Attachment_J.14_-_DHS_4300A_Sensitive_Systems_Handbook.pdf

PDF 2 MB Posted

Attached to
Transportation Security Equipment Deployment Services (TEDS) Federal contract opportunity
Solicitation number
HSTS04-14-R-CT4049
Issued by
Department of Homeland Security Transportation Security Administration

About this file

Attachment J.14 DHS 4300A Sensitive Systems Handbook

View the file

Other files for this federal contract opportunity

Other files attached to Transportation Security Equipment Deployment Services (TEDS), newest first.
File Type Posted
Attachment_J_3_-_Question_and_Answer_Sheet_A00003.pdf PDF
HSTS04-14-R-CT4049_-_SF_30_A00003.pdf PDF
Attachment_J.3_-_Question_and_Answer_Sheet_Amendment_A00002.pdf PDF
Attachment_J.10_-_Pricing_Worksheets_CENTRAL_A00002.xlsx XLSX spreadsheet
HSTS04-14-R-CT4049_Amendment_A00002.pdf PDF
Attachment_J.11_-_Pricing_Worksheets_WEST_A00002.xlsx XLSX spreadsheet
Attachment_J.9_-_Pricing_Worksheets_EAST_A00002.xlsx XLSX spreadsheet
HSTS04-14-R-CT4049_-_SF_30_A00002.pdf PDF
Attachment_J.5_-_Task_Order_02.pdf PDF
Attachment_J.15_-_OST_Test_and_Evaluation_Guidebook.pdf PDF
HSTS04-14-R-CT4049_Amendment_A00001.pdf PDF
Attachment_J.7_-_Past_Performance_Statement.docx DOCX document
Attachment_J.11_-_Pricing_Worksheets_WEST_A00001.xlsx XLSX spreadsheet
HSTS04-14-R-CT4049_-_SF_30.pdf PDF
Attachment_J.3_-_Question_and_Answer_Sheet_A00001.pdf PDF
Attachment_J.16_-_OST_Test_and_Evaluation_Guide.pdf PDF
Attachment_J.4_-_Task_Order_01.pdf PDF
Attachment_J.10_-_Pricing_Worksheets_CENTRAL_A00001.xlsx XLSX spreadsheet
Attachment_J.13_-_TSA_Information_Assurance_Handbook.pdf PDF
Attachment_J.9_-_Pricing_Worksheets_EAST_A00001.xlsx XLSX spreadsheet
Attachment_J.17_OST_OA_Test_and_Evaluation_Policy.pdf PDF
Attachment_J.4_-_Task_Order_01.pdf PDF
Attachment_J.7_-_Past_Performance_Statement.docx DOCX document
Attachment_J.8_-_Past_Performance_Questionnaire.docx DOCX document
Attachment_J.11_-_Pricing_Worksheets_WEST.xlsx XLSX spreadsheet
Attachment_J.6_-_DHS_Subcontracting_Plan_Review_Checklist.pdf PDF
Attachment_J.5_-_Task_Order_02.pdf PDF
Attachment_J.3_-_Question_and_Answer_Sheet.xlsx XLSX spreadsheet
Attachment_J.1_-_FED_Map.pdf PDF
HSTS04-14-R-CT4049.pdf PDF
Attachment_J.2_-_SCA_DBA_Spreadsheet.pdf PDF
Attachment_J.9_-_Pricing_Worksheets_EAST.xlsx XLSX spreadsheet
Attachment_J.10_-_Pricing_Worksheets_CENTRAL.xlsx XLSX spreadsheet
Attachment_J.12_-_Pricing_Worksheets_ALL.xlsx XLSX spreadsheet
Show all 34

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DHS 4300A

Sensitive Systems Handbook

Version 9.1 July 24, 2012

Protecting the Information that Secures the Homeland

DHS 4300A SENSITIVE SYSTEMS HANDBOOK

4300A Sensitive Systems Handbook v9.1 ii July 24. 2012

This page intentionally left blank

4300A Sensitive Systems Handbook v9.1 iii July 24. 2012

Contents

1.0 INTRODUCTION

1.1 Information Security Program and Implementation Guidelines

1.2 Authorities

1.3 Policy Overview

1.4 Definitions

1.4.1 Sensitive Information

1.4.2 Public Information

1.4.3 National Security Information

1.4.4 Classified National Security Information

1.4.5 National Intelligence Information

1.4.6 Foreign Intelligence Information

1.4.7 Information Technology

1.4.8 DHS System

1.4.9 Component

1.4.10 Trust Zone

1.4.11 Continuity of Operations

1.4.12 Continuity of Operations Plan

1.4.13 Essential Functions

1.4.14 Vital Records

1.4.15 Federal Information Security Management Act

1.4.16 Personally Identifiable Information

1.4.17 Sensitive Personally Identifiable Information

1.4.18 Privacy Sensitive System

1.4.19 Strong Authentication

1.4.20 Two-Factor Authentication

1.5 Waivers and Exceptions

1.5.1 Waivers

1.5.2 Exceptions

1.5.3 Waiver or Exception Requests

1.5.4 Requests for Exception to U.S. Citizenship Requirement

1.6 Electronic Signature

1.7 Information Sharing

1.8 Threats

1.8.1 Internal Threats

1.8.2 Criminal Threats

1.8.3 Foreign Threats

1.8.4 Lost or Stolen Equipment

1.8.5 Supply Chain Threats

1.9 Changes to Policy

2.0 ROLES AND RESPONSIBILITIES

4300A Sensitive Systems Handbook v9.1 iv July 24. 2012

2.1 Information Security Program Roles

2.1.1 DHS Senior Agency Information Security Officer

2.1.2 DHS Chief Information Security Officer

2.1.3 Component Chief Information Security Officer

2.1.4 Component Information Systems Security Manager

2.1.5 Risk Executive

2.1.6 Authorizing Official

2.1.7 Security Control Assessor

2.1.8 Information Systems Security Officer

2.2 Other Roles

2.2.1 Secretary of Homeland Security

2.2.2 Under Secretaries and Heads of DHS Components

2.2.3 DHS Chief Information Officer

2.2.4 Component Chief Information Officer

2.2.5 DHS Chief Security Officer

2.2.6 DHS Chief Privacy Officer

2.2.7 DHS Chief Financial Officer

2.2.8 Program Managers

2.2.9 System Owners

2.2.10 Common Control Provider

2.2.11 DHS Employees, Contractors, and Others Working on Behalf of DHS

3.0 MANAGEMENT POLICIES

3.1 Basic Requirements

3.2 `Capital Planning and Investment Control

3.2.1 Capital Planning and Investment Control Process

3.3 Contractors and Outsourced Operations

3.4 Performance Measures and Metrics

3.5 Continuity Planning for Critical DHS Assets

3.5.1 Continuity of Operations Planning

3.5.2 Contingency Planning

3.6 System Engineering Life Cycle

3.6.1 Planning

3.6.2 Requirements Definition

3.6.3 Design

3.6.4 Development

3.6.5 Test

3.6.6 Implementation

3.6.7 Operations and Maintenance

3.6.8 Disposition

3.7 Configuration Management

3.8 Risk Management

3.8.1 Risk Assessment

3.8.2 Risk Mitigation

3.8.3 Evaluation and Assessment

3.9 Security Authorization and Security Assessments

4300A Sensitive Systems Handbook v9.1 v July 24. 2012

3.9.1 FIPS 199 Categorization and the NIST SP 800-53 Controls

3.9.2 Privacy Impact Assessment

3.9.3 E-Authentication

3.9.4 Risk Assessment

3.9.5 Security Plan

3.9.6 Contingency Plan

3.9.7 Security Control Assessment Plan

3.9.8 Contingency Plan Testing

3.9.9 Security Assessment Report

3.9.10 Plan of Action and Milestones

3.9.11 Authorization to Operate Letter

3.9.12 Annual Self-Assessments

3.10 Information Security Review and Assistance

3.10.1 Review and Assistance Management and Oversight

3.10.2 Information Security Assistance

3.10.3 Information Security Reviews

3.11 Security Working Groups and Forums

3.11.1 CISO Council

3.11.2 DHS Information Security Training Working Group

3.11.3 DHS Security Policy Working Group

3.12 Information Security Policy Violation and Disciplinary Action

3.13 Required Reporting

3.14 Privacy and Data Security

3.14.1 Personally Identifiable Information

3.14.2 Privacy Threshold Analyses

3.14.3 Privacy Impact Assessments

3.14.4 System of Record Notices

3.14.5 Protecting Privacy Sensitive Systems

3.14.6 Privacy Incident Reporting

3.14.7 E-Authentication

3.15 DHS CFO Designated Systems

3.16 Social Media

3.17 Health Insurance Portability and Accountability Act

3.18 Cloud Services

4.0 OPERATIONAL CONTROLS

4.1 Personnel

4.1.1 Personnel Screening and Position Categorization

4.1.2 Rules of Behavior

4.1.3 Access to Sensitive Information

4.1.4 Separation of Duties

4.1.5 Information Security Awareness, Training, and Education

4.1.6 Separation from Duty

4.2 Physical Security

4.2.1 General Physical Access

4.2.2 Sensitive Facility

4300A Sensitive Systems Handbook v9.1 vi July 24. 2012

4.3 Media Controls

4.3.1 Media Protection

4.3.2 Media Marking and Transport

4.3.3 Media Sanitization and Disposal

4.3.4 Production, Input/Output Controls

4.4 Voice Communications Security

4.4.1 Private Branch Exchange

4.4.2 Telephone Communications

4.4.3 Voice Mail

4.5 Data Communications

4.5.1 Telecommunications Protection Techniques

4.5.2 Facsimiles

4.5.3 Video Teleconferencing

4.5.4 Voice Over Data Networks

4.6 Wireless Network Communications

4.6.1 Wireless Systems

4.6.2 Wireless Portable Electronic Devices

4.6.3 Wireless Tactical Systems

4.6.4 Radio Frequency Identification

4.7 Overseas Communications

4.8 Equipment

4.8.1 Workstations

4.8.2 Laptop Computers and Other Mobile Computing Devices

4.8.3 Personally Owned Equipment and Software

4.8.4 Hardware and Software

4.8.5 Personal Use of Government Office Equipment and DHS

Systems/Computers

4.8.6 Wireless Settings for Peripheral Equipment

4.9 Department Information Security Operations

4.9.1 Security Incidents and Incident Response and Reporting

4.9.2 Law Enforcement Incident Response

4.9.3 Definitions and Incident Categories

4.10 Documentation

4.11 Information and Data Backup

4.12 Converging Technologies

5.0 TECHNICAL CONTROLS

5.1 Identification and Authentication

5.1.1 Passwords

5.2 Access Control

5.2.1 Automatic Account Lockout

5.2.2 Automatic Session Termination

5.2.3 Warning Banner

5.3 Auditing

5.4 Network and Communications Security

5.4.1 Remote Access and Dial-In

4300A Sensitive Systems Handbook v9.1 vii July 24. 2012

5.4.2 Network Security Monitoring

5.4.3 Network Connectivity

5.4.4 Firewalls and Policy Enforcement Points

5.4.5 Internet Security

5.4.6 Email Security

5.4.7 Personal Email Accounts

5.4.8 Testing and Vulnerability Management

5.4.9 Peer-to-Peer Technology

5.5 Cryptography

5.5.1 Encryption

5.5.2 Public Key Infrastructure

5.5.3 Public Key/Private Key

5.6 Malware Protection

5.6.1 Types of Malware

5.6.2 How Malware Affects Systems

5.6.3 Procedures When Malware Is Detected On a System

5.7 Product Assurance

5.8 Supply Chain

6.0 DOCUMENT CHANGE REQUESTS

7.0 QUESTIONS AND COMMENTS

APPENDIX A ACRONYMS AND ABBREVIATIONS

APPENDIX B GLOSSARY

APPENDIX C REFERENCES

APPENDIX D DOCUMENT CHANGE HISTORY

Enclosure 1—DHS Secure Baseline Configuration Guides

• Cisco Router Secure Baseline Configuration Guide

• HP-UX Secure Baseline Configuration Guide

• Linux Secure Baseline Configuration Guide

• Solaris Secure Baseline Configuration Guide

• Solaris 10 Secure Baseline Configuration Guide

• Windows Secure Baseline Configuration Guide

• SQL Server Secure Baseline Configuration Guide

• ORACLE Secure Baseline Configuration Guide

• Legacy Windows NT Configuration Guidance

− Guidance for Securing Windows NT

4300A Sensitive Systems Handbook v9.1 viii July 24. 2012

− Level One Benchmark Windows NT 4-0 Operating Systems V1.0.5

− Guide to Securing Microsoft Windows NT Network

− Addendum to the NSA Guide to Securing Microsoft Windows NT Networks and NSA Guides to Securing Windows 2000

• Windows 2003 Server/Windows XP/Windows Vista Secure Baseline Configuration Guide

Attachment A—Requirements Traceability Matrix [removed as of v9.1]

Attachment B—Waivers and Exceptions Request Form

Attachment C—Information Systems Security Officer Designation Letter

Attachment D—Type Authorization

Attachment E—FISMA Reporting

Attachment F—Incident Response and Reporting

Attachment G—Rules of Behavior

Attachment H—Plan of Action and Milestones (POA&M) Process Guide

Attachment I—Workstation Logon, Logoff, and Locking Procedures [removed as of v9.1]

Attachment J—Requesting Exceptions to Citizenship Requirement

Attachment K—IT Contingency Plan Template

Attachment L—Password Management

Attachment M—Tailoring the NIST SP 800-53 Security Controls

Attachment N—Preparation of Interconnection Security Agreements

Attachment O—Vulnerability Assessment Program

Attachment P—Document Change Requests

Attachment Q1—Wireless Systems

Attachment Q2—Wireless Portable Electronic Devices

Attachment Q3—Wireless Tactical Systems

Attachment Q4—Sensitive RFID Systems

Attachment R—Compliance Framework for CFO Designated Financial Systems

Attachment S—Compliance Framework for Privacy Systems

Attachment S1—Managing CREs Containing SPII

Attachment T—Acronyms and Abbreviations [removed as of v9.1]

Attachment X—Social Media

4300A Sensitive Systems Handbook v9.1 ix July 24. 2012

This page intentionally left blank

4300A Sensitive Systems Handbook v9.1 1 July 24. 2012

1.0 INTRODUCTION

This handbook is a compilation of the best practices used by Department of Homeland Security (DHS) Components and includes requirements contained in various National Institute of Standards and Technology (NIST) publications, Office of Management and Budget (OMB) direction, and Congressional and Executive mandates.

The Handbook serves as a foundation on which Components can develop, build, and implement information security programs; it provides specific techniques and procedures for implementing the requirements of the DHS Information Security Program for Sensitive Systems. These baseline security requirements (BLSR) are generated by the DHS information security policies published in “DHS Sensitive Systems Policy Directive 4300A.” BLSRs must be addressed when developing and maintaining information security documents.

The scope and contents of this handbook will be updated as new capabilities are added to DHS systems, as security standards are upgraded, and as a result of user experience and comment.

This handbook addresses only information security and is issued as implementation guidance under the authority of the DHS Chief Information Officer (CIO) through the Office of the DHS Chief Information Security Officer (CISO).

The aspects of information security addressed by this Handbook pertain to personnel, physical, information, and industrial security; investigations; emergency preparedness; and domestic counterterrorism. . Additional information will be published by the proponents of these programs.

1.1 Information Security Program and Implementation Guidelines

The DHS Information Security Program provides a baseline of policies, standards, and guidelines for DHS Components. This Handbook provides direction to managers and senior executives for managing and protecting sensitive systems. It also outlines policies relating to management, operational, and technical controls necessary for ensuring confidentiality, integrity, availability, authenticity, and nonrepudiation within DHS information system infrastructure and operations.

Policy elements are designed to be broad in scope. Implementation information can often be found in specific NIST publications, such as NIST Special Publication (SP) 800-53, “Recommended Security Controls for Federal Systems and Organizations.”

The policies and direction contained in this document apply to all DHS Components.

Information security policies and implementing procedures for National Security Systems are covered in separate publications, “DHS National Security Systems Policy Directive 4300B” and DHS 4300B National Security Systems Handbook.” These publications are available on the DHS CISO website.

Policy elements are effective when issued. Any policy elements that have not been implemented within ninety (90) days shall be considered a weakness and either a system or program Plan of Action and Milestones (POA&M) must be generated by the Component for the identified weaknesses. When this Policy Directive is changed, the CISO will ensure that appropriate

4300A Sensitive Systems Handbook v9.1 2 July 24. 2012 changes in DHS Security Compliance tools, Risk Management System (RMS), and Trusted Agent FISMA1 (TAF); tool changes are made available to the Department within forty-five (45) days of the changes.

1.2 Authorities

The following list provides the authoritative references for the DHS sensitive information security program. Additional references are located in Appendix C of this document.

The following are authoritative references for the DHS sensitive information security program.

Additional references are located in Appendix C to this Handbook.

• E-Government Act of 2002, including Title III, Federal Information Security Management Act (FISMA), Public Law 107-347, codified at 44 USC. §§ 3541-3549

• OMB Circular A-130, “Management of Federal Information Resources,” revised, November 30, 2000

• DHS Management Directive (MD) 140-01, “Information Technology Systems Security,” July 31, 2007

• DHS Sensitive Systems Policy Directive 4300A

• NIST Federal Information Processing Standard (FIPS) 200, “Minimum Security Requirements for Federal Information and Information Systems,” March 2006”

• NIST SP 800-53, Rev 3, “Recommended Security Controls for Federal Information Systems and Organizations,” August 2009, with updated errata May 01, 2010”

1.3 Policy Overview

DHS information security policies define the security management structure and foundation needed to measure progress and compliance. Policies in this document are organized in three sections:

• Management Controls – These controls focus on managing both system information security controls and system risk. These controls consist of risk mitigation techniques normally used by management.

• Operational Controls – These controls focus on mechanisms primarily implemented and executed by people. Operational controls are designed to improve the security of a particular system or group of systems and often rely on management and technical controls.

• Technical Controls – These controls focus on security controls executed by information systems. Technical controls provide automated protection from unauthorized access or misuse; facilitate detection of security violations; and support security requirements for applications and data.

1 FISMA: Federal Information Security Management Act, 44 U.S.C 3541 http://dhsconnect.dhs.gov/policies/Instructions/Directive%20140-01%20Information%20Technology%20Systems%20Security%20(Revision%2000).pdf

4300A Sensitive Systems Handbook v9.1 3 July 24. 2012

1.4 Definitions

The definitions in this section apply to the policies and procedures discussed in this document.

Other definitions may be found in the “National Information Assurance (IA) Glossary,” and in “Privacy Incident Handling Guidance and the Privacy Compliance.”

1.4.1 Sensitive Information

Sensitive information is information not otherwise categorized by statute or regulation that if disclosed could have an adverse impact on the welfare or privacy of individuals or on the welfare or conduct of Federal programs or other programs or operations essential to the national interest.

Examples of sensitive information include personal data such as Social Security numbers; trade secrets; system vulnerability information; pre-solicitation procurement documents, such as statements of work; and information pertaining to law enforcement investigative methods;

similarly, detailed reports related to computer security deficiencies in internal controls are also sensitive information because of the potential damage that could be caused by the misuse of this information. System vulnerability information about a financial system shall be considered Sensitive Financial Information. All sensitive information must be protected from loss, misuse, modification, and unauthorized access.

1.4.2 Public Information

This type of information can be disclosed to the public without restriction but requires protection against erroneous manipulation or alteration (e.g., public websites).

1.4.3 National Security Information

Information that has been determined, pursuant to Executive Order 13526, “Classified National Security Information,” or any predecessor order, to require protection against unauthorized disclosure.

1.4.4 Classified National Security Information

Information that has been determined, pursuant to Executive Order 13526, “Classified National Security Information,” to require protection against unauthorized disclosure and is marked to indicate its classified status.

1.4.5 National Intelligence Information

The following definition is provided in the Intelligence Reform and Terrorism Prevention Act of 2004 (IRTPA), Public Law 108-458, 118 Stat. 3638:

“The terms ‘national intelligence’ and ‘intelligence related to national security’ refer to all intelligence, regardless of the source from which derived and including information gathered within or outside the United States, that – “(A) pertains, as determined consistent with any guidance issued by the President, to more than one United States Government agency; and “(B) that involves – (i) threats to the http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/National_Information_Assurance_Glossary.pdf http://www.dhs.gov/Privacy

4300A Sensitive Systems Handbook v9.1 4 July 24. 2012

United States, its people, property, or interests; (ii) the development, proliferation, or use of weapons of mass destruction; or (iii) any other matter bearing on United States national or homeland security.”

1.4.6 Foreign Intelligence Information

This type of information relates to the capabilities, intentions, and activities of foreign powers, organizations, or persons, but does not include counterintelligence except for information on international terrorist activities.

1.4.7 Information Technology

Division E of the Information Technology Management Reform Act of 1996, Public Law 104- 106, codified at 40 USC 1401 et seq., commonly referred to as the Clinger-Cohen Act of 1996, defines Information Technology (IT) as

“any equipment or interconnected system or subsystem of equipment that is used in the automatic acquisition, storage, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by an Executive agency.”

For purposes of the preceding definition, “equipment” refers to that used by any DHS Component or contractor, if the contractor requires the use of such equipment in the performance of a service or the furnishing of a product in support of DHS.

The term information technology includes computers, ancillary equipment, software, firmware, and similar procedures, services (including support services), and related resources.

The term information system as used in this policy document, is equivalent to the term IT system.

1.4.8 DHS System

A DHS system is any information system that transmits, stores, or processes data or information and is (1) owned, leased, or operated by any DHS Component; (2) operated by a contractor on behalf of DHS; or (3) operated by another Federal, state, or local Government agency on behalf of DHS. DHS systems include general support systems and major applications.

1.4.8.1 General Support System

A general support system (GSS) is an interconnected set of information resources that share common functionality and are under the same direct management control. A GSS normally includes hardware, software, information, applications, communications, data and users.

Examples of GSS include local area networks (LAN), including smart terminals that support a branch office, Department-wide backbones, communications networks, and Departmental data processing centers including their operating systems and utilities.

Note: Security for GSSs in use at DHS Headquarters shall be under the oversight of the DHS Office of the Chief Information Officer (OCIO), with support from the DHS Security Operations Center (SOC). All other GSSs shall be under the direct oversight of respective Component CISOs, with support from the Component’s Security Operations Center (SOC). Every GSS must have an Information Systems Security Officer (ISSO) assigned.

4300A Sensitive Systems Handbook v9.1 5 July 24. 2012

1.4.8.2 Major Application

A major application (MA) is an automated information system (AIS) that “requires special attention to security due to the risk and magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of the information in the application.2” [Note: All Federal applications require some level of protection.] Certain applications, because of the information they contain, however, require special management oversight and should be treated as MAs. An MA is distinguishable from a GSS by the fact that it is a discrete application, whereas a GSS may support multiple applications. Each MA must be under the direct oversight of a Component CISO or Information System Security Manager (ISSM), and must have an ISSO assigned.

1.4.9 Component

A DHS Component is any organization which reports directly to the Office of the Secretary (including the Secretary, the Deputy Secretary, the Chief of Staff, the Counselors, and their respective staff, when approved as such by the secretary.

1.4.10 Trust Zone

A Trust Zone consists of any combination of people, information resources, data systems, and networks that are subject to a shared security policy (a set of rules governing access to data and services). For example, a Trust Zone may be set up between different network segments that require specific usage policies based on information processed, such as law enforcement information.

1.4.11 Continuity of Operations

Internal organizational efforts to ensure that a viable capability exists to continue essential functions across a wide range of potential emergencies, through plans and procedures that:

• Delineate essential functions and supporting information systems

• Specify succession to office and the emergency delegation of authority

• Provide for the safekeeping of vital records and databases

• Identify alternate operating facilities

• Provide for interoperable communications

• Validate the capability through tests, training, and exercises

1.4.12 Continuity of Operations Plan

A plan that provides for the continuity of essential functions of an organization in the event that an emergency prevents occupancy of its primary facility. It provides the organization with an operational framework for continuing its essential functions when normal operations are disrupted or otherwise cannot be conducted from its primary facility.

2 OMB Circular A-130

4300A Sensitive Systems Handbook v9.1 6 July 24. 2012

1.4.13 Essential Functions

Essential Functions are those that enable Executive Branch agencies to provide vital services, exercise civil authority, maintain the safety and well being of the general populace, and sustain industrial capability andthe national economy base during an emergency.

1.4.14 Vital Records

Vital records are Electronic and hardcopy documents, references, databases, and information systems needed to support essential functions under the full spectrum of emergencies. Categories of vital records may include:

• Emergency operating records – emergency plans and directive(s); orders of succession;

delegations of authority; staffing assignments; selected program records needed to continue the most critical agency operations; and related policy or procedural records.

• Legal and financial rights records – records that protect the legal and financial rights of the Government and of the individuals directly affected by its activities. Examples include accounts receivable records, social security records, payroll records, retirement records, and insurance records. These records were formerly defined as “rights-and-interests” records.

• Records used to perform national security preparedness functions and activities in accordance with Executive Orders (EO).

• Operational Data – information used in the execution of any DHS mission.

1.4.15 Federal Information Security Management Act

FISMA requires each agency to develop, document, and implement an agency-wide information security program that will provide a high-level of security for the information and information systems supporting the operations and assets of the agency, including those provided or managed by another agency, contractor, or other source. Statutory requirements include:

(1) Periodic assessments of the risk and magnitude of the harm that could result from the unauthorized access, use, disclosure, disruption, modification, or destruction of information and information systems that support the operations and assets of the agency.

(2) Policies and procedures that:

a. Are based on the risk assessments required by paragraph (1) above

b. Cost-effectively reduce information security risks to an acceptable level

c. Ensure that information security is addressed throughout the life cycle of each agency information system

d. Ensure compliance with

i. Other applicable Federal policies and procedures as may be prescribed by OMB and NIST Minimally acceptable system configuration requirements, as determined by the agency

ii. Any other applicable requirements, including standards and guidelines for national security systems issued in accordance with law and as directed by the President

4300A Sensitive Systems Handbook v9.1 7 July 24. 2012

(3) Subordinate plans for providing adequate information security for networks, facilities, and information systems, as appropriate;

(4) Security awareness training to inform personnel, including contractors, others working on behalf of DHS, and others who use information systems supporting operations and assets of the Department. Such training shall convey knowledge of

a. Information security risks associated with their activities

b. Their responsibility to comply with agency policies and procedures designed to reduce these risks

(5) Periodic testing and evaluation of the effectiveness of information security policies, procedures, and practices, to be performed with a frequency depending on risk, but no less than annually. This testing:

a. Shall include testing of management, operational, and technical controls of every information system identified in the Department’s inventory

b. May include testing relied on by the Office of Inspector General (OIG)

(6) A process for planning, implementing, evaluating, and documenting remedial actions to address any deficiencies in the Department’s information security policies, procedures, and practices

(7) Procedures for detecting, reporting, and responding to security incidents, consistent with standards and guidelines published by the United States Computer Emergency Readiness Team (US-CERT)

a. Mitigating risks associated with incidents before substantial damage is done

b. Notifying and consulting with US-CERT

c. Notifying and consulting with:

i. Law enforcement agencies and relevant OIG

ii. An office designated by the President for any incident involving a national security system

iii. Other agency or offices, as required

(8) Plans and procedures to ensure continuity of operations (CO)for information systems that support the operations and assets of the Department

FISMA requires that the CIO designate a senior agency information security official who shall develop and maintain a Department-wide information security program. The designee’s responsibilities include:

• Developing and maintaining information security policies, procedures, and control techniques that address all applicable requirements

• Training and overseeing personnel with significant information security responsibilities

• Assisting senior Department officials with respect to their responsibilities under the statute

4300A Sensitive Systems Handbook v9.1 8 July 24. 2012

• Ensuring that the Department has sufficient trained personnel to ensure the Department’s compliance with the statute and related policies, procedures, standards, and guidelines

• Ensuring that the Department CIO, in coordination with other senior Department officials, reports annually to the Secretary on the effectiveness of the Department’s information security program, including the progress of remedial actions

1.4.16 Personally Identifiable Information

Personally Identifiable Information (PII) is any information that permits the identity of an individual to be directly or indirectly inferred, including any information which is linked or linkable to that individual regardless of whether the individual is a U.S. citizen, lawful permanent resident, a visitor to the U.S., or a Department employee or contractor.

1.4.17 Sensitive Personally Identifiable Information

Sensitive PII is PII which if lost, compromised, or disclosed without authorization could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. Examples of Sensitive PII include Social Security numbers, Alien Registration Numbers (A-Number), criminal history information, and medical information. Sensitive PII requires more stringent handling guidelines because of the greater sensitivity of the information.

1.4.18 Privacy Sensitive System

A Privacy Sensitive System is any system that collects, uses, disseminates, or maintains PII or Sensitive PII.

1.4.19 Strong Authentication

Strong authentication is a layered authentication approach relying on two or more authenticators to establish the identity of an originator or receiver of information.

1.4.20 Two-Factor Authentication

Authentication can involve something the user knows (e.g., a password), something the user has (e.g., a smart card), or something the user “is” (e.g., a fingerprint or voice pattern). Single-factor authentication uses only one of the three forms of authentication, while two-factor authentication uses any two of the three forms. Three-factor authentication uses all three forms.

1.5 Waivers and Exceptions

1.5.1 Waivers

Components may request waivers to, or exceptions from, any portion of this Policy Directive for up to six (6) months at any time they are unable to fully comply with a Policy Directive requirement. Waiver requests are routed through the Component’s ISSO for the system, to the Component’s CISO or ISSM, and then to the DHS CISO. All submitters shall coordinate with the Authorizing Official (AO) prior to submission. If a material weakness is reported in an audit report, and the weakness is not scheduled for remediation within twelve (12) months, the Component must submit a waiver request to the DHS CISO. If the material weakness is in a

4300A Sensitive Systems Handbook v9.1 9 July 24. 2012 financial system, the Component Chief Financial Officer (CFO) must also approve the waiver request before sending to the DHS CISO.

In all cases, waivers shall be requested for an appropriate period based on a reasonable remediation strategy.

1.5.2 Exceptions

Components may request an exception whenever unable to bring a system control weakness into compliance or when a weakness requires a permanent exception to DHS policy. Exceptions are usually limited to systems that are unable to comply due to detrimental impact on mission, excessive costs, or, for non-essential systems, clearly documented end of platform life within eighteen (18) months, or for commercial-off-the-shelf (COTS) products that cannot be configured to support the control requirement. Exception requests are routed through the Component CISO/ISSM, to the DHS CISO. All submitters shall coordinate with the AO prior to submission.

The risk that results from the exception also must be approved and accepted by the AO and by the Component CFO if the system is a financial or mixed financial system.

1.5.3 Waiver or Exception Requests

The Waivers and Exceptions Request Form found in Attachment B of the DHS 4300A Sensitive Systems Handbook shall be used.

Component ISSOs, audit liaisons, and others may develop the waiver or exception request, but the System Owner shall submit the request through the Component’s CISO/ISSM.

Waiver requests shall include documentation of mission impact as operational justification;

mission impact, risk acceptance; risk mitigation measures; and a POA&M for bringing the system procedures or control weakness into compliance.

Exception requests shall include the operational justification (document mission impact), as well as efforts to mitigate the risk based to include descriptions of counter measures or compensating controls currently in place.

Any waiver or exception requests for CFO-Designated Systems must be submitted to and approved by the Component’s CFO prior to the DHS CFO’s submission to the DHS CISO. Any waiver or exception requests for Privacy Sensitive Systems must be submitted to and approved by the Component’s Privacy Officer or senior Privacy Point of Contact (PPOC) prior to being submitted to the DHS CISO.

All approved waiver and exception requests must be directed through the Component’s CISO/ISSM who will in turn direct them to the DHS CISO.

Policy ID DHS Policy Statements Relevant

Controls

1.5.3.a This Policy Directive and the DHS 4300A Sensitive Systems Handbook apply to all DHS employees, contractors, detailees, others working on behalf of DHS, and users of DHS information systems that collect, generate, process, store, display, transmit, or receive DHS data unless an approved waiver or

4300A Sensitive Systems Handbook v9.1 10 July 24. 2012

Policy ID DHS Policy Statements Relevant

Controls exception has been granted. This includes prototypes, telecommunications systems, and all systems in all phases of the Systems Engineering Life Cycle

(SELC).

1.5.3.b Systems without an Authority to Operate (ATO) when this policy is issued shall comply with all of its policy statements or obtain appropriate waivers and/or exceptions. Systems with an ATO shall comply within 90 days of the date of this Policy is issued or obtain appropriate waivers and/or exceptions.

(A new ATO is only required for significant changes.)

PL-1

1.5.3.c Each waiver or exception request shall include the system name, and system TAF Inventory ID, operational justification, and risk mitigation.

CM-3

1.5.3.d Components shall request a waiver whenever they are temporarily unable to comply fully with any portion of this policy.

CA-2

1.5.3.e All waiver requests shall identify the POA&M for bringing the system or program into compliance.

CA-5,

PM-4

1.5.3.f The Component CISO/ISSM shall approve all waiver requests prior to submitting them to the DHS CISO.

CA-6

1.5.3.g Waiver requests submitted without sufficient information shall be returned for clarification prior to making a decision.

CA-6

1.5.3.h A waiver shall normally be issued for six (6) months or less. The DHS CISO may issue waivers for longer than six (6) months in exceptional situations.

Waivers may be renewed by following the same process as in the initial request.

CA-2

1.5.3.i The Head of the Component shall approve any waiver request that results in a total waiver time exceeding twelve (12) months before sending the request to the DHS CISO. The waiver shall also be reported as a material weakness in the Component’s FISMA report.

1.5.3.j Components shall request an exception whenever they are permanently unable to fully comply with any portion of this policy.

CA-2

1.5.3.k All approved waivers shall be reported in the Component’s FISMA report. CA-6

1.5.3.l The DHS CFO shall approve all requests for waivers and exceptions for financial systems prior to their submission to the DHS CISO.

CA-6

1.5.3.m The Component’s Privacy Officer or Senior PPOC shall approve all requests for waivers and exceptions for Privacy Sensitive Systems prior to their submission to the DHS CISO.

4300A Sensitive Systems Handbook v9.1 11 July 24. 2012

1.5.4 Requests for Exception to U.S. Citizenship Requirement

Special procedures apply for exception to the requirement that persons accessing DHS systems be U.S. citizens. Under normal circumstances, only U.S. citizens are allowed access to DHS systems and networks; but there is a need at times to grant access to foreign nationals. Access for foreign nationals is normally a long-term commitment, and exceptions to pertinent policies are treated separately from standard exceptions and waivers. The approval chain for an exception to the U.S. citizenship requirement flows through the Component Head, the Office of Security, and the CIO. An electronic form for requesting exceptions to the U.S. citizenship requirement is published in this Handbook’s Attachment J, “Requesting Exceptions to Citizenship Requirement.”

Policy ID DHS Policy Statements Relevant

Controls

1.5.4.a Persons of dual citizenship, where one of the citizenships includes U.S.

citizenship, shall be treated as U.S. citizens for the purposes of this Policy Directive.

1.5.4.b The System Owner shall submit each request for exception to the U.S.

Citizenship policy to the Component Head. The Component Head shall obtain concurrence from the DHS Chief Security Officer (CSO) and CIO prior to the approval becoming effective.

PS-3

1.5.4.c Additional compensating controls shall be maintained for foreign nationals, based on nations lists maintained by the DHS CSO.

PS-3

1.6 Electronic Signature

Pursuant to Sections 1703 and 1705 of the Government Paperwork Elimination Act (GPEA), OMB Memorandum M-00-10, “Procedures and Guidance on Implementing of the Government Paperwork Elimination Act,”3 requires executive agencies to provide the option for electronic maintenance, submission, and disclosure of information when practicable as a substitute for paper, and to use and accept electronic signatures.

Electronic signatures are essential in the Department’s business processes and IT environments;

reducing reliance on paper transactions improves information sharing, strengthens information security, and streamlines business processes, while reducing both cost and environmental impact.

Electronic signature solutions must be approved by the Component CISO.

3 Government Paperwork Elimination Act (GPEA), Pub L 105-277, 44 USC 3501 (note)provide for the use

4300A Sensitive Systems Handbook v9.1 12 July 24. 2012

Policy ID DHS Policy Statements Relevant

Controls

1.6.a For DHS purposes, electronic signatures are preferred to pen and ink or facsimile signatures in all cases, except where pen and ink signatures are required by public law, statute, Executive Order, or other agency requirement.

1.6.b Wherever practicable, Components shall use and accept electronic signatures. ---

1.6.c Components shall accept electronic signatures whenever the signature’s digital certificate is current, electronically verifiable, and issued by a medium or high assurance DHS Certification Authority (CA) or other medium or high CA under the Federal Bridge Certification Authority (FBCA) or Common Authority.

1.6.d Components shall accept and be able to verify Personal Identity Verification (PIV) credentials issued by other Federal agencies as proof of identity.

1.6.e As mandated by the Government Paperwork Elimination Act (GPEA) and OMB M-00-10, Components shall provide for the use and acceptance of electronic signatures when practicable.

1.7 Information Sharing

The DHS SOC exchanges information with Component SOCs, Network Operations Centers (NOC), the Homeland Secure Data Network (HSDN) SOC, the Intelligence Community, and with external organizations in order to facilitate the security and operation of the DHS network.

This exchange enhances situational awareness and provides a common operating picture to network managers. The operating picture is developed from information obtained from “raw” fault, configuration management, accounting, performance, and security data. This data is monitored, collected, analyzed, processed, and reported by the NOCs and SOCs.

The DHS SOC is responsible for communicating other information such as incident reports, notifications, vulnerability alerts and operational statuses to Component SOCs, Component CISOs/ISSMs and other identified Component points of contact.

The DHS SOC portal implements role-based user profiles that allow Components to use the website’s incident database capabilities. Users assigned to Component groups shall be able to perform actions such as:

Entering incident information into the DHS SOC incident database

Generating preformatted incident reports

Initiating queries of the incident database

Viewing FISMA incident reporting numbers

Automating portions of the Information Security Vulnerability Management (ISVM) program

4300A Sensitive Systems Handbook v9.1 13 July 24. 2012

Automating portions of the vulnerability assessment program

1.8 Threats

Emphasis on e-Government has added the general public to the class of Government computer users and has transferred the repository for official records from paper to electronic media.

Information systems are often connected to different parts of an organization; interconnected with other organizations’ systems; and with the Internet. Remote access for telecommuting and building management services (e.g., badge systems; heating, ventilating, and air-conditioning (HVAC); and entry) may require additional connections, all of which introduce additional risks.

Wireless systems such as cell phones, pagers, and other portable electronic devices (PED) allow personnel to stay in touch with their offices and wireless local area networks (WLAN) permit connection from various locations throughout a building. While these technologies provide greater flexibility and convenience, they also introduce additional risks.

As technologies continue to converge, (cell phones with Internet access, walkie-talkie communications, and video; low cost Voice over Internet Protocol [VoIP]; copiers that allow network printing; printing over the Internet; , and facsimile [fax] functions) operating costs are reduced, making them tempting to implement, however each of these technology advancements contains inherent security risks and presents challenges to security professionals.

1.8.1 Internal Threats

Managers are generally aware of natural and physical threats, such as earthquakes, tornadoes, fires, floods, electric outages, and plumbing disasters, but may not have the same level of awareness regarding disasters or threats originating from within their organizations. The threat from DHS users should not be underestimated. Sensitive data can be lost, corrupted, or compromised through malicious or careless acts. A malicious user can intentionally cause harm to the Department’s reputation and data. Uninformed or careless users can inflict similar damage.

Converging technologies combine the vulnerabilities of the individual technologies, so care must be taken to ensure that systems are designed with no single points of failure. (For example, if the building HVAC were connected to the data network it would become necessary to ensure that an outage or attack on the HVAC would not also cause a network outage.)

1.8.2 Criminal Threats

Malicious code remains a threat to DHS systems. Malware and those who employ it have become very sophisticated; malicious code can be tailored to the recipient. This code can be transferred to an unsuspecting user’s machine by various means, including email, visiting infected websites, or across a network. These capabilities may be used to steal, alter, or destroy data; export malicious code to other systems; add backdoors that would permit access to data or network resources; or prevent the legitimate use of the individual computer or network service.

Instructions for exploiting hardware or software vulnerabilities are often available on hacker sites within hours of discovery. Skilled hackers routinely target e-commerce sites to obtain credit card numbers. Persons with hacking skills are often hired to perform espionage activities.

4300A Sensitive Systems Handbook v9.1 14 July 24. 2012

1.8.3 Foreign Threats

Foreign Governments routinely conduct espionage activities to obtain information that will be useful to their own industrial/government base and operations. They also have the resources to disrupt Internet communications and have launched successful cyber attacks.

Wireless communications are easily eavesdropped on using commercially available equipment, and it is relatively easy to detect and exploit wireless access points. Employees overseas should assume their wireless communications (BlackBerry, cell phone, etc) are being monitored.

Many software manufacturers outsource software code development, which raises concerns about whether malicious or criminal code has been inserted. Indeed, it is becoming increasingly difficult to determine the actual provenance of an organization’s information systems because code and equipment are assembled from so many sources.

1.8.4 Lost or Stolen Equipment

Lost or stolen equipment also poses a threat. Data on portable computing devices (laptops, smart phones, etc) or storage media (Universal Serial Bus (USB) drives, compact disks (CD), etc) can reveal sensitive information, such as changes to legislation, investigations, or economic analyses.

Thefts from offices, airports, automobiles, and hotel rooms occur regularly.

1.8.5 Supply Chain Threats

A supply chain threat is a man-made threat achieved through exploitation of the system’s supply chain or acquisition process.

A system’s supply chain is composed of the organizations, people, activities, information, resources, and facilities for designing, creating and moving a product or service from suppliers through to the integrated system (including its sub-components), and into service by the original acquirer.

1.9 Changes to Policy

Procedures and guidance for implementing this policy are outlined in a companion publication, DHS 4300A Sensitive Systems Handbook and its attachments. The Handbook serves as a foundation for Components to use in developing and implementing their information security programs.

For interpretation or clarification of DHS information security policies found in this policy document and of the procedures and guidance found in the DHS 4300A Sensitive Systems Handbook, contact the DHS CISO at infosec@dhs.gov.

Changes to this policy and to the Handbook may be requested by submitting to the respective ISSM/CISO the form included in DHS 4300A Sensitive Systems Handbook, Attachment P, “Document Change Requests.”

Policy ID DHS Policy Statements Relevant

Controls

1.9.a The DHS CISO shall be the authority for interpretation, clarification, and PL-1 mailto:infosec@dhs.gov

4300A Sensitive Systems Handbook v9.1 15 July 24. 2012

Policy ID DHS Policy Statements Relevant

Controls modification of the DHS Sensitive Systems Policy Directive 4300A and for the DHS 4300A Sensitive Systems Handbook (inclusive of all appendices and attachments).

1.9.b The DHS CISO shall update the DHS Sensitive Systems Policy Directive 4300A and the DHS 4300A Sensitive Systems Handbook at least annually.

PL-1

4300A Sensitive Systems Handbook v9.1 16 July 24. 2012

2.0 ROLES AND RESPONSIBILITIES

Security is inherently a Government responsibility; contractors, others working on behalf of the Department of Homeland Security (DHS), and other sources may assist in the performance of security functions, but a DHS employee must always be designated as the responsible agent for all security requirements and functions. This section outlines the roles and responsibilities for implementing these requirements.

2.1 Information Security Program Roles

Designated personnel play a major role in the planning and implementation of information security requirements. Roles directly responsible for information system security are described in the subsections that follow.

2.1.1 DHS Senior Agency Information Security Officer

Policy ID DHS Policy Statements Relevant

Controls

2.1.1.a The DHS Chief Information Security Officer (CISO) shall perform the duties and responsibilities of the DHS Senior Agency Information Security Officer

(SAISO).

PL-1,

PM-2

2.1.2 DHS Chief Information Security Officer

The DHS CISO shall implement and manage the DHS Information Security Program to ensure compliance with applicable Federal laws, Executive Orders, directives, policies, and regulations.

The DHS CISO reports directly to the DHS Chief Information Officer (CIO) and is the principal advisor on information security matters.

Policy ID DHS Policy Statements Relevant

Controls

2.1.2.a The DHS CISO shall implement and manage the DHS-wide Information Security Program.

PL-1,

PM-2

2.1.2.b The DHS CISO will serve as the CIO’s primary liaison with the organization’s Authorizing Officials (AO), information system owners and Information Systems Security Officers (ISSO).

The DHS CISO:

Implements and manages the Department-wide Information Security Program and ensures compliance with the Federal Information Security Management Act (FISMA), Office of Management and Budget (OMB) directives, and other Federal requirements

• Issues Department-wide information security policy, guidance, and architecture requirements for all DHS systems and networks. These policies shall incorporate National Institute of

4300A Sensitive Systems Handbook v9.1 17 July 24. 2012

Standards and Technology (NIST) guidance, as well as all applicable OMB memorandums and circulars

• Facilitates development of subordinate plans for providing adequate information security for networks, facilities, and systems or groups of information systems

• Serves as the principal Departmental liaison with organizations outside DHS in matters relating to information security

• Reviews and approves the tools, techniques, and methodologies planned for use in certifying and authorizing DHS systems, and for reporting and managing systems-level FISMA data.

This responsibility includes reviews and approval of Security Control Assessment plans, Contingency Plans, and security risk assessments.

• Consults with the DHS Chief Security Officer (CSO) on matters pertaining to physical security, personnel security, information security, investigations, and Sensitive Compartmented Information (SCI) systems, as they relate to information security and infrastructure

• Develops and implements procedures for detecting, reporting, and responding to information security incidents

• Ensures preparation and maintenance of plans…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .