Attachment 5 - IPS 1-17 Information Security Program.docx

DOCX document 534 KB Posted

Attached to
Peace Corps MAC Support Services Federal contract opportunity
Solicitation number
1145PC20Q0022
Issued by
Peace Corps

View the file

Other files for this federal contract opportunity

Other files attached to Peace Corps MAC Support Services, newest first.
File Type Posted
Attachment 1 - 209-Vulnerability Management Plan-2019.04_Final.pdf PDF
1145PC20Q0022 Final 5.22.20.doc DOC document
Attachment 4 - MS 899 Breach Notification Response Plan.docx DOCX document
Attachment 3 - CISA_Incident Reporting Requirements Update _March 29 2019.pdf PDF
Attachment 2 - 701-Incident Response Plan 2019.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Information Security Control Catalog

(ISCC)

Effective Date:

March 15, 2018

Prepared by:

Office of the Chief Information Officer Security, Policy, & Governance Branch (SP&G) 1122 20th Street NW Washington, D.C. 20526

Peace Corps Information Security Control Catalog v 1.0 March 15, 2018

Annual Review Record

The Information Security Control Catalog shall be reviewed annually with the review date and reviewer name recorded in the table below.

Reviewer
Review Date
Comments

Revision History

VERSION (YYMMDD)

AUTHOR

DESCRIPTION OF REVISIONS

v .1
C. Bursenos
Initial draft
v .11
C. Bursenos
Final draft
180313
M. Terry
Final

Sensitive but Unclassified Information

Executive Summary

This document is subordinate to Peace Corps MS 542 Information Security Policy and is designed to support Peace Corps’ Information System Risk Management Framework (RMF) Process. This guide consolidates minimum baseline guidance for each of the National Institute for Standards and Technology (NIST) privacy and security control families for all Federal Information Security Modernization Act (FISMA) reportable systems. A FISMA reportable system is any IT system used to store, process or transmit Peace Corps owned information to support the mission of Peace Corps. This includes cloud or contractor owned/managed systems.

This document is organized into three sections as follows:

Section 1 – Introduction: Describes the background, purpose, scope, and governance of this document.

Section 2 - Control Catalog: Identifies the minimum controls to be implemented where possible. Contains a complete list of privacy and security controls with Peace Corps specific criteria.

Appendices containing a list of references, acronyms, a glossary of terms, and a list of security laws and federal regulations referenced.

Information Security Control Catalog Peace Corps

Sensitive but Unclassified Information

Table of Contents

1.Introduction4
1.1Background4
1.2Purpose4
1.3Scope5
1.4Audience5
1.5Authority5
1.6Effective Date6
1.7Governance6
1.8Compliance6
1.9Risk Acceptance7
1.10Roles and Responsibilities7
2.Control Catalog8
2.1Security Controls8
2.1.1Access Control (AC)8
2.1.2Awareness and Training (AT)24
2.1.3Audit and Accountability (AU)27
2.1.4Security Assessment and Authorization (CA)36
2.1.5Configuration Management (CM)43
2.1.6Contingency Planning (CP)56
2.1.7Identification and Authentication (IA)68
2.1.8Incident Response (IR)103
2.1.9Maintenance (MA)108
2.1.10Media Protection (MP)114
2.1.11Physical and Environmental Protection (PE)119
2.1.12Planning (PL)127
2.1.13Personnel Security (PS)131
2.1.14Risk Assessment (RA)135
2.1.15System and Services Acquisition (SA)139
2.1.16System and Communications Protection (SC)147
2.1.17System and Information Integrity (SI)156
Appendix A: REFERENCES164
Appendix B: ACRONYMS167
Appendix C: GLOSSARY170
Appendix D: RELEVANT LAWS AND REGULATIONS201
2.1.18US Public Laws201
2.1.19Office of Management and Budget (OMB) Regulations203
2.1.20Peace Corps Administrative and Organization Orders204
2.1.21Other204

Introduction

Loss or disruption of a critical information system or services could have major ramifications to the mission, business processes, and volunteer activities that Peace Corps has been established to support. Security controls are the safeguards and countermeasures prescribed for an information system that are designed to: (i) protect the confidentiality, integrity, and availability of information that is processed, stored, and transmitted by those information systems; and to (ii) satisfy a set of defined security requirements established by the Peace Corps in response to applicable laws, regulations, executive orders and Federal policies. Through the careful selection and implementation of controls, Peace Corps can adequately mitigate the risk incurred by using information and information systems in the execution of Peace Corps’ mission and business function.

Background

The Federal Information Security Modernization Act (FISMA) of 2014 provides a comprehensive framework for ensuring the effectiveness of information security controls over information resources that support Federal operations and assets, and defines “adequate security” as security commensurate with the risk and magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of information. This includes ensuring that systems and applications used by Peace Corps operate effectively and provide appropriate confidentiality, integrity, and availability with cost effective management, operational and technical controls.

In support of FISMA, NIST Federal Information Processing Standards (FIPS) Publication 200, Minimum Security Requirements for Federal Information and Information Systems, directs that all Federal Government agencies ensure that adequate security controls be implemented for their information subsystems. The guidelines provided in FIPS 200 are applicable to all federal information systems other than those systems designated as national security systems as defined in 44 U.S.C., Chapter 35, Coordination of Federal Information Policy § 3542. This document describes how the Peace Corps will comply with FISMA and other related directives.

The security policies captured in this document were developed to meet the minimum legally and federally mandated requirements for information security and are based on the Federal Government standards and procedures issued by the Office of Management and Budget (OMB), NIST, and the General Services Administration (GSA).

Purpose

The purpose of this Peace Corps Information Security Catalog (ISC) is to document Peace Corps security and privacy policies and minimum control standards as required by FISMA and provide a common reference to be used by Peace Corps personnel. It identifies and documents the minimum security controls as required by FIPS 200, Minimum Security Requirements for Federal Information and Information Systems, as defined by the NIST Special Publication (SP) 800-53, Security and Privacy Controls for Federal Information Systems and Organizations, and commensurate with a system’s security categorization defined by FIPS 199, Standards for Security Categorization of Federal Information and Information Systems. This document establishes the minimal baseline requirements for each control but more stringent requirements enforced at the discretion of the systems Authorizing Official.

CSAM is the agency’s official repository for all control guidance. If incongruences exist between CSAM and the ISCC, CSAM will be considered authoritative.

Scope

This document reflects the control minimal baselines established in CSAM. The content applies to all Peace Corps employees and contractor employees accessing or using Peace Corps information systems or data processed, transmitted, and/or stored on Peace Corps information subsystems; and to contractor employees providing services to the Peace Corps who use Peace Corps information systems or data. This document applies to all Peace Corps information systems and supporting resources, independent of size, location, or interconnection(s). Additionally, this document applies to all types of media used to store Peace Corps agency sensitive information and personally identifiable information (PII) which includes, but is not limited to: hard drives, compact disks, DVDs, magnetic media, and solid-state media (Universal Serial Bus (USB) flash drives). Finally, this document applies to all media output to include digital and hard-copy (paper records) formats that contain Peace Corps agency-sensitive information and PII.

This content also applies to Peace Corps owned and operating information systems and systems owned or operated by contractor employees, guest researchers, collaborators, and other federal agencies that help to carry out the Peace Corps mission, whether or not such information systems or equipment are owned or leased by the government or on government property. The security and privacy policies set forth in this document apply to all IT procurement activities to include cloud based services as defined by NIST in SP 800-145, as well as other applicable regulations, policies and laws.

Audience

This document will be made available to all federal and non-federal personnel who use, are involved with, or have responsibilities supporting the Solution Delivery Framework. Documents will be available in the Peace Corps Library on the Peace Corps Intranet. Document references under each control family are authorized by the associated policy and becomes an extension of the control family policy. Implementation guidance is addressed in Section 2 Security and Privacy Controls.

Authority

This document is issued under the authority of the Peace Corps Chief Information Security Officer (CISO).

Effective Date

This document is effective immediately when signed by the CISO, superseding any previous versions of this document. System Owners have 180 days to comply per policy. Compliance with CSAM controls beyond the specified timeframe shall be managed through the Plan of Action and Milestones (POA&Ms) or through a Risk Acceptance Letter.

Governance

This document supplements 542 and provides Organizationally Defined Values (ODVs) required by NIST SP 800-53. CSAM is the agency’s official repository for all security control guidance in Section 2 Control Catalog that support policy statements established in MS542. If incongruences exist between CSAM and the ISCC, CSAM will be considered authoritative.

SP&G will review and, as necessary, update all CSAM controls and policy statements at least annually or when new legal, regulatory or authoritative guidance is issued.

Request for changes to this document or CSAM should be directed to SP&G through ciso@peacecorps.gov.

SP&G will review and execute any necessary updates to CSAM controls documented in Section 2 Control Catalog. SP&G and the Privacy office will solicit stakeholder comments and adjudicate all comments received during the comment period. Once updates are finalized, SP&G will present the changes to the OCIO. The CISO will authorize the update to be incorporated into CSAM.

System owners will be expected to comply with new control requirements no later than the next assessment cycle.

Compliance

Compliance with the CSAM control requirements are mandatory. The ISCC is intended to provide a consolidated reference for Peace Corps controls documented in CSAM. It is Peace Corps’ policy that personnel and information systems abide by or exceed the requirements outlined in this document for each NIST SP 800-53 family of controls. SP&G will assess Peace Corps’ adherence with this document through various oversight and compliance measures.

Individuals found to be non-compliant with this policy may be subject to corrective action including any or all of the following:

a. Employee discipline under MS 647.

b. Contractor suspension or debarment.

c. Removal of an individual’s authority to access Peace Corps information systems.

Peace Corps information systems are required to have a current Authorization-to-Operate (ATO) designated by the Peace Corp Authorizing Official. A system that is found to be non-compliant with this policy shall be subject to CIO and CPO review and action.

Risk Acceptance

The Peace Corps Authorizing Official will approve the tailoring of security control baselines.

In cases where an information system cannot comply with a particular privacy or security control for technical or financial reasons, or because it precludes Peace Corps from supporting mission or business functions, justifications for non-compliance must be documented using the Risk Acceptance process. The Risk Acceptance memo must be formally signed by the Authorizing Official (AO). Risk Acceptance memos are only valid for one year from the date of the AO’s signature and must be reviewed on an annual basis. It is the responsibility of the Information System Security Officer (ISSO) to maintain the Risk Acceptance memo in Peace Corps’ Cyber Security and Assessment Methodology (CSAM) tool and to review the memo on an annual basis as part of the Continuous Monitoring program.

The risk acceptance process shall be implemented as follows:

1. A Risk Acceptance Letter will be submitted to the AO, via the SO or ISSM;

2. Risk Acceptance Letters will be addressed from the SO or ISSM;

3. Risk Acceptance Letters will list the controls that cannot be fully implemented along with the CSAM-derived Risk Impact, justify the risk, and compensating controls in-place to meet the spirit of the control;

4. Corrective action items will be specified in the Risk Acceptance Letter, if appropriate;

5. Risk Acceptances will result in a POA&M describing the plan to come into conformance with policy, and the mitigating control;

6. Risk Acceptance Letters must be reviewed at least annually and after major changes to the system. Evidence of this review must be documented and uploaded into CSAM.

Roles and Responsibilities

The responsibility to protect Peace Corps information and technological resources extends to all nonpublic users and requires collaboration across various offices to coordinate activities associated with the Peace Corps security posture, technological environment, and overall risk management. The key roles and responsibilities for carrying out the provisions of this ISCC are outlined in the MS542 Peace Corps Information Security Policy.

Designation letters must be maintained for the following roles:

a) Authorizing Official (AO),

b) System Owner (SO),

c) Information System Security Managers (ISSM), and

d) Information System Security Officers (ISSO)

Each assigned individual must certify receipt of the designation letter indicating their commitment to adhere to the policies established by Peace Corps. SP&G will conduct workforce training for each role to ensure each individual understands their role in the Risk Management Framework and are properly trained.

Control Catalog Security Controls

The following section describe the security controls required for low, moderate, and high baselines information systems, as defined by NIST 800-53 Revision 4 and Peace Corps Security policies. The requirements documented herein represent the minimum security requirements for each security baseline. Additionally, System Owners at their discretion may elect to include additional controls documented below, including non-selected security controls (those not required for any systems). If non-selected controls are included in an information system baseline, it is the responsibility of the System Owner, with the guidance of the ISSM or ISSO, to define any control assignments and selections in the information system security plan. Peace Corps maintains low and moderate systems; therefore, the high security controls are only included in this catalog should a system owner wish to select a high security control and for consistency purposes. The bolded text within each control statement under the Control Name/Requirement column is the minimum organizationally defined parameters (ODPs) for the agency.

Access Control (AC)

The objective of Access Control is to address the considerations that will help to ensure that Peace Corps IT Resources and information assets are properly protected against unauthorized access while meeting the access requirements for authorized users. System Owners are responsible for ensuring all applicable AC controls address the requirement at the system level.

Control Number
Control Name/Requirement
Security Baselines
Low
Moderate
High

Access Control Policy and Procedures

AC-1

Reference Access Control Policy section of MS542.

The policy and procedures must be reviewed and updated at least annually.

X

Account Management

AC-2

All Peace Corps information systems must manage information system accounts by:

a. Identifying account types (i.e., general user (individual, group), system, application, guest, elevated and temporary);

b. Assigning account managers for

Control Number
Control Name/Requirement
Security Baselines
Low
Moderate
High

information system accounts;

c. Establishing conditions for group membership;

d. Identifying authorized users of the information system and specifying access privileges and other attributes for each account;

e. Requiring appropriate approvals from the ISSO for requests to establish accounts;

f. Creating, enabling, modifying, disabling, and removing information system accounts in accordance with the Enterprise Systems and Services Access Control Process;

g. Monitoring the use of information system accounts;

h. Notifying account managers when accounts are no longer required and when information system users are terminated, transferred, or information system usage or need to-know/need-to-share changes;

i. Authorizing access to the system based on:

(i) a valid access authorization; (ii) intended system usage; and (iii) other attributes as required by the organization or associated missions/business functions;

j. Reviewing accounts for compliance with account management requirements at least annually; and

k. Establishing a process for reissuing shared or group account credentials when individuals are removed from the group.

Account Management| Automated System Account Management

AC-2 (1)

Automated mechanisms should be employed to support the management of information system accounts.

Account Management| Removal of Temporary/Emergency Accounts

AC-2 (2)

Information systems automatically disable temporary and emergency accounts 24 hours after creation.

Control Number
Control Name/Requirement
Security Baselines
Low
Moderate
High

Account Management| Disable Inactive Accounts

AC-2 (3)

Information systems must automatically disable inactive accounts after 90 days; All system and application account types must be reviewed at least annually and disabled if no longer required.

Account
Management| Automated Audit
Actions

AC-2 (4)

Automated mechanisms should be employed to ensure that account creation, modification, disabling, and termination actions are audited and, as required, the ISSO must be notified.

Account Management| Inactivity Logout

AC-2 (5)

The Peace Corps should require that users log out when access to the system is no longer required to fulfill their job duties.

This enhancement only applies to High categorization systems that currently don’t exist within Peace Corps. If any High systems are introduced in the future this requirements will be further defined.

Account Management| Account Monitoring/Atypical Use

AC-2 (12)

Peace Corps should:

a. Monitor information system accounts for anomalous use such as accessing information systems at certain times of the day and from locations that are not consistent with the normal usage patterns of individuals working in organizations; and

b. Report atypical usage of information system accounts to system administrators and/or incident response personnel.

categorization systems that currently don’t exist within Peace Corps. If any High systems are introduced in the future requirements will be further defined.

Control Number
Control Name/Requirement
Security Baselines
Low
Moderate
High

Account Management| Disable Accounts for High-Risk Individuals

AC-2 (13)

Peace Corps must disable accounts of users posing a significant risk within an immediate time period of discovery of the risk.

categorization systems that currently don’t exist within Peace Corps. If any High systems are introduced in the future requirements will be further defined.

Access Enforcement

AC-3

Peace Corps must ensure that all information systems enforce assigned authorizations for logical access to the information system.

Information Flow Enforcement

AC-4

The information system enforces approved authorizations for controlling the flow of information within the system and between interconnected systems through the use of controlled interfaces (CI) that implement controls and requirements delineated in Peace Corps’ Information Security Architecture.

A CI is a mechanism that facilitates adjudicating the security policies of different interconnected information systems (e.g., controlling the flow of information into or out of an interconnected system).

Separation of Duties

AC-5

All Peace Corps information systems must:

a. Separate duties of individuals to prevent the potential for abuse of authorized privileges and helps to reduce the risk of malevolent activity without collusion;

b. Document separation of duties; and

c. Define information system access authorizations to support separation of duties.

Least Privilege

AC-6

Peace Corps information systems must employ the concept of least privilege, allowing only authorized accesses for users (and processes acting on behalf of users) which are necessary to accomplish

Control Number
Control Name/Requirement
Security Baselines
Low
Moderate
High

assigned tasks in accordance with Peace Corps missions and business functions.

Least Privilege| Authorize Access to Security Functions

AC-6 (1)

Access to establish system accounts, configure access authorizations (i.e., permissions, privileges), set events to be audited, and set intrusion detection parameters must be explicitly authorized.

Least Privilege| Non-Privileged Access for Non-Security Functions

AC-6 (2)

Users of information system accounts, or roles, with access to establish system accounts, configure access authorizations (i.e., permissions, privileges), set events to be audited, and set intrusion detection parameters must use non- privileged accounts, or roles, when accessing other system functions, and use of privileged accounts must be audited for such functions.

Least Privilege| Network Access to Privileged Commands

AC-6 (3)

Peace Corps authorizes network access to perform remote administration only for compelling operational needs and documents the rationale for such access in the security plan for the information system.

categorization systems that currently don’t exist within Peace Corps. If any High systems are introduced in the future requirements will be further defined.

Least Privilege| Privileged Accounts

AC-6 (5)

Peace Corps restricts privileged accounts on the information system to system administrators.

Least Privilege| Auditing Use of Privileged Functions

AC-6 (9)

Peace Corps information systems must audit the execution of privileged functions.

Control Number
Control Name/Requirement
Security Baselines
Low
Moderate
High

Auditing the use of privileged functions is one way to detect such misuse, and in doing so, help mitigate the risk from insider threats and the advanced persistent threat.

Least Privilege| Prohibit non-Privileged Users from Executing Privileged Functions

AC-6 (10)

Peace Corps information systems must prevent non- privileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures.

Unsuccessful Login Attempts

AC-7

Peace Corps information systems accounts must:

a. Enforce a limit of five (5) consecutive invalid login attempts by a user during a 30 minute time period; and

b. Automatically lock the account until released by an administrator, when the maximum number of unsuccessful attempts is exceeded. This control applies regardless of whether the login occurs via a local or network connection.

System Use Notification

AC-8

The information system:

a. Displays to users standard notification within the Peace Corps Directive IM-05-02 before granting access to the system that provides privacy and security notices consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance and states that:

1. Users are accessing a U.S. Government information system;

2. Information system usage may be monitored, recorded, and subject to audit;

Control Number
Control Name/Requirement
Security Baselines
Low
Moderate
High

3. Unauthorized use of the information system is prohibited and subject to criminal and civil penalties; and

4. Use of the information system indicates consent to monitoring and recording;

b. Retains the notification message or banner on the screen until users acknowledge the usage conditions and take explicit actions to log on to or further access the information system; and

c. For publicly accessible systems:

1. Displays system use information that provides privacy and security notices consistent with applicable federal laws, Executive orders, directives, policies, regulations, standards, and guidance, before granting further access;

2. Displays references, if any, to monitoring, recording, or auditing that are consistent with privacy accommodations for such systems that generally prohibit those activities; and

3. Includes a description of the authorized uses of the system.

Warning banners is displayed when individuals log in to the information system. System use notification is for information system access that includes an interactive login interface with a human user and does not require notification when an interactive interface does not exist.

The following is the official Peace Corps warning banner:

WARNING!!! WARNING!!! WARNING!!!

This computer system is the property of the United States Peace Corps. It may only be accessed and used for official Government business by authorized personnel.

Unauthorized access or use of this computer system is strictly prohibited and may subject violators to criminal, civil, and/or administrative action. The Peace Corps may monitor any activity, information, or communication on the system.

All activity, communication, and information on this system may be intercepted, recorded, read, copied, retrieved, and disclosed by and to authorized personnel for official purposes, including criminal investigations.

Users have no right of privacy or any reasonable expectation of privacy in the use of this computer system and any communication or information stored within the system.

Access or use of this computer system by any person, whether authorized or unauthorized, constitutes consent to all of these terms.

Control Number
Control Name/Requirement
Security Baselines
Low
Moderate
High

Concurrent Session Control

AC-10

Peace Corps information systems should limit the number of concurrent sessions for privileged and unprivileged accounts to a maximum of 2 concurrent sessions for privileged accounts and 5 concurrent sessions for unprivileged. Concurrent sessions must be kept to as low as possible based on risk.

Control Number
Control Name/Requirement
Security Baselines
Low
Moderate
High

Session Lock

AC-11

Peace Corps information systems must:

a. Prevent further access to the system by initiating a session lock after 15 minutes of inactivity or upon receiving a request from a user; and

b. Retain the session lock until the user reestablishes access using established identification and authentication procedures.

Session Lock| Pattern Hiding Displays

AC-11 (1)

Peace Corps information systems must conceal, via the session lock, information previously visible on the display with a publicly viewable image.

Session Termination

AC-12

The information system automatically terminates a user session after 30 minutes of inactivity or at the end of the session.

Permitted Actions without Identification or Authentication

AC-14

Peace Corps does the following:

a. Identifies [access only to public information] that can be performed on the information system without identification or authentication consistent with organizational missions/business functions; and

b. Documents and provides supporting rationale in the security plan for the information system, user actions not requiring identification or authentication.

Control Number
Control Name/Requirement
Security Baselines
Low
Moderate
High

Remote Access

AC-17

Peace Corps must ensure that:

a. Usage restrictions, configuration/connection requirements and implementation guidance for each type of allowed remote access method are established and documented; and

b. Remote access to information systems is authorized prior to allowing such connection;

X
X
X

Remote Access| Automated Monitoring/Control

AC-17 (1)

Automated mechanisms must be employed to facilitate the monitoring and control of remote access methods.

Remote Access| Protection of Confidentiality/Integrity Using Encryption

AC-17 (2)

Cryptographic mechanisms must be used to protect the confidentiality and integrity of remote access sessions.

Remote Access| Managed Access Control Points

AC-17 (3)

All remote access must be controlled through a limited number of managed access points.

Remote Access| Privileged Commands/ Access

Control Number
Control Name/Requirement
Security Baselines
Low
Moderate
High

AC-17 (4)

Execution of privileged commands and access to security-relevant information via remote access must be authorized only for compelling operational needs as documented in the System Security Plan.

Wireless Access

AC-18

Peace Corps must ensure that:

a. Usage restriction, configuration/connection requirements, and implementation guidance for wireless access are established; and

b. Wireless access to the information system is authorized prior to allowing such connection.

Not Applicable if wireless access to information subsystems is not permitted.

Wireless Access| Authentication and Encryption

AC-18 (1)

All Peace Corps information systems must protect wireless access to the system using authentication of users and devices and encryption.

Not Applicable if wireless access to information systems is not permitted.

Wireless Access| Restrict Configuration by Users

AC-18 (4)

Peace Corps should identify and explicitly authorize users allowed to independently configure wireless networking capabilities. Peace Corps ensures that users cannot independently configure wireless networking capabilities.

This enhancement only applies to High categorization systems that currently don’t exist within Peace Corps. If any High systems are introduced in the future this requirements will be further defined.

Control Number
Control Name/Requirement
Security Baselines
Low
Moderate
High

Wireless Access| Antennas/Transmission Power Levels

AC-18 (5)

Peace Corps should select radio antennas and calibrates transmission power levels to reduce the probability that usable signals can be received outside of organization-controlled boundaries.

categorization systems that currently don’t exist within Peace Corps. If any High systems are introduced in the future this requirements will be further defined.

Access Control for Mobile Devices

AC-19

a.Usage restrictions, configuration requirements, connection requirements, and implementation guidance are established for Peace Corps-controlled mobile devices; and
b.The connections of mobile devices to organizational information systems are authorized.

System Owners, in coordination with the CISO, must authorize the use of portable and mobile devices based on system sensitivity and risk level.

Access Control for Mobile Devices| Full Device/Container-Based Encryption

AC-19 (5)

Peace Corps employs full-device encryption and container-based encryption to protect the confidentiality and integrity of information on

Control Number
Control Name/Requirement
Security Baselines
Low
Moderate
High

all Peace Corps-owned mobile devices and personally owned devices that have been approved for remote access, respectively.

Use of External Information Systems

AC-20

Peace Corps should establish terms and conditions for all external information systems, consistent with any trust relationships established with other organizations owning, operating, and/or maintaining external information systems, allowing authorized individuals to:

a. Access the information system from external information systems; and

b. Process, store, or transmit organization- controlled information using external information systems.

External information systems include, but are not limited to: (i) personally owned information systems (e.g., computers, cellular telephones, or personal digital assistants); (ii) privately owned computing and communications devices resident in commercial or public facilities (e.g., hotels, convention centers, or airports); (iii) information systems owned or controlled by nonfederal governmental organizations; and (iv) federal information systems that are not owned by, operated by, or under the direct supervision and authority of the organization.

Use of External Information Systems| Limits on Authorized Use

AC-20 (1)

Peace Corps must ensure that only permitted authorized individuals use an external information system to access the information system or to process, store, or transmit organization-controlled information only when:

a. The implementation of required security controls on the external system as specified in the organization’s information security policy and security plan is verified; and/or

Control Number
Control Name/Requirement
Security Baselines
Low
Moderate
High

b. approved information system connection or processing agreements with organizational entity hosting the external information system are retained.

Use of External Information Systems| Portable Storage Devices

AC-20 (2)

Peace Corps must ensure that the use of Peace Corps-controlled portable storage devices by authorized individuals on external information systems is restricted, in accordance with the Peace Corps requirements.

Information Sharing

AC-21

Peace Corps must:

a. Facilitate information sharing by enabling authorized users to determine whether access authorizations assigned to the sharing partner match the access restrictions on the information for contract sensitive information, PII, or proprietary information as contractually obligated ; and

b. Employ manual processes to assist users in making information sharing/collaboration decisions.

Publicly Accessible Content

AC-22

a. Individuals are designated to post information onto Peace Corps information systems that is publicly accessible;

b. Authorized individuals are trained to ensure that publicly accessible information does not contain nonpublic information;

c. Proposed content of publicly accessible information for nonpublic information is reviewed prior to posting on Peace Corps information systems to ensure that nonpublic information is not included; and

d. The content on publicly accessible Peace Corps information systems is reviewed for nonpublic information at least annually;

Control Number
Control Name/Requirement
Security Baselines
Low
Moderate
High

and nonpublic information is removed from publicly accessible Peace Corps information systems, if discovered.

Table 28. Access Control - Control Family Security Baselines Awareness and Training (AT)

The entire Peace Corps user base must have the knowledge to recognize potential security concerns and understand the channels available to properly report those concerns to the appropriate authorities for action. In addition, those authorities need the necessary tools and skills to carry out their assigned duties effectively. Awareness and training ensures that every individual involved in using and managing IT:

· Understand their roles and responsibilities related to the organizational mission;

· Understand the organization’s security policy, procedures, and practices; and

· Have at least adequate knowledge of the security and privacy controls required and available to protect the IT resources for which they are responsible.

Control Number

Control Name/Requirement Security Baselines

Low
Moderat e
High

Security Awareness and Training Policy and Procedures

AT-1

Reference the Awareness and Training (AT) section of MS542.

The policy and procedures must be reviewed and updated at least annually.

Security Awareness Training

AT-2

Peace Corps provides basic security awareness training to information system users (including managers, senior executives, and contractors):

a. As part of initial training for new users;

b. When required by information system changes; and

c. At least annually thereafter.

Security Awareness| Insider Threat

AT-2 (2)

X
X

Control Number

Security Baselines

Low
Moderat e
High

Peace Corps must include security awareness training on recognizing and reporting potential indicators of insider threat.

Potential indicators and possible precursors of insider threat can include behaviors such as inordinate, long-term job dissatisfaction, attempts to gain access to information not required for job performance, unexplained access to financial resources, bullying or sexual harassment of fellow employees, workplace violence, and other serious violations of organizational policies, procedures, directives, rules, or practices etc.

Role-Based Security Training

AT-3

Peace Corps provides role-based security training to personnel with assigned security roles and responsibilities:

a. Before authorizing access to the information system or performing assigned duties;

b. When required by information system changes; and

c. At least annually thereafter.

Security Training Records

AT-4

Peace Corps should ensure that:

a. Individual information systems security training activities, including basic security awareness training and specific information systems security training are documented and monitored; and

b. Individual training records are retained for two (2) years (current year and past year).

Table 29. Awareness and Training Control Family Security Baselines

Audit and Accountability (AU)

Audit trails maintain a record of activities by a system or user. In conjunction with appropriate tools and procedures, audit trails can provide individual accountability, a means to reconstruct events, detect intrusions, and identify problems. System audit trails, or event logs, provide a record of events in support of activities to monitor and enforce the IT system security policy.

All auditable events are subject to recording and routine review by the Peace Corps CISO and auditors for inappropriate or illegal activity. System owners must ensure the protection of system event logs commensurate with the highest level of sensitivity of the information residing on the system.

Control Number

Security Baselines

Low
Moderat e
High

Audit and Accountability Policy

AU-1

Reference Audit and Accountability (AU) Policy section of MS542.

The policy must be reviewed and updated at least annually.

X
X
X

Audit Events

AU-2

Peace Corps ensures that:

a. Based on system impact level, Peace Corps information systems are capable of auditing the following events:

1. Account creation, modification, disabling, and deletion

2. Administrative permissions executed on user accounts

3. Administrative permissions executed on system resources

4. Failed login attempts and account lockout

5. Use of “su”, “pu”, “root”, “administrator”, or equivalent accounts

6. Activity log roll-over, deletion, or editing, and

7. All computer-readable data extracts from databases containing PII;

Control Number

Security Baselines

Low
Moderat e
High

b. Security audit function is coordinated with other Peace Corps entities requiring audit-related information to enhance mutual support and to help guide the selection of auditable events;

c. Based on current threat information and ongoing assessment of risk, a documented determination is made that the list of auditable events is deemed adequate to support after- the-fact investigations of security incidents or if additional controls should be implemented and Deviations from the list of auditable events due to system audit functionality capabilities, along with justifications, must be documented in relevant system security plans.

Audit Events| Reviews and Updates

AU-2 (3)

Peace Corps reviews and updates the list of audited events at least annually.

Content of Audit Records

AU-3

The Peace Corps information systems must generate audit records that contain sufficient information to establish what type of event occurred, when (date and time) the event occurred, where the event occurred, the source of the event, the outcome of the event, and the identity of any individuals or subjects associated with the event.

Content of Audit Records| Additional Audit Information

AU-3 (1)

The Peace Corps information system generates audit records containing at a minimum: :

a. The date and time of the event;

b. The software or hardware component of the information system;

c. where the event occurred;

d. The type of event;

e.The subject identity (the user of the component in which the event occurred); and

Control Number

Security Baselines

Low
Moderat e
High

e. The outcome (success or failure) of the event.

Content of Audit Records| Centralized Management of Planned Audit Record Content

AU-3 (2)

The Peace Corps information system provides centralized management and configuration of the content to be captured in audit records generated by information system components.

categorization systems that currently don’t exist within Peace Corps. If any High categorization systems are introduced in the future this requirement will be further defined.

Audit Storage Capacity

AU-4

Peace Corps allocates audit record storage capacity in accordance with

Response to Audit Processing Failures

AU-5

Peace Corps ensures that, in the event of an audit processing failure, information systems:

Alerts Peace Corps-CERT in the event of an audit processing failure; and Overwrite oldest audit records first.

Response to Audit Processing Failures| Audit Storage Capacity

AU-5 (1)

Information systems must provide a warning to system administrators immediately when allocated audit record storage volume reaches 75% of maximum audit record storage capacity.

categorization systems that currently don’t exist within Peace Corps. If any High categorization systems are introduced in the future this requirement will be further defined.

Control Number

Security Baselines

Low
Moderat e
High

Response to Audit Processing Failures| Real-Time Alerts

AU-5 (2)

Information systems must provide a real-time alert to system administrators when the following audit failure events occur:

a. Account creation, modification, disabling, and deletion;

b. Administrative permissions executed on user accounts (i.e., inclusion in access groups, reset of password, account lockout override);

c. Administrative permissions executed on system resources (i.e., addition of users or groups to access lists, creation of share points, creation of new access groups, change of access group permissions);

d. Failed login attempts and account lockout;

e. Use of “su,” “pu,” “root,” “administrator,” or equivalent accounts;

f. Activity log roll-over, deletion, or editing; and

g. All computer-readable data extracts from databases containing personally identifiable information (PII);

categorization systems that currently don’t exist within Peace Corps. If any High systems are introduced this requirements will be further defined.

Audit Review, Analysis, and Reporting

AU-6

a. Audit records for information systems are reviewed and analyzed monthly for indications of unusual or suspicious activity and

b. Any findings are reported to CSIRT.

Control Number

Security Baselines

Low
Moderat e
High

Audit Review, Analysis, and Reporting| Processing Integration

AU-6 (1)

Information systems should integrate audit review, analysis, and reporting processes to support Peace Corps processes for investigation and response to suspicious activities.

Audit Review, Analysis, and Reporting| Correlate Audit Repositories

AU-6 (3)

Peace Corps should ensure that information system audit records are analyzed and correlated across different repositories to gain organization-wide situational awareness.

Audit Review, Analysis, and Reporting| Integration/Scanning and Monitoring Capabilities

AU-6 (5)

Peace Corps should integrate analysis of audit records with analysis of information system monitoring information to further enhance the ability to identify inappropriate or unusual activity.

This enhancement only applies to High categorization systems that currently don’t exist within Peace Corps. If any High systems are introduced in the future this requirements will be further defined.

Audit Review, Analysis, and Reporting| Correlation with Physical Monitoring

AU-6 (6)

Peace Corps should correlate information from audit records with information obtained from monitoring physical access to further enhance the ability to identify suspicious, inappropriate, unusual, or malevolent activity.

This enhancement only applies to High categorization systems that currently don’t exist within Peace Corps. If any High systems are introduced

Control Number

Security Baselines

Low
Moderat e
High

in the future this requirements will be further defined.

Audit Reduction and Report Generation

AU-7

Peace Corps information systems must provide an audit reduction and report generation capability that:

a. Supports on-demand audit review, analysis, and reporting requirements and after-the-fact investigations of security incidents; and

b. Does not alter the original content or time ordering of audit records.

Audit Reduction and Report Generation| Automatic Processing

AU-7 (1)

Information systems should provide the capability to automatically process audit records for events of interest based upon selectable event criteria.

Events of interest could be for example: identities of individuals, event type, event dates, event location, IP address involved, information objects, or system resources involved, etc.

Time Stamps

AU-8

a. Use internal system clocks to generate time stamps for audit records; and

b. Record time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT) and meets to the thousandth of a second.

Time Stamps| Synchronization with Authoritative Time Source

AU-8 (1)

Compare the internal information system clocks at least daily with authoritative Network Time Protocol (NTP) servers and Synchronize the

Control Number

Security Baselines

Low
Moderat e
High

internal system clocks to the authoritative time source when the time difference is greater than 5 minutes.

Protection of Audit Information

AU-9

Peace Corps information systems must protect audit information and audit tools from unauthorized access, modification, and deletion.

Protection of Audit Information| Audit Backup on Separate Physical Systems/Components

AU-9 (2)

Peace Corps information systems must back up audit records weekly onto a physically different system or system component than the system or component being audited.

categorization systems that currently don’t exist within Peace Corps. If any High systems are introduced in the future this requirements will be further defined.

Protection of Audit Information| Cryptographic Protection

AU-9 (3)

Peace Corps information systems must implement cryptographic mechanisms to protect the integrity of audit information and audit tools.

categorization systems that currently don’t exist within Peace Corps. If any High systems are introduced in the future this requirements will be further defined.

Protection of Audit Information| Access by Subset of Privileged Users

AU-9 (4)

Peace Corps authorizes access to management of audit functionality to only SP&G and Security and Incident Response teams.

Non-Repudiation

AU-10

X

Control Number

Security Baselines

Low
Moderat e
High

System Owners must ensure that information systems protect against an individual (or process acting on behalf of an individual) falsely denying having performed a particular action (e.g., created information, sent a message, approved information to indicate concurrence, etc.)

This security control only applies to High Categorization systems that currently don’t exist within Peace Corps. If any High systems are introduced in the future this requirements will be further defined.

Audit Record Retention

AU-11

Peace Corps retains audit records for 2 years to support investigations of security incidents and where applicable 7 years to meet Federal Tax Information (FTI) requirements

Audit Generation

AU-12

Peace Corps must ensure that information systems:

a. Provide audit record generation capability for the list of auditable events in AU-2 for all information system components;

b. Allows SP&G, System Owner or personnel managing information system to select which auditable events are to be audited by specific components of the information system; and

c. Generate audit records for the list of audited events in AU-2 with the content defined in AU-3.

Audit Generation| System-Wide/Time-Correlated Audit Trail

AU-12 (1)

Audit records from all information system and network components where audit capability is deployed/available must be compiled into a system- wide (logical or physical) audit trail that is time- correlated to within a two-minute level of tolerance for relationships between time stamps of individual records in the audit trail.

Control Number

Security Baselines

Low
Moderat e
High

Categorization systems that currently don’t exist within Peace Corps. If any High systems are introduced in the future this requirements will be further defined.

Audit Generation| Changes by Authorized Individuals

AU- 12(3)

The information system provides the capability for system administrators to change the auditing to be performed on information system components based on specific event criteria within specific timeframes necessary to address certain threat situations and/or facilitate audit reduction, analysis, and reporting.

Categorization systems that currently don’t exist within Peace Corps. If any High systems are introduced in the future this requirements will be further defined.

Table 30. Audit and Accountability Control Family Security Baselines

Security Assessment and Authorization (CA)

Security Assessment and Authorization is the process of formal assessment, and authorization of system security controls that protect IT systems and data stored in and processed by those systems. This process recognizes, evaluates, and assigns responsibility for the risk of operating an IT system, encompasses the system’s life cycle, and ensures that the risk of operating a system is recognized, evaluated, and accepted. The Authorization process implements the concept of “adequate security,” or security commensurate with risk, including the magnitude of harm resulting from the unauthorized access, use, disclosure, disruption, modification, or destruction of information, which is defined in OMB Circular A-130.

Control Number

Security Baselines

Low
Moderat e
High

Security Assessment and Authorization Policy and Procedures

CA-1

Reference the Security Assessment and Authorization (CA) Policy section of MS542.

The…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .