Attachment 01 - Network Access Security Policy.docx
DOCX document 47 KB Posted
- Attached to
- Nationwide Default Management Services (NDMS) Federal contract opportunity
- Solicitation number
- DRAFT-12SAD222R0001
- Issued by
- Not on record
View the file
Other files for this federal contract opportunity
Show all 27
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment 01 Network Access Security Policy Solicitation 12SAD122R0001
NETWORK ACCESS SECURITY POLICY
SEE FAR 39.101
A. General Policy Statement
(1) This policy establishes requirements for the secure access and transmission of data on all USDA Office of the Chief Information Officer (OCIO), Information Technology Services (ITS) networks to prevent unauthorized use or misuse of Federal Government information.
B. Policy Detail These standards must be followed:
(1) External Connections:
(a) All servers, network devices, or appliances hosting information or resources accessed from the Internet must be placed in a protected web farm which is separated from the internet and separated from the OCIO-ITS network by a firewall.
(b) Firewalls, Intrusion Detection and Prevention Systems and router-based controls, including Access Control Lists (ACL), must be used to control, restrict, and monitor all network traffic to and from the OCIO-ITS networks.
(c) All network traffic between OCIO-ITS locations must be transported on dedicated OCIO-ITS owned circuits or through a Virtual Private Network (VPN) connection meeting encryption levels set by OCIO-ITS security policies.
(d) No OCIO-ITS office must have Internet connectivity through any service provider other than the connectivity provided by OCIO-ITS network operations.
(2) Warning Banners
(a) The following Warning Banner must appear prior to system/network logon in order to provide fair notice regarding proper use to all devices attempting to access OCIO-ITS systems and networks
(b) Warning Banner:
Unauthorized access to this United States Government Computer System and software is prohibited by Title 18, United States Code 1030. This statute states that: Whoever knowingly, or intentionally accesses a computer without authorization or exceeds authorized access, and by means of such conduct, obtains, alters, damages, destroys, or discloses information or prevents authorized use of (data or a computer owned by or operated for) the Government of the United States must be punished by a fine under this title or imprisonment for not more than 10 years, or both.
All activities on this system and network may be monitored, intercepted, recorded, read, copied, or captured in any manner and disclosed in any manner, by authorized personnel. THERE IS NO RIGHT OF PRIVACY IN THIS SYSTEM. System personnel may give to law enforcement officials any potential evidence of crime found on USDA computer systems. USE OF THIS SYSTEM BY ANY USER, AUTHORIZED OR UNAUTHORIZED, CONSTITUTES CONSENT TO THIS MONITORING, INTERCEPTION, RECORDING, READING, COPYING OR CAPTURING AND DISCLOSURE. REPORT UNAUTHORIZED USE TO AN INFORMATION SYSTEMS SECURITY OFFICER.
(3) Remote Access
(a) General Access
1. Remote telecommunication access to Government computers presents special security concerns. A combination of physical controls, unique user identifiers, passwords, terminal identifiers, access control software, and strict adherence to security procedures is required to protect the information from unauthorized access.
2. Government-owned computer equipment, software, and communications are required for remote interaction to an OCIO-ITS network or computer system; i.e. direct interface to a system.
3. Business partners accessing via remote connection to OCIO-ITS network or computer system must have authorization and approval from OCIO-ITS ISSPM.
4. Remote access privileges to any OCIO-ITS network must meet USDA remote access and approval guidelines as described in DM3525-003: Telework & Remote Access Security, Part 3 or its replacement.
5. All connectivity established must be based on the principle of least access in accordance with the approved business requirements and security review.
6. All remote access connections must comply with OCIO-ITS Security Policy Manual Chapter Three: Authorization and Access Control Security Policy or its replacement.
7. All remote connections must be disconnected after 15 minutes of inactivity,
8. All Non-OCIO-ITS Government-owned devices must be equipped with antivirus software that is kept current with the latest virus signatures and must be consistently configured to ensure security against known vulnerabilities in operating systems and application software. Refer to OCIO-ITS Security Policy Manual Chapter Sixteen: Patch Management Security Policy, and OCIO-ITS Security Policy Manual Chapter Twenty-Seven: Virus Protection Security Policy, or their replacements, for additional information.
9. Reconfiguration of equipment used for remote access into the OCIO-ITS network is not permitted except for changes made to network and printer connection settings while in travel status for the explicit purpose of an approved connection. Under no condition should security features be lessened to make the change(s). Upon returning to the official duty station, all settings must be returned to the default configuration prior to re-connection to the OCIO-ITS network.
10. The OCIO-ITS Information Systems Security Program Manager (ISSPM) must ensure and verify that remotely connected systems are periodically scanned for security vulnerabilities. Suggestion – Specify how this must be managed.
11. The OCIO-ITS ISSPM is responsible for verifying the appropriate usage of remote access.
12. All security incidents or violations of this policy must be reported in accordance with OCIO-ITS Security Policy Manual Chapter Ten: Incident Identification, Declaration, Reporting, and Handling Security Policy or its replacement.
C. Privacy Act, Sensitive or Classified Data
(1) Decisions regarding the proper use and handling of sensitive data, as well as records subject to the Privacy Act, are delegated to individual supervisors who permit employees access the OCIO-ITS network remotely. Due to the sensitive nature of payroll and personnel databases, applications not normally accessible using public web browsers, must not be accessible remotely.
(2) Care must be taken to ensure those records subject to the Privacy Act and sensitive data are not disclosed to anyone except to those who are authorized access to such information in order to perform their duties. Organizations allowing employees to access records subject to the Privacy Act from a remote work site must maintain appropriate administrative, technical, and physical safeguards to ensure the security and confidentiality of the records.
D. Dial-Up Access
(1) Circuits used for direct connectivity to the OCIO-ITS network for administration and emergency purposes are permitted. The OCIO-ITS Telecom Operations Branch (TOB) staff must maintain a listing of telecommunication lines, their location, and purpose. Updated listings must be provided to the OCIO-ITS ISSPM as changes are made. Access to use these emergency lines must be tightly controlled.
(2) Routers for dedicated Integrated Services Digital Network (ISDN) lines configured for access to the OCIO-ITS network must meet minimum authentication requirements determined by the OCIO-ITS Operations Security Branch (OSB).
(3) All installations using dial-up solutions must obtain written approval from the OCIO-ITS ISSPM prior to implementation.
(4) Passwords used for dial-up authentication must be changed at a minimum of every 30 days.
E. Internet Access
(1) All network connections established with OCIO-ITS networks from the Internet must be protected by a Virtual Private Network (VPN) or an encrypted web browser.
(2) All VPN solutions must use encryption and authentication schemes that comply with OCIO-ITS OSB requirements.
(3) A list of currently permitted ports must be maintained and kept current by the TOB Branch and monitored by OSB. Only those protocols and ports required to perform business-related remote functions are to be permitted by the firewall.
(4) Distributed file sharing (i.e., Windows SMB file shares, SAMBA file shares, Network File Systems) must only be used by remote users/sites when connected through secured access (i.e., VPN access, authenticated dial-up connection, dedicated secure line, etc.)
(5) Internet access to USDA sites, both secured and public, is permissible from personal home computers (e.g. accessible USDA web pages; Bureau of Public Debt (BPD) time and attendance site; Outlook Web Access (OWA); etc.). No files accessed from the above should be saved locally.
F. Other OCIO-ITS or Partner Connections
(1) All parties that require connection through access to non-public OCIO-ITS resources fall under this section, regardless of whether Telco circuits, such as frame relay or ISDN, or VPN technology is used for the connection.
(2) All new extranet connectivity must go through a security review with the OCIO-ITS ISSPM. These reviews must ensure that all access matches the business requirements to the best possible method, and that the principle of least access is followed. (Should Interconnection Security Agreements be referenced here?)
(3) Organizations that wish to establish connectivity must file a new site request with the OCIO-ITS Telecom Operations Branch (TOB). The TOB must engage the OSB to address security issues inherent in the project. The sponsoring organization must provide full and complete information regarding the business requirements and technical specifications of the proposed access in writing to the Telecom Operations Branch and the OSB as requested.
(4) In no case must the OCIO-ITS exclusively depend upon the non-OCIO-ITS site to protect the connection to OCIO-ITS networks or resources
(5) The connecting organization is responsible for notifying the TOB and the OSB when there is a material change to their previously provided information. This must ensure that security and connectivity evolve accordingly. All changes in access must be accompanied by a valid business justification and are subject to a security review.
(6) When access is no longer required, the connecting organization must notify the OCIO-ITS TOB responsible for that connectivity, which must immediately terminate the access.
(7) The OCIO-ITS ISSPM is responsible for verifying an annual audit of extranet connections by the OCIO-ITS TOB to ensure that all existing connections are still required and that the access provided meets the current business requirements and technical standard. The OCIO-ITS ISSPM is also responsible for verifying that connections that are no longer being used to conduct business are terminated immediately.
G. Remote Control All remote-control programs that permit a user to manage another computer over a network connection must comply with the following standards:
(1) The OCIO-ITS ISSPM must verify that guidance has been provided on the implementation of the security features in the OCIO-ITS-provided remote access software package.
(2) All remote-control hosts must require a username and password to establish a connection. Usernames and passwords must meet the requirements set in the OCIO-ITS Security Policy Manual Chapter Three: Authorization and Access Control Security Policy.
(3) Remote control software must retain log files and audit trails according to the OCIO-ITS Security Policy Manual Chapter Two: Audit Security Policy.
(4) Telework
(a) General Requirements
1. A combination of physical controls, unique user identifiers, passwords, terminal identifiers, access control software, and strict adherence to security procedures is required to protect the OCIO-ITS infrastructure network from unauthorized remote access.
2. Temporary access (‘hoteling’) and emergency work away from one’s official duty station is considered “remote access” (see section above), not Telework
3. All Telework activity must follow the practices established for OCIO-ITS “Internet Access” as documented above.
4. Only OCIO-ITS-owned equipment, software, and materials, approved and tested for access to the OCIO-ITS network, must be used for Telework duties on the OCIO-ITS network. No personal equipment is permitted except as noted earlier in this document. No older, pre-OCIO-ITS equipment configured with unique RD-based builds is permitted.
5. Government-owned equipment must only be used for official duties. Only Telework participants are authorized to use Government-furnished equipment.
6. An employee who participates in the Telework program must certify in writing the security level of the official information used outside the primary worksite and the protection of Government-owned equipment and property.
7. OCIO-ITS retains the right to inspect the home or alternate worksite and the equipment used by an employee to ensure that proposed worksites are safe and that all equipment is adequately installed, maintained, and secured.
8. The employee must return all OCIO-ITS-owned equipment, software, and materials at the conclusion of the Telework arrangement or at the request of OCIO-ITS.
9. Telework is not considered an employee right. Supervisors and/or the applicable OCIO-ITS ISSPM can suspend or terminate an individual’s privilege to participate in the Telework program at any time. Where appropriate, disciplinary actions must be taken against the individual.
H. Privacy Act, Sensitive or Classified Data
(1) Decisions regarding the proper use and handling of sensitive data, as well as records subject to the Privacy Act, are delegated to individual supervisors who permit employees to work at home. Due to the sensitive nature of payroll and personnel databases, applications not normally accessible using public web browsers, must not be accessible to Telework participants.
(2) Care must be taken to ensure those records subject to the Privacy Act and sensitive data are not disclosed to anyone except to those who are authorized access to such information in order to perform their duties. Organizations allowing employees to access records subject to the Privacy Act from a remote work site must maintain appropriate administrative, technical, and physical safeguards to ensure the security and confidentiality of the records.
I. Data Access for Telework Participants
(1) Sensitive data is to be stored on Government-owned media or systems only.
(2) OCIO-ITS approved encryption software must be loaded on equipment for Telework participants accessing sensitive data.
(3) Participants must be trained to use the software package provided.
(4) Correspondence files and historical records are likely to be one-of-a-kind and may not be taken from the primary worksite. Since these records exist mainly in hardcopy, they are inaccessible via electronic means. Scanners and imaging systems(copiers) may be used to reproduce records for use off-site, if needed.
J. Computer Security Requirements
1. Computers utilized in support of the Telework program must be loaded and maintained with the current, common computing core load, up-to-date virus engines and definition files, and the applicable VPN remote access software, as supplied by OCIO-ITS. Telework supervisors must notify the information technology staff of any additional software requirements of the participant.
2. Telework participants must comply with security procedures to protect Government information stored on magnetic media of workplace computers.
3. Any equipment that must be serviced by non-Government service providers must have all sensitive information removed from media or memory prior to having the system repaired or rebuilt, in accordance with OCIO-ITS Security Policy Manual Chapter Thirteen: Media Sanitization and Disposal Security Policy or its replacement.
(5) Wireless Technology
(a) Use of wireless technology is available to all laptop users who have an OCIO-ITS configured, common core load and demonstrate a business need for wireless connectivity. Educated use is necessary due to the inherent security risks associated with wireless technology.
1. Users must be in the VPN mode when using wireless to engage in business processes.
2. A USDA approved access node must be available.
3. A hotel or business establishment, to which the user is offered wireless access as a business client, is an acceptable use, including for international use, provided the laptop is serving a USDA business process. NOTE: All international travel involving the use and transportation of OCIO-ITS equipment must be approved by the OCIO-ITS ISSPM.
4. Use of a business’ wireless network without an established client relationship with their network is not permissible.
5. ‘War driving’ or other similar methods used for the purpose of locating an access node is not an acceptable use.
6. ‘Piggybacking service’, considered the unauthorized tapping into someone else’s wireless Internet connection, such as a neighbor or local business, is not an acceptable use.
7. Establishing a new access node within a Federal building (e.g. a conference room or office) is not permissible unless approved by the ISSPM and notification is provided to OSB.
8. If the event that multiple access nodes are made available, in addition to the client source, only the client source node is permissible for use.
(b) The OCIO-ITS ISSPM is responsible for monitoring usage of wireless technology within the OCIO- ITS infrastructure network environment.
(c) Only Government-owned and OCIO-ITS approved wireless devices may access the OCIO-ITS network or any of its network devices.
(d) All wireless devices accessing the OCIO-ITS network must comply with the standards detailed in OCIO-ITS Security Policy Manual Chapter Thirty-Three: OCIO-ITS Wireless Technology Security Policy or its replacement.
(6) Exceptions All exceptions to this policy require a detailed waiver approved by the OCIO-ITS ISSPM, as documented in Introduction to the OCIO-ITS Security Policy Manual using the OCIO-ITS Security Waiver Form. Exceptions to Department Policy must also require a departmental exception, as detailed in CS-020: Cyber Security Memorandum and Guidance Regarding Submission of Waiver Requests.
(7) Incident Reporting and Response In the event of a security vulnerability or breach, malicious activity, successful attack, or violation of this policy has been discovered or suspected, an incident must be reported in accordance with Chapter Ten: Incident Identification, Declaration, Reporting, and Handling Security Policy or its replacement
(8) Enforcement Violation of this policy must be subject to disciplinary action up to and including termination.
By signing the above, I am acknowledging I have read and understand USDA’s NETWORK ACCESS SECURITY POLICY:
| _________________________________ | _____________________________ | |
| Offeror | Date |
image1.png
File details come from the government source that posted it. Updated .