20 - IPS Requirement Document 1C CSP
8 MB Posted
- Attached to
- Professional Service Schedule Federal contract opportunity
- Solicitation number
- FCO00CORP0000C
- Issued by
- GSA Federal Acquisition Service
About this file
20 - IPS Requirement Document 1C CSP
Text of this file
[SYSTEM NAME] [ACRONYM]
System Security Plan [Date]
Identity Protection Services (IPS) IPS Requirements Document 1C in Support of SIN 520-20 dtd November 2017 (PSS Refresh #36)
Document Prepared By Company Representative Responsible for this Plan (Name, Position)
Company Name
Address Line 1
Address Line 2
City, State Zip
E-mail Address
Phone Number
Identity Protection Services (IPS) IPS 520-20 Requirements Document 1C dtd November 2017 (PSS Refresh #34)
Document Revision History
| Date |
| Comments |
| Version |
| Author |
| [Date] |
| Initial Version |
| 1.0 |
| [Name] |
AttachmentsInstruction: Attachments may vary on a system-by-system basis. The following appendices are considered standard SSP attachments. They are not required as part of this submission, but may be required at the task order level.
Attachment 1: Privacy Impact Assessment Attachment 2: FIPS 199 Security Categorization Attachment 3: e-Authentication Assurance Level Attachment 4: Interconnection Security Agreement(s)/Memoranda of Understanding Attachment 5: Control Tailoring Workbook Attachment 6: Control Summary Table (based on FIPS 199 Categorization) Attachment 7: Contingency Plan Attachment 8: Contingency Plan Test Report Attachment 9: Incident Response Plan Attachment 10: Incident response Plan Test Report Attachment 11: Configuration Management Plan Attachment 12: Continuous Monitoring Plan (if applicable) Attachment 13: Rules of Behavior (if applicable) Attachment 14: Code Review Report (if applicable) Other Attachments, as necessary
Table of Contents
| 1 | Information System Name | 1 |
| 2 | Information System Categorization | 1 |
| 2.1 | Information Types | 1 |
| 2.2 | Potential Impacts of Security Objectives | 2 |
| 2.3 | E-Authentication Determination (E-Auth) | 2 |
| 3 | Information System Owner | 3 |
| 4 | Authorizing Official | 3 |
| 5 | Other Designated Contacts | 4 |
| 6 | Assignment of Security Responsibility | 4 |
| 7 | Information System Operational Status | 5 |
| 8 | Information System Type | 5 |
| 8.1 | Systems Providing Controls to [ACRONYM] | 5 |
| 8.2 | Systems Receiving Controls from [ACRONYM] | 5 |
| 9 | General System Description | 6 |
| 9.1 | Information System Locations | 6 |
| 9.2 | Information System Components and Boundaries | 6 |
| 9.3 | Types of Users | 7 |
| 9.4 | Network Architecture | 7 |
| 10 | System Environment | 8 |
| 10.1 | Asset Inventory | 8 |
| 10.2 | Software Inventory | 8 |
| 10.3 | Data Flow | 9 |
| 10.4 | Ports, Protocols and Services | 9 |
| 11 | System Interconnections | 10 |
| 12 | Applicable Laws and Regulations | 12 |
| 13 | Minimum Security Controls | 13 |
| 13.1 | Access Control | 13 |
| 13.1.1 | AC-1: Access Control Policy and Procedures | 13 |
| 13.1.2 | AC-2: Account Management | 14 |
| 13.1.3 | AC-2 (1): Account Management | Automated System Account Management | 16 |
| 13.1.4 | AC-2 (2): Account Management | Removal of Temporary/Emergency Accounts | 17 |
| 13.1.5 | AC-2 (3): Account Management | Disable Inactive Accounts | 17 |
| 13.1.6 | AC-2 (4): Account Management | Automated Audit Actions | 18 |
| 13.1.7 | AC-3: Access Enforcement | 18 |
| 13.1.8 | AC-4: Information Flow Enforcement | 19 |
| 13.1.9 | AC-5: Separation of Duties | 20 |
| 13.1.10 | AC-6: Least Privilege | 21 |
| 13.1.11 | AC-6 (1): Least Privilege | Authorize Access to Security Functions | 21 |
| 13.1.12 | AC-6 (2): Least Privilege | Non-Privileged Access for Nonsecurity Functions | 22 |
| 13.1.13 | AC-6 (5): Least Privilege | Privileged Accounts | 23 |
| 13.1.14 | AC-6 (9): Least Privilege | Auditing Use of Privileged Functions | 23 |
| 13.1.15 | AC-6 (10): Least Privilege | Prohibit Non-Privileged Users from Executing Privileged Functions | 24 |
| 13.1.16 | AC-7: Unsuccessful Login Attempts | 24 |
| 13.1.17 | AC-8: System Use Notification | 25 |
| 13.1.18 | AC-11: Session Lock | 26 |
| 13.1.19 | AC-11 (1): Session Lock | Pattern Hiding Displays | 27 |
| 13.1.20 | AC-12: Session Termination | 28 |
| 13.1.21 | AC-14: Permitted Actions Without Identification or Authentication | 28 |
| 13.1.22 | AC-17: Remote Access | 29 |
| 13.1.23 | AC-17 (1): Remote Access | Automated Monitoring/Control | 30 |
| 13.1.24 | AC-17 (2): Remote Access | Protection of Confidentiality/Integrity Using Encryption | 30 |
| 13.1.25 | AC-17 (3): Remote Access | Managed Access Control Points | 31 |
| 13.1.26 | AC-17 (4): Remote Access | Privileged Commands/Access | 31 |
| 13.1.27 | AC-18: Wireless Access | 32 |
| 13.1.28 | AC-18 (1): Wireless Access | Authentication and Encryption | 33 |
| 13.1.29 | AC-19: Access Control for Mobile Devices | 33 |
| 13.1.30 | AC-19 (5): Access Control for Wireless Devices | Full Device / Container Based Encryption | 34 |
| 13.1.31 | AC-20: Use of External Information Systems | 35 |
| 13.1.32 | AC-20 (1): Use of External Information Systems | Limits on Authorized Use | 36 |
| 13.1.33 | AC-20 (2): Use of External Information Systems | Portable Storage Devices | 36 |
| 13.1.34 | AC-21: Information Sharing | 37 |
| 13.1.35 | AC-22: Publicly Accessible Content | 38 |
| 13.2 | Awareness and Training | 39 |
| 13.2.1 | AT-1: Security Awareness and Training Policy and Procedures | 39 |
| 13.2.2 | AT-2: Security Awareness Training | 40 |
| 13.2.3 | AT-2 (2): Security Awareness Training | Insider Threat | 41 |
| 13.2.4 | AT-3: Role-Based Security Training | 41 |
| 13.2.5 | AT-4: Security Training Records | 42 |
| 13.3 | Audit and Accountability | 43 |
| 13.3.1 | AU-1: Audit and Accountability Policy and Procedures | 43 |
| 13.3.2 | AU-2: Audit Events | 44 |
| 13.3.3 | AU-2 (3): Auditable Events | Reviews and Updates | 45 |
| 13.3.4 | AU-3: Content of Audit Records | 46 |
| 13.3.5 | AU-3 (1): Content of Audit Records | Additional Audit Information | 46 |
| 13.3.6 | AU-4: Audit Storage Capacity | 47 |
| 13.3.7 | AU-5: Response to Audit Processing Failures | 48 |
| 13.3.8 | AU-6: Audit Review, Analysis, and Reporting | 48 |
| 13.3.9 | AU-6 (1): Audit Review, Analysis, and Reporting | Process Integration | 49 |
| 13.3.10 | AU-6 (3): Audit Review, Analysis, and Reporting | Correlate Audit Repositories | 50 |
| 13.3.11 | AU-7: Audit Reduction and Report Generation | 50 |
| 13.3.12 | AU-7 (1): Audit Reduction and Report Generation | Automatic Processing | 51 |
| 13.3.13 | AU-8: Time Stamps | 52 |
| 13.3.14 | AU-8 (1): Time Stamps | Synchronization with Authoritative Time Source | 53 |
| 13.3.15 | AU-9: Protection of Audit Information | 54 |
| 13.3.16 | AU-9 (4): Protection of Audit Information | Access by Subset of Privileged Users | 54 |
| 13.3.17 | AU-11: Audit Record Retention | 55 |
| 13.3.18 | AU-12: Audit Generation | 55 |
| 13.4 | Security Assessment and Authorization | 56 |
| 13.4.1 | CA-1: Security Assessment and Authorization Policy and Procedures | 56 |
| 13.4.2 | CA-2: Security Assessments | 57 |
| 13.4.3 | CA-2 (1): Security Assessments | Independent Assessors | 58 |
| 13.4.4 | CA-3: System Interconnections | 59 |
| 13.4.5 | CA-3 (5): System Interconnections | Restrictions on External System Connections | 60 |
| 13.4.6 | CA-5: Plan of Action and Milestones | 61 |
| 13.4.7 | CA-6: Security Authorization | 61 |
| 13.4.8 | CA-7: Continuous Monitoring | 62 |
| 13.4.9 | CA-7 (1): Continuous Monitoring | Independent Assessment | 64 |
| 13.4.10 | CA-8: Penetration Testing | 64 |
| 13.4.11 | CA-8 (1): Penetration Testing | Independent Penetration Agent or Team | 65 |
| 13.4.12 | CA-9: Internal System Connections | 66 |
| 13.5 | Configuration Management | 66 |
| 13.5.1 | CM-1: Configuration Management Policy and Procedures | 66 |
| 13.5.2 | CM-2: Baseline Configuration | 67 |
| 13.5.3 | CM-2 (1): Baseline Configuration | Reviews and Updates | 68 |
| 13.5.4 | CM-2 (2): Baseline Configuration | Automation Support for Accuracy / Currency | 69 |
| 13.5.5 | CM-2 (3): Baseline Configuration | Retention of Previous Configurations | 69 |
| 13.5.6 | CM-2 (7): Baseline Configuration | Configure Systems, Components, or Devices for High-Risk Areas | 70 |
| 13.5.7 | CM-3: Configuration Change Control | 71 |
| 13.5.8 | CM-3 (2): Configuration Change Control | Test/Validate/Document Changes | 72 |
| 13.5.9 | CM-4: Security Impact Analysis | 73 |
| 13.5.10 | CM-5: Access Restrictions for Change | 73 |
| 13.5.11 | CM-6: Configuration Settings | 74 |
| 13.5.12 | CM-6 (1): Configuration Settings | Automated Central Management / Application / Verification | 75 |
| 13.5.13 | CM-7: Least Functionality | 76 |
| 13.5.14 | CM-7 (1): Least Functionality | Periodic Review | 77 |
| 13.5.15 | CM-7 (2): Least Functionality | Prevent Program Execution | 78 |
| 13.5.16 | CM-7 (4): Least Functionality | Unauthorized Software/Blacklisting | 78 |
| 13.5.17 | CM-8: Information System Component Inventory | 79 |
| 13.5.18 | CM-8 (1): Information System Component Inventory | Updates During Installations / Removals | 80 |
| 13.5.19 | CM-8 (2): Information System Component Inventory | Automated Maintenance | 81 |
| 13.5.20 | CM-8 (3): Information System Component Inventory | Automated Unauthorized Component Detection | 81 |
| 13.5.21 | CM-8 (5): Information System Component Inventory | No Duplicate Accounting of Components | 82 |
| 13.5.22 | CM-8 (6): Information System Component Inventory | Assessed Configurations / Approved Deviations | 83 |
| 13.5.23 | CM-9: Configuration Management Plan | 83 |
| 13.5.24 | CM-10: Software Usage Restrictions | 84 |
| 13.5.25 | CM-11: User-Installed Software | 85 |
| 13.6 | Contingency Planning | 86 |
| 13.6.1 | CP-1: Contingency Planning Policy and Procedures | 86 |
| 13.6.2 | CP-2: Contingency Plan | 87 |
| 13.6.3 | CP-2 (1): Contingency Plan | Coordinate With Related Plans | 89 |
| 13.6.4 | CP-2 (3): Contingency Plan | Resume Essential Missions/Business Functions | 89 |
| 13.6.5 | CP-2 (8): Contingency Plan | Identify Critical Assets | 90 |
| 13.6.6 | CP-3: Contingency Training | 91 |
| 13.6.7 | CP-4: Contingency Plan Testing | 91 |
| 13.6.8 | CP-4 (1): Contingency Plan Testing | Coordinate With Related Plans | 92 |
| 13.6.9 | CP-6: Alternate Storage Site | 93 |
| 13.6.10 | CP-6 (1): Alternate Storage Site | Separation from Primary Site | 94 |
| 13.6.11 | CP-6 (3): Alternate Storage Site | Accessibility | 94 |
| 13.6.12 | CP-7: Alternate Processing Site | 95 |
| 13.6.13 | CP-7 (1): Alternate Processing Site | Separation from Primary Site | 96 |
| 13.6.14 | CP-7 (2): Alternate Processing Site | Accessibility | 96 |
| 13.6.15 | CP-7 (3): Alternate Processing Site | Priority of Service | 97 |
| 13.6.16 | CP-8: Telecommunication Services | 98 |
| 13.6.17 | CP-8 (1): Telecommunication Services | Priority of Service Provisions | 98 |
| 13.6.18 | CP-8 (2): Telecommunication Services | Single Points of Failure | 99 |
| 13.6.19 | CP-9: Information System Backup | 100 |
| 13.6.20 | CP-9 (1): Information System Backup | Testing for Reliability/Integrity | 101 |
| 13.6.21 | CP-10: Information System Recovery and Reconstitution | 101 |
| 13.6.22 | CP-10 (2): Information System Recovery and Reconstitution | Transaction Recovery | 102 |
| 13.7 | Identification and Authentication | 103 |
| 13.7.1 | IA-1: Identification and Authentication Policy and Procedures | 103 |
| 13.7.2 | IA-2: Identification and Authentication (Organizational Users) | 104 |
| 13.7.3 | IA-2 (1): Identification and Authentication (Organizational Users) | Network Access to Privileged Accounts | 104 |
| 13.7.4 | IA-2 (2): Identification and Authentication (Organizational Users) | Network Access to Non-Privileged Accounts | 105 |
| 13.7.5 | IA-2 (3): Identification and Authentication (Organizational Users) | Local Access to Privileged Accounts | 105 |
| 13.7.6 | IA-2 (8): Identification and Authentication (Organizational Users) |Network Access to Privileged Accounts – Replay Resistant | 106 |
| 13.7.7 | IA-2 (11): Identification and Authentication (Organizational Users) | Remote Access – Separate Device | 107 |
| 13.7.8 | IA-2 (12): Identification and Authentication (Organizational Users) | Acceptance of PIV Credentials | 107 |
| 13.7.9 | IA-3: Device Identification and Authentication | 108 |
| 13.7.10 | IA-4: Identifier Management | 109 |
| 13.7.11 | IA-5: Authenticator Management | 110 |
| 13.7.12 | IA-5 (1): Authenticator Management | Password-Based Authentication | 112 |
| 13.7.13 | IA-5 (2): Authenticator Management | PKI-Based Authentication | 113 |
| 13.7.14 | IA-5 (3): Authenticator Management | In-Person or Trusted Third-Party Registration | 114 |
| 13.7.15 | IA-5 (11): Authenticator Management | Hardware Token-Based Authentication | 115 |
| 13.7.16 | IA-6: Authenticator Feedback | 115 |
| 13.7.17 | IA-7: Cryptographic Module Authentication | 116 |
| 13.7.18 | IA-8: Identification and Authentication (Non-Organizational Users) | 117 |
| 13.7.19 | IA-8 (1): Identification and Authentication (Non-Organizational Users) | Acceptance of PIV Credentials from Other Agencies | 117 |
| 13.7.20 | IA-8 (2): Identification and Authentication (Non-Organizational Users) | Acceptance of Third-Party Credentials | 118 |
| 13.7.21 | IA-8 (3): Identification and Authentication (Non-Organizational Users) | Use of FICAM-Approved Products | 118 |
| 13.7.22 | IA-8 (4): Identification and Authentication (Non-Organizational Users) | Use of FICAM-Issued Profiles | 119 |
| 13.8 | Incident Response | 120 |
| 13.8.1 | IR-1: Incident Response Policy and Procedures | 120 |
| 13.8.2 | IR-2: Incident Response Training | 121 |
| 13.8.3 | IR-3: Incident Response Testing | 122 |
| 13.8.4 | IR-3 (2): Incident Response Testing | Coordination with Related Plans | 122 |
| 13.8.5 | IR-4: Incident Handling | 123 |
| 13.8.6 | IR-4 (1): Incident Handling | Automated Incident Handling Processes | 124 |
| 13.8.7 | IR-5: Incident Monitoring | 124 |
| 13.8.8 | IR-6: Incident Reporting | 125 |
| 13.8.9 | IR-6 (1): Incident Reporting | Automated Reporting | 126 |
| 13.8.10 | IR-7: Incident Response Assistance | 126 |
| 13.8.11 | IR-7 (1): Incident Response Assistance | Automation Support for Availability of Information/Support | 127 |
| 13.8.12 | IR-8: Incident Response Plan | 127 |
| 13.9 | Maintenance | 129 |
| 13.9.1 | MA-1: System Maintenance Policy and Procedures | 129 |
| 13.9.2 | MA-2: Controlled Maintenance | 130 |
| 13.9.3 | MA-3: Maintenance Tools | 131 |
| 13.9.4 | MA-3 (1): Maintenance Tools | Inspect Tools | 132 |
| 13.9.5 | MA-3 (2): Maintenance Tools | Inspect Media | 133 |
| 13.9.6 | MA-4: Nonlocal Maintenance | 133 |
| 13.9.7 | MA-4 (2): Nonlocal Maintenance | Document Nonlocal Maintenance | 134 |
| 13.9.8 | MA-5: Maintenance Personnel | 135 |
| 13.9.9 | MA-6: Timely Maintenance | 136 |
| 13.10 | Media Protection | 136 |
| 13.10.1 | MP-1: Media Protection Policy and Procedures | 136 |
| 13.10.2 | MP-2: Media Access | 137 |
| 13.10.3 | MP-3: Media Marking | 138 |
| 13.10.4 | MP-4: Media Storage | 139 |
| 13.10.5 | MP-5: Media Transport | 140 |
| 13.10.6 | MP-5 (4): Media Transport | Cryptographic Protection | 141 |
| 13.10.7 | MP-6: Media Sanitization | 141 |
| 13.10.8 | MP-7: Media Use | 142 |
| 13.10.9 | MP-7 (1): Media Use | Prohibit Use Without Owner | 143 |
| 13.11 | Physical and Environmental Protection | 143 |
| 13.11.1 | PE-1: Physical and Environmental Protection Policy and Procedures | 143 |
| 13.11.2 | PE-2: Physical Access Authorizations | 144 |
| 13.11.3 | PE-3: Physical Access Control | 145 |
| 13.11.4 | PE-4: Access Control for Transmission Medium | 147 |
| 13.11.5 | PE-5: Access Control for Output Devices | 147 |
| 13.11.6 | PE-6: Monitoring Physical Access | 148 |
| 13.11.7 | PE-6 (1): Monitoring Physical Access | Intrusion Alarms/Surveillance Equipment | 149 |
| 13.11.8 | PE-8: Visitor Access Records | 149 |
| 13.11.9 | PE-9: Power Equipment and Cabling | 150 |
| 13.11.10 | PE-10: Emergency Shutoff | 151 |
| 13.11.11 | PE-11: Emergency Power | 152 |
| 13.11.12 | PE-12: Emergency Lighting | 152 |
| 13.11.13 | PE-13: Fire Protection | 153 |
| 13.11.14 | PE-13 (3): Fire Protection | Automatic Fire Suppression | 153 |
| 13.11.15 | PE-14: Temperature and Humidity Controls | 154 |
| 13.11.16 | PE-15: Water Damage Protection | 155 |
| 13.11.17 | PE-16: Delivery and Removal | 155 |
| 13.11.18 | PE-17: Alternate Work Site | 156 |
| 13.12 | Planning | 157 |
| 13.12.1 | PL-1: Security Planning Policy and Procedures | 157 |
| 13.12.2 | PL-2: System Security Plan | 158 |
| 13.12.3 | PL-2 (3): System Security Plan | Coordinate with Other Organizational Entities | 159 |
| 13.12.4 | PL-4: Rules of Behavior | 160 |
| 13.12.5 | PL-4 (1): Rules of Behavior | Social Media and Networking Restrictions | 161 |
| 13.12.6 | PL-8: Information Security Architecture | 162 |
| 13.13 | Personnel Security | 163 |
| 13.13.1 | PS-1: Personnel Security Policy and Procedures | 163 |
| 13.13.2 | PS-2: Position Risk Designation | 163 |
| 13.13.3 | PS-3: Personnel Screening | 164 |
| 13.13.4 | PS-4: Personnel Termination | 165 |
| 13.13.5 | PS-5: Personnel Transfer | 166 |
| 13.13.6 | PS-6: Access Agreements | 167 |
| 13.13.7 | PS-7: Third-Party Personnel Security | 168 |
| 13.13.8 | PS-8: Personnel Sanctions | 169 |
| 13.14 | Risk Assessment | 170 |
| 13.14.1 | RA-1: Risk Assessment Policy and Procedures | 170 |
| 13.14.2 | RA-2: Security Categorization | 171 |
| 13.14.3 | RA-3: Risk Assessment | 172 |
| 13.14.4 | RA-5: Vulnerability Scanning | 173 |
| 13.14.5 | RA-5 (1): Vulnerability Scanning | Update Tool Capability | 175 |
| 13.14.6 | RA-5 (2): Vulnerability Scanning | Update by Frequency / Prior to New Scan / When Identified | 175 |
| 13.14.7 | RA-5 (5): Vulnerability Scanning | Privileged Access | 176 |
| 13.15 | System and Services Acquisition | 176 |
| 13.15.1 | SA-1: System and Services Acquisition Policy and Procedures | 176 |
| 13.15.2 | SA-2: Allocation of Resources | 177 |
| 13.15.3 | SA-3: System Development Life Cycle | 178 |
| 13.15.4 | SA-4: Acquisition Process | 179 |
| 13.15.5 | SA-4 (1): Acquisition Process | Functional Properties of Security Controls | 181 |
| 13.15.6 | SA-4 (2): Acquisition Process | Design / Implementation Information for Security Controls | 181 |
| 13.15.7 | SA-4 (9): Acquisition Process | Functions / Ports / Protocols / Services in Use | 182 |
| 13.15.8 | SA-4 (10): Acquisition Process | Use of Approved PIV Products | 183 |
| 13.15.9 | SA-5: Information System Documentation | 183 |
| 13.15.10 | SA-8: Security Engineering Principles | 185 |
| 13.15.11 | SA-9: External Information System Services | 185 |
| 13.15.12 | SA-9 (2): External Information System Services | Identification of Functions / Ports / Protocols/ Services | 186 |
| 13.15.13 | SA-10: Developer Configuration Management | 187 |
| 13.15.14 | SA-11: Developer Security Testing and Evaluation | 188 |
| 13.15.15 | SA-22: Unsupported System Components | 189 |
| 13.16 | System and Communications Protection | 190 |
| 13.16.1 | SC-1: System and Communications Protection Policy and Procedures | 190 |
| 13.16.2 | SC-2: Application Partitioning | 191 |
| 13.16.3 | SC-4: Information In Shared Resources | 192 |
| 13.16.4 | SC-5: Denial of Service Protection | 192 |
| 13.16.5 | SC-7: Boundary Protection | 193 |
| 13.16.6 | SC-7 (3): Boundary Protection | Access Points | 194 |
| 13.16.7 | SC-7 (4): Boundary Protection | External Telecommunication Services | 194 |
| 13.16.8 | SC-7 (5): Boundary Protection | Deny by Default / Allow by Exception | 195 |
| 13.16.9 | SC-7 (7): Boundary Protection | Prevent Split Tunneling for Remote Devices | 196 |
| 13.16.10 | SC-8: Transmission Confidentiality and Integrity | 196 |
| 13.16.11 | SC-8 (1): Transmission Confidentiality and Integrity | Cryptographic or Alternate Physical Protection | 197 |
| 13.16.12 | SC-10: Network Disconnect | 197 |
| 13.16.13 | SC-12: Cryptographic Key Establishment & Management | 198 |
| 13.16.14 | SC-13: Cryptographic Protection | 199 |
| 13.16.15 | SC-15: Collaborative Computing Devices | 199 |
| 13.16.16 | SC-17: Public Key Infrastructure Certificates | 200 |
| 13.16.17 | SC-18: Mobile Code | 201 |
| 13.16.18 | SC-19: Voice Over Internet Protocol | 202 |
| 13.16.19 | SC-20: Secure Name/Address Resolution Service (Authoritative Source) | 202 |
| 13.16.20 | SC-21: Secure Name/Address Resolution Service (Recursive or Caching Resolver) | 203 |
| 13.16.21 | SC-22: Architecture and Provisioning for Name/Address Resolution Service | 204 |
| 13.16.22 | SC-23: Session Authenticity | 204 |
| 13.16.23 | SC-28: Protection of Information at Rest | 205 |
| 13.16.24 | SC-28 (1): Protection of Information at Rest | Cryptographic Protection | 206 |
| 13.16.25 | SC-39: Process Isolation | 206 |
| 13.17 | System and Information Integrity | 207 |
| 13.17.1 | SI-1: System and Information Integrity Policy and Procedures | 207 |
| 13.17.2 | SI-2: Flaw Remediation | 208 |
| 13.17.3 | SI-2 (2): Flaw Remediation | Automated Flaw Remediation Status | 209 |
| 13.17.4 | SI-2 (3): Flaw Remediation | Time to Remediate Flaws / Benchmarks for Corrective Actions | 209 |
| 13.17.5 | SI-3: Malicious Code Protection | 210 |
| 13.17.6 | SI-3 (1): Malicious Code Protection | Central Management | 211 |
| 13.17.7 | SI-3 (2): Malicious Code Protection | Automatic Updates | 212 |
| 13.17.8 | SI-3 (7): Malicious Code Protection | Nonsignature-Based Detection | 212 |
| 13.17.9 | SI-4: Information System Monitoring | 213 |
| 13.17.10 | SI-4 (2): Information System Monitoring | Automated Tools for Real-Time Analysis | 215 |
| 13.17.11 | SI-4 (4): Information System Monitoring | Inbound and Outbound Communications Traffic | 215 |
| 13.17.12 | SI-4 (5): Information System Monitoring | System-Generated Alerts | 216 |
| 13.17.13 | SI-5: Security Alerts, Advisories, and Directives | 217 |
| 13.17.14 | SI-7: Software, Firmware, and Information Integrity | 217 |
| 13.17.15 | SI-7 (1): Software, Firmware, and Information Integrity | Integrity Checks | 218 |
| 13.17.16 | SI-7 (7): Software, Firmware, and Information Integrity | Integration of Detection and Response | 219 |
| 13.17.17 | SI-8: Spam Protection | 219 |
| 13.17.18 | SI-8 (1): Spam Protection | Central Management | 220 |
| 13.17.19 | SI-8 (2): Spam Protection | Automatic Updates | 220 |
| 13.17.20 | SI-10: Information Input Validation | 221 |
| 13.17.21 | SI-11: Error Handling | 222 |
| 13.17.22 | SI-12: Information Handling and Retention | 223 |
| 13.17.23 | SI-16: Memory Protection | 223 |
| 14 | Privacy Controls | 225 |
| 14.1 | Authority and Purpose | 225 |
| 14.1.1 | AP-1: Authority to Collect | 225 |
| 14.1.2 | AP-2: Purpose Specification | 225 |
| 14.2 | Accountability, Audit, and Risk Management | 226 |
| 14.2.1 | AR-1: Governance and Privacy Program | 226 |
| 14.2.2 | AR-2: Privacy Impact and Risk Assessment | 227 |
| 14.2.3 | AR-3: Privacy Requirements For Contractors and Service Providers | 227 |
| 14.2.4 | AR-4: Privacy Monitoring and Auditing | 228 |
| 14.2.5 | AR-5: Privacy Awareness and Training | 229 |
| 14.2.6 | AR-6: Privacy Reporting | 229 |
| 14.2.7 | AR-7: Privacy-Enhanced System Design and Development | 230 |
| 14.2.8 | AR-8: Accounting of Disclosures | 230 |
| 14.3 | Data Quality and Integrity | 231 |
| 14.3.1 | DI-1: Data Quality | 231 |
| 14.3.2 | DI-2: Data Integrity and Data Integrity Board | 232 |
| 14.3.3 | DM-1: Minimization of Personally Identifiable Information (PII) | 232 |
| 14.3.4 | DM-2: Data Retention and Disposal | 233 |
| 14.3.5 | DM-3: Minimization of PII used in Testing, Training, and Research | 234 |
| 14.4 | Individual Participation and Redress | 235 |
| 14.4.1 | IP-1: Consent | 235 |
| 14.4.2 | IP-2: Individual Access | 235 |
| 14.4.3 | IP-3: Redress | 236 |
| 14.4.4 | IP-4: Complaint Management | 237 |
| 14.5 | Security | 237 |
| 14.5.1 | SE-1: Inventory of Personally Identifiable Information | 237 |
| 14.5.2 | SE-2: Privacy Incident Response | 238 |
| 14.6 | Transparency | 239 |
| 14.6.1 | TR-1: Privacy Notice | 239 |
| 14.6.2 | TR-2: System of Records Notices and Privacy Act Statements | 239 |
| 14.6.3 | TR-3: Dissemination of Privacy Program Information | 240 |
| 14.7 | Use Limitation | 241 |
| 14.7.1 | UL-1: Internal Use | 241 |
| 14.7.2 | UL-2: Information Sharing with Third Parties | 241 |
| APPENDIX A – Acronyms, Terms and Definitions | 243 | |
| APPENDIX B – References | 251 | |
| APPENDIX C – Hosted Subsystems (if applicable) | 253 | |
| Other Appendices, as necessary | 254 |
Tables and Figures
| Table 11. Information System Name and Identifier | 1 |
| Table 21. Overall Information System Categorization | 1 |
| Table 22. Information System Types | 2 |
| Table 23. Security Objective Impacts | 2 |
| Table 24. E-Authentication Determination | 2 |
| Table 25. E-Authentication Assurance Level Summary | 3 |
| Table 71. System Operational Status | 5 |
| Table 81. Systems Providing Controls | 5 |
| Table 82. Systems Receiving Controls | 6 |
| Table 91. System Locations | 6 |
| Table 92. System Assets | 6 |
| Table 93. User Roles and Privileges | 7 |
| Table 101. Asset Physical and Virtual Components | 8 |
| Table 102. Software Components | 8 |
| Table 103. Ports, Protocols, and Services | 9 |
| Table 111. System Interconnections | 10 |
| Table 112. Connection Details of Interconnected Systems | 11 |
| Figure 91. Network Diagram | 8 |
| Figure 101. Data Flow Diagram | 9 |
Page ix
Information System Name This System Security Plan (SSP) provides an overview of the security requirements for the [SYSTEM NAME] [ACRONYM] and describes the controls in place or planned for implementation to provide a level of security appropriate for the information to be transmitted, processed or stored by the system.
The security safeguards implemented for the [ACRONYM] meet the policy and control requirements as set forth in this SSP. All systems are subject to monitoring consistent with applicable laws, regulations, agency policies, procedures and practices.
Table 11. Information System Name and Identifier IT Investment Portfolio Summary ID:
| Information System Name: |
| [ACRONYM] |
| Information System Abbreviation: |
| [ACRONYM] |
Information System Categorization The overall information system security categorization is noted in the following table.
Note: A FIPS 199 Security Categorization document must be completed and submitted as an Attachment to this SSP.
Table 21. Overall Information System Categorization
| Low |
| |_| |
| Moderate |
| |_| |
| High |
| |_| |
Information Types The following tables identify the information types and impact levels that are input, stored, processed, and/or output from the [ACRONYM] environment. The security impact levels for confidentiality, integrity, and availability for each of the information types are expressed as low, moderate, or high. The security impact levels are based on the potential impact definitions for each of the security objectives (i.e., confidentiality, integrity, and availability) discussed in NIST SP 800-60 and FIPS Pub 199 (Note: The information types found in NIST SP 800-60, Volumes I and II, Revision 1 are the same information types found in the Federal Enterprise Architecture (FEA) Consolidated Reference Model).
Table 22. Information System Types
| Information Type |
| Confidentiality |
| Integrity |
| Availability |
| [First Type] |
| Low |
| Moderate |
| Low |
| [Second Type] |
| Low |
| Moderate |
| Low |
| [Third Type] |
| Moderate |
| Moderate |
| Moderate |
Potential Impacts of Security Objectives Based on the information provided above, the potential impacts for each security objective, per FIPS 199) for the [ACRONYM] environment is summarized in the table below.
Table 23. Security Objective Impacts
| Security Objective |
| Low, Moderate or High |
| Confidentiality |
| Moderate |
| Integrity |
| Moderate |
| Availability |
| Moderate |
E-Authentication Determination (E-Auth) The information system e-Authentication determination is described in the following table.
Instruction: Any information system that has a “No” response to any one of the three questions does not need an E-Authentication risk analysis or assessment. For a system that has a "Yes" response to all of the questions, complete the E-Authentication Plan (a template is available).
Table 24. E-Authentication Determination
| Yes |
| No |
| E-Authentication Questions |
| |_| |
| |_| |
| Does the system require authentication via the Internet? |
| |_| |
| |_| |
| Is data being transmitted over the Internet via browsers? |
| |_| |
| |_| |
| Do users connect to the system from over the Internet? |
The summary E-Authentication Assurance Level is recorded in the following table.
Note: A e-Authentication Assurance Level document must be completed and submitted as an Attachment to this SSP.
Table 25. E-Authentication Assurance Level Summary E-Authentication Assurance Level
| System Name: |
| [SYSTEM NAME] |
| System Owner: |
| [Organization] |
| Assurance Level: |
| [E-AUTHENTICAION LEVEL NUMBER] |
| Date Approved: |
| [Date] |
Information System Owner The following individual is identified as the System Owner/Program Manager for this system.
Name
Title
Organization
Address
Phone Number
Email Address
Authorizing Official The Authorizing Official (AO) for this information system is identified below.
Name
Title
Organization
Address
Phone Number
Email Address
Other Designated Contacts The individual(s) identified below possess in-depth knowledge of this system and/or its functions and operation.
Name
Title
Organization
Address
Phone Number
Email Address
Name
Title
Organization
Address
Phone Number
Email Address
Assignment of Security Responsibility The Information System Security Officer (ISSO) has been appointed and is identified below.
Name
Title
Organization
Address
Phone Number
Email Address
Information System Operational Status The system is currently in the life-cycle phase noted in the following table.
Table 71. System Operational Status System Status
| |_| |
| Operational |
| The system is operating and in production. |
| |_| |
| Under Development |
| The system is being designed, developed, or implemented. |
| |_| |
| Major Modification |
| The system is undergoing a major change, development, or transition. |
| |_| |
| Other |
| Explain: |
Information System Type The [ACRONYM] is a [General Support System (GSS)/Major Application (MA)/Subsystem].
Systems Providing Controls to [ACRONYM] The systems identified in the following table provide controls (common or hybrid) to [ACRONYM]. List all systems providing controls, the controls they provide, and identify if it is provided as a Common or Hybrid control.
Table 81. Systems Providing Controls
| [Providing System Name] |
| [Providing System Owner] |
| [Providing System ATO Date] |
| [Control Identifier] |
| [Control Name] |
| Common/Hybrid |
| [Control Identifier] |
| [Control Name] |
| Common/Hybrid |
| [Control Identifier] |
| [Control Name] |
| Common/Hybrid |
| [Providing System Name] |
| [Providing System Owner] |
| [Providing System ATO Date] |
| [Control Identifier] |
| [Control Name] |
| Common/Hybrid |
| [Control Identifier] |
| [Control Name] |
| Common/Hybrid |
| [Control Identifier] |
| [Control Name] |
| Common/Hybrid |
Systems Receiving Controls from [ACRONYM] [ACRONYM] provides the controls (common or hybrid) listed to the systems identified in the following table. List any controls provided to any systems and identify if it is provided as a Common or Hybrid control.
Table 82. Systems Receiving Controls
| [Receiving System Name] |
| [Receiving System Owner] |
| [Receiving System ATO Date] |
| [Control Identifier] |
| [Control Name] |
| Common/Hybrid |
| [Control Identifier] |
| [Control Name] |
| Common/Hybrid |
| [Control Identifier] |
| [Control Name] |
| Common/Hybrid |
| [Receiving System Name] |
| [Receiving System Owner] |
| [Receiving System ATO Date] |
| [Control Identifier] |
| [Control Name] |
| Common/Hybrid |
| [Control Identifier] |
| [Control Name] |
| Common/Hybrid |
| [Control Identifier] |
| [Control Name] |
| Common/Hybrid |
General System Description (Provide a general description of the system, including its function and purpose).
Information System Locations Physically, the [ACRONYM] environment resides at the locations identified below.
Table 91. System Locations Primary Secondary
Secondary (if applicable) Secondary
Information System Components and Boundaries The components of the [ACRONYM] environment can be broken down into the following groups of asset types. The assets are also portrayed in the network diagram in Section 9.4.
The controls described in Section 13 of this document may apply to some or all of these asset types.
Table 92. System Assets
| Asset Type |
| Description of Function or Service Provided |
Types of Users Instruction: For an External User, please write “Not Applicable” in the Sensitivity Level Column. Please include systems administrators and database administrators as role types. (Also include web server administrators, network administrators, and firewall administrators if these individuals have the ability to configure a device or host.) Add additional rows if necessary.
All users have their employee status categorized with a sensitivity level in accordance with PS-2. Employees are considered Internal Users. All other users are considered External Users. User privileges (authorization permission after authentication takes place) are described in the table that follows.
Table 93. User Roles and Privileges
| Role |
| Internal or External |
| Sensitivity Level |
| Authorized Privileges and Functions Performed |
Note: User roles typically align with Active Directory, LDAP, Role-based Access Controls (RBAC), NIS and UNIX groups, and/or UNIX netgroups.
Network Architecture Instruction: In the space that follows, provide an architectural diagram which provides a visual depiction of the major hardware components of the information system.
The following architectural diagram provides a visual depiction of the major hardware components of the [ACRONYM].
Figure 91. Network Diagram System Environment Instruction: In the space that follows, provide a general description of the technical system environment. Include information about all system environments that are used, e.g., production environment, test environment, staging or QA environments
Asset Inventory The following table lists the virtual and physical components of the [ACRONYM].
Table 101. Asset Physical and Virtual Components
| IP Address/Hostname |
| Make |
| Model and Firmware |
| Location |
| Components that Use this Device |
Software Inventory The following table lists the principle software components for [ACRONYM].
Table 102. Software Components
| IP Address/Hostname |
| Function |
| Version |
| Patch Level |
| Virtual (Yes / No) |
Data Flow Instruction: In this section describe the flow of data in and out of system boundaries and insert a data flow diagram. If necessary, include multiple data flow diagrams.
Figure 101. Data Flow Diagram Ports, Protocols and Services The table below lists the Ports, Protocols, and Services enabled in this information system. TCP ports are indicated with a T and UDP ports are indicated with a U.
Instruction: In the column labeled “Used By” please indicate the components of the information system that make use of the ports, protocols, and services. In the column labeled “Purpose” indicate the purpose for the service (e.g., system logging, HTTP redirector, load balancing). This table should be consistent with CM-6. Add more rows as needed.
Table 103. Ports, Protocols, and Services
| Ports (T or U) |
| Protocols |
| Services |
| Purpose |
| Used By |
System Interconnections Instruction: List data covering all interconnected systems in the two tables in this section. Add additional rows as needed.
· The first table is modeled after the System Interconnection table in NIST SP 800-18. It primarily covers the A&A status of connected systems where an ISA or MOU is required.
· The second table provides detailed information that is contained in an ISA or MOU. For systems where an ISA or MOU does not exist this data is vital to understanding the nature of the interconnection. For systems with an ISA or MOU this table provides a summary of information about the interconnection. Provide the IP address and interface identifier (ie0, ie1, ie2) for the system that provides the connection. Name the organization and the IP address of the external system. Indicate how the connection is being secured. For Connection Security indicate how the connection is being secured. For Data Direction, indicate which direction the packets are flowing. For Information Being Transmitted, describe what type of data is being transmitted. If a dedicated telecom line is used, indicate the circuit number.
Table 111. System Interconnections
| System Name |
| Organization |
| Type of System |
(GSS, MA, Subsystem)
| Agreement Type (ISA, MOU) |
| Date of Agreement |
| FIPS 199 Security Category of System |
| A&A Status of System |
| Name and Title of AO |
Table 112. Connection Details of Interconnected Systems
| System Name |
| Organization |
| Point of Contact and Phone Number |
| Connection Security (IPSec VPN, SSL, Certificates, Secure File Transfer, etc.) |
| Data Direction (incoming, outgoing, or both) |
| Information Being Transmitted |
| Ports or Circuit # |
Note: Additional information regarding each connection may be found in its associated MOU.
Applicable Laws and Regulations
See Appendix B, References.
Minimum Security Controls Minimum security controls for the [ACRONYM] environment are contained in the following sections.
Note: In the control summary tables the Control Origination section has a selection for Hybrid Controls. Preparers of the SSP may add additional Hybrid Control selections if the system inherits portions of a control from more than one system.
Instruction: In the space that follows for the implementation, provide a description of how the control is implemented. The implementation statement should stand on its own and not be a “parroting” back of the NIST SP 800-53 Rev. 4 security requirements. Additionally, the response should speak to all platforms in use (e.g., web, database, Operating System types [Windows, Linux, etc.]), and network devices.
For all Control Summary Information, if any are considered planned, in the implementation response state when it will be implemented and the steps currently being performed to implement.
For Implementation Status noted as “Not Applicable” a statement must be provided in the implementation response stating why it is considered not applicable.
Access Control AC-1: Access Control Policy and Procedures The organization:
a. Develops, documents, and disseminates to [Information System Security Manager, Information System Security Officer, System Owners (e.g., System Program Managers, System Project Managers), Acquisitions/Contracting Officers, Custodians]:
1. An access control policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
2. Procedures to facilitate the implementation of the access control policy and associated access controls; and
b. Reviews and updates the current:
1. Access control policy [biennially]; and
2. Access control procedures [biennially].
| AC-1 |
| Control Summary Information |
Implementation Status:
|_| Implemented |_| Partially Implemented |_| Planned |_| Alternative implementation |_| Not applicable
Control Origination:
|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP) |_| System Specific Control
AC-1 Describe how the control is implemented.
Part a
Part b
AC-2: Account Management The organization:
a. Identifies and selects the following types of information system accounts to support organizational missions/business functions: [minimum - System Administrator, Network Administrator, Application Administrator, Database Administrator, Identifying account types. Standard and elevated privilege user accounts. (i.e., individual, group, system, application, guest/anonymous, and temporary)];
b. Assigns account managers for information system accounts;
c. Establishes conditions for group and role membership;
d. Specifies authorized users of the information system, group and role membership, and access authorizations (i.e., privileges) and other attributes (as required) for each account;
e. Requires approvals by [System Owner and Organizational and government personnel with access control responsibilities of the authorization boundary] for requests to create information system accounts;
f. Creates, enables, modifies, disables, and removes information system accounts in accordance with [SCAP Benchmark, NIST Security Configuration Checklist, DISA Security Technical Implementation Guides (STIGs) and/or NSA Guides]
g. Monitors the use of information system accounts;
h. Notifies account managers:
1. When accounts are no longer required;
2. When users are terminated or transferred; and
3. When individual information system usage or need-to-know changes;
i. Authorizes access to the information system based on:
1. A valid access authorization;
2. Intended system usage; and
3. Other attributes as required by the organization or associated missions/business functions;
j. Reviews accounts for compliance with account management requirements [annually]; and
k. Establishes a process for reissuing shared/group account credentials (if deployed) when individuals are removed from the group.
| AC-2 |
| Control Summary Information |
Implementation Status:
|_| Implemented |_| Partially Implemented |_| Planned |_| Alternative implementation |_| Not applicable
Control Origination:
|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP)
AC-2 Describe how the control is implemented.
Part a
Part b
Part c
Part d
Part e
Part f
Part g
Part h
Part i
Part j
Part k
AC-2 (1): Account Management | Automated System Account Management The organization employs automated mechanisms to support the management of information system accounts.
| AC-2 (1) |
| Control Enhancement Summary Information |
Implementation Status:
|_| Implemented |_| Partially Implemented |_| Planned |_| Alternative implementation |_| Not applicable
Control Origination:
|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP)
AC-2 (1) Describe how the control is implemented.
AC-2 (2): Account Management | Removal of Temporary/Emergency Accounts The information system automatically [disables] temporary and emergency accounts after [no more than 90 days].
| AC-2 (2) |
| Control Enhancement Summary Information |
Implementation Status:
|_| Implemented |_| Partially Implemented |_| Planned |_| Alternative implementation |_| Not applicable
Control Origination:
|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP)
AC-2 (2) Describe how the control is implemented.
AC-2 (3): Account Management | Disable Inactive Accounts The information system automatically disables inactive accounts after [90 Days for User Level Accounts, 35 days for non-user level accounts].
| AC-2 (3) |
| Control Enhancement Summary Information |
Implementation Status:
|_| Implemented |_| Partially Implemented |_| Planned |_| Alternative implementation |_| Not applicable
Control Origination:
|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP)
AC-2 (3) Describe how the control is implemented.
AC-2 (4): Account Management | Automated Audit Actions The information system automatically audits account creation, modification, enabling, disabling, and removal actions, and notifies [Administrators (Application, System, Network, etc.), Information System Security Officer, Information System Security Manager, System Program Managers, and System Project Managers].
| AC-2 (4) |
| Control Enhancement Summary Information |
Implementation Status:
|_| Implemented |_| Partially Implemented |_| Planned |_| Alternative implementation |_| Not applicable
Control Origination:
|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP)
AC-2 (4) What is the solutions and how is it implemented?
AC-3: Access Enforcement The information system enforces approved authorizations for logical access to information and system resources in accordance with applicable access control policies.
| AC-3 |
| Control Summary Information |
Implementation Status:
|_| Implemented |_| Partially Implemented |_| Planned |_| Alternative implementation |_| Not applicable
Control Origination:
|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP)
AC-3 Describe how the control is implemented.
AC-4: Information Flow Enforcement The information system enforces approved authorizations for controlling the flow of information within the system and between interconnected systems based on [Web Service Security (WS Security), WS-Security Policy, WS Trust, WS Policy Framework, Security Assertion Markup Language (SAML), eXtensible Access Control Markup Language (XACML)].
| AC-4 |
| Control Summary Information |
Implementation Status:
|_| Implemented |_| Partially Implemented |_| Planned |_| Alternative implementation |_| Not applicable
Control Origination:
|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP)
AC-4 Describe how the control is implemented.
AC-5: Separation of Duties
a. Separates [using the roles and responsibilities as a foundation, Data Owners can identify specific types of users that can be authorized to obtain access to each IT resource for functions such as these:
· General user activities (e.g., resource or file access)
· System development (e.g., programmers and database)
· Technical operations and system or network administration];
b. Documents separation of duties of individuals; and
c. Defines information system access authorizations to support separation of duties.
| AC-5 |
| Control Summary Information |
Implementation Status:
|_| Implemented |_| Partially Implemented |_| Planned |_| Alternative implementation |_| Not applicable
Control Origination:
|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP)
AC-5 Describe how the control is implemented.
Part a
Part b
Part c
AC-6: Least Privilege The organization employs the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with organizational missions and business functions.
| AC-6 |
| Control Summary Information |
Implementation Status:
|_| Implemented |_| Partially implemented |_| Planned |_| Alternative implementation |_| Not applicable
Control Origination:
|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP)
AC-6 Describe how the control is implemented.
AC-6 (1): Least Privilege | Authorize Access to Security Functions The organization explicitly authorizes access to [Contractor recommendation to be approved and accepted by the AO].
| AC-6 (1) |
| Control Enhancement Summary Information |
Implementation Status:
|_| Implemented |_| Partially implemented |_| Planned |_| Alternative implementation |_| Not applicable
Control Origination:
|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP) |_| System Specific Control
AC-6 (1) Describe how the control is implemented.
AC-6 (2): Least Privilege | Non-Privileged Access for Nonsecurity Functions The organization requires that users of information system accounts, or roles, with access to [all Security Functions (examples of security functions include but are not limited to: establishing system accounts, configuring access authorizations (i.e., permissions, privileges), setting events to be audited, and setting intrusion detection parameters, system programming, system and security administration, other privileged functions)], use non-privileged accounts or roles, when accessing nonsecurity functions.
| AC-6 (2) |
| Control Enhancement Summary Information |
Implementation Status:
|_| Implemented |_| Partially implemented |_| Planned |_| Alternative implementation |_| Not applicable
Control Origination:
|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP) |_| System Specific Control
AC-6 (2) Describe how the control is implemented.
AC-6 (5): Least Privilege | Privileged Accounts The organization restricts privileged accounts on the information system to [Employees who have resource administrative access (such as system administrators, database administrators, telecom administrators, developers, etc.)].
| AC-6 (5) |
| Control Enhancement Summary Information |
Implementation Status:
|_| Implemented |_| Partially Implemented |_| Planned |_| Alternative implementation |_| Not applicable
Control Origination:
|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP) |_| System Specific Control
AC-6 (5) Describe how the control is implemented.
AC-6 (9): Least Privilege | Auditing Use of Privileged Functions The information system audits the execution of privileged functions.
| AC-6 (9) |
| Control Enhancement Summary Information |
Implementation Status:
|_| Implemented |_| Partially Implemented |_| Planned |_| Alternative implementation |_| Not applicable
Control Origination:
|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP) |_| System Specific Control
AC-6 (9) Describe how the control is implemented.
AC-6 (10): Least Privilege | Prohibit Non-Privileged Users from Executing Privileged Functions The information system prevents non-privileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures.
| AC-6 (10) |
| Control Enhancement Summary Information |
Implementation Status:
|_| Implemented |_| Partially Implemented |_| Planned |_| Alternative implementation |_| Not applicable
Control Origination:
|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP) |_| System Specific Control
AC-6 (10) Describe how the control is implemented.
AC-7: Unsuccessful Login Attempts The information system:
a. Enforces a limit of [not more than ten (10) failed access attempts] consecutive invalid logon attempts by a user during a [30 minute time period]; and
b. Automatically [locks the account/node for [30 minutes]; locks the account/node until released by an administrator; delays next logon prompt for [30 minutes]] when the maximum number of unsuccessful attempts is exceeded.
| AC-7 |
| Control Summary Information |
Implementation Status:
|_| Implemented |_| Partially Implemented |_| Planned |_| Alternative implementation |_| Not applicable
Control Origination:
|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP) |_| System Specific Control
AC-7 Describe how the control is implemented.
Part a
Part b
AC-8: System Use Notification
a. Displays to users [a warning banner/system use notification message] before granting access to the system that provides privacy and security notices consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance and states that:
1. Users are accessing a U.S. Government information system;
2. Information system usage may be monitored, recorded, and subject to audit;
3. Unauthorized use of the information system is prohibited and subject to criminal and civil penalties; and
4. Use of the information system indicates consent to monitoring and recording;
b. Retains the notification message or banner on the screen until users acknowledge the usage conditions and take explicit actions to log on to or further access the information system; and
c. For publicly accessible systems:
1. Displays system use information [when access via logon interfaces with human users], before granting further access;
2. Displays references, if any, to monitoring, recording, or auditing that are consistent with privacy accommodations for such systems that generally prohibit those activities; and
3. Includes a description of the authorized uses of the system.
| AC-8 |
| Control Summary Information |
Implementation Status:
|_| Implemented |_| Partially Implemented |_| Planned |_| Alternative implementation |_| Not applicable
Control Origination:
|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP) |_| System Specific Control
AC-8 Describe how the control is implemented.
Part a
Part b
Part c
AC-11: Session Lock
a. Prevents further access to the system by initiating a session lock after [15 minutes] of inactivity or upon receiving a request from a user; and
b.…
This is the start of the file's text. The full file is on GovTribe.
Other files for this federal contract opportunity
Show all 24
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
File details come from the government source that posted it.