Attachment 38b - IT_Security_Handbook.pdf

PDF 2 MB Posted

Attached to
Patent Data and Document Management (PDDM) Federal contract opportunity
Solicitation number
1333BJ20R00151004
Issued by
Department of Commerce US Patent and Trademark Office

About this file

This is a Request for Proposals from the United States Patent and Trademark Office seeking contractor support to manage the patent application processing lifecycle. Services required include managing the initial filing of patent applications, processing throughout examination, and final application disposition. A thorough understanding of requirements can only be gained by carefully reviewing the RFP, Statement of Work, references, and attachments provided in Section J, including an RFP Section J glossary defining terms. The attachment version dates are noted in the Section J crosswalk.

View the file

Other files for this federal contract opportunity

Other files attached to Patent Data and Document Management (PDDM), newest first.
File Type Posted
1333BJ20R00151004_Amendment 0003_track changes.pdf PDF
Attachment 39 - Transition Plan Framework_updated.docx DOCX document
Attachment 13a - FEPIB 2020-06.doc DOC document
Attachment 26 - DCB 2020-14.docx DOCX document
Attachment 40-Pricing Template_updated.xlsx XLSX spreadsheet
Attachment 08 - Glossary of Terms_updated.docx DOCX document
Attachment 26 - DCB 2020-17.docx DOCX document
Attachment 26 - DCB 2020-16.docx DOCX document
Attachment 13a - FEPIB 2020-04.doc DOC document
PDDM RFP Questions and Responses.pdf PDF
Amendment 0001_1333BJ20R00151004.pdf PDF
Attachment 25b - Consolidated Listing of Official Gazette Notices_2018-01-25.pdf PDF
Attachment 05c - QA of EFS WEb Submissions Error Categories and Historical Volumes.xlsx XLSX spreadsheet
Attachment 16 - PG Pub Processes.pdf PDF
Attachment 39 - Transition Plan Framework.docx DOCX document
Attachment 13a - FEPIB 2020-02.doc DOC document
Attachment 25a - eOG_manual_2020.docx DOCX document
Attachment 14 - Quality Assurance of EFS-Web Submissions20190917.docx DOCX document
Attachment 10b.zip ZIP file
Attachment 13 - Front End Processing (FEP) Manual for Indexing and Scanning.docx DOCX document
Attachment 33 - PALM Basics.pptx PPTX presentation
Attachment 05a - Historical Data_Page Counts and Volumes.docx DOCX document
Attachment 41 - Past Performance Questionnaire.docx DOCX document
Attachment 31a - DCB 2020-None.docx DOCX document
Attachment 26.zip ZIP file
Attachment 17b - (jpg) u-bibdat1.jpg JPG image
Attachment 18 - DCB 2020-04.docx DOCX document
Attachment 38a - Cloud Services Usage Policy.pdf PDF
Attachment 38 - IT Security Requirements - 2020-04.docx DOCX document
Attachment 13a - FEPIB 2020-03.doc DOC document
Attachment 08 - Glossary of Terms.docx DOCX document
Attachment 17d - (jpg) us-request-v15-2013-01-25.jpg JPG image
Attachment 07 - IFW Document Codes - Document Code Dictionary 2020-04-15.pdf PDF
Attachment 03a - USPTO Computer Specs.xlsx XLSX spreadsheet
Attachment 43 - Surveillance Plan.docx DOCX document
Request for Proposals No. 1333BJ20R00151004.pdf PDF
Attachment 18 - DCB 2020-12.docx DOCX document
Attachment 05b- Weekly Serialized Filings.xls XLS spreadsheet
Attachment 32 - CofC Patent Term Adjustment SOP_Nov 13 2017.pptx PPTX presentation
Attachment 12 - Front End Processes.pdf PDF
Attachment 37 - PreExam Manual with Supplemental Instructions 9-20-2018.pdf PDF
Attachment 30 - Certificate of Correction Process.pdf PDF
Attachment 27 - Grant - Red Book Instructions.docx DOCX document
Attachment 10c - Link to USPTO Website.docx DOCX document
Attachment 17e - (txt) -ExportTOC1.txt TXT text file
Attachment 21 - Post Allowance Processes.pdf PDF
Attachment 35a - PE2E-eDRS-Manual.pdf PDF
Attachment 28 - Grant - Yellow Book Instructions.docx DOCX document
Attachment 23 - DataEntryManual-NON-UTILITY-2020.doc DOC document
Attachment 17c - (jpg) u-suppub8-2012-12-04.jpg JPG image
Show all 50

Patent Data and Document Management (PDDM) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

For Official Use Only

UNITED STATES

PATENT AND TRADEMARK OFFICE (USPTO)

IT SECURITY HANDBOOK

March 26, 2019

Version 5.5

USPTO IT Security Handbook March 2019 ii

DOCUMENT HISTORY

Change

Number

Date of

Change

Sections

Changed Revision Summary

Person

Approving

Change v0.5 04/26/07 All Initial Submission Quentin

Robinson v0.6 07/18/07 All Revised all sections based on renaming remaining LOE as per USPTO TOM

Quentin

Robinson v0.7 8/23/07 All New org structure incorporated more minor edits.

Quentin

Robinson v0.8 10/3/07 All General editing Quentin

Robinson v2.5 12/20/07 All General Editing Quentin

Robinson v2.8.1 6/16/08 Signature Changed Approving Authority Katherine Queen v3.0 12/13/10 All

- Replaced/ removed outdated and superseded references.

- Added references to additional

Federal, DOC, and USPTO policies and procedures.

- Removed processes and procedures contained in, and repetitive of, lower tier documents.

- Revised and added to security controls that were not completely or correctly addressed.

- Reformatted to comply with current

CIO Policy Documents template.

- Updated Acronym and Terms lists.

- Corrected spelling and grammar errors throughout.

Missing Link

Security v3.0.1 4/7/11 All

Revised all sections to make it consistent with the Department of

Commerce IT Security Program Policy

(DOC ITSPP) and NIST 800- 53 Rev

3.

A3IS

v3.1 12/19/11 All

- Replaced/ removed outdated and superseded references.

- Added references to additional

Federal, DOC, and USPTO policies and procedures.

- Removed processes and procedures contained in, and repetitive of, lower tier documents.

- Revised and added to security

Missing Link

Security

USPTO IT Security Handbook March 2019 iii

Change

Number

Date of

Change

Sections

Changed Revision Summary

Person

Approving

Change controls that were not completely or correctly addressed.

- Updated Acronym and Terms lists.

- Corrected spelling and grammar errors throughout.

v3.2 12/23/11 All

- Changes implemented per comments received.

Missing Link

Security v3.3 1/13/12 All

- Fixed formatting inconsistencies.

- Updated per comments received during review cycle

Missing Link

Security v3.4 2/3/12 All

- Removed all IT Security Handbook

Policy references

- Updated CM-7 requirements

Missing Link

Security v3.5 2/29/2012 All - Update RA-5 requirements Missing Link

Security v3.6 5/09/2012 All

- Updated per comments received during final review cycle

Missing Link

Security v3.7 8/21/2012 All

- Updated AC-2 requirements

- Changed SAISO to SISO

- Updated roles and responsibilities

Missing Link

Security v3.8 2/08/2013 Role and

Responsibilities

- Added FPOC Role

- Removed SLIC reference

A3IS

v4.0 10/2013 All - Revised to address 800-53 Rev.4 A3IS

V4.1 11/2014 All - Annual review and update A3IS

V4.2 12/30/2014 Section 4.8

- Incident Response Reporting requirements were updated based on new DOC guidance

A3IS

V 4.3 12/16/2015 Multiple sections

- Annual review and updates – removed reference to management, operational and technical controls throughout the document; updated document with the most recent NIST guidance, USPTO and DOC policy and procedures and updated links;

updated section 2.1; added section

3.2.9: Information Owner/Steward;

added privacy controls under

Appendix A; updated Appendix C and D; updated following security control requirements: all dash 1 security controls, AC-2.11, AC-4, AC-6, AC-7, AC-8, AC-12, AC-14, AC-18.1, AC-19, AC-21, AT-3, A3IS

USPTO IT Security Handbook March 2019 iv

Change

Number

Date of

Change

Sections

Changed Revision Summary

Person

Approving

Change

AU-2, AU-5.2, AU-6, AU-9.4, AU-

11, CA-5, CM-2.7, CM-3, CM-7.2,

CM-7.4, CM-7.5, CP-4, IA-2.11, IA-

5, IA-5.1, IR-3, MP-5, PE-15, PE-17,

PL-2.3, PS-8, RA-5, SA-3, SA-4,

SC-5, SC-7.3, SC-7.4, SC-13, SC-23

SI-2, SI-7, SI-7.1, SI-16, PM-5, PM-

6, AR-7.

V 4.4 05/09/2016 Section 4.7

- IA-5, IA-5(1) security controls to address public facing systems authenticator requirements

A3IS

V 4.5 7/11/2016 Multiple sections

- AC-8; reference to DOC ITSSP A3IS

V 4.6 8/31/2016 Multiple sections

- IA-5, IA-5(1) with further clarification on public facing systems

A3IS

V. 4.7 9/19/2016 Multiple

Sections

- Section 3.2.16, IR-6 (incident reporting to address new DOC

Incident Response Policy);

A3IS

v. 4.8 12/31/2016 Annual review and update

Section 4.1.4 RA-5 (scanning requirements)

A3IS

V 4.9 02/10/2017 Multiple

Sections

-Added DOC CITR-024, FedRAMP

Applicability reference to section 2.1

-Added FedRAMP applicable security controls to Section IV along with

FedRAMP requirements

-Updated all dash 1 security controls in section 4 to identify that policy and procedures updates are done as needed and annually

-Added banner note to AC-8

-Added FedRAMP requirements relevant to AC-20

-AU-8- updated to one second requirement for DOC consistency

-IR-6 updated to address OIG requirement to report incidents as necessary to OIG and law enforcement

-Added NIST 800 52 rev 1 TLS requirements to SC-23

V 5.0 4/14/2017 Section 4.1.4 Updated RA-5 scanning requirement to address OIG audit finding

A3IS

V 5.1 6/12/2017 Section 4.1,

4.5 -Updated CM-7.2, 7.4 and CM-11 with unapproved software removal

USPTO IT Security Handbook March 2019 v

Change

Number

Date of

Change

Sections

Changed Revision Summary

Person

Approving

Change information.

-Updated AC-6 and enhancements 1, 2 and 9 with new requirements from

DOC CITR-026.

-Updated AC-2 to address requirement for review of privileged accounts twice a year.

V 5.2 8/22/2017 Section 4.13

Updated PS-4, PS-7 control to address

KPMG audit and clarify employee or contractor termination and account deactivation requirements.

A3IS

V 5.3 03/26/2018 Multiple

Sections

Updated following:

-All dash 1 security controls to distinguish between review and update requirement.

-AC-2, to address service and non human accounts requirement, including review of privileged account twice a year per DOC CITR-026.

-AC-6, updated to address CITR-026 requirements.

-AC-12, added requirement on termination of remote session and privileged accounts session.

-AU-3, addressed audit requirements for data extracts from database holding sensitive information.

- CA-2, added section on CSP

FedRAMP requirements.

-CP-4, added section on CIO approval for performing tabletop CP exercises for the systems with the low FIPS 199 availability categorization and defined functional and tabletop exercises requirements.

-IA-5, added PIV cards usage for initial

PTONet access to Note section.

-IR-6, updated section on external communication associated with incident.

-PE-17, updated ERA portal to Team

Portal.

-PS-4, PS-5 to address A-123 Audit.

-SA-9, added section on CSP

USPTO IT Security Handbook March 2019 vi

Change

Number

Date of

Change

Sections

Changed Revision Summary

Person

Approving

Change

FedRAMP requirements references.

-SC-28, added section on allowed mechanisms to achieve confidentiality and integrity of data at rest.

-SI-5, added DOC CIRT, OMB and vendors as external organizations that

USPTO receives security alerts and advisories.

-PM-4, added references to POA&M minimum standards.

V 5.4 6/2018 Section 2.1 Updated Administrative Access Right policy reference #

A3IS

V 5.5 3/26/2019

Sections: 2.1, 3.2.18, 4.1, 4.3, 4.4, 4.5, 4.14, 5.1, appendix

B, C, D

Annual review and updates:

- section 2.1, policy and procedures updates;

-section 3.2.18- SAOP/CPO role;

-section 4.1, AC-17 control;

-section 4.3, AU-2 control;

-section 4.4, CA-3.3, CA-8, CA-8.1 controls;

-section 4.5, CA-3 control (CCBP link);

-section 4.14, RA-5.6 control;

-section 4.16, SC-23 updated encryption requirements;

-section 5.1, minor changes to privacy controls: AP-1, AR-1;

-Appendix B, added SAOP/CPO;

-Updated references in appendix C and

D

USPTO IT Security Handbook March 2019 vii

Table of Contents

1 INTRODUCTION

1.1 BACKGROUND

1.2 PURPOSE

1.3 SCOPE, MANAGEMENT COMMITMENT AND COORDINATION, AND APPLICABILITY

1.4 UPDATE AND REVIEW

1.5 AUTHORITY

1.6 COMPLIANCE

1.7 USPTO IT SECURITY PROGRAM DOCUMENTATION

2 IT SECURITY HANDBOOK

2.1 EFFECTIVE DATE

2.2 RISK ACCEPTANCE

2.3 ENFORCEMENT

3 IT SECURITY ROLES AND RESPONSIBILITIES

3.1 PERSONNEL

3.2 ROLES AND RESPONSIBILITIES

3.2.1 USPTO Chief Information Officer (CIO)

3.2.2 Co-Authorizing Official (Co-AO)

3.2.3 Authorizing Official Designated Representative (AODR)

3.2.4 USPTO Business Area Heads

3.2.5 USPTO Senior Information Security Officer (SISO)

3.2.6 USPTO Risk Executive Function

3.2.7 USPTO Security Authorization and Compliance Manager

3.2.8 USPTO System Owner

3.2.9 Information Owner/Steward

3.2.10 USPTO Common Control Provider

3.2.11 USPTO Information System Security Manager (ISSM)

3.2.12 USPTO Information System Security Officer (ISSO)

3.2.13 USPTO Facilitation Point of Contact (FPOC)

3.2.14 USPTO System and Network Administrators/Technical Lead (TL)

3.2.15 USPTO Security Control Assessor

3.2.16 USPTO Computer Incident Response Team

3.2.17 Key Contingency Roles

3.2.18 USPTO Chief Privacy Officer/Senior Agency Official for Privacy

3.3 ADDITIONAL ROLES

3.3.1 Contracting Officer (CO)

3.3.2 Contracting Officer’s Technical Representative (COTR)

3.4 USPTO OFFICES

3.4.1 Office of the Chief Information Officer (OCIO)

3.4.2 Office of Organizational Policy and Governance (OPG)

3.4.3 Office of Infrastructure Engineering and Operations (IEO)

3.4.4 USPTO Office of Security

3.4.5 Office of Inspector General (OIG)

4 IT SECURITY CONTROLS

4.1 ACCESS CONTROL (AC)

4.2 AWARENESS AND TRAINING (AT)

4.3 AUDIT AND ACCOUNTABILITY (AU)

4.4 SECURITY ASSESSMENT AND AUTHORIZATION (CA)

USPTO IT Security Handbook March 2019 viii

4.5 CONFIGURATION MANAGEMENT (CM)

4.6 CONTINGENCY PLANNING (CP)

4.7 IDENTIFICATION AND AUTHENTICATION (IA)

4.8 INCIDENT RESPONSE (IR)

4.9 MAINTENANCE (MA)

4.10 MEDIA PROTECTION (MP)

4.11 PHYSICAL AND ENVIRONMENTAL PROTECTION (PE)

4.12 PLANNING (PL)

4.13 PERSONNEL SECURITY (PS)

4.14 RISK ASSESSMENT (RA)

4.15 SYSTEM AND SERVICES ACQUISITION (SA)

4.16 SYSTEM AND COMMUNICATIONS PROTECTION (SC)

4.17 SYSTEM AND INFORMATION INTEGRITY (SI)

4.18 PROGRAM MANAGEMENT (PM)

5 PRIVACY CONTROLS

5.1 AUTHORITY AND PURPOSE (AP)

5.2 ACCOUNTABILITY, AUDIT, AND RISK MANAGEMENT (AR)

5.3 DATA QUALITY AND INTEGRITY (DI)

5.4 DATA MINIMIZATION AND RETENTION (DM)

5.5 INDIVIDUAL PARTICIPATION AND REDRESS (IP)

5.6 SECURITY (SE)

5.7 TRANSPARENCY (TR)

5.8 USE LIMITATION (UL) ................................................................................................................................ A-1 APPENDIX A. ACRONYMS AND ABBREVIATIONS ........................................................................ A-2 APPENDIX B. GLOSSARY ....................................................................................................................... B-1 APPENDIX C. REFERENCES ................................................................................................................... C-1 APPENDIX D. ................................................................................................................................................... D-1 IT SECURITY LAWS AND FEDERAL REGULATIONS ............................................................................ D-1

USPTO IT Security Handbook March 2019

1 Introduction

The Federal Information Security Modernization Act (FISMA) provides a comprehensive framework for ensuring the effectiveness of information security controls over information resources that support

Federal operations and assets, and defines “adequate security” as security commensurate with the risk and magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of information. This includes ensuring that systems and applications used by the agency operate effectively and provide appropriate confidentiality, integrity, and availability with cost effective security and privacy controls. This document sets forth the United States Patent and Trademark Office (USPTO) IT Security

Handbook.

1.1 Background

The National Institute of Standards and Technology (NIST) Federal Information Processing Standards

(FIPS) Publication 200, Minimum Security Requirements for Federal Information and Information

Systems, directs that all Federal Government agencies ensure that adequate security controls be implemented for their information subsystems. The guidelines provided in FIPS 200 are applicable to all federal information systems other than those systems designated as national security systems as defined in 44 U.S.C., Chapter 35, Coordination of Federal Information Policy § 3542. This handbook describes how the United States Patent and Trademark Office (USPTO) will comply with FISMA and other related directives.

The IT security policies captured in this Handbook were developed to meet the minimum legally and federally mandated requirements for information security and are based on the Federal Government standards and procedures issued by the Office of Management and Budget (OMB), NIST, and the

General Services Administration (GSA). Appendix C of this Handbook provides a list of references used in developing this handbook.

1.2 Purpose

The purpose of this USPTO IT Security Handbook is to document security policies and procedures, in accordance with Federal government mandated requirements. This Handbook addresses requirements and guidance set forth by the Federal Information Security Modernization Act (FISMA). It also encompasses minimum security controls as required by the Federal Information Processing Standard

(FIPS) 200, Minimum Security Requirements for Federal Information and Information Systems; and defined by the current National Institute of Standards and Technology (NIST) Special Publication (SP)

800-53 Revision 4, Security and Privacy Controls for Federal Information Systems and Organizations, commensurate with security categorization defined by FIPS 199, Standards for Security Categorization of Federal Information and Information Systems.

1.3 Scope, Management Commitment and Coordination, and Applicability

The provisions of this Handbook apply to all USPTO employees and contractor employees accessing or using USPTO information subsystems or data processed, transmitted, and/or stored on USPTO information subsystems; and to contractor employees providing services to the USPTO who use

USPTO information subsystems or data. This Handbook applies to all USPTO information systems and supporting resources, independent of size, location, or interconnection(s). Additionally, this

Handbook applies to all types of media used to store USPTO agency sensitive information and personally identifiable information (PII) which includes, but is not limited to: (i) hard drives, (ii) CDs, USPTO IT Security Handbook March 2019

(iii) DVDs, (iv) other magnetic media, and (v) solid-state media (Universal Serial Bus (USB) flash drive). Finally, it applies to all media output (to include digital, hard-copy (paper records), and microfilm formats) that contain USPTO classified or agency-sensitive information and PII.

This Handbook also applies to information subsystems and equipment, including network devices, operated and used by contractor employees, guest researchers, collaborators, and other federal agencies that help carry out the USPTO mission, whether or not such information subsystems or equipment are owned or leased by the government or on government property. The security policies set forth in this

Handbook apply to all IT procurement activities.

1.4 Update and Review

Policies will be reviewed, at minimum on an annual basis and updated as needed. Policies may be reviewed more frequently as necessary (e.g., due to new Federal or USPTO mandates updates and changes).

1.5 Authority

This Handbook is issued under the authority of the USPTO Chief Information Officer (CIO). The most critical Federal laws, regulations, Executive Orders, policies, standards, and directives followed are indicated below.

E-Government Act of 2002

The Privacy Act of 1974

Clinger-Cohen Act of 1996

National Technology Transfer and Advancement Act of 1996

Health Insurance Portability and Accountability Act of 1996 (HIPAA)

Federal Information Security Management Act of 2002 (FISMA)

Federal Information Security Modernization Act of 2014 (FISMA)

Federal Financial Management Improvement Act of 1996 (FFMIA)

Federal Acquisition Streamlining Act of 1994 (FASA)

United States Government Accountability Office, Federal Information System Controls Audit

Manual (FISCAM)

OMB Circulars

OMB Memoranda

Federal Information Processing Standards (FIPS)

NIST Special Publications

1.6 Compliance

Compliance with this Handbook is mandatory. It is USPTO policy that personnel and information systems abide by or exceed the requirements outlined in this Handbook and the associated procedures for each NIST SP 800-53 rev 4 family of controls. The Senior Information Security Officer (SISO) will periodically assess USPTO’s adherence with this Handbook through various oversight and compliance measures.

In cases where an information systems cannot comply with this Handbook, for technical or financial reasons, or because it precludes USPTO from supporting mission or business functions, justifications for

USPTO IT Security Handbook March 2019 non-compliance must be documented using the risk acceptance process, addressed by the System Owner, and submitted to the CIO via the SISO. Risk Acceptance process is officially documented in the USPTO

IT Policy on Security Risk Acceptance, OCIO-POL-35.

1.7 USPTO IT Security Program Documentation

This Handbook is organized into five sections to address information security as follows:

Section 1 – Introduction: Describes the background, purpose, scope, and documentation.

Section 2 – IT Security Handbook: Describes the authority, effective date, risk acceptance memos, and enforcement.

Section 3 – IT Security Roles and Responsibilities: Provides an outline of the departmental offices, roles, and IT groups.

Section 4 and 5 – Baseline Security Controls: Contain a complete list of security controls with

USPTO specific criteria including additional FedRAMP controls and program management and privacy controls.

A listing of acronyms, terms, and references can be found in the appendices.

USPTO IT Security Handbook March 2019

2 IT Security Handbook

USPTO shall develop, document, and implement an IT security program to protect the confidentiality, integrity, and availability of USPTO information and systems in accordance with the

Federal Information Security Modernization Act (FISMA) of 2014.

USPTO shall use FIPS 199 to categorize information systems and determine their appropriate impact levels (Low, Moderate, or High). The USPTO shall select the security controls baseline defined in current NIST SP 800-53, rev 4, based on the system’s impact level, and tailor, supplement, and implement the baseline according to NIST 800-53. The USPTO shall use current NIST SP 800-53A, Revision 4, Guide for Assessing Security and Privacy Controls in Federal Information Systems and

Organizations, Building Effective Assessment Plans, as the basis for assessing information system security controls to determine the extent to which they are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements. The

USPTO shall authorize information systems in accordance with the current NIST SP 800-37 revision

1, Guide for Applying the Risk Management Framework to Federal Information Systems, A Security

Life Cycle Approach. The USPTO shall be compliant with revisions to the aforementioned documents within one year of their issuance.

2.1 Effective Date

The USPTO IT Security Handbook is effective when signed by the CIO, superseding previous versions of this document. This version also incorporates the requirements of the following DOC Commerce

Information Technology Requirements (CITRs), which will remain in effect until superseded by updated

CITRs:

CITR-005: Removable Media Devices

CITR-006: Information System Security Training for Significant Roles

CITR-008: Remote Access

CITR-011: Peer-to-Peer Technology

CITR-014: Wireless Encryption Enhancements Policy

CITR-015: Contingency Plan Testing

CITR-016: Vulnerability Scanning and Patch Management

CITR-017: Security Configuration Checklist Program

CITR-018: IT Security Plan of Action and Milestones (POA&M)

CITR-019: Risk Management Framework

CITR-020: Safeguarding Information while on Foreign Travel

CITR-021: Password Management

CITR-022: Access and Use Policy

CITR-023:Pre-Acquisition Supply Chain Risk Assessment

CITR-024: FedRAMP Applicability

CITR-026: Privileged Accounts Management

For information about all current CITRs, please visit the DOC IT Security Program Policy website:

https://connection.commerce.gov/policy/20140528/it-security-program-policy-and-commerce-information-technology-requirements https://connection.commerce.gov/policy/20140528/it-security-program-policy-and-commerce-information-technology-requirements https://connection.commerce.gov/policy/20140528/it-security-program-policy-and-commerce-information-technology-requirements

USPTO IT Security Handbook March 2019

The following USPTO OCIO policies and procedures were merged into the associated NIST family-based set of procedures:

Access Control (AC) Procedures o OCIO-POL-11: Administrative Access Rights o OCIO-POL-12: Password Protected Screensaver o OCIO-POL-15: Remote Access o OCIO-POL-48: IT Separation of Duties o OCIO-POL-41: IT User Account Deactivation o OCIO: POL-34: Mobile Device Management

Audit and Accountability (AU) Procedures o OCIO-POL-20: Network and AIS Audit, Logging, and Monitoring

Awareness and Training (AT) Procedures o OCIO-POL-19: IT Security Education Awareness Training

Configuration Management (CM) Procedures o OCIO-POL-31: Enterprise Configuration Management o OCIO-POL-32: Enterprise Change Management o OCIO-POL-6: Information Security Foreign Travel o OCIO-POL-13: Peer To Peer Software and File Sharing

Contingency Planning (CP) Procedures

Identification and Authentication (IA) Procedures o OCIO-POL-21: Password Management o OCIO-POL-49: Personal Identity Verification (PIV) Card Authentication

Incident Response (IR) Procedures o OCIO-POL-45: CIO Command Center (OCIO) o OCIO-POL-17: Breach Notification

Maintenance (MA) Procedures

Media Protection (MP) Procedures o OCIO-POL-23: Personally Identifiable Data Removal o OCIO-PRC-9: Sanitization and Disposal of Mobile Devices

Personnel Security (PS) Procedures o OCIO-POL-41: IT User Account Deactivation

Physical and Environmental Protection (PE) Procedures o OCIO-5012-09: IT Facility Emergency Power Off (EPO) Switches o OCIO-POL-6: Information Security Foreign Travel

Planning (PL) Procedures o OCIO-POL-18: IT Privacy o OCIO-POL-36: Rules of the Road o OCIO-POL-35: IT Policy on Security Risk Acceptance

Program Management (PM) Procedures

Risk Assessment (RA) Procedures o Vulnerability/Compliance Scanning and Analysis Standard Operating Procedures o OCIO-POL-35: IT Policy on Security Risk Acceptance

Security Assessment and Authorization (CA) Procedures o OCIO-POL-51: OCIO Agreements with US Federal Agencies and International

Organizations

USPTO IT Security Handbook March 2019 o USPTO Continuous Monitoring Procedures

System and Services Acquisition (SA) Procedures o OCIO-1004-10: IT Desktop Hardware Acquisition Management o OCIO-POL-29: Vendor Performance Information Policy o OCIO-POL-24: System Development Life Cycle (SDLC) o OCIO-POL-38: Server and Storage Provisioning

System and Information Integrity (SI) Procedures o OCIO-POL-16: Anti-Virus

System and Communications Protection (SC) Procedures o OCIO-POL-14: Certificate Policy for the USPTO o OCIO-POL-23: Personally Identifiable Data Removal o OCIO-POL-18: IT Privacy

For information about these USPTO Policies, visit the USPTO intranet site:

https://usptogov.sharepoint.com/sites/a142efd3/Documents/Forms/All%20Approved%20Documents

.aspx

System Owners are required to comply with this Handbook within 120 days of its effective date.

Compliance with this Handbook beyond the specified timeframe shall be managed through the Plan of Action and Milestones (POA&Ms).

The USPTO Senior Information Security Officer (SISO) will review the USPTO IT Security

Handbook at least annually or more often if needed and incorporate updates as necessary including new federal requirements. The revised USPTO IT Security Handbook shall be reviewed and approved by the concurrence of the USPTO CIO. Subsequent to this, the USPTO Cybersecurity

Division will incorporate the changes into this Handbook and the revision shall be reviewed by, and meet the concurrence of USPTO stakeholders before presentation to the CIO for signature.

2.2 Risk Acceptance

The USPTO Authorizing Officials (AOs) shall approve the tailoring of security control baselines.

For controls and parameters that require risk acceptance memos, requests shall be submitted to the

USPTO CIO, through the SISO. In addition, the USPTO CIO has the discretion to elevate the risk acceptance approval process to the level of the Office of the Department of Commerce CIO when actions or controls are identified that affect department-wide security. Risk acceptance memo requests shall justify and describe the controls that cannot be fully implemented and the compensating controls in-place. Corrective action items shall be specified in the risk acceptance requests, if appropriate. System Owners (SO) shall use the POA&Ms to track and manage progress towards compliance.

Upon request from the USPTO CIO, each SO shall verify the Department-level risk acceptance requirements and submit copies of risk acceptance memos for performing Department-wide trend analysis and Enterprise risk management.

The risk acceptance process shall be implemented as follows:

Risk Acceptance requests shall be submitted to the CIO, via the SISO;

Risk Acceptance memo shall be addressed from the System Owner;

https://usptogov.sharepoint.com/sites/a142efd3/Documents/Forms/All%20Approved%20Documents.aspx

USPTO IT Security Handbook March 2019

Risk acceptance requests shall justify and describe the controls that cannot be fully implemented and the compensating controls in-place;

Corrective action items shall be specified in the risk acceptance memo requests, if appropriate;

Risk acceptance requests should include a POA&M describing the plan to come into conformance with policy or the risk accepted control;

The USPTO CIO has the discretion to elevate the risk acceptance approval to the Department

CIO in the event the risk acceptance affects Departmental security; and

The CIO has 30 days to respond to a risk acceptance memo request. This response shall include:

o Approval, and conditions for approval, including expiration date o Denial, or basis for denial, if that is the decision o Additional information on the risk acceptance request as identified by the CIO.

Please refer to the USPTO IT Policy on Security Risk Acceptance, OCIO-POL-35 for more details.

2.3 Enforcement

Failure to comply with any provisions of the Handbook may result in administrative or adverse action in accordance with the Office of Human Resources (OHR) policies. Perceived threats to system integrity, confidentiality, or availability shall result in suspension of system access as necessary to contain the perceived threat. An offense that is in violation of local, state, or Federal laws may result in suspension of system access and shall be reported to the appropriate law enforcement authorities.

USPTO IT security policies shall be enforced through the following:

Oversight

Inspection

Audit

Each USPTO Contracting Officer’s Technical Representative (COTR) has contract oversight security responsibility and shall ensure that contractor-related security requirements are followed throughout the contract life-cycle.

USPTO IT Security Handbook March 2019

3 IT Security Roles and Responsibilities

The responsibility to protect USPTO information and technological resources extends to all non-public users and requires collaboration across various offices to coordinate activities associated with the USPTO security posture, technological environment, and overall risk management.

3.1 Personnel

All USPTO employees and contractor employees are responsible for carrying out the provisions of this Handbook.

3.2 Roles and Responsibilities

The key roles and responsibilities for carrying out the provisions of this Handbook are outlined below.

3.2.1 USPTO Chief Information Officer (CIO)

Within the USPTO, the role of Authorizing Official (AO) is generally assigned to the CIO. The CIO manages USPTO’s Information Technology (IT) infrastructure and its risk management program.

The CIO has the following IT Security responsibilities:

Develop, maintain, and oversee the USPTO IT Security Program;

Appoint, in writing, a Senior Information Security Officer (SISO) to implement the IT Security

Program within USPTO;

Ensure, in coordination with senior USPTO officials, the implementation of the requirements of a

USPTO-wide IT Security Program (as specified in § 3544, paragraph (b), of the FISMA);

Ensure the USPTO annually performs an independent evaluation of the IT Security Program and its practices (as specified in § 3545 of the FISMA);

Provide overall management of and leadership and direction to the IT Security Program;

Assist and advise senior agency officials regarding their responsibilities for security, including

System Security Plans (SSPs);

Report regularly on the status of the IT Security Program to the Director and advise the Director on Security matters;

Consult with and brief USPTO Executive Management regarding all critical information system security issues;

In coordination with other agency officials, report annually to the agency head on the effectiveness of the agency information security program, including progress of remedial actions;

Assess and advise the USPTO Director of weaknesses In the IT Security Program, as appropriate, for annual accountability reporting;

Ensure managers for all IT resources are identified and that security authorization for those resources are accomplished within the planned timeframe;

Determine the acceptable level of residual risk for an information subsystems and if an information subsystems will adequately protect sensitive USPTO information;

Approve SSPs;

Review the Security Authorization Package (SAP) and sign the Authorization Decision

Document. The following authorization decisions can be made by the AO:

USPTO IT Security Handbook March 2019 o Authorization To Operate (ATO) – Full authorization will be granted when all of the following apply:

The authorization package is complete.

No corrective actions are required or may require minor corrective actions.

(Note: There may be findings during the authorization effort that are turned into a

POA&M, but do not prevent an ATO).

Residual risks are acceptable to the AO.

o Authorization To Operate (ATO) with Conditions – Special type of authorization allowing an information system to operate in an operational environment by assessing a limited set of controls to include volatile controls as defined by DOC CITR-19. This type of authorization will be given only when system need to be put in production to support continuity of organizational mission and business requirements. The system will be authorized to operate for a specified time period in accordance with the terms and conditions established by the authorizing officials. This limited authorization will be granted when all of the following apply:

Vulnerability scans have been performed on the system and there are no major high risk vulnerabilities discovered. If necessary corrective actions (POA&Ms) are identified.

Volatile controls, as determined by DOC, have been assessed.

Residual risks are accepted for a limited time identified in the ATO letter that also includes all terms and conditions that need to be completed associated with the given ATO termination date.

o Interim Authority to Test (IATT) – The USPTO AO can exercise its authority to grant this special type of authorization decision allowing an information system to operate in an operational environment for the express purpose of testing the system with actual operational (i.e., live) data for a specified time period. An interim authorization to test is granted by an authorizing official only when the operational environment or live data is required to complete specific test objectives.

o Denial of Authorization to Operate (DATO) – If the authorizing official, after reviewing the authorization package and any additional inputs provided by the risk executive

(function), deems that the risk to organizational operations and assets, individuals, other organizations, and the Nation is unacceptable and immediate steps cannot be taken to reduce the risk to an acceptable level, a denial of authorization to operate is issued for the information system or for the common controls inherited by organizational information systems. The system may not be placed into operation until at least an IATT is granted.

Monitor and report IT security program compliance with Federal laws and USPTO IT security policies;

Serve as the IT security liaison to external organizations;

Ensure sufficient resources are available to implement the USPTO IT security program in coordination with the Director and the Heads of USPTO Business Units;

Ensure USPTO IT security planning and execution is practiced throughout the life cycle of each

USPTO system;

Ensure a PTO Computer Incident Response Team (CIRT) is staffed, trained, and maintained in a state of readiness;

Ensure that persons with IT security responsibilities have appropriate role-based training;

USPTO IT Security Handbook March 2019

Assist oversight groups in compliance reviews and other reporting requirements;

Provide feedback to oversight groups on the status of the program in USPTO and suggest improvements or areas of concern in the USPTO program;

Establish an overall strategy for the IT Security Awareness and Training Program;

Ensure the program is sufficiently staffed and funded to achieve its approved objectives in a timely manner;

Ensure effective tracking and reporting mechanisms are in place to accurately determine course completion, and to evaluate the awareness and training program;

Establish plans, procedures and schedules to correct any IT security awareness and training material weaknesses identified during formal inspections and evaluations; and

Ensure that USPTO IT security policies are developed, approved and maintained in a timely manner.

3.2.2 Co-Authorizing Official (Co-AO)

The role of USPTO Co-AO could be assigned to the chiefs/directors of following USPTO Offices: Patent

Office, Chief Administrative Officer, Chief Financial Officer, Equal Employment Opportunity and

Diversity, etc. The CO-AOs roles are documented in the respective system SSP. The Co-AO approves system security requirements including SSPs, ATO letters, IATT letter, etc.

Co-AO is responsible for ensuring continued ATOs for systems under their responsibility by reaffirming acceptable Continuous Monitoring results and accepting risks at least annually for systems that fall under their responsibility.

AO/CO-AO role has inherent U.S. Government authority and is assigned to government personnel only.

3.2.3 Authorizing Official Designated Representative (AODR)

The authorizing official designated representative is an organizational official that acts on behalf of an authorizing official to coordinate and conduct the required day-to-day activities associated with the security authorization process. Authorizing official designated representatives can be empowered by authorizing officials to make certain decisions with regard to the planning and resourcing of the security authorization process, approval of the security plan, approval and monitoring the implementation of plans of action and milestones, and the assessment and/or determination of risk. The designated representative may also be called upon to prepare the final authorization package, obtain the authorizing official’s signature on the authorization decision document, and transmit the authorization package to appropriate organizational officials. The only activity that cannot be delegated to the designated representative by the authorizing official is the authorization decision and signing of the associated authorization decision document (i.e., the acceptance of risk to organizational operations and assets, individuals, other organizations, and the Nation).

3.2.4 USPTO Business Area Heads

USPTO business areas heads have assigned Authorizing Officials (AO) who co-signs with the CIO

AO for those business systems under their area of responsibility. These could include the USPTO

Office of Patents and Trademarks, Office of Chief Administrative Officer; Office of Chief Financial

Officer; Office of the Equal Employment Opportunity and Diversity, etc.

USPTO IT Security Handbook March 2019

3.2.5 USPTO Senior Information Security Officer (SISO)

At the USPTO, the SISO has assessing responsibilities. The SISO is the agency official responsible for: (i) carrying out the security executive role under FISMA; (ii) possessing professional qualifications, including training and experience, required to administer the information security program functions; (iii) having information security duties as that official’s primary duty; and, (iv) heading an office with the mission and resources to assist in ensuring agency compliance with

FISMA.

The SISO is responsible for determining the level of effort and resources required for information subsystems security authorization; reviewing the information subsystems security categorization;

and, performing analysis and accepting the information subsystems SSP. The SISO (or supporting staff member) may also serve as the AO’s designated representative responsible for providing authorization recommendations to the AO. The SISO serves as the CIO’s primary liaison to the

Agency’s AOs, SOs, and Information System Security Officers (ISSO). Additionally, the SISO has the following responsibilities for IT Security:

Identify resource requirements, including funds, personnel and contractors, needed to manage the

USPTO IT Security Program;

Develop and maintain USPTO IT security policy, procedures, standards, and guidance consistent with Federal requirements and provide protection for the electronic information and information systems that support the operations and assets of the agency including those provided or managed by another agency or contractor;

Develop, document, and implement subordinate plans for providing adequate security for networks, facilities, and systems or groups of information systems;

Coordinate matters of physical security for IT resources with the USPTO Security Office;

Ensure that all systems have current and effective IT security plans that accurately reflect system status;

Ensure that appropriate security features are implemented in new systems and that they at least meet the minimum-security requirements defined in this Handbook;

Ensure the security of an information system throughout its life cycle and that IT security is integrated in the USPTO strategic IT planning and enterprise architecture (EA) efforts;

Ensure that periodic assessments are performed of the risk and magnitude of harm that could result from unauthorized access, use, disclosure, or disruption of information and information systems that support the operations and assets of the Agency;

Ensure that an AO, SO, and ISSO have been appointed for each information subsystems within the USPTO and maintain up-to-date records of these assignments;

Ensure that SSPs are properly prepared for all IT systems owned and operated by the USPTO;

Coordinate the development, review, and acceptance of SSPs with the SO, ISSO, and the AO;

Review SSPs, as submitted, making appropriate written comments that will be sent to the originator for corrective action;

Ensure ISSO review and update all SSPs, at least annually, and incorporate changes or completed milestone actions;

Ensure that periodic Security Test and Assessment (ST&A) plans are developed, documented, and implemented, no less than annually, to assess the effectiveness of information security policies, procedures, and practices;

Coordinate the identification, implementation and assessment of common security controls;

USPTO IT Security Handbook March 2019

Establish a process to track remedial actions to mitigate risks in accordance with Plans of Action and Milestones (POA&M) to address any deficiencies in the information security policies, procedures and practices of the Agency;

Review proposed system changes and act as approval authority for changes that impact system security;

Lead development, implementation and enforcement of USPTO IT Security policies and procedures;

Manage and oversee internal and external reviews and inspections to ensure compliance with established policies and procedures;

Serve as the principal Point of Contact (POC) on IT security activities within USPTO;

Ensure appropriate IT Security Awareness Training is provided;

Advise the SO of security features and procedures for systems;

Ensure the OCIO Configuration Management (CM) process and System Development Life Cycle

(SDLC) is used to maintain IT Security documentation;

Identify and recommend security and privacy controls improvements to management;

Ensure appropriate incident response capabilities;

Interface and coordinate with the Office of the Inspector General (OIG) on IT Security reviews and issues;

Assign each USPTO system a unique identification number that will identify the Agency and the specific system;

Ensure that IT systems are categorized, in conjunction with other staff;

Maintain a tracking system for implementation of the required controls and authorization status for all USPTO systems;

Ensure that all systems have effective, quality security documentation in place, including:

o Security assessment reports (SAR), o Current and effective IT security plans that accurately reflect system status, o continuous monitoring, o Current and tested contingency plans (CPs), and o Current security authorization (ATO).

Maintain the major application and general support system inventory;

Provide information to systems administrators and others concerning risks and potential risks to systems;

Notify SOs and ISSO of user infractions identified during routine compliance assessments and any required actions;

Advise the CIO and business area heads of technological IT security advances that can be used on an agency-wide scale;

Report to the CIO and external entities such as OMB, Government Accountability Office (GAO), and Congress, on IT Security Program status;

Ensure that all users and managers have an effective way to provide feedback on the quality and quantity of IT Security awareness and training material and its presentation; and

Ensure that IT Security awareness and training material is reviewed annually and updated when necessary.

3.2.6 USPTO Risk Executive Function

The risk executive (function) is an individual or group that helps to ensure that: (i) risk-related considerations for individual information systems, to include authorization decisions, are viewed from an

USPTO IT Security Handbook March 2019 organization-wide perspective with regard to the overall strategic goals and objectives of the USPTO in carrying out its core missions and business functions; and (ii) managing information system-related security risks is consistent across the USPTO, reflects organizational risk tolerance, and is considered along with other types of risks in order to ensure mission/business success. The risk executive (function) coordinates with the senior leadership of USPTO to:

Provide a comprehensive, organization-wide, holistic approach for addressing risk—an approach that provides a greater understanding of the integrated operations of the organization;

Develop a risk management strategy for USPTO providing a strategic view of information security-related risks with regard to the organization as a whole;

Facilitate the sharing of risk-related information among authorizing officials and other senior leaders within the USPTO;

Provide oversight for all risk management-related activities across USPTO (e.g., security categorizations) to help ensure consistent and effective risk acceptance decisions;

Ensure that authorization decisions consider all factors necessary for mission and business success;

Provide an USPTO-wide forum to consider all sources of risk (including aggregated risk) to organizational operations and assets, individuals, other organizations, and the Nation;

Promote cooperation and collaboration among authorizing officials to include authorization actions requiring shared responsibility;

Ensure that the shared responsibility for supporting organizational mission/business functions using external providers of information and services receives the needed visibility and is elevated to the appropriate decision-making authorities; and

Identify the USPTO risk posture based on the aggregated risk to information from the operation and use of the information systems for which USPTO is responsible.

The risk executive function at the USPTO consists of USPTO Cybersecurity management personnel.

3.2.7 USPTO Security Authorization and Compliance Manager

The Security Authorization and Compliance Manager is responsible for managing the security authorization process for all information subsystems. The security authorization and compliance manager plays an essential role in security and is, ideally, intimately aware of functional system requirements. The security authorization and compliance manager builds the business case for the acquisition of appropriate security solutions that help ensure mission accomplishment in the face of real-world threats. Additionally, the security authorization and compliance manager has the following IT Security responsibilities:

Possess the knowledge and skills to appropriately incorporate IT security throughout a system’s

SDLC process to protect the business operations and information the system supports;

Work with the SO, ISSO and SISO to meet shared IT security responsibilities; and

Ensure system development and operations staff is knowledgeable of the security authorization requirements and processes for their systems and are provided related training.

3.2.8 USPTO System Owner

The System Owner (SO) has responsibility for the Master System (grouping of multiple subsystems into FISMA reportable master system), while the role of managing individual systems within the

USPTO IT Security Handbook March 2019 master system is typically assigned to the ISSO. The SO has the following responsibilities for IT

Security:

Determine and implement an appropriate level of security commensurate with the system sensitivity level;

Prepare and conduct the preliminary risk assessment (PRA) and retirement risk assessment for all assigned information subsystems;

Perform risk assessments (RA) at least annually or as part of continuous monitoring activities, to re-evaluate sensitivity of the system, risks, and mitigation strategies. Take appropriate steps to reduce or eliminate vulnerabilities after receiving the results of continuous monitoring activities and update RAR accordingly;

Develop and maintain the SSP in coordination with the System Administrator, ISSO, SISO and end users;

Update the SSP during all continuous monitoring activities, including authorization, annual assessments and significant changes to the systems. During significant changes, where deemed necessary, the system should be re-authorized;

Develop, maintain, and review the SAP including SSPs and CPs for all systems under their responsibility and submit the SAP to the AO or their designated representative;

Ensure that the provisions of this Handbook are implemented for their information subsystems;

Oversee the ST&A Plan when the system undergoes a major change and perform continuous monitoring of the information subsystems;

Establish system-level POA&M and implement and monitor corrective actions to timely completion;

Ensure the information subsystems are deployed and operating according to the agreed-upon security requirements;

Decide who has access to the system and grant individuals the fewest privileges necessary for job performance, re-evaluate the access privileges at least annually, and revoke access in accordance with agency guidelines upon personnel transfer, termination, or change in duties;

Establish appropriate Rules of the Road for all systems that apply to all personnel managing, administering, or having access to the IT system;

Ensure systems’ personnel are properly designated, monitored, and trained, including appointment in writing of an individual to serve as the Technical Lead (TL), if appropriate;

Inform appropriate agency officials of the need to conduct a security authorization effort and ensure that appropriate resources are available for the effort;

Assist in the identification, implementation, and assessment of common security controls specific to their assigned information subsystems;

Conduct Continuous Monitoring activities including configuration management, control testing, POA&M updates, and reporting status for their assigned information subsystems;

Ensure knowledge and skills to incorporate IT security throughout the system’s SDLC process to protect the business operations and information the system supports;

Work with the CIO and SISO to meet shared IT security responsibilities; and

Coordinate with the Cybersecurity division Facilitation Point of Contact (FPOC) in execution of duties and responsibilities in association with this role to meet FISMA compliance requirements.

USPTO addresses the security requirements for System Owner (SO) through assignment of

Federal employees from the business unit coupled with full time contractor Security Subject

Matter Expert support to meet FISMA compliance requirements. This approach ensures business representation as well as expert security support in meeting FISMA requirements.

USPTO IT Security Handbook March 2019

3.2.9 Information Owner/Steward

The information owner/steward is an organizational official with statutory, management, or operational authority for specified information and the responsibility for establishing the policies and procedures governing its generation, collection, processing, dissemination, and disposal.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .