20080126OCC-ITSecurityQualQuestions-Primary800-53.doc

DOC document 189 KB Posted

Attached to
Defined Contribution Plan Provider Federal contract opportunity
Solicitation number
CC-08-HQ-R-0021
Issued by
Department of the Treasury Office of the Comptroller of the Currency

About this file

Preliminary IT Security Self-Assessment

View the file

Other files for this federal contract opportunity

Other files attached to Defined Contribution Plan Provider, newest first.
File Type Posted
SF30Amend4.pdf PDF
SF30Amend3.pdf PDF
SF30Amend2.pdf PDF
FAR522123Reps Certs.rtf RTF text file
ResponsestoRFPQuestions.doc DOC document
Locations.xls XLS spreadsheet
SF30A.pdf PDF
401kSTATEMENTOFWORK021108.doc DOC document
AnnualNIST800-53SecuritySelf-AssessmentTemplateFIPS199LevelModer —
PastPerformanceQuestionnaire401(k).doc DOC document
401kSTATEMENTOFWORK021108.docm DOCM document
SF1449.pdf PDF
401(k)FeeDisclosureForm.pdf PDF
RFPCC-08-HQ-R-0021.rtf RTF text file
401KSummaryPlanDescriptionupdate0707.doc DOC document
EvaluationQuestionaireVersion6.doc DOC document
Show all 16

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Office of the Comptroller of the Currency

Third Party Service Provider Preliminary Information Security

Self Assessment

PURPOSE AND OBJECTIVE OF PRELIMINARY SECURITY SELF ASSESSMENT FOR THIRD PARTY SERVICE PROVIDERS” The Office of the Comptroller of the Currency (OCC) requires third party service providers to have an information security program that provides management, operational and technical safeguards to protect OCC information resources. This self-assessment questionnaire is based on security control requirements established by the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 and Federal Information Processing Standard (FIPS) 200. The security control references are based on the primary security topics identified in NIST SP 800-53 and, as a result, do not list all the 800-53 sub-controls. Three additional questions are specific to the OCC’s requirements. This questionnaire, once completed, will be analyzed by OCC Information Security Office (ISO) personnel to provide the OCC’s contracting officer with a preliminary assessment of the respondent’s security program. The ISO’s analysis will rely solely on the quality and completeness of the respondent’s answers. The ISO will conduct further analyses, review, and testing of the apparent winning bidder’s control environment based on the full SP 800-53 control requirements. Explanation of terms, concepts and other items related to federal information security requirements can be found in the Frequently Asked Questions (FAQ) at the end of this questionnaire.

INSTRUCTIONS FOR COMPLETING the OCC’S THIRD PARTY SERVICE PROVIDER PRELIMINARY INFORMATION SECURITY SELF ASSESSMENT SECURITY QUESTIONNAIRE

1. The self-assessment questionnaire must be completed by staff who are responsible for the security control environment that will be used to protect the confidentiality, integrity and availability of OCC information resources.

2. The OCC requires attestations for all self-assessments made by its third party service providers. Once completed, this questionnaire must be reviewed and approved by a senior officer of the organization. The formal attestation letter must be submitted as part of any official response to the request for proposal, statement of work, and/or other contracting document.

3. Terms used in this document are based on “Glossary of Key Information Security Terms, NIST Interagency Reports (NIST IR 7298), April 2006”. Additional guidance is available at the end of this document in a frequently asked questions section.

4. Please review the checklist included on the Contact Information and Signature page to ensure completeness prior to final submission.

TABLE OF CONTENTS

2TABLE OF CONTENTS

3CONTACT INFORMATION AND SIGNATURE PAGE

3CHECKLIST

4ATTESTATION LETTER

51. ACCESS CONTROL (AC)

52. AWARENESS AND TRAINING (AT)

53. AUDIT AND ACCOUNTABILITY (AU)

64. CERTIFICATION, ACCREDITATION, AND SECURITY ASSESSMENTS (CA)

65. CONFIGURATION MANAGEMENT (CM)

66. CONTINGENCY PLANNING (CP)

77. IDENTIFICATION AND AUTHENTICATION (IA)

78. INCIDENT RESPONSE (IR)

79. MAINTENANCE (MA)

810. MEDIA PROTECTION (MP)

811. PHYSICAL AND ENVIRONMENTAL PROTECTION (PE)

812. PLANNING (PL)

913. PERSONNEL SECURITY (PS)

914. RISK ASSESSMENT (RA)

915. SYSTEM AND SERVICES ACQUISITION (SA)

1016. SYSTEM AND COMMUNICATIONS PROTECTION (SC)

1017. SYSTEM AND INFORMATION INTEGRITY (SI)

1018. ENCRYPTION

1119. BREECH NOTIFICATION

1120. INFORMATION SECURITY GOVERNANCE & COMPLIANCE FRAMEWORK(S)

12FREQUENTLY ASKED QUESTIONS

12(1) Why does OCC require its third party service providers to complete this preliminary self assessment questionnaire?

12(2) What does the term ‘information security’ mean?

12(3) What does the term ‘information system’ mean?

12(4) What do the terms ‘confidentiality, integrity and availability’ mean?

13(5) How does the government define sensitive information?

13(6) How does the government define security control?

13(7) What is NIST Special Publication 800-53, Revision II, Recommended Security Controls for Federal Information Systems, December 2007 and where can I find more information on it?

13(8) What is FIPS 200, Minimum Security Requirements for Federal Information and Information Systems, March 2006 and where can I find more information on it?

14(9) What are the standards and guides used to create this preliminary self-assessment?

14(10) What other standards and guides are used in the OCC Information Security program?

CONTACT INFORMATION AND SIGNATURE PAGE

CHIEF INFORMATION SECURITY OFFICER

Name

Title

Date

Email

Phone Number

Signature

CHIEF INFORMATION OFFICER

Name

Email

CONTRACTING OFFICIAL

Name

Email

OTHER

Name

Email

CHECKLIST

COMPLETED ALL OF THE QUESTIONS ON THE SELF ASSESSMENT?

Assessment REVIEWED AND APPROVED BY KNOWLEDGEABLE STAFF?

PROVIDED CLARIFYING COMMENTS WHERE NECESSARY?

SIGNED AND DATED THE SIGNATURE PAGE?

ATTESTATION LETTER APPROVED AND SIGNED BY A SENIOR EXECUTIVE?

ATTESTATION LETTER

1. Statements made in response to the “Office of the Comptroller of the Currency’s Third Party Service Provider Preliminary Information Security Self Assessment” are accurate to the best of my knowledge;

2. Statements made in response to the “Office of the Comptroller of the Currency’s Third Party Service Provider Preliminary Information Security Self Assessment” were made by knowledgeable and qualified professionals in the internal control structure of my organization;

3. There has been no:

a. Knowledge of fraud involving (1) management, (2) employees who have significant roles in the internal control structure, or (3) others where the fraud could have a material effect on the organization’s ability to maintain operations, ensure adequate safeguards over client information, and/or cause serious harm to the reputation of the organization and/or it’s clients;

b. Communications from federal agencies concerning noncompliance with, or deficiencies in, financial reporting practices that could have a significant effect on the organization; and

c. Knowledge of any allegations of fraud or suspected fraud affecting the organization received in communications from employees, former employees, analysts, regulators, or others.

The undersigned attests to the completeness and accuracy of the applicable responses made in support of submitting “Office of the Comptroller of the Currency’s Third Party Service Provider Preliminary Information Security Self Assessment” to the Office of the Comptroller of the Currency.

Executive Officer (signature)

Printed Name

1. ACCESS CONTROL (AC)

Class: Technical

Does the service provider limit: (i) information system access to authorized users, processes acting on behalf of authorized users or devices (including other information systems); and (ii) the types of transactions and functions that authorized users are permitted to exercise?

YES/NO/Partial
Comments

2. AWARENESS AND TRAINING (AT)

Class: Operational

Does the service provider: (i) ensure that managers and users of organizational information systems are made aware of the security risks associated with their activities and of the applicable laws, corporate policies, standards, instructions, regulations, or procedures related to the security of the service provider’s information systems; and (ii) ensure that personnel are adequately trained to carry out their assigned information security-related duties and responsibilities?

YES/NO/Partial
Comments

3. AUDIT AND ACCOUNTABILITY (AU)

Does the service provider: (i) create, protect, and retain information system audit records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful, unauthorized, or inappropriate information system activity; and (ii) ensure that the actions of individual information system users can be uniquely traced to those users so they can be held accountable for their actions?

YES/NO/Partial
Comments

4. CERTIFICATION, ACCREDITATION, AND SECURITY ASSESSMENTS (CA)

Class: Management

Does the service provider: (i) periodically assess the security controls in organizational information systems to determine if the security controls are effective in their application; (ii) develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational information systems; (iii) authorize the operation of organizational information systems and any associated information system connections; and (iv) monitor information system security controls on an on-going basis to ensure the continued effectiveness of the security controls?

YES/NO/Partial
Comments

5. CONFIGURATION MANAGEMENT (CM)

Does the service provider: (i) establish and maintain baseline configurations and inventories of organizational information systems; (ii) establish and enforce security configuration settings for information technology products employed in organizational information systems; and (iii) monitor and control changes to the baseline configurations and to the constituent components of organizational information systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles?

YES/NO/Partial
Comments

6. CONTINGENCY PLANNING (CP)

Does the service provider establish, maintain, and effectively implement plans for emergency response, backup operations, and post-disaster recovery for organizational information systems to ensure the availability of critical information resources and continuity of operations in emergency situations?

YES/NO/Partial
Comments

7. IDENTIFICATION AND AUTHENTICATION (IA)

Does the service provider: (i) identify information system users, processes acting on behalf of users, or devices; and (ii) authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems?

YES/NO/Partial
Comments

8. INCIDENT RESPONSE (IR)

Does the service provider: (i) establish an operational incident response capability for organizational information systems that includes adequate preparation, detection, analysis, containment, recovery, and user response activities; (ii) track, document, and report incidents to appropriate organizational officials and/or authorities?

YES/NO/Partial
Comments

9. MAINTENANCE (MA)

Does the service provider: (i) perform periodic and timely maintenance on organizational information systems; and (ii) provide effective controls on the tools, techniques, mechanisms, and personnel used to conduct information system maintenance?

YES/NO/Partial
Comments

10. MEDIA PROTECTION (MP)

Does the service provider: (i) protect information contained in organizational information systems in printed form or on digital media; (ii) limit access to information in printed form or on digital media removed from organizational information systems to authorized users; and (iii) sanitize or destroy digital media before disposal or release for reuse?

YES/NO/Partial
Comments

11. PHYSICAL AND ENVIRONMENTAL PROTECTION (PE)

Does the service provider: (i) limit physical access to information systems, equipment, and the respective operating environments to authorized individuals; (ii) protect the physical plant and support infrastructure for information systems; (iii) provide supporting utilities for information systems; (iv) protect information systems against environmental hazards; and (v) provide appropriate environmental controls in facilities containing information systems?

YES/NO/Partial
Comments

12. PLANNING (PL)

Does the service provider develop, document, periodically update, and implement security plans for organizational information systems that describe the security controls in place or planned for the information systems and the rules of behavior for individuals accessing the information systems?

YES/NO/Partial
Comments

13. PERSONNEL SECURITY (PS)

Does the service provider: (i) ensure that individuals occupying positions of responsibility within its organization (including third-party service providers) are trustworthy and meet established security criteria for those positions; (ii) ensure that organizational information and information systems are protected during personnel actions such as terminations and transfers; and (iii) employ formal sanctions for personnel failing to comply with organizational security policies and procedures?

YES/NO/Partial
Comments

14. RISK ASSESSMENT (RA)

Does the service provider periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational information systems and the associated processing, storage, or transmission of organizational information?

YES/NO/Partial
Comments

15. SYSTEM AND SERVICES ACQUISITION (SA)

Does the service provider: (i) allocate sufficient resources to adequately protect organizational information systems; (ii) employ system development life cycle processes that incorporate information security considerations; (iii) employ software usage and installation restrictions; and (iv) ensure that third-party providers employ adequate security measures to protect outsourced organizational information, applications, and/or services?

YES/NO/Partial
Comments

16. SYSTEM AND COMMUNICATIONS PROTECTION (SC)

Does the service provider: (i) monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems; and (ii) employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational information systems?

YES/NO/Partial
Comments

17. SYSTEM AND INFORMATION INTEGRITY (SI)

Does the service provider: (i) identify, report, and correct information and information system flaws in a timely manner; (ii) provide protection from malicious code at appropriate locations within organizational information systems; and (iii) monitor information system security alerts and advisories and take appropriate actions in response?

YES/NO/Partial
Comments

18. ENCRYPTION

Class: OCC SPECIFIC Does the service provider use encryption technologies that are (i) compliant with National Institute of Standards and Technology FIPS PUB-142 standards; (ii) used to safeguard portable computing devices, including portable storage devices and media; (iii) used to safeguard workstations, laptops, servers, and backup tapes; and only allow remote access to it’s information technology resources via encrypted, two factor authentication technologies?

YES/NO/Partial
Comments

19. BREECH NOTIFICATION

Does the service provider have (i) policy, procedures, and regularly tested breech notification practices; (ii) does the service provider have an executive committee involved to oversee its breech notification practices; and (iii) does the service provider have publicly available materials on its breech notification practices?

YES/NO/Partial
Comments

20. INFORMATION SECURITY GOVERNANCE & COMPLIANCE FRAMEWORK(S)

Does the service provider have (i) an executive-sponsored information security governance practice that is linked to its Internal Control responsibilities; (ii) does the service provider adhere to either mandatory or voluntary information security frameworks, such as, COSO, CoBIT, ITIL, ISO 27001/ISO 17799/BS 7799, NSA IAM , or is required to report on its internal controls under the GBLA, SOX, HIPPA, FISMA, PCI, California State Bill– SB 1386, Safe Harbor, Basel II Accord or a framework or regulatory requirement not mentioned here; (iii) if the answer to (ii) is yes please note in the comment section below what framework is used and which regulatory requirements govern the service provider’s information security practices?

YES/NO/Partial
Comments

FREQUENTLY ASKED QUESTIONS

(1) Why does OCC require its third party service providers to complete this preliminary self assessment questionnaire?

The E-Government Act and various Office of Management and Budget (OMB) OMB directives require that all information systems that process government information have a minimum security configuration.

This requirement applies to all information and information systems that support the operations and assets of the agency, including those provided or managed by another agency, contractor, or other source.

(2) What does the term ‘information security’ mean?

The federal government defines ‘information security’ as “protecting information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction”.

(3) What does the term ‘information system’ mean?

An information system is a discrete set of information resources organized expressly for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information. Information system components include, but are not limited to, mainframes, servers, workstations, network components, operating systems, middleware, and applications. Network components can include, for example, such devices as firewalls, sensors (local or remote), switches, guards, routers, gateways, wireless access points, and network appliances. Servers can include, for example, database servers, authentication servers, electronic mail and web servers, proxy servers, domain name servers, and network time servers. Information system components are either purchased commercially off-the-shelf or are custom-developed and can be deployed in land-based, sea-based, airborne, and/or space-based information systems.

(4) What do the terms ‘confidentiality, integrity and availability’ mean?

The term confidentiality means preserving authorized restrictions on access and disclosure, including means for protecting personal privacy and proprietary information; integrity means guarding against improper information modification or destruction, and includes ensuring information nonrepudiation and authenticity; and availability means ensuring timely and reliable access to and use of information.

(5) How does the government define sensitive information?

Any information, the loss, misuse, or unauthorized access to or modification of which could adversely affect the national interest or the conduct of federal programs, or the privacy to which individuals are entitled under section 552a of Title 5, United States Code (the Privacy Act), but which has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense or foreign policy. The term sensitive not only refers to unclassified private data or proprietary information, but to highly classified national security government information as well.

(6) How does the government define security control?

OCC’s information security controls are based on the National Institute of Standards and Technology (NIST) Special Publication 800-53. Security controls are the management, operational, and technical safeguards or countermeasures prescribed for an information system to protect the confidentiality, integrity, and availability of a system and its information. Management controls focus on the management of risk and the management of information system security. Operational controls are those safeguards which are primarily implemented and executed by people (as opposed to systems). Technical controls are primarily implemented and executed by an information system through mechanisms contained in the hardware, software, or firmware components of the system. .

(7) What is NIST Special Publication 800-53, Revision II, Recommended Security Controls for Federal Information Systems, December 2007 and where can I find more information on it?

NIST SP 800-53 provides guidelines for selecting and specifying security controls for information systems supporting the executive agencies of the federal government. These guidelines apply to all components of an information system that process, store, or transmit federal information. The publication provides guidance to federal agencies implementing FIPS 200, Minimum Security Requirements for Federal Information and Information Systems. In addition to the agencies of the federal government, state, local, and tribal governments, and private sector organizations that compose the critical infrastructure of the United States, are encouraged to use these guidelines, as appropriate. More information can be found at http://csrc.nist.gov/publications/PubsSPs.html and at http://csrc.nist.gov/groups/SMA/fisma/controls.html.

(8) What is FIPS 200, Minimum Security Requirements for Federal Information and Information Systems, March 2006 and where can I find more information on it?

Federal Information Processing Standard (FIPS 200), Minimum Security Requirements for Federal Information and Information Systems, is mandatory, non-waiverable standard developed in response to the Federal Information Security Management Act of 2002. The combination of FIPS 200 and NIST Special Publication 800-53 requires a foundational level of security for all federal information and information systems. The agency's risk assessment process validates the security control set and determines if any additional controls are needed to protect agency operations (including mission, functions, image, or reputation), agency assets, individuals, other organizations, or the Nation. The resulting set of security controls establishes a level of “security due diligence” for the federal agency and its contractors. More information can be found at http://csrc.nist.gov/publications/PubsFIPS.html and at http://csrc.nist.gov/groups/SMA/fisma/controls.html.

(9) What are the standards and guides used to create this preliminary self-assessment?

OCC’s “Third Party Service Provider Preliminary Information Security Self Assessment” questionnaire is derived from NIST SP 800-53 Rev. 2 Recommended Security Controls for Federal Information Systems Dec 2007; NIST SP 800-53a “(Draft) Guide for Assessing the Security Controls in Federal Information Systems”, Dec 18, 2007; NIST SP 800-60 “Guide for Mapping Types of Information and Information Systems to Security Categories, June 2004”; and OCC’s “Annual NIST 800-53 Security Self-Assessment Template-FIPS 199 Level: Moderate Controls”, July 2007.

(10) What other standards and guides are used in the OCC Information Security program?

NIST maintains a complete library of standards and guides OCC and other federal agencies are required to implement and comply with at http://csrc.nist.gov/groups/SMA/fisma/library.html.

� NIST FIPS PUB 142: Security Requirements for Cryptographic Modules, May 25, 2001. http://csrc.nist.gov/publications/fips/fips140-2/fips1402.pdf

� E-Government Act of 2002., Section 3544 (b)(2)(D)(iii); the E-Government Act (P.L. 107-347), passed by the one hundred and seventh Congress and signed into law by the President in December 2002, recognized the importance of information security to the economic and national security interests of the United States. Title III of the E-Government Act, entitled the Federal Information Security Management Act (FISMA), emphasizes the need for organizations to develop, document, and implement an organization-wide program to provide security for the information systems that support its operations and assets.

P:\Acquisitions & Procurements\401k\2008 01 26 OCC-IT Security Qual Questions-Primary 800-53.doc -1-

File details come from the government source that posted it. Updated .