AnnualNIST800-53SecuritySelf-AssessmentTemplateFIPS199LevelModer
533 KB Posted
- Attached to
- Defined Contribution Plan Provider Federal contract opportunity
- Solicitation number
- CC-08-HQ-R-0021
About this file
Annual NIST IT Security Self-Assessment
Text of this file
Annual NIST 800-53 Security Self-Assessment Template
FIPS 199 Level: Moderate
SENSITIVE SECURITY INFORMATION
SENSITIVE SECURITY INFORMATION
SECURITY SELF-ASSESSMENT REPORT
FOR
<SYSTEM NAME
<DATE>
Program Manager: <INSERT PM NAME & CONTACT INFORMATION>
CONTACT INFORMATION AND SIGNATURE PAGE
CHIEF INFORMATION SECURITY OFFICER
Name
Title
Date
Phone Number
Signature
CHIEF INFORMATION OFFICER
Name
CONTRACTING OFFICAL
Name
OTHER
Name
OTHER
Name
TABLE OF CONTENTS
2INTRODUCTION
2Purpose and Objective of Assesment
31. ACCESS Control (AC)
3Class: Technical
72. AWARENESS AND TRAINING (AT)
7Class: Operational
83. AUDIT AND ACCOUNTABILITY (AU)
8Class: Technical
114. CERTIFICATION, ACCREDITATION, AND SECURITY ASSESSMENTS (CA)
11Class: Management
135. ConFIGURATION MANAGEMENT (CM)
13Class: Operational
156. ContINGENCY PLANNING (CP)
15Class: Operational
197. IDENTIFICATION AND AUTHENTICATION (IA)
19Class: Technical
218. INCIDENT RESPONSE (IR)
21Class: Operational
239. MAINTENANCE (MA)
23Class: Operational
2510. MEDIA PROTECTION (MP)
25Class: Operational
2711. PHYSICAL AND ENVIRONMENTAL PROTECTION (PE)
27Class: Operational
3112. PLANNING (PL)
31Class: Management
3313. PERSONNEL SECURITY (PS)
33Class: Operational
3514. RISK ASSESSMENT (RA)
35Class: Management
3715. SYSTEM AND SERVICES ACQUISITION (SA)
37Class: Management
3916. SYSTEM AND COMMUNICATIONS PROTECTION (SC)
39Class: Technical
4217. SYSTEM AND INFORMATION INTEGRITY (SI)
42Class: Operational
44APPENDIX A - LIST OF ACRONYMS
INTRODUCTION
The Office of the Comptroller of the Currency (OCC) requires that the <INSERT SYSTEM NAME OR THIRD PARTY SERVICE PROVIDER> undergo a self-assessment annually in accordance with the Federal Information Security Management Act (FISMA). Self-assessments provide a method for OCC officials to determine the current status of their respective information security programs. This report represents the security self-assessment of <INSERT SYSTEM NAME OR THIRD PARTY SERVICE PROVIDER> and follows the prescribed format outlined in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, Recommended Security Controls for Federal Information Systems.
Purpose and Objective of Assesment: OCC requires third parties entrusted with its data to have an information security program in place that provides management, operational and technical safeguards to protect its data. Additionally, all OCC systems, be they operated by the OCC itself and/or a third party are required to complete an annual security self-assessments to fulfill FISMA reporting requirements.
1. ACCESS Control (AC) Class: Technical
Organizations must limit: (i) information system access to authorized users, processes acting on behalf of authorized users or devices (including other information systems); and (ii) the types of transactions and functions that authorized users are permitted to exercise.
| Specific Control |
| Fully Satisfied (FS) |
| Partially Satisfied (PS) |
| Not Satisfied (NS) |
| Comments |
AC-1, Access Control Policy & Procedures
The organization develops, disseminates, periodically reviews/updates: (i) a formal, documented, access control policy that addresses purpose, scope, roles, responsibilities, and compliance; and (ii) formal, documented procedures to facilitate the implementation of the access control policy and associated access controls.
AC-2, Account Management
The organization manages information system accounts, including establishing, activating, modifying, reviewing, disabling, and removing accounts. The organization reviews information system accounts [at least annually]. The organization employs automated mechanisms to support the management of information system accounts. The information system automatically terminates temporary and emergency accounts after [three days]. The information system automatically disables inactive accounts after [30 days].
AC-3, Access Enforcement
The information system enforces assigned authorizations for controlling access to the system in accordance with applicable policy. The information system ensures that access to security functions (deployed in hardware, software, or firmware) and information is restricted to authorized personnel (e.g., security administrators).
AC-4, Information Flow Enforcement
The information system enforces assigned authorizations for controlling the flow of information within the system and between interconnected systems in accordance with applicable policy.
AC-5, Separation of Duties
The information system enforces separation of duties through assigned access authorizations.
AC-6, Least Privilege
The information system enforces the most restrictive set of rights/privileges or accesses needed by users (or processes acting on behalf of users) for the performance of specified tasks.
AC-7, Unsuccessful Login Attempts
The information system enforces a limit of [three] consecutive invalid access attempts by a user during a [30 minute] time period. The information system automatically [locks the account until intervening action is taken by the Help Desk] when the maximum number of unsuccessful attempts is exceeded.
AC-8, System Use Notification
The information system displays an approved, system use notification message before gaining system access informing potential users:
(i) that the user is accessing a US Government information system;
(ii) that system usage may be monitored, recorded, and subject to audit;
(iii) that unauthorized use of the system is prohibited and subject to criminal and civil penalties; and
(iv) that use of the system indicates consent to monitoring and recording.
The system use notification message provides appropriate privacy and security notices (based on associated privacy and security policies or summaries) and remains on the screen until the user takes explicit actions to log into the system.
AC-11, Session Lock
The information system prevents further access to the system by initiating a session lock that remains in effect until the user reestablishes access using appropriate I&A procedures.
AC-12, Session Termination
The information system automatically terminates a remote session after [five minutes] of inactivity. For workstations, a screen-lock function must be activated after 15 minutes of inactivity.
AC-13, Supervision & Review – Access Control
The organization supervises and reviews the activities of users with respect to the enforcement and usage of information system access controls.
AC-14, Permitted Actions Without Identification or Authentication
The organization identifies specific user actions that can be performed on the information system without identification or authentication. The organization permits actions to be performed without identification or authentication only to the extent necessary to accomplish mission objectives.
AC-17, Remote Access
The organization documents, monitors, and controls all methods of remote access (e.g., dial-up, Internet) to the information system, including remote access for privileged functions. Appropriate organization officials authorize each remote access method for the information system and authorize only the necessary users for each access method. The organization employs automated mechanisms to facilitate the monitoring and control of remote access methods. The organization uses encryption to protect the confidentiality of remote access sessions. The organization controls all remote accesses through a managed access control point.
AC-18, Wireless Access Restrictions
The organization:
(i) establishes usage restrictions and implementation guidance for wireless technologies; and
(ii) documents, monitors, and controls wireless access to the information system.
Appropriate organizational officials authorize the use of wireless technologies. The organization uses authentication and encryption to protect wireless access to the information system.
AC-19, Access Control for Portable & Mobile Systems
(i) establishes usage restrictions and implementation guidance for portable and mobile devices; and
(ii) documents, monitors, and controls device access to organizational networks.
Appropriate organizational officials authorize the use of portable and mobile devices.
AC-20, Personally Owned Information Systems
The organization restricts the use of personally owned information systems for official US Government business involving the processing, storage, or transmission of Federal information.
2. AWARENESS AND TRAINING (AT)
Class: Operational
Organizations must limit: (i) ensure that managers and users of organizational information systems are made aware of the security risks associated with their activities and of the applicable laws, executive orders, directives, policies, standards, instructions, regulations, or procedures related to the security of organizational information systems; and (ii) ensure that organizational personnel are adequately trained to carry out their assigned information security-related duties and responsibilities.
| Specific Control |
| Fully Satisfied (FS) |
| Partially Satisfied (PS) |
| Not Satisfied (NS) |
| Comments |
AT-1, Security Awareness and Training Policy and Procedures
The organization develops, disseminates, periodically reviews/updates: (i) a formal, documented, security awareness and training policy has been that addresses purpose, scope, roles, responsibilities, and compliance; and (ii) formal, documented procedures to facilitate the implementation of the security awareness and training policy and associated security awareness and training controls.
AT-2, Security Awareness
The organization ensures all users (including managers and senior executives) are exposed to basic information system security awareness materials before authorizing access to the system and [at least annually] thereafter.
AT-3, Security Training
The organization identifies personnel with significant information system security roles and responsibilities, documents those roles and responsibilities, and provides appropriate information system security training before authorizing access to the system and [annually] thereafter.
AT-4, Security Training Records
The organization documents and monitors individual information system security training activities, including basic security awareness training and specific information system security training.
3. AUDIT AND ACCOUNTABILITY (AU)
Class: Technical
Organizations must: (i) create, protect, and retain information system audit records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful, unauthorized, or inappropriate information system activity; and (ii) ensure that the actions of individual information system users can be uniquely traced to those users so they can be held accountable for their actions.
| Specific Control |
| Fully Satisfied (FS) |
| Partially Satisfied (PS) |
| Not Satisfied (NS) |
| Comments |
AU-1, Audit and Accountability Policy and Procedures
The organization develops, disseminates, periodically reviews/updates:
(i) a formal, documented, audit and accountability policy that addresses purpose, scope, roles, responsibilities, and compliance; and
(ii) formal, documented procedures to facilitate the implementation of the audit and accountability policy and associated audit and accountability controls.
AU-2, Auditable Events
The information system audit generates audit records for each of the following events: [process creation, process deletion, setting subject security attributes, process group and control terminal constraints, object creation, object receipt, object transmission, object deletion, object open, object close, setting object security attributes, importing or exporting an object, adding users, changing user attributes, adding groups, changing group attributes, user login, user logoff, changing user authentication information, authentication configuration, audit administration, use of system administration privilege, file system configuration, device definition and configuration, system configuration parameter definition, normal system startup and shutdown, RAS configuration, remote maintenance sessions, other system configuration events, access permission refusals, privilege failures, diagnostically detected faults and system errors, attempted alteration of system port configuration].
AU-3, Content of Audit Records
The information system captures sufficient information in audit records to establish what events occurred, the source of the events, and the outcome of the events. The information system provides the capability to include additional, more detailed information in the audit records for audit events identified by type, location, or subject.
AU-4, Audit Storage Capacity
The organization allocates sufficient audit record storage capacity and configures auditing to prevent such capacity being exceeded.
AU-5, Audit Processing
In the event of an audit failure or audit storage capacity being reached, the information system alerts appropriate organizational officials and takes the following action: [overwrite the oldest audit records].
AU-6, Audit Monitoring, Analysis, and Reporting
The organization regularly reviews/analyzes audit records for indications of inappropriate or unusual activity, investigates suspicious activity or suspected violations, reports findings to appropriate officials, and takes necessary actions.
AU-7, Audit Reduction and Report Generation
The information system provides an audit reduction and report generation capability.
AU-8, Time Stamps
The information system provides time stamps for use in audit record generation.
AU-9, Protection of Audit Information
The information system protects audit information and audit tools from unauthorized access, modification, and deletion.
AU-11, Audit Retention
The organization retains audit logs for [at least one year from the date of creation] to provide support for after-the-fact investigations of security incidents and to meet regulatory and organizational information retention periods
4. CERTIFICATION, ACCREDITATION, AND SECURITY ASSESSMENTS (CA)
Class: Management Organizations must: (i) periodically assess the security controls in organizational information systems to determine if the security controls are effective in their application; (ii) develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational information systems; (iii) authorize the operation of organizational information systems and any associated information system connections; and (iv) monitor information system security controls on an on-going basis to ensure the continued effectiveness of the security controls.
| Specific Control |
| Fully Satisfied (FS) |
| Partially Satisfied (PS) |
| Not Satisfied (NS) |
| Comments |
CA-1, Certification, Accreditation, and Security Assessment Policies and Procedures
The organization develops, disseminates, periodically reviews/updates:
(i) formal, documented security assessment and certification and accreditation policies that address purpose, scope, roles, responsibilities, and compliance; and
(ii) formal, documented procedures to facilitate the implementation of the security assessment and certification and accreditation policies and associated assessment, certification, and accreditation controls.
CA-2, Security Assessments
The organization conducts an assessment of the security controls in the information system [at least annually] to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system.
CA-3, Information System Connections
The organization authorizes all connections from the information system to other information systems outside of the accreditation boundary and monitors/controls the system interconnections on an on-going basis. Appropriate organizational officials approve system interconnection agreements.
CA-4, Security Certification
The organization conducts an assessment of the security controls in the information system to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system.
CA-5, Plan of Action and Milestones (POA&M)
The organization develops and updates [monthly], a POA&M for the information system that documents the organization’s planned, implemented, and evaluated remedial actions to correct any deficiencies noted during the assessment of the security controls and to reduce or eliminate known vulnerabilities in the system.
CA-6, Security Accreditation
The organization authorizes (i.e., accredits) the information system for processing before operations and updates the authorization [every three years or when a major change is made to the system]. A senior organizational official signs and approves the security accreditation.
CA-7, Continuous Monitoring
The organization monitors the security controls in the system on an on-going basis.
5. ConFIGURATION MANAGEMENT (CM)
Organizations must: (i) establish and maintain baseline configurations and inventories of organizational information systems; (ii) establish and enforce security configuration settings for information technology products employed in organizational information systems; and (iii) monitor and control changes to the baseline configurations and to the constituent components of organizational information systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.
| Specific Control |
| Fully Satisfied (FS) |
| Partially Satisfied (PS) |
| Not Satisfied (NS) |
| Comments |
CM-1, Configuration Management Policy and Procedures
The organization develops, disseminates, and periodically reviews/updates:
(i) a formal, documented, CM policy that addresses purpose, scope, roles, responsibilities, and compliance; and
(ii) formal, documented procedures to facilitate the implementation of the CM policy and associated CM controls.
CM-2, Baseline Configuration
The organization develops, documents, and maintains a current, baseline configuration of the information system and an inventory of the system’s constituent components. The organization updates the baseline configuration as an integral part of information system component installations.
CM-3, Configuration Change Control
The organization documents and controls changes to the information system. Appropriate organizational officials approve information system changes in accordance with organizational policies and procedures.
CM-4, Monitoring Configuration Changes
The organization monitors changes to the information system and conducts security impact analyses to determine the effects of the changes.
CM-5, Access Restrictions for Change
The organization enforces access restrictions associated with changes to the information system.
CM-6, Configuration Settings
The organization configures the security settings of IT products to the most restrictive mode consistent with information system operational requirements.
CM-7, Least Functionality
The organization configures the information system to provide only essential capabilities and specifically prohibits and/or restricts the use of functions, ports, protocols, and/or services in accordance with the UTNProtect Policy. The organization reviews the information system for compliance with this policy [at least every three years in conjunction with the certification and accreditation process and when a major change is made to thesystem]. After this, it is incumbent upon the Program Manager to notify the NMIMC Enterprise Assurance Team when the information system becomes non-compliant.
6. ContINGENCY PLANNING (CP)
Organizations must establish, maintain, and effectively implement plans for emergency response, backup operations, and post-disaster recovery for organizational information systems to ensure the availability of critical information resources and continuity of operations in emergency situations.
| Specific Control |
| Fully Satisfied (FS) |
| Partially Satisfied (PS) |
| Not Satisfied (NS) |
| Comments |
CP-1, Contingency Planning Policy and Procedures
The organization develops, disseminates, periodically reviews/updates:
(i) a formal, documented, contingency planning policy that addresses purpose, scope, roles, responsibilities, and compliance; and
(ii) formal, documented procedures to facilitate the implementation of the contingency planning policy and associated contingency planning controls.
CP-2, Contingency Plan
The organization develops and implements a contingency plan for the information system addressing contingency roles, responsibilities, assigned individuals with contact information, and activities associated with restoring the system after a disruption or failure. Designated officials within the organization review and approve the contingency plan and distribute copies of the plan to key contingency personnel. The organization coordinates contingency plan development with organizational elements responsible for related plans (e.g., Business Continuity Plan, Disaster Recovery Plan, COOP, Business Recovery Plan, and Incident Response Plan).
CP-3, Contingency Training
The organization trains personnel in their contingency roles and responsibilities with respect to the information system and provides refresher training [at least annually].
CP-4, Contingency Plan Testing
The organization tests the contingency plan for the information system [at least annually] using organization-defined tests and exercises to determine the plan’s effectiveness and the organization’s readiness to execute the plan. Appropriate officials within the organization review the contingency plan test results and initiate corrective actions. The organization coordinates contingency plan testing with organizational elements responsible for related plans (e.g., Business Continuity Plan, Disaster Recovery Plan, COOP, Business Recovery Plan, and Incident Response Plan).
CP-5, Contingency Plan Update
The organization reviews the contingency plan for the information system [at least annually] and revises the plan to address system/organizational changes or problems encountered during plan implementation, execution, or testing.
CP-6, Alternate Storage Sites
The organization identifies an alternate storage site and initiates necessary agreements to permit the storage of system backup information. The alternate storage site is geographically separated from the primary storage site so as not to be susceptible to the same hazards.
CP-7, Alternate Processing Sites
The organization identifies an alternate processing site and initiates necessary agreements to permit the resumption of information system operations for critical mission/business functions within [24 hours] when the primary processing capabilities are unavailable. The alternate processing site is geographically separated from the primary storage site so as not to be susceptible to the same hazards. The organization identifies potential accessibility problems to the alternate processing site in the event of a wide-area disruption or disaster and outlines explicit mitigation actions. Alternate processing site agreements contain priority-of-service provisions in accordance with the organization’s availability requirements.
CP-8, Telecommunications Services
The organization identifies primary and alternate telecommunications services to support the information system and initiates necessary agreements to permit the resumption of system operations for critical mission/business functions within [24 hours] when the primary telecommunications capabilities are unavailable. Primary and alternate telecommunications service agreements contain priority-of-service provisions in accordance with the organization’s availability requirements. Alternate telecommunications services do not share a single point of failure with primary telecommunications services.
CP-9, Information System Backup
The organization conducts backups of user-level and system-level information (including system state information) contained in the information system [weekly] and [partial] backups of user-level and system-level information [daily] and stores backup information at an appropriately secured location. The organization tests backup information [at least quarterly] to ensure media reliability and information integrity.
CP-10, Information System Recovery and Reconstitution
The organization employs mechanisms with supporting procedures to allow the information system to be recovered and reconstituted to the system’s original state after a disruption or failure.
7. IDENTIFICATION AND AUTHENTICATION (IA)
Organizations must: (i) identify information system users, processes acting on behalf of users, or devices; and (ii) authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.
| Specific Control |
| Fully Satisfied (FS) |
| Partially Satisfied (PS) |
| Not Satisfied (NS) |
| Comments |
IA-1, Identification and Authentication Policy and Procedures
The organization develops, disseminates, periodically reviews/updates:
(i) a formal, documented, I&A policy that addresses purpose, scope, roles, responsibilities, and compliance; and
(ii) formal, documented procedures to facilitate the implementation of the I&A policy and associated I&A controls.
IA-2, User Identification and Authentication
The information system uniquely identifies and authenticates users (or processes acting on behalf of users).
IA-3, Device Identification and Authentication
The information system identifies and authenticates specific devices before establishing a connection.
IA-4, Identifier Management
The organization manages user IDs by:
(i) uniquely identifying each user;
(ii) verifying the identity of each user;
(iii) receiving authorization to issue a user ID from an appropriate organization official;
(iv) ensuring that the user ID is issued to the intended party;
(v) disabling user ID after [30 days] of inactivity; and (vi) archiving user IDs.
IA-5, Authenticator Management
The organization manages information system authenticators (e.g., tokens, PKI certificates, biometrics, passwords, key cards) by:
(i) defining initial authenticator content;
(ii) establishing administrative procedures for initial authenticator distribution, for lost/compromised, or damaged authenticators, and for revoking authenticators; and
(iii) changing default authenticators upon system installation.
IA-6, Authenticator Feedback
The information system provides feedback to a user during an attempted authentication and that feedback does not compromise the authentication mechanism.
IA-7, Cryptographic Module Authentication
For authentication to a cryptographic module, the information system employs authentication methods that meet the requirements of FIPS PUB 140-2.
8. INCIDENT RESPONSE (IR)
Organizations must: (i) establish an operational incident response capability for organizational information systems that includes adequate preparation, detection, analysis, containment, recovery, and user response activities; and (ii) track, document, and report incidents to appropriate organizational officials and/or authorities.
| Specific Control |
| Fully Satisfied (FS) |
| Partially Satisfied (PS) |
| Not Satisfied (NS) |
| Comments |
IR-1, Incident Response Policy and Procedures
The organization develops, disseminates, periodically reviews/updates:
(i) a formal, documented, incident response policy that addresses purpose, scope, roles, responsibilities, and compliance; and
(ii) formal, documented, procedures to facilitate the implementation of the incident response policy and associated controls.
IR-2, Incident Response Training
The organization trains personnel in their incident response roles and responsibilities with respect to the information system and provides refresher training [at least annually].
IR-3, Incident Response Testing
The organization tests the incident response capability for the information system [at least annually] using organization-defined tests and exercises to determine the incident response effectiveness and documents the results.
IR-4, Incident Handling
The organization implements an incident handling capability for security incidents that includes preparation, detection and analysis, containment, eradication, and recovery. The organization employs automated mechanisms to support the incident handling process.
IR-5, Incident Monitoring
The organization tracks and documents information system security incidents on an on-going basis.
IR-6, Incident Reporting
The organization promptly reports incident information to appropriate authorities. The organization employs automated mechanisms to assist in the reporting of security incidents.
IR-7, Incident Response Assistance
The organization provides an incident support resource that offers advice and assistance to users of the information system for the handling and reporting of security incidents. The support resource is an integral part of the organization’s incident response capability. The organization employs automated mechanisms to increase the availability of incident response-related information and support.
9. MAINTENANCE (MA)
Organizations must: (i) perform periodic and timely maintenance on organizational information systems; and (ii) provide effective controls on the tools, techniques, mechanisms, and personnel used to conduct information system maintenance.
| Specific Control |
| Fully Satisfied (FS) |
| Partially Satisfied (PS) |
| Not Satisfied (NS) |
| Comments |
MA-1, System Maintenance Policy and Procedures
The organization develops, disseminates, periodically reviews/updates:
(i) a formal, documented, system maintenance policy that addresses purpose, scope, roles, responsibilities, and compliance; and
(ii) formal, documented procedures to facilitate the implementation of the information system maintenance policy and associated system maintenance controls.
MA-2, Periodic Maintenance
The organization schedules, performs, and documents routine preventive and regular maintenance on the components of the information system in accordance with manufacturer or vendor specifications and/or organizational requirements. The organization maintains a maintenance log for the information system that includes:
(i) date and time of maintenance;
(ii) name of individual performing the maintenance; (iii) name of escort, if necessary;
(iv) description of maintenance performed; and
(v) list of equipment removed or replaced, including identification numbers, if applicable.
MA-3, Maintenance Tools
The organization approves, controls, and monitors the use of information system maintenance tools and maintains the tools on an on-going basis.
MA-4, Remote Maintenance
The organization approves, controls, and monitors remotely executed maintenance and diagnostic activities.
MA-5, Maintenance Personnel
The organization maintains a list of personnel authorized to perform maintenance on the information system. Only authorized personnel perform maintenance on the information system.
MA-6, Timely Maintenance
The organization obtains maintenance support and spare parts for key information system components within [24 hours] of failure.
10. MEDIA PROTECTION (MP)
Organizations must: (i) protect information contained in organizational information systems in printed form or on digital media; (ii) limit access to information in printed form or on digital media removed from organizational information systems to authorized users; and (iii) sanitize or destroy digital media before disposal or release for reuse.
| Specific Control |
| Fully Satisfied (FS) |
| Partially Satisfied (PS) |
| Not Satisfied (NS) |
| Comments |
MP-1, Media Protection Policy and Procedures
The organization develops, disseminates, periodically reviews/updates:
(i) a formal, documented, media protection policy that addresses purpose, scope, roles, responsibilities, and compliance; and
(ii) formal, documented procedures to facilitate the implementation of the media protection policy and associated media protection controls.
MP-2, Media Access
The organization ensures that only authorized users have access to information in printed form or on digital media removed from the information system.
MP-3, Media Labeling
The organization affixes external labels to removable storage media and information system output indicating the distribution limitations and handling caveats of the information. The organization reviews requests for exemptions on a case-by-case basis. System hardware components do not have to be labeled in this way.
MP-4, Media Storage
The organization physically controls and securely stores system media, both paper and electronic, based on the highest FIPS PUB 199 security category of the information recorded on the media.
MP-5, Media Transport
The organization controls system media (paper and electronic) and restricts the pickup, receipt, transfer, and delivery of such media to authorized personnel.
MP-6, Media Sanitization
The organization sanitizes information system digital media using approved equipment, techniques, and procedures. The organization tracks, documents, and verifies media sanitization actions and periodically tests sanitization equipment/ procedures to ensure correct performance.
MP-7, Media Destruction and Disposal
The organization sanitizes or destroys information system digital media before its disposal or release for reuse outside the organization, to prevent unauthorized individuals from gaining access to and using the information contained on the media.
11. PHYSICAL AND ENVIRONMENTAL PROTECTION (PE)
Organizations must: (i) limit physical access to information systems, equipment, and the respective operating environments to authorized individuals; (ii) protect the physical plant and support infrastructure for information systems; (iii) provide supporting utilities for information systems; (iv) protect information systems against environmental hazards; and (v) provide appropriate environmental controls in facilities containing information systems.
| Specific Control |
| Fully Satisfied (FS) |
| Partially Satisfied (PS) |
| Not Satisfied (NS) |
| Comments |
PE-1, Physical and Environmental Protection Policy and Procedures
The organization develops, disseminates, periodically reviews/updates:
(i) a formal, documented, physical and environmental protection policy that addresses purpose, scope, roles, responsibilities, and compliance; and
(ii) formal, documented procedures to facilitate the implementation of the physical and environmental protection policy and associated physical and environmental protection controls.
PE-2, Physical Access Authentications
The organization develops and keeps current lists of personnel with authorized access to facilities containing systems (except for those areas within the facilities officially designated as publicly accessible) and issues appropriate authorization credentials (e.g., badges, ID cards, smart cards). Designated officials within the organization review and approve the access list and authorization credentials [at least monthly].
PE-3, Physical Access Control
The organization controls all physical access points (including designated entry/exit points) to facilities containing information systems (except for those areas within the facilities officially designated as publicly accessible) and verifies individual access authorizations before granting access to the facilities. The organization also controls access to areas officially designated as publicly accessible, as appropriate, in accordance with the organization’s assessment of risk.
PE-5, Access Control for Display Medium
The organization controls physical access to information system devices that display information to prevent unauthorized individuals from observing the display output.
PE-6, Monitoring Physical Access
The organization monitors physical access to systems to detect and respond to incidents. The organization monitors real-time intrusion alarms and surveillance equipment.
PE-7, Visitor Control
The organization controls physical access to information systems by authenticating visitors before authorizing access to facilities or areas other than areas designated as publicly accessible. The organization escorts visitors and monitors visitor activity, when required.
PE-8, Access Logs
The organization maintains a visitor access log to facilities (except for those areas within the facility officially designated as publicly accessible) that includes:
(i) name and organization of the person visiting;
(ii) signature of the visitor;
(iii) form of identification;
(iv) date of access;
(v) time of entry and departure;
(vi) purpose of visit; and
(vii) name and organization of the person(s) visited.
Designated officials within the organization review the access logs [daily] after closeout. The organization employs automated mechanisms to facilitate the maintenance and review of access logs.
PE-9, Power Equipment and Power Cabling
The organization protects power equipment and cabling supporting the system from damage and destruction.
PE-10, Emergency Shutoff
For specific locations within a facility containing concentrations of information system resources (e.g., data centers, server rooms, mainframe rooms), the organization provides the capability of shutting off power to any IT component that may be malfunctioning (e.g., due to an electrical fire) or threatened (e.g., due to a water leak) without endangering personnel by requiring them to approach the equipment.
PE-11, Emergency Power
The organization provides a short-term UPS to facilitate an orderly shutdown of the information system in the event of a primary power source loss.
PE-12, Emergency Lighting
The organization employs and maintains automatic emergency lighting systems that activate in the event of a power outage or disruption and that cover emergency exits and evacuation routes.
PE-13, Fire Protection
The organization employs and maintains fire suppression and detection devices/systems that can be activated in the event of a fire. Fire suppression and detection devices/systems activate automatically in the event of a fire.
PE-14, Temperature and Humidity Controls
The organization regularly maintains within acceptable levels and monitors the temperature and humidity within facilities containing information systems.
PE-15, Water Damage Protection
The organization protects the information system from water damage resulting from broken plumbing lines or other sources of water leakage by ensuring that master shutoff valves are accessible, working properly, and known to key personnel.
PE-16, Delivery and Removal
The organization controls information system-related items (i.e., hardware, firmware, software) entering and exiting the facility and maintains appropriate records of those items.
PE-17, Alternate Work Site
Individuals within the organization employ appropriate information system security controls at alternate work sites.
12. PLANNING (PL)
Organizations must develop, document, periodically update, and implement security plans for organizational information systems that describe the security controls in place or planned for the information systems and the rules of behavior for individuals accessing the information systems.
| Specific Control |
| Fully Satisfied (FS) |
| Partially Satisfied (PS) |
| Not Satisfied (NS) |
| Comments |
PL-1, Security Planning Policy and Procedures
The organization develops, disseminates, periodically reviews/updates: (i) a formal, documented, security planning policy that addresses purpose, scope, roles, responsibilities, and compliance; and (ii) formal, documented procedures to facilitate the implementation of the security planning policy and associated security planning controls.
PL-2, System Security Plan (SSP)
The organization develops and implements a security plan for the information system that provides an overview of the security requirements for the system and a description of the security controls in place or planned for meeting those requirements. Designated officials within the organization review and approve the plan.
PL-3, SSP Update
The organization reviews the SSP for the information system [every three years and when a major change is made to the system] and revises the plan to address system/ organizational changes or problems identified during plan implementation or security control assessments.
PL-4, Rules of Behavior (ROB)
The organization establishes and makes readily available to all information system users a set of rules that describes their responsibilities and expected behavior with regard to information system usage. The organization receives signed acknowledgement from users indicating that they have read, understand, and agree to abide by the rules of behavior, before authorizing access to the information system.
PL-5, Privacy Impact Assessment (PIA)
The organization conducts a PIA on the system.
13. PERSONNEL SECURITY (PS)
Organizations must: (i) ensure that individuals occupying positions of responsibility within organizations (including third-party service providers) are trustworthy and meet established security criteria for those positions; (ii) ensure that organizational information and information systems are protected during personnel actions such as terminations and transfers; and (iii) employ formal sanctions for personnel failing to comply with organizational security policies and procedures.
| Specific Control |
| Fully Satisfied (FS) |
| Partially Satisfied (PS) |
| Not Satisfied (NS) |
| Comments |
PS-1, Personnel Security Policy and Procedures
The organization develops, disseminates, periodically reviews/updates:
(i) a formal, documented, personnel security policy that addresses purpose, scope, roles, responsibilities, and compliance; and
(ii) formal, documented procedures to facilitate the implementation of the personnel security policy and associated personnel security controls.
PS-2, Position Categorization
The organization assigns a risk designation to all positions and establishes screening criteria for individuals filling those positions. The organization reviews and revises position risk designations [every five to 15 years, depending on the required clearance level].
PS-3, Personnel Screening
The organization screens individuals requiring access to organizational information and systems before authorizing access.
PS-4, Personnel Termination
When employment is terminated, the organization terminates information system access, conducts exit interviews, ensures the return of all organizational information system-related property (e.g., keys, identification cards, building passes), and ensures that appropriate personnel have access to official records created by the terminated employee that are stored on organizational information systems.
PS-5, Personnel Transfer
The organization reviews information systems/facilities access authorizations when individuals are reassigned or transferred to other positions within the organization and initiates appropriate actions (e.g., reissuing, keys, identification cards, building passes; closing old accounts and establishing new accounts; and changing system access authorizations).
PS-6, Access Agreements
The organization completes appropriate access agreements (e.g., nondisclosure agreements, acceptable use agreements, ROB, conflict of interest agreements) for individuals requiring access to organizational information and information systems before authorizing access.
PS-7, Third-Party Personnel Security
The organization establishes personnel security requirements for third-party providers (e.g., service bureaus, contractors, and other organizations providing information system development, IT services, outsourced applications, and network and security management) and monitors provider compliance to ensure adequate security.
PS-8, Personnel Sanctions
The organization employs a formal sanctions process for personnel failing to comply with established information security policies and procedures.
14. RISK ASSESSMENT (RA)
Organizations must periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational information systems and the associated processing, storage, ortransmission of organizational information.
| Specific Control |
| Fully Satisfied (FS) |
| Partially Satisfied (PS) |
| Not Satisfied (NS) |
| Comments |
RA-1, Risk Assessment Policy and Procedures
The organization develops, disseminates, periodically reviews/updates: (i) a formal, documented risk assessment policy that addresses purpose, scope, roles, responsibilities, and compliance; and (ii) formal, documented procedures to facilitate the implementation of the risk assessment policy and associated risk assessment controls.
RA-2, Security Categorization
The organization categorizes the information system and the information processed, stored, or transmitted by the system in accordance with FIPS PUB 199 and documents the results (including supporting rationale) in the SSP. Designated senior-level officials within the organization review and approve the security categorizations.
RA-3, Risk Assessment
The organization conducts assessments of the risk and magnitude of harm that could result from the unauthorized access, use, disclosure, disruption, modification, or destruction of information and information systems that support the operations and assets of the agency.
RA-4, Risk Assessment Update
The organization updates the risk assessment [every three years] or whenever there are significant changes to the information system, the facilities where the system resides, or other conditions that may impact the security or accreditation status of the system.
RA-5, Vulnerability Scanning
Using appropriate vulnerability scanning tools and techniques, the organization scans for vulnerabilities in the information system [at least annually] or when significant new vulnerabilities affecting the system are identified and reported. Vulnerability scanning tools include the capability to readily update the list of vulnerabilities scanned. The organization updates the list of information system vulnerabilities [monthly] or when significant, new vulnerabilities are identified and reported.
15. SYSTEM AND SERVICES ACQUISITION (SA)
Organizations must: (i) allocate sufficient resources to adequately protect organizational information systems; (ii) employ system development life cycle processes that incorporate information security considerations; (iii) employ software usage and installation restrictions; and (iv) ensure that third-party providers employ adequate security measures to protect outsourced organizational information, applications, and/or services.
| Specific Control |
| Fully Satisfied (FS) |
| Partially Satisfied (PS) |
| Not Satisfied (NS) |
| Comments |
SA-1, System and Services Acquisition Policy and Procedures
The organization develops, disseminates, periodically reviews/updates:
(i) a formal, documented, system and services acquisition policy that addresses purpose, scope, roles, responsibilities, and compliance; and
(ii) formal, documented procedures to facilitate the implementation of the system and services acquisition policy and associated services acquisition controls.
SA-2, Allocation of Resources
The organization determines, documents, and allocates as part of its capital planning and investment control process the resources required to adequately protect the information system.
SA-3, Life Cycle Support
The organization manages the information system using a System Development Life Cycle (SDLC) methodology that includes information security considerations.
SA-4, Acquisitions
The organization includes security requirements and/or security specifications, either explicitly or by reference, in information system acquisition contracts based on an assessment of risk.
SA-5, Information System Documentation
The organization ensures that adequate documentation for the information system and its constituent components is available, protected when required, and distributed to authorized personnel. The organization includes documentation describing the functional properties of the security controls employed within the information system with sufficient detail to permit analysis and testing of the controls.
SA-6, Software Usage Restrictions
The organization complies with software usage restrictions.
SA-7, User Installed Software
The organization enforces explicit rules governing the downloading and installation of software by users.
SA-8, Security Design Principles
The organization designs and implements the information system using security engineering principles.
SA-9, Outsourced Information System Services
The organization ensures that third-party providers of information system services employ adequate security controls in accordance with applicable federal laws, directives, policies, regulations, standards, guidance, and established SLAs. The organization monitors security control compliance.
SA-11, Developer Security Testing
The information system developer creates a ST&E Plan, implements the plan, and documents the results. Developmental security test results may be used in support of the security C&A process for the delivered information system.
16. SYSTEM AND COMMUNICATIONS PROTECTION (SC)
Organizations must: (i) monitor, control, and protect organizational communications(i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems; and (ii) employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational information systems.
| Specific Control |
| Fully Satisfied (FS) |
| Partially Satisfied (PS) |
| Not Satisfied (NS) |
| Comments |
SC-1, System and Communications Protection Policy and Procedures
The organization develops, disseminates, periodically reviews/updates:
(i) a formal, documented, system and communications protection policy that addresses purpose, scope, roles, responsibilities, and compliance; and
(ii) formal, documented procedures to facilitate the implementation of the system and communications protection policy and associated system and communications protection controls.
SC-2,…
This is the start of the file's text. The full file is on GovTribe.
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| SF30Amend4.pdf | ||
| SF30Amend3.pdf | ||
| SF30Amend2.pdf | ||
| ResponsestoRFPQuestions.doc | DOC document | |
| Locations.xls | XLS spreadsheet | |
| FAR522123Reps Certs.rtf | RTF text file | |
| SF30A.pdf | ||
| PastPerformanceQuestionnaire401(k).doc | DOC document | |
| 401kSTATEMENTOFWORK021108.docm | DOCM document | |
| SF1449.pdf | ||
| 401(k)FeeDisclosureForm.pdf | ||
| RFPCC-08-HQ-R-0021.rtf | RTF text file | |
| 401KSummaryPlanDescriptionupdate0707.doc | DOC document | |
| 401kSTATEMENTOFWORK021108.doc | DOC document | |
| 20080126OCC-ITSecurityQualQuestions-Primary800-53.doc | DOC document | |
| EvaluationQuestionaireVersion6.doc | DOC document |
Show all 16
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
File details come from the government source that posted it. Updated .