Attachment_J.13_-_TSA_Information_Assurance_Handbook.pdf

PDF 2 MB Posted

Attached to
Transportation Security Equipment Deployment Services (TEDS) Federal contract opportunity
Solicitation number
HSTS04-14-R-CT4049
Issued by
Department of Homeland Security Transportation Security Administration

About this file

Attachment J.13 - TSA Information Assurance Handbook

View the file

Other files for this federal contract opportunity

Other files attached to Transportation Security Equipment Deployment Services (TEDS), newest first.
File Type Posted
Attachment_J_3_-_Question_and_Answer_Sheet_A00003.pdf PDF
HSTS04-14-R-CT4049_-_SF_30_A00003.pdf PDF
Attachment_J.10_-_Pricing_Worksheets_CENTRAL_A00002.xlsx XLSX spreadsheet
Attachment_J.3_-_Question_and_Answer_Sheet_Amendment_A00002.pdf PDF
HSTS04-14-R-CT4049_-_SF_30_A00002.pdf PDF
HSTS04-14-R-CT4049_Amendment_A00002.pdf PDF
Attachment_J.11_-_Pricing_Worksheets_WEST_A00002.xlsx XLSX spreadsheet
Attachment_J.9_-_Pricing_Worksheets_EAST_A00002.xlsx XLSX spreadsheet
Attachment_J.15_-_OST_Test_and_Evaluation_Guidebook.pdf PDF
HSTS04-14-R-CT4049_Amendment_A00001.pdf PDF
Attachment_J.7_-_Past_Performance_Statement.docx DOCX document
Attachment_J.11_-_Pricing_Worksheets_WEST_A00001.xlsx XLSX spreadsheet
Attachment_J.5_-_Task_Order_02.pdf PDF
Attachment_J.4_-_Task_Order_01.pdf PDF
Attachment_J.10_-_Pricing_Worksheets_CENTRAL_A00001.xlsx XLSX spreadsheet
Attachment_J.9_-_Pricing_Worksheets_EAST_A00001.xlsx XLSX spreadsheet
Attachment_J.17_OST_OA_Test_and_Evaluation_Policy.pdf PDF
HSTS04-14-R-CT4049_-_SF_30.pdf PDF
Attachment_J.3_-_Question_and_Answer_Sheet_A00001.pdf PDF
Attachment_J.14_-_DHS_4300A_Sensitive_Systems_Handbook.pdf PDF
Attachment_J.16_-_OST_Test_and_Evaluation_Guide.pdf PDF
Attachment_J.6_-_DHS_Subcontracting_Plan_Review_Checklist.pdf PDF
Attachment_J.4_-_Task_Order_01.pdf PDF
Attachment_J.7_-_Past_Performance_Statement.docx DOCX document
Attachment_J.8_-_Past_Performance_Questionnaire.docx DOCX document
Attachment_J.11_-_Pricing_Worksheets_WEST.xlsx XLSX spreadsheet
Attachment_J.2_-_SCA_DBA_Spreadsheet.pdf PDF
Attachment_J.9_-_Pricing_Worksheets_EAST.xlsx XLSX spreadsheet
Attachment_J.10_-_Pricing_Worksheets_CENTRAL.xlsx XLSX spreadsheet
Attachment_J.12_-_Pricing_Worksheets_ALL.xlsx XLSX spreadsheet
Attachment_J.5_-_Task_Order_02.pdf PDF
Attachment_J.3_-_Question_and_Answer_Sheet.xlsx XLSX spreadsheet
Attachment_J.1_-_FED_Map.pdf PDF
HSTS04-14-R-CT4049.pdf PDF
Show all 34

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

TRANSPORTATION SECURITY ADMINISTRATION

OFFICE OF INFORMATION TECHNOLOGY

TSA Information Assurance Handbook

Attachment 1 to TSA MD 1400.3

6 June 2014

Version 9.2.2

INFORMATION ASSURANCE HANDBOOK

This Page Intentionally Left Blank

Table of Contents Table of Contents

1. Purpose

2. Scope

3. Policy

3.1 Access Control (AC)

3.2 Awareness and Training (AT)

3.3 Audit and Accountability (AU)

3.4 Security Assessment and Authorization (CA)

3.5 Configuration Management (CM)

3.6 Contingency Planning (CP)

3.7 Identification and Authentication (IA)

3.8 Incident Response (IR)

3.9 Maintenance (MA)

3.10 Media Protection (MP)

3.11 Physical and Environmental Protection (PE)

3.12 Planning (PL)

3.13 Personnel Security (PS)

3.14 Risk Assessment (RA)

3.15 System and Services Acquisition (SA)

3.16 System and Communications Protection (SC)

3.17 System and Information Integrity (SI)

3.18 Program Management (PM)

4. Roles and Responsibilities

4.1 Chief Information Officer

4.2 CISO

4.3 System Owner

4.4 Information Owner

4.5 Information Systems Security Officer

4.6 Authorizing Official

4.7 Security Control Assessor

4.8 Outsourcing Contractors

4.9 Information System Users

5. Definitions

6. Abbreviations

7. Acknowledgements

8. Authorities

9. Document Change History

10. Document Control information

11. Effective Date and Implementation

1. Purpose This handbook implements the policies and requirements of the Transportation Security Administration (TSA) Management Directive (MD) 1400.3, Information Technology Security by establishing guidance applicable to the use, development, and maintenance of TSA Information Technology (IT) assets, networks and systems. The guidance contained herein are designed to ensure the Confidentiality, Integrity, Availability, and overall assurance of TSA information. This handbook is supplemented by published extension documents, TSA Technical Standards (TS) and Standard Operating Procedures (SOP). TSs and SOPs are published on the TSA Information Assurance Policy iShare website at:

https://team.ishare.tsa.dhs.gov/sites/ITSEC/CP/PC/policy/default.aspx This document is used to identify responsibilities by educating and increasing awareness of TSA information assurance (IA) policy. References to the specific areas and authorities to enable successful execution of tasks and job requirements are identified herein.

2. Scope The policies within TSA MD 1400.3 apply to all TSA employees, contractors, vendors, detailees, others working on behalf of TSA, non-TSA individuals authorized to access TSA information systems, and to all TSA information systems that collect, generate, process, store, display, transmit, or receive TSA data, including prototypes and telecommunications systems, in all phases of the System Engineering Life Cycle (SELC) unless an approved waiver has been granted. The above assets shall be collectively referred to as "IT assets" throughout the document.

The structure of this document is based on the controls contained in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 Revision 3, Recommended Security Controls for Federal Information Systems and Organizations. Furthermore, the controls identified are mapped to Federal Information Processing Standards (FIPS) Publication 199, Standards for Security Categorization of Federal Information and Information Systems, which establishes the foundation for categorizing systems based on three security objectives: Confidentiality, Integrity, and Availability. These publications and other relevant NIST guidance are available online at http://csrc.nist.gov/. Security objectives are assigned a potential impact level, also known as “impact level” throughout this handbook, of Low, Moderate or High. Within the tables of requirements in this document, the applicability of each control statement are provided in the “Allocations” column with the following abbreviations: Low (L), Moderate (M), High (H), Privacy System (P), Chief Financial Officer (CFO) Designated Financial System (F), and none (*).

Definitions for terms in this document may be located in Section 5 Definitions of this document. For definitions not identified, the NIST Glossary of Key Information Security Terms should be used as a baseline for reference.

http://csrc.nist.gov/ http://nvlpubs.nist.gov/nistpubs/ir/2013/NIST.IR.7298r2.pdf

The DHS Sensitive Systems Policy Directive 4300A and its supporting Handbook shall take precedence in instances where there is conflict with TSA MD 1400.3 and this supporting handbook unless otherwise identified in TSA policy.

With the recent advent of the DHS Trusted Internet Connection (TIC) infrastructure initiative as mandated by OMB M-08-05, this TSA IA Policy Handbook and its extension documents shall address the expansion in scope from a current TSA-only management service function to a DHS entity entrusted in providing a more centrally managed Semi-Trusted/DMZ environment. The overall purpose of the DHS TIC effort is to optimize and standardize the security of individual external network connections (extranet services) currently in use by the TSA and other agencies.

The CISO has the flexibility and the resources to work with DHS with the presumption that TSA has the full and complete trust in DHS from an architectural perspective to serve as the new provider and management of TSA’s current Semi-Trusted zone. Additional details may be found in the TSA TIC Migration Plan of Action and Milestones Agreement and Approval document, dated August 31, 2011, under VPN Service (p. 7) in that, “DHS OneNet network infrastructure is a Department managed service to the DHS Component and should be considered trusted.”

In cases where current TSA policy is conflicting, the policy identified in this handbook shall take precedence. The TSA Chief Information Security Officer (CISO) shall make the final arbitration decision in the case of any conflicting guidance in policy documents. In addition, in cases where this handbook conflicts with SSI Office or Privacy Office policy and procedures, the appropriate office’s guidance shall take precedence.

http://www.whitehouse.gov/omb/memoranda_2008

3. Policy

3.1 Access Control (AC)

The implementation of proper access control is a critical element of the information assurance (IA) solution. TSA and DHS-trusted IT related assets provide an environment that allows active network use by individuals in the performance of their assigned tasks while also ensuring appropriate measures are in place to maintain the integrity of network information through limited and controlled access. This control supports the logical access control measures of TSA and DHS-trusted IT assets, and is applicable to all elements of TSA IT assets whenever a claim of identity is made.

Specific detailed guidance of the information security requirements on access control is contained in the TSA TSs and include: TS-001 Passwords/PINs, TS-002 Encryption, TS-003 WiFi, TS-008 End User Assets, TS-010 Network Interconnections, TS-012 Port Security, TS-015 Network Logical Access Control, TS-016 Remote Access, TS-023 Voice over Internet Protocol (VOIP), TS-024 Radio Frequency Identification (RFID), TS-025 Virtual Private Networks (VPNs), TS-028 Web Applications, TS-030 Internet Site Access, TS-036 Infrastructure Asset Security, TS-037 Server Security and TS-049 Information Systems Logging.

Other guidance: OMB Memorandum 04-04, 08-05, and 08-27. FIPS Publications 140-2, 199 and

201. NIST Special Publications 800-12, 800-16, 800-46, 800-48, 800-63, 800-73, 800-77, 800-78, 800-98, 800-94, 800-100, 800-113, 800-114, 800-121, and 800-124. DHS 4300A Policy Directive (PD) Attachment L, Password Management.

3.1.1 Access Control Policy and Procedures (AC-1)

Policy

ID Policy Element DHS 4300A

NIST SP

800-53 Category

1.1.1 The CISO shall develop, disseminate, and annually review/update a formal, documented access control policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among TSA and DHS trusted entities, and compliance;

and formal, documented procedures to facilitate the implementation of the access control policy and associated controls that provide protection from unauthorized alteration, loss, unavailability, or disclosure of information.

5.2.a 5.4.3.a

AC-1 LMH

P

1.1.2 The System Owner (SO) shall be responsible for the management of access controls for IT assets for the information system including oversight and agreements as needed for IT assets outside of direct control by TSA personnel.

5.2.a 5.4.3.a

AC-1

AC-2

LMH

P

1.1.3 For the purpose of maintenance, only individuals with current authorization and access to maintain TSA or DHS equipment shall be allowed unescorted access to TSA IT assets. All others shall be escorted.

5.2.a 5.4.3.a

AC-1 LMH

P

1.1.4 The Information System Security Officer (ISSO) shall ensure all scheduled preventative maintenance and unscheduled maintenance is documented in the on-site maintenance log.

5.2.a 5.4.3.a

ID Policy Element DHS

4300A

NIST SP

800-53 Category

1.1.5 All TSA privileged access control shall be in compliance with the TSA Office of Information Technology (OIT) SOP Privileged Access.

5.2.a 5.4.3.a

AC-1 LMH

P

1.1.6 Authorization for emergency and temporary access to accounts by anyone other than the defined account owner shall be strictly controlled and approved by the CISO, Deputy CISO, or other designee prior to being granted.

5.2.a 5.2.d

5.4.3.a

AC-1

AC-2

LMH

P

1.1.7 The ISSO shall provide on-going supervision and review of actions of personnel who enforce access controls and those who are subject to enforcement.

5.2.a 5.4.3.a

AC-1 LMH

P

1.1.8 The ISSO shall routinely review activity logs for signs of inappropriate actions and response action shall be taken as required.

5.2.a 5.4.3.a

AC-1 LMH

P

1.1.9 Changes to user access rights shall be regularly reviewed, at least quarterly, by the user’s supervisor independent of the information security function.

5.2.a 5.4.3.a

AC-1 LMH

P

1.1.10 The user’s supervisor shall notify the system ISSO of any abnormal activity and support investigation activities upon request.

5.2.a 5.4.3.a

3.1.2 Account Management (AC-2)

Standard user accounts are established by the TSA after the completion of the TSA Form 1403, Computer and Personal Electronic Device (PED) Access Agreement, available via the Online Learning Center (OLC). The data and applications available to the specific user are defined by an evaluation of that user’s needs to perform his or her duties. A properly completed TSA Form 1403 is used to identify the user and the user’s privileges, in order to create a user profile. Account management is a critical element in the defense-in-depth approach and provides protection from unauthorized system access. All data, applications, and IT assets of the TSA network are accessed through defined user accounts. The establishment of these user accounts is rigorously controlled throughout the user life cycle.

Policy

ID Policy Element DHS 4300A

NIST SP

800-53 Category

1.2.1 The SO shall be responsible for management and oversight of all accounts used to access the information system.

5.2 4.1.3.a

AC-2 LMH

F

1.2.2 The ISSO shall support the SO in account management by:

- Identifying account types (to include individual, group, system, application, guest/anonymous, and temporary);

- Establishing conditions for group membership;

- Enacting processes to identify authorized users of the information system and specify access privileges;

- Requiring appropriate approvals for requests to establish accounts;

- Enacting processes to establish, activate, modify, disable, and remove accounts;

- Enacting processes to specifically authorize and monitor the use

5.2 4.1.6.d

AC-2 LMH

F

4300A

NIST SP

800-53 Category of guest/ anonymous and temporary accounts;

- Notifying account managers when temporary accounts are no longer required and when information system users are terminated, transferred, or information system usage or need-to know/ need-to-share changes;

- Enacting processes to deactivate both temporary accounts that are no longer required and accounts of terminated or transferred users;

- Enacting process to grant access to the system based on a valid access authorization, intended system usage, and other attributes as required by the TSA or associated missions/business functions; and

- Enacting process to review accounts on an annual basis.

1.2.3 The ISSO shall ensure that access control implementations follow the principles of least privilege and separation of duties and shall require users to use unique identifiers. Privileged users will have separate accounts from their standard user accounts in order to perform privileged access.

5.2.b AC-2 LMH F

1.2.4 Social Security Numbers shall not be used as login IDs. 5.2.b AC-2 LMH F

1.2.5 The Authorizing Official (AO) shall review and approve any individual requiring administrator privileges. The AO may delegate this duty to the CISO in writing, an appropriate SO or Program Manager in compliance with the OIT SOP Privileged Access.

2.1.6.d 4.1.4.b

AC-2 LMH

F

1.2.6 Emergency and temporary access authorization shall be strictly controlled and shall be approved by the CISO, Deputy CISO, or other designee prior to being granted.

5.2.d AC-2 LMH F

1.2.7 Systems that are part of the Critical DHS Assets Program shall have provisions to allow the CISO to approve new user accounts as part of a Continuity of Operations (COOP) scenario.

3.5.1.f AC-2 LMH F

1.2.8 The SO shall ensure that the duties and responsibilities of critical information system functions are divided among different individuals to minimize the possibility that any one individual would have the necessary authority or system access to be able to engage in fraudulent or criminal activity.

4.1.4.a AC-2

AC-5

LMH

F

1.2.9 Reserved

1.2.10 The SO shall implement procedures to ensure that system access is suspended for personnel on extended absences.

4.1.6.c AC-2

IA-4

LMH

F

1.2.11 Standard user accounts shall require a TSA Form 1403 Computer and Personal Electronic Device (PED) Access Agreement completed by the user prior to granting the user access.

Not Defined

AC-2 LMH

F

1.2.12 Data and applications assigned and available to each specific user are defined by an evaluation of that user’s needs to perform his or her duties and approved by the SO.

Not Defined

AC-2 LMH

4300A

NIST SP

800-53 Category

1.2.13 All data, applications, and IT assets of the TSA network shall be accessed through defined user accounts.

5.2 AC-2 LMH

F

1.2.14 User assets shall be locked out after fifteen (15) minutes of inactivity.

5.2 AC-2

LMH

1.2.15 Users shall lock end user assets when not in use and stepping away from the asset.

5.2 AC-2

1.2.16 Automated mechanisms shall be implemented by the ISSO to support the management of information system accounts.

Not Defined

AC-2

(1)

LMH

F

1.2.17 The SO shall ensure the system automatically terminates temporary and emergency accounts NLT five (5) days of activation

Not Defined

AC-2

(2)

MH

F

1.2.18 Reserved

1.2.19 The SO shall ensure the system automatically audits account creation, modification, disabling, and termination actions and notifies appropriate support and response personnel.

Not Defined

AC-2

(4)

MH

F

1.2.20 Users shall log out of any system when no longer in use. 5.2 AC-2 (5)

LMH

F

1.2.21 Reserved

1.2.22 The ISSO shall monitor for atypical usage and report atypical usage to the SO.

5.2 AC-2

(5)

LMH

F

1.2.23 Reserved

1.2.24 Reserved

1.2.25 All email messages generated or forwarded by a TSA user shall have the user’s identity as the originator.

5.1 AC-2 LMH

3.1.3 Access Enforcement (AC-3)

Access control policies (to include identity-based policies, role-based policies, attribute-based policies) and access enforcement mechanisms (to include access control lists (ACL), access control matrices, cryptography) are employed by TSA to control access between users or processes acting on behalf of users and objects (to include devices, files, records, processes, programs, domains) in the information system. In addition to enforcing authorized access at the information system level, access enforcement mechanisms are employed at the application level, when necessary, to provide increased information security for TSA. Consideration is given to the implementation of an audited, explicit override of automated mechanisms in the event of emergencies or other serious events. Encryption of stored information shall be FIPS 140-2 (as amended) compliant. For information, the cryptography used is dependent on the Security level of the information. Mechanisms implemented by AC-3 are configured to enforce authorizations determined by other security controls.

4300A

NIST SP

800-53 Category

1.3.1 Access control policies and access enforcement mechanisms shall be employed by TSA systems to control access between users (or processes acting on behalf of users) and objects (to include devices, files, records, processes, programs, domains) in the system.

5.2.a AC-3 LMH

FP

1.3.2 The SO shall ensure the system enforces approved authorizations for logical access to the system in compliance with applicable policy.

5.2.a 5.4.3.a

AC-3 LMH

FP

1.3.3 Authorization of logical access control plans shall be approved in writing by the AO.

Not Defined

AC-3 LMH

FP

1.3.4 The ISSO shall implement controls to ensure that only authorized individuals are able to participate in videoconferences.

4.5.2.a AC-3 LMH

FP

1.3.5 Physical and logical access to TSA IT assets shall be limited to individuals on the asset’s ACL by the ISSO.

Not Defined

AC-3

CM-6

LMH

FP

1.3.6 The SO shall ensure that all data-at-rest, particularly in cloud or other virtual environments, preserves its identification and access requirements (anyone with access to data storage containing more than one type of information must have specific access authorization for every type of data in the data storage.

5.2.g AC-3 LMH

FP

1.3.7 The SO shall ensure that all information systems utilizing cloud computing services are secured in compliance with TS-072 Cloud Computing and Virtualization.

Not Defined

AC-3 LMH

FP

1.3.8 TSA data hosted on a shared service environment/cloud service provider shall go through an approved TIC.

5.4.3.b AC-3 LMH

FP

3.1.4 Information Flow Enforcement (AC-4)

ID Policy Element DHS

4300A

NIST SP

800-53 Category

1.4.1 The ISSO shall ensure the information system enforces approved authorizations for controlling the flow of information within the system and between interconnected systems in compliance with TSA and DHS policy and as documented in the Security Plan (SP).

5.4.1 AC-4 MH

FP

1.4.2 TSA email systems shall provide for security commensurate with the risk and magnitude of the harm resulting from the loss, misuse, or unauthorized access to or modification of information contained in the email system.

5.4.1 5.4.6.e

AC-4 MH

FP

1.4.3 TSA users shall not perform actions to bypass email screening tools (to include renaming file extensions, etc.).

5.4.1 AC-4 MH

FP

1.4.4 If SSI or Personally Identifiable Information (PII) is sent by email, users shall encrypt the information in compliance with TS-002 Encryption.

5.4.1 AC-4 MH

FP

1.4.5 Appropriate transmission protections, commensurate with the highest sensitivity of information to be discussed over the video teleconference, shall be in compliance with TSA and DHS policies and shall be in place prior to initiating a teleconference.

4.6.3.b 5.4.1

AC-4

SC-8

SC-9

MH

FP

1.4.6 In non-operational environments (to include training laboratories, development environments, test environments) where non-TSA

5.4.1 AC-4 MH

4300A

NIST SP

800-53 Category personnel have physical access, connectivity to the TSA production network is prohibited. Additionally, no TSA operational information can reside on any computer equipment in these environments.

1.4.7 Prior to posting sensitive content on TSA web sites, both internal and external, established data redaction processes shall be followed to include independent review where necessary.

Not Defined

AC-4 MH

FP

1.4.8 Content shall be posted to TSA web sites in compliance with the Rules of Behavior (control PL-4) and all policy set forth by Office of Human Capital (OHC) in TS MD 1100.73-5 Employee Responsibilities And Conduct and DHS MD 4400.1 DHS Web (Internet, Intranet, and Extranet Information) and Information Systems.

Not Defined

AC-4 MH

FP

1.4.9 SSI, sensitive data and information protected under the Privacy Act shall be posted to TSA internal web sites only if access controls are in place and approved by IAD, and the content has been approved in advance by the SSI Branch and/or Privacy Office and the Information Owner (IO) for posting.

Not Defined

AC-4 MH

FP

1.4.10 Information regarding TSA personnel or their families, (to include names, phone numbers and addresses) assigned to units that are sensitive, routinely deployable, or stationed in foreign territories shall not be released nor shall such individuals be identified in photographs or articles including:

- Internal program agenda, correspondence, and memos not appropriate for general distribution.

- Procurement or acquisition sensitive information.

- Operations Security (OPSEC) and Information Security

(INFOSEC) material.

- Other sensitive information, which by statute TSA is not required to encrypt, but should only be posted when authorized by the Information Owner (IO). This includes Law Enforcement Sensitive (LES) and For Official Use Only (FOUO) information.

Not Defined

AC-4 MH

FP

1.4.11 The ISSO shall ensure fax servers are configured so that incoming communications lines cannot be used to access the network or any data on fax servers.

4.5.2.b AC-4 LMH

FP

1.4.12 The ISSO shall ensure data communication connections via modems are limited and are tightly controlled.

5.4.1.a AC-4

AC-17

LMH

FP

1.4.13 Data communication connections via modems are not allowed unless they have been authorized by the CISO.

5.4.1.a AC-4

AC-17

LMH

FP

1.4.14 Remote access to DHS networks shall be approved and only be accomplished through equipment specifically approved for that purpose.

5.4.1.a AC-4

AC-17

LMH

FP

1.4.15 Tethering through wireless mobile devices is prohibited unless approved by the AO.

5.4.1.a AC-4

AC-17

http://dhsconnect.dhs.gov/policies/Instructions/4400.1%20DHS%20Web%20(Internet,%20Intranet,%20and%20Extranet%20Information)%20and%20Information%20Systems.pdf

4300A

NIST SP

800-53 Category

1.4.16 Remote access of PII shall comply with all TSA requirements for sensitive systems, including strong authentication. Secure communication shall be accomplished via VPN or equivalent encryption and two-factor authentication. The Security Plan (SP) shall document any remote access of PII, and the remote access shall be approved by the AO prior to implementation.

5.4.1.c AC-4

AC-17

MH

FP

1.4.17 Auto-forwarding or redirecting of TSA email to addresses outside of the .gov or .mil domain is prohibited and shall not be used.

5.4.6.i AC-4 LMH

3.1.5 Separation of Duties (AC-5)

ID Policy Element DHS 4300A

NIST SP

800-53 Category

1.5.1 Reserved

1.5.2 The ISSO shall document the separation of duties within the SP and the implementation of separation of duties through assigned information system access authorizations.

5.2 AC-5 MH

F

1.5.3 Duty requirements for mission critical processing functions shall be clearly documented and distributed to more than one individual.

5.2 AC-5 MH

F

1.5.4 The ISSO shall be notified of instances or areas where a single individual is responsible for the performance of an entire mission processing function (to include data input, data processing, log maintenance, application maintenance, data back up, and recovery).

3.7 4.1.4

AC-5 MH

F

1.5.5 Standard user accounts are issued to the individual identified on the account request form. Standard user accounts are for the use of this specific individual and the account identifier (user name) and password are solely to be used by this individual.

5.2.c AC-5

IA-5

MH

F

1.5.6 Separation of duties shall ensure that personnel who control the generation of information security historical data shall not be the same personnel who audit and review that data in compliance with the TS-049 Information Systems Logging.

3.7 AC-5 LMH

3.1.6 Least privilege (AC-6)

ID Policy Element DHS

4300A

NIST SP

800-53 Category

1.6.1 The SO shall ensure the information system employs the concept of least privilege, allowing only authorized accesses for users (and processes acting on behalf of users), which are necessary to accomplish assigned tasks in accordance with TSA and DHS missions and business functions.

4.1.4 AC-6 MH

FP

1.6.2 Port security on a network appliance within the TSA/DHS network shall be configured by default to deny all and permit by exception.

Specific detailed guidance on port security is contained in the TSA

4.1.4 AC-6 MH

4300A

NIST SP

800-53 Category

TS-012 Port Security.

1.6.3 Users, personnel using, or supporting TSA systems shall not attempt to use service accounts or any other account to circumvent resource or security restrictions.

4.1.4 AC-6 MH

FP

1.6.4 Each system shall be configured to restrict a user or process to the least privileges or access required to perform authorized tasks.

4.1.4 AC-6 MH

FP

1.6.5 Remote access privileges shall only be granted to authorized TSA employees, contractors, and agents with valid business requirements for remote access.

4.1.4 AC-6 MH

FP

1.6.6 Each remote access account request shall be formally reviewed and approved by the SO.

4.1.4

AC-6 MH

1.6.7 Each system’s ISSO shall submit an up-to-date list to the TSA Security Operations Center (SOC) each month, containing the names of individuals allowed systems remote access.

4.1.4 AC-6 MH

FP

1.6.8 ISSOs shall limit network communications to specific protocols to reduce network and firewall rule complexity. Additional information can be found in the TSA TS-019 Network Communication Protocol.

4.1.4 AC-6 MH

FP

1.6.9 Least privilege is applicable to all infrastructure and end user assets on all TSA networks regardless of SELC status.

4.1.4 AC-6 MH

FP

1.6.10 Privileged accounts shall only be used with the specific functions for which the accounts were assigned. All other system functions (to include email, web browsing, and document preparation) shall use accounts with the lowest necessary privileges.

4.1.4 AC-6 MH

FP

1.6.11 The SO shall ensure data stored on RFID tags is limited to the greatest extent possible, recording information beyond an identifier only when required for the application mission. When data beyond an identifier is stored on a tag, the tag’s memory shall be protected by access control.

4.6.4.b AC-6

PL-5

MH

FP

1.6.12 The SO shall ensure systems that collect, process, or store Protected Health Information (PHI) protect that information in compliance with HIPAA regulations.

3.17.a AC-6

MP-1

LMH

FP

1.6.13 All downloads of PII via remote access shall follow the concept of least privilege and shall be documented in the SP.

5.4.1.d AC-6 MH

FP

1.6.14 The AO, or delegated authority, shall provide final approval of privileged access accounts to TSA systems.

Not Defined

AC-6

(1)

LMH

FP

1.6.15 Users of privileged system accounts (Privileged Users) shall use non-privileged accounts when accessing non-privileged functions (to include email, web-browsing, document creation)

4.1.4.c AC-6 (2)

LMH

FP

1.6.16 The SO shall audit any use of privileged accounts, or roles, for non-privileged functions.

1.6.17 The SO and AO shall only authorize network access to sensitive or mission-critical data for compelling operational needs, and the ISSO

Not Defined

AC-6

(3)

4300A

NIST SP

800-53 Category shall document the rationale for such access in the SP.

1.6.18 Reserved

1.6.19 The ISSO shall limit super user accounts to designated system administration personnel.

Not Defined

AC-6

(5)

3.1.7 Unsuccessful Logon Attempts (AC-7)

ID Policy Element DHS 4300A

NIST SP

800-53 Category

1.7.1 All user accounts shall be automatically locked after three (3) consecutive failed logon attempts.

5.2.1.a AC-7 LMH F

1.7.2 Accounts locked due to failed login attempts shall automatically unlock after twenty (20) minutes.

5.2.1.b AC-7 LMH F

1.7.3 Single Point of Contact (SPOC) procedures for unlocking an account prior to the twenty (20) minute lockout period shall be approved by the CISO.

5.2.1.c AC-7 LMH F

1.7.4 Workstation, laptop, and tablet logon, logoff, and locking procedures shall be consistent with DHS 4300A PD Attachment I Workstation Logon, Logoff, and Locking Procedures.

3.7 AC-3

CM-2

3.1.8 System Use Notification (AC-8)

This control implements the requirements of DHS MD 4400.1, DHS Web (Internet, Intranet, and Extranet Information) and Information Systems, regarding the proper allocation of safeguards for TSA Internet, Intranet, and Extranet web sites and the proper notification to individuals of privacy safeguards.

Policy

ID Policy Element DHS 4300A

NIST SP

800-53 Category

1.8.1 A TSA approved logon warning banner message shall be displayed on the login screens of TSA IT assets that have a viewing screen (to include workstations, laptops, tablets, and mobile devices) to the extent technologically feasible.

4.8.5 5.2.3

AC-8 LMH

F

1.8.2 The DHS approved warning banner, as stated in DHS 4300A, paragraph 5.2.3, shall be utilized as the TSA approved logon warning banner.

4.8.5 5.2.3.a

AC-8 LMH

F

1.8.3 Reserved

1.8.4 The SO shall ensure clear privacy policies are posted on TSA web sites, as well as at any other known, major entry points to sites, and at any web page where personal information is posted or collected.

4.8.5 4.9

5.2.3

AC-8 LMH

F

1.8.5 Security and privacy policies shall be clearly labeled and easily viewed at the entry point to every TSA web site.

4.8.5 4.9

AC-8 LMH

4300A

NIST SP

800-53 Category

5.2.3.b

1.8.6 TSA information system users shall have no expectations of privacy associated with the use of the system. By completing the authentication process, the user acknowledges his or her consent to monitoring. The use of TSA office equipment and TSA systems/computers constitutes consent to monitoring and auditing of the equipment/systems. Monitoring includes the tracking of internal transactions and external transactions such as Internet access. It also includes auditing of stored data on local and network storage devices as well as removable media. Consent to monitoring shall be noted within the signed rules of behavior.

4.8.5.c 4.8.5.d 4.8.5.e

AC-8

PL-4

3.1.9 Previous Logon (Access) Notification (AC-9)

Currently, this control does not apply to any control baselines, nor does it apply to Privacy or Financial systems.

3.1.10 Concurrent Session Control (AC-10)

ID Policy Element DHS 4300A

NIST SP

800-53 Category

1.10.1 Concurrent logins to the same system or application using the same authentication credentials are not allowed, unless a specific business or operational need is documented and approved by the AO.

5.2.f AC-10 H

3.1.11 Session Lock (AC-11)

Information concerning this control may be found in TSA TS-015 Network Logical Access Control.

Policy

ID Policy Element DHS 4300A

NIST SP

800-53 Category

1.11.1 Network applications or systems shall automatically lock user sessions when the session is inactive for twenty (20) minutes. The user shall be required to re-authenticate to re-establish network access.

5.2.2.a 5.2.2.b

AC-11 MH

3.1.12 Session Termination (AC-12)

Currently, this control applies to Moderate and High control baselines.

3.1.13 Supervision and Review—Access Control (AC-13) (Withdrawn) This control has been withdrawn by NIST and is no longer in force.

3.1.14 Permitted Actions without Identification or Authentication (AC-14)

ID Policy Element DHS 4300A

NIST SP

800-53 Category

1.14.1 The CISO shall approve any actions on an information system to be performed by a user without proper identification and authentication in order to accomplish mission/business objectives.

Not Defined

AC-14

(1)

1.14.2 The SO shall document and provide supporting rationale in the SP for all user actions not requiring identification and authentication.

Not Defined

AC-14 LMH

3.1.15 Automated Marking (AC-15) (Withdrawn)

3.1.16 Security Attributes (AC-16)

3.1.17 Remote Access (AC-17)

This control provides direction for minimizing the threats associated with remote access and applies to all authorized TSA employees, contractors, vendors, and agents with remote access to TSA IT assets. Remote access implementations that are covered by this policy include, but are not limited to, VPNs, dial-in modems, frame relay, Integrated Services Digital Network (ISDN), Secure Shell (SSH) connections, and connections made through asynchronous transfer mode (ATM), Wireless, or Digital Subscriber Line (DSL).

Remote access controls are applicable to information systems other than public web servers or systems specifically designed for public access.

Policy

ID Policy Element DHS 4300A

NIST SP

800-53 Category

1.17.1 The SO shall document allowed methods of remote access to the information system, establish usage restrictions and implementation guidance for each allowed remote access method.

5.1 AC-17 LMH

FP

1.17.2 The CISO shall establish usage restrictions and implementation guidance for each allowed remote access method.

5.1 AC-17 LMH

FP

1.17.3 The SO shall ensure the information system and/ or SOC monitors for unauthorized remote access to the information system.

5.1 AC-17 LMH

FP

1.17.4 The AO, or delegated authority, shall authorize remote access to the information system prior to connection.

5.1 AC-17 LMH

FP

1.17.5 The SO shall enforce requirements for remote connections to the information system.

5.1 AC-17 LMH

FP

1.17.6 The ISSO shall ensure that the inbound dial-in capabilities are disabled on any multifunction device connected to a TSA information system containing sensitive data.

4.12.j AC-17 LMH

FP

1.17.7 The ISSO shall ensure that Remote Desktop connections, such as Microsoft’s Remote Desktop Protocol (RDP), are not used to

5.4.5.f AC-17 LMH

4300A

NIST SP

800-53 Category connect to or from any TSA computer without the use of an authentication method that employs secure authentication.

FP

1.17.8 Remote access of PII shall not permit the download and remote storage of information unless the requirements for the use of removable media with sensitive information have been addressed.

5.4.1.d AC-17 LMH

FP

1.17.9 The CISO shall ensure TSA systems employ automated mechanisms to facilitate monitoring and control of remote access methods.

Not Defined

AC-17

(1)

LMH

FP

1.17.10 The SO shall ensure the system uses cryptography to protect the Confidentiality and Integrity of remote access sessions in compliance with TS-002 Encryption.

Not Defined

AC-17

(2)

LMH

FP

1.17.11 The SO shall ensure the system routes remote access through a limited number of managed access control points.

Not Defined

AC-17

(3)

LMH

FP

1.17.12 The CISO shall authorize remote access for the execution of privileged commands and security-relevant information only for compelling operational needs and the ISSO shall document the rationale for such access in the security plan for the information system.

Not Defined

AC-17

(4)

LMH

FP

1.17.13 The CISO shall ensure operational systems continuously monitor for unauthorized remote connections and take appropriate action if an unauthorized connection is discovered.

Not Defined

AC-17

(5)

LMH

FP

1.17.14 The SO shall ensure that users protect information about remote access mechanisms from unauthorized use and disclosure.

Not Defined

AC-17

(6)

MH

FP

1.17.15 The CISO shall ensure that remote sessions for accessing sensitive systems are logged and monitored in compliance with TS-049 Information Systems Logging

5.3.c AC-17 (7)

LMH

FP

1.17.16 The SO shall ensure the system disables unauthorized protocols except for explicitly identified components in support of specific operational requirements, with a signed and approved waiver from the CISO.

Not Defined

AC-17

(8)

3.1.18 Wireless Access (AC-18)

ID Policy Element DHS

4300A

NIST SP

800-53 Category

1.18.1 The CISO shall ensure the establishment of usage restrictions and implementation guidance for wireless access. See TS-003, WiFi (802.11) and DHS 4300A Attachment Q1, Wireless Systems

5.1 4.6.1.g

AC-18

PM-5

1.18.2 The CISO shall ensure unauthorized wireless access to TSA information systems is monitored.

5.1 4.6.1.g

AC-18 LMH

1.18.3 The CISO shall authorize wireless access to information systems prior to implementation.

1.18.4 The CISO shall enforce requirements for wireless connections to the information system.

4300A

NIST SP

800-53 Category

1.18.5 Wireless mobile devices shall only be tethered or otherwise physically or wirelessly connected to TSA information systems with AO authorization.

4.6.2.b AC-18

1.18.6 The CISO shall ensure WiFi, Bluetooth, and RFID are implemented in compliance with TS-003 WiFi, TS-004 Bluetooth, and TS-024 RFID. Also see NIST SP 800-121 rev 1 for Guide to Bluetooth Security.

Not

AC-18

1.18.7 The SO shall ensure the system protects wireless access to the system using authentication and encryption.

Not Defined

AC-18

MH

1.18.8 The SO shall implement and enforce continuous monitoring for unauthorized wireless connections to the information system, including scanning for unauthorized wireless access points and shall take appropriate action if an unauthorized connection is discovered.

Not Defined

AC-18

(2)

H

1.18.9 Reserved

1.18.10 The SO shall not allow users to independently configure wireless networking capabilities.

Not Defined

AC-18

(4)

3.1.19 Access Control for Mobile Devices (AC-19)

This control provides general security direction for mobile TSA IT assets allocated to end users in the performance of their assigned duties. TSA IT assets include, but are not limited to: workstations, laptop computers, mobile devices such as tablets, infrastructure devices (switches, routers, firewalls, etc.), software (individual and enterprise), firmware, peripheral devices (Universal Serial Bus (USB) drives, USB microphones, keyboards, etc.), and Mobile Electronic Media (MEM). These requirements shall extend to TSA IT assets located at non-TSA facilities. The user shall review supporting sections of the TSA TS-008 End User Assets, for specific asset policy. The DHS 4300A Sensitive System Handbook Attachment Q1 “Wireless Systems”, DHS 4300A Handbook Attachment Q2 “Mobile Devices”, as well as the NIST SP 800-124, Rev 1 “Guidelines for Managing the Security of Mobile Devices in the Enterprise”, has guidance on wireless, mobile devices, mobile applications and mobile management in the enterprise. The DHS Enterprise Secure Architecture (ESA) Secure Mobile Computing also provides security principles and safeguarding guidelines.

Lastly, the NIST SP 800-164 Guidelines on Hardware-Rooted Security in Mobile Devices, as well as the NIST SP 800-163 Guidelines for Testing and Vetting Mobile Applications both provide general references for safeguarding mobile components.

Policy

ID Policy Element DHS 4300A

NIST SP

800-53 Category

1.19.1 The AO shall authorize connection of mobile devices to TSA information systems.

Not

AC-19

1.19.2 The CISO shall ensure monitoring of unauthorized connections of mobile devices to TSA information systems.

Not

1.19.3 The SO shall:

- Enforce requirements for the connection of mobile devices to

4.6.2 AC-19

http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Pages/archdocs.aspx http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Pages/archdocs.aspx

4300A

NIST SP

800-53 Category

TSA information systems, and

- Disable information system functionality that provides the capability for automatic execution of code on mobile devices without user direction.

1.19.4 The SO of mobile devices shall:

- Issues specially configured mobile devices to individuals traveling to locations that the TSA deems to be of significant risk, and

- Apply preventative measures to mobile devices returning from these locations.

Not

1.19.5 Information stored on laptop computers, tablets or other mobile computing device that may be used in a residence or on travel shall use encryption in compliance with TS-002 Encryption.

4.8.2.b

PL-4

1.19.6 Laptop computers, tablets and other mobile computing devices shall be secured when unattended via a locking cable, or locked office, or locked cabinet or desk.

4.8.2.c

1.19.7 Users on non-routine travel outside the U.S. or its territories shall inform both their immediate supervisor and Division Director (or Delegated Official) in writing and obtain written approval prior to taking their laptop computer or other mobile computing device overseas.

4.8.2.d

1.19.8 Unclassified mobile devices and other wireless enabled devices or any recording device shall not be used within areas where classified information is discussed, processed or stored.

4.6.2.a 4.6.2.k

1.19.9 The CISO shall approve the use of writable, removable media in TSA information systems.

4.3.1.a AC-19

MP-2

PM-9

1.19.10 Personally owned, removable media shall not be used on TSA systems.

4.3.1.c AC-19 (2)

MP-1

1.19.11 Only TSA owned and approved removable media may be used with TSA information systems.

Not Defined

AC-19

(3)

1.19.12 Users who telework may connect their TSA-issued laptop to their home peripheral equipment such as a: monitor, keyboard, and mouse. None of these three peripheral devices will have residual memory and all must be cabled or hardwired (no wireless connection).

Not Defined

AC-19

(5)

LMH

1.19.13 Mobile device users shall have available to them: preauthorized, reusable, secured and compliant mobile applications (or apps) and services. This shall be done via an authorized and dedicated TSA enterprise applications catalog, code repository, and library or apps store.

4.6.2 AC-19

SC-18

LMH

1.19.14 For secure mobile applications:

- restrict which app stores, library, repository or catalog may be

4.6.2 AC-19

SC-18

4300A

NIST SP

800-53 Category used and which applications may be installed through whitelisting or blacklisting;

- restrict the amount and types of commercial pre-loaded mobile applications;

- restrict permissions assigned to each mobile application;

- ensure proper build, configuration, internal testing, independent third party penetration testing or application vulnerability scanning, deployment, installation, update, tracking and removal of applications;

- maintain an accurate and detailed inventory of all mobile applications;

- restrict the use of application synchronization (example: local device synch services, remote synch services and websites);

- verify digital signatures on mobile applications to ensure that only apps from trusted entities are installed on the device and that the code has not been modified;

- limit mobile device deployment to TSA-sanctioned devices, technologies, and applications by using Mobile Device Management (MDM) systems, which allows centralization of mobile devices and enforcement of security policies on the devices;

- mobile devices and applications shall be incorporated into the TSA systems development life cycle (SDLC) process, and shall consider phases such as product: initiation, design, development, testing, independent third party testing or application vulnerability scanning, implementation, deployment, O&M and disposition;

- shall be centrally managed by an enterprise Mobile Application Management (MAM), which functions to evaluate and select mobile applications, as well as acts as an authorized enterprise application store for users. MAM also provides for the ability to monitor installed applications and remotely upgrade or uninstall applications, as necessary; and

- allow for Over-the-Air (OTA) software distribution, configuration change detection, remote data-wipe, remote configuration, and asset/property management.

1.19.15 A mobile device shall allow for remote purging/wiping of information in order to address the threat of theft, loss of the device or failed logons.

4.6.2 AC-7

MP-6(8)

LMH

1.19.16 Federal employees shall not engage in text messaging when (a) driving a Government-Owned-Vehicle (GOV), driving a Privately- Owned-Vehicle (POV) while on official Government business, or

(b) when using electronic equipment supplied by the Government while driving.

4.1.2, 4.1.5

AT-1

PL-4

PS-6

LMH

1.19.17 Personal devices such as Bringing Your Own Device (BYOD) are prohibited without prior approval of the AO since these devices tend to be untrustworthy. There is also frequent “jailbreaking” and

4.8.3 SA-6

MP-7

4300A

NIST SP

800-53 Category rooting of these devices where built-in restrictions on security, OS use, etc. have been bypassed.

3.1.20 Use of External Information Systems (AC-20)

ID Policy Element DHS

4300A

NIST SP

800-53 Category

1.20.1 The SO shall establish terms and conditions with other external organizations owning, operating, and/or maintaining external information systems that allow authorized individuals to:

- Access the TSA information system from the external information systems and process, store, and/or

- Transmit TSA-controlled information using the external information systems.

Not Defined

AC-20 LMH

1.20.2 TSA owned removable media shall not be connected to any non- TSA IT asset unless authorized by the AO.

4.3.1.e AC-20

PM-9

LMH

1.20.3 Any device that has been obtained through civil or criminal asset forfeiture shall not be used as part of a TSA information system nor used to process TSA information.

4.8.3.c AC-20 LMH

1.20.4 The SO shall develop and enforce procedures to ensure proper malware scanning of media prior to installation of primary hard drives, software with associated files, and other purchased products.

5.6.c AC-20 LMH

1.20.5 The use of Internet webmail (to include Gmail, Yahoo, AOL, Hotmail) or other personal email accounts is not authorized over TSA furnished equipment or network connections.

5.4.7.a AC-20

SA-7

LMH

1.20.6 The AO shall approve the use an external information system to access TSA systems or to process, store, or transmit TSA-controlled information.

Not Defined

AC-20

(1)

LMH

1.20.7 The AO shall approve the use of a TSA portable storage media on external systems.

Not Defined

AC-20

(2)

LMH

1.20.8 Sensitive TSA information shall only be emailed via .gov or .mil email systems. Sensitive TSA information shall not be sent to or from personal or commercial email addresses.

Not Defined

AC-20

3.1.21 Information Sharing (AC-21)

Currently, this control applies to Moderate and High control baselines.

3.1.22 Publicly Accessible Content (AC-22)

ID Policy Element DHS 4300A

NIST SP

800-53 Category

1.22.1 The IO shall designate individuals authorized to clear TSA information for public release and recommends posting of information onto a TSA information system that is publicly

Not

AC-22 LMH

4300A

NIST SP

800-53 Category accessible.

1.22.2 The IO shall ensure that individuals authorized to clear TSA information for public release are properly trained to ensure that publicly accessible information does not contain nonpublic information.

Not Defined

AC-22 LMH

1.22.3 The proposed content of publicly accessible information for nonpublic information will be reviewed for public clearance prior to posting onto information systems.

Not Defined

AC-22 LMH

1.22.4 The IO shall review and report the content on publicly accessible TSA information systems for nonpublic information quarterly.

Not Defined

AC-22 LMH

1.22.5 The IO shall remove and report nonpublic information from the publicly accessible TSA information system, when discovered.

Not Defined

AC-22 LMH

1.22.6 The TSA Office of Strategic Communications and Public Affairs shall designate “content managers” to post official TSA content to social media sites.

3.16.a AC-22

SA-6

LMH

1.22.7 Content managers shall ensure posted content to TSA web sites is in keeping with the TSA Terms of Service (TOS) and guidelines for a given social media host (to include YouTube, Twitter, etc). Under no circumstances shall sensitive information be posted to social media sites.

3.16.b AC-22

SC-4

LMH

1.22.8 Content managers shall ensure information is not posted to any social media site for which the Department has not approved and published final posting guidelines and TOS.

3.16.c AC-22

SA-6

SC-4

LMH

1.22.9 Content managers shall review and understand the appropriate Department-level TOS for the appropriate social media host.

3.16.d AC-22

SC-4

AT-3

LMH

1.22.10 Content managers shall make a risk decision prior to posting any information and shall recognize that social medial hosts are not TSA information systems and therefore subject only to the TSA TOS and not to TSA policy. Once released, information is no longer under TSA control.

3.16.e AC-22

AT-2

SC-4

SI-9

LMH

3.1.23 Data Mining Protection (AC-23)

Policy

ID Policy Element

DHS

4300A

NIST SP

800-53 Category

1.23.1 Reserved

3.2 Awareness and Training (AT)

All TSA users are required to have annual security awareness training commensurate with their system responsibilities. Prior to gaining access to TSA information systems, all TSA users are required to sign TSA Form 1403 Computer and PED Access Agreement and annually thereafter. In addition, all users are required to have a level of awareness to support their responsibilities in protecting the security of the TSA information systems. These goals are accomplished through initial and refresher training in compliance with the TSA Security Awareness, Training, and Education policy and DHS 4300A.. This control applies to all TSA personnel and contractors.

3.2.1 Security Awareness and Training Policy and Procedures (AT-1)

ID Policy Element DHS 4300A

NIST SP

800-53 Category

2.1.1 The CISO shall develop, disseminate, and annually review/update a formal, documented security awareness and training policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among TSA entities, and compliance; and formal, documented procedures to facilitate the implementation of the security awareness and training policy and associated security awareness and training controls.

2.1.3 4.1.5.a

AT-1 LMH

P

2.1.2 The CISO shall ensure the maintenance of an ongoing IT

Security/information assurance awareness program comprised of training, posters, newsletters, and other promotional material.

Not Defined

AT-1 LMH

P

2.1.3 The CIO and CISO shall provide resources to develop or acquire, refine, and deliver IT Security/IA or Cyber Security Awareness Training and Significant Security Responsibility position security training.

4.1.5

AT-1 LMH

2.1.4 The SO shall factor training impacts into proposed or planned technology or operational changes.

4.1.5 AT-1 LMH

P

2.1.5 The CISO shall prepare and submit IT Security/IA Awareness, Training, and Education statistics monthly and training reports to the DHS IT Security Training Program Director as required by DHS 4300A.

4.1.5.g 4.1.5.h

AT-1 LMH

P

2.1.6 The…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .