Attachment I - fcc-information-security-and-privacy-policy.pdf

PDF 525 KB Posted

Attached to
FCC Auction Bidding System and Support Services Federal contract opportunity
Solicitation number
273FCC23R0018
Issued by
Federal Communications Commission

About this file

This document outlines requirements for auction bidding system and support services. The Federal Communications Commission is soliciting proposals to provide an auction bidding system and ongoing support. Key requirements include developing and maintaining a web-based system to facilitate auction bidding processes, providing customer support services to auction participants, and conducting education and training. Proposers must have experience in auction design, FCC auction rules and processes, and web development. The contract term is five years with three optional one-year extensions. Proposals are due by February 15, 2023 and contract award is expected by May 15, 2023. Pricing will be evaluated using a best value determination considering technical quality and price.

View the file

Other files for this federal contract opportunity

Other files attached to FCC Auction Bidding System and Support Services, newest first.
File Type Posted
Attachment F - FCC Auction Bidding System and Support Services - SF1449 Terms and Conditions.pdf PDF
Attachment A - FCC Auction Bidding System and Support Services - SOW-updated 9-5-2023 for QandA.pdf PDF
Attachment H - FCC Contractor - Telework Policy.pdf PDF
Attachment E - FCC Auction Bidding System and Support Services - Pricing Sheet.xlsx XLSX spreadsheet
Attachment G - FCC Auction Bidding System and Support Services - QandA Received 8-29-2023.xlsx XLSX spreadsheet
Attachment G - FCC Auction Bidding System and Support Services - QandA Received 8-29-2023.pdf PDF
Attachment H - FCC Contractor - Telework Policy.pdf PDF
Attachment F - FCC Auction Bidding System and Support Services - SF1449 Terms and Conditions.pdf PDF
Attachment B - FCC Auction Bidding System and Support Services - Instructions to Offerors.pdf PDF
Attachment G - FCC Auction Bidding System and Support Services - Questions and Answers Template.xlsx XLSX spreadsheet
Attachment A - FCC Auction Bidding System and Support Services - SOW.pdf PDF
Attachment C - FCC Auction Bidding System and Support Services - Evaluation Criteria.pdf PDF
Attachment E - FCC Auction Bidding System and Support Services - Pricing Sheet.xlsx XLSX spreadsheet
Attachment D - FCC Auction Bidding System and Support Services - Requirements Template.xlsx XLSX spreadsheet
Show all 14

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

FCC POLICY FOR

INFORMATION SECURITY

AND PRIVACY

VERSION 4.8

MAY 11, 2021

OFFICE OF THE MANAGING DIRECTOR

45 L STREET NE, WASHINGTON DC 20554

FCC SECURITY AND PRIVACY POLICY

INFORMATION TECHNOLOGY 1

Information Technology

Record of Approval Document Approval

Title: Chief Information Security Officer Printed Name: Andrea Simpson Signature:

Date

Title: Senior Agency Official for Privacy Printed Name: Margaret Drake Signature:

Date

Revision Log Version Date Description Author

4.0 02/24/2016 Initial Draft Hema Dixit

4.1 01/25/2019 Update and Review Al Shipman

4.1 02/8/2019 Annual Review Mike Luong

4.2 03/19/2019 Annual Review and Update Hans Agarwal

4.3 04/26/2019 Update SAOP information Al Shipman

4.4 01/13/2020 Review and Update Shahid Aziz

4.5 03/24/2020 Privacy Office Updates Bahareh Moradi

4.6 04/01/2020 IT Security Updates Hans Agarwal

4.7 4/10/2020 IT and OGC Collaborative Agreements Hans Agarwal

/Bahareh Moradi

4.8 05/07/2021 Annual Review and Update Hans Agarwal

INFORMATION TECHNOLOGY 2

NOTE

The Federal Communication Commission (FCC) Risk Management and Governance Framework (RMF) and the supporting documentation is a dynamic process where the management concepts and related documents are continually being refined and updated to better meet the needs of the FCC.

To that end, the review of existing FCC Information Technology security-related policies/procedures for National Institute of Standards and Technology (NIST) 800-53 controls is an active project. A collaborative team including the Office of the Chief Information Security Officer (CISO), Compliance, Network Security Operations Center (NSOC), Information System Security Officers (ISSO), Plan of Action and Milestone (POA&M) management, and other Subject Matter Experts (SME) are comprehensively reviewing and updating policies for each NIST Control Family and ensuring procedures and continuous monitoring mechanisms are in place. In the event that a specific policy requirement cannot be met as explicitly stated, a waiver request may be submitted. Approved waivers shall be associated with a NIST security control and tracked as a POA&M.

INFORMATION TECHNOLOGY 3

Table of Contents

1. Purpose

2. Objectives

3. Scope

4. Policy

5. Introduction

6. Rules of Behavior

7. Virtual Private Network (VPN)

8. Management Controls

9. Operational Controls

10. Technical Controls

11. Privacy Controls

12. Privacy Reporting and Handling

13. Compliance

14. Federal Guidance

15. Enterprise Risk Management

16. Information Security Architecture and Operations

17. Roles & Responsibilities

18. Effective Dates

19. Information and Assistance

20. Waivers of Policy Requirements and Disciplinary Actions for Non-Compliance Appendix A – Supporting Program Policies and Procedures Appendix B – Applicable Laws/Guidance

INFORMATION TECHNOLOGY 4

1. Purpose The Federal Communications Commission’s (FCC or Commission) information and Information Systems1 are fundamental to its daily operations and future success. FCC shall implement policies, procedures and controls at all levels to protect the confidentiality and integrity of information stored and processed on our systems, and to ensure that the systems and information are available to authorized persons when required.

The purpose of this policy is to establish the FCC Information Security and Privacy Policy (ISPP) in compliance with applicable laws, regulations, and standards of the Federal Government. This policy establishes Information Security and privacy guidelines that bureaus and offices shall implement and comply with to ensure the availability, integrity, and confidentiality of FCC information and information technology (IT) resources.

2. Objectives As an independent U.S. government agency overseen by Congress, the Commission regulates interstate and international communications by radio, television, wire, satellite, and cable in all 50 states, the District of Columbia and U.S. territories by implementing and enforcing America’s communications law and regulations. The FCC collects, generates, and stores technical communication related information, as well as financial and other sensitive data.

Most of this information relates to the telecommunications industry, and as such, has access restrictions as required under legislative and regulatory directives.

The objective of the FCC Information Security and Privacy Policy is to support the FCC mission and business operations by requiring security measures for Information Systems and Information Technology1 (IT) that safeguard the confidentiality, integrity, and availability (CIA) of the information in those FCC technologies and systems 2 .These terms are defined as follows:

• Confidentiality: Preserving authorized restrictions on access and disclosure, including means for protecting personal privacy and proprietary information. A loss of confidentiality is the unauthorized disclosure of information.

• Integrity: Guarding against improper information modification or destruction and includes ensuring information non-repudiation and authenticity. A loss of integrity is the unauthorized modification or destruction of information.

• Availability: Ensuring timely and reliable access to and use of information. Loss of availability is the disruption of access to or use of information or an Information System.3

1 44 U.S.C. 3502(8); 44 U.S.C. 3552(3); Office of Management and Budget (OMB) Circular A-130, “Managing Information as a Strategic Resource,” August 28, 2016 (OMB Circular A-130) at 31.

2 44 U.S.C. 3552(3); OMB Circular A-130 at 30.

3 OMB Circular A-130 at 30.

INFORMATION TECHNOLOGY 5

To accomplish the objectives of the ISPP, the FCC has established an enterprise-wide Information Security and Privacy Program based on four goals/pillars:

• Security and Privacy Management: Oversee security and privacy activities that protect IT and Information Resources through implementation of policies and procedures that support quality assurance and training and awareness.

• Security and Privacy Risk Management and Compliance: Manage IT security and privacy risks to identify, analyze, and respond appropriately that adversely affect FCC business objectives; establish an internal controls program to ensure compliance with federal requirements and internal policies and procedures; and enhance Plan of Action and Milestones (POA&M) 4 oversight.

• IT Security Operations: Establish a robust security operations program that allows FCC IT to address security and privacy requirements, create transparency with IT stakeholders, and streamline complex processes to ensure efficient implementation of cost-effective solutions.

• Security Architecture and Engineering Management: Support the information security concerns of FCC, its partners by implementing a strategy dedicated to assuring the security architecture and design of Information Systems, build security and privacy considerations into the System Development Life Cycle (SDLC) 5 process, and position FCC as a leader in enterprise security for current and emerging technologies.

3. Scope The Information Security and Privacy Policy applies to:

• All FCC employees

• Contractors, subcontractors, and external organizations that process or handle any FCC information, data, or IT system.

This policy applies to all information systems that is collected or maintained by, or on behalf of, FCC and all Information Systems used or operated by FCC, by a contractor, or any organization on behalf of FCC.

4. Policy The FCC 's cyber mission is to ensure the security of our Information Resources, Information Technology, and communications to provide a secure, reliable, and resilient platform where both the Commission and the public can access information. The Commission increasingly relies on Information Technology, specifically the internet, wireless and mobile devices, and

4 National Institute of Standards and Technology (NIST) Glossary of Key Information Security Terms (NISTIR 7298) (Rev. 3) July 3, 2019.

5 Id.

INFORMATION TECHNOLOGY 6

data exchange services to conduct its business. Cybersecurity6 measures are crucial to ensuring the protection and preservation of the confidentiality, integrity, and availability of electronic Information Resources critical to the FCC, the U.S. Government, and the public.

The Information Security and Privacy Policy comprises the Cybersecurity management structure and foundation to measure progress and compliance, and is organized into thirteen major sections as follows:

1. INTRODUCTION – This section covers among other items, an overview of the Information Security and Privacy Policy, various cyber threats, and information technology definitions.

2. RULES OF BEHAVIOR (RoB) – This section covers the required agreements all personnel must adhere to when using federal systems.

3. MANAGEMENT CONTROLS – This section covers controls implemented at the agency level, independent of any particular information system, and essential for managing both system Information Security controls and privacy risk.7 These controls consist of risk mitigation techniques used by management.

4. OPERATIONAL CONTROLS – This section covers controls that focus on mechanisms primarily implemented and executed by individuals. Operational controls are designed to improve the security of a system or group of systems and often rely on management and technical controls.

5. TECHNICAL CONTROLS – This section covers security controls executed by Information Systems. Technical controls provide automated protection from unauthorized access or misuse, facilitate detection of security violations, and support security requirements for applications and data.

6. PRIVACY CONTROLS – This section covers controls focused on the administrative, technical, and physical safeguards employed within the FCC to ensure compliance with applicable privacy requirements and manage privacy risks.8

7. COMPLIANCE – This section details the compliance aspect of the controls noted above as per statutory, OMB, NIST, and FCC requirements.

6 OMB Circular A-130 at 28.

7 Id. a t 34.

8 Id.

INFORMATION TECHNOLOGY 7

8. FEDERAL REPORTING –This section details the FCC’s reporting requirements, including for compliance with the Federal Information Security Management Act of 20029.

9. ENTERPRISE RISK MANAGEMENT – This section details IT specific requirements of the FCC Enterprise Risk Management program.

10. INFORMATION SECURITY ARCHITECTURE AND OPERATIONS – This section explains the requirement that the IT security system architecture must align with the enterprises mission and strategic plan.10

11. ROLES and RESPONSIBILITIES – This section covers in detail the roles and responsibilities of FCC leadership and employees, including management, information security staff, contractors, system owners, and users.

12. APPENDICES A and B provide the supporting program policies and procedures as well as a list of the applicable laws and guidance references.

5. Introduction All FCC information shall be protected from unauthorized access, use, disclosure, duplication, modification, diversion, or destruction, whether accidental or intentional, to maintain confidentiality, integrity, and availability (CIA).

The security and privacy controls that provide this protection shall meet minimum federal requirements with additional risk-based and business-driven control implementation achieved through a multi layered security structure. This multi-layered approach is to address security and privacy at the network, application, database, operating system, and infrastructure layers across the enterprise.

Access to all FCC information shall be limited based on a least-privilege approach and a need-to-know basis. Authorized user access shall be limited to only the information necessary for the performance of required tasks.

Information Security and privacy is a responsibility shared by senior agency officials, all FCC managers and staff, business, Information, and Information System Owners, IT professionals, 9 The Federal Information Security Management Act of 2002 (FISMA 2002), enacted as Title III, E-Government Act of 2002, Pub. L. No. 107-347, 116 Stat. 2899, 2946 (Dec. 17, 2002) was subsequently modified by the Federal Information Security Modernization Act of 2014 (Pub. L. No. 113-283, Dec. 18, 2014). As modified, FISMA is codified at 44 U.S.C. § 3551 et seq.

10 OMB Circular A-130 at 30

INFORMATION TECHNOLOGY 8

and all other users of FCC information and Information Systems.

The controls implemented to protect FCC systems and information are defined by the NIST Special Publication (SP) 800-5311 and serve as a security baseline with the flexibility to allow tailoring and enhancement when necessary. The applicability of NIST controls is contingent on the security categorization12 of each system. The security categorization is determined using the Federal Information Processing Standards (FIPS) Publication 199.13 Based on the security categorization of the system (High, Moderate, Low), the required baseline internal controls are selected.

The three distinct control categories that are leveraged and implemented within the FCC environment are Management, Technical, and Operational controls. Within those categories, there are control families that detail specific objectives when considering the achievement of CIA. The controls and families that the FCC implements across its assets and tests periodically, in accordance with NIST SP 800-53 and OMB Circulars A-12314 and A-130, are listed below in sections on Management, Operational, and Technical controls. The FCC Information security and Privacy Policy supplements the individual security policies tailored for each of the control families and serves as the governing policy for the FCC.

6. Rules of Behavior FISMA and OMB A-130 mandate that federal agencies “establish rules of behavior, including consequences for violating rules of behavior, for employees and contractors that have access to Federal information or information systems, including those that create, collect, use, process, store, maintain, disseminate, disclose, or dispose of PII; and ensure that employees and contractors have read and agreed to abide by the rules of behavior for the Federal information and information systems for which they require access prior to being granted access.” Prior to providing access to FCC systems, all personnel, including contractors, and others working on behalf of the FCC, must sign the FCC’s established Rules of Behavior (RoB). The RoB clearly delineate responsibilities and expected behavior of all individuals with access to FCC systems.

The rules state the consequences of non-compliance.

• The Office of the Chief Information Officer (OCIO) shall define and maintain enterprise FCC

RoB that can be used for all Information Systems. The RoB shall be reviewed and updated as necessary.

• Information System Owners may define and maintain additional RoB for all Information Systems under their purview, if they believe the enterprise RoB is not enough for their particular system.

11 NIST Special Publication 800-53, Security and Privacy Controls for Federal Information Systems and Organizations (Rev. 5), September 2020, (NIST-SP 800-53).

12 OMB Circular A-130 at 36 13 NIST FIPS Publication 199, Standards for Security Categorization of Federal Information and Information Systems, Feb. 2004; OMB Circular A-130 at Appendix I-4.

14 OMB Circular A-123, “Management Accountability and Control,” June 21, 1995 (OMB Circular A-123).

INFORMATION TECHNOLOGY 9

The OCIO shall ensure that users requesting access to FCC systems sign the FCC Information Technology and Privacy RoB after receiving training on both the RoB and the disciplinary actions that may result if the rules are violated.

Users are required to complete mandatory Security Awareness Training before accessing any FCC information or system. This training shall be required on yearly basis. The Security Awareness training also includes a Privacy Awareness Training module.

The Rules of Behavior provide a non-exhaustive list of prohibitive uses as well as restricted for appropriate use guidance for FCC Information Technology and Systems, and are located on the FCC Intranet at:

http://intranet.fcc.gov/docs/omd/itc/emagazine/forms/FCC%20IT%20Rules%20of%20Behavior_ FY21-FINAL.pdf

7. Virtual Private Network (VPN)

Virtual Private Networks (VPN) are utilized for external access to the FCC network

• Approval and justification from the Office of the Managing Director (OMD) is required prior to implementation and access by FCC employees and contractors to the VPN, which allows direct access to the FCC network from outside the FCC network.

• Users authorized/issued RSA SecurID tokens for the purpose of accessing FCC systems from remote locations must adhere to the following guidance:

o RSA SecurID tokens are the property of the FCC and must be returned upon request by the FCC Service Center, when the user no longer has a valid, work-related need for remote access, or when an employee leaves the Commission.

o When a user fails to return his or her RSA SecurID token as requested, the FCC Service Center will contact the user’s Bureau/Office and will deactivate the token.

o Users are responsible for protecting the RSA SecurID token from loss, theft, and damage.

o Users must contact the FCC Service Center immediately if their SecurID token is lost, stolen or damaged.

o The RSA SecurID token contains a battery with an expected life of several years. Users must return the RSA SecurID token to the FCC Service Center if the battery dies or if the token fails for any reason. Users must not dispose of the RSA SecurID token.

http://intranet.fcc.gov/docs/omd/itc/emagazine/forms/FCC%20IT%20Rules%20of%20Behavior_FY21-FINAL.pdf http://intranet.fcc.gov/docs/omd/itc/emagazine/forms/FCC%20IT%20Rules%20of%20Behavior_FY21-FINAL.pdf

INFORMATION TECHNOLOGY 10

8. Management Controls Management controls are implemented at the organizational level and not specific to individual Information Systems. Management controls have been designed to facilitate compliance with applicable federal laws, executive orders, directives, policies, regulations, and standards. These controls focus on the programmatic, organization-wide Information Security requirements that are independent of any Information System and are essential for managing Information Security programs. The FCC requires Management controls which are listed within the policies below.

Each of the policies specify the individual(s) responsible for the development, implementation, and monitoring of the management controls.

Program Management (PM) - The FCC Policy for Program Management addresses the purpose, scope, roles, and responsibilities of managing the ongoing protection of information assets, satisfying regulatory obligations, and managing risk using the Risk Management Framework (RMF) as defined by NIST SP 800-37.15 The FCC Program Management Plan and the ISPP, in conjunction with the supporting policies listed in Section 10, form the governing basis for program management at the FCC.

Security Planning (PL) - The FCC Policy for Security Planning addresses the purpose, scope, roles, and responsibilities for planning Information System security for the FCC. This policy addresses the development of System Security Plans, the Rules of Behavior for the FCC user community, and the FCC Security Architecture. The policy follows the NIST SP 800-18, Guide for Developing Security Plans for Federal Information Systems.16

System Services and Acquisition (SA) - The FCC Policy for System Services and Acquisition establishes an effective third-party risk management program by addressing the purpose, scope, roles, and responsibilities for managing risks from third-party products and service providers. and. The policy ensures that Cybersecurity and Risk Management are embedded into the System Development Life Cycle (SDLC) and Agile processes. It provides guidance for the establishment of strong Service Level Agreements (SLAs), Memorandums of Understanding (MOUs), or Interconnection Security Agreements (ISAs), which document security requirements for externally hosted systems.

Risk Assessment (RA) - The FCC Policy for Risk Assessment addresses the purpose, scope, roles, and responsibilities for assessing and mitigating risk. The FCC Policy for Risk Assessment establishes the process that Information System Owners shall follow to conduct risk assessments of the systems under their purview. Risk Management shall be

15 NIST SP 800-37, Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy, (Rev. 2) Dec. 2018 (NIST SP 800-37).

16 NIST SP 800-81, Guide for Developing Security Plans for Federal Information Systems (Rev. 1), Feb. 2006 (NIST

SP 800-81).

INFORMATION TECHNOLOGY 11

incorporated throughout all phases of the System Development Life Cycle (SDLC) for all Information Systems and applications in the FCC enterprise. Assessing and mitigating risk is an integral part of the planning, development, implementation, operation, and disposal of all FCC systems and applications. The controls specified in the RA policy include Risk Assessment, Security Categorization, and Vulnerability Scanning.

Security Assessment and Authorization (CA) - The FCC Policy for Security Assessment and Authorization (A&A) addresses the purpose, scope, roles, and responsibilities for Security Assessment and the Authorization-to-Operate (ATO) process. The FCC Policy for Security Assessment and Authorization follows the guidance of NIST SP 800-37, which provides a well-defined process for authorizing Information Systems to operate in the FCC enterprise.

The FCC shall apply the principles of the RMF throughout the entire SDLC processes of Information Systems and applications. The application of the RMF principles assist FCC Authorizing Officials with making risk-based system authorization decisions.

9. Operational Controls Operational controls support the day-to-day procedures and mechanisms to protect FCC information and Information Systems. Policies for the operational control families are described below. Supporting documentation is listed in Section 10. The policies and procedures shall be reviewed and updated when warranted by changes to the enterprise, but not less than each fiscal year. The operational control families are:

Personnel Security (PS) - The FCC Policy for Personnel Security provides guidance for managing risks related to personnel screening, termination, transfer, access agreements, and third-party personnel security and personnel sanctions through the establishment of an effective personnel security program.

Awareness and Training (AT) - The FCC Policy for Security Awareness and Training addresses the purpose, scope, roles, and responsibilities for educating FCC staff and contractors on Cybersecurity awareness by providing guidance on training, including Insider Threat training, and the maintenance of security training records.

Media Protection (MP) - The FCC Policy for Media Protection addresses the purpose, scope, roles, and responsibilities for ensuring protection of FCC media by providing guidance on media access, marking, storage, transport, sanitization, and use.

Contingency Planning (CP) - The FCC Policy for Contingency Planning provides guidance for managing risks from information asset disruptions, failures, and disasters through the establishment of an effective contingency planning program. The contingency planning program helps the FCC implement security best practices regarding enterprise business

INFORMATION TECHNOLOGY 12

continuity and disaster recovery. The FCC Policy for Contingency Planning follows the NIST SP 800-34, Contingency Planning Guide for Federal Information Systems17 and applies to all IT resources owned or operated by the FCC.

System and Information Integrity (SI) - The FCC Policy for System and Information Integrity addresses the purpose, scope, roles, and responsibilities for ensuring system information integrity and provides guidance on flaw remediation, malicious code, monitoring, security alerts, software, firmware, spam protection, input validation, error handling, information handling and retention, and memory protection.

Incident Response (IR) - The FCC Policy for Incident Response establishes FCC policy regarding handling various types of security incidents that can compromise the availability, integrity, and confidentiality of FCC Information Systems and network resources. The purpose of this incident response policy is to document, authorize, and establish incident handling standards, disciplines, and processes within the FCC that reflect best practices within law enforcement and the FCC cybersecurity community.

Configuration Management (CM) - The FCC Policy for Configuration Management addresses the purpose, scope, roles, and responsibilities for managing the configuration of hardware and software elements within FCC Information Systems and networks. CM within the FCC consists of a multi-layered structure – policy, procedures, processes, and compliance monitoring. The FCC Policy for Configuration Management provides technical and administrative direction for conducting Configuration Management in accordance with NIST SP 800-12818 The CM policy provides direction to bureaus and offices maintaining the Configuration Management process. It also directs the establishment of a Change Advisory Board (CAB) or Configuration Change Management Board (CCB), and a Configuration Management Database (CMDB) that contains and tracks relevant information about configuration items, their attributes, baselines, documentation, changes, and relationships.

Physical and Environmental Protection (PE) - The FCC Policy for Physical and Environmental

Protection addresses the purpose, scope, roles, and responsibilities for mitigating risks from physical security and environmental threats. The FCC Policy for Physical and Environmental Protection provides guidance on the establishment of an effective physical security and environmental controls program. This policy shall be enforced at all on-premises FCC owned/managed areas such as IBM Allegany Ballistics Laboratory (ABL), 17 NIST Special Publication 800-34, Contingency Planning Guide for Federal Information Systems (Rev. 1), Nov. 11, 2010.

18 NIST SP 800-128, Guide for Security-Focused Configuration Management of Information Systems, Oct. 10, 2019

(NIST SP 800-128).

https://sp13.fccnet.win.fcc.gov/omd-itc/dwir/IR/Internal/Compliance/ISSO/Shared%20Documents/Draft%20Documents%20for%20CISO%27s%20Review/LMT%20Draft%20-%20FCC_Policy_for_Physical_and_Environmental_Protection.docx https://sp13.fccnet.win.fcc.gov/omd-itc/dwir/IR/Internal/Compliance/ISSO/Shared%20Documents/Draft%20Documents%20for%20CISO%27s%20Review/LMT%20Draft%20-%20FCC_Policy_for_Physical_and_Environmental_Protection.docx

INFORMATION TECHNOLOGY 13

Gettysburg, etc. Cloud Service Providers shall be required to provide attestation reports (ex: SOC 2) to the FCC to ensure the physical environment is sound.

Maintenance (MA) – The FCC Policy for Maintenance (MA) addresses the purpose, scope, roles, and responsibilities for managing risks from information asset maintenance and repairs through the establishment of an effective System Maintenance program. The System Maintenance program affords the FCC the ability to implement security best practices regarding FCC Information System maintenance and repairs. This policy is applicable to all Information Technology (IT) resources owned or operated by the FCC.

10. Technical Controls Technical controls are those security mechanisms employed within an Information System’s hardware, software, or firmware to protect the system and its information from unauthorized access, use, disclosure, disruption, modification, or destruction. They are used to authorize or restrict the activities of all levels of users within an individual system by employing access based on least-privilege required and a need-to-know approach. The technical control families are:

Access Control (AC) - The FCC Policy for Access Control addresses the purpose, scope, roles, and responsibilities for controlling access to FCC Information Systems and data. The FCC Policy for Access Control establishes the access controls that bureaus and offices shall implement and comply with to ensure the availability, integrity, and confidentiality of FCC information and information technology (IT) resources.

Identification and Authorization (IA) - The FCC Policy for Identification and Authorization addresses the purpose, scope, roles, and responsibilities for identifying users and devices that access FCC Information Systems and data. The FCC Policy for Identification and Authentication establishes controls ensuring FCC Information Systems are configured to uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users). Identifiers include user IDs, passwords, and other unique factors that allow the system/assets to identify the user.

Audit and Accountability (AU) - The FCC Policy for Audit and Accountability addresses the purpose, scope, roles, and responsibilities for audit and accountability of Information Systems and data. The Policy provides guidance for maintaining accountability for FCC Information Systems and how to handle deficiencies.

System and Communication (SC) - The FCC Policy for System and Communication Protection implements specific security control requirements from the SC control family, as identified in NIST SP 800-53, into the FCC network. The FCC Policy for System and Communication Protection provides guidance to address critical security requirements

INFORMATION TECHNOLOGY 14

such as application partitioning, boundary protection, transmission of data to ensure confidentiality and integrity, encryption, and other relevant measures as it relates to the communication of data across the FCC network.

11. Privacy Controls Under the Privacy Act and FISMA,19 the FCC has statutory obligations to protect Personally Identifiable Information (PII) 20 about individuals that it collects, uses, maintains, and disseminates, and to safeguard and report on PII stored on its Information Systems. The Commission provides public notice about its systems of records by publication in the Federal Register.21 The FCC is also required to conduct a Privacy Impact Assessment (PIA) when it develops, procures, or uses information technology to create, collect, use, process, store, maintain, disseminate, disclose, or dispose of PII.22

In addition to Systems of Record Notices (SORNs), PIAs, and internal controls, the FCC meets its obligations through:

• Policy review by Senior Agency Official for Privacy (SAOP);

• The collaborative work of the NSOC and Privacy team jointly manage PII breaches and execute required reporting requirements;

• Annual Table-top breach exercises (per fiscal year) and annual review of the breach response plan by the SAOP;23

• Ensuring contracts include necessary provisions related to privacy and that contractors are held to privacy requirements;

• Annual FISMA reporting; and,

• Training and awareness efforts across the FCC.

The FCC has also incorporated guidance from OMB Circular A-130 regarding agency responsibilities for protecting and managing PII.24

The privacy control families can be implemented at the organizational or Information System level, under the leadership and oversight of the Senior Agency Official for Privacy (SAOP) and in coordination with the Chief Information Security Officer (CISO), Chief Information Officer (CIO), program officials, legal counsel, and others as appropriate. At the FCC, SAOP approval is required as a pre-condition for the issuance of the authority to operate (ATO) an Information System.

19 5 USC § 552a 20 OMB Circular A-130 at 33.

21 See the FCC’s Systems of Records Notices (SORNs) at https://www.fcc.gov/managing-director/privacy-transparency/privacy-act-information.

22 OMB Circular A-123 at 44-46.

23 OMB Memorandum 17-12, “Preparing for and Responding to a Breach of Personally Identifiable Information,” Jan. 3, 2017 (OMB M-17-12).

24 OMB Circular A-130 at App. II.

INFORMATION TECHNOLOGY 15

12. Privacy Reporting and Handling The FCC Policy for Privacy Incident Handling addresses guidance requiring federal agencies to develop and implement policies, plans, and procedures to safeguard personally identifiable information (PII) in its possession, and to prevent the compromise of PII. The FCC Policy for Privacy Incident Handling and the Processing PII Breach procedures provide detailed directions for addressing, responding to, and reporting privacy incidents.

13. Compliance Under OMB A-123, FISMA, and NIST SP 800-37 the FCC is required to ensure all systems have a valid ATO. The FCC Policy for Security Assessment and Authorization details the process and implementation requirements. Any IT program level deficiencies identified during the ATO process for each FCC Information System, including vendor systems, shall be recorded in POA&Ms and managed in accordance with the FCC POA&M Management Guide.

Authorized systems shall be monitored for risk using continuous monitoring processes performed throughout the system lifecycle. The continuous monitoring processes will be based on the Information System’s FIPS categorization and the Information System shall be reviewed for authorization every three years, at minimum. In addition, any deficiencies identified from continuous monitoring shall be documented in a POA&M and associated with a NIST 800-53 control.

FCC systems hosted by Cloud Service Providers (CSP), shall be compliant with NIST SP 800-144 and NIST SP 800-146, 25 and must be certified by the Federal Risk and Authorization Management Program (FedRAMP) to have an authority to operate. The FCC has developed a policy addressing the procurement, deployment, and utilization of cloud computing services across the FCC.

14. Federal Guidance FISMA and OMBD dictate reporting requirements tied to Information Security. FISMA requires agency program officials, chief information officers, senior agency officials for privacy, and inspectors general (IGs) to conduct annual reviews of their agencies’ Information Security and privacy programs and report the results to OMB. OMB uses this data to carry out its oversight responsibilities and to prepare its annual report to Congress on agency compliance with the Act.

FISMA metrics are organized around the NIST Framework for Improving Critical Infrastructure

25 NIST SP 800-144, Guidelines on Security and Privacy in Public Cloud Computing, Dec. 2011; NIST SP 800-146, Cloud Computing Synopsis and Recommendations, May 2012.

INFORMATION TECHNOLOGY 16

Cybersecurity (Cybersecurity Framework),26 which set a standard for managing and reducing cybersecurity risks. The metrics are based on the Cybersecurity Framework’s five functions:

Identify, Protect, Detect, Respond, and Recover. The Cybersecurity Framework, when used in conjunction with NIST SP 800-37, provide agencies with a comprehensive structure for making more informed, risk-based decisions and managing cybersecurity risks across their enterprise.

Using these tools, the FCC has established measurements for the Information Security program.

Reporting requirements also include notifying Congress of major information security incidents (as defined by NIST SP 800-6127) as they occur and annually. FCC has established the FCC Policy for Incident Response, which details the reporting requirements related to incidents. The Policy for Incident Response also addresses required incident reporting to United States Computer Emergency Readiness Team (US–CERT). US-CERT serves as the central reporting point for all federal Information Security incidents, required by FISMA and OMB M 06-19.28

15. Enterprise Risk Management According to OMB Circular A-123,29 an effective agency wide approach to proactively identifying and addressing threats and vulnerabilities should be identified and managed to better achieve an IT organization’s goals and objectives. Agencies should work to acknowledging the full spectrum of their external and internal risks by understanding the combined impact of risks as an interrelated portfolio, rather than addressing risks only in silos by each bureau or office. In support of Information Security and Privacy considerations, the FCC has adopted the IT Enterprise Risk Management (ERM)program and established an approved ERM IT Charter and Governance Guide. The charter and governance guide document and define a robust program to manage IT risks at the Commission. The FCC also maintains an online portal using SharePoint to record, maintain, and manage risks within its Risk Register, which is a tracker to document the risks and relevant actions.

16. Information Security Architecture and Operations The FCC has an obligation to strategically allocate safeguards (procedural, technical, and physical) in the security architecture to protect against adversaries and other threats.

The initiatives that will support the security architecture include:

26 NIST Framework for Improving Critical Infrastructure Cybersecurity (Version 1.1), Apr. 16, 2018, available at https://www.nist.gov/publications/framework-improving-critical-infrastructure-cybersecurity-version-11 (NIST Cybersecurity Framework).

27 NIST Special Publication 800-61, Computer Security Incident Handling Guide (Rev. 2), Aug. 2012, (NIST-SP 800-61).

28 OMB Memorandum 06-19, “Reporting Incidents Involving Personally Identifiable Information and Incorporating the Cost for Security in Agency Information Technology Investments,” Jul. 12, 2006 (OMB M-06-19).

29 OMB Circular A-123, “Management’s Responsibility for Enterprise Risk Management and Internal Control,” Jul.

15, 2016 (OMB Circular A-123).

https://www.nist.gov/publications/framework-improving-critical-infrastructure-cybersecurity-version-11

INFORMATION TECHNOLOGY 17

• Working with key stakeholders to establish guidelines for security requirements, security principles, and best practices

• Implementing baseline technical security and privacy requirements

• Integrate security and privacy into the SDLC

• Create security guidelines for performing security risk assessments and code reviews

• Utilize software scanning techniques

• Collaborate with internal and external stakeholders to establish reusable repository of components, frameworks, libraries, and tools

While implementing safeguards into the security architecture is important, establishing a robust security operations program to support the security architecture is also imperative.

The initiatives that will support the security operations program include:

• Establish transparency with IT stakeholders;

• Strengthen incident management program;

• Implement a security authorization process that is streamlined, efficient, and cost effective; and

• Strengthen IT privacy posture.

As per the noted control families above, critical controls that support the implementation of the security architecture requirements are addressed in the Systems and Communication, System and Information Integrity, Configuration Management, and Privacy Policies. Combining Management, Operational, Technical, and Privacy controls help ensure that the FCC’s security architecture is planned appropriately, and that IT operations are sustainable within a secure posture.

17. Roles & Responsibilities Listed below are the major responsibilities for the key positions that oversee FCC information security.

FCC Chief Information Officer (CIO)

Mandated by the Clinger-Cohen Act of 1996 and FISMA, the FCC Chief Information Officer (CIO) has overall responsibility for the FCC IT Security Program. Responsibilities include:

1. Oversee the development and maintenance of a Commission-wide information security program;

2. Appoint in writing an FCC employee to serve as the FCC Chief Information Security Officer

(CISO);

3. As appropriate, serve as or appoints in writing the Authorizing Officer (AO) for FCC Information Systems;

INFORMATION TECHNOLOGY 18

4. Participate in developing FCC performance plans, including descriptions of the time periods and budget, staffing, and training resources required to implement the Commission-wide security program;

5. Ensure that FCC security programs integrate fully into the FCC enterprise architecture and capital planning and investment control processes;

6. Report to the FCC Managing Director on matters relating to the security of FCC systems;

7. Coordinate and advocate resources for enterprise security solutions; and

8. Lead the FCC Contingency Planning program.

FCC Chief Information Security Officer (CISO)

The FCC CISO shall carry out the CIO’s responsibilities under FISMA, have Information Security responsibilities as his/her primary duty, possess professional qualifications to administer FCC Information Security functions, and head an office with the mission and resources to assist in achieving and maintaining organizational compliance with the FCC information security policies, standards and procedures. The FCC CISO is responsible for the following activities:

1. Lead FCC Information Security programs and promoting proper Information Security practices;

2. Support the FCC SAOP in order to integrate FCC privacy program initiatives into FCC

Information Security practices, where applicable;

3. Support the FCC SAOP in documenting and managing privacy implementation in FCC IT systems;

4. Foster communication and collaboration among FCC’s Information Security and privacy stakeholders to share knowledge and to better understand threats to FCC information;

5. Provide information about the FCC Information Security policies to management and throughout the FCC while also supporting SAOP in communicating required Privacy policies;

6. Provide advice and assistance to other organizational personnel concerning the security of sensitive information and of critical data processing capabilities;

7. Advise the FCC CIO about Information Security exploitations in accordance with the

Information Security reporting procedures developed and implemented by the FCC;

8. Disseminate information on potential security threats and recommended safeguards;

9. Ensure that roles with significant security responsibilities are identified and documented;

10. Assess the need for Information Security awareness training and coordinate training activities for relevant audiences, such as FCC staff, including contractors;

11. Draft Information Security policy, standards, and practices/procedures through the issuance of the FCC Information Security Organizational Defined Values (ODV) for all required controls per NIST 800-53;

12. Assist Bureau Chiefs/System Owners in establishing and implementing the required security safeguards to protect computer hardware, software, and data from improper use or abuse;

INFORMATION TECHNOLOGY 19

13. Ensure FCC-wide implementation of FCC policies and procedures that relate to Information Security incident response;

14. Appoint the FCC Lead for the FCC Incident Response Team and direct the investigation and resolution of Information Security incidents within FCC;

15. Collaborate and support the FCC SAOP when Privacy response activities occur within FCC;

16. Support general Information Security awareness and role-based training activities for all personnel using, operating, supervising, or managing FCC Information Systems;

FCC Senior Agency Official for Privacy (SAOP)

The FCC Senior Agency Official for Privacy has major statutory responsibilities under the Privacy Act of 1974. Responsibilities include:

1. Develop, implement, and maintain a Commission-wide governance and privacy program to ensure compliance with all applicable laws and regulations regarding the collection, use, maintenance, sharing, and disposal of PII by programs and Information Systems;

2. Monitor federal privacy laws and policy for changes that affect the FCC privacy program;

3. Allocate enough resources to implement and operate the Commission-wide privacy program;

4. Develop a strategic Commission privacy plan for implementing applicable privacy controls, policies, and procedures;

5. Develop, disseminate, and implement operational privacy policies and procedures that govern the appropriate privacy and security controls for programs, Information Systems, or technologies involving PII;

6. Update privacy plans, policies, and procedures biennially;

7. Oversee privacy incident management, to include providing guidance to system owners, and where appropriate coordination with system owners responding to suspected or confirmed privacy incidents;

8. Coordinate with the FCC CIO, CISO, and senior management regarding privacy incidents;

9. Approve all Commission Privacy Compliance Documentation, including Initial Privacy

Assessments (IPAs), PIAs, ATOs and SORNs;

10. Ensure and or coordinate with the appropriate FCC parties (e.g., NSOC) that the reporting requirements that involve PII or otherwise impact privacy occurs;

11. Provide Commission-wide annual and refresher privacy training;

12. Conduct annual table-top exercises for the FCC’s breach response team; and

13. Complete the SAOP component of the FCC’s annual FISMA report.

18. Effective Dates This policy becomes effective on the date the FCC CISO and SAOP, respectively each sign it, and remains in effect until superseded or cancelled by either the FCC CISO or SAOP. The policy provides additional guidance for the specific NIST control family. Please refer to this policy as the

INFORMATION TECHNOLOGY 20

enterprise level policy for all of FCC.

19. Information and Assistance FCC shall develop and implement an Information Security Program that provides policies, standards, procedures, and guidance to ensure the protection of our information and Information Systems.

Please contact the Chief Information Security Officer, at CISOSupport@fcc.gov or the SAOP at privacy@fcc.gov for further information on this policy.

20. Waivers of Policy Requirements and Disciplinary Actions for Non-Compliance

All FCC employees and contractors are required to conform to this policy. In the event that an FCC user cannot meet a specific requirement in this policy, a waiver request should be submitted to the individuals’ B/O Chief and FCC CISO for review. If the specific requirement involves PII, the waiver must also be submitted to the SAOP. The waiver request shall explain the reason for the request, identify compensating controls/actions that meet the intent of the policy, and identify how the compensating controls/actions provide a similar or greater level of defense or compliance than the policy requirement.

Approved waivers shall be associated with a NIST security and /or privacy control and tracked as a POA&M. A violation of any of the responsibilities contained in this policy may be cause for disciplinary or adverse action. Disciplinary or adverse action shall be in accordance with applicable FCC policies, and/or law and regulations.

Appendix A – Supporting Program Policies and Procedures To safeguard the FCC’s information and Information Systems effectively, the FCC has established an agency-wide IT Security and Privacy Program. This Policy and the following supporting policies define management decisions concerning the protection of FCC information assets.

The FCC has established three classes of IT security program policies: Management, Operational, and Technical.

Management policies consist of those policies that address agency-wide management decisions on the security of the information and Information Systems and the associated risk to FCC assets and operations. These policies are:

• FCC Policy for Program Management

• FCC Policy for Security Planning

• FCC Policy for Risk Assessment mailto:CISOSupport@fcc.gov mailto:privacy@fcc.gov

INFORMATION TECHNOLOGY 21

• FCC Policy for System and Services Acquisition

• FCC policy for Security Assessment and Authorization

Operational policies consist of those policies that address the day-to-day operations and focus on tasks and their supporting procedures for the protection of FCC information and Information Systems. These policies are:

• FCC Policy for Personnel Security

• FCC Policy for Physical and Environmental Protection

• FCC Policy for Configuration Management

• FCC Policy for Maintenance

• FCC Policy for System and Information Integrity

• FCC Policy for Media Protection

• FCC Policy for Incident Response

• FCC Policy for Contingency Planning

• FCC Policy for Awareness and Training

Technical policies are those security mechanisms employed within an Information System’s hardware, software, or firmware to protect the system and its information from unauthorized access, use, disclosure, disruption, modification, or destruction. They are used to authorize or restrict the activities of all levels of users within an individual system by employing access based on a least-privilege and need-to-know approach. These policies are:

• FCC Policy for Identification and Authentication

• FCC Policy for Audit and Accountability

• FCC Policy for Access Control

• FCC Policy for Security Audit Logging

• FCC Policy for System and Communications Protection

Protecting the privacy of individuals and their PII that is collected, used, maintained, shared, and disposed of by FCC Information Systems, is a fundamental responsibility of FCC. The following policies provide a structured set of controls for protecting privacy. These documents are:

• FCC Privacy Act Manual

• FCC Procedures for Responding to a PII Data Breach

Appendix B – Applicable Laws/Guidance The following laws and guidance and any officially designated successors are applicable to this policy. While not every item below is referenced in the narrative of this Policy, all are applicable given the overall requirements for a proper, robust Security and Compliance program.

FCC Directives and Policies

• FCC Information Security Program Directive, Number 1479.2; dated March 2019

• Compliance with Privacy Laws and Guidance, Number: 1113.2; dated April 2016

INFORMATION TECHNOLOGY 22

• FCC Privacy Act Manual, Number 1113.1; dated March 2016

• FCC Personnel Security…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .