5_EESOH-MIS.pdf

PDF 487 KB Posted

Attached to
Base Operations Support Services, Avon Park AFR, Florida Federal contract opportunity
Solicitation number
FA4814-16-R-0004
Issued by
Department of the Air Force Air Mobility Command

About this file

5 EESOH-MIS

View the file

Other files for this federal contract opportunity

Other files attached to Base Operations Support Services, Avon Park AFR, Florida, newest first.
File Type Posted
3_Appendix_A-5_Target_Maintenance_Historical_Data.pdf PDF
4_Appendix_D_-_Facilities_Systems_Equipment.pdf PDF
7_Pesticide_Product_Summary.pdf PDF
6_Int_Pest_Management_Plan.pdf PDF
2_Appendix_A-Workload.pdf PDF
FA4814-16-R-0004-0003.pdf PDF
9_AF_Real_Property_Report_7115_ASPR.pdf PDF
RFI_Response_Sheet.pdf PDF
1_PWS_30_March_2016.pdf PDF
8_AF_Real_Property_Report_7115_ASPQ.pdf PDF
FA4814-16-R-0004-0002.pdf PDF
FA4814-16-R-0004-0001.pdf PDF
Sign_In_Sheet.pdf PDF
Avon_Park_Request_for_Information.docx DOCX document
Attachment_1_PPQ.pdf PDF
Attachment_2_PPI_Tool_Instructions.pdf PDF
Attachment_3_Past_Performance_Summary_Sheet_(PPSS).pdf PDF
Appendix_E_-_Applicable_Publications.pdf PDF
Appendix_B_-_Maps_and_Site_Plans.pdf PDF
Appendix_A_-_Workload.pdf PDF
Appendix_C_-_GOVERNMENT_FURNISHED_PROPERTY.pdf PDF
FA4814-16-R-0004.pdf PDF
Appendix_H_-_ABBREVIATIONS_and_ACRONYMS.pdf PDF
1_PWS_BOS_Services.pdf PDF
3_Service_Contract_Act_Wage_Determination.pdf PDF
2_QASP_BOS_Avon_Park.pdf PDF
Appendix_D_-_Facilities_Systems_Equip_for_Ops_Maint_Eng.pdf PDF
Appendix_I_-_Minimum_Essential_Level_Vehicles.pdf PDF
Appendix_F_-_Support_Agreements _MOAs_and_Contracts.pdf PDF
4_Davis_Bacon_Wage_Determination.pdf PDF
Appendix_G_-_Contractor_Employee_Certifications.pdf PDF
Appendix_J_-_Forms _Reports _Submittals _and_Technical_Letters.pdf PDF
https //www.fbo.gov/utils/view id 4062ba4be1dfcf0903f51bcf7b0ec97e —
DRAFT Appendix I - Minimum Essential Level Vehicles.pdf PDF
DRAFT Appendix F - Support Agreements MOAs and Contracts.pdf PDF
DRAFT Appendix G - Contractor Employee Certifications.pdf PDF
DRAFT Appendix E - Applicable Publications_Updated.pdf PDF
DRAFT Appendix A - Workload.pdf PDF
DRAFT Appendix H - ABBREVIATIONS and ACRONYMS.pdf PDF
DRAFT Performance Work Statement.pdf PDF
DRAFT Appendix J - Forms Reports Submittals and Technical Letters.pdf PDF
DRAFT Appendix D - Facilities Systems Equip for Ops Maint Eng.pdf PDF
DRAFT Appendix B - Maps and Site Plans.pdf PDF
DRAFT Appendix C - GOVERNMENT FURNISHED PROPERTY.pdf PDF
Show all 44

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Air Force Office of the Civil Engineer

Information Technology Branch

ACCOUNT MANAGEMENT PLAN

ENTERPRISE ENVIRONMENTAL SAFETY AND

OCCUPATIONAL HEALTH - MANAGEMENT

INFORMATION SYSTEM (EESOH-MIS)

Version 2.0

December 2015

Distribution limited to U.S. Government agencies and U.S. DoD contractors only.

Requests for this document must be referred to AFLCMC/HIBD-CE, 201 E. Moore Dr.

Bldg 856, Rm 208D Maxwell AFB - Gunter Annex 36114-3005

Nov 2015 Page ii

This page is intentionally blank

History of Document Changes

Nov 2015 Page iii

Version Publication Date Name Description of Change

1 April 2011 Michael Cylke Published 2 Nov 2015 Multiple Updated for process under

EESOH-MIS Version 2.0.5

Table of Contents

Nov 2015 Page iv

Contents

1.1 Executive Summary

1.2 Account Management Policy Derived Guidance

1.3 Method of Access Control

1.4 Access Restrictions

1.5 EESOH-MIS SAAR Roles and Responsibilities

1.5.1 Users Role and Responsibility

1.5.2 Supervisor Role and Responsibility

1.5.3 Information Assurance Officer (IAO)/Information System Security Officer (ISSO) Role and Responsibility

1.5.4 Security Manager Role and Responsibility

1.5.5 SAAR POC Role and Responsibility

1.5.6 EESOH-MIS Helpdesk Role and Responsibility

1.5.7 EESOH-MIS Functional Management Office (FMO) (Air Force) Roles and Responsibilities

1.5.8 EESOH-MIS Functional Management Office (Army) Roles and Responsibilities

1.6 Assignment of SAAR POCs

1.7 Annual Account Review

1.8 SAAR Retention

1.9. EESOH-MIS Automated User Management

APPENDIX A – EESOH-MIS SAAR INSTRUCTIONS

APPENDIX B – EESOH-MIS RULES OF BEHAVIOR

APPENDIX C – EESOH-MIS ROLES

APPENDIX D – SAAR POC DESIGNATION TEMPLATE

Figure 1 – EESOH-MIS SAAR Routing

Table 1 - References Table 2 – EESOH-MIS Functional Appointee (SAAR POC) Matrix

EESOH-MIS Account Management Policy

Nov 2015 Page 1

1.1 Executive Summary

In accordance with the EESOH-MIS System Security Plan, this policy discusses the requirements for managing user accounts for access to the Enterprise Environmental Safety and Occupational Health Management Information System (EESOH- MIS). The Account Management policy defines the process for creating, managing and disabling user accounts and associated roles and responsibilities. It is essential for all those who use, operate, or manage EESOH-MIS to adhere to the guidance contained in this policy.

1.2 Account Management Policy Derived Guidance

The Account Management policy is derived from the Federal/DoD/Air Force publications listed in Table 1 below and applies to all military, civilians, and DoD contractor personnel, who use, operate, or manage EESOH-MIS. EESOH-MIS accounts are established by the EESOH-MIS Helpdesk (contracted by AFLCMC/HIBD-CE), based on requests from the appropriate Information Owner. The Information Owner is sometimes referred to as the Functional Appointee or the System Authorization Access Request (SAAR) Point of Contact (POC). For the purposes of this document, the term SAAR POC is used. The SAAR POC is responsible for approving access to EESOH-MIS and retains the DD Form 2875, System Authorization Access Request (SAAR) for filing and auditing purposes. Beginning with EESOH-MIS version 2.0.5, the SAAR POC will submit completed and compliant SAARs to the EESOH-MIS Help Desk for upload into EESOH-MIS and EESOH-MIS will be the central storage for SAARs. With version 2.0.5, the SAAR POC is not required to maintain copies locally. Refer to EESOH- MIS SAAR POC Matrix (Table 2) to determine the appropriate SAAR POC.

Publication Title FISCAM Federal Information System Controls Audit Manual (FISCAM) CJCSI 6510.01F Information Assurance (IA) and Computer Network Defense (CND) DoD Instruction 8500.01 Cybersecurity NIST SP 800-53 Rev 4 Security and Privacy Controls for Federal Information Systems and Organizations DoD Instruction 8510.01 Risk Management Framework (RMF) for DoD Information Technology (IT) MPTO 00-33B-5004 Access Control for Information Systems MPTO 00-33B-5006 End Point Security for Information Systems AFI 33-200 Cybersecurity Program Management AFMAN 33-282 Computer Security (COMPUSEC) SAF/CIO A6 Memo Access Controls for Air Force Information Systems

Table 1 - References

1.3 Method of Access Control

EESOH-MIS users are required to obtain a DoD Common Access Card (CAC), for Air Force Portal access before they are able to access EESOH-MIS. Prior to gaining access, the user must complete a DD Form 2875, SAAR to document that he/she has a valid Need-to-Know for the data contained in the information system. Need-to-Know determination is the decision made by an authorized holder of official information that a prospective recipient requires access to specific official information to carry out official duties (reference (i)). Ref: Department of Defense Instruction 8500.01E Cybersecurity. The user’s supervisor is responsible for verifying Need-to-Know and determining access requirements. User access is role-based and restricted based on Need-to-Know and least-privilege principles per installation. The SAAR is coordinated through the user’s management and security channels for approval, then forwarded to the appropriate SAAR POC for approving EESOH-MIS access and subsequent submittal to the EESOH-MIS Help Desk. The type of EESOH-MIS user and their functional area (i.e. HazMat, HazWaste and Clean- Up) determines the appropriate SAAR POC. (Refer to the EESOH-MIS SAAR POC Matrix in Table 2).

Completed SAARs are forwarded to the EESOH-MIS Helpdesk so that the user account can be created

Nov 2015 Page 2 and roles assigned per installation based on the validated SAAR. The EESOH-MIS Helpdesk will verify the SAAR POC signing the form is valid prior to creating new accounts. The EESOH-MIS Helpdesk will notify the SAAR POC and new user once the account is activated. The user can then have access to EESOH-MIS by using their CAC. The account access procedure is summarized in the flowchart (Figure 1).

Improperly completed SAARs or an invalid SAAR POC will be returned to the requestor without action.

The SAAR POC Matrix (Table 2 below) determines the appropriate SAAR POC responsible for approving EESOH-MIS access.

1- Service

2-YOU ARE THIS

TYPE OF USER

3-WANT TO ACCESS

THIS MODULE

4-THIS IS YOUR

SAAR POC

5-SAAR POC

to SAAR POC

HM HW ER CU

AF

Installation User, to include installation level contractors)

X X X Installation

HM/HW/ER SAAR

POC AFCEC FMO SAAR POC

AF

Any user (except ANG) X AFCEC CleanUp

SAAR POC AFCEC FMO SAAR POC

AF All ANG users X ANG CleanUp SAAR

POC

AFCEC CleanUp SAAR

POC

AF

AFCEC Staff, IST/RST and supporting contractors, interface users, and others

X X X

AFCEC FMO SAAR

POC AFCEC FMO SAAR POC

AF

PMO staff and supporting contractors

X X X X

PMO SAAR POC PMO SAAR POC

DLA

All users except Clean Up X X DLA SAAR POC AFCEC FMO SAAR POC

ARMY

Installation User, to include installation level contractors)

X X Installation HM/HW

SAAR POC USACE/EMCX SAAR POC

ARMY

HQ IMCOM and supporting personnel, all others

X X USACE/EMCX SAAR

POC USACE/EMCX SAAR POC

Table 2 – EESOH-MIS Functional Appointee (SAAR POC) Matrix

Nov 2015 Page 3

NOTE: This policy, the EESOH-MIS SAAR template, EESOH-MIS Roles, and Frequently Asked Questions (FAQ), are located on the EESOH-MIS support portal home page (https://www.eesoh-mis.com) to assist new users in completing the DD Form 2875.

Figure 1 – EESOH-MIS SAAR Routing

1.4 Access Restrictions

Within the EESOH-MIS application, accounts are active, disabled, or deleted.

− Active users - allowed access to EESOH-MIS based on installation and assigned roles − Disabled users – account is disabled so that the user cannot access the application. In accordance with AFMAN 33-282, Computer Security (COMPUSEC), all accounts with inactivity exceeding 30 days or personnel on extended TDY and unable to access their accounts, will be disabled. EESOH-MIS will automatically inactivate a user after 30 days of inactivity and includes an exception of 90 days for National Guard and Reserve Members IAW the AF CIO exception. If the user has established an email in their user profile, and automated email reminder will be sent to the user after 20 days of inactivation. The user’s SAAR POC may reactivate a disabled account in EESOH-MIS.

− Deleted users – accounts are no longer available for reactivation or use. EESOH-MIS will automatically inactivate a user after 90 days of inactivity. User accounts are never truly “deleted” from the database, but the word “deleted” is used in the EESOH-MIS application to denote the status of a user that cannot be reactivated. User information is retained in EESOH-MIS to preserve the history of the user along with all environmental transactions for tracking compliance. Examples of circumstances that would call for “deleting” a user account include, but are not limited to: change of duties, termination of job, Permanent Change of Station (PCS), extended TDY, extended inactivity or security violation. Deleted users that require access to EESOH-MIS are required to accomplish a new SAAR and are re-processed as a new user.

The SAAR POC can set disabled accounts to active or may modify a user record in EESOH to establish a future deletion date.

Before transferring to a new installation, users must first notify their appropriate SAAR POC so the account can be deleted. At the gaining location, users will accomplish a new DD Form 2875 and submit it to the appropriate SAAR POC to have a new account activated with the proper roles and installation. The EESOH-MIS Helpdesk can disable or inactivate a user promptly, upon

User prepares

SAAR

Supervisor Approves

SAAR

IAO

Approves

SAAR

SAAR POC

Approves

SAAR

Security Approves

SAAR

Completed

SAAR

These three may flow in a different order depending on location

EESOH- Helpdesk checks SAAR for completeness and validates SAAR

POC, creates new user, and notifies SAAR POC and new user

Nov 2015 Page 4 request, if and when the need arises, e.g. user abuses their access and responsibility for the safeguarding of EESOH-MIS data.

NOTE: The 30 day disable and 90 day deletion functions are done via automated script. If this job fails, it is possible for accounts to show as inactive for 31 or 91 days, respectively, before the next script run.

1.5 EESOH-MIS SAAR Roles and Responsibilities

The following roles and responsibilities are applicable to managing EESOH-MIS accounts. For step by step instructions on completing the DD Form 2875, refer to the supplemental instructions, Frequently Asked Questions (FAQ) and the SAAR POC Matrix located on the EESOH-MIS support portal home page (https://www.eesoh-mis.com).

1.5.1 Users Role and Responsibility.

Each user, in addition to satisfying all rules of behavior and responsibilities that apply to any AF portal user, shall:

1. Protect EESOH-MIS data from any unauthorized personnel without a Need-to-Know for EESOH-MIS information.

2. Read the EESOH-MIS Rules of Behavior. The User signature in Block 11, signifies reading and understanding of the EESOH-MIS Rules of Behavior as stated in block 27.

3. Complete DD Form 2875 Part 1 Blocks 1-12, and 27as required, in accordance with the attached instructions; with the understanding they are responsible and accountable for their access to EESOH-MIS.

4. Coordinate DD Form 2875 through their respective supervisor, Information Assurance Officer (IAO), Security Manager and the appropriate SAAR POC for approved access.

5. Notify the SAAR POC when job changes are required, role changes are required, or access is no longer required (i.e. PCS, termination of job, extended TDY, etc.).

1.5.2 Supervisor Role and Responsibility.

Each supervisor shall:

1. Complete Part 2 Blocks 13-20b and 27as required, on the prospective users’ DD Form

2875 with the understanding they are responsible and accountable for the justification for access and verification of Need-to-Know.

2. Return the DD Form 2875 back to the user for continued coordination to the IAO, security manager, and the appropriate SAAR POC for approved access. Note: the order of routing may vary between installations.

3. Notify the SAAR POC when access is no longer required (i.e. job changes, PCS, termination of job, extended TDY, etc.).1.5.3 Information Assurance Officer (IAO)/Information System Security Officer (ISSO) Role and Responsibility.

1.5.3 The IAO/ISSO shall:

1. Protect EESOH-MIS data from any unauthorized personnel without a Need-to-Know for EESOH-MIS information.

2. Complete Part 2 Blocks 22-25 and 27 on the prospective users’ DD2875 with the understanding that the responsibility and accountability for concurring with system access and verification of Need-to-Know rests with the IAO/ISSO.

3. Return the DD Form 2875 back to the user for continued coordination to the security manager and finally the appropriate SAAR POC for approved access. Note: the order https://www.eesoh-mis.com/

Nov 2015 Page 5 of routing may vary between installations.

1.5.4 Security Manager Role and Responsibility.

The Security Manager validates the background investigation or clearance information of the prospective EESOH-MIS user. Any local security manager with Joint Personnel Adjudication System (JPAS) access to validate background investigation type and date can sign the DD Form 2875. This validation check provides the latest security status at the time of authorized access.

Each Security Manger, in addition to satisfying all rules of behavior and responsibilities that apply to any AF system user, shall:

1. Complete Part 3 Blocks 28-32 on the prospective users’ DD Form 2875 with the understanding they are responsible and accountable for the verified background investigation type and date.

2. Return the DD Form 2875 back to the user for final coordination with the appropriate functional appointee for approved access. Note: the order of routing may vary between installations.

3. Notify the SAAR POC when access needs to be disabled (e.g. security violation).

1.5.5 SAAR POC Role and Responsibility.

The SAAR POC shall:

1. Complete Part 2 Blocks 21-21b on the prospective users’ DD Form 2875 with the understanding they are responsible and accountable for approving access to EESOH-

MIS.

2. Ensure SAAR is properly filled out in accordance with the EESOH-MIS SAAR requirements (Appendix A)and ensure that the requested roles are appropriate for the user assigned tasks and location.

3. Re-enable disabled installation user accounts as required.

4. Enter a Projected end-date in EESOH-MIS for users who no longer require access.

5. Recertify user access on an annual basis (see section 1.7 below for annual recertification requirements).

6. The Primary SAAR POC is responsible to notify the respective FMO SAAR POC when alternate SAAR POCs no longer perform SAAR POC duties.

1.5.6 EESOH-MIS Helpdesk Role and Responsibility.

The EESOH-MIS Helpdesk shall:

1. Upon receiving a compliant SAAR with assigned roles per installation, verify the SAAR

POC is valid for the user and location. Create the user account in EESOH-MIS and notify the SAAR POC and user when action is completed. Return all incomplete or erroneously completed SAARs to the user for correction.

2. Complete user information and load the SAAR into EESOH-MIS.

3. Adjust user accounts to disabled or inactive if/when appropriate, as directed by the appropriate SAAR POC or a security manager.

4. Assign the role of SAAR POC in EESOH-MIS to SAAR POCs as requested by the appropriate Air Force and Army Functional Management Office designee.

1.5.7 EESOH-MIS Air Force (AF) Functional Management Office (FMO) Roles and Responsibilities.

The FMO shall:

1. Maintain and update the SAAR POC Matrix (Table 1). Inform and coordinate with all stakeholders if a change is required, i.e. PMO, Security, Helpdesk.

2. Approve and maintain the Air Force SAAR POC roles in EESOH-MIS. Inform the

Nov 2015 Page 6

Help Desk via digitally signed email or other correspondence of valid SAAR POCs.

Retain SAAR POC designation letters as long as the role is active in EESOH-MIS.

3. Perform a monthly quality assurance check on a random selection of user SAARs and either take the appropriate corrective action or notify the SAAR POC of a non-compliant SAAR requiring corrective action. Users found with non-compliant SAARs are given 10 business days to correct the SAAR or the Helpdesk will be notified to disable the user due to a non-compliant SAAR. The validated SAARs will be annotated on a log maintained on the EESOH-MIS SharePoint Site.

1.5.8 EESOH-MIS Army Functional Management Office Roles and Responsibilities.

The FMO shall:

1. Approve and maintain the Army SAAR POCs roles in EESOH-MIS. Inform the Help

Desk via digitally signed email or other correspondence of valid SAAR POCs. Retain SAAR POC designation letters as long as the role is active in EESOH-MIS.

2. Perform a monthly quality assurance check on a random selection of user SAARs and either take the appropriate corrective action or notify the SAAR POC of a non-compliant SAAR requiring corrective action. Users found with non-compliant SAARs may be given 10 business days to correct the SAAR or the Helpdesk will be notified to disable the user due to a non-compliant SAAR. The SAARs validated will be annotated on a log maintained on the EESOH-MIS SharePoint Site.

1.6 Assignment of SAAR POCs

1. SAAR POCs will be designated in writing by the unit commander using the template at Appendix D). New designation letters are required for POC changes. Digitally signed emails are acceptable.

2. Installations must have one primary and may designate alternates.

3. Designation letters will be forwarded to the respective FMOs (AF: AFCEC/FMO, Army: USACE/EMCX).

1.7 Annual Account Recertification

Validation of user access is a continuous process in EESOH-MIS. Users are automatically disabled after 30 days of non-access. Users are automatically “deleted” after 90 days in a disabled status. Users in the National Guard, Reserves, or on an extended TDY may set this status in their user profile which will extend the disabled status to 120 days. Users found to erroneously set their status to National Guard, Reserves or extended TDY will be deleted.

The SAAR POC will conduct an annual review to recertify user access. The review must be completed within 30 days of review requirements. EESOH-MIS will provide reports of users requiring annual recertification each month. Annual reviews must be recorded in EESOH-MIS for each user to satisfy audit requirements. The annual review will consist of the following actions:

1. Review EESOH-MIS reports for users requiring annual review.

2. Verify the user’s job requires continued access and assigned roles to EESOH-MIS as stated on their SAAR. This may be accomplished in a variety of methods as long as the SAAR POC annotates the EESOH-MIS user record in EESOH-MIS on the method and date that the verification occurred to demonstrate compliance. The annotation in EESOH-MIS by the SAAR POC certifies the recertification occurred. Verification methods may include:

- User contacted via telecon

- User contacted via email or other written communication

Nov 2015 Page 7

3. Disabled users should be deleted as soon as it is determined the user no longer requires access to EESOH-MIS, i.e. change of jobs, PCS, retirement, etc.

4. If the user will no longer require access to EESOH-MIS, enter a projected end date and reason into the User record. EESOH-MIS will delete the user on the projected end date or the next day if the end date is the same day. If the user roles require adjustment, send a digitally signed email to the EESOH Helpdesk for modification of roles.

1.8 SAAR Retention.

SAARs shall be maintained in EESOH-MIS for one year, in accordance with Record Management requirements, after a user status becomes “deleted” in EESOH-MIS.

1.9. EESOH-MIS Automated User Management.

EESOH-MIS performs several automated tasks to assist with user management.

1. Sends email to users after 20 days of inactivity.

2. Disables users after 30 days of inactivity.

3. Deletes users after 90 days of inactivity.

4. Ensures roles assigned to user profile match roles in system. Prohibits the assignment of a role not in the user profile.

5. Identifies authorized SAAR POCs.

Note: Any automated EESOH-MIS action may be delayed due to a system failure to run a nightly routine or system down time.

APPENDIX A – EESOH-MIS SAAR Instructions

Nov 2015 Page 8

APPENDIX A – EESOH-MIS SAAR INSTRUCTIONS

Responsible Party Field Instructions Type of Request Check One User User ID enter the user Portal ID User Date Enter today’s date User System Name EESOH-MIS User Location GCSS-AF

PART I: ENDORSEMENT OF ACCESS BY INFORMATION OWNER, USER

SUPERVISOR OR GOVT SPONSOR

User (1) Name The last name, first name, and middle initial of the user

User (2) Organization The user's current organization (i.e. Air Force, Army, DLA, Navy, DoD, etc.) and government agency or commercial firm)

User (3) Office Symbol/Department

The office symbol within the current organization (i.e. SDI)

User (4) Telephone Number/DSN

The Defense Switching Network (DSN) phone number of the user. If DSN is unavailable, indicate commercial number

User (5)Official E-mail Address The user's official e-mail address User (6) Job Title/Grade/Rank The civilian job title (Example: Systems

Analyst, GS-14, Pay Clerk, GS-5)/military rank (COL, United States Army, CMSgt, USAF) or "Contractor" if user is a contractor

User (7) Official Mailing Address

The user's official mailing address

User (8) Citizenship Check one User (9) Designation of Person Check one User (10) IA Training and

Awareness Certification Requirements

User must check that he/she has completed the Annual Information Awareness Training and the date. Note: Date must have a minimum of 30 days prior to expiration

User (11) User's Signature User must DIGITALLY sign the DD Form 2875 with the understanding that they are responsible and accountable for their password and access to the system(s) and compliance with the "EESOH-MIS Rules of Behavior” (ROB).

User (12) Date The date user signs the form. Date may be blank if on digital signature

PART II: ENDORSEMENT OF ACCESS BY INFORMATION OWNER, USER

SUPERVISOR OR GOVT SPONSOR

Nov 2015 Page 9

Responsible Party Field Instructions Supervisor (13) Justification for

Access A brief statement is required to justify establishment of an initial USER ID. Provide appropriate information if the USER ID or access to the current USER ID is modified.

List the module(s) required. Note: The Cleanup Module request must be a separate

SAAR.

Example Justification Statement: “EESOH- MIS access required to perform the task of [insert description of job supporting access to EESOH] in accordance with the specified roles in block 27. Access to the following module(s) is required: [list modules]. Provide any other justification as needed.”

The EESOH-MIS modules are Hazmat, Hazwaste, Environmental Reporting and Cleanup.

SUPERVISOR (14) Type of Access Required

Place an "X" in the appropriate box.

(Authorized - Individual with normal access.

Privileged - Those with privilege to amend or change system configuration, parameters, or settings.)

SUPERVISOR (15) User Requires Access To

Place an "X" in UNCLASSIFIED

SUPERVISOR (16) Verification of Need to Know

Check to verify that the user requires access as requested

SUPERVISOR (16a) Expiration Date for Access

The user must specify expiration date if less than 1 year. CONTRACTORS must enter the Period of Performance (POP) expiration date, Contract number and Company Name

SUPERVISOR (17) Supervisor's Name (Print Name)

The supervisor or representative prints his/her name to indicate that the above information has been verified and that access is required

SUPERVISOR (18) Supervisor's Signature Supervisor's DIGITAL signature is required by the endorser or his/her representative.

The COR must sign for CONTRACTORS

SUPERVISOR (19) Date Date supervisor signs the form. Date may be blank if on digital signature

SUPERVISOR (20) Supervisor's Organization/Department

Supervisor's organization and department

SUPERVISOR (20a) E-mail Address Supervisor's e-mail address SUPERVISOR (20b) Phone Number Supervisor's telephone number SAAR POC (21) Signature of DIGITAL signature of the functional

Nov 2015 Page 10

Responsible Party Field Instructions Information Owner/OPR appointee responsible for approving access to the system being requested. THIS IS YOUR

DESIGNATED EESOH-MIS SAAR POC

as noted on the SAAR Matrix in Table 2

SAAR POC (21a) Phone Number Functional appointee (SAAR POC) telephone number

SAAR POC (21b) Date The date the functional appointee signs the DD Form 2875. Date may be blank if on digital signature

IAO (22) Signature of Information Assurance Officer (IAO) or Appointee.

DIGITAL signature of the IAO or Appointee of the office responsible for approving access to the system being requested

IAO (23)

Organization/Department

IAO's organization and department

IAO (24) Phone Number IAO's telephone number IAO (25) Date The date IAO signs the DD Form 2875. May be blank if date on digital signature.

USER (26) Name The last name, first name, and middle initial of the user

USER,

SUPERVISOR,

SAAR POC

(27) Optional Information

This item is intended to add additional information, as required.

Insert the following statement:

“Rules of Behavior (ROB): The ROB is a set of rules that describe the IA operations of the DoD information system and clearly delineate those IA responsibilities and expected behavior standards for all personnel are in place. Signed acknowledgement is verified by user signing block 11 of this form.

Supervisor signature in Block 18 verifies roles assigned are least privileged based on “Need to Know” and commensurate with duty function.”

Access Roles: List the roles required by the user.

Note: The supervisor uses this section to indicate specific access roles per installation required by the user from the roles spreadsheet for EESOH-MIS.

Users' access is restricted to "least privilege" based on role and "Need-to-Know" commensurate with their duty function. Installation and role selection may require discussion with the EESOH-MIS SAAR POC and/or the EESOH-MIS Installation administrator to ensure the correct roles per installation are selected. Refer to “EESOH-MIS Roles” spreadsheet attached and located at the

Nov 2015 Page 11

Responsible Party Field Instructions EESOH-MIS support portal (https://www.eesoh-mis.com/index.php) for specifics about each role.

Installation Requiring Access: List the installation(s) where the user requires access.

Justification for more than one installation: Explain role/job of user requiring more than one installation

C. PART III. CERTIFICATION OF BACKGROUND INVESTIGATION OR Clearance SECURITY (28) Type of Investigation The user's last type of background investigation (i.e., NAC, NACI, or SSBI) SECURITY (28a) Date of

Investigation Date of last investigation

SECURITY (28b) Clearance Level The user's current security clearance level (Secret or Top Secret)

SECURITY (28c) IT Level Designation

The user's IT designation (Level I, Level II, or Level III)

SECURITY (29) Verified By The Security Manager or representative prints his/her name to indicate that the above clearance and investigation information has been verified

SECURITY (30) Security Manager Telephone Number

The telephone number of the Security Manager or his/her representative

SECURITY (31) Security Manager Signature

The DIGITAL signature of the Security Manager or his/her representative indicates that the above clearance and investigation information has been verified

SECURITY (32) Date The date that the form was signed by the Security Manager or his/her representative.

Date may be blank if on digital signature

D. PART IV: leave blank

APPENDIX B – EESOH-MIS Rules of Behavior

Nov 2015 Page 12

APPENDIX B – EESOH-MIS RULES OF BEHAVIOR

1.0 Introduction

In accordance with (IAW) the Office of Management and Budget (OMB) Circular Number A-130, Appendix III, Security of Federal Automated Information Resources “ establish a set of rules of behavior concerning use of, security in, and the acceptable level of risk for, the system. The rules shall be based on the needs of the various users of the system. The security required by the rules shall be only as stringent as necessary to provide adequate security for information in the system. Such rules shall clearly delineate responsibilities and expected behavior of all individuals with access to the system. They shall also include appropriate limits on interconnections to other systems and shall define service provision and restoration priorities. Finally, they shall be clear about the consequences of behavior not consistent with the rules.”

2.0 Applicability

All users shall follow the rules set forth in the EESOH-MIS System Security Policy (SSP). They must also sign a DD Form 2875 as a System Authorization Access Request (SAAR) and User Acknowledgement, to confirm that each user has read and acknowledges these System Rules of Behavior, and understands the consequences of not being in compliance with them. These rules extend to all the EESOH-MIS software, developmental and operational entities, development contractor[s] and subscribers, and to all personnel developing, operating, administering, or sustaining interfacing systems. All EESOH-MIS users must be fully aware of, and abide by, the EESOH-MIS security policies as well as related Federal, DoD, and Air Force directives.

WARNING

Failure to follow the appropriate EESOH-MIS security guidance can result in administrative (e.g., loss of network or computer access for specific periods of time) or legal actions (e.g., court martial action for military personnel or prosecution in federal court for civilian personnel) for violators.

3.0 Purpose and Responsibilities

The purpose of this document is to ensure that EESOH-MIS has established rules of behavior concerning:

₋ The use of the system ₋ The security of the system.

₋ The acceptable level of risk for the system.

"Rules of Behavior" refer to the actions that ordinary operators and administrators must take to ensure the security of EESOH-MIS. These actions are specified in detail in the EESOH-MIS System Security Policy (SSP). The EESOH-MIS SSP supports Information Systems Security (ISS) personnel who are responsible for the continuous maintenance of information security. They prescribe detailed procedures that must be carried out by administrators and operators to ensure the secure operation of EESOH-MIS. Specifically, EESOH-MIS personnel must use the system for the mission for which it was designed. The following documents outline the EESOH-MIS system Rules of Behavior. These guidelines will help you fulfill security-related responsibilities as you use EESOH-MIS to perform official duties. For additional details, please see:

₋ AFI 33-200 – Air Force Cybersecurity Program Management ₋ AFMAN 33-282 – Computer Security (COMPUSEC) ₋ EESOH-MIS System Security Policy (SSP)

Nov 2015 Page 13

4.0 Information Sensitivity

EESOH-MIS has been determined to contain no For Official Use Only (FOUO) data. However, access to EESOH-MIS information will be limited only to those with valid need for such access in order to perform a legitimate organizational function. A prospective EESOH-MIS user is required to obtain a DoD Local Area Network (LAN) account and DoD PKI Common Access Card (CAC), along with subsequent access to the GCSS-AF controlled Air Force Portal as a pre-requisite for EESOH-MIS access. The user must then complete a SAAR DD Form 2875, to document that he/she has a valid Need-to-Know for the information contained in the information system before access to the application is granted. Security is everyone's responsibility. Everyone must read, understand, and abide by these rules. If you have doubt about what to do, seek assistance from security personnel.

5.0 General Rules of Behavior

All users must:

a. Log out every time they leave their workplaces.

b. Protect government resources from physical disaster as well as natural, human, and other physical threats.

c. Control entry to the facility. Positively identify anyone attempting access to the workstation. Verify their need-to-know and authorization to use the workstation for official business.

d. Secure resources that process or handle EESOH-MIS data and provide adequate protection during and after duty hours.

e. Know how to fulfill the Contingency Plan roles and responsibilities.

f. Report all suspected or known compromise incidents to their local information security manager.

6.0 Establishing an EESOH-MIS Account:

Referencing EESOH-MIS Account Management Policy, a prospective EESOH-MIS user is required to obtain a DoD Local Area Network (LAN) account and DoD Common Access Card (CAC), along with subsequent access to the Air Force Portal as a pre-requisite for EESOH-MIS access. The user must then complete a SAAR DD Form 2875, to document that he/she has a valid Need-to-Know for the information contained in the information system before access is granted. Need-to-Know determination is the decision made by an authorized holder of official information that a prospective recipient requires access to specific official information to carry out official duties (reference (i)). Ref: Department of Defense Directive 8500, Cybersecurity. The user’s supervisor is responsible for verifying Need-to-Know and determining access requirements. User access is role-based and restricted based on Need-to-Know and least-privilege principles per installation. The DD Form 2875 is coordinated through the user’s management and security channels for approval and then forwarded to the appropriate functional appointee for approving EESOH-MIS access and retained for filing and auditing purposes. The type of EESOH-MIS user and their functional area (i.e. HazMat, HazWaste and Clean-Up) determines the appropriate functional appointee (Refer to the EESOH-MIS Functional Appointee Matrix in the EESOH-MIS Account Management Policy). After the appropriate functional appointee validates the DD Form 2875, he/she notifies the EESOH-MIS Helpdesk, by uploading the SAAR and user data to the AFCEC SharePoint site at

Nov 2015 Page 14 https://afcec-portal.lackland.af.mil/sites/Helpdesk/eesoh_saars/Forms/AllItems.aspx.0F

1 The EESOH-MIS accounts are established by the EESOH-MIS Helpdesk. The EESOH-MIS Helpdesk will notify the functional appointee once the account is activated, who will in turn notify the prospective user. The user can then log into their EESOH-MIS account using their CAC.

7.0 Common Access Card Use and Protection

During your log-on to EESOH-MIS, you must use a properly prepared DoD CAC with the PIN.

DoD CACs also provide the ability to add digital signatures and provide encryption through the use of Public Key Infrastructure (PKI). Both features reinforce the concept of non-repudiation;

that is, the assurance that an activity or event can be positively traced to the individual responsible for that activity or event. All personnel must remember that their DoD CACs are also their identification cards, and are used for gaining entry to facilities. The DoD CAC issuing authority issues CACs and PINs, not the system Program Office (PO) or the GCSS-AF System Administrators (SA). All users are responsible for the proper use and protection of the DoD CACs and PINs issued to them. Users must, at a minimum, safeguard CACs as "For Official Use Only" according to these rules:

₋ Protect PINs at the unclassified sensitive level, committing them to memory--never write them down.

₋ Destroy media containing PINs associated with the CACs in accordance with unclassified sensitive handling instructions.

₋ Never share CACs/PINs, even in an emergency.

₋ Never use personal information or commonly used sequences of numbers to construct

PINs.

₋ Report any suspected or actual compromise of CACs/PINs.

₋ Never leave CACs unattended in CAC readers while logged on.

₋ Retain CACs in their personal possession at all times when not logged on at their workstations.

₋ Report lost, misplaced, or stolen CACs to their supervisors and security.

8.0 Client Workstation Protection

All users, within the limits of practicality and commensurate with the judgment of the EESOH- MIS AO, must protect EESOH-MIS workstations. Refer to AFI 33-200, Cybersecurity Program Management, for more details.

a. Never leave a workstation unprotected while "logged-on."

b. Enable the system’s password-protected screensaver or employ physical measures.

c. Challenge any individual that cannot be positively identified and verify the individual's authorized status.

d. Each machine must have the most current and approved anti-virus software to detect or remove malicious software viruses--especially from diskettes received from another location. If virus-scanning tools are not present or not configured properly, on your computer, contact your SA immediately

1 Note: previous policy required a “digitally signed” e-mail, so that the user account can be created and roles assigned per installation based on the validated DD Form 2875. The digitally signed e-mail ensures the request is from a “verified” functional appointee through non-repudiation.

https://afcec-portal.lackland.af.mil/sites/Helpdesk/eesoh_saars/Forms/AllItems.aspx

Nov 2015 Page 15

9 Security Personnel AFI 33-200 describes the overall responsibilities and roles for the security staff. Know who these security people are and seek their assistance when needed.

a. System Administrator The GCSS-AF System Administrators (SA) assigned to support the EESOH-MIS application within the GCSS-AF enclave are the focal point for all technical matters concerning EESOH-MIS within the GCSS-AF enclave. GCSS-AF SA security-related duties include, but are not limited to, security checks; disk and file maintenance;

performance data collection; and security audit trail management and monitoring. The GCSS-AF SA also enforces DoD CAC PKI access control through GCSS-AF enclave to the EESOH-MIS application, and coordinates security policies and requirements with program management.

b. Information System Security Manager (ISSM) The ISSM is the single point of contact for coordinating security activities between the EESOH-MIS user and the various internal and external organizations. In addition, the ISSM conducts security training (or coordinates the presentation of security training). The ISSM shall also oversee all C&A processes relating to EESOH-MIS. The ISSM will develop and maintain EESOH-MIS Cybersecurity program and security documentation.

The ISSM will ensure that incidents are reported to the AO, and will notify the AO of any impacts to the security posture of EESOH-MIS.

c. Client Support Administrator (CSA) The installation CSA is the first person to contact when workstation-related problems (not EESOH-MIS-supported application software problems) occur. If the CSA is unable to correct the problem, the CSA will up channel for assistance.

d. Functional Users Functional users are individuals who log onto EESOH-MIS application through the GCSS- AF controlled AF Portal with a DoD CAC to perform their mission-related duties. As a functional user, you must comply with security policies and these System Rules of Behavior.

10 Software Rules Never load or execute privately-owned software on the GCSS-AF servers hosting the EESOH- MIS application. This prohibition includes personally-written or locally developed software. Use only software approved and provided by GCSS-AF. Users who deviate from these rules may invalidate this security certification and accreditation and/or have sanctions imposed.

Nov 2015 Page 16

11 EESOH-MIS Security Rules and Procedures Data Aggregation - Data aggregation occurs when separate pieces of data at one sensitivity level (e.g., sensitive) combine to form an aggregated data set whose sensitivity exceeds the sensitivity of any of its constituent pieces. When you request information, be fully aware of the potential for data aggregation. Limit the viewing of information that would result in data aggregation.

Based on DoDM5200.01, Information Security Program, all EESOH-MIS data is not exempt from release to the public under Freedom of Information Act (FOIA). However, EESOH-MIS has been determined to contain no For Official Use Only (FOUO) data. There is no specific marking or labeling authorized for the designation of EESOH-MIS information as determined by the Mission Owner. Access to the information shall be limited only to those with valid need for such access in order to perform a legitimate organizational function, as dictated by common-sense principles of security management.

Use EESOH-MIS for official duty purposes only. Be aware that the system routinely and silently records the actions you take in its Security Audit Trail. You can be held accountable for unauthorized use. Other important rules are:

a. Use only those functions you need to perform your duties -- do not "experiment"!

b. Be alert for unexpected output. Verify that you obtain only those reports you intended to produce, and no more. If you get an unexpected report, take the following actions:

i. Double-check your work – you may have inadvertently requested the report.

ii. If the situation persists, contact the CSA or EESOH-MIS Helpdesk for assistance or guidance.

12 Marking, Handling, and Storing Rules EESOH-MIS has been determined to contain no For Official Use Only (FOUO) data. There is no specific marking or labeling authorized for the designation of EESOH-MIS information as determined by the Mission Owner. As a user, you are responsible to protect EESOH-MIS data from any unauthorized personnel without a Need-to- Know for EESOH-MIS information.

Appendix C - EESOH-MIS Roles List

Nov 2015 Page 17

APPENDIX C – EESOH-MIS ROLES

Module EESOH-MIS Role Role Use Business Role

Restriction System

Restriction

Hazmat Hazmart

Operators of Hazmat Tracking Activities (HTAs)/HAZMARTs responsible for the tracking, receiving, issuing, and storage of Hazmats.

Personnel operating Hazmat Tracking Activities

None

Hazmat Shop USER Shop personnel requiring access to EESOH.

Role can initiate process authorization and material request.

As needed

Hazmat Hazwaste

Shop Supervisor

Supervisor and alternate for a shop using Hazmat and/or generates Hazwaste.

Shop supervisors and their alternate

Hazmat HMMP Responsible for the installation hazardous material management. Typically the Installation Hazardous Material Manager.

One primary and two alternates per installation.

Hazmat Environmental Functional

An environmental functional will review environmental related issues in the system such as Process Authorizations.

Only Environmental Office personnel

Hazmat Occupational Health Functional

An occupational health functional that will review occupational health related issues in the system.

Highly restricted to personnel in the Bioenvironmental function

Hazmat Safety Functional

A safety functional that will review safety related issues in the system.

Only personnel in the Safety function

Hazmat Functional Unit Environmental Coordinators (UECs), optional reviewer or notification of process authorization

UECs, Fire Department, other reviewers

Hazmat Hazmat Administrator

Responsible for modifying the Hazmat related pick lists.

Restricted to

AFCEC/FMO

AFCEC/FMO,

PMO GROUP

Hazmat Hazmart Inventory Administrator

Hazmart Manager responsible for updating Hazmat inventory records in EESOH (installation-wide and historical data)

Restricted to one primary and one alternate per installation if required.

None

Hazmat Inventory Administrator

Responsible for updating Hazmat inventory records in EESOH.

Highly Restricted.

Role approved by

AFCEC/FMO

Assign by System SAAR

POC

Hazmat Shelf Life Manager

Responsible for updating inventory expiration dates at a system level

Restricted to

AFCEC/FMO FMO ONLY

Shared Interface Admin

Responsible for interface management such as APIMS and DRMS.

One primary and one alternate per Interface system

Nov 2015 Page 18

Module EESOH-MIS Role Role Use Business Role

Restriction System

Restriction

Hazmat MDR Approver

Installation level approver for Disposition Requests. This is an optional role for each installation and the requirement must also be established in installation preferences.

One primary and one alternate per installation

Hazwaste Hazwaste Administrator

Responsible for the setup of the Hazwaste functions in the shared areas for the installation, including the Hazwaste related pick list.

One primary and one alternate per installation

Enterprise Reports

Allows for system-wide report roll-ups. AFCEC and PMO only None

Hazwaste Hazwaste Site Manager

Allows for site stream setup and profile modification and approval limited to specific sites.

As needed None

Hazwaste Hazwaste Container Initiator

Allows site level container initiation. As needed None

Hazwaste Hazwaste Associate Manager

Same as the Hazwaste Manager with the exception of approvals and transmission to

DRMO.

Hazwaste managers None

Hazwaste Hazwaste Manager

Responsible for installation Hazwaste program. Includes approvals and transmission to DRMO.

Hazwaste manager responsible for DRMS transactions

Hazwaste Hazwaste View Only View only to Hazwaste module. As needed None

Shared Organization Steward Organization data steward.

One primary and one alternate per installation

NONE

Shared Personnel Steward Personnel data steward.

One primary and one alternate per installation

None

Cleanup Air Staff Administrator

Responsible for managing the funding for MAJCOMs and Organizations/Programs.

Access to create and manage projects at the Air Staff level, view projects at the MAJCOM and Installation level, and view site information for Installations.

Approved by Air Staff

– 12/28 – change this to Restricted to Data Group SAAR POC

CLEANUP

GROUP

Cleanup Cleanup Administrator Manages pick list for Cleanup options.

Restricted to Data Group leadership– 12/28 – change this to Restricted to Data Group SAAR POC

CLEANUP

GROUP

Cleanup MAJCOM Creates and manages projects at a MAJCOM level. Responsible for validating installation level MTS projects. The Air

Limited to MAJCOM

ANG

CLEANUP

GROUP

Nov 2015 Page 19

Module EESOH-MIS Role Role Use Business Role

Restriction System

Restriction

National Guard (ANG) MAJCOM role is responsible for validating all of the ANG installation level projects and sites

Cleanup R-PMO Data Group

(Restoration Program Management Office Data Group) The R-PMO is responsible for installations associated to the R-PMO, under the ERA program with the exception of the Air National Guard. Role can update the Amounts fields that would normally be updateable at the MAJCOM level with the exception of the MAJCOM Review field

Approved by Data Group SAAR POC

CLEANUP

GROUP

Cleanup

R-PMO

Program Manager

The Restoration Program Management Office Program Manager R-PMO is responsible for installations associated to the R-PMO, under the ERA program with the exception of the Air National Guard.

Role can also edit the Project Information tab for R-PMO associated Installations. The R-PMO Program Manager will only be able to update a limited number of Amounts fields that would typically be updated at the MAJCOM level. The MAJCOM Review field can only be updated by the R-PMO Program Manager

Approved by Data Group SAAR POC

CLEANUP

GROUP

Cleanup Cleanup User Installation USER responsible for creating and managing sites and installation level projects

Approved by Data Group SAAR POC

CLEANUP

GROUP

Cleanup Cleanup User View Only

View-only to the cleanup media, and those shared areas that the cleanup USER requires

Approved by Data Group SAAR POC

CLEANUP

GROUP

Cleanup Chief Financial Officer (CFO)

CFO view only access to the same projects as the R-PMO roles. Can access and the search the same criteria as the R-PMO data group

Approved by Data Group SAAR POC

CLEANUP

GROUP

Environmental Quality

Environmental Quality (EQ) User View Only

View-only access to the cleanup media and shared areas

Approved by AFCEC EQ Data Group SAAR

POC

EQ GROUP

Environmental Quality EQ User Installation User responsible for creating installation level projects

Approved by AFCEC EQ Data Group SAAR

POC

EQ GROUP

Environmental Quality EQ MAJCOM Creates and manages projects at an EQ

MAJCOM level

Approved by AFCEC EQ Data Group SAAR

POC

EQ GROUP

Environmental Quality EQ CFO

CFO view only accesses to the same projects as the EQ data group roles. Can access and the search the same criteria as

Approved by AFCEC EQ Data Group SAAR

EQ GROUP

Nov 2015 Page 20

Module EESOH-MIS Role Role Use Business Role

Restriction System

Restriction the EQ data group POC

Environmental Quality

EQ Program Manager

EQ PM responsible for installations associated to the PM, under the ENV program. The EQ PM is able create installation level projects and update a limited number of Amounts fields

Approved by AFCEC EQ Data Group SAAR

POC

EQ GROUP

Environmental Quality EQ Data Group

EQ PM responsible for installations associated to the EQ module, under the ENV program. Roles can create, edit, and delete sites and projects

Approved by AFCEC EQ Data Group SAAR

POC

EQ GROUP

Environmental Reporting ER Admin

AFCEC administrator responsible for managing Data Call process. This includes creating, editing and modifying Data Call templates and Data Calls

Restricted to

AFCEC/CZCA AFCEC GROUP

Environmental Reporting ER SME

AFCEC Subject Matter Expert (SME) responsible for validating and QA/QC the data entered by the Base-level ER USER and ER Reviewer Responsible for reviewing the submitted data call and either accepting or rejecting the data call from the ER USER and ER Reviewer

Approved by AFCEC ER Program Manager AFCEC GROUP

Environmental Reporting ER USER

The USER responsible for entering the data for a specific Base. The same person may be responsible for all Media, or each Media may have a designated contact or any combination (per business policy)

As needed None

Environmental Reporting ER Reviewer

The AFCEC RST/IST/ANG/AFRC (previously MAJCOM) responsible for reviewing and validating data by ER USER only. Capable of entering data on behalf of a specific base

RST/IST or ANG/AFRC MAJCOM level personnel.

AFCEC, RST,

IST

*Shared Read Only Read only As needed – only accesses hazmat and shared

None

Shared Enterprise Contract Manager

Allows the creation and modification of enterprise-level contracts. PMO and AFCEC only None

Shared Installation Admin

Responsible for setting up Installation preferences and the administration of centralized functions such as workflow.

Gatekeeper for EESOH-MIS access at the…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .