Attachment 3 - CISA_Incident Reporting Requirements Update _March 29 2019.pdf
PDF 386 KB Posted
- Attached to
- Peace Corps MAC Support Services Federal contract opportunity
- Solicitation number
- 1145PC20Q0022
- Issued by
- Peace Corps
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 1145PC20Q0022 Final 5.22.20.doc | DOC document | |
| Attachment 1 - 209-Vulnerability Management Plan-2019.04_Final.pdf | ||
| Attachment 4 - MS 899 Breach Notification Response Plan.docx | DOCX document | |
| Attachment 2 - 701-Incident Response Plan 2019.pdf | ||
| Attachment 5 - IPS 1-17 Information Security Program.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
For Official Use Only
March 28, 2019
C I S A | C Y B E R S E C U R I T Y A N D I N F R A S T R U C T U R E S E C U R I T Y A G E N C Y
FEDERAL INCIDENT
REPORTING – UPDATE AND
CURRENT STATUS
Agenda
Opening and Desired Outcomes
Current Status
Overview OMB M-19-02 – Incident Reporting
Incident Reporting Highlights and Proposed Changes
Engagement and Reporting Notional Timeline
Discussion
Desired Outcomes
Shared awareness of the timeline for updating Federal incident reporting requirements.
Shared awareness of the implications and capacity to address OMB M-19-02 reporting.
Begin identifying areas or additional artifacts/support that may be needed.
Guidance, reporting templates, incident ingest schemas, etc.
Current Status and Progress Aug – Sept 2018: Engaged SOC managers to discuss planned incident reporting notification updates.
Oct 2018: OMB M-19-02 released
Desire for improved coordination and incident response to support agencies.
DHS and OMB gain improved visibility into Federal incidents and reporting.
Mar 2019: Re-engage broader Federal Civilian Executive Branch entities on reporting implications.
Apr – May 2019: Continued FCEB engagement on incident reporting requirements and implications.
Overview of Reporting Requirements
(OMB M-19-02)
Reinforces FISMA requirements: reports to OMB and DHS; annual reports to appropriate Congressional committees.
Major Incidents
Report to NCCIC and OMB OFCIO within one hour.
Report to Congressional committees and OIG within seven days.
Supplemental reports to Congress as appropriate.
Per PPD-41, if an incident is a major incident, it is also a “significant cyber incident.”
Thus, a major incident will also trigger the coordination mechanisms outlined in
PPD-41 and potentially require participation and actions from a Cyber Unified
Coordination Group.
A major incident determination is required for any unauthorized modification of, unauthorized deletion of, unauthorized exfiltration of, or unauthorized access to the
PII of 100,000 or more people.
Agencies should assess each breach on a case-by-case basis to determine whether the breach meets the definition of a major incident.
Incident Reporting (OMB M-19-02)
INCIDENT Per FISMA: An occurrence that (A) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system;
or (B) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.
MAJOR
INCIDENT
Per M-19-02: Any incident that is likely to result in demonstrable harm to the national security interests, foreign relations, or the economy of the United States or to the public confidence, civil liberties, or public health and safety of the American people. Agencies should determine the level of impact of the incident by using the existing incident management process established in NIST SP 800-61 Rev 2.
OR
A breach that involves personally identifiable information (PII) that, if exfiltrated, modified, deleted, or otherwise compromised, is likely to result in demonstrable harm to the national security interests, foreign relations, or the economy of the United States, or to the public confidence, civil liberties, or public health and safety of the American people. Major incident determination required for breaches involving PII of 100,000 or more people.
BREACH Per M-17-12: The loss of control, compromise, unauthorized, disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose.
Reporting Highlights
INCIDENTS MAJOR INCIDENTS BREACHES
INITIAL REPORT
• 1 hour after determination
NCCIC NCCIC, OMB OFCIO NCCIC
72-HOUR UPDATE
• Every 72 hours until remediation
NCCIC NCCIC NCCIC
POST-INCIDENT UPDATE
• 7 days after remediation
NCCIC NCCIC NCCIC
CONGRESSIONAL REPORT
• 7 days after determination
Congress, OIG Congress, OIG
• If major incident
SUPPLEMENTAL CONGRESSIONAL
REPORTS
• Within reasonable period of time
Congress, OIG Congress, OIG
• If major incident
POST-BREACH CONGRESSIONAL
REPORTS
• 30 days after determination
Congress, OIG
• If major incident
Proposed Reporting Changes Change name from Federal Incident Notification Guidelines (FING), to Federal
Incident Reporting Requirements (FIRR).
Ensure a common set of terms are adopted for reporting and use, such as:
Incident: As defined by FISMA 2014
Event: As defined by NIST SP 800-61 Rev 2
“Potential incidents” shall no longer be reported to NCCIC; only confirmed incidents.
Both potential and confirmed breaches will be reported to NCCIC.
Describe/provide mechanism(s) to automate reporting to NCCIC.
Reporting Responsibility
FCEB entities shall designate an entity within their organization that will report and update on all incidents, major incidents, and breaches to NCCIC.
Once identified, the designated entity shall adhere to the timeframes identified.
Critical timeframes for incidents, major incidents, and breaches established.
Proposed Reporting Changes (2)
Identify critical infrastructure sector and impacted systems.
Detail attack vectors and indicators of compromise.
Provide information on current stage of incident handling lifecycle (i.e. containment, eradication, recovery). Explain strategy used, whether successful or not, and how strategy will be adjusted if unsuccessful.
Provide timeline of identified or suspected compromised systems communicating with other systems.
Upon request and if available, provide memory captures as well as system and network logs.
When submitting breach reports, provide: whether breach is associated with a previous incident, upgraded to major incident, and if agency is contracting out assistance for breach.
Engagement and Report Notional Timeline
FY19 Q3
• Late April – Release
Draft to FCEB
• May – Conduct FCEB Working Sessions
• Late May/Early June
– Release Final Draft to FCEB
FY19 Q4
• June - September –
Agency Preparation & Planning
FY20 Q1
• Updated Report
Requirements Released Publicly
Public Review period
Discussion What are the challenges with existing incident reporting requirements?
How do changes to incident reporting requirements impact your incident response policy, plan, and procedures?
What can you begin doing to prepare for the release of updated incident reporting requirements?
Will you need to collaborate with additional entities within your organization?
What other impacts should we be considering as part of this update?
What can CISA provide to assist with this process? Guidance, reporting templates, data/ingest schemas?
Federal Upcoming Events
April 2 & 9: Securing the DNS Ecosystem:
Interagency Listening
Sessions
Week of May 6 and
13: Incident
Reporting Working
Sessions
Thursdays: Weekly SOC Call
April 18: Introduction to Creating Queries & Reports Using Release 5 of the CDM Agency Dashboard
April 30:
Cybersecurity
Priorities and Action
Coordination Call
May 1: DHS Federal
Cybersecurity
Advisory Council
(FCAC)
CIOs and CISOs All Cyber Leaders Program Leads & Analysts
For more information on these events e-mail
CyberLiaison@hq.dhs.gov
Acronyms FISMA: Federal Information Security Modernization Act of 2014
OFCIO: Office of the Federal Chief Information Officer
OIG: Office of the Inspector General
OMB: Office of Management and Budget
NCCIC: National Cybersecurity & Communications Integration Center
NIST: National Institute of Standards and Technology
PoCs: Points of Contact
PPD: Presidential Policy Directive
SP: Special Publication
TLP: Traffic Light Protocol
File details come from the government source that posted it. Updated .