Amendment05DOJStandardPhysicalSecurity.pdf
PDF 296 KB Posted
- Attached to
- Medical Adjudication Services Correction Federal contract opportunity
- Solicitation number
- RFQ100-0006-07
About this file
DOJ IT Security Standard
View the file
Other files for this federal contract opportunity
Show all 27
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Department of Justice
DEPARTMENT OF JUSTICE
INFORMATION TECHNOLOGY SECURITY
STANDARD
PHYSICAL AND ENVIRONMENTAL
PROTECTION (PE)
CONTROL FAMILY
December 2006
Information Technology Security Staff
601 Pennsylvania Avenue NW
Suite 230
Washington, DC 20530
** FINAL ** Page 1
REVIEW/UPDATE HISTORY
Version Date Author Comment Authorization
1.0 30 Jan 2004 ITSS Staff Implementation Release 1.0 Dennis Heretick and
Vance Hitch
2.0 July 2005 ITSS Staff SEPS, Metrics & TOC Dennis Heretick and Vance E. Hitch
3.0 December 2006 ITSS Staff Formal Release of Standard Vance E. Hitch
** FINAL ** Page 2
TABLE OF CONTENTS
Foreword
1. General
1.1 Review and Update
1.2 Roles and Responsibilities
1.3 Security Categorization and Compliance
1.3.1 Security Categorization for Systems Processing Sensitive But Unclassified Information
1.3.2 Security Categorization for Systems Processing Classified, Non-Sensitive Compartmented Information (SCI)
1.3.3 Compliance
1.4 References
1.5 Definitions
2. Department-Wide Procedures and Controls
2.1 Requirements for Unclassified and Classified Systems
Control Number: PE-01 - Physical and Environmental Policy and Procedures Control Number: PE-02 - Physical Access Authorizations Control Number: PE-03 - Physical Access Control Control Number: PE-04 - Access Control for Transmission Medium Control Number: PE-05 - Access Control for Display Medium Control Number: PE-06 - Monitoring Physical Access Control Number: PE-07 - Visitor Control Control Number: PE-08 - Access Logs Control Number: PE-09 - Power Equipment and Power Cabling Control Number: PE-10 - Emergency Shutoff Control Number: PE-11 - Emergency Power Control Number: PE-12 - Emergency Lighting Control Number: PE-13 - Fire Protection Control Number: PE-14 - Temperature and Humidity Controls Control Number: PE-15 - Water Damage Protection Control Number: PE-16 - Delivery and Removal Control Number: PE-17 - Alternate Work Site
2.2 Additional Requirements for Classified Systems
3. Component Procedures
** FINAL ** Page 3
FOREWORD
PURPOSE - This mandatory standard provides minimum Department of Justice (DOJ) requirements for information and information technology (IT) systems that process, store, or transmit Sensitive but Unclassified (SBU) and/or classified information (but not systems that process, store, or transmit Sensitive Compartmented Information (SCI)). This standard supplements but does not supersede any DOJ Order. Components may impose more stringent security measures to supplement this standard.
SCOPE - This standard applies to all individuals, organizations, and entities that control, operate, maintain, and/or access DOJ information and IT systems, inclusive of contractors acting on behalf of DOJ, and any external organizations or their representatives, who are granted access to DOJ IT resources, such as other Federal agencies. The provisions of this standard apply to hardware, software, communications, media, and facilities.
CANCELLATION - DOJ IT Security Standard Version 2.0, dated July 2005.
AUTHORITIES - The Deputy Chief Information Officer, IT Security, is responsible for providing security policy, guidance, implementation and oversight for IT systems. Questions or comments regarding this standard should be directed to the IT Security Staff.
VANCE E. HITCH
Chief Information Officer
** FINAL ** Page 4
1. GENERAL
1.1 Review and Update
Questions or comments concerning this document should be addressed to:
Deputy Director, Information Technology Security Staff U.S. Department of Justice 601 Pennsylvania Avenue, NW Suite 230 Washington, D.C. 20530
This standard will be reviewed annually and updated, if required, to respond to questions and comments, and to address additional guidance received from national policy authorities (e.g.
National Institute of Standards and Technology).
1.2 Roles and Responsibilities
Specific responsibilities are identified in the detailed procedures shown below in section 2.
1.3 Security Categorization and Compliance
1.3.1 Security Categorization for Systems Processing Sensitive But Unclassified Information
The applicable baseline (Low, Moderate, or High) for the required security requirements for each Sensitive But Unclassified (SBU) DOJ IT system is derived from the system’s security categorization determined using the methodology described in Federal Information Processing Standard (FIPS) Publication 199, National Institute of Standards and Technology (NIST) Special Publication (SP) 800-60 and NIST SP 800-53 requirements for FIPS 199 determination (security control RA-2) as follows:
• Security Categorization Process: FIPS 199 describes three security objectives:
confidentiality, integrity, and availability.
(i) NIST SP 800-60, Volume 1 provides a list of common information types and their associated recommended security objectives. Using NIST SP 800-60, Volume 1 (or the FIPS 199 Wizard in the DOJ-approved Cyber Security Assessment and Management (CSAM) Toolkit tools), the appropriate security category of low, moderate or high is assigned to each of these objectives for each of the system’s information types.
(ii) The system’s information types are reviewed in NIST SP 800-60, Volume 2 to determine if any special factors (e.g. privacy, financial, medical) apply that require increasing an objective for the information type. Appropriate adjustments are made and an explanation documented in the system security plan.
(iii) The overall security category for each security objective is the highest value across each of the information types.
(iv) The security objectives may also be enhanced by the certification and accreditation team and component senior leadership (e.g. component senior security officer and chief information officer) after assessing the appropriateness of the security categories to the type of system (e.g. mission critical, financial, general support system) and the threats and vulnerabilities to the system and its information. Explanation for this adjustment in the security category level is documented in the system security plan.
(v) The security category for the overall system is based on the highest security category (e.g. high water mark) for all three objectives.
** FINAL ** Page 5
• Security Requirements Applicability: The system security category determines the application of individual security requirements contained in this IT Security Standard for SBU systems. Security requirements marked L (Low) apply to systems with a security category of low, moderate or high. Requirements marked M (Moderate) apply to systems with a security category of moderate or high. Requirements marked H (High) apply only to the high security category. Once determined in accordance with FIPS 199, security requirements that uniquely support the confidentiality, integrity, or availability security objectives may be downgraded to the corresponding requirements in a lower baseline (or appropriately modified or eliminated if not defined in a lower baseline) if, and only if, the downgrading action: (i) is consistent with the FIPS 199 security categorization for the corresponding security objectives of confidentiality, integrity, or availability before moving to the high water mark; (ii) is supported by an organizational assessment of risk;
and (iii) does not affect the security relevant information within the information system.
When all three conditions are met, such a downgrading does not require a waiver and is not considered a risk based decision. However, the affected control’s compliance description in the system security plan must include the rationale for the downgrading.
The DOJ-approved CSAM Toolkit tools provide a FIPS 199 wizard for recording information types and their default values for confidentiality, integrity, and availability.
It also supports explanation of security category increases and justification of security category decreases.
1.3.2 Security Categorization for Systems Processing Classified, Non-Sensitive Compartmented Information (SCI)
A variant of the security categorization process described for SBU systems above is used by certain DOJ Components for systems that process classified, non-SCI, information. In this process, the security category for confidentiality is always high, resulting in a FIPS 199 level of High for all classified systems for FISMA reporting purposes, but not necessarily for security requirement selection purposes. The FIPS 199 methodology is used to establish the security objectives for integrity and availability. The results may be upgraded based on other factors determined by the certification and accreditation team and component senior leadership.
Security requirements that uniquely support integrity or availability objectives may be applied at their corresponding individual security category level if, and only if, the result: (i) is consistent with the security categorization for the corresponding security objective of integrity or availability; (ii) does not affect the security relevant information within the information system;
and (iii) is approved by the certification and accreditation team. Explanation for this adjustment in the security category level is documented in the system security plan at either control objective level in the FIPS 199 determination or security control level in the control compliance description, whichever is relevant.
1.3.3 Compliance
Compliance with all applicable security control requirements in this standard is mandatory for all Department of Justice (DOJ) information technology (IT) systems that process, store, or transmit Sensitive but Unclassified (SBU) and/or classified information (but not systems that process, ** FINAL ** Page 6 store, or transmit Sensitive Compartmented Information (SCI)). Compliance with each security control is validated during:
• Security Test and Evaluation (prior to the system becoming operational)
• Annual Self Assessments
• Annual Office of the Chief Information Officer (OCIO) IT System Evaluations
With the diverse nature of today’s information systems, organizations may find it necessary, on occasion, to specify and employ compensating security controls when compliance with the identified security controls for a system cannot be fully attained. A compensating security control is a management, operational, or technical control (e.g. safeguard or countermeasure) employed in lieu of a recommended security control in the low, moderate, or high baselines described in NIST Special Publication 800-53 that provides equivalent or comparable protection for an information system. A compensating control for an information system may be employed by an organization only under the following conditions: (i) the organization selects the compensating control from NIST Special Publication 800-53 or adopts another suitable compensating control if an appropriate compensating control is not available in the 800-53 security control catalog; (ii) the organization provides a complete and convincing rationale and justification for how the compensating control provides an equivalent security capability or level of protection for the information system and why the related baseline security control could not be employed; and (iii) the organization assesses and formally accepts the risk associated with employing the compensating control in the information system. The use of compensating security controls shall be documented in the system security plan and approved by the authorizing official for the information system. A waiver is not required for application of compensating controls that provide equivalent security capability or level of protection.
For controls where the vulnerability is only partially mitigated by compensating controls, the residual risk is considered a risk based decision by the Authorizing Official and requires a waiver by the Department Chief Information Officer.
1.4 References
Committee on National Security Systems (CNSS) Instruction No. 4009 - National Information Assurance (IA) Glossary, Revised June 2006.
Committee on National Security Systems (CNSS) Policy No. 17 - National Information Assurance (IA) Policy on Wireless Capabilities, August 2005.
Department of Justice (DOJ) Order 2640.2x - Information Technology Security, Current Version.
Director of Central Intelligence Directive (DCID) 6/3 - Protecting Sensitive Compartmented Information within Information Systems, 11 December 2003
DOJ Order 2880.1B - Information Resources Management Program, September 27, 2005.
DOJ IT Security Program Management Plan (PMP), Current Version.
DOJ Security Program Operating Manual (SPOM), May 2005.
** FINAL ** Page 7
DOJ IT Security Certification and Accreditation (C&A) Handbook, Current Version.
Executive Order 12958 - Classified National Security Information, April 17, 1995.
Federal Information Processing Standard (FIPS) Publication 140-2 - Security Requirements For Cryptographic Modules, May 25, 2001 (with change notices dated December 3, 2002.)
FIPS Publication 197 - Advanced Encryption Standard (AES), 2001 November 26.
FIPS Publication 199 - Standards for Security Categorization of Federal Information and Information Systems, February 2004.
FIPS Publication 200 - Minimum Security Requirements for Federal Information and Information Systems, March 2006.
Federal Information System Controls Audit Manual (FISCAM) January 1999.
Federal Information Security Management Act (FISMA) - E-Government Act, (Public Law 107-347), Title III, December 2002.
National Institute of Standards and Technology (NIST) Special Publication (SP) 800-12 - An Introduction to Computer Security: The NIST Handbook, October 1995.
NIST SP 800-15 - Minimum Interoperability Specification for PKI Components (MISPC), Version 1, September 3, 1997.
NIST SP 800-16 - Information Technology Security Training Requirements: A Role- and Performance-Based Model, April 1998.
NIST SP 800-18 Revision 1 - Guide for Developing Security Plans for Federal Information Systems, February 2006.
NIST SP 800-26 - Security Self Assessment Guide for Information Technology Systems, November 2001.
NIST SP 800-30 - Risk Management Guide for Information Technology Systems, July 2002.
NIST SP 800-34 - Contingency Planning Guide for Information Technology Systems, June 2002.
NIST SP 800-37 - Guide for the Security Certification and Accreditation of Federal Information Systems, May 2004.
NIST SP 800-46 - Security for Telecommuting and Broadband Communications, 13 December 1996.
NIST SP 800-47 - Security Guide for Interconnecting Information Technology Systems, August 2002.
NIST SP 800-48 - Wireless Network Security 802.11, Bluetooth and Handheld Devices.
November 2002.
** FINAL ** Page 8 http://www.gao.gov/special.pubs/ai12.19.6.pdf
NIST SP 800-50 - Building an Information Technology Security Awareness and Training Program, October 2003.
NIST SP 800-53 - Recommended Security Controls for Federal Information Systems, February 2005.
NIST SP 800-57 - Recommendation on Key Management, August 2005.
NIST SP 800-58 - Security Considerations for Voice Over IP Systems, January 2005.
NIST SP 800-59 - Guideline for Identifying an Information System as a National Security System, August 2003.
NIST SP 800-60 - Guide for Mapping Types of Information and Information Systems to Security Categories, June 2004.
NIST SP 800-61 - Computer Security Incident Handling Guide, January 2004.
NIST SP 800-63 - Electronic Authentication Guideline, Version 1.0.2, April 2006.
NIST SP 800-64 - Security Considerations in the Information System Development Life Cycle, Revision 1, June 2004
NIST Interagency Report (IR) 7298 - Glossary of Information Security Terms, April 25, 2006.
National Security Telecommunications And Information Systems Security Instruction (NSTISSI) No. 7003 - Protective Distribution Systems, 13 December 1996.
Office of Management and Budget (OMB) Memorandum 00-13 - Privacy Policies and Data Collection on Federal Web Sites, June 22, 2000.
OMB Memorandum 06-16 - Protection of Sensitive Agency Information, June 23, 2006.
OMB Memorandum 06-19 - Reporting Incidents Involving Personally Identifiable Information and Incorporating the Cost for Security in Agency Information Technology Investments, July 12, 2006.
OMB Circular A-130, Appendix III - Security of Federal Automated Information Resources, November, 2000.
1.5 Definitions
Consistently – In the context of this standard, the term “consistently” means “conforming to the same principles or course of action”. [Source ITSS].
Continuous – In the context of this standard, the term “continuous” is synonymous with “periodic”. Where the terms “continuous” and/or “periodic” are used in a requirement, how often the requirement must be performed will depend on the nature of the requirement. [Source
ITSS].
** FINAL ** Page 9
National Security Information – Information that has been determined, pursuant to (NSI) Executive Order 12958 or any predecessor order, to require protection against unauthorized disclosure. [Source CNSSI 4009].
National Security System – Any telecommunications or information system operated by the United States Government, the function, operation, or use of which: 1. involves intelligence activities; 2. involves cryptologic activities related to national security; 3. involves command and control of military forces; 4. involves equipment that is an integral part of a weapon or weapon system; or 5. is critical to the direct fulfillment of military or intelligence missions and does not include a system that is to be used for routine administrative and business applications (including payroll, finance, logistics, and personnel management applications). (Title 40 U.S.C.
Section1452, Information Technology Management Reform Act of 1996.). [Source CNSSI 4009].
On-going – In the context of this standard, the term “on-going” means “progressing or developing”. [Source ITSS].
Organization – In the context of this standard, the term “organization” refers to the department, component, or other entity that owns, operates, or uses information or an information system.
[Source ITSS].
Plan of Action and Milestones (POA&M) – A document that identifies tasks needing to be accomplished. It details resources required to accomplish the elements of the plan, any milestones in meeting the tasks, and scheduled completion dates for the milestones. [Source NIST
IR 7298].
Security Test and Evaluation (ST&E) – Examination and analysis of the safeguards required to protect an information system, as they have been applied in an operational environment, to determine the security posture of that system. [Source CNSSI 4009].
Sensitive Compartmented Information (SCI) – Classified information concerning or derived from intelligence sources, methods, or analytical processes, which is required to be handled within formal access control systems established by the Director of Central Intelligence. [Source
CNSSI 4009].
System (Including Information System, or Information Technology System) – A discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information. [Source CNSSI 4009 and NIST IR 7298].
Security Category – The characterization of information or an information system based on an assessment of the potential impact that a loss of confidentiality, integrity, or availability of such information or information system would have on organizational operations, organizational assets, or individuals. [Source NIST IR 7298].
Security Control Baseline – The set of minimum security controls defined for a low-impact, moderate-impact, or high-impact information system. [Source NIST IR 7298].
** FINAL ** Page 10
System Security Plan – Formal document that provides an overview of the security requirements for the information system and describes the security controls in place or planned for meeting those requirements. [Source NIST IR 7298].
Threat – Any circumstance or event with the potential to adversely impact agency operations (including mission, functions, image, or reputation), agency assets, or individuals through an information system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service. [Source NIST IR 7298].
Vulnerability – Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source. [Source NIST IR 7298].
2. DEPARTMENT-WIDE PROCEDURES AND CONTROLS
2.1 Requirements for Unclassified and Classified Systems
All Department of Justice (DOJ) component information technology (IT) systems and networks must comply with the following requirements:
Control Number: PE-01 - Physical and Environmental Policy and Procedures Policy: The organization develops, disseminates, and periodically reviews/updates: (i) a formal, documented, physical and environmental protection policy that addresses purpose, scope, roles, responsibilities, and compliance; and (ii) formal, documented procedures to facilitate the implementation of the physical and environmental protection policy and associated physical and environmental protection controls.
Roles and Responsibilities: Planning: Department Level: SEPS, CIO, CISO, IT Sec Council;
Component Level: Facility Security, CIO Implementation: Component Level: System Owner; Security Program Manager
Certification Testing: Certification Agent (CA)/CA Rep
Result Ref No. Implementation Standard/Procedure Level PE-01.02-01 Physical and environmental protection policy and procedures exist and document the purpose, scope, roles, responsibilities, compliance and review/change history. The physical and environmental protection policy and procedures are consistent with applicable federal laws, directives, policies, regulations, standards, and guidance. The documents are disseminated to appropriate elements within the organization. (NIST 800-53)
LMH
PE-01.02-05 Physical and Environmental protection policy and procedures are reviewed at least annually and updated when organizational review indicates updates are required.
(NIST 800-53)
LMH
PE-01.08-01 Eating, drinking, and other behavior that may damage computer equipment is prohibited in computer labs and server rooms. (FISCAM)
LMH
PE-01.04-01 For SCI systems only, all technical security safeguards base their effectiveness on the assumption, either explicit or implicit, that all segments of the Security Support Structure have adequate physical security protection. (DCID 6/3)
O
** FINAL ** Page 11
Result Ref No. Implementation Standard/Procedure Level PE-01.05-01 For SCI systems only, unencrypted SCI shall be processed only in Sensitive
Compartmented Information Facilities (SCIF). (DCID 6/3) O
PE-01.06-01 For SCI systems only, if a Temporary SCIF (TSCIF) is used, it is an approved SCIF that may be used to process intelligence information for only a limited time period.
(DCID 6/3)
Control Number: PE-02 - Physical Access Authorizations Policy: The organization develops and keeps current lists of personnel with authorized access to facilities containing information systems (except for those areas within the facilities officially designated as publicly accessible) and issues appropriate authorization credentials (e.g., badges, identification cards, smart cards). Designated officials within the organization review and approve the access list and authorization credentials (at least annually).
Roles and Responsibilities: Implementation: Component Level: System Owner; System Owner Rep; Security Program Manager
Certification Testing: Certification Agent (CA)/CA Rep
Result Ref No. Implementation Standard/Procedure Level PE-02.01-01 A list of personnel with authorized access to facilities containing information systems is maintained and is current. (NIST 800-53)
LMH
PE-02.01-02 The organization promptly removes personnel no longer requiring access from access lists. (NIST 800-53)
LMH
PE-02.02-01 Authorization credentials are issued to authorized personnel with access to information system facilities. (NIST 800-53)
LMH
PE-02.03-01 Heads of component or sponsoring office review and approve the information systems facilities authorized access list and authorization picture badges at least annually.
(NIST 800-53)
LMH
Control Number: PE-03 - Physical Access Control Policy: The organization controls all physical access points (including designated entry/exit points) to facilities containing information systems (except for those areas within the facilities officially designated as publicly accessible) and verifies individual access authorizations before granting access to the facilities. The organization also controls access to areas officially designated as publicly accessible, as appropriate, in accordance with the organization’s assessment of risk.
Roles and Responsibilities: Implementation: Component Level: System Owner; System Owner Rep; Security Program Manager
Certification Testing: Certification Agent (CA)/CA Rep
Result Ref No. Implementation Standard/Procedure Level PE-03.01-01 Access control to non-public buildings and sensitive area entry points is controlled through mechanisms such as: guards, identification badges, or entry devices such as key cards, biometrics, keys, locks, combinations. (NIST 800-53)
LMH
PE-03.01-03 After an emergency-related event, the organization restricts reentry to facilities to authorized individuals only. (NIST 800-53)
** FINAL ** Page 12
PE-03.05-01 Access to public areas is controlled as appropriate in accordance with organizational assessment of risk. (NIST 800-53)
Control Number: PE-04 - Access Control for Transmission Medium Policy: The organization controls physical access to information system transmission lines carrying unencrypted information to prevent eavesdropping, in-transit modification, disruption, or physical tampering.
Roles and Responsibilities: Implementation: Component Level: System Owner; System Owner Rep; Security Program Manager
Certification Testing: Certification Agent (CA)/CA Rep
Result Ref No. Implementation Standard/Procedure Level PE-04.02-01 For transmission of SBU data outside of DOJ facilities, appropriate controls are in place to ensure information system transmission lines carrying unencrypted information prevent (i) eavesdropping, (ii) in-transit modification, and (iii) disruption, or physical tampering in accordance with DOJ policies and procedures. (NIST 800-53)
MH
PE-04.03-01 The organization has implemented appropriate mechanisms to mitigate the risk of electromagnetic interception of unencrypted NSI or SCI information consistent with the requirements contained in: NSTISSAM TEMPEST/2-95, RED/BLACK INSTALLATION GUIDANCE; NSTISSI 7003, Protected Distribution Systems; and CNSS 300, Control of Compromising Emanations. (NSTISSI 7003)
MH
Control Number: PE-05 - Access Control for Display Medium Policy: The organization controls physical access to information system devices that display information to prevent unauthorized individuals from observing the display output.
Roles and Responsibilities: Implementation: Component Level: System Owner; System Owner Representative; Security Program Manager
Result Ref No. Implementation Standard/Procedure Level PE-05.01-02 Unauthorized individuals are prevented from physical access to the information system, including output display. (NIST 800-53)
Control Number: PE-06 - Monitoring Physical Access Policy: The organization monitors physical access to information systems to detect and respond to incidents.
Roles and Responsibilities: Implementation: Component Level: System Owner; System Owner Representative
Result Ref No. Implementation Standard/Procedure Level PE-06.01-01 Physical accesses are monitored and logged for incident detection and response purposes and logs are reviewed periodically. (NIST 800-53)
LMH
PE-06.04-02 Suspicious access activity is investigated and appropriate action taken to include remedial actions and follow-up investigations for security violations and suspicious activities as appropriate. (NIST 800-53)
** FINAL ** Page 13
PE-06.02-01 Real-time intrusion alarms and surveillance equipment are monitored by the organization. (NIST 800-53)
MH
PE-06.03-01 Automated mechanisms are employed by the organization to ensure potential intrusions are recognized and appropriate response actions initiated. (NIST 800-53)
H
Control Number: PE-07 - Visitor Control Policy: The organization controls physical access to information systems by authenticating visitors before authorizing access to facilities or areas other than areas designated as publicly accessible.
Roles and Responsibilities: Implementation: Component Level: System Owner; Security Program Manager
Result Ref No. Implementation Standard/Procedure Level PE-07.01-01 Visitor access appointment logs are maintained to indicate that verification procedures are completed. (NIST 800-53)
LMH
PE-07.02-01 The organization escorts visitors in accordance with the DOJ Visitor Access Policy.
Control Number: PE-08 - Access Logs Policy: The organization maintains a visitor access log to facilities (except for those areas within the facilities officially designated as publicly accessible) that includes: (i) name and organization of the person visiting, (ii) visitor date of access, (iii) visitor time of entry and departure, (iv) purpose of visit, (v) name and organization of the person visited, and (vi) full name of the visitor's escort.. Designated officials within the organization review the access logs in accordance to the organization’s policies after closeout.
Roles and Responsibilities: Implementation: Component Level: System Owner; Security Program Coordinator; Security Program Manager
Certification Testing: Certification Agent (CA)/CA Rep
Result Ref No. Implementation Standard/Procedure Level PE-08.01-01 The facilities visitor access logs includes: (i) name and organization of the person visiting, (ii) visitor date of access, (iii) visitor time of entry and departure, (iv) purpose of visit, (v) name and organization of the person visited, and (vi) full name of the visitor's escort. (NIST 800-53)
Control Number: PE-09 - Power Equipment and Power Cabling Policy: The organization protects power equipment and power cabling for the information system from damage and destruction.
Roles and Responsibilities: Implementation: Component Level: System Owner; System Owner Rep; Security Program Manager
Certification Testing: Certification Agent (CA)/CA Rep
** FINAL ** Page 14
PE-09.01-01 The organization follows its policies and procedures for protecting power cabling and equipment. (NIST 800-53)
Control Number: PE-10 - Emergency Shutoff Policy: For specific locations within a facility containing concentrations of information system resources (e.g., data centers, server rooms, mainframe rooms), the organization provides the capability of shutting off power to any information technology component that may be malfunctioning (e.g., due to an electrical fire) or threatened (e.g., due to a water leak) without endangering personnel by requiring them to approach the equipment.
Roles and Responsibilities: Implementation: Component Level: System Owner; System Owner Rep
Certification Testing: Certification Agent (CA)/CA Rep
Result Ref No. Implementation Standard/Procedure Level PE-10.02-01 Emergency shutoff capability exists, emergency shutoff procedures are well documented and employees are trained in usage of emergency shutoff mechanisms.
Control Number: PE-11 - Emergency Power Policy: The organization provides a short-term uninterruptible power supply to facilitate an orderly shutdown of the information system in the event of a primary power source loss.
Roles and Responsibilities: Implementation: Component Level: System Owner; System Owner Rep; Security Program Manager
Certification Testing: Certification Agent (CA)/CA Rep
Result Ref No. Implementation Standard/Procedure Level PE-11.01-01 A short-term uninterruptible power supply is provided to facilitate an orderly shutdown of the information system in the event of a primary power source loss.
(NIST 800-53)
MH
PE-11.02-01 A long-term alternate power supply is provided for the information system that is capable of maintaining a minimally required operational capability in the event of an extended loss of the primary power source. (NIST 800-53)
Control Number: PE-12 - Emergency Lighting Policy: The organization employs and maintains automatic emergency lighting systems that activate in the event of a power outage or disruption and that cover emergency exits and evacuation routes.
Roles and Responsibilities: Implementation: Component Level: System Owner; Security Program Coordinator
Certification Testing: Certification Agent (CA)/CA Rep
** FINAL ** Page 15
PE-12.01-01 Emergency lighting systems activate in the event of a power outage or disruption and cover emergency exits and evacuation routes. (NIST 800-53)
Control Number: PE-13 - Fire Protection Policy: The organization employs and maintains fire suppression and detection devices/systems that can be activated in the event of a fire.
Roles and Responsibilities: Implementation: Component Level: System Owner; System Owner Representative
Certification Testing: Certification Agent (CA)/CA Rep
Result Ref No. Implementation Standard/Procedure Level PE-13.01-01 Appropriate fire suppression and prevention devices are installed and working. (NIST
800-53)
LMH
PE-13.02-01 Fire suppression and prevention devices activate automatically in the event of a fire.
(NIST 800-53)
MH
PE-13.03-01 Fire suppression and detection devices/systems provide automatic notification of any activation to the organization and emergency responders. (NIST 800-53)
Control Number: PE-14 - Temperature and Humidity Controls resources (e.g., data centers, server rooms, mainframe rooms), the organization regularly maintains within acceptable levels and monitors the temperature and humidity within facilities containing information systems.
Roles and Responsibilities: Implementation: Component Level: System Owner; System Owner Rep; Security Program Manager
Result Ref No. Implementation Standard/Procedure Level PE-14.01-01 Maintenance logs are used to demonstrate proper maintenance history for heating and air-conditioning systems as required, based on organizational assessment of risk.
Control Number: PE-15 - Water Damage Protection resources (e.g., data centers, server rooms, mainframe rooms), the organization protects the information system from water damage resulting from broken plumbing lines or other sources of water leakage by ensuring that master shutoff valves are accessible, working properly, and known to key personnel.
Roles and Responsibilities: Implementation: Component Level: System Owner; System Owner Rep; Security Program Manager
Certification Testing: Certification Agent (CA)/CA Rep
** FINAL ** Page 16
PE-15.02-01 Master shutoff valves are accessible and working properly. (NIST 800-53) MH PE-15.02-51 Key personnel know where water shut-off valves are located. (NIST 800-53) MH PE-15.04-01 Mechanisms are in place to automatically close shutoff valves in the event of a significant water leak. (NIST 800-53)
Control Number: PE-16 - Delivery and Removal Policy: The organization controls information system- related items (i.e., hardware, firmware, software) entering and exiting the facility and maintains appropriate records of those items.
Roles and Responsibilities: Implementation: Component Level: System Owner; System Owner Rep; Security Program Manager
Result Ref No. Implementation Standard/Procedure Level PE-16.01-02 The organization controls delivery areas and, if possible, isolates the areas from the information system and media libraries to avoid unauthorized access. (NIST 800-53)
LMH
PE-16.01-01 Information system related items entering and exiting the facility are controlled and properly logged. (NIST 800-53)
Control Number: PE-17 - Alternate Work Site Policy: Individuals within the organization employ appropriate information system security controls at alternate work sites.
Roles and Responsibilities: Implementation: Component Level: System Owner; System Owner Rep; Security Program Manager
Result Ref No. Implementation Standard/Procedure Level PE-17.03-01 Appropriate security controls are employed for employees to communicate securely and report security problems when at alternate work sites. (NIST 800-53)
2.2 Additional Requirements for Classified Systems
The security, administration and management of classified information shall also comply with specific requirements found in the Department of Justice (DOJ) Security Program Operating Manual (SPOM), Federal requirements for national security systems, and Instructions published by the Committee on National Security Systems (CNSS).
3. COMPONENT PROCEDURES
All DOJ Components may, but are not required to supplement this standard as needed to support their operational environment and technical configurations.
** FINAL ** Page 17
File details come from the government source that posted it. Updated .