Attachment J-10 U.S. Sergeant at Arms Standard Operating Procedures (SOPS) for Cybersecurity.pdf

PDF 1 MB Posted

Attached to
U. S. Senate Information Technology Support Contract (ITSC) V Federal contract opportunity
Solicitation number
2025-R-001
Issued by
United States Senate

About this file

This document is a Standard Operating Procedures (SOP) for Cybersecurity from the U.S. Senate Sergeant at Arms, dated October 2021. The SOP establishes comprehensive cybersecurity policies and procedures for protecting Senate information systems, networks, and data, including detailed requirements for contractors providing IT products and services to the Senate.

The SOP covers key areas including information security policies, access controls, system administration, computer user guidelines, contractor responsibilities, remote access protocols, incident response procedures, and cloud computing requirements. Notable requirements include: contractors must undergo background checks before accessing Senate systems, maintain a Contractor Security Plan (CSP), implement least privilege access models, provide cybersecurity training to staff, follow specific password management protocols, patch systems according to defined timeframes (1-28 days based on severity), and ensure cloud services meet FedRAMP Moderate or High impact levels. The document emphasizes protection of Senate data integrity, confidentiality and availability while establishing clear responsibilities for contractors to maintain security controls, report incidents, and ensure business continuity.

View the file

Other files for this federal contract opportunity

Other files attached to U. S. Senate Information Technology Support Contract (ITSC) V, newest first.
File Type Posted
SAA Form 30 - Solicitation 2025-R-001 Amendment 005.pdf PDF
2025-R-001 (RFP) Information Technology Support Contract V Amendment 005.pdf PDF
2025-R-001 (RFP) Information Technology Support Contract V (Redlined) Amendment 005.pdf PDF
2025-R-001 (RFP) Information Technology Support Contract V Amendment 004 (Redlined).pdf PDF
Solicitation 2025-R-001 Amendment 004.pdf PDF
Solicitation 2025-R-001 Amendment 004.pdf PDF
Attachment J-02 US Senate Office Locations (v2).xlsx XLSX spreadsheet
2025-R-001 (RFP) Information Technology Support Contract V Amendment 004 (Redlined).pdf PDF
Attachment J-05 Service Level Agreement with Incentives and Penalties (v2).docx DOCX document
2025-R-001 (RFP) Information Technology Support Contract V Amendment 004 .pdf PDF
Appendix A-2 Representative Hardware List (v2).docx DOCX document
2025-R-001 (RFP) Information Technology Support Contract V (Amendment 003 - Redline Version 4.1.2025).docx DOCX document
Solicitation 2025-R-001 Amendment 003.pdf PDF
2025-R-001 (RFP) Information Technology Support Contract V - Amendment 003 (4.1.2025).pdf PDF
Attachment J-14 Specifications for the Help Desk and Other Work Spaces (Revised 3.14.25).pdf PDF
2025-R-001 (RFP) Information Technology Support Contract V (Amendment 002 - Redline Version 3.14.2025).docx DOCX document
2025-R-001 (RFP) Information Technology Support Contract V (Amendment 002 3.14.2025).pdf PDF
2025-R-001 (RFP) Information Technology Support Contract V (Amendment 001 2.14.2025).pdf PDF
2025-R-001 (RFP) Information Technology Support Contract V (Amendment 001 Redline Version 2.14.2025).docx DOCX document
Appendix A-1 - Past Performance Questionnaire - ITSC V (RFP).pdf PDF
Appendix A-2 Representative Hardware List.docx DOCX document
Attachment J-08 - Senate Standard Hardware Products.pdf PDF
Attachment J-12 Acknowledgement of Receipt AOR Form.pdf PDF
Attachment J-19 Glossary.docx DOCX document
Attachment J-17 Help Desk Statistics.xlsx XLSX spreadsheet
2025-R-001 (RFP) Information Technology Support Contract V (2.10.2025).pdf PDF
Attachment J-07 Senate Standard Software Products.pdf PDF
Attachment J-02 US Senate Office Locations.xlsx XLSX spreadsheet
Attachment J-04 Technical Environment.docx DOCX document
Attachment J-14 Specifications for the Help Desk and Other Work Spaces.pdf PDF
Attachment J-20 Section 208 Compliance Certificate.pdf PDF
Attachment J-13 Record of Equipment Transfer.pdf PDF
Attachment J-06 Service Level Agreement Ticket Review Process.docx DOCX document
Attachment J-09 Office Profile Data Points.docx DOCX document
Attachment J-01 Supported Washington DC Locations.docx DOCX document
Attachment J-18 IT System Consultants.docx DOCX document
Attachment J-03 Inventory of Installed Hardware.pdf PDF
Attachment J-11 Installation Instructions.pdf PDF
Attachment J-05 Service Level Agreement with Incentives and Penalties.docx DOCX document
Attachment J-15 Off-Site vendor procedures.docx DOCX document
Attachment J-16 - Post-Election Office Moves.docx DOCX document
Show all 41

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Version: 3.0 Page 1 of 51

U. S. Senate

Sergeant at Arms

Standard Operating Procedures

For

Cybersecurity

October 2021

Table of Contents

1 U.S. Senate Information Systems Security Policy for Senate Unclassified Systems and Networks

2 Sergeant at Arms Cybersecurity Policy

2.1 Compliance

3 Office of the Chief Information Officer Cybersecurity Policy

3.1 Purpose

3.2 Scope

3.3 Objectives

3.4 Responsibilities

3.5 Standard

3.6 Enforcement

4 Non-disclosure of Sensitive Information

5 Access to Senate Office Information

5.1 Senate Office Systems

5.2 Senate Office Information on SAA Resources

6 Project Management

7 System Administration

8 Computer User Guidelines

8.1 User Responsibilities

8.2 Basic Computer Care

8.3 Securing the Work Area

8.4 Closing Up at the End of the Day

8.5 Working Away From the Office

8.6 Selecting Good Passwords

8.7 Protecting Passwords

8.8 Computer Viruses

8.9 Imported Software

8.10 Protecting Against Disaster

8.11 Deleting Files

8.12 Copyrights

8.13 Email Guidelines

8.14 Communications

8.15 Internet

8.16 Reporting Violations

9 Classified National Security information

10 Remote Network Access

11 Perimeter Email Filtering

12 Access to Restricted Areas

13 Senate ID Card

13.1 Postal Square Sixth Floor and Other Senate Site Access

13.2 Care of ID Cards

13.3 Postal Square Visitors

13.4 Postal Square Data Center

14 Contractor Responsibilities for Cybersecurity

14.1 Contractor Access to Senate Systems and Services

14.1.1 SAA Systems and Services

14.1.2 Senate Office Systems

14.2 Contractor Cybersecurity Plan

14.2.1 Least Privilege Model

14.2.2 Configuration Management

14.2.3 Maintenance Policies and Procedures

14.2.4 Technician Training and Authorization

14.2.5 Third Party Security Requirements

14.2.6 Developer Security Test Plan

14.2.7 Supply Chain Security

14.2.8 Incident Response Plan

14.3 Contractor Cybersecurity Measures, Policies, and Procedures

14.3.1 Corporate Responsibility

14.3.2 Data Protection

14.3.3 Media Protection

14.3.4 Personnel Security Controls

14.3.5 Cybersecurity Incident Response Plan and Procedures

14.3.6 Cybersecurity Training

14.3.7 Chain of Trust Partner Agreement

14.3.8 Remote Access

14.3.9 Contractor Accounts

14.3.10 Continuity of Operations Plan

14.3.11 Personnel Termination Procedures

14.3.12 Software Updates and Patches

14.3.13 Cloud Service Use

14.3.14 Breach Notification

15 Senate System Remote Access Authorization Form

16 Cybersecurity Responsibilities Acknowledgement

Document Revision History

Version Description Date

3.0 Reorganized the document to place policy related content in sections 1,2, and 3 of this document and contractor requirements in sections 14 and 15 including content updates incorporating previously separate cybersecurity related contractor requirements documents. Also added breach notification, vulnerability remediation timeframe, and cloud service cybersecurity contractor requirements to section 14, and removed references to Senate Mainframe system which was retired from service in 2021.

10/05/2021

1 U.S. SENATE INFORMATION SYSTEMS SECURITY POLICY FOR SENATE

UNCLASSIFIED SYSTEMS AND NETWORKS

As a critical part of our nation's leadership, the United States Senate (the Senate) processes and develops information vital to our nation's well-being. The Senate information technology environment is a valuable asset in carrying out legislative responsibilities and daily functions.

Senate members, staff, and support elements require timely access to reliable information processing for both routine operations and major decisions. The Senate has a responsibility to protect its information from the threat of unauthorized access, modification, destruction, or disclosure, and to protect its information assets from loss or misuse.

The Senate is a large, diverse organization whose systems include hundreds of local area networks (LANs) on Capitol Hill and at state offices, mainframe computer services, and networked resources both within the Senate and with other Legislative Branch organizations. The

Senate also relies on access to commercial and public (Internet) information services.

Interconnectivity provides Senate users with remarkable resources and capabilities, yet it also significantly increases the risks to Senate systems. In a networked environment, consideration must be given to the risks of such connections.

Security of a network is determined by the security afforded each component level. As a result, a local risk management decision becomes a global risk management decision since the total is only as protected as its weakest link. In order to manage the risks associated with its networked environment, organizations must balance their information technology needs with the need to provide due care and diligence to protect not only all Senate information and systems, but also those systems to which Senate systems are linked.

The Senate's Information Systems Security goals are:

to assure adequate levels of protection, confidentiality and integrity of Senate systems and networks;

to prevent or detect and counter threats to Senate information and systems; and to ensure that Senate information and information processing assets are available when needed.

These goals include the following:

information is protected against unauthorized access;

information is protected against unauthorized modification;

information maintains its integrity;

information will be available when needed;

systems are protected against unauthorized modification;

systems are not subject to denial of service;

systems are not subject to accidental or malicious destruction;

systems cannot be used as a "pass through" for unauthorized access to other networks/systems;

systems maintain the integrity of Senate information and the system security features implemented; and contingency operations will meet the needs of the Senate.

The Senate handles sensitive information and operates critical information technology systems, both of which require protection. Senate information may be sensitive, proprietary, or classified.

The integrity of Senate information and systems is critical to maintaining public confidence.

Instructions/policies regarding Senate classified systems are issued by the office of Senate

Security.

This Information Systems Security policy applies to all Senate unclassified systems utilizing information technology, to include:

automated information systems;

networks;

telephone switching equipment and voice mail systems;

video teleconferencing;

physical alarm systems;

physical access systems (i.e., badge readers);

web and mobile applications;

communication software;

computerized facsimile; and other computer-based systems and software.

Within the Senate, the Sergeant at Arms Chief Information Officer is responsible for assuring adequate levels of protection for those information technology systems which it operates/maintains on behalf of the Senate. Such systems include the Senate Network, Mainframe, physical and virtual servers, storage, etc. Each individual Senate office is responsible for assuring the protection of those information technology systems which it owns/operates.

This Information Systems Security policy applies to Senate and non-Senate personnel (i.e., vendors, contractors) operating, maintaining or using Senate information processing resources including those provided as cloud services.

The SAA Cybersecurity Department is the focal point for information system security issues which affect US Senate systems and operations. The Cybersecurity Department will:

maintain a Senate-wide information security incident response capability to support timely notification and response to threats to Senate information technology systems;

collect pertinent information on information technology systems, their vulnerabilities and threats, and disseminate it, as appropriate, to Senate elements; and work with appropriate offices to address information security problems that may affect

Senate systems.

At the request of individual Senate offices, the Cybersecurity Department will also provide:

guidelines presenting physical, personnel, communications, hardware, software, and procedural security measures to protect information technology systems from inadvertent or deliberate compromise, damage or destruction;

advice and assistance in helping Senate offices understand, establish, and implement information security measures;

information security services (i.e., technical assistance, risk assessments, etc.); and information security education and awareness presentations.

2 SERGEANT AT ARMS CYBERSECURITY POLICY

Information in all its forms and through its life cycle will be protected from unauthorized modification, destruction, disclosure, or denial, whether accidental or intentional. The cost of such protection will be consistent with the sensitivity and value of the information to the United

States Senate. This protection includes the peripherals, hardware, and software used to process, store, and transmit the information.

Each Sergeant at Arms (SAA) department or office is responsible for determining the sensitivity of the data created and/or processed in the organization and establishing and/or defining appropriate controls and acceptable levels of risks. Under certain circumstances, it may be necessary for the SAA department or office to access a Senate-issued computer to an employee, contractor, or temporary help to recover documents. For this reason, the Office of the Sergeant at Arms reserves the right to access all computer files stored on SAA department or office workstations at any time.

Information stored on department or office computers is the property of the Senate and is not private. Employees of the SAA, contractors, or temporary help on assignment to the United

States Senate may not make copies of any software licensed to the Senate or to the SAA and remove it from the department or office. Employees, contractors, or temporary help on assignment to the United States Senate are also prohibited from using unlicensed software on individual computers or LAN’s.

The Sergeant at Arms has established the Cybersecurity Department which is responsible for ensuring that appropriate organizational security procedures and standards are developed to support the cybersecurity policy. The Cybersecurity Department is responsible for coordinating the implementation of information security measures within all SAA departments and offices, and providing management assurance that the organization is in compliance with policy, legislative, and contractual requirements regarding cybersecurity.

2.1 Compliance

Non-compliance with this policy may lead to disciplinary action by the SAA, including revocation of computer user privileges, admonishment, reprimand, suspension, or termination of employment. Under certain circumstances, unauthorized access to or modification, disclosure, or destruction of Senate information may give rise to civil and/or legal activity. Any computer systems that do not adhere to Senate or SAA cybersecurity policies, or for which no specific

Senate or SAA cybersecurity policies are published may be refused access to the Senate data network and may be deemed inappropriate for storing or accessing Senate information.

3 OFFICE OF THE CHIEF INFORMATION OFFICER CYBERSECURITY POLICY

3.1 Purpose

Under the U. S. Senate Information Security Policy, the SAA is responsible for assuring protection for information technology systems operated and maintained on behalf of the Senate. It is the policy of the Chief Information Officer (CIO) to take appropriate measures to assure adequate levels of security, confidentiality, and integrity of U. S. Senate information and information technology resources under its custodianship.

3.2 Scope

This policy applies to all U. S. Senate information technology resources and to all employees, contractors and any other individuals who access, process, or have custody of Senate information using the SAA’s services and facilities.

3.3 Objectives

The objectives of this policy include but are not limited to the following:

provide a high level of security and integrity for information technology resources and data;

prevent any compromise of the integrity, availability, or confidentiality of the data or the systems that process and store data;

safeguard proprietary, personal, privileged, or otherwise sensitive data entrusted to the

SAA;

ensure individual accountability; and ensure the ability to survive hazards and maintain continuity of operations consistent with the criticality of information requirements.

3.4 Responsibilities

The CIO is responsible for providing enforcement of and top management support for the

Cybersecurity Policy.

The SAA Directors, Managers, and Supervisors are responsible for developing security requirements and monitoring proper safeguard practices relative to their functional areas. This includes strict adherence to all protection and control criteria specified by an information owner for data, applications, and services under the SAA’s custodial control. They shall maintain effective overall controls to prevent damage or destruction that might adversely affect an information owner's operational schedule.

All SAA employees and contractors are required to protect assets assigned to them, to implement and enforce the established security practices and procedures, and to notify SAA/CIO management or the Senate COR, if applicable, of security violations and problems.

Senate offices are responsible for establishing, publishing, and implementing safeguards relative to maintaining the security of their office systems and for the information maintained on those systems.

Owners and/or originators of applications and services that operate on the SAA’s platforms are responsible for specifying the security requirements usage controls, and access controls for those applications and services.

Every originator, custodian and/or user of Senate information must ensure that the data under his or her direction and/or control is properly identified and safeguarded according to its sensitivity, proprietary nature, and criticality.

Individuals with access to the SAA facilities are allowed only the use of information technology resources and information for which they are authorized. Such authorization must be obtained from the individual’s supervisor or the Senate COR, whichever is applicable. They must adhere to the specific security measures and controls that have been established for those resources and information.

3.5 Standard

The SAA CIO Cybersecurity Policy and Standard Operating Procedures (SOPs) will serve as the minimum acceptable requirements for data security practices to be applied by management and employees. In addition, these SOPs will be a basis for compliance, monitoring, and review.

3.6 Enforcement

Violations of standards, procedures, or guidelines established in support of this policy will be brought to the attention of the CIO for appropriate action. Failure to follow established security policies and procedures may result in admonishment, reprimand, loss of access privileges, suspension, termination of employment, and/or liability for damages depending on the severity of the violation.

4 NON-DISCLOSURE OF SENSITIVE INFORMATION

Employees, contractors on assignment to the Senate, and all others granted access to SAA facilities and information resources may not disclose, assist in, or facilitate the disclosure of sensitive information by any means--verbally, materially, electronically, or otherwise--to any person or agency not entitled to receive it. Sensitive information includes the following:

Senate Office Data (information of which SAA Departments have been given custody by any

Senate office or information which the SAA maintains for any Senate office);

Computer Software and Supporting Documentation (licensed commercial software and systems developed in-house); and

Personally Identifiable Information (PII) (home addresses, home telephone numbers, social security numbers, date of birth, employment history, salary, credit or any other financial or personal information relating to Senate staff).

In accordance with Rule XI of the Standing Rules of the Senate, Senate property, records or documents may not be released or removed without proper authorization, and such property or information may not be used for personal reasons.

Violations of this policy will be brought to the attention of management for appropriate action, which could include termination of employment and/or liability for damages.

5 ACCESS TO SENATE OFFICE INFORMATION

5.1 Senate Office Systems

Senate offices are responsible for establishing, publishing and implementing safeguards relative to maintaining the security of their office systems and for the information maintained on those systems. They control access to their own computer systems both locally and remotely. SAA technical support staff (including support contractors) may at times require access to these systems, but the office controls the extent and degree of access. Each office must weigh for itself the risks of providing access to support staff against the necessity of sustaining efficient, reliable, and secure system operations.

In all cases, SAA support staff may access an office system only when they have been granted specific permission by the office. The permission is normally granted by the office providing the support staff member with a logon ID and password combination to allow access. Once logged onto a Senate office system, support staff may be given privileged administrator capabilities so they can resolve critical problems. The Office is responsible for monitoring all work performed under these circumstances and ensuring that access privileges are not misused.

Remote access increases risk but may be necessary at times when problems cannot be resolved over the phone and someone cannot quickly or easily be dispatched to an Office. System unavailability for the length of time needed for a technician to travel to the Office, log on the system, diagnose and correct the problem may not be acceptable for some Offices. In these instances, remote access by SAA support staff can represent an acceptable risk for timely resolution of an acute problem. Usage of a one-time password can reduce the risk.

Offices are advised to establish a special account that is activated only when remote support requiring high-level privileges is needed. The password should be changed after each support effort so that access is allowed only for a limited period. Offices are cautioned to closely monitor system activity at times when this account is used. An Office can validate the identity of anyone requesting remote access over the telephone by asking for a number to call the person back. The

Office can verify the number before calling back and providing access.

5.2 Senate Office Information on SAA Resources

Senate office data transmitted over networks or stored on central computer platforms, including cloud platforms, provided by the SAA is never monitored for content unless specifically requested in writing by the Senator or Office authorized personnel and authorized by the SAA. In that instance, monitoring is performed on the requesting Office’s data as authorized and only for a limited length of time. All monitoring information is turned over to the requesting office. No monitoring data is retained on file by the SAA.

Offices maintaining information on platforms operated by the SAA are responsible for specifying the security requirements, usage and access controls for their information. For these situations, it may be necessary for SAA support staff to access Senate Office data to address a problem. In all such cases, consent from the Office to access this information must be obtained first.

SAA staff assisting Senate offices with managing their information on central platforms should:

access Senate Office data only to the extent necessary to perform the work needed to assist the Office;

never reproduce Office data unless specifically directed to do so by the Office;

never disclose Office information to third parties without written consent of the Office; and return all data (including copies) to the Office.

If an emergency requires access of Senate Office information to maintain the integrity or availability of the Senate technology infrastructure, the Office will be advised that its assistance is required to address the situation.

In the course of their regular duties, SAA support staff may discover evidence of violation of

Senate or SAA security policies. Violations should be reported to the SAA and the responsible

Senate office. Staff requested to participate in an investigation will be approved by the SAA and the Senate Office.

6 PROJECT MANAGEMENT

Security and controls must be designed into the services and products provided by SAA departments. Project Managers are responsible for determining measures needed to meet a project’s operational purpose in a practical, usable, cost-effective fashion without sacrificing security.

A Project Manager should determine the following:

who owns information;

who is responsible for the integrity of information and other resources;

who is to allow or deny access to information and on whose authority;

who is responsible for detecting security violations or compromises;

who conducts security reviews; and what are the security responsibilities of individual users and how are these communicated.

Security measures are most effective when addressed in the design phase. Potential risks should be identified and evaluated, and cost-effective safeguards selected to provide prudent levels of protection without sacrificing productivity.

It is important to note that absolute security is not achievable. In some cases, it may be reasonable for management to decide to accept some risk rather than expend resources mitigating such risk. The cost of having enough levels of security and availability must be balanced with efficiency and usability. Controls should not be excessively cumbersome to the users of the product or service.

The ability to recover from a disruption of services is also a major consideration. A determination must be made as to the level of effort that is justified to satisfy requirements for continuous availability.

Security responsibilities in the development and deployment of SAA products and services.

Apply the Principle of Least Possible Privilege. Limit users to information and transaction authority as spelled out by the information owner.

Provide for individual accountability. Have the information owner identify significant events that should be recorded and tracked.

Screen contractor staff and require them to undergo a background check before providing privileged access to Senate resources.

Remove privileged access when that access is no longer needed. When an employee announces his or her intention to resign, immediately remove all privileges except for those needed to close out assignments.

Educate all project staff, including contractor staff, on their personal and supervisory security responsibilities.

Monitor Security. Establish a way to detect unusual events and bring them to the attention of the appropriate party.

Develop a method to verify that the product or service is functioning as intended. This can also be used as evaluation criteria for security audits.

Provide a method to recover from troublesome events, whether minor problems or major disruptions. Availability is a question of what outages or loss of service can be tolerated.

Safeguard all sensitive documentation. This includes documentation that reveals the logic, methodology or procedural aspects of applications or system software. Documentation should be stored in secure areas, and duplicates stored at an off-site location.

Safeguard all media on which information is represented or stored to a level commensurate with the sensitivity of the information it contains.

All information on the Senate systems is considered to be sensitive and should be afforded some protection. The information owner should provide guidance regarding the sensitivity level of data. Protect media identified as containing sensitive information from unauthorized access. Keep sensitive reports in a secure location.

Sanitize highly sensitive data from magnetic media and shred documents containing highly sensitive information when no longer needed.

Develop controls to prevent misuse of an SAA product or service.

Assess the security implications on the existing Senate infrastructure prior to introducing any new products or services.

7 SYSTEM ADMINISTRATION

System Administrators are responsible for implementing appropriate security measures on the systems they administer. Each Administrator is expected to establish controls to protect information assets and ensure continuity of system operations. Selected controls should be appropriate for the sensitivity, criticality, and value of the information stored and processed on the system.

The following checklist outlines what is expected of Administrators in applying baseline security measures.

Inform users of system security policies, guidelines, and standard operating procedures.

Maintain a plan to address disruptions and extensive service interruptions.

Physically secure sensitive or critical file servers.

Physically secure external modems for remote connections.

Use available operating system security features.

Apply vigorous password management for privileged accounts.

o Require a minimum password length of twelve characters o Assign unique logon IDs to all users.

Eliminate guest and generic IDs.

Safeguard the Administrator account.

o Enroll the account in the Senate Privileged Account Management (PAM) service o Select a password with a minimum length of twelve characters.

o Change the password at least every three months.

o Use the account only when administrator privileges are needed.

o Do not use the account when accessing the Internet.

Promptly deactivate accounts for terminated or reassigned staff.

Use available monitoring and auditing facilities to log security relevant events and review logs daily.

Provide only necessary operating system functionality and remove any unneeded programs and services.

Monitor electronic mailing lists for news of new operating system vulnerabilities and apply and test relevant security patches promptly.

Maintain backups of the current operating system and application configurations.

Make frequent backups of critical files on a regularly scheduled basis as defined by the system owner.

Store backups in a secure, environmentally protected location at least 100 feet from the file servers. Enterprise Operations Enterprise IT Systems Branch can arrange for storage at the Senate’s off-site facility.

Use all appropriate Cybersecurity Department specified anti-virus/anti-malware software and update signature files regularly.

Maintain records of security problems and violations to help identify patterns and trends that point to new vulnerabilities or the weakening of existing controls.

Assess the security implications of any new technology prior to implementation.

Establish an Emergency Access Account (EAA). Place the EAA logon ID and password in a sealed envelope marked for emergency use only. Store the envelope in a secure, locked place known to system management. Change the password after use.

Notify SAA/CIO Cybersecurity Department at 202 228 2927, option 1, or email csoc@saa.senate.gov of any suspected security breach or violation.

8 COMPUTER USER GUIDELINES

All individuals with access to Senate computers and networks are expected to understand, respect and follow established security policies. They are personally accountable for their actions when using these resources. The following checklist outlines what is expected of everyone using

Senate information technology:

8.1 User Responsibilities

Do not circumvent security mechanisms and procedures established to protect information.

Use screen saver passwords, anti-virus software, and other available safeguards.

Use effective password management. Select good passwords and protect them from disclosure.

Safeguard your Multifactor Authentication (MFA) token and other access devices.

Protect against introducing viruses or malicious code into any Senate computer.

Honor copyright and license restrictions.

mailto:csoc@saa.senate.gov

Do not attempt to gain unauthorized access to information.

Use only authorized software on your computer.

Do not use software, equipment, or communications lines for anything other than authorized use.

Use electronic mail properly. Do not “snoop” or “spoof.”

Conform to the published terms of use on all systems and networks.

Delete sensitive files so that residual data is not retrievable by others.

Check the credentials of anyone who works on or services your computer.

Immediately report any security incident involving computers or networks to your System

Administrator.

Complete annual Cybersecurity awareness training.

8.2 Basic Computer Care

Locate your computer away from sources of heat and direct sunlight. Computer equipment is sensitive to extreme changes in the office environment.

Keep your computer’s air vents free of obstruction so the system has adequate ventilation.

Use your surge protector to prevent problems with spikes, surges and dips in the power supply.

Keep your work area as clean and dust-free as possible. Occasionally wipe the exterior surfaces of the system with a soft, damp cloth.

Food particles, liquids, ashes, and smoke residue can damage equipment. Avoid eating, drinking and smoking near your computer.

Do not move computer equipment yourself. You can seriously damage a computer and data stored on its fixed disk by moving it improperly. Contact your System Administrator about relocating equipment.

Do not open any part of the system. Removing covers can violate manufacturers’ warranties.

Handle removable storage (e.g. CDs and DVDs) with care. Acquire removable storage boxes from the Stationery Store to protect such storage when not in use.

Avoid extremes of heat and cold when storing computer media.

Protect removable storage from dust, cigarette ashes, crumbs, and liquids.

8.3 Securing the Work Area

Do not provide access or information to strangers.

Politely challenge and assist people who do not belong in your work area.

Do not let unauthorized personnel work on or service your computer.

Examine the credentials of service personnel you do not recognize or are not expecting.

Contact your System Administrator immediately if you have any reservations.

Use the password feature of your screen saver.

Log off or lock your computer before leaving it unattended.

Keep removable storage such as thumb drives, CDs, and DVDs in a secure place so they cannot be picked up by visitors.

Shred or otherwise destroy paper output (computer listings, reports, etc.) that contains sensitive information. Do not discard such output in waste cans where it can be retrieved by others.

8.4 Closing Up at the End of the Day

Log off and power down your computer.

Lock up sensitive documents and removable storage containing sensitive data.

8.5 Working Away From the Office

Maintain good security practices with your laptop or home computer.

Do not copy office files to your laptop or home computer without authorization.

Safeguard laptops, mobile devices, and removable storage such as thumb drives, CDs, and

DVDs from theft or accidental loss while traveling.

Only connect to the Senate using Senate approved/issued devices. Office files stored on a home computer can be accessed by other family members and their friends. Take precautions so that they are not copied along with games or other software.

Do not store office removable storage such as thumb drives, CDs, and DVDs with that for home use.

Use virus detection software on your home computer or laptop and keep it up to date.

Transport computer media in proper containers. Magnetic field sources you encounter in transit can erase computer data.

Never leave a mobile device or removable storage such as thumb drives, CDs, and DVDs in your car or anywhere where it may be exposed to rapid temperature variations or sunlight.

8.6 Selecting Good Passwords

Select obscure passwords that are easy for you to remember and hard for others to guess.

Don't use your name, logon ID, birthday, address, telephone, license plate, or social security number.

Don't use persons, places, or things that can be closely identified with you.

Don't use any word you can find in a dictionary.

Do combine upper/lower case letters, numbers, and special characters in your password.

8.7 Protecting Passwords

Do not share your password or reveal it to others.

If it is necessary to disclose your password, change it when the need for others to know it is over.

If you write down your password, lock it up. Do not leave it where it can be easily found.

Change your password at least every year.

8.8 Computer Viruses

Use Senate approved virus detection software on your computer.

Scan all incoming removable media, files, and programs for viruses.

Keep virus detection software up to date.

Use only authorized software or software from reputable sources

Report any virus infection to your System Administrator.

8.9 Imported Software

Do not import or download software without authorization.

Import or download software only from official sources.

Get source code if possible.

Use data integrity check programs to verify imported software.

Check out software on a computer not connected to a LAN.

Never execute programs from an unknown or unreliable source.

8.10 Protecting Against Disaster

Be sure to back up all critical data.

Make multiple copies of critical files.

Keep the back-up copies up to date.

Store backups in a secure place.

It is not necessary to backup SAA-provided programs. System Administrators maintain backups of software and of data stored on file servers.

If you have software that you’ve installed yourself, make a backup copy before you load it on your computer and write protect that copy. Store the original installation files in a secure location. Scan the files for viruses before making the backup, and do not proceed with the backup if you discover a virus.

Contact your System Administrator if you are not sure what files you need to back up yourself.

8.11 Deleting Files

Remember that simply deleting or erasing a file may leave residual data that is still accessible to someone with the proper tools.

Do not dispose of storage media or release computer equipment for replacement or repair without taking precautions to physically remove sensitive information, including residual data from deleted files.

8.12 Copyrights

Do not copy licensed software for the purpose of installing it on another computer.

Unauthorized reproduction of copyrighted software is against the law. Software installed on your computer is authorized for in-office use only.

Do not make copies of the documentation provided with Senate-supplied software unless copying is authorized in the license agreement.

8.13 Email Guidelines

Do not send unnecessary emails.

Write clear, courteous email messages that reflect well on you and the Senate.

Consider how your email message may be perceived if it is forwarded to another unintended recipient.

Do not send an email message while you are angry or upset.

Be careful with addressing. A simple keying error can result in your message being sent to the wrong individual or distribution list.

Do not have any expectation of privacy with email unless you encrypt your messages.

Do not react to inflammatory or unusual mail without checking with the originator to make sure he or she actually sent the message and that it has not been altered. Disguising identity or altering messages on email is not difficult.

Do not store or execute an attachment from an unknown source.

8.14 Communications

Do not use an analog line for anything other than its intended purpose.

Protect your MFA device. Do not lend it to anyone else. Lock up your PIN. Never keep the

PIN with your device.

8.15 Internet

Do not transmit anything over the Internet that requires confidentiality without encrypting it first.

If you receive an email message that is out of character for the sender, examine the message’s header information for evidence of a forgery. The header sent with Internet email messages identifies the sender, the host from which the message was sent, and a list of mail-forwarding hosts through which the message traveled to reach you.

For sensitive email, use an encryption key to create a digital signature to sign your email message. Signing a message in this way proves the sender is the true originator and that it has not been altered by anyone else.

Never store any email attachment from an unknown source on your computer

Never execute any program received in an email attachment from an unknown source

Disable ActiveX and Java on your Web browser before visiting any site where you are not sure of its authenticity. Hostile applets can delete files, read private data or infect your computer with malicious code.

Access only known sites that safeguard their postings from tampering.

Download executable files only from reputable sites.

Contact your Systems Administrator if you require an application to be installed on your system. Only download business required software from legitimate sites on the Internet and scan them using Anti-Virus prior to installation. Checksums or other provided methods to verify the authenticity of the application can also be used to ensure that the application has not been altered.

Scan every program obtained from the Internet with an up-to-date virus detection utility.

Remember that virus scanners detect only viruses and may not catch other types of destructive code that may be hidden in another program.

First test any software obtained from the Internet on a system that is not connected to the

Senate network to limit any damage in case it does contain destructive code.

Make sure you access files directly from the official source. Files posted by a secondary source may have been altered. A URL may have been changed so you may not actually be at the page you intended to access. Double check the URL to make sure you are at the correct location.

8.16 Reporting Violations

Notify your System Administrator of any suspected computer/communications misuse, abuse or security incident.

9 CLASSIFIED NATIONAL SECURITY INFORMATION

Only key members and staff of the U.S. Senate receive, produce, and maintain classified information vital to national security. This is official information which requires protection in the interests of U.S. national security. It may relate to national defense, foreign relations, economic matters, or critical technologies. It is the exclusive property of the U.S. government.

The Office of Senate Security under the Secretary of the Senate ensures that classified information is strictly controlled. Regulations governing its management are outlined in the U. S.

Senate Security Manual.

Only staff having a valid security clearance on file at the Office of Senate Security may have access to classified information or systems that process classified information. SAA staff with clearances are expected to be familiar with and abide by the regulations in the U. S. Senate Security Manual.

Senate staff may not sign for or directly accept classified documents. Couriers delivering classified material should be directed to the Office of Senate Security (SVC-217).

The Office of Senate Security (202-224-5632) should be called immediately if a document is discovered which appears to be classified or any time a breach involving classified information is suspected.

10 REMOTE NETWORK ACCESS

Remote access to common services on the Senate Network and specifically-authorized LANs are available to those with a valid MFA account and its associated device which may be the authorized user’s Senate provided mobile device with a Senate provided software authenticator app or a purpose specific hardware token (MFAT). Supervisors can acquire accounts for themselves and their staff by forwarding a request through TranSAAct.

A MFAT is a security device that automatically displays a randomly generated access code which is used as a password. The Senate provided mobile device or MFAT is typically used with Cisco

AnyConnect VPN software to access the Senate VPN.

All MFAT users are expected to:

safeguard the MFAT and never lend it to anyone else; and report a lost or stolen MFAT immediately to IT Support Services Telecom Help Desk (202-

224-9611).

While a MFAT is rugged, it is also a delicate instrument. Precautions to be followed include the following:

do not drop or bend it;

do not leave it in your car or anywhere else where it may be subjected to extremes of temperature;

do not subject it to undue mechanical stress or shock; and do not immerse it in liquid.

11 PERIMETER EMAIL FILTERING

Senate office expectations are that electronic messages including file attachments will be kept private except as authorized by the owner, sender, or recipient of the information.

Senate email users expect privacy protection against both interception of electronic communications while in transmission and against unauthorized intrusion into email stored on their systems.

The SAA respects Senate email users’ privacy and does not monitor the contents of their email communications unless specifically requested in writing by the Senator or Office Head and authorized by the SAA. In that instance, monitoring is performed on the requesting Office’s data as authorized and only for a limited length of time. All monitoring information is turned over to the requesting office. No monitoring data is retained on file by the SAA.

To protect the integrity of transmitted information and the integrity of Senate office systems, software programs may be used at the network perimeter to monitor email traffic for the presence of computer viruses, network worms, and other malicious code. These programs only examine email data for the presence of specific hostile code signatures.

If a perimeter scanning program detects a code signature in an email message or attachment, the hostile code will be removed and the sanitized message forwarded to the recipient. If the code cannot be removed, the recipient will be notified that the message contained a virus or other malicious code. The message will be quarantined (or deleted). No information on the content of the scanned messages or attachments is retained by the SAA.

In the case of global threats where a hostile code signature has not yet been identified, mail from a specific network address, with a specific header text or with a specific file attachment may be intercepted and quarantined (or deleted). This action will be taken for critical or unusual events that could compromise the quality, utility, or functionality of SAA services and operations and which may result in information loss or compromise, service denial or disruption for Senate users.

12 ACCESS TO RESTRICTED AREAS

Sergeant at Arms (SAA) employees and non-SAA personnel with access to restricted areas of the

Capitol or Senate office buildings are responsible for understanding and following adopted security practices and procedures, and notifying appropriate management of security violations and problems. SAA and contractor staff are expected to maintain the security in any access-controlled area by not allowing unauthorized entry. Any unusual events, suspicious individuals, or illegal activities are to be reported to the Capitol Police immediately.

13 SENATE ID CARD

All Senate staff are issued a photo identification card, commonly referred to as a Senate ID card.

This card is renewed at the beginning of each Congress. Senate contract staff receive special identification cards (different color border) valid for the period they are on assignment to the

Senate.

The Senate ID card is always to be worn and readily visible while within restricted access areas of the Capitol and office buildings. Individuals displaying a Senate ID card may use any entrance to the Capitol and the Congressional office buildings. Contractor access to some areas is limited to normal business hours. In the case of the Postal Square building, once the cardholder is inside of the building, the Senate ID card will allow entry to Sergeant at Arms Office space.

A Senate ID card in the possession of anyone other than the individual to whom it was issued will be confiscated by the Capitol Police. A police report will be filed, the individual’s supervisor notified, and the card will be voided.

The Senate ID card must be surrendered upon termination of employment or assignment to the

Senate. Supervisors are responsible for ensuring that cards from terminating staff, including contract staff, are returned.

Report lost or stolen cards immediately to the Senate ID Office. To obtain a replacement card, a form must be filed with the ID Office. A new card will be issued three days after the form is received.

13.1 Postal Square Sixth Floor and Other Senate Site Access

Staff working on the sixth floor of Postal Square or at other Senate sites are issued ID cards that are programmed for the proximity readers located in such areas. The security is controlled by the

U. S. Capitol Police. Access to restricted areas at such locations is determined by the zones coded into the ID card. Requests for changes to the coded access level should be directed through a

Branch Manager to the Director of Enterprise Operations.

The below ID card holder’s requirements should be followed.

Use the ID card only to gain access in the regular performance of duty. Any other use constitutes a security violation and may result in disciplinary action or legal prosecution. An

ID card in the possession of anyone other than the individual to whom the card is issued will be confiscated by the Capitol Police. A report will be filed, and the matter turned over to the Sergeant at Arms for disciplinary action.

Ensure that all doors used to gain access by proximity reader are properly closed and secured after each use.

Contact Capitol Police immediately any time the security of a restricted area is in question.

Report lost, stolen, or defective ID cards to your supervisor or Contracting Officer Technical

Representative who will then report the issue to SAA Admin Facilities at

Admin_Facilities@saa.senate.gov. Lost or stolen ID cards must be reported immediately so the access codes can be deactivated. If the ID card is subsequently recovered after a new one is issued, turn it in to SAA Administrative Services.

13.2 Care of ID Cards

The Senate ID Cards contain components which are sensitive to severe stress or temperature. To assure long badge life avoid the following actions:

Putting the card in a back pocket, unprotected, and sitting on it;

using the card as a tool such as a window scraper or to pry things open;

bending the card in excess; and exposing the card to harsh elements such as chemicals, dirt, or water.

13.3 Postal Square Visitors

All visitors, are screened at the Bureau of Labor Statistics (BLS) First Street Desks. BLS will only accept visitor registration requests from the Senate 6th floor receptionist.

Anyone who arranges for admittance of visitors to Postal Square is responsible for those visitors and will be held accountable for their actions while in the building.

Register visitors with the Front Desk at least twenty-four hours prior to the visit. The Front Desk will accept visitor authorization only from SAA employees and contractors located at Postal

Square.

SAA staff who have individuals visiting Postal Square on a regular basis may request that those individuals be placed on the Frequent Visitors List. Persons on this list will be admitted during regular BLS business hours without prior registration. Contact SAA Administration for information on how to add a visitor to this list.

Unplanned visitors or those who are not preauthorized can arrange for immediate admittance by providing a contact name and phone number of staff stationed at Postal Square. If the Senate staff contact is not available, the visitors will not be admitted.

Discuss special needs, such as open seminars where the names of expected visitors may not be known, with SAA Administrative Services well in advance of the visit.

During BLS security hours (6:00 p.m. to 6:00 a.m., Monday through Friday, Saturday, Sunday and

Holidays), visitors must be verified and escorted by a SAA employee to and from the BLS security desk. Outside of BLS security hours, visitors who are unable to provide proper identification and obtain a certified escort will be denied access to the building.

13.4 Postal Square Data Center

ID card Access to the PSQ Data Center is restricted to only those SAA and contractor employees whose work responsibilities require their frequent and regular presence in the area. These individuals may temporarily admit visitors to the Data Center provided such visitors are escorted by authorized Senate staff while in the area. A Visitors Log is maintained at each entrance to the

Data Center.

Staff admitting visitors into the Data Center are responsible for those visitors and will be held accountable for their actions while in the facility. It is their responsibility to escort the visitors and to ensure that they sign the Data Center Visitors Log. All persons receiving temporary access must sign the visitor’s log when they first enter and sign out when they leave the area for the day.

Tours, presentations, or any other activity involving the presence of groups of people in the Data

Center require prior approval from the Director of Enterprise Operations. Notify the supervisors of the sections located in this facility when the group will be visiting.

Photographing, filming, or videotaping is not allowed in this area without the permission of the

Committee on Rules and Administration.

14 CONTRACTOR RESPONSIBILITIES FOR CYBERSECURITY

For contractor products (hardware and/or software) and/or services (CPS) supplied to the

Senate, the contractor shall adhere to all relevant US Government standards for cybersecurity including but not limited to the latest published revisions of US Department of Commerce

National Institute of Standards and…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .