Attachment 5 - IPS 1-17 Information Security Program.docx
DOCX document 534 KB Posted
- Attached to
- Peace Corps MAC Support Services Federal contract opportunity
- Solicitation number
- 1145PC20Q0022
- Issued by
- Peace Corps
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment 1 - 209-Vulnerability Management Plan-2019.04_Final.pdf | ||
| 1145PC20Q0022 Final 5.22.20.doc | DOC document | |
| Attachment 4 - MS 899 Breach Notification Response Plan.docx | DOCX document | |
| Attachment 3 - CISA_Incident Reporting Requirements Update _March 29 2019.pdf | ||
| Attachment 2 - 701-Incident Response Plan 2019.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Information Security Control Catalog
(ISCC)
Effective Date:
March 15, 2018
Prepared by:
Office of the Chief Information Officer Security, Policy, & Governance Branch (SP&G) 1122 20th Street NW Washington, D.C. 20526
Peace Corps Information Security Control Catalog v 1.0 March 15, 2018
Annual Review Record
The Information Security Control Catalog shall be reviewed annually with the review date and reviewer name recorded in the table below.
| Reviewer |
| Review Date |
| Comments |
Revision History
VERSION (YYMMDD)
AUTHOR
DESCRIPTION OF REVISIONS
| v .1 |
| C. Bursenos |
| Initial draft |
| v .11 |
| C. Bursenos |
| Final draft |
| 180313 |
| M. Terry |
| Final |
Sensitive but Unclassified Information
Executive Summary
This document is subordinate to Peace Corps MS 542 Information Security Policy and is designed to support Peace Corps’ Information System Risk Management Framework (RMF) Process. This guide consolidates minimum baseline guidance for each of the National Institute for Standards and Technology (NIST) privacy and security control families for all Federal Information Security Modernization Act (FISMA) reportable systems. A FISMA reportable system is any IT system used to store, process or transmit Peace Corps owned information to support the mission of Peace Corps. This includes cloud or contractor owned/managed systems.
This document is organized into three sections as follows:
Section 1 – Introduction: Describes the background, purpose, scope, and governance of this document.
Section 2 - Control Catalog: Identifies the minimum controls to be implemented where possible. Contains a complete list of privacy and security controls with Peace Corps specific criteria.
Appendices containing a list of references, acronyms, a glossary of terms, and a list of security laws and federal regulations referenced.
Information Security Control Catalog Peace Corps
Sensitive but Unclassified Information
Table of Contents
| 1. | Introduction | 4 |
| 1.1 | Background | 4 |
| 1.2 | Purpose | 4 |
| 1.3 | Scope | 5 |
| 1.4 | Audience | 5 |
| 1.5 | Authority | 5 |
| 1.6 | Effective Date | 6 |
| 1.7 | Governance | 6 |
| 1.8 | Compliance | 6 |
| 1.9 | Risk Acceptance | 7 |
| 1.10 | Roles and Responsibilities | 7 |
| 2. | Control Catalog | 8 |
| 2.1 | Security Controls | 8 |
| 2.1.1 | Access Control (AC) | 8 |
| 2.1.2 | Awareness and Training (AT) | 24 |
| 2.1.3 | Audit and Accountability (AU) | 27 |
| 2.1.4 | Security Assessment and Authorization (CA) | 36 |
| 2.1.5 | Configuration Management (CM) | 43 |
| 2.1.6 | Contingency Planning (CP) | 56 |
| 2.1.7 | Identification and Authentication (IA) | 68 |
| 2.1.8 | Incident Response (IR) | 103 |
| 2.1.9 | Maintenance (MA) | 108 |
| 2.1.10 | Media Protection (MP) | 114 |
| 2.1.11 | Physical and Environmental Protection (PE) | 119 |
| 2.1.12 | Planning (PL) | 127 |
| 2.1.13 | Personnel Security (PS) | 131 |
| 2.1.14 | Risk Assessment (RA) | 135 |
| 2.1.15 | System and Services Acquisition (SA) | 139 |
| 2.1.16 | System and Communications Protection (SC) | 147 |
| 2.1.17 | System and Information Integrity (SI) | 156 |
| Appendix A: REFERENCES | 164 | |
| Appendix B: ACRONYMS | 167 | |
| Appendix C: GLOSSARY | 170 | |
| Appendix D: RELEVANT LAWS AND REGULATIONS | 201 | |
| 2.1.18 | US Public Laws | 201 |
| 2.1.19 | Office of Management and Budget (OMB) Regulations | 203 |
| 2.1.20 | Peace Corps Administrative and Organization Orders | 204 |
| 2.1.21 | Other | 204 |
Introduction
Loss or disruption of a critical information system or services could have major ramifications to the mission, business processes, and volunteer activities that Peace Corps has been established to support. Security controls are the safeguards and countermeasures prescribed for an information system that are designed to: (i) protect the confidentiality, integrity, and availability of information that is processed, stored, and transmitted by those information systems; and to (ii) satisfy a set of defined security requirements established by the Peace Corps in response to applicable laws, regulations, executive orders and Federal policies. Through the careful selection and implementation of controls, Peace Corps can adequately mitigate the risk incurred by using information and information systems in the execution of Peace Corps’ mission and business function.
Background
The Federal Information Security Modernization Act (FISMA) of 2014 provides a comprehensive framework for ensuring the effectiveness of information security controls over information resources that support Federal operations and assets, and defines “adequate security” as security commensurate with the risk and magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of information. This includes ensuring that systems and applications used by Peace Corps operate effectively and provide appropriate confidentiality, integrity, and availability with cost effective management, operational and technical controls.
In support of FISMA, NIST Federal Information Processing Standards (FIPS) Publication 200, Minimum Security Requirements for Federal Information and Information Systems, directs that all Federal Government agencies ensure that adequate security controls be implemented for their information subsystems. The guidelines provided in FIPS 200 are applicable to all federal information systems other than those systems designated as national security systems as defined in 44 U.S.C., Chapter 35, Coordination of Federal Information Policy § 3542. This document describes how the Peace Corps will comply with FISMA and other related directives.
The security policies captured in this document were developed to meet the minimum legally and federally mandated requirements for information security and are based on the Federal Government standards and procedures issued by the Office of Management and Budget (OMB), NIST, and the General Services Administration (GSA).
Purpose
The purpose of this Peace Corps Information Security Catalog (ISC) is to document Peace Corps security and privacy policies and minimum control standards as required by FISMA and provide a common reference to be used by Peace Corps personnel. It identifies and documents the minimum security controls as required by FIPS 200, Minimum Security Requirements for Federal Information and Information Systems, as defined by the NIST Special Publication (SP) 800-53, Security and Privacy Controls for Federal Information Systems and Organizations, and commensurate with a system’s security categorization defined by FIPS 199, Standards for Security Categorization of Federal Information and Information Systems. This document establishes the minimal baseline requirements for each control but more stringent requirements enforced at the discretion of the systems Authorizing Official.
CSAM is the agency’s official repository for all control guidance. If incongruences exist between CSAM and the ISCC, CSAM will be considered authoritative.
Scope
This document reflects the control minimal baselines established in CSAM. The content applies to all Peace Corps employees and contractor employees accessing or using Peace Corps information systems or data processed, transmitted, and/or stored on Peace Corps information subsystems; and to contractor employees providing services to the Peace Corps who use Peace Corps information systems or data. This document applies to all Peace Corps information systems and supporting resources, independent of size, location, or interconnection(s). Additionally, this document applies to all types of media used to store Peace Corps agency sensitive information and personally identifiable information (PII) which includes, but is not limited to: hard drives, compact disks, DVDs, magnetic media, and solid-state media (Universal Serial Bus (USB) flash drives). Finally, this document applies to all media output to include digital and hard-copy (paper records) formats that contain Peace Corps agency-sensitive information and PII.
This content also applies to Peace Corps owned and operating information systems and systems owned or operated by contractor employees, guest researchers, collaborators, and other federal agencies that help to carry out the Peace Corps mission, whether or not such information systems or equipment are owned or leased by the government or on government property. The security and privacy policies set forth in this document apply to all IT procurement activities to include cloud based services as defined by NIST in SP 800-145, as well as other applicable regulations, policies and laws.
Audience
This document will be made available to all federal and non-federal personnel who use, are involved with, or have responsibilities supporting the Solution Delivery Framework. Documents will be available in the Peace Corps Library on the Peace Corps Intranet. Document references under each control family are authorized by the associated policy and becomes an extension of the control family policy. Implementation guidance is addressed in Section 2 Security and Privacy Controls.
Authority
This document is issued under the authority of the Peace Corps Chief Information Security Officer (CISO).
Effective Date
This document is effective immediately when signed by the CISO, superseding any previous versions of this document. System Owners have 180 days to comply per policy. Compliance with CSAM controls beyond the specified timeframe shall be managed through the Plan of Action and Milestones (POA&Ms) or through a Risk Acceptance Letter.
Governance
This document supplements 542 and provides Organizationally Defined Values (ODVs) required by NIST SP 800-53. CSAM is the agency’s official repository for all security control guidance in Section 2 Control Catalog that support policy statements established in MS542. If incongruences exist between CSAM and the ISCC, CSAM will be considered authoritative.
SP&G will review and, as necessary, update all CSAM controls and policy statements at least annually or when new legal, regulatory or authoritative guidance is issued.
Request for changes to this document or CSAM should be directed to SP&G through ciso@peacecorps.gov.
SP&G will review and execute any necessary updates to CSAM controls documented in Section 2 Control Catalog. SP&G and the Privacy office will solicit stakeholder comments and adjudicate all comments received during the comment period. Once updates are finalized, SP&G will present the changes to the OCIO. The CISO will authorize the update to be incorporated into CSAM.
System owners will be expected to comply with new control requirements no later than the next assessment cycle.
Compliance
Compliance with the CSAM control requirements are mandatory. The ISCC is intended to provide a consolidated reference for Peace Corps controls documented in CSAM. It is Peace Corps’ policy that personnel and information systems abide by or exceed the requirements outlined in this document for each NIST SP 800-53 family of controls. SP&G will assess Peace Corps’ adherence with this document through various oversight and compliance measures.
Individuals found to be non-compliant with this policy may be subject to corrective action including any or all of the following:
a. Employee discipline under MS 647.
b. Contractor suspension or debarment.
c. Removal of an individual’s authority to access Peace Corps information systems.
Peace Corps information systems are required to have a current Authorization-to-Operate (ATO) designated by the Peace Corp Authorizing Official. A system that is found to be non-compliant with this policy shall be subject to CIO and CPO review and action.
Risk Acceptance
The Peace Corps Authorizing Official will approve the tailoring of security control baselines.
In cases where an information system cannot comply with a particular privacy or security control for technical or financial reasons, or because it precludes Peace Corps from supporting mission or business functions, justifications for non-compliance must be documented using the Risk Acceptance process. The Risk Acceptance memo must be formally signed by the Authorizing Official (AO). Risk Acceptance memos are only valid for one year from the date of the AO’s signature and must be reviewed on an annual basis. It is the responsibility of the Information System Security Officer (ISSO) to maintain the Risk Acceptance memo in Peace Corps’ Cyber Security and Assessment Methodology (CSAM) tool and to review the memo on an annual basis as part of the Continuous Monitoring program.
The risk acceptance process shall be implemented as follows:
1. A Risk Acceptance Letter will be submitted to the AO, via the SO or ISSM;
2. Risk Acceptance Letters will be addressed from the SO or ISSM;
3. Risk Acceptance Letters will list the controls that cannot be fully implemented along with the CSAM-derived Risk Impact, justify the risk, and compensating controls in-place to meet the spirit of the control;
4. Corrective action items will be specified in the Risk Acceptance Letter, if appropriate;
5. Risk Acceptances will result in a POA&M describing the plan to come into conformance with policy, and the mitigating control;
6. Risk Acceptance Letters must be reviewed at least annually and after major changes to the system. Evidence of this review must be documented and uploaded into CSAM.
Roles and Responsibilities
The responsibility to protect Peace Corps information and technological resources extends to all nonpublic users and requires collaboration across various offices to coordinate activities associated with the Peace Corps security posture, technological environment, and overall risk management. The key roles and responsibilities for carrying out the provisions of this ISCC are outlined in the MS542 Peace Corps Information Security Policy.
Designation letters must be maintained for the following roles:
a) Authorizing Official (AO),
b) System Owner (SO),
c) Information System Security Managers (ISSM), and
d) Information System Security Officers (ISSO)
Each assigned individual must certify receipt of the designation letter indicating their commitment to adhere to the policies established by Peace Corps. SP&G will conduct workforce training for each role to ensure each individual understands their role in the Risk Management Framework and are properly trained.
Control Catalog Security Controls
The following section describe the security controls required for low, moderate, and high baselines information systems, as defined by NIST 800-53 Revision 4 and Peace Corps Security policies. The requirements documented herein represent the minimum security requirements for each security baseline. Additionally, System Owners at their discretion may elect to include additional controls documented below, including non-selected security controls (those not required for any systems). If non-selected controls are included in an information system baseline, it is the responsibility of the System Owner, with the guidance of the ISSM or ISSO, to define any control assignments and selections in the information system security plan. Peace Corps maintains low and moderate systems; therefore, the high security controls are only included in this catalog should a system owner wish to select a high security control and for consistency purposes. The bolded text within each control statement under the Control Name/Requirement column is the minimum organizationally defined parameters (ODPs) for the agency.
Access Control (AC)
The objective of Access Control is to address the considerations that will help to ensure that Peace Corps IT Resources and information assets are properly protected against unauthorized access while meeting the access requirements for authorized users. System Owners are responsible for ensuring all applicable AC controls address the requirement at the system level.
| Control Number |
| Control Name/Requirement |
| Security Baselines |
| Low |
| Moderate |
| High |
Access Control Policy and Procedures
AC-1
Reference Access Control Policy section of MS542.
The policy and procedures must be reviewed and updated at least annually.
X
Account Management
AC-2
All Peace Corps information systems must manage information system accounts by:
a. Identifying account types (i.e., general user (individual, group), system, application, guest, elevated and temporary);
b. Assigning account managers for
| Control Number |
| Control Name/Requirement |
| Security Baselines |
| Low |
| Moderate |
| High |
information system accounts;
c. Establishing conditions for group membership;
d. Identifying authorized users of the information system and specifying access privileges and other attributes for each account;
e. Requiring appropriate approvals from the ISSO for requests to establish accounts;
f. Creating, enabling, modifying, disabling, and removing information system accounts in accordance with the Enterprise Systems and Services Access Control Process;
g. Monitoring the use of information system accounts;
h. Notifying account managers when accounts are no longer required and when information system users are terminated, transferred, or information system usage or need to-know/need-to-share changes;
i. Authorizing access to the system based on:
(i) a valid access authorization; (ii) intended system usage; and (iii) other attributes as required by the organization or associated missions/business functions;
j. Reviewing accounts for compliance with account management requirements at least annually; and
k. Establishing a process for reissuing shared or group account credentials when individuals are removed from the group.
Account Management| Automated System Account Management
AC-2 (1)
Automated mechanisms should be employed to support the management of information system accounts.
Account Management| Removal of Temporary/Emergency Accounts
AC-2 (2)
Information systems automatically disable temporary and emergency accounts 24 hours after creation.
| Control Number |
| Control Name/Requirement |
| Security Baselines |
| Low |
| Moderate |
| High |
Account Management| Disable Inactive Accounts
AC-2 (3)
Information systems must automatically disable inactive accounts after 90 days; All system and application account types must be reviewed at least annually and disabled if no longer required.
| Account |
| Management| Automated Audit |
| Actions |
AC-2 (4)
Automated mechanisms should be employed to ensure that account creation, modification, disabling, and termination actions are audited and, as required, the ISSO must be notified.
Account Management| Inactivity Logout
AC-2 (5)
The Peace Corps should require that users log out when access to the system is no longer required to fulfill their job duties.
This enhancement only applies to High categorization systems that currently don’t exist within Peace Corps. If any High systems are introduced in the future this requirements will be further defined.
Account Management| Account Monitoring/Atypical Use
AC-2 (12)
Peace Corps should:
a. Monitor information system accounts for anomalous use such as accessing information systems at certain times of the day and from locations that are not consistent with the normal usage patterns of individuals working in organizations; and
b. Report atypical usage of information system accounts to system administrators and/or incident response personnel.
categorization systems that currently don’t exist within Peace Corps. If any High systems are introduced in the future requirements will be further defined.
| Control Number |
| Control Name/Requirement |
| Security Baselines |
| Low |
| Moderate |
| High |
Account Management| Disable Accounts for High-Risk Individuals
AC-2 (13)
Peace Corps must disable accounts of users posing a significant risk within an immediate time period of discovery of the risk.
categorization systems that currently don’t exist within Peace Corps. If any High systems are introduced in the future requirements will be further defined.
Access Enforcement
AC-3
Peace Corps must ensure that all information systems enforce assigned authorizations for logical access to the information system.
Information Flow Enforcement
AC-4
The information system enforces approved authorizations for controlling the flow of information within the system and between interconnected systems through the use of controlled interfaces (CI) that implement controls and requirements delineated in Peace Corps’ Information Security Architecture.
A CI is a mechanism that facilitates adjudicating the security policies of different interconnected information systems (e.g., controlling the flow of information into or out of an interconnected system).
Separation of Duties
AC-5
All Peace Corps information systems must:
a. Separate duties of individuals to prevent the potential for abuse of authorized privileges and helps to reduce the risk of malevolent activity without collusion;
b. Document separation of duties; and
c. Define information system access authorizations to support separation of duties.
Least Privilege
AC-6
Peace Corps information systems must employ the concept of least privilege, allowing only authorized accesses for users (and processes acting on behalf of users) which are necessary to accomplish
| Control Number |
| Control Name/Requirement |
| Security Baselines |
| Low |
| Moderate |
| High |
assigned tasks in accordance with Peace Corps missions and business functions.
Least Privilege| Authorize Access to Security Functions
AC-6 (1)
Access to establish system accounts, configure access authorizations (i.e., permissions, privileges), set events to be audited, and set intrusion detection parameters must be explicitly authorized.
Least Privilege| Non-Privileged Access for Non-Security Functions
AC-6 (2)
Users of information system accounts, or roles, with access to establish system accounts, configure access authorizations (i.e., permissions, privileges), set events to be audited, and set intrusion detection parameters must use non- privileged accounts, or roles, when accessing other system functions, and use of privileged accounts must be audited for such functions.
Least Privilege| Network Access to Privileged Commands
AC-6 (3)
Peace Corps authorizes network access to perform remote administration only for compelling operational needs and documents the rationale for such access in the security plan for the information system.
categorization systems that currently don’t exist within Peace Corps. If any High systems are introduced in the future requirements will be further defined.
Least Privilege| Privileged Accounts
AC-6 (5)
Peace Corps restricts privileged accounts on the information system to system administrators.
Least Privilege| Auditing Use of Privileged Functions
AC-6 (9)
Peace Corps information systems must audit the execution of privileged functions.
| Control Number |
| Control Name/Requirement |
| Security Baselines |
| Low |
| Moderate |
| High |
Auditing the use of privileged functions is one way to detect such misuse, and in doing so, help mitigate the risk from insider threats and the advanced persistent threat.
Least Privilege| Prohibit non-Privileged Users from Executing Privileged Functions
AC-6 (10)
Peace Corps information systems must prevent non- privileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures.
Unsuccessful Login Attempts
AC-7
Peace Corps information systems accounts must:
a. Enforce a limit of five (5) consecutive invalid login attempts by a user during a 30 minute time period; and
b. Automatically lock the account until released by an administrator, when the maximum number of unsuccessful attempts is exceeded. This control applies regardless of whether the login occurs via a local or network connection.
System Use Notification
AC-8
The information system:
a. Displays to users standard notification within the Peace Corps Directive IM-05-02 before granting access to the system that provides privacy and security notices consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance and states that:
1. Users are accessing a U.S. Government information system;
2. Information system usage may be monitored, recorded, and subject to audit;
| Control Number |
| Control Name/Requirement |
| Security Baselines |
| Low |
| Moderate |
| High |
3. Unauthorized use of the information system is prohibited and subject to criminal and civil penalties; and
4. Use of the information system indicates consent to monitoring and recording;
b. Retains the notification message or banner on the screen until users acknowledge the usage conditions and take explicit actions to log on to or further access the information system; and
c. For publicly accessible systems:
1. Displays system use information that provides privacy and security notices consistent with applicable federal laws, Executive orders, directives, policies, regulations, standards, and guidance, before granting further access;
2. Displays references, if any, to monitoring, recording, or auditing that are consistent with privacy accommodations for such systems that generally prohibit those activities; and
3. Includes a description of the authorized uses of the system.
Warning banners is displayed when individuals log in to the information system. System use notification is for information system access that includes an interactive login interface with a human user and does not require notification when an interactive interface does not exist.
The following is the official Peace Corps warning banner:
WARNING!!! WARNING!!! WARNING!!!
This computer system is the property of the United States Peace Corps. It may only be accessed and used for official Government business by authorized personnel.
Unauthorized access or use of this computer system is strictly prohibited and may subject violators to criminal, civil, and/or administrative action. The Peace Corps may monitor any activity, information, or communication on the system.
All activity, communication, and information on this system may be intercepted, recorded, read, copied, retrieved, and disclosed by and to authorized personnel for official purposes, including criminal investigations.
Users have no right of privacy or any reasonable expectation of privacy in the use of this computer system and any communication or information stored within the system.
Access or use of this computer system by any person, whether authorized or unauthorized, constitutes consent to all of these terms.
| Control Number |
| Control Name/Requirement |
| Security Baselines |
| Low |
| Moderate |
| High |
Concurrent Session Control
AC-10
Peace Corps information systems should limit the number of concurrent sessions for privileged and unprivileged accounts to a maximum of 2 concurrent sessions for privileged accounts and 5 concurrent sessions for unprivileged. Concurrent sessions must be kept to as low as possible based on risk.
| Control Number |
| Control Name/Requirement |
| Security Baselines |
| Low |
| Moderate |
| High |
Session Lock
AC-11
Peace Corps information systems must:
a. Prevent further access to the system by initiating a session lock after 15 minutes of inactivity or upon receiving a request from a user; and
b. Retain the session lock until the user reestablishes access using established identification and authentication procedures.
Session Lock| Pattern Hiding Displays
AC-11 (1)
Peace Corps information systems must conceal, via the session lock, information previously visible on the display with a publicly viewable image.
Session Termination
AC-12
The information system automatically terminates a user session after 30 minutes of inactivity or at the end of the session.
Permitted Actions without Identification or Authentication
AC-14
Peace Corps does the following:
a. Identifies [access only to public information] that can be performed on the information system without identification or authentication consistent with organizational missions/business functions; and
b. Documents and provides supporting rationale in the security plan for the information system, user actions not requiring identification or authentication.
| Control Number |
| Control Name/Requirement |
| Security Baselines |
| Low |
| Moderate |
| High |
Remote Access
AC-17
Peace Corps must ensure that:
a. Usage restrictions, configuration/connection requirements and implementation guidance for each type of allowed remote access method are established and documented; and
b. Remote access to information systems is authorized prior to allowing such connection;
| X |
| X |
| X |
Remote Access| Automated Monitoring/Control
AC-17 (1)
Automated mechanisms must be employed to facilitate the monitoring and control of remote access methods.
Remote Access| Protection of Confidentiality/Integrity Using Encryption
AC-17 (2)
Cryptographic mechanisms must be used to protect the confidentiality and integrity of remote access sessions.
Remote Access| Managed Access Control Points
AC-17 (3)
All remote access must be controlled through a limited number of managed access points.
Remote Access| Privileged Commands/ Access
| Control Number |
| Control Name/Requirement |
| Security Baselines |
| Low |
| Moderate |
| High |
AC-17 (4)
Execution of privileged commands and access to security-relevant information via remote access must be authorized only for compelling operational needs as documented in the System Security Plan.
Wireless Access
AC-18
Peace Corps must ensure that:
a. Usage restriction, configuration/connection requirements, and implementation guidance for wireless access are established; and
b. Wireless access to the information system is authorized prior to allowing such connection.
Not Applicable if wireless access to information subsystems is not permitted.
Wireless Access| Authentication and Encryption
AC-18 (1)
All Peace Corps information systems must protect wireless access to the system using authentication of users and devices and encryption.
Not Applicable if wireless access to information systems is not permitted.
Wireless Access| Restrict Configuration by Users
AC-18 (4)
Peace Corps should identify and explicitly authorize users allowed to independently configure wireless networking capabilities. Peace Corps ensures that users cannot independently configure wireless networking capabilities.
This enhancement only applies to High categorization systems that currently don’t exist within Peace Corps. If any High systems are introduced in the future this requirements will be further defined.
| Control Number |
| Control Name/Requirement |
| Security Baselines |
| Low |
| Moderate |
| High |
Wireless Access| Antennas/Transmission Power Levels
AC-18 (5)
Peace Corps should select radio antennas and calibrates transmission power levels to reduce the probability that usable signals can be received outside of organization-controlled boundaries.
categorization systems that currently don’t exist within Peace Corps. If any High systems are introduced in the future this requirements will be further defined.
Access Control for Mobile Devices
AC-19
| a. | Usage restrictions, configuration requirements, connection requirements, and implementation guidance are established for Peace Corps-controlled mobile devices; and |
| b. | The connections of mobile devices to organizational information systems are authorized. |
System Owners, in coordination with the CISO, must authorize the use of portable and mobile devices based on system sensitivity and risk level.
Access Control for Mobile Devices| Full Device/Container-Based Encryption
AC-19 (5)
Peace Corps employs full-device encryption and container-based encryption to protect the confidentiality and integrity of information on
| Control Number |
| Control Name/Requirement |
| Security Baselines |
| Low |
| Moderate |
| High |
all Peace Corps-owned mobile devices and personally owned devices that have been approved for remote access, respectively.
Use of External Information Systems
AC-20
Peace Corps should establish terms and conditions for all external information systems, consistent with any trust relationships established with other organizations owning, operating, and/or maintaining external information systems, allowing authorized individuals to:
a. Access the information system from external information systems; and
b. Process, store, or transmit organization- controlled information using external information systems.
External information systems include, but are not limited to: (i) personally owned information systems (e.g., computers, cellular telephones, or personal digital assistants); (ii) privately owned computing and communications devices resident in commercial or public facilities (e.g., hotels, convention centers, or airports); (iii) information systems owned or controlled by nonfederal governmental organizations; and (iv) federal information systems that are not owned by, operated by, or under the direct supervision and authority of the organization.
Use of External Information Systems| Limits on Authorized Use
AC-20 (1)
Peace Corps must ensure that only permitted authorized individuals use an external information system to access the information system or to process, store, or transmit organization-controlled information only when:
a. The implementation of required security controls on the external system as specified in the organization’s information security policy and security plan is verified; and/or
| Control Number |
| Control Name/Requirement |
| Security Baselines |
| Low |
| Moderate |
| High |
b. approved information system connection or processing agreements with organizational entity hosting the external information system are retained.
Use of External Information Systems| Portable Storage Devices
AC-20 (2)
Peace Corps must ensure that the use of Peace Corps-controlled portable storage devices by authorized individuals on external information systems is restricted, in accordance with the Peace Corps requirements.
Information Sharing
AC-21
Peace Corps must:
a. Facilitate information sharing by enabling authorized users to determine whether access authorizations assigned to the sharing partner match the access restrictions on the information for contract sensitive information, PII, or proprietary information as contractually obligated ; and
b. Employ manual processes to assist users in making information sharing/collaboration decisions.
Publicly Accessible Content
AC-22
a. Individuals are designated to post information onto Peace Corps information systems that is publicly accessible;
b. Authorized individuals are trained to ensure that publicly accessible information does not contain nonpublic information;
c. Proposed content of publicly accessible information for nonpublic information is reviewed prior to posting on Peace Corps information systems to ensure that nonpublic information is not included; and
d. The content on publicly accessible Peace Corps information systems is reviewed for nonpublic information at least annually;
| Control Number |
| Control Name/Requirement |
| Security Baselines |
| Low |
| Moderate |
| High |
and nonpublic information is removed from publicly accessible Peace Corps information systems, if discovered.
Table 28. Access Control - Control Family Security Baselines Awareness and Training (AT)
The entire Peace Corps user base must have the knowledge to recognize potential security concerns and understand the channels available to properly report those concerns to the appropriate authorities for action. In addition, those authorities need the necessary tools and skills to carry out their assigned duties effectively. Awareness and training ensures that every individual involved in using and managing IT:
· Understand their roles and responsibilities related to the organizational mission;
· Understand the organization’s security policy, procedures, and practices; and
· Have at least adequate knowledge of the security and privacy controls required and available to protect the IT resources for which they are responsible.
Control Number
Control Name/Requirement Security Baselines
| Low |
| Moderat e |
| High |
Security Awareness and Training Policy and Procedures
AT-1
Reference the Awareness and Training (AT) section of MS542.
The policy and procedures must be reviewed and updated at least annually.
Security Awareness Training
AT-2
Peace Corps provides basic security awareness training to information system users (including managers, senior executives, and contractors):
a. As part of initial training for new users;
b. When required by information system changes; and
c. At least annually thereafter.
Security Awareness| Insider Threat
AT-2 (2)
| X |
| X |
Control Number
Security Baselines
| Low |
| Moderat e |
| High |
Peace Corps must include security awareness training on recognizing and reporting potential indicators of insider threat.
Potential indicators and possible precursors of insider threat can include behaviors such as inordinate, long-term job dissatisfaction, attempts to gain access to information not required for job performance, unexplained access to financial resources, bullying or sexual harassment of fellow employees, workplace violence, and other serious violations of organizational policies, procedures, directives, rules, or practices etc.
Role-Based Security Training
AT-3
Peace Corps provides role-based security training to personnel with assigned security roles and responsibilities:
a. Before authorizing access to the information system or performing assigned duties;
b. When required by information system changes; and
c. At least annually thereafter.
Security Training Records
AT-4
Peace Corps should ensure that:
a. Individual information systems security training activities, including basic security awareness training and specific information systems security training are documented and monitored; and
b. Individual training records are retained for two (2) years (current year and past year).
Table 29. Awareness and Training Control Family Security Baselines
Audit and Accountability (AU)
Audit trails maintain a record of activities by a system or user. In conjunction with appropriate tools and procedures, audit trails can provide individual accountability, a means to reconstruct events, detect intrusions, and identify problems. System audit trails, or event logs, provide a record of events in support of activities to monitor and enforce the IT system security policy.
All auditable events are subject to recording and routine review by the Peace Corps CISO and auditors for inappropriate or illegal activity. System owners must ensure the protection of system event logs commensurate with the highest level of sensitivity of the information residing on the system.
Control Number
Security Baselines
| Low |
| Moderat e |
| High |
Audit and Accountability Policy
AU-1
Reference Audit and Accountability (AU) Policy section of MS542.
The policy must be reviewed and updated at least annually.
| X |
| X |
| X |
Audit Events
AU-2
Peace Corps ensures that:
a. Based on system impact level, Peace Corps information systems are capable of auditing the following events:
1. Account creation, modification, disabling, and deletion
2. Administrative permissions executed on user accounts
3. Administrative permissions executed on system resources
4. Failed login attempts and account lockout
5. Use of “su”, “pu”, “root”, “administrator”, or equivalent accounts
6. Activity log roll-over, deletion, or editing, and
7. All computer-readable data extracts from databases containing PII;
Control Number
Security Baselines
| Low |
| Moderat e |
| High |
b. Security audit function is coordinated with other Peace Corps entities requiring audit-related information to enhance mutual support and to help guide the selection of auditable events;
c. Based on current threat information and ongoing assessment of risk, a documented determination is made that the list of auditable events is deemed adequate to support after- the-fact investigations of security incidents or if additional controls should be implemented and Deviations from the list of auditable events due to system audit functionality capabilities, along with justifications, must be documented in relevant system security plans.
Audit Events| Reviews and Updates
AU-2 (3)
Peace Corps reviews and updates the list of audited events at least annually.
Content of Audit Records
AU-3
The Peace Corps information systems must generate audit records that contain sufficient information to establish what type of event occurred, when (date and time) the event occurred, where the event occurred, the source of the event, the outcome of the event, and the identity of any individuals or subjects associated with the event.
Content of Audit Records| Additional Audit Information
AU-3 (1)
The Peace Corps information system generates audit records containing at a minimum: :
a. The date and time of the event;
b. The software or hardware component of the information system;
c. where the event occurred;
d. The type of event;
e.The subject identity (the user of the component in which the event occurred); and
Control Number
Security Baselines
| Low |
| Moderat e |
| High |
e. The outcome (success or failure) of the event.
Content of Audit Records| Centralized Management of Planned Audit Record Content
AU-3 (2)
The Peace Corps information system provides centralized management and configuration of the content to be captured in audit records generated by information system components.
categorization systems that currently don’t exist within Peace Corps. If any High categorization systems are introduced in the future this requirement will be further defined.
Audit Storage Capacity
AU-4
Peace Corps allocates audit record storage capacity in accordance with
Response to Audit Processing Failures
AU-5
Peace Corps ensures that, in the event of an audit processing failure, information systems:
Alerts Peace Corps-CERT in the event of an audit processing failure; and Overwrite oldest audit records first.
Response to Audit Processing Failures| Audit Storage Capacity
AU-5 (1)
Information systems must provide a warning to system administrators immediately when allocated audit record storage volume reaches 75% of maximum audit record storage capacity.
categorization systems that currently don’t exist within Peace Corps. If any High categorization systems are introduced in the future this requirement will be further defined.
Control Number
Security Baselines
| Low |
| Moderat e |
| High |
Response to Audit Processing Failures| Real-Time Alerts
AU-5 (2)
Information systems must provide a real-time alert to system administrators when the following audit failure events occur:
a. Account creation, modification, disabling, and deletion;
b. Administrative permissions executed on user accounts (i.e., inclusion in access groups, reset of password, account lockout override);
c. Administrative permissions executed on system resources (i.e., addition of users or groups to access lists, creation of share points, creation of new access groups, change of access group permissions);
d. Failed login attempts and account lockout;
e. Use of “su,” “pu,” “root,” “administrator,” or equivalent accounts;
f. Activity log roll-over, deletion, or editing; and
g. All computer-readable data extracts from databases containing personally identifiable information (PII);
categorization systems that currently don’t exist within Peace Corps. If any High systems are introduced this requirements will be further defined.
Audit Review, Analysis, and Reporting
AU-6
a. Audit records for information systems are reviewed and analyzed monthly for indications of unusual or suspicious activity and
b. Any findings are reported to CSIRT.
Control Number
Security Baselines
| Low |
| Moderat e |
| High |
Audit Review, Analysis, and Reporting| Processing Integration
AU-6 (1)
Information systems should integrate audit review, analysis, and reporting processes to support Peace Corps processes for investigation and response to suspicious activities.
Audit Review, Analysis, and Reporting| Correlate Audit Repositories
AU-6 (3)
Peace Corps should ensure that information system audit records are analyzed and correlated across different repositories to gain organization-wide situational awareness.
Audit Review, Analysis, and Reporting| Integration/Scanning and Monitoring Capabilities
AU-6 (5)
Peace Corps should integrate analysis of audit records with analysis of information system monitoring information to further enhance the ability to identify inappropriate or unusual activity.
This enhancement only applies to High categorization systems that currently don’t exist within Peace Corps. If any High systems are introduced in the future this requirements will be further defined.
Audit Review, Analysis, and Reporting| Correlation with Physical Monitoring
AU-6 (6)
Peace Corps should correlate information from audit records with information obtained from monitoring physical access to further enhance the ability to identify suspicious, inappropriate, unusual, or malevolent activity.
This enhancement only applies to High categorization systems that currently don’t exist within Peace Corps. If any High systems are introduced
Control Number
Security Baselines
| Low |
| Moderat e |
| High |
in the future this requirements will be further defined.
Audit Reduction and Report Generation
AU-7
Peace Corps information systems must provide an audit reduction and report generation capability that:
a. Supports on-demand audit review, analysis, and reporting requirements and after-the-fact investigations of security incidents; and
b. Does not alter the original content or time ordering of audit records.
Audit Reduction and Report Generation| Automatic Processing
AU-7 (1)
Information systems should provide the capability to automatically process audit records for events of interest based upon selectable event criteria.
Events of interest could be for example: identities of individuals, event type, event dates, event location, IP address involved, information objects, or system resources involved, etc.
Time Stamps
AU-8
a. Use internal system clocks to generate time stamps for audit records; and
b. Record time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT) and meets to the thousandth of a second.
Time Stamps| Synchronization with Authoritative Time Source
AU-8 (1)
Compare the internal information system clocks at least daily with authoritative Network Time Protocol (NTP) servers and Synchronize the
Control Number
Security Baselines
| Low |
| Moderat e |
| High |
internal system clocks to the authoritative time source when the time difference is greater than 5 minutes.
Protection of Audit Information
AU-9
Peace Corps information systems must protect audit information and audit tools from unauthorized access, modification, and deletion.
Protection of Audit Information| Audit Backup on Separate Physical Systems/Components
AU-9 (2)
Peace Corps information systems must back up audit records weekly onto a physically different system or system component than the system or component being audited.
categorization systems that currently don’t exist within Peace Corps. If any High systems are introduced in the future this requirements will be further defined.
Protection of Audit Information| Cryptographic Protection
AU-9 (3)
Peace Corps information systems must implement cryptographic mechanisms to protect the integrity of audit information and audit tools.
categorization systems that currently don’t exist within Peace Corps. If any High systems are introduced in the future this requirements will be further defined.
Protection of Audit Information| Access by Subset of Privileged Users
AU-9 (4)
Peace Corps authorizes access to management of audit functionality to only SP&G and Security and Incident Response teams.
Non-Repudiation
AU-10
X
Control Number
Security Baselines
| Low |
| Moderat e |
| High |
System Owners must ensure that information systems protect against an individual (or process acting on behalf of an individual) falsely denying having performed a particular action (e.g., created information, sent a message, approved information to indicate concurrence, etc.)
This security control only applies to High Categorization systems that currently don’t exist within Peace Corps. If any High systems are introduced in the future this requirements will be further defined.
Audit Record Retention
AU-11
Peace Corps retains audit records for 2 years to support investigations of security incidents and where applicable 7 years to meet Federal Tax Information (FTI) requirements
Audit Generation
AU-12
Peace Corps must ensure that information systems:
a. Provide audit record generation capability for the list of auditable events in AU-2 for all information system components;
b. Allows SP&G, System Owner or personnel managing information system to select which auditable events are to be audited by specific components of the information system; and
c. Generate audit records for the list of audited events in AU-2 with the content defined in AU-3.
Audit Generation| System-Wide/Time-Correlated Audit Trail
AU-12 (1)
Audit records from all information system and network components where audit capability is deployed/available must be compiled into a system- wide (logical or physical) audit trail that is time- correlated to within a two-minute level of tolerance for relationships between time stamps of individual records in the audit trail.
Control Number
Security Baselines
| Low |
| Moderat e |
| High |
Categorization systems that currently don’t exist within Peace Corps. If any High systems are introduced in the future this requirements will be further defined.
Audit Generation| Changes by Authorized Individuals
AU- 12(3)
The information system provides the capability for system administrators to change the auditing to be performed on information system components based on specific event criteria within specific timeframes necessary to address certain threat situations and/or facilitate audit reduction, analysis, and reporting.
Categorization systems that currently don’t exist within Peace Corps. If any High systems are introduced in the future this requirements will be further defined.
Table 30. Audit and Accountability Control Family Security Baselines
Security Assessment and Authorization (CA)
Security Assessment and Authorization is the process of formal assessment, and authorization of system security controls that protect IT systems and data stored in and processed by those systems. This process recognizes, evaluates, and assigns responsibility for the risk of operating an IT system, encompasses the system’s life cycle, and ensures that the risk of operating a system is recognized, evaluated, and accepted. The Authorization process implements the concept of “adequate security,” or security commensurate with risk, including the magnitude of harm resulting from the unauthorized access, use, disclosure, disruption, modification, or destruction of information, which is defined in OMB Circular A-130.
Control Number
Security Baselines
| Low |
| Moderat e |
| High |
Security Assessment and Authorization Policy and Procedures
CA-1
Reference the Security Assessment and Authorization (CA) Policy section of MS542.
The…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .