Enclosure EE - CASQ.pdf
PDF 204 KB Posted
- Attached to
- Near Space Network Services - Final RFP Federal contract opportunity
- Solicitation number
- 80GSFC22R0029
View the file
Other files for this federal contract opportunity
Show all 37
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
RFP 80GSFC22R0029
Vendor: Period of Performance:
Satellite(s) & Operator(s):
1) 2) 3) 4) 5)
Item Number: Name Description Vendor’s Response:
CS-1 Space Systems/Command Encryption for Control Link
Please describe the cryptography used to secure and authenticate the space system Telemetry, Tracking and Control link(s). NSA-approved or FIPS 140-3 validated cryptography, or combination of commercial best practice engineering and operational solutions and enhancements.
CS-2 Space Systems/ Voice Communications
What, if any, secure voice or secure data communications are available to the Prime Contractor to support anomaly investigation and resolution?
CS-3
Space Systems/ Interference Identification, Characterization, and Geo-location
What Electro-Magnet Interference/ Radio-Frequency Interference (EMF/RFI) Identification, Characterization, and Geo-location capability is available to support resolution of purposeful and accidental incidents of interference?
CS-4
Space Systems/ Spacecraft, Operators, and TT&C stations
Identify the Primary and Secondary TT&C stations for each satellite to be used in support of the solution.
CS-5 Space Systems/ Ground Stations
Identify all Ground Stations and/or NOCs to be used in support of the solution.
AC-2 ACCOUNT MANAGEMENT
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization: a. Identifies and selects the following types of information system accounts to support organizational missions/business functions:
System Administrator, Network Administrator, Application Administrator, and Database Administrator accounts; b. Assigns account managers for information system accounts; c. Establishes conditions for group and role membership; d. Specifies authorized users of the information system, group and role membership, and access authorizations (i.e., privileges) and other attributes (as required) for each account; e. Requires approvals by System Owner and Authorizing Official for requests to create information system accounts; f. Creates, enables, modifies, disables, and removes information system accounts in accordance with industry standards (e.g. NIST, ISO, FISMA); g. Monitors the use of, information system accounts; h. Notifies account managers: 1. When accounts are no longer required; 2. When users are terminated or transferred; 3. When individual information system usage or need-to-know changes; i. Authorizes access to the information system based on: 1. A valid access authorization; 2. Intended system usage; and 3. Other attributes as required by the organization or associated missions/business functions; j. Reviews accounts for compliance with account management requirements semi-annually; and k. Establishes a process for reissuing shared/group account credentials (if deployed) when individuals are removed from the group.
AC-5 SEPARATION OF DUTIES
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization: a. Separates user access according to “least privilege” by limiting non-privileged functions to non-privileged accounts, and privileged functions are limited to privileged accounts. Users who have higher privilege or “need-to-know” are still restricted to non-privileged accounts for non-privileged function; b. Documents separation of duties of individuals; and c.
Defines information system access authorizations to support separation of duties.
End User:
Task Order Number:
RFP# 80GSFC22R0029 Enclosure EE - CASQ
COMMERCIAL ARCHITECTURE SECURITY QUESTIONAIRE
5370914
Is the Tracking, Telemetry, and Control (TT&C) network connected to the Internet?
Is the Tracking, Telemetry, and Control (TT&C) network separate from other networks?
Do you have SIPRNET, a STE, or other classified networks in your facility?
Does the requirement call for a steerable beam to be repositioned during the term of the lease?
Table 2: COMSATCOM IA QUESTIONNAIRE References:
a. Committee on National Security Systems Policy 12, National Information Assurance Policy for Space Systems used to Support National Security Missions, 28 November 2012
b. National Institute of Standards and Technology Special Publication 800-53, Rev 4, Security and Privacy Controls for Federal Information Systems, April 2013
Access Control
Will utilization of the proposed transponder(s) be limited to only the DoD?
Space System Security
AC-7 UNSUCCESSFUL LOGON
ATTEMPTS
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The information system: a. Enforces a limit of not more than three (3) consecutive invalid logon attempts by a user during a 30 minute time period;
and b. Automatically locks the account/node for a (30 minute time period);
and delays next logon prompt for (30 minutes) when the maximum number of unsuccessful attempts is exceeded.
AC-8 SYSTEM USE
NOTIFICATION
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization: a. Displays to users a warning message before granting access to the system that provides privacy and security notices consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance and states that: 1. Users are accessing a private information system; 2. Information system usage may be monitored, recorded, and subject to audit; 3. Unauthorized use of the information system is prohibited and subject to criminal and civil penalties;
and 4. Use of the information system indicates consent to monitoring and recording;
AC-17 REMOTE ACCESS
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The information system: a. implements FIPS validated or NSA approved cryptography in accordance with applicable federal laws, Executive Orders.
b. monitors and controls remote access using automated mechanisms. c.
manages access through authorized network access control points.
AC-20 USE OF EXTERNAL
INFORMATION SYSTEMS
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The information system: a.prohibits the use of external information systems to the extent possible. b.
AT-2 SECURITY AWARENESS
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization provides basic security awareness training to information system users (including managers, senior executives, and contractors): a.
As part of initial training for new users; b. When required by information system changes; and c. Annually thereafter.
(2) The organization includes security awareness training on recognizing and reporting potential indicators of insider threat.
AT-3 ROLE-BASED SECURITY
TRAINING
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization provides role-based security training to personnel with assigned security roles and responsibilities: a. Before authorizing access to the information system or performing assigned duties; b. When required by information system changes; and c. Annually thereafter.
Audit and Accountability
Awareness and Training
AU-2 AUDIT EVENTS
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization: a. Determines, based on a risk assessment and mission/business needs, that the information system must be capable of auditing the following events: Successful and unsuccessful Account logon events, account management events, object access, policy change, privilege functions, process tracking, and system events. Web applications should log all admin activity, authentication checks, authorization checks, data deletions, data access, data changes, and permission changes; b.
Coordinates the security audit function with other organizational entities requiring audit-related information to enhance mutual support and to help guide the selection of auditable events; c. Provides a rationale for why the list of auditable events are deemed to be adequate to support after-the-fact investigations of security incidents; and d. Determines, based on current threat information and ongoing assessment of risk, that the following events are to be audited within the information system: all admin activity, authentication checks, authorization checks, data deletions, data access, data changes, and permission changes.
(3) The organization reviews and updates the audited events annually, or in the event of any system change with IA implications. Systems should employ an automated, on-line continuous monitoring audit trail creation capability.
AU-6 AUDIT REVIEW, ANALYSIS,
AND REPORTING
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization: a. Reviews and analyzes information system audit records weekly for indications of inappropriate or unusual activity; and b. Reports findings to Information System Security Manager, Information System Security Officer, System Owners (aka System Program Managers, System Project Managers, Acquisitions/Contracting Officers, and Custodians).
(3) The organization analyzes and correlates audit records across different repositories to gain organization-wide situational awareness.
AU-7 AUDIT REDUCTION AND
REPORT GENERATION
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The information system provides an audit reduction and report generation capability that: a. Supports on-demand audit review, analysis, and reporting requirements and after-the-fact investigations of security incidents; and b.
Does not alter the original content or time ordering of audit records.
AU-9 PROTECTION OF AUDIT
INFORMATION
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The information system protects audit information and audit tools from unauthorized access, modification, and deletion.
(4) The organization authorizes access to management of audit functionality to only Administrators (Application, System, Network, etc.), Information System Security Officer, Information System Security Manager, System Program Managers, and System Project Managers.
Describe how the proposed solution addresses the Information Assurance
AU-11 Audit Record Retention
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here: The organization retains records for a minimun (TBD, must review npr 1441.1d or applicable IT handbooks for requirements)
CA-2 SECURITY ASSESSMENTS
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization: a. Develops a security assessment plan that describes the scope of the assessment including: 1. Security controls and control enhancements under assessment; 2. Assessment procedures to be used to determine security control effectiveness; and 3. Assessment environment, assessment team, and assessment roles and responsibilities; b. Assesses the security controls in the information system and its environment of operation annually to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting established security requirements; c.
Produces a security assessment report that documents the results of the assessment; and d. Provides the results of the security control assessment Information System Security Manager, Information System Security Officer, System Owners (aka System Program Managers, System Project Managers, Acquisitions/Contracting Officers, Custodians).
Security Assessment
CA-3 SECURITY
INTERCONNECTIONS
Describe any interconnections associated with the proposed solution and address the Information Assurance and Cyber Security concerns stated here: The Organization:
a. Develops a security document, such as an interconnection security agreement, with any additional interconnection partners. b. Ensure that the security document with all interconnection security partners meets or exceeds the requirements associated with the proposed solution. c.
Documents interconnections in network architecture and data flow diagrams.
CA-5 PLAN OF ACTION AND
MILESTONES
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization: a. Develops a plan of action and milestones for the information system to document the organization’s planned remedial actions to correct weaknesses or deficiencies noted during the assessment of the security controls and to reduce or eliminate known vulnerabilities in the system; and b. Updates existing plan of action and milestones quarterly based on the findings from security controls assessments, security impact analyses, and continuous monitoring activities.
CA-7 CONTINUOUS
MONITORING
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization develops a continuous monitoring strategy and implements a continuous monitoring program that includes: a. Establishment of testing procedures that include periodic and unannounced in-depth monitoring and provides specific penetration testing to ensure compliance and maintain integrity of the system by applying these test metrics to continuous monitoring programs to be monitored; b. Establishment of monthly for monitoring and annually for assessments supporting such monitoring; c.
Ongoing security control assessments in accordance with the organizational continuous monitoring strategy; d. Ongoing security status monitoring of organization-defined metrics in accordance with the organizational continuous monitoring strategy; e. Correlation and analysis of security-related information generated by assessments and monitoring; f. Response actions to address results of the analysis of security-related information; and
g. Reporting the security status of organization and the information system to Information System Security Manager, Information System Security Officer, System Owners (aka System Program Managers, System Project Managers, Acquisitions/Contracting Officers, and Custodians monthly.
CM-2 BASELINE
CONFIGURATION
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization develops, documents, and maintains under configuration control, a current baseline configuration of the information system.
CM-3 CONFIGURATION CHANGE
CONTROL
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization: a. Determines the types of changes to the information system that are configuration-controlled; b. Reviews proposed configuration-controlled changes to the information system and approves or disapproves such changes with explicit consideration for security impact analyses; c.
Documents configuration change decisions associated with the information system; d. Implements approved configuration-controlled changes to the information system; e. Retains records of configuration-controlled changes to the information system for a time period in-accordance with best information assurance security practices; f. Audits and reviews activities associated with configuration-controlled changes to the information system;
and g. Coordinates and provides oversight for configuration change control activities through a charted Configuration Control Board (CCB) that convenes regularly and monitors: - Changes to the information system, including upgrades, modifications - Changes to the configuration settings for information technology products (e.g., operating systems, firewalls, routers).
- Emergency changes - Changes to remediate flaws.
CM-6 CONFIGURATION
SETTINGS
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization: a. Establishes and documents mandatory configuration settings for information technology products employed within the information system using industry information assurance security best practices technical guidelines, NIST guidelines, Center for Internet Security guidelines (Level 1), or industry best practice guidelines in hardening their systems, as deemed appropriate by the system Authorizing Official. Implemented checklists must be integrated with Security Content Automation Protocol (SCAP) content that reflect the most restrictive mode consistent with operational requirements; b. Implements the configuration settings; c.
Identifies, documents, and approves exceptions from the mandatory configuration settings for individual components within the information system based on explicit operational requirements; and d. Monitors and controls changes to the configuration settings in accordance with organizational policies and procedures.
Configuration Management
CM-8 INFORMATION SYSTEM
COMPONENT INVENTORY
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization: a. Develops and documents an inventory of information system components that: 1. Accurately reflects the current information system; 2. Includes all components within the authorization boundary of the information system; 3. Is at the level of granularity deemed necessary for tracking and reporting; and 4. Includes System Owner and Authorizing Official information deemed necessary to achieve effective information system component accountability; and b. Reviews and updates the information system component inventory at least annually.
(1) The organization updates the inventory of information system components as an integral part of component installations, removals, and information system updates.
CP-2 Contingency Plan
Describe how the proposed solution addresses the Informaiton Assurance and Cyber Security concerns stated here: The organization: a.
Develops a contingency plan that identifies essential mission and business functions and then provides recover objections, resortation priorities and metrics; b. socializes and conducts sufficient training to essential personal to ensure familiarity with the contingency plan; c. Coordinates contingency planning activities with incident handling activities
CP-9 INFORMATION SYSTEM
BACKUP
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization: a. Conducts backups of user-level information contained in the information system that allows for immediate (rapid) restoration with little to no loss of operability; b. Conducts backups of system-level information contained in the information system that allows for immediate (rapid) restoration with little to no loss of operability; c. Conducts backups of information system documentation including security-related documentation that allows for immediate (rapid) restoration with little to no loss of operability; and d. Protects the confidentiality and integrity of backup information at the storage locations.
Identification and Authenticiation
IA-1
IDENTIFICATION AND
AUTHENTICATION POLICY
AND PROCEDURES
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here: The organization utilizes an identificaiton and authenticiation system that identifies and validates both devices and users on their systems.
IR-2 INCIDENT RESPONSE
TRAINING
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization provides incident response training to information system users consistent with assigned roles and responsibilities: a. Within 30 days of assuming an incident response role or responsibility; b. When required by information system changes; and c. Annually thereafter.
IR-3 INCIDENT RESPONSE
TESTING
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization tests the incident response capability for the information system annually using established incident response plan to determine the incident response effectiveness and documents the results.
(2) The organization coordinates incident response testing with organizational elements responsible for related plans.
IR-4 INCIDENT HANDLING
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization: a. Implements an incident handling capability for security incidents that includes preparation, detection and analysis, containment, eradication, and recovery; b. Coordinates incident handling activities with contingency planning activities; and c. Incorporates lessons learned from ongoing incident handling activities into incident response procedures, training, and testing/exercises, and implements the resulting changes accordingly.
IR-5 INCIDENT MONITORING
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization tracks and documents information system security incidents.
IR-6 INCIDENT REPORTING
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization: a. Requires personnel to report suspected security incidents to the organizational incident response capability within 30 minutes of detection; and b. Reports security incident information to System Owner and Information Systems Security Manager.
Maintenance
Incident Response
Contingency Planning
MA-2 CONTROLLED
MAINTENANCE
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization: a. Schedules, performs, documents, and reviews records of maintenance and repairs on information system components in accordance with manufacturer or vendor specifications and/or organizational requirements; b. Approves and monitors all maintenance activities, whether performed on site or remotely and whether the equipment is serviced on site or removed to another location; c. Requires that Information System Security Manager, Information System Security Officer, System Owners (aka System Program Managers, System Project Managers, Custodians explicitly approve the removal of the information system or system components from organizational facilities for off-site maintenance or repairs; d. Sanitizes equipment to remove all information from associated media prior to removal from organizational facilities for off-site maintenance or repairs; e. Checks all potentially impacted security controls to verify that the controls are still functioning properly following maintenance or repair actions; and f. Includes: Date and time of maintenance; Name of the individual performing the maintenance; Name of escort, if necessary; A description of the maintenance performed; and A list of equipment removed or replaced (including identification numbers, if applicable) in organizational maintenance records.
PE-2 PHYSICAL ACCESS
AUTHORIZATIONS
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization: a. Develops, approves, and maintains a list of individuals with authorized access to the facility where the information system resides;
b. Issues authorization credentials for facility access; c. Reviews the access list detailing authorized facility access by individuals at least annually; and d.
Removes individuals from the facility access list when access is no longer required.
PE-3 PHYSICAL ACCESS
CONTROL
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization: a. Enforces physical access authorizations at every point to facilities housing workstations that process or display sensitive information or unclassified information that has not been cleared for release by; 1. Verifying individual access authorizations before granting access to the facility; and 2. Controlling ingress/egress to the facility using a required two forms of identification to gain access to the facility (e.g. ID Badge, key card, cipher PIN, biometrics). Including ingress/egress monitoring by guards or alarms 24 x 7, where intrusion alarm systems are monitored; b. Maintains physical access audit logs for all ingress and egress of the housing facility and controlled areas within the facility; c. Provides security policy to control access to areas within the facility officially designated as publicly accessible;
d. Escorts visitors and monitors visitor activity as defined by parameters in the security policy; e. Secures keys, combinations, and other physical access devices; f. Inventories: physical access devices (e.g. access cards, ID badges) every at least annually; and g. Changes combinations and keys at least annually and/or when keys are lost, combinations are compromised, or individuals are transferred or terminated.
PE-5 ACCESS CONTROL FOR
OUTPUT DEVICES
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization controls physical access to information system output devices to prevent unauthorized individuals from obtaining the output.
PE-6 MONITORING PHYSICAL
ACCESS
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization: a. Monitors physical access to the information system to detect and respond to physical security incidents; b. Reviews physical access logs at least quarterly and upon occurrence of any physical security incidents or potential indications of events; and c. Coordinates results of reviews and investigations with the organization’s incident response capability.
PE-17 ALTERNATE WORK SITE
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization: a. Employs access and security controls equivalent to the primary work site at alternate work sites; b. Assesses as feasible, the effectiveness of security controls at alternate work sites; and c. Provides a means for employees to communicate with information security personnel in case of security incidents or problems.
PS-3 PERSONNEL SCREENING
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization: a. Screens individuals prior to authorizing access to the information system; and b. Rescreens individuals according to corporate HR policy for non-cleared personnel and NISPOM policy for National Security Clearances (e.g. SECRET, TOP SECRET).
Personnel Security
Physical and Environmental Protection
PS-4 PERSONNEL
TERMINATION
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization, upon termination of individual employment: a. Disables information system access immediately upon termination; b.
Terminates/revokes any authenticators/credentials associated with the individual; c. Conducts exit interviews that include a discussion of termination actions specified by Senior Management; d. Retrieves all security-related organizational information system-related property; e.
Retains access to organizational information and information systems formerly controlled by terminated individual; and f. Notifies management, personnel, operations and security staff within immediately upon termination.
PS-5 PERSONNEL TRANSFER
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization: a. Reviews and confirms ongoing operational need for current logical and physical access authorizations to information systems/facilities when individuals are reassigned or transferred to other positions within the organization; b. Initiates transfer or reassignment actions within immediately following the formal transfer action; c. Modifies access authorization as needed to correspond with any changes in operational need due to reassignment or transfer; and d. Notifies management, personnel, operations and security staff within immediately upon reassignment or transfer action.
RA-3 RISK ASSESSMENT
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization: a. Conducts an assessment of risk, including the likelihood and magnitude of harm, from the unauthorized access, use, disclosure, disruption, modification, or destruction of the information system and the information it processes, stores, or transmits; b. Documents risk assessment results in a security assessment report; c. Reviews risk assessment results annually; d. Disseminates risk assessment results to Information System Security Manager, Information System Security Officer, System Owners (aka System Program Managers, System Project Managers, Custodians; and e. Updates the risk assessment at least every three (3) years or whenever there are significant changes to the information system or environment of operation (including the identification of new threats and vulnerabilities), or other conditions that may impact the security state of the system.
*RA-5 Tentative VULNERABILITY
SCANNING
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization: a. Scans for vulnerabilities in the information system and hosted applications at least monthly and when new vulnerabilities potentially affecting the system/applications are identified and reported; b. Employs vulnerability scanning tools and techniques that facilitate interoperability among tools and automate parts of the vulnerability management process by using standards for: 1. Enumerating platforms, software flaws, and improper configurations; 2. Formatting checklists and test procedures; and
3. Measuring vulnerability impact; c. Analyzes vulnerability scan reports and results from security control assessments; d. Remediates legitimate vulnerabilities for critical and high risk vulnerabilities within 30 days, within 90 days for all moderate risk vulnerabilities, and 120 days for all other vulnerabilities in accordance with an organizational assessment of risk; and
e. Shares information obtained from the vulnerability scanning process and security control assessments with senior management, the system owner and information system security officer (ISSO) to help eliminate similar vulnerabilities in other information systems (i.e., systemic weaknesses or deficiencies).
(5) The information system implements privileged access authorization to all information system components for all vulnerability scanning activities.
*SA-8 Tentative Could Breach Proprietary
DATA
SECURITY ENGINEERING
PRINCIPLES
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization applies information system security engineering principles in the specification, design, development, implementation, and modification of the information system.
SC-7 BOUNDARY PROTECTION
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The information system: a. Monitors and controls communications at the external boundary of the system and at key internal boundaries within the system; b. Implements subnetworks for publicly accessible system components that are logically separated from internal organizational networks; and c. Connects to external networks or information systems only through managed interfaces consisting of boundary protection devices arranged in accordance with organizational security architecture.
(5) The information system at managed interfaces denies network communications traffic by default and allows network communications traffic by exception (i.e., deny all, permit by exception).
(7) The information system, in conjunction with a remote device, prevents the device from simultaneously establishing non-remote connections with the system and communicating via some other connection to resources in external networks.
System and Communications Protection
System Service and Acquisition
Risk Assessment
SC-8
TRANSMISSION
CONFIDENTIALITY AND
INTEGRITY
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The information system protects the confidentiality and integrity of transmitted information.
(1) The information system implements cryptographic mechanisms to prevent unauthorized disclosure of information and detect changes to information during transmission unless otherwise protected by protected distribution system.
SC-12
CRYPTOGRAPHIC KEY
ESTABLISHMENT AND
MANAGEMENT
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization establishes and manages cryptographic keys for required cryptography employed within the information system in accordance with NIST and FIPS compliance requirements for key generation, distribution, storage, access, and destruction.
SC-13 CRYPTOGRAPHIC
PROTECTION
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The information system implements FIPS validated or NSA approved cryptography in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.
SC-23 SESSION AUTHENTICITY
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The information system protects the authenticity of communications sessions.
SC-28 PROTECTION OF
INFORMATION AT REST
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The information system protects the confidentiality and integrity of all information at rest.
SI-2 FLAW REMEDIATION
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization: a. Identifies, reports, and corrects information system flaws; b. Tests software and firmware updates related to flaw remediation for effectiveness and potential side effects before installation; c. Installs security-relevant software and firmware updates within 30 days of the release of the updates; and d. Incorporates flaw remediation into the organizational configuration management process.
SI-3 MALICIOUS CODE
PROTECTION
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization: a. Employs malicious code protection mechanisms at information system entry and exit points to detect and eradicate malicious code; b. Updates malicious code protection mechanisms whenever new releases are available in accordance with organizational configuration management policy and procedures; c. Configures malicious code protection mechanisms to: 1. Perform periodic scans of the information system daily and real-time scans of files from external sources at network entry/exit points as the files are downloaded, opened, or executed in accordance with organizational security policy; and 2. Block, quarantine malicious code, and send alert to administrator of all actions in response to malicious code detection; and d. Addresses the receipt of false positives during malicious code detection and eradication and the resulting potential impact on the availability of the information system.
SI-5
SECURITY ALERTS,
ADVISORIES, AND
DIRECTIVES
Describe how the proposed solution addresses the Information Assurance and Cyber Security concerns stated here:
The organization: a. Receives information system security alerts, advisories, and directives from US-CERT and OMB on an ongoing basis; b. Generates internal security alerts, advisories, and directives as deemed necessary; c.
Disseminates security alerts, advisories, and directives to: all staff with system administration, monitoring, and/or security responsibilities including but not limited to ISSM, ISSO, System Program Managers, Sys/Net/App Admins, etc.; and d. Implements security directives in accordance with established time frames, or notifies the issuing organization of the degree of noncompliance.
End of Questionnaire
System and Information Integrity
File details come from the government source that posted it. Updated .