Attachment_11_-_Security_Policies_&_Procedures_Peace_Corps_Manual_Section_542.pdf

PDF 525 KB Posted

Attached to
Peace Corps Learning Management System Federal contract opportunity
Solicitation number
PC-17-Q-030
Issued by
Peace Corps

About this file

Attachment 11 Security Policies & Procedures Peace Corps Manual Section 542

View the file

Other files for this federal contract opportunity

Other files attached to Peace Corps Learning Management System, newest first.
File Type Posted
Solicitation_PC-17-Q-030_Amendment_0003.docx DOCX document
Solicitation_PC-17-Q-030_Amendment_0002.docx DOCX document
RFQ_Questions_and_Answers_4.13.17.xlsx XLSX spreadsheet
ATTACHMENT_2_-_Functional_and_Technical_Requirements_(Final).xlsx XLSX spreadsheet
Solicitation_PC-17-Q-030_Amendment_0001_Posted_3.29.docx DOCX document
RFQ_Questons_and_Answers.docx DOCX document
ATTACHMENT_4_-_SF-182_Requirements.docx DOCX document
Attachment_9_-_Offeror_Representation_and_Certifications.docx DOCX document
ATTACHMENT_6_-_Plugins_overview.docx DOCX document
Solicitation_PC-17-Q-030.docx DOCX document
ATTACHMENT_2_-_Functional_and_Technical_Requirements_(Final).xlsx XLSX spreadsheet
ATTACHMENT_3_-_Data_Migration.docx DOCX document
ATTACHMENT_5_-_Workflows.docx DOCX document
Attachment_14_-_Form_SF_1449.pdf PDF
Attachment_13_Solution_Delivery_Framework_SOP_v5.pptx PPTX presentation
Attachment_10_-_Peace_Corps_Manual_Section_899,_Breach_Notification_Response_Plan.docx DOCX document
Attachment_8_Domestic_Vendor_File_Form.pdf PDF
Attachment_1_Pricing_Table.xlsx XLSX spreadsheet
Attachment_7_-_Demonstration_Requirements.docx DOCX document
Show all 19

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Procedures to Support MS 542:

Information Security

Version 1.0

November 25, 2014

Procedures to Support MS 542: Information Security

Table of Contents

1.0 Purpose

2.0 Applicability

3.0 Definitions

4.0 Procedure Objectives

5.0 Rules of Behavior

6.0 External Connections

7.0 Systems Access and Account Management

8.0 Wireless Access

9.0 Computer Security Incident Response Capability

10.0 Emerging Technologies and Electronic Communications

11.0 Malicious Code Prevention and Corrective Action

12.0 Internet-Based Services

13.0 IT Security Awareness Training and Education Program

14.0 System Assessment & Authorization (A&A)

15.0 Peace Corps Headquarters IT Sensitive Areas Access

Appendix A: Definitions

1.0 Purpose

The procedures in this document set the minimum continuous monitoring and practices required to support the Peace Corps’ policy (MS 542) that governs the security of the agency’s information and computer systems. The goal of these procedures is to ensure consistent protection confidentiality, integrity, and availability of the agency’s information and computer systems. The procedures provide the framework for supporting Peace Corps’ information security policy and related Office of the Chief Information Officer (OCIO) standards and security requirements. Detailed procedures may be documented in Standard Operating Procedures (SOPs).

2.0 Applicability

These procedures support Peace Corps Policy MS 542. Both documents are written in compliance with federal laws, requirements, regulations, and guidance governing information security. This includes the Federal Information Security Management Act of 2002 (FISMA), National Institute of Standards and Technology (NIST) Special Publications, Office of Management and Budget (OMB) Circulars and Memorandums, and Federal Information Processing Standards (FIPS) Publications.

The procedures apply to the Peace Corps:

• Information resources and systems as defined in MS 542.

• IT services, systems, databases, applications, mobile devices, and networks that create, collect, process, store, transmit, or provide access to agency information.

• Personnel who have responsibility for the budgeting, procurement, development, administration, operation, assessment, authorization, and contractual obligation for agency information systems.

3.0 Definitions

Information Security terms used in this document are defined in Appendix A, along with those defined here:

• Authorizing Official (AO): A senior (federal) official or executive with the authority to formally assume responsibility for operating an information system at an acceptable level of risk to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation.

• Information System: A discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information. Note: Information systems also include specialized systems, such as industrial/process control systems, telephone switching and private branch exchange (PBX) systems, and environmental control systems.

• Information System Security Manager (ISSM): A security expert who works closely with their assigned system Authorizing Official (AO) to ensure that the AO understands and accepts the appropriate level of system risk and security posture.

• System Owner (SO): The official responsible for the overall procurement, development, integration, modification, operation and maintenance, and disposal of an information system.

4.0 Procedure Objectives

By using these procedures, Peace Corps staff will be able to ensure:

• Availability by protecting against intentional or accidental attempts to deny legitimate users access to information or systems.

• Integrity of Information by protecting against unauthorized alteration or manipulation that could compromise accuracy, completeness, and reliability.

• Integrity of Systems by protecting against unauthorized alteration or use that could jeopardize system reliability or make systems accessible to unauthorized individuals or groups.

• Confidentiality of Information by protecting information of Volunteers, trainees, personnel and the agency against unauthorized access or use.

• Accountability by tracing actions to their source through non-repudiation, deterrence, intrusion prevention, security monitoring, recovery, and legal admissibility of records.

• Assurance by developing confidence that technical and operational security measures work as intended by providing intended functionality while preventing undesired actions.

5.0 Rules of Behavior

All users who have access to Peace Corps information and computer systems are required to follow the Rules of Behavior for General Users. Users who have elevated/privileged access shall also adhere to Rules of Behavior for Privileged Users.

6.0 External Connections

These procedures apply to all Peace Corps owned, leased, and operated computers and networks, including stand-alone and laptop computers, smart phones, thumb drives, or any other mobile device capable of creating, collecting, processing, storing, and/or aggregating or transmitting information. Connections to the Peace Corps environment shall be approved by the OCIO and meet minimal security standards.

6.1 Basic Security Measures

External connections require physical and/or logical firewalls and anti-virus software to be in place prior to connectivity. There shall be a means to ensure that anti-virus software is kept http://inside.peacecorps.gov/index.cfm?viewDocument&document_id=46795&filetype=docx http://inside.peacecorps.gov/index.cfm?viewDocument&document_id=46796&filetype=doc current. Additionally, a Memorandum of Understanding (MOU) or Interconnection Security Agreement (ISA) that sets the terms, configurations, and dates for the connections shall be agreed to by both the Peace Corps and the connecting organization.

6.2 External Connections Inventory

All Peace Corps offices that have established external connections shall, at least annually, (until automated means to inventory these connections are available), conduct an inventory of external connections and report them to the OCIO Director, IT Security Assurance and Compliance.

6.3 Memorandum of Understanding (MOU)

The MOU between the Peace Corps and a non-Peace Corps organization shall include:

a. A list of interconnected computer systems, including the Internet.

b. A list of unique system identifiers, if appropriate.

c. The name of each system.

d. The name of the organization owning each non-Peace Corps system.

e. The type of interconnection (e.g., TCP/IP, Dial, SNA).

f. A short summary of major concerns or considerations regarding the interconnection.

g. The name and title of authorizing management officials for both Peace Corps and the non-Peace Corps organization.

h. The signature of authorizing management officials for both Peace Corps and the non-

Peace Corps organization.

i. A list of any Privacy Act systems of records, if applicable.

j. The sensitivity level of each system.

k. A description of the interaction among systems.

l. Rules of behavior and any security concerns.

7.0 Systems Access and Account Management

Information Systems Access Management Procedures provide least privilege access for managing three distinctive types of accounts: general users, privileged users/system administrators, and Service Accounts. The goal is to prevent unauthorized information and computer systems access. Access management helps to protect the availability, integrity, and confidentiality of information technology (IT) assets. The OCIO defines and manages the procedures for account access for the Peace Corps technologies. These procedures include:

• The process of requesting, establishing, and issuing system and user accounts (on boarding).

• Reviewing system and users’ accounts and access authorizations.

• Assigning and removing user roles and permissions.

• Managing user identity and authentication.

• The process of disabling system and user accounts (off boarding).

7.1 Preparation for Systems Access

Once Safety and Security authorizes an individual for workplace access, (PC401A - Workplace Access Authorization Form), Human Resources (HR) emails the appropriate Business Unit Point of Contact (i.e., Staffing Analyst), requesting creation of a new account record in the Peace Corps Personnel Tracking System (PTS). All new personnel/users must complete OCIO’s Self- Directed IT Orientation packet, information security training, and if applicable, the Use of Mobile IT Device training. Each user is also required to read, acknowledge, and sign the Rules of Behavior appropriate for the user’s level of system access. (i.e., Rules of Behavior for Volunteers/Trainees, for General Users, and/or for Privileged Users).

7.2 Information System Access Notification

Before granting access to a system, a use notification banner must display privacy and security notices consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance.

The message must state that: (i) users are accessing a U.S. Government information system; (ii) system usage may be monitored, recorded, intercepted, and subject to audit; (iii) unauthorized use of the system is prohibited and subject to criminal and civil penalties; (iv) there is no right to privacy; and (v) use of the system indicates consent to monitoring and recording. The notification message on the screen shall display until the user takes explicit actions to login to or further access the Peace Corps information system.

7.3 Authentication of User Identity and Compliance

Authentication of a user's identity is commonly accomplished with physical or software-based tokens, account identifiers, passwords, or biometrics. General users, privileged users, and Service Accounts require unique User IDs and passwords. Initial and default passwords are distributed to users in a secure manner, which prevents disclosure to other individuals.

The agency reserves the right to monitor compliance with its password policy by installing or running security programs or utilities that have the capacity to reveal misuse of a password by individual users. If technically feasible, each operating system and application shall be programmed to monitor compliance.

Peace Corps contractors and staff with IT responsibilities shall ensure that all Peace Corps multi-user, sensitive information systems, desktops, laptops, and related devices under their authority have and use a password mechanism that authenticates the identity of each person who accesses http://inside.peacecorps.gov/index.cfm?viewDocument&document_id=7186&filetype=doc http://inside.peacecorps.gov/index.cfm?viewDocument&document_id=7186&filetype=doc any of the sensitive systems for which they are responsible. Refer to Appendix A: Definitions for Peace Corps’ definition of “sensitive information”.

7.4 User Account Names and Passwords

User and Service Accounts must be configured to comply with the following password requirements:

• General User accounts: must be at least eight (8) characters long.

• Privileged User accounts: must be a minimum of twelve (12) characters.

• Service Accounts: must be a minimum of thirty-two (32) characters.

• Must be composed of at least three(3) of the following groups of characters:

o Capital letter o Lowercase letter o Number o Special character.

• Cannot contain the user’s first name, surname, username, semi-colons, or apostrophes.

• Can only be used once. The password history feature must be set to prevent the use of the previous 24 passwords generated for each individual user. (Service Accounts: No password reuse within a 5-year period).

• Maximum password age is to be set to 90 days. (Service Accounts will be set to expire after one (1) year).

• Minimum password age must be set to one (1) day.

• Maximum password age for an initial/default password must be set for three (3) days.

• Passwords entered incorrectly: five (5) consecutive tries, locks out the account.

o The OCIO Service Desk/post IT Specialist will have the capability to unlock a user’s network account after lockout. In a self-service environment, the end-user shall be able to reset their own account password or unlock their own account.

Passwords are to be changed under the following conditions:

• After logging on with an initial/default password.

• Before their expiration.

• Immediately following any suspected compromise.

Remote Desktop Services are not to save passwords or user names; users will have to enter their credentials each time that they login to the network.

Once the new user has been given access to the information system for the first time, the system must immediately force the user to change the initial password.

• Re-authentication of users shall be required after a specified period of inactivity.

• Password protected screen saver lockout must be configured to lock the desktop after 15 minutes of inactivity.

• System must be configured to automatically prompt users to change their passwords at least 14 days prior to the expiration date.

• Administrator account passwords must be protected at the highest level demanded by the sensitivity of the system.

• Administrator passwords must be stored in a designated locked file cabinet, a GSA approved safe, or a CISO-approved encrypted password storage mechanism to prevent the passwords from being acquired by a malicious party.

Additional password use procedures are defined through the Rules of Behavior for General Users and Rules of Behavior for Privileged Users.

7.5 On-Boarding General Users’ Systems Access Accounts

The following on-boarding procedures begin when the individual has a new PTS account (see Section 7.1 above). The individual’s sponsor/supervisor submits the request for PTS action to the OCIO Service Desk/post IT Specialist at least 5-working days before the new user’s initial access/start date. Submission of this form initiates creation and activation of the user’s network account ID and systems user accounts, with approved roles or access rights, based on the position and associated role-based access requirements.

• For users who have mobile devices and remote access, refer to the MS 545 Mobile Device Policy.

• OCIO Service Desk staff verify the new personnel status in PTS, creates a user account and initial password for the network account. (The new account remains inactive pending receipt of the signed user Rules of Behavior for General Users.) The AD Account Management SOP and IT Specialist (ITS) Handbook contain the procedures for creating standard AD user accounts.

• The new user logs onto the Peace Corps network within three (3) days of receiving their username and temporary password. New users are required to:

o Abide by the rules stated in Security Awareness Training and the Rules of Behavior for General Users. Immediately change the temporary password assigned for first login to the Peace Corps network.

7.6 Modifying Active User Account Access

Once a user’s Peace Corps information system access is established with the authorized account(s) and access rights, Account Management best practices and federal guidelines require continuous monitoring, change management, and oversight of all user accounts and access rights.

http://inside.peacecorps.gov/index.cfm?viewDocument&document_id=46795&filetype=doc http://inside.peacecorps.gov/index.cfm?viewDocument&document_id=46795&filetype=doc

• Modifications to a user’s existing information systems access settings requires PTS action, whether triggered by a transfer, promotion, new assignment, temporary escalation, or other business factor. The Business Unit staff POC updates PTS to reflect status changes.

• The OCIO Service Desk makes any requested changes after receiving the signed form.

7.7 Continuous Monitoring of Information Systems Access Management The OCIO Service Desk/post IT Specialist is responsible for ensuring that auditing is enabled for account creation, modification, disabling, and termination actions, with notifications and reporting capabilities, as required.

7.8 Account/Password Management Oversight

System Owners (SOs) or their Information System Security Manager (ISSM) shall review General User accounts annually, to verify that system access is still authorized, that access is required, and that separation of duties is maintained. The methods and procedures for this review will vary by information system. However, this is a mandatory activity for all FISMA reportable systems. Account passwords shall have the shortest practical lifetime. Accounts that have been inactive for 90 days must be disabled. User accounts disabled for more than 90 days must be removed. Volunteer user accounts are not to be disabled until one day after their last day of service.

It is the responsibility of system administrators to:

• Provide usable reports to Systems Owners and ISSMs so they may review active and disabled accounts to ensure authorized persons have access to their systems.

• Update system access when there are changes.

• Ensure that users change their passwords within three (3) days of receiving their initial/default password, at least once within a 90-day cycle, and immediately following any suspected compromise.

• Disable user accounts if passwords are not changed within the above-specified timeframes. Refer to the AD Account Management SOP for managing disabled accounts.

Ensure account and system password hashes are stored using a National Institute of Standards and Technology (NIST) approved hashing algorithm or similarly secure encryption method.

• Ensure that systems are programmed so that passwords will not display on a screen.

It is the responsibility of the SO/ISSM to:

• Review Information Systems’ Access Reports to confirm that the list of accounts and users with access are still authorized and required.

• Review the Disabled Accounts Report and approve account deletion by the OCIO Service Desk/post IT Specialist.

• Acknowledge that user’s access rights are authorized and still required.

It is the responsibility of the user to:

• Change password(s) as required.

• Immediately report potential account/password compromise to the Service Desk/post IT Specialist.

• Successfully complete the annual Security Awareness Training course and exam.

It is the responsibility of the OCIO Service Desk/post IT Specialist to support and modify user accounts as authorized.

7.9 Off-Boarding Information Systems Access for General Users To maintain integrity of the systems’ access policy, the OCIO has developed an Access Management strategy for deactivating user access when staff leaves the agency.

The procedures for disabling or deleting user accounts in Active Directory (AD) can be found in AD Account Management SOP or the IT Specialist Handbook.

As part of the Off-Boarding process for any staff, or Volunteers with network access, the sponsor/supervisor is required to:

• Submit a PTS Change Request to ensure staff account access properly terminated.

• If an involuntary departure occurs, notify the department head, the OCIO and HR immediately. Also, contact the CIO and CISO immediately if the employee has OCIO responsibilities.

The OCIO Service Desk/post IT Specialist is responsible to:

• Collect all agency-issued IT hardware devices and associated peripherals assigned to the user, as specified on the Information Technology Services Procurement Form (PC 2075-e).

• Sign Section E of Peace Corps Clearance for Final Payment (Form PC-671A), confirming that user returned assigned IT equipment.

• Disable user accounts on the date provided on Form PC 2075-e.

Off-Boarding is complete when network and system accounts and files have been appropriately transitioned, transferred to another account, permanently disabled, or moved to their final state.

The specific procedures will vary by information system or component requirements.

http://inside.peacecorps.gov/index.cfm?viewDocument?viewDocument&document_id=53361&filetype=pdf http://inside.peacecorps.gov/index.cfm?viewDocument?viewDocument&document_id=53361&filetype=pdf http://inside.peacecorps.gov/index.cfm?viewDocument?viewDocument&document_id=53099&filetype=pdf

7.10 Privileged User Account Management

Privileged users are authorized (and therefore, trusted) to perform system and application administrative and security-related functions beyond General User access. A Privileged user has an information system account with approved, elevated privileges (e.g., administrators).

All personnel who require Privileged (and/or Administrator) account access must submit a completed Privileged User Account Request (Form PC-2076-e), signed by their sponsor/supervisor/IT Specialist and the CISO/CD or DMO. The Privileged User must also read and sign the Peace Corps Rules of Behavior for Privileged Users, prior to receiving privileged access to Peace Corps information systems. Once the user signs all forms and submits them to the supervisor/sponsor, they will receive their Privileged User ID and password.

7.11 Service Account Management

Service Accounts are assigned to services (executables) that run at system start-up or when triggered by events or scheduled instances. These services often run in the background, without much user prompting or interaction. Service Accounts associated with executables are often built-in to the services, as a means to access resources needed to perform their activities.

Therefore, these types of accounts usually correspond to the service, not an actual person. There are services that require User Accounts to perform certain functions; in those instances, organizations may employ Domain accounts to run the services as well.

It is Peace Corps’ policy to remove default Vendor or Service Accounts, and implement new accounts and passwords on all information systems immediately upon installation, prior to deployment.

System Administrators:

• Establish the Service Account User ID

• Create a password in compliance with Section 7.4 of this guide

• Store User IDs and passwords securely in the OU container in Active Directory (AD).

7.12 RPCV Account Management

The Peace Corps provides IT equipment for RPCVs’ use at Career Resource Centers, located at Headquarters and the Regional Recruiting Offices (RROs). There are limitations on the RPCVs’ use of the designated computers, to ensure that the equipment is secure and the computer environment remains stable. The Service Desk must follow the procedures below to manage the RPCV user accounts:

• Assign a local computer account (User ID) to each RPCV computer, using the format RPCV-XXX where the XXX is a three-letter code identifying the RRO and a number (e.g., RPCV-CH1, RPCV-CH2).

http://inside.peacecorps.gov/index.cfm?viewDocument?viewDocument&document_id=53360&filetype=pdf http://inside.peacecorps.gov/index.cfm?viewDocument&document_id=46796&filetype=docx

• Create a password for each RPCV computer that is consistent with the agency’s password policy, found in Rules of Behavior for General Users and Rules of Behavior for Privileged Users, under MS 542.

• Change each RPCV computer password at least once every six (6) months.

• Ensure that RPCV computers connect only to the Internet, not to the Peace Corps network.

8.0 Wireless Access

8.1 Wireless Access at HQ

The use of the ‘Employees’ SSID wireless connection is limited to Peace Corps staff exclusively.

The use of the ‘Guests’ SSID wireless connection is intended for contractors and visitors. The wireless connection will give staff access only to the Internet, similar to using a public wireless connection. To access internal Headquarters resources (i.e., the Intranet), the user must leverage the remote access methods normally used from outside the agency, such as VMware View, the VPN, and Outlook Web Access (OWA). Individuals using wireless at HQ should refer to Accessing Wi-Fi at HQ procedures.

8.2 Wireless Access at Posts

Wireless Internet connectivity is available to Volunteers at posts. Before being granted access, each Volunteer must read and sign the Peace Corps Volunteer Wireless Usage Agreement (PC- 2120), which confirms that they understand and agree to comply with Peace Corps’ policies for accessing the Internet using the Volunteer wireless connection.

The Volunteer wireless connection is intended only for Volunteers’ use; however, the Country Director’s office may also give staff access to the Volunteers’ wireless connection as long as staff usage does not consume the bandwidth intended for Volunteers.

9.0 Computer Security Incident Response Capability

The Peace Corps’ Incident Response Plan and Procedures are documented separately.

10.0 Emerging Technologies and Electronic

Communications

Electronic communications refers to email and emerging forms of communications such as Microsoft’s Lync services and enterprise social media software such as Yammer. The procedures that have applied historically to email shall also generally apply to these emerging electronic communications.

Agency employees shall use the Peace Corps email systems for official and authorized purposes only, except as permitted under MS 643 Limited Personal Use of Government Office Equipment.

http://inside.peacecorps.gov/index.cfm?viewDocument&document_id=25368&searchResults&search=access%20AND%20wi-fi%20AND%20at%20AND%20hq http://inside.peacecorps.gov/index.cfm?viewDocument?viewDocument&document_id=53910&filetype=pdf http://inside.peacecorps.gov/content/documents/policies/ms_643.cfm

Employees are expected to use common sense, good judgment, and propriety in their use of the system. Guidance for use of email is found in the Rules of Behavior for General Users and Rules of Behavior for Privileged Users.

10.1 Emerging Technologies and Electronic Communications Privacy Agency employees should have no expectation of privacy when using the Peace Corps electronic communications systems. Although certain employees with special access privileges are expressly prohibited from reading others' electronic communications, they may do so if authorized by appropriate senior management officials, or if technical or administrative problems create a situation for which it is necessary for such employees to read messages. In addition, electronic communication messages are government property and agency officials may access those messages whenever there is a legitimate governmental purpose for doing so.

10.2 Electronic Communications Records Management

The National Archives and Records Administration (NARA) has issued standards for the management of federal records created or received via email. Specifically, the National Archives and Records Administration Management Guide Series (1995), states that electronic record-keeping systems shall be designed to ensure the security and integrity of records, preservation of records for the time they are needed, and migration of data to other agency systems or subsequent systems. Records management officers and record custodians should emphasize to users that electronic communication messages are generally considered public records, subject to retention. The OCIO will ensure that electronic communications are properly archived as required by federal standards.

11.0 Malicious Code Prevention and Corrective Action

All network users shall take reasonable precautions, according to their roles and responsibilities, to avoid the possibility of malicious code being introduced into the agency's equipment and networks.

Only authorized software shall be installed and used on Peace Corps' equipment and networks.

11.1 Data Backup and Protection

System Administrators shall ensure regular backups of data occur on their systems as a precaution against data loss. This includes the following activities:

1. Configure the anti-virus software to notify the user when a virus was detected and/or cleaned from data or the user’s email.

2. Configure application or system logs to record and retain information regarding infections that are detected.

http://inside.peacecorps.gov/index.cfm?viewDocument&document_id=46795&filetype=doc

3. Keep anti-virus signature file updates and application programs current with vendor releases for servers and workstations.

4. Use available tools and procedures compatible with the systems’ technical capacity to guard against the placement or storage of malicious code on the agency's servers.

For File Servers:

1. Implement a regular schedule for virus signature file updates from vendors to be loaded onto the servers and desktops.

2. Configure Distribution File Server systems to perform a virus signature "pushdown" when a new virus identified by authorized personnel requires immediate action that cannot wait for the monthly update.

3. Initiate a routine daily schedule (day or night) for scanning viruses.

For Desktops, Laptops, and Mobile Devices:

1. Implement real-time, automatic scanning of removable media, e.g., flash drives.

2. Implement a regular, weekly schedule for virus scans of all hard drives on PCs and laptops.

3. If feasible, lock desktop anti-virus client settings so users cannot turn off the client protection.

For Email:

1. Configure real-time, automatic scanning of email attachments when received or opened by the user.

2. Configure email servers to automatically scan and quarantine email attachments considered or known to be potentially harmful or threatening.

12.0 Internet-Based Services

These procedures provide guidance for agency staff and contractors who create, manage, and maintain web-based services, which include the public-facing Internet, the Intranet, and Extranet sites. These procedures apply regardless of the hosting locations; they apply to agency or externally hosted websites.

Peace Corps staff shall only use web-based service sites that reflect and support the Peace Corps' mission, goals, and objectives, and follow consistent prudent, operational, security, and privacy considerations. They shall be designed to support the widest possible range of potential users and computing platforms, and shall be consistent with Section 508 of the Rehabilitation Act of 1973, as amended.

12.1 Web Services

Web-based services shall adhere to the following security rules:

a. Software used to access the web-based services shall be coordinated with OCIO and shall incorporate security patches.

b. Any files downloaded over the Internet shall be scanned for viruses by default, using approved virus detection software.

c. Websites known to serve malicious code or malware shall be blocked.

d. Peace Corps reserves the right to monitor Internet usage by its employees and contractors. Any user suspected of misuse may have all transactions and material retained for further action. Internet addresses of offensive sites shall be forwarded to the OCIO, Chief Information Security Officer (CISO), or the Office of the Inspector General (OIG) as appropriate.

e. A notice of the agency's privacy policy shall be posted on all publically accessible agency websites.

f. Only OCIO-approved versions of browser software shall be used or downloaded.

OCIO shall make approved sources for licensed web software available to users.

g. Sensitive information shall not be stored unencrypted on any web server available to the public, but it may be published (so that it cannot be altered) on public web servers if the appropriate levels of risk mitigation and data protection have been implemented in accordance with Peace Corps and federal policies.

h. Before information may be posted on a web-based system, it shall be reviewed and approved for release under the provisions of the Publishing Guide of the appropriate agency office or business unit.

i. Permission to use copyrighted information shall be obtained and documented before it can be posted on the agency's website.

12.2 Web Servers

Web-based services shall be developed on web servers, following these management rules:

a. Users are not permitted to download, install, or run web servers on Peace Corps systems. On-site web servers shall be permitted and installed only with the approval of the OCIO Director, Production Operations & Infrastructure.

b. The OCIO provides security guidance and oversight for web servers acquired for agency use that are external to the agency.

c. Web servers and data that are accessible to the general public and external parties shall be located on a screened subnet such as the Demilitarized Zone (DMZ) or in an Extranet (a protected network area that allows access by external Internet users) to isolate them from agency production systems.

d. All network protocols other than HTTP, HTTPS, and IPSEC, shall be disabled, (e.g., Telnet, FTP, etc.), if not specifically needed for services.

e. When using a web remote administrative tool, access by remote users is restricted to authorized systems (via IP address, rather than hostname). DEFAULT PASSWORDS

SHALL NOT BE USED.

f. When processing or transmitting sensitive information over the public Internet, users shall ensure that the latest version of Transport Layer Security (TLS) or Secure Sockets layer (SSL), such as Version 3.0, or other such NIST approved mechanism is used to encrypt the data as it is sent from the user's browser to the web server and to the end recipient.

g. Email shall be encrypted when sent from a browser to the web server.

h. Publicly accessible Peace Corps websites shall be thoroughly tested to ensure links work as designed.

i. The web server software, and the software of the underlying operating system, shall contain all manufacturer-recommended patches for the version in use.

j. On UNIX/Linux systems, web servers shall not be run as "root."

k. Web forms shall validate input and sanitize output.

12.3 Remote Web Services Administration

Installing software on agency web servers to permit remote administration puts the systems and network at risk. Therefore, installations must meet the following requirements in order to mitigate the risks:

a. Remote access to administrative systems must be authenticated by two or more factors. (Remote access is defined as crossing or using a public network to gain access to the administrative system.)

b. Remote administration traffic shall be encrypted so that attackers monitoring network traffic cannot obtain passwords or inject malicious commands into conversations.

c. Packet filtering shall be used to allow remote administration only from a designated set of hosts.

d. As determined by the CISO, remotely administrated web hosts shall be maintained at a higher degree of security than normal hosts.

12.4 Roles and Responsibilities

The OCIO is responsible for providing technical guidance for securing agency websites and policy guidance for internal enterprise websites and sub-sites within the agency’s Intranet. The Office of Communications is responsible for providing policy guidance on the agency’s public-facing websites. This includes rules for establishing, operating, and maintaining websites, providing and managing web services within the IT infrastructure, and reviewing and approving additions and changes to website policies and procedures.

13.0 IT Security Awareness Training and Education

Program

All users of Peace Corps information systems, including guards and contractors, shall complete Security Awareness Training (SAT) before being granted system access, and on an annual basis thereafter, in order to retain system access privileges. Training and educational requirements are based on the user’s level of access and their system roles. Regular Security Awareness Training is necessary to reinforce users’ understanding of their responsibilities in keeping Volunteer data and computer systems safe, reduce inappropriate behavior, and to minimize errors and omissions when using the agency’s computer systems.

The OCIO IT Security Team is responsible for creating, updating, and maintaining the Security Awareness Training (SAT), Privileged User Training (PUT), and other role-based training programs and materials. Additionally, the OCIO shall provide brochures, newsletters, and posters, pens, etc., to assist in enforcing users’ security awareness throughout the year.

13.1 General Training and Education Requirements

The Security Awareness Training program shall effectively train IT professionals in relevant security procedures and necessary security skills and competencies, such as those that meet management, systems design, development, acquisition, and auditing requirements. Users cannot attend Vendor marketing briefings in lieu of agency training requirements. Security Awareness Training must meet the following criteria:

a. Train users according to each individual’s roles, responsibilities, and job functions.

b. Provide formal “expert” training by the OCIO or by external courses approved by the OCIO Director of IT Security Assurance and Compliance.

c. Require that individuals in positions of moderate or high risk, as defined by the IT related personnel investigation policy, attend OCIO IT security update meetings or receive related communications throughout the year.

d. Require all IT professionals to participate in periodic training events, especially when there is a significant change in the IT security environment or procedures, or when IT professionals enter a new position that deals with sensitive information.

13.2 New Hire Security Awareness Training

1. Before receiving their Account ID and password, new hires and contractors must complete the self-directed IT Security Awareness Training packet. The packet shall contain the following documents:

• Self-paced IT Orientation Workflow Diagram

• Your Information Security Responsibilities

• Rules of Behavior (for General Users and/or for Privileged Users)

• Using the Peace Corps IT Systems

• IT Security Exam

• User’s Verification Form

• Online Software Training Reference Guide.

2. When the new hire has read all documents, completed the IT Security Exam, and signed the Rules of Behavior and IT User’s Verification Form, the OCIO Service Desk/post IT Specialist will grant the user access to the network and appropriate application systems.

13.3 Annual Security Awareness Refresher Training

All Peace Corps users shall renew their Security Awareness Training and certification annually.

The Refresher course is made available to users in last quarter each year and must be completed before the end of the fiscal year. The OCIO IT Security Team is responsible for the creation and distribution of training to all users. They also manage and track training progress through completion. Users who do not complete their annual Refresher training will have their Peace Corps network access disabled until they successfully complete training and the exam. Refer to the Annual Security Awareness Training Plan and Procedures for details.

13.4 IT Security Professionals (Privileged Users) Training and Education Requirements

IT security professionals (i.e., OCIO CISO, and CISO staff), as well as system engineers, developers, and system administrators, shall routinely update their security skills and stay abreast of changes in technology that affect security. This means they shall:

a. Understand the IT security policies and practices and their rationale.

b. Maintain an in-depth knowledge of the ever-evolving threats to, vulnerabilities of, and safeguards for IT systems.

c. Maintain thorough understanding of categories of concerns and how to apply appropriate safeguards.

d. Complete Privileged User Training course and examination annually.

e. Read and sign Rules of Behavior for Privileged Users before gaining elevated access to Peace Corps information systems.

Qualifying formal IT Security training for IT Security professionals may include courses, workshops, seminars, security conferences, video, computer-based, and/or product-specific training.

a. Part-time security professionals (with 74% or less security duties), who are Information System Security Officers (ISSOs) shall complete a minimum of 30 hours of formal IT security training per year.

b. Full-time IT security professionals (with 75% or more security duties) shall complete a minimum of 60 hours of formal security education each year.

13.5 Other Role-Based Training

NIST SP 800-16 states the need for Role-Based IT security training, for individuals whose role in the organization indicates a need for special knowledge of IT security threats, vulnerabilities, and safeguards.

Completion of proper security training ensures IT and security personnel are aware of new risks and vulnerabilities that may compromise the confidentiality, integrity, and availability of data.

So, in addition to General User and Privileged User Training, individuals with significant security roles shall be required to complete Role-Based Training.

The OCIO Role-Based Security Training program will identify and monitor changes to key personnel with significant security roles, and establish training requirements for each identified role. Role-Based Training shall target the knowledge, skills, and abilities an individual needs to perform the IT security responsibilities specific to each of his or her roles in the organization.

When an individual’s role change requires specialized training, they will be required to demonstrate completion and competency in the area(s) identified before being granted access to the application and/or system.

14.0 System Assessment & Authorization (A&A)

A System Assessment and Authorization (A&A) is required for new Information systems, networks, applications, and databases - and those undergoing significant modifications – before they are put into operation.

The OCIO IT Security Team works with the SOs to assign a FISMA categorization to each new information system, regardless of its physical location (i.e., HQ Data Center, post infrastructure, or cloud hosting service). IT Security conducts an independent assessment to evaluate the new/changed technologies. Assessments are required to verify that system development and/or changes comply with FISMA policies and standards. Systems that meet applicable FISMA standards have their Authorization to Operate (ATO) continued unless the system undergoes significant changes during that period.

14.1 Assessment Support

The OCIO CISO shall be available to provide assistance and oversight to Authorizing Officials (AOs) and SOs at any stage of the Assessment process. The CISO shall verify that an owner’s assessment and authorization (A&A) activities are consistent with the policy and procedure requirements.

SOs should budget for and begin the A&A process early in the development of their systems as dictated by the OCIO Solutions lifecycle. The benefits of early A&A engagement include:

a. Improved coordination and effectiveness of security for the agency

b. Involvement of all participants in each necessary phase

c. Integration of appropriate security measures that are least costly to implement.

Once the system has been categorized, a system ISSM is assigned. The ISSM will review, validate, and ensure that all IT security requirements are satisfactorily met and stored in a central repository (i.e., CSAM or IT Security SharePoint site).

14.2 Assessment & Authorization Procedures

The procedures below provide a general guideline for conducting the A&A process. Refer to the NIST Special Publication 800-37 Revision 1 for current assessment requirements.

Systems shall be documented by both business personnel and an Information Systems Security Officer (ISSO). The assessment package shall meet NIST requirements.

1. The SO/ISSM ensures all FISMA artifacts are documented and available for the assessment.

2. The ISSM retains an independent assessor (or assessment team) to perform the A&A.

3. Independent assessor(s) perform(s) the A&A, which shall include the following areas of evaluation:

• System categorization is accurate (i.e., low/medium/high risk)

• System design, process, and operations are in compliance with FISMA controls for that categorization

• All artifacts are complete and accurately reflect requirements

• Risks have been identified, documented, and either mitigated or accepted with justification.

4. The assessor creates the Assessment Report; the report shall include assessment results, recommendations, risks, and other findings.

5. The assessor meets with the SO/ISSM and other stakeholders to discuss the Assessment Report, finalize it, and determine whether to make the recommendation to issue the ATO.

6. The ISSM submits the Assessment Report and recommendations to the CISO for review and approval.

7. If the CISO agrees with granting the ATO, he/she sends the Assessment Report/package to the system’s AO for final decision.

8. The AO shall make the final decision on granting the ATO. The AO will either:

• Grant complete approval of the yearly ATO.

• Grant approval of the ATO, with an approved Risk Waiver, accepting identified risks.

• Grant conditional ATO, with requirements to mitigate certain risks within a specified timeframe.

• Deny the ATO, based on identified risks and/or other assessment results.

14.3 Auditable Event Tracking

All operational Peace Corps IT systems shall enable audit and normal logging processes;

auditable event logs will be used for the following:

1. Individual Accountability. Audit trails shall be used to support accountability by providing a construct for non-repudiation.

2. Reconstruction of Events. Audit trails shall be used to support Root Cause Analysis, which investigates the how, when, and why normal operations ceased.

3. Intrusion Detection. Audit trails shall be designed and implemented to record appropriate information to assist in intrusion detection.

4. Problem Identification. Audit trails shall be used as online tools to help identify problems other than intrusions, as they occur.

An audit trail shall include sufficient information to establish the type of activity (unauthorized access or a malfunction) that occurred or suspected and who (or what) caused them. Given the diversity of IT systems' capabilities and missions, the scope and contents of the audit trail shall balance security needs with performance needs, privacy, and costs.

NIST 800-53, Revision 4 requirements follow:

• Audit logs must identify each entity accessing the system, time and date of the access, time and date of session termination; and for use of elevated privileges, the entities’ activities.

• Audit logs for email applications must include email sender, email recipient(s), the size of the message, and the size and name of any attachment.

• Audit logs for IT systems with database components, must include who accessed the database, what database was accessed, and which records were accessed, changed, or deleted.

• Audit logs must be protected from unauthorized access, modification, and destruction.

• Audited events shall be documented in the appropriate system security plan or baseline configuration document of that operating system, network device, or application.

14.3.1 Creating the IT Audit Log

Audit tracking requirements will vary across information systems; however, in order to comply with FISMA requirements, every system IT system must contain an Audit Log, which captures and tracks at minimum, the following data:

• Identification of each user and device accessing or attempting to access an IT system

• Date and time of the access and logoff

• Sufficient information to establish what type of event occurred, when (date and time) the event occurred, where the event occurred, the source of the event, the outcome (success or failure) of the event, and the identity of any user/subject associated with the event.

The following list is representative of events that would provide an acceptable audit trail:

• User login – unsuccessful, and successful, including use of permissions/privileges and activities that might modify, bypass, or negate IT security safeguards and security-relevant actions associated with transaction(s) being processed.

• Server Startup and Shutdown – unsuccessful and successful, including major configuration changes

• Service/Application Startup and Shutdown -- unsuccessful and successful, including major configuration changes

• Client Requests and Server Responses – log successful user authentications and actions requested, PII or financial records accessed by each user, recording each URL requested and the type of response provided by the server

• User Account Permission Modifications -- unsuccessful and successful

• User Account Additions and Deletions -- unsuccessful and successful

• IP Address or Hostname associated with a given event – unsuccessful and successful

• Software Installation or Removal -- unsuccessful and successful

• Sensitive Data Extracts – unsuccessful and successful, including Personal Identifiable

Information (PII)

• Usage Information – unsuccessful and successful transactions, including a count of transactions performed within a certain period and the size of transactions

15.0 Peace Corps Headquarters IT Sensitive Areas Access

The Director of Production Operations & Infrastructure maintains Sensitive Area Access Management Procedures, which cover authorized personnel’s physical access to the Peace Corps Headquarters' IT-sensitive/secure areas. These areas include the Data Center, Network Operations Center (NOC), Uninterrupted Power Supply (UPS) room, engineering lab, Atlanta Data Center, RRO Office space, and the telephone closets.

Appendix A: Definitions Access -- A connection between users, or processes acting on behalf of users, and devices, files, records, processes, programs, domains, or other objects in an information system that allow reading, writing, modification, or deletion of those objects depending on level of access.

Access Control (AC) -- Mechanisms and policies that restrict or control access to an information system and the data in that system. An Access Control List (ACL) specifies what operations different users can perform on specific files and directories (assets).

Assessment Team -- Personnel who validate the results of the risk assessment and verify that the System Security Plan (SSP) controls are present and operating correctly.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .