Appendix_2 _NARA_IT_Security_Requirements.docx

DOCX document 274 KB Posted

Attached to
Presidential Libraries, Visitor Services System Federal contract opportunity
Solicitation number
NAMA-15-Q-0024
Issued by
National Archives and Records Administration

About this file

NARA IT Security Requirements

View the file

Other files for this federal contract opportunity

Other files attached to Presidential Libraries, Visitor Services System, newest first.
File Type Posted
NAMA-15-Q-0024_Amendment_002_Correction_to_Appendix_10_Final.doc DOC document
Appendix_10 _Current_Oniste_Hardware.xlsx XLSX spreadsheet
NAMA-15-Q-0024_Amendment_001_Questions_and_Answers_Final.doc DOC document
Appendix_10 _Current_Onsite_Hardware_Matrix.docx DOCX document
Appendix_9 _Presidential_Library_and_Museum_Addresses.docx DOCX document
Appendix_6 _NARA_DD.xlsx XLSX spreadsheet
NAMA-15-Q-0024_VSS_Attachments_1-13.docx DOCX document
Appendix_8 _Sample_Reports.zip ZIP file
Appendix_7 _LP_Attendance_Data.pdf PDF
Appendix_4 _NARA_CMDB.xlsx XLSX spreadsheet
Appendix_1 _NARA_SDLC.pdf PDF
Appendix_3 _NARA_CMP.docx DOCX document
Appendix_5 _NARA_VDD.docx DOCX document
Show all 13

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

NARA

IT Security Requirements

NATIONAL ARCHIVES AND RECORDS ADMINISTRATION

November 10, 2014

Version 6.0 Enterprise Architecture IT Security Requirement Version 6.0

SecA.Requirements.docx i November 10, 2014

Version Control Document version

Description of contents/revisions

Editor

Date

6.0
Revised entire document to reflect new NIST SP800-53Rev4 guidance
J. Appleman
11/10/14

Table of Contents

1.Introduction1
2.NARA IT Security Requirements2
2.1Access Control Requirements2
2.2Awareness and Training Requirements20
2.3Audit and Accountability Requirements22
2.4Security Assessment and Authorization Requirements31
2.5Configuration Management Requirements35
2.6Contingency Planning Requirements44
2.7Identification and Authentication Requirements51
2.8Incident Response Requirements59
2.9Maintenance Requirements65
2.10Media Protection Requirements70
2.11Physical and Environmental Protection Requirements74
2.12Security Planning Requirements82
2.13Security Program Requirements86
2.14Personnel Security Requirements90
2.15Risk Assessment Requirements94
2.16System and Services Acquisition Requirements97
2.17System and Communications Protection Requirements113
2.18System and Information Integrity Requirements130
3.NARA Privacy Controls143
3.1Authority and Purpose143
3.2Accountability, Audit, and Risk Management144
3.3Data Quality and Integrity146
3.4Data Minimization and Retention147
3.5Individual Participation and Redress148
3.6Security150
3.7Transparency150
3.8Use Limitation151
Appendix A: Requirements Traceability153
A.1 NIST Requirements for Federal Information153
A.2 OMB Requirements for Privacy within Federal Information153
A.3 ISOO Requirements for Safeguarding Classified Information154
A.4 GAO Requirements for Resources Management156
A.5 FISMA Requirements for Information Security Management157
A.6 ISO Requirements for IT Security Operations157

Enterprise Architecture IT Security Requirement Version 6.0

SecA.Requirements.docx 51 November 10, 2014

1. Introduction As expressed in the IT Security Domain Model, NARA has the following three major sources of IT security requirements:

· Needs for IT Security determined by NARA’s risk profile and based upon an analysis of NARA’s business and IT risk assessments;

· Needs for IT security specifically mandated by or implied by Federal laws, directives and guidelines; and

· Needs for IT security specifically stated by or implied by NARA’s IT Security Policies.

This release of NARA’s IT Security Architecture documents security requirements mandated by FIPS 200, Minimum Security Requirements for Federal Information Systems. The security controls expressed in this publication represents NISTS’s specification for minimum security requirements that must be met by Federal Agencies. The NIST 800 Series of computer security guidelines are published under the authority of the Federal Information Security Management Act (FISMA) of 2002. The security controls specified by NIST Special Publication 800-53 are intended to safeguard the confidentiality, integrity and availability of information as required under FISMA.

It is important to recognize OMB and NIST documents referenced in the IT Security Architecture are guidance documents or templates to be used by agencies to develop their own security architectures. They are not final products tailored for NARA and should not be directly utilized by NARA developers.

For example, NIST Special Publication 800-53 describes the following access controls on unsuccessful login attempts:

“The information system enforces a limit of [Assignment: organization-defined number] consecutive invalid access attempts by a user during a [Assignment: organization-defined time period] time period; and automatically [Selection: locks the account/node for an [Assignment: organization-defined time period], delays next login prompt according to [Assignment: organization-denied delay algorithm.]] when the maximum number of unsuccessful attempts is exceeded.”

The IT Security Architecture uses the above criteria to develop NARA’s own control objectives. These are then used to develop policies, requirements, mechanisms, and specifications used to implement the control. This provides a single, consistent source of NARA-wide policy and prevents each organization form developing individual interpretations of Federal guidance. NARA system developers should utilize NARA’s IT Security Architecture for their security requirements. NARA system developers should not independently develop their own security requirements based on their individual interpretations of federal guidance.

For reference purposes, all of NARA’s tailoring to the NIST controls are maintained in square brackets (e.g., “[“ and “]”).

2. NARA IT Security Requirements The IT Security Requirements are derived from the controls identified in NIST Special Publication (SP) 800-53 for unclassified information systems and classified information systems. The requirements for classified information systems were formerly derived from Director of Central Intelligence Directive (DCID) 6/3, but have since been merged into the Rev. 4 version of the NIST SP 800-53. NIST SP 800-53 represents the specific requirements that must be met to implement the control to the required level for confidentiality, integrity, and availability.

Most of the requirements apply to all of NARA or to all information systems. These will be stated as “NARA shall…” or “Each information system shall…” as appropriate. Other requirements only apply to information systems at a moderate or high level of confidentiality, integrity or availability. These requirements will be qualified as being “For high availability information systems” or “For moderate integrity information systems” or something similar. A few of the requirements are not mandated for any particular system, but can be implemented where data is “deemed by the NARA System Owner to require additional protection” to enhance a particular security control. While no information system is required to enhance security beyond the minimum required levels, if stronger security is desired, it may be enhanced using these controls and control enhancements. Additional requirements that apply to classified systems will be noted as such.

2.1 Access Control Requirements

AC-1. Access Control Policy and Procedures

P1
LOW AC-1
MOD AC-1
HIGH AC-1

AC-1. For all data, the NARA Office of Information Services (I) shall:

AC-1a. Develop, document and disseminate:

1. An access control policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among NARA entities, and compliance; and

2. Procedures to facilitate the implementation of the access control policy and associated access controls; and AC-1b. Review and update the current:

1. Access control policy at least annually; and

2. Access control procedures at least annually.

AC-2. Account Management

P1
LOW AC-2
MOD AC-2 (1) (2) (3) (4)
HIGH AC-2 (1) (2) (3) (4) (5) (11) (12) (13)

AC-2. For all data, the NARA System Owner shall:

AC-2a. Identify account types (i.e., individual, group, system, application, guest/anonymous, and temporary);

AC-2b. Assign account managers for information system accounts;

AC-2c. Establish conditions for group and role membership;

AC-2d. Specify authorized users of the information system, group and role membership, and access authorizations (i.e., privileges) and other attributes (as required) for each account;

AC-2e. Require approvals by ISSO and system owner for requests to create information system accounts;

AC-2f. Create, enable, modify, disable, and remove information system accounts in accordance with NARA 804, Information Technology (IT) Systems Security;

AC-2g. Monitor the use of, information system accounts;

AC-2h. Notify account managers:

1. When accounts are no longer required;

2. When users are terminated or transferred; and

3. When individual information system usage or need-to-know changes;

AC-2i. Authorize access to the information system based on:

1. A valid access authorization;

2. Intended system usage; and

3. Other attributes as required by the system functions;

AC-2j. Review accounts compliance with account management requirements [at least annually].

AC-2k. Establish a process for reissuing shared/group account credentials (if deployed) when individuals are removed from the group.

AC-2(1) For data requiring moderate or high confidentiality, the NARA System Owner shall employ automated mechanisms to support the management of information system accounts.

AC-2(2) For data requiring moderate or high confidentiality, the information system shall automatically disable temporary and emergency accounts after [a period not to exceed 15 days for unclassified information systems or 72 hours for classified information systems].

AC-2(3) For data requiring moderate or high confidentiality, the information system shall automatically disable inactive accounts after [a period not to exceed 365 days for unclassified information systems or 30 days for classified information systems].

AC-2(4) For data requiring moderate or high confidentiality, the information system shall automatically audit account creation, modification, disabling, and removal actions and shall notify, as required, appropriate individuals.

AC-2 (5) For data requiring high confidentiality, the NARA System Owner shall:

· Require that users log out when [15 minutes of inactivity have occurred]

· Determine normal time-of-day and duration usage for information system accounts;

· Monitor for atypical usage of information system accounts; and

· Report atypical usage to designated NARA officials.

AC-2(6) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall dynamically manage user privileges and associated access authorizations.

AC-2(7) For data deemed by the NARA System Owner to require this additional confidentiality protection, the NARA System Owner shall:

(a) Establish and administer privileged user accounts in accordance with a role-based access scheme that organizes information system and network privileges into roles;

(b) Monitor privileged role assignments; and

(c) Disable account when privileged role assignments are no longer appropriate.

AC-2(8) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall create [SSP-defined information system accounts] dynamically.

AC-2(9) For data deemed by the NARA System Owner to require this additional confidentiality protection, NARA shall only permit the use of shared/group accounts that meet [SSP-defined conditions for establishing shared/group accounts].

AC-2(10) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall terminate shared/group account credentials when members leave the group.

AC-2(11) For data requiring high confidentiality, the information system shall enforce [SSP-defined circumstances and/or usage conditions] for [SSP-defined information system accounts].

AC-2 (12) For data requiring high confidentiality, the NARA System Owner shall:

(a) Monitor information system accounts for [SSP-defined atypical use]; and

(b) Reports atypical usage of information system accounts to system operators, ISSO and System Owner.

AC-2 (13) For data For data requiring high confidentiality, the NARA System Owner shall disable accounts of users posing a significant risk within [SSP defined time period] of discovery of the risk.

AC-3. Access Enforcement

LOW AC-3
MOD AC-3
HIGH AC-3

AC-3. For all data, the information system shall enforce approved authorizations for logical access to the system and system resources in accordance with NARA applicable access control policy.

· The NARAnet GSS shall provide multifactor access control as a common control for remote and local access to the network. The authentication capability shall be available to externally hosted systems which restrict access to NARA account holders.

· Multifactor access mechanisms shall include credentials from HSPD 12 compliant PIV cards.

· Users with elevated security privileges shall access the system using a multi factor authentication mechanism that complies with applicable federal directives and NARA policy.

· Minor applications receive access enforcement as a service from the General Support System of which they are a part.

· If the security plan of a minor application requires auditing of the actions of users with elevated security privileges, those users shall authenticate using multi-factor mechanisms.

· Minor applications which contain PII enforce assigned authorizations for controlling access to the system in accordance with applicable policy AC-3(1) [Withdrawn: Incorporated into AC-6].

AC-3(2) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall enforce dual authorization for [SSP defined privileged commands and/or other SSP-defined actions].

AC-3(3) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall enforce [SSP-defined mandatory access control policies] over all subjects and objects where the policy specifies that:

(a) The policy is uniformly enforced across all subjects and objects within the boundary of the information system;

(b) A subject that has been granted access to information is constrained from doing any of the following;

(1) Passing the information to unauthorized subjects or objects;

(2) Granting its privileges to other subjects;

(3) Changing one or more security attributes on subjects, objects, the information system, or information system components;

(4) Choosing the security attributes and attribute values to be associated with newly created or modified objects; or

(5) Changing the rules governing access control; and

(c) [SSP-defined subjects] may explicitly be granted [SSP-defined privileges (i.e., they are trusted subjects)] such that they are not limited by some or all of the above constraints.

AC-3(4) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall enforce a Discretionary Access Control (DAC) over defined subjects and objects where the policy specifies that a subject who has been granted access to information can do one or more of the following:

(a) Pass the information to any other subjects or objects;

(b) Grant its privileges to other subjects;

(c) Change security attributes on subjects, objects, the information system, or the information system’s components;

(d) Choose the security attributes to be associated with newly created or revised objects; or

(e) Change the rules governing access control.

AC-3(5) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall prevent access to [SSP defined Information] except during secure, non-operable system states.

AC-3(6) [Withdrawn: Incorporated into MP-4 and SC-28].

AC-3 (7) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall enforce a role-based access control policy over defined subjects and objects and controls access based upon [SSP-defined roles and users authorized to assume such roles].

AC-3 (8) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall enforce the revocation of access authorizations resulting from changes to the security attributes of subjects and objects based on [SSP-defined rules governing the timing of revocations of access authorizations].

AC-3 (9) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall not release information outside of the established system boundary unless:

(a)The receiving [SSP-defined information system or system component] provides [SSP-defined security safeguards]; and
(b)[SSP-defined security safeguards] are used to validate the appropriateness of the information designated for release.

AC-3 (10) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall employ an audited override of automated access control mechanisms under [SSP-defined conditions].

AC-4. Information Flow Enforcement

P1
LOW Not Selected
MOD AC-4
HIGH AC-4

AC-4. For data requiring moderate or high confidentiality, the information system shall enforce approved authorizations for controlling the flow of information within the system and between interconnected systems in accordance with applicable policy.

AC-4 (1) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall enforce information flow control using explicit security attributes on information, source, and destination objects as a basis for flow control decisions.

AC-4 (2) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall enforce information flow control using protected processing domains (e.g., domain type-enforcement) as a basis for flow control decisions.

AC-4 (3) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall enforce dynamic information flow control based on policy that allows or disallows information flows based on changing conditions or operational considerations.

AC-4 (4) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall prevent encrypted data from bypassing content-checking mechanisms.

AC-4 (5) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall enforce [SSP-defined limitations] on embedding data types within other data types.

AC-4 (6) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall enforce information flow control [on SSP-defined metadata].

AC-4 (7) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall enforce [SSP-defined one-way flows] using hardware mechanisms.

AC-4 (8) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall enforce information flow control using [SSP-defined security policy filters] as a basis for flow control decisions for [SSP-defined information flows].

AC-4 (9) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall enforce the use of human review for [SSP-defined security policy filters] when the system is not capable of making an information flow control decision.

AC-4 (10) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall provide the capability for a privileged administrator to enable/disable [SSP-defined security policy filters] under [SSP-defined conditions].

AC-4 (11) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall provide the capability for a privileged administrator to configure [SSP-defined security policy filters] to support different security policies.

AC-4 (12) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system, when transferring information between different security domains, shall use [SSP-defined data type identifiers] to validate data essential for information flows decisions.

AC-4 (13) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system, when transferring information between different security domains, shall decompose information into [SSP-defined policy-relevant subcomponents] for submission to policy enforcement mechanisms.

AC-4 (14) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system, when transferring information between different security domains, shall implement [SSP-defined security policy filters] requiring fully enumerated formats that restrict data structure and content.

AC-4 (15) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system, when transferring information between different security domains, examines the information for the presence of [SSP-defined unsanctioned information] and prohibits the transfer of such information in accordance with the [NARA security policy].

AC-4 (16) [Withdrawn: Incorporated into AC-4].

AC-4 (17) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall uniquely identify and authenticate source and destination points by [SSP-defined: organization, system, application, individual] for information transfer.

AC-4 (18) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall bind security attributes to information using [SSP-defined binding techniques] to facilitate information flow policy enforcement.

AC-4 (19) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system, when transferring information between different security domains, shall apply the same security policy filtering to metadata as it applies to data payloads.

AC-4 (20) For data deemed by the NARA System Owner to require this additional confidentiality protection, the system owner shall employ [NARA-defined solutions in approved configurations] to control the flow of [SSP-defined information] across security domains.

AC-4 (21) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall separate information flows logically or physically using [SSP-defined mechanisms and/or techniques] to accomplish [SSP-defined required separations by types of information].

AC-4 (22) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall provide access from a single device to computing platforms, applications, or data residing on multiple different security domains, while preventing any information flow between the different security domains.

AC-5. Separation of Duties

P1
LOW Not Selected
MOD AC-5
HIGH AC-5

AC-5. For data requiring moderate or high confidentiality, the NARA System Owner shall:

AC-5a. Separate [SSP-defined duties of individuals];

AC-5b. Document separation of duties of individuals; and AC-5c. Define information system access authorizations to support separation of duties.

AC-6. Least Privilege

P1
LOW Not Selected
MOD AC-6 (1) (2) (5) (9) (10)
HIGH AC-6 (1) (2) (3) (5) (9) (10)

AC-6. For data requiring moderate or high confidentiality, the NARA System Owner shall employ the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with NARA missions and business functions.

AC-6 (1) For data requiring moderate or high confidentiality, the NARA System Owner shall explicitly authorize access to [SSP-defined list of security functions (deployed in hardware, software, and firmware) and security-relevant information].

AC-6 (2) For data requiring moderate or high confidentiality, the NARA System Owner shall require that users of information system accounts, or roles, with access to [SSP-defined list of security functions or security-relevant information], use non-privileged accounts, or roles, when accessing other system functions, and, if feasible, audits any use of privileged accounts or roles for such functions.

AC-6 (3) For data requiring high confidentiality, the NARA System Owner shall authorize network access to [SSP-defined privileged commands] only for compelling operational needs and documents the rationale for such access in the security plan for the information system.

AC-6(4) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall provide separate processing domains to enable finer-grained allocation of user privileges.

AC-6 (5) For data requiring moderate or high confidentiality, the NARA System Owner shall restrict privileged accounts on the information system to [SPP-defined personnel or roles].

AC-6 (6) For data deemed by the NARA System Owner to require this additional confidentiality protection, the NARA System Owner shall prohibit privileged access to the information system by non-NARA users.

AC-6 (7) For data deemed by the NARA System Owner to require this additional confidentiality protection, the System Owner shall:

(a)Review at [SSP-defined frequency] the privileges assigned to [SSP-defined roles or classes of users] to validate the need for such privileges; and
(b)Reassign or remove privileges, if necessary, to correctly reflect NARA mission/business needs.

AC-6 (8) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall prevent [SSP-defined software] from executing at higher privilege levels than users executing the software.

AC-6 (9) For data requiring moderate or high confidentiality, the information system shall audit the execution of privileged functions.

AC-6 (10) For data requiring moderate or high confidentiality, the information system shall prevent non-privileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures.

AC-7. Unsuccessful Login Attempts

P2
LOW AC-7
MOD AC-7
HIGH AC-7

AC-7. For all data, the information system shall:

AC-7a. Enforce a limit of [a maximum of 5 for unclassified information systems or 3 for classified information systems] consecutive invalid login attempts by a user during a [15 minute period]; and AC-7b. Automatically [lock the account/node for at least 15 minutes for unclassified information systems or 10 minutes for classified information systems] when the maximum number of unsuccessful attempts is exceeded.

AC-7(1) [Withdrawn: Incorporated into AC-7].

AC-7(2) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall purges/wipes information from [NARA defined mobile devices] based on [SSP-defined purging/wiping requirements/techniques] after [5] consecutive, unsuccessful device logon attempts.

AC-8. System Use Notification

P1
LOW AC-8
MOD AC-8
HIGH AC-8

AC-8. For all data, the information system shall:

AC-8a. Display to users [an approved system use notification message or banner] before granting access to the system that provides privacy and security notices consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance and states that:

· Users are accessing a U.S. Government information system;

· Information system usage may be monitored, recorded, and subject to audit;

· Unauthorized use of the system is prohibited and subject to criminal and civil penalties; and

· Use of the information system indicates consent to monitoring and recording;

AC-8b. Retain the notification message or banner on the screen until users acknowledge the usage conditions and take explicit actions to log on to or further access the information system; and AC-8c. For publicly accessible systems:

1. Display the system use information when appropriate, before granting further access;

2. Display references, if any, to monitoring, recording, or auditing that are consistent with privacy accommodations for such systems that generally prohibit those activities; and

3. Include a description of the authorized uses of the system.

AC-9. Previous Logon (Access) Notification

P0
LOW Not Selected
MOD Not Selected
HIGH Not Selected

AC-9. For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall notify the user, upon successful logon (access) to the system, of the date and time of the last logon (access).

AC-9 (1) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall notify the user, upon successful logon/access, of the number of unsuccessful logon/access attempts since the last successful logon/access.

AC-9 (2) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall notify the user of the number of [unsuccessful login attempts] during [the period since the last successful login/access attempt].

AC-9 (3) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall notify the user of change to [SSP-defined set of security-related changes to the user’s account] during [SSP-defined time period].

AC-9 (4) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall notify the user, upon successful logon (access), of the following additional information: [SSP-defined information to be included in addition to the date and time of the last logon (access)].

AC-10. Concurrent Session Control

P3
LOW Not Selected
MOD Not Selected
HIGH AC-10

AC-10. For data requiring high confidentiality, the information system shall limit the number of concurrent sessions for each system account to [a maximum of three (3) sessions].

AC-11. Session Lock

P3
LOW Not Selected
MOD AC-11 (1)
HIGH AC-11 (1)

AC-11. For data requiring moderate or high confidentiality, the information system shall:

Ac-11a. Prevent further access to the system by initiating a session lock after [30 minutes] of inactivity or upon receiving a request from a user; and AC-11b. Retain the session lock until the user reestablishes access using established identification and authentication procedures.

AC-11(1) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system conceals, via the session lock, information previously visible on the display with a publicly viewable image.

AC-12. Session Termination

P2
LOW Not Selected
MOD AC-12
HIGH AC-12

AC-12 . For data requiring moderate or high confidentiality, the information system automatically terminates a user session after [SSP-defined conditions or trigger events requiring session disconnect].

AC-12 (1) The information system shall:

(a) Provide a logout capability for user-initiated communications sessions whenever authentication is used to gain access to [SSP-defined information resources]; and

(b) Displays an explicit logout message to users indicating the reliable termination of authenticated communications sessions.

AC-13. Supervision and Review — Access Control AC-13 . [Withdrawn: Incorporated into AC-2 and AU-6].

AC-14. Permitted Actions without Identification or Authentication

P3
LOW AC-14
MOD AC-14
HIGH AC-14

AC-14. For all data, the NARA System Owner shall:

AC-14a. Identify [SSP-defined user actions] that can be performed on the information system without identification or authentication consistent with NARA missions/business functions; and AC-14b. Document and provide supporting rationale in the security plan for the information system, user actions not requiring identification and authentication.

AC-14(1) [Withdrawn: Incorporated into AC-14].

AC-15. Automated Marking AC-15 . [Withdrawn: Incorporated into MP-3].

AC-16. Security Attributes

P0
LOW Not Selected
MOD Not Selected
HIGH Not Selected

AC-16. For data deemed by the NARA System Owner to require this additional confidentiality protection, the System Owner shall:

AC-16a. Provide the means to associate [SSP-defined types of security attributes] having [SSP-defined security attribute values] with information in storage, in process, and/or in transmission;

AC-16b. Ensure that the security attribute associations are made and retained with the information;

AC-16c. Establish the permitted [SSP-defined security attributes] for [SSP-defined information systems]; and AC-16d. Determines the permitted [SSP-defined values or ranges] for each of the established security attributes.

AC-16 (1) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall dynamically associates security attributes with [SSP-defined subjects and objects] in accordance with [SSP-defined security policies] as information is created and combined.

AC-16 (2) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall provide authorized individuals (or processes acting on behalf of individuals) the capability to define or change the value of associated security attributes.

AC-16 (3) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall maintain the association and integrity of [SSP-defined security attributes] to [SSP-defined subjects and objects].

AC-16(4) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall support the association of [SSP-defined security attributes] with [SSP-defined subjects and objects] by authorized individuals (or processes acting on behalf of individuals).

AC-16 (5) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall displays security attributes in human-readable form on each object that the system transmits to output devices to identify [SSP-identified special dissemination, handling, or distribution instructions] using [SSP-identified human-readable, standard naming conventions].

AC-16 (6) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall allow personnel to associate, and maintain the association of [SSP-defined security attributes] with [SSP-defined subjects and objects] in accordance with [SSP-defined security policies].

AC-16 (7) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall provides a consistent interpretation of security attributes transmitted between distributed information system components.

AC-16 (8) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall implements [SSP-defined techniques or technologies] with [SSP-defined level of assurance] in associating security attributes to information.

AC-16 (9) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall ensures that security attributes associated with information are reassigned only via re-grading mechanisms validated using [SSP-defined techniques or procedures].

AC-16 (10) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall provides authorized individuals the capability to define or change the type and value of security attributes available for association with subjects and objects.

AC-17. Remote Access

P1
LOW AC-17
MOD AC-17 (1) (2) (3) (4)
HIGH AC-17 (1) (2) (3) (4)

AC-17. For all data, the NARA Office of Information Services (I) shall:

AC-17a. Establish and document usage restrictions, configuration/connection requirements, and implementation guidance for each type of remote access allowed; and AC-17b. Authorize remote access to the information system prior to allowing such connections.

AC-17 (1) For data requiring moderate or high confidentiality, the information system shall monitor and control remote access methods.

AC-17 (2) For data requiring moderate or high confidentiality, the information system shall implement cryptographic mechanisms to protect the confidentiality and integrity of remote access sessions.

AC-17 (3) For data requiring moderate or high confidentiality, the information system shall route all remote accesses through a [SSP-defined number] managed access control points.

AC-17 (4) For data requiring moderate or high confidentiality, the NARA Office of Information Services (I) shall:

(a) authorize the execution of privileged commands and access to security-relevant information via remote access only for [SSP-defined needs]; and

(b) document the rationale for such access in the security plan for the information system.

AC-17 (5) [Withdrawn: Incorporated into AC-17].

AC-17(6) For data deemed by the NARA System Owner to require this additional confidentiality protection, the NARA Office of Information Services (I) shall ensure that users protect information about remote access mechanisms from unauthorized use and disclosure.

AC-17(7) [Withdrawn: Incorporated into AC-3 ].

AC-17(8) [Withdrawn: Incorporated into CM-7 ].

AC-17 (9) For data deemed by the NARA System Owner to require this additional confidentiality protection, the System Owner shall provide the capability to expeditiously disconnect or disable remote access to the information system within [SSP-defined time period].

AC-18. Wireless Access

P1
LOW AC-18
MOD AC-18 (1)
HIGH AC-18 (1) (4) (5)

AC-18. For all data, the NARA Office of Information Services (I) shall:

AC-18a. Establish usage restrictions, configuration/connection requirements, and implementation guidance for wireless access;

AC-18b. Authorize wireless access to the information system prior to connection AC-18 (1) For data requiring moderate or high confidentiality, the information system shall protect wireless access to the system using authentication of [Selection (one or more): users; devices] and encryption.

AC-18(2) [Withdrawn: Incorporated into SI-4 ].

AC-18(3) For data deemed by the NARA System Owner to require this additional confidentiality protection, the NARA System Owner shall disable, when not intended for use, wireless networking capabilities internally embedded within information system components prior to issuance and deployment.

AC-18(4) For data requiring high confidentiality, the NARA Office of Information Services (I) shall identify and explicitly authorize users allowed to independently configure wireless networking capabilities.

AC-18(5) For data requiring high confidentiality, the NARA Office of Information Services (I) shall select radio antennas and calibrate transmission power levels to reduce the probability that usable signals can be received outside of NARA-controlled boundaries..

AC-19. Access Control for Mobile Devices

P1
LOW AC-19
MOD AC-19 (5)
HIGH AC-19 (5)

AC-19. For all data, the NARA Office of Information Services (I) shall:

AC-19a. Establish usage restrictions, configuration requirements, and implementation guidance for NARA-controlled mobile devices; and AC-19b. Authorize the connection of mobile devices to NARA information systems;

AC-19(1) [Withdrawn: Incorporated into MP-7].

AC-19(2) [Withdrawn: Incorporated into MP-7].

AC-19(3) [Withdrawn: Incorporated into MP-7].

AC-19(4) For data deemed by the NARA System Owner to require this additional confidentiality protection, the NARA Office of Information Services (I) shall:

(a) Prohibit the use of unclassified mobile devices in facilities containing information systems processing, storing, or transmitting classified information unless specifically permitted by the authorizing official; and

(b) Enforce the following restrictions on individuals permitted by the authorizing official to use unclassified mobile devices in facilities containing information systems processing, storing, or transmitting classified information:

(1) Connection of unclassified mobile devices to classified information systems is prohibited;

(2) Connection of unclassified mobile devices to unclassified information systems requires approval from the authorizing official;

(3) Use of internal or external modems or wireless interfaces within the unclassified mobile devices is prohibited; and

(4) Unclassified mobile devices and the information stored on those devices are subject to random reviews and inspections by [Office of Information Services (I)], and if classified information is found, the incident handling policy is followed.

(c) Restrict the connection of classified mobile devices to classified information systems in accordance with [NARA-defined security policies].

AC-19 (5) For data requiring moderate high confidentiality, NARA employs [Selection: full-device encryption; container encryption] to protect the confidentiality and integrity of information on [SSP-defined mobile devices].

AC-20. Use of External Information Systems

P1
LOW AC-20
MOD AC-20 (1) (2)
HIGH AC-20 (1) (2)

AC-20. For all data, the NARA Office of Information Services (I) shall establish terms and conditions, consistent with any trust relationships established with other organizations owning, operating, and/or maintaining external information systems, allowing authorized individuals to:

AC-20a. Access the information system from the external information systems; and AC-20b. Process, store, and/or transmit NARA-controlled information using the external information systems.

AC-20 (1) For data requiring moderate or high confidentiality, the NARA Office of Information Services (I) shall permit authorized individuals to use an external information system to access the information system or to process, store, or transmit NARA-controlled information only when the NARA Office of Information Services (I) has:

(a) Verified the implementation of required security controls on the external system as specified in the NARA Office of Information Services (I)’s information security policy and security plan; or

(b) Retained approved information system connection or processing agreements with the NARA entity hosting the external information system.

AC-20 (2) For data requiring moderate or high confidentiality, the NARA Office of Information Services (I) shall [restrict] the use of NARA-controlled portable storage media by authorized individuals on external information systems.

AC-20 (3) For data deemed by the NARA System Owner to require this additional confidentiality protection, the NARA Office of Information Services (I) shall [restrict] the use of non-NARA owned information systems, system components, or devices to process, store, or transmit NARA information.

AC-20 (4) For data deemed by the NARA System Owner to require this additional confidentiality protection, the NARA Office of Information Services (I) shall prohibit the use of [NARA-defined network accessible storage devises] in external information systems.

AC-21. Information Sharing

P2
LOW Not Selected
MOD AC-21
HIGH AC-21

AC-21. For data requiring moderate or high confidentiality, the NARA System Owner shall:

AC-21a. Facilitate information sharing by enabling authorized users to determine whether access authorizations assigned to the sharing partner match the access restrictions on the information for [SSP-defined information sharing circumstances where user discretion is required]; and AC-21b. Employ [SSP-defined automated mechanisms or manual processes] to assist users in making information sharing/collaboration decisions.

AC-21 (1) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall enforce information-sharing decisions by authorized users based on access authorizations of sharing partners and access restrictions on information to be shared.

AC-21 (2) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall implement information search and retrieval services that enforce [SSP-defined information sharing restrictions].

AC-22. Publicly Accessible Content

P3
LOW AC-22
MOD AC-22
HIGH AC-22

AC-22. For all data, the NARA Office of Information Services (I) shall:

AC-22a. Designate individuals authorized to post information onto a publicly accessible information system;

AC-22b. Train authorized individuals to ensure that publicly accessible information does not contain nonpublic information;

AC-22c. Review the proposed content of information prior to posting onto the publicly accessible information system to ensure that nonpublic information is not included; and AC-22d. Review the content on the publicly accessible NARA information system for nonpublic information [annually]; and removes such information, if discovered.

AC-23. Data Mining Protection

P0
LOW Not Selected
MOD Not Selected
HIGH Not Selected

AC-23. For data deemed by the NARA System Owner to require this additional confidentiality protection, the System Owner shall employ [SSP-defined data mining prevention and detection techniques] for [SSP-defined data storage objects] to adequately detect and protect against data mining.

AC-24 ACCESS CONTROL DECISIONS

P0
LOW Not Selected
MOD Not Selected
HIGH Not Selected

AC-24. For data deemed by the NARA System Owner to require this additional confidentiality protection, the System Owner shall establish procedures to ensure [SSP-defined access control decisions] are applied to each access request prior to access enforcement.

AC-24 (1) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall transmit [SSP-defined access authorization information] using [SSP-defined security safeguards] to [SSP-defined information systems] that enforce access control decisions.

AC-24 (2) For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall enforce access control decisions based on [SSP-defined security attributes] that do not include the identity of the user or process acting on behalf of the user.

AC-25 REFERENCE MONITOR

P0
LOW Not Selected
MOD Not Selected
HIGH Not Selected

AC-25. For data deemed by the NARA System Owner to require this additional confidentiality protection, the information system shall implement a reference monitor for [SSP-defined access control policies] that is tamperproof, always invoked, and small enough to be subject to analysis and testing, the completeness of which can be assured.

2.2 Awareness and Training Requirements

AT-1. Security Awareness and Training Policy and Procedures

P1
LOW AT-1
MOD AT-1
HIGH AT-1

AT-1. The NARA Office of Information Services (I) shall:

AT-1a. Develop, document, and disseminate, to NARA personnel:

1. A security awareness and training policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among NARA entities, and compliance; and

2. 2. Procedures to facilitate the implementation of the security awareness and training policy and associated security awareness and training controls; and AT-1b. Review and update the current:

1. Security awareness and training policy [at least annually]; and

2. Security awareness and training procedures [at least annually].

AT-2. Security Awareness Training

P1
LOW AT-2
MOD AT-2 (2)
HIGH AT-2 (2)

AT-2. For all data, the NARA Office of Information Services IT Security Staff (IT) shall provide basic security awareness training to information system users (including managers, senior executives, and contractors):

AT-2a. As part of initial training for new users;

AT-2b. When required by system changes; and AT-2c. [at least annually] thereafter.

AT-2(1) For all data, the NARA Office of Information Services IT Security Staff (IT) shall include practical exercises in security awareness training that simulate actual cyber attacks.

AT-2(2) For all data, NARA Office of Information Services IT Security Staff (IT) shall include security awareness training on recognizing and reporting potential indicators of insider threat.

AT-3. Role-Based Security Training

P1
LOW AT-3
MOD AT-3
HIGH AT-3

AT-3. For all data, the NARA Office of Information Services IT Security Staff (IT) shall provide role-based security-related training to personnel with assigned security roles and responsibilities:

AT-3a. Before authorizing access to the information system or performing assigned duties;

AT-3b. When required by information system changes; and AT-3c. [at least annually] thereafter.

AT-3(1) For data deemed by the NARA System Owner to require this additional integrity protection, the NARA Office of Information Services IT Security Staff (IT) shall provide [employees] with initial and [at least annually] training in the employment and operation of environmental controls.

AT-3(2) For data deemed by the NARA System Owner to require this additional integrity protection, the NARA Office of Information Services IT Security Staff (IT) shall provide [employees] with initial and [at least annually] training in the employment and operation of physical security controls.

AT-3(3) For data deemed by the NARA System Owner to require this additional integrity protection, the NARA Office of Information Services IT Security Staff (IT) shall include practical exercises in security training that reinforce training objectives.

AT-3(4) For data deemed by the NARA System Owner to require this additional integrity protection, the NARA Office of Information Services IT Security Staff (IT) shall provide training to its personnel on [Phishing/Spear Phishing, Shoulder surfing, Dumpster diving, Data mining, and Social Engineering] to recognize suspicious communications and anomalous behavior in NARA information systems.

AT-4. Security Training Records

P3
LOW AT-4
MOD AT-4
HIGH AT-4

AT-4. For all data, the NARA System Owner shall:

AT-4a. Document and monitor individual information system security training activities including basic security awareness training and specific information system security training; and AT-4b. Retain individual training records for [three years].

AT-5. Contacts with Security Groups and Associations AT-5. [Withdrawn: Incorporated into PM-15].

2.3 Audit and Accountability…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .