WCMBP_Section_J_Attachment_16_-_Computer_Security_Handbook_4-0_AMD_5.pdf
PDF 5 MB Posted
- Attached to
- Solicitation Notice for Workers' Compensation Medical Bill Processing (WCMBP) Federal contract opportunity
- Solicitation number
- DOL141RP21903
About this file
WCMBP_Section_J_Attachment_16_-_Computer_Security_Handbook
View the file
Other files for this federal contract opportunity
Show all 50
Solicitation Notice for Workers' Compensation Medical Bill Processing (WCMBP) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
U.S. DEPARTMENT OF LABOR
Office of the Chief Information Officer
Computer Security Handbook Edition 4.0
INTRODUCTION
VERSION 1.0
AUGUST 2011
U.S. Dept. of Labor Computer Security Handbook Introduction
Version 1.0 ii August 2011
DOCUMENT CHANGE HISTORY
Date Filename / Version # Author Revision Description
8/1/2011 1.0 OCIO Security Final
DOCUMENT REVIEW HISTORY
Date Version # Reviewers
Version 1.0 iii April 2011
TABLE OF CONTENTS
1 EXECUTIVE SUMMARY
2 VERSION 4.0 RELEASE NOTES
3 INTRODUCTION
4 PURPOSE
5 USING THE HANDBOOK
6 OBJECTIVES
7 SCOPE AND APPLICABILITY
8 DEFINITIONS
9 COMPUTER SECURITY HANDBOOK VOLUMES
Version 1.0 1 April 2011
1 EXECUTIVE SUMMARY
The Department of Labor (DOL) Computer Security Handbook (CSH) publishes Department-wide policies, procedures, standards, and templates. Minimum requirements contained within these items are in compliance with National Institute of Standards and Technology (NIST) guidance and satisfy the requirements of the E-Government Act including Title III, Federal Information Security Management Act (FISMA), the Clinger-Cohen Act, OMB Circular A-130, Homeland Security Presidential Directives HSPD 7, 8 and 12, and the DOL Cyber Security Program Plan (CSPP). The handbook was developed to facilitate commonality in planning, assessment, implementation, and reporting formats throughout the Department.
All DOL major applications (MAs) and general support systems (GSSs) require some level of protection, which is determined by evaluating the sensitivity and criticality of the information processed, the relationship of the system to the organization’s mission, and the economic value of the system’s components. The DOL CSH provides guidance on implementing the cyber security policy outlined in DOL Manual Series-9, Chapters 400, 900, 1200, the DOL CSPP, NIST publications, and best practices from other federal and private sector organizations. The effective application of the CSH will help agencies evaluate and strengthen their information technology architecture to protect the confidentiality, integrity, and availability of DOL data and systems.
This handbook is a reference for Information Security Officers (ISO) and other individuals, including contractors, who perform cyber security-related tasks, such as developing system security plans (SSPs), developing contingency plans, and authorizing DOL information systems.
This CSH is divided into volumes that each address a specific subject and is structured around NIST Special Publication (SP) 800-53 where each volume represents a different family of controls (e.g. Volume 14 Risk Assessment). Because the CSH is varied in its approach, separate volumes help users focus only on the most applicable subject. Volumes containing templates will also include easy-to-follow instructions.
Release 4.0 of the introduction and all accompanying volumes supersedes all previous versions of the DOL CSH.
http://www.cio.gov/documents/e_gov_act_2002.pdf� http://www.cio.gov/documents_details.cfm/uid/1F432CB6-2170-9AD7-F2F9BFC351F83400/structure/Laws,%20Regulations,%20and%20Guidance/category/IT%20Related%20Laws%20and%20Regulations� http://labornet.dol.gov/workplaceresources/policies/DLMS/DLMS09/dlms9-0400.htm� http://labornet.dol.gov/workplaceresources/policies/DLMS/DLMS09/dlms9-0900.htm� http://labornet.dol.gov/workplaceresources/policies/DLMS/DLMS09/dlms9-1200.htm�
Version 1.0 2 April 2011
2 VERSION 4.0 RELEASE NOTES
The following list outlines the summary of major modifications to the 4th edition of the DOL
CSH:
• Volume content (i.e. control family content) has been updated to align with NIST SP 800-53, Revision 3 and additional considerations have been made for the upcoming release of 800-53 Revision 4.
• DOL policy sections, which were previously distributed such that each control family had a separate, individual policy document (previously referred to as “Section I”), have been consolidated into a single, central policy document (CSH Volume 0).
• Sections that were duplicative in previous editions of the CSH have been removed from individual volumes and relocated into the central policy document (CSH Volume 0) and/or introduction document.
• Several format changes, which vary from previous CSH editions, have been incorporated into the 4th
• NIST-defined implementation “priority ratings” have been included in the 4 edition of the CSH to streamline the policy and procedure volumes, including the overall length and file size of documents.
th edition of the CSH for each control within each of the procedure documents (note that these ratings do not relate to risk, threat, or criticality, but rather are only meant to represent groupings of control elements to be implemented in sequence).
Version 1.0 3 April 2011
3 INTRODUCTION
The DOL CSH is intended to provide policies, procedures, standards, and processes to assist DOL agencies in implementing effective security programs that achieve compliance with relevant laws, regulations, and policies governing the security of federal information systems.
As the fundamental laws, guidelines, and standards upon which this Handbook is based change periodically, DOL policies must evolve and align accordingly. For this reason and to adapt to evolving and maturing technologies, the Office of the Chief Information Officer’s (OCIO) Security Program is releasing this updated version of the CSH. Additionally, a feedback period was provided and feedback from DOL agencies has been incorporated into this release as appropriate.
Version 1.0 4 April 2011
4 PURPOSE
The purpose of this handbook is to update Department-wide policies, procedures, guidance, and templates in better alignment with the latest revisions of NIST guidance and DOL internal business and IT directives. The updated CSH will help satisfy evolving FISMA requirements as well as the E-Government Act, the Clinger-Cohen Act, Office of Management Budget (OMB) guidance, Homeland Security Presidential Directives (HSPDs), and the DOL Cyber Security Program Plan (CSPP). The handbook was updated to facilitate commonality in planning, assessment, implementation, and reporting formats throughout the Department.
Version 1.0 5 April 2011
5 USING THE HANDBOOK
This handbook was designed to provide practical guidance in the areas covered by each volume.
The CSH volumes contain examples and implementation information and have the ability to serve as stand alone documents.
This handbook should be used as a reference by ISOs and other individuals who will be performing cyber security-related tasks, such as developing SSPs, implementing IT systems, or establishing a computer incident response and reporting program.
The following diagram captures the integrated activities and the deliverables that support the security authorization process at DOL. The diagram is representative of the high level security authorization process framework for which the individual volumes provide detailed tactical information.
Figure 5.1 – High-Level Security Lifecycle Framework
Version 1.0 6 April 2011
6 OBJECTIVES
The objective of this handbook is to facilitate the standardization of agency information security processes and procedures. Specific volumes of the CSH contain DOL procedures for the completion of the following program requirements:
Introduction Volume 0 Information Security Policy Volume 1 Access Control Volume 2 Awareness and Training Volume 3 Audit and Accountability Volume 4 Security Assessment and Authorization Volume 5 Configuration Management Volume 6 Contingency Planning Volume 7 Identification and Authentication Volume 8 Incident Response Volume 9 Maintenance Volume 10 Media Protection Volume 11 Physical and Environmental Protection Volume 12 Planning Volume 13 Personnel Security Volume 14 Risk Assessment Volume 15 System and Services Acquisition Volume 16 System and Communications Protection Volume 17 System and Information Integrity Volume 18 Program Management Volume 19 Cyber Security Program Plan Volume 20 Inventory Methodology Volume 21 Glossary
Version 1.0 7 April 2011
7 SCOPE AND APPLICABILITY
This handbook is primarily a DOL document. The policies, procedures, and format are not binding on external organizations that have interconnectivity with DOL systems. A Memorandum of Understanding (MOU) and / or Interconnection Security Agreement (ISA) should be in place for these connections.
The procedures are binding on all operators of DOL systems. An “operator” of a DOL system is any individual or organization who processes, stores, or transmits information on a DOL system on behalf of DOL to accomplish a DOL function. An example of a DOL operator who is not a DOL employee is a local or state government employee or contractor processing information on behalf of DOL to accomplish a DOL business or IT function.
Version 1.0 8 April 2011
8 DEFINITIONS
Policy Statements
CSH policy statements are in accordance with federal governance (e.g. NIST SP 800-53, Rev. 3).
Policy statements articulate management’s intent regarding how DOL must meet the intent of the control. CSH policy statements are a set of generalized statements that define the overarching information protection objective for DOL. Adherence to policy statements is required. Within the DOL CSH, policy statements are practices that are:
• Federally mandated by law, executive order, policy
• Applicable to all DOL information systems
• Supported by specific standards or procedures
• Written in a general manner so that they do not require frequent revision
• Stated at the beginning of each procedure
An example is provided below:
3.1.1: Manage Information System Accounts [L/M/H]
All information systems must manage information system accounts, including establishing, activating, modifying, reviewing, disabling, and removing accounts.
Account management includes the identification of account types (i.e. individual, group, and system), establishment of conditions for group membership, and assignment of associated authorizations.
Standards
Standards (or requirements) provide specific information security requirements in accordance with federal and Departmental governance. While policy statements are broad, standards provide explicit direction regarding how to protect DOL information and meet the full intent of the security control. Many of the standards will map directly to NIST requirements but some are derived from other federal mandates as well as Departmental initiatives. Standards are listed numerically in the grey box portion of each procedure. Adherence to standards is required.
Guidance
Guidance provides Agencies with additional information on the application of security controls and control enhancements, and the environments in which these specialized systems operate.
Guidance also provides information as to why a particular security control or control enhancement may not be applicable in some agency environments and may be a candidate for tailoring (e.g. compensating controls). Informational references to NIST or other federal guidance is provided within this section.
Version 1.0 9 April 2011
Refer to NIST SP 800-12, 800-43, and 800-66 for guidance on account management
Guidance:
Sources
Sources are federal or Departmental documents, publications, or memorandums in which the standards (or requirements) are derived.
NIST SP 800-5, AC-12 Session Termination Sources:
Version 1.0 10 April 2011
9 COMPUTER SECURITY HANDBOOK VOLUMES
This handbook is divided into volumes that cover specific security control families. From time to time, amendments to volumes will become necessary and will be published. Agencies will be notified when amendments are available. The content of each volume is discussed briefly below.
Note that each of the volumes below have been formulated to comply with guidance contained within Special Publication (SP) 800-53, Recommended Security Controls for Federal Information Systems.
Introduction contains an overview of the information contained in each volume of this handbook.
Volume 0: Information Security Policies contains high-level Departmental cyber security policy guidance. This single volume contains policy statements relating to each of the eighteen NIST control families.
Volume 1: Access Control contains procedures for implementing access controls within the DOL agencies as well as agency information systems in accordance with NIST Federal Information Processing Standards (FIPS) Publication (PUB) 200, Minimum Security Requirements for Information and Information Systems.
Volume 2: Awareness and Training contains procedures for implementing and developing a Computer Security Awareness and Training (CSAT) program at the agency level. Under the E- Government Act, the Director of the Office of Personnel Management, in coordination with the Director of the Office and Management and Budget (OMB), were charged with the duty of issuing policies to promote the development of performance standards for training. Those policies and standards have not yet been drafted. Therefore, current guidance in this area is NIST SP 800-16, Information Technology Security Training Requirements: A Role and Performance Based Model.
Volume 3: Audit and Accountability contains procedures for implementing audit and accountability controls within the DOL agencies as well as agency information systems in accordance with FIPS PUB 200.
Volume 4: Security Assessment and Authorization contains procedures and requirements for conducting security authorization on federal information systems. Security authorization is the approval granted to a major application (MA) or general support system (GSS) to process in an operational environment. It is made on the basis of a certification by the designated technical personnel that the system meets pre-specified technical requirements for achieving adequate system security. The technical and non-technical evaluation of an IT system that produces the necessary information required by the designated approving authority (DAA) to make a credible, risk-based decision on whether to place the system into operation is known as security authorization. Authorization is the official management decision given by a senior agency official to authorize operation of an information system and to explicitly accept the risk to agency operations, agency assets, or individuals based on the implementation of set of security controls. The guidance provided in this volume is compliant with Office of Management and http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/sp800-53-rev3-final_updated-errata_05-01-2010.pdf� http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/sp800-53-rev3-final_updated-errata_05-01-2010.pdf� http://csrc.nist.gov/publications/fips/fips200/FIPS-200-final-march.pdf� http://csrc.nist.gov/publications/fips/fips200/FIPS-200-final-march.pdf� http://csrc.nist.gov/publications/nistpubs/800-16/800-16.pdf� http://csrc.nist.gov/publications/nistpubs/800-16/800-16.pdf�
Version 1.0 11 April 2011
Budget (OMB) Circular A-130, (requiring federal agencies to plan for security, ensure that appropriate officials are assigned security responsibility, and authorize system processing prior to operations and, periodically, thereafter) and NIST SP 800-37, Guidelines for the Security Certification and Accreditation of Federal Information Technology Systems.
Volume 5: Configuration Management contains procedures for implementing configuration management controls within the DOL agencies as well as agency information systems in accordance with FIPS 200.
Volume 6: Contingency Planning contains procedures for preparing, implementing, and testing a Contingency Plan. Contingency planning refers to a coordinated strategy involving plans, procedures, and technical measures that enable the recovery of IT systems, operations, and data after a disruption. Contingency planning involves the establishment of thorough plans and procedures and technical measures that can enable a system to be recovered quickly and effectively following a service disruption or disaster. Additionally, this volume addresses the testing of a contingency plan and the components that should be tested on an annual basis. The guidance is compliant with NIST SP 800-34, Contingency Planning Guide for Information Technology Systems.
Volume 7: Identification and Authentication contains procedures for implementing identification and authentication controls with the DOL agencies as well as agency information systems in accordance with FIPS 200, FIPS 201, HSPD-12, and Federal Identity, Credential, and Access Management (FICAM).
Volume 8: Incident Response contains the procedures for the Department’s Computer Security Incident Response Capability (CSIRC). Volume 8 is compliant with NIST SP-800-61, Computer Security Incident Handling Guide and incident reporting guidelines from the United States Computer Emergency Response Team (US-CERT).
Volume 9: Maintenance contains procedures for implementing maintenance controls within the DOL agencies as well as agency information systems in accordance with FIPS 200.
Volume 10: Media Protection contains procedures for implementing media protection and sanitization controls within the DOL agencies as well as agency information systems in accordance with FIPS 200.
Volume 11: Physical and Environmental Protection contains procedures for implementing physical and environmental protection controls within the DOL agencies as well as agency information systems in accordance with FIPS 200.
Volume 12: Planning contains the procedures, methodology, and template for conducting privacy impact assessment (PIAs). PIAs are required by TITLE II, Federal Management and Promotion of Electronic Government Services, of the E-Government Act of 2002. The purpose of a PIA is to assess whether a system that contains Personally Identifying Information (PII) meets legal privacy protection requirements. It also contains the DOL SSP policy, procedures, and template for the Department for MAs and GSSs. An SSP should be initiated at the earliest http://www.whitehouse.gov/omb/circulars_a130_a130trans4/� http://csrc.nist.gov/publications/nistpubs/800-37-rev1/sp800-37-rev1-final.pdf� http://csrc.nist.gov/publications/nistpubs/800-37-rev1/sp800-37-rev1-final.pdf� http://csrc.nist.gov/publications/nistpubs/800-34-rev1/sp800-34-rev1_errata-Nov11-2010.pdf� http://csrc.nist.gov/publications/nistpubs/800-34-rev1/sp800-34-rev1_errata-Nov11-2010.pdf� http://csrc.nist.gov/publications/nistpubs/800-61-rev1/SP800-61rev1.pdf� http://csrc.nist.gov/publications/nistpubs/800-61-rev1/SP800-61rev1.pdf� http://www.cio.gov/documents/e_gov_act_2002.pdf�
Version 1.0 12 April 2011 phases of a federal information system’s life cycle. SSPs contain descriptions of the protection afforded the system by managerial, operational, and technical means. The SSP is considered the most important security document for a system. OMB Circular A-130 requires the implementation of a system security plan for each MA and GSS.
Volume 13: Personnel Security contains procedures for implementing personnel security controls within the DOL agencies as well as agency information systems in accordance with FIPS 200 and HSPD-12.
Volume 14: Risk Assessment contains the risk assessment (RA) methodology, procedures and template for Department of Labor information technology systems. The performance of a RA is a critical step in identifying appropriate controls for assuring the confidentiality, integrity, and availability of DOL systems and the information they process. This methodology presents a standardized template for documenting a RA at the DOL in accordance with the NIST SP 800- 30, Risk Management Guide for Information Technology Systems.
Volume 15: System and Services Acquisition contains procedures for implementing system and services acquisition controls within the DOL agencies as well as agency information systems in accordance with FIPS 200.
Volume 16: System and Communications Protection contains procedures for implementing system and communications protection controls within the DOL agencies as well as agency information systems in accordance with FIPS 200.
Volume 17: System Information Integrity contains procedures for implementing system information integrity controls within the DOL agencies as well as agency information systems in accordance with FIPS 200.
Volume 18: Program Management contains security requirements defined in the Information Processing Standards Publication 200, Minimum Security Requirements for Federal Information and Information Systems.
Volume 19: Cyber Security Program Plan outlines the Department’s IT security program.
Volume 20: Inventory Methodology contains policies, procedures, and templates for Department-wide determination of and categorization for information systems.
Volume 21: Glossary contains a list and definition of words and expressions relevant to the security of federal information systems and technology. This replaces the separate glossaries previously maintained within each volume. An acronym list is also provided.
http://www.whitehouse.gov/omb/circulars/a130/a130trans4.html� http://csrc.nist.gov/publications/nistpubs/800-30/sp800-30.pdf�
U.S. DEPARTMENT OF LABOR
Office of the Chief Information Officer
Computer Security Handbook Edition 4.0
Volume 0
INFORMATION SECURITY POLICIES
VERSION 1.1
OCTOBER 2011
U.S. Dept. of Labor Computer Security Handbook Information Security Policies
Version 1.1 ii October 2011
DOCUMENT CHANGE HISTORY
Date Filename / Version # Author Revision Description
8/1/2011 1.0 OCIO Security Updated CSH Ver. 3.2 to comply with changes in NIST SP 800-53
Rev. 3, including agency feedback
10/7/2011 1.1 OCIO Security Added Inventory Methodology Policy
DOCUMENT REVIEW HISTORY
Date Version # Reviewers
8/1/2011 1.0 OCIO Security
10/7/2011 1.1 OCIO Security
08/17/2012 1.1 OCIO Security
Version 1.1 iii October 2011
TABLE OF CONTENTS
1 INTRODUCTION
1.1 Background
1.2 Purpose
1.3 Scope and Applicability
1.4 Update and Review
1.5 Authority
1.6 Guidance and Sources
1.7 Compliance
2 ACCESS CONTROL (VOLUME 1)
2.1 Policies
2.1.1 Wireless
2.1.2 Portable and Mobile Devices
2.1.3 External Information Systems
2.2 Roles and Responsibilities
2.2.1 Deputy Secretary
2.2.2 Chief Information Officer
2.2.3 Chief Information Security Officer
2.2.4 Designated Approving Authority
2.2.5 Information Security Officer
2.2.6 System Owner
2.2.7 OCIO Security
3 AWARENESS AND TRAINING (VOLUME 2)
3.1 Policies
3.2 Roles and Responsibilities
3.2.1 Chief Information Officer
3.2.2 Chief Information Security Officer
3.2.3 Designated Approving Authority
3.2.4 Information Security Officer
3.2.5 System Owner
3.2.6 All Users
4 AUDIT AND ACCOUNTABILITY (VOLUME 3)
4.1 Policies
4.2 Roles and Responsibilities
4.2.1 Chief Information Officer
4.2.2 Chief Information Security Officer
4.2.3 Designated Approving Authority
4.2.4 Information Security Officer
4.2.5 System Owner
5 SECURITY ASSESSMENT AND AUTHORIZATION (VOLUME 4)
5.1 Policies
5.1.1 System Authorization Boundary, System Connection, Security Authorization
Version 1.1 iv October 2011
5.1.2 Continuous Monitoring
5.1.3 Plan of Action and Milestones
5.2 Roles and Responsibilities
5.2.1 Chief Information Officer
5.2.2 Chief Information Security Officer
5.2.3 Designated Approving Authority
5.2.4 Information Security Officer
5.2.5 System Owner
6 CONFIGURATION MANAGEMENT (VOLUME 5)
6.1 Policies
6.2 Roles and Responsibilities
6.2.1 Chief Information Officer
6.2.2 Chief Information Security Officer
6.2.3 Designated Approving Authority
6.2.4 Information Security Officer
6.2.5 System Owner
7 CONTINGENCY PLANNING (VOLUME 6)
7.1 Policy
7.2 Roles and Responsibilities
7.2.1 Chief Information Officer
7.2.2 Chief Information Security Officer
7.2.3 Designated Approving Authority
7.2.4 Information Security Officer
7.2.5 System Owner
7.2.6 Contingency Plan Coordinator
8 IDENTIFICATION AND AUTHENTICATION (VOLUME 7)
8.1 Policies
8.2 Roles and Responsibilities
8.2.1 Chief Information Officer
8.2.2 Chief Information Security Officer
8.2.3 Designated Approving Authority
8.2.4 Information Security Officer
8.2.5 System Owner
9 INCIDENT RESPONSE (VOLUME 8)
9.1 Policy
9.2 Roles and Responsibilities
9.2.1 Chief Information Officer
9.2.2 Chief Information Security Officer
9.2.3 Designated Approving Authority
9.2.4 Information Security Officer
9.2.5 System Owner
9.2.6 System Users
10 MAINTENANCE (VOLUME 9)
Version 1.1 v October 2011
10.1 Policy
10.2 Roles and Responsibilities
10.2.1 Chief Information Officer
10.2.2 Chief Information Security Officer
10.2.3 Designated Approving Authority
10.2.4 Information Security Officer
10.2.5 System Owner
11 MEDIA PROTECTION (VOLUME 10)
11.1 Policy
11.2 Roles and Responsibilities
11.2.1 Chief Information Officer
11.2.2 Chief Information Security Officer
11.2.3 Designated Approving Authority
11.2.4 Information Security Officer
11.2.5 System Owner
12 PHYSICAL AND ENVIRONMENTAL PROTECTION (VOLUME 11)
12.1 Policy
12.2 Roles and Responsibilities
12.2.1 Chief Information Officer
12.2.2 Chief Information Security Officer
12.2.3 Designated Approving Authority
12.2.4 Information Security Officer
12.2.5 System Owner
13 PLANNING (VOLUME 12)
13.1 Policies
13.1.1 System Security Plan
13.1.2 Rules of Behavior
13.1.3 Privacy Impact Assessment
13.2 Roles and Responsibilities
13.2.1 Chief Information Officer
13.2.2 Chief Information Security Officer
13.2.3 Designated Approving Authority
13.2.4 Information Security Officer
13.2.5 System Owner
13.2.6 Office of the Solicitor
13.2.7 System Users
14 PERSONNEL SECURITY (VOLUME 13)
14.1 Policy
14.2 Roles and Responsibilities
14.2.1 Chief Information Officer
14.2.2 Chief Information Security Officer
14.2.3 Designated Approving Authority
14.2.4 Information Security Officer
14.2.5 System Owner
Version 1.1 vi October 2011
15 RISK ASSESSMENT (VOLUME 14)
15.1 Policy
15.1.1 Risk Assessment
15.1.2 Risk Assessment Updates
15.1.3 Vulnerability Scanning
15.2 Roles and Responsibilities
15.2.1 Chief Information Officer
15.2.2 Chief Information Security Officer
15.2.3 Designated Approving Authority
15.2.4 Information Security Officer
15.2.5 System Owner
16 SYSTEM AND SERVICES ACQUISITION (VOLUME 15)
16.1 Policy
16.1.1 Capital Planning
16.1.2 System Development Life Cycle
16.2 Roles and Responsibilities
16.2.1 Chief Information Officer
16.2.2 Chief Information Security Officer
16.2.3 Designated Approving Authority
16.2.4 Information Security Officer
16.2.5 System Owner
16.2.6 Project Manager
17 SYSTEM AND COMMUNICATIONS PROTECTION (VOLUME 16)
17.1 Policies
17.1.1 Network Security
17.1.2 Communications Security
17.1.3 Mobile Code
17.1.4 Voice over Internet Protocol
17.2 Roles and Responsibilities
17.2.1 Chief Information Officer
17.2.2 Chief Information Security Officer
17.2.3 Designated Approving Authority
17.2.4 Information Security Officer
17.2.5 System Owner
18 SYSTEM AND INFORMATION INTEGRITY (VOLUME 17)
18.1 Policies
18.1.1 System and Information Integrity
18.2 Roles and Responsibilities
18.2.1 Chief Information Officer
18.2.2 Chief Information Security Officer
18.2.3 Designated Approving Authority
18.2.4 Information Security Officer
18.2.5 System Owner
19 PROGRAM MANAGEMENT (VOLUME 18)
Version 1.1 vii October 2011
20 CYBER SECURITY PROGRAM PLAN (VOLUME 19)
21 INVENTORY METHODOLOGY (VOLUME 20)
21.1 Policies
21.2 Roles and Responsibilities
21.2.1 Chief Information Officer (CIO)
21.2.2 Chief Information Security Officer (CISO)
21.2.3 Designated Approving Authority (DAA)
21.2.4 Information Security Officer (ISO)
21.2.5 System Owner
Version 1.1 1 October 2011
1 INTRODUCTION
1.1 Background
The Department of Labor (DOL) requires agencies to adopt a minimum set of security controls to protect their information and information systems. The Federal Information Processing Standards (FIPS) 200, Minimum Security Requirements for Federal Information and Information Systems, specifies the minimum security requirements for federal information and information systems. The Department is responsible for ensuring that all DOL information systems meet the minimum security requirements defined in FIPS 200 through the use of the security controls provided in the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 Revision 3, Recommended Security Controls for Federal Information Systems. The Department has developed information security policies and procedures to ensure controls are properly implemented and maintained.
1.2 Purpose
This document establishes uniform policies, authorities, responsibilities, and compliance for all information security families across the Department.
1.3 Scope and Applicability
The provisions of these policies pertain to all DOL agencies and information systems. Agency senior management shall ensure that information systems operated by or on behalf of the Department receive adequate security equivalent to the safeguards required of systems operated internally to the Department. Systems under development must meet the security planning requirements commensurate with the sensitivity of the information they house and the current life cycle phase in accordance with the DOL System Development Life Cycle Management Manual (SDLCMM).
1.4 Update and Review
The Department reviews and/or updates security policies and procedures at least annually,
1.5 Author ity
These policies are issued under the authority of the Department of Labor Manual Series (DLMS) 9, Information Technology, Chapter 400, Security. The most critical laws, regulations, Executive Orders, policies, standards, and directives pertaining to access control and the protection of information resources are indicated below. References to the full list of statutes, federal regulations, directives, and NIST publications applicable to information security are provided below.
• E-Government Act of 2002
• The Privacy Act of 1974
• Clinger-Cohen Act of 1996
• National Technology Transfer and Advancement Act of 1996
Version 1.1 2 October 2011
• Health Insurance Portability and Accountability Act of 1996 (HIPAA)
• Federal Information Security Management Act of 2002 (FISMA)
• Federal Financial Management Improvement Act of 1996 (FFMIA)
• Federal Acquisition Streamlining Act of 1994 (FASA)
• United States General Accounting Office, Federal Information System Controls Audit
Manual (FISCAM)
• OMB Circulars
• OMB Memoranda
• Federal Information Processing Standards (FIPS)
• NIST Special Publications
• Department of Labor Manual Series (DLMS)
• DOL Policy for PIV Card Issuance to New Federal Employees and Contractors
• Department of Labor System Development Life Cycle Management Manual (SDLCMM)
1.6 Guidance and Sources
The Authorities cited above serve as the basis for the development of the CSH minimum standards and guidelines. For the specific authority referenced for the control standard or guideline, refer to the “guidance” and “sources” sections listed beneath the standards grey box in the procedure documents.
1.7 Compliance
Compliance with all policies defined in this volume is mandatory. It is DOL policy that Department personnel and information systems abide by or exceed the requirements outlined in this document and subsequent procedures and templates. OCIO Security will periodically assess agency adherence with this policy through various oversight and compliance measures.
General Compliance
In cases where an agency cannot comply with this policy for technical or financial reasons, or because it precludes an agency from supporting its mission or business function, justifications for noncompliance must be documented using the policy exemption process and submitted to the OCIO for approval. Refer to Volume 12 Security Planning for instructions on the policy/procedure exemption process. Resulting risks from this deviation must be documented in the appropriate risk management and security planning documentation. Systems failing to meet minimum security planning requirements may be severely restricted in their operational readiness and availability.
Throughout all DOL CSH volumes, relevant external sources, guides, and documents are referenced for the purposes of supplemental guidance, support, and in-depth explanation. All external references mentioned throughout the CSH are current “latest release” documents in place at the time of the publication of CSH version 4.0. For up-to-date future guidance and support, it may be appropriate to reference materials that postdate the current CSH revision and included references.
Document References
Version 1.1 3 October 2011
DOL component agency ISOs shall review the controls in the agency SSPs for compliance with DOL and agency information security policies and procedures prior to submission to OCIO Security. Agencies shall remediate identified weaknesses using the plan of action and milestones (POA&M) process.
ISO Documentation Compliance Review
To ensure that control processes are executed correctly, OCIO Security will review security controls as part of the system security plan review for each information system during the security authorization oversight process. OCIO Security will periodically verify the implementation of a sample of controls as part of the security control assessment program.
Identified weaknesses in access controls will be reported to the ISO and system owner for remediation. These weaknesses must be documented in a POA&M.
OCIO Documentation Compliance Review
Version 1.1 4 October 2011
2 ACCESS CONTROL (VOLUME 1)
2.1 Policies
Access controls must be configured and applied to all DOL information systems. The appropriate hardware, software, and procedural access control mechanisms must be defined and developed with the System Security Plan (SSP) during the Planning & Requirements Definition Phase of the system development life cycle in accordance with the SDLCMM, and updated and maintained throughout the remaining life cycle phases for the system. Access control mechanisms must be configured in order to support the management of information system accounts and enforce access authorizations, separation of duties, least privilege, limit of invalid access attempts, and information flow. According to procedures and standards set forth by the Department, the information system must be configured in order to provide a system use notification, session locks, automatic session termination, and identify specific actions that are permitted without identification and authentication. In accordance with procedures and standards set forth by the Department, the information system shall automatically limit the number of concurrent sessions for users and automatically mark output using standard naming conventions. User activity (to include account inactivity) and user access privileges must be supervised and reviewed periodically (on an on-going basis) for inappropriate activities and to ensure that privileges are appropriate and necessary. Remote access methods must be authorized, monitored, and controlled. Remote access to protected personally identifiable information (PII) and other sensitive data must be protected using a secure, encrypted channel that is certified FIPS 140-2 (as amended) compliant. All remote access to DOL systems must be authenticated using at least two-factors. All DOL agencies shall review the access control mechanisms on an annual basis as a part of continuous monitoring when the security self-assessments are performed.
2.1.1 Wireless
Where wireless technologies are employed by an information system, wireless controls must be configured and applied to all DOL information systems. The appropriate hardware, software, and procedural wireless mechanisms must be defined and developed during the Planning & Requirements Definition Phase of the system development life cycle, and updated and maintained throughout the remaining life cycle phases for the system in accordance with the SDLCMM. In addition, wireless mechanisms must be configured using NIST approved common security configuration standards and checklists in order to restrict usage, implement guidance, and control access to the information system.
Wireless technologies must comply with procedures and standards set forth by the Department and approval must take place between the agency’s Enterprise Architecture (EA) Program Management Office (PMO) and the information system personnel. According to procedures and standards set forth by the Department, the appropriate officials shall authorize the use of wireless technologies. NIST SP 800-48 and SP 800-97 must be applied to the information system in the absence of guidance from the Department. All DOL agencies shall review the wireless mechanisms on an annual basis as part of continuous monitoring when the security self-assessments are performed.
Version 1.1 5 October 2011
Wireless communications are subject to equivalent controls and restrictions as wired communications. Wireless technology requires additional controls to implement equivalent protections. A wireless network not included as a component of an existing general support system (GSS) must be classified as a GSS and is required to satisfy all applicable security requirements. Wireless technologies / devices used for storing, processing, and/or transmitting information must first be approved by the Office of the Chief Information Officer (OCIO), through the EA governance process prior to implementation. The equipment must be evaluated by the governing authority, using risk management principles and determine the appropriate minimum separation distances and countermeasures.
2.1.2 Por table and Mobile Devices
Where portable and mobile devices are employed by information systems, access controls for those devices must be configured and applied to all DOL information systems. The appropriate hardware, software, and procedural access control mechanisms for portable and mobile devices must be defined and developed during the Planning & Requirements Definition Phase of the system development life cycle, and updated and maintained throughout the remaining life cycle phases for the system in accordance with the SDLCMM. Access control for portable and mobile devices must be configured in order to restrict usage, implement guidance, and control access to the information system. According to procedures and standards set forth by the Department, appropriate officials shall authorize the use of portable and mobile devices. Protected PII or other sensitive data must only be stored on portable or mobile devices when absolutely necessary to meet business requirements as determined by the system owner and only for the duration of the specific business assignment for which the data is required. Protected PII and other sensitive data stored on portable and mobile devices issued by DOL must be protected with approved encryption. Any information technology device (mobile or stationary) used to access or store protected PII or other sensitive data must either be the property of the government or government-authorized or leased, and must be configured to meet the requirements of this and other applicable policies. In cases where this can not be met, the agency DAA must authorize the use of each non-government owned device. Use of any portable device or media without encryption must be approved in writing by the Deputy Secretary of Labor or his or her designee in accordance with DLMS 9-1200, in accordance with non sensitive data encryption exemption request process. All reasonable measures will be taken to ensure that portable media containing protected PII and other sensitive data are stored inside a safe or in a secured, locked cabinet, room, or area during periods when the media is not in transit or in active use. All DOL agencies shall review the access control mechanisms for portable and mobile devices on an annual basis as part of continuous monitoring when the security self-assessments are performed.
2.1.3 External Information Systems
All DOL information systems shall establish access controls, including terms and conditions, for authorized individuals to use external information systems to access DOL information resources and to process, store, and/or transmit DOL controlled information. External information systems are information systems or components of information systems that are outside of the authorization boundary established by the agency and for which DOL typically has no direct control over the application of required security controls or the assessment of security control
Version 1.1 6 October 2011 effectiveness. The appropriate hardware, software, and procedural access control mechanisms for external information systems must be defined and developed during the Planning & Requirements Definition Phase of the system development life cycle, and updated and maintained throughout the remaining life cycle phases for the system in accordance with the SDLCMM. According to procedures and standards set forth by the Department, the appropriate officials shall authorize the use of external information systems and establish terms and conditions for the use of external information systems when processing, storing, or transmitting federal information. All DOL agencies shall review the access control mechanisms for external owned information systems on an annual basis as part of continuous monitoring when the security self-assessments are performed.
2.2 Roles and Responsibilities
As part of management’s commitment to properly implement federal and Departmental policies, procedures, and guidelines, and to ensure agencies effectively coordinate amongst agency resources to safeguard DOL information, agency roles and responsibilities for access control activities within DOL are defined and identified below:
2.2.1 Deputy Secretary
The Deputy Secretary has the following responsibilities with respect to access control:
• Authorizes, in writing, the use of any portable device or media which carry non-encrypted DOL data that is determined to be non-sensitive
2.2.2 Chief Information Officer
The Chief Information Officer (CIO) has the following responsibilities with respect to access control:
• Designates a Chief Information Security Officer (CISO) who shall carry out the CIO's responsibilities for access controls for the information system
2.2.3 Chief Information Secur ity Officer
The CISO has the following responsibilities with respect to access control:
• Carries out the CIO's responsibilities for access control
• Develops and maintains information security policies, procedures, and control techniques to address access control
• Through management of OCIO Security, performs oversight of agency compliance with
Departmental information access control policies and procedures
• Reviews and approves all policy exemptions to the DOL access control policy and procedures provided in the CSH provided risks are adequately mitigated
Version 1.1 7 October 2011
2.2.4 Designated Approving Author ity
The Designated Approving Authority (DAA) has the following responsibilities with respect to access control:
• Approves the access controls contained within the system security plans as part of the security authorization process
• Authorizes access control policy exemption requests and formally accepts residual risks to agency information resources
• Authorizes the use of each non-government owned portable or mobile device permitted to access an information system for which they are responsible
• Authorizes the use of information systems (internal or external) used on behalf of or for the DOL.
2.2.5 Information Secur ity Officer
The agency Information Security Officer (ISO) has the following responsibilities with respect to access control:
• Plays an active role in coordinating the development and update of access controls in the system security plan as well as coordinating with the system owner any changes to the system and assessing the security impact of those changes
2.2.6 System Owner
The System Owner serves as the overall responsible authority for the procurement, development, integration, modification, operation, maintenance, and sequence disposition or retirement of the information system. The System Owner or System Owner Designee (designated in writing) has the following responsibilities with respect to access control:
• Authorizes or denies access to the information system and the types of privileges or access rights;
• Updates the access controls in the system security plan whenever a significant change occurs or every three years at a minimum; and
• Implements all applicable access security controls.
2.2.7 OCIO Secur ity
The OCIO Security is the team responsible for carrying out information security activities, as directed by the CISO.
3 AWARENESS AND TRAINING (VOLUME 2)
3.1 Policies
Awareness and training controls must be established for all DOL information systems. The appropriate awareness and training procedures and standards must be defined and developed during the Planning & Requirements Definition Phase of the system development life cycle, and updated and maintained throughout the remaining life cycle phases for the system in accordance
Version 1.1 8 October 2011 with the SDLCMM. According to procedures and standards set forth by the Department, the information system must follow such established requirements on security awareness, security training, and documenting and monitoring security training records. All DOL agencies shall review the awareness and training controls on an annual basis when the self-assessments are performed.
3.2 Roles and Responsibilities
Roles and responsibilities for awareness and training within DOL are identified below:
3.2.1 Chief Information Officer
The CIO has the following responsibilities with respect to awareness and training:
• Designates a CISO who shall carry out the CIO's responsibilities for awareness and training for the information system
3.2.2 Chief Information Secur ity Officer
The CISO has the following responsibilities with respect to awareness and training:
• Carries out the CIO's responsibilities for awareness and training
• Develops and maintains information security policies, procedures, and control techniques to address awareness and training
• Through management of OCIO Security, performs oversight of agency compliance with
Departmental information awareness and training policy and procedures
3.2.3 Designated Approving Author ity
The DAA has the following responsibilities with respect to awareness and training:
• Approves the awareness and training controls contained within the system security plans as part of the C&A process
• Approves list of required trainees and required level of training as identified by the System Owner.
3.2.4 Information Secur ity Officer
The ISO has the following responsibilities with respect to awareness and training:
• Plays an active role in coordinating the development and update of awareness and training controls in the system security plan as well as coordinating with the system owner any changes to the system and assessing the security impact of those changes
3.2.5 System Owner
integration, modification, or operation and maintenance of the information system. The System Owner or System Owner Designee (designated in writing) has the following responsibilities with respect to awareness and training:
Version 1.1 9 October 2011
• Updates the awareness and training controls in the system security plan whenever a significant change occurs or every three years at a minimum
• Implements the awareness and training controls
• Identifies trainees and the level of training required for their employees (including but not limited to senior, mid, and entry) depending upon their job functions and experience.
3.2.6 All Users
DOL information users (Federal Employees and Contractor Staff) are expected to review and comply with the policies, procedures, and standards for awareness and training to include training for information systems security, privacy awareness, and role-based training for individuals who hold positions with significant security roles and responsibilities.
4 AUDIT AND ACCOUNTABILITY (VOLUME 3)
4.1 Policies
Audit and accountability controls must be configured and applied to all DOL information systems. The appropriate hardware, software, and procedural auditing mechanisms shall be defined and developed during the Planning & Requirements Definition Phase of the system development life cycle, and updated and maintained throughout the remaining life cycle phases for the system in accordance with the SDLCMM. In addition, audit and accountability mechanisms must be configured in order to generate reports of auditable events. The content of the audit records must capture sufficient information to support after-the-fact investigations.
According to procedures and standards set forth by the Department, the information system must allocate sufficient space for the storage and retention of audit records, be prepared for audit failure, protect audit information and tools, and system personnel are to perform timely reviews of audit records. All DOL agencies shall review the audit mechanisms on an annual basis when the self-assessments are performed. Logging of auditable events must be used for individual accountability, reconstruction of events, intrusion detection, and problem identification.
4.2 Roles and Responsibilities
Roles and responsibilities for audit and accountability within DOL are identified below:
4.2.1 Chief Information Officer
The CIO has the following responsibilities with respect to audit and accountability:
• Designates a CISO who shall carry out the CIO's responsibilities for audit and accountability for the information system
Version 1.1 10 October 2011
4.2.2 Chief Information Secur ity Officer
The CISO has the following responsibilities with respect to audit and accountability:
• Carries out the CIO's responsibilities for audit and accountability
• Develops and maintains information security policies, procedures, and control techniques to address audit and accountability
Departmental information auditing policy and procedures.
4.2.3 Designated Approving Author ity
The DAA has the following responsibilities with respect to audit and accountability:
• Approves the audit and accountability controls contained within the SSPs as part of the C&A process
4.2.4 Information Secur ity Officer
The ISO has the following…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .