Attachment 8 - Security Controls.xlsx
XLSX spreadsheet 78 KB Posted
- Attached to
- GSA Global Supply OCONUS Logistics Operations Support Solution - EUCOM Federal contract opportunity
- Solicitation number
- 47QSCC23R0008
- Issued by
- GSA Federal Acquisition Service
View the file
Other files for this federal contract opportunity
Show all 22
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Sheet1
| Control (or Control Enhancement) Name | Control Text | Discussion | Frequency | |
| Reference NIST Special Publication 800-53 for additional guidance and information | ||||
| https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf | I.e. monthly, annually, quarterly, etc. |
Offeror/Contractor fill in frequencies where requested below.
Define "regularly" "frequently" for reviews where applicable. Define notification timelines where applicable.
| Training | |||
| Literacy Training and Awareness | Insider Threat | Provide literacy training on recognizing and reporting potential indicators of insider threat. | Potential indicators and possible precursors of insider threat can include behaviors such as inordinate, long-term job dissatisfaction; attempts to gain access to information not required for job performance; unexplained access to financial resources; bullying or harassment of fellow employees; workplace violence; and other serious violations of policies, procedures, directives, regulations, rules, or practices. Literacy training includes how to communicate the concerns of employees and management regarding potential indicators of insider threat through channels established by the organization and in accordance with established policies and procedures. Organizations may consider tailoring insider threat awareness topics to the role. For example, training for managers may be focused on changes in the behavior of team members, while training for employees may be focused on more general observations. | Offeror/Contractor Fill In: |
Training will be provided ____________ Literacy Training and Awareness | Suspicious Communications and Anomalous System Behavior Provide literacy training on recognizing suspicious communications and anomalous behavior in organizational systems. A well-trained workforce provides another organizational control that can be employed as part of a defense-in-depth strategy to protect against malicious code coming into organizations via email or the web applications. Personnel are trained to look for indications of potentially suspicious email (e.g., receiving an unexpected email, receiving an email containing strange or poor grammar, or receiving an email from an unfamiliar sender that appears to be from a known sponsor or contractor). Personnel are also trained on how to respond to suspicious email or web communications. For this process to work effectively, personnel are trained and made aware of what constitutes suspicious communications. Training personnel on how to recognize anomalous behaviors in systems can provide organizations with early warning for the presence of malicious code. Recognition of anomalous behavior by organizational personnel can supplement malicious code detection and protection tools and systems employed by organizations. Offeror/Contractor Fill In:
Training will be provided ____________
| Role-based Training | a. Provide role-based security and privacy training to personnel before authorizing access to the systems, information, warehouses or performing assigned duties; | |
| Update training content when required by role-based, facility, and/or system changes and incorporate lessons learned from internal or external security incidents or breaches into role-based training. | Organizations determine the content of training based on the assigned roles and responsibilities of individuals as well as the security and privacy requirements of organizations and the systems to which personnel have authorized access, including technical training specifically tailored for assigned duties. Roles that may require role-based training include senior leaders or management officials (e.g., head of agency/chief executive officer, chief information officer, senior accountable official for risk management, senior agency information security officer, senior agency official for privacy), system owners; authorizing officials; system security officers; privacy officers; acquisition and procurement officials; enterprise architects; systems engineers; software developers; systems security engineers; privacy engineers; system, network, and database administrators; auditors; personnel conducting configuration management activities; personnel performing verification and validation activities; personnel with access to system-level software; control assessors; personnel with contingency planning and incident response duties; personnel with privacy management responsibilities; and personnel with access to personally identifiable information. | |
| Comprehensive role-based training addresses management, operational, and technical roles and responsibilities covering physical, personnel, and technical controls. Role-based training also includes policies, procedures, tools, methods, and artifacts for the security and privacy roles defined. Organizations provide the training necessary for individuals to fulfill their responsibilities related to operations and supply chain risk management within the context of organizational security and privacy programs. Role-based training also applies to contractors who provide services to federal agencies. Types of training include web-based and computer-based training, classroom-style training, and hands-on training (including micro-training). Updating role-based training on a regular basis helps to ensure that the content remains relevant and effective. Events that may precipitate an update to role-based training content include, but are not limited to, assessment or audit findings, security incidents or breaches, or changes in applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. | Offeror/Contractor Fill In: |
Training will be provided ____________ Reviews to update will be conducted at least __________ Role-based Training | Physical Security Controls Provide role-based training in the employment and operation of physical security controls. Physical security controls include physical access control devices, physical intrusion and detection alarms, operating procedures for facility security guards, and monitoring or surveillance equipment. Offeror/Contractor Fill In:
Training will be provided ____________
| Physical Access Procedures and Authorizations | |
| Policy and Procedures | a. Develop, document, and disseminate to organization-defined personnel or roles |
1. physical and environmental protection policy that:
(a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
(b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and
2. Procedures to facilitate the implementation of the physical and environmental protection policy and the associated physical and environmental protection controls;
| b. Designate a role/personnel to manage the development, documentation, and dissemination of the physical and environmental protection policy and procedures | Physical and environmental protection policy and procedures address the controls in the PE family that are implemented within systems and organizations. The risk management strategy is an important factor in establishing such policies and procedures. Policies and procedures contribute to security and privacy assurance. Therefore, it is important that security and privacy programs collaborate on the development of physical and environmental protection policy and procedures. Security and privacy program policies and procedures at the organization level are preferable, in general, and may obviate the need for mission- or system-specific policies and procedures. The policy can be included as part of the general security and privacy policy or be represented by multiple policies that reflect the complex nature of organizations. Procedures can be established for security and privacy programs, for mission or business processes, and for systems, if needed. Procedures describe how the policies or controls are implemented and can be directed at the individual or role that is the object of the procedure. Procedures can be documented in system security and privacy plans or in one or more separate documents. Events that may precipitate an update to physical and environmental protection policy and procedures include assessment or audit findings, security incidents or breaches, or changes in applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. Simply restating controls does not constitute an organizational policy or procedure. | Within 30 days of contract award |
| Physical Access Authorizations | a. Develop, approve, and maintain a list of individuals with authorized access to the facility |
b. Issue authorization credentials for facility access;
c. Frequently review the access list detailing authorized facility access by individuals; and
d. Remove individuals from the facility access list when access is no longer required. Physical access authorizations apply to employees and visitors. Individuals with permanent physical access authorization credentials are not considered visitors. Authorization credentials include ID badges, identification cards, and smart cards. Organizations determine the strength of authorization credentials needed consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. Physical access authorizations may not be necessary to access certain areas within facilities that are designated as publicly accessible. Offeror/Contractor Fill In:
Reviews will be conducted at least ________
| Physical Access Authorizations | Access by Position or Role | Restrict unescorted access to the facility | Role-based facility access includes access by authorized permanent and regular/routine maintenance personnel, duty officers, and emergency medical staff. | ||
| Individuals without required security clearances, access approvals, or need to know are escorted by individuals with appropriate physical access authorizations. | Always (24/7) | |||
| Physical Access Authorizations | Two Forms of Identification | Require two forms of identification from the following forms of identification for visitor access to the warehouse facility | Acceptable forms of identification may include passports, drivers’ licenses, and Personal Identity Verification (PIV) cards. For gaining access to facilities using automated mechanisms, organizations may use PIV cards, key cards, PINs, and biometrics. | Always | |
| Physical Access Control | a. Enforce physical access authorizations by: |
1. Verifying individual access authorizations before granting access to the facility; and
2. Controlling ingress and egress to the facility using, or guards
b. Maintain physical access audit logs for entry or exit points,
c. Control access to areas within the facility designated as publicly accessible by implementing the following controls:
d. Escort visitors and control visitor activity];
e. Secure keys, combinations, and other physical access devices;
f. Regularly inventory physical access devices; and
g. Regularly change combinations and keys and/or when keys are lost, combinations are compromised, or when individuals possessing the keys or combinations are transferred or terminated. Physical access control applies to employees and visitors. Individuals with permanent physical access authorizations are not considered visitors. Physical access controls for publicly accessible areas may include physical access control logs/records, guards, or physical access devices and barriers to prevent movement from publicly accessible areas to non-public areas. Organizations determine the types of guards needed, including professional security staff, system users, or administrative staff. Physical access devices include keys, locks, combinations, biometric readers, and card readers. Physical access control systems comply with applicable laws, executive orders, directives, policies, regulations, standards, and guidelines. Organizations have flexibility in the types of audit logs employed. Audit logs can be procedural, automated, or some combination thereof. Physical access points can include facility access points, interior access points to systems that require supplemental access controls, or both. Components of systems may be in areas designated as publicly accessible with organizations controlling access to the components. Always enforce physical access authorizations.
Offeror/Contractor Fill In:
Inventories will be conducted at least ________
| Physical Access Control | System Access | Enforce physical access authorizations to the system in addition to the physical access controls for the facility. | Control of physical access to the system provides additional physical security for those areas within facilities where there is a concentration of system components. | Always |
| Physical Access Control | Facility and Systems | Perform regular security checks at the physical perimeter of the facility. | Organizations determine the extent, frequency, and/or randomness of security checks to adequately mitigate risk associated with exfiltration. | Offeror/Contractor Fill In: |
Security checks wll be conducted at least _______
| Physical Access Control | Continuous Guards | Employ guards to control physical access points to the facility. | Employing guards at selected physical access points to the facility provides a more rapid response capability for organizations. Guards also provide the opportunity for human surveillance in areas of the facility not covered by video surveillance. | Always |
| Physical Access Control | Lockable Casings | Use lockable physical casings to protect physical assets and from unauthorized physical access. | The greatest risk from the use of portable devices—such as smart phones, tablets, and notebook computers—is theft. Organizations can employ lockable, physical casings to reduce or eliminate the risk of equipment theft. Such casings come in a variety of sizes, from units that protect a single notebook computer to full cabinets that can protect multiple servers, computers, and peripherals. Lockable physical casings can be used in conjunction with cable locks or lockdown plates to prevent the theft of the locked casing containing the computer equipment. | Always |
| Physical Access Control | Tamper Protection | Employ detect; and prevent physical tampering or alteration of physical assets, systems, and inventory. | Organizations can implement tamper detection and prevention at selected hardware components or implement tamper detection at some components and tamper prevention at other components. Detection and prevention activities can employ many types of anti-tamper technologies, including tamper-detection seals and anti-tamper coatings. Anti-tamper programs help to detect hardware alterations through counterfeiting and other supply chain-related risks. | Always |
| Physical Access Control | Physical Barriers | Limit access to the facility using physical barriers. | Physical barriers may include bollards, concrete slabs, jersey walls, and hydraulic active vehicle barriers. | Always |
| Physical Access Control | Access Control Vestibules | Employ access control vestibules at organization-defined locations within the facility. | An access control vestibule is part of a physical access control system that typically provides a space between two sets of interlocking doors. Vestibules are designed to prevent unauthorized individuals from following authorized individuals into facilities with controlled access. This activity, also known as piggybacking or tailgating, results in unauthorized access to the facility. Interlocking door controllers can be used to limit the number of individuals who enter controlled access points and to provide containment areas while authorization for physical access is verified. Interlocking door controllers can be fully automated (i.e., controlling the opening and closing of the doors) or partially automated (i.e., using security guards to control the number of individuals entering the containment area). | Always |
| Physical Access Control | Transportation and deliveries | Employ security and access control measures for transportation (i.e. delivery trucks). Ensure all drivers are vetted in smiliar manner to access to facilities procedures. Ensure drivers and other related individuals are vetted, cleared and verified in accordance to organizational security procedures. Ensure policies are in place to secure all trucks and other physical assets when not in use to prevent tampering. | All base access requirements are determined by DoD and local base authorities, and must be strictly followed, in addition to internal security and access control measures. | Always |
| Monitoring Access | |||
| Monitoring Physical Access | a. Monitor physical access to the facility to detect and respond to physical security incidents; |
b. Regularly review physical access logs; and
c. Coordinate results of reviews and investigations with the organizational incident response capability. Physical access monitoring includes publicly accessible areas within organizational facilities. Examples of physical access monitoring include the employment of guards, video surveillance equipment (i.e., cameras), and sensor devices. Reviewing physical access logs can help identify suspicious activity, anomalous events, or potential threats. The reviews can be supported by audit logging controls, such as AU-2, if the access logs are part of an automated system. Organizational incident response capabilities include investigations of physical security incidents and responses to the incidents. Incidents include security violations or suspicious physical access activities. Suspicious physical access activities include accesses outside of normal work hours, repeated accesses to areas not normally accessed, accesses for unusual lengths of time, and out-of-sequence accesses. Always monitor access.
Offeror/Contractor Fill In:
Reviews of logs will be conducted at least ________
| Monitoring Physical Access | Intrusion Alarms and Surveillance Equipment | Monitor physical access to the facility using physical intrusion alarms and surveillance equipment. | Physical intrusion alarms can be employed to alert security personnel when unauthorized access to the facility is attempted. Alarm systems work in conjunction with physical barriers, physical access control systems, and security guards by triggering a response when these other forms of security have been compromised or breached. Physical intrusion alarms can include different types of sensor devices, such as motion sensors, contact sensors, and broken glass sensors. Surveillance equipment includes video cameras installed at strategic locations throughout the facility. | Always |
| Monitoring Physical Access | Automated Intrusion Recognition and Responses | Recognize potential intrusions and initiate using automated mechanisms. | Response actions can include notifying selected organizational personnel or law enforcement personnel. Automated mechanisms implemented to initiate response actions include system alert notifications, email and text messages, and activating door locking mechanisms. Physical access monitoring can be coordinated with intrusion detection systems and system monitoring capabilities to provide integrated threat coverage for the organization. | Always |
| Monitoring Physical Access | Video Surveillance | (a) Employ video surveillance of operational areas. |
(b) Review video recordings frequently; and
(c) Retain video recordings for organization-defined time period. Video surveillance focuses on recording activity in specified areas for the purposes of subsequent review, if circumstances so warrant. Video recordings are typically reviewed to detect anomalous events or incidents. Monitoring the surveillance video is not required, although organizations may choose to do so. There may be legal considerations when performing and retaining video surveillance, especially if such surveillance is in a public location. Surveillance: always Offeror/Contractor Fill In:
Recordings will be reviewed at least _____________ Recordings will be retained at least ______________
| Monitoring Physical Access | Monitoring Physical Access to Systems | Monitor physical access to the system in addition to the physical access monitoring of the facility | Monitoring physical access to systems provides additional monitoring for those areas within facilities where there is a concentration of system components, including server rooms, media storage areas, and communications centers. Physical access monitoring can be coordinated with intrusion detection systems and system monitoring capabilities to provide comprehensive and integrated threat coverage for the organization. | Always |
| Visitor Access Records | a. Maintain visitor access records to the facility; |
b. Review visitor access records; and
c. Report anomalies in visitor access records to organization-defined personnel. Visitor access records include the names and organizations of individuals visiting, visitor signatures, forms of identification, dates of access, entry and departure times, purpose of visits, and the names and organizations of individuals visited. Access record reviews determine if access authorizations are current and are still required to support organizational mission and business functions. Access records are not required for publicly accessible areas. Always maintain visitor access records.
Offeror/Contractor Fill In:
Access records will be reviewed at least _____________ Visitor Access Records | Automated Records Maintenance and Review Maintain and review visitor access records using organization-defined automated mechanisms. Visitor access records may be stored and maintained in a database management system that is accessible by organizational personnel. Automated access to such records facilitates record reviews on a regular basis to determine if access authorizations are current and still required to support organizational mission and business functions. Always Offeror/Contractor Fill In:
Access records will be reviewed at least _____________
| Visitor Access Records | Limit Personally Identifiable Information Elements | Limit personally identifiable information contained in visitor access records. | Organizations may have requirements that specify the contents of visitor access records. Limiting personally identifiable information in visitor access records when such information is not needed for operational purposes helps reduce the level of privacy risk created by a system. | Always |
| Personnel Security | |||
| Policy and Procedures | a. Develop, document, and disseminate to |
1. Personnel security policy that:
(a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
(b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and
2. Procedures to facilitate the implementation of the personnel security policy and the associated personnel security controls;
| b. Designate an organization-defined official] to manage the development, documentation, and dissemination of the personnel security policy and procedures | Personnel security policy and procedures for the controls in the PS family that are implemented within systems and organizations. The risk management strategy is an important factor in establishing such policies and procedures. Policies and procedures contribute to security and privacy assurance. Therefore, it is important that security and privacy programs collaborate on their development. Security and privacy program policies and procedures at the organization level are preferable, in general, and may obviate the need for mission level or system-specific policies and procedures. The policy can be included as part of the general security and privacy policy or be represented by multiple policies reflecting the complex nature of organizations. Procedures can be established for security and privacy programs, for mission/business processes, and for systems, if needed. Procedures describe how the policies or controls are implemented and can be directed at the individual or role that is the object of the procedure. Procedures can be documented in system security and privacy plans or in one or more separate documents. Events that may precipitate an update to personnel security policy and procedures include, but are not limited to, assessment or audit findings, security incidents or breaches, or changes in applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. Simply restating controls does not constitute an organizational policy or procedure. | Within 30 days of contract award |
| Personnel Screening | Information Requiring Special Protective Measures | Verify that individuals accessing a system processing, storing, or transmitting information have valid access authorizations that are demonstrated by assigned official government duties. | |
| Satisfy organization-defined additional personnel screening criteria. | Organizational information that requires special protection includes controlled unclassified information. Personnel security criteria include position sensitivity background screening requirements. | Prior to access |
| Access Agreements | a. Develop and document access agreements for organizational systems; |
b. Frequently review and update the access agreements; and
c. Verify that individuals requiring access to organizational information and systems:
1. Sign appropriate access agreements prior to being granted access; and
2. Re-sign access agreements to maintain access to organizational systems when access agreements have been updated. Access agreements include nondisclosure agreements, acceptable use agreements, rules of behavior, and conflict-of-interest agreements. Signed access agreements include an acknowledgement that individuals have read, understand, and agree to abide by the constraints associated with organizational systems to which access is authorized. Organizations can use electronic signatures to acknowledge access agreements unless specifically prohibited by organizational policy. Develop agreements within 60 days of contract award.
Offeror/Contractor Fill In:
Reviews for updates will be conducted at least __________
| Access Agreements | Post-employment Requirements | (a) Notify individuals of applicable, legally binding post-employment requirements for protection of organizational information; and | |
| (b) Require individuals to sign an acknowledgment of these requirements, if applicable, as part of granting initial access to covered information. | Organizations consult with the Contracting Officer regarding matters of post-employment requirements on terminated individuals. | Prior to access |
| External Personnel Security | a. Establish personnel security requirements, including security roles and responsibilities for external providers; |
b. Require external providers to comply with personnel security policies and procedures established by the organization;
c. Document personnel security requirements;
d. Require external providers to notify organization-defined personnel of any personnel transfers or terminations of external personnel who possess organizational credentials and/or badges, or who have system privileges; and
e. Monitor provider compliance with personnel security requirements. External provider refers to organizations other than the organization operating or acquiring the system. External providers include service bureaus, contractors, and other organizations that provide system development, information technology services, testing or assessment services, outsourced applications, and network/security management. Organizations explicitly include personnel security requirements in acquisition-related documents. External providers may have personnel working at organizational facilities with credentials, badges, or system privileges issued by organizations. Notifications of external personnel changes ensure the appropriate termination of privileges and credentials. Organizations define the transfers and terminations deemed reportable by security-related characteristics that include functions, roles, and the nature of credentials or privileges associated with transferred or terminated individuals. Establish requirements within 60 days of contract award.
Offeror/Contractor Fill In:
- Notification required within __________ of personnel transfer or termination
- Reviews for compliance monitoring conducted at least _________
| Personnel Sanctions | a. Employ a formal sanctions process for individuals failing to comply with established information security and privacy policies and procedures; and | |
| b. Notify organization-defined personnel or roles when a formal employee sanctions process is initiated, identifying the individual sanctioned and the reason for the sanction. | Organizational sanctions reflect applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. Sanctions processes are described in access agreements and can be included as part of general personnel policies for organizations and/or specified in security and privacy policies. Organizations consult with the Office of the General Counsel regarding matters of employee sanctions. | Offeror/Contractor Fill In: |
Notify within ____ of inititation Position Descriptions Incorporate security and privacy roles and responsibilities into organizational position descriptions. Specification of security and privacy roles in individual organizational position descriptions facilitates clarity in understanding the security or privacy responsibilities associated with the roles and the role-based security and privacy training requirements for the roles. Within 30 days of contract award
File details come from the government source that posted it. Updated .