20 - IPS Requirement Document 1C CSP

8 MB Posted

Attached to
Professional Service Schedule Federal contract opportunity
Solicitation number
FCO00CORP0000C
Issued by
GSA Federal Acquisition Service

About this file

20 - IPS Requirement Document 1C CSP

Text of this file

[SYSTEM NAME] [ACRONYM]

System Security Plan [Date]

Identity Protection Services (IPS) IPS Requirements Document 1C in Support of SIN 520-20 dtd November 2017 (PSS Refresh #36)

Document Prepared By Company Representative Responsible for this Plan (Name, Position)

Company Name

Address Line 1

Address Line 2

City, State Zip

E-mail Address

Phone Number

Identity Protection Services (IPS) IPS 520-20 Requirements Document 1C dtd November 2017 (PSS Refresh #34)

Document Revision History

Date
Comments
Version
Author
[Date]
Initial Version
1.0
[Name]

AttachmentsInstruction: Attachments may vary on a system-by-system basis. The following appendices are considered standard SSP attachments. They are not required as part of this submission, but may be required at the task order level.

Attachment 1: Privacy Impact Assessment Attachment 2: FIPS 199 Security Categorization Attachment 3: e-Authentication Assurance Level Attachment 4: Interconnection Security Agreement(s)/Memoranda of Understanding Attachment 5: Control Tailoring Workbook Attachment 6: Control Summary Table (based on FIPS 199 Categorization) Attachment 7: Contingency Plan Attachment 8: Contingency Plan Test Report Attachment 9: Incident Response Plan Attachment 10: Incident response Plan Test Report Attachment 11: Configuration Management Plan Attachment 12: Continuous Monitoring Plan (if applicable) Attachment 13: Rules of Behavior (if applicable) Attachment 14: Code Review Report (if applicable) Other Attachments, as necessary

Table of Contents

1Information System Name1
2Information System Categorization1
2.1Information Types1
2.2Potential Impacts of Security Objectives2
2.3E-Authentication Determination (E-Auth)2
3Information System Owner3
4Authorizing Official3
5Other Designated Contacts4
6Assignment of Security Responsibility4
7Information System Operational Status5
8Information System Type5
8.1Systems Providing Controls to [ACRONYM]5
8.2Systems Receiving Controls from [ACRONYM]5
9General System Description6
9.1Information System Locations6
9.2Information System Components and Boundaries6
9.3Types of Users7
9.4Network Architecture7
10System Environment8
10.1Asset Inventory8
10.2Software Inventory8
10.3Data Flow9
10.4Ports, Protocols and Services9
11System Interconnections10
12Applicable Laws and Regulations12
13Minimum Security Controls13
13.1Access Control13
13.1.1AC-1: Access Control Policy and Procedures13
13.1.2AC-2: Account Management14
13.1.3AC-2 (1): Account Management | Automated System Account Management16
13.1.4AC-2 (2): Account Management | Removal of Temporary/Emergency Accounts17
13.1.5AC-2 (3): Account Management | Disable Inactive Accounts17
13.1.6AC-2 (4): Account Management | Automated Audit Actions18
13.1.7AC-3: Access Enforcement18
13.1.8AC-4: Information Flow Enforcement19
13.1.9AC-5: Separation of Duties20
13.1.10AC-6: Least Privilege21
13.1.11AC-6 (1): Least Privilege | Authorize Access to Security Functions21
13.1.12AC-6 (2): Least Privilege | Non-Privileged Access for Nonsecurity Functions22
13.1.13AC-6 (5): Least Privilege | Privileged Accounts23
13.1.14AC-6 (9): Least Privilege | Auditing Use of Privileged Functions23
13.1.15AC-6 (10): Least Privilege | Prohibit Non-Privileged Users from Executing Privileged Functions24
13.1.16AC-7: Unsuccessful Login Attempts24
13.1.17AC-8: System Use Notification25
13.1.18AC-11: Session Lock26
13.1.19AC-11 (1): Session Lock | Pattern Hiding Displays27
13.1.20AC-12: Session Termination28
13.1.21AC-14: Permitted Actions Without Identification or Authentication28
13.1.22AC-17: Remote Access29
13.1.23AC-17 (1): Remote Access | Automated Monitoring/Control30
13.1.24AC-17 (2): Remote Access | Protection of Confidentiality/Integrity Using Encryption30
13.1.25AC-17 (3): Remote Access | Managed Access Control Points31
13.1.26AC-17 (4): Remote Access | Privileged Commands/Access31
13.1.27AC-18: Wireless Access32
13.1.28AC-18 (1): Wireless Access | Authentication and Encryption33
13.1.29AC-19: Access Control for Mobile Devices33
13.1.30AC-19 (5): Access Control for Wireless Devices | Full Device / Container Based Encryption34
13.1.31AC-20: Use of External Information Systems35
13.1.32AC-20 (1): Use of External Information Systems | Limits on Authorized Use36
13.1.33AC-20 (2): Use of External Information Systems | Portable Storage Devices36
13.1.34AC-21: Information Sharing37
13.1.35AC-22: Publicly Accessible Content38
13.2Awareness and Training39
13.2.1AT-1: Security Awareness and Training Policy and Procedures39
13.2.2AT-2: Security Awareness Training40
13.2.3AT-2 (2): Security Awareness Training | Insider Threat41
13.2.4AT-3: Role-Based Security Training41
13.2.5AT-4: Security Training Records42
13.3Audit and Accountability43
13.3.1AU-1: Audit and Accountability Policy and Procedures43
13.3.2AU-2: Audit Events44
13.3.3AU-2 (3): Auditable Events | Reviews and Updates45
13.3.4AU-3: Content of Audit Records46
13.3.5AU-3 (1): Content of Audit Records | Additional Audit Information46
13.3.6AU-4: Audit Storage Capacity47
13.3.7AU-5: Response to Audit Processing Failures48
13.3.8AU-6: Audit Review, Analysis, and Reporting48
13.3.9AU-6 (1): Audit Review, Analysis, and Reporting | Process Integration49
13.3.10AU-6 (3): Audit Review, Analysis, and Reporting | Correlate Audit Repositories50
13.3.11AU-7: Audit Reduction and Report Generation50
13.3.12AU-7 (1): Audit Reduction and Report Generation | Automatic Processing51
13.3.13AU-8: Time Stamps52
13.3.14AU-8 (1): Time Stamps | Synchronization with Authoritative Time Source53
13.3.15AU-9: Protection of Audit Information54
13.3.16AU-9 (4): Protection of Audit Information | Access by Subset of Privileged Users54
13.3.17AU-11: Audit Record Retention55
13.3.18AU-12: Audit Generation55
13.4Security Assessment and Authorization56
13.4.1CA-1: Security Assessment and Authorization Policy and Procedures56
13.4.2CA-2: Security Assessments57
13.4.3CA-2 (1): Security Assessments | Independent Assessors58
13.4.4CA-3: System Interconnections59
13.4.5CA-3 (5): System Interconnections | Restrictions on External System Connections60
13.4.6CA-5: Plan of Action and Milestones61
13.4.7CA-6: Security Authorization61
13.4.8CA-7: Continuous Monitoring62
13.4.9CA-7 (1): Continuous Monitoring | Independent Assessment64
13.4.10CA-8: Penetration Testing64
13.4.11CA-8 (1): Penetration Testing | Independent Penetration Agent or Team65
13.4.12CA-9: Internal System Connections66
13.5Configuration Management66
13.5.1CM-1: Configuration Management Policy and Procedures66
13.5.2CM-2: Baseline Configuration67
13.5.3CM-2 (1): Baseline Configuration | Reviews and Updates68
13.5.4CM-2 (2): Baseline Configuration | Automation Support for Accuracy / Currency69
13.5.5CM-2 (3): Baseline Configuration | Retention of Previous Configurations69
13.5.6CM-2 (7): Baseline Configuration | Configure Systems, Components, or Devices for High-Risk Areas70
13.5.7CM-3: Configuration Change Control71
13.5.8CM-3 (2): Configuration Change Control | Test/Validate/Document Changes72
13.5.9CM-4: Security Impact Analysis73
13.5.10CM-5: Access Restrictions for Change73
13.5.11CM-6: Configuration Settings74
13.5.12CM-6 (1): Configuration Settings | Automated Central Management / Application / Verification75
13.5.13CM-7: Least Functionality76
13.5.14CM-7 (1): Least Functionality | Periodic Review77
13.5.15CM-7 (2): Least Functionality | Prevent Program Execution78
13.5.16CM-7 (4): Least Functionality | Unauthorized Software/Blacklisting78
13.5.17CM-8: Information System Component Inventory79
13.5.18CM-8 (1): Information System Component Inventory | Updates During Installations / Removals80
13.5.19CM-8 (2): Information System Component Inventory | Automated Maintenance81
13.5.20CM-8 (3): Information System Component Inventory | Automated Unauthorized Component Detection81
13.5.21CM-8 (5): Information System Component Inventory | No Duplicate Accounting of Components82
13.5.22CM-8 (6): Information System Component Inventory | Assessed Configurations / Approved Deviations83
13.5.23CM-9: Configuration Management Plan83
13.5.24CM-10: Software Usage Restrictions84
13.5.25CM-11: User-Installed Software85
13.6Contingency Planning86
13.6.1CP-1: Contingency Planning Policy and Procedures86
13.6.2CP-2: Contingency Plan87
13.6.3CP-2 (1): Contingency Plan | Coordinate With Related Plans89
13.6.4CP-2 (3): Contingency Plan | Resume Essential Missions/Business Functions89
13.6.5CP-2 (8): Contingency Plan | Identify Critical Assets90
13.6.6CP-3: Contingency Training91
13.6.7CP-4: Contingency Plan Testing91
13.6.8CP-4 (1): Contingency Plan Testing | Coordinate With Related Plans92
13.6.9CP-6: Alternate Storage Site93
13.6.10CP-6 (1): Alternate Storage Site | Separation from Primary Site94
13.6.11CP-6 (3): Alternate Storage Site | Accessibility94
13.6.12CP-7: Alternate Processing Site95
13.6.13CP-7 (1): Alternate Processing Site | Separation from Primary Site96
13.6.14CP-7 (2): Alternate Processing Site | Accessibility96
13.6.15CP-7 (3): Alternate Processing Site | Priority of Service97
13.6.16CP-8: Telecommunication Services98
13.6.17CP-8 (1): Telecommunication Services | Priority of Service Provisions98
13.6.18CP-8 (2): Telecommunication Services | Single Points of Failure99
13.6.19CP-9: Information System Backup100
13.6.20CP-9 (1): Information System Backup | Testing for Reliability/Integrity101
13.6.21CP-10: Information System Recovery and Reconstitution101
13.6.22CP-10 (2): Information System Recovery and Reconstitution | Transaction Recovery102
13.7Identification and Authentication103
13.7.1IA-1: Identification and Authentication Policy and Procedures103
13.7.2IA-2: Identification and Authentication (Organizational Users)104
13.7.3IA-2 (1): Identification and Authentication (Organizational Users) | Network Access to Privileged Accounts104
13.7.4IA-2 (2): Identification and Authentication (Organizational Users) | Network Access to Non-Privileged Accounts105
13.7.5IA-2 (3): Identification and Authentication (Organizational Users) | Local Access to Privileged Accounts105
13.7.6IA-2 (8): Identification and Authentication (Organizational Users) |Network Access to Privileged Accounts – Replay Resistant106
13.7.7IA-2 (11): Identification and Authentication (Organizational Users) | Remote Access – Separate Device107
13.7.8IA-2 (12): Identification and Authentication (Organizational Users) | Acceptance of PIV Credentials107
13.7.9IA-3: Device Identification and Authentication108
13.7.10IA-4: Identifier Management109
13.7.11IA-5: Authenticator Management110
13.7.12IA-5 (1): Authenticator Management | Password-Based Authentication112
13.7.13IA-5 (2): Authenticator Management | PKI-Based Authentication113
13.7.14IA-5 (3): Authenticator Management | In-Person or Trusted Third-Party Registration114
13.7.15IA-5 (11): Authenticator Management | Hardware Token-Based Authentication115
13.7.16IA-6: Authenticator Feedback115
13.7.17IA-7: Cryptographic Module Authentication116
13.7.18IA-8: Identification and Authentication (Non-Organizational Users)117
13.7.19IA-8 (1): Identification and Authentication (Non-Organizational Users) | Acceptance of PIV Credentials from Other Agencies117
13.7.20IA-8 (2): Identification and Authentication (Non-Organizational Users) | Acceptance of Third-Party Credentials118
13.7.21IA-8 (3): Identification and Authentication (Non-Organizational Users) | Use of FICAM-Approved Products118
13.7.22IA-8 (4): Identification and Authentication (Non-Organizational Users) | Use of FICAM-Issued Profiles119
13.8Incident Response120
13.8.1IR-1: Incident Response Policy and Procedures120
13.8.2IR-2: Incident Response Training121
13.8.3IR-3: Incident Response Testing122
13.8.4IR-3 (2): Incident Response Testing | Coordination with Related Plans122
13.8.5IR-4: Incident Handling123
13.8.6IR-4 (1): Incident Handling | Automated Incident Handling Processes124
13.8.7IR-5: Incident Monitoring124
13.8.8IR-6: Incident Reporting125
13.8.9IR-6 (1): Incident Reporting | Automated Reporting126
13.8.10IR-7: Incident Response Assistance126
13.8.11IR-7 (1): Incident Response Assistance | Automation Support for Availability of Information/Support127
13.8.12IR-8: Incident Response Plan127
13.9Maintenance129
13.9.1MA-1: System Maintenance Policy and Procedures129
13.9.2MA-2: Controlled Maintenance130
13.9.3MA-3: Maintenance Tools131
13.9.4MA-3 (1): Maintenance Tools | Inspect Tools132
13.9.5MA-3 (2): Maintenance Tools | Inspect Media133
13.9.6MA-4: Nonlocal Maintenance133
13.9.7MA-4 (2): Nonlocal Maintenance | Document Nonlocal Maintenance134
13.9.8MA-5: Maintenance Personnel135
13.9.9MA-6: Timely Maintenance136
13.10Media Protection136
13.10.1MP-1: Media Protection Policy and Procedures136
13.10.2MP-2: Media Access137
13.10.3MP-3: Media Marking138
13.10.4MP-4: Media Storage139
13.10.5MP-5: Media Transport140
13.10.6MP-5 (4): Media Transport | Cryptographic Protection141
13.10.7MP-6: Media Sanitization141
13.10.8MP-7: Media Use142
13.10.9MP-7 (1): Media Use | Prohibit Use Without Owner143
13.11Physical and Environmental Protection143
13.11.1PE-1: Physical and Environmental Protection Policy and Procedures143
13.11.2PE-2: Physical Access Authorizations144
13.11.3PE-3: Physical Access Control145
13.11.4PE-4: Access Control for Transmission Medium147
13.11.5PE-5: Access Control for Output Devices147
13.11.6PE-6: Monitoring Physical Access148
13.11.7PE-6 (1): Monitoring Physical Access | Intrusion Alarms/Surveillance Equipment149
13.11.8PE-8: Visitor Access Records149
13.11.9PE-9: Power Equipment and Cabling150
13.11.10PE-10: Emergency Shutoff151
13.11.11PE-11: Emergency Power152
13.11.12PE-12: Emergency Lighting152
13.11.13PE-13: Fire Protection153
13.11.14PE-13 (3): Fire Protection | Automatic Fire Suppression153
13.11.15PE-14: Temperature and Humidity Controls154
13.11.16PE-15: Water Damage Protection155
13.11.17PE-16: Delivery and Removal155
13.11.18PE-17: Alternate Work Site156
13.12Planning157
13.12.1PL-1: Security Planning Policy and Procedures157
13.12.2PL-2: System Security Plan158
13.12.3PL-2 (3): System Security Plan | Coordinate with Other Organizational Entities159
13.12.4PL-4: Rules of Behavior160
13.12.5PL-4 (1): Rules of Behavior | Social Media and Networking Restrictions161
13.12.6PL-8: Information Security Architecture162
13.13Personnel Security163
13.13.1PS-1: Personnel Security Policy and Procedures163
13.13.2PS-2: Position Risk Designation163
13.13.3PS-3: Personnel Screening164
13.13.4PS-4: Personnel Termination165
13.13.5PS-5: Personnel Transfer166
13.13.6PS-6: Access Agreements167
13.13.7PS-7: Third-Party Personnel Security168
13.13.8PS-8: Personnel Sanctions169
13.14Risk Assessment170
13.14.1RA-1: Risk Assessment Policy and Procedures170
13.14.2RA-2: Security Categorization171
13.14.3RA-3: Risk Assessment172
13.14.4RA-5: Vulnerability Scanning173
13.14.5RA-5 (1): Vulnerability Scanning | Update Tool Capability175
13.14.6RA-5 (2): Vulnerability Scanning | Update by Frequency / Prior to New Scan / When Identified175
13.14.7RA-5 (5): Vulnerability Scanning | Privileged Access176
13.15System and Services Acquisition176
13.15.1SA-1: System and Services Acquisition Policy and Procedures176
13.15.2SA-2: Allocation of Resources177
13.15.3SA-3: System Development Life Cycle178
13.15.4SA-4: Acquisition Process179
13.15.5SA-4 (1): Acquisition Process | Functional Properties of Security Controls181
13.15.6SA-4 (2): Acquisition Process | Design / Implementation Information for Security Controls181
13.15.7SA-4 (9): Acquisition Process | Functions / Ports / Protocols / Services in Use182
13.15.8SA-4 (10): Acquisition Process | Use of Approved PIV Products183
13.15.9SA-5: Information System Documentation183
13.15.10SA-8: Security Engineering Principles185
13.15.11SA-9: External Information System Services185
13.15.12SA-9 (2): External Information System Services | Identification of Functions / Ports / Protocols/ Services186
13.15.13SA-10: Developer Configuration Management187
13.15.14SA-11: Developer Security Testing and Evaluation188
13.15.15SA-22: Unsupported System Components189
13.16System and Communications Protection190
13.16.1SC-1: System and Communications Protection Policy and Procedures190
13.16.2SC-2: Application Partitioning191
13.16.3SC-4: Information In Shared Resources192
13.16.4SC-5: Denial of Service Protection192
13.16.5SC-7: Boundary Protection193
13.16.6SC-7 (3): Boundary Protection | Access Points194
13.16.7SC-7 (4): Boundary Protection | External Telecommunication Services194
13.16.8SC-7 (5): Boundary Protection | Deny by Default / Allow by Exception195
13.16.9SC-7 (7): Boundary Protection | Prevent Split Tunneling for Remote Devices196
13.16.10SC-8: Transmission Confidentiality and Integrity196
13.16.11SC-8 (1): Transmission Confidentiality and Integrity | Cryptographic or Alternate Physical Protection197
13.16.12SC-10: Network Disconnect197
13.16.13SC-12: Cryptographic Key Establishment & Management198
13.16.14SC-13: Cryptographic Protection199
13.16.15SC-15: Collaborative Computing Devices199
13.16.16SC-17: Public Key Infrastructure Certificates200
13.16.17SC-18: Mobile Code201
13.16.18SC-19: Voice Over Internet Protocol202
13.16.19SC-20: Secure Name/Address Resolution Service (Authoritative Source)202
13.16.20SC-21: Secure Name/Address Resolution Service (Recursive or Caching Resolver)203
13.16.21SC-22: Architecture and Provisioning for Name/Address Resolution Service204
13.16.22SC-23: Session Authenticity204
13.16.23SC-28: Protection of Information at Rest205
13.16.24SC-28 (1): Protection of Information at Rest | Cryptographic Protection206
13.16.25SC-39: Process Isolation206
13.17System and Information Integrity207
13.17.1SI-1: System and Information Integrity Policy and Procedures207
13.17.2SI-2: Flaw Remediation208
13.17.3SI-2 (2): Flaw Remediation | Automated Flaw Remediation Status209
13.17.4SI-2 (3): Flaw Remediation | Time to Remediate Flaws / Benchmarks for Corrective Actions209
13.17.5SI-3: Malicious Code Protection210
13.17.6SI-3 (1): Malicious Code Protection | Central Management211
13.17.7SI-3 (2): Malicious Code Protection | Automatic Updates212
13.17.8SI-3 (7): Malicious Code Protection | Nonsignature-Based Detection212
13.17.9SI-4: Information System Monitoring213
13.17.10SI-4 (2): Information System Monitoring | Automated Tools for Real-Time Analysis215
13.17.11SI-4 (4): Information System Monitoring | Inbound and Outbound Communications Traffic215
13.17.12SI-4 (5): Information System Monitoring | System-Generated Alerts216
13.17.13SI-5: Security Alerts, Advisories, and Directives217
13.17.14SI-7: Software, Firmware, and Information Integrity217
13.17.15SI-7 (1): Software, Firmware, and Information Integrity | Integrity Checks218
13.17.16SI-7 (7): Software, Firmware, and Information Integrity | Integration of Detection and Response219
13.17.17SI-8: Spam Protection219
13.17.18SI-8 (1): Spam Protection | Central Management220
13.17.19SI-8 (2): Spam Protection | Automatic Updates220
13.17.20SI-10: Information Input Validation221
13.17.21SI-11: Error Handling222
13.17.22SI-12: Information Handling and Retention223
13.17.23SI-16: Memory Protection223
14Privacy Controls225
14.1Authority and Purpose225
14.1.1AP-1: Authority to Collect225
14.1.2AP-2: Purpose Specification225
14.2Accountability, Audit, and Risk Management226
14.2.1AR-1: Governance and Privacy Program226
14.2.2AR-2: Privacy Impact and Risk Assessment227
14.2.3AR-3: Privacy Requirements For Contractors and Service Providers227
14.2.4AR-4: Privacy Monitoring and Auditing228
14.2.5AR-5: Privacy Awareness and Training229
14.2.6AR-6: Privacy Reporting229
14.2.7AR-7: Privacy-Enhanced System Design and Development230
14.2.8AR-8: Accounting of Disclosures230
14.3Data Quality and Integrity231
14.3.1DI-1: Data Quality231
14.3.2DI-2: Data Integrity and Data Integrity Board232
14.3.3DM-1: Minimization of Personally Identifiable Information (PII)232
14.3.4DM-2: Data Retention and Disposal233
14.3.5DM-3: Minimization of PII used in Testing, Training, and Research234
14.4Individual Participation and Redress235
14.4.1IP-1: Consent235
14.4.2IP-2: Individual Access235
14.4.3IP-3: Redress236
14.4.4IP-4: Complaint Management237
14.5Security237
14.5.1SE-1: Inventory of Personally Identifiable Information237
14.5.2SE-2: Privacy Incident Response238
14.6Transparency239
14.6.1TR-1: Privacy Notice239
14.6.2TR-2: System of Records Notices and Privacy Act Statements239
14.6.3TR-3: Dissemination of Privacy Program Information240
14.7Use Limitation241
14.7.1UL-1: Internal Use241
14.7.2UL-2: Information Sharing with Third Parties241
APPENDIX A – Acronyms, Terms and Definitions243
APPENDIX B – References251
APPENDIX C – Hosted Subsystems (if applicable)253
Other Appendices, as necessary254

Tables and Figures

Table 11. Information System Name and Identifier1
Table 21. Overall Information System Categorization1
Table 22. Information System Types2
Table 23. Security Objective Impacts2
Table 24. E-Authentication Determination2
Table 25. E-Authentication Assurance Level Summary3
Table 71. System Operational Status5
Table 81. Systems Providing Controls5
Table 82. Systems Receiving Controls6
Table 91. System Locations6
Table 92. System Assets6
Table 93. User Roles and Privileges7
Table 101. Asset Physical and Virtual Components8
Table 102. Software Components8
Table 103. Ports, Protocols, and Services9
Table 111. System Interconnections10
Table 112. Connection Details of Interconnected Systems11
Figure 91. Network Diagram8
Figure 101. Data Flow Diagram9

Page ix

Information System Name This System Security Plan (SSP) provides an overview of the security requirements for the [SYSTEM NAME] [ACRONYM] and describes the controls in place or planned for implementation to provide a level of security appropriate for the information to be transmitted, processed or stored by the system.

The security safeguards implemented for the [ACRONYM] meet the policy and control requirements as set forth in this SSP. All systems are subject to monitoring consistent with applicable laws, regulations, agency policies, procedures and practices.

Table 11. Information System Name and Identifier IT Investment Portfolio Summary ID:

Information System Name:
[ACRONYM]
Information System Abbreviation:
[ACRONYM]

Information System Categorization The overall information system security categorization is noted in the following table.

Note: A FIPS 199 Security Categorization document must be completed and submitted as an Attachment to this SSP.

Table 21. Overall Information System Categorization

Low
|_|
Moderate
|_|
High
|_|

Information Types The following tables identify the information types and impact levels that are input, stored, processed, and/or output from the [ACRONYM] environment. The security impact levels for confidentiality, integrity, and availability for each of the information types are expressed as low, moderate, or high. The security impact levels are based on the potential impact definitions for each of the security objectives (i.e., confidentiality, integrity, and availability) discussed in NIST SP 800-60 and FIPS Pub 199 (Note: The information types found in NIST SP 800-60, Volumes I and II, Revision 1 are the same information types found in the Federal Enterprise Architecture (FEA) Consolidated Reference Model).

Table 22. Information System Types

Information Type
Confidentiality
Integrity
Availability
[First Type]
Low
Moderate
Low
[Second Type]
Low
Moderate
Low
[Third Type]
Moderate
Moderate
Moderate

Potential Impacts of Security Objectives Based on the information provided above, the potential impacts for each security objective, per FIPS 199) for the [ACRONYM] environment is summarized in the table below.

Table 23. Security Objective Impacts

Security Objective
Low, Moderate or High
Confidentiality
Moderate
Integrity
Moderate
Availability
Moderate

E-Authentication Determination (E-Auth) The information system e-Authentication determination is described in the following table.

Instruction: Any information system that has a “No” response to any one of the three questions does not need an E-Authentication risk analysis or assessment. For a system that has a "Yes" response to all of the questions, complete the E-Authentication Plan (a template is available).

Table 24. E-Authentication Determination

Yes
No
E-Authentication Questions
|_|
|_|
Does the system require authentication via the Internet?
|_|
|_|
Is data being transmitted over the Internet via browsers?
|_|
|_|
Do users connect to the system from over the Internet?

The summary E-Authentication Assurance Level is recorded in the following table.

Note: A e-Authentication Assurance Level document must be completed and submitted as an Attachment to this SSP.

Table 25. E-Authentication Assurance Level Summary E-Authentication Assurance Level

System Name:
[SYSTEM NAME]
System Owner:
[Organization]
Assurance Level:
[E-AUTHENTICAION LEVEL NUMBER]
Date Approved:
[Date]

Information System Owner The following individual is identified as the System Owner/Program Manager for this system.

Name

Title

Organization

Address

Phone Number

Email Address

Authorizing Official The Authorizing Official (AO) for this information system is identified below.

Name

Title

Organization

Address

Phone Number

Email Address

Other Designated Contacts The individual(s) identified below possess in-depth knowledge of this system and/or its functions and operation.

Name

Title

Organization

Address

Phone Number

Email Address

Name

Title

Organization

Address

Phone Number

Email Address

Assignment of Security Responsibility The Information System Security Officer (ISSO) has been appointed and is identified below.

Name

Title

Organization

Address

Phone Number

Email Address

Information System Operational Status The system is currently in the life-cycle phase noted in the following table.

Table 71. System Operational Status System Status

|_|
Operational
The system is operating and in production.
|_|
Under Development
The system is being designed, developed, or implemented.
|_|
Major Modification
The system is undergoing a major change, development, or transition.
|_|
Other
Explain:

Information System Type The [ACRONYM] is a [General Support System (GSS)/Major Application (MA)/Subsystem].

Systems Providing Controls to [ACRONYM] The systems identified in the following table provide controls (common or hybrid) to [ACRONYM]. List all systems providing controls, the controls they provide, and identify if it is provided as a Common or Hybrid control.

Table 81. Systems Providing Controls

[Providing System Name]
[Providing System Owner]
[Providing System ATO Date]
[Control Identifier]
[Control Name]
Common/Hybrid
[Control Identifier]
[Control Name]
Common/Hybrid
[Control Identifier]
[Control Name]
Common/Hybrid
[Providing System Name]
[Providing System Owner]
[Providing System ATO Date]
[Control Identifier]
[Control Name]
Common/Hybrid
[Control Identifier]
[Control Name]
Common/Hybrid
[Control Identifier]
[Control Name]
Common/Hybrid

Systems Receiving Controls from [ACRONYM] [ACRONYM] provides the controls (common or hybrid) listed to the systems identified in the following table. List any controls provided to any systems and identify if it is provided as a Common or Hybrid control.

Table 82. Systems Receiving Controls

[Receiving System Name]
[Receiving System Owner]
[Receiving System ATO Date]
[Control Identifier]
[Control Name]
Common/Hybrid
[Control Identifier]
[Control Name]
Common/Hybrid
[Control Identifier]
[Control Name]
Common/Hybrid
[Receiving System Name]
[Receiving System Owner]
[Receiving System ATO Date]
[Control Identifier]
[Control Name]
Common/Hybrid
[Control Identifier]
[Control Name]
Common/Hybrid
[Control Identifier]
[Control Name]
Common/Hybrid

General System Description (Provide a general description of the system, including its function and purpose).

Information System Locations Physically, the [ACRONYM] environment resides at the locations identified below.

Table 91. System Locations Primary Secondary

Secondary (if applicable) Secondary

Information System Components and Boundaries The components of the [ACRONYM] environment can be broken down into the following groups of asset types. The assets are also portrayed in the network diagram in Section 9.4.

The controls described in Section 13 of this document may apply to some or all of these asset types.

Table 92. System Assets

Asset Type
Description of Function or Service Provided

Types of Users Instruction: For an External User, please write “Not Applicable” in the Sensitivity Level Column. Please include systems administrators and database administrators as role types. (Also include web server administrators, network administrators, and firewall administrators if these individuals have the ability to configure a device or host.) Add additional rows if necessary.

All users have their employee status categorized with a sensitivity level in accordance with PS-2. Employees are considered Internal Users. All other users are considered External Users. User privileges (authorization permission after authentication takes place) are described in the table that follows.

Table 93. User Roles and Privileges

Role
Internal or External
Sensitivity Level
Authorized Privileges and Functions Performed

Note: User roles typically align with Active Directory, LDAP, Role-based Access Controls (RBAC), NIS and UNIX groups, and/or UNIX netgroups.

Network Architecture Instruction: In the space that follows, provide an architectural diagram which provides a visual depiction of the major hardware components of the information system.

The following architectural diagram provides a visual depiction of the major hardware components of the [ACRONYM].

Figure 91. Network Diagram System Environment Instruction: In the space that follows, provide a general description of the technical system environment. Include information about all system environments that are used, e.g., production environment, test environment, staging or QA environments

Asset Inventory The following table lists the virtual and physical components of the [ACRONYM].

Table 101. Asset Physical and Virtual Components

IP Address/Hostname
Make
Model and Firmware
Location
Components that Use this Device

Software Inventory The following table lists the principle software components for [ACRONYM].

Table 102. Software Components

IP Address/Hostname
Function
Version
Patch Level
Virtual (Yes / No)

Data Flow Instruction: In this section describe the flow of data in and out of system boundaries and insert a data flow diagram. If necessary, include multiple data flow diagrams.

Figure 101. Data Flow Diagram Ports, Protocols and Services The table below lists the Ports, Protocols, and Services enabled in this information system. TCP ports are indicated with a T and UDP ports are indicated with a U.

Instruction: In the column labeled “Used By” please indicate the components of the information system that make use of the ports, protocols, and services. In the column labeled “Purpose” indicate the purpose for the service (e.g., system logging, HTTP redirector, load balancing). This table should be consistent with CM-6. Add more rows as needed.

Table 103. Ports, Protocols, and Services

Ports (T or U)
Protocols
Services
Purpose
Used By

System Interconnections Instruction: List data covering all interconnected systems in the two tables in this section. Add additional rows as needed.

· The first table is modeled after the System Interconnection table in NIST SP 800-18. It primarily covers the A&A status of connected systems where an ISA or MOU is required.

· The second table provides detailed information that is contained in an ISA or MOU. For systems where an ISA or MOU does not exist this data is vital to understanding the nature of the interconnection. For systems with an ISA or MOU this table provides a summary of information about the interconnection. Provide the IP address and interface identifier (ie0, ie1, ie2) for the system that provides the connection. Name the organization and the IP address of the external system. Indicate how the connection is being secured. For Connection Security indicate how the connection is being secured. For Data Direction, indicate which direction the packets are flowing. For Information Being Transmitted, describe what type of data is being transmitted. If a dedicated telecom line is used, indicate the circuit number.

Table 111. System Interconnections

System Name
Organization
Type of System

(GSS, MA, Subsystem)

Agreement Type (ISA, MOU)
Date of Agreement
FIPS 199 Security Category of System
A&A Status of System
Name and Title of AO

Table 112. Connection Details of Interconnected Systems

System Name
Organization
Point of Contact and Phone Number
Connection Security (IPSec VPN, SSL, Certificates, Secure File Transfer, etc.)
Data Direction (incoming, outgoing, or both)
Information Being Transmitted
Ports or Circuit #

Note: Additional information regarding each connection may be found in its associated MOU.

Applicable Laws and Regulations

See Appendix B, References.

Minimum Security Controls Minimum security controls for the [ACRONYM] environment are contained in the following sections.

Note: In the control summary tables the Control Origination section has a selection for Hybrid Controls. Preparers of the SSP may add additional Hybrid Control selections if the system inherits portions of a control from more than one system.

Instruction: In the space that follows for the implementation, provide a description of how the control is implemented. The implementation statement should stand on its own and not be a “parroting” back of the NIST SP 800-53 Rev. 4 security requirements. Additionally, the response should speak to all platforms in use (e.g., web, database, Operating System types [Windows, Linux, etc.]), and network devices.

For all Control Summary Information, if any are considered planned, in the implementation response state when it will be implemented and the steps currently being performed to implement.

For Implementation Status noted as “Not Applicable” a statement must be provided in the implementation response stating why it is considered not applicable.

Access Control AC-1: Access Control Policy and Procedures The organization:

a. Develops, documents, and disseminates to [Information System Security Manager, Information System Security Officer, System Owners (e.g., System Program Managers, System Project Managers), Acquisitions/Contracting Officers, Custodians]:

1. An access control policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and

2. Procedures to facilitate the implementation of the access control policy and associated access controls; and

b. Reviews and updates the current:

1. Access control policy [biennially]; and

2. Access control procedures [biennially].

AC-1
Control Summary Information

Implementation Status:

|_| Implemented |_| Partially Implemented |_| Planned |_| Alternative implementation |_| Not applicable

Control Origination:

|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP) |_| System Specific Control

AC-1 Describe how the control is implemented.

Part a

Part b

AC-2: Account Management The organization:

a. Identifies and selects the following types of information system accounts to support organizational missions/business functions: [minimum - System Administrator, Network Administrator, Application Administrator, Database Administrator, Identifying account types. Standard and elevated privilege user accounts. (i.e., individual, group, system, application, guest/anonymous, and temporary)];

b. Assigns account managers for information system accounts;

c. Establishes conditions for group and role membership;

d. Specifies authorized users of the information system, group and role membership, and access authorizations (i.e., privileges) and other attributes (as required) for each account;

e. Requires approvals by [System Owner and Organizational and government personnel with access control responsibilities of the authorization boundary] for requests to create information system accounts;

f. Creates, enables, modifies, disables, and removes information system accounts in accordance with [SCAP Benchmark, NIST Security Configuration Checklist, DISA Security Technical Implementation Guides (STIGs) and/or NSA Guides]

g. Monitors the use of information system accounts;

h. Notifies account managers:

1. When accounts are no longer required;

2. When users are terminated or transferred; and

3. When individual information system usage or need-to-know changes;

i. Authorizes access to the information system based on:

1. A valid access authorization;

2. Intended system usage; and

3. Other attributes as required by the organization or associated missions/business functions;

j. Reviews accounts for compliance with account management requirements [annually]; and

k. Establishes a process for reissuing shared/group account credentials (if deployed) when individuals are removed from the group.

AC-2
Control Summary Information

Implementation Status:

|_| Implemented |_| Partially Implemented |_| Planned |_| Alternative implementation |_| Not applicable

Control Origination:

|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP)

AC-2 Describe how the control is implemented.

Part a

Part b

Part c

Part d

Part e

Part f

Part g

Part h

Part i

Part j

Part k

AC-2 (1): Account Management | Automated System Account Management The organization employs automated mechanisms to support the management of information system accounts.

AC-2 (1)
Control Enhancement Summary Information

Implementation Status:

|_| Implemented |_| Partially Implemented |_| Planned |_| Alternative implementation |_| Not applicable

Control Origination:

|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP)

AC-2 (1) Describe how the control is implemented.

AC-2 (2): Account Management | Removal of Temporary/Emergency Accounts The information system automatically [disables] temporary and emergency accounts after [no more than 90 days].

AC-2 (2)
Control Enhancement Summary Information

Implementation Status:

|_| Implemented |_| Partially Implemented |_| Planned |_| Alternative implementation |_| Not applicable

Control Origination:

|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP)

AC-2 (2) Describe how the control is implemented.

AC-2 (3): Account Management | Disable Inactive Accounts The information system automatically disables inactive accounts after [90 Days for User Level Accounts, 35 days for non-user level accounts].

AC-2 (3)
Control Enhancement Summary Information

Implementation Status:

|_| Implemented |_| Partially Implemented |_| Planned |_| Alternative implementation |_| Not applicable

Control Origination:

|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP)

AC-2 (3) Describe how the control is implemented.

AC-2 (4): Account Management | Automated Audit Actions The information system automatically audits account creation, modification, enabling, disabling, and removal actions, and notifies [Administrators (Application, System, Network, etc.), Information System Security Officer, Information System Security Manager, System Program Managers, and System Project Managers].

AC-2 (4)
Control Enhancement Summary Information

Implementation Status:

|_| Implemented |_| Partially Implemented |_| Planned |_| Alternative implementation |_| Not applicable

Control Origination:

|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP)

AC-2 (4) What is the solutions and how is it implemented?

AC-3: Access Enforcement The information system enforces approved authorizations for logical access to information and system resources in accordance with applicable access control policies.

AC-3
Control Summary Information

Implementation Status:

|_| Implemented |_| Partially Implemented |_| Planned |_| Alternative implementation |_| Not applicable

Control Origination:

|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP)

AC-3 Describe how the control is implemented.

AC-4: Information Flow Enforcement The information system enforces approved authorizations for controlling the flow of information within the system and between interconnected systems based on [Web Service Security (WS Security), WS-Security Policy, WS Trust, WS Policy Framework, Security Assertion Markup Language (SAML), eXtensible Access Control Markup Language (XACML)].

AC-4
Control Summary Information

Implementation Status:

|_| Implemented |_| Partially Implemented |_| Planned |_| Alternative implementation |_| Not applicable

Control Origination:

|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP)

AC-4 Describe how the control is implemented.

AC-5: Separation of Duties

a. Separates [using the roles and responsibilities as a foundation, Data Owners can identify specific types of users that can be authorized to obtain access to each IT resource for functions such as these:

· General user activities (e.g., resource or file access)

· System development (e.g., programmers and database)

· Technical operations and system or network administration];

b. Documents separation of duties of individuals; and

c. Defines information system access authorizations to support separation of duties.

AC-5
Control Summary Information

Implementation Status:

|_| Implemented |_| Partially Implemented |_| Planned |_| Alternative implementation |_| Not applicable

Control Origination:

|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP)

AC-5 Describe how the control is implemented.

Part a

Part b

Part c

AC-6: Least Privilege The organization employs the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with organizational missions and business functions.

AC-6
Control Summary Information

Implementation Status:

|_| Implemented |_| Partially implemented |_| Planned |_| Alternative implementation |_| Not applicable

Control Origination:

|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP)

AC-6 Describe how the control is implemented.

AC-6 (1): Least Privilege | Authorize Access to Security Functions The organization explicitly authorizes access to [Contractor recommendation to be approved and accepted by the AO].

AC-6 (1)
Control Enhancement Summary Information

Implementation Status:

|_| Implemented |_| Partially implemented |_| Planned |_| Alternative implementation |_| Not applicable

Control Origination:

|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP) |_| System Specific Control

AC-6 (1) Describe how the control is implemented.

AC-6 (2): Least Privilege | Non-Privileged Access for Nonsecurity Functions The organization requires that users of information system accounts, or roles, with access to [all Security Functions (examples of security functions include but are not limited to: establishing system accounts, configuring access authorizations (i.e., permissions, privileges), setting events to be audited, and setting intrusion detection parameters, system programming, system and security administration, other privileged functions)], use non-privileged accounts or roles, when accessing nonsecurity functions.

AC-6 (2)
Control Enhancement Summary Information

Implementation Status:

|_| Implemented |_| Partially implemented |_| Planned |_| Alternative implementation |_| Not applicable

Control Origination:

|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP) |_| System Specific Control

AC-6 (2) Describe how the control is implemented.

AC-6 (5): Least Privilege | Privileged Accounts The organization restricts privileged accounts on the information system to [Employees who have resource administrative access (such as system administrators, database administrators, telecom administrators, developers, etc.)].

AC-6 (5)
Control Enhancement Summary Information

Implementation Status:

|_| Implemented |_| Partially Implemented |_| Planned |_| Alternative implementation |_| Not applicable

Control Origination:

|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP) |_| System Specific Control

AC-6 (5) Describe how the control is implemented.

AC-6 (9): Least Privilege | Auditing Use of Privileged Functions The information system audits the execution of privileged functions.

AC-6 (9)
Control Enhancement Summary Information

Implementation Status:

|_| Implemented |_| Partially Implemented |_| Planned |_| Alternative implementation |_| Not applicable

Control Origination:

|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP) |_| System Specific Control

AC-6 (9) Describe how the control is implemented.

AC-6 (10): Least Privilege | Prohibit Non-Privileged Users from Executing Privileged Functions The information system prevents non-privileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures.

AC-6 (10)
Control Enhancement Summary Information

Implementation Status:

|_| Implemented |_| Partially Implemented |_| Planned |_| Alternative implementation |_| Not applicable

Control Origination:

|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP) |_| System Specific Control

AC-6 (10) Describe how the control is implemented.

AC-7: Unsuccessful Login Attempts The information system:

a. Enforces a limit of [not more than ten (10) failed access attempts] consecutive invalid logon attempts by a user during a [30 minute time period]; and

b. Automatically [locks the account/node for [30 minutes]; locks the account/node until released by an administrator; delays next logon prompt for [30 minutes]] when the maximum number of unsuccessful attempts is exceeded.

AC-7
Control Summary Information

Implementation Status:

|_| Implemented |_| Partially Implemented |_| Planned |_| Alternative implementation |_| Not applicable

Control Origination:

|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP) |_| System Specific Control

AC-7 Describe how the control is implemented.

Part a

Part b

AC-8: System Use Notification

a. Displays to users [a warning banner/system use notification message] before granting access to the system that provides privacy and security notices consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance and states that:

1. Users are accessing a U.S. Government information system;

2. Information system usage may be monitored, recorded, and subject to audit;

3. Unauthorized use of the information system is prohibited and subject to criminal and civil penalties; and

4. Use of the information system indicates consent to monitoring and recording;

b. Retains the notification message or banner on the screen until users acknowledge the usage conditions and take explicit actions to log on to or further access the information system; and

c. For publicly accessible systems:

1. Displays system use information [when access via logon interfaces with human users], before granting further access;

2. Displays references, if any, to monitoring, recording, or auditing that are consistent with privacy accommodations for such systems that generally prohibit those activities; and

3. Includes a description of the authorized uses of the system.

AC-8
Control Summary Information

Implementation Status:

|_| Implemented |_| Partially Implemented |_| Planned |_| Alternative implementation |_| Not applicable

Control Origination:

|_| Inherited from: [Enter System’s Name] |_| [Source System’s Name] Common Control |_| Hybrid Control (Shared Between [SYSTEM NAME] and [Source System’s Name]; see also [Source System’s Name] SSP) |_| System Specific Control

AC-8 Describe how the control is implemented.

Part a

Part b

Part c

AC-11: Session Lock

a. Prevents further access to the system by initiating a session lock after [15 minutes] of inactivity or upon receiving a request from a user; and

b.…

This is the start of the file's text. The full file is on GovTribe.

Other files for this federal contract opportunity

Show all 24

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

File details come from the government source that posted it.