Exhibit 011 -TD P 85-01.xlsx

XLSX spreadsheet 344 KB Posted

Attached to
Cash PAK System Federal contract opportunity
Solicitation number
2031ZA23R00015
Issued by
Department of the Treasury Bureau of Engraving and Printing

About this file

This is a solicitation for a Cash PAK System. The Department of the Treasury Bureau of Engraving and Printing is seeking a solution to automate the packaging of currency. Vendors must be able to design, build, install, and maintain a fully automated system capable of counting and securely wrapping stacks of currency at high speeds with integrated quality control. Proposals are due by January 15, 2023 with award anticipated by March 31, 2023. The contract will have a one year base period and four one-year options. The solicitation includes detailed technical requirements for throughput, accuracy, security features and maintenance support.

View the file

Other files for this federal contract opportunity

Show all 22

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Instructions

Instructions for Appendix A: Minimum Standard Parameters
This appendix contains minimum parameters as determined by the Department for NIST SP 800-53 security controls that have an organization assignment, as well as Treasury-specific requirements. Treasury requirements are mapped to the NIST controls to which they most closely relate. For reference purposes, some NIST controls that do not require a parameter to be defined are also included. Appendix A is not a comprehensive list of baseline security requirements. The following information explains the structure of the appendix along with instructions for its use in developing a tailored security control baseline.
1. NIST Control Number (column 1)
a. Control names and numbers are from NIST SP 800-53.
2. Reference Number (column 2)
a. Part one of the reference number is the NIST control number (e.g. AC-1).
b. Part two is the source of the requirement.
i. ‘N’ is for NIST.
ii. ‘T’ is for Treasury.
c. Part three identifies each discrete requirement of a control.
i. NIST sourced controls are assigned a two-digit value beginning with 00 for each requirement within a control (e.g. AC-2 includes a.-k.; therefore its numeric

values are 00-14). The numbers reset to 00 for every NIST control.

ii. Treasury sourced requirements are assigned a three-digit value, beginning at 001, and increment continuously throughout the appendix.
3. The Control or Requirement (column 3)
a. Bureaus shall ensure that parameters marked ‘[bureau-defined]’ are established and documented. Bureau-defined parameters provide the capability to tailor

security controls and control enhancements based on:

i. security requirements to support organizational missions/business functions and operational needs;
ii. risk assessments and organizational risk tolerance; and
iii. security requirements originating in federal laws, Executive Orders, directives, policy (including Treasury policy), regulations, standards, and/or guidelines.
b. Where a ‘[Selection:]’ value is not assigned, bureaus may assign their own.
c. Bureaus shall designate each control as common, system-specific, or hybrid controls.
4. The Baseline (columns 4, 5, 6)
a. L=Low, M=Moderate, H=High
i. Controls or requirements marked with an ‘X’ in the L, M, or H columns means they are part of that baseline.
ii. A ‘P’ in the "Baseline" columns means that the control is a program-level control. These controls are:
1. deployed organization-wide;
2. supporting information security programs;
3. not associated with security control baselines; and
4. independent of any system impact level.
iii. “X” in the “C” column (column 7) means that the control is a Cyber Critical Infrastructure Protection control. These controls are applied to information

systems designated as Cyber Critical Infrastructure Assets by the Departmental CIO.

Implementation of the Critical Infrastructure System Control Overlay

Information systems designated as Cyber Critical Infrastructure Assets shall implement the security controls designated by an “X” in the “C” column of Appendix A:

1) The “Critical Infrastructure Control Overlay” shall be applied to all components within the designated Cyber Critical Infrastructure Asset systems security boundary.
a. GUIDANCE: Information systems normally consist of components (servers, routers, batch processing routines, mainframes, etc.) that when combined allow the

overall system to perform its intended function. The intent is to increase the trustworthiness and resiliency of the overall system by applying the control overlay to all the components of the designated system, where applicable. It is understood that security controls are applicable only to information system components that provide or support the capability addressed by the controls. Please document the implementation accordingly.

2) The controls in the Cyber Critical Infrastructure Overlay may be tailored per the “Tailoring Baseline Security Controls” policy in the following section.
a. If the Authorizing Official, in coordination with the system and organizational officials, determines that a control in the Overlay shall not be implemented (also

referred to as “tailoring-out”) on a designated Cyber Critical Infrastructure Asset, the associated documentation for this risk-based decision not to implement shall be submitted to the Department Cyber CIP Program Manager and the Departmental CISO for review.

Tailoring Baseline Security Controls

Step two of the RMF is the selection of an applicable security control baseline based on the results of the security categorization and the application of tailoring guidance. Per NIST SP 800-53 Revision 4, the use of the term baseline is intentional. The security controls and control enhancements in the baselines are a starting point from which control/enhancements can be removed, added, or specialized based on the tailoring guidance in Section 3.2.

The tailoring process, as an integral part of security control selection and specification, is part of a comprehensive organizational risk management process—framing, assessing, responding to, and monitoring information security risk. Bureaus shall use risk management guidance to facilitate risk-based decision making regarding the applicability of security controls in the security control baselines. Bureaus shall consider the tailoring process to achieve cost-effective, risk-based security that supports organizational mission/business needs. Tailoring activities are approved by authorizing officials in coordination with selected organizational officials (e.g., Risk Executive [function], CIOs, CISOs, Information System Owners, or common control providers) prior to implementing the security controls.

Conversely, bureaus shall not remove security controls for operational convenience. Tailoring decisions regarding security controls should be defensible based on mission/business needs and accompanied by explicit risk-based determinations. Tailoring decisions, including the specific rationale for those decisions, are documented in the security plans for information systems. Every security control from the applicable security control baseline is accounted for either by the organization (e.g., common control provider) or by the system owner. If certain security controls are tailored out, compensating security controls are selected if needed, and the associated rationale is recorded in security plans (or references/pointers to other relevant documentation are provided) for the information systems and approved by the AO and other responsible officials as part of the security plan approval process.

Documenting significant risk management decisions in the security control selection process is imperative in order for AOs to have the necessary information to make credible, risk-based decisions with regard to the authorization of information systems. Since information systems, environments of operation, and personnel associated with the system development life cycle are subject to change, providing the assumptions, constraints, and rationale supporting those important risk decisions allows for a better understanding in the future of the security state of the information systems or environments of operation at the time the original risk decisions were made and facilitates identifying changes, when previous risk decisions are revisited.

The tailoring guidance previously described may only be applied to NIST baseline controls. Implementation of Treasury requirements in Appendix A (i.e., those with a ‘T’ in the Reference number) is mandatory. Bureaus may choose to tailor Treasury requirements if supported by risk assessment by selecting compensating controls only under the following conditions:

1) Compensating controls must be selected from NIST SP 800-53, TD P 85-01 Appendix A, or a bureau documented control, when applicable;
2) Bureaus must provide a documented complete and convincing rationale and justification for how the compensating control provides an equivalent security

capability to the AO with a copy to the Bureau CISO for review; and

3) Use of approved compensating controls must be recorded in security plans.

Exceptions to Treasury Requirements

Bureau-wide exceptions to Treasury requirements shall be managed differently than information system tailoring. Documentation of exception requests to Treasury requirements must include operational justification, risk acceptance, and risk mitigation measures. Such requests must be submitted to and approved by the Bureau CIO, in consultation with the Bureau CISO. An approved exception must be signed by the individuals in these roles and held by the bureau, with a copy submitted to the Department CIO via the Department CISO for review.

Appendix A Instructions

Appendix A + CIP2

ControlsRequirementsTD P 85-01 Appendix ALMHCIP
Cyber CIP Overlay Control Count (When Control and Cip Filter set):
306764Baseline Control Count:504664743303
BaselineOverlay
NIST CONTROL #REFERENCE #REQUIREMENTLMHCIP
AC-1AC-1_N.00ACCESS CONTROL POLICY AND PROCEDURES

The organization:

a. Develops, documents, and disseminates to [Bureau-defined personnel or roles]:

1. An access control policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; andXXX
AC-1_N.012. Procedures to facilitate the implementation of the access control policy and associated access controls; andXXX
AC-1_N.02b. Reviews and updates the current:
1. Access control policy [at least every three years or if there is a significant change]; andXXX
AC-1_N.032. Access control procedures [at least every three years or if there is a significant change].XXX
AC-2AC-2_N.00ACCOUNT MANAGEMENT

Control: The organization:

a. Identifies and selects the following types of information system accounts to support organizational missions/business functions: [Bureau-defined information system account types];

(see b-e in 800-53 rev 4)XXXX
AC-2_N.01b. Assigns account managers for information system accounts;XXXX
AC-2_N.02c. Establishes conditions for group and role membership;XXXX
AC-2_N.03d. Specifies authorized users of the information system, group and role membership, and access authorizations (i.e., privileges) and other attributes (as required) for each account;XXXX
AC-2_N.04e. Requires approvals by [Bureau-defined personnel or roles] for requests to create information system accounts;XXXX
AC-2_N.05f. Creates, enables, modifies, disables, and removes information system accounts in accordance with [Bureau-defined procedures or conditions];
(see g, h, I in 800-53 rev 4)XXXX
AC-2_N.06g. Monitors the use of information system accounts;XXXX
AC-2_N.07h. Notifies account managers:
1. When accounts are no longer required;XXXX
AC-2_N.082. When users are terminated or transferred; andXXXX
AC-2_N.093. When individual information system usage or need-to-know changes;XXXX
AC-2_N.10i. Authorizes access to the information system based on:
1. A valid access authorization;XXXX
AC-2_N.112. Intended system usage; andXXXX
AC-2_N.123. Other attributes as required by the organization or associated missions/business functions;XXXX
AC-2_N.13j. Reviews accounts for compliance with account management requirements [of users annually; privileged users semi-annually]; andXXXX
AC-2_N.14k. Establishes a process for reissuing shared/group account credentials (if deployed) when individuals are removed from the group.XXXX
AC-2(2)AC-2(2)_N.00ACCOUNT MANAGEMENT | REMOVAL OF TEMPORARY / EMERGENCY ACCOUNTS
The information system automatically [Selection: removes; disables] temporary and emergency accounts after [no longer than two business days].XX
AC-2(3)AC-2(3)_N.00ACCOUNT MANAGEMENT | DISABLE INACTIVE ACCOUNTS
The information system automatically disables inactive accounts after [120 days (Public users can be determined by the Bureau)].XX
AC-2(4)AC-2(4)_N.00ACCOUNT MANAGEMENT | AUTOMATED AUDIT ACTIONS
The information system automatically audits account creation, modification, enabling, disabling, and removal actions, and notifies [Bureau-defined personnel or roles].XX
AC-2(5)AC-2(5)_N.00ACCOUNT MANAGEMENT | INACTIVITY LOGOUT
The organization requires that users log out when [Bureau-defined time period of expected inactivity or description of when to log out]X
AC-2(11)AC-2(11)_N.00ACCOUNT MANAGEMENT | USAGE CONDITIONS
The information system enforces [Bureau-defined circumstances and/or usage conditions] for [Bureau-defined information system accounts].X
AC-2(12)AC-2(12)_N.00ACCOUNT MANAGEMENT | ACCOUNT MONITORING / ATYPICAL USAGE

The organization:

(a) Monitors information system accounts for [Bureau-defined atypical use]; andX
AC-2(12)_N.01(b) Reports atypical usage of information system accounts to [Bureau-defined personnel or roles].X
AC-2(13)AC-2(13)_N.00ACCOUNT MANAGEMENT | DISABLE ACCOUNTS FOR HIGH-RISK INDIVIDUALS
The organization disables accounts of users posing a significant risk within [Bureau-defined, but not greater than one business day time period] of discovery of the risk.X
AC-3AC-3_N.00ACCESS ENFORCEMENT
Control: The information system enforces approved authorizations for logical access to information and system resources in accordance with applicable access control policies.XXXX
AC-3_T.002Users having accounts with administrators access privileges on Treasury systems may access those accounts only from Treasury government or authorized government contractor systems.

INFORMATIVE: In other words, a key intent is to prohibit personally-owned or public kiosk (e.g., library) systems from being used for remote Administrator access.

INFORMATIVE: If individuals with administrator rights require e-mail or Internet access beyond local boundaries, one alternative would be to issue separate, non-privileged accounts (one per affected individual) for that purpose. For the considerations of this section, administrator accounts/rights are those that allow for the installation or configuration of software on any Treasury asset.XXXX
AC-4AC-4_N.00INFORMATION FLOW ENFORCEMENT
Control: The information system enforces approved authorizations for controlling the flow of information within the system and between interconnected systems based on [applicable policies, agreements, contracts and/or procedures].XXX
AC-5AC-5_N.00SEPARATION OF DUTIES

Control: The organization:

a. Separates [Bureau-defined duties of individuals];XX
AC-6AC-6_N.00LEAST PRIVILEGE
Control: The organization employs the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with organizational missions and business functions.XXX
AC-6_T.003Accounts with administrative privileges (including local administrator rights) shall be prohibited from web browsing and other Internet connections outside of the local protected boundary (usually Treasury) unless such risk is accepted in writing by the Bureau CIO.

INFORMATIVE: If individuals with administrator rights require e-mail or Internet access beyond local boundaries, one alternative would be to issue separate, non-privileged accounts (one per affected individual) for that purpose. For the considerations of this section, administrator accounts/rights are those that allow for the installation or configuration of software on any Treasury asset.

XXX
AC-6_T.004Accounts with administrative privileges (including local administrator rights) shall be blocked from access to e-mail unless such risk is accepted in writing by the Bureau CIO.
INFORMATIVE: If individuals with administrator rights require e-mail or Internet access beyond local boundaries, one alternative would be to issue separate, non-privileged accounts (one per affected individual) for that purpose. For the considerations of this section, administrator accounts/rights are those that allow for the installation or configuration of software on any Treasury asset.XXX
AC-6(1)AC-6(1)_N.00LEAST PRIVILEGE | AUTHORIZE ACCESS TO SECURITY FUNCTIONS
The organization explicitly authorizes access to [Bureau-defined security functions (deployed in hardware, software, and firmware) and security-relevant information].XX
AC-6(2)AC-6(2)_N.00LEAST PRIVILEGE | NON-PRIVILEGED ACCESS FOR NONSECURITY FUNCTIONS
The organization requires that users of information system accounts, or roles, with access to [security functions including but are not limited to: establishing system accounts, configuring access authorizations (i.e., permissions, privileges), setting events to be audited, and setting intrusion detection parameters], use non-privileged accounts or roles, when accessing nonsecurity functions.XX
AC-6(3)AC-6(3)_N.00LEAST PRIVILEGE | NETWORK ACCESS TO PRIVILEGED COMMANDS
The organization authorizes network access to [Bureau-defined privileged commands] only for [Bureau-defined compelling operational needs] and documents the rationale for such access in the security plan for the information system.XX
AC-6(5)AC-6(5)_N.00LEAST PRIVILEGE | PRIVILEGED ACCOUNTS
The organization restricts privileged accounts on the information system to [Bureau-defined personnel or roles].XX
AC-6(6)AC-6(6)_N.00LEAST PRIVILEGE | PRIVILEGED ACCESS BY NON-ORGANIZATIONAL USERS
The organization prohibits privileged access to the information system by non-organizational users.X
AC-7AC-7_N.00UNSUCCESSFUL LOGON ATTEMPTS

Control: The information system:

a. Enforces a limit of [three] consecutive invalid logon attempts by a user during a [120 minute period; andXXX
AC-7_N.01b. (LOW, MODERATE) Automatically [locks the account/node for 15 minutes or until released by an administrator] when the maximum number of unsuccessful attempts is exceeded.XX
AC-7_N.01b.(HIGH) Automatically [locks the account/node until released by an administrator] when the maximum number of unsuccessful attempts is exceeded.X
AC-8AC-8_N.00SYSTEM USE NOTIFICATION

Control: The information system:

a. Displays to users [Bureau-defined system use notification message or banner] before granting access to the system that provides privacy and security notices consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance and states that:

1. Users are accessing a U.S. Government information system;

(see 2-4, and b. in 80-53 rev 4)XXX
AC-8_N.05c. For publicly accessible systems:
1. Displays system use information [Bureau-defined conditions], before granting further access;XXX
AC-10AC-10_N.00CONCURRENT SESSION CONTROL
Control: The information system limits the number of concurrent sessions for each [Bureau-defined account and/or account type] to [one for non-privileged users and three for privileged users].X
AC-11AC-11_N.00SESSION LOCK

Control: The information system:

a. Prevents further access to the system by initiating a session lock after [30 minutes or less] of inactivity or upon receiving a request from a user; andXX
AC-12AC-12_N.00SESSION TERMINATION
Control: The information system automatically terminates a user session after [Bureau-defined conditions or trigger events requiring session disconnect].XX
AC-14AC-14_N.00PERMITTED ACTIONS WITHOUT IDENTIFICATION OR AUTHENTICATION

Control: The organization:

a. Identifies [Bureau-defined user actions] that can be performed on the information system without identification or authentication consistent with organizational missions/business functions; andXXX
AC-17AC-17_N.00REMOTE ACCESS

Control: The organization:

a. Establishes and documents usage restrictions, configuration/connection requirements, and implementation guidance for each type of remote access allowed; andXXX
AC-17_N.01b. Authorizes remote access to the information system prior to allowing such connections.XXX
AC-17_T.006Two-factor authentication shall be implemented for all remote access back to a Departmental system.

INFORMATIVE: "Remote access" is defined as LAN-like access to a Treasury system from a location or facility not controlled by a Treasury organization. Access to websites and other systems available to the public, as well as access to non-Treasury or publicly available information, is not considered "remote access."

Examples: If a Treasury employee works at home on a personally-owned computer using public or non-Treasury information, that would not entail “remote access.” If a State of Rhode Island employee has been granted access to a Treasury system and that employee accesses the Treasury system from a State of Rhode Island facility, it would be considered “remote access.” A Treasury employee using a Treasury laptop without connectivity back to a Treasury system for an audit at a firm in a commercial office building would not be considered “remote access.”XXX
AC-17(2)AC-17(2)_N.00REMOTE ACCESS | PROTECTION OF CONFIDENTIALITY / INTEGRITY USING ENCRYPTION
The information system implements cryptographic mechanisms to protect the confidentiality and integrity of remote access sessions.XX
AC-17(2)_T.206Remote Access Security. Remote access sessions to Treasury IT assets (e.g., networks, systems) shall only be provided through an encryption mechanism such as a virtual private network (VPN) connection that meets FIPS 140 validation requirements.
INFORMATIVE: This control does not apply to sessions used for the dissemination of non-sensitive information to the public.XXX
AC-17(3)AC-17(3)_N.00REMOTE ACCESS | MANAGED ACCESS CONTROL POINTS
The information system routes all remote accesses through [Bureau-defined number] managed network access control points.XX
AC-17(4)AC-17(4)_N.00REMOTE ACCESS | PRIVILEGED COMMANDS / ACCESS

The organization:

(a) Authorizes the execution of privileged commands and access to security-relevant information via remote access only for [Bureau-defined needs]; andXX
AC-18AC-18_N.00WIRELESS ACCESS

Control: The organization:

a. Establishes usage restrictions, configuration/connection requirements, and implementation guidance for wireless access; andXXX
AC-18_N.01b. Authorizes wireless access to the information system prior to allowing such connections.XXX
AC-18_T.246Treasury bureaus shall coordinate with the Treasury Office of Intelligence and Analysis to establish a wireless program to protect National Security Systems (NSS) when unclassified wireless technologies are used to transmit, receive, process, or store unclassified data in the proximity of Treasury NSS or National Security Information (NSI).
INFORMATIVE: This control also applies to any/all guest wireless networks.XXX
AC-18_T.247Guest wireless networks operated by or on behalf of Treasury in Treasury facilities shall be completely logically separate from all Treasury networks.XXX
AC-18(3)_T.008Bureaus shall ensure that unapproved wireless networking capabilities of desktops, laptops, printers, copiers, fax machines, SCADA systems, and other devices are disabled (through automated means, where technically possible) and monitored through automated means for unauthorized changes.
INFORMATIVE: One alternative yet acceptable approach to “monitoring through automated means” is regularly pushing out settings that restrict unapproved wireless connections.XXX
AC-18_T.009Bureaus shall monitor for unauthorized wireless access to the information system and enforce requirements for wireless connections to the information system.XXX
AC-18_T.010Implementation and use of wireless networks must be approved by the Authorizing Official in accordance with organizational risk tolerance and commensurate with the security categorization of the data to be carried by the system, which may be no higher than the security categorization of the systemXXX
AC-18_T.012Bureaus shall scan for rogue wireless access points and other wireless activity that are not in compliance with Departmental policy.XXX
AC-18(1)AC-18(1)_N.00WIRELESS ACCESS | AUTHENTICATION AND ENCRYPTION
The information system protects wireless access to the system using authentication of [Selection (one or more): users; devices] and encryption.XX
AC-18(3)AC-18(3)_N.00WIRELESS ACCESS | DISABLE WIRELESS NETWORKING
The organization disables, when not intended for use, wireless networking capabilities internally embedded within information system components prior to issuance and deployment.XXX
AC-18(3)_T.011Bureaus shall employ security mechanisms for wireless networks consistent with the sensitivity of the information to be transmitted. For transmissions of FIPS 199 MODERATE or HIGH confidentiality information, FIPS 140-2 validated encryption must be employed.XX
AC-19AC-19_N.00ACCESS CONTROL FOR MOBILE DEVICES

Control: The organization:

a. Establishes usage restrictions, configuration requirements, connection requirements, and implementation guidance for organization-controlled mobile devices; andXXX
AC-19_N.01b. Authorizes and monitors the connection of mobile devices to organizational information systems.XXX
AC-19_T.016Bureaus shall ensure that all Treasury information on all mobile devices is encrypted using FIPS 140-2 (or succeeding guidance) validated encryption technology, except when no such encryption technology solutions are available to address a specific device.XXX
AC-19_T.018The bureau CISO or designee must give written approval before an individual within the office may take a government-owned laptop computer and/or other mobile devices overseas.PPP
AC-19_T.019Bureau deployment of government-owned mobile devices to process, store, or transmit Treasury information must be approved by the Authorizing Official in accordance with organizational risk tolerance and commensurate with the security categorization of the data to be processed, stored, or transmitted, which may be no higher than the security categorization of the devices.XXX
AC-19_T.020Mobile devices taken outside the U.S. (whether for official or personal travel) may not connect wirelessly to a Treasury system unless sanitized.

INFORMATIVE: Excluded is this situation of transiting another country provided the device remains under the immediate control of the user.

INFORMATIVE: It is permissible simply to prohibit non-wireless mobile device connections entirely.XXX
AC-19_T.021This control addresses laptop computers that are temporarily taken overseas. All laptops temporarily taken overseas must be protected by: 1) full disk FIPS validated encryption; 2) disabling any wireless capability; and 3) either disabling all USB ports(s) or use of tamper-evident bags/seals/containers each time the laptop is left unattended (i.e., not under the direct and immediate control of a U.S. Government employee or authorized government contractor). If any laptop is not protected as described above, it may not be reconnected to a Treasury system or network until sanitized.XXX
AC-19_T.022Laptops and other devices containing Treasury information categorized as High or Moderate (confidentiality) under FIPS 199 shall not be connected to networks while outside the U.S., unless employing a separate hard drive or a secure partition (physical or virtual) with a separate operating system instance that contains no High or Moderate Treasury information.XX
AC-19_T.023Hard drives or partitions that connect to networks while outside the U.S. shall not be connected to Treasury networks at any time.XXX
AC-19_T.024During overseas travel, batteries shall be removed from battery-powered mobile devices and stored separate from the device when the device is left unattended. The battery also shall be removed if the device is within auditable range of sensitive conversations while overseas.
INFORMATIVE: This control applies to any mobile device where removable of the battery is possibleXXX
AC-19_T.025During overseas travel, SIM cards shall be removed and stored separate from devices that employ them when going through non-U.S. customs.
INFORMATIVE: This control applies to any mobile device where removal of the battery is possibleXXX
AC-19_T.026Bureaus shall provide users with procedures to follow during foreign travel when a device is taken out of their possession and view for other than routine airport security scans.ppp
AC-19(5)AC-19(5)_N.00ACCESS CONTROL FOR MOBILE DEVICES | FULL DEVICE / CONTAINER-BASED ENCRYPTION
The organization employs [Selection: full-device encryption; container encryption] to protect the confidentiality and integrity of information on [Bureau-defined mobile devices].XX
AC-20(1)AC-20(1)_N.00USE OF EXTERNAL INFORMATION SYSTEMS | LIMITS ON AUTHORIZED USE

The organization permits authorized individuals to use an external information system to access the information system or to process, store, or transmit organization-controlled information only when the organization:

(a) Verifies the implementation of required security controls on the external system as specified in the organization’s information security policy and security plan; orXX
AC-20(1)_N.01(b) Retains approved information system connection or processing agreements with the organizational entity hosting the external information system.XX
AC-20(2)AC-20(2)_N.00USE OF EXTERNAL INFORMATION SYSTEMS | PORTABLE STORAGE DEVICES
The organization [Selection: restricts; prohibits] the use of organization-controlled portable storage devices by authorized individuals on external information systems.XX
AC-20(3)AC-20(3)_N.00USE OF EXTERNAL INFORMATION SYSTEMS | NON-ORGANIZATIONALLY OWNED SYSTEMS / COMPONENTS / DEVICES
The organization [prohibits] the use of non-organizationally owned information systems, system components, or devices to process, store, or transmit organizational [FIPS 199 High] information.X
AC-20(3)_T.028Approval by the bureau CISO and AO is required for use of non-government-furnished IT equipment to store, access, process, or transmit Treasury FIPS 199 Low and Moderate information, with the exception that minor amounts of incidental (and no higher than FIPS 199 LOW confidentiality) information, such as phone numbers or an employee's daily schedule, may be permitted by authorization of the employee's supervisor. (This control does not apply to information made available proactively to the general public by the Treasury).

INFORMATIVE: Government-provided secure virtual environments installed on non-government furnished equipment may be used to access Treasury information, unless prohibited or otherwise restricted by Bureau policy.

INFORMATIVE: Government-provided secure virtual environments installed on non-government furnished equipment are considered to be the same as government-furnished equipment.XX
AC-20(3)_T.029Bureaus that permit use of non-government furnished IT equipment per control T.028 to process, store, or transmit Treasury information shall establish terms and conditions of each use. The systems and conditions shall address, at a minimum, NIST SP 800-53 Appendix F, Control AC-20 and, when applicable, NIST SP 800-53 Appendix F, Control AC-20, and AC-20(1).XXX
AC-20(3)_T.030Approval by the bureau CISO and AO is required for connection of non-government furnished or contractor-owned IT devices (including USB-connected portable storage and mobile devices) to Treasury systems or networks. (This control does not apply to networks and systems intended for use by the general public)XXX
AC-21AC-21_N.00INFORMATION SHARING

Control: The organization:

a. Facilitates information sharing by enabling authorized users to determine whether access authorizations assigned to the sharing partner match the access restrictions on the information for [Bureau-defined information sharing circumstances where user discretion is required]; andXX
AC-21_N.01b. Employs [Bureau-defined automated mechanisms or manual processes] to assist users in making information sharing/collaboration decisions.XX
AC-22AC-22_N.00PUBLICLY ACCESSIBLE CONTENT

Control: The organization:

a. Designates individuals authorized to post information onto a publicly accessible information system;XXX
AC-22_N.01b. Trains authorized individuals to ensure that publicly accessible information does not contain nonpublic information;XXX
AC-22_N.02c. Reviews the proposed content of information prior to posting onto the publicly accessible information system to ensure that nonpublic information is not included; andXXX
AC-22_N.03d. Reviews the content on the publicly accessible information system for nonpublic information [quarterly] and removes such information, if discovered.XXX
AT-1AT-1_N.00SECURITY AWARENESS AND TRAINING POLICY AND PROCEDURES

Control: The organization:

a. Develops, documents, and disseminates to [Bureau-defined personnel or roles]:

1. A security awareness and training policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; andXXX
AT-1_N.012. Procedures to facilitate the implementation of the security awareness and training policy and associated security awareness and training controls; andXXX
AT-1_N.02b. Reviews and updates the current:
1. Security awareness and training policy [every three years or if there is a significant change]; andXXX
AT-1_N.032. Security awareness and training procedures [every three years or if there is a significant change].XXX
AT-2AT-2_N.00SECURITY AWARENESS TRAINING

Control: The organization provides basic security awareness training to information system users (including managers, senior executives, and contractors):

a. As part of initial training for new users [within 5 business days of being granted access to a Treasury information system (Informative: Bureaus may fulfill this requirement for users’ first 60 days by having them review and accept the rules of behavior)];XXX
AT-2_N.01b. When required by information system changes; andXXX
AT-2_N.02c. [annually] thereafter.XXX
AT-2_T.034Bureaus shall train users and provide means to ensure workstations are adequately protected from theft -- particularly in regard to laptops acting as workstations.XXX
AT-2_T.035At least once per quarter, Bureaus shall distribute security awareness reminders/updates to all users.
INFORMATIVE: This is in addition to annual awareness training. Security awareness updates may be sent via e-mail. Unlike the need to track annual training by individual, Bureaus are not required to track quarterly awareness updates by individual.PPP
AT-2_T.249At least once per quarter, Bureaus shall conduct phishing email simulation exercises.PPP
AT-2_T.250Bureaus shall notify the Treasury Government Security Operations Center (GSOC) prior to executing any phishing email simulation exercise.PPP
AT-3AT-3_N.00ROLE-BASED SECURITY TRAINING

Control: The organization provides role-based security training to personnel with assigned security roles and responsibilities:

a. Before authorizing access to the information system or performing assigned duties;XXX
AT-3_N.01b. When required by information system changes; andXXX
AT-3_N.02c. [annually (see Appendix H for roles that require specialized training)] thereafter.XXX
AT-4AT-4_N.00SECURITY TRAINING RECORDS

Control: The organization:

a. Documents and monitors individual information system security training activities including basic security awareness training and specific information system security training; andXXX
AT-4_N.01b. Retains individual training records for [at least five years].XXX
AU-1AU-1_N.00AUDIT AND ACCOUNTABILITY POLICY AND PROCEDURES

Control: The organization:

a. Develops, documents, and disseminates to [Bureau-defined personnel or roles]:

1. An audit and accountability policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; andXXX
AU-1_N.012. Procedures to facilitate the implementation of the audit and accountability policy and associated audit and accountability controls; andXXX
AU-1_N.02b. Reviews and updates the current:
1. Audit and accountability policy [every three years or if there is a significant change ]; andXXX
AU-1_N.032. Audit and accountability procedures [every three years or if there is a significant change].XXX
AU-2AU-2_N.00AUDIT EVENTS

Control: The organization:

a. Determines that the information system is capable of auditing the following events: [identity of each user and device accessing or attempting to access an IT system; time and date of the access and the logoff; activities that might modify, bypass, or negate IT security safeguards; security-relevant actions associated with processing; user generation of reports and extracts containing information categorized High or Moderate for confidentiality (to the extent technically feasible); and other Bureau defined events];XX
AU-2_N.01b. Coordinates the security audit function with other organizational entities requiring audit-related information to enhance mutual support and to help guide the selection of auditable events;XXX
AU-2_N.02c. Provides a rationale for why the auditable events are deemed to be adequate to support after-the-fact investigations of security incidents; andXXX
AU-2_N.03d. Determines that the following events are to be audited within the information system: [user generation of reports and extracts containing information categorized High or Moderate for confidentiality (to the extent technically feasible); and Bureau-defined audited events (the subset of the auditable events defined in AU-2 a.) along with the frequency of (or situation requiring) auditing for each identified event].XX
AU-2_T.038Bureaus shall develop and implement local procedures and/or technical/operational/ administrative controls to ensure that extracts containing FIPS 199 High or Moderate for confidentiality information are erased within 90 days or that continued use is still required.XX
AU-2(3)AU-2(3)_N.00AUDIT EVENTS | REVIEWS AND UPDATES
The organization reviews and updates the audited events [every two years].XX
AU-3(1)AU-3(1)_N.00CONTENT OF AUDIT RECORDS | ADDITIONAL AUDIT INFORMATION
The information system generates audit records containing the following additional information: [details to facilitate the reconstruction of events if unauthorized activity or a malfunction occurs or is suspected].XX
AU-3(2)AU-3(2)_N.00CONTENT OF AUDIT RECORDS | CENTRALIZED MANAGEMENT OF PLANNED AUDIT RECORD CONTENT
The information system provides centralized management and configuration of the content to be captured in audit records generated by [Bureau-defined information system components].X
AU-4AU-4_N.00AUDIT STORAGE CAPACITY
Control: The organization allocates audit record storage capacity in accordance with [Bureau-defined audit record storage requirements].XXX
AU-5AU-5_N.00RESPONSE TO AUDIT PROCESSING FAILURES

Control: The information system:

a. Alerts [Bureau-defined personnel or roles] in the event of an audit processing failure; andXXX
AU-5_N.01b. Takes the following additional actions: [Bureau-defined actions to be taken (e.g., shut down information system, overwrite oldest audit records, stop generating audit records)].XXX
AU-5(1)AU-5(1)_N.00RESPONSE TO AUDIT PROCESSING FAILURES | AUDIT STORAGE CAPACITY
The information system provides a warning to [Bureau-defined personnel, roles, and/or locations] within [Bureau-defined time period] when allocated audit record storage volume reaches [Bureau-defined percentage] of repository maximum audit record storage capacity.X
AU-5(2)AU-5(2)_N.00RESPONSE TO AUDIT PROCESSING FAILURES | REAL-TIME ALERTS
The information system provides an alert in [Bureau-defined real-time period] to [Bureau-defined personnel, roles, and/or locations] when the following audit failure events occur: [Bureau-defined audit failure events requiring real-time alerts].X
AU-6AU-6_N.00AUDIT REVIEW, ANALYSIS, AND REPORTING

Control: The organization:

a. Reviews and analyzes information system audit records [at frequency in accordance with a risk based decision and documented in the System Security Plan] for indications of [Bureau-defined inappropriate or unusual activity]; andXXXX
AU-6_N.01b. Reports findings to [Bureau-defined personnel or roles].XXXX
AU-6(1)AU-6(1)_N.00AUDIT AND ACCOUNTABILITY | PROCESS INTEGRATION
The organization employs automated mechanisms to integrate audit review, analysis, and reporting processes to support organizational processes for investigation and response to suspicious activities.XXX
AU-6(3)AU-6(3)_N.00AUDIT AND ACCOUNTABILITY | CORRELATE AUDIT REPOSITORIES
The organization analyzes and correlates audit records across different repositories to gain organization-wide situational awareness.XXX
AU-6(5)AU-6(5)_N.00AUDIT REVIEW, ANALYSIS, AND REPORTING | INTEGRATION / SCANNING AND MONITORING CAPABILITIES
The organization integrates analysis of audit records with analysis of [Selection (one or more): vulnerability scanning information; performance data; information system monitoring information; [Bureau-defined data/information collected from other sources]] to further enhance the ability to identify inappropriate or unusual activity.X
AU-7(1)AU-7(1)_N.00AUDIT REDUCTION AND REPORT GENERATION | AUTOMATIC PROCESSING
The information system provides the capability to process audit records for events of interest based on [Bureau-defined audit fields within audit records].XX
AU-8AU-8_N.00TIME STAMPS

Control: The information system:

a. Uses internal system clocks to generate time stamps for audit records; andXXX
AU-8_N.01b. Records time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT) and meets [Bureau-defined granularity of time measurement].XXX
AU-8(1)AU-8(1)_N.00TIME STAMPS | SYNCHRONIZATION WITH AUTHORITATIVE TIME SOURCE

The information system:

(a) Compares the internal information system clocks [at least on a quarterly basis] with [Bureau-defined authoritative time source]; andXX
AU-8(1)_N.01(b) Synchronizes the internal system clocks to the authoritative time source when the time difference is greater than [Bureau-defined time period].XX
AU-9AU-9_N.00PROTECTION OF AUDIT INFORMATION
The information system protects audit information and audit tools from unauthorized access, modification, and deletion.XXXX
AU-9(2)AU-9(2)_N.00PROTECTION OF AUDIT INFORMATION | AUDIT BACKUP ON SEPARATE PHYSICAL SYSTEMS / COMPONENTS
The information system backs up audit records [Bureau-defined frequency] onto a physically different system or system component than the system or component being audited.X
AU-9(4)AU-9(4)_N.00PROTECTION OF AUDIT INFORMATION | ACCESS BY SUBSET OF PRIVILEGED USERS
The organization authorizes access to management of audit functionality to only [Bureau-defined subset of privileged users].XX
AU-10AU-10_N.00NON-REPUDIATION
Control: The information system protects against an individual (or process acting on behalf of an individual) falsely denying having performed [Bureau-defined actions to be covered by non-repudiation].X
AU-11AU-11_N.00AUDIT RECORD RETENTION
Control: The organization retains audit records for [according to Records Management TD 80-05 and General Counsel] to provide support for after-the-fact investigations of security incidents and to meet regulatory and organizational information retention requirements.XXX
AU-12AU-12_N.00AUDIT GENERATION

Control: The information system:

a. Provides audit record generation capability for the auditable events defined in AU-2 a. at [Bureau-defined information system components];XXX
AU-12_N.01b. Allows [Bureau-defined personnel or roles] to select which auditable events are to be audited by specific components of the information system; andXXX
AU-12(1)AU-12(1)_N.00AUDIT GENERATION | SYSTEM-WIDE / TIME-CORRELATED AUDIT TRAIL
The information system compiles audit records from [all components] into a system-wide (logical or physical) audit trail that is time-correlated to within [1 minute of Coordinated Universal Time (UTC) as based upon a recognized time authority (e.g. NIST). Audit records should be stored in UTC format for consistency].X
AU-12(3)AU-12(3)_N.00AUDIT GENERATION | CHANGES BY AUTHORIZED INDIVIDUALS
The information system provides the capability for [Bureau-defined individuals or roles] to change the auditing to be performed on [Bureau-defined information system components] based on [Bureau-defined selectable event criteria] within [Bureau-defined time thresholds].X
CA-1CA-1_N.00SECURITY ASSESSMENT AND AUTHORIZATION POLICY AND PROCEDURES

Control: The organization:

a. Develops, documents, and disseminates to [Bureau-defined personnel or roles]:

1. A security assessment and authorization policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; andXXX
CA-1_N.012. Procedures to facilitate the implementation of the security assessment and authorization policy and associated security assessment and authorization controls; andXXX
CA-1_N.02b. Reviews and updates the current:
1. Security assessment and authorization policy [every three years or if there is a significant change]; andXXX
CA-1_N.032. Security assessment and authorization procedures [every three years or if there is a significant change].XXX
CA-2CA-2_N.00SECURITY ASSESSMENTS

Control: The organization:

a. Develops a security assessment plan that describes the scope of the assessment including:

1. Security controls and control enhancements under assessment;XXXX
CA-2_N.012. Assessment procedures to be used to determine security control effectiveness; andXXXX
CA-2_N.023. Assessment environment, assessment team, and assessment roles and responsibilities;XXXX
CA-2_N.03b. Assesses the security controls in the information system and its environment of operation [at least annually] to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting established security requirements;XXXX
CA-2_N.04c. Produces a security assessment report that documents the results of the assessment; andXXXX
CA-2_N.05d. Provides the results of the security control assessment to [Bureau-defined individuals or roles].XXXX
CA-2_T.041Priority for selection of controls to be tested should be: 1) those POA&M items completed within the applicable timeframe and 2) high-volatility security controls.

INFORMATIVE: There is no set number of controls to be tested annually; however, the number of controls should take into account the FIPS 199 security categorization level of the system. Controls selected for testing should not be limited to technical controls, but also include operational and management controls.

INFORMATIVE: With regard to volatility, by their nature, operational controls require that correct actions be taken by individuals. Due to potential for personnel turnover, degradation in infrequently used skills, and other factors, many operational controls are volatile, which should be taken into account when selecting controls for testing. Additionally, this volatility with regard to individuals also affects access controls, particularly keeping access control lists and permissions (both for general support systems and applications) up to date. Bureaus should also consider the importance of specific controls to the security of a system. Controls that are crucial to the protection of a system should be considered for selection as part of the testing requirement. These are not necessarily the same as highly volatile controls and may or may not be POA&M items.XXXX
CA-2_T.042For new SA&A and re-certifications, the testing accomplished in the SA&A would meet the annual FISMA testing requirement.XXXX
CA-2_T.054When testing of a security control reveals that the control is not functioning as expected, and corrective action has been taken to mitigate the weakness, the finding and corrective action should be documented within the testing documentation. In this case, it would not be entered into the POA&M.XXXX
CA-2(1)CA-2(1)_N.00SECURITY ASSESSMENTS | INDEPENDENT ASSESSORS
The organization employs assessors or assessment teams with [Bureau-defined level of independence] to conduct security control assessments.XXX
CA-2(2)CA-2(2)_N.00SECURITY ASSESSMENTS | SPECIALIZED ASSESSMENTS
The organization includes as part of security control assessments, [annual], [announced], [penetration testing and other [Bureau-defined other forms of security assessment (e.g. in-depth monitoring; vulnerability scanning; malicious user testing; insider threat assessment; performance/load testing)]X
CA-3CA-3_N.00SYSTEM INTERCONNECTIONS

Control: The organization:

a. Authorizes connections from the information system to other information systems through the use of Interconnection Security Agreements;XXXX
CA-3_N.01b. Documents, for each interconnection, the interface characteristics, security requirements, and the nature of the information communicated ; andXXXX
CA-3_N.02c. Reviews and updates Interconnection Security Agreements [Bureau-defined frequency].XXXX

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .