Attachment 3 - CISA_Incident Reporting Requirements Update _March 29 2019.pdf

PDF 386 KB Posted

Attached to
Peace Corps MAC Support Services Federal contract opportunity
Solicitation number
1145PC20Q0022
Issued by
Peace Corps

View the file

Other files for this federal contract opportunity

Other files attached to Peace Corps MAC Support Services, newest first.
File Type Posted
1145PC20Q0022 Final 5.22.20.doc DOC document
Attachment 1 - 209-Vulnerability Management Plan-2019.04_Final.pdf PDF
Attachment 4 - MS 899 Breach Notification Response Plan.docx DOCX document
Attachment 2 - 701-Incident Response Plan 2019.pdf PDF
Attachment 5 - IPS 1-17 Information Security Program.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

For Official Use Only

March 28, 2019

C I S A | C Y B E R S E C U R I T Y A N D I N F R A S T R U C T U R E S E C U R I T Y A G E N C Y

FEDERAL INCIDENT

REPORTING – UPDATE AND

CURRENT STATUS

Agenda

Opening and Desired Outcomes

Current Status

Overview OMB M-19-02 – Incident Reporting

Incident Reporting Highlights and Proposed Changes

Engagement and Reporting Notional Timeline

Discussion

Desired Outcomes

Shared awareness of the timeline for updating Federal incident reporting requirements.

Shared awareness of the implications and capacity to address OMB M-19-02 reporting.

Begin identifying areas or additional artifacts/support that may be needed.

Guidance, reporting templates, incident ingest schemas, etc.

Current Status and Progress Aug – Sept 2018: Engaged SOC managers to discuss planned incident reporting notification updates.

Oct 2018: OMB M-19-02 released

Desire for improved coordination and incident response to support agencies.

DHS and OMB gain improved visibility into Federal incidents and reporting.

Mar 2019: Re-engage broader Federal Civilian Executive Branch entities on reporting implications.

Apr – May 2019: Continued FCEB engagement on incident reporting requirements and implications.

Overview of Reporting Requirements

(OMB M-19-02)

Reinforces FISMA requirements: reports to OMB and DHS; annual reports to appropriate Congressional committees.

Major Incidents

Report to NCCIC and OMB OFCIO within one hour.

Report to Congressional committees and OIG within seven days.

Supplemental reports to Congress as appropriate.

Per PPD-41, if an incident is a major incident, it is also a “significant cyber incident.”

Thus, a major incident will also trigger the coordination mechanisms outlined in

PPD-41 and potentially require participation and actions from a Cyber Unified

Coordination Group.

A major incident determination is required for any unauthorized modification of, unauthorized deletion of, unauthorized exfiltration of, or unauthorized access to the

PII of 100,000 or more people.

Agencies should assess each breach on a case-by-case basis to determine whether the breach meets the definition of a major incident.

Incident Reporting (OMB M-19-02)

INCIDENT Per FISMA: An occurrence that (A) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system;

or (B) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.

MAJOR

INCIDENT

Per M-19-02: Any incident that is likely to result in demonstrable harm to the national security interests, foreign relations, or the economy of the United States or to the public confidence, civil liberties, or public health and safety of the American people. Agencies should determine the level of impact of the incident by using the existing incident management process established in NIST SP 800-61 Rev 2.

OR

A breach that involves personally identifiable information (PII) that, if exfiltrated, modified, deleted, or otherwise compromised, is likely to result in demonstrable harm to the national security interests, foreign relations, or the economy of the United States, or to the public confidence, civil liberties, or public health and safety of the American people. Major incident determination required for breaches involving PII of 100,000 or more people.

BREACH Per M-17-12: The loss of control, compromise, unauthorized, disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose.

Reporting Highlights

INCIDENTS MAJOR INCIDENTS BREACHES

INITIAL REPORT

• 1 hour after determination

NCCIC NCCIC, OMB OFCIO NCCIC

72-HOUR UPDATE

• Every 72 hours until remediation

NCCIC NCCIC NCCIC

POST-INCIDENT UPDATE

• 7 days after remediation

NCCIC NCCIC NCCIC

CONGRESSIONAL REPORT

• 7 days after determination

Congress, OIG Congress, OIG

• If major incident

SUPPLEMENTAL CONGRESSIONAL

REPORTS

• Within reasonable period of time

Congress, OIG Congress, OIG

• If major incident

POST-BREACH CONGRESSIONAL

REPORTS

• 30 days after determination

Congress, OIG

• If major incident

Proposed Reporting Changes Change name from Federal Incident Notification Guidelines (FING), to Federal

Incident Reporting Requirements (FIRR).

Ensure a common set of terms are adopted for reporting and use, such as:

Incident: As defined by FISMA 2014

Event: As defined by NIST SP 800-61 Rev 2

“Potential incidents” shall no longer be reported to NCCIC; only confirmed incidents.

Both potential and confirmed breaches will be reported to NCCIC.

Describe/provide mechanism(s) to automate reporting to NCCIC.

Reporting Responsibility

FCEB entities shall designate an entity within their organization that will report and update on all incidents, major incidents, and breaches to NCCIC.

Once identified, the designated entity shall adhere to the timeframes identified.

Critical timeframes for incidents, major incidents, and breaches established.

Proposed Reporting Changes (2)

Identify critical infrastructure sector and impacted systems.

Detail attack vectors and indicators of compromise.

Provide information on current stage of incident handling lifecycle (i.e. containment, eradication, recovery). Explain strategy used, whether successful or not, and how strategy will be adjusted if unsuccessful.

Provide timeline of identified or suspected compromised systems communicating with other systems.

Upon request and if available, provide memory captures as well as system and network logs.

When submitting breach reports, provide: whether breach is associated with a previous incident, upgraded to major incident, and if agency is contracting out assistance for breach.

Engagement and Report Notional Timeline

FY19 Q3

• Late April – Release

Draft to FCEB

• May – Conduct FCEB Working Sessions

• Late May/Early June

– Release Final Draft to FCEB

FY19 Q4

• June - September –

Agency Preparation & Planning

FY20 Q1

• Updated Report

Requirements Released Publicly

Public Review period

Discussion What are the challenges with existing incident reporting requirements?

How do changes to incident reporting requirements impact your incident response policy, plan, and procedures?

What can you begin doing to prepare for the release of updated incident reporting requirements?

Will you need to collaborate with additional entities within your organization?

What other impacts should we be considering as part of this update?

What can CISA provide to assist with this process? Guidance, reporting templates, data/ingest schemas?

Federal Upcoming Events

April 2 & 9: Securing the DNS Ecosystem:

Interagency Listening

Sessions

Week of May 6 and

13: Incident

Reporting Working

Sessions

Thursdays: Weekly SOC Call

April 18: Introduction to Creating Queries & Reports Using Release 5 of the CDM Agency Dashboard

April 30:

Cybersecurity

Priorities and Action

Coordination Call

May 1: DHS Federal

Cybersecurity

Advisory Council

(FCAC)

CIOs and CISOs All Cyber Leaders Program Leads & Analysts

For more information on these events e-mail

CyberLiaison@hq.dhs.gov

Acronyms FISMA: Federal Information Security Modernization Act of 2014

OFCIO: Office of the Federal Chief Information Officer

OIG: Office of the Inspector General

OMB: Office of Management and Budget

NCCIC: National Cybersecurity & Communications Integration Center

NIST: National Institute of Standards and Technology

PoCs: Points of Contact

PPD: Presidential Policy Directive

SP: Special Publication

TLP: Traffic Light Protocol

File details come from the government source that posted it. Updated .