SharePoint RFP Tech - IA Program Policy-Handbook FINAL as of 20090127.doc

DOC document 1 MB Posted

Attached to
SharePoint Integration and Support Services Federal contract opportunity
Solicitation number
HSCETC-10-R-00015
Issued by
Immigration and Customs Enforcement

About this file

DHS Sensitive Systems Handbook

View the file

Other files for this federal contract opportunity

Other files attached to SharePoint Integration and Support Services, newest first.
File Type Posted
HSCETC-10-R-00015 A0003.pdf PDF
Attachment 3-Pricing Matrix.xls XLS spreadsheet
Attach 7DD254.pdf PDF
Attach 4 OCIO.doc DOC document
A0002 Sol 55-64.pdf PDF
Attach 1 SOW —
A0002 Sol 116-131.pdf PDF
A0002 Sol 5-54.pdf PDF
Attach 2 PPQ.doc DOC document
Attach 6ClassContract.pdf PDF
A0002CoverSheet.pdf PDF
A0002 Sol 65-115.pdf PDF
HSCETC-10-R-00015P0001.pdf PDF
RFPQuestionSharePoint 4 20 20 final.pdf PDF
SharePoint RFP Tech - ICE_MOSS 20Intranet 20Physical 20Production 20Topology_jpg.jpg JPG image
SharePoint RFP - Section B - M.doc DOC document
SharePoint RFP - Section A.pdf PDF
SharePoint RFP Tech - SLM 20Hand 20Book.pdf PDF
SharePoint RFP - Attach 4 - OCI Disclosure Forms.pdf PDF
SharePoint RFP Tech - 33443 Information Assurance Program Policy FINAL asof 20100309.doc DOC document
SharePoint RFP Tech - DHS_Sensitive_Systems_Policy_4300A_v7dot1.doc DOC document
SharePoint RFP Tech - Table of Contents - ICE- OCIO Technical Documents .doc DOC document
SharePoint RFP Tech - DHS 20MD 20140-02.pdf PDF
SharePoint RFP Tech - SLM 20Test 20Evaluation.pdf PDF
SharePoint RFP - Attach 2 -Past Perf Questions.pdf PDF
SharePoint RFP Tech - Standards Web Services .doc DOC document
SharePoint RFP - Response to Questions Asked at Pre-Proposal Conference —
SharePoint RFP Tech - SLM 20Tech 20Ref 20guide 20Book.pdf PDF
SharePoint RFP - Attach 3 - Pricing Matrix.pdf PDF
SharePoint RFP Tech - Systems 20Assurance 20Plan.pdf PDF
SharePoint RFP - Attach 1- TO SOW.pdf PDF
SharePoint - Pre-Proposal Conference Presentation —
SharePoint - Pre-Proposal Conference - List of Registrants.xls XLS spreadsheet
SharePoint - Answers to Questions on Draft SOW.doc DOC document
SharePoint - Registration Form.doc DOC document
SharePoint - SOW.doc DOC document
SharePoint - SOW_Task Order1.doc DOC document
Show all 37

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ICE IA Program Policy Handbook XXXXXX

This page intentionally left blank

DOCUMENT CHANGE HISTORY

Version
Date
Description
0.1
May 27, 2008
Draft Baseline Release
0.2
August 4, 2008
Revised Draft for Implementation of ICE PTF Comments
0.3
September 2, 2008
Rewrite based on DASM policy drafting recommendations
0.5
November 17, 2008
Implementation of ICE Program Office Comments
1.0
December 16, 2008
ICE Policy and Handbook Approval

TABLE OF CONTENTS

11.0 Introduction

11.1 Overview

11.2 Authorities

21.3 Information Assurance Policy and Procedures Framework

31.4 Document Organization

41.5 Application

41.6 Waivers and Exceptions

41.6.1 U.S. Citizen Exception Requests

41.7 Information Sharing and Communication Strategy

51.8 Requests

62.0 definitions

62.1.1 Accreditation

62.1.2 Adequate Security

62.1.3 Assurance

62.1.4 Authentication

62.1.5 Authority to Operate (ATO)

62.1.6 Authorizing Official

62.1.7 Authorizing Official Designated Representative

62.1.8 Availability

72.1.9 Certification

72.1.10 Chief Information Officer (CIO)

72.1.11 Chief Information Security Officer (CISO)

72.1.12 Common Control

72.1.13 Compensating Security Control

72.1.14 Classified National Security Information

72.1.15 Component

72.1.16 Computer Security Incident Response Center (CSIRC)

82.1.17 Confidentiality

82.1.18 Configuration Control

82.1.19 External Information System

82.1.20 External Information System Service

82.1.21 External Information System Service Provider

82.1.22 Federal Information Security Management Act (FISMA)

82.1.23 Federal Information System

82.1.24 Hybrid Security Control

82.1.25 Incident

92.1.26 Information Assurance (IA)

92.1.27 Information Assurance Objective

92.1.28 Information Assurance Policy

92.1.29 Information Owner

92.1.30 Information Resources

92.1.31 Information Security Requirements

92.1.32 Information System

92.1.33 Information System Owner (ISO)

102.1.34 Information System Security Engineer

102.1.35 Information System Security Engineering

102.1.36 Information System-related Security Risks

102.1.37 Information System Security Officer (ISSO)

102.1.38 Information Technology (IT)

102.1.39 Integrity

102.1.40 Interconnection Security Agreement (ISA)

112.1.41 Information Security Controls

112.1.42 Information Technology General Control (ITGC)

112.1.43 Law Enforcement

112.1.44 Major Application

112.1.45 Operational Data

112.1.46 Organization

112.1.47 Non-repudiation

122.1.48 Personally Identifiable Information (PII)

122.1.49 Plan of Action and Milestones (POA&M)

122.1.50 Privacy Impact Assessment (PIA)

122.1.51 Privacy Threshold Analysis (PTA)

122.1.52 Procedure

122.1.53 Public Information

122.1.54 Risk

122.1.55 Risk Assessment

122.1.56 Risk Management

132.1.57 Security Authorization Boundary

132.1.58 Security Category

132.1.59 Security Control

132.1.60 Security Inheritance

132.1.61 Security Impact Analysis

132.1.62 Sensitive Information

142.1.63 Subsystem

142.1.64 System of Record Notice (SORN)

142.1.65 System Security Plan

142.1.66 System-specific Security Control

142.1.67 Threat

142.1.68 Threat Source

142.1.69 Trust Zone

142.1.70 Vital Records

152.1.71 Vulnerability

153.0 Roles and Responsibilities

153.1 Assistant Secretary (AS)

153.2 Deputy Assistant Secretary for Management (DASM)

163.3 Deputy Assistant Secretary for Operations (DASO)

163.4 ICE Chief Information Officer (CIO)

173.4.1 Director for the Architecture Division, OCIO

173.4.2 Director for the Engineering Division, OCIO

183.4.3 Director for the System Development Division, OCIO

183.4.4 Director for the Operations Division, OCIO

183.5 ICE Chief Information Security Officer (CISO)

203.5.1 Deputy Chief Information Security Officer (D-CISO)

213.5.2 Regional Information Assurance Manager (RIAM)

213.5.3 Security Operations Center (SOC)/Computer Security Incident Response Center (CSIRC) Manager

233.5.4 Security Risk Analyst

243.6 Chief Security Officer (CSO)

243.7 Privacy Officer

253.8 Program Managers

263.9 United States Computer Emergency Readiness Team (US-CERT)

263.10 Designated Accrediting Authority (DAA)

263.11 Information Systems Security Officer (ISSO) and Alternate ISSO (AISSO)

273.12 Information System Owners (ISO)

293.13 Chief Financial Officer (CFO)

293.14 Director, Office of Acquisitions Management, OCFO (OAM)

303.15 ICE Office of Professional Responsibility (OPR)

303.16 All Users of ICE Information Assets

314.0 management policies

314.1 Basic Requirements

314.2 Capital Planning and Investment Control

324.3 Contractors and Outsourced Operations

324.4 Performance Measures and Metrics

324.5 Continuity Planning for Critical DHS Assets

334.5.1 Continuity of Operations Planning (COOP)

334.5.2 IT Contingency Planning (CP)

344.6 System Life Cycle

344.7 Configuration Management

354.8 Risk Management

354.9 Certification and Accreditation (C&A), Remediation, and Reporting

374.10 IT Security Review and Assistance

374.11 Security Working Groups and Forums

374.11.1 CISO Board

384.11.2 DHS IT Security Training Working Group

384.12 IT Security Policy Violation and Disciplinary Action

384.13 Required Reporting

394.14 Privacy and Data Security

394.14.1 Personally Identifiable Information (PII)

404.14.2 Privacy Threshold Analyses (PTA)

414.14.3 Privacy Impact Assessments (PIA)

414.14.4 System of Record Notices (SORN)

414.14.5 Privacy Incident Reporting

424.14.6 E-Authentication

424.15 DHS Chief Financial Officer-Designated Financial Systems

455.0 operationaL POLICIES

455.1 Personnel

455.1.1 Citizenship, Personnel Screening, and Position Categorization

455.1.2 Rules of Behavior

455.1.3 Access to Sensitive Information

465.1.4 Separation of Duties

465.1.5 IT Security Awareness, Training, and Education

475.1.6 Separation from Duty

475.2 IT Physical Security

475.2.1 General Physical Access

485.2.2 Sensitive Facility

485.3 Media Controls

485.3.1 Media Protection

485.3.2 Media Marking

485.3.3 Media Sanitization and Disposal

495.3.4 Production, Input/Output Controls

495.4 Voice Communications Security

495.4.1 Private Branch Exchange

495.4.2 Telephone Communications

495.4.3 Voice Mail

495.5 Data Communications

495.5.1 Telecommunications Protection Techniques

505.5.2 Facsimiles

505.5.3 Video Teleconferencing

505.5.4 Voice over Data Networks

505.6 Wireless Communications

515.6.1 Wireless Systems

525.6.2 Wireless Portable Electronic Devices (PED)

535.6.2.1 Cellular Phones

535.6.2.2 Pagers

535.6.2.3 Multifunctional Wireless Devices

545.6.3 Wireless Tactical Systems

545.6.4 Radio Frequency Identification (RFID)

555.7 Overseas Communications

555.8 Equipment

555.8.1 Workstations

555.8.2 Laptop Computers and Other Mobile Computing Devices

565.8.3 Personally Owned Equipment and Software (Not owned by or contracted for by the Government)

565.8.4 Hardware and Software

565.8.5 Personal Use of Government Office Equipment and DHS IT Systems and/or Computers

575.8.6 Wireless Settings for Peripheral Equipment

575.9 Department Information Security Operations

585.9.1 Security Incidents and Incident Response and Reporting

595.9.2 Law Enforcement Incident Response

605.10 Documentation (Manuals, Network Diagrams)

605.11 Information and Data Backup

605.12 Converging Technologies

626.0

TECHNICAL POLICIES

626.1 Identification and Authentication

626.1.1 Passwords

636.2 Access Control

636.2.1 Automatic Account Lockout

636.2.2 Automatic Session Termination

646.2.3 Warning Banner

646.3 Auditing

656.4 Network and Communications Security

656.4.1 Remote Access and Dial-In

656.4.2 Network Security Monitoring

666.4.3 Network Connectivity

666.4.4 Firewalls

676.4.5 Internet Security

686.4.6 Email Security

686.4.7 Personal Email Accounts

686.4.8 Testing and Vulnerability Management

696.4.9 Peer-to-Peer Technology

696.5 Cryptography

706.5.1 Encryption

706.5.2 Public Key Infrastructure

716.5.3 Public Key/Private Key

736.6 Virus Protection

736.7 Product Assurance

747.0 Document Change Requests

748.0 Questions and Comments

29.0 Acronyms and Abbreviations

1.0 Introduction

This document articulates the U.S. Immigration and Customs Enforcement (ICE) Information Assurance (IA) Program policies and procedures for all ICE sensitive information and systems. This IA Program Policy Handbook serves as the framework for which to develop and integrate information assurance within the agency. When ICE Programs use the System Life Cycle (SLC) to develop and maintain Information Technology (IT) security documents, they must also incorporate the baseline security requirements (BLSRs) we include in this IA Program Policy Handbook and all other subsequent IA Program Handbook Attachments.

1.1 Overview

The ICE Information Assurance Program Policy Handbook is a baseline of policies, standards, and guidelines for all ICE Programs. This document provides direction and accountability to all users of ICE information assets for managing and protecting ICE sensitive information and systems. The policies and direction contained in this document are derived primarily from the Department of Homeland Security (DHS) 4300A Sensitive Systems Policy and Handbook. It also identifies policies relating to the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 Revision 2 information security controls.

ICE-specific policies and procedures for National Security Systems are covered in DHS National Security Systems Policy Directive 4300B and DHS 4300B National Security Systems Handbook. This ICE IA Program Handbook does not apply to systems that process, store, or transmit Classified National Security or National Intelligence Information.

All policy elements within this document are effective when issued. Any policy elements that have not been implemented within 90 days shall be considered an information assurance weakness. Either a system or program Plan of Action and Milestones (POA&M) must be generated by the ICE Information Assurance Division (IAD) to identify and track the information assurance weaknesses or submission of a waiver request must occur. ICE is presently using the DHS Security Compliance tools known as Requirements Management System (RMS) and Trusted Agent FISMA (TAF) for information assurance management. The ICE Information Assurance Division (IAD) within the Office of the Chief Information Officer (OCIO) maintains and manages access to these systems.

1.2 Authorities

1) Federal Information Security Management Act (FISMA) of 2002, November 25, 2002 2) Public Law 107-347, Title III of the E-Government Act of 2002 3) Executive Order 13231 of October 16, 2001, Critical Infrastructure Protection in the Information Age, as amended 4) 44 United States Code (U.S.C.), Section 3542, Postal Accountability and Enhancement Act of 2006, as amended 5) Title 36 Code of Federal Regulations (C.F.R.) Part 1236, Management of Vital Records, revised as of July 1, 2000 6) Presidential Decision Directive 7, Critical Infrastructure Identification, Prioritization, and Protection, December 17, 2003 7) Homeland Security Presidential Directive 12 (HSPD-12), Policy for a Common Identification Standard for Federal Employees and Contractors, August 27, 2004 8) Office of Management and Budget (OMB) Memorandum 07-16, Safeguarding Against and Responding to the Breach of Personally Identifiable Information, May 22, 2007 9) Department of State (DOS) 12 Foreign Affairs Manual (FAM) 600, Information Security Technology, June 22, 2000 10) DHS Management Directives (MD): namely MD 121-01-001, 140-01, 0470.2; 140-01 (formerly known as MD 4300.1); MD 4400.1; MD 4500.1; MD 4600.1; MD 11042.1; MD 11043; MD 11044; MD 11045; MD 11046; MD 11047; MD 11056.1; MD 11050.2; MD 0007.1; and MD 0121.1 11) National Institute of Standards and Technology (NIST) Special Publications (e.g., 800-16, 800-30, 800-34, 800-35, 800-36, 800-37, 800-39, 800-47, 800-50, 800-53, 800-53(A), 800-55, 800-64, 800-65, 800-70, 800-80, 800.88, 800-92, 800-97, 800-100, and 800-121) and all Federal Information Processing Standards (FIPS) 12) DHS MD 140-01 (formerly known as MD 4300.1) which includes DHS 4300 Series Policy and Handbooks, as amended 13) CNSS Instruction No. 4009, National Information Assurance Glossary, Revised June 2006

14) CNSS Instruction No. 1001, National Instruction on Classified Information Spillage, February 2008

1.3 Information Assurance Policy and Procedures Framework

The IA Program shall provide the structure and resources necessary to oversee the protection of information and information technology and support IA as a strategic organizational capability to enable DHS/ICE missions and business functions. The ICE IA Program is a framework for the strategic management of information-related risks and the consistent implementation of confidentiality, integrity, availability, and authentication controls.

In compliance with the Federal Information Security Management Act (FISMA), the ICE IA Program shall include the following primary functions.

· Information Assurance Governance – Develop and publish risk-based, cost-effective ICE IA policy, procedures, and control techniques to address all applicable requirements throughout the life cycle of each ICE information system to ensure compliance with applicable requirements.

· Information Assurance Awareness and Training –Establish and implement an in-depth Information Assurance Division Training Program for ICE federal and contractor personnel, and other users of ICE information and information assets. All ICE system users shall receive and shall successfully complete annual Information Assurance Awareness Training (IAAT). This includes training and oversight of personnel with significant responsibilities for IA with respect to such responsibilities.

· Capital Planning and Investment Control (CPIC) Integration – Establish a comprehensive framework to enable the development, institutionalization, assessment, and improvement of the ICE IA Program.

· Interconnecting Systems – Generate and manage written interconnection security agreements that specify the technical and information security requirements of the interconnection, define the responsibilities of the participating organizations, and specify the rules governing these interconnections based on a mutually acceptable level of risk.

· Information Assurance Performance Measures – Develop and establish quantifiable performance metrics based on IA performance goals and objectives that are easily obtainable, repeatable, relevant, useful, and measurable in order to capture and provide meaningful performance data to apply lessons learned, improve the effectiveness of existing information security controls, and plan for future controls to meet new information security requirements as they occur. This includes periodically testing and evaluating the effectiveness of information security policies, procedures and practices.

· Plan of Actions and Milestones – Establish and maintain a process for planning, implementing, evaluating, and documenting remedial action to address any deficiencies in the ICE IA policies, procedures, and practices.

· Contingency Planning – Ensure preparation and maintenance of plans and procedures to provide continuity of operations for information systems that support ICE operations and assets.

· Risk Management - Assess risk and magnitude of the harm resulting from unauthorized access, use, disclosure, disruption, modification, or destruction of information and information systems that support ICE operations and assets.

· Certification, Accreditation, and Security Assessments - Test and evaluate the effectiveness of information assurance policies, procedures, practices, and security controls to be performed with a frequency depending on risk, but no less than annually.

· Information Security Products and Services Acquisition – Plan for and provide adequate information assurance products and services for ICE networks, facilities, information systems, or groups of information systems, as appropriate.

· Incident Response – Define and implement subordinate procedures for detecting, reporting, and responding to ICE information security incidents.

· Security Operations Center – Develop and implement subordinate plans for providing adequate information security for ICE networks, facilities, and systems or groups of information systems.

· Configuration Management – Establish and manage a process for planning, implementing, evaluating, and documenting remedial actions to address any deficiencies in ICE information assurance policies, procedures, and practices.

1.4 Document Organization

The IA policies and procedures in this document are organized under the three overarching IA control areas: management, operational, and technical. These IA control areas are then broken down by NIST 800-53 Revision 2 control families where we differentiate the ICE-specific IA policy and procedures.

The document reflects ICE IA Policy statements along with corresponding procedures. IA policy traceability is by an identification number (ID#) within tables throughout this document that corresponds with the BLSR in the IA Requirements Traceability Matrix (RTM). The tables also include the following relevant compliance areas.

· Mandate – Policy that requires specific performance of ICE to meet Federal Information Security Management Act (FISMA), other public laws, and Federal Information Processing Standards (FIPS) and NIST security control requirements.

· Order – DHS-defined policy requirements within the DHS 4300A Sensitive Systems Policy or Handbook or any other DHS policy that ICE is enforcing to satisfy organizational demands and maintain Department operations.

· Standard – ICE-specific policy statements that are necessary to maintain the ICE security posture and appropriately manage risks so that no adverse effects occur to ICE operations and assets, individuals, other organizations, or the Nation.

1.5 Application

ICE POLICY STATEMENT
ID#
COMPLIANCE

AREA

All ICE federal and contractor personnel, and all others working on behalf of ICE accessing ICE data, shall comply with all IA requirements within this document and articulated in the DHS 4300 series policy and handbooks.

Order

1.6 Waivers and Exceptions

Refer to Attachment B of the DHS 4300A concerning the procedures defining the ICE waiver and exception policy.

DHS Policy

All waivers and exception requests for a specific system shall include the system name and system TrustedAgent FISMA (TAF) Inventory ID.

1.6.1 U.S. Citizen Exception Requests

Special procedures apply for exception to the requirement that persons accessing DHS systems be U.S. Citizens (policy 4.1.1e). Under normal conditions, only U.S. Citizens are allowed access to DHS systems and networks. However, at times there is a need to grant access to foreign nationals. Access for foreign nationals is normally a long-term commitment, and exceptions to appropriate policies are treated separately from standard exceptions and waivers. The approval chain for an exception to the U.S. Citizenship requirement flows through the Component Head, the Office of Security, and the Chief Information Officer. Attachment J to the DHS 4300A Sensitive Systems Handbook provides an electronic form for requesting exceptions to the U.S. Citizenship requirement.

1.7 Information Sharing and Communication Strategy

The DHS Security Operations Center (SOC) exchanges information with ICE SOC, Network Operations Centers (NOCs), the Homeland Secure Data Network (HSDN) SOC, the Intelligence Community, and with external organizations in order to facilitate the security and operation of the DHS network. This exchange enhances situational awareness and provides a common operating picture to network managers. The operating picture is developed from information obtained from “raw” fault, configuration management, accounting, performance, and security data. This data is monitored, collected, analyzed, processed, and reported by the NOCs and SOCs.

The DHS SOC is responsible for communicating other information such as incident reports, notifications, vulnerability alerts and operational statuses to the Component SOCs, Component CISOs/ISSMs or other identified Component points of contact.

The DHS SOC portal implements role-based user profiles that allow Components to use the website’s incident database capabilities. Users assigned to Component groups shall be able to perform actions such as:

· Entering incident information into the DHS SOC incident database

· Generating preformatted incident reports

· Initiating queries of the incident database

· Viewing FISMA incident reporting numbers

· Automating portions of the Information Security Vulnerability Management (ISVM) program

· Automating portions of the vulnerability assessment program.

1.8 Requests

Please send document change requests to this ICE IA Program Policy Handbook via email to ICE IADivision@dhs.gov.

Contact the ICE CISO at ICE IADivision@dhs.gov for policy and/or procedure clarifications.

2.0 definitions

The following definitions apply to the policies and procedures outlined in this document.

2.1.1 Accreditation

Accreditation is the official management decision by the Designated Accrediting Authority (DAA) that authorizes the operation of an IT system. It includes explicitly accepting the risk to agency operations, assets, or individuals, based on the implementation of an agreed-upon set of information security controls. The DAA accepts security responsibility for the operation of IA certified systems and officially declares that a specified IT system shall adequately protect related information.

2.1.2 Adequate Security

Adequate security is security commensurate with the risk and the magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of information.

2.1.3 Assurance

The grounds for confidence that the set of intended security controls in an information system are effective in their application.

2.1.4 Authentication

Verifying the identity of a user, process, or device, often as a prerequisite to allowing access to resources in an information system.

2.1.5 Authority to Operate (ATO)

The official management decision given by a senior ICE official to authorize operation of an information system and to explicitly accept the risk to ICE operations (including mission, functions, image, or reputation), ICE assets, individuals, other organizations, and the Nation based on the implementation of an agreed-upon set of security controls.

2.1.6 Authorizing Official

A senior ICE official with the authority to formally assume responsibility for operating an information system at an acceptable level of risk to ICE operations (including mission, functions, image, or reputation), ICE assets, individuals, other organizations, and the Nation.

For ICE, this individual is the ICE CISO.

2.1.7 Authorizing Official Designated Representative

An ICE official acting on behalf of an Authorizing Official in carrying out and coordinating the required activities associated with security authorization.

2.1.8 Availability

Availability is ensuring timely and reliable access to and use of information.

2.1.9 Certification

The testing and/or evaluation of the management, operational, and technical security controls in an information system to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system.

2.1.10 Chief Information Officer (CIO)

The senior ICE official responsible for (i) providing advice and other assistance to the Assistant Secretary and other senior management personnel of ICE to ensure that information technology is acquired and information resources are managed in a manner that is consistent with laws, Executive Orders, directives, policies, regulations, and priorities established by the ICE Assistant Secretary; (ii) developing, maintaining, and facilitating the implementation of a sound and integrated information technology architecture for ICE; and (iii) promoting the effective and efficient design and operation of all major information resources management processes for the agency, including improvements to work processes of ICE.

2.1.11 Chief Information Security Officer (CISO)

An ICE senior official responsible for carrying out the Chief Information Officer responsibilities under FISMA and serving as the Chief Information Officer’s primary liaison to ICE authorizing officials, information system owners, and information system security officers. This term is synonymous with Senior Agency Information Security Officer (SAISO).

2.1.12 Common Control

Common control is a security control that is inherited by an information system.

2.1.13 Compensating Security Control

The management, operational, and technical controls (i.e., safeguards or countermeasures) employed by an organization in lieu of the recommended controls in the low, moderate, or high baselines described in NIST Special Publication 800-53 or in Committee on National Security Systems (CNSS) Instruction 1253, that provide equivalent or comparable protection for an information system.

2.1.14 Classified National Security Information

Information that has been determined, pursuant to Executive Order 12958, as amended, or any predecessor order, to require protection against unauthorized disclosure and is marked to indicate its classified status (e.g. Confidential, Secret, or Top Secret).

2.1.15 Component

A constituent part of the ICE enterprise architecture that serves as an element of a system.

2.1.16 Computer Security Incident Response Center (CSIRC)

The CSIRC is capable of responding to computer incidents 24 hours a day, 7 days a week and maintains an open bridge line to provide rapid, scalable access. It provides technical assistance, shares security advisories, and facilitates two-way information sharing. The CSIRC works with the Secure Operations Center (SOC) to detect and respond to suspected and confirmed incidents and interacts with the U.S.-Computer Emergency Response Team (US-CERT) as required.

2.1.17 Confidentiality

Preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information.

2.1.18 Configuration Control

Configuration control is a process for controlling modifications to hardware, firmware, software, and documentation to protect the information system against improper modifications before, during, and after system implementation.

2.1.19 External Information System

External information system is an information system or component of an information system that is outside of the authorization boundary established by ICE and for which ICE typically has no direct control over the application of required security controls or the assessment of security control effectiveness.

2.1.20 External Information System Service

An information system service that is implemented outside of the authorization boundary of an ICE information system (i.e., a service that is used by, but not a part of, an ICE information system).

2.1.21 External Information System Service Provider

A provider of external information system services to ICE through a variety of consumer-producer relationships, including but not limited to: service level agreements, outsourcing arrangements (i.e., through contracts, interagency agreements); licensing agreements; and/or federal exchanges.

2.1.22 Federal Information Security Management Act (FISMA)

FISMA directs that all Federal agencies develop and implement an agency-wide information system security program designed to safeguard IT assets and data. DHS bases its C&A policy on the recommendations set forth in NIST SP 800-37, Guide for the Security Certification and Accreditation of Federal Information Systems, and OMB Circular A-130, Appendix III, Security of Federal Automated Information Resources.

2.1.23 Federal Information System

A federal information system is an information system used or operated by a federal agency, or by a contractor of a federal agency or by another organization on behalf of a federal agency. By definition, ICE is a “federal agency”.

2.1.24 Hybrid Security Control

A hybrid security control is part common control and part system-specific control.

2.1.25 Incident

An occurrence that actually or potentially jeopardizes the confidentiality, integrity, or availability of an information system or the information the system processes, stores, or transmits or that constitutes a violation or imminent threat of violation of security policies, security procedures, or acceptable use policies.

2.1.26 Information Assurance (IA)

Information Assurance is the practice of protecting information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide availability, integrity, authentication, confidentiality, and non-repudiation. This includes providing for restoration of information systems by incorporating a protection, detection, and reaction capability.

2.1.27 Information Assurance Objective

Information assurance objectives are confidentiality, integrity, authentication, availability, and non-repudiation.

2.1.28 Information Assurance Policy

Aggregate of directives, regulations, rules, and practices that prescribe how ICE manages, protects, and distributes information.

2.1.29 Information Owner

Information owners are officials with statutory or operational authority for specified information and responsibility for establishing the controls for its generation, collection, processing, dissemination, and disposal.

2.1.30 Information Resources

Information resources are information and related resources, such as personnel, equipment, funds, and information technology.

2.1.31 Information Security Requirements

Requirements levied on an information system that are derived from applicable laws, Executive Orders, directives, policies, standards, instructions, regulations, procedures, or organizational mission and/or business case needs to ensure the confidentiality, integrity, and availability of the information being processed, stored, or transmitted.

2.1.32 Information System

A discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information in accordance with defined procedures, whether automated or manual that is used by ICE, a contractor, or another organization operating on behalf of ICE.

2.1.33 Information System Owner (ISO)

Information system owners are officials responsible for the overall procurement, development, integration, modification, operation, and maintenance of an information system. For ICE, this individual is the Program Manager.

2.1.34 Information System Security Engineer

Individual assigned responsibility for conducting information system security engineering activities.

2.1.35 Information System Security Engineering

Information system security engineering is a process that captures and refines information security requirements and ensures their integration into information technology component products and information systems through purposeful security design or configuration.

2.1.36 Information System-related Security Risks

Information system-related security risks are those risks that arise through the loss of confidentiality, integrity, authentication, availability, or non-repudiation of information or information systems and consider impacts to ICE (including assets, mission, functions, image, or reputation), individuals, other organizations, and the Nation.

2.1.37 Information System Security Officer (ISSO)

Individual assigned responsibility for maintaining the appropriate operational security posture for an information system or program. An Information Systems Security Officer (ISSO) shall be appointed in writing by the Program/Business Manager for each ICE IT system. An ISSO may either be an appropriately cleared (i.e., 5C, 6C, T1, or T2) Federal employee or support contractor and may be assigned to more than one system and is responsible for ensuring the implementation and effectiveness of security controls in accordance with Department policies. For DHS CFO-designated financial systems, ISSO duties shall not be assigned as a collateral duty and no other significant collateral duties shall be assigned.

2.1.38 Information Technology (IT)

Any equipment or interconnected system or subsystem of equipment that is used in the automatic acquisition, storage, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the executive agency. For purposes of the preceding sentence, equipment is used by ICE if the equipment is used by ICE directly or is used by a contractor under a contract with ICE which: (i) requires the use of such equipment or (ii) requires the use, to a significant extent, of such equipment in the performance of a service or the furnishing of a product. The term information technology includes computers, ancillary equipment, software, firmware and similar procedures, services (including support services), and related resources.

2.1.39 Integrity

Guarding against improper information modification or destruction, and includes ensuring information non-repudiation and authenticity.

2.1.40 Interconnection Security Agreement (ISA)

An agreement established between the organizations that own and operate connected IT systems to document the technical requirements of the interconnection.

2.1.41 Information Security Controls

The management, operational, and technical controls (i.e., safeguards or countermeasures) prescribed for an information system to protect the confidentiality, integrity, and availability of the system or its information.

2.1.42 Information Technology General Control (ITGC)

ITGCs represent the foundation of the IT control structure. They help ensure the reliability of data generated by IT systems and support the assertion that systems operate as intended and that output is reliable.

2.1.43 Law Enforcement

Law enforcement organizations include those DHS entities engaged in the protection of U.S. citizens and national infrastructure assets, as well as the enforcement of immigration, customs, transportation, and financial laws including, but not limited to: financial crimes, export violations related to defense munitions items and strategic dual-use technology, drug and contraband smuggling, human smuggling and trafficking, identity document and immigration benefit fraud, visa violations, alien migration interdiction, worksite enforcement, intellectual property, trade related commercial fraud, child pornography, counterfeiting and financial, cyber, air piracy, and organized crime.

2.1.44 Major Application

A major application (MA) is an automated information system (AIS) that “requires special attention to security due to the risk and magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of the information in the application.

” Note: All Federal applications require some level of protection. However, certain applications, because of the information in them, require special management oversight and should be treated as major. An MA is distinguishable from a GSS by the fact that it is a discrete application, whereas a GSS may support multiple applications. Each major application must be under the direct oversight of a Component CISO/ISSM and must have one or more Information Systems Security Officers (ISSO) assigned.

2.1.45 Operational Data

Operational data is information used in the execution of any ICE mission.

2.1.46 Organization

An organization is a federal agency or, as appropriate, any of its operational elements.

ICE is an organization.

2.1.47 Non-repudiation

Assurance that sender and recipient identities of a message are provided so that neither can later deny having possessed the data.

2.1.48 Personally Identifiable Information (PII)

Information that permits the identity of an individual to be directly or indirectly inferred, including any other information that is linked or linkable to that individual regardless of whether the individual is a U.S. Citizen, Legal Permanent Resident, or a visitor to the U.S. This definition includes information about DHS employees and contractors or any other individuals who may be external to the organization.

2.1.49 Plan of Action and Milestones (POA&M)

A document that identifies tasks needing to be accomplished, resources required to accomplish the elements of the plan, any milestones in meeting the tasks, and scheduled completion dates for the milestones.

2.1.50 Privacy Impact Assessment (PIA)

The Privacy Impact Assessment is the mechanism required by Section 208 of the E-Government Act of 2002 to assess a system's potential impact on privacy.

2.1.51 Privacy Threshold Analysis (PTA)

This is an administrative form to efficiently and effectively identify the use of Personally Identifiable Information (PII) for every IT project to determine the need for further privacy compliance analysis.

2.1.52 Procedure

A specification of series of actions, acts or operations which have to be executed in the same manner in order to always obtain the same result in the same circumstances. A procedure may also indicate a sequence of activities, tasks, steps, decisions, calculations and processes, that when undertaken in the sequence laid down produces the described result, product or outcome.

2.1.53 Public Information

This type of information can be disclosed to the public without restriction but requires protection against erroneous manipulation or alteration (e.g., Public Web sites).

2.1.54 Risk

A measure of the extent to which an entity is threatened by a potential circumstance or event and typically a function of the likelihood of the circumstances or event occurring and of the resulting adverse impacts.

2.1.55 Risk Assessment

The process of determining risks, that is, determining the extent to which an entity is threatened by potential, adverse circumstances or events. Risk assessment is part of risk management and is conducted throughout the Risk Management Framework (RMF).

2.1.56 Risk Management

Risk management is a management process employed by ICE to achieve and maintain an acceptable level of risk. The Risk Management Framework describes the recommended process for managing information system-related security risks.

2.1.57 Security Authorization Boundary

All components of an information system to be authorized for operation by an authorizing official and excludes separately authorized systems, to which the information system is connected.

2.1.58 Security Category

The characterization of information or an information system based on an assessment of the potential impact that a loss of confidentiality, integrity, or availability of such information or information system would have on ICE operations, ICE assets, individuals, other organizations, or the Nation.

2.1.59 Security Control

Security safeguards applied to an information system. They are grouped into three families of controls (management, operational, and technical), based upon who or what executes the control.

2.1.60 Security Inheritance

A situation in which an information system or application receives protection from security controls (or portions of security controls) that are developed, implemented, and assessed for effectiveness by other entities either internal or external to ICE where the system or application resides.

2.1.61 Security Impact Analysis

The analysis conducted by an ICE official, often during the maintenance phase of the security authorization process, to determine the extent to which changes to an information system or its environment or operation have impacted the security state of the system.

2.1.62 Sensitive Information

“Sensitive information” is information not otherwise categorized by statute or regulation that, if disclosed, could have an adverse impact on the welfare or privacy of individuals or on the welfare or conduct of Federal programs or other programs or operations essential to the national interest. Examples of sensitive information include personal data such as Social Security Number; trade secrets; system vulnerability information; pre-solicitation procurement documents, such as statements of work; and law enforcement investigative methods. Similarly, detailed reports related to computer security deficiencies in internal controls are also sensitive information because of the potential damage that could be caused by the misuse of this information. Information concerning financial systems shall be identified as Sensitive Financial Information if, on another system, it would be identified as system vulnerability information. All sensitive information must be protected from loss, misuse, modification, and unauthorized access.

With the exception of certain types of information protected by statute (e.g., Sensitive Security Information, Critical Infrastructure Information), there are no specific Federal criteria and no standard terminology for designating types of sensitive information. Such designations are left to the discretion of each individual Federal agency. “For Official Use Only” (FOUO) is the term used within DHS to identify unclassified information of a sensitive nature that is not otherwise categorized by statute or regulation.

2.1.63 Subsystem

A subsystem is a major subdivision or component of an information system consisting of information, information technology, and personnel that performs one or more specific functions.

2.1.64 System of Record Notice (SORN)

The SORN is a public notice required by the Privacy Act of 1974, as amended, that describes how and why an agency maintains, uses, and shares personal information about U.S. citizens and lawful permanent residents. A SORN is generally required when an individual’s name or other unique identifier is used to retrieve other associated information from a system.

2.1.65 System Security Plan

Formal document that provides an overview of the security requirements for the information system and describes the security controls in place or planned for meeting those requirements.

2.1.66 System-specific Security Control

A system-specific security control is a security control for an information system that has not been designated as a common control.

2.1.67 Threat

Any circumstance or event with the potential to adversely impact ICE operations (including mission, functions, image, or reputation), ICE assets, individuals, other organizations, or the Nation through an information system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service.

2.1.68 Threat Source

The intent and method targeted at the intentional exploitation of a vulnerability or a situation and method that may accidentally trigger a vulnerability. This term is synonymous with threat agent.

2.1.69 Trust Zone

A Trust Zone consists of a group of people, information resources, data systems, and/or networks subject to a shared security policy (set of rules governing access to data and services). For example, a Trust Zone may be set up between different network segments that require specific usage policies based on information processed, such as law enforcement information.

2.1.70 Vital Records

Electronic and hardcopy documents, references, records, databases, and IT systems needed to support essential functions under the full spectrum of emergencies. Categories of these types of records may include:

· Emergency operating records—emergency plans and directive(s), orders of succession, delegations of authority, staffing assignments, selected program records needed to continue the most critical agency operations, as well as related policy or procedural records.

· Legal and financial rights records—protect the legal and financial rights of the Government and of the individuals directly affected by its activities. Examples include accounts receivable records, social security records, payroll records, retirement records, and insurance records. These records were formerly defined as “rights-and-interests” records.

· Records used to perform national security preparedness functions and activities (E.O. 12656).

2.1.71 Vulnerability

A flaw or weakness in a system’s design, implementation, operation, or management that would allow unauthorized use or unauthorized access to the system.

3.0 Roles and Responsibilities

Protecting the ICE IT infrastructure and data is a responsibility for all users. In addition to the general user community, various ICE positions retain a certain delegated and specialized IA support function. The following is a list of roles and responsibilities within the IA support structure.

3.1 Assistant Secretary (AS)

The ICE Assistant Secretary (AS) shall:

· Ensure that information security processes are integrated with strategic and operational planning processes to secure ICE missions.

· Ensure that an information security program is developed, documented, and implemented to provide security for all systems, networks, and data that support the operations of the organization acquisition strategies and oversight of procurement activities and contracts.

· Ensure that senior officials within ICE are given the necessary authority to secure the operations and assets under their control.

· Appoint the Chief Information Officer (CIO) as appropriate and delegating authority to that individual to ensure compliance with applicable information security requirements.

· Ensure that the CIO, in coordination with the other ICE senior officials, reports annually to the ICE Assistant Secretary on the effectiveness of the ICE IA Program, including the progress of remedial actions.

· Ensure that adequate funding for IA is provided for ICE IT systems and that adequate funding requirements are included for all IT systems budgets.

· Ensure that IT system data are entered into the appropriate DHS Security Management Tools to support DHS IA oversight and FISMA reporting requirements.

· Ensure that the requirements for an IA performance metrics program are implemented.

3.2 Deputy Assistant Secretary for Management (DASM)

The Deputy Assistant Secretary for Management (DASM) shall:

· Appoint the ICE Chief Information Security Officer (CISO)

· Ensure that ICE has highly trained personnel to support compliance with IA policies, processes, standards, and guidelines.

· Provide secure financial management policies, standards and systems.

· Establish secure acquisition and contract management strategies.

· Ensure that management entities within the Office of the Deputy Assistant Secretary for Management adhere to and are compliant with all aspects of the IA policy and any subsequent handbooks.

3.3 Deputy Assistant Secretary for Operations (DASO)

The Deputy Assistant Secretary for Operations (DASO) shall:

· Ensure that operational entities within the Office of the Deputy Assistant Secretary for Operations adhere to and are compliant with all aspects of the IA policy and any subsequent handbooks.

3.4 ICE Chief Information Officer (CIO)

The ICE Chief Information Officer (CIO) shall provide management direction to ICE information security operations and is the principal advocate for ICE information security incident response. The ICE CIO will either be the DAA for or designate in writing a DAA for ICE general support systems. The ICE CIO shall:

· Establish and oversee the ICE Information Assurance Program.

· Ensure appointment of an ICE Chief Information Security Officer (CISO) and ensure that the CISO has resources to assist in ensuring compliance with all relevant IA policy.

· Maintain IA policies, procedures, and control techniques to address all applicable requirements.

· Report annually, in coordination with the other ICE senior officials, to the Assistant Secretary on the effectiveness of the ICE IA Program, including progress of remedial actions.

· Serve as the DAA for any IT system where a DAA has not been appointed or where a vacancy exists.

· Ensure that IA concerns are addressed by an ICE Configuration Control Board (CCB), Architecture Review Board (ARB), and Investment Review Board (IRB).

· Ensure that an accurate IT systems inventory is established and maintained.

· Ensure that an IA performance metrics program is developed, implemented, and funded.

· Advise the DHS CIO of any issues regarding infrastructure protection, vulnerabilities or issues that may cause public concern or loss of credibility.

· Ensure that information security incidents are reported to the DHS SOC within reporting time requirements as defined in F of the DHS 4300A Sensitive Systems Handbook.

· Work with the DHS CIO and Public Affairs Office in preparation for public release of information security incident information. The DHS CIO, or designated representative, has sole responsibility for public release of security incident information.

· Ensure compliance with DHS IT policy and all other applicable IA policy requirements.

The CIO shall be responsible for overseeing implementation and compliance of ICE Chief Financial Office-designated financial systems. The CIO shall:

· Review and evaluate the ICE CFO-designated financial systems to ensure IT General Controls (ITGCs) are in place and working effectively.

· Work with the system owners to ensure remediation of ITGC deficiencies related to ICE CFO-designated financial systems.

· Track and monitor progress of ITGC POA&Ms and remediation efforts for ICE.

· Ensure completion of Memoranda of Understanding (MOUs) and Interconnection Security Agreements (ISAs) for CFO-designated financial system interconnections with any system not owned by DHS; ensure that they include appropriate information security clauses; and monitor service provider for compliance with MOUs and ISAs.

· Implement the Department-wide system development lifecycle methodology and monitor user compliance.

· As part of developing new financial applications or updating existing applications, integrate CFO feedback to ensure user requirements are adequately addressed.

· Develop and test ICE disaster recovery plan. Coordinate with ICE CFO to incorporate business continuity requirements and test on a periodic basis.

· Based on ICE CFO requirements, execute policies for the routine backup and recovery of financial data. Implement policies and procedures for rotating backup media off-site.

3.4.1 Director for the Architecture Division, OCIO

The Director for the…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .