SharePoint RFP Tech - IA Program Policy-Handbook FINAL as of 20090127.doc
DOC document 1 MB Posted
- Attached to
- SharePoint Integration and Support Services Federal contract opportunity
- Solicitation number
- HSCETC-10-R-00015
- Issued by
- Immigration and Customs Enforcement
About this file
DHS Sensitive Systems Handbook
View the file
Other files for this federal contract opportunity
Show all 37
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ICE IA Program Policy Handbook XXXXXX
This page intentionally left blank
DOCUMENT CHANGE HISTORY
| Version |
| Date |
| Description |
| 0.1 |
| May 27, 2008 |
| Draft Baseline Release |
| 0.2 |
| August 4, 2008 |
| Revised Draft for Implementation of ICE PTF Comments |
| 0.3 |
| September 2, 2008 |
| Rewrite based on DASM policy drafting recommendations |
| 0.5 |
| November 17, 2008 |
| Implementation of ICE Program Office Comments |
| 1.0 |
| December 16, 2008 |
| ICE Policy and Handbook Approval |
TABLE OF CONTENTS
11.0 Introduction
11.1 Overview
11.2 Authorities
21.3 Information Assurance Policy and Procedures Framework
31.4 Document Organization
41.5 Application
41.6 Waivers and Exceptions
41.6.1 U.S. Citizen Exception Requests
41.7 Information Sharing and Communication Strategy
51.8 Requests
62.0 definitions
62.1.1 Accreditation
62.1.2 Adequate Security
62.1.3 Assurance
62.1.4 Authentication
62.1.5 Authority to Operate (ATO)
62.1.6 Authorizing Official
62.1.7 Authorizing Official Designated Representative
62.1.8 Availability
72.1.9 Certification
72.1.10 Chief Information Officer (CIO)
72.1.11 Chief Information Security Officer (CISO)
72.1.12 Common Control
72.1.13 Compensating Security Control
72.1.14 Classified National Security Information
72.1.15 Component
72.1.16 Computer Security Incident Response Center (CSIRC)
82.1.17 Confidentiality
82.1.18 Configuration Control
82.1.19 External Information System
82.1.20 External Information System Service
82.1.21 External Information System Service Provider
82.1.22 Federal Information Security Management Act (FISMA)
82.1.23 Federal Information System
82.1.24 Hybrid Security Control
82.1.25 Incident
92.1.26 Information Assurance (IA)
92.1.27 Information Assurance Objective
92.1.28 Information Assurance Policy
92.1.29 Information Owner
92.1.30 Information Resources
92.1.31 Information Security Requirements
92.1.32 Information System
92.1.33 Information System Owner (ISO)
102.1.34 Information System Security Engineer
102.1.35 Information System Security Engineering
102.1.36 Information System-related Security Risks
102.1.37 Information System Security Officer (ISSO)
102.1.38 Information Technology (IT)
102.1.39 Integrity
102.1.40 Interconnection Security Agreement (ISA)
112.1.41 Information Security Controls
112.1.42 Information Technology General Control (ITGC)
112.1.43 Law Enforcement
112.1.44 Major Application
112.1.45 Operational Data
112.1.46 Organization
112.1.47 Non-repudiation
122.1.48 Personally Identifiable Information (PII)
122.1.49 Plan of Action and Milestones (POA&M)
122.1.50 Privacy Impact Assessment (PIA)
122.1.51 Privacy Threshold Analysis (PTA)
122.1.52 Procedure
122.1.53 Public Information
122.1.54 Risk
122.1.55 Risk Assessment
122.1.56 Risk Management
132.1.57 Security Authorization Boundary
132.1.58 Security Category
132.1.59 Security Control
132.1.60 Security Inheritance
132.1.61 Security Impact Analysis
132.1.62 Sensitive Information
142.1.63 Subsystem
142.1.64 System of Record Notice (SORN)
142.1.65 System Security Plan
142.1.66 System-specific Security Control
142.1.67 Threat
142.1.68 Threat Source
142.1.69 Trust Zone
142.1.70 Vital Records
152.1.71 Vulnerability
153.0 Roles and Responsibilities
153.1 Assistant Secretary (AS)
153.2 Deputy Assistant Secretary for Management (DASM)
163.3 Deputy Assistant Secretary for Operations (DASO)
163.4 ICE Chief Information Officer (CIO)
173.4.1 Director for the Architecture Division, OCIO
173.4.2 Director for the Engineering Division, OCIO
183.4.3 Director for the System Development Division, OCIO
183.4.4 Director for the Operations Division, OCIO
183.5 ICE Chief Information Security Officer (CISO)
203.5.1 Deputy Chief Information Security Officer (D-CISO)
213.5.2 Regional Information Assurance Manager (RIAM)
213.5.3 Security Operations Center (SOC)/Computer Security Incident Response Center (CSIRC) Manager
233.5.4 Security Risk Analyst
243.6 Chief Security Officer (CSO)
243.7 Privacy Officer
253.8 Program Managers
263.9 United States Computer Emergency Readiness Team (US-CERT)
263.10 Designated Accrediting Authority (DAA)
263.11 Information Systems Security Officer (ISSO) and Alternate ISSO (AISSO)
273.12 Information System Owners (ISO)
293.13 Chief Financial Officer (CFO)
293.14 Director, Office of Acquisitions Management, OCFO (OAM)
303.15 ICE Office of Professional Responsibility (OPR)
303.16 All Users of ICE Information Assets
314.0 management policies
314.1 Basic Requirements
314.2 Capital Planning and Investment Control
324.3 Contractors and Outsourced Operations
324.4 Performance Measures and Metrics
324.5 Continuity Planning for Critical DHS Assets
334.5.1 Continuity of Operations Planning (COOP)
334.5.2 IT Contingency Planning (CP)
344.6 System Life Cycle
344.7 Configuration Management
354.8 Risk Management
354.9 Certification and Accreditation (C&A), Remediation, and Reporting
374.10 IT Security Review and Assistance
374.11 Security Working Groups and Forums
374.11.1 CISO Board
384.11.2 DHS IT Security Training Working Group
384.12 IT Security Policy Violation and Disciplinary Action
384.13 Required Reporting
394.14 Privacy and Data Security
394.14.1 Personally Identifiable Information (PII)
404.14.2 Privacy Threshold Analyses (PTA)
414.14.3 Privacy Impact Assessments (PIA)
414.14.4 System of Record Notices (SORN)
414.14.5 Privacy Incident Reporting
424.14.6 E-Authentication
424.15 DHS Chief Financial Officer-Designated Financial Systems
455.0 operationaL POLICIES
455.1 Personnel
455.1.1 Citizenship, Personnel Screening, and Position Categorization
455.1.2 Rules of Behavior
455.1.3 Access to Sensitive Information
465.1.4 Separation of Duties
465.1.5 IT Security Awareness, Training, and Education
475.1.6 Separation from Duty
475.2 IT Physical Security
475.2.1 General Physical Access
485.2.2 Sensitive Facility
485.3 Media Controls
485.3.1 Media Protection
485.3.2 Media Marking
485.3.3 Media Sanitization and Disposal
495.3.4 Production, Input/Output Controls
495.4 Voice Communications Security
495.4.1 Private Branch Exchange
495.4.2 Telephone Communications
495.4.3 Voice Mail
495.5 Data Communications
495.5.1 Telecommunications Protection Techniques
505.5.2 Facsimiles
505.5.3 Video Teleconferencing
505.5.4 Voice over Data Networks
505.6 Wireless Communications
515.6.1 Wireless Systems
525.6.2 Wireless Portable Electronic Devices (PED)
535.6.2.1 Cellular Phones
535.6.2.2 Pagers
535.6.2.3 Multifunctional Wireless Devices
545.6.3 Wireless Tactical Systems
545.6.4 Radio Frequency Identification (RFID)
555.7 Overseas Communications
555.8 Equipment
555.8.1 Workstations
555.8.2 Laptop Computers and Other Mobile Computing Devices
565.8.3 Personally Owned Equipment and Software (Not owned by or contracted for by the Government)
565.8.4 Hardware and Software
565.8.5 Personal Use of Government Office Equipment and DHS IT Systems and/or Computers
575.8.6 Wireless Settings for Peripheral Equipment
575.9 Department Information Security Operations
585.9.1 Security Incidents and Incident Response and Reporting
595.9.2 Law Enforcement Incident Response
605.10 Documentation (Manuals, Network Diagrams)
605.11 Information and Data Backup
605.12 Converging Technologies
626.0
TECHNICAL POLICIES
626.1 Identification and Authentication
626.1.1 Passwords
636.2 Access Control
636.2.1 Automatic Account Lockout
636.2.2 Automatic Session Termination
646.2.3 Warning Banner
646.3 Auditing
656.4 Network and Communications Security
656.4.1 Remote Access and Dial-In
656.4.2 Network Security Monitoring
666.4.3 Network Connectivity
666.4.4 Firewalls
676.4.5 Internet Security
686.4.6 Email Security
686.4.7 Personal Email Accounts
686.4.8 Testing and Vulnerability Management
696.4.9 Peer-to-Peer Technology
696.5 Cryptography
706.5.1 Encryption
706.5.2 Public Key Infrastructure
716.5.3 Public Key/Private Key
736.6 Virus Protection
736.7 Product Assurance
747.0 Document Change Requests
748.0 Questions and Comments
29.0 Acronyms and Abbreviations
1.0 Introduction
This document articulates the U.S. Immigration and Customs Enforcement (ICE) Information Assurance (IA) Program policies and procedures for all ICE sensitive information and systems. This IA Program Policy Handbook serves as the framework for which to develop and integrate information assurance within the agency. When ICE Programs use the System Life Cycle (SLC) to develop and maintain Information Technology (IT) security documents, they must also incorporate the baseline security requirements (BLSRs) we include in this IA Program Policy Handbook and all other subsequent IA Program Handbook Attachments.
1.1 Overview
The ICE Information Assurance Program Policy Handbook is a baseline of policies, standards, and guidelines for all ICE Programs. This document provides direction and accountability to all users of ICE information assets for managing and protecting ICE sensitive information and systems. The policies and direction contained in this document are derived primarily from the Department of Homeland Security (DHS) 4300A Sensitive Systems Policy and Handbook. It also identifies policies relating to the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 Revision 2 information security controls.
ICE-specific policies and procedures for National Security Systems are covered in DHS National Security Systems Policy Directive 4300B and DHS 4300B National Security Systems Handbook. This ICE IA Program Handbook does not apply to systems that process, store, or transmit Classified National Security or National Intelligence Information.
All policy elements within this document are effective when issued. Any policy elements that have not been implemented within 90 days shall be considered an information assurance weakness. Either a system or program Plan of Action and Milestones (POA&M) must be generated by the ICE Information Assurance Division (IAD) to identify and track the information assurance weaknesses or submission of a waiver request must occur. ICE is presently using the DHS Security Compliance tools known as Requirements Management System (RMS) and Trusted Agent FISMA (TAF) for information assurance management. The ICE Information Assurance Division (IAD) within the Office of the Chief Information Officer (OCIO) maintains and manages access to these systems.
1.2 Authorities
1) Federal Information Security Management Act (FISMA) of 2002, November 25, 2002 2) Public Law 107-347, Title III of the E-Government Act of 2002 3) Executive Order 13231 of October 16, 2001, Critical Infrastructure Protection in the Information Age, as amended 4) 44 United States Code (U.S.C.), Section 3542, Postal Accountability and Enhancement Act of 2006, as amended 5) Title 36 Code of Federal Regulations (C.F.R.) Part 1236, Management of Vital Records, revised as of July 1, 2000 6) Presidential Decision Directive 7, Critical Infrastructure Identification, Prioritization, and Protection, December 17, 2003 7) Homeland Security Presidential Directive 12 (HSPD-12), Policy for a Common Identification Standard for Federal Employees and Contractors, August 27, 2004 8) Office of Management and Budget (OMB) Memorandum 07-16, Safeguarding Against and Responding to the Breach of Personally Identifiable Information, May 22, 2007 9) Department of State (DOS) 12 Foreign Affairs Manual (FAM) 600, Information Security Technology, June 22, 2000 10) DHS Management Directives (MD): namely MD 121-01-001, 140-01, 0470.2; 140-01 (formerly known as MD 4300.1); MD 4400.1; MD 4500.1; MD 4600.1; MD 11042.1; MD 11043; MD 11044; MD 11045; MD 11046; MD 11047; MD 11056.1; MD 11050.2; MD 0007.1; and MD 0121.1 11) National Institute of Standards and Technology (NIST) Special Publications (e.g., 800-16, 800-30, 800-34, 800-35, 800-36, 800-37, 800-39, 800-47, 800-50, 800-53, 800-53(A), 800-55, 800-64, 800-65, 800-70, 800-80, 800.88, 800-92, 800-97, 800-100, and 800-121) and all Federal Information Processing Standards (FIPS) 12) DHS MD 140-01 (formerly known as MD 4300.1) which includes DHS 4300 Series Policy and Handbooks, as amended 13) CNSS Instruction No. 4009, National Information Assurance Glossary, Revised June 2006
14) CNSS Instruction No. 1001, National Instruction on Classified Information Spillage, February 2008
1.3 Information Assurance Policy and Procedures Framework
The IA Program shall provide the structure and resources necessary to oversee the protection of information and information technology and support IA as a strategic organizational capability to enable DHS/ICE missions and business functions. The ICE IA Program is a framework for the strategic management of information-related risks and the consistent implementation of confidentiality, integrity, availability, and authentication controls.
In compliance with the Federal Information Security Management Act (FISMA), the ICE IA Program shall include the following primary functions.
· Information Assurance Governance – Develop and publish risk-based, cost-effective ICE IA policy, procedures, and control techniques to address all applicable requirements throughout the life cycle of each ICE information system to ensure compliance with applicable requirements.
· Information Assurance Awareness and Training –Establish and implement an in-depth Information Assurance Division Training Program for ICE federal and contractor personnel, and other users of ICE information and information assets. All ICE system users shall receive and shall successfully complete annual Information Assurance Awareness Training (IAAT). This includes training and oversight of personnel with significant responsibilities for IA with respect to such responsibilities.
· Capital Planning and Investment Control (CPIC) Integration – Establish a comprehensive framework to enable the development, institutionalization, assessment, and improvement of the ICE IA Program.
· Interconnecting Systems – Generate and manage written interconnection security agreements that specify the technical and information security requirements of the interconnection, define the responsibilities of the participating organizations, and specify the rules governing these interconnections based on a mutually acceptable level of risk.
· Information Assurance Performance Measures – Develop and establish quantifiable performance metrics based on IA performance goals and objectives that are easily obtainable, repeatable, relevant, useful, and measurable in order to capture and provide meaningful performance data to apply lessons learned, improve the effectiveness of existing information security controls, and plan for future controls to meet new information security requirements as they occur. This includes periodically testing and evaluating the effectiveness of information security policies, procedures and practices.
· Plan of Actions and Milestones – Establish and maintain a process for planning, implementing, evaluating, and documenting remedial action to address any deficiencies in the ICE IA policies, procedures, and practices.
· Contingency Planning – Ensure preparation and maintenance of plans and procedures to provide continuity of operations for information systems that support ICE operations and assets.
· Risk Management - Assess risk and magnitude of the harm resulting from unauthorized access, use, disclosure, disruption, modification, or destruction of information and information systems that support ICE operations and assets.
· Certification, Accreditation, and Security Assessments - Test and evaluate the effectiveness of information assurance policies, procedures, practices, and security controls to be performed with a frequency depending on risk, but no less than annually.
· Information Security Products and Services Acquisition – Plan for and provide adequate information assurance products and services for ICE networks, facilities, information systems, or groups of information systems, as appropriate.
· Incident Response – Define and implement subordinate procedures for detecting, reporting, and responding to ICE information security incidents.
· Security Operations Center – Develop and implement subordinate plans for providing adequate information security for ICE networks, facilities, and systems or groups of information systems.
· Configuration Management – Establish and manage a process for planning, implementing, evaluating, and documenting remedial actions to address any deficiencies in ICE information assurance policies, procedures, and practices.
1.4 Document Organization
The IA policies and procedures in this document are organized under the three overarching IA control areas: management, operational, and technical. These IA control areas are then broken down by NIST 800-53 Revision 2 control families where we differentiate the ICE-specific IA policy and procedures.
The document reflects ICE IA Policy statements along with corresponding procedures. IA policy traceability is by an identification number (ID#) within tables throughout this document that corresponds with the BLSR in the IA Requirements Traceability Matrix (RTM). The tables also include the following relevant compliance areas.
· Mandate – Policy that requires specific performance of ICE to meet Federal Information Security Management Act (FISMA), other public laws, and Federal Information Processing Standards (FIPS) and NIST security control requirements.
· Order – DHS-defined policy requirements within the DHS 4300A Sensitive Systems Policy or Handbook or any other DHS policy that ICE is enforcing to satisfy organizational demands and maintain Department operations.
· Standard – ICE-specific policy statements that are necessary to maintain the ICE security posture and appropriately manage risks so that no adverse effects occur to ICE operations and assets, individuals, other organizations, or the Nation.
1.5 Application
| ICE POLICY STATEMENT |
| ID# |
| COMPLIANCE |
AREA
All ICE federal and contractor personnel, and all others working on behalf of ICE accessing ICE data, shall comply with all IA requirements within this document and articulated in the DHS 4300 series policy and handbooks.
Order
1.6 Waivers and Exceptions
Refer to Attachment B of the DHS 4300A concerning the procedures defining the ICE waiver and exception policy.
DHS Policy
All waivers and exception requests for a specific system shall include the system name and system TrustedAgent FISMA (TAF) Inventory ID.
1.6.1 U.S. Citizen Exception Requests
Special procedures apply for exception to the requirement that persons accessing DHS systems be U.S. Citizens (policy 4.1.1e). Under normal conditions, only U.S. Citizens are allowed access to DHS systems and networks. However, at times there is a need to grant access to foreign nationals. Access for foreign nationals is normally a long-term commitment, and exceptions to appropriate policies are treated separately from standard exceptions and waivers. The approval chain for an exception to the U.S. Citizenship requirement flows through the Component Head, the Office of Security, and the Chief Information Officer. Attachment J to the DHS 4300A Sensitive Systems Handbook provides an electronic form for requesting exceptions to the U.S. Citizenship requirement.
1.7 Information Sharing and Communication Strategy
The DHS Security Operations Center (SOC) exchanges information with ICE SOC, Network Operations Centers (NOCs), the Homeland Secure Data Network (HSDN) SOC, the Intelligence Community, and with external organizations in order to facilitate the security and operation of the DHS network. This exchange enhances situational awareness and provides a common operating picture to network managers. The operating picture is developed from information obtained from “raw” fault, configuration management, accounting, performance, and security data. This data is monitored, collected, analyzed, processed, and reported by the NOCs and SOCs.
The DHS SOC is responsible for communicating other information such as incident reports, notifications, vulnerability alerts and operational statuses to the Component SOCs, Component CISOs/ISSMs or other identified Component points of contact.
The DHS SOC portal implements role-based user profiles that allow Components to use the website’s incident database capabilities. Users assigned to Component groups shall be able to perform actions such as:
· Entering incident information into the DHS SOC incident database
· Generating preformatted incident reports
· Initiating queries of the incident database
· Viewing FISMA incident reporting numbers
· Automating portions of the Information Security Vulnerability Management (ISVM) program
· Automating portions of the vulnerability assessment program.
1.8 Requests
Please send document change requests to this ICE IA Program Policy Handbook via email to ICE IADivision@dhs.gov.
Contact the ICE CISO at ICE IADivision@dhs.gov for policy and/or procedure clarifications.
2.0 definitions
The following definitions apply to the policies and procedures outlined in this document.
2.1.1 Accreditation
Accreditation is the official management decision by the Designated Accrediting Authority (DAA) that authorizes the operation of an IT system. It includes explicitly accepting the risk to agency operations, assets, or individuals, based on the implementation of an agreed-upon set of information security controls. The DAA accepts security responsibility for the operation of IA certified systems and officially declares that a specified IT system shall adequately protect related information.
2.1.2 Adequate Security
Adequate security is security commensurate with the risk and the magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of information.
2.1.3 Assurance
The grounds for confidence that the set of intended security controls in an information system are effective in their application.
2.1.4 Authentication
Verifying the identity of a user, process, or device, often as a prerequisite to allowing access to resources in an information system.
2.1.5 Authority to Operate (ATO)
The official management decision given by a senior ICE official to authorize operation of an information system and to explicitly accept the risk to ICE operations (including mission, functions, image, or reputation), ICE assets, individuals, other organizations, and the Nation based on the implementation of an agreed-upon set of security controls.
2.1.6 Authorizing Official
A senior ICE official with the authority to formally assume responsibility for operating an information system at an acceptable level of risk to ICE operations (including mission, functions, image, or reputation), ICE assets, individuals, other organizations, and the Nation.
For ICE, this individual is the ICE CISO.
2.1.7 Authorizing Official Designated Representative
An ICE official acting on behalf of an Authorizing Official in carrying out and coordinating the required activities associated with security authorization.
2.1.8 Availability
Availability is ensuring timely and reliable access to and use of information.
2.1.9 Certification
The testing and/or evaluation of the management, operational, and technical security controls in an information system to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system.
2.1.10 Chief Information Officer (CIO)
The senior ICE official responsible for (i) providing advice and other assistance to the Assistant Secretary and other senior management personnel of ICE to ensure that information technology is acquired and information resources are managed in a manner that is consistent with laws, Executive Orders, directives, policies, regulations, and priorities established by the ICE Assistant Secretary; (ii) developing, maintaining, and facilitating the implementation of a sound and integrated information technology architecture for ICE; and (iii) promoting the effective and efficient design and operation of all major information resources management processes for the agency, including improvements to work processes of ICE.
2.1.11 Chief Information Security Officer (CISO)
An ICE senior official responsible for carrying out the Chief Information Officer responsibilities under FISMA and serving as the Chief Information Officer’s primary liaison to ICE authorizing officials, information system owners, and information system security officers. This term is synonymous with Senior Agency Information Security Officer (SAISO).
2.1.12 Common Control
Common control is a security control that is inherited by an information system.
2.1.13 Compensating Security Control
The management, operational, and technical controls (i.e., safeguards or countermeasures) employed by an organization in lieu of the recommended controls in the low, moderate, or high baselines described in NIST Special Publication 800-53 or in Committee on National Security Systems (CNSS) Instruction 1253, that provide equivalent or comparable protection for an information system.
2.1.14 Classified National Security Information
Information that has been determined, pursuant to Executive Order 12958, as amended, or any predecessor order, to require protection against unauthorized disclosure and is marked to indicate its classified status (e.g. Confidential, Secret, or Top Secret).
2.1.15 Component
A constituent part of the ICE enterprise architecture that serves as an element of a system.
2.1.16 Computer Security Incident Response Center (CSIRC)
The CSIRC is capable of responding to computer incidents 24 hours a day, 7 days a week and maintains an open bridge line to provide rapid, scalable access. It provides technical assistance, shares security advisories, and facilitates two-way information sharing. The CSIRC works with the Secure Operations Center (SOC) to detect and respond to suspected and confirmed incidents and interacts with the U.S.-Computer Emergency Response Team (US-CERT) as required.
2.1.17 Confidentiality
Preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information.
2.1.18 Configuration Control
Configuration control is a process for controlling modifications to hardware, firmware, software, and documentation to protect the information system against improper modifications before, during, and after system implementation.
2.1.19 External Information System
External information system is an information system or component of an information system that is outside of the authorization boundary established by ICE and for which ICE typically has no direct control over the application of required security controls or the assessment of security control effectiveness.
2.1.20 External Information System Service
An information system service that is implemented outside of the authorization boundary of an ICE information system (i.e., a service that is used by, but not a part of, an ICE information system).
2.1.21 External Information System Service Provider
A provider of external information system services to ICE through a variety of consumer-producer relationships, including but not limited to: service level agreements, outsourcing arrangements (i.e., through contracts, interagency agreements); licensing agreements; and/or federal exchanges.
2.1.22 Federal Information Security Management Act (FISMA)
FISMA directs that all Federal agencies develop and implement an agency-wide information system security program designed to safeguard IT assets and data. DHS bases its C&A policy on the recommendations set forth in NIST SP 800-37, Guide for the Security Certification and Accreditation of Federal Information Systems, and OMB Circular A-130, Appendix III, Security of Federal Automated Information Resources.
2.1.23 Federal Information System
A federal information system is an information system used or operated by a federal agency, or by a contractor of a federal agency or by another organization on behalf of a federal agency. By definition, ICE is a “federal agency”.
2.1.24 Hybrid Security Control
A hybrid security control is part common control and part system-specific control.
2.1.25 Incident
An occurrence that actually or potentially jeopardizes the confidentiality, integrity, or availability of an information system or the information the system processes, stores, or transmits or that constitutes a violation or imminent threat of violation of security policies, security procedures, or acceptable use policies.
2.1.26 Information Assurance (IA)
Information Assurance is the practice of protecting information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide availability, integrity, authentication, confidentiality, and non-repudiation. This includes providing for restoration of information systems by incorporating a protection, detection, and reaction capability.
2.1.27 Information Assurance Objective
Information assurance objectives are confidentiality, integrity, authentication, availability, and non-repudiation.
2.1.28 Information Assurance Policy
Aggregate of directives, regulations, rules, and practices that prescribe how ICE manages, protects, and distributes information.
2.1.29 Information Owner
Information owners are officials with statutory or operational authority for specified information and responsibility for establishing the controls for its generation, collection, processing, dissemination, and disposal.
2.1.30 Information Resources
Information resources are information and related resources, such as personnel, equipment, funds, and information technology.
2.1.31 Information Security Requirements
Requirements levied on an information system that are derived from applicable laws, Executive Orders, directives, policies, standards, instructions, regulations, procedures, or organizational mission and/or business case needs to ensure the confidentiality, integrity, and availability of the information being processed, stored, or transmitted.
2.1.32 Information System
A discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information in accordance with defined procedures, whether automated or manual that is used by ICE, a contractor, or another organization operating on behalf of ICE.
2.1.33 Information System Owner (ISO)
Information system owners are officials responsible for the overall procurement, development, integration, modification, operation, and maintenance of an information system. For ICE, this individual is the Program Manager.
2.1.34 Information System Security Engineer
Individual assigned responsibility for conducting information system security engineering activities.
2.1.35 Information System Security Engineering
Information system security engineering is a process that captures and refines information security requirements and ensures their integration into information technology component products and information systems through purposeful security design or configuration.
2.1.36 Information System-related Security Risks
Information system-related security risks are those risks that arise through the loss of confidentiality, integrity, authentication, availability, or non-repudiation of information or information systems and consider impacts to ICE (including assets, mission, functions, image, or reputation), individuals, other organizations, and the Nation.
2.1.37 Information System Security Officer (ISSO)
Individual assigned responsibility for maintaining the appropriate operational security posture for an information system or program. An Information Systems Security Officer (ISSO) shall be appointed in writing by the Program/Business Manager for each ICE IT system. An ISSO may either be an appropriately cleared (i.e., 5C, 6C, T1, or T2) Federal employee or support contractor and may be assigned to more than one system and is responsible for ensuring the implementation and effectiveness of security controls in accordance with Department policies. For DHS CFO-designated financial systems, ISSO duties shall not be assigned as a collateral duty and no other significant collateral duties shall be assigned.
2.1.38 Information Technology (IT)
Any equipment or interconnected system or subsystem of equipment that is used in the automatic acquisition, storage, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the executive agency. For purposes of the preceding sentence, equipment is used by ICE if the equipment is used by ICE directly or is used by a contractor under a contract with ICE which: (i) requires the use of such equipment or (ii) requires the use, to a significant extent, of such equipment in the performance of a service or the furnishing of a product. The term information technology includes computers, ancillary equipment, software, firmware and similar procedures, services (including support services), and related resources.
2.1.39 Integrity
Guarding against improper information modification or destruction, and includes ensuring information non-repudiation and authenticity.
2.1.40 Interconnection Security Agreement (ISA)
An agreement established between the organizations that own and operate connected IT systems to document the technical requirements of the interconnection.
2.1.41 Information Security Controls
The management, operational, and technical controls (i.e., safeguards or countermeasures) prescribed for an information system to protect the confidentiality, integrity, and availability of the system or its information.
2.1.42 Information Technology General Control (ITGC)
ITGCs represent the foundation of the IT control structure. They help ensure the reliability of data generated by IT systems and support the assertion that systems operate as intended and that output is reliable.
2.1.43 Law Enforcement
Law enforcement organizations include those DHS entities engaged in the protection of U.S. citizens and national infrastructure assets, as well as the enforcement of immigration, customs, transportation, and financial laws including, but not limited to: financial crimes, export violations related to defense munitions items and strategic dual-use technology, drug and contraband smuggling, human smuggling and trafficking, identity document and immigration benefit fraud, visa violations, alien migration interdiction, worksite enforcement, intellectual property, trade related commercial fraud, child pornography, counterfeiting and financial, cyber, air piracy, and organized crime.
2.1.44 Major Application
A major application (MA) is an automated information system (AIS) that “requires special attention to security due to the risk and magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of the information in the application.
” Note: All Federal applications require some level of protection. However, certain applications, because of the information in them, require special management oversight and should be treated as major. An MA is distinguishable from a GSS by the fact that it is a discrete application, whereas a GSS may support multiple applications. Each major application must be under the direct oversight of a Component CISO/ISSM and must have one or more Information Systems Security Officers (ISSO) assigned.
2.1.45 Operational Data
Operational data is information used in the execution of any ICE mission.
2.1.46 Organization
An organization is a federal agency or, as appropriate, any of its operational elements.
ICE is an organization.
2.1.47 Non-repudiation
Assurance that sender and recipient identities of a message are provided so that neither can later deny having possessed the data.
2.1.48 Personally Identifiable Information (PII)
Information that permits the identity of an individual to be directly or indirectly inferred, including any other information that is linked or linkable to that individual regardless of whether the individual is a U.S. Citizen, Legal Permanent Resident, or a visitor to the U.S. This definition includes information about DHS employees and contractors or any other individuals who may be external to the organization.
2.1.49 Plan of Action and Milestones (POA&M)
A document that identifies tasks needing to be accomplished, resources required to accomplish the elements of the plan, any milestones in meeting the tasks, and scheduled completion dates for the milestones.
2.1.50 Privacy Impact Assessment (PIA)
The Privacy Impact Assessment is the mechanism required by Section 208 of the E-Government Act of 2002 to assess a system's potential impact on privacy.
2.1.51 Privacy Threshold Analysis (PTA)
This is an administrative form to efficiently and effectively identify the use of Personally Identifiable Information (PII) for every IT project to determine the need for further privacy compliance analysis.
2.1.52 Procedure
A specification of series of actions, acts or operations which have to be executed in the same manner in order to always obtain the same result in the same circumstances. A procedure may also indicate a sequence of activities, tasks, steps, decisions, calculations and processes, that when undertaken in the sequence laid down produces the described result, product or outcome.
2.1.53 Public Information
This type of information can be disclosed to the public without restriction but requires protection against erroneous manipulation or alteration (e.g., Public Web sites).
2.1.54 Risk
A measure of the extent to which an entity is threatened by a potential circumstance or event and typically a function of the likelihood of the circumstances or event occurring and of the resulting adverse impacts.
2.1.55 Risk Assessment
The process of determining risks, that is, determining the extent to which an entity is threatened by potential, adverse circumstances or events. Risk assessment is part of risk management and is conducted throughout the Risk Management Framework (RMF).
2.1.56 Risk Management
Risk management is a management process employed by ICE to achieve and maintain an acceptable level of risk. The Risk Management Framework describes the recommended process for managing information system-related security risks.
2.1.57 Security Authorization Boundary
All components of an information system to be authorized for operation by an authorizing official and excludes separately authorized systems, to which the information system is connected.
2.1.58 Security Category
The characterization of information or an information system based on an assessment of the potential impact that a loss of confidentiality, integrity, or availability of such information or information system would have on ICE operations, ICE assets, individuals, other organizations, or the Nation.
2.1.59 Security Control
Security safeguards applied to an information system. They are grouped into three families of controls (management, operational, and technical), based upon who or what executes the control.
2.1.60 Security Inheritance
A situation in which an information system or application receives protection from security controls (or portions of security controls) that are developed, implemented, and assessed for effectiveness by other entities either internal or external to ICE where the system or application resides.
2.1.61 Security Impact Analysis
The analysis conducted by an ICE official, often during the maintenance phase of the security authorization process, to determine the extent to which changes to an information system or its environment or operation have impacted the security state of the system.
2.1.62 Sensitive Information
“Sensitive information” is information not otherwise categorized by statute or regulation that, if disclosed, could have an adverse impact on the welfare or privacy of individuals or on the welfare or conduct of Federal programs or other programs or operations essential to the national interest. Examples of sensitive information include personal data such as Social Security Number; trade secrets; system vulnerability information; pre-solicitation procurement documents, such as statements of work; and law enforcement investigative methods. Similarly, detailed reports related to computer security deficiencies in internal controls are also sensitive information because of the potential damage that could be caused by the misuse of this information. Information concerning financial systems shall be identified as Sensitive Financial Information if, on another system, it would be identified as system vulnerability information. All sensitive information must be protected from loss, misuse, modification, and unauthorized access.
With the exception of certain types of information protected by statute (e.g., Sensitive Security Information, Critical Infrastructure Information), there are no specific Federal criteria and no standard terminology for designating types of sensitive information. Such designations are left to the discretion of each individual Federal agency. “For Official Use Only” (FOUO) is the term used within DHS to identify unclassified information of a sensitive nature that is not otherwise categorized by statute or regulation.
2.1.63 Subsystem
A subsystem is a major subdivision or component of an information system consisting of information, information technology, and personnel that performs one or more specific functions.
2.1.64 System of Record Notice (SORN)
The SORN is a public notice required by the Privacy Act of 1974, as amended, that describes how and why an agency maintains, uses, and shares personal information about U.S. citizens and lawful permanent residents. A SORN is generally required when an individual’s name or other unique identifier is used to retrieve other associated information from a system.
2.1.65 System Security Plan
Formal document that provides an overview of the security requirements for the information system and describes the security controls in place or planned for meeting those requirements.
2.1.66 System-specific Security Control
A system-specific security control is a security control for an information system that has not been designated as a common control.
2.1.67 Threat
Any circumstance or event with the potential to adversely impact ICE operations (including mission, functions, image, or reputation), ICE assets, individuals, other organizations, or the Nation through an information system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service.
2.1.68 Threat Source
The intent and method targeted at the intentional exploitation of a vulnerability or a situation and method that may accidentally trigger a vulnerability. This term is synonymous with threat agent.
2.1.69 Trust Zone
A Trust Zone consists of a group of people, information resources, data systems, and/or networks subject to a shared security policy (set of rules governing access to data and services). For example, a Trust Zone may be set up between different network segments that require specific usage policies based on information processed, such as law enforcement information.
2.1.70 Vital Records
Electronic and hardcopy documents, references, records, databases, and IT systems needed to support essential functions under the full spectrum of emergencies. Categories of these types of records may include:
· Emergency operating records—emergency plans and directive(s), orders of succession, delegations of authority, staffing assignments, selected program records needed to continue the most critical agency operations, as well as related policy or procedural records.
· Legal and financial rights records—protect the legal and financial rights of the Government and of the individuals directly affected by its activities. Examples include accounts receivable records, social security records, payroll records, retirement records, and insurance records. These records were formerly defined as “rights-and-interests” records.
· Records used to perform national security preparedness functions and activities (E.O. 12656).
2.1.71 Vulnerability
A flaw or weakness in a system’s design, implementation, operation, or management that would allow unauthorized use or unauthorized access to the system.
3.0 Roles and Responsibilities
Protecting the ICE IT infrastructure and data is a responsibility for all users. In addition to the general user community, various ICE positions retain a certain delegated and specialized IA support function. The following is a list of roles and responsibilities within the IA support structure.
3.1 Assistant Secretary (AS)
The ICE Assistant Secretary (AS) shall:
· Ensure that information security processes are integrated with strategic and operational planning processes to secure ICE missions.
· Ensure that an information security program is developed, documented, and implemented to provide security for all systems, networks, and data that support the operations of the organization acquisition strategies and oversight of procurement activities and contracts.
· Ensure that senior officials within ICE are given the necessary authority to secure the operations and assets under their control.
· Appoint the Chief Information Officer (CIO) as appropriate and delegating authority to that individual to ensure compliance with applicable information security requirements.
· Ensure that the CIO, in coordination with the other ICE senior officials, reports annually to the ICE Assistant Secretary on the effectiveness of the ICE IA Program, including the progress of remedial actions.
· Ensure that adequate funding for IA is provided for ICE IT systems and that adequate funding requirements are included for all IT systems budgets.
· Ensure that IT system data are entered into the appropriate DHS Security Management Tools to support DHS IA oversight and FISMA reporting requirements.
· Ensure that the requirements for an IA performance metrics program are implemented.
3.2 Deputy Assistant Secretary for Management (DASM)
The Deputy Assistant Secretary for Management (DASM) shall:
· Appoint the ICE Chief Information Security Officer (CISO)
· Ensure that ICE has highly trained personnel to support compliance with IA policies, processes, standards, and guidelines.
· Provide secure financial management policies, standards and systems.
· Establish secure acquisition and contract management strategies.
· Ensure that management entities within the Office of the Deputy Assistant Secretary for Management adhere to and are compliant with all aspects of the IA policy and any subsequent handbooks.
3.3 Deputy Assistant Secretary for Operations (DASO)
The Deputy Assistant Secretary for Operations (DASO) shall:
· Ensure that operational entities within the Office of the Deputy Assistant Secretary for Operations adhere to and are compliant with all aspects of the IA policy and any subsequent handbooks.
3.4 ICE Chief Information Officer (CIO)
The ICE Chief Information Officer (CIO) shall provide management direction to ICE information security operations and is the principal advocate for ICE information security incident response. The ICE CIO will either be the DAA for or designate in writing a DAA for ICE general support systems. The ICE CIO shall:
· Establish and oversee the ICE Information Assurance Program.
· Ensure appointment of an ICE Chief Information Security Officer (CISO) and ensure that the CISO has resources to assist in ensuring compliance with all relevant IA policy.
· Maintain IA policies, procedures, and control techniques to address all applicable requirements.
· Report annually, in coordination with the other ICE senior officials, to the Assistant Secretary on the effectiveness of the ICE IA Program, including progress of remedial actions.
· Serve as the DAA for any IT system where a DAA has not been appointed or where a vacancy exists.
· Ensure that IA concerns are addressed by an ICE Configuration Control Board (CCB), Architecture Review Board (ARB), and Investment Review Board (IRB).
· Ensure that an accurate IT systems inventory is established and maintained.
· Ensure that an IA performance metrics program is developed, implemented, and funded.
· Advise the DHS CIO of any issues regarding infrastructure protection, vulnerabilities or issues that may cause public concern or loss of credibility.
· Ensure that information security incidents are reported to the DHS SOC within reporting time requirements as defined in F of the DHS 4300A Sensitive Systems Handbook.
· Work with the DHS CIO and Public Affairs Office in preparation for public release of information security incident information. The DHS CIO, or designated representative, has sole responsibility for public release of security incident information.
· Ensure compliance with DHS IT policy and all other applicable IA policy requirements.
The CIO shall be responsible for overseeing implementation and compliance of ICE Chief Financial Office-designated financial systems. The CIO shall:
· Review and evaluate the ICE CFO-designated financial systems to ensure IT General Controls (ITGCs) are in place and working effectively.
· Work with the system owners to ensure remediation of ITGC deficiencies related to ICE CFO-designated financial systems.
· Track and monitor progress of ITGC POA&Ms and remediation efforts for ICE.
· Ensure completion of Memoranda of Understanding (MOUs) and Interconnection Security Agreements (ISAs) for CFO-designated financial system interconnections with any system not owned by DHS; ensure that they include appropriate information security clauses; and monitor service provider for compliance with MOUs and ISAs.
· Implement the Department-wide system development lifecycle methodology and monitor user compliance.
· As part of developing new financial applications or updating existing applications, integrate CFO feedback to ensure user requirements are adequately addressed.
· Develop and test ICE disaster recovery plan. Coordinate with ICE CFO to incorporate business continuity requirements and test on a periodic basis.
· Based on ICE CFO requirements, execute policies for the routine backup and recovery of financial data. Implement policies and procedures for rotating backup media off-site.
3.4.1 Director for the Architecture Division, OCIO
The Director for the…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .