L0TC15 Ultrasonic PD Attch 2 Security Controls Overlay.xlsx
XLSX spreadsheet 2 MB Posted
- Attached to
- Ultrasonic Federal contract opportunity
- Solicitation number
- F3QCCM0169A002
About this file
This solicitation is for an ultrasonic non-destructive testing system. The 402nd Commodities Maintenance Group at Robins AFB, GA requires a turnkey gantry-style ultrasonic NDT inspection system to utilize through transmission and pulse echo testing to identify internal flaws, water entrapment, delamination, and disbonds through a two tower gantry mounted system. The basic system shall be installed in Building 169, and there is an option to retrofit the existing system in Building 323 with new motion and ultrasonic components. The contractor shall provide all labor, materials, shipping, delivery, and travel to deliver the required system. This is a total small business set aside being conducted by the Department of the Air Force Materiel Command Air Force Sustainment Center.
View the file
Other files for this federal contract opportunity
Show all 17
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
CONTROLS BY SELECTED CIA VALUES
| INSTRUCTIONS: Select C, I, A impact levels in the yellow boxes below to see the resultant control set | FYI/For interest only… for this C-I-A selection: | |||||||||||||||||
| For a CNSSI Baseline that does NOT include controls marked with a "+" (controls added to the NIST 800-53 for NSS) | ||||||||||||||||||
| Select values for C, I, A: | 140 | Total number of controls in CNSSI BASELINE | ||||||||||||||||
| C: | LOW | For the selected values of C, I, A there are | 10 | Number of controls added to CNSSI baseline by NIST OVERLAY | ||||||||||||||
| I: | LOW | 150 | controls resulting from 800-82 Baseline | 0 | Number of controls removed from the CNSSI baseline by the NIST OVERLAY | |||||||||||||
| A: | LOW | For a CNSSI Baseline that DOES include controls marked with a "+" (controls added for NSS) | ||||||||||||||||
| 310 | Total number of controls in CNSSI BASELINE | |||||||||||||||||
| FINAL CONTROL SET (AFTER OVERLAY IS APPLIED) | HOW TO OBTAIN THE FINAL CONTROL SET FROM | |||||||||||||||||
| THE EMASS CONTROL SET | 7 | Number of controls added to CNSSI baseline by NIST OVERLAY | ||||||||||||||||
| 167 | Number of controls removed from the CNSSI baseline by the NIST OVERLAY | |||||||||||||||||
| COMMENT OUT THESE CONTROLS | ADD THESE CONTROLS | (USE THESE FOR COMPARISON TO EMASS) | ||||||||||||||||
| For 1253 Baseline which DOES NOT include controls with a "+" | For 1253 Baseline which DOES include controls with a "+" | |||||||||||||||||
| -------- | -------- | -------- | Removed by NIST Overlay | Added by NIST Overlay | Removed by NIST Overlay | Added by NIST Overlay | ||||||||||||
| AC-1 | AC-2(4) | AC-21 | -------- | -------- | -------- | -------- | ||||||||||||
| AC-2 | AC-2(5) | CP-12 | AC-21 | AC-2(4) | AC-21 | |||||||||||||
| AC-3 | AC-2(7) | PE-11 | AU-4(1) | AC-2(5) | CP-12 | |||||||||||||
| AC-7 | AC-2(9) | PE-11(1) | CM-7(1) | AC-2(7) | PE-11 | |||||||||||||
| AC-8 | AC-2(10) | PL-2(3) | CP-12 | AC-2(9) | PE-11(1) | |||||||||||||
| AC-14 | AC-2(12) | SC-41 | IA-3 | AC-2(10) | PL-2(3) | |||||||||||||
| AC-17 | AC-2(13) | SI-17 | PE-11 | AC-2(12) | SC-41 | |||||||||||||
| AC-18 | AC-3(4) | PE-11(1) | AC-2(13) | SI-17 | ||||||||||||||
| AC-19 | AC-5 | PL-2(3) | AC-3(4) | |||||||||||||||
| AC-20 | AC-6 | SC-41 | AC-5 | |||||||||||||||
| AC-21 | AC-6(1) | SI-17 | AC-6 | |||||||||||||||
| AC-22 | AC-6(2) | AC-6(1) | ||||||||||||||||
| AT-1 | AC-6(5) | AC-6(2) | ||||||||||||||||
| AT-2 | AC-6(7) | AC-6(5) | ||||||||||||||||
| AT-3 | AC-6(8) | AC-6(7) | ||||||||||||||||
| AT-4 | AC-6(9) | AC-6(8) | ||||||||||||||||
| AU-1 | AC-6(10) | AC-6(9) | ||||||||||||||||
| AU-2 | AC-11 | AC-6(10) | ||||||||||||||||
| AU-3 | AC-11(1) | AC-11 | ||||||||||||||||
| AU-4 | AC-17(1) | AC-11(1) | ||||||||||||||||
| AU-4(1) | AC-17(2) | AC-17(1) | ||||||||||||||||
| AU-5 | AC-17(3) | AC-17(2) | ||||||||||||||||
| AU-6 | AC-17(4) | AC-17(3) | ||||||||||||||||
| AU-8 | AC-17(6) | AC-17(4) | ||||||||||||||||
| AU-9 | AC-17(9) | AC-17(6) | ||||||||||||||||
| AU-11 | AC-18(1) | AC-17(9) | ||||||||||||||||
| AU-12 | AC-18(3) | AC-18(1) | ||||||||||||||||
| CA-1 | AC-18(4) | AC-18(3) | ||||||||||||||||
| CA-2 | AC-20(1) | AC-18(4) | ||||||||||||||||
| CA-3 | AC-20(2) | AC-20(1) | ||||||||||||||||
| CA-5 | AC-20(3) | AC-20(2) | ||||||||||||||||
| CA-6 | AT-2(2) | AC-20(3) | ||||||||||||||||
| CA-7 | AT-3(2) | AT-2(2) | ||||||||||||||||
| CA-9 | AT-3(4) | AT-3(2) | ||||||||||||||||
| CM-1 | AU-2(3) | AT-3(4) | ||||||||||||||||
| CM-2 | AU-3(1) | AU-2(3) | ||||||||||||||||
| CM-4 | AU-5(1) | AU-3(1) | ||||||||||||||||
| CM-6 | AU-6(1) | AU-5(1) | ||||||||||||||||
| CM-7 | AU-6(3) | AU-6(1) | ||||||||||||||||
| CM-7(1) | AU-6(4) | AU-6(3) | ||||||||||||||||
| CM-8 | AU-6(10) | AU-6(4) | ||||||||||||||||
| CM-10 | AU-8(1) | AU-6(10) | ||||||||||||||||
| CM-11 | AU-9(4) | AU-8(1) | ||||||||||||||||
| CP-1 | AU-11(1) | AU-9(4) | ||||||||||||||||
| CP-2 | AU-12(1) | AU-11(1) | ||||||||||||||||
| CP-3 | AU-12(3) | AU-12(1) | ||||||||||||||||
| CP-4 | AU-14 | AU-12(3) | ||||||||||||||||
| CP-9 | AU-14(1) | AU-14 | ||||||||||||||||
| CP-10 | AU-14(2) | AU-14(1) | ||||||||||||||||
| CP-12 | AU-14(3) | AU-14(2) | ||||||||||||||||
| IA-1 | CA-2(1) | AU-14(3) | ||||||||||||||||
| IA-2 | CA-3(1) | CA-2(1) | ||||||||||||||||
| IA-2(1) | CA-3(5) | CA-3(1) | ||||||||||||||||
| IA-2(12) | CM-2(1) | CA-3(5) | ||||||||||||||||
| IA-3 | CM-3 | CM-2(1) | ||||||||||||||||
| IA-4 | CM-3(4) | CM-3 | ||||||||||||||||
| IA-5 | CM-3(6) | CM-3(4) | ||||||||||||||||
| IA-5(1) | CM-5 | CM-3(6) | ||||||||||||||||
| IA-5(11) | CM-5(5) | CM-5 | ||||||||||||||||
| IA-6 | CM-5(6) | CM-5(5) | ||||||||||||||||
| IA-7 | CM-7(2) | CM-5(6) | ||||||||||||||||
| IA-8 | CM-7(3) | CM-7(2) | ||||||||||||||||
| IA-8(1) | CM-7(5) | CM-7(3) | ||||||||||||||||
| IA-8(2) | CM-8(2) | CM-7(5) | ||||||||||||||||
| IA-8(3) | CM-8(3) | CM-8(2) | ||||||||||||||||
| IA-8(4) | CM-9 | CM-8(3) | ||||||||||||||||
| IR-1 | CM-10(1) | CM-9 | ||||||||||||||||
| IR-2 | CM-11(2) | CM-10(1) | ||||||||||||||||
| IR-4 | IA-2(2) | CM-11(2) | ||||||||||||||||
| IR-5 | IA-2(5) | IA-2(2) | ||||||||||||||||
| IR-6 | IA-2(8) | IA-2(5) | ||||||||||||||||
| IR-7 | IA-2(11) | IA-2(8) | ||||||||||||||||
| IR-8 | IA-4(4) | IA-2(11) | ||||||||||||||||
| MA-1 | IA-5(4) | IA-4(4) | ||||||||||||||||
| MA-2 | IA-5(7) | IA-5(4) | ||||||||||||||||
| MA-4 | IA-5(8) | IA-5(7) | ||||||||||||||||
| MA-5 | IA-5(13) | IA-5(8) | ||||||||||||||||
| MP-1 | IA-5(14) | IA-5(13) | ||||||||||||||||
| MP-2 | IR-3 | IA-5(14) | ||||||||||||||||
| MP-6 | IR-4(4) | IR-3 | ||||||||||||||||
| MP-7 | IR-4(6) | IR-4(4) | ||||||||||||||||
| PE-1 | IR-4(7) | IR-4(6) | ||||||||||||||||
| PE-2 | IR-4(8) | IR-4(7) | ||||||||||||||||
| PE-3 | IR-6(2) | IR-4(8) | ||||||||||||||||
| PE-6 | IR-7(2) | IR-6(2) | ||||||||||||||||
| PE-8 | IR-9 | IR-7(2) | ||||||||||||||||
| PE-11 | IR-9(1) | IR-9 | ||||||||||||||||
| PE-11(1) | IR-9(2) | IR-9(1) | ||||||||||||||||
| PE-12 | IR-9(4) | IR-9(2) | ||||||||||||||||
| PE-13 | MA-3 | IR-9(4) | ||||||||||||||||
| PE-14 | MA-3(2) | MA-3 | ||||||||||||||||
| PE-15 | MA-3(3) | MA-3(2) | ||||||||||||||||
| PE-16 | MA-4(3) | MA-3(3) | ||||||||||||||||
| PL-1 | MA-4(6) | MA-4(3) | ||||||||||||||||
| PL-2 | MA-4(7) | MA-4(6) | ||||||||||||||||
| PL-2(3) | MP-7(1) | MA-4(7) | ||||||||||||||||
| PL-4 | PE-3(1) | MP-7(1) | ||||||||||||||||
| PS-1 | PL-8 | PE-3(1) | ||||||||||||||||
| PS-2 | PL-8(1) | PL-8 | ||||||||||||||||
| PS-3 | PL-8(2) | PL-8(1) | ||||||||||||||||
| PS-4 | PS-4(1) | PL-8(2) | ||||||||||||||||
| PS-5 | PS-6(3) | PS-4(1) | ||||||||||||||||
| PS-6 | RA-5(1) | PS-6(3) | ||||||||||||||||
| PS-7 | RA-5(2) | RA-5(1) | ||||||||||||||||
| PS-8 | RA-5(4) | RA-5(2) | ||||||||||||||||
| RA-1 | RA-5(5) | RA-5(4) | ||||||||||||||||
| RA-2 | SA-4(7) | RA-5(5) | ||||||||||||||||
| RA-3 | SA-4(9) | SA-4(7) | ||||||||||||||||
| RA-5 | SA-8 | SA-4(9) | ||||||||||||||||
| SA-1 | SA-9(1) | SA-8 | ||||||||||||||||
| SA-2 | SA-9(2) | SA-9(1) | ||||||||||||||||
| SA-3 | SA-10 | SA-9(2) | ||||||||||||||||
| SA-4 | SA-10(1) | SA-10 | ||||||||||||||||
| SA-4(10) | SA-12 | SA-10(1) | ||||||||||||||||
| SA-5 | SA-15 | SA-12 | ||||||||||||||||
| SA-9 | SA-15(9) | SA-15 | ||||||||||||||||
| SC-1 | SA-19 | SA-15(9) | ||||||||||||||||
| SC-5 | SC-5(1) | SA-19 | ||||||||||||||||
| SC-7 | SC-7(3) | SC-5(1) | ||||||||||||||||
| SC-12 | SC-7(4) | SC-7(3) | ||||||||||||||||
| SC-13 | SC-7(5) | SC-7(4) | ||||||||||||||||
| SC-15 | SC-7(7) | SC-7(5) | ||||||||||||||||
| SC-20 | SC-7(8) | SC-7(7) | ||||||||||||||||
| SC-21 | SC-7(9) | SC-7(8) | ||||||||||||||||
| SC-22 | SC-7(10) | SC-7(9) | ||||||||||||||||
| SC-39 | SC-7(11) | SC-7(10) | ||||||||||||||||
| SC-41 | SC-7(12) | SC-7(11) | ||||||||||||||||
| SI-1 | SC-7(13) | SC-7(12) | ||||||||||||||||
| SI-2 | SC-7(14) | SC-7(13) | ||||||||||||||||
| SI-3 | SC-8 | SC-7(14) | ||||||||||||||||
| SI-4 | SC-8(1) | SC-8 | ||||||||||||||||
| SI-5 | SC-17 | SC-8(1) | ||||||||||||||||
| SI-12 | SC-18 | SC-17 | ||||||||||||||||
| SI-17 | SC-18(1) | SC-18 | ||||||||||||||||
| PM-1 | SC-18(2) | SC-18(1) | ||||||||||||||||
| PM-2 | SC-18(3) | SC-18(2) | ||||||||||||||||
| PM-3 | SC-18(4) | SC-18(3) | ||||||||||||||||
| PM-4 | SC-19 | SC-18(4) | ||||||||||||||||
| PM-5 | SC-23 | SC-19 | ||||||||||||||||
| PM-6 | SC-23(1) | SC-23 | ||||||||||||||||
| PM-7 | SC-23(3) | SC-23(1) | ||||||||||||||||
| PM-8 | SC-23(5) | SC-23(3) | ||||||||||||||||
| PM-9 | SC-28 | SC-23(5) | ||||||||||||||||
| PM-10 | SC-28(1) | SC-28 | ||||||||||||||||
| PM-11 | SC-38 | SC-28(1) | ||||||||||||||||
| PM-12 | SI-2(1) | SC-38 | ||||||||||||||||
| PM-13 | SI-2(2) | SI-2(1) | ||||||||||||||||
| PM-14 | SI-2(3) | SI-2(2) | ||||||||||||||||
| PM-15 | SI-2(6) | SI-2(3) | ||||||||||||||||
| PM-16 | SI-3(1) | SI-2(6) | ||||||||||||||||
| SI-3(2) | SI-3(1) | |||||||||||||||||
| SI-3(10) | SI-3(2) | |||||||||||||||||
| SI-4(1) | SI-3(10) | |||||||||||||||||
| SI-4(4) | SI-4(1) | |||||||||||||||||
| SI-4(5) | SI-4(4) | |||||||||||||||||
| SI-4(11) | SI-4(5) | |||||||||||||||||
| SI-4(12) | SI-4(11) | |||||||||||||||||
| SI-4(14) | SI-4(12) | |||||||||||||||||
| SI-4(15) | SI-4(14) | |||||||||||||||||
| SI-4(16) | SI-4(15) | |||||||||||||||||
| SI-4(19) | SI-4(16) | |||||||||||||||||
| SI-4(20) | SI-4(19) | |||||||||||||||||
| SI-4(22) | SI-4(20) | |||||||||||||||||
| SI-4(23) | SI-4(22) | |||||||||||||||||
| SI-7(14) | SI-4(23) | |||||||||||||||||
| SI-10 | SI-7(14) | |||||||||||||||||
| SI-11 | SI-10 | |||||||||||||||||
| SI-11 |
MORE_DETAIL_CONTROLS_BY...
| The final control set from CONTROLS BY SELECTED CIA VALUES tab with additional information - Control Title, Control Text, Supplemental Guidance | |
| C-I-A: | LOW-LOW-LOW |
| Control Number | Control Title | Control Text | Supplemental Guidance | Number of Assess Procs |
| AC-1 | ACCESS CONTROL POLICY AND PROCEDURES | The organization: |
a. Develops, documents, and disseminates to [Assignment: organization-defined personnel or roles]:
1. An access control policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
2. Procedures to facilitate the implementation of the access control policy and associated access controls; and
b. Reviews and updates the current:
1. Access control policy [Assignment: organization-defined frequency]; and
2. Access control procedures [Assignment: organization-defined frequency]. This control addresses the establishment of policy and procedures for the effective implementation of selected security controls and control enhancements in the AC family. Policy and procedures reflect applicable federal laws, Executive Orders, directives, regulations, policies, standards, and guidance. Security program policies and procedures at the organization level may make the need for system-specific policies and procedures unnecessary. The policy can be included as part of the general information security policy for organizations or conversely, can be represented by multiple policies reflecting the complex nature of certain organizations. The procedures can be established for the security program in general and for particular information systems, if needed. The organizational risk management strategy is a key factor in establishing policy and procedures. Related control: PM-9.
| ICS Supplemental Guidance: The policy specifically addresses the unique properties and requirements of ICS and the relationship to non-ICS systems. ICS access by vendors and maintenance staff can occur over a very large facility footprint or geographic area and into unobserved spaces such as mechanical/electrical rooms, ceilings, floors, field substations, switch and valve vaults, and pump stations. | 12 | ||
| AC-2 | ACCOUNT MANAGEMENT | The organization: |
a. Identifies and selects the following types of information system accounts to support organizational missions/business functions: [Assignment: organization-defined information system account types];
b. Assigns account managers for information system accounts;
c. Establishes conditions for group and role membership;
d. Specifies authorized users of the information system, group and role membership, and access authorizations (i.e., privileges) and other attributes (as required) for each account;
e. Requires approvals by [Assignment: organization-defined personnel or roles] for requests to create information system accounts;
f. Creates, enables, modifies, disables, and removes information system accounts in accordance with [Assignment: organization-defined procedures or conditions];
g. Monitors the use of information system accounts;
h. Notifies account managers:
1. When accounts are no longer required;
2. When users are terminated or transferred; and
3. When individual information system usage or need-to-know changes;
i. Authorizes access to the information system based on:
1. A valid access authorization;
2. Intended system usage; and
3. Other attributes as required by the organization or associated missions/business functions;
j. Reviews accounts for compliance with account management requirements [Assignment: organization-defined frequency]; and
k. Establishes a process for reissuing shared/group account credentials (if deployed) when individuals are removed from the group. Supplemental Guidance: Information system account types include, for example, individual, shared, group, system, guest/anonymous, emergency, developer/manufacturer/vendor, temporary, and service. Some of the account management requirements listed above can be implemented by organizational information systems. The identification of authorized users of the information system and the specification of access privileges reflects the requirements in other security controls in the security plan. Users requiring administrative privileges on information system accounts receive additional scrutiny by appropriate organizational personnel (e.g., system owner, mission/business owner, or chief information security officer) responsible for approving such accounts and privileged access. Organizations may choose to define access privileges or other attributes by account, by type of account, or a combination of both. Other attributes required for authorizing access include, for example, restrictions on time-of-day, day-of-week, and point-of-origin. In defining other account attributes, organizations consider system-related requirements (e.g., scheduled maintenance, system upgrades) and mission/business requirements, (e.g., time zone differences, customer requirements, remote access to support travel requirements). Failure to consider these factors could affect information system availability. Temporary and emergency accounts are accounts intended for short-term use. Organizations establish temporary accounts as a part of normal account activation procedures when there is a need for short-term accounts without the demand for immediacy in account activation. Organizations establish emergency accounts in response to crisis situations and with the need for rapid account activation. Therefore, emergency account activation may bypass normal account authorization processes. Emergency and temporary accounts are not to be confused with infrequently used accounts (e.g., local logon accounts used for special tasks defined by organizations or when network resources are unavailable). Such accounts remain available and are not subject to automatic disabling or removal dates. Conditions for disabling or deactivating accounts include, for example: (i) when shared/group, emergency, or temporary accounts are no longer required; or (ii) when individuals are transferred or terminated. Some types of information system accounts may require specialized training. Related controls: AC-3, AC-4, AC-5, AC-6, AC-10, AC-17, AC-19, AC-20, AU-9, IA-2, IA-4, IA-5, IA-8, CM-5, CM-6, CM-11, MA-3, MA-4, MA-5, PL-4, SC-13.
| ICS Supplemental Guidance: Example compensating controls include providing increased physical security, personnel security, intrusion detection, auditing measures. | 24 | |||
| AC-3 | ACCESS ENFORCEMENT | The information system enforces approved authorizations for logical access to information and system resources in accordance with applicable access control policies. | Supplemental Guidance: Access control policies (e.g., identity-based policies, role-based policies, attribute-based policies) and access enforcement mechanisms (e.g., access control lists, access control matrices, cryptography) control access between active entities or subjects (i.e., users or processes acting on behalf of users) and passive entities or objects (e.g., devices, files, records, domains) in information systems. In addition to enforcing authorized access at the information system level and recognizing that information systems can host many applications and services in support of organizational missions and business operations, access enforcement mechanisms can also be employed at the application and service level to provide increased information security. Related controls: AC-2, AC-4, AC-5, AC-6, AC-16, AC-17, AC-18, AC-19, AC-20, AC-21, AC-22, AU-9, CM-5, CM-6, CM-11, MA-3, MA-4, MA-5, PE-3. |
| ICS Supplemental Guidance: The organization ensures that access enforcement mechanisms do not adversely impact the operational performance of the ICS. Example compensating controls include encapsulation. Policy for logical access control to Non-Addressable and Non-Routable system resources and the associated information is made explicit. Access control mechanisms include hardware, firmware, and software that controls or has device access, such as device drivers and communications controllers. Physical access control may serve as a compensating control for logical access control, however, it may not provide sufficient granularity in situations where users require access to different functions. Logical access enforcement may be implemented in encapsulating hardware and software. | 1 | ||
| AC-7 | UNSUCCESSFUL LOGIN ATTEMPTS | The information system: |
a. Enforces a limit of [Assignment: organization-defined number] consecutive invalid logon attempts by a user during a [Assignment: organization-defined time period]; and
b. Automatically [Selection: locks the account/node for an [Assignment: organization-defined time period]; locks the account/node until released by an administrator; delays next logon prompt according to [Assignment: organization-defined delay algorithm]] when the maximum number of unsuccessful attempts is exceeded. Supplemental Guidance: This control applies regardless of whether the logon occurs via a local or network connection. Due to the potential for denial of service, automatic lockouts initiated by information systems are usually temporary and automatically release after a predetermined time period established by organizations. If a delay algorithm is selected, organizations may choose to employ different algorithms for different information system components based on the capabilities of those components. Responses to unsuccessful logon attempts may be implemented at both the operating system and the application levels. Related controls: AC-2, AC-9, AC-14, IA-5.
| ICS Supplemental Guidance: Many ICS must remain continuously on and operators remain logged onto the system at all times. A “log-over” capability may be employed. Example compensating controls include logging or recording all unsuccessful login attempts and alerting ICS security personnel though alarms or other means when the number of organization-defined consecutive invalid access attempts is exceeded. | 6 | ||
| AC-8 | SYSTEM USE NOTIFICATION | The information system: |
a. Displays to users [Assignment: organization-defined system use notification message or banner] before granting access to the system that provides privacy and security notices consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance and states that:
1. Users are accessing a U.S. Government information system;
2. Information system usage may be monitored, recorded, and subject to audit;
3. Unauthorized use of the information system is prohibited and subject to criminal and civil penalties; and
4. Use of the information system indicates consent to monitoring and recording;
b. Retains the notification message or banner on the screen until users acknowledge the usage conditions and take explicit actions to log on to or further access the information system; and
c. For publicly accessible systems:
1. Displays system use information [Assignment: organization-defined conditions], before granting further access;
2. Displays references, if any, to monitoring, recording, or auditing that are consistent with privacy accommodations for such systems that generally prohibit those activities; and
3. Includes a description of the authorized uses of the system. Supplemental Guidance: System use notifications can be implemented using messages or warning banners displayed before individuals log in to information systems. System use notifications are used only for access via logon interfaces with human users and are not required when such human interfaces do not exist. Organizations consider system use notification messages/banners displayed in multiple languages based on specific organizational needs and the demographics of information system users. Organizations also consult with the Office of the General Counsel for legal review and approval of warning banner content.
| ICS Supplemental Guidance: Many ICS must remain continuously on and system use notification may not be supported or effective. Example compensating controls include posting physical notices in ICS facilities. | 13 | ||
| AC-14 | PERMITTED ACTIONS WITHOUT IDENTIFICATION OR AUTHENTICATION | The organization: |
a. Identifies [Assignment: organization-defined user actions] that can be performed on the information system without identification or authentication consistent with organizational missions/business functions; and
| b. Documents and provides supporting rationale in the security plan for the information system, user actions not requiring identification or authentication. | Supplemental Guidance: This control addresses situations in which organizations determine that no identification or authentication is required in organizational information systems. Organizations may allow a limited number of user actions without identification or authentication including, for example, when individuals access public websites or other publicly accessible federal information systems, when individuals use mobile phones to receive calls, or when facsimiles are received. Organizations also identify actions that normally require identification or authentication but may under certain circumstances (e.g., emergencies), allow identification or authentication mechanisms to be bypassed. Such bypasses may occur, for example, via a software-readable physical switch that commands bypass of the logon functionality and is protected from accidental or unmonitored use. This control does not apply to situations where identification and authentication have already occurred and are not repeated, but rather to situations where identification and authentication have not yet occurred. Organizations may decide that there are no user actions that can be performed on organizational information systems without identification and authentication and thus, the values for assignment statements can be none. Related controls: CP-2, IA-2. | 2 | |
| AC-17 | REMOTE ACCESS | The organization: |
a. Establishes and documents usage restrictions, configuration/connection requirements, and implementation guidance for each type of remote access allowed; and
b. Authorizes remote access to the information system prior to allowing such connections. Supplemental Guidance: Remote access is access to organizational information systems by users (or processes acting on behalf of users) communicating through external networks (e.g., the Internet). Remote access methods include, for example, dial-up, broadband, and wireless. Organizations often employ encrypted virtual private networks (VPNs) to enhance confidentiality and integrity over remote connections. The use of encrypted VPNs does not make the access non-remote; however, the use of VPNs, when adequately provisioned with appropriate security controls (e.g., employing appropriate encryption techniques for confidentiality and integrity protection) may provide sufficient assurance to the organization that it can effectively treat such connections as internal networks. Still, VPN connections traverse external networks, and the encrypted VPN does not enhance the availability of remote connections. Also, VPNs with encrypted tunnels can affect the organizational capability to adequately monitor network communications traffic for malicious code. Remote access controls apply to information systems other than public web servers or systems designed for public access. This control addresses authorization prior to allowing remote access without specifying the formats for such authorization. While organizations may use interconnection security agreements to authorize remote access connections, such agreements are not required by this control. Enforcing access restrictions for remote connections is addressed in AC-3. Related controls: AC-2, AC-3, AC-18, AC-19, AC-20, CA-3, CA-7, CM-8, IA-2, IA-3, IA-8, MA-4, PE-17, PL-4, SC-10, SI-4.
| ICS Supplemental Guidance: In situations where the ICS cannot implement any or all of the components of this control, the organization employs other mechanisms or procedures as compensating controls in accordance with the general tailoring guidance. | 5 | ||
| AC-18 | WIRELESS ACCESS | The organization: |
a. Establishes usage restrictions, configuration/connection requirements, and implementation guidance for wireless access; and
b. Authorizes wireless access to the information system prior to allowing such connections. Supplemental Guidance: Wireless technologies include, for example, microwave, packet radio (UHF/VHF), 802.11x, and Bluetooth. Wireless networks use authentication protocols (e.g., EAP/TLS, PEAP), which provide credential protection and mutual authentication. Related controls: AC-2, AC-3, AC-17, AC-19, CA-3, CA-7, CM-8, IA-2, IA-3, IA-8, PL-4, SI-4.
| ICS Supplemental Guidance: In situations where the ICS cannot implement any or all of the components of this control, the organization employs other mechanisms or procedures as compensating controls in accordance with the general tailoring guidance. | 4 | ||
| AC-19 | ACCESS CONTROL FOR MOBILE DEVICES | The organization: |
a. Establishes usage restrictions, configuration requirements, connection requirements, and implementation guidance for organization-controlled mobile devices; and
| b. Authorizes the connection of mobile devices to organizational information systems. | Supplemental Guidance: A mobile device is a computing device that: (i) has a small form factor such that it can easily be carried by a single individual; (ii) is designed to operate without a physical connection (e.g., wirelessly transmit or receive information); (iii) possesses local, non-removable or removable data storage; and (iv) includes a self-contained power source. Mobile devices may also include voice communication capabilities, on-board sensors that allow the device to capture information, and/or built-in features for synchronizing local data with remote locations. Examples include smart phones, E-readers, and tablets. Mobile devices are typically associated with a single individual and the device is usually in close proximity to the individual; however, the degree of proximity can vary depending upon on the form factor and size of the device. The processing, storage, and transmission capability of the mobile device may be comparable to or merely a subset of desktop systems, depending upon the nature and intended purpose of the device. Due to the large variety of mobile devices with different technical characteristics and capabilities, organizational restrictions may vary for the different classes/types of such devices. Usage restrictions and specific implementation guidance for mobile devices include, for example, configuration management, device identification and authentication, implementation of mandatory protective software (e.g., malicious code detection, firewall), scanning devices for malicious code, updating virus protection software, scanning for critical software updates and patches, conducting primary operating system (and possibly other resident software) integrity checks, and disabling unnecessary hardware (e.g., wireless, infrared). Organizations are cautioned that the need to provide adequate security for mobile devices goes beyond the requirements in this control. Many safeguards and countermeasures for mobile devices are reflected in other security controls in the catalog allocated in the initial control baselines as starting points for the development of security plans and overlays using the tailoring process. There may also be some degree of overlap in the requirements articulated by the security controls within the different families of controls. AC-20 addresses mobile devices that are not organization-controlled. Related controls: AC-3, AC-7, AC-18, AC-20, CA-9, CM-2, IA-2, IA-3, MP-2, MP-4, MP-5, PL-4, SC-7, SC-43, SI-3, SI-4. | 5 | |
| AC-20 | USE OF EXTERNAL INFORMATION SYSTEMS | The organization establishes terms and conditions, consistent with any trust relationships established with other organizations owning, operating, and/or maintaining external information systems, allowing authorized individuals to: |
a. Access the information system from external information systems; and
b. Process, store, or transmit organization-controlled information using external information systems. Supplemental Guidance: External information systems are information systems or components of information systems that are outside of the authorization boundary established by organizations and for which organizations typically have no direct supervision and authority over the application of required security controls or the assessment of control effectiveness. External information systems include, for example: (i) personally owned information systems/devices (e.g., notebook computers, smart phones, tablets, personal digital assistants); (ii) privately owned computing and communications devices resident in commercial or public facilities (e.g., hotels, train stations, convention centers, shopping malls, or airports); (iii) information systems owned or controlled by nonfederal governmental organizations; and (iv) federal information systems that are not owned by, operated by, or under the direct supervision and authority of organizations. This control also addresses the use of external information systems for the processing, storage, or transmission of organizational information, including, for example, accessing cloud services (e.g., infrastructure as a service, platform as a service, or software as a service) from organizational information systems.
For some external information systems (i.e., information systems operated by other federal agencies, including organizations subordinate to those agencies), the trust relationships that have been established between those organizations and the originating organization may be such, that no explicit terms and conditions are required. Information systems within these organizations would not be considered external. These situations occur when, for example, there are pre-existing sharing/trust agreements (either implicit or explicit) established between federal agencies or organizations subordinate to those agencies, or when such trust agreements are specified by applicable laws, Executive Orders, directives, or policies. Authorized individuals include, for example, organizational personnel, contractors, or other individuals with authorized access to organizational information systems and over which organizations have the authority to impose rules of behavior with regard to system access. Restrictions that organizations impose on authorized individuals need not be uniform, as those restrictions may vary depending upon the trust relationships between organizations. Therefore, organizations may choose to impose different security restrictions on contractors than on state, local, or tribal governments.
This control does not apply to the use of external information systems to access public interfaces to organizational information systems (e.g., individuals accessing federal information through www.usa.gov). Organizations establish terms and conditions for the use of external information systems in accordance with organizational security policies and procedures. Terms and conditions address as a minimum: types of applications that can be accessed on organizational information systems from external information systems; and the highest security category of information that can be processed, stored, or transmitted on external information systems. If terms and conditions with the owners of external information systems cannot be established, organizations may impose restrictions on organizational personnel using those external systems. Related controls: AC-3, AC-17, AC-19, CA-3, PL-4, SA-9.
| ICS Supplemental Guidance: Organizations refine the definition of “external” to reflect lines of authority and responsibility; granularity of organization entity; and their relationships. An organization may consider a system to be external if that system performs different functions, implements different policies, comes under different managers, or does not provide sufficient visibility into the implementation of security controls to allow the establishment of a satisfactory trust relationship. For example, a process control system and a business data processing system would typically be considered external to each other. Access to an ICS for support by a business partner, such as a vendor or support contractor, is another common example. The definition and trustworthiness of external information systems is reexamined with respect to ICS functions, purposes, technology, and limitations to establish a clear documented technical or business case for use and an acceptance of the risk inherent in the use of an external information system. | 2 | ||
| AC-21 | INFORMATION SHARING | The organization: |
a. Facilitates information sharing by enabling authorized users to determine whether access authorizations assigned to the sharing partner match the access restrictions on the information for [Assignment: organization-defined information sharing circumstances where user discretion is required]; and
b. Employs [Assignment: organization-defined automated mechanisms or manual processes] to assist users in making information sharing/collaboration decisions. Supplemental Guidance: This control applies to information that may be restricted in some manner (e.g., privileged medical information, contract-sensitive information, proprietary information, personally identifiable information, classified information related to special access programs or compartments) based on some formal or administrative determination. Depending on the particular information-sharing circumstances, sharing partners may be defined at the individual, group, or organizational level. Information may be defined by content, type, security category, or special access program/compartment. Related control: AC-3.
| ICS Supplemental Guidance: The organization should collaborate and share information about potential incidents on a timely basis. The DHS National Cybersecurity & Communications Integration Center (NCCIC), http://www.dhs.gov/about-national-cybersecurity-communications-integration-center serves as a centralized location where operational elements involved in cybersecurity and communications reliance are coordinated and integrated. The Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) http://ics-cert.us-cert.gov/ics-cert/ collaborates with international and private sector Computer Emergency Response Teams (CERTs) to share control systems-related security incidents and mitigation measures. Organizations should consider having both an unclassified and classified information sharing capability. | 4 | ||
| AC-22 | PUBLICLY ACCESSIBLE CONTENT | The organization: |
a. Designates individuals authorized to post information onto a publicly accessible information system;
b. Trains authorized individuals to ensure that publicly accessible information does not contain nonpublic information;
c. Reviews the proposed content of information prior to posting onto the publicly accessible information system to ensure that nonpublic information is not included; and
d. Reviews the content on the publicly accessible information system for nonpublic information [Assignment: organization-defined frequency] and removes such information, if discovered. Supplemental Guidance: In accordance with federal laws, Executive Orders, directives, policies, regulations, standards, and/or guidance, the general public is not authorized access to nonpublic information (e.g., information protected under the Privacy Act and proprietary information). This control addresses information systems that are controlled by the organization and accessible to the general public, typically without identification or authentication. The posting of information on non-organization information systems is covered by organizational policy. Related controls: AC-3, AC-4, AT-2, AT-3, AU-13.
| ICS Supplemental Guidance: Generally, public access to ICS systems is not permitted. Selected information may be transferred to a publicly accessible information system, possibly with added controls (e.g., introduction of fuzziness or delay). | 6 | ||
| AT-1 | SECURITY AWARENESS AND TRAINING POLICY AND PROCEDURES | The organization: |
a. Develops, documents, and disseminates to [Assignment: organization-defined personnel or roles]:
1. A security awareness and training policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
2. Procedures to facilitate the implementation of the security awareness and training policy and associated security awareness and training controls; and
b. Reviews and updates the current:
1. Security awareness and training policy [Assignment: organization-defined frequency]; and
2. Security awareness and training procedures [Assignment: organization-defined frequency]. Supplemental Guidance: This control addresses the establishment of policy and procedures for the effective implementation of selected security controls and control enhancements in the AT family. Policy and procedures reflect applicable federal laws, Executive Orders, directives, regulations, policies, standards, and guidance. Security program policies and procedures at the organization level may make the need for system-specific policies and procedures unnecessary. The policy can be included as part of the general information security policy for organizations or conversely, can be represented by multiple policies reflecting the complex nature of certain organizations. The procedures can be established for the security program in general and for particular information systems, if needed. The organizational risk management strategy is a key factor in establishing policy and procedures. Related control: PM-9.
| ICS Supplemental Guidance: The policy specifically addresses the unique properties and requirements of ICS and the relationship to non-ICS systems. | 10 | ||
| AT-2 | SECURITY AWARENESS TRAINING | The organization provides basic security awareness training to information system users (including managers, senior executives, and contractors): |
a. As part of initial training for new users;
b. When required by information system changes; and
c. [Assignment: organization-defined frequency] thereafter. Supplemental Guidance: Organizations determine the appropriate content of security awareness training and security awareness techniques based on the specific organizational requirements and the information systems to which personnel have authorized access. The content includes a basic understanding of the need for information security and user actions to maintain security and to respond to suspected security incidents. The content also addresses awareness of the need for operations security. Security awareness techniques can include, for example, displaying posters, offering supplies inscribed with security reminders, generating email advisories/notices from senior organizational officials, displaying logon screen messages, and conducting information security awareness events. Related controls: AT-3, AT-4, PL-4.
| ICS Supplemental Guidance: Security awareness training includes initial and periodic review of ICS-specific policies, standard operating procedures, security trends, and vulnerabilities. The ICS security awareness program is consistent with the requirements of the security awareness and training policy established by the organization. | 4 | ||
| AT-3 | ROLE-BASED SECURITY TRAINING | The organization provides role-based security training to personnel with assigned security roles and responsibilities: |
a. Before authorizing access to the information system or performing assigned duties;
b. When required by information system changes; and
c. [Assignment: organization-defined frequency] thereafter. Supplemental Guidance: Organizations determine the appropriate content of security training based on the assigned roles and responsibilities of individuals and the specific security requirements of organizations and the information systems to which personnel have authorized access. In addition, organizations provide enterprise architects, information system developers, software developers, acquisition/procurement officials, information system managers, system/network administrators, personnel conducting configuration management and auditing activities, personnel performing independent verification and validation activities, security control assessors, and other personnel having access to system-level software, adequate security-related technical training specifically tailored for their assigned duties. Comprehensive role-based training addresses management, operational, and technical roles and responsibilities covering physical, personnel, and technical safeguards and countermeasures. Such training can include for example, policies, procedures, tools, and artifacts for the organizational security roles defined. Organizations also provide the training necessary for individuals to carry out their responsibilities related to operations and supply chain security within the context of organizational information security programs. Role-based security training also applies to contractors providing services to federal agencies. Related controls: AT-2, AT-4, PL-4, PS-7, SA-3, SA-12, SA-16.
| ICS Supplemental Guidance: Security training includes initial and periodic review of ICS-specific policies, standard operating procedures, security trends, and vulnerabilities. The ICS security training program is consistent with the requirements of the security awareness and training policy established by the organization. | 4 | ||
| AT-4 | SECURITY TRAINING RECORDS | The organization: |
a. Documents and monitors individual information system security training activities including basic security awareness training and specific information system security training; and
| b. Retains individual training records for [Assignment: organization-defined time period]. | Supplemental Guidance: Documentation for specialized training may be maintained by individual supervisors at the option of the organization. Related controls: AT-2, AT-3, PM-14. | 4 | |
| AU-1 | AUDIT AND ACCOUNTABILITY POLICY AND PROCEDURES | The organization: |
a. Develops, documents, and disseminates to [Assignment: organization-defined personnel or roles]:
1. An audit and accountability policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
2. Procedures to facilitate the implementation of the audit and accountability policy and associated audit and accountability controls; and
b. Reviews and updates the current:
1. Audit and accountability policy [Assignment: organization-defined frequency]; and
2. Audit and accountability procedures [Assignment: organization-defined frequency]. Supplemental Guidance: This control addresses the establishment of policy and procedures for the effective implementation of selected security controls and control enhancements in the AU family. Policy and procedures reflect applicable federal laws, Executive Orders, directives, regulations, policies, standards, and guidance. Security program policies and procedures at the organization level may make the need for system-specific policies and procedures unnecessary. The policy can be included as part of the general information security policy for organizations or conversely, can be represented by multiple policies reflecting the complex nature of certain organizations. The procedures can be established for the security program in general and for particular information systems, if needed. The organizational risk management strategy is a key factor in establishing policy and procedures. Related control: PM-9.
| ICS Supplemental Guidance: The policy specifically addresses the unique properties and requirements of ICS and the relationship to non-ICS systems. | 10 | ||
| AU-2 | AUDIT EVENTS | The organization: |
a. Determines that the information system is capable of auditing the following events: [Assignment: organization-defined auditable events];
b. Coordinates the security audit function with other organizational entities requiring audit-related information to enhance mutual support and to help guide the selection of auditable events;
c. Provides a rationale for why the auditable events are deemed to be adequate to support after-the-fact investigations of security incidents; and
d. Determines that the following events are to be audited within the information system: [Assignment: organization-defined audited events (the subset of the auditable events defined in AU-2 a.) along with the frequency of (or situation requiring) auditing for each identified event]. Supplemental Guidance: An event is any observable occurrence in an organizational information system. Organizations identify audit events as those events which are significant and relevant to the security of information systems and the environments in which those systems operate in order to meet specific and ongoing audit needs. Audit events can include, for example, password changes, failed logons, or failed accesses related to information systems, administrative privilege usage, PIV credential usage, or third-party credential usage. In determining the set of auditable events, organizations consider the auditing appropriate for each of the security controls to be implemented. To balance auditing requirements with other information system needs, this control also requires identifying that subset of auditable events that are audited at a given point in time. For example, organizations may determine that information systems must have the capability to log every file access both successful and unsuccessful, but not activate that capability except for specific circumstances due to the potential burden on system performance. Auditing requirements, including the need for auditable events, may be referenced in other security controls and control enhancements. Organizations also include auditable events that are required by applicable federal laws, Executive Orders, directives, policies, regulations, and standards. Audit records can be generated at various levels of abstraction, including at the packet level as information traverses the network. Selecting the appropriate level of abstraction is a critical aspect of an audit capability and can facilitate the identification of root causes to problems. Organizations consider in the definition of auditable events, the auditing necessary to cover related events such as the steps in distributed, transaction-based processes (e.g., processes that are distributed across multiple organizations) and actions that occur in service-oriented architectures. Related controls: AC-6, AC-17, AU-3, AU-12, MA-4, MP-2, MP-4, SI-4.
| ICS Supplemental Guidance: The organization may designate ICS events as audit events, requiring that ICS data and/or telemetry be recorded as audit data. | 7 | |||
| AU-3 | CONTENT OF AUDIT RECORDS | The information system generates audit records containing information that establishes what type of event occurred, when the event occurred, where the event occurred, the source of the event, the outcome of the event, and the identity of any individuals or subjects associated with the event. | Supplemental Guidance: Audit record content that may be necessary to satisfy the requirement of this control, includes, for example, time stamps, source and destination addresses, user/process identifiers, event descriptions, success/fail indications, filenames involved, and access control or flow control rules invoked. Event outcomes can include indicators of event success or failure and event-specific results (e.g., the security state of the information system after the event occurred). Related controls: AU-2, AU-8, AU-12, SI-11. |
| ICS Supplemental Guidance: Example compensating controls include providing an auditing capability on a separate information system. | 6 | |||
| AU-4 | AUDIT STORAGE CAPACITY | The organization allocates audit record storage capacity in accordance with [Assignment: organization-defined audit record storage requirements]. | Supplemental Guidance: Organizations consider the types of auditing to be performed and the audit processing requirements when allocating audit storage capacity. Allocating sufficient audit storage capacity reduces the likelihood of such capacity being exceeded and resulting in the potential loss or reduction of auditing capability. Related controls: AU-2, AU-5, AU-6, AU-7, AU-11, SI-4. |
| 2 | |||
| AU-4(1) | AUDIT STORAGE CAPACITY | TRANSFER TO ALTERNATE STORAGE | The information system off-loads audit records [Assignment: organization-defined frequency] onto a different system or media than the system being audited. | Supplemental Guidance: Off-loading is a process designed to preserve the confidentiality and integrity of audit records by moving the records from the primary information system to a secondary or alternate system. It is a common process in information systems with limited audit storage capacity; the audit storage is used only in a transitory fashion until the system can communicate with the secondary or alternate system designated for storing the audit records, at which point the information is transferred. |
ICS Supplemental Guidance: Legacy ICS are typically configured with remote storage on a separate information system (e.g., the historian accumulates historical operational ICS data and is backed up for storage at a different site). ICS are currently using online backup services and increasingly moving to Cloud based and Virtualized services. Retention of some data (e.g., SCADA telemetry) may be required by regulatory authorities.
| Rationale for adding AU-4 (1) to all baselines: Legacy ICS components typically do not have capacity to store or analyze audit data. The retention periods for some data, particularly compliance data, may require large volumes of storage. | 2 | ||
| AU-5 | RESPONSE TO AUDIT PROCESSING FAILURES | The information system: |
a. Alerts [Assignment: organization-defined personnel or roles] in the event of an audit processing failure; and
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .