PAISC_Attachment A2.pdf
PDF 14 MB Posted
- Attached to
- Paying Agent-related Information Security Consultant (PAISC) Federal contract opportunity
- Solicitation number
- PBGC01-RP-12-0060
- Issued by
- Pension Benefit Guaranty Corporation
About this file
Attachment A2
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| FormSF30.pdf | ||
| PAISC_Q A.pdf | ||
| PAISC_Attachment B.pdf | ||
| PAISC_Attachment A1.pdf | ||
| PAISC_Attachment C.pdf | ||
| Request for Proposal.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Paying Agent-related Information Security Consultant (PAISC) Contract
PBGC Solicitation Number PBGC01-RP-12-0025
Attachment A2
This attachment includes the following documents (in this order) as listed in section C – 1.3.2.1
Enterprise Information Security Office (EISO) directives programs, and policies:
SE-STD-01-17: PBGC Life Cycle Security Standard SE-STD-01-18: PBGC Security Impact Analysis Standard SE-STD-01-19: PBGC Access Restrictions for Change Standard SE-STD-01-20: PBGC Physical and Environmental Security Standard SE-STD-01-21: PBGC Security Incident Handling Standard SE-STD-01-22: PBGC Security Audit Standard SE-STD-01-23: PBGC Information System Monitoring Standard SE-STD-01-24: PBGC Maintenance Security Standard SE-STD-01-25: PBGC Physical Access Standard SE-STD-01-26: PBGC Information System Connections Standard SE-STD-01-27: PBGC Identification and Authentication Standard SE-STD-01-28: PBGC Media Security Standard SE-STD-01-29: PBGC Security Training and Testing Standard SE-STD-01-30: PBGC System Protection Standard SE-STD-01-31: PBGC User-Installed Software Standard SE-STD-01-32: PBGC Access Control Standard SE-STD-01-33: PBGC Voice over Intranet Protocol Standard
This attachment also includes the following three documents (in this order) which are not listed in the original Request for Proposal, since they are newly published documents from PBGC’s Enterprise
Information Security Office:
SE-GDE-01-01: Security Authorization Guide SE-PRC-01-01: PBGC Security Awareness and Training Procedures SE-PRC-02-01: Security Incident Response Procedures
SE-STD-01-17
2011.12.06 Page 1 of 2
PBGC Life Cycle Security Standard
Purpose The PBGC Life Cycle Security Standard defines requirements related to life cycle support, developer configuration management, and developer security testing.
Scope This standard applies to all information systems used or operated by PBGC, a contractor of PBGC, or another organization on behalf of PBGC.
Authority/ References
• PBGC Cyber Security Policy
• PBGC Information Security Controls Matrix
• NIST SP 800-37, Revision 1, Guide for Applying the Risk Management
Framework to Federal Information Systems, February 2010, section 3.4
• NIST SP 800-53, Revision 3, SA-3
• NIST SP 800-53, Revision 3, SA-10
• NIST SP 800-53, Revision 3, SA-11
• NIST SP 800-64 Revision 2, Security Considerations in the Information System
Development Life Cycle, October 2008, section 3
Approving Body Governance Control Board (GCB)
Owner Enterprise Information Security Office (EISO)
Collaborator Information Technology and Business Modernization Department (ITBMD)
Implementer GSS Information System Owner or
Major Application Information System Owners / Information Owners or
Minor Application or Component Owners or
Vendors/Suppliers of Externally Hosted Systems
Standard Type Management
Control Number SE-STD-01-17 PBGC Life Cycle Security Standard
Standard This standard consists of the following requirements:
Life Cycle Support (SA-3)
1. PBGC manages the information system using its Information Technology
Solutions Cycle Methodology (ITSLCM), which includes information security considerations.
2. PBGC defines and documents information system security roles and responsibilities throughout the system development life cycle.
3. PBGC identifies individuals having information system security roles and responsibilities.
SE-STD-01-18
01.17.2012 Page 1 of 2
PBGC Security Impact Analysis Standard
Purpose The PBGC Security Impact Analysis Standard defines the requirement to analyze the potential security effects of changes to the information system.
Scope This standard applies to all information systems used or operated by PBGC, or by a contractor of PBGC, or another organization on behalf of PBGC.
Authority/ References
PBGC Cyber Security Policy PBGC Information Security Controls Manual (primary) NIST 800-53, Revision 3, CM-4
Approving Body Governance Coordination Board (GCB)
Owner Enterprise Information Security Office (EISO)
Collaborator Information System Security Officer (ISSO) Information System Owner (ISO) Release Manager Configuration Manager
Implementer GSS Information System Owner or Major Application Information System Owners / Information Owners or Minor Application or Component Owners or Vendors/Suppliers of Externally Hosted Systems
Standard Type Operational
Control Number SE-STD-01-18 Security Impact Analysis Standard
Standard This standard consists of the following requirements:
1. Security impact analyses must be conducted as a function of the PBGC Change Management process to determine potential security impacts of planned change(s) prior to change implementation.
2. Security impact analyses are conducted by personnel with information security responsibilities, such as system administrators, system security officers or managers, and system security engineers.
3. Individuals conducting security impact analyses have the appropriate skills and technical expertise to analyze the changes to information systems and their security ramifications.
4. Security impact analysis may include, for example, reviewing information system documentation such as the security plan to understand how specific security controls are implemented within the system and how the changes
SE-STD-01-19
01.17.2012
PBGC Access Restrictions for Change Standard
Purpose The PBGC Access Restrictions for Change Standard defines the requirement to define, document, approve, and enforce physical and logical access restrictions associated with changes to the information system.
Scope This standard applies to all information systems used or operated by PBGC, or by a contractor of PBGC, or another organization on behalf of PBGC.
Authority/ References
PBGC Cyber Security Policy PBGC Information Security Controls Manual (primary) PBGC Entrance on Duty and Separation Procedures for Federal and Contract
Employees PBGC Order GA-10-11, HSPD-12 Credential Issuance for Federal Employees and Contractors NIST 800-53, Revision 3, CM-5
Approving Body Governance Coordination Board (GCB)
Owner Enterprise Information Security Office (EISO)
Collaborator Information System Security Officer (ISSO) Information System Owner (ISO) Configuration Manager Facilities and Services Department (FASD)
Implementer FASD Security Personnel or GSS Information System Owner or Major Application Information System Owners / Information Owners or Minor Application or Component Owners or Vendors/Suppliers of Externally Hosted Systems
Standard Type Operational
Control Number SE-STD-01-19 Access Restrictions for Change Standard http://intranet/DirPolDel/Directives/PM_05_1.pdf http://intranet/DirPolDel/Directives/PM_05_1.pdf
SE-STD-01-20
01.17.2012 Page 1 of 4
PBGC Physical & Environmental Security
Purpose The PBGC Physical & Environmental Security Standard defines the requirements related to power equipment and power cabling; emergency shutoff, power, and lighting; fire and water damage protection; temperature and humidity controls;
equipment delivery and removal; alternate work sites; and location of information system components.
Scope This standard applies to all information systems used or operated by PBGC, or by a contractor of PBGC, or another organization on behalf of PBGC.
Authority/ References
PBGC Cyber Security Policy PBGC Information Security Controls Manual (primary) Federal, State and Local OSHA regulations and Fire and Life Safety codes NIST 800-53, Revision 3, PE-9 NIST 800-53, Revision 3, PE-10 NIST 800-53, Revision 3, PE-11 NIST 800-53, Revision 3, PE-12 NIST 800-53, Revision 3, PE-13 NIST 800-53, Revision 3, PE-14 NIST 800-53, Revision 3, PE-15 NIST 800-53, Revision 3, PE-16 NIST 800-53, Revision 3, PE-17 NIST 800-53, Revision 3, PE-18 NIST SP 800-46, Revision 1, Guide to Enterprise Telework and Remote
Access Security, June 2009
Approving Body Governance Coordiantion Board (GCB)
Owner Enterprise Information Security Office (EISO)
Collaborator IT Infrastructure Operations Department (ITIOD) Facilities and Services Department (FASD)
Implementer IT Infrastructure Operations Department (ITIOD) or
Facilities and Services Department (FASD) or
GSS Information System Owner or Major Application Information System Owners / Information Owners or Minor Application or Component Owners or
01.17.2012 Page 2 of 4
Vendors/Suppliers of Externally Hosted Systems
Standard Type Operational
Control Number SE-STD-01-20 PBGC Physical & Environmental Security Standard
Standard This standard consists of the following requirements:
Power Equipment and Power Cabling (PE-9)
1. Protect power equipment and power cabling for the information system from damage and destruction.
2. OIT & FASD employ redundant and parallel power cabling paths.
3. OIT & FASD employ automatic voltage controls for PBGC’s GSS and MA systems.
Emergency Shutoff (PE-10)
1. Provide the capability to shut off power to the information system or individual system components in emergency situations.
2. Place emergency shutoff switches or devices in PBGC’s information technology data centers to facilitate safe and easy access for personnel.
3. Protect the emergency power shutoff capability from unauthorized activation.
Emergency Power (PE-11)
1. Provide a short-term uninterruptible power supply to facilitate an orderly shutdown of the information system in the event of a primary power source loss.
2. OIT & FASD provide a long-term alternate power supply for the information system that is capable of maintaining minimally required operational capability in the event of an extended loss of the primary power source.
3. OIT & FASD provide a long-term alternate power supply for the information system that is self-contained and not reliant on external power generation.
Emergency Lighting (PE-12)
1. Employ and maintain automatic emergency lighting for the information system that activates in the event of a power outage or disruption and that covers emergency exits and evacuation routes within the facility.
2. OIT & FASD provide emergency lighting for all areas within the facility supporting essential missions and business functions.
NOTE: PBGC shall ensure that contracts with the building owners include provisions for employing and maintaining automatic emergency lighting as required by local building codes.
Fire Protection (PE-13)
1. Employ and maintain fire suppression and detection devices and systems for the information system that are installed and operating according to local building and fire codes.
NOTE: PBGC shall ensure that contracts are in place, either through the building owner or a private vendor, to employ and maintain fire suppression and detection systems as required by local building codes.
01.17.2012 Page 3 of 4
2. Employ fire detection devices/systems for the information system that activate automatically and notify the organization and emergency responders in the event of a fire.
3. Employ fire suppression devices/systems for the information system that provide automatic notification of any activation to the organization and emergency responders.
4. Employ an automatic fire suppression capability for the information system when the facility is not staffed on a continuous basis.
5. OIT & FASD ensure that the facility undergoes fire marshal inspections and promptly resolves identified deficiencies based on, at minimum, local jurisdiction requirements.
Temperature and Humidity Controls (PE-14)
1. Maintain temperature and humidity levels within the facility where the information system resides at a temperature of 70–73°F and relative humidity of 50 percent +/- 10 percent.
2. Monitor temperature and humidity levels continuously.
3. OIT & FASD employ automatic temperature and humidity controls in the facility to prevent fluctuations potentially harmful to the information system.
4. OIT & FASD employ temperature and humidity monitoring that provides an alarm or notification of changes potentially harmful to personnel or equipment.
Water Damage Protection (PE-15)
1. Protect the information system from damage resulting from water leakage by providing master shutoff valves that are accessible, working properly, and known to key personnel.
2. OIT & FASD employ mechanisms that, without the need for manual intervention, protect the information system from water damage in the event of a water leak.
Delivery and Removal (PE-16)
1. Authorize, monitor, and control information system components (e.g., laptops, servers, workstations, network devices, etc.) entering and exiting the facility and maintain records of those items. This requirement pertains only to delivery to and removal from the data center (entering and leaving federal possession).
Alternate Work Site (PE-17)
1. Employ appropriate security control protections at alternate work sites.
Appropriate is in regards to the level of system categorization. Since most of PBGC data and system are at "Moderate" the appropriate security levels will be to meet such control selections. This will be a common control at the agency level.
2. Assess, as feasible, the effectiveness of security controls at alternate work sites.
3. Provide a means for employees to communicate with information security personnel and FASD security personnel in case of security incidents or problems.
Location of Information System Components (PE-18)
1. Position information system components within the facility to minimize potential damage from physical and environmental hazards and to minimize
SE-STD-01-21
01.17.2012 Page 1 of 3
PBGC Security Incident Handling Standard
Purpose
The PBGC Security Incident Handling Standard defines the requirement to develop a detailed incident response plan; track and document information system security incidents; implement an incident handling capability for security incidents; require personnel to report suspected security incidents; and provide an incident response support resource.
Scope This standard applies to all information systems used or operated by PBGC, a contractor of PBGC, or another organization on behalf of PBGC.
Authority/ References
PBGC Cyber Security Policy PBGC Information Security Controls Matrix PBGC IM 10-3, Protecting Sensitive Information, 4/23/08 NIST 800-53, Revision 3, IR-4 NIST 800-53, Revision 3, IR-5 NIST 800-53, Revision 3, IR-6 NIST 800-53, Revision 3, IR-7 NIST 800-53, Revision 3, IR-8
NIST 800-61
Approving Body
Governance Coordination Board (GCB)
Owner Enterprise Information Security Office (EISO)
Collaborator Senior Agency Official for Privacy (SAOP) Facilities and Services Department (FASD) Office of General Counsel (OGC) IT Infrastructure Operations Department (ITIOD) Office of Inspector General (OIG)
Implementer Senior Agency Information Security Officer (SAISO) or GSS Information System Owner or Major Application Information System Owners / Information Owners or Minor Application or Component Owners or Vendors/Suppliers of Externally Hosted Systems
Standard Type
Operational
Control Number
SE-STD-01-21 PBGC Security Incident Handling Standard
SE-STD-01-21
01.17.2012 Page 2 of 3
Incident Handling (IR-4)
1. Monitor and implement an incident handling capability for security incidents that includes preparation, detection, analysis, containment, eradication, and recovery.
2. Coordinate incident handling activities with contingency planning activities.
3. Incorporate lessons learned from ongoing incident handling activities into incident response procedures, training, testing, and exercises, and implement the resulting changes accordingly.
4. Employ automated mechanisms to support the incident handling process, including an automated answering and/or ticketing system for the service desk, RSS and Atom feeds, subscriptions, distribution lists, etc.
Incident Monitoring (IR-5)
1. Track and document information system security incidents. All security incidents must be reported to the information system security officer (ISSO) or PBGC CERT.
2. The ISSO must maintain a log of all incidents that occur at PBGC for at least 3 years.
Information system owners must maintain logs of incident reports for at least 3 years.
3. Automated mechanisms must be used to help track security incidents.
Incident Reporting (IR-6)
1. Under IM 10-3 § 7, PBGC employees or contractors who become aware that sensitive PBGC information may have been lost or improperly accessed or disclosed, regardless of format, must immediately report their concern to their supervisor or the Contracting Officer’s Technical Representative (COTR), as appropriate, and to PBGC’s ISSO.
2. Report security incident information to designated authorities.
3. Employ automated mechanisms to assist in reporting security incidents.
Incident Response Assistance (IR-7)
1. The ISSO serves as the incident response support resource, integral to the PBGC incident response capability, offering advice and assistance to users of the information system for handling and reporting security incidents.
2. Employ automated mechanisms to increase the availability of incident response-related information and support.
Incident Response Plan (IR-8)
1. Develop an incident response plan that:
a. Provides the organization with a roadmap for implementing its incident response capability.
b. Describes the structure and organization of the incident response capability.
c. Provides a high-level approach for how the incident response capability fits into the overall organization.
d. Meets the unique requirements of the organization, which relate to mission, size, structure, and functions.
e. Defines reportable incidents.
f. Provides metrics for measuring the incident response capability within the organization.
g. Defines the resources and management support needed to effectively maintain and mature an incident response capability.
h. Is reviewed and approved by designated officials within the organization.
2. Distribute copies of the incident response plan to appropriate PBGC personnel.
3. Review and test the incident response plan annually.
SE-STD-01-22
PBGC Security Audit Standard
Purpose The PBGC Security Audit Standard defines the requirement to document audit generation requirements; employ effective audit record time stamps; document audit record retention time frames; develop and document audit review, analysis, and reporting requirements; employ audit reduction and report generation tools and techniques; allocate sufficient audit record storage capacity; protect audit information; and develop appropriate responses to audit processing failures.
Scope This standard applies to all information systems used or operated by PBGC or by a contractor of PBGC or another organization on behalf of PBGC.
Authority/ References
• PBGC Cyber Security Policy
• PBGC Information Security Control Matrix
• NIST 800-53, Revision 3, AU-2
• NIST 800-53, Revision 3, AU-3
• NIST 800-53, Revision 3, AU-4
• NIST 800-53, Revision 3, AU-5
• NIST 800-53, Revision 3, AU-6
• NIST 800-53, Revision 3, AU-7
• NIST 800-53, Revision 3, AU-8
• NIST 800-53, Revision 3, AU-9
• NIST 800-53, Revision 3, AU-11
• NIST 800-53, Revision 3, AU-12
Approving Body Technical Review Board (TRB)
Owner Enterprise Information Security Office (EISO)
Collaborator IT Infrastructure Operations Department (ITIOD)
Implementer GSS Information System Owner or
Major Application Information System Owners / Information Owners or
Minor Application or Component Owners or
Vendors/Suppliers of Externally Hosted Systems
Standard Type Technical
Control Number SE-STD-01-22 PBGC Security Audit Standard
Auditable Events (AU-2)
1. Determine, based on a risk assessment and mission and business needs, that the information system must be capable of auditing the following events:
a. Account creation, modification, disabling, and deletion;
b. Administrative permissions executed on user accounts (i.e., inclusion in access groups, reset of password, account lockout override);
c. Administrative permissions executed on system resources (i.e., addition of users or groups to access lists, creation of share points, creation of new access groups, change of access group permissions);
d. Failed login attempts and account lockout;
e. Use of “su,” “pu,” “root,” “administrator,” or equivalent accounts;
f. Activity log roll-over, deletion, or editing; and
g. All computer-readable data extracts from databases containing personally identifiable information (PII);
2. Coordinate the security audit function with other PBGC entities requiring audit-related information to enhance mutual support and to help guide the selection of auditable events;
3. Provide a rationale for why the listed auditable events are deemed to be adequate to support after-the-fact investigation of security incidents;
4. Determine, based on current threat information and ongoing risk assessment, which additional events are to be audited within the information system;
5. Review and update the list of auditable events at least annually or in the event of a major system change; and
6. Execution of privileged function events to be audited by the information system.
Content of Audit Records (AU-3)
1. Information systems must produce audit records that contain sufficient information that, at a minimum, establish what type of event occurred, when (date and time) it occurred, where it occurred, its source, its outcome (success or failure), and the identity of any user or subject associated with it. The following elements must be part of every audit record:
a. The date and time of the event;
b. The software or hardware component of the information system where the event occurred;
c. The type of event;
d. The subject identity (the user of the component in which the event occurred); and
e. The outcome (success or failure) of the event.
2. The information system includes the capability to capture more detailed information in the audit records for audit events identified by type, location, or subject.
Audit Storage Capacity (AU-4)
1. Allocate storage capacity for audit records, and configure auditing to reduce the likelihood that the capacity will be exceeded.
Response to Audit Processing Failures (AU-5)
1. Alert designated PBGC officials in the event of an audit processing failure; and
2. Take the following additional actions:
a. Once the information system reaches 75 percent of maximum audit record storage capacity, the system must be configured, preferably with automated mechanisms, to alert system personnel with a warning. This warning must be disseminated via email or page.
b. Once the maximum storage capacity for audit logs is reached or an audit failure occurs, the information system must overwrite the oldest audit records or automatically shut down in an effort to eliminate the chance of an occurrence in the absence of auditing and accountability.
The action taken will be consistent with the current PBGC record retention policy or any federal regulations governing the information system or application. The action taken and its justification will be documented in the SSP.
Audit Review, Analysis, and Reporting (AU-6)
1. Review and analyze information system audit records monthly for indications of inappropriate or unusual activity, and report findings to designated PBGC officials;
2. For information systems containing PII, use the monthly review of audit logs to help determine which data extracts must be deleted; and
3. Adjust the level of audit review, analysis, and reporting within the information system when there is a change in risk to PBGC operations, PBGC assets, individuals, other organizations, or the nation based on law enforcement information, intelligence information, or other credible sources of information.
Audit Reduction and Report Generation (AU-7)
1. The information system can perform audit reductions and generate reports;
and
2. The information system can automatically process audit records for events of interest based on selectable event criteria.
Time Stamps (AU-8)
1. All audit records must include time stamps that are synchronized system-wide using internal system clocks; and
2. The information system synchronizes internal information system clocks at least daily with authoritative Network Time Protocol (NTP) servers.
Protection of Audit Information (AU-9)
1. Audit logs and audit tools must be accessible only to authorized personnel.
Audit Record Retention (AU-11)
1. PBGC retains audit records for 2 years to support investigations of security incidents and to meet regulatory and PBGC information retention requirements.
Audit Generation (AU-12)
1. Provide audit record generation capability for the list of auditable events defined in AU-2 for information systems and applications;
2. Allow designated PBGC personnel to select which auditable events are to be audited by specific components of the system; and
3. Generate audit records for the list of audited events defined in AU-2 with the content as defined in AU-3.
Metrics FOR FUTURE USE
SE-STD-01-23
PBGC Information System Monitoring
Purpose The PBGC Information System Monitoring Standard defines the requirement to use tools and techniques to monitor events on the information system, detect attacks, and identify unauthorized use of the system. It covers deploying monitoring devices strategically within the information system to collect essential information and at ad hoc locations within the system to track specific types of transactions of interest. It also specifies the requirement to obtain legal opinion with regard to information system monitoring activities in accordance with applicable federal laws, Executive orders, directives, policies, or regulations.
Scope This standard applies to all information systems used or operated by PBGC, a contractor of PBGC, or another organization on behalf of PBGC.
Authority/ References
PBGC Cyber Security Policy PBGC Information Security Controls Matrix NIST 800-53, Revision 3, SI-4
Approving Body Governance Coordination Board (GCB)
Owner Enterprise Information Security Office (EISO)
Collaborator IT Infrastructure Operations Department (ITIOD) Information System Security Officer (ISSO) Information System Owner (ISO) Office of General Council (OGC) Senior Agency Information Security Officer (SAISO)
Implementer GSS Information System Owner or Major Application Information System Owners / Information Owners or Minor Application or Component Owners or Vendors/Suppliers of Externally Hosted Systems
Standard Type Operational
Control Number SE-STD-01-23 Information System Monitoring Standard
Standard This standard consists of the following requirements:
Information System Monitoring (SI-4)
1. Monitor events on the information system in accordance with PBGC policy and detect information system attacks.
SE-STD-01-24
PBGC Maintenance Security Standard
Purpose The PBGC Maintenance Security Standard defines the requirements to schedule, perform, document, and review records of maintenance and repairs on information system components; authorize, monitor, and control non-local maintenance and diagnostic activities; establish a process for authorizing maintenance personnel;
obtain maintenance support and spare parts for critical information system components; and approve, control, monitor the use of, and maintain on an ongoing basis information system maintenance tools.
Scope This standard applies to all information systems used or operated by PBGC, a contractor of PBGC, or another organization on behalf of PBGC.
Authority/ References
PBGC Cyber Security Policy PBGC Information Security Controls Matrix PBGC Order GA-10-03, Property Management PBGC Order IM-15-1, PBGC Records Management Program NIST 800-53, Revision 3, MA-2 NIST 800-53, Revision 3, MA-3 NIST 800-53, Revision 3, MA-4 NIST 800-53, Revision 3, MA-5 NIST 800-53, Revision 3, MA-6
Approving Body Governance Coordination Board (GCB)
Owner Enterprise Information Security Office (EISO)
Collaborator IT Infrastructure Operations Department (ITIOD) Facilities and Services Department (FASD)
Implementer GSS Information System Owner or Major Application Information System Owners / Information Owners or Minor Application or Component Owners or Vendors/Suppliers of Externally Hosted Systems
Standard Type Operational
Control Number SE-STD-01-24 PBGC Maintenance Security Standard
Standard This standard consists of the following requirements:
Controlled Maintenance (MA-2)
1. Schedule, perform, document, and review records of maintenance and repairs on information system components in accordance with manufacturer
SE-STD-01-24
or vendor specifications and/or PBGC requirements.
2. Control all maintenance activities, whether performed on-site or remotely and whether the equipment is serviced on-site or removed to another location.
3. Require that a designated official explicitly approve the removal of the information system or system components from PBGC facilities for off-site maintenance or repairs.
4. Sanitize equipment to remove all information from associated media before removal from PBGC facilities for off-site maintenance or repairs.
5. Check all potentially affected security controls to verify that the controls are still functioning properly following maintenance or repair actions.
6. Maintain maintenance records for information systems that include:
a. Date and time of maintenance
b. Name of the individual performing the maintenance
c. Name of escort
d. A description of the maintenance performed
e. A list of equipment removed or replaced (including identification numbers, if applicable)
f. Service level adherence (if any)
Maintenance Tools (MA-3)
1. Information system maintenance tools must be approved, controlled, monitored and maintained on an ongoing basis.
2. PBGC inspects all maintenance tools carried into a facility by maintenance personnel for obvious improper modifications.
3. PBGC checks all media containing diagnostic and test programs for malicious code before the media are used in the information system.
Non-Local Maintenance (MA-4)
1. Authorize, monitor, and control non-local maintenance and diagnostic activities.
2. The use of remote diagnostic tools on the information system must be approved by the Chief Information Officer (CIO) and described in the SSP.
3. Employ strong identification and authentication techniques in establishing non-local maintenance and diagnostic sessions.
4. If the remote maintenance session uses password-based authentication, the password for the information system must be changed following each remote maintenance service.
5. Maintain records for non-local maintenance and diagnostic activities;
6. Terminate all sessions and network connections when non-local maintenance is completed.
7. Audit non-local maintenance and diagnostic sessions, and have designated
PBGC personnel to review the maintenance records of the sessions; the ISSO shall review maintenance logs on a monthly basis.
8. Document, in the security plan for the information system, the installation and use of non-local maintenance and diagnostic connections. Non-local maintenance and diagnostic activities are those activities conducted by individuals communicating through a network—either an external network (e.g., the Internet) or an internal network. In contrast, local maintenance and diagnostic activities are those activities carried out by individuals physically present at the information system or information system component and not communicating across a network connection.
SE-STD-01-25
PBGC Physical Access Standard
Purpose The PBGC Physical Access Standard defines the requirements to develop and keep current a list of personnel with authorized access to the facility where the information systems reside; control physical access to information system distribution and transmission lines within organizational facilities; control physical access to information system output devices to prevent unauthorized individuals from obtaining the output; monitor and periodically review physical access to the information system; maintain and periodically review visitor access records; and enforce and verify physical access authorizations for all physical access points.
Scope This standard applies to all information systems used or operated by PBGC, a contractor of PBGC, or another organization on behalf of PBGC.
Authority/ References
PBGC Cyber Security Policy PBGC Information Security Controls Matrix PBGC Order GA-10-11, PBGC HSPD-12 Credential Issuance for Federal
Employees and Contractors PBGC Order GA-10-9, Display of PBGC Identification Badges NIST 800-53, Revision 3, PE-2 NIST 800-53, Revision 3, PE-3 NIST 800-53, Revision 3, PE-4 NIST 800-53, Revision 3, PE-5 NIST 800-53, Revision 3, PE-6 NIST 800-53, Revision 3, PE-7 NIST 800-53, Revision 3, PE-8
Approving Body Governance Coordination Board (GCB)
Owner Enterprise Information Security Office (EISO) Facilities and Services Department (FASD)
Collaborator IT Infrastructure Operations Department (ITIOD)
Implementer FASD Security Personnel or GSS Information System Owner or Major Application Information System Owners / Information Owners or Minor Application or Component Owners or Vendors/Suppliers of Externally Hosted Systems
Control Number SE-STD-01-25 PBGC Physical Access Standard
SE-STD-01-25
Physical Access Authorizations (PE-2)
1. Develop and keep current a list of personnel with authorized access to the facility where the information system resides, except for areas within the facility officially designated as publicly accessible.
2. Issue authorization credentials.
3. Review and approve the access list and authorization credentials at least annually, removing personnel no longer requiring access.
Physical Access Control (PE-3)
1. Enforce physical access authorizations for all physical access points (including designated entry and exit points) to the facility where the information system resides, except for areas within the facility officially designated as publicly accessible.
2. Verify individual access authorizations before granting access to the facility;
3. Control entry to the facility containing the information system using physical access devices and/or guards.
4. Control access to areas officially designated as publicly accessible in accordance with the organization’s assessment of risk.
5. Secure keys, combinations, and other physical access devices.
6. Inventory physical access devices at least annually.
7. Change combinations every 6 months and when keys are reissued.
Maintain a log of keys issued. Require the use of a Key Request form to demonstrate management approval prior to issuing a new key.
Access Control for Transmission Medium (PE-4)
1. Control physical access to information system distribution and transmission lines within PBGC facilities.
Access Control for Output Devices (PE-5)
1. Control physical access to information system output devices to prevent unauthorized individuals from obtaining the output.
Monitoring Physical Access (PE-6)
1. Monitor physical access to the information system to detect and respond to physical security incidents.
2. Review physical access logs annually and review all access security control systems for inactivity, monthly.
3. Coordinate results of reviews and investigations with the organization’s incident response capability.
4. Monitor real-time physical intrusion alarms and surveillance equipment.
Visitor Control (PE-7)
1. Control physical access to the information system by authenticating visitors before authorizing access to the facility where the information system resides, except for areas designated as publicly accessible.
2. Escort visitors and monitor visitor activity.
Access Records (PE-8)
1. Maintain records of visitor access to the facility where the information system resides, except for areas within the facility officially designated as publicly accessible.
SE-STD-01-26
PBGC Information System Connections Standard
Purpose The PBGC Information System Connections Standard defines the requirement to authorize connections from a PBGC information system to other information systems outside the authorization boundary by using interconnection security agreements (ISAs). It also defines the requirement to monitor the information system connections to verify enforcement of security requirements.
Scope This standard applies to all information systems used or operated by PBGC, a contractor of PBGC, or another organization on behalf of PBGC.
Authority/ References
• PBGC Cyber Security Policy
• PBGC Information Security Controls Matrix
• NIST 800-47, Security Guide for Interconnecting Information Technology
Systems
• NIST 800-53, Revision 3, CA-3
Approving Body Governance Control Board (GCB)
Owner Enterprise Information Security Office (EISO)
Collaborator Information System Security Officer (ISSO) Information System Owner (ISO) Authorizing Official (AO)
Implementer GSS Information System Owner or
Major Application Information System Owners / Information Owners or
Minor Application or Component Owners or
Vendors/Suppliers of Externally Hosted Systems
Standard Type Management
Control Number SE-STD-01-26 Information System Connections Standard
Standard This standard consists of the following requirements:
Information System Connections (CA-3)
1. Authorize connections from the information system to other information systems outside the authorization boundary by using Interconnection Security Agreements.
2. Document, for each connection, the interface characteristics, security requirements, and nature of the information communicated. This applies to
SE-STD-01-27
PBGC Identification and Authentication Standard
Purpose The PBGC Identification and Authentication Standard defines the requirement to uniquely identify and authenticate PBGC users; uniquely identify and authenticate specific types of devices before establishing a connection; manage information system identifiers for users and devices by receiving authorization from a designated PBGC official; manage information system authenticators for users and devices by verifying their identity; and uniquely identify and authenticate non-PBGC users.
Scope This standard applies to all information systems used or operated by PBGC or by a contractor of PBGC or another organization on behalf of PBGC.
Authority/ References
• PBGC Cyber Security Policy
• PBGC Information Security Controls Matrix
• NIST 800-53, Revision 3, IA-2
• NIST 800-53, Revision 3, IA-3
• NIST 800-53, Revision 3, IA-4
• NIST 800-53, Revision 3, IA-5
• NIST 800-53, Revision 3, IA-6
• NIST 800-53, Revision 3, IA-8
• NIST 800-63, Electronic Authentication Guideline
• Office of Management and Budget (OMB) Memorandum 04-04, E-
Authentication Guidance for Federal Agencies
• OMB Memorandum 07-11, Implementation of Commonly Accepted Security
Configurations for Windows Operating Systems
Approving Body Technical Review Board (TRB)
Owner Enterprise Information Security Office (EISO)
Collaborator IT Infrastructure Operations Department (ITIOD)
Implementer GSS Information System Owner or
Major Application Information System Owners / Information Owners or
Minor Application or Component Owners or
Vendors/Suppliers of Externally Hosted Systems
Standard Type Technical
Control Number SE-STD-01-27 PBGC Identification and Authentication Standard
Standard This standard consists of the following requirements:
Identification and Authentication (Organizational Users) (IA-2)
1. Uniquely identify and authenticate PBGC users or processes acting on behalf of PBGC users;
2. Use multifactor authentication for network access to privileged accounts;
3. Use multifactor authentication for local access to privileged accounts; and
4. Use replay-resistant authentication mechanisms, such as challenges, time synchronous authentication or challenge-response one-time authenticators for network access to privileged accounts.
Device Identification and Authentication (IA-3)
1. Uniquely identify and authenticate all network devices (e.g., network switches, routers, servers, workstations, laptops, printers, other peripheral devices, smart phones, tablet PCs, etc.) before establishing a connection.
Identifier Management (IA-4)
1. Manage information system identifiers for users and devices by:
a. Receiving authorization from a designated PBGC official to assign a user or device identifier;
b. Selecting an identifier that uniquely identifies an individual or device;
c. Assigning the user identifier to the intended party, or the device identifier to the intended device;
d. Permanently preventing reuse of user or device identifiers; and
e. Disabling the user identifier after 21 days of inactivity.
Authenticator Management (IA-5)
1. Manage information system authenticators for users and devices by:
a. Verifying, as part of the initial authenticator distribution, the identity of the individual and/or device receiving the authenticator;
b. Establishing initial authenticator content for authenticators defined by
PBGC;
c. Ensuring that authenticators have sufficient strength of mechanism for their intended use;
d. Establishing and implementing administrative procedures for initial authenticator distribution; for lost, compromised, or damaged authenticators; and for revoking authenticators;
e. Changing default content of authenticators upon information system installation;
f. Establishing a maximum 90 day lifetime restriction for authenticators (if appropriate);
g. Changing or refreshing authenticators at least quarterly;
h. Protecting authenticator content from unauthorized disclosure and modification; and
i. Requiring users to take, and having devices implement, specific measures to safeguard authenticators.
2. For password-based authentication:
a. Require admin-level account passwords to be at least 13 characters long, user-level account passwords to be at least 10 characters long, and to use characters from each of the following categories:
1. Uppercase letters (A, B, C, …, Z)
2. Lowercase letters (a, b, c, …, z)
3. Special characters (!, @, #, $, %, ^, &, *, etc.)
4. Numbers (0,1, 2, …, 9)
b. Require at least one changed character when new passwords are created;
c. Encrypt or hash passwords in storage and in transmission;
d. Enforce password lifetime restrictions of 1 day minimum and 90 days maximum; and
e. Prohibit password reuse for 15 generations.
3. For public key infrastructure (PKI)-based authentication, the information system:
a. Validates certificates by constructing a certification path (with status information) to an accepted trust anchor;
b. Enforces authorized access to the corresponding private key; and
c. Maps the authenticated identity to the user account.
4. Require that the registration process to receive Homeland Security Presidential Directive (HSPD)-12 smartcards and other PKI authenticators be carried out in person before a designated registration authority with authorization by a designated PBGC official (e.g., a supervisor).
Authenticator Feedback (IA-6)
1. Obscure feedback of authentication information during the authentication process to protect the information from possible exploitation or use by unauthorized individuals.
Identification and Authentication (Non-Organizational Users) (IA-8)
1. Uniquely identify and authenticate to the information system non-PBGC users, or processes acting on behalf of non-PBGC users.
SE-STD-01-28
PBGC Media Security Standard
Purpose The PBGC Media Security Standard defines the requirements to restrict access to digital and non-digital media; mark, in accordance with PBGC policies and procedures, removable information system media and output; physically control and securely store digital and non-digital media; protect and control types of digital and non-digital media during transport; and sanitize information system media, both digital and non-digital, before disposal or release.
Scope This standard applies to all information systems used or operated by PBGC, a contractor of PBGC, or another organization on behalf of PBGC.
Authority/ References
PBGC Cyber Security Policy PBGC Information Security Controls Matrix PBGC Order GA-10-03, Property Management NIST 800-53, Revision 3, MP-2 NIST 800-53, Revision 3, MP-3 NIST 800-53, Revision 3, MP-4 NIST 800-53, Revision 3, MP-5 NIST 800-53, Revision 3, MP-6
Approving Body Governance Coordination Board (GCB)
Owner Enterprise Information Security Office (EISO)
Collaborator IT Infrastructure Operations Department (ITIOD)
Implementer GSS Information System Owner or Major Application Information System Owners / Information Owners or Minor Application or Component Owners or Vendors/Suppliers of Externally Hosted Systems
Standard Type Operational
Control Number SE-STD-01-28 PBGC Media Security Standard
Standard This standard consists of the following requirements:
Media Access (MP-2)
1. Restrict access to digital and non-digital media to authorized users.
2. Employ automated mechanisms to restrict access to media storage areas and to audit attempted and successful access events.
Media Marking (MP-3)
SE-STD-01-29
01.26.2012 Page 1 of 3
PBGC Security Training and Testing
Purpose The PBGC Security Training and Testing Standard defines the requirements related to security awareness training, role-based security training, security training records, contingency training, contingency plan testing and exercises, incident response training, and incident response testing and exercises.
Scope This standard applies to all information systems used or operated by PBGC, a contractor of PBGC, or another organization on behalf of PBGC.
Authority/ References
PBGC Cyber Security Policy PBGC Information Security Controls Matrix FCD-1, Federal Continuity Directive-1 HSPD-20, Homeland Security Presidential Directive-20 for a National
Continuity Policy NIST 800-53, Revision 3, AT-2 NIST 800-53, Revision 3, AT-3 NIST 800-53, Revision 3, AT-4 NIST 800-53, Revision 3, CP-3 NIST 800-53, Revision 3, CP-4 NIST 800-53, Revision 3, IR-2 NIST 800-53, Revision 3, IR-3
Approving Body Governance Coordination Board (GCB)
Owner Enterprise Information Security Office (EISO)
Collaborator Senior Agency Official for Privacy (SAOP) Facilities and Services Department (FASD)
Implementer Senior Agency Information Security Officer (SAISO) or Facilities and Services Department (FASD) or GSS Information System Owner or Major Application Information System Owners / Information Owners or Minor Application or Component Owners or Vendors/Suppliers of Externally Hosted Systems
SE-STD-01-29
01.26.2012 Page 2 of 3
Control Number SE-STD-01-29 PBGC Security Training and Testing Standard
Security Awareness (AT-2)
1. Provide basic security awareness training to all information system users, including managers, senior executives, and contractors:
a. As part of initial training for new users
b. When required by system changes
c. Annually thereafter
Security Training (AT-3)
1. Provide role-based security-related training:
a. Before authorizing access to the system or performing assigned duties
b. When required by system changes
c. Annually thereafter
Security Training Records (AT-4)
1. Document and monitor individual information system security training activities, including basic security awareness training and specific information systems security training.
2. Retain individual training records in accordance with the PBGC records retention schedule.
Contingency Training (CP-3)
1. Train personnel in their contingency roles and responsibilities with respect to the information system.
2. Provide refresher training annually.
Contingency Plan Testing and Exercises (CP-4)
1. Test and/or exercise the contingency plan for the information system annually, using PBGC-defined and information system-specific tests and exercises to determine the plan’s effectiveness and PBGC’s readiness to execute the plan.
2. Review the contingency plan test or exercise results and initiate corrective actions.
3. Coordinate contingency plan testing and/or exercises with organizational elements responsible for related plans.
Incident Response Training (IR-2)
1. Train personnel in their incident response roles and responsibilities with respect to the information system.
a. Minimum of 2 hours of incident response training required.
2. Provide refresher training annually.
Incident Response Testing and Exercises (IR-3)
1. Test and/or exercise the incident response capability for the information system annually using scenario-based exercises to determine the incident response effectiveness.
2. Document the results of incident response testing and exercises.
SE-STD-01-30
PBGC System Protection Standard Purpose The PBGC System Protection Standard defines the requirement to protect the authenticity of communications sessions and the confidentiality and integrity of information at rest, and to terminate the network connection associated with a communications session at the end of the session or after a period of inactivity.
Scope This standard applies to all information systems used or operated by PBGC, or by a contractor of PBGC or another organization on behalf of PBGC.
Authority/ References
• PBGC Cyber Security Policy
• PBGC Information Security Controls Matrix
• NIST 800-53, Revision 3, SC-10
• NIST 800-53, Revision 3, SC-23
• NIST 800-53, Revision 3, SC-28
Approving Body Technical Review Board (TRB)
Owner Enterprise Information Security Office (EISO)
Collaborator IT Infrastructure Operations Department (ITIOD)
Implementer GSS Information System Owner or
Major Application Information System Owners / Information Owners or
Minor Application or Component Owners or
Vendors/Suppliers of Externally Hosted Systems
Standard Type Technical
Control Number SE-STD-01-30 PBGC System Protection Standard
Standard This standard consists of the following requirements:
Network Disconnect (SC-10)
1. Terminate all network connections associated with a communications session, with the exception of service account connections, at the end of the session or after 30 minutes of inactivity.
Session Authenticity (SC-23)
1. Provide mechanisms to protect the authenticity of communications sessions
(as opposed to packet-level protection).
Protection of Information at Rest (SC-28)
SE-STD-01-30
1. Protect the confidentiality and integrity of information at rest.
SE-STD-01-31
PBGC User-Installed Software Standard
Purpose The PBGC User-Installed Software Standard defines the requirement to enforce explicit rules governing the installation of software by users.
Scope This standard applies to all information systems used or operated by PBGC, or by a contractor of PBGC or another organization on behalf of PBGC.
Authority/ References
• PBGC…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .