Control: The organization:
a. Develops an information security architecture for the information system that:
1. Describes the overall philosophy, requirements, and approach to be taken with regard to protecting the confidentiality, integrity, and availability of organizational information;
2. Describes how the information security architecture is integrated into and supports the enterprise architecture; and
3. Describes any information security assumptions about, and dependencies on, external services;
b. Reviews and updates the information security architecture annually to reflect updates in the enterprise architecture; and
c. Ensures that planned information security architecture changes are reflected in the security plan, the security Concept of Operations (CONOPS), and organizational procurements/acquisitions.
The SBIWTP has created a highly segmented network architecture that consists of four (4) segments.
Segment 1 is the processing zone located throughout the plant and each zone is shielded by using a Tofino firewall to filter and limit the interaction between the various zones. Segment 2 is the System. It is segregated from zone 3 and it limits the interaction to a few ports required for updates and security definitions. The architecture is tested annually to ensure the integrity of the logical and physical separation.
The goal is to ensure the processing zones and the SCADA are fully protected from the internet while allowing administration and other supporting services to be provided by an intermediary network segment which is located in segment 3. The overall architecture is depicted in the network diagram shown in Section 1.8
2.3 (RA) Risk Assessment
2.3.1 (RA-1) Risk Assessment Policy and Procedures
Control: The organization:
a. Develops, documents, and disseminates to CDM service providers and SBIWTP operations contrator:
1. A risk assessment policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
2. Procedures to facilitate the implementation of the risk assessment policy and associated risk assessment controls; and
b. Reviews and updates the current:
1. Risk assessment policy and;
2. Risk assessment procedures bi-annually.
The SBIWTP has developed a risk assessment policy that addresses the following:
a. It addresses purpose, scope, roles, responsibilities, management commitment, coordination among SBIWTP and IBWC entities. It also addresses compliance standards and follows the recommendations described in ANSI 02-01:2007. The risk assessment policy addresses Health Safety and Environmental concerns as outlined in the standard.
b. The risk assessment policy and its associated procedures are reviewed and updated annually.
2.3.2 (RA-2) Security Categorization
Control: The organization:
a. Categorizes information and the information system in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance;
b. Documents the security categorization results (including supporting rationale) in the security plan for the information system; and
c. Ensures that the authorizing official or authorizing official designated representative reviews and approves the security categorization decision.
The SBIWTP has implemented the following to address security categorization:
a. The System has been categorized by using the Federal Information Processing Standard
(FIPS) 199 standard. The System has criticality watermark of High. This standard has been followed in accordance with all applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance.
b. The System has documented the security categorization results, including the supporting rationale, in Section 1.11.1 of this SSP.
c. The SBIWTP has ensured that the authorizing official has reviewed and approved the security categorization decision by obtaining the authorizing official’s signature on this
SSP.
2.3.3 (RA-3) Risk Assessment
Control: The organization:
a. Conducts an assessment of risk, including the likelihood and magnitude of harm, from the unauthorized access, use, disclosure, disruption, modification, or destruction of the information system and the information it processes, stores, or transmits;
b. Documents risk assessment results in risk assessment reports.;
c. Reviews risk assessment results monthly;
d. Disseminates risk assessment results to maintenance contractors; and
e. Updates the risk assessment monthly or whenever there are significant changes to the information system or environment of…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .