5_EESOH-MIS.pdf
PDF 487 KB Posted
- Attached to
- Base Operations Support Services, Avon Park AFR, Florida Federal contract opportunity
- Solicitation number
- FA4814-16-R-0004
About this file
5 EESOH-MIS
View the file
Other files for this federal contract opportunity
Show all 44
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Air Force Office of the Civil Engineer
Information Technology Branch
ACCOUNT MANAGEMENT PLAN
ENTERPRISE ENVIRONMENTAL SAFETY AND
OCCUPATIONAL HEALTH - MANAGEMENT
INFORMATION SYSTEM (EESOH-MIS)
Version 2.0
December 2015
Distribution limited to U.S. Government agencies and U.S. DoD contractors only.
Requests for this document must be referred to AFLCMC/HIBD-CE, 201 E. Moore Dr.
Bldg 856, Rm 208D Maxwell AFB - Gunter Annex 36114-3005
Nov 2015 Page ii
This page is intentionally blank
History of Document Changes
Nov 2015 Page iii
Version Publication Date Name Description of Change
1 April 2011 Michael Cylke Published 2 Nov 2015 Multiple Updated for process under
EESOH-MIS Version 2.0.5
Table of Contents
Nov 2015 Page iv
Contents
1.1 Executive Summary
1.2 Account Management Policy Derived Guidance
1.3 Method of Access Control
1.4 Access Restrictions
1.5 EESOH-MIS SAAR Roles and Responsibilities
1.5.1 Users Role and Responsibility
1.5.2 Supervisor Role and Responsibility
1.5.3 Information Assurance Officer (IAO)/Information System Security Officer (ISSO) Role and Responsibility
1.5.4 Security Manager Role and Responsibility
1.5.5 SAAR POC Role and Responsibility
1.5.6 EESOH-MIS Helpdesk Role and Responsibility
1.5.7 EESOH-MIS Functional Management Office (FMO) (Air Force) Roles and Responsibilities
1.5.8 EESOH-MIS Functional Management Office (Army) Roles and Responsibilities
1.6 Assignment of SAAR POCs
1.7 Annual Account Review
1.8 SAAR Retention
1.9. EESOH-MIS Automated User Management
APPENDIX A – EESOH-MIS SAAR INSTRUCTIONS
APPENDIX B – EESOH-MIS RULES OF BEHAVIOR
APPENDIX C – EESOH-MIS ROLES
APPENDIX D – SAAR POC DESIGNATION TEMPLATE
Figure 1 – EESOH-MIS SAAR Routing
Table 1 - References Table 2 – EESOH-MIS Functional Appointee (SAAR POC) Matrix
EESOH-MIS Account Management Policy
Nov 2015 Page 1
1.1 Executive Summary
In accordance with the EESOH-MIS System Security Plan, this policy discusses the requirements for managing user accounts for access to the Enterprise Environmental Safety and Occupational Health Management Information System (EESOH- MIS). The Account Management policy defines the process for creating, managing and disabling user accounts and associated roles and responsibilities. It is essential for all those who use, operate, or manage EESOH-MIS to adhere to the guidance contained in this policy.
1.2 Account Management Policy Derived Guidance
The Account Management policy is derived from the Federal/DoD/Air Force publications listed in Table 1 below and applies to all military, civilians, and DoD contractor personnel, who use, operate, or manage EESOH-MIS. EESOH-MIS accounts are established by the EESOH-MIS Helpdesk (contracted by AFLCMC/HIBD-CE), based on requests from the appropriate Information Owner. The Information Owner is sometimes referred to as the Functional Appointee or the System Authorization Access Request (SAAR) Point of Contact (POC). For the purposes of this document, the term SAAR POC is used. The SAAR POC is responsible for approving access to EESOH-MIS and retains the DD Form 2875, System Authorization Access Request (SAAR) for filing and auditing purposes. Beginning with EESOH-MIS version 2.0.5, the SAAR POC will submit completed and compliant SAARs to the EESOH-MIS Help Desk for upload into EESOH-MIS and EESOH-MIS will be the central storage for SAARs. With version 2.0.5, the SAAR POC is not required to maintain copies locally. Refer to EESOH- MIS SAAR POC Matrix (Table 2) to determine the appropriate SAAR POC.
Publication Title FISCAM Federal Information System Controls Audit Manual (FISCAM) CJCSI 6510.01F Information Assurance (IA) and Computer Network Defense (CND) DoD Instruction 8500.01 Cybersecurity NIST SP 800-53 Rev 4 Security and Privacy Controls for Federal Information Systems and Organizations DoD Instruction 8510.01 Risk Management Framework (RMF) for DoD Information Technology (IT) MPTO 00-33B-5004 Access Control for Information Systems MPTO 00-33B-5006 End Point Security for Information Systems AFI 33-200 Cybersecurity Program Management AFMAN 33-282 Computer Security (COMPUSEC) SAF/CIO A6 Memo Access Controls for Air Force Information Systems
Table 1 - References
1.3 Method of Access Control
EESOH-MIS users are required to obtain a DoD Common Access Card (CAC), for Air Force Portal access before they are able to access EESOH-MIS. Prior to gaining access, the user must complete a DD Form 2875, SAAR to document that he/she has a valid Need-to-Know for the data contained in the information system. Need-to-Know determination is the decision made by an authorized holder of official information that a prospective recipient requires access to specific official information to carry out official duties (reference (i)). Ref: Department of Defense Instruction 8500.01E Cybersecurity. The user’s supervisor is responsible for verifying Need-to-Know and determining access requirements. User access is role-based and restricted based on Need-to-Know and least-privilege principles per installation. The SAAR is coordinated through the user’s management and security channels for approval, then forwarded to the appropriate SAAR POC for approving EESOH-MIS access and subsequent submittal to the EESOH-MIS Help Desk. The type of EESOH-MIS user and their functional area (i.e. HazMat, HazWaste and Clean- Up) determines the appropriate SAAR POC. (Refer to the EESOH-MIS SAAR POC Matrix in Table 2).
Completed SAARs are forwarded to the EESOH-MIS Helpdesk so that the user account can be created
Nov 2015 Page 2 and roles assigned per installation based on the validated SAAR. The EESOH-MIS Helpdesk will verify the SAAR POC signing the form is valid prior to creating new accounts. The EESOH-MIS Helpdesk will notify the SAAR POC and new user once the account is activated. The user can then have access to EESOH-MIS by using their CAC. The account access procedure is summarized in the flowchart (Figure 1).
Improperly completed SAARs or an invalid SAAR POC will be returned to the requestor without action.
The SAAR POC Matrix (Table 2 below) determines the appropriate SAAR POC responsible for approving EESOH-MIS access.
1- Service
2-YOU ARE THIS
TYPE OF USER
3-WANT TO ACCESS
THIS MODULE
4-THIS IS YOUR
SAAR POC
5-SAAR POC
to SAAR POC
HM HW ER CU
AF
Installation User, to include installation level contractors)
X X X Installation
HM/HW/ER SAAR
POC AFCEC FMO SAAR POC
AF
Any user (except ANG) X AFCEC CleanUp
SAAR POC AFCEC FMO SAAR POC
AF All ANG users X ANG CleanUp SAAR
POC
AFCEC CleanUp SAAR
POC
AF
AFCEC Staff, IST/RST and supporting contractors, interface users, and others
X X X
AFCEC FMO SAAR
POC AFCEC FMO SAAR POC
AF
PMO staff and supporting contractors
X X X X
PMO SAAR POC PMO SAAR POC
DLA
All users except Clean Up X X DLA SAAR POC AFCEC FMO SAAR POC
ARMY
Installation User, to include installation level contractors)
X X Installation HM/HW
SAAR POC USACE/EMCX SAAR POC
ARMY
HQ IMCOM and supporting personnel, all others
X X USACE/EMCX SAAR
POC USACE/EMCX SAAR POC
Table 2 – EESOH-MIS Functional Appointee (SAAR POC) Matrix
Nov 2015 Page 3
NOTE: This policy, the EESOH-MIS SAAR template, EESOH-MIS Roles, and Frequently Asked Questions (FAQ), are located on the EESOH-MIS support portal home page (https://www.eesoh-mis.com) to assist new users in completing the DD Form 2875.
Figure 1 – EESOH-MIS SAAR Routing
1.4 Access Restrictions
Within the EESOH-MIS application, accounts are active, disabled, or deleted.
− Active users - allowed access to EESOH-MIS based on installation and assigned roles − Disabled users – account is disabled so that the user cannot access the application. In accordance with AFMAN 33-282, Computer Security (COMPUSEC), all accounts with inactivity exceeding 30 days or personnel on extended TDY and unable to access their accounts, will be disabled. EESOH-MIS will automatically inactivate a user after 30 days of inactivity and includes an exception of 90 days for National Guard and Reserve Members IAW the AF CIO exception. If the user has established an email in their user profile, and automated email reminder will be sent to the user after 20 days of inactivation. The user’s SAAR POC may reactivate a disabled account in EESOH-MIS.
− Deleted users – accounts are no longer available for reactivation or use. EESOH-MIS will automatically inactivate a user after 90 days of inactivity. User accounts are never truly “deleted” from the database, but the word “deleted” is used in the EESOH-MIS application to denote the status of a user that cannot be reactivated. User information is retained in EESOH-MIS to preserve the history of the user along with all environmental transactions for tracking compliance. Examples of circumstances that would call for “deleting” a user account include, but are not limited to: change of duties, termination of job, Permanent Change of Station (PCS), extended TDY, extended inactivity or security violation. Deleted users that require access to EESOH-MIS are required to accomplish a new SAAR and are re-processed as a new user.
The SAAR POC can set disabled accounts to active or may modify a user record in EESOH to establish a future deletion date.
Before transferring to a new installation, users must first notify their appropriate SAAR POC so the account can be deleted. At the gaining location, users will accomplish a new DD Form 2875 and submit it to the appropriate SAAR POC to have a new account activated with the proper roles and installation. The EESOH-MIS Helpdesk can disable or inactivate a user promptly, upon
User prepares
SAAR
Supervisor Approves
SAAR
IAO
Approves
SAAR
SAAR POC
Approves
SAAR
Security Approves
SAAR
Completed
SAAR
These three may flow in a different order depending on location
EESOH- Helpdesk checks SAAR for completeness and validates SAAR
POC, creates new user, and notifies SAAR POC and new user
Nov 2015 Page 4 request, if and when the need arises, e.g. user abuses their access and responsibility for the safeguarding of EESOH-MIS data.
NOTE: The 30 day disable and 90 day deletion functions are done via automated script. If this job fails, it is possible for accounts to show as inactive for 31 or 91 days, respectively, before the next script run.
1.5 EESOH-MIS SAAR Roles and Responsibilities
The following roles and responsibilities are applicable to managing EESOH-MIS accounts. For step by step instructions on completing the DD Form 2875, refer to the supplemental instructions, Frequently Asked Questions (FAQ) and the SAAR POC Matrix located on the EESOH-MIS support portal home page (https://www.eesoh-mis.com).
1.5.1 Users Role and Responsibility.
Each user, in addition to satisfying all rules of behavior and responsibilities that apply to any AF portal user, shall:
1. Protect EESOH-MIS data from any unauthorized personnel without a Need-to-Know for EESOH-MIS information.
2. Read the EESOH-MIS Rules of Behavior. The User signature in Block 11, signifies reading and understanding of the EESOH-MIS Rules of Behavior as stated in block 27.
3. Complete DD Form 2875 Part 1 Blocks 1-12, and 27as required, in accordance with the attached instructions; with the understanding they are responsible and accountable for their access to EESOH-MIS.
4. Coordinate DD Form 2875 through their respective supervisor, Information Assurance Officer (IAO), Security Manager and the appropriate SAAR POC for approved access.
5. Notify the SAAR POC when job changes are required, role changes are required, or access is no longer required (i.e. PCS, termination of job, extended TDY, etc.).
1.5.2 Supervisor Role and Responsibility.
Each supervisor shall:
1. Complete Part 2 Blocks 13-20b and 27as required, on the prospective users’ DD Form
2875 with the understanding they are responsible and accountable for the justification for access and verification of Need-to-Know.
2. Return the DD Form 2875 back to the user for continued coordination to the IAO, security manager, and the appropriate SAAR POC for approved access. Note: the order of routing may vary between installations.
3. Notify the SAAR POC when access is no longer required (i.e. job changes, PCS, termination of job, extended TDY, etc.).1.5.3 Information Assurance Officer (IAO)/Information System Security Officer (ISSO) Role and Responsibility.
1.5.3 The IAO/ISSO shall:
1. Protect EESOH-MIS data from any unauthorized personnel without a Need-to-Know for EESOH-MIS information.
2. Complete Part 2 Blocks 22-25 and 27 on the prospective users’ DD2875 with the understanding that the responsibility and accountability for concurring with system access and verification of Need-to-Know rests with the IAO/ISSO.
3. Return the DD Form 2875 back to the user for continued coordination to the security manager and finally the appropriate SAAR POC for approved access. Note: the order https://www.eesoh-mis.com/
Nov 2015 Page 5 of routing may vary between installations.
1.5.4 Security Manager Role and Responsibility.
The Security Manager validates the background investigation or clearance information of the prospective EESOH-MIS user. Any local security manager with Joint Personnel Adjudication System (JPAS) access to validate background investigation type and date can sign the DD Form 2875. This validation check provides the latest security status at the time of authorized access.
Each Security Manger, in addition to satisfying all rules of behavior and responsibilities that apply to any AF system user, shall:
1. Complete Part 3 Blocks 28-32 on the prospective users’ DD Form 2875 with the understanding they are responsible and accountable for the verified background investigation type and date.
2. Return the DD Form 2875 back to the user for final coordination with the appropriate functional appointee for approved access. Note: the order of routing may vary between installations.
3. Notify the SAAR POC when access needs to be disabled (e.g. security violation).
1.5.5 SAAR POC Role and Responsibility.
The SAAR POC shall:
1. Complete Part 2 Blocks 21-21b on the prospective users’ DD Form 2875 with the understanding they are responsible and accountable for approving access to EESOH-
MIS.
2. Ensure SAAR is properly filled out in accordance with the EESOH-MIS SAAR requirements (Appendix A)and ensure that the requested roles are appropriate for the user assigned tasks and location.
3. Re-enable disabled installation user accounts as required.
4. Enter a Projected end-date in EESOH-MIS for users who no longer require access.
5. Recertify user access on an annual basis (see section 1.7 below for annual recertification requirements).
6. The Primary SAAR POC is responsible to notify the respective FMO SAAR POC when alternate SAAR POCs no longer perform SAAR POC duties.
1.5.6 EESOH-MIS Helpdesk Role and Responsibility.
The EESOH-MIS Helpdesk shall:
1. Upon receiving a compliant SAAR with assigned roles per installation, verify the SAAR
POC is valid for the user and location. Create the user account in EESOH-MIS and notify the SAAR POC and user when action is completed. Return all incomplete or erroneously completed SAARs to the user for correction.
2. Complete user information and load the SAAR into EESOH-MIS.
3. Adjust user accounts to disabled or inactive if/when appropriate, as directed by the appropriate SAAR POC or a security manager.
4. Assign the role of SAAR POC in EESOH-MIS to SAAR POCs as requested by the appropriate Air Force and Army Functional Management Office designee.
1.5.7 EESOH-MIS Air Force (AF) Functional Management Office (FMO) Roles and Responsibilities.
The FMO shall:
1. Maintain and update the SAAR POC Matrix (Table 1). Inform and coordinate with all stakeholders if a change is required, i.e. PMO, Security, Helpdesk.
2. Approve and maintain the Air Force SAAR POC roles in EESOH-MIS. Inform the
Nov 2015 Page 6
Help Desk via digitally signed email or other correspondence of valid SAAR POCs.
Retain SAAR POC designation letters as long as the role is active in EESOH-MIS.
3. Perform a monthly quality assurance check on a random selection of user SAARs and either take the appropriate corrective action or notify the SAAR POC of a non-compliant SAAR requiring corrective action. Users found with non-compliant SAARs are given 10 business days to correct the SAAR or the Helpdesk will be notified to disable the user due to a non-compliant SAAR. The validated SAARs will be annotated on a log maintained on the EESOH-MIS SharePoint Site.
1.5.8 EESOH-MIS Army Functional Management Office Roles and Responsibilities.
The FMO shall:
1. Approve and maintain the Army SAAR POCs roles in EESOH-MIS. Inform the Help
Desk via digitally signed email or other correspondence of valid SAAR POCs. Retain SAAR POC designation letters as long as the role is active in EESOH-MIS.
2. Perform a monthly quality assurance check on a random selection of user SAARs and either take the appropriate corrective action or notify the SAAR POC of a non-compliant SAAR requiring corrective action. Users found with non-compliant SAARs may be given 10 business days to correct the SAAR or the Helpdesk will be notified to disable the user due to a non-compliant SAAR. The SAARs validated will be annotated on a log maintained on the EESOH-MIS SharePoint Site.
1.6 Assignment of SAAR POCs
1. SAAR POCs will be designated in writing by the unit commander using the template at Appendix D). New designation letters are required for POC changes. Digitally signed emails are acceptable.
2. Installations must have one primary and may designate alternates.
3. Designation letters will be forwarded to the respective FMOs (AF: AFCEC/FMO, Army: USACE/EMCX).
1.7 Annual Account Recertification
Validation of user access is a continuous process in EESOH-MIS. Users are automatically disabled after 30 days of non-access. Users are automatically “deleted” after 90 days in a disabled status. Users in the National Guard, Reserves, or on an extended TDY may set this status in their user profile which will extend the disabled status to 120 days. Users found to erroneously set their status to National Guard, Reserves or extended TDY will be deleted.
The SAAR POC will conduct an annual review to recertify user access. The review must be completed within 30 days of review requirements. EESOH-MIS will provide reports of users requiring annual recertification each month. Annual reviews must be recorded in EESOH-MIS for each user to satisfy audit requirements. The annual review will consist of the following actions:
1. Review EESOH-MIS reports for users requiring annual review.
2. Verify the user’s job requires continued access and assigned roles to EESOH-MIS as stated on their SAAR. This may be accomplished in a variety of methods as long as the SAAR POC annotates the EESOH-MIS user record in EESOH-MIS on the method and date that the verification occurred to demonstrate compliance. The annotation in EESOH-MIS by the SAAR POC certifies the recertification occurred. Verification methods may include:
- User contacted via telecon
- User contacted via email or other written communication
Nov 2015 Page 7
3. Disabled users should be deleted as soon as it is determined the user no longer requires access to EESOH-MIS, i.e. change of jobs, PCS, retirement, etc.
4. If the user will no longer require access to EESOH-MIS, enter a projected end date and reason into the User record. EESOH-MIS will delete the user on the projected end date or the next day if the end date is the same day. If the user roles require adjustment, send a digitally signed email to the EESOH Helpdesk for modification of roles.
1.8 SAAR Retention.
SAARs shall be maintained in EESOH-MIS for one year, in accordance with Record Management requirements, after a user status becomes “deleted” in EESOH-MIS.
1.9. EESOH-MIS Automated User Management.
EESOH-MIS performs several automated tasks to assist with user management.
1. Sends email to users after 20 days of inactivity.
2. Disables users after 30 days of inactivity.
3. Deletes users after 90 days of inactivity.
4. Ensures roles assigned to user profile match roles in system. Prohibits the assignment of a role not in the user profile.
5. Identifies authorized SAAR POCs.
Note: Any automated EESOH-MIS action may be delayed due to a system failure to run a nightly routine or system down time.
APPENDIX A – EESOH-MIS SAAR Instructions
Nov 2015 Page 8
APPENDIX A – EESOH-MIS SAAR INSTRUCTIONS
Responsible Party Field Instructions Type of Request Check One User User ID enter the user Portal ID User Date Enter today’s date User System Name EESOH-MIS User Location GCSS-AF
PART I: ENDORSEMENT OF ACCESS BY INFORMATION OWNER, USER
SUPERVISOR OR GOVT SPONSOR
User (1) Name The last name, first name, and middle initial of the user
User (2) Organization The user's current organization (i.e. Air Force, Army, DLA, Navy, DoD, etc.) and government agency or commercial firm)
User (3) Office Symbol/Department
The office symbol within the current organization (i.e. SDI)
User (4) Telephone Number/DSN
The Defense Switching Network (DSN) phone number of the user. If DSN is unavailable, indicate commercial number
User (5)Official E-mail Address The user's official e-mail address User (6) Job Title/Grade/Rank The civilian job title (Example: Systems
Analyst, GS-14, Pay Clerk, GS-5)/military rank (COL, United States Army, CMSgt, USAF) or "Contractor" if user is a contractor
User (7) Official Mailing Address
The user's official mailing address
User (8) Citizenship Check one User (9) Designation of Person Check one User (10) IA Training and
Awareness Certification Requirements
User must check that he/she has completed the Annual Information Awareness Training and the date. Note: Date must have a minimum of 30 days prior to expiration
User (11) User's Signature User must DIGITALLY sign the DD Form 2875 with the understanding that they are responsible and accountable for their password and access to the system(s) and compliance with the "EESOH-MIS Rules of Behavior” (ROB).
User (12) Date The date user signs the form. Date may be blank if on digital signature
PART II: ENDORSEMENT OF ACCESS BY INFORMATION OWNER, USER
SUPERVISOR OR GOVT SPONSOR
Nov 2015 Page 9
Responsible Party Field Instructions Supervisor (13) Justification for
Access A brief statement is required to justify establishment of an initial USER ID. Provide appropriate information if the USER ID or access to the current USER ID is modified.
List the module(s) required. Note: The Cleanup Module request must be a separate
SAAR.
Example Justification Statement: “EESOH- MIS access required to perform the task of [insert description of job supporting access to EESOH] in accordance with the specified roles in block 27. Access to the following module(s) is required: [list modules]. Provide any other justification as needed.”
The EESOH-MIS modules are Hazmat, Hazwaste, Environmental Reporting and Cleanup.
SUPERVISOR (14) Type of Access Required
Place an "X" in the appropriate box.
(Authorized - Individual with normal access.
Privileged - Those with privilege to amend or change system configuration, parameters, or settings.)
SUPERVISOR (15) User Requires Access To
Place an "X" in UNCLASSIFIED
SUPERVISOR (16) Verification of Need to Know
Check to verify that the user requires access as requested
SUPERVISOR (16a) Expiration Date for Access
The user must specify expiration date if less than 1 year. CONTRACTORS must enter the Period of Performance (POP) expiration date, Contract number and Company Name
SUPERVISOR (17) Supervisor's Name (Print Name)
The supervisor or representative prints his/her name to indicate that the above information has been verified and that access is required
SUPERVISOR (18) Supervisor's Signature Supervisor's DIGITAL signature is required by the endorser or his/her representative.
The COR must sign for CONTRACTORS
SUPERVISOR (19) Date Date supervisor signs the form. Date may be blank if on digital signature
SUPERVISOR (20) Supervisor's Organization/Department
Supervisor's organization and department
SUPERVISOR (20a) E-mail Address Supervisor's e-mail address SUPERVISOR (20b) Phone Number Supervisor's telephone number SAAR POC (21) Signature of DIGITAL signature of the functional
Nov 2015 Page 10
Responsible Party Field Instructions Information Owner/OPR appointee responsible for approving access to the system being requested. THIS IS YOUR
DESIGNATED EESOH-MIS SAAR POC
as noted on the SAAR Matrix in Table 2
SAAR POC (21a) Phone Number Functional appointee (SAAR POC) telephone number
SAAR POC (21b) Date The date the functional appointee signs the DD Form 2875. Date may be blank if on digital signature
IAO (22) Signature of Information Assurance Officer (IAO) or Appointee.
DIGITAL signature of the IAO or Appointee of the office responsible for approving access to the system being requested
IAO (23)
Organization/Department
IAO's organization and department
IAO (24) Phone Number IAO's telephone number IAO (25) Date The date IAO signs the DD Form 2875. May be blank if date on digital signature.
USER (26) Name The last name, first name, and middle initial of the user
USER,
SUPERVISOR,
SAAR POC
(27) Optional Information
This item is intended to add additional information, as required.
Insert the following statement:
“Rules of Behavior (ROB): The ROB is a set of rules that describe the IA operations of the DoD information system and clearly delineate those IA responsibilities and expected behavior standards for all personnel are in place. Signed acknowledgement is verified by user signing block 11 of this form.
Supervisor signature in Block 18 verifies roles assigned are least privileged based on “Need to Know” and commensurate with duty function.”
Access Roles: List the roles required by the user.
Note: The supervisor uses this section to indicate specific access roles per installation required by the user from the roles spreadsheet for EESOH-MIS.
Users' access is restricted to "least privilege" based on role and "Need-to-Know" commensurate with their duty function. Installation and role selection may require discussion with the EESOH-MIS SAAR POC and/or the EESOH-MIS Installation administrator to ensure the correct roles per installation are selected. Refer to “EESOH-MIS Roles” spreadsheet attached and located at the
Nov 2015 Page 11
Responsible Party Field Instructions EESOH-MIS support portal (https://www.eesoh-mis.com/index.php) for specifics about each role.
Installation Requiring Access: List the installation(s) where the user requires access.
Justification for more than one installation: Explain role/job of user requiring more than one installation
C. PART III. CERTIFICATION OF BACKGROUND INVESTIGATION OR Clearance SECURITY (28) Type of Investigation The user's last type of background investigation (i.e., NAC, NACI, or SSBI) SECURITY (28a) Date of
Investigation Date of last investigation
SECURITY (28b) Clearance Level The user's current security clearance level (Secret or Top Secret)
SECURITY (28c) IT Level Designation
The user's IT designation (Level I, Level II, or Level III)
SECURITY (29) Verified By The Security Manager or representative prints his/her name to indicate that the above clearance and investigation information has been verified
SECURITY (30) Security Manager Telephone Number
The telephone number of the Security Manager or his/her representative
SECURITY (31) Security Manager Signature
The DIGITAL signature of the Security Manager or his/her representative indicates that the above clearance and investigation information has been verified
SECURITY (32) Date The date that the form was signed by the Security Manager or his/her representative.
Date may be blank if on digital signature
D. PART IV: leave blank
APPENDIX B – EESOH-MIS Rules of Behavior
Nov 2015 Page 12
APPENDIX B – EESOH-MIS RULES OF BEHAVIOR
1.0 Introduction
In accordance with (IAW) the Office of Management and Budget (OMB) Circular Number A-130, Appendix III, Security of Federal Automated Information Resources “ establish a set of rules of behavior concerning use of, security in, and the acceptable level of risk for, the system. The rules shall be based on the needs of the various users of the system. The security required by the rules shall be only as stringent as necessary to provide adequate security for information in the system. Such rules shall clearly delineate responsibilities and expected behavior of all individuals with access to the system. They shall also include appropriate limits on interconnections to other systems and shall define service provision and restoration priorities. Finally, they shall be clear about the consequences of behavior not consistent with the rules.”
2.0 Applicability
All users shall follow the rules set forth in the EESOH-MIS System Security Policy (SSP). They must also sign a DD Form 2875 as a System Authorization Access Request (SAAR) and User Acknowledgement, to confirm that each user has read and acknowledges these System Rules of Behavior, and understands the consequences of not being in compliance with them. These rules extend to all the EESOH-MIS software, developmental and operational entities, development contractor[s] and subscribers, and to all personnel developing, operating, administering, or sustaining interfacing systems. All EESOH-MIS users must be fully aware of, and abide by, the EESOH-MIS security policies as well as related Federal, DoD, and Air Force directives.
WARNING
Failure to follow the appropriate EESOH-MIS security guidance can result in administrative (e.g., loss of network or computer access for specific periods of time) or legal actions (e.g., court martial action for military personnel or prosecution in federal court for civilian personnel) for violators.
3.0 Purpose and Responsibilities
The purpose of this document is to ensure that EESOH-MIS has established rules of behavior concerning:
₋ The use of the system ₋ The security of the system.
₋ The acceptable level of risk for the system.
"Rules of Behavior" refer to the actions that ordinary operators and administrators must take to ensure the security of EESOH-MIS. These actions are specified in detail in the EESOH-MIS System Security Policy (SSP). The EESOH-MIS SSP supports Information Systems Security (ISS) personnel who are responsible for the continuous maintenance of information security. They prescribe detailed procedures that must be carried out by administrators and operators to ensure the secure operation of EESOH-MIS. Specifically, EESOH-MIS personnel must use the system for the mission for which it was designed. The following documents outline the EESOH-MIS system Rules of Behavior. These guidelines will help you fulfill security-related responsibilities as you use EESOH-MIS to perform official duties. For additional details, please see:
₋ AFI 33-200 – Air Force Cybersecurity Program Management ₋ AFMAN 33-282 – Computer Security (COMPUSEC) ₋ EESOH-MIS System Security Policy (SSP)
Nov 2015 Page 13
4.0 Information Sensitivity
EESOH-MIS has been determined to contain no For Official Use Only (FOUO) data. However, access to EESOH-MIS information will be limited only to those with valid need for such access in order to perform a legitimate organizational function. A prospective EESOH-MIS user is required to obtain a DoD Local Area Network (LAN) account and DoD PKI Common Access Card (CAC), along with subsequent access to the GCSS-AF controlled Air Force Portal as a pre-requisite for EESOH-MIS access. The user must then complete a SAAR DD Form 2875, to document that he/she has a valid Need-to-Know for the information contained in the information system before access to the application is granted. Security is everyone's responsibility. Everyone must read, understand, and abide by these rules. If you have doubt about what to do, seek assistance from security personnel.
5.0 General Rules of Behavior
All users must:
a. Log out every time they leave their workplaces.
b. Protect government resources from physical disaster as well as natural, human, and other physical threats.
c. Control entry to the facility. Positively identify anyone attempting access to the workstation. Verify their need-to-know and authorization to use the workstation for official business.
d. Secure resources that process or handle EESOH-MIS data and provide adequate protection during and after duty hours.
e. Know how to fulfill the Contingency Plan roles and responsibilities.
f. Report all suspected or known compromise incidents to their local information security manager.
6.0 Establishing an EESOH-MIS Account:
Referencing EESOH-MIS Account Management Policy, a prospective EESOH-MIS user is required to obtain a DoD Local Area Network (LAN) account and DoD Common Access Card (CAC), along with subsequent access to the Air Force Portal as a pre-requisite for EESOH-MIS access. The user must then complete a SAAR DD Form 2875, to document that he/she has a valid Need-to-Know for the information contained in the information system before access is granted. Need-to-Know determination is the decision made by an authorized holder of official information that a prospective recipient requires access to specific official information to carry out official duties (reference (i)). Ref: Department of Defense Directive 8500, Cybersecurity. The user’s supervisor is responsible for verifying Need-to-Know and determining access requirements. User access is role-based and restricted based on Need-to-Know and least-privilege principles per installation. The DD Form 2875 is coordinated through the user’s management and security channels for approval and then forwarded to the appropriate functional appointee for approving EESOH-MIS access and retained for filing and auditing purposes. The type of EESOH-MIS user and their functional area (i.e. HazMat, HazWaste and Clean-Up) determines the appropriate functional appointee (Refer to the EESOH-MIS Functional Appointee Matrix in the EESOH-MIS Account Management Policy). After the appropriate functional appointee validates the DD Form 2875, he/she notifies the EESOH-MIS Helpdesk, by uploading the SAAR and user data to the AFCEC SharePoint site at
Nov 2015 Page 14 https://afcec-portal.lackland.af.mil/sites/Helpdesk/eesoh_saars/Forms/AllItems.aspx.0F
1 The EESOH-MIS accounts are established by the EESOH-MIS Helpdesk. The EESOH-MIS Helpdesk will notify the functional appointee once the account is activated, who will in turn notify the prospective user. The user can then log into their EESOH-MIS account using their CAC.
7.0 Common Access Card Use and Protection
During your log-on to EESOH-MIS, you must use a properly prepared DoD CAC with the PIN.
DoD CACs also provide the ability to add digital signatures and provide encryption through the use of Public Key Infrastructure (PKI). Both features reinforce the concept of non-repudiation;
that is, the assurance that an activity or event can be positively traced to the individual responsible for that activity or event. All personnel must remember that their DoD CACs are also their identification cards, and are used for gaining entry to facilities. The DoD CAC issuing authority issues CACs and PINs, not the system Program Office (PO) or the GCSS-AF System Administrators (SA). All users are responsible for the proper use and protection of the DoD CACs and PINs issued to them. Users must, at a minimum, safeguard CACs as "For Official Use Only" according to these rules:
₋ Protect PINs at the unclassified sensitive level, committing them to memory--never write them down.
₋ Destroy media containing PINs associated with the CACs in accordance with unclassified sensitive handling instructions.
₋ Never share CACs/PINs, even in an emergency.
₋ Never use personal information or commonly used sequences of numbers to construct
PINs.
₋ Report any suspected or actual compromise of CACs/PINs.
₋ Never leave CACs unattended in CAC readers while logged on.
₋ Retain CACs in their personal possession at all times when not logged on at their workstations.
₋ Report lost, misplaced, or stolen CACs to their supervisors and security.
8.0 Client Workstation Protection
All users, within the limits of practicality and commensurate with the judgment of the EESOH- MIS AO, must protect EESOH-MIS workstations. Refer to AFI 33-200, Cybersecurity Program Management, for more details.
a. Never leave a workstation unprotected while "logged-on."
b. Enable the system’s password-protected screensaver or employ physical measures.
c. Challenge any individual that cannot be positively identified and verify the individual's authorized status.
d. Each machine must have the most current and approved anti-virus software to detect or remove malicious software viruses--especially from diskettes received from another location. If virus-scanning tools are not present or not configured properly, on your computer, contact your SA immediately
1 Note: previous policy required a “digitally signed” e-mail, so that the user account can be created and roles assigned per installation based on the validated DD Form 2875. The digitally signed e-mail ensures the request is from a “verified” functional appointee through non-repudiation.
https://afcec-portal.lackland.af.mil/sites/Helpdesk/eesoh_saars/Forms/AllItems.aspx
Nov 2015 Page 15
9 Security Personnel AFI 33-200 describes the overall responsibilities and roles for the security staff. Know who these security people are and seek their assistance when needed.
a. System Administrator The GCSS-AF System Administrators (SA) assigned to support the EESOH-MIS application within the GCSS-AF enclave are the focal point for all technical matters concerning EESOH-MIS within the GCSS-AF enclave. GCSS-AF SA security-related duties include, but are not limited to, security checks; disk and file maintenance;
performance data collection; and security audit trail management and monitoring. The GCSS-AF SA also enforces DoD CAC PKI access control through GCSS-AF enclave to the EESOH-MIS application, and coordinates security policies and requirements with program management.
b. Information System Security Manager (ISSM) The ISSM is the single point of contact for coordinating security activities between the EESOH-MIS user and the various internal and external organizations. In addition, the ISSM conducts security training (or coordinates the presentation of security training). The ISSM shall also oversee all C&A processes relating to EESOH-MIS. The ISSM will develop and maintain EESOH-MIS Cybersecurity program and security documentation.
The ISSM will ensure that incidents are reported to the AO, and will notify the AO of any impacts to the security posture of EESOH-MIS.
c. Client Support Administrator (CSA) The installation CSA is the first person to contact when workstation-related problems (not EESOH-MIS-supported application software problems) occur. If the CSA is unable to correct the problem, the CSA will up channel for assistance.
d. Functional Users Functional users are individuals who log onto EESOH-MIS application through the GCSS- AF controlled AF Portal with a DoD CAC to perform their mission-related duties. As a functional user, you must comply with security policies and these System Rules of Behavior.
10 Software Rules Never load or execute privately-owned software on the GCSS-AF servers hosting the EESOH- MIS application. This prohibition includes personally-written or locally developed software. Use only software approved and provided by GCSS-AF. Users who deviate from these rules may invalidate this security certification and accreditation and/or have sanctions imposed.
Nov 2015 Page 16
11 EESOH-MIS Security Rules and Procedures Data Aggregation - Data aggregation occurs when separate pieces of data at one sensitivity level (e.g., sensitive) combine to form an aggregated data set whose sensitivity exceeds the sensitivity of any of its constituent pieces. When you request information, be fully aware of the potential for data aggregation. Limit the viewing of information that would result in data aggregation.
Based on DoDM5200.01, Information Security Program, all EESOH-MIS data is not exempt from release to the public under Freedom of Information Act (FOIA). However, EESOH-MIS has been determined to contain no For Official Use Only (FOUO) data. There is no specific marking or labeling authorized for the designation of EESOH-MIS information as determined by the Mission Owner. Access to the information shall be limited only to those with valid need for such access in order to perform a legitimate organizational function, as dictated by common-sense principles of security management.
Use EESOH-MIS for official duty purposes only. Be aware that the system routinely and silently records the actions you take in its Security Audit Trail. You can be held accountable for unauthorized use. Other important rules are:
a. Use only those functions you need to perform your duties -- do not "experiment"!
b. Be alert for unexpected output. Verify that you obtain only those reports you intended to produce, and no more. If you get an unexpected report, take the following actions:
i. Double-check your work – you may have inadvertently requested the report.
ii. If the situation persists, contact the CSA or EESOH-MIS Helpdesk for assistance or guidance.
12 Marking, Handling, and Storing Rules EESOH-MIS has been determined to contain no For Official Use Only (FOUO) data. There is no specific marking or labeling authorized for the designation of EESOH-MIS information as determined by the Mission Owner. As a user, you are responsible to protect EESOH-MIS data from any unauthorized personnel without a Need-to- Know for EESOH-MIS information.
Appendix C - EESOH-MIS Roles List
Nov 2015 Page 17
APPENDIX C – EESOH-MIS ROLES
Module EESOH-MIS Role Role Use Business Role
Restriction System
Restriction
Hazmat Hazmart
Operators of Hazmat Tracking Activities (HTAs)/HAZMARTs responsible for the tracking, receiving, issuing, and storage of Hazmats.
Personnel operating Hazmat Tracking Activities
None
Hazmat Shop USER Shop personnel requiring access to EESOH.
Role can initiate process authorization and material request.
As needed
Hazmat Hazwaste
Shop Supervisor
Supervisor and alternate for a shop using Hazmat and/or generates Hazwaste.
Shop supervisors and their alternate
Hazmat HMMP Responsible for the installation hazardous material management. Typically the Installation Hazardous Material Manager.
One primary and two alternates per installation.
Hazmat Environmental Functional
An environmental functional will review environmental related issues in the system such as Process Authorizations.
Only Environmental Office personnel
Hazmat Occupational Health Functional
An occupational health functional that will review occupational health related issues in the system.
Highly restricted to personnel in the Bioenvironmental function
Hazmat Safety Functional
A safety functional that will review safety related issues in the system.
Only personnel in the Safety function
Hazmat Functional Unit Environmental Coordinators (UECs), optional reviewer or notification of process authorization
UECs, Fire Department, other reviewers
Hazmat Hazmat Administrator
Responsible for modifying the Hazmat related pick lists.
Restricted to
AFCEC/FMO
AFCEC/FMO,
PMO GROUP
Hazmat Hazmart Inventory Administrator
Hazmart Manager responsible for updating Hazmat inventory records in EESOH (installation-wide and historical data)
Restricted to one primary and one alternate per installation if required.
None
Hazmat Inventory Administrator
Responsible for updating Hazmat inventory records in EESOH.
Highly Restricted.
Role approved by
AFCEC/FMO
Assign by System SAAR
POC
Hazmat Shelf Life Manager
Responsible for updating inventory expiration dates at a system level
Restricted to
AFCEC/FMO FMO ONLY
Shared Interface Admin
Responsible for interface management such as APIMS and DRMS.
One primary and one alternate per Interface system
Nov 2015 Page 18
Module EESOH-MIS Role Role Use Business Role
Restriction System
Restriction
Hazmat MDR Approver
Installation level approver for Disposition Requests. This is an optional role for each installation and the requirement must also be established in installation preferences.
One primary and one alternate per installation
Hazwaste Hazwaste Administrator
Responsible for the setup of the Hazwaste functions in the shared areas for the installation, including the Hazwaste related pick list.
One primary and one alternate per installation
Enterprise Reports
Allows for system-wide report roll-ups. AFCEC and PMO only None
Hazwaste Hazwaste Site Manager
Allows for site stream setup and profile modification and approval limited to specific sites.
As needed None
Hazwaste Hazwaste Container Initiator
Allows site level container initiation. As needed None
Hazwaste Hazwaste Associate Manager
Same as the Hazwaste Manager with the exception of approvals and transmission to
DRMO.
Hazwaste managers None
Hazwaste Hazwaste Manager
Responsible for installation Hazwaste program. Includes approvals and transmission to DRMO.
Hazwaste manager responsible for DRMS transactions
Hazwaste Hazwaste View Only View only to Hazwaste module. As needed None
Shared Organization Steward Organization data steward.
One primary and one alternate per installation
NONE
Shared Personnel Steward Personnel data steward.
One primary and one alternate per installation
None
Cleanup Air Staff Administrator
Responsible for managing the funding for MAJCOMs and Organizations/Programs.
Access to create and manage projects at the Air Staff level, view projects at the MAJCOM and Installation level, and view site information for Installations.
Approved by Air Staff
– 12/28 – change this to Restricted to Data Group SAAR POC
CLEANUP
GROUP
Cleanup Cleanup Administrator Manages pick list for Cleanup options.
Restricted to Data Group leadership– 12/28 – change this to Restricted to Data Group SAAR POC
CLEANUP
GROUP
Cleanup MAJCOM Creates and manages projects at a MAJCOM level. Responsible for validating installation level MTS projects. The Air
Limited to MAJCOM
ANG
CLEANUP
GROUP
Nov 2015 Page 19
Module EESOH-MIS Role Role Use Business Role
Restriction System
Restriction
National Guard (ANG) MAJCOM role is responsible for validating all of the ANG installation level projects and sites
Cleanup R-PMO Data Group
(Restoration Program Management Office Data Group) The R-PMO is responsible for installations associated to the R-PMO, under the ERA program with the exception of the Air National Guard. Role can update the Amounts fields that would normally be updateable at the MAJCOM level with the exception of the MAJCOM Review field
Approved by Data Group SAAR POC
CLEANUP
GROUP
Cleanup
R-PMO
Program Manager
The Restoration Program Management Office Program Manager R-PMO is responsible for installations associated to the R-PMO, under the ERA program with the exception of the Air National Guard.
Role can also edit the Project Information tab for R-PMO associated Installations. The R-PMO Program Manager will only be able to update a limited number of Amounts fields that would typically be updated at the MAJCOM level. The MAJCOM Review field can only be updated by the R-PMO Program Manager
Approved by Data Group SAAR POC
CLEANUP
GROUP
Cleanup Cleanup User Installation USER responsible for creating and managing sites and installation level projects
Approved by Data Group SAAR POC
CLEANUP
GROUP
Cleanup Cleanup User View Only
View-only to the cleanup media, and those shared areas that the cleanup USER requires
Approved by Data Group SAAR POC
CLEANUP
GROUP
Cleanup Chief Financial Officer (CFO)
CFO view only access to the same projects as the R-PMO roles. Can access and the search the same criteria as the R-PMO data group
Approved by Data Group SAAR POC
CLEANUP
GROUP
Environmental Quality
Environmental Quality (EQ) User View Only
View-only access to the cleanup media and shared areas
Approved by AFCEC EQ Data Group SAAR
POC
EQ GROUP
Environmental Quality EQ User Installation User responsible for creating installation level projects
Approved by AFCEC EQ Data Group SAAR
POC
EQ GROUP
Environmental Quality EQ MAJCOM Creates and manages projects at an EQ
MAJCOM level
Approved by AFCEC EQ Data Group SAAR
POC
EQ GROUP
Environmental Quality EQ CFO
CFO view only accesses to the same projects as the EQ data group roles. Can access and the search the same criteria as
Approved by AFCEC EQ Data Group SAAR
EQ GROUP
Nov 2015 Page 20
Module EESOH-MIS Role Role Use Business Role
Restriction System
Restriction the EQ data group POC
Environmental Quality
EQ Program Manager
EQ PM responsible for installations associated to the PM, under the ENV program. The EQ PM is able create installation level projects and update a limited number of Amounts fields
Approved by AFCEC EQ Data Group SAAR
POC
EQ GROUP
Environmental Quality EQ Data Group
EQ PM responsible for installations associated to the EQ module, under the ENV program. Roles can create, edit, and delete sites and projects
Approved by AFCEC EQ Data Group SAAR
POC
EQ GROUP
Environmental Reporting ER Admin
AFCEC administrator responsible for managing Data Call process. This includes creating, editing and modifying Data Call templates and Data Calls
Restricted to
AFCEC/CZCA AFCEC GROUP
Environmental Reporting ER SME
AFCEC Subject Matter Expert (SME) responsible for validating and QA/QC the data entered by the Base-level ER USER and ER Reviewer Responsible for reviewing the submitted data call and either accepting or rejecting the data call from the ER USER and ER Reviewer
Approved by AFCEC ER Program Manager AFCEC GROUP
Environmental Reporting ER USER
The USER responsible for entering the data for a specific Base. The same person may be responsible for all Media, or each Media may have a designated contact or any combination (per business policy)
As needed None
Environmental Reporting ER Reviewer
The AFCEC RST/IST/ANG/AFRC (previously MAJCOM) responsible for reviewing and validating data by ER USER only. Capable of entering data on behalf of a specific base
RST/IST or ANG/AFRC MAJCOM level personnel.
AFCEC, RST,
IST
*Shared Read Only Read only As needed – only accesses hazmat and shared
None
Shared Enterprise Contract Manager
Allows the creation and modification of enterprise-level contracts. PMO and AFCEC only None
Shared Installation Admin
Responsible for setting up Installation preferences and the administration of centralized functions such as workflow.
Gatekeeper for EESOH-MIS access at the…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .