Attach 17 - Order 7-4 Information Technology Security.pdf

PDF 5 MB Posted

Attached to
AOC MACC Onboarding Federal contract opportunity
Solicitation number
AOCACB25R0006
Issued by
Architect of the Capitol

About this file

This is an Information Technology Security policy order (Order 7-4) from the Architect of the Capitol (AOC) that establishes requirements and responsibilities for protecting AOC information systems. The order outlines specific roles and duties for employees, contractors, supervisors, business owners, system owners, the Chief Information Officer (CIO), and Chief Information Security Officer (CISO).

The policy details key security requirements including mandatory AOC Rules of Behavior acknowledgement, annual security awareness training, specialized role-based training for industrial control systems, and prohibition of password sharing. It establishes that the CIO is the authorizing official for all systems and applications, and only the CIO can enter into interconnection security agreements. Industrial control systems have strict requirements - they cannot connect to the internet or other networks without CIO/CISO approval. The order includes a comprehensive compliance checklist covering responsibilities across all roles. The policy supersedes previous IT security orders from 2014 and 2008, with updates to clearance processes, employee/contractor responsibilities, and industrial control system requirements.

View the file

Other files for this federal contract opportunity

Show all 21

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

A fti!IRlfih

"'"""' ARCHITECT

OF THE CAPITOL

Architect of the Capitol U.S. Capitol, Room SB-16 Washington, DC 20515 202.228.1793 www.aoc.gov

EFFECTIVE DATE: October 10, 2017

SUBJECT: Information Technology Security

SERIES: Information Technology Manual

United States Government

ORDER 7-4

DESCRIPTION: This order establishes the policy, requirements and responsibilities for protecting the information systems under the authority or control of the Architect of the Capitol

(AOC).

SCOPE: This order applies to all persons with access to information and other resources under the authority or control of the AOC. This includes AOC employees, volunteers, contractors, subcontractors and their employees. Those persons to whom this order applies are referred to as "covered persons."

OPR: The office of primary responsibility (OPR) is the Information Technology Division (ITD).

SUMMARY OF CHANGES: This version includes a change in the clearance process for separating employees (section 5.2); further details the responsibilities of employees and contractors (section 5.1), the chief information officer (section 5.5), ITD (section 5.7, including restoring the requirement for the United States Capitol Police clearance process to be completed before an AOC system account will be created, which was omitted in the prior policy update) and the business owner (section 5.3); and details requirements related to industrial control systems (section 2.3).

SUPERSEDES: This order supersedes AOC Order 7-4, Information Technology Security dated October 3, 2014, and AOC Order 7-3-2, Network Perimeter Policy dated September 8, 2008.

tephen T. Ayers, FAIA, LE Architect of the Capitol

ORDER OF THE ARCHITECT OF THE CAPITOL 7-4

INFORMATION TECHNOLOGY SECURITY

TABLE OF CONTENTS:

1. Purpose

2. Policy

2.1. General Requirements

2.2. Interconnection Security Agreements

2.3. Industrial Control Systems

3. Coverage

4. Definitions

5. Roles and Responsibilities

5.1 . Employees and Contractors

5.2. Supervisors and Contracting Officer's Technical Representatives (COTRs)

5.3. Business Owner

5.4. System Owner

5.5. Chief Information Officer

5.6. Chieflnformation Security Officer

5.7. ITD

5.8. Information System Administrator

5.9. Assessor

5.10. United States Capitol Police, House and Senate Personnel with AOC Accounts

5.11 . Third-Party Systems

6. Authorities and References Appendix A - Compliance Checklist

AOC Order 7-4, October 10, 2017 2

1. Purpose

The purpose of this order is to establish the policy, requirements and responsibilities to protect information systems under the authority or control of the Architect of the Capitol (AOC). The AOC makes concerted efforts to adopt government or business best practices to protect its information systems and prevent unauthorized access. The chief information officer (CIO) and the chief information security officer (CISO) review best practices that include, but are not exclusive to, those from the National Institute of Standards and Technology; Federal Information Processing Standard; International Information Systems Security Certification Consortium; System Administration, Networking and Security Institute; Information Systems Audit and Control Association, among other IT security-related best practices to determine which to adopt for the AOC. Due to changes in threats, these best practices may change quickly.

2. Policy

2.1. General Requirements

2.1.1. The AOC requires that covered persons protect AOC data and information systems. Failure to comply with this policy by AOC employees will be handled in accordance with AOC Order 752-1 , Discipline. Non-compliance by contractors, sub-contractors or other third parties will be handled according to the applicable contract or agreement with the AOC.

2.1.2: The Architect of the Capitol designates the CIO as the authorizing official to grant, suspend, revoke and modify the authority to operate for all general support systems, and major and minor applications under the AOC's authority or control.

Additional information on the CIO's responsibilities are included in AOC Order 8- 2, Information Technology Management, and section 5.5 of this policy.

2.2. Interconnection Security Agreements

In order to protect AOC information, external interconnections between AOC-owned information systems and other systems may only exist ifthere is a formal interconnection security agreement. Only the CIO is authorized to enter into and administer an interconnection security agreement.

2.3. Industrial Control Systems

2.3.1. AOC industrial control systems, which include supervisory control and data acquisition systems, are the most essential components of the AOC' s critical infrastructure.

2.3.2. AOC industrial control systems, which include supervisory control and data acquisition systems:

AOC Order 7-4, October 10, 2017 3

2.3.2.1 . Shall not be connected to the Internet

2.3.2.2. Are considered highly categorized information systems, and appropriate security controls must be applied as deemed necessary by the CIO

2.3.2.3. Shall not be interconnected with other networks without the written approval from the CIO or CISO

2.3.3. Personnel that access, use or manage industrial control systems, which include supervisory control and data acquisition systems, must take specialized IT security roles-based training, as directed by the CISO.

3. Coverage

This policy applies to all AOC organizations, employees, volunteers, contractors, subcontractors and their employees.

4. Definitions

4.1. Assessment or Security Assessment: The testing and/or evaluation of the management, operational and technical security controls in an information system to determine the extent to which the controls are implemented correctly, operating as intended and are producing the desired outcome with respect to meeting the security requirements for the system. There are two types of security assessments (full and annual). The full security assessment occurs during Assessment and Authorization periods or when a significant change occurs to the system. The annual security assessment occurs during non Assessment and Authorization periods and assesses approximately one-third of the controls of the full security assessment.

4.2. Assessor*: The individual, group or organization responsible for conducting a security assessment.

4.3. Authority to Operate*: The official management decision given by a senior agency official to authorize operation of an information system and to explicitly accept the risk to agency operations (including mission, functions, image or reputation), assets or individuals, based on the implementation of an agreed-upon set of security controls.

4.4. Authorization Boundary*: All components of an information system to be authorized for operation by an authorizing official, excluding separately authorized systems to which the information system is connected.

4.5. Business Owner: The official with statutory or operational authority for specified information, and responsibility for establishing the controls for generating, collecting, processing, disseminating and disposing the information. The business owner is

*Glossary of Key Information Security Terms, NI STIR 7298, Revision 2, May 2013.

AOC Order 7-4, October 10, 2017 4 responsible for the business requirements of the system, e.g., whether the system is needed and how it should be modified, and for its procurement. The business owner must work with the system owner or ITD when procuring IT-related equipment, software and services, in accordance with AOC Order 8-2, IT Management.

4.6. Chief Information Security Officer*: The official responsible for carrying out the chief information officer's responsibilities for information systems security and serving as the primary liaison to the agency's authorizing officials, system owners and information security staff.

4.7. Confidentiality*: Preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information.

4.8. Covered Persons: This includes AOC employees, volunteers, contractors, subcontractors and their employees. For the purpose of this order, those persons to whom this order applies are referred to as "covered persons."

4.9. General Support System*: An interconnected set of information resources under the same direct management control which shares common functionality. A system normally includes hardware, software, information, data, applications, communications and people.

A system can be, for example, a local area network including smart terminals that supports a branch office, an agency-wide backbone, a communications network, a departmental data processing center, including its operating system and utilities, a tactical radio network, or a shared information processing service organization.

4.10. Incident*: An occurrence that actually or potentially jeopardizes the confidentiality, integrity or availability of an information system or the information the system processes, stores or transmits or that constitutes a violation or imminent threat of violation of security policies, security procedures or acceptable use policies.

4.11. Industrial Control System*: An information system used to control industrial processes such as manufacturing, product handling, production and distribution. Industrial control systems include supervisory control and data acquisition systems used to control geographically dispersed assets, as well as distributed control systems and smaller control systems using programmable logic controllers to control localized processes.

4.12. Information Security*: The protection of information and information systems from unauthorized access, use, disclosure, disruption, modification or destruction in order to provide confidentiality, integrity and availability.

4.13. Information System or System: A separate set of information resources organized for collecting, processing, maintaining, using, sharing, disseminating or disposing information. Information system includes the aggregate of information technology, data, *Glossary of Key Information Security Terms, NISTIR 7298, Revision 2, May 2013.

AOC Order 7-4, October 10, 2017 5 hardware, software and associated resources. The AOC has defined the boundaries of its AOC-owned information systems, which are termed authorization boundaries.

4.14. Integrity*: Guarding against improper information modification or destruction and includes ensuring information non-repudiation and authenticity.

4.15. Interconnection Security Agreement*: An agreement established between the organizations that own and operate connected IT systems to document the technical requirements of the interconnection. The interconnection security agreement also supports a memorandum of understanding or a memorandum of agreement between the organizations. Only the CIO is authorized to enter into and administer these agreements.

4.16. Major Application*: An application that requires special attention to security due to the risk and magnitude of the harm resulting from the loss, misuse or unauthorized access to or modification of the information in the application. Note: All federal applications require some level of protection. Certain applications, because of the information in them, however, require special management oversight and should be treated as major.

Adequate security for other applications should be provided by security of the system in which they operate.

4.17. Management Controls*: For the purpose of this order, the security controls (i.e. , safeguards or countermeasures) for an information system that focus on the management of risk and the management of information system security.

4.18. Minor Application*: An application, other than a major application, that requires attention to security due to the risk and magnitude of harm resulting from the loss, misuse or unauthorized access to or modification of the information in the application.

Minor applications are typically included as part of a general support system.

4.19. Operational Controls*: For the purpose of this order, the security controls (i.e., safeguards or countermeasures) for an information system that are primarily implemented and executed by people (as opposed to systems).

4.20. Plan of Action and Milestones*: A document that identifies tasks that need to be accomplished. It details resources required to accomplish the elements of the plan, any milestones in meeting the tasks and scheduled completion dates for the milestones.

4.21. Risk Management*: The process of managing risks to organizational operations (including mission, functions, image or reputation), organizational assets or individuals resulting from the operation of an information system, and includes: (i) the conduct of a risk assessment; (ii) the implementation of a risk mitigation strategy; and (iii) employment of techniques and procedures for the continuous monitoring of the security state of the information system.

AOC Order 7-4, October 10, 2017 6

4.22. Security Controls*: For the purpose of this order, the management, operational and technical controls (i.e., safeguards or countermeasures) prescribed for an information system to protect the confidentiality, integrity and availability of the system and its information.

4.23. Security Requirements•: Requirements levied on an information system that are derived from applicable laws, directives, policies, standards, instructions, regulations, procedures, organizational mission or business case needs to ensure the confidentiality, integrity and availability of the information being processed, stored or transmitted.

4.24. Supervisory Control and Data Acquisition*: A generic name for a computerized system that is capable of gathering and processing data and applying operational controls over long distances. Typical uses include power transmission and distribution and pipeline systems. It was designed for the unique communication challenges (delays, data integrity, etc.) posed by the various media that must be used, such as phone lines, microwaves and satellites.

4.25. System Administrator: A user with the highest level of privileged rights on an information system. System administrators can, for example, create, disable and manage user accounts, server accounts, databases, routers and firewalls. System administrators are responsible for the daily administration of information systems or associated users.

System administrators assist system owners and business owners in implementing controls on their systems. System administrators assist the CISO in creating, implementing, managing and updating secure configurations on information systems.

4.26. System or Security Categorization*: The characterization of information or an information system based on an assessment of the potential impact that a loss of confidentiality, integrity or availability of such information or information system would have on organizational operations, organizational assets or individuals.

4.27. System Owner: The official responsible for the overall procurement, development, integration, modification or operation and maintenance of an information system. They are responsible for operating that system in accordance with the data protection and user access requirements of the business owner. System owner is synonymous with information system owner. The system owner and the business owner may work together on the procurement of a system.

4.28. System Security Plan*: A formal document that provides an overview of the security requirements for the information system and describes the security controls in place or planned for meeting those requirements.

4.29. Technical Controls*: The security controls (i.e., safeguards or countermeasures) for an information system that are primarily implemented and executed by the information

AOC Order 7-4, October 10, 2017 7 system through mechanisms contained in the hardware, software or firmware components of the system.

4.30. Third-Party System: An information system or component of an information system for which the following apply:

• It is outside of the authorization boundary established by the first-party organization (e.g., the AOC)

• The first-party organization typically has no direct control over the application of required security controls or the assessment of security control effectiveness

The third-party information system vendors, also known as external information system vendors, must follow the terms of their contract, service level agreement, memorandum of understanding or memorandum of agreement, and applicable interconnection security agreement (if an interconnection with an AOC-owned information system and their information system exists).

4.31. User*: Individual or (system) process authorized to access an information system.

5. Roles and Responsibilities

5.1. Employees and Contractors

5.1.1 . All AOC employees and contractors shall assist in the protection of information systems and data as discussed in this policy. All AOC employees and contractors shall:

5.1.1.1. Read and sign, or electronically acknowledge, the AOC Rules of Behavior to acquire and maintain access to AOC-owned information systems. The AOC Rules of Behavior are provided by ITD when a new AOC account is requested and when acknowledgements are required. The AOC Rules of Behavior form may be located for reference on the AOC intranet.

5.1 .1.2. Not share their AOC system passwords with anyone, which includes supervisors. It is an AOC policy violation to share AOC system passwords. Violations, or suspected violations, must be reported to the Information Security Team (infosec@aoc.gov).

5.1.1.3. Successfully complete the AOC computer security awareness training annually, if the employee or contractor has an AOC information system user account. Notification will be emailed when, how and where to access the training. A failure to complete the training will result in the denial of access privileges to the AOC network and systems until this requirement is satisfied.

AOC Order 7-4, October 10, 2017 8

5.1.1.4. Successfully complete the appropriate information systems roles-based training for selected AOC personnel upon request from the CIO, CISO, system owner or business owner; failure to take the specialized roles-based training will result in the denial of access privileges to the information system in question until this requirement is satisfied.

5.1.1.5. Sign the AOC non-disclosure agreement, if an AOC contractor. ITD provides the AOC non-disclosure agreement for a contractor' s signature when a new AOC account is requested. The AOC non-disclosure agreement can be found within the AOC intranet document library.

5.1.1.6. Include information security requirements and/or information security specifications in IT-related acquisition contracts based on an assessment of risks and in accordance with applicable laws, policies, regulations and standards. IT-related contracts shall include the following security-related language:

• "The Offeror, if hosting an information system on behalf of the AOC, must conduct either an Assessment and Authorization of their system in accordance with National Institute of Standards 800-Series Special Publications guidance, or conduct independent assessments of their information security controls by a third-party assessment organization using industry standard metrics and methodologies."

• "The Offeror shall ensure that its IT-related products or services comply with AOC policies, and applicable standards and guidelines, including AOC Order 7-4, IT Security. Personnel with AOC system accounts responsible for rendering the Offeror's services shall be subject to the same security requirements as AOC employees including but not limited to rules of behavior and computer security awareness training."

5.1.2. All AOC employees and contractors shall include ITD in IT planning efforts in accordance with AOC Order 8-2, IT Management. IT requests, including networking changes, may be submitted through the IT Help Desk (helpdesk@aoc.gov, 202.225.4321).

5.1.3. AOC employees and contractors are responsible for reporting violations or suspected violations of this policy to the Information Security Team (infosec@aoc.gov).

5.2. Supervisors and Contracting Officer's Technical Representatives (COTRs)

AOC supervisors and COTRs shall assist and ensure their applicable personnel protect information systems and data as discussed in this policy. Supervisors and COTRs have

AOC Order 7-4, October 10, 2017 9 the authority to request system account access for their employees or contractors by submitting a request to the IT Help Desk (helpdesk@aoc.gov, 202.225.4321), which will be granted based upon the access rules of the system's business owner. The supervisor or COTR shall provide, in a timely manner, the IT Help Desk with information on the appropriate user accounts to be created, the information systems the user must have access to and the level of access for the applicable user. Upon termination, removal or retirement of an employee or contractor, supervisors and COTRs must inform ITD as soon as possible, by the following:

5.2.1. Supervisors must follow the clearance process detailed in AOC Order 296-4, Off boarding Separating Employees, for employees.

5.2.2. COTRs must email the group "AMMD Clearance" for separating contractors, until the process is replaced with an automated system. Upon implementation of an automated clearance system for contractors, COTRs must follow the process to use the automated clearance system.

5.3. Business Owner

Each AOC business owner, in collaboration with the CIO and CISO, shall set the requirements to protect the data that will be stored in their system; set the rules for authorized users on the system and set the requirements for access to the system. These requirements are documented by the CISO in the system security plan.

5.4. System Owner

AOC system owners and their designees have the following responsibilities:

5.4.1. Assist and ensure their applicable personnel assist with protecting their information system as discussed in this policy

5.4.2. Manage user account access in accordance with the data protection and data access requirements of the business owner

5.4.3. Ensure the security planning process is incorporated into the information system's life cycle

5.4.4. Successfully complete the appropriate information systems roles-based training annually

5.4.5. Ensure contingency planning and incident response activities occur for the respective information system

AOC Order 7-4, October 10, 2017 10

5.5. Chief Information Officer

In addition to the responsibilities included in AOC Order 8-2, Information Technology Management, the CIO is to:

5.5.1. Assume responsibilities as the authorizing official set forth in section 2.1.2 of this policy

5.5.2. Designate the CISO to serve in the organizational role of the senior agency information security officer and have security oversight of all information systems and applications for the AOC within the scope of this policy

5.5.3. Assume responsibility for the confidentiality, integrity and availability of AOC information; the CIO uses this knowledge to determine which controls are most applicable to AOC systems, and major and minor applications

5.5.4. Formulate and update, in collaboration with the CISO, an AOC IT Security Standard, which serves as the risk management framework for IT systems security in the AOC; this framework is used to prioritize and tailor which controls will be implemented on a system and application, based upon organizational priorities and control effectiveness and applicability; the controls will be tailored and selected during the System Categorization and Security Controls Selection phase of the Assessment and Authorization process referenced in the AOC IT Security Standard; due to its sensitive information, the AOC IT Security Standard is available only to authorized AOC personnel from the CISO (ciso@aoc.gov); the AOC IT Security Standard is not applicable for contractor-owned or third-party systems; additional information related to the confidentiality of AOC information is included in AOC Order 4-16, Privacy

5.5.5. Delegate security functions to respective staff or contract personnel to carry out these functions

5.5.6. Make exceptions to these security functions on a case-by-case basis, when justified and documented in a Letter of Acceptance of Risk; the Letter of Acceptance of Risk states that the CIO has reviewed the assessment documents and agrees to accept the system; a Letter of Acceptance of Risk template is available for reference within the AOC intranet document library using the search tool

5.5.7. Enter into and administer interconnection security agreements

5.5.8. Provide a help desk service to fulfill user account requests, which can be delegated to respective staff and contract personnel

5.5.9. Designate a Configuration Control Board, in accordance with AOC Order 8-3, IT Governance Charter; the Configuration Control Board controls and manages

AOC Order 7-4, October IO, 2017 11 configuration changes to the AOC' s IT baseline, considering the risk to other AOC information systems, such as in-network changes

5.6. Chief Information Security Officer

The CISO shall:

5.6.1. Serve in the organizational role of the senior agency information security officer and have security oversight of all information systems and applications for the AOC within the scope of this policy

5.6.2. Formulate and update an AOC IT Security Standard, in collaboration with the CIO, which serves as the risk management framework for IT systems security in the

AOC

5.6.3. On occasion, delegate security functions to respective staff or contract personnel to carry out these functions

5.7. ITD

5.7.1 . The IT Help Desk is responsible for maintaining and managing all AOC system accounts.

5.7.2. ITD shall not create an AOC system account until the United States Capitol Police clearance process is completed for the user.

5.7.3. The IT Help Desk shall notify the IT property manager of reports oflost or stolen IT equipment in accordance with AOC Order 8-4, Accountable IT Property.

5.7.4. The ITD Information Security Team (infosec@aoc.gov), under the direction of the CISO, is responsible for handling IT security-related issues (e.g., suspicious emails, actual or potential incidents) and other IT security-related tasks.

5.8. Information System Administrator

Each AOC-owned information system administrator must assist with the protection of information discussed in this policy. System administrators must manage the level of user access per the approved request from the AOC IT Help Desk enumerated within this policy. Each AOC-owned information system administrator must successfully complete the appropriate information systems roles-based training annually.

5.9. Assessor

The assessor for the AOC shall conduct independent security assessments of the management, operational and technical security controls for an information system in order to determine the extent controls are correctly implemented, operate as intended and

AOC Order 7-4, October 10, 2017 12 produce the desired outcome with respect to meeting the security requirements for the system.

The assessor then recommends corrective actions to reduce or eliminate vulnerabilities in the information system. The assessor provides an independent assessment of the system security plan and other related documentation. The assessor shall use the AOC IT Security Standard to assess AOC-owned information systems. The AOC IT Security Standard is available only to authorized AOC personnel from the CISO (ciso@aoc.gov) due to its sensitive information. The assessor will create a plan of action and milestones for controls that are found to not be implemented or partially implemented.

5.10. United States Capitol Police, House and Senate Personnel with AOC Accounts

United States Capitol Police, U.S. House of Representatives and United States Senate personnel with AOC accounts must complete the AOC Rules of Behavior when granted access to an AOC user account or AOC-owned information system. The AOC Rules of Behavior must also be completed periodically if requested by the AOC. Each such user will receive security awareness training from their respective organization instead of the standard AOC security awareness training.

5.11. Third-Party Systems

Vendors or other federal agencies that host third-party systems with AOC data, must:

5. J 1.1. Follow their contract terms, service level agreement, memorandum of understanding or memorandum of agreement, and applicable interconnection security agreement (if an interconnection with an AOC-owned information system and their information system exists)

5.11.2. Follow an industry-recognized standard that requires their system receives an independent assessment of its information security controls

5.11.3. Present confirmation that the independent assessment has occurred, upon request of the CISO through the COTR, or AOC point of contact for the outside system

5.11.4. Inform the COTR, or AOC point of contact, and the AOC CISO of any breach of their information system as prescribed under this order and in the contract, service level agreement, memorandum of understanding or memorandum of agreement

6. Authorities and References

• AOC Order 752-1, Discipline

• AOC Order 4-16, Privacy

• AOC Order 8-2, Information Technology Management

• AOC Order 8-3, IT Governance Charter

AOC Order 7-4, October 10, 2017 13

• AOC Order 8-4, Accountable IT Property

• AOC Order 600-1, Telework Program

• AOC Order 296-4, Off-boarding Separating Employees

• Glossary of Key Information Security Terms, NISTIR 7298, Revision 2, May 2013

AOC Order 7-4, October 10, 2017 14

Appendix A - Compliance Checklist

QUESTION YES NO NIA

I.

2.

3.

4.

5.

EMPLOYEE and CONTRACTOR RESPONSIBILITIES

Has the employee or contractor read and signed or electronically acknowledged the AOC D Rules of Behavior in order to acquire or maintain access to AOC-owned information s stems?

Has the employee or contractor fully complied with this policy of not sharing any AOC 0 s stem asswords with an one, includin their su ervisor?

Has the contractor signed the AOC non-disclosure agreement? D

If the employee or contractor has an AOC information system user account, have they D com Ieted the annual AOC com uter securi awareness trainin ?

If applicable, has the employee or contractor successfully completed the appropriate 0 information s stems roles-based trainin ?

6. Has an employee or contractor who accesses, uses or manages industrial control systems 0 taken s ecialized IT securi roles-based trainin ?

7. In an IT-related acquisition contract, have information security requirements and/or 0 information security specifications been included, including the security-related language as detailed in this olic ?

8. Has the employee or contractor included ITO in their IT planning efforts in accordance 0 with AOC Order 8-2, IT Mana ement?

9. Has the employee or contractor reported violations or suspected violations of this policy 0 to infosec aoc. ov?

SUPERVISORS AND CONTRACTING OFFICER'S TECHNICAL

REPRESENTATIVES' COTR RESPONSIBILITIES

l. Has the AOC supervisor or COTR assisted and ensured their applicable personnel protect 0 their information as discussed in this olic ?

2. Has the supervisor or COTR submitted a request to the IT Help Desk for user accounts to D be created in a timel manner?

3. Has the supervisor promptly followed the clearance process detailed in AOC Order 296- 0 4, Off-boardin Se aratin Em Io ees, for em lo ees se aratin from the AOC?

4. Has the COTR, as soon as possible, emailed the group "AMMO Clearance" for 0 contractors se aratin from the AOC?

5. Has the COTR ensured third-party system vendors have followed the terms of their D contract, service level agreement, memorandum of understanding or memorandum of a reement, and interconnection securi a reement as a licable ?

6. Has the applicable AOC point of contact ensured another federal agency hosting a third- D party system with AOC data has followed the terms of their agreement(s) with the AOC, e.g., contract, service level agreement, memorandum of understanding or memorandum of a reement, and interconnection securi a eement as a Iicable ?

BUSINESS OWNER RESPONSIBILITIES

1. Has the AOC business owner, in collaboration with the ClO and CISO, set the 0 re uirements for rotectin the data that will be stored in theirs stem?

2. Has the AOC business owner set the rules for authorized users on the system and the 0 re uirements for access to the s stem?

3. Has the AOC business owner worked with the system owner or ITO when procuring IT- 0 related equipment, software and services, in accordance with AOC Order 8-2, IT Mana ement?

AOC Order 7-4, October 10, 2017

D D

D

D D

D D

D

D D

D D

D D

D D

D

D

D

D D

D D

D D

D D

D

OPR (INFORMATION TECHNOLOGY DIVISION (ITD)) RESPONSIBILITIES

I. Has ITO provided a help desk service to fulfill user account requests? D D LJ

2. Has ITO ensured that no AOC system accounts are created until the United States D D LJ

Capitol Police clearance process for the user has been completed?

3. Has the IT Help Desk ensured each user completes the AOC Rules of Behavior when D D LJ issued an AOC user account?

4. Has the IT Help Desk ensured each contractor has completed the AOC non-disclosure D D LJ agreement when issued an AOC user account?

5. Has ITO denied any user access privileges to the AOC network and systems until the D D D user completes their annual computer security awareness training?

6. Has ITO denied access privileges to the information system in question for applicable D D D personnel until they complete their specialized roles-based training?

7. Has the IT Help Desk forwarded reports of lost or stolen IT equipment to the IT property LJ D D manager in accordance with AOC Order 8-4, Accountable IT Property?

8. Has the Information Security Team, under the direction of the CISO, handled IT D D D security-related tasks?

9. Has the chief information officer designated a Configuration Control Board that will LJ D LJ control and manage configuration changes to the AOC's IT baseline?

CHIEF INFORMATION OFFICER (CIO) RESPONSIBILITIES

I. Has the CIO granted, suspended, revoked or modified, as needed, the authority to operate LJ D LJ any general support systems, major applications and minor applications under the authority or control of the AOC?

2. Has the CIO designated a chief information security officer to serve in the organizational LJ D LJ role of the senior agency information security officer and have security oversight of all information systems and applications for the AOC within the scope of this policy?

3. Does the CIO understand the requirements for confidentiality, integrity and availability LJ D D of AOC information?

4. Has the CTO determined what controls are most applicable to AOC systems, major LJ D LJ applications and minor annlications?

5. Has the CIO determined the appropriate security controls for the AOC's industrial D D D control systems?

6. Has the CIO, in collaboration with the CISO, formulated and updated an AOC IT D D D Security Standard, which will serve as the risk management framework for IT systems security in the AOC?

7. Has the CIO authorized all interconnection security agreements? LJ D LJ

CHIEF INFORMATION SECURITY OFFICER (CISO) RESPONSIBILITIES

1. Does the CISO serve in the organizational role of the senior agency information security D D D officer and have security oversight of all information systems and applications for the AOC within the scope of this policy?

2. Has the CISO ensured business owners ' requirements for protecting their data are LJ D LJ documented in a system security plan?

3. Has the CISO ensured external interconnections between AOC-owned information D D D systems and other systems have interconnection service agreements?

4. Has the CISO ensured industrial control systems are not connected to the Internet, and LJ D LJ unless formally approved by the CIO or CISO, are not interconnected with other networks?

5. Has the CISO ensured that personnel who have access to, use or manage industrial D D D control systems have taken specialized IT security roles-based training?

6. Has the CISO, in conjunction with the COTR, confirmed information system vendors LJ D D have followed an industry-recognized standard requiring that their system receive an independent assessment of their information security controls?

AOC Order 7-4, October 10, 2017 16

7. Has the CISO, in conjunction with the COTR (or applicable AOC point of contact), LJ D D ensured agreements with vendors (or other federal agencies) who host third-party systems for the AOC, required the vendor (or agency) to inform the COTR (or applicable AOC point of contact) and the AOC CISO of any breach of their information system?

8. Has the CISO ensured the assessor for the AOC has conducted independent security D D D assessments of the management, operational and technical security controls in AOC information systems?

9. Has the CISO ensured the assessor provides recommended corrective actions to reduce or D D LJ eliminate vulnerabilities in the information system?

10. Has the CISO ensured the assessor provides an independent assessment of the system D D D security plans to ensure the plans provide a set of security controls?

11. Has the CISO ensured the assessor has created a plan of action and milestones for D D D controls that are found to not be implemented or partially implemented?

SYSTEM OWNER (OR DESIGNEE) RESPONSIBILITIES

I. Has the AOC system owner assisted and ensured their applicable personnel assist in the D D D protection of their information system as discussed in this policy?

2. Has the system owner managed user account access in accordance with the data D D D protection and data access requirements of the business owner?

3. Has the system owner ensured the security planning process is incorporated into their D D LJ information system's life cycle?

4. Has the AOC system owner successfully completed the appropriate information systems D D LJ roles-based training annually?

5. Has the AOC system owner ensured contingency planning and incident response D LJ D activities occur on their respective information system?

INFORMATION SYSTEM ADMINISTRATOR R ESPONSIBILITIES

I. Has the AOC-owned information system administrator assisted in the protection of the D D D information as discussed in this policy?

2. Has the system administrator managed the level of user access per the approved request D LJ D as discussed within this AOC policy?

3. Has the AOC-owned information system administrator successfully completed the LJ D LJ appropriate information systems roles-based training annually?

For each "No" answer, complete the following table.

Question# JUSTIFICATION/RATIONALE Responsible Person Phone to Contact

Comments:

AOC Order 7-4, October 10, 2017 17

OPR: Date:

AOC Order 7-4, October 10, 2017 18

File details come from the government source that posted it. Updated .