SharePoint RFP Tech - 33443 Information Assurance Program Policy FINAL asof 20100309.doc
DOC document 67 KB Posted
- Attached to
- SharePoint Integration and Support Services Federal contract opportunity
- Solicitation number
- HSCETC-10-R-00015
- Issued by
- Immigration and Customs Enforcement
About this file
Information Assurance Program Policy
View the file
Other files for this federal contract opportunity
Show all 37
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PAGE
DISTRIBUTION:
ICE
DIRECTIVE NO.:
TBD
ISSUE DATE:
TBD
EFFECTIVE DATE:
TBD
REVIEW DATE:
TBD
SUPERSEDES:
See Section 3 Below.
DIRECTIVE TITLE: INFORMATION ASSURANCE PROGRAM POLICY
1.
PURPOSE and SCOPE. This Directive establishes the U.S. Immigration and Customs Enforcement (ICE) Information Assurance (IA) Program in accordance with Department of Homeland Security (DHS) Management Directive (MD) 140-01 (formerly known as MD 4300.1) and title III of the E-Government Act formally known as the Federal Information Security Management Act (FISMA). This Directive applies to all users of ICE information systems.
2. AUTHORITIES.
2.1. DHS MD 140-01 (formerly known as MD 4300.1) which includes DHS 4300 Series Policy and Handbooks, as amended.
2.2.
Public Law 107-347, Federal Information Security Management Act (FISMA) of 2002.
3.
SUPERSEDED/CANCELLED POLICY/SUMMARY OF CHANGES. This Directive is the originating and establishing policy for the Information Assurance Program.
4.
BACKGROUND. The ICE IA Program exists to protect the ICE information technology infrastructure from harm while enabling information sharing and mission accomplishment. As a law enforcement agency which processes and stores sensitive data and operates sensitive IT systems, ICE requires an effective IA Program to measure compliance with policies and procedures and publish additional IA guidance and handbooks as necessary.
5.
DEFINITIONS. The following definitions are provided for the purposes of this Directive.
5.1.
Federal Information Security Management Act (FISMA) - Federal law that directs all Federal agencies develop and implement an agency-wide information systems security program designed to safeguard information technology (IT) assets and data.
5.2.
Information Assurance (IA) – Information Assurance is the practice of protecting information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide availability, integrity, authentication, confidentiality, and non-repudiation.
6.
POLICY. All ICE information system users shall comply with requirements derived from FISMA and DHS MD 140-01 (formerly known as MD 4300.1) and all ICE IA Program Handbooks. The ICE Chief Information Security Officer shall publish IA Program Handbooks under the authority of this policy.
7.
RESPONSIBILITIES.
7.1.
Deputy Assistant Secretary (DAS) for Management shall appoint the ICE Chief Information Security Officer (CISO), ensure that ICE has highly trained personnel to support compliance with IA policies, processes, standards, and guidelines, and ensure that entities within the Office of the DAS for Management adhere to and are compliant with all aspects of this IA Program policy and any subsequent IA Program Handbooks.
7.2.
DAS for Operations shall ensure that operational entities within the Office of the DAS for Operations adhere to and are compliant with all aspects of this IA Program policy and any subsequent IA Program Handbooks.
7.3. All ICE employees shall comply with the provisions of this Directive and all other applicable Federal laws, directives and DHS/ICE policy governing the information security of all systems, information, and programs under his or her control.
7.4.
Chief Information Officer (CIO) shall provide management direction to ICE IA operations and ensure the appointment of an ICE CISO.
7.5.
ICE Chief Information Security Officer (CISO) shall be designated as the Senior Agency Information Security Official for purposes of the FISMA statute. The CISO also serves as the Director of the OCIO Information Assurance Division (IAD), and shall be responsible for developing, implementing, and overseeing the ICE IA Program which includes publishing IA Program Handbooks.
7.6.
Deputy Chief Information Security Officer (D-CISO) shall act on behalf of the ICE CISO where necessary to ensure that the daily CISO duties within the organization are complete in order to maintain the security posture of ICE IT operations and ensure continuity of interaction with DHS CISO and DHS Security Operation Center (SOC).
7.7.
Chief Security Officer (CSO) shall be responsible for the overall implementation and management of personnel security (to include employee misconduct investigations) and physical security controls across ICE. As the ICE IA Program is developed, the ICE CISO will collaborate with the CSO to ensure the appropriate coordination of complementary security controls to effectively secure all ICE information assets.
7.8.
Director, Office of Acquisition Management (OAQ) shall be responsible for ensuring the implementation of all applicable IA requirements and policies within ICE contracts and coordinating with the CISO to facilitate appropriate monitoring of contract performance in IA compliance.
7.9 The Principal Legal Advisor shall be responsible for advising all ICE operational entities regarding legal requirements that could affect the collection, maintenance, and disclosure of information entered into or contained in ICE IT systems.
8.
PROCEDURES. To fully integrate information assurance within the agency, IAD will periodically revise the IA Program Handbook and develop and publish (as needed) relevant IA Program Handbooks to detail agency and employee responsibilities and establish accountability.
9.
ATTACHMENTS. None.
10.
NO PRIVATE RIGHT STATEMENT.
This Directive is an internal policy statement of ICE. It is not intended to and does not create any rights, privileges, or benefits, substantive or procedural, enforceable by any party against the United States; its components, agencies, or other entities; its officers or employees; or any other person.
Approved___________________________ John P. Torres Acting Assistant Secretary U.S. Immigration and Customs Enforcement
U.S. IMMIGRATION AND CUSTOMS ENFORCEMENT
ICE Policy System
Information Assurance Program Policy Information Assurance Program Policy
File details come from the government source that posted it. Updated .