Attachment 38b - IT_Security_Handbook.pdf
PDF 2 MB Posted
- Attached to
- Patent Data and Document Management (PDDM) Federal contract opportunity
- Solicitation number
- 1333BJ20R00151004
About this file
This is a Request for Proposals from the United States Patent and Trademark Office seeking contractor support to manage the patent application processing lifecycle. Services required include managing the initial filing of patent applications, processing throughout examination, and final application disposition. A thorough understanding of requirements can only be gained by carefully reviewing the RFP, Statement of Work, references, and attachments provided in Section J, including an RFP Section J glossary defining terms. The attachment version dates are noted in the Section J crosswalk.
View the file
Other files for this federal contract opportunity
Show all 50
Patent Data and Document Management (PDDM) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
For Official Use Only
UNITED STATES
PATENT AND TRADEMARK OFFICE (USPTO)
IT SECURITY HANDBOOK
March 26, 2019
Version 5.5
USPTO IT Security Handbook March 2019 ii
DOCUMENT HISTORY
Change
Number
Date of
Change
Sections
Changed Revision Summary
Person
Approving
Change v0.5 04/26/07 All Initial Submission Quentin
Robinson v0.6 07/18/07 All Revised all sections based on renaming remaining LOE as per USPTO TOM
Quentin
Robinson v0.7 8/23/07 All New org structure incorporated more minor edits.
Quentin
Robinson v0.8 10/3/07 All General editing Quentin
Robinson v2.5 12/20/07 All General Editing Quentin
Robinson v2.8.1 6/16/08 Signature Changed Approving Authority Katherine Queen v3.0 12/13/10 All
- Replaced/ removed outdated and superseded references.
- Added references to additional
Federal, DOC, and USPTO policies and procedures.
- Removed processes and procedures contained in, and repetitive of, lower tier documents.
- Revised and added to security controls that were not completely or correctly addressed.
- Reformatted to comply with current
CIO Policy Documents template.
- Updated Acronym and Terms lists.
- Corrected spelling and grammar errors throughout.
Missing Link
Security v3.0.1 4/7/11 All
Revised all sections to make it consistent with the Department of
Commerce IT Security Program Policy
(DOC ITSPP) and NIST 800- 53 Rev
3.
A3IS
v3.1 12/19/11 All
- Replaced/ removed outdated and superseded references.
- Added references to additional
Federal, DOC, and USPTO policies and procedures.
- Removed processes and procedures contained in, and repetitive of, lower tier documents.
- Revised and added to security
Missing Link
Security
USPTO IT Security Handbook March 2019 iii
Change
Number
Date of
Change
Sections
Changed Revision Summary
Person
Approving
Change controls that were not completely or correctly addressed.
- Updated Acronym and Terms lists.
- Corrected spelling and grammar errors throughout.
v3.2 12/23/11 All
- Changes implemented per comments received.
Missing Link
Security v3.3 1/13/12 All
- Fixed formatting inconsistencies.
- Updated per comments received during review cycle
Missing Link
Security v3.4 2/3/12 All
- Removed all IT Security Handbook
Policy references
- Updated CM-7 requirements
Missing Link
Security v3.5 2/29/2012 All - Update RA-5 requirements Missing Link
Security v3.6 5/09/2012 All
- Updated per comments received during final review cycle
Missing Link
Security v3.7 8/21/2012 All
- Updated AC-2 requirements
- Changed SAISO to SISO
- Updated roles and responsibilities
Missing Link
Security v3.8 2/08/2013 Role and
Responsibilities
- Added FPOC Role
- Removed SLIC reference
A3IS
v4.0 10/2013 All - Revised to address 800-53 Rev.4 A3IS
V4.1 11/2014 All - Annual review and update A3IS
V4.2 12/30/2014 Section 4.8
- Incident Response Reporting requirements were updated based on new DOC guidance
A3IS
V 4.3 12/16/2015 Multiple sections
- Annual review and updates – removed reference to management, operational and technical controls throughout the document; updated document with the most recent NIST guidance, USPTO and DOC policy and procedures and updated links;
updated section 2.1; added section
3.2.9: Information Owner/Steward;
added privacy controls under
Appendix A; updated Appendix C and D; updated following security control requirements: all dash 1 security controls, AC-2.11, AC-4, AC-6, AC-7, AC-8, AC-12, AC-14, AC-18.1, AC-19, AC-21, AT-3, A3IS
USPTO IT Security Handbook March 2019 iv
Change
Number
Date of
Change
Sections
Changed Revision Summary
Person
Approving
Change
AU-2, AU-5.2, AU-6, AU-9.4, AU-
11, CA-5, CM-2.7, CM-3, CM-7.2,
CM-7.4, CM-7.5, CP-4, IA-2.11, IA-
5, IA-5.1, IR-3, MP-5, PE-15, PE-17,
PL-2.3, PS-8, RA-5, SA-3, SA-4,
SC-5, SC-7.3, SC-7.4, SC-13, SC-23
SI-2, SI-7, SI-7.1, SI-16, PM-5, PM-
6, AR-7.
V 4.4 05/09/2016 Section 4.7
- IA-5, IA-5(1) security controls to address public facing systems authenticator requirements
A3IS
V 4.5 7/11/2016 Multiple sections
- AC-8; reference to DOC ITSSP A3IS
V 4.6 8/31/2016 Multiple sections
- IA-5, IA-5(1) with further clarification on public facing systems
A3IS
V. 4.7 9/19/2016 Multiple
Sections
- Section 3.2.16, IR-6 (incident reporting to address new DOC
Incident Response Policy);
A3IS
v. 4.8 12/31/2016 Annual review and update
Section 4.1.4 RA-5 (scanning requirements)
A3IS
V 4.9 02/10/2017 Multiple
Sections
-Added DOC CITR-024, FedRAMP
Applicability reference to section 2.1
-Added FedRAMP applicable security controls to Section IV along with
FedRAMP requirements
-Updated all dash 1 security controls in section 4 to identify that policy and procedures updates are done as needed and annually
-Added banner note to AC-8
-Added FedRAMP requirements relevant to AC-20
-AU-8- updated to one second requirement for DOC consistency
-IR-6 updated to address OIG requirement to report incidents as necessary to OIG and law enforcement
-Added NIST 800 52 rev 1 TLS requirements to SC-23
V 5.0 4/14/2017 Section 4.1.4 Updated RA-5 scanning requirement to address OIG audit finding
A3IS
V 5.1 6/12/2017 Section 4.1,
4.5 -Updated CM-7.2, 7.4 and CM-11 with unapproved software removal
USPTO IT Security Handbook March 2019 v
Change
Number
Date of
Change
Sections
Changed Revision Summary
Person
Approving
Change information.
-Updated AC-6 and enhancements 1, 2 and 9 with new requirements from
DOC CITR-026.
-Updated AC-2 to address requirement for review of privileged accounts twice a year.
V 5.2 8/22/2017 Section 4.13
Updated PS-4, PS-7 control to address
KPMG audit and clarify employee or contractor termination and account deactivation requirements.
A3IS
V 5.3 03/26/2018 Multiple
Sections
Updated following:
-All dash 1 security controls to distinguish between review and update requirement.
-AC-2, to address service and non human accounts requirement, including review of privileged account twice a year per DOC CITR-026.
-AC-6, updated to address CITR-026 requirements.
-AC-12, added requirement on termination of remote session and privileged accounts session.
-AU-3, addressed audit requirements for data extracts from database holding sensitive information.
- CA-2, added section on CSP
FedRAMP requirements.
-CP-4, added section on CIO approval for performing tabletop CP exercises for the systems with the low FIPS 199 availability categorization and defined functional and tabletop exercises requirements.
-IA-5, added PIV cards usage for initial
PTONet access to Note section.
-IR-6, updated section on external communication associated with incident.
-PE-17, updated ERA portal to Team
Portal.
-PS-4, PS-5 to address A-123 Audit.
-SA-9, added section on CSP
USPTO IT Security Handbook March 2019 vi
Change
Number
Date of
Change
Sections
Changed Revision Summary
Person
Approving
Change
FedRAMP requirements references.
-SC-28, added section on allowed mechanisms to achieve confidentiality and integrity of data at rest.
-SI-5, added DOC CIRT, OMB and vendors as external organizations that
USPTO receives security alerts and advisories.
-PM-4, added references to POA&M minimum standards.
V 5.4 6/2018 Section 2.1 Updated Administrative Access Right policy reference #
A3IS
V 5.5 3/26/2019
Sections: 2.1, 3.2.18, 4.1, 4.3, 4.4, 4.5, 4.14, 5.1, appendix
B, C, D
Annual review and updates:
- section 2.1, policy and procedures updates;
-section 3.2.18- SAOP/CPO role;
-section 4.1, AC-17 control;
-section 4.3, AU-2 control;
-section 4.4, CA-3.3, CA-8, CA-8.1 controls;
-section 4.5, CA-3 control (CCBP link);
-section 4.14, RA-5.6 control;
-section 4.16, SC-23 updated encryption requirements;
-section 5.1, minor changes to privacy controls: AP-1, AR-1;
-Appendix B, added SAOP/CPO;
-Updated references in appendix C and
D
USPTO IT Security Handbook March 2019 vii
Table of Contents
1 INTRODUCTION
1.1 BACKGROUND
1.2 PURPOSE
1.3 SCOPE, MANAGEMENT COMMITMENT AND COORDINATION, AND APPLICABILITY
1.4 UPDATE AND REVIEW
1.5 AUTHORITY
1.6 COMPLIANCE
1.7 USPTO IT SECURITY PROGRAM DOCUMENTATION
2 IT SECURITY HANDBOOK
2.1 EFFECTIVE DATE
2.2 RISK ACCEPTANCE
2.3 ENFORCEMENT
3 IT SECURITY ROLES AND RESPONSIBILITIES
3.1 PERSONNEL
3.2 ROLES AND RESPONSIBILITIES
3.2.1 USPTO Chief Information Officer (CIO)
3.2.2 Co-Authorizing Official (Co-AO)
3.2.3 Authorizing Official Designated Representative (AODR)
3.2.4 USPTO Business Area Heads
3.2.5 USPTO Senior Information Security Officer (SISO)
3.2.6 USPTO Risk Executive Function
3.2.7 USPTO Security Authorization and Compliance Manager
3.2.8 USPTO System Owner
3.2.9 Information Owner/Steward
3.2.10 USPTO Common Control Provider
3.2.11 USPTO Information System Security Manager (ISSM)
3.2.12 USPTO Information System Security Officer (ISSO)
3.2.13 USPTO Facilitation Point of Contact (FPOC)
3.2.14 USPTO System and Network Administrators/Technical Lead (TL)
3.2.15 USPTO Security Control Assessor
3.2.16 USPTO Computer Incident Response Team
3.2.17 Key Contingency Roles
3.2.18 USPTO Chief Privacy Officer/Senior Agency Official for Privacy
3.3 ADDITIONAL ROLES
3.3.1 Contracting Officer (CO)
3.3.2 Contracting Officer’s Technical Representative (COTR)
3.4 USPTO OFFICES
3.4.1 Office of the Chief Information Officer (OCIO)
3.4.2 Office of Organizational Policy and Governance (OPG)
3.4.3 Office of Infrastructure Engineering and Operations (IEO)
3.4.4 USPTO Office of Security
3.4.5 Office of Inspector General (OIG)
4 IT SECURITY CONTROLS
4.1 ACCESS CONTROL (AC)
4.2 AWARENESS AND TRAINING (AT)
4.3 AUDIT AND ACCOUNTABILITY (AU)
4.4 SECURITY ASSESSMENT AND AUTHORIZATION (CA)
USPTO IT Security Handbook March 2019 viii
4.5 CONFIGURATION MANAGEMENT (CM)
4.6 CONTINGENCY PLANNING (CP)
4.7 IDENTIFICATION AND AUTHENTICATION (IA)
4.8 INCIDENT RESPONSE (IR)
4.9 MAINTENANCE (MA)
4.10 MEDIA PROTECTION (MP)
4.11 PHYSICAL AND ENVIRONMENTAL PROTECTION (PE)
4.12 PLANNING (PL)
4.13 PERSONNEL SECURITY (PS)
4.14 RISK ASSESSMENT (RA)
4.15 SYSTEM AND SERVICES ACQUISITION (SA)
4.16 SYSTEM AND COMMUNICATIONS PROTECTION (SC)
4.17 SYSTEM AND INFORMATION INTEGRITY (SI)
4.18 PROGRAM MANAGEMENT (PM)
5 PRIVACY CONTROLS
5.1 AUTHORITY AND PURPOSE (AP)
5.2 ACCOUNTABILITY, AUDIT, AND RISK MANAGEMENT (AR)
5.3 DATA QUALITY AND INTEGRITY (DI)
5.4 DATA MINIMIZATION AND RETENTION (DM)
5.5 INDIVIDUAL PARTICIPATION AND REDRESS (IP)
5.6 SECURITY (SE)
5.7 TRANSPARENCY (TR)
5.8 USE LIMITATION (UL) ................................................................................................................................ A-1 APPENDIX A. ACRONYMS AND ABBREVIATIONS ........................................................................ A-2 APPENDIX B. GLOSSARY ....................................................................................................................... B-1 APPENDIX C. REFERENCES ................................................................................................................... C-1 APPENDIX D. ................................................................................................................................................... D-1 IT SECURITY LAWS AND FEDERAL REGULATIONS ............................................................................ D-1
USPTO IT Security Handbook March 2019
1 Introduction
The Federal Information Security Modernization Act (FISMA) provides a comprehensive framework for ensuring the effectiveness of information security controls over information resources that support
Federal operations and assets, and defines “adequate security” as security commensurate with the risk and magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of information. This includes ensuring that systems and applications used by the agency operate effectively and provide appropriate confidentiality, integrity, and availability with cost effective security and privacy controls. This document sets forth the United States Patent and Trademark Office (USPTO) IT Security
Handbook.
1.1 Background
The National Institute of Standards and Technology (NIST) Federal Information Processing Standards
(FIPS) Publication 200, Minimum Security Requirements for Federal Information and Information
Systems, directs that all Federal Government agencies ensure that adequate security controls be implemented for their information subsystems. The guidelines provided in FIPS 200 are applicable to all federal information systems other than those systems designated as national security systems as defined in 44 U.S.C., Chapter 35, Coordination of Federal Information Policy § 3542. This handbook describes how the United States Patent and Trademark Office (USPTO) will comply with FISMA and other related directives.
The IT security policies captured in this Handbook were developed to meet the minimum legally and federally mandated requirements for information security and are based on the Federal Government standards and procedures issued by the Office of Management and Budget (OMB), NIST, and the
General Services Administration (GSA). Appendix C of this Handbook provides a list of references used in developing this handbook.
1.2 Purpose
The purpose of this USPTO IT Security Handbook is to document security policies and procedures, in accordance with Federal government mandated requirements. This Handbook addresses requirements and guidance set forth by the Federal Information Security Modernization Act (FISMA). It also encompasses minimum security controls as required by the Federal Information Processing Standard
(FIPS) 200, Minimum Security Requirements for Federal Information and Information Systems; and defined by the current National Institute of Standards and Technology (NIST) Special Publication (SP)
800-53 Revision 4, Security and Privacy Controls for Federal Information Systems and Organizations, commensurate with security categorization defined by FIPS 199, Standards for Security Categorization of Federal Information and Information Systems.
1.3 Scope, Management Commitment and Coordination, and Applicability
The provisions of this Handbook apply to all USPTO employees and contractor employees accessing or using USPTO information subsystems or data processed, transmitted, and/or stored on USPTO information subsystems; and to contractor employees providing services to the USPTO who use
USPTO information subsystems or data. This Handbook applies to all USPTO information systems and supporting resources, independent of size, location, or interconnection(s). Additionally, this
Handbook applies to all types of media used to store USPTO agency sensitive information and personally identifiable information (PII) which includes, but is not limited to: (i) hard drives, (ii) CDs, USPTO IT Security Handbook March 2019
(iii) DVDs, (iv) other magnetic media, and (v) solid-state media (Universal Serial Bus (USB) flash drive). Finally, it applies to all media output (to include digital, hard-copy (paper records), and microfilm formats) that contain USPTO classified or agency-sensitive information and PII.
This Handbook also applies to information subsystems and equipment, including network devices, operated and used by contractor employees, guest researchers, collaborators, and other federal agencies that help carry out the USPTO mission, whether or not such information subsystems or equipment are owned or leased by the government or on government property. The security policies set forth in this
Handbook apply to all IT procurement activities.
1.4 Update and Review
Policies will be reviewed, at minimum on an annual basis and updated as needed. Policies may be reviewed more frequently as necessary (e.g., due to new Federal or USPTO mandates updates and changes).
1.5 Authority
This Handbook is issued under the authority of the USPTO Chief Information Officer (CIO). The most critical Federal laws, regulations, Executive Orders, policies, standards, and directives followed are indicated below.
E-Government Act of 2002
The Privacy Act of 1974
Clinger-Cohen Act of 1996
National Technology Transfer and Advancement Act of 1996
Health Insurance Portability and Accountability Act of 1996 (HIPAA)
Federal Information Security Management Act of 2002 (FISMA)
Federal Information Security Modernization Act of 2014 (FISMA)
Federal Financial Management Improvement Act of 1996 (FFMIA)
Federal Acquisition Streamlining Act of 1994 (FASA)
United States Government Accountability Office, Federal Information System Controls Audit
Manual (FISCAM)
OMB Circulars
OMB Memoranda
Federal Information Processing Standards (FIPS)
NIST Special Publications
1.6 Compliance
Compliance with this Handbook is mandatory. It is USPTO policy that personnel and information systems abide by or exceed the requirements outlined in this Handbook and the associated procedures for each NIST SP 800-53 rev 4 family of controls. The Senior Information Security Officer (SISO) will periodically assess USPTO’s adherence with this Handbook through various oversight and compliance measures.
In cases where an information systems cannot comply with this Handbook, for technical or financial reasons, or because it precludes USPTO from supporting mission or business functions, justifications for
USPTO IT Security Handbook March 2019 non-compliance must be documented using the risk acceptance process, addressed by the System Owner, and submitted to the CIO via the SISO. Risk Acceptance process is officially documented in the USPTO
IT Policy on Security Risk Acceptance, OCIO-POL-35.
1.7 USPTO IT Security Program Documentation
This Handbook is organized into five sections to address information security as follows:
Section 1 – Introduction: Describes the background, purpose, scope, and documentation.
Section 2 – IT Security Handbook: Describes the authority, effective date, risk acceptance memos, and enforcement.
Section 3 – IT Security Roles and Responsibilities: Provides an outline of the departmental offices, roles, and IT groups.
Section 4 and 5 – Baseline Security Controls: Contain a complete list of security controls with
USPTO specific criteria including additional FedRAMP controls and program management and privacy controls.
A listing of acronyms, terms, and references can be found in the appendices.
USPTO IT Security Handbook March 2019
2 IT Security Handbook
USPTO shall develop, document, and implement an IT security program to protect the confidentiality, integrity, and availability of USPTO information and systems in accordance with the
Federal Information Security Modernization Act (FISMA) of 2014.
USPTO shall use FIPS 199 to categorize information systems and determine their appropriate impact levels (Low, Moderate, or High). The USPTO shall select the security controls baseline defined in current NIST SP 800-53, rev 4, based on the system’s impact level, and tailor, supplement, and implement the baseline according to NIST 800-53. The USPTO shall use current NIST SP 800-53A, Revision 4, Guide for Assessing Security and Privacy Controls in Federal Information Systems and
Organizations, Building Effective Assessment Plans, as the basis for assessing information system security controls to determine the extent to which they are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements. The
USPTO shall authorize information systems in accordance with the current NIST SP 800-37 revision
1, Guide for Applying the Risk Management Framework to Federal Information Systems, A Security
Life Cycle Approach. The USPTO shall be compliant with revisions to the aforementioned documents within one year of their issuance.
2.1 Effective Date
The USPTO IT Security Handbook is effective when signed by the CIO, superseding previous versions of this document. This version also incorporates the requirements of the following DOC Commerce
Information Technology Requirements (CITRs), which will remain in effect until superseded by updated
CITRs:
CITR-005: Removable Media Devices
CITR-006: Information System Security Training for Significant Roles
CITR-008: Remote Access
CITR-011: Peer-to-Peer Technology
CITR-014: Wireless Encryption Enhancements Policy
CITR-015: Contingency Plan Testing
CITR-016: Vulnerability Scanning and Patch Management
CITR-017: Security Configuration Checklist Program
CITR-018: IT Security Plan of Action and Milestones (POA&M)
CITR-019: Risk Management Framework
CITR-020: Safeguarding Information while on Foreign Travel
CITR-021: Password Management
CITR-022: Access and Use Policy
CITR-023:Pre-Acquisition Supply Chain Risk Assessment
CITR-024: FedRAMP Applicability
CITR-026: Privileged Accounts Management
For information about all current CITRs, please visit the DOC IT Security Program Policy website:
https://connection.commerce.gov/policy/20140528/it-security-program-policy-and-commerce-information-technology-requirements https://connection.commerce.gov/policy/20140528/it-security-program-policy-and-commerce-information-technology-requirements https://connection.commerce.gov/policy/20140528/it-security-program-policy-and-commerce-information-technology-requirements
USPTO IT Security Handbook March 2019
The following USPTO OCIO policies and procedures were merged into the associated NIST family-based set of procedures:
Access Control (AC) Procedures o OCIO-POL-11: Administrative Access Rights o OCIO-POL-12: Password Protected Screensaver o OCIO-POL-15: Remote Access o OCIO-POL-48: IT Separation of Duties o OCIO-POL-41: IT User Account Deactivation o OCIO: POL-34: Mobile Device Management
Audit and Accountability (AU) Procedures o OCIO-POL-20: Network and AIS Audit, Logging, and Monitoring
Awareness and Training (AT) Procedures o OCIO-POL-19: IT Security Education Awareness Training
Configuration Management (CM) Procedures o OCIO-POL-31: Enterprise Configuration Management o OCIO-POL-32: Enterprise Change Management o OCIO-POL-6: Information Security Foreign Travel o OCIO-POL-13: Peer To Peer Software and File Sharing
Contingency Planning (CP) Procedures
Identification and Authentication (IA) Procedures o OCIO-POL-21: Password Management o OCIO-POL-49: Personal Identity Verification (PIV) Card Authentication
Incident Response (IR) Procedures o OCIO-POL-45: CIO Command Center (OCIO) o OCIO-POL-17: Breach Notification
Maintenance (MA) Procedures
Media Protection (MP) Procedures o OCIO-POL-23: Personally Identifiable Data Removal o OCIO-PRC-9: Sanitization and Disposal of Mobile Devices
Personnel Security (PS) Procedures o OCIO-POL-41: IT User Account Deactivation
Physical and Environmental Protection (PE) Procedures o OCIO-5012-09: IT Facility Emergency Power Off (EPO) Switches o OCIO-POL-6: Information Security Foreign Travel
Planning (PL) Procedures o OCIO-POL-18: IT Privacy o OCIO-POL-36: Rules of the Road o OCIO-POL-35: IT Policy on Security Risk Acceptance
Program Management (PM) Procedures
Risk Assessment (RA) Procedures o Vulnerability/Compliance Scanning and Analysis Standard Operating Procedures o OCIO-POL-35: IT Policy on Security Risk Acceptance
Security Assessment and Authorization (CA) Procedures o OCIO-POL-51: OCIO Agreements with US Federal Agencies and International
Organizations
USPTO IT Security Handbook March 2019 o USPTO Continuous Monitoring Procedures
System and Services Acquisition (SA) Procedures o OCIO-1004-10: IT Desktop Hardware Acquisition Management o OCIO-POL-29: Vendor Performance Information Policy o OCIO-POL-24: System Development Life Cycle (SDLC) o OCIO-POL-38: Server and Storage Provisioning
System and Information Integrity (SI) Procedures o OCIO-POL-16: Anti-Virus
System and Communications Protection (SC) Procedures o OCIO-POL-14: Certificate Policy for the USPTO o OCIO-POL-23: Personally Identifiable Data Removal o OCIO-POL-18: IT Privacy
For information about these USPTO Policies, visit the USPTO intranet site:
https://usptogov.sharepoint.com/sites/a142efd3/Documents/Forms/All%20Approved%20Documents
.aspx
System Owners are required to comply with this Handbook within 120 days of its effective date.
Compliance with this Handbook beyond the specified timeframe shall be managed through the Plan of Action and Milestones (POA&Ms).
The USPTO Senior Information Security Officer (SISO) will review the USPTO IT Security
Handbook at least annually or more often if needed and incorporate updates as necessary including new federal requirements. The revised USPTO IT Security Handbook shall be reviewed and approved by the concurrence of the USPTO CIO. Subsequent to this, the USPTO Cybersecurity
Division will incorporate the changes into this Handbook and the revision shall be reviewed by, and meet the concurrence of USPTO stakeholders before presentation to the CIO for signature.
2.2 Risk Acceptance
The USPTO Authorizing Officials (AOs) shall approve the tailoring of security control baselines.
For controls and parameters that require risk acceptance memos, requests shall be submitted to the
USPTO CIO, through the SISO. In addition, the USPTO CIO has the discretion to elevate the risk acceptance approval process to the level of the Office of the Department of Commerce CIO when actions or controls are identified that affect department-wide security. Risk acceptance memo requests shall justify and describe the controls that cannot be fully implemented and the compensating controls in-place. Corrective action items shall be specified in the risk acceptance requests, if appropriate. System Owners (SO) shall use the POA&Ms to track and manage progress towards compliance.
Upon request from the USPTO CIO, each SO shall verify the Department-level risk acceptance requirements and submit copies of risk acceptance memos for performing Department-wide trend analysis and Enterprise risk management.
The risk acceptance process shall be implemented as follows:
Risk Acceptance requests shall be submitted to the CIO, via the SISO;
Risk Acceptance memo shall be addressed from the System Owner;
https://usptogov.sharepoint.com/sites/a142efd3/Documents/Forms/All%20Approved%20Documents.aspx
USPTO IT Security Handbook March 2019
Risk acceptance requests shall justify and describe the controls that cannot be fully implemented and the compensating controls in-place;
Corrective action items shall be specified in the risk acceptance memo requests, if appropriate;
Risk acceptance requests should include a POA&M describing the plan to come into conformance with policy or the risk accepted control;
The USPTO CIO has the discretion to elevate the risk acceptance approval to the Department
CIO in the event the risk acceptance affects Departmental security; and
The CIO has 30 days to respond to a risk acceptance memo request. This response shall include:
o Approval, and conditions for approval, including expiration date o Denial, or basis for denial, if that is the decision o Additional information on the risk acceptance request as identified by the CIO.
Please refer to the USPTO IT Policy on Security Risk Acceptance, OCIO-POL-35 for more details.
2.3 Enforcement
Failure to comply with any provisions of the Handbook may result in administrative or adverse action in accordance with the Office of Human Resources (OHR) policies. Perceived threats to system integrity, confidentiality, or availability shall result in suspension of system access as necessary to contain the perceived threat. An offense that is in violation of local, state, or Federal laws may result in suspension of system access and shall be reported to the appropriate law enforcement authorities.
USPTO IT security policies shall be enforced through the following:
Oversight
Inspection
Audit
Each USPTO Contracting Officer’s Technical Representative (COTR) has contract oversight security responsibility and shall ensure that contractor-related security requirements are followed throughout the contract life-cycle.
USPTO IT Security Handbook March 2019
3 IT Security Roles and Responsibilities
The responsibility to protect USPTO information and technological resources extends to all non-public users and requires collaboration across various offices to coordinate activities associated with the USPTO security posture, technological environment, and overall risk management.
3.1 Personnel
All USPTO employees and contractor employees are responsible for carrying out the provisions of this Handbook.
3.2 Roles and Responsibilities
The key roles and responsibilities for carrying out the provisions of this Handbook are outlined below.
3.2.1 USPTO Chief Information Officer (CIO)
Within the USPTO, the role of Authorizing Official (AO) is generally assigned to the CIO. The CIO manages USPTO’s Information Technology (IT) infrastructure and its risk management program.
The CIO has the following IT Security responsibilities:
Develop, maintain, and oversee the USPTO IT Security Program;
Appoint, in writing, a Senior Information Security Officer (SISO) to implement the IT Security
Program within USPTO;
Ensure, in coordination with senior USPTO officials, the implementation of the requirements of a
USPTO-wide IT Security Program (as specified in § 3544, paragraph (b), of the FISMA);
Ensure the USPTO annually performs an independent evaluation of the IT Security Program and its practices (as specified in § 3545 of the FISMA);
Provide overall management of and leadership and direction to the IT Security Program;
Assist and advise senior agency officials regarding their responsibilities for security, including
System Security Plans (SSPs);
Report regularly on the status of the IT Security Program to the Director and advise the Director on Security matters;
Consult with and brief USPTO Executive Management regarding all critical information system security issues;
In coordination with other agency officials, report annually to the agency head on the effectiveness of the agency information security program, including progress of remedial actions;
Assess and advise the USPTO Director of weaknesses In the IT Security Program, as appropriate, for annual accountability reporting;
Ensure managers for all IT resources are identified and that security authorization for those resources are accomplished within the planned timeframe;
Determine the acceptable level of residual risk for an information subsystems and if an information subsystems will adequately protect sensitive USPTO information;
Approve SSPs;
Review the Security Authorization Package (SAP) and sign the Authorization Decision
Document. The following authorization decisions can be made by the AO:
USPTO IT Security Handbook March 2019 o Authorization To Operate (ATO) – Full authorization will be granted when all of the following apply:
The authorization package is complete.
No corrective actions are required or may require minor corrective actions.
(Note: There may be findings during the authorization effort that are turned into a
POA&M, but do not prevent an ATO).
Residual risks are acceptable to the AO.
o Authorization To Operate (ATO) with Conditions – Special type of authorization allowing an information system to operate in an operational environment by assessing a limited set of controls to include volatile controls as defined by DOC CITR-19. This type of authorization will be given only when system need to be put in production to support continuity of organizational mission and business requirements. The system will be authorized to operate for a specified time period in accordance with the terms and conditions established by the authorizing officials. This limited authorization will be granted when all of the following apply:
Vulnerability scans have been performed on the system and there are no major high risk vulnerabilities discovered. If necessary corrective actions (POA&Ms) are identified.
Volatile controls, as determined by DOC, have been assessed.
Residual risks are accepted for a limited time identified in the ATO letter that also includes all terms and conditions that need to be completed associated with the given ATO termination date.
o Interim Authority to Test (IATT) – The USPTO AO can exercise its authority to grant this special type of authorization decision allowing an information system to operate in an operational environment for the express purpose of testing the system with actual operational (i.e., live) data for a specified time period. An interim authorization to test is granted by an authorizing official only when the operational environment or live data is required to complete specific test objectives.
o Denial of Authorization to Operate (DATO) – If the authorizing official, after reviewing the authorization package and any additional inputs provided by the risk executive
(function), deems that the risk to organizational operations and assets, individuals, other organizations, and the Nation is unacceptable and immediate steps cannot be taken to reduce the risk to an acceptable level, a denial of authorization to operate is issued for the information system or for the common controls inherited by organizational information systems. The system may not be placed into operation until at least an IATT is granted.
Monitor and report IT security program compliance with Federal laws and USPTO IT security policies;
Serve as the IT security liaison to external organizations;
Ensure sufficient resources are available to implement the USPTO IT security program in coordination with the Director and the Heads of USPTO Business Units;
Ensure USPTO IT security planning and execution is practiced throughout the life cycle of each
USPTO system;
Ensure a PTO Computer Incident Response Team (CIRT) is staffed, trained, and maintained in a state of readiness;
Ensure that persons with IT security responsibilities have appropriate role-based training;
USPTO IT Security Handbook March 2019
Assist oversight groups in compliance reviews and other reporting requirements;
Provide feedback to oversight groups on the status of the program in USPTO and suggest improvements or areas of concern in the USPTO program;
Establish an overall strategy for the IT Security Awareness and Training Program;
Ensure the program is sufficiently staffed and funded to achieve its approved objectives in a timely manner;
Ensure effective tracking and reporting mechanisms are in place to accurately determine course completion, and to evaluate the awareness and training program;
Establish plans, procedures and schedules to correct any IT security awareness and training material weaknesses identified during formal inspections and evaluations; and
Ensure that USPTO IT security policies are developed, approved and maintained in a timely manner.
3.2.2 Co-Authorizing Official (Co-AO)
The role of USPTO Co-AO could be assigned to the chiefs/directors of following USPTO Offices: Patent
Office, Chief Administrative Officer, Chief Financial Officer, Equal Employment Opportunity and
Diversity, etc. The CO-AOs roles are documented in the respective system SSP. The Co-AO approves system security requirements including SSPs, ATO letters, IATT letter, etc.
Co-AO is responsible for ensuring continued ATOs for systems under their responsibility by reaffirming acceptable Continuous Monitoring results and accepting risks at least annually for systems that fall under their responsibility.
AO/CO-AO role has inherent U.S. Government authority and is assigned to government personnel only.
3.2.3 Authorizing Official Designated Representative (AODR)
The authorizing official designated representative is an organizational official that acts on behalf of an authorizing official to coordinate and conduct the required day-to-day activities associated with the security authorization process. Authorizing official designated representatives can be empowered by authorizing officials to make certain decisions with regard to the planning and resourcing of the security authorization process, approval of the security plan, approval and monitoring the implementation of plans of action and milestones, and the assessment and/or determination of risk. The designated representative may also be called upon to prepare the final authorization package, obtain the authorizing official’s signature on the authorization decision document, and transmit the authorization package to appropriate organizational officials. The only activity that cannot be delegated to the designated representative by the authorizing official is the authorization decision and signing of the associated authorization decision document (i.e., the acceptance of risk to organizational operations and assets, individuals, other organizations, and the Nation).
3.2.4 USPTO Business Area Heads
USPTO business areas heads have assigned Authorizing Officials (AO) who co-signs with the CIO
AO for those business systems under their area of responsibility. These could include the USPTO
Office of Patents and Trademarks, Office of Chief Administrative Officer; Office of Chief Financial
Officer; Office of the Equal Employment Opportunity and Diversity, etc.
USPTO IT Security Handbook March 2019
3.2.5 USPTO Senior Information Security Officer (SISO)
At the USPTO, the SISO has assessing responsibilities. The SISO is the agency official responsible for: (i) carrying out the security executive role under FISMA; (ii) possessing professional qualifications, including training and experience, required to administer the information security program functions; (iii) having information security duties as that official’s primary duty; and, (iv) heading an office with the mission and resources to assist in ensuring agency compliance with
FISMA.
The SISO is responsible for determining the level of effort and resources required for information subsystems security authorization; reviewing the information subsystems security categorization;
and, performing analysis and accepting the information subsystems SSP. The SISO (or supporting staff member) may also serve as the AO’s designated representative responsible for providing authorization recommendations to the AO. The SISO serves as the CIO’s primary liaison to the
Agency’s AOs, SOs, and Information System Security Officers (ISSO). Additionally, the SISO has the following responsibilities for IT Security:
Identify resource requirements, including funds, personnel and contractors, needed to manage the
USPTO IT Security Program;
Develop and maintain USPTO IT security policy, procedures, standards, and guidance consistent with Federal requirements and provide protection for the electronic information and information systems that support the operations and assets of the agency including those provided or managed by another agency or contractor;
Develop, document, and implement subordinate plans for providing adequate security for networks, facilities, and systems or groups of information systems;
Coordinate matters of physical security for IT resources with the USPTO Security Office;
Ensure that all systems have current and effective IT security plans that accurately reflect system status;
Ensure that appropriate security features are implemented in new systems and that they at least meet the minimum-security requirements defined in this Handbook;
Ensure the security of an information system throughout its life cycle and that IT security is integrated in the USPTO strategic IT planning and enterprise architecture (EA) efforts;
Ensure that periodic assessments are performed of the risk and magnitude of harm that could result from unauthorized access, use, disclosure, or disruption of information and information systems that support the operations and assets of the Agency;
Ensure that an AO, SO, and ISSO have been appointed for each information subsystems within the USPTO and maintain up-to-date records of these assignments;
Ensure that SSPs are properly prepared for all IT systems owned and operated by the USPTO;
Coordinate the development, review, and acceptance of SSPs with the SO, ISSO, and the AO;
Review SSPs, as submitted, making appropriate written comments that will be sent to the originator for corrective action;
Ensure ISSO review and update all SSPs, at least annually, and incorporate changes or completed milestone actions;
Ensure that periodic Security Test and Assessment (ST&A) plans are developed, documented, and implemented, no less than annually, to assess the effectiveness of information security policies, procedures, and practices;
Coordinate the identification, implementation and assessment of common security controls;
USPTO IT Security Handbook March 2019
Establish a process to track remedial actions to mitigate risks in accordance with Plans of Action and Milestones (POA&M) to address any deficiencies in the information security policies, procedures and practices of the Agency;
Review proposed system changes and act as approval authority for changes that impact system security;
Lead development, implementation and enforcement of USPTO IT Security policies and procedures;
Manage and oversee internal and external reviews and inspections to ensure compliance with established policies and procedures;
Serve as the principal Point of Contact (POC) on IT security activities within USPTO;
Ensure appropriate IT Security Awareness Training is provided;
Advise the SO of security features and procedures for systems;
Ensure the OCIO Configuration Management (CM) process and System Development Life Cycle
(SDLC) is used to maintain IT Security documentation;
Identify and recommend security and privacy controls improvements to management;
Ensure appropriate incident response capabilities;
Interface and coordinate with the Office of the Inspector General (OIG) on IT Security reviews and issues;
Assign each USPTO system a unique identification number that will identify the Agency and the specific system;
Ensure that IT systems are categorized, in conjunction with other staff;
Maintain a tracking system for implementation of the required controls and authorization status for all USPTO systems;
Ensure that all systems have effective, quality security documentation in place, including:
o Security assessment reports (SAR), o Current and effective IT security plans that accurately reflect system status, o continuous monitoring, o Current and tested contingency plans (CPs), and o Current security authorization (ATO).
Maintain the major application and general support system inventory;
Provide information to systems administrators and others concerning risks and potential risks to systems;
Notify SOs and ISSO of user infractions identified during routine compliance assessments and any required actions;
Advise the CIO and business area heads of technological IT security advances that can be used on an agency-wide scale;
Report to the CIO and external entities such as OMB, Government Accountability Office (GAO), and Congress, on IT Security Program status;
Ensure that all users and managers have an effective way to provide feedback on the quality and quantity of IT Security awareness and training material and its presentation; and
Ensure that IT Security awareness and training material is reviewed annually and updated when necessary.
3.2.6 USPTO Risk Executive Function
The risk executive (function) is an individual or group that helps to ensure that: (i) risk-related considerations for individual information systems, to include authorization decisions, are viewed from an
USPTO IT Security Handbook March 2019 organization-wide perspective with regard to the overall strategic goals and objectives of the USPTO in carrying out its core missions and business functions; and (ii) managing information system-related security risks is consistent across the USPTO, reflects organizational risk tolerance, and is considered along with other types of risks in order to ensure mission/business success. The risk executive (function) coordinates with the senior leadership of USPTO to:
Provide a comprehensive, organization-wide, holistic approach for addressing risk—an approach that provides a greater understanding of the integrated operations of the organization;
Develop a risk management strategy for USPTO providing a strategic view of information security-related risks with regard to the organization as a whole;
Facilitate the sharing of risk-related information among authorizing officials and other senior leaders within the USPTO;
Provide oversight for all risk management-related activities across USPTO (e.g., security categorizations) to help ensure consistent and effective risk acceptance decisions;
Ensure that authorization decisions consider all factors necessary for mission and business success;
Provide an USPTO-wide forum to consider all sources of risk (including aggregated risk) to organizational operations and assets, individuals, other organizations, and the Nation;
Promote cooperation and collaboration among authorizing officials to include authorization actions requiring shared responsibility;
Ensure that the shared responsibility for supporting organizational mission/business functions using external providers of information and services receives the needed visibility and is elevated to the appropriate decision-making authorities; and
Identify the USPTO risk posture based on the aggregated risk to information from the operation and use of the information systems for which USPTO is responsible.
The risk executive function at the USPTO consists of USPTO Cybersecurity management personnel.
3.2.7 USPTO Security Authorization and Compliance Manager
The Security Authorization and Compliance Manager is responsible for managing the security authorization process for all information subsystems. The security authorization and compliance manager plays an essential role in security and is, ideally, intimately aware of functional system requirements. The security authorization and compliance manager builds the business case for the acquisition of appropriate security solutions that help ensure mission accomplishment in the face of real-world threats. Additionally, the security authorization and compliance manager has the following IT Security responsibilities:
Possess the knowledge and skills to appropriately incorporate IT security throughout a system’s
SDLC process to protect the business operations and information the system supports;
Work with the SO, ISSO and SISO to meet shared IT security responsibilities; and
Ensure system development and operations staff is knowledgeable of the security authorization requirements and processes for their systems and are provided related training.
3.2.8 USPTO System Owner
The System Owner (SO) has responsibility for the Master System (grouping of multiple subsystems into FISMA reportable master system), while the role of managing individual systems within the
USPTO IT Security Handbook March 2019 master system is typically assigned to the ISSO. The SO has the following responsibilities for IT
Security:
Determine and implement an appropriate level of security commensurate with the system sensitivity level;
Prepare and conduct the preliminary risk assessment (PRA) and retirement risk assessment for all assigned information subsystems;
Perform risk assessments (RA) at least annually or as part of continuous monitoring activities, to re-evaluate sensitivity of the system, risks, and mitigation strategies. Take appropriate steps to reduce or eliminate vulnerabilities after receiving the results of continuous monitoring activities and update RAR accordingly;
Develop and maintain the SSP in coordination with the System Administrator, ISSO, SISO and end users;
Update the SSP during all continuous monitoring activities, including authorization, annual assessments and significant changes to the systems. During significant changes, where deemed necessary, the system should be re-authorized;
Develop, maintain, and review the SAP including SSPs and CPs for all systems under their responsibility and submit the SAP to the AO or their designated representative;
Ensure that the provisions of this Handbook are implemented for their information subsystems;
Oversee the ST&A Plan when the system undergoes a major change and perform continuous monitoring of the information subsystems;
Establish system-level POA&M and implement and monitor corrective actions to timely completion;
Ensure the information subsystems are deployed and operating according to the agreed-upon security requirements;
Decide who has access to the system and grant individuals the fewest privileges necessary for job performance, re-evaluate the access privileges at least annually, and revoke access in accordance with agency guidelines upon personnel transfer, termination, or change in duties;
Establish appropriate Rules of the Road for all systems that apply to all personnel managing, administering, or having access to the IT system;
Ensure systems’ personnel are properly designated, monitored, and trained, including appointment in writing of an individual to serve as the Technical Lead (TL), if appropriate;
Inform appropriate agency officials of the need to conduct a security authorization effort and ensure that appropriate resources are available for the effort;
Assist in the identification, implementation, and assessment of common security controls specific to their assigned information subsystems;
Conduct Continuous Monitoring activities including configuration management, control testing, POA&M updates, and reporting status for their assigned information subsystems;
Ensure knowledge and skills to incorporate IT security throughout the system’s SDLC process to protect the business operations and information the system supports;
Work with the CIO and SISO to meet shared IT security responsibilities; and
Coordinate with the Cybersecurity division Facilitation Point of Contact (FPOC) in execution of duties and responsibilities in association with this role to meet FISMA compliance requirements.
USPTO addresses the security requirements for System Owner (SO) through assignment of
Federal employees from the business unit coupled with full time contractor Security Subject
Matter Expert support to meet FISMA compliance requirements. This approach ensures business representation as well as expert security support in meeting FISMA requirements.
USPTO IT Security Handbook March 2019
3.2.9 Information Owner/Steward
The information owner/steward is an organizational official with statutory, management, or operational authority for specified information and the responsibility for establishing the policies and procedures governing its generation, collection, processing, dissemination, and disposal.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .