ITS-HBK-2810.06-2B IT Security Awareness Trng Education May 2019 .pdf

PDF 7 MB Posted

Attached to
Orion Main Engine Federal contract opportunity
Solicitation number
80JSC020R0031
Issued by
National Aeronautics and Space Administration Johnson Space Center

About this file

This document outlines a solicitation for the Orion Main Engine. NASA/Johnson Space Center is seeking proposals for the Orion Main Engine no later than June 11, 2020 at 1:30 PM Central Time. A virtual pre-proposal conference will be held on April 2, 2020 from 8:30 AM to 12:00 PM Central Time; registration instructions are provided in an attached document. Documents related to this procurement, including the RFP and any amendments, are available on a designated NASA website. Offerors are responsible for downloading relevant documents. A presolicitation synopsis was previously issued under reference number 80JSC020OME. Proposals are due no later than June 11, 2020 at 1:30 PM Central Time.

View the file

Other files for this federal contract opportunity

Show all 21

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

INFORMATION TECHNOLOGY SECURITY HANDBOOK

IT SECURITY AWAR NES , TRAI ING

AND EDUCA ION

EFFECTIVE DATE: MAY 2019

IT SECURITY AWARENESS, TRAINING AND EDUCATION ITS-HBK-2810.06-2B

Table of Contents Table of Contents

Change History

1 lntroduction.................................................................................................................................... , .. 4

1.1 Purpose

1.2 Scope

1.3 Point(s) of Contact for Handbook

1.4 Applicability

1.5 Applicable Documents

2 Security Controls and Corresponding Roles and Responsibilities

2.1 Security Awareness Training (AT-2)

2.2 Role-Based Security Training (AT-3) ........................................................................................,. 9

2.3 Training Records (AT-4)

2.4 Reporting

2.5 Phishing Supplemental Training Requirement

3 System for Administration, Training, and Educational Resources for NASA (SATERN)

3.1 SATERN

3.1.1 Accessing SATERN

Appendix A: External Role-Based Training Validation Form

Appendix B: Acronyms

Appendix C: Glossary

Distribution:

NODIS

Approved

Associate Chief Information Officer for Cybersecurity & Privacy

Date / 7

21 Page

Change History

Version Date Change Description

1.0 xx/xx/201x Update and consolidation of Awareness and

Training handbooks; addition of supplemental phishing training and Individual development training.

3I Page

1 Introduction NASA requirements for protecting the security of NASA information and information systems are derived from National Institute of Standards and Technology (NIST) guidance. Information System

Owners (ISOs) and other personnel responsible for the protection of NASA information or information systems shall follow NIST guidance in the proper security categorization (Federal Information Processing

Standards {FIPS} 199, Standards for Security Categorization for Federal Information and Information

Systems), and in the selection and implementation of information security controls (FIPS 200, Minimum

Security Requirements for Federal Information and Information Systems and NIST Special Publication {SP)

800-53 Rev. 4, Recommended Security Controls for Federal Information Systems and Organizations), in a manner consistent with the Risk Management Framework (NIST SP 800-37 Revision 1, Guide for Applying the Risk Management Framework to Federal Information Systems). NASA Policy Directive (NPD) 2810.lE, NASA Information Security Policy, NASA Procedural Requirements {NPR) 2810.1A, Security of Information

Technology, and the collection of 2810 Information Security Technology Handbooks (ITS-HBK) satisfy the policy and procedure controls of NISTSP 800-53 Revision 4, Recommended Security Controls for Federal

Information Systems and Organizations.

NPR 2810.1A, Security of Information Technology, designates this handbook as a guide of NASA's

Awareness and Training (AT) information security controls.

This handbook supports the implementation of requirements in NPR 2810.1A, Security of Information

Technology {IT) and NPD 2810.lE, NASA Information Security Policy. It also augments NIST guidance with

NASA-specific requirements, procedures, and recommendations, where applicable. NASA-specific guidance does not negate NIST guidance unless explicitly stated. The Agency's organizationally defined values are integrated into the control requirements within the Risk Information Security Compliance

System (RISCS) system.

This handbook establishes the NASA IT Security Program's role-based training standards. IT security awareness training is required for all personnel with access to NASA information and information systems prior to IT or network access and annually thereafter.

Additional training is required for individuals with Significant Security Responsibilities (SSR) - as highlighted in NIST SP 800-53, Awareness and Training 3 (AT-3) Security Training. Any individual who is assigned an Agency role that may have a significant impact on cyber security is designated as having SSR.

The security comprehensive role-based training addresses management, operational, and technical roles and responsibilities covering physical, personnel, and technical safeguards and countermeasures.This includes all users with privileged network user accounts, users who have managerial, administration, or operational responsibilities that enable them to affect the system or information security.

This handbook also addresses supplemental phishing training required for IT users who have been identified as susceptible to phishing threats. This supplemental training expands upon the phishing threat training provided in the new employee and annual IT Security Awareness Training required for all

NASA employees.

41 Page

The Security Awareness and Training control family relates to the information security knowledge requirements for all users of Agency information and information systems, and the development and delivery of courses and other training resources to enable and validate satisfaction of those requirements. NASA Users are responsible for meeting Agency security training requirements in order to gain and maintain access to any NASA information system resource. Furthermore, certain roles at

NASA, including managers and those with significant information security responsibilities, have to comply with additional security training and awareness requirements.

1.1 Purpose

Learning is a continuum; it starts with awareness, builds to training, and evolves into education. An effective IT security awareness and training program explains proper rules of behavior for the use of agency IT systems and information. The program communicates IT security policies and procedures that need to be followed. This must precede and lay the basis for any sanctions imposed due to noncompliance. Users first should be informed of the expectations. Accountability must be derived from a fully informed, well-trained, and aware workforce.

This document provides guidelines for maintaining a comprehensive awareness and training program, as part of NASA's IT security program. Federal agencies and organizations cannot protect the confidentiality, integrity, and availability of information in today's highly networked systems environment without ensuring that all people-involved in using and managing IT understand their roles and responsibilities related to the organizational mission, understand the organization's IT security policy, procedures, and practices, and have at least adequate knowledge of the various management, operational, and technical controls required and available to protect the IT resources for which they are responsible. Initial and annual IT security awareness training will help reinforce these requirements so that personnel understand their IT security responsibilities, organizational policies, and how to properly use and protect the IT resources entrusted to them.

Regarding role-based training, in order to protect NASA's information, IT and other information resources, NASA must ensure that individuals with Significant Security Responsibilities (SSR) are equipped with the necessary knowledge to accomplish their tasks. SSR applies to any individual who is assigned an Agency role that may have a significant impact on security. This IT security handbook, defines and documents the groups of individuals NASA identifies as having SSR. Additionally, this handbook defines the initial and continuing education training requirements for individuals with SSR.

1.2 Scope

The requirements from this Handbook apply to all users accessing NASA IT resources, such as workstations, and laptops, and to access, process, store, receive, or transmit NASA information. Failure to complete mandatory awareness and training requirements within the specified timeframe will adversely impact access to, and use of, NASA-owned or NASA-controlled systems, networks, and information.

Although NASA handbooks may contain "shall" (requirements) statements, they are not intended to be requirements documents. Pursuant to NPR 1400.lK, portions of NASA handbooks containing procedural or process guidance may be cited in contract, program, and other Agency documents, and may become requirements when a NASA directive specifies their use by citing the document title, revision

SI Page letter/number, and date; or, when a NASA manager with authority over a NASA program, project, or other activity, identifies it as a requirement.

A documented rationale and/or justification shall accompany any non-concurrence, disapproval, denial, or request for deviation from the policy guidance or procedural requirements set forth in this handbook to support such decision. The documented rational/justification shall be provided to the NASA Cybersecurity and Privacy Division (CSPD) and the point of contact for this handbook, in coordination with Center Information Security Officers (CISO), to review and validate for the record.

1.3 Point(s) of Contact for Handbook

For any questions or comments regarding the contents of this Handbook contact:

• hg-d 1-cspd-pol icy@ma i I.nasa.gov

Any questions or concerns regarding perceived gaps in policy or implementation guidance, conflicting procedural requirements, lack of clarity pertaining to specified roles and responsibilities, or issues associated with interpretation shall be elevated to the NASA CSPD, in coordination with the CISO, and directed to the at_tention of the point of contact for this particular handbook to address and resolve.

1.4 Applicability

This Handbook is applicable to NASA Headquarters and NASA Centers, including Component Facilities and Technical and Service Support Centers. This language applies to Jet Propulsion Laboratory (JPL), a

Federally Funded Research and Development Center (FFRDC), other contractors, authorized users, grant recipients, or parties to agreements only to the extent specified or referenced in the appropriate contracts, grants, or agreements.

1.5 Applicable Documents

Federal Law

• Federal Information Security Modernization Act of2014 {FISMA)

Office of Personnel Management (OPM) and Office of Management and Budget (0MB)

• OPM Title 5 CFR § 930.301 Subpart C, Information Security Responsibilities for Employees who Manage or Use Federal Information Systems, Sec. 930.301 lnfor"!ation systems security awareness training program

• Office of Management and Budget {0MB) Circular A-130 Management of Federal Automated Information Resources Appendix Ill, Security of Federal Automated Information Resources §3{a)(2)(b)

Federal Information Processing Standards (FIPS)

• FIPS 199, Standards for Security Categorization for Federal Information and Information Systems

• FfPS 200, Minimum Security Requirements for Federal Information and Information Systems

GI Page https://nasa.gov

National Institute of Standards and Technology {NIST)

• NISTSP 800-16, Information Training Security Requirements; A Role- and Performance-Based Model

• NISTSP 800-37, Guide for Applying the Risk Management Framework to Federal Information

Systems

• NIST SP 800-50, Building an Information Technology Security Awareness and Training Program

• NIST SP 800-53, Recommended Security Controls for Federal Information Systems and Organizations

National Aeronautics and Space Administration {NASA)

• NPD 1382.17) NASA Privacy Policy

• NPD 2800.18, Managing Information Technology

• NPD 2810.1£, NASA Information Security Policy

• NPR 1382.1A, NASA Privacy Procedural Requirements

• NPR 1441.1£, NASA Records and Retention Schedule

• NPR 2810.1A, Security of Information Technology

• ITS-HBK-00018, Format and Procedures for IT Security Policies and Handbooks

• ITS-HBK-2810.15-028, Access Control and Elevated Privileges

• SF-182 Request, Authorization, Agreement and Certification of Training

Cancellations, Updates, Consolidations

• /TS-HBK-2810.06-02, Role-Based Training

• ITS-HBK-2810.06-01, Security Awareness and Training

2 Security Controls and Corresponding Roles and Responsibilities

2.1 Security Awareness Training (AT-2)

• The Senior Agency Information Security Officer (SAISO}:

o Ensures the availability of annual security awareness training for the Agency.

• The JTSATC PM:

o Authors and maintains security awareness training for use across the Agency.

o Uses the System for Administration, Training, and Education Resources for NASA

(SATERN) and NAMS platforms as a mechanism to upload, manage, and track/record security awareness training.

• The Center CISO:

o Maintains oversight of information security awareness training completion by

Center personnel through SATERN.

o Designates a POC for IT Security Training.

o Ensures the delivery of training to personnel through alternative means, when necessary.

71 Page

• Substitution of alternative training for the NASA information security awareness training shall not be allowed unless prior approval has been obtained from the SAISO.

• If an alternate method of training delivery is used, the training Instructor shall provide the Center CISO with:

• A brief summary of the methods of training delivery used;

• A statement that the NASA information security awareness course content was used for the training; and

• A list of trainees with both printed/typed names and signature of the individual that attended the training.

• Ensure the completion of training statistics report actions as assigned by the Office of the Chief Information Officer (OCIO).

• The Center IT Security Training POC:

o Supports the Center CISO in ensuring compliance with the FISMA metrics for role based IT Security training.

o Serves as Center POC for questions and issues regarding the requirements of this

Handbook.

o Serves as liaison between the ITSATC, Center CISO, and the individuals who are required to take all mandatory annual training and role-based training.

• The ISSO:

o Maintains oversight of information security awareness training completion by personnel with access to information systems under their control or purview.

• The ISO:

o Prior to authorizing access, and annually thereafter, ensures 100 percent of users with login access to information systems or applications under their purview complete annual Cybersecurity and Sensitive Unclassified Information Awareness Training..

o Ensures that user access to NASA information systems or applications under their purview is terminated, including the administrative and/or privileged access, if the required annual or other specified information security-related training is not completed.

• The NASA User:

o Completes the Cybersecurity and Sensitive Unclassified Information Awareness

Training prior to accessing NASA information systems and applications and annually thereafter as long as access to NASA information, information systems, or IT resources continues.

• Onboarding/New Hires. As a general rule, all introductory training requirements should be satisfied before new NASA-personnel gain logical and/or physical access to NASA IT systems or NASA facilities. If not feasible, new NASA personnel shall complete training requirements within ten (10) days of obtaining a PIV card.

Bl Page

2.2 Role-Based Security Training (AT-3)

The IT security training requirements for each of the roles outlined in this document are summarized on the ITSATC website. For additional information on NASA training reference the for Role 0 Based Training

URL at https:llitsatc.nasa.gov/ training/role-based-training/.

• The following roles are assigned based on an individual's job description and title:

o NASA CIO and Deputies o Center CIOs and Deputies o SAISO and Deputy SAISO o Center CISOs and Deputies o Center Privacy Managers (CPM) o Incident Responders o Agency and Center Incident Response Managers (IRM)

• The following roles are assigned based on an individual's role with respect to a SSP recorded in RISCS:

o Authorizing Official (AO) o Information System Owner (ISO) o Information Owner (10) o Information System Security Officer (ISSO) o Security Control Assessor (SCA)

• The following NASA roles are designated as having SSR:

o AO o Center CIO and Deputy o Center CISO and Deputy o CPMs o 10 o Incident Responder o IRM o ISO o ISSO o NASA CIO and Deputies o SAISO o SCA

• The ITSATC PM:

o Identifies and document those roles that have significant information security responsibilities that require initial and annual role-based information security training in accordance with NIST SP 800-16, Information Training Security Requirements; A Role- and Performance-Based Model.

o Identifies training that will satisfy the role-based IT Security training requirements.

o Maintain a list of valid SSR training offerings that satisfy the requirements in this handbook on the ITSATC website.

o Creates courses within SATERN that are assigned to the roles identified in this

Handbook.

o Provides reports to IT Security Training POCs regarding the completion training requirements.

9I Page https:llitsatc.nasa.gov/training/role-based-training o Compiles performance metrics on training requirements for Center verification and reporting to FISMA.

o Provides ad hoc status reports on the completion of the requirements of this Handbook to Centers and Agency IT Security personnel to demonstrate the progress of efforts to comply with training requirements.

o Provides monthly reports to the Center CISOs and the Agency CSPD on the number of individuals (at each Center and within the Agency) with SSR for each role and if they have met annual training requirements.

• Reporting for SSR shall be derived from SATERN for all roles except elevated privileges (EP). EP is reported through the NASA Account Management System {NAMS): refer to ITS-HBK-2810.15-018, Access Control and Elevated Privileges for details on EP.

• The Center C/0:

o Maintains oversight of the completion of role-based information security training to ensure initial and annual refresher training is completed by Center personnel approved for administrative and/or privileged access to NASA information, information systems and/or IT resources, in accordance with procedures outlined by /TS-HBK-2810.15-02, Access Control and Elevated Privileges.

• The Center C/SO:

o Provides initial list to the ITSATC and notify the ITSATC when changes are made to the list.

o Ensures that Center individuals with SSR comply with the requirements outlined within this handbook.

o Verifies Center FISMA training metrics are properly reported.

• The /SSO:

o Maintains oversight of the completion of role-based information security training to ensure initial and annual refresher training is completed by organizational personnel approved for administrative and/or privileged access to NASA information, information systems and/or IT resources, in accordance with procedures outlined by JTS-HBK-2810.15-02, Access Control, and Elevated Privileges.

• The ISO:

o Ensures roles with SSR and/or EP are documented in the SSP.

o Ensures the individuals with SSR and/or EP:

• Complete required role-based training and are capable of performing assigned roles and responsibilities.

• Complete annual refresher training as required.

• The NASA User with SSR:

o Completes appropriate role-based information security-related training, as outlined in ITS-HBK-2810.15-02, Access Control and Elevated Privileges, that addresses the procedures and processes necessary to meet the security requirements of the role before being authorized privileged access to the information, information system and/or IT resources and complete the training annually thereafter.

• If the user completes appropriate training other than that recommended by ITSATC, they should complete the External Role-Based Training Validation

10 I Page form per Appendix, and submit it to ITSATC with either Center CISO or Training POC approval. The following information shall be documented in SATERN for each training item completed:

• Training name

• Location

• Training type

• Description of content

• Date(s) of training

• Number of hours

• Vendor (or instructor if internal) o Reports role changes to the Center CISOs and IT Security Training POC.

2.3 Training Records (AT-4)

• TheSA/50:

o Provides oversight of Information Security Awareness Training and role-based information security training is tracked using the SATERN Learning Management

System (LMS) and training records destroyed 5-years after separation of employee or when no longer needed in accordance with NPR 1441.lE, NASA Records

Management Program Requirements.

• The ITSATC PM:

o Maintains and tracks all NASA information security awareness training and role based training documentation and modules.

o Utilizes SATERN to:

• Assign and monitor progress of Information Security Awareness training compliance.

• Track employee role-based information security training requirements and completion status.

• Maintain a central repository for all NASA information security-related training documentation.

• The NASA User:

o Ensures their training records are up to date and reflect completion of all mandatory, role-based, and individual development training requirements.

2.4 Reporting

The ITSATC shall provide monthly reports to the Center CISOs and the Agency CSPD on the status of all mandatory annual IT security training and role-based training requirements for NASA personnel.

• Reporting for SSR shall be derived from SATERN for all roles except EP. This reporting will identify, on a Center and Agency basis, the number of individuals with SSR for each role and if they have met the annual training requirements.

• Reporting for individuals with EP shall be completed using the process associated with the NASA Account Management System (NAMS), as NAMS processes validate the training requirements prior to granting EP.

11 I Page

IT SECURITY AWARENESS, TRAINING AND EDUCATION ITS-HBK-2810.06-2 B

2.5 Phishing Supplemental Training Requirement

Supplemental phishing training is not a NIST SP 800-53 control, but it is an important requirement with associated roles and responsibilities.

Phishing is the act of soliciting personal or sensitive information or tricking IT users into running malicious software through e-mail or websites while posing as a legitimate associate or business.

Phishing is recognized throughout Government and the private sector to be one of the most prevalent methods for malicious actors to gain unauthorized access to IT systems, networks, and data. In order to mitigate this threat, NASA has included phishing awareness information in the annual Cybersecurity and

Sensitive Unclassified Information Awareness Training that is already mandated for all NASA IT users.

The NASA OCIO conducts periodic "phishing exercises" to measure the effectiveness of training and further increase awareness. As part of on these periodic exercises, the OCIO identifies users who appear to need increased awareness of the threat which phishing poses to NASA when IT users improperly respond to real phishing emails. NASA OCIO has defined a "recurring clicker" as a NASA IT user who clicks on a link or provides data in response to a test email sent as during an OCIO phishing exercise at least twice within three consecutive exercises.

Supplemental training about phishing is required for select NASA IT users who have been identified as susceptible to phishing threats. This training expands upon the phishing threat training provided in the new employee and annual IT Security Awareness Training required for all NASA employees.

As with any mandatory annual training requirement, failure to complete this training requirement within the specified timeframe will adversely impact access to, and use of, NASA-owned or NASA controlled systems, networks, and information.

• The NASA C/O:

o Promulgates policies, procedures, and processes related to phishing training requirements.

• TheSA/SO:

o Oversees implementation of mandatory training requirement focused on those

NASA IT users that are susceptible to phishing threats, and serve as the point of contact for questions.

• The /TSATC PM:

o Distributes supplemental phishing training materials to the Center CISOs to support instructor-led anti-phishing training o Loads anti-phishing training materials onto SATERN for self-paced computer-based training.

o Tracks completion of supplemen~al training requirements.

• The Center CISO:

o Oversees the implementation/enforcement of the anti-phishing training requirement, and ensure that training is completed within 60 days of employee notification.

12 I Page o Grants employee extensions to the 60-day completion requirement upon receipt of adequate justification from the employee (e.g., extended leave, medical reasons).

o Ensures that user access to NASA information systems or applications under their purview is suspended, including the administrative and/or privileged access, for those employees who fail to successfully complete anti-phishing training and anti phishing exercises, as appropriate.

• The NASA User:

o Completes the mandatory training requirement within the specified timeframe and ensure their records in SATERN reflect completion of the training.

• Note: Failure to complete these training requirement in a timely manner could adversely impact access to, and use of, NASA-owned or NASA controlled systems, networks, and information.

3 System for Administration, Training, and Educational Resources for

NASA (SATERN)

The System for Administration, Training, and Educational Resources for NASA (SATERN) provides web based access to training and career development resources. A full list of recommended training is located at itsatc.nasa.gov.

3.1 SATERN

3.1.1 Accessing SATERN

To access SATERN, launch your Internet browser and go to https:/Jsatern.nasa.qov. If you need help using the site visit the SATERN Informational Web site at https:/lsaterninfo.nasa.qov. Navigate to

"Resources> Guides & Aids" and click "How do I log into SATERN?" job aid for step-by-step instructions.

For assistance with SATERN, contact the NSSC Contact Center at 877-677-2123 or nssc contact@nasa.gov.

13I Page mailto:contact@nasa.gov https:/lsaterninfo.nasa.qov https:/Jsatern.nasa.qov https://itsatc.nasa.gov

Appendix A: External Role-Based Training Validation Form The SF-182 Request, Authorization, Agreement, and Certification of Training is the official form for all external training requests. Eligible NASA civil servants may submit a request for external training (e.g., conferences, academic courses, and other external events) via the SF-182 form. NASA employees submit electronic requests for external training online and have them automatically approved, tracked, and recorded in SATERN.

After employees attend/complete training, they will receive an e-mail notification to complete the mandatory SATERN on line verification. If they attended an academic course, they are required to submit their final grade to their Center training office. Employees must complete the verification and submit their final grade to receive credit on their Learning History. Individuals with SSR designations may complete courses other than those recommended with the approval of their Center CISO or ITS Training

POCs. The External Role-Based Training Validation Form must be completed and signed by either the

Center CISO or the ITS Training POC.

Individuals with Significant Security Responsibilities (SSR) are required to complete mandatory training annually according to the NASA Role-Based Training Handbook (HBK) 2810. To support this requirement, for each role, courses have been selected from the internal IT Security library (NASA ITS) and vendor constructed courses (Skillsoft and ITPro TV). However, as an incumbent in the role, you are permitted to elect an external course that is approved as a substitute to the NASA recommended internal training courses. The External Role-Based Training Validation Form is available at https: //itsatc.nasa.gov/ training/role-based-training/external-rbt-validation-form/ ..

National Aeronautics and Space Administration

EXTERNAL ROLE-BASED TRAINING VALIDATION FORM

Individuals with Significant Security Responsibilities ISSR) are required to complete. mandatory training annuallv according to the NASA Role Based Training Handbook (HBK) 2810. To support this requirement., for each role, courses haft been selected from the Internal IT security library (NASA ns) and vendor constructed courses (Sldlsoft and ITPro TV]. However. as an incumbent in the role, you an! permitted to e1ect an external course that IS apJ)l'"Dved as a substitute to the NASA recommended Internal training courses..

Upon electing an external course~ this form must be completed~o document and valfdate your completion of the tralnin& requirement.

l. Identify• course and,_ approval from the CISO or ITSEC POC.

2. complete the course and flH In the Jnformatron detaRrng the tralnTnc In the table be.low.

3. Sign end date the form.

4. Email or print out a copy and obtain• sianature from an rr security Professfanal at your center as a validation of the approprlstencss of tht completed training to yaur ........,d role that has significant securtty responsibllllles.

5, Send th~ sJC<llKI form and I sc.annt...>d copy of training comptetlOn certificates for each Item listed befow to: eatemal--t'bt-valdation@!tisb.naa,cov

Print Leamer Name Date

Print CISO (or IT Se,! POC) NMne CISO (MIT 5ec: POC) Ol&IUI S/cn&lw" Date https://itsatc.nasa.gov

14 I Page https://itsatc.nasa.gov mailto:eatemal--t'bt-valdation@!tisb.naa,cov https://itsatc.nasa.gov/training/role-based-training/external-rbt-validation-form

IT SECURl1Y AWARENESS, TRAINING AND EDUCATION ITS-HBK-2810.06-2B

Appendix B: Acronyms AO Authorizing Official

ACES Agency Consolidated End-User Services

AT Awareness and Training

CAP Certified Authorization Professional

CSPD Cybersecurity and Privacy Division

CIC Chief Information Officer

CISM Certified Information Security Manager

CISO [Center] Chief Information Security Officer

CISSP Certified Information Systems Security Professional

CPM Center Privacy Manager -

CSSLP Certified Secure Software Lifecycle Professional

EP Elevated Privilege

FIPS Federal Information Processing Standards

FISMA Federal Information Security Management Act

HBK Handbook

IDP Individual Development Plan

10 Information Owner

IRM Incident Response Manager

ISO Information System Owner

ISSE Information System Security Engineer

ISSO Information System Security Officer

IT Information Technology

ITS Information Technology Security

ITSATC Information Technology Security Awareness and Training Center

LMS Learning Management System

NAMS NASA Account Management System

NASA National Aeronautics and Space Administration

NIST National Institute of Standards and Technology

NPD NASA Policy Directive

15 I Page

NPR NASA Procedural Requirement

OCIO Office of the Chief Information Officer

OHCM Office of Human Capital Management

OPM Office of Personnel Management

OS Operating System

POC Point of Contact

PM Program Manager

SA System Administrator

SAISO Senior Agency Information Security Officer

SATERN System for Administration, Training, and Education Resources for NASA

SCA Security Control Assessment soc Security Operations Center

SP Special Publication

SR Service Request

SSR Significant Security Responsibilities

SSP System Security Plan

16 I Page

Appendix C: Glossary Awareness The ability of the user to recognize or avoid behaviors that would compromise cybersecurity; the practice of good behaviors that will maintain cybersecurity;

and act wisely and cautiously, where judgment is needed, to support organizational cybersecurity. Awareness is not training, although training can promote awareness. The purpose of awareness presentations is simply to focus attention on security. Awareness presentations are intended to allow individuals to recognize IT security concerns and respond accordingly.

Education Knowledge or skill obtained or developed by a learning process. Education integrates all of the security skills and competencies of the various functional specialties into a common body of knowledge, with the goal of producing IT security specialists and professionals capable of vision and pro-active response.

Role The responsibility and functions that a person is currently performing within their agency; established by individual Federal Organization or Agency through position descriptions, hierarchy charts, responsibilities, etc.

Training The action provided to a user in the acquisition of knowledge, skills, and competencies. The training level of the learning continuum strived to produce relevant and needed security skills and competencies by practitioners of functional specialties in addition to IT security (e.g., management, systems design, and development, acquisition, auditing).

17 I Page

Accessibility Report

Filename:

ITS-HBK-2810.06-2B IT Security Awareness Trng Education May 2019 .pdf

Report created by:

Organization:

[Enter personal and organization information through the Preferences > Identity dialog.]

Summary

The checker found no problems in this document.

Needs manual check: 2

Passed manually: 0

Failed manually: 0

Skipped: 3

Passed: 27

Failed: 0

Detailed Report

Document

Rule Name Status Description

Accessibility permission flag Passed Accessibility permission flag must be set

Image-only PDF Passed Document is not image-only PDF

Tagged PDF Passed Document is tagged PDF

Logical Reading Order Needs manual check Document structure provides a logical reading order

Primary language Passed Text language is specified

Title Passed Document title is showing in title bar

Bookmarks Passed Bookmarks are present in large documents

Color contrast Needs manual check Document has appropriate color contrast

Page Content

Rule Name Status Description

Tagged content Passed All page content is tagged

Tagged annotations Passed All annotations are tagged

Tab order Passed Tab order is consistent with structure order

Character encoding Passed Reliable character encoding is provided

Tagged multimedia Passed All multimedia objects are tagged

Screen flicker Passed Page will not cause screen flicker

Scripts Passed No inaccessible scripts

Timed responses Passed Page does not require timed responses

Navigation links Passed Navigation links are not repetitive

Forms

Rule Name Status Description

Tagged form fields Passed All form fields are tagged

Field descriptions Passed All form fields have description

Alternate Text

Rule Name Status Description

Figures alternate text Passed Figures require alternate text

Nested alternate text Passed Alternate text that will never be read

Associated with content Passed Alternate text must be associated with some content

Hides annotation Passed Alternate text should not hide annotation

Other elements alternate text Passed Other elements that require alternate text

Tables

Rule Name Status Description

Rows Passed TR must be a child of Table, THead, TBody, or TFoot

TH and TD Passed TH and TD must be children of TR

Headers Skipped Tables should have headers

Regularity Passed Tables must contain the same number of columns in each row and rows in each column

Summary Skipped Tables must have a summary

Lists

Rule Name Status Description

List items Passed LI must be a child of L

Lbl and LBody Passed Lbl and LBody must be children of LI

Headings

Rule Name Status Description

Appropriate nesting Skipped Appropriate nesting

Back to Top

File details come from the government source that posted it. Updated .