Exhibit 011 -TD P 85-01.xlsx
XLSX spreadsheet 344 KB Posted
- Attached to
- Cash PAK System Federal contract opportunity
- Solicitation number
- 2031ZA23R00015
About this file
This is a solicitation for a Cash PAK System. The Department of the Treasury Bureau of Engraving and Printing is seeking a solution to automate the packaging of currency. Vendors must be able to design, build, install, and maintain a fully automated system capable of counting and securely wrapping stacks of currency at high speeds with integrated quality control. Proposals are due by January 15, 2023 with award anticipated by March 31, 2023. The contract will have a one year base period and four one-year options. The solicitation includes detailed technical requirements for throughput, accuracy, security features and maintenance support.
View the file
Other files for this federal contract opportunity
Show all 22
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Instructions
| Instructions for Appendix A: Minimum Standard Parameters |
| This appendix contains minimum parameters as determined by the Department for NIST SP 800-53 security controls that have an organization assignment, as well as Treasury-specific requirements. Treasury requirements are mapped to the NIST controls to which they most closely relate. For reference purposes, some NIST controls that do not require a parameter to be defined are also included. Appendix A is not a comprehensive list of baseline security requirements. The following information explains the structure of the appendix along with instructions for its use in developing a tailored security control baseline. |
| 1. NIST Control Number (column 1) |
| a. Control names and numbers are from NIST SP 800-53. |
| 2. Reference Number (column 2) |
| a. Part one of the reference number is the NIST control number (e.g. AC-1). |
| b. Part two is the source of the requirement. |
| i. ‘N’ is for NIST. |
| ii. ‘T’ is for Treasury. |
| c. Part three identifies each discrete requirement of a control. |
| i. NIST sourced controls are assigned a two-digit value beginning with 00 for each requirement within a control (e.g. AC-2 includes a.-k.; therefore its numeric |
values are 00-14). The numbers reset to 00 for every NIST control.
| ii. Treasury sourced requirements are assigned a three-digit value, beginning at 001, and increment continuously throughout the appendix. |
| 3. The Control or Requirement (column 3) |
| a. Bureaus shall ensure that parameters marked ‘[bureau-defined]’ are established and documented. Bureau-defined parameters provide the capability to tailor |
security controls and control enhancements based on:
| i. security requirements to support organizational missions/business functions and operational needs; |
| ii. risk assessments and organizational risk tolerance; and |
| iii. security requirements originating in federal laws, Executive Orders, directives, policy (including Treasury policy), regulations, standards, and/or guidelines. |
| b. Where a ‘[Selection:]’ value is not assigned, bureaus may assign their own. |
| c. Bureaus shall designate each control as common, system-specific, or hybrid controls. |
| 4. The Baseline (columns 4, 5, 6) |
| a. L=Low, M=Moderate, H=High |
| i. Controls or requirements marked with an ‘X’ in the L, M, or H columns means they are part of that baseline. |
| ii. A ‘P’ in the "Baseline" columns means that the control is a program-level control. These controls are: |
| 1. deployed organization-wide; |
| 2. supporting information security programs; |
| 3. not associated with security control baselines; and |
| 4. independent of any system impact level. |
| iii. “X” in the “C” column (column 7) means that the control is a Cyber Critical Infrastructure Protection control. These controls are applied to information |
systems designated as Cyber Critical Infrastructure Assets by the Departmental CIO.
Implementation of the Critical Infrastructure System Control Overlay
Information systems designated as Cyber Critical Infrastructure Assets shall implement the security controls designated by an “X” in the “C” column of Appendix A:
| 1) The “Critical Infrastructure Control Overlay” shall be applied to all components within the designated Cyber Critical Infrastructure Asset systems security boundary. |
| a. GUIDANCE: Information systems normally consist of components (servers, routers, batch processing routines, mainframes, etc.) that when combined allow the |
overall system to perform its intended function. The intent is to increase the trustworthiness and resiliency of the overall system by applying the control overlay to all the components of the designated system, where applicable. It is understood that security controls are applicable only to information system components that provide or support the capability addressed by the controls. Please document the implementation accordingly.
| 2) The controls in the Cyber Critical Infrastructure Overlay may be tailored per the “Tailoring Baseline Security Controls” policy in the following section. |
| a. If the Authorizing Official, in coordination with the system and organizational officials, determines that a control in the Overlay shall not be implemented (also |
referred to as “tailoring-out”) on a designated Cyber Critical Infrastructure Asset, the associated documentation for this risk-based decision not to implement shall be submitted to the Department Cyber CIP Program Manager and the Departmental CISO for review.
Tailoring Baseline Security Controls
Step two of the RMF is the selection of an applicable security control baseline based on the results of the security categorization and the application of tailoring guidance. Per NIST SP 800-53 Revision 4, the use of the term baseline is intentional. The security controls and control enhancements in the baselines are a starting point from which control/enhancements can be removed, added, or specialized based on the tailoring guidance in Section 3.2.
The tailoring process, as an integral part of security control selection and specification, is part of a comprehensive organizational risk management process—framing, assessing, responding to, and monitoring information security risk. Bureaus shall use risk management guidance to facilitate risk-based decision making regarding the applicability of security controls in the security control baselines. Bureaus shall consider the tailoring process to achieve cost-effective, risk-based security that supports organizational mission/business needs. Tailoring activities are approved by authorizing officials in coordination with selected organizational officials (e.g., Risk Executive [function], CIOs, CISOs, Information System Owners, or common control providers) prior to implementing the security controls.
Conversely, bureaus shall not remove security controls for operational convenience. Tailoring decisions regarding security controls should be defensible based on mission/business needs and accompanied by explicit risk-based determinations. Tailoring decisions, including the specific rationale for those decisions, are documented in the security plans for information systems. Every security control from the applicable security control baseline is accounted for either by the organization (e.g., common control provider) or by the system owner. If certain security controls are tailored out, compensating security controls are selected if needed, and the associated rationale is recorded in security plans (or references/pointers to other relevant documentation are provided) for the information systems and approved by the AO and other responsible officials as part of the security plan approval process.
Documenting significant risk management decisions in the security control selection process is imperative in order for AOs to have the necessary information to make credible, risk-based decisions with regard to the authorization of information systems. Since information systems, environments of operation, and personnel associated with the system development life cycle are subject to change, providing the assumptions, constraints, and rationale supporting those important risk decisions allows for a better understanding in the future of the security state of the information systems or environments of operation at the time the original risk decisions were made and facilitates identifying changes, when previous risk decisions are revisited.
The tailoring guidance previously described may only be applied to NIST baseline controls. Implementation of Treasury requirements in Appendix A (i.e., those with a ‘T’ in the Reference number) is mandatory. Bureaus may choose to tailor Treasury requirements if supported by risk assessment by selecting compensating controls only under the following conditions:
| 1) Compensating controls must be selected from NIST SP 800-53, TD P 85-01 Appendix A, or a bureau documented control, when applicable; |
| 2) Bureaus must provide a documented complete and convincing rationale and justification for how the compensating control provides an equivalent security |
capability to the AO with a copy to the Bureau CISO for review; and
3) Use of approved compensating controls must be recorded in security plans.
Exceptions to Treasury Requirements
Bureau-wide exceptions to Treasury requirements shall be managed differently than information system tailoring. Documentation of exception requests to Treasury requirements must include operational justification, risk acceptance, and risk mitigation measures. Such requests must be submitted to and approved by the Bureau CIO, in consultation with the Bureau CISO. An approved exception must be signed by the individuals in these roles and held by the bureau, with a copy submitted to the Department CIO via the Department CISO for review.
Appendix A Instructions
Appendix A + CIP2
| Controls | Requirements | TD P 85-01 Appendix A | L | M | H | CIP |
| Cyber CIP Overlay Control Count (When Control and Cip Filter set): | ||||||
| 306 | 764 | Baseline Control Count: | 504 | 664 | 743 | 303 |
| Baseline | Overlay | |||||
| NIST CONTROL # | REFERENCE # | REQUIREMENT | L | M | H | CIP |
| AC-1 | AC-1_N.00 | ACCESS CONTROL POLICY AND PROCEDURES |
The organization:
a. Develops, documents, and disseminates to [Bureau-defined personnel or roles]:
| 1. An access control policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and | X | X | X | |||
| AC-1_N.01 | 2. Procedures to facilitate the implementation of the access control policy and associated access controls; and | X | X | X | ||
| AC-1_N.02 | b. Reviews and updates the current: | |||||
| 1. Access control policy [at least every three years or if there is a significant change]; and | X | X | X | |||
| AC-1_N.03 | 2. Access control procedures [at least every three years or if there is a significant change]. | X | X | X | ||
| AC-2 | AC-2_N.00 | ACCOUNT MANAGEMENT |
Control: The organization:
a. Identifies and selects the following types of information system accounts to support organizational missions/business functions: [Bureau-defined information system account types];
| (see b-e in 800-53 rev 4) | X | X | X | X | |||
| AC-2_N.01 | b. Assigns account managers for information system accounts; | X | X | X | X | ||
| AC-2_N.02 | c. Establishes conditions for group and role membership; | X | X | X | X | ||
| AC-2_N.03 | d. Specifies authorized users of the information system, group and role membership, and access authorizations (i.e., privileges) and other attributes (as required) for each account; | X | X | X | X | ||
| AC-2_N.04 | e. Requires approvals by [Bureau-defined personnel or roles] for requests to create information system accounts; | X | X | X | X | ||
| AC-2_N.05 | f. Creates, enables, modifies, disables, and removes information system accounts in accordance with [Bureau-defined procedures or conditions]; | ||||||
| (see g, h, I in 800-53 rev 4) | X | X | X | X | |||
| AC-2_N.06 | g. Monitors the use of information system accounts; | X | X | X | X | ||
| AC-2_N.07 | h. Notifies account managers: | ||||||
| 1. When accounts are no longer required; | X | X | X | X | |||
| AC-2_N.08 | 2. When users are terminated or transferred; and | X | X | X | X | ||
| AC-2_N.09 | 3. When individual information system usage or need-to-know changes; | X | X | X | X | ||
| AC-2_N.10 | i. Authorizes access to the information system based on: | ||||||
| 1. A valid access authorization; | X | X | X | X | |||
| AC-2_N.11 | 2. Intended system usage; and | X | X | X | X | ||
| AC-2_N.12 | 3. Other attributes as required by the organization or associated missions/business functions; | X | X | X | X | ||
| AC-2_N.13 | j. Reviews accounts for compliance with account management requirements [of users annually; privileged users semi-annually]; and | X | X | X | X | ||
| AC-2_N.14 | k. Establishes a process for reissuing shared/group account credentials (if deployed) when individuals are removed from the group. | X | X | X | X | ||
| AC-2(2) | AC-2(2)_N.00 | ACCOUNT MANAGEMENT | REMOVAL OF TEMPORARY / EMERGENCY ACCOUNTS | |||||
| The information system automatically [Selection: removes; disables] temporary and emergency accounts after [no longer than two business days]. | X | X | |||||
| AC-2(3) | AC-2(3)_N.00 | ACCOUNT MANAGEMENT | DISABLE INACTIVE ACCOUNTS | |||||
| The information system automatically disables inactive accounts after [120 days (Public users can be determined by the Bureau)]. | X | X | |||||
| AC-2(4) | AC-2(4)_N.00 | ACCOUNT MANAGEMENT | AUTOMATED AUDIT ACTIONS | |||||
| The information system automatically audits account creation, modification, enabling, disabling, and removal actions, and notifies [Bureau-defined personnel or roles]. | X | X | |||||
| AC-2(5) | AC-2(5)_N.00 | ACCOUNT MANAGEMENT | INACTIVITY LOGOUT | |||||
| The organization requires that users log out when [Bureau-defined time period of expected inactivity or description of when to log out] | X | ||||||
| AC-2(11) | AC-2(11)_N.00 | ACCOUNT MANAGEMENT | USAGE CONDITIONS | |||||
| The information system enforces [Bureau-defined circumstances and/or usage conditions] for [Bureau-defined information system accounts]. | X | ||||||
| AC-2(12) | AC-2(12)_N.00 | ACCOUNT MANAGEMENT | ACCOUNT MONITORING / ATYPICAL USAGE |
The organization:
| (a) Monitors information system accounts for [Bureau-defined atypical use]; and | X | ||||
| AC-2(12)_N.01 | (b) Reports atypical usage of information system accounts to [Bureau-defined personnel or roles]. | X | |||
| AC-2(13) | AC-2(13)_N.00 | ACCOUNT MANAGEMENT | DISABLE ACCOUNTS FOR HIGH-RISK INDIVIDUALS | |||
| The organization disables accounts of users posing a significant risk within [Bureau-defined, but not greater than one business day time period] of discovery of the risk. | X | ||||
| AC-3 | AC-3_N.00 | ACCESS ENFORCEMENT | |||
| Control: The information system enforces approved authorizations for logical access to information and system resources in accordance with applicable access control policies. | X | X | X | X | |
| AC-3_T.002 | Users having accounts with administrators access privileges on Treasury systems may access those accounts only from Treasury government or authorized government contractor systems. |
INFORMATIVE: In other words, a key intent is to prohibit personally-owned or public kiosk (e.g., library) systems from being used for remote Administrator access.
| INFORMATIVE: If individuals with administrator rights require e-mail or Internet access beyond local boundaries, one alternative would be to issue separate, non-privileged accounts (one per affected individual) for that purpose. For the considerations of this section, administrator accounts/rights are those that allow for the installation or configuration of software on any Treasury asset. | X | X | X | X |
| AC-4 | AC-4_N.00 | INFORMATION FLOW ENFORCEMENT | ||
| Control: The information system enforces approved authorizations for controlling the flow of information within the system and between interconnected systems based on [applicable policies, agreements, contracts and/or procedures]. | X | X | X | |
| AC-5 | AC-5_N.00 | SEPARATION OF DUTIES |
Control: The organization:
| a. Separates [Bureau-defined duties of individuals]; | X | X | ||
| AC-6 | AC-6_N.00 | LEAST PRIVILEGE | ||
| Control: The organization employs the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with organizational missions and business functions. | X | X | X | |
| AC-6_T.003 | Accounts with administrative privileges (including local administrator rights) shall be prohibited from web browsing and other Internet connections outside of the local protected boundary (usually Treasury) unless such risk is accepted in writing by the Bureau CIO. |
INFORMATIVE: If individuals with administrator rights require e-mail or Internet access beyond local boundaries, one alternative would be to issue separate, non-privileged accounts (one per affected individual) for that purpose. For the considerations of this section, administrator accounts/rights are those that allow for the installation or configuration of software on any Treasury asset.
| X | X | X |
| AC-6_T.004 | Accounts with administrative privileges (including local administrator rights) shall be blocked from access to e-mail unless such risk is accepted in writing by the Bureau CIO. |
| INFORMATIVE: If individuals with administrator rights require e-mail or Internet access beyond local boundaries, one alternative would be to issue separate, non-privileged accounts (one per affected individual) for that purpose. For the considerations of this section, administrator accounts/rights are those that allow for the installation or configuration of software on any Treasury asset. | X | X | X | |
| AC-6(1) | AC-6(1)_N.00 | LEAST PRIVILEGE | AUTHORIZE ACCESS TO SECURITY FUNCTIONS | ||
| The organization explicitly authorizes access to [Bureau-defined security functions (deployed in hardware, software, and firmware) and security-relevant information]. | X | X | ||
| AC-6(2) | AC-6(2)_N.00 | LEAST PRIVILEGE | NON-PRIVILEGED ACCESS FOR NONSECURITY FUNCTIONS | ||
| The organization requires that users of information system accounts, or roles, with access to [security functions including but are not limited to: establishing system accounts, configuring access authorizations (i.e., permissions, privileges), setting events to be audited, and setting intrusion detection parameters], use non-privileged accounts or roles, when accessing nonsecurity functions. | X | X | ||
| AC-6(3) | AC-6(3)_N.00 | LEAST PRIVILEGE | NETWORK ACCESS TO PRIVILEGED COMMANDS | ||
| The organization authorizes network access to [Bureau-defined privileged commands] only for [Bureau-defined compelling operational needs] and documents the rationale for such access in the security plan for the information system. | X | X | ||
| AC-6(5) | AC-6(5)_N.00 | LEAST PRIVILEGE | PRIVILEGED ACCOUNTS | ||
| The organization restricts privileged accounts on the information system to [Bureau-defined personnel or roles]. | X | X | ||
| AC-6(6) | AC-6(6)_N.00 | LEAST PRIVILEGE | PRIVILEGED ACCESS BY NON-ORGANIZATIONAL USERS | ||
| The organization prohibits privileged access to the information system by non-organizational users. | X | |||
| AC-7 | AC-7_N.00 | UNSUCCESSFUL LOGON ATTEMPTS |
Control: The information system:
| a. Enforces a limit of [three] consecutive invalid logon attempts by a user during a [120 minute period; and | X | X | X | |||
| AC-7_N.01 | b. (LOW, MODERATE) Automatically [locks the account/node for 15 minutes or until released by an administrator] when the maximum number of unsuccessful attempts is exceeded. | X | X | |||
| AC-7_N.01 | b.(HIGH) Automatically [locks the account/node until released by an administrator] when the maximum number of unsuccessful attempts is exceeded. | X | ||||
| AC-8 | AC-8_N.00 | SYSTEM USE NOTIFICATION |
Control: The information system:
a. Displays to users [Bureau-defined system use notification message or banner] before granting access to the system that provides privacy and security notices consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance and states that:
1. Users are accessing a U.S. Government information system;
| (see 2-4, and b. in 80-53 rev 4) | X | X | X |
| AC-8_N.05 | c. For publicly accessible systems: | ||
| 1. Displays system use information [Bureau-defined conditions], before granting further access; | X | X | X |
| AC-10 | AC-10_N.00 | CONCURRENT SESSION CONTROL | |
| Control: The information system limits the number of concurrent sessions for each [Bureau-defined account and/or account type] to [one for non-privileged users and three for privileged users]. | X | ||
| AC-11 | AC-11_N.00 | SESSION LOCK |
Control: The information system:
| a. Prevents further access to the system by initiating a session lock after [30 minutes or less] of inactivity or upon receiving a request from a user; and | X | X | |
| AC-12 | AC-12_N.00 | SESSION TERMINATION | |
| Control: The information system automatically terminates a user session after [Bureau-defined conditions or trigger events requiring session disconnect]. | X | X | |
| AC-14 | AC-14_N.00 | PERMITTED ACTIONS WITHOUT IDENTIFICATION OR AUTHENTICATION |
Control: The organization:
| a. Identifies [Bureau-defined user actions] that can be performed on the information system without identification or authentication consistent with organizational missions/business functions; and | X | X | X |
| AC-17 | AC-17_N.00 | REMOTE ACCESS |
Control: The organization:
| a. Establishes and documents usage restrictions, configuration/connection requirements, and implementation guidance for each type of remote access allowed; and | X | X | X | |||
| AC-17_N.01 | b. Authorizes remote access to the information system prior to allowing such connections. | X | X | X | ||
| AC-17_T.006 | Two-factor authentication shall be implemented for all remote access back to a Departmental system. |
INFORMATIVE: "Remote access" is defined as LAN-like access to a Treasury system from a location or facility not controlled by a Treasury organization. Access to websites and other systems available to the public, as well as access to non-Treasury or publicly available information, is not considered "remote access."
| Examples: If a Treasury employee works at home on a personally-owned computer using public or non-Treasury information, that would not entail “remote access.” If a State of Rhode Island employee has been granted access to a Treasury system and that employee accesses the Treasury system from a State of Rhode Island facility, it would be considered “remote access.” A Treasury employee using a Treasury laptop without connectivity back to a Treasury system for an audit at a firm in a commercial office building would not be considered “remote access.” | X | X | X |
| AC-17(2) | AC-17(2)_N.00 | REMOTE ACCESS | PROTECTION OF CONFIDENTIALITY / INTEGRITY USING ENCRYPTION | |
| The information system implements cryptographic mechanisms to protect the confidentiality and integrity of remote access sessions. | X | X | |
| AC-17(2)_T.206 | Remote Access Security. Remote access sessions to Treasury IT assets (e.g., networks, systems) shall only be provided through an encryption mechanism such as a virtual private network (VPN) connection that meets FIPS 140 validation requirements. |
| INFORMATIVE: This control does not apply to sessions used for the dissemination of non-sensitive information to the public. | X | X | X |
| AC-17(3) | AC-17(3)_N.00 | REMOTE ACCESS | MANAGED ACCESS CONTROL POINTS | |
| The information system routes all remote accesses through [Bureau-defined number] managed network access control points. | X | X | |
| AC-17(4) | AC-17(4)_N.00 | REMOTE ACCESS | PRIVILEGED COMMANDS / ACCESS |
The organization:
| (a) Authorizes the execution of privileged commands and access to security-relevant information via remote access only for [Bureau-defined needs]; and | X | X | |
| AC-18 | AC-18_N.00 | WIRELESS ACCESS |
Control: The organization:
| a. Establishes usage restrictions, configuration/connection requirements, and implementation guidance for wireless access; and | X | X | X | |||
| AC-18_N.01 | b. Authorizes wireless access to the information system prior to allowing such connections. | X | X | X | ||
| AC-18_T.246 | Treasury bureaus shall coordinate with the Treasury Office of Intelligence and Analysis to establish a wireless program to protect National Security Systems (NSS) when unclassified wireless technologies are used to transmit, receive, process, or store unclassified data in the proximity of Treasury NSS or National Security Information (NSI). |
| INFORMATIVE: This control also applies to any/all guest wireless networks. | X | X | X | |||
| AC-18_T.247 | Guest wireless networks operated by or on behalf of Treasury in Treasury facilities shall be completely logically separate from all Treasury networks. | X | X | X | ||
| AC-18(3)_T.008 | Bureaus shall ensure that unapproved wireless networking capabilities of desktops, laptops, printers, copiers, fax machines, SCADA systems, and other devices are disabled (through automated means, where technically possible) and monitored through automated means for unauthorized changes. |
| INFORMATIVE: One alternative yet acceptable approach to “monitoring through automated means” is regularly pushing out settings that restrict unapproved wireless connections. | X | X | X | |||
| AC-18_T.009 | Bureaus shall monitor for unauthorized wireless access to the information system and enforce requirements for wireless connections to the information system. | X | X | X | ||
| AC-18_T.010 | Implementation and use of wireless networks must be approved by the Authorizing Official in accordance with organizational risk tolerance and commensurate with the security categorization of the data to be carried by the system, which may be no higher than the security categorization of the system | X | X | X | ||
| AC-18_T.012 | Bureaus shall scan for rogue wireless access points and other wireless activity that are not in compliance with Departmental policy. | X | X | X | ||
| AC-18(1) | AC-18(1)_N.00 | WIRELESS ACCESS | AUTHENTICATION AND ENCRYPTION | ||||
| The information system protects wireless access to the system using authentication of [Selection (one or more): users; devices] and encryption. | X | X | ||||
| AC-18(3) | AC-18(3)_N.00 | WIRELESS ACCESS | DISABLE WIRELESS NETWORKING | ||||
| The organization disables, when not intended for use, wireless networking capabilities internally embedded within information system components prior to issuance and deployment. | X | X | X | |||
| AC-18(3)_T.011 | Bureaus shall employ security mechanisms for wireless networks consistent with the sensitivity of the information to be transmitted. For transmissions of FIPS 199 MODERATE or HIGH confidentiality information, FIPS 140-2 validated encryption must be employed. | X | X | |||
| AC-19 | AC-19_N.00 | ACCESS CONTROL FOR MOBILE DEVICES |
Control: The organization:
| a. Establishes usage restrictions, configuration requirements, connection requirements, and implementation guidance for organization-controlled mobile devices; and | X | X | X | |||
| AC-19_N.01 | b. Authorizes and monitors the connection of mobile devices to organizational information systems. | X | X | X | ||
| AC-19_T.016 | Bureaus shall ensure that all Treasury information on all mobile devices is encrypted using FIPS 140-2 (or succeeding guidance) validated encryption technology, except when no such encryption technology solutions are available to address a specific device. | X | X | X | ||
| AC-19_T.018 | The bureau CISO or designee must give written approval before an individual within the office may take a government-owned laptop computer and/or other mobile devices overseas. | P | P | P | ||
| AC-19_T.019 | Bureau deployment of government-owned mobile devices to process, store, or transmit Treasury information must be approved by the Authorizing Official in accordance with organizational risk tolerance and commensurate with the security categorization of the data to be processed, stored, or transmitted, which may be no higher than the security categorization of the devices. | X | X | X | ||
| AC-19_T.020 | Mobile devices taken outside the U.S. (whether for official or personal travel) may not connect wirelessly to a Treasury system unless sanitized. |
INFORMATIVE: Excluded is this situation of transiting another country provided the device remains under the immediate control of the user.
| INFORMATIVE: It is permissible simply to prohibit non-wireless mobile device connections entirely. | X | X | X | |||
| AC-19_T.021 | This control addresses laptop computers that are temporarily taken overseas. All laptops temporarily taken overseas must be protected by: 1) full disk FIPS validated encryption; 2) disabling any wireless capability; and 3) either disabling all USB ports(s) or use of tamper-evident bags/seals/containers each time the laptop is left unattended (i.e., not under the direct and immediate control of a U.S. Government employee or authorized government contractor). If any laptop is not protected as described above, it may not be reconnected to a Treasury system or network until sanitized. | X | X | X | ||
| AC-19_T.022 | Laptops and other devices containing Treasury information categorized as High or Moderate (confidentiality) under FIPS 199 shall not be connected to networks while outside the U.S., unless employing a separate hard drive or a secure partition (physical or virtual) with a separate operating system instance that contains no High or Moderate Treasury information. | X | X | |||
| AC-19_T.023 | Hard drives or partitions that connect to networks while outside the U.S. shall not be connected to Treasury networks at any time. | X | X | X | ||
| AC-19_T.024 | During overseas travel, batteries shall be removed from battery-powered mobile devices and stored separate from the device when the device is left unattended. The battery also shall be removed if the device is within auditable range of sensitive conversations while overseas. |
| INFORMATIVE: This control applies to any mobile device where removable of the battery is possible | X | X | X |
| AC-19_T.025 | During overseas travel, SIM cards shall be removed and stored separate from devices that employ them when going through non-U.S. customs. |
| INFORMATIVE: This control applies to any mobile device where removal of the battery is possible | X | X | X | |||
| AC-19_T.026 | Bureaus shall provide users with procedures to follow during foreign travel when a device is taken out of their possession and view for other than routine airport security scans. | p | p | p | ||
| AC-19(5) | AC-19(5)_N.00 | ACCESS CONTROL FOR MOBILE DEVICES | FULL DEVICE / CONTAINER-BASED ENCRYPTION | ||||
| The organization employs [Selection: full-device encryption; container encryption] to protect the confidentiality and integrity of information on [Bureau-defined mobile devices]. | X | X | ||||
| AC-20(1) | AC-20(1)_N.00 | USE OF EXTERNAL INFORMATION SYSTEMS | LIMITS ON AUTHORIZED USE |
The organization permits authorized individuals to use an external information system to access the information system or to process, store, or transmit organization-controlled information only when the organization:
| (a) Verifies the implementation of required security controls on the external system as specified in the organization’s information security policy and security plan; or | X | X | |||
| AC-20(1)_N.01 | (b) Retains approved information system connection or processing agreements with the organizational entity hosting the external information system. | X | X | ||
| AC-20(2) | AC-20(2)_N.00 | USE OF EXTERNAL INFORMATION SYSTEMS | PORTABLE STORAGE DEVICES | |||
| The organization [Selection: restricts; prohibits] the use of organization-controlled portable storage devices by authorized individuals on external information systems. | X | X | |||
| AC-20(3) | AC-20(3)_N.00 | USE OF EXTERNAL INFORMATION SYSTEMS | NON-ORGANIZATIONALLY OWNED SYSTEMS / COMPONENTS / DEVICES | |||
| The organization [prohibits] the use of non-organizationally owned information systems, system components, or devices to process, store, or transmit organizational [FIPS 199 High] information. | X | ||||
| AC-20(3)_T.028 | Approval by the bureau CISO and AO is required for use of non-government-furnished IT equipment to store, access, process, or transmit Treasury FIPS 199 Low and Moderate information, with the exception that minor amounts of incidental (and no higher than FIPS 199 LOW confidentiality) information, such as phone numbers or an employee's daily schedule, may be permitted by authorization of the employee's supervisor. (This control does not apply to information made available proactively to the general public by the Treasury). |
INFORMATIVE: Government-provided secure virtual environments installed on non-government furnished equipment may be used to access Treasury information, unless prohibited or otherwise restricted by Bureau policy.
| INFORMATIVE: Government-provided secure virtual environments installed on non-government furnished equipment are considered to be the same as government-furnished equipment. | X | X | ||||
| AC-20(3)_T.029 | Bureaus that permit use of non-government furnished IT equipment per control T.028 to process, store, or transmit Treasury information shall establish terms and conditions of each use. The systems and conditions shall address, at a minimum, NIST SP 800-53 Appendix F, Control AC-20 and, when applicable, NIST SP 800-53 Appendix F, Control AC-20, and AC-20(1). | X | X | X | ||
| AC-20(3)_T.030 | Approval by the bureau CISO and AO is required for connection of non-government furnished or contractor-owned IT devices (including USB-connected portable storage and mobile devices) to Treasury systems or networks. (This control does not apply to networks and systems intended for use by the general public) | X | X | X | ||
| AC-21 | AC-21_N.00 | INFORMATION SHARING |
Control: The organization:
| a. Facilitates information sharing by enabling authorized users to determine whether access authorizations assigned to the sharing partner match the access restrictions on the information for [Bureau-defined information sharing circumstances where user discretion is required]; and | X | X | |||
| AC-21_N.01 | b. Employs [Bureau-defined automated mechanisms or manual processes] to assist users in making information sharing/collaboration decisions. | X | X | ||
| AC-22 | AC-22_N.00 | PUBLICLY ACCESSIBLE CONTENT |
Control: The organization:
| a. Designates individuals authorized to post information onto a publicly accessible information system; | X | X | X | |||
| AC-22_N.01 | b. Trains authorized individuals to ensure that publicly accessible information does not contain nonpublic information; | X | X | X | ||
| AC-22_N.02 | c. Reviews the proposed content of information prior to posting onto the publicly accessible information system to ensure that nonpublic information is not included; and | X | X | X | ||
| AC-22_N.03 | d. Reviews the content on the publicly accessible information system for nonpublic information [quarterly] and removes such information, if discovered. | X | X | X | ||
| AT-1 | AT-1_N.00 | SECURITY AWARENESS AND TRAINING POLICY AND PROCEDURES |
Control: The organization:
a. Develops, documents, and disseminates to [Bureau-defined personnel or roles]:
| 1. A security awareness and training policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and | X | X | X | |||
| AT-1_N.01 | 2. Procedures to facilitate the implementation of the security awareness and training policy and associated security awareness and training controls; and | X | X | X | ||
| AT-1_N.02 | b. Reviews and updates the current: | |||||
| 1. Security awareness and training policy [every three years or if there is a significant change]; and | X | X | X | |||
| AT-1_N.03 | 2. Security awareness and training procedures [every three years or if there is a significant change]. | X | X | X | ||
| AT-2 | AT-2_N.00 | SECURITY AWARENESS TRAINING |
Control: The organization provides basic security awareness training to information system users (including managers, senior executives, and contractors):
| a. As part of initial training for new users [within 5 business days of being granted access to a Treasury information system (Informative: Bureaus may fulfill this requirement for users’ first 60 days by having them review and accept the rules of behavior)]; | X | X | X | |||
| AT-2_N.01 | b. When required by information system changes; and | X | X | X | ||
| AT-2_N.02 | c. [annually] thereafter. | X | X | X | ||
| AT-2_T.034 | Bureaus shall train users and provide means to ensure workstations are adequately protected from theft -- particularly in regard to laptops acting as workstations. | X | X | X | ||
| AT-2_T.035 | At least once per quarter, Bureaus shall distribute security awareness reminders/updates to all users. |
| INFORMATIVE: This is in addition to annual awareness training. Security awareness updates may be sent via e-mail. Unlike the need to track annual training by individual, Bureaus are not required to track quarterly awareness updates by individual. | P | P | P | |||
| AT-2_T.249 | At least once per quarter, Bureaus shall conduct phishing email simulation exercises. | P | P | P | ||
| AT-2_T.250 | Bureaus shall notify the Treasury Government Security Operations Center (GSOC) prior to executing any phishing email simulation exercise. | P | P | P | ||
| AT-3 | AT-3_N.00 | ROLE-BASED SECURITY TRAINING |
Control: The organization provides role-based security training to personnel with assigned security roles and responsibilities:
| a. Before authorizing access to the information system or performing assigned duties; | X | X | X | |||
| AT-3_N.01 | b. When required by information system changes; and | X | X | X | ||
| AT-3_N.02 | c. [annually (see Appendix H for roles that require specialized training)] thereafter. | X | X | X | ||
| AT-4 | AT-4_N.00 | SECURITY TRAINING RECORDS |
Control: The organization:
| a. Documents and monitors individual information system security training activities including basic security awareness training and specific information system security training; and | X | X | X | |||
| AT-4_N.01 | b. Retains individual training records for [at least five years]. | X | X | X | ||
| AU-1 | AU-1_N.00 | AUDIT AND ACCOUNTABILITY POLICY AND PROCEDURES |
Control: The organization:
a. Develops, documents, and disseminates to [Bureau-defined personnel or roles]:
| 1. An audit and accountability policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and | X | X | X | |||
| AU-1_N.01 | 2. Procedures to facilitate the implementation of the audit and accountability policy and associated audit and accountability controls; and | X | X | X | ||
| AU-1_N.02 | b. Reviews and updates the current: | |||||
| 1. Audit and accountability policy [every three years or if there is a significant change ]; and | X | X | X | |||
| AU-1_N.03 | 2. Audit and accountability procedures [every three years or if there is a significant change]. | X | X | X | ||
| AU-2 | AU-2_N.00 | AUDIT EVENTS |
Control: The organization:
| a. Determines that the information system is capable of auditing the following events: [identity of each user and device accessing or attempting to access an IT system; time and date of the access and the logoff; activities that might modify, bypass, or negate IT security safeguards; security-relevant actions associated with processing; user generation of reports and extracts containing information categorized High or Moderate for confidentiality (to the extent technically feasible); and other Bureau defined events]; | X | X | ||||
| AU-2_N.01 | b. Coordinates the security audit function with other organizational entities requiring audit-related information to enhance mutual support and to help guide the selection of auditable events; | X | X | X | ||
| AU-2_N.02 | c. Provides a rationale for why the auditable events are deemed to be adequate to support after-the-fact investigations of security incidents; and | X | X | X | ||
| AU-2_N.03 | d. Determines that the following events are to be audited within the information system: [user generation of reports and extracts containing information categorized High or Moderate for confidentiality (to the extent technically feasible); and Bureau-defined audited events (the subset of the auditable events defined in AU-2 a.) along with the frequency of (or situation requiring) auditing for each identified event]. | X | X | |||
| AU-2_T.038 | Bureaus shall develop and implement local procedures and/or technical/operational/ administrative controls to ensure that extracts containing FIPS 199 High or Moderate for confidentiality information are erased within 90 days or that continued use is still required. | X | X | |||
| AU-2(3) | AU-2(3)_N.00 | AUDIT EVENTS | REVIEWS AND UPDATES | ||||
| The organization reviews and updates the audited events [every two years]. | X | X | ||||
| AU-3(1) | AU-3(1)_N.00 | CONTENT OF AUDIT RECORDS | ADDITIONAL AUDIT INFORMATION | ||||
| The information system generates audit records containing the following additional information: [details to facilitate the reconstruction of events if unauthorized activity or a malfunction occurs or is suspected]. | X | X | ||||
| AU-3(2) | AU-3(2)_N.00 | CONTENT OF AUDIT RECORDS | CENTRALIZED MANAGEMENT OF PLANNED AUDIT RECORD CONTENT | ||||
| The information system provides centralized management and configuration of the content to be captured in audit records generated by [Bureau-defined information system components]. | X | |||||
| AU-4 | AU-4_N.00 | AUDIT STORAGE CAPACITY | ||||
| Control: The organization allocates audit record storage capacity in accordance with [Bureau-defined audit record storage requirements]. | X | X | X | |||
| AU-5 | AU-5_N.00 | RESPONSE TO AUDIT PROCESSING FAILURES |
Control: The information system:
| a. Alerts [Bureau-defined personnel or roles] in the event of an audit processing failure; and | X | X | X | |||
| AU-5_N.01 | b. Takes the following additional actions: [Bureau-defined actions to be taken (e.g., shut down information system, overwrite oldest audit records, stop generating audit records)]. | X | X | X | ||
| AU-5(1) | AU-5(1)_N.00 | RESPONSE TO AUDIT PROCESSING FAILURES | AUDIT STORAGE CAPACITY | ||||
| The information system provides a warning to [Bureau-defined personnel, roles, and/or locations] within [Bureau-defined time period] when allocated audit record storage volume reaches [Bureau-defined percentage] of repository maximum audit record storage capacity. | X | |||||
| AU-5(2) | AU-5(2)_N.00 | RESPONSE TO AUDIT PROCESSING FAILURES | REAL-TIME ALERTS | ||||
| The information system provides an alert in [Bureau-defined real-time period] to [Bureau-defined personnel, roles, and/or locations] when the following audit failure events occur: [Bureau-defined audit failure events requiring real-time alerts]. | X | |||||
| AU-6 | AU-6_N.00 | AUDIT REVIEW, ANALYSIS, AND REPORTING |
Control: The organization:
| a. Reviews and analyzes information system audit records [at frequency in accordance with a risk based decision and documented in the System Security Plan] for indications of [Bureau-defined inappropriate or unusual activity]; and | X | X | X | X | |||
| AU-6_N.01 | b. Reports findings to [Bureau-defined personnel or roles]. | X | X | X | X | ||
| AU-6(1) | AU-6(1)_N.00 | AUDIT AND ACCOUNTABILITY | PROCESS INTEGRATION | |||||
| The organization employs automated mechanisms to integrate audit review, analysis, and reporting processes to support organizational processes for investigation and response to suspicious activities. | X | X | X | ||||
| AU-6(3) | AU-6(3)_N.00 | AUDIT AND ACCOUNTABILITY | CORRELATE AUDIT REPOSITORIES | |||||
| The organization analyzes and correlates audit records across different repositories to gain organization-wide situational awareness. | X | X | X | ||||
| AU-6(5) | AU-6(5)_N.00 | AUDIT REVIEW, ANALYSIS, AND REPORTING | INTEGRATION / SCANNING AND MONITORING CAPABILITIES | |||||
| The organization integrates analysis of audit records with analysis of [Selection (one or more): vulnerability scanning information; performance data; information system monitoring information; [Bureau-defined data/information collected from other sources]] to further enhance the ability to identify inappropriate or unusual activity. | X | ||||||
| AU-7(1) | AU-7(1)_N.00 | AUDIT REDUCTION AND REPORT GENERATION | AUTOMATIC PROCESSING | |||||
| The information system provides the capability to process audit records for events of interest based on [Bureau-defined audit fields within audit records]. | X | X | |||||
| AU-8 | AU-8_N.00 | TIME STAMPS |
Control: The information system:
| a. Uses internal system clocks to generate time stamps for audit records; and | X | X | X | |||
| AU-8_N.01 | b. Records time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT) and meets [Bureau-defined granularity of time measurement]. | X | X | X | ||
| AU-8(1) | AU-8(1)_N.00 | TIME STAMPS | SYNCHRONIZATION WITH AUTHORITATIVE TIME SOURCE |
The information system:
| (a) Compares the internal information system clocks [at least on a quarterly basis] with [Bureau-defined authoritative time source]; and | X | X | ||||
| AU-8(1)_N.01 | (b) Synchronizes the internal system clocks to the authoritative time source when the time difference is greater than [Bureau-defined time period]. | X | X | |||
| AU-9 | AU-9_N.00 | PROTECTION OF AUDIT INFORMATION | ||||
| The information system protects audit information and audit tools from unauthorized access, modification, and deletion. | X | X | X | X | ||
| AU-9(2) | AU-9(2)_N.00 | PROTECTION OF AUDIT INFORMATION | AUDIT BACKUP ON SEPARATE PHYSICAL SYSTEMS / COMPONENTS | ||||
| The information system backs up audit records [Bureau-defined frequency] onto a physically different system or system component than the system or component being audited. | X | |||||
| AU-9(4) | AU-9(4)_N.00 | PROTECTION OF AUDIT INFORMATION | ACCESS BY SUBSET OF PRIVILEGED USERS | ||||
| The organization authorizes access to management of audit functionality to only [Bureau-defined subset of privileged users]. | X | X | ||||
| AU-10 | AU-10_N.00 | NON-REPUDIATION | ||||
| Control: The information system protects against an individual (or process acting on behalf of an individual) falsely denying having performed [Bureau-defined actions to be covered by non-repudiation]. | X | |||||
| AU-11 | AU-11_N.00 | AUDIT RECORD RETENTION | ||||
| Control: The organization retains audit records for [according to Records Management TD 80-05 and General Counsel] to provide support for after-the-fact investigations of security incidents and to meet regulatory and organizational information retention requirements. | X | X | X | |||
| AU-12 | AU-12_N.00 | AUDIT GENERATION |
Control: The information system:
| a. Provides audit record generation capability for the auditable events defined in AU-2 a. at [Bureau-defined information system components]; | X | X | X | |||
| AU-12_N.01 | b. Allows [Bureau-defined personnel or roles] to select which auditable events are to be audited by specific components of the information system; and | X | X | X | ||
| AU-12(1) | AU-12(1)_N.00 | AUDIT GENERATION | SYSTEM-WIDE / TIME-CORRELATED AUDIT TRAIL | ||||
| The information system compiles audit records from [all components] into a system-wide (logical or physical) audit trail that is time-correlated to within [1 minute of Coordinated Universal Time (UTC) as based upon a recognized time authority (e.g. NIST). Audit records should be stored in UTC format for consistency]. | X | |||||
| AU-12(3) | AU-12(3)_N.00 | AUDIT GENERATION | CHANGES BY AUTHORIZED INDIVIDUALS | ||||
| The information system provides the capability for [Bureau-defined individuals or roles] to change the auditing to be performed on [Bureau-defined information system components] based on [Bureau-defined selectable event criteria] within [Bureau-defined time thresholds]. | X | |||||
| CA-1 | CA-1_N.00 | SECURITY ASSESSMENT AND AUTHORIZATION POLICY AND PROCEDURES |
Control: The organization:
a. Develops, documents, and disseminates to [Bureau-defined personnel or roles]:
| 1. A security assessment and authorization policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and | X | X | X | |||
| CA-1_N.01 | 2. Procedures to facilitate the implementation of the security assessment and authorization policy and associated security assessment and authorization controls; and | X | X | X | ||
| CA-1_N.02 | b. Reviews and updates the current: | |||||
| 1. Security assessment and authorization policy [every three years or if there is a significant change]; and | X | X | X | |||
| CA-1_N.03 | 2. Security assessment and authorization procedures [every three years or if there is a significant change]. | X | X | X | ||
| CA-2 | CA-2_N.00 | SECURITY ASSESSMENTS |
Control: The organization:
a. Develops a security assessment plan that describes the scope of the assessment including:
| 1. Security controls and control enhancements under assessment; | X | X | X | X | |||
| CA-2_N.01 | 2. Assessment procedures to be used to determine security control effectiveness; and | X | X | X | X | ||
| CA-2_N.02 | 3. Assessment environment, assessment team, and assessment roles and responsibilities; | X | X | X | X | ||
| CA-2_N.03 | b. Assesses the security controls in the information system and its environment of operation [at least annually] to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting established security requirements; | X | X | X | X | ||
| CA-2_N.04 | c. Produces a security assessment report that documents the results of the assessment; and | X | X | X | X | ||
| CA-2_N.05 | d. Provides the results of the security control assessment to [Bureau-defined individuals or roles]. | X | X | X | X | ||
| CA-2_T.041 | Priority for selection of controls to be tested should be: 1) those POA&M items completed within the applicable timeframe and 2) high-volatility security controls. |
INFORMATIVE: There is no set number of controls to be tested annually; however, the number of controls should take into account the FIPS 199 security categorization level of the system. Controls selected for testing should not be limited to technical controls, but also include operational and management controls.
| INFORMATIVE: With regard to volatility, by their nature, operational controls require that correct actions be taken by individuals. Due to potential for personnel turnover, degradation in infrequently used skills, and other factors, many operational controls are volatile, which should be taken into account when selecting controls for testing. Additionally, this volatility with regard to individuals also affects access controls, particularly keeping access control lists and permissions (both for general support systems and applications) up to date. Bureaus should also consider the importance of specific controls to the security of a system. Controls that are crucial to the protection of a system should be considered for selection as part of the testing requirement. These are not necessarily the same as highly volatile controls and may or may not be POA&M items. | X | X | X | X | |||
| CA-2_T.042 | For new SA&A and re-certifications, the testing accomplished in the SA&A would meet the annual FISMA testing requirement. | X | X | X | X | ||
| CA-2_T.054 | When testing of a security control reveals that the control is not functioning as expected, and corrective action has been taken to mitigate the weakness, the finding and corrective action should be documented within the testing documentation. In this case, it would not be entered into the POA&M. | X | X | X | X | ||
| CA-2(1) | CA-2(1)_N.00 | SECURITY ASSESSMENTS | INDEPENDENT ASSESSORS | |||||
| The organization employs assessors or assessment teams with [Bureau-defined level of independence] to conduct security control assessments. | X | X | X | ||||
| CA-2(2) | CA-2(2)_N.00 | SECURITY ASSESSMENTS | SPECIALIZED ASSESSMENTS | |||||
| The organization includes as part of security control assessments, [annual], [announced], [penetration testing and other [Bureau-defined other forms of security assessment (e.g. in-depth monitoring; vulnerability scanning; malicious user testing; insider threat assessment; performance/load testing)] | X | ||||||
| CA-3 | CA-3_N.00 | SYSTEM INTERCONNECTIONS |
Control: The organization:
| a. Authorizes connections from the information system to other information systems through the use of Interconnection Security Agreements; | X | X | X | X | |||
| CA-3_N.01 | b. Documents, for each interconnection, the interface characteristics, security requirements, and the nature of the information communicated ; and | X | X | X | X | ||
| CA-3_N.02 | c. Reviews and updates Interconnection Security Agreements [Bureau-defined frequency]. | X | X | X | X |
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .