SharePoint RFP Tech - DHS_Sensitive_Systems_Policy_4300A_v7dot1.doc
DOC document 1 MB Posted
- Attached to
- SharePoint Integration and Support Services Federal contract opportunity
- Solicitation number
- HSCETC-10-R-00015
- Issued by
- Immigration and Customs Enforcement
About this file
DHS Sensitive Systems Policy
View the file
Other files for this federal contract opportunity
Show all 37
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DHS Sensitive Systems Policy Directive 4300A
DHS Sensitive Systems Policy
Directive 4300A
Version 7.1 October 1, 2009 This is the implementation of DHS Management Directive 140-01 Information Technology System Security, July 31, 2007 Department of Homeland Security
This page intentionally left blank
TABLE OF CONTENTS
11.0 Introduction
11.1 Information Security Program Policy
11.2 Authorities
11.3 Policy Overview
11.4 Definitions
11.4.1 Classified National Security Information
11.4.2 National Intelligence Information
11.4.3 National Security Information
11.4.4 Foreign Intelligence Information
11.4.5 Sensitive Information
11.4.6 Public Information
11.4.7 Information Technology
11.4.8 DHS System
11.4.8.1 General Support System
11.4.8.2 Major Application
11.4.9 Component
11.4.10 Trust Zone
11.4.11 Continuity of Operations
11.4.12 Continuity of Operations Plan
11.4.13 Essential Functions
11.4.14 Vital Records
11.4.15 Operational Data
11.4.16 Federal Information Security Management Act
11.4.17 Personally Identifiable Information
11.4.18 Sensitive Personally Identifiable Information
11.4.19 Privacy Sensitive System
11.4.20 Strong Authentication
11.4.21 Two-Factor Authentication
11.5 Waivers and Exceptions
11.5.1 Waivers
11.5.2 Exceptions
11.5.3 Waiver or Exception Requests
11.5.4 U.S. Citizen Exception Requests
11.6 Information Sharing and Communication Strategy
11.7 Changes to Policy
12.0 Roles and Responsibilities
12.1 Information Security Program Roles
12.1.1 DHS Senior Agency Information Security Officer
12.1.2 DHS Chief Information Security Officer
12.1.3 Component Chief Information Security Officer
12.1.4 Component Information Systems Security Manager
12.1.5 Risk Executive
12.1.6 Authorizing Official
12.1.7 Certifying Official
12.1.8 Information Systems Security Officer
12.2 Other Roles
12.2.1 Secretary of Homeland Security
12.2.2 Under Secretaries and Heads of DHS Components
12.2.3 DHS Chief Information Officer
12.2.4 Component Chief Information Officer
12.2.5 DHS Chief Security Officer
12.2.6 DHS Chief Privacy Officer
12.2.7 DHS Chief Financial Officer
1All systems on the CFO Designated Systems List are required to conform with the policies defined in this section.
12.2.8 Program Managers
12.2.9 System Owners
12.2.10 DHS Employees, Contractors, and Others Working On Behalf of DHS
13.0 management policies
13.1 Basic Requirements
13.2 Capital Planning and Investment Control
13.3 Contractors and Outsourced Operations
13.4 Performance Measures and Metrics
13.5 Continuity Planning for Critical DHS Assets
13.5.1 Continuity of Operations Planning
13.5.2 Contingency Planning
13.6 System Life Cycle
13.7 Configuration Management
13.8 Risk Management
13.9 Certification, Accreditation, and Security Assessments
13.10 Information Security Review and Assistance
13.11 Security Working Groups and Forums
13.11.1 CISO Council
13.11.2 DHS Information Security Training Working Group
13.12 Information Security Policy Violation and Disciplinary Action
13.13 Required Reporting
13.14 Privacy and Data Security
13.14.1 Personally Identifiable Information
13.14.2 Privacy Threshold Analyses
13.14.3 Privacy Impact Assessments
13.14.4 System of Record Notices
13.14.5 Protecting Privacy Sensitive Systems
13.14.6 Privacy Incident Reporting
13.14.7 E-Authentication
13.15 DHS Chief Financial Officer Designated Systems
13.16 Social Media
14.0 operationaL POLICIES
14.1 Personnel
14.1.1 Citizenship, Personnel Screening, and Position Categorization
14.1.2 Rules of Behavior
14.1.3 Access to Sensitive Information
14.1.4 Separation of Duties
14.1.5 Information Security Awareness, Training, and Education
14.1.6 Separation From Duty
14.2 Physical Security
14.2.1 General Physical Access
14.2.2 Sensitive Facility
14.3 Media Controls
14.3.1 Media Protection
14.3.2 Media Marking and Transport
14.3.3 Media Sanitization and Disposal
14.3.4 Production, Input/Output Controls
14.4 Voice Communications Security
14.4.1 Private Branch Exchange
14.4.2 Telephone Communications
14.4.3 Voice Mail
14.5 Data Communications
14.5.1 Telecommunications Protection Techniques
14.5.2 Facsimiles
14.5.3 Video Teleconferencing
14.5.4 Voice Over Data Networks
14.6 Wireless Network Communications
14.6.1 Wireless Systems
14.6.2 Wireless Portable Electronic Devices
14.6.2.1 Cellular Phones
14.6.2.2 Pagers
14.6.2.3 Multifunctional Wireless Devices
14.6.3 Wireless Tactical Systems
14.6.4 Radio Frequency Identification
14.7 Overseas Communications
14.8 Equipment
14.8.1 Workstations
14.8.2 Laptop Computers and Other Mobile Computing Devices
14.8.3 Personally Owned Equipment and Software
14.8.4 Hardware and Software
14.8.5 Personal Use of Government Office Equipment and DHS Systems/Computers
14.8.6 Wireless Settings for Peripheral Equipment
14.9 Department Information Security Operations
14.9.1 Security Incidents and Incident Response and Reporting
14.9.2 Law Enforcement Incident Response
14.10 Documentation
14.11 Information and Data Backup
14.12 Converging Technologies
15.0
TECHNICAL POLICIES
15.1 Identification and Authentication
15.1.1 Passwords
15.2 Access Control
15.2.1 Automatic Account Lockout
15.2.2 Automatic Session Termination
15.2.3 Warning Banner
15.3 Auditing
15.4 Network and Communications Security
15.4.1 Remote Access and Dial-In
15.4.2 Network Security Monitoring
15.4.3 Network Connectivity
15.4.4 Firewalls and Policy Enforcement Points
15.4.5 Internet Security
15.4.6 Email Security
15.4.7 Personal Email Accounts
15.4.8 Testing and Vulnerability Management
15.4.9 Peer-to-Peer Technology
15.5 Cryptography
15.5.1 Encryption
15.5.2 Public Key Infrastructure
15.5.3 Public Key/Private Key
15.6 Malware Protection
15.7 Product Assurance
16.0 Document Change Requests
17.0 Questions and Comments
1APPENDIX A
Acronyms
1APPENDIX B
Glossary
1APPENDIX C
references
1APPENDIX D
DOCUMENT CHANGE HISTORY
1.0 Introduction
This document articulates the Department of Homeland Security (DHS) Information Security Program policies for sensitive systems. Procedures for implementing these policies are outlined in a companion publication, DHS 4300A Sensitive Systems Handbook. The handbook serves as a foundation for Components to develop and implement their information security programs. The baseline security requirements (BLSRs) included in the handbook must be addressed when developing and maintaining information security documents.
1.1 Information Security Program Policy
The DHS Information Security Program provides a baseline of policies, standards, and guidelines for DHS Components. This document provides direction to managers and senior executives for managing and protecting sensitive systems. It also outlines policies relating to management, operational, and technical controls necessary for ensuring confidentiality, integrity, availability, authenticity, and nonrepudiation within the DHS information system infrastructure and operations. Policy elements are designed to be broad in scope. Specific implementation information can often be found in specific National Institute for Standards and Technology (NIST) publications, such as NIST Special Publication (SP) 800-53, Recommended Security Controls for Federal Systems.
The policies and direction contained in this document apply to all DHS Components. Information security policies and implementing procedures for National Security Systems are covered in separate publications, DHS National Security Systems Policy Directive 4300B and DHS 4300B National Security Systems Handbook. For intelligence systems, refer to DHS 4300C, Sensitive Compartmented Information (SCI) Systems. These publications are available on the DHS CISO website.
The DHS Information Security Program does not apply to systems that process, store, or transmit National Intelligence Information.
Policy elements are effective when issued. Any policy elements that have not been implemented within ninety (90) days shall be considered a weakness and either a system or program POA&M must be generated by the Component for the identified weaknesses. When DHS Security Compliance tools, Risk Management System (RMS) and TrustedAgent FISMA (TAF) are required to be updated to reflect policy element changes, tool changes shall be available to the Department within forty-five (45) days of the policy changes.
1.2 Authorities
The following list provides the authoritative references for the DHS sensitive information security program. Additional references are located in Appendix C of this document.
· Public Law 107-347, E-Government Act of 2002, including Title III, Federal Information Security Management Act (FISMA)
· Office of Management and Budget (OMB) Circular A-130, Management of Federal Information Resources
· DHS Management Directive 140-01, Information Technology Security Services
· NIST Federal Information Processing Standards (FIPS) 200, Minimum Security Requirements for Federal Information and Information Systems
· NIST SP 800-53, Recommended Security Controls for Federal Information Systems
1.3 Policy Overview
DHS information security policies delineate the security management structure and foundation to measure progress and compliance. Policies in this document are organized under three areas:
· Management Controls – Focus on managing both the system information security controls and system risk. These controls consist of risk mitigation techniques and concerns normally addressed by management.
· Operational Controls – Focus on mechanisms primarily implemented and executed by people. These controls are designed to improve the security of a particular system, or group of systems and often rely on management and technical controls.
· Technical Controls – Focus on security controls executed by information systems. These controls provide automated protection from unauthorized access or misuse. They facilitate detection of security violations, and support security requirements for applications and data.
1.4 Definitions
The following definitions apply to the policies and procedures outlined in this document. Other definitions may be found in the National Information Assurance (IA) Glossary, as well as the Privacy Incident Handling Guidance and the Privacy Compliance documentation.
1.4.1 Classified National Security Information
Information that has been determined, pursuant to Executive Order 12958, Classified National Security Information, as amended, or any predecessor order, to require protection against unauthorized disclosure and is marked to indicate its classified status.
1.4.2 National Intelligence Information
The following definition is provided in Public Law 108-458, Intelligence Reform and Terrorism Prevention Act of 2004, December 17, 2004, “The terms ‘national intelligence’ and ‘intelligence related to national security’ refer to all intelligence, regardless of the source from which derived and including information gathered within or outside the United States, that – “(A) pertains, as determined consistent with any guidance issued by the President, to more than one United States Government agency; and “(B) that involves – (i) threats to the United States, its people, property, or interests; (ii) the development, proliferation, or use of weapons of mass destruction; or (iii) any other matter bearing on United States national or homeland security.”
1.4.3 National Security Information
Information that has been determined, pursuant to Executive Order 12958, Classified National Security Information, or any predecessor order, to require protection against unauthorized disclosure.
1.4.4 Foreign Intelligence Information
This type of information relates to the capabilities, intentions, and activities of foreign powers, organizations, or persons, but does not include counterintelligence except for information on international terrorist activities.
1.4.5 Sensitive Information
Sensitive information is information not otherwise categorized by statute or regulation that if disclosed could have an adverse impact on the welfare or privacy of individuals or on the welfare or conduct of Federal programs or other programs or operations essential to the national interest. Examples of sensitive information include personal data such as Social Security number; trade secrets; system vulnerability information; pre-solicitation procurement documents, such as statements of work; and law enforcement investigative methods; similarly, detailed reports related to computer security deficiencies in internal controls are also sensitive information because of the potential damage that could be caused by the misuse of this information. System vulnerability information about a financial system shall be considered Sensitive Financial Information. All sensitive information must be protected from loss, misuse, modification, and unauthorized access.
With the exception of certain types of information protected by statute (e.g. Sensitive Security Information, Critical Infrastructure Information), there are no specific Federal criteria and no standard terminology for designating types of sensitive information. Such designations are left to the discretion of each individual Federal agency.“For Official Use Only” (FOUO) is the term used within DHS to identify unclassified information of a sensitive nature that is not otherwise categorized by statute or regulation. DHS will adopt the term “Controlled Unclassified Information” (CUI) at a later date.
1.4.6 Public Information
This type of information can be disclosed to the public without restriction but requires protection against erroneous manipulation or alteration (e.g. Public Web sites).
1.4.7 Information Technology
The Clinger-Cohen Act defines information technology (IT) as any equipment or interconnected system or subsystem of equipment that is used in the automatic acquisition, storage, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by an Executive agency.
For purposes of the preceding definition, “equipment” refers to that used by any DHS Component or contractor, if the contractor requires the use of such equipment in the performance of a service or the furnishing of a product in support of DHS.
The term “information technology” includes computers, ancillary equipment, software, firmware, and similar procedures, services (including support services), and related resources.
1.4.8 DHS System
A DHS system is any IT that is (1) owned, leased, or operated by any DHS Component, (2) operated by a contractor on behalf of DHS, or (3) operated by another Federal, state, or local Government agency on behalf of DHS. DHS systems include general support systems and major applications.
1.4.8.1 General Support System
A general support system (GSS) is an interconnected set of information resources under the same direct management control that share common functionality. A GSS normally includes hardware, software, information, applications, communications, data and users. Examples of a GSS include a local area network (LAN), including smart terminals that support a branch office, a Department-wide backbone, a communications network, or a Departmental data processing center including its operating system and utilities.
Note: Security for GSS in use at DHS Headquarters shall be under the oversight of the DHS Office of the CIO, with support from the DHS Enterprise Operations Center (EOC). All other GSS shall be under the direct oversight of the respective Component CISOs, with support from the appropriate Component Security Operations Center (SOC). All GSS must have one or more Information Systems Security Officers (ISSO) assigned.
1.4.8.2 Major Application
A major application (MA) is an automated information system (AIS) that “requires special attention to security due to the risk and magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of the information in the application.
” Note: All Federal applications require some level of protection. Certain applications, because of the information in them, however, require special management oversight and should be treated as major. An MA is distinguishable from a GSS by the fact that it is a discrete application, whereas a GSS may support multiple applications. Each MA must be under the direct oversight of a Component CISO/ISSM, and must have one or more Information Systems Security Officers (ISSO) assigned.
1.4.9 Component
A DHS Component is any of the entities within DHS, including all DHS offices and independent agencies.
1.4.10 Trust Zone
A Trust Zone consists of a group of people, information resources, data systems, and/or networks subject to a shared security policy (set of rules governing access to data and services). For example, a Trust Zone may be set up between different network segments that require specific usage policies based on information processed, such as law enforcement information.
1.4.11 Continuity of Operations
Internal organizational efforts to ensure that a viable capability exists to continue essential functions across a wide range of potential emergencies, through plans and procedures that:
· Delineate essential functions and supporting information systems
· Specify succession to office and the emergency delegation of authority
· Provide for the safekeeping of vital records and databases
· Identify alternate operating facilities
· Provide for interoperable communications
· Validate the capability through tests, training, and exercises
1.4.12 Continuity of Operations Plan
A plan that provides for the continuity of essential functions of an organization in the event that an emergency prevents occupancy of its primary facility. It provides the organization with an operational framework for continuing its essential functions when normal operations are disrupted or otherwise cannot be conducted from its primary facility.
1.4.13 Essential Functions
Functions that enable Federal Executive Branch agencies to provide vital services, exercise civil authority, maintain the safety and well being of the general populace, and sustain the industrial/economic base during an emergency.
1.4.14 Vital Records
Electronic and hardcopy documents, references, records, databases, and information systems needed to support essential functions under the full spectrum of emergencies. Categories of these types of records may include:
· Emergency operating records – emergency plans and directive(s), orders of succession, delegations of authority, staffing assignments, selected program records needed to continue the most critical agency operations, as well as related policy or procedural records.
· Legal and financial rights records – protect the legal and financial rights of the Government and of the individuals directly affected by its activities. Examples include accounts receivable records, social security records, payroll records, retirement records, and insurance records. These records were formerly defined as “rights-and-interests” records.
· Records used to perform national security preparedness functions and activities (E.O. 12656).
1.4.15 Operational Data
Operational data is information used in the execution of any DHS mission.
1.4.16 Federal Information Security Management Act
The Federal Information Security Management Act of 2002 (FISMA) requires each agency to develop, document, and implement an agency-wide information security program to provide a high-level of security for the information and information systems that support the operations and assets of the agency, including those provided or managed by another agency, contractor, or other source. Statutory requirements include:
(1) Periodic assessments of the risk and magnitude of the harm that could result from the unauthorized access, use, disclosure, disruption, modification, or destruction of information and information systems that support the operations and assets of the agency.
(2) Policies and procedures that:
a. Are based on the risk assessments required by paragraph (1) above
b. Cost-effectively reduce information security risks to an acceptable level
c. Ensure that information security is addressed throughout the life cycle of each agency information system
d. Ensure compliance with
i. Other Federal policies and procedures as may be prescribed by OMB and NIST, or other agencies when appropriate
ii. Minimally acceptable system configuration requirements, as determined by the agency
iii. Any other applicable requirements, including standards and guidelines for national security systems issued in accordance with law and as directed by the President
(3) Subordinate plans for providing adequate information security for networks, facilities, and systems or groups of information systems, as appropriate;
(4) Security awareness to inform personnel, including contractors, others working on behalf of DHS, and other users of information systems that support operations and assets of the Department, of:
a. Information security risks associated with their activities
b. Their responsibilities in complying with agency policies and procedures designed to reduce these risks
(5) Periodic testing and evaluation of the effectiveness of information security policies, procedures, and practices, to be performed with a frequency depending on risk, but no less than annually. This testing:
a. Shall include testing of management, operational, and technical controls of every information system identified in the Department’s inventory
b. May include testing relied on by the Office of Inspector General;
(6) A process for planning, implementing, evaluating, and documenting remedial actions to address any deficiencies in the information security policies, procedures, and practices of the Department
(7) Procedures for detecting, reporting, and responding to security incidents, consistent with standards and guidelines promulgated by US-CERT
a. Mitigating risks associated with incidents before substantial damage is done
b. Notifying and consulting with the US-CERT
c. Notifying and consulting with:
i. Law enforcement agencies and relevant Offices of Inspector General
ii. An office designated by the President for any incident involving a national security system
iii. Other agency or offices, as required
(8) Plans and procedures to ensure continuity of operations for information systems that support the operations and assets of the Department
FISMA requires the CIO to designate a senior agency information security official who shall develop and maintain a Department-wide information security program as required by the statute. Responsibilities include:
· Developing and maintaining information security policies, procedures, and control techniques to address all applicable requirements
· Training and overseeing personnel with significant responsibilities for information security with respect to such responsibilities
· Assisting senior Department officials concerning their responsibilities under the statute
· Ensuring that the Department has trained personnel sufficient to assist the Department in complying with the requirements of this subchapter and related policies, procedures, standards, and guidelines; and
· Ensuring that the Department Chief Information Officer, in coordination with other senior Department officials, reports annually to the Department head on the effectiveness of the Department information security program, including progress of remedial actions
1.4.17 Personally Identifiable Information
Personally Identifiable Information (PII) is any information that permits the identity of an individual to be directly or indirectly inferred, including any other information that is linked or linkable to an individual regardless of whether the individual is a U.S. Citizen, legal permanent resident, or a visitor to the U.S.
1.4.18 Sensitive Personally Identifiable Information
Sensitive PII is PII that requires stricter handling guidelines because of the nature of the data and the increased risk to an individual if compromised, and if lost, compromised, or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. Examples of sensitive PII include Social Security numbers or alien number (A-number).
1.4.19 Privacy Sensitive System
A Privacy Sensitive System is any system that collects, uses, disseminates, or maintains PII or sensitive PII.
1.4.20 Strong Authentication
Strong authentication is a layered authentication approach relying on two or more authenticators to establish the identity of an originator or receiver of information.
1.4.21 Two-Factor Authentication
Authentication can involve something the user knows (e.g., a password), something the user has (e.g., a smart card), or something the user “is” (e.g., a fingerprint or voice pattern). Single-factor authentication uses only one of the three forms of authentication, while two-factor authentication uses any two of the three forms. Three-factor authentication uses all three forms.
1.5 Waivers and Exceptions
1.5.1 Waivers
Components may request waivers to, or exceptions from, any portion of this policy, for up to six (6) months, any time they are unable to fully comply with policy requirements. Requests are made, through the Component’s Information Systems Security Officer (ISSO) for the system, to the Component’s respective Chief Information Security Officer (CISO, and then to the DHS CISO. Requests shall include the operational justification, risk acceptance, risk mitigation measures, and a plan for bringing the system into compliance.
If a material weakness is reported in an audit report, and the control weakness is not scheduled to be remediated within twelve (12) months, the Component must submit a waiver request to the DHS CISO. If the material weakness is against a financial system, the Component CFO must also approve the waiver request before sending to the DHS CISO.
All waiver requests must identify the POA&M for bringing the system procedures or control weakness into compliance. In all cases waivers shall be requested for an appropriate period based on a reasonable remediation strategy.
1.5.2 Exceptions
Components may request an exception whenever they are unable to bring a system control weakness into compliance or when it requires a permanent exception to DHS policy. Exceptions are generally limited to systems that are unable to comply due to detrimental impact to mission, excessive costs, and/or clearly documented end of platform life for non-essential systems within eighteen (18) months, Commercial-Off-the-Shelf (COTS) products that cannot be configured to support the control requirement, etc. This request is made, through the Component respective CISO, to the DHS CISO and shall include the operational justification, risk acceptance, and risk mitigation measures. (The respective CISO is the CISO with that system in his or her inventory.)
The resulting risk also must be approved and accepted by the Authorizing Official (AO) and by the Component CFO if the system is a financial or mixed financial system.
1.5.3 Waiver or Exception Requests
The Waivers and Exceptions Request Form, located in Attachment B of the DHS 4300A Sensitive Systems Handbook, shall be used.
Component ISSOs, audit liaisons, and others may develop the waiver or exception request, but the System Owner must submit the request through the Component’s respective CISO.
Justification for the waiver request shall document mission impact by the operational system, as well as efforts to mitigate the risk based on descriptions of counter measures or compensating controls currently in place.
Any waiver or exception requests for CFO Designated Systems must additionally be submitted to and approved by the Component’s CFO.
All approved waiver and exception requests must be directed to the Component’s respective CISO to the DHS CISO.
| Policy ID |
| DHS Policy Statements |
| Relevant Controls |
| 1.5.3.a |
| Systems without an ATO when this policy is issued shall comply with all of its policy statements or obtain appropriate waivers and/or exceptions. |
| PL-1 |
| 1.5.3.b |
| Systems with an ATO when this policy is issued shall comply with all of its policy statements within ninety (90) days or obtain appropriate waivers and/or exceptions. (A new ATO is only required for significant changes.) |
| PL-1 |
| 1.5.3.c |
| Each waiver or exception request shall include the system name, and system TrustedAgent FISMA (TAF) Inventory ID, operational justification, and risk mitigation. |
| CM-3 |
| 1.5.3.d |
| Components shall request a waiver whenever they are temporarily unable to comply fully with any portion of this policy. |
| CA-4 |
| 1.5.3.e |
| All waiver requests shall identify the POA&M for bringing the system or program into compliance. |
| CA-5, PM-4 |
| 1.5.3.f |
| The respective CISO shall approve all waiver requests prior to submitting them to the DHS CISO. (The respective CISO is the CISO with that system in his or her inventory.) |
| CA-6 |
| 1.5.3.g |
| Requests submitted without sufficient information shall be returned for clarification prior to making a decision. |
| CA-6 |
| 1.5.3.h |
| A waiver shall be issued for six (6) months or less. The DHS CISO reserves the right to issue waivers for longer than six (6) months in exceptional situations. Waivers may be renewed by following the same process as in the initial request. |
| CA-4 |
| 1.5.3.i |
| The Head of the Component shall approve any waiver request that results in a total waiver time exceeding twelve (12) months before sending it to the DHS CISO. The waiver shall also be reported as a material weakness in the Component’s FISMA report. |
| --- |
| 1.5.3.j |
| Components shall request an exception whenever they are permanently unable to comply fully with any portion of this policy. |
| CA-4 |
| 1.5.3.k |
| The Component Head shall make a recommendation to the DHS CISO for all exception requests and any waiver request that extends beyond twelve (12) months. (Exceptions granted on the basis of compensating controls are not considered to be policy violations.) All such waivers and exceptions shall be reported in the Component’s FISMA report. |
| CA-6 |
| 1.5.3.l |
| The DHS CFO shall approve all requests for waivers and exceptions for financial systems prior to their submission to the DHS CISO. |
| CA-6 |
1.5.4 U.S. Citizen Exception Requests
Special procedures apply for exception to the requirement that persons accessing DHS systems be U.S. Citizens. Under normal circumstances, only U.S. Citizens are allowed access to DHS systems and networks, however at times there is a need to grant access to foreign nationals. Access for foreign nationals is normally a long-term commitment, and exceptions to appropriate policies are treated separately from standard exceptions and waivers. The approval chain for an exception to the U.S. Citizenship requirement flows through the Component Head, the Office of Security, and the CIO. An electronic form for requesting exceptions to the U.S. Citizenship requirement is published in Attachment J of the DHS 4300A Sensitive Systems Handbook.
| Policy ID |
| DHS Policy Statements |
| Relevant Controls |
| 1.5.4.a |
| Persons of dual citizenship, where one of the citizenships includes U.S. Citizenship, shall be treated as U.S. Citizens for the purposes of this directive. |
| --- |
| 1.5.4.b |
| The System Owner shall submit each request for exception to the U.S. Citizenship policy to the Component Head. The Component Head shall obtain concurrence from the Chief Security Officer (CSO) and the Chief Information Officer (CIO) prior to the approval becoming effective. |
| PS-3 |
| 1.5.4.c |
| Additional compensating controls shall be maintained for foreign nationals, based on nations lists maintained by the DHS CSO. |
| --- |
1.6 Information Sharing and Communication Strategy
The DHS Enterprise Operations Center (EOC) exchanges information with Component SOCs, Network Operations Centers (NOCs), the Homeland Secure Data Network (HSDN) SOC, the Intelligence Community, and with external organizations in order to facilitate the security and operation of the DHS network. This exchange enhances situational awareness and provides a common operating picture to network managers. The operating picture is developed from information obtained from “raw” fault, configuration management, accounting, performance, and security data. This data is monitored, collected, analyzed, processed, and reported by the NOCs and SOCs.
The DHS EOC is responsible for communicating other information such as incident reports, notifications, vulnerability alerts and operational statuses to the Component SOCs, Component CISOs/ISSMs or other identified Component points of contact.
The DHS EOC portal implements role-based user profiles that allow Components to use the website’s incident database capabilities. Users assigned to Component groups shall be able to perform actions such as:
· Entering incident information into the DHS EOC incident database
· Generating preformatted incident reports
· Initiating queries of the incident database
· Viewing FISMA incident reporting numbers
· Automating portions of the Information Security Vulnerability Management (ISVM) program
· Automating portions of the vulnerability assessment program
| Policy ID |
| DHS Policy Statements |
| Relevant Controls |
| 1.6.a |
| For DHS purposes, electronic signatures are preferred to pen and ink or facsimile signatures in all cases except where pen and ink signatures are required by public law, Executive Order, or other agency requirements. |
| --- |
1.7 Changes to Policy
Procedures and guidance for implementing this policy are outlined in a companion publication, DHS 4300A Sensitive Systems Handbook with attachments. The handbook serves as a foundation for Components to use in developing and implementing their information security programs.
For interpretation or clarification of DHS information security policies found in this policy document and of the procedures and guidance found in the DHS 4300A Sensitive Systems Handbook, contact the DHS CISO at infosec@dhs.gov.
Changes to this policy and to the handbook may be requested by submitting the form included in DHS 4300A Sensitive Systems Handbook Attachment P – Document Change Requests to the respective ISSM/CISO.
| Policy ID |
| DHS Policy Statements |
| Relevant Controls |
| 1.7.a |
| The DHS CISO shall be the authority for interpretation, clarification, and modification of the DHS Sensitive Systems Policy Directive 4300A and the DHS 4300A Sensitive Systems Handbook (inclusive of all appendices and attachments). |
| PL-1 |
| 1.7.b |
| The DHS CISO shall update the DHS Sensitive Systems Policy Directive 4300A and the DHS 4300A Sensitive Systems Handbook at least annually. |
| PL-1 |
2.0 Roles and Responsibilities
Security is an inherently Governmental responsibility; contractors, others working on behalf of DHS, and other sources may assist in the performance of security functions, but a DHS employee must always be designated as the responsible agent for all security requirements and functions. This section outlines the roles and responsibilities for implementing these requirements.
2.1 Information Security Program Roles
Designated personnel play a major role in the planning and implementation of information security requirements. Roles directly responsible for information system security are described in the following subsections.
2.1.1 DHS Senior Agency Information Security Officer
| Policy ID |
| DHS Policy Statements |
| Relevant Controls |
| 2.1.1.a |
| The DHS CISO shall perform the duties and responsibilities of the DHS Senior Agency Information Security Officer (SAISO). |
| PL-1, PM-2 |
2.1.2 DHS Chief Information Security Officer
The DHS CISO shall implement and manage the DHS Information Security Program to ensure compliance with applicable Federal laws, Executive Orders, directives, policies, and regulations.
The DHS CISO reports directly to the DHS CIO and is the principal advisor for information security matters.
| Policy ID |
| DHS Policy Statements |
| Relevant Controls |
| 2.1.2.a |
| The DHS CISO shall implement and manage the DHS-wide Information Security Program. |
| PL-1, PM-2 |
The DHS CISO:
· Implements and manages the Department-wide Information Security Program and ensures compliance with FISMA, OMB, and other Federal requirements
· Issues Department-wide information security policy, guidance, and architecture requirements for all DHS systems and networks. These policies shall incorporate NIST guidance, as well as all applicable OMB memoranda and circulars
· Facilitates development of subordinate plans for providing adequate information security for networks, facilities, and systems or groups of information systems
· Serves as the principal Departmental liaison with organizations outside the DHS for matters relating to information security
· Reviews and approves the tools, techniques, and methodologies planned for use in certifying and accrediting DHS systems, and for reporting and managing systems-level FISMA data. This includes Security Test and Evaluation (ST&E) plans, Contingency Plans, and security risk assessments.
· Consults with the DHS Chief Security Officer on matters pertaining to physical security, personnel security, information security, investigations, and Sensitive Compartmented Information (SCI) systems, as they relate to information security and infrastructure
· Develops and implements procedures for detecting, reporting, and responding to information security incidents
· Ensures preparation and maintenance of plans and procedures to provide continuity of operations for information systems
· Ensures that Department personnel, contractors, and others working on behalf of DHS receive appropriate information security awareness
· Chairs the CISO Council. This Council is comprised of all Component CISOs, and is the Department’s sole coordination body for any issues associated with information security policy, management, and operations. Component ISSMs will be invited to CISO Council meetings as required
· Maintains a comprehensive inventory of all GSS and MA in use within the Department
· Security management for every GSS shall be under the direct oversight of either the DHS CISO (for enterprise systems) or a Component CISO (for Component-specific general support systems)
· MAs must be under the direct control of either a Component CISO or Component ISSM
· Maintains a repository for all IA C&A documentation and modifications
· Performs security reviews for all planned information systems acquisitions over $2.5 million and additional selected cases
· Provides oversight of all security operations functions within the Department
· Maintains classified threat assessment capability in support of security operations
· Performs annual program assessments for each of the Components
· Performs periodic compliance reviews for selected systems and applications
· Publishes monthly compliance scorecards
· Delegates specific authorities and responsibilities for maintaining a high degree of compliance to Component CISOs and ISSMs, as appropriate
· Reports annually to the Secretary on the effectiveness of the Department information security program, including progress of remedial actions. This report provides the primary basis for the Secretary’s annual FISMA report to both the Office of Management and Budget and to the United States Congress.
· Assists senior Department officials concerning their responsibilities under the statute
· Heads an office with the mission and resources to assist in ensuring Department compliance with information security requirements
· Appoints a DHS employee to serve as the Headquarters CISO
· Appoints a DHS employee to serve as the National Security Systems (NSS) CISO
2.1.3 Component Chief Information Security Officer
The Component CISO implements and manages all aspects of the Component Information Security Program to ensure compliance with DHS policy and guidance that implement FISMA, other laws, and Executive Orders.
| Policy ID |
| DHS Policy Statements |
| Relevant Controls |
| 2.1.3.a |
| Component CISOs shall develop and maintain a Component-wide information security program in accordance with the DHS security program. |
| PL-1, PM-2 |
| 2.1.3.b |
| All Components shall be responsible to the appropriate CISO. Components without a fulltime CISO shall be responsible to the HQ CISO. |
| --- |
The following Components shall have a fulltime CISO:
· Customs and Border Protection
· Immigration and Customs Enforcement
· Transportation Security Administration
· United States Secret Service
· United States Coast Guard
· Federal Emergency Management Agency
· United States Citizenship and Immigration Services
· Federal Law Enforcement Training Center
· Office of the Inspector General
· Headquarters, Department of Homeland Security
· The DHS CISO shall also appoint an NSS CISO
Component CISOs:
· Oversee the Component information security program
· Ensure that the Component CIO is kept apprised of all pertinent matters involving the security of information systems
· Ensure that information security-related decisions and information, including updates to the 4300 series of information security publications, are distributed to the ISSOs and other appropriate persons within their Component
· Approve and/or validate all Component information system security reporting
· Consult with the Component Privacy Officer or Privacy Point of Contact (PPOC) for reporting and handling of privacy incidents
· Manage information security resources including oversight and review of security requirements in funding documents
· Review and approve the security of hardware and software prior to implementation into the Component SOC
· Periodically test the security of implemented systems
· Implement and manage a POA&M process for remediation
· Ensure that ISSOs are appointed for each information system managed at the Component level. Review and approve ISSO appointments
· Ensure that weekly incident reports are submitted to the DHS EOC
· Acknowledge receipt of Information Security Vulnerability Management (ISVM) messages, report compliance with requirements or notify the granting of waivers
· Manage Component firewall rule sets
· Ensure that Interconnection Security Agreements (ISAs) are maintained for all connections between systems that do not have the same security policy
· Ensure execution of the DHS Logging Strategy detailed in the DHS 4300A Sensitive Systems Handbook
· Ensure adherence to the DHS Secure Baseline Configuration Guides
· Ensure reporting of vulnerability scanning activities to the DHS EOC as detailed in Attachment O, Vulnerability Management Program, of DHS 4300A Sensitive Systems Handbook
· Develop and maintain a Component-wide information security program in accordance with Department policies and guidance
· Implement Department information security policies, procedures, and control techniques to address all applicable requirements
· Ensure training and oversight for personnel with significant responsibilities for information security
· Oversee the C&A process for GSSs and MAs in use within the Component
· Maintain an independent Component-wide Security Test and Evaluation (ST&E) Program to ensure a consistent approach to testing of effectiveness of controls
· Ensure that an appropriate SOC performs an independent network assessment as part of the ST&E process for each application that is accredited
· Ensure that enterprise security tools are utilized
· Exercise oversight over all Component security operations functions, including the Component SOCs Component CISO qualifications include:
· Possess professional qualifications, including training and experience, required to administer the functions described, including maintaining a Top Secret/Sensitive Compartmented Information (TS/SCI) clearance.
· Have information security duties as that official’s primary duty
· Participate in the DHS CISO Council, chaired by the DHS CISO
· Head an office with the mission and resources to assist in ensuring Component compliance with this directive and to coordinate, develop, implement, and maintain an organization-wide information security program
· Serve as the Component Risk Executive
2.1.4 Component Information Systems Security Manager
Components that are not required to have a fulltime CISO shall have a fulltime Information Systems Security Manager (ISSM). The ISSM is designated in writing by the Component CIO, with the concurrence of the HQ CISO.
| Policy ID |
| DHS Policy Statements |
| Relevant Controls |
| 2.1.4.a |
| Component ISSMs shall serve as the principal interface between the HQ CISO, Component ISSOs and other security practitioners. |
| --- |
| 2.1.4.b |
| The Component ISSM shall work directly with the HQ CISO. |
| --- |
The ISSM plays a critical role in ensuring that the DHS Information Security Program is implemented and maintained throughout the Component.
Component ISSMs:
· Oversee the Component information security program
· Ensure that the Component CIO and HQ CISO are kept apprised of all pertinent matters involving the security of information systems
· Ensure that information security-related decisions and information, including updates to the 4300 series of information security publications, are distributed to the ISSOs and other appropriate persons within their Component
· Validate all Component information system security reporting
· Consult with the Component Privacy Officer or Privacy Point of Contact (PPOC) for reporting and handling of privacy incidents
· Manage information security resources including oversight and review of security requirements in funding documents
· Periodically test the security of implemented systems
· Implement and manage a POA&M process for remediation
· Ensure that ISSOs are appointed for each information system managed at the Component level
· Ensure that weekly incident reports are forwarded to the HQ CISO
· Acknowledge receipt of Information Security Vulnerability Management (ISVM) messages, report compliance with requirements or notify the granting of waivers
· Ensure adherence to the DHS Secure Baseline Configuration Guides
· Develop and publish procedures necessary to implement the requirements of DHS information security policy within the appropriate Component
· Implement Department information security policies, procedures, and control techniques to address all applicable requirements
· Ensure training and oversight for personnel with significant responsibilities for information security
· Oversee the C&A process for MAs in use within the Component
· Maintain an independent Component-wide ST&E Program to ensure a consistent approach to testing of effectiveness of controls
· Ensure that an appropriate SOC performs an independent network assessment as part of the ST&E process for each application that is accredited
· Ensure that enterprise security tools are utilized
2.1.5 Risk Executive
A Risk Executive ensures that risks are managed consistently across the organization. In keeping with its organizational structure, DHS has two levels of Risk Executives – Departmental and Component. All DHS Risk Executives:
· Ensure that managing information system-related security risks is consistent across the organization, reflects organizational risk tolerance, and is performed as part of an organization-wide process that considers other organizational risks affecting mission/business success
· Ensure that information security considerations for individual information systems, including the specific authorization decisions for those systems, are viewed from an organization-wide perspective with regard to the overall strategic goals and objectives of the organization
· Provide visibility into the decisions of authorizing officials and a holistic view of risk to the organization beyond the risk associated with the operation and use of individual information systems
· Facilitate the sharing of security-related and risk-related information among authorizing officials and other senior leaders within the organization in order to help these officials consider all types of risks that may affect mission and business success and the overall interests of the organization at large
The DHS Risk Executive (the DHS CISO) develops information security policy, establishes the standards for system security risk, oversees risk management and monitoring, and approves all waivers and exceptions to DHS policy.
The Component Risk Executives (Component CISOs) may establish standards for system security risk more stringent than the DHS standard. They implement the system security risk management and monitoring program and submit requests for higher-risk deviations from the enterprise standard.
| Policy ID |
| DHS Policy Statements |
| Relevant Controls |
| 2.1.5.a |
| The DHS CISO shall be the DHS Risk Executive. |
| PL-1, PM-9 |
| 2.1.5.b |
| Each Component CISO shall be the Risk Executive within his or her Component. |
| PL-1, PM-9 |
2.1.6 Authorizing Official
The AO formally assumes responsibility for operating an information system at an acceptable level of risk.
| Policy ID |
| DHS Policy Statements |
| Relevant Controls |
| 2.1.6.a |
| The DHS CIO shall act as the AO for enterprise information systems or shall designate one in writing. |
| CA-6 |
| 2.1.6.b |
| The Component CIO shall act as the AO for Component information systems or shall designate one in writing. |
| CA-6 |
| 2.1.6.c |
| An AO may be responsible for more than one system. |
| CA-6 |
2.1.7 Certifying Official
A Certifying Official is assigned in writing to each information system by an appropriate Component official, typically the Component Head or Component CIO.
The Certifying Official and the team conducting a certification must be impartial, that is, free from any perceived or actual conflicts of interest with respect to the developmental, operational, and/or management chain of command associated with the information system or to the determination of security control effectiveness.
For systems with low impact, a Certifying Official and/or certifying team do not need to be independent so long as assessment results are carefully reviewed and analyzed by an independent team of experts to validate their completeness, consistency, and veracity.
The AO decides the required level of certifier independence based on the criticality and sensitivity of the information system and the ultimate risk to organizational operations, organizational assets, and individuals. The AO determines if the level of certifier independence is sufficient to provide confidence that the assessment results produced are sound and can be used to make credible, risk-based decisions.
| Policy ID |
| DHS Policy Statements |
| Relevant Controls |
| 2.1.7.a |
| The Component CISO shall serve as Certifying Official when no other person has been officially designated. |
| CA-4 |
| 2.1.7.b |
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .