Attachment M SBM Oregon Standards Spreadsheet V 2.3.4 for Round 2.xlsx

XLSX spreadsheet 129 KB Posted

Attached to
Oregon State Based Insurance Marketplace Solution State and local contract opportunity
Solicitation number
S-DASOBO-00010624
Issued by
Marion County, Oregon

About this file

This document is an attachment related to a State-Based Insurance Marketplace (SBM) Solution Platform and related Customer Assistance Center contract opportunity issued by the Oregon Department of Administrative Services (DAS) on behalf of the Oregon Health Authority. The RFP seeks to procure a SBM solution and related services. Vendors are required to complete various tabs in the provided spreadsheet, including providing a solution description, mapping to the Oregon IT Control Standards, and indicating control applicability and implementation status. The contract opportunity is open to all qualified vendors, with the anticipated award of one contract resulting from this RFP process.

The pricing terms, funding requirements, and other salient commercial details are not included in this particular attachment. However, the attachment does provide an overview of the security and control standards that will be required of the selected vendor, demonstrating the State of Oregon's emphasis on information security and risk management for this critical system that will serve Oregon residents.

View the file

Other files for this state and local contract opportunity

Other files attached to Oregon State Based Insurance Marketplace Solution, newest first.
File Type Posted
ATTACHMENT A_S-DASOBO-00010624_Sample Contract.docx DOCX document
ATTACHMENT E_S-DASOBO-00010624 Price Proposal 4.4.2024.xlsx XLSX spreadsheet
ATTACHMENT H_S-DASOBO-00010624_Requirements.xlsx XLSX spreadsheet
RFP AMENDMENT NO 3 SBM RFP RESPONSES TO QUESTIONS FROM PROPOSERS_3 .docx DOCX document
Notice_S-DASOBO-00010624_Round _1_Competitive_Range_Determination Final.docx DOCX document
ATTACHMENT A1_S-DASOBO-00010624_Scope of Services.docx DOCX document
ATTACHMENT J_S-DASOBO-00010624_Project Timeline-Enrollment Baseline (1).docx DOCX document
ATTACHMENT K_S-DASOBO-00010624_Project-specific Acronyms and Definitions.docx DOCX document
Attachment E SBM Price Proposal Template for Round 2 .xlsx XLSX spreadsheet
AMENDMENT NO 3_RFP S-DASOBO-00010624_Extension QA Responses.docx DOCX document
Attachment L SBM Demo Use Cases for Round 2 .xlsx XLSX spreadsheet
ADDENDUM 6 SBM for Round 2 _Final.docx DOCX document
Cancellation Notice_S-DASOBO-00010624.pdf PDF
1_RFP_S-DASOBO-00010624_FINAL RELEASED.docx DOCX document
ATTACHMENT I_S-DASOBO-00010624 Current and Future FDSH Integration.pdf PDF
AMENDMENT NO 2_RFP S-DASOBO-00010624_VPPTC Insurance_FINAL RELEASED (002).docx DOCX document
ADDENDUM 5 SBM Instructions for Round 2 .docx DOCX document
Show all 17

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Instructions

Oregon Standards Spreadsheet Description and Use Instructions:
This tool is provided to assist agencies in understanding the solution and vendor's security status.

This is to be filled out by the Vendor IT and information security personnel.

Control Applicability:
o For vendor-managed solutions that are not hosted in State-managed environments, the terms "State", "agency", or specific state-related position should be interpreted as "vendor" or equivalent vendor-related postion.
o For Vendors working in State-managed environments, the agency requirements and reporting will apply unless otherwise stated in contract. Vendor organizational controls must appropriately match State Standards.
General information:
**The requirements are directly from the Statewide Information Technology (IT) Control Standards (Standards), as such the below sections are Static.
o Control (Column’s A-B)
o Control Name (Column C): Control details can be viewed in the attached cell note, or found in the Standards.
o Policies and procedures for each control family in this document are referenced in the Statewide Information Security Plan (the “Plan”). Individual policies for each control family may be linked or supplied as separate documents upon request. The individual policies reference the applicable controls that are defined in this document. If require more background, refer to the Statewide Information Security Plan for additional details on policies and procedures.
o The classification needs to be updated to Level 3 - Restricted when this document begins to be filled in.
Reference Links:
Statewide Information Technology (IT) Control Standards (Standards)
Statewide Information Security Program Plan
NIST SP 800.53 r5 Glossary (starts on page 394)
PHASE 1 BID RESPONSE
Proposer Task: Proposer will complete the remaining sections per instructions below.
o Fill out Solution Description tab.
o Fill out Standards tab.
o Requirement Managed by (Columns D-G): Proposer responds to indicate if the control is the responsibility of the agency, the vendor, a third pary or if it is a shared control.
X: signifies the control is the responsibility of the entity
Blank: signifies the control is not the entity's responsibility
o Control Implemented as is (Columns H-K): The Proposer selects whether the control is provided as part of the base solution, an add-on, from a third party, or not supported
X: signifies where the control is provided
Blank: signifies the control is not provided
o Description how Control is Met (Column L): Proposer shall provide the description of how the control is met. If the control is not supported, indicate not supported.
PHASE 2 VENDOR SSP RESPONSE
Vendor Task: Vendor will complete the remaining sections per instructions below.
o Update Solution Description tab, as needed.
o Fill out Phase 2 on Standards tab.
o Control Applicability (Columns M-P): Vendor responds to indicate if the control is a Common Control (common to the organization), System Specific control, Hybrid control (has both Common and System Specific aspects), or is Not Applicable.
X: signifies the control type
o Control Status is (Columns Q-S): The Vendor selects whether the control is Implemented, Partially Implemented (added information required in Description), and Not Implemented (added information required in Description).
X: signifies where the control is provided
o Describe how Control is Met (Column T): Vendor shall provide the description of how the control is met.
PHASE 3 AGENCY SSP RESPONSE
Agency Task: Agency will complete the remaining sections per instructions below.
o Fill out Phase 3 on Standards tab.
o Control Applicability (Columns U-X): Agency responds to indicate if the control is a Common Control (common to the organization), System Specific control, Hybrid control (has both Common and System Specific aspects), or is Not Applicable.
X: signifies the control type
o Control Status is (Columns Y-AA): The Agency selects whether the control is Implemented, Partially Implemented (added information required in Description), and Not Implemented (added information required in Description).
X: signifies where the control is provided
o Describe how Control is Met (Column AB): Agency shall provide the description of how the control is met.

https://www.oregon.gov/eis/cyber-security-services/documents/2019statewideinformationandcybersecuritystandardsv1.0.pdf?utm_source=EIS&utm_medium=egov_redirect&utm_campaign=https%3A%2F%2Fwww.oregon.gov%2Fdas%2Foscio%2Fdocuments%2F2019statewideinformationandcybersecuritystandardsv1.0.pdfhttps://www.oregon.gov/eis/cyber-security-services/Documents/eis-css-statewide-information-security-program-plan.pdfhttps://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdfhttps://www.oregon.gov/eis/cyber-security-services/Documents/eis-css-statewide-information-technology(IT)-control-standards.pdf Solution Description

Topics:Description:
Describe the solution.

Author: Include:

Solution purpose.

Solution architecture.

What is the shared responsibility model?

Author: Include:

What the vendor is responsible for?

What the customer (agency) is responsible for? Note, these may include the Complementary User Entity Controls (CUEC) from the SOC 2 Type 2 assessment report.

References:

NIST Cloud Computing Reference Architecture (NIST SP 500-292) NSA Uphold the Clould Shared Responsibility Model (Mar 2024) ISACA Now Blog, "The Customer's Responsibility in the Cloud Shared Responsibility Model", 9 September 2022

Examples:

https://aws.amazon.com/compliance/shared-responsibility-model/ https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility https://cloud.google.com/architecture/framework/security/shared-responsibility-shared-fate

Where is the solution physically hosted and with which hosting provider, including failover?
Where are the administration, support and development teams located?
What other services or solutions is the solution dependent on?

Author: Include:

Dependencies and the 3rd party vendors or partners involved.

Standards

ControlControl Name CONTROL ENHANCEMENT NAMES (are in caps)Phase 1 Bid ResponsePhase 2 Vendor SSP ResponsePhase 3 Agency SSP Response
Proposer Response
Requirement Managed byControl Implemented as:Describe how Control is Met.Control ApplicabilityControl StatusDescribe how Control is Met.Control ApplicabilityControl StatusDescribe how Control is Met.
AgencyVendorThird Party (identify who)Shared (agency/vendor)BaseAdd-onThird Party (identify who)Not supportedDescriptionCommon ControlSystem SpecificHybridNot ApplicableImplementedPartially ImplementedNot ImplementedDescriptionCommon ControlSystem SpecificHybridNot ApplicableImplementedPartially ImplementedNot ImplementedDescription
AC-1Access Control Policy and Procedures
AC-2Account Management

Author: Control Detail:

a. Define and document the types of accounts allowed and specifically prohibited for use within the system;

b. Assign account managers;

c. Require account manager or designee approval for group and role membership;

d. Specify:

1. Authorized users of the system;

2. Group and role membership; and

3. Access authorizations (i.e., privileges) and organization-defined attributes (as required) for each account;

e. Require approvals by account manager or designee for requests to create accounts;

f. Create, enable, modify, disable, and remove accounts in accordance with organization-defined policy, procedures, prerequisites, and criteria;

g. Monitor the use of accounts;

h. Notify account manager or designee within:

1. Twenty-four (24) hours when accounts are no longer required;

2. Eight (8) hours when users are terminated or transferred; and

3. Eight (8) hours when system usage or need-to-know changes for an individual;

i. Authorize access to the system based on:

1. A valid access authorization;

2. Intended system usage; and

3. Applicable federal and state laws and regulations;

j. Review accounts for compliance with account management requirements at least annually;

k. Establish and implement a process for changing shared or group account authenticators (if deployed) when individuals are removed from the group; and

l. Align account management processes with personnel termination and transfer processes.

AC-2(1) AUTOMATED SYSTEM ACCOUNT MANAGEMENT

Author: Control Detail:

Support the management of system accounts using automated mechanisms.

AC-2(2) AUTOMATED TEMPORARY AND EMERGENCY ACCOUNT MANAGEMENT

Author: Control Detail:

Automatically disable temporary and emergency accounts after no more than thirty (30) days.

AC-2(3) DISABLE ACCOUNTS

Author: Control Detail:

Disable accounts within twenty-four (24) hours when the accounts:

a. Have expired;

b. Are no longer associated with a user or individual;

c. Are in violation of organizational policy; or

d. Have been inactive for ninety (90) days

AC-2(4) AUTOMATED AUDIT ACTIONS

Author: Control Detail:

Automatically audit account creation, modification, enabling, disabling, and removal actions.

AC-2(5) INACTIVITY LOGOUT

Author: Control Detail:

Require that users log out when leaving their workstation unattended

AC-2(7) PRIVILEGED USER ACCOUNTS

Author: Control Detail:

a. Establish and administer privileged user accounts in accordance with a role-based access scheme;

b. Monitor privileged role or attribute assignments;

c. Monitor changes to roles or attributes; and

d. Revoke access when privileged role or attribute assignments are no longer appropriate.

AC-2(9) RESTRICTION ON USE OF SHARED AND GROUP ACCOUNTS

Author: Control Detail:

Only permit the use of shared and group accounts that meet organization-defined need with justification statement that explains why such accounts are necessary.

AC-2(12) ACCOUNT MONITORING FOR ATYPICAL USAGE

Author: Control Detail:

a. Monitor system accounts for organization-defined atypical usage; and

b. Report atypical usage of system accounts in accordance with the organization’s Incident Response Plan.

AC-2(13) DISABLE ACCOUNTS FOR HIGH-RISK INDIVIDUALS

Author: Control Detail:

Disable accounts of individuals within one (1) hour of discovery of user posing a significant risk.

AC-3 Access Enforcement Author: Control Detail:

Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.

AC-4 Information Flow Enforcement Author: Control Detail:

Enforce approved authorizations for controlling the flow of information within the system and between connected systems based on organization-defined information control flow policies.

AC-4(21) PHYSICAL OR LOGICAL SEPERATION OF INFORMATION FLOWS

Author: Control Detail:

Separate information flows logically or physically using organization-defined mechanisms and/or techniques to accomplish required separations by types of information.

AC-5 Separation of Duties Author: Control Detail:

a. Identify and document roles and permissions; and

b. Define system access authorizations to support separation of duties.

AC-6 Least Privilege Author: Control Detail:

Employ the principle of least privilege, allowing only authorized access for users, or processes acting on behalf of users, that are necessary to accomplish assigned organizational tasks.

AC-6(1) AUTHORIZE ACCESS TO SECURITY FUNCTIONS

Author: Control Detail:

Authorize access for privileged users to:

a. Security functions; and

b. Security-relevant information.

AC-6(2) NON-PRIVILEGED ACCESS FOR NONSECURITY FUNCTIONS

Author: Control Detail:

Require that users of system accounts (or roles) with access to all security functions use non-privileged accounts or roles, when accessing non-security functions.

AC-6(5) PRIVILEGED ACCOUNTS

Author: Control Detail:

Restrict privileged accounts on the system to authorized individuals with a need for elevated privileges.

AC-6(7) REVIEW OF USER PRIVILEGES

Author: Control Detail:

a. Review the privileges assigned to all users with privileges at least annually to validate the need for such privileges; and

b. Reassign or remove privileges, if necessary, to correctly reflect organizational mission and business needs.

AC-6(9) LOG USE OF PRIVILEGED FUNCTIONS

Author: Control Detail:

Log the execution of privileged functions.

AC-6(10) PROHIBIT NON-PRIVILEGED USERS FROM EXECUTING PRIVILEGED FUNCTIONS

Author: Control Detail:

Prevent non-privileged users from executing privileged functions.

AC-7 Unsuccessful Logon Attempts Author: Control Detail:

a. Enforce a limit of no more than three (3) consecutive invalid logon attempts by a user during a fifteen

(15) minute period;

1. For mobile devices: not more than ten (10) consecutive invalid attempts; and

b. Automatically lock the account or node for a minimum of thirty (30) minutes or until unlocked by an administrator.

AC-8 System Use Notification Author: Control Detail:

Prior to granting access to the system, display to users an approved system use notification that provides privacy and security notices consistent with applicable federal and state laws. Executive Orders, directives, policies, regulations, standards, and guidance.

a. The system use notification message shall, at a minimum, provide the following information:

1. Users are accessing a U.S. Government system;

2. System usage may be monitored, recorded, and subject to audit;

3. Unauthorized use of the system is prohibited and subject to criminal and civil penalties; and

4. Use of the system indicates consent to monitoring and recording;

b. Retain the notification message or banner on the screen until users acknowledge the usage conditions and take explicit actions to log on to or further access the system; and

c. For publicly accessible systems:

1. Display system use information notification, before granting further access to the publicly accessible system;

2. Display references, if any, to monitoring, recording, or auditing that are consistent with privacy accommodations for such systems that generally prohibit those activities; and

3. Include a description of the authorized uses of the system.

AC-11 Device Lock Author: Control Detail:

a. Prevent further access to the system by:

1. Initiating a device lock after fifteen (15) minutes of inactivity

i) For mobile devices, five (5) minutes; and

2. Requiring the user to initiate a device lock before leaving the system unattended; and

b. Retain the device lock until the authorized user reestablishes access using identification and authentication procedures.

AC-11(1) PATTERN-HIDING DISPLAYS

Author: Control Detail:

Conceal, via the device lock, information previously visible on the display, with a publicly viewable image.

AC-12 Session Termination Author: Control Detail:

Automatically terminate user sessions after 30 minutes of inactivity, unless otherwise defined in the applicable system security plan.

AC-14 Permitted Actions without Identification or Authentication Author: Control Detail:

a. Identify specific user actions that can be performed on the system without identification or authentication consistent with agency missions and business functions; and

b. Document and provide supporting rationale in system security plans for user actions that do not require identification and authorization.

AC-17 Remote Access Author: Control Detail:

a. Establish and document usage restrictions, configuration / connection requirements, and implementation guidance for each type of remote access allowed; and

b. Authorize each type of remote access to the system prior to allowing such connections.

AC-17(1) MONITORING AND CONTROL

Author: Control Detail:

Employ automated mechanisms to monitor and control remote access methods.

AC-17(2) PROTECTION OF CONFIDENTIALITY / INTEGRITY USING ENCRYPTION

Author: Control Detail:

Implement cryptographic mechanisms to protect the confidentiality and integrity of remote access sessions.

AC-17(3) MANAGED ACCESS CONTROL POINTS

Author: Control Detail:

Route all remote accesses through authorized and managed network access control points.

AC-17(4) PRIVILEGED COMMANDS AND ACCESS

Author: Control Detail:

a. Authorize the execution of privileged commands and access to security-relevant information via remote access only in a format that provides assessable evidence and when there is a compelling business need; and

b. Document the rationale for such access in the SSP.

AC-18 Wireless Access Author: Control Detail:

a. Establish configuration requirements, connection requirements, and implementation guidance for each type of wireless access; and

b. Authorize each type of wireless access to the system prior to allowing such connections.

AC-18(1) AUTHENTICATION AND ENCRYPTION

Author: Control Detail:

Protect wireless access to the system using authentication of both user and devices, and encryption.

AC-18(3) DISABLE WIRELESS NETWORKING

Author: Control Detail:

Disable, when not intended for use, wireless networking capabilities embedded within system components prior to issuance and deployment.

AC-19 Access Control for Mobile Devices Author: Control Detail:

a. Establish configuration requirements, connection requirements, and implementation guidance for organization-controlled mobile devices, to include when such devices are outside of controlled areas;

and

b. Authorize the connection of mobile devices to organizational systems.

AC-19(5) FULL DEVICE AND CONTAINER-BASED ENCRYPTION

Author: Control Detail:

Employ full-device encryption to protect the confidentiality and integrity of information on all mobile devices.

AC-20 Use of External Systems Author: Control Detail:

Establish terms and conditions, consistent with any trust relationships established with other organizations owning, operating, and / or maintaining external systems, allowing authorized individuals to:

a. Access internal information systems or system components from external systems; and

b. Process, store, or transmit organization-controlled information using external systems.

AC-20(1) LIMITS ON AUTHORIZED USE

Author: Control Detail:

Permit authorized individuals to use an external system to access the system or to process, store, or transmit organization-controlled information only after:

a. Verification of the implementation of controls on the external system as specified in the Organization’s security policies and plans; or

b. Retention of approved system connection or processing agreements with the organizational entity hosting the external system.

AC-20(2) PORTABLE STORAGE DEVICES

Author: Control Detail:

Restrict the use of organization-controlled portable storage devices by authorized individuals on external systems using agency documented and approved restrictions.

AC-21 INFORMATION SHARING

Author: Control Detail:

a. Enable authorized users to determine whether access authorizations assigned to a sharing partner match the information’s access and use restrictions for information sharing circumstances where user discretion is required; and

b. Employ automated mechanisms or manual processes compliant with agency requirements to assist users in making information sharing and collaboration decisions.

AC-22 Publicly Accessible Content Author: Control Detail:

a. Designate individuals that are authorized to make information publicly accessible;

b. Train authorized individuals to ensure that publicly accessible information does not contain nonpublic information;

c. Review the proposed content of information prior to posting onto the publicly accessible system to ensure that nonpublic information is not included; and

d. Review content on the publicly accessible system for non-public information at least quarterly and remove such information, if discovered.

AT-1Awareness and Training Policy and Procedures
AT-2Security Awareness and Training

Author: Control Detail:

a. Provide security literacy training to system users (including managers, senior executives, and contractors):

1. As part of initial training for new users and at least annually thereafter; and

2. When required by system changes or following significant events;

b. Employ supplement training as necessary to increase the security awareness of system users and to meet regulatory and compliance obligations;

c. Update literacy training and awareness content at least annually and following significant events; and

d. Incorporate lessons learned from internal or external security incidents into literacy training and awareness techniques.

AT-2(2) INSIDER THREAT

Author: Control Detail:

Provide literacy training on recognizing and reporting potential indicators of insider threat.

AT-2(3) SOCIAL ENGINEERING AND MINING

Author: Control Detail:

Provide literacy training on recognizing and reporting potential and actual instances of social engineering and social mining.

AT-3 Role-Based Training Author: Control Detail:

a. Provide role-based security training to software development personnel; personnel with privileged access; and other personnel as required by applicable laws, Executive Orders, directives, policies, regulations, standards, and guidance:

1. Before authorizing access to the system, information, or performing assigned duties, and at least annually thereafter; and

2. When required by system changes;

b. Update role-based training content at least annually and following significant events; and

c. Incorporate lessons learned from internal or external security incidents into role-based training.

AT-4 Security Training Records Author: Control Detail:

a. Document and monitor individual system security training activities, including security awareness training, and specific role-based system security training; and

b. Retain individual training records for at least one (1) year or one (1) year after completion of a specific training program.

AU-1Audit and Accountability Policy and Procedures
AU-2Events Logging

Author: Control Detail:

a. Identify the types of events that systems are capable of logging in support of the audit function that, at a minimum, includes:

1. For on-premises applications:

i) successful and unsuccessful account logon events;

ii) account management events;

iii) object access;

iv) policy change;

v) privilege functions;

vi) process tracking; and

vii) system events.

2. For Web applications:

i) all administrator activity;

ii) authentication checks;

iii) authorization checks;

iv) data deletions;

v) data access;

vi) data changes; and

vii) permission changes;

b. Coordinate the event logging function with other organizational entities requiring audit-related information to guide and inform the selection criteria for events to be logged;

c. Specify the event types for logging within the system consisting of a subset of the event types defined in AU-2 (a), along with the frequency of (or situation requiring) logging for each identified event type;

d. Provide a rationale for why the event types selected for logging are deemed to be adequate to support after-the-fact investigations of incidents; and

e. Review and update the event types selected for logging at least annually, or when a major change to the system occurs.

AU-3 Content of Audit Records Author: Control Detail:

Ensure that audit records contain information that establishes the following:

a. What type of event occurred;

b. When the event occurred;

c. Where the event occurred;

d. Source of the event;

e. Outcome of the event; and

f. Identity of any individuals, subjects, or objects/entities associated with the event.

AU-3(1) ADDITIONAL AUDIT INFORMATION

Author: Control Detail:

Generate audit records containing the information necessary to facilitate the reconstruction of events in the event (or suspected event) of unauthorized activity or malfunction.

AU-4 Audit Log Storage Capacity Author: Control Detail:

Allocate audit log storage capacity to accommodate State of Oregon records retention schedules and any other applicable retention requirements.

AU-5 Response to Audit Processing Failures Author: Control Detail:

a. Alert agency designated personnel or roles when the event of an audit logging process failure; and

b. Overwrite oldest record(s).

AU-6 Audit Review, Analysis, and Reporting Author: Control Detail:

a. Review and analyze system audit records at least weekly for indications of inappropriate or unusual activity;

b. Report findings to appropriate organization according to agency, State of Oregon, and Federal Incident Response Policy and procedures; and

c. Adjust the level of audit record review, analysis, and reporting within the system when there is a change in risk based on law enforcement information, intelligence information, or other credible sources of information.

AU-6(1) PROCESS INTEGRATION

Author: Control Detail:

Integrate audit record review, analysis, and reporting processes.

AU-6(3) CORRELATE AUDIT REPOSITORIES

Author: Control Detail:

Analyze and correlate audit records across different repositories to gain organization-wide situational awareness.

AU-7 Audit Record Reduction and Report Generation Author: Control Detail:

Provide and implement an audit reduction and report generation capability that:

a. Supports on-demand audit record review, analysis, and reporting requirements and after-the-fact investigations of incidents; and

b. Does not alter the original content or time ordering of audit records.

AU-7(1) AUTOMATIC PROCESSING

Author: Control Detail:

Provide and implement the capability to process, sort, and search audit records for events of interest based on individual items, or combinations of items contained in the audit records, as defined in AU-3.

AU-8 Time Stamps Author: Control Detail:

a. Use internal system clocks to generate time stamps for audit records; and

b. Record time stamps for audit records that meet organization-defined granularity of time measurement; and that use Coordinated Universal Time, have a fixed local time offset from Coordinated Universal Time, or that include the local time offset as part of the time stamp.

AU-9 Protection of Audit Information Author: Control Detail:

a. Protect audit information and audit logging tools from unauthorized access, modification, and deletion; and

b. Alert the Organization-assigned personnel upon detection of unauthorized access, modification, or deletion of audit information.

AU-9(4) ACCESS BY SUBSET OF PRIVILEGED USERS

Author: Control Detail:

Authorize access to management of audit logging functionality to only personnel that have a need to know and have been expressly authorized for this function.

AU-11 Audit Record Retention Author: Control Detail:

Retain audit records for at least ninety (90) days to provide support for after-the-fact investigations of incidents and to meet regulatory and organizational information retention requirements.

AU-12 Audit Record Generation Author: Control Detail:

a. Provide audit record generation capability for the event types the system is capable of auditing as defined in AU-2a on all information system and network components where audit capability is deployed/available;

b. Allow agency system owners, agency information owners, or system security administrators to select the event types that are to be logged by specific components of the system; and

c. Generate audit records for the event types defined in AU-2 that include the audit record content defined in AU-3.

CA-1Assessment, Authorization, and Monitoring Policy and Procedures
CA-2Security Assessments

Author: Control Detail:

a. Select the appropriate assessor or assessment team for the type of assessment to be conducted;

b. Develop a control assessment plan that describes the scope of the assessment including:

1. Controls and control enhancements under assessment;

2. Assessment procedures to be used to determine control effectiveness; and

3. Assessment environment, assessment team, and assessment roles and responsibilities;

c. Ensure the control assessment plan is reviewed and approved by the Authorizing Official (AO) or designated representative prior to conducting the assessment;

d. Assess the controls in the system and its environment of operation at least annually, or when there is a significant change to the system, to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting established security requirements;

e. Produce a control assessment report that document the results of the assessment; and

f. Provide the results of the control assessment to AO and other parties as described in the Oregon Statewide Information Security Plan.

CA-2(1) INDEPENDENT ASSESSORS

Author: Control Detail:

Employ independent assessors or assessment teams to conduct security control assessments.

CA-2(3) LEVERAGING RESULTS FROM EXTERNAL ORGANIZATIONS

Author: Control Detail:

Leverage the results of control assessments performed by external organizations.

CA-3 System Interconnections Author: Control Detail:

a. Approve and manage the exchange of information between the system and other systems by means of formal agreements (e.g., interconnection security agreements, information exchange security agreements, memoranda of understanding or agreement, service level agreements, user agreements, or nondisclosure agreements);

b. Document, as part of each exchange agreement, the interface characteristics, security requirements, controls, and responsibilities for each system, and the impact level of the information communicated; and

c. Review and update the agreements annually.

CA-5 Plan of Action and Milestones Author: Control Detail:

a. Develop a plan of action and milestones for the system to document the planned remediation actions of the Organization to correct weaknesses or deficiencies noted during the assessment of the controls and to reduce or eliminate known vulnerabilities in the system; and

b. Update existing plan of action and milestones at least monthly based on the findings from control assessments, independent audits or reviews, and continuous monitoring activities.

CA-6 Authorization Author: Control Detail:

a. Assign a senior official as the AO for the system;

b. Assign a senior official as the AO for common controls available for inheritance by organizational systems;

c. Ensure that the AO for the system, before commencing operations:

1. Accepts the use of common controls inherited by the system; and

2. Authorizes the system to operate;

d. Ensure that the Authorizing Official for common controls authorizes the use of those controls for inheritance by organizational systems; and

e. Update the authorizations at least every three (3) years or when a significant change occurs.

CA-7 Continuous Monitoring Author: Control Detail:

Develop a system-level continuous monitoring strategy and implement continuous monitoring in accordance with the Organization-level continuous monitoring strategy that includes:

a. Establishing the system-level metrics to be monitored and documented in the applicable SSP;

b. Establishing organization-defined frequencies (no less than annually) for monitoring and organization-defined frequencies (no less than annually) for assessment of control effectiveness;

c. Ongoing control assessments in accordance with the continuous monitoring strategy;

d. Ongoing monitoring of system and organization-defined metrics in accordance with the continuous monitoring strategy;

e. Correlation and analysis of information generated by control assessments and monitoring;

f. Response actions to address results of the analysis of control assessment and monitoring information; and

g. Reporting the security status of the system to the Agency Director, or designee thereof, at least annually.

CA-7(1) INDEPENDENT ASSESSORS

Author: Control Detail:

Employ independent assessors or assessment teams to monitor the controls in the system on an ongoing basis.

CA-7(4) RISK MONITORING

Author: Control Detail:

a. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following:

1. Effectiveness monitoring; 2. Compliance monitoring; and

3. Change monitoring.

CA-8 Penetration Testing Author: Control Detail:

Conduct penetration testing at least annually.

CA-8(1) INDEPENDENT PENETRATION TESTING AGENT OR TEAM

Author: Control Detail:

Employ an independent penetration testing agent or team to perform penetration testing on the system or system components.

CA-8(2) RED TEAM EXERCISES

Author: Control Detail:

Employ red-team exercises to simulate attempts by adversaries to compromise organizational systems in accordance with applicable rules of engagement.

CA-9 Internal System Connections Author: Control Detail:

a. Authorize internal connections of intra-system components to the system;

b. Document, for each internal connection, the interface characteristics, security requirements, and the nature of the information communicated;

c. Terminate internal system connections according to the session limit standards as specified under AC-12 and SC-10; and

d. Review annually the continued need for each internal connection.

CM-1Configuration Management Policy and Procedures
CM-2Baseline Configuration

Author: Control Detail:

a. Develop, document, and maintain current baseline configurations;

b. Review and update the baseline configurations:

1. At least annually or when a significant change occurs;

2. When required due to compliance requirement or direction from an authoritative body; and

3. When system components are installed or upgraded

CM-2(2) AUTOMATION SUPPORT FOR ACCURACY AND CURRENCY

Author: Control Detail:

Maintain the currency, completeness, accuracy, and availability of the baseline configuration of the system using organization-defined automated mechanisms.

CM-2(3) RETENTION OF PREVIOUS CONFIURATIONS

Author: Control Detail:

Retain secure images or templates, according to approved configuration standards, for all systems in the enterprise, of previous versions of baseline configurations of the system to support rollback.

CM-2(7) CONFIGURE SYSTEMS AND COMPONENTS FOR HIGH-RISK AREAS

Author: Control Detail:

State devices may only be used when traveling for approved state business; State-owned devices are not allowed to travel with an employee on personal travel outside of the country without prior CSS consultation.

a. When travelling internationally to countries sanctioned by the United States Treasury (https://ofac.treasury.gov/sanctions-programs-and-country-information) or United States State Department (https://www.state.gov/economic-sanctions-programs/):

1. All state business must be performed using a onetime use or burner device:

i) Onetime use or burner devices will have no access to state networks;

ii) Passwords for onetime use or burner devices must be different than daily Active Directory (AD) password;

iii) Username and password for onetime use or burner devices must not match any other account login and be unique; and

iv) Full disk encryption for onetime use or burner devices (Full disk encryption may be illegal in some countries. Please consult with DOJ before travel begins); and

2. Access to Enterprise Cloud Platforms is prohibited;

b. When travelling internationally to non-sanctioned countries, devices that contain data classified as level 3 or above may only contain that data which is necessary for the purpose associated with the travel. Any state-issued and -managed device must be hardened according to the Statewide Information Technology Control Standards. Additionally, Level 1, Published PAGE 18

2. Full disk encryption must be implemented on laptops and other portable computing devices (Full disk encryption may be illegal in some countries. Please consult with DOJ before travel begins);

3. Personnel must use VPN to access state networks; and

4. State-managed mobile devices (e.g., tablets, cell phones) must be enrolled in mobile device management (MDM);

c. Upon return from travel to a sanctioned country, user passwords must be reset and devices must be returned to organizational information technology support personnel to perform the following actions:

1. Devices must not connect to internal networks;

2. Any data must be copied to external media and scanned for malware before transferring to state network or managed devices;

3. Devices must be re-image before returning to checkout status, if applicable; and

d. Upon return from travel to a non-sanctioned country:

1. Device must be re-imaged before connecting to the state network; and

2. User passwords must be reset before returning to work

CM-3 Configuration Change Control Author: Control Detail:

a. Determine and document the types of changes to systems that are to be configuration-controlled;

b. Review proposed configuration-controlled changes to the system and approve or disapprove such changes with explicit consideration for security impact analyses;

c. Document configuration change decisions associated with the system;

d. Implement approved configuration-controlled changes to the system;

e. Retain records of configuration-controlled changes to systems according to applicable laws, Executive Orders, directives, policies, regulations, standards, and guidance;

f. Monitor and review activities associated with configuration-controlled changes to the system; and

g. Coordinate and provide oversight for configuration change control activities through regular change control meeting that convenes: The frequency of these meetings is dependent upon the needs of the agency and should take into account the typical number and impact of changes.

CM-3(2) TEST/VALIDATE/DOCUMENT CHANGES

Author: Control Detail:

Test, validate, and document changes to the system before finalizing the implementation of the changes

CM-3(4) SECURITY REPRESENTATIVE

Author: Control Detail:

Require security representation as a part of the change advisory board or process.

CM-4 Security Impact Analyses Author: Control Detail:

Analyze changes to systems to determine potential security impacts prior to change implementation.

CM-4(2) VERIFICATION OF SECURITY FUNTIONS

Author: Control Detail:

After system changes, verify that the impacted controls are implemented correctly, operating as intended, and producing the desired outcome with regard to meeting the security requirements for the system.

CM-5 Access Restrictions for Change Author: Control Detail:

Define, document, approve, and enforce physical and logical access restrictions associated with changes to the system.

CM-5(1) AUTOMATED ACCESS ENFORCEMENT AND AUDIT RECORDS

Author: Control Detail:

a. Enforce access restrictions using automated mechanisms; and

b. Automatically generate audit records of the enforcement actions.

CM-5(5) PRIVILEGE LIMITATIONS FOR PRODUCTION AND OPERATIONS

Author: Control Detail:

a. Limit privileges to change system components and system-related information within a production or operational environment; and

b. Review and reevaluate privileges at least quarterly CM-6 Configuration Settings Author: Control Detail:

a. Establish and document configuration settings for components employed within the system that reflect the most restrictive mode consistent with operational requirements using CIS Level 1 Benchmark;

b. Implement the configuration settings;

c. Identify, document, and approve any deviations from established configuration settings for components within the system based on operational requirements; and

d. Monitor and control changes to the configuration settings in accordance with organizational policies and procedures.

CM-6(1) AUTOMATED MANAGEMENT, APPLICATION AND VERIFICATION

Author: Control Detail:

Manage, apply, and verify configuration settings using organization-defined automated mechanisms.

CM-7 Least Functionality Author: Control Detail:

a. Configure the system to provide only essential capabilities;

b. Disable or remove by default, all network ports, protocols, server roles, software, and services.

CM-7(1) PERIODIC REVIEW

Author: Control Detail:

a. Configure the system to provide only essential capabilities;

b. Disable or remove by default, all network ports, protocols, server roles, software, and services.

CM-7(2) PREVENT PROGRAM EXECUTION

Author: Control Detail:

Prevent program execution in accordance with the Organization-defined policies, rules of behavior, and/or access agreements regarding software program usage and restrictions; rules authorizing the terms and conditions of software program usage.

CM-7(5) ALLOW BY EXCEPTION

Author: Control Detail:

a. Identify and maintain a current inventory of all software assets that are authorized to execute on the system;

b. Employ a deny-all, permit-by-exception methodology to allow the execution of authorized software programs on the system; and

c. Review and update the list of authorized software programs at least annually or when there is a change.

CM-8 System Component Inventory Author: Control Detail:

a. Develop and document an inventory of system components that:

1. Accurately reflects the current system;

2. Includes all components within the system;

3. Does not include duplicate accounting of components or components assigned to any other system;

4. Is at the level of granularity deemed necessary for tracking and reporting; and

5. Includes organization-defined information deemed necessary to achieve effective system component accountability; and

b. Review and update the system component inventory at least monthly.

CM-8(1) UPDATES DURING INSTALLATION/REMOVALS

Author: Control Detail:

Update the inventory of system components as part of component installations, removals, and system updates.

CM-8(3) AUTOMATED UNAUTHORIZED COMPONENT DETECTION

Author: Control Detail:

a. Detect the presence of unauthorized hardware, software, and firmware components within the system using automated mechanisms with a maximum five-minute delay in detection; and

b. Remove or quarantine unauthorized components from the network when unauthorized components are detected.

CM-9 Configuration Management Plan Author: Control Detail:

Develop, document, and implement a configuration management plan for the systems, that:

a. Addresses roles, responsibilities, and configuration management processes and procedures;

b. Establishes a process for identifying configuration items throughout the System Development Life Cycle (SDLC) and for managing the configuration of the configuration items;

Level 1, Published PAGE 21

c. Defines the configuration items for the system and places the configuration items under configuration management;

d. Is reviewed and approved by the Agency Chief Information Officer (CIO) or equivalent, or designee thereof; and

e. Protects the configuration management plan from unauthorized disclosure and modification.

CM-10 Software Usage Restrictions Author: Control Detail:

a. Use software and associated documentation in accordance with contract agreements and copyright laws;

b. Track the use of software and associated documentation protected by quantity licenses to control copying and distribution; and

c. Control and document the use of peer-to-peer file sharing technologies to ensure that this capability is not used for the unauthorized distribution, display, performance, or reproduction of copyrighted work.

CM-11 User-Installed Software Author: Control Detail:

a. Establish policies governing the installation of software by users;

b. Enforce software installation policies through procedural and automated methods; and

c. Monitor policy compliance continuously.

CM-12 Information Location Author: Control Detail:

a. Identify and document the location of a data inventory, based on the enterprise data governance policy and the specific system components on which the information is processed and stored;

b. Identify and document users who have access to the system and system components where the information is processed and stored; and

c. Document changes to the location (i.e., system or system components) where the information is processed and stored.

CM-12(1) AUTOMATED TOOLS TO SUPPORT INFORMATION LOCATION

Author: Control Detail:

Use automated tools to identify all sensitive data stored, processed, or transmitted through enterprise assets, including those located onsite or at a remote service provider, and update the enterprise's sensitive data inventory to ensure controls are in place to protect organizational information.

CP-1Contingency Planning Policy and Procedures
CP-2Contingency Plan

Author: Control Detail:

a. Develop a contingency plan for the system(s) that:

1. Identifies essential missions and business functions and associated contingency requirements;

2. Provides recovery objectives, restoration priorities, and metrics;

3. Addresses contingency roles, responsibilities assigned individuals with contact information;

4. Addresses maintaining essential missions and business functions despite a system disruption, compromise, or failure;

5. Addresses eventual, full system restoration without deterioration of the controls originally planned and implemented;

6. Addresses the sharing of contingency information; and

7. Is reviewed and approved by the Agency Head or equivalent;

b. Distribute copies of the contingency plan to key contingency personnel;

c. Coordinate contingency planning activities with incident handling activities;

d. Review the contingency plan for the system at least annually;

e. Update the contingency plan to address changes to the organization, system, or environment of operation and problems encountered during contingency plan implementation, execution, or testing;

f. Communicate contingency plan changes to key contingency personnel;

g. Incorporate lessons learned from contingency plan testing, training, or actual contingency activities into contingency testing and training; and

h. Protect the contingency plan from unauthorized modification and disclosure.

CP-2(1) COORDINATE WITH RELATED PLANS

Author: Control Detail:

Coordinate contingency plan development with organizational elements responsible for related plans

CP-2(3) RESUME ESSENTIAL MISSION

Author: Control Detail:

Plan for the resumption of all mission and business functions within time periods documented in the Continuity Plan of contingency plan activation

CP-2(8) IDENTIFY CRITICAL ASSETS

Author: Control Detail:

Identify and document critical system assets supporting essential mission and business functions.

CP-3 Contingency Training Author: Control Detail:

a. Provide contingency training to system users consistent with their assigned contingency roles and responsibilities:

1. Within ten (10) days of assuming a contingency role or responsibility;

2. When required by system changes; and Level 1, Published PAGE 23

3. At least annually thereafter; and

b. Review and update contingency training content at least annually and following significant events.

CP-4 Contingency Plan Testing Author: Control Detail:

a. Perform a functional exercise at least annually to test the contingency plan for the system to determine the effectiveness of the plan and the readiness to execute the plan;

b. Review the contingency plan test results; and

c. Initiate corrective actions, if needed.

CP-4(1) COORDINATE WITH RELATED PLANS

Author: Control Detail:

Coordinate Contingency Plan testing with organizational elements responsible for related plans.

CP-6 Alternate Storage Site Author: Control Detail:

a. Establish an alternate storage site, including necessary agreements to permit the storage and retrieval of system backup information; and

b. Ensure that the alternate storage site provides security controls equivalent to that of the primary site.

CP-6(1) ALTERNATE SITE/ SEPARATION FROM PRIMARY SITE

Author: Control Detail:

Identify an alternate storage site that is sufficiently separated from the primary storage site to reduce susceptibility to the same threats.

CP-6(3) ACCESSIBILITY

Author: Control Detail:

Identify potential accessibility problems to the alternate storage site in the event of an area-wide disruption or disaster and outlines explicit mitigation actions.

CP-7 Alternate Processing Site Author: Control Detail:

a. Establish an alternate processing site including necessary agreements to permit the transfer and resumption of system operations for essential missions and business functions within time-periods consistent with organization-defined recovery time and recovery point objectives when the primary processing capabilities are unavailable;

b. Make available at the alternate processing site, the equipment and supplies required to transfer and resume operations or put contracts in place to support delivery to the site within the Organizationdefined time-period for transfer and resumption; and

c. Provide controls at the alternate processing site that are equivalent to those at the primary site.

CP-7(1) SEPARATION FROM PRIMARY SITE

Author: Control Detail:

Identify an alternate processing site that is sufficiently separated from the primary processing site to reduce susceptibility to the same threats

CP-7(2) ACCESSIBILITY

Author: Control Detail:

Identify potential accessibility problems to the alternate processing site in the event of an area-wide disruption or disaster and outlines explicit mitigation actions.

CP-7(3) PRIORITY OF SERVICE

Author: Control Detail:

Develop alternate processing site agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives).

CP-8 Telecommunications Services Author: Control Detail:

Establish alternate telecommunications services, including necessary agreements to permit the resumption of system operations for essential mission and business functions within agency-defined recovery time and recovery point objectives when the primary telecommunications capabilities are unavailable at either the primary or alternate processing or storage sites

CP-8(1) PRIORITY OF SERVICE PROVISIONS

Author: Control Detail:

a. Develop primary and alternate telecommunications service agreements that contain priority-ofservice provisions in accordance with organizational availability requirements (including recovery time objectives); and

b. Request Telecommunications Service Priority for all telecommunications services used for national security emergency preparedness if the primary and/or alternate telecommunications services are provided by a common carrier.

CP-8(2) SINGLE POINTS OF FAILURE

Author: Control Detail:

Obtain alternate telecommunications services to reduce the likelihood of sharing a single point of failure with primary telecommunications services CP-9 System Backup…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .