Amendment05P.S.1237_013.pdf
PDF 165 KB Posted
- Attached to
- Medical Adjudication Services Correction Federal contract opportunity
- Solicitation number
- RFQ100-0006-07
About this file
P1237 13 Information Security
View the file
Other files for this federal contract opportunity
Show all 27
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Program Statement
U.S. Department of Justice Federal Bureau of Prisons
OPI: IPD/OIS
NUMBER: P1237.13
DATE: 3/31/2006
SUBJECT: Information Security
1. PURPOSE AND SCOPE. To require that each Bureau office and institution (including Federal Prison Industries and the National Institute of Corrections) establish and implement information security programs that provide cost-effective safeguards and controls for all computer systems, terminals, workstations, telecommunications systems and equipment, and for all SENSITIVE BUT UNCLASSIFIED information, to include electronic and hard-copy media.
Moreover, telecommunication systems that interface or are operated by computer technology are also governed by the security requirements for information systems.
Each security program must include at least the minimum managerial, operational, and technical controls prescribed in this Program Statement (PS).
This program implements Office of Management and Budget (OMB) Circular No. A-130, Appendix III, which requires that Executive Branch departments implement Information Security Programs.
Not included in this PS are the processing and handling of CLASSIFIED or National Security Information (NSI), which must be approved by the Department of Justice’s Department Security Officer and the Bureau of Prisons’s Chief Information Security Officer (CISO).
The Privacy Act of 1974 requires that disclosure of specified information be limited to authorized persons and agencies. All SENSITIVE BUT UNCLASSIFIED information must be protected as it is processed, stored, transported, or transmitted.
2. PROGRAM OBJECTIVES. The expected results of this program are:
a. The security of information, computers, terminals, P1237.13 3/31/2006 telecommunications, and data communications systems will be maintained.
b. Software installed on any Bureau computer system will be legally purchased and licensed and used in compliance with the licensing agreement of the software vendor.
c. Staff who use or supervise the use of Bureau computer systems will be informed about their responsibilities with regard to information and computer security and trained to meet those responsibilities.
3. DIRECTIVES AFFECTED
a. Directive Rescinded
P1237.11 Information Security Programs (10/24/97)
b. Directives Referenced
P1210.23 Management Control and Program Review Manual (8/21/02)
P1237.10 Personal Computers, Network Standards Manual (11/24/97)
P1315.07 Legal Activities, Inmate (11/5/99) P1351.05 Release of Information (9/19/02) P3000.02 Human Resource Management Manual (11/1/93) P3420.09 Standards of Employee Conduct (2/5/99) P3906.16 Employee Development Manual (3/21/97) P5266.10 Incoming Publications (1/10/03) P5580.07 Personal Property, Inmate (12/28/05)
c. Other References
P.L. 107-347 Federal Information Security Management Act (FISMA) (Title III of the E- Government Act of 2002)
28 CFR Part 17 CLASSIFIED National Security Information and Access to CLASSIFIED Information
OMB Bulletin 90-08 Guidance for Preparation of Security Plans for Federal Computer Systems that Contain Sensitive Information
OMB Circular A-130 Appendix III, Management of Federal Information Resources
SPOM DOJ Security Program Operating Manual E.O. 10450 Security Requirements for Government
Employment
DOJ Order 2620.7 Limited Official Use DOJ Order 2610.2A Employment Security Regulations DOJ Order 2640.2E Information Technology Security DOJ SDLC (Ver. 2) Department of Justice Systems
Development Life Cycle Guidance Document
FIPS PUB 87 Guidelines for ADP Contingency Planning FIPS PUB 112 Password Usage FIPS PUB 197 Advanced Encryption Standard GAO FISCAM Federal Information System Controls
Audit Manual NIST PUB 500-172 Special Publication on Computer Security
Training Guidelines NIST SP800-12 Introduction to Computer Security
(Handbook) NIST SP800-14 Generally Accepted Principles and
Practices for Securing IT Systems NIST SP800-18 Guide for Developing Security Plans for
IT Systems NIST SP800-26 Security Self Assessment Guide for IT
Systems NIST SP800-30 Risk Management Guide for IT Systems NIST SP800-34 Contingency Planning Guide for IT
Systems NIST SP800-37 Guidelines for Security Certification and Accreditation of Federal IT Systems NIST SP800-53 Recommended Security Controls for
Federal Information Systems
4. STANDARDS REFERENCED
a. American Correctional Association 4th Edition Standards for Adult Correctional Institutions: 4-4100, 4-4101, and 4-4106
b. American Correctional Association 3rd Edition Standards for Adult Local Detention Facilities: 3-ALDF-1F-01 and 3-ALDF-1F-02
c. American Correctional Association 2nd Edition Standards for Administration of Correctional Agencies: 2-CO-1F-02 and
2-CO-1F-06
5. ACTION
a. Each facility-head must appoint an Information Security Officer (ISO) to manage and coordinate the overall Information Security Program. The Bureau’s Chief of Information Security must be notified of the appointment, except where noted in this PS. In addition, institutions must establish an Information Security Committee chaired by an Associate Warden (institutions only).
b. Community Corrections Management (CCM) offices, or other geographically remote offices, must be included in the nearest Regional Information Security Program to which they are assigned.
Any office assigned to, but geographically separated from, the Central Office must have an appointed ISO.
c. Each facility must develop and establish an Information Security Program that is customized to the unique properties of the local site.
d. All staff who handle sensitive information by any means, access computers or telecommunications systems in performing their duties or supervising the use of such systems must follow the procedures and meet the requirements of this PS.
e. Documentation required by this PS must be retained in accordance with BOP-RIDS (N1-129-00-04, Item #3 or N1-129-00-19, Item #4).
/s/ Harley G. Lappin Director
Table of Contents
TABLE OF CONTENTS
1. MANAGERIAL AND ADMINISTRATIVE CONTROLS
a. Information Security Program
b. Exceptions and Special Considerations
c. Roles and Responsibilities
d. Information Security Committee (institutions only)
e. Information Classifications
f. Security Architecture and Design
g. Life Cycle Management
h. Monitoring
i. Remote Control
j. Wireless Technologies
k. Mobile Code
l. Staff and Inmate Computers (institutions only)
m. Inmate Access to Computers and Information Systems
n. Review of Security Controls
2. OPERATIONAL AND PHYSICAL CONTROLS
a. Personnel Security
b. Physical and Environmental Security
c. Information Protection and Integrity
d. Telecommunications, Network, and Internet Security
e. Access Management
f. Software Controls
g. Data Integrity
h. Security Awareness, Training, and Education
i. Incident Response and Reporting
j. System Specific Controls
3. TECHNICAL CONTROLS
a. Scope
b. Authentication
c. Logical Access Controls
d. Encryption and Cryptography
Chapter 1, Page 1
1. MANAGERIAL AND ADMINISTRATIVE CONTROLS
a. Information Security Program. Each local office or facility must establish and document an Information Security Program.
At a minimum, the program must include:
• Network and Computer Access Rules
• Internet Access
• SENSITIVE Information Labeling and Handling
• Data Backup and Recovery
• Security Violations and Response
• Personnel Security and Clearance
• Contingency Planning
• Lost or Stolen Computing Devices
• Information Security Committee
• Inmate Access (institutions only)
A documented set of procedures that detail a plan of action covering the mentioned topics will be established and approved by the Chief Executive Officer (CEO). Matters affecting conditions of employment may be negotiable consistent with applicable law, rule, and regulation.
Because of the various security levels within the Bureau, each Information Security Program should be tailored to address the environment, issues, and concerns of that facility and need only address security issues not covered in this policy.
b. Exceptions and Special Considerations. Facilities other than institutions do not require the stringent security practices needed in institutions. Such facilities, usually administrative offices, are not required to establish an Information Security Committee or address issues regarding Inmate Access. Other special considerations are:
(1) Regional Offices. Regional offices must include the Community Correctional Management (CCM) office in their Information Security Programs.
(2) Training Centers. Training Centers must establish their Information Security Programs in the same manner as regional offices.
(3) CCM Offices. A CCM office must abide by the information security program its regional office establishes.
Chapter 1, Page 2
(4) Privatized Contracted Facilities. These facilities will abide by the information security guidelines negotiated in the award contract. Absent specific rules, standards, and guidelines, this PS must be used.
(5) Central Office. The Central Office must develop a local program that addresses its unique issues.
(6) UNICOR. UNICOR has special considerations afforded them in order to operate effectively. UNICOR must abide by the same guidelines as other Bureau components, except as noted in this PS.
c. Roles and Responsibilities. Individuals accessing information must be responsible for its safe and secure use, from its initial use to its disposal. Some individuals will assume certain roles based on their positions, while others assume roles based on how the information is used.
The following describes a hierarchy of key roles that Bureau personnel support and participate in Information Security implementation.
• Chief Information Officer (CIO). Responsible for oversight and management of the Bureau's IT programs, including the Information Security Program.
• Chief Executive Officer (CEO). Ensures the Information Security Program at each Bureau location is carried out within the guidelines of Bureau policy. The CEO designates an ISO, approves local procedures for the secure storage and handling of hard copy sensitive documentation and printouts used for Bureau business, and serves as Accrediting Authority (AA) for sensitive computer systems for which he/she has oversight.
• Chief Information Security Officer (CISO). Manages and directs the national Bureau Information Security Program. The CISO provides guidance to ISOs and coordinates and monitors performance of Bureau computer risk analyses, system security plans, contingency plans, and compliance reviews.
• Information Security Administrator (ISA). Works under the direction of the CISO and provides day-to-day monitoring of Bureau systems including compiling and
Chapter 1, Page 3 making formal reports of security violations, including virus infections, blocked viruses, intrusion detection and suspicious user activities.
• Regional Computer Services Administrator (RCSA).
Provides oversight and guidance to institution ISOs and acts as the ISO for his/her location.
• Information Security Officer (ISO). Establishes and directs the local Information Security Program, which encompasses the computer and telecommunications security programs. ISOs also ensure that the implementation of security measures is commensurate with the sensitivity of information maintained at the site. ISOs develop, and submit for the CEO’s approval, written procedures for safeguarding sensitive information, report security violations and virus infections to the CEO and the Central Office Information Security Section (INFOSEC), and assist employees with information security matters, including safeguarding and marking sensitive information.
• Assistant Information Security Officer (AISO). Perform the ISO’s duties for a department, office, location, computer system, or systems. The following individuals are designated as AISOs: all LAN administrators, PBX administrator, UNICOR computer specialist/system administrator, SIS, and communications technician/specialist.
• System Application Developer. Include appropriate information safeguards and security in an application system’s life cycle design and perform a risk analysis of his/her application systems.
• Accrediting Authority (AA). CEOs are designated AAs for sensitive computer systems under their purview.
AAs certify, based upon the ISO's recommendation, that system documentation and safeguards are within the bounds of acceptable risk. Significant changes affecting (enhancing or degrading) the system’s security or operation made during its life cycle are formally documented and coordinated with the AA.
• LAN and Computer Systems Administrators. Complete a system security plan, contingency plan, certification, and accreditation for each non-enterprise system for which they are responsible. LAN/System Administrators also update contingency plans as needed, ensure that
Chapter 1, Page 4 all software installed on hard drives under their control is licensed, and serve as at least an AISO, if not previously appointed as an ISO.
• System Owners and Data Managers. Develop and implement policies and procedures and adequately train users to ensure that system and application security and access controls are adequate.
• Employee Services Managers (ESM). Coordinate Information Security and other related training.
• Human Resource Managers (HRM). Notify ISOs and IT staff of new users requiring access as well as the modification or termination of access for existing users.
d. Information Security Committee (Institutions Only)
(1) Establishment. The CEO must establish an Information Security Committee to maintain, coordinate, and plan security compliance. Information Security Committee meetings are not mandatory for non-secure facilities.
(2) Membership. The CEO must appoint an Associate Warden to chair the committee with the ISO conducting the meeting. Committee members must consist of no lower than Assistant Department Head-level personnel, representing each discipline within the facility.
Union membership will be consistent with the Master Agreement.
(3) Meetings. The Information Security Committee must meet at least quarterly and whenever significant security issues arise. Only the CEO may authorize cancelling a scheduled meeting or excuse a required member’s absence, in which case, a suitable substitute may be sent as a representative. Minutes of the meeting must be published and copies distributed to the members.
e. Information Classifications. Information managed by the Bureau can be categorized into four distinct categories:
(1) Public. This is information that has been deemed releasable to the general public.
Chapter 1, Page 5
(2) Non-critical. Information or data that is neither essential to the operations of the facility nor critical to its mission. There is no requirement to archive this kind of information.
(3) SENSITIVE BUT UNCLASSIFIED (SBU). SENSITIVE
information is essentially information that, if released to the public, would pose an unacceptable risk to the Bureau, its employees, or its inmate population.
(4) CLASSIFIED. Systems that process CLASSIFIED information must be specifically identified, certified by the Department of Justice’s Department Security Officer (DSO), and secured commensurate with the type of information being processed or stored. Refer to the Security Program Operating Manual for CLASSIFIED materials. The National Security Information (NSI) determines what markings are appropriate for CLASSIFIED documents or media.
f. Security Architecture and Design
(1) Hardware Infrastructure. The infrastructure of wide area networks (WANs) and local area networks (LANs) must be designed with security planned and integrated into its development.
(2) Software Development. Whether developed in-house, contracted, or procured, security must be integrated into the System Development Life-Cycle (SDLC) of software the Bureau uses as detailed in the Certification and Accreditation (C&A) process.
g. Life Cycle Management (Application & Software Development).
A system shall be managed from its inception to its disposal, with each phase planned and documented.
(1) Initiation Phase
(a) System Owners. System Owners are identified and are responsible for documentation. Systems developed or procured for enterprise-wide use are typically owned by an entire discipline. Systems developed or procured locally are owned by the facility and approved by the CEO.
(b) Sensitivity Assessment. Security objectives are established, along with a sensitivity assessment (confidentiality, integrity, availability) to
Chapter 1, Page 6 identify and determine the type and sensitivity level of information processed.
(c) Privacy Act Impact Assessment. A Privacy Act Impact Assessment may be required for certain systems in accordance with Bureau policy.
(2) Development or Acquisition Phase
(a) System Development Life Cycle (SDLC). As part of the system Life Cycle, each information system or application, whether developed in-house or procured, staff must document its development in accordance with SDLC methodology. In addition, the Office of Information Systems (OIS) must approve software applications, whether developed locally or developed for the enterprise, before being made operational for use on the network.
If the application is developed locally, the ISO must consider the source code SENSITIVE and archive (backup-up) according to policy. More complex systems may require additional life cycle phases to develop the system properly. Refer to the Department of Justice Systems Development Life Cycle Guidance Document for detailed information.
1. Certification and Accreditation (C&A). The C&A process required for documenting and managing automated information systems developed or used by the Bureau, whether adopted by the facility, regional office, training centers, or the Central Office.
C&As ensure the security aspect of systems are addressed, well-documented, and understood by the system owners and management.
2. Certification. Certification is the comprehensive analysis of technical and nontechnical security controls. When the System Security Plan, Risk Assessment, Contingency Plan, Security Guide, and Certification Test Results Report are completed, the Certification Official must evaluate the system. The official will be appropriately skilled and knowledgeable in areas of information security and in the system’s technical details. The
Chapter 1, Page 7
Certification Official must prepare a Security Evaluation Report summarizing compliance with security requirements. In addition, the official must prepare an Accreditation Memorandum with a recommendation for, or against, accreditation, listing residual risks to the Designated Accrediting Authority (DAA) as part of the written request for accreditation. The C&A packet must be reviewed annually to determine if any changes warrant re-certification.
A. System Security Plan. System Security Plans will provide an overview of the security requirements and controls required for all computer systems that process SENSITIVE information or are operationally critical. The System Security Plan must comply with the National Institute of Standards and Technology (NIST) Special Publication SP800-18 Guidelines for the Security Certification and Accreditation of Federal Information Technology Systems.
System Security plans will include a Rules of Behavior (ROB) document for each system.
If applicable, and when required by law, rule, regulation, or the Master Agreement, the Union will be notified prior to implementing the Rules of Behavior. The employees’ acknowledgment of any Rules of Behavior will indicate notification/receipt of the Rules.
Bargaining union employees do not waive any bargaining unit rights they are entitled to by acknowledgment of the Rules of Behavior.
B. Risk Assessment. A risk assessment must be performed for each automated information system, whether developed locally, regionally, or nationally. The assessment must determine threats and vulnerabilities as well as provide appropriate cost-effective controls to achieve and maintain an acceptable level
Chapter 1, Page 8 or risk. Assessments must be performed annually in accordance with NIST Special Publication 800-30, Risk Management Guide for Information Technology Systems.
C. Security Test and Evaluation (ST&E) Report. The system’s security mechanisms must be tested and found to work as claimed in the system documentation. Testing must be done to ensure that there are no obvious ways for an unauthorized user to bypass or otherwise defeat the security protection mechanisms. Testing must also include a search for obvious flaws that would allow violation of resource isolation or that would permit unauthorized access to the audit or authentication data.
D. Contingency Plans. Contingency plans for information systems are required as part of the C&A process. All plans must be:
• completed in accordance with NIST Special Publication 800-34 Contingency Planning Guide for Information Technology Systems and
• developed, maintained, and tested within 90 days after development and annually thereafter.
Note: There is a distinction between contingency planning for information systems and contingency planning for a facility’s ADP operations.
Contingency plans for ADP operations are addressed separately in this PS.
E. System Security Guide. The System Security Guide provides the end-user with the necessary knowledge to understand the system’s security mechanisms.
Chapter 1, Page 9
3. Accreditation. Accreditation is the official executive authorization to operate the system or application. It is based on the certification process as well as other management considerations. Accreditation is required for all operationally critical systems or systems that process SENSITIVE information. Once all certification documents are completed, INFOSEC (or local ISO if system is developed locally), in cooperation with the system owners, must prepare a request for accreditation and submit it to the DAA. The system may be allowed to operate with no conditions, or be based on certain conditions detailed in the accreditation document.
• Interim Approval to Operate (IAO). The DAA may grant a 90-day IAO contingent upon specific actions that must be resolved no later than 90 days.
Approval may not exceed 180 days, including all extensions, and must ensure that adequate protective measures exist as detailed in the System Security Plan.
(3) Implementation Phase
Documentation. INFOSEC must retain a copy of all reports, plans, memorandums, certifications, accreditations, and detailed analyses. System owners, administrators, the ISO, and users must also have access to pertinent documentation at the site where the system is located or accessed.
(4) Operation Phase
Change Management. A system to record changes and approvals must be implemented to ensure that modifications to the system are properly tested, approved, and documented.
Chapter 1, Page 10
(5) Disposal Phase
(a) Media Disposal. Electronic and physical media produced by the system must be disposed as described in this PS (see the section on Disposal of SENSITIVE Electronic Media).
(b) Archives. Backup media must be archived using methods that assures its integrity and recovery.
h. Monitoring. Persons using DoJ or Bureau computer systems are subject to monitoring. Accessing such systems constitutes consent to monitoring. Persons using or accessing computer systems unlawfully or without authorization may be subject to disciplinary or criminal prosecution and penalties.
• Keystroke Monitoring. Keystroke monitoring is the process used to view or record both the keystrokes (or other input actions, such as a mouse) entered by a computer user and the computer's response during an interactive session. Keystroke monitoring is a more invasive form of monitoring and can only be used if the facility’s CEO authorizes it in writing.
i. Remote Control. Remote control access to servers and workstations may be performed only by individuals the local ISO or higher approves. If the desired workstation to be remotely controlled is being used, the end-user must give permission for the remote control session to take place. If permission is denied, then the session cannot take place.
j. Wireless Technologies. The use of wireless technologies must provide the same protection afforded wired technologies. Wireless technologies must incorporate transmission encryption and storage encryption, in accordance with the standard minimum encryption strength outlined in the Federal Information Processing Standards (FIPS) 197. In addition, the Central Office Network Administration Branch, OIS must pre-approve, in writing, any technology connected to BOPNet.
k. Mobile Code. The use of mobile code, the executable parts of web-browser applets (i.e. Active X, certain Java scripts), may be permitted only through approved sources.
If employed, such content must be managed through change control processes.
l. Staff and Inmate Computers (Institutions Only). Computer
Chapter 1, Page 11 systems used by Bureau employees must be distinguished from inmate computer systems. Inmate computers and printers must display clearly a blue label as “INMATE ACCESS.” Bureau employees may operate “INMATE ACCESS” computers when necessary, however, inmates will never operate computers or peripherals that are not specifically labeled “INMATE ACCESS.” Any workstation not displaying the blue "INMATE ACCESS" label is presumed as staff only and may not be accessed by inmates.
• Exception. Workstations accessed by inmates as part of UNICOR vocational, repair, refurbish, or recycling operations are exempt.
m. Inmate Access to Computers and Information Systems. Inmate access to computer resources must be determined locally, except as otherwise specified in the Program Statement on Legal Activities, Inmate, and will depend upon the resources available for supervised compliance with the following prohibitions:
(1) Workstations. Inmates may not access:
(a) Workstations not displaying the blue “Inmate Access” label.
(b) Any computer that is operationally critical or contains SENSITIVE information.
(c) Workstations attached to BOPNet, SENTRY, or the Internet.
(2) Electronic Media. Inmates may receive certain electronic media under special conditions. Such media may be accepted only from the inmate’s legal representatives. Acceptable electronic formats are audio tapes, diskettes, audio disc, CD-ROM, and DVD.
(a) Local Procedures. Except as otherwise specified in the Program Statement on Legal Activities, Inmate, local facilities will determine the level and frequency of access, along with screening procedures and means of viewing such electronic material. As with all electronic media, antivirus scanning must be performed before use.
Chapter 1, Page 12
(b) Mailing Electronic Media. Inmates may neither receive nor mail electronic media to individuals or parties, except as specifically authorized by staff in accordance with the Program Statement on Legal Activities, Inmate.
(3) Monitoring. Inmates must be monitored whenever in an area where computers are located. Inmates may not be allowed access to SBU areas, to include computers connected to BOPNet, without constant supervision.
(4) Physical Controls. Computer systems and equipment approved for inmate use must be secured appropriately to prevent theft, damage, or misuse. Such controls should prevent access to the workstation’s internal components or removal of its peripherals.
Other controls, such as surveillance or electronic monitoring, may be applied in lieu of physical controls. Such controls must be appropriate to the value and security of the equipment being protected.
(5) Application Development. Inmates are prohibited from developing software and software applications, to include using the tools to construct applications.
Such tools include any software compiler, Hyper Text Markup Language (HTML) tools, macro editors, debuggers, and other scripting tools (excluding text editors).
Inmates are also prohibited from receiving instruction in software development, except when expressed in theoretical concepts.
(6) Work Detail. Inmates may perform various data entry or other computer related duties using various software applications within the boundaries of this PS.
Software applications that allow inmates to manipulate photo or signature images are prohibited. In addition, inmates may not process or have access to SENSITIVE or Privacy Act information.
• Task-Specific. Inmates may be allowed access only to the hardware and software needed to perform their assigned tasks.
(7) Software Tools and Utilities. Inmate use of software tools and utilities must be approved at the local facility. If permitted, appropriate controls must be in place to ensure data integrity and prevent misuse.
Chapter 1, Page 13
• Exception. As part of a vocational, repair, refurbish, or recycling program, inmates enrolled in the program may be allowed to receive instruction and use software tools and utilities.
The following criteria must be followed:
1. An area for use in the vocational, repair, refurbishment, or recycling operations must be set-aside and isolated from other areas of the facility and built with solid walls from floor to ceiling.
2. Media (diskettes, fixed drives, cell phones, pagers, etc.) appropriated by repair and refurbishing operations must be sanitized without any attempt to restore data. An AISO or higher must perform and verify sanitization according to this PS.
3. Appropriate controls must be in place to verify and monitor the inventory of hardware and software of such operations and to ensure unauthorized access is prevented. Such controls can be in the form of physical surveillance, electronic monitoring, or supervised oversight.
(8) Inmate Personal Use of Computer Equipment. Inmates are prohibited from using computers for personal use, such as legal activities or correspondence to relatives (except under certain conditions). This includes the use of printers and printing materials, diskettes, CD- ROM burning, and other such activities.
• Exception. Certain computing materials may be authorized for inmate use and possession, which may include certain kinds of printouts as authorized by local policy and screened by appropriate staff. An example is some materials generated as a result of an Educational or Vocational program or as specified in the Program Statement on Legal Activities, Inmate. Only the facility CEO can authorize other personal uses of computer equipment, such as legal activities or other correspondence, in writing.
(9) Inmate Workstation Security. Inmate access workstations must be configured to restrict inmate actions to allow only the specific functions to perform
Chapter 1, Page 14 their assignments or duties. Workstation security must be established from the operating system level or lower and must demonstrate and enforce the policy restrictions and controls stated in this PS.
Specialized security software is not authorized unless approved by the ISS.
• Controls and Restrictions
1. Inmates must be restricted from accessing operating system files or any utilities that can be used to modify or disrupt the functioning of the operating system, installed software, or any programs on the computer.
2. Controls must be in place to ensure that each inmate is individually and uniquely identified on the workstation or inmate LAN.
The inmate’s register number must be assigned as their User ID and all inmates are required to have a password assigned for authentication.
3. Network administration and security must be managed and delivered from the file server.
Inmates must not be allowed Administrative rights to file servers, unless under instructional purposes and under close and constant supervision.
4. Workstations must be configured to allow inmates to perform their specific tasks and nothing more. Access to other programs, tools, or utilities not required must be either removed or restricted from access.
Workstations must be configured to prevent inmates from accessing hardware ports, unless needed to perform authorized tasks.
(10) Inmate Education and Training Programs. Inmates taking part in education and training programs are afforded the use of computers and computer systems, if approved locally. This PS’ requirements must apply along with the following provisions:
(a) Instruction in word processing, spreadsheets, database management, or other office related functions is permitted.
Chapter 1, Page 15
(b) Prohibited instructional topics include software languages, macro or script languages, formula and software algorithms, and any training in malicious software development, such as software viruses.
• Exception. Theoretical instruction of the mentioned topics is acceptable.
(c) Curriculum for inmate instruction in the area of computer literacy, office automation, or any instruction that teaches electronics or telecommunications must be approved by the Regional Supervisor of Education and the Regional Computer Services Administrator (RCSA).
(11) Inmate Use of Office Automation Equipment. Inmate use of office automation equipment, such as typewriters, calculators, document copiers, scanners, etc., is specified in the Program Statement on Legal Activities, Inmate.
(12) Inmate Possession of Electronic Devices. Electronic devices that interfere, or can be configured to interfere, with information systems or a facility’s operation are prohibited. Devices considered affecting information systems are, but not limited to:
• cell phones,
• any radio-frequency generating device,
• wireless computing devices, and
• peripherals.
Further information on this topic can be found in the Program Statement on Inmate Personal Property.
(13) Prohibited Publications. Information Technology (IT) magazines, books, and other publications that supply information on the computer underground or other such malicious activities are prohibited from inmate possession, in conjunction with the publications mentioned in the Program Statement on Incoming Publications. Upon releasing a publication to an inmate, media such as CD-ROMs and diskettes, must be removed and confiscated.
(14) Rules of Behavior. Inmates using automated office equipment, including computers and computer systems, must receive proper instruction on acceptable behavior when using such equipment. Inmates must be instructed
Chapter 1, Page 16 specifically as to the tasks, transactions, or other actions that are permissible and prohibited with office automation equipment.
• Inmates will be aware of the consequences of inappropriate behavior including the removal of computer-use privileges and other sanctions.
(15) Training. If detailed to operate computers or computer systems, the inmate must be trained appropriately to operate such systems. The training must include the required technical instruction as well as the Rules of Behavior for each system being used.
n. Review of Security Controls
(1) Information Security Program. Each facility’s Information Security Program is required to be reviewed annually either through an Operational or Program Review, as specified in the Program Statement on Management Control and Program Review.
(2) Certification & Accreditation (C&A). The System Owner will review each system’s C&A packet annually to determine if system changes warrant a re-certification.
In addition to the annual review, each system will be re-certified and re-accredited every three years.
(3) Contingency Plan (ADP Operations). Each facility hosting automated data processing services and equipment such as LAN connectivity devices, computers, and information processing services must formulate and test their Contingency Plans (Business Continuity Plans, Disaster Recovery Plans, or other similarly named plan) annually and receive approval from the CEO.
• Any modifications to the plans resulting from testing must also have CEO approval.
(4) Access Review. System owners must review user’s access at least annually to ensure privileges are appropriate.
In addition, the facility’s personnel roster from the Human Resource Management (HRM) office should be matched with network user accounts to ensure separated employees have not retained access.
• Creating, modifying, and terminating accounts must be part of the intake and outtake procedures using the Magic Service Desk system for documentation.
Chapter 1, Page 17
(5) Boundary Protection Devices. Devices such as gateways, routers, and firewalls that protect network traffic boundaries must be tested quarterly to ensure the network’s security.
(6) Reporting. The submission of audit reports, plans, incident reports, and test results must be performed as required in this PS.
Chapter 2, Page 1
2. OPERATIONAL AND PHYSICAL CONTROLS
a. Personnel Security
(1) Personnel Clearance Requirement. The ISO must ensure all personnel security requirements are met before granting access to SENSITIVE information, information systems, or Computer Rooms. The local HRM office must notify the ISO of the security status for new employees. The method of notification should be specified in the local information security program under Personnel Security.
(2) Security Clearances and Background Checks for Bureau Systems. Bureau employees, contractors, and others, who access, design, develop, support, or maintain Bureau information systems must have personnel security clearances commensurate with the highest level of information that is accessible on the system, pursuant to the DoJ order on Employment Security Regulations and the Human Resource Management Manual.
(a) Information Systems. Persons requiring access to Bureau computers and information systems must have, at a minimum, a National Agency Check and Inquiries (NACI) initiated. The ISO must ensure the end-user has a NACI case number and schedule date before granting access.
Persons requiring ADMINISTRATIVE or SUPERVISORY system access must also undergo a Bureau Limited Background Investigation (LBI) as prescribed in the Human Resource Management Manual.
(b) SENSITIVE Information (Non-information Systems).
Persons accessing SENSITIVE information that is not accessible through an automated system must be cleared before such access is granted by obtaining, at a minimum, an Office of Personnel Management (OPM) National Agency Check with Inquiries (NACI) investigation and Federal Bureau of Investigation (FBI) Criminal History Check (i.e. fingerprint check results). Advance NACI results must receive a favorable review prior to badge issuance.
Note: If the Advance NACI is not received within five days of the background investigation’s scheduling date, the
Chapter 2, Page 2 identification card can be issued based on a favorable review of the Security Questionnaire and the fingerprint check results. Pre-employment reviews, and related favorable or unfavorable decisions, will be made at the operational level consistent with current selection authority.
(3) Escort Requirement. Persons not approved to access SENSITIVE information, computer systems, or computer rooms must be escorted by a knowledgeable staff member with appropriate access and authority to these areas.
The escorting staff member must ensure that the uncleared person does not access SENSITIVE information or any resources that could compromise security.
(4) Contractors. Contractors may not repair or maintain computer information systems without proper clearance.
Contractors servicing Bureau information technology devices must have, at a minimum, an OPM NACI investigation and FBI Criminal History Check (i.e.
fingerprint check results).
(5) Foreign Nationals. Non-US citizens are prohibited from accessing or assisting in developing, operating, managing, servicing, or maintaining Bureau or DoJ information systems, unless the Director of the Bureau of Prisons (with the concurrence of the DOJ CIO and Department Security Officer) grants a waiver.
(6) Staff Management
(a) In-processing. To access Bureau information systems, new and transferring employees must:
• receive a documented initial security briefing from the ISO to make the individual familiar with Bureau national and local security policies;
• be cleared for access via a NACI Case Number and Date supplied by the HRM office;
• receive a briefing on Bureau authenticating protocols; and
• review the local information security program
Chapter 2, Page 3 and this PS.
(b) Out-processing Departing Employees. The ISO at the losing location must disable or delete the departing member’s user ID within one working day and delete the ID within 30 days. The following steps must be documented to protect critical or SENSITIVE data from loss:
1. Notification of Departure. The HRM office must notify the ISO of an employee's transfer, or changes in work status, (i.e.
termination, resignation, home duty, etc.)
including contractors, public health service employees, and volunteers via electronic mail (e-mail) within one working day of the effective date. The Computer Services Department must also be listed on the processing form HRM uses as an area to be completed or cleared.
2. Separations. For all involuntary separations and suspensions, the departing employee's access must be disabled immediately and the immediate supervisor or ISO must confiscate applicable mobile electronic computing devices and media.
Employees who are not being sanctioned while on home duty status may be allowed continued access (depending on local approvals).
Procedures for handling SENSITIVE information will continue to be in effect.
For routine voluntary separations, the employee's access must be terminated no later than one working day following departure.
b. Physical and Environmental Security
(1) Information Technology (IT) systems (computers, networks, and telecommunications systems) must be protected physically from threats and hazards and documented appropriately.
(a) Computer Rooms. Computer Rooms must be the primary area for housing Automated Data Processing
Chapter 2, Page 4
(ADP) equipment used to provide network and other ADP services to computer users. These rooms must be secured appropriately in accordance with the facility’s security level. This includes protection from environmental hazards, natural disasters, vandalism, sabotage, and theft.
1. Construction. Computer Rooms must be constructed with:
• True walls solid from floor to ceiling with no easily accessible external windows;
• Solid-core Doors;
• Deadbolt Locks with a One-inch Throw;
• Intrusion Detection and Fire Alarms
(where necessary); and
• Shielded External Cabling.
Exception: Facilities may employ procedural techniques to compensate for less physical controls. Procedural techniques, such as surveillance, must ensure the prevention of unauthorized entry. The CEO has final approval for procedural techniques the ISO recommends.
2. Access Control List. The ISO must submit to the CEO for approval an Access Control List (ACL) for each designated Computer Room, identifying personnel authorized for unescorted access. A staff member who is listed must escort persons not listed. As the approving authority, the CEO is not required to be listed. The ACL must be on file with any key-issuing authorities and posted at all Computer Rooms, clearly visible prior to entry.
(b) Workstations. Computer workstations (and their peripherals) must be secured appropriately in locked offices, or by other secure means, when not attended. The end-user must be responsible for ensuring the workstation is secured and must report any security problems to his/her supervisor or the ISO. For workstations in areas where computers are shared by several users, security responsibility will fall to the Department Head.
Chapter 2, Page 5
(c) Other Information Asset Devices. Other ADP equipment located in dispersed locations must be protected from hazards and secured appropriately.
1. Routers, Gateways, and Switches. Network devices that operate on the boundaries of the Bureau and DOJ network enterprises must be protected from unauthorized intrusion, viruses, or any disruption of the normal processing and flow of information.
Protection schemes such as firewalls, antivirus agents, and intrusion detection systems (IDS) will be installed at identified points of interface using a risk-based implementation.
2. Firewalls. At a minimum, firewalls must be configured:
• as a device dedicated solely to firewall operations;
• with unused ports and services disabled;
• to block access from untrusted or unknown networks; and
• that if the firewall fails, it must fail in a closed or secure state.
3. Intrusion Detection Systems (IDS). IDSs must be configured as follows:
• install as part of the boundary protection devices that are external connections to the DoJ or the Bureau;
• install as part of an internal boundary protection device if a Risk Analysis indicates it;
• detect potential security breaches in progress (real time);
• be installed on multiuser systems to detect intrusions on hosts and other file servers directly accessible from outside Bureau or DoJ administration;
• operate in accordance with 18 U.S.C. § 2511, the Electronic Communications Privacy Act.
Chapter 2, Page 6
4. Private Branch Exchange (PBX) Security. PBX devices that require remote vendor maintenance via a dial-in telephone line must have a single dedicated telephone line configured as follows:
• Access to the public-switched telephone network must be disabled at all times except during an authorized and supervised maintenance session.
• An audit trail containing date, time, identity of users, and activities performed is required (logs).
• Encryption is required for transmissions.
• Identification and authentication are required. If authentication is provided through a password mechanism, the password lifetime use for the remote session must be limited only to that session (one-time password).
c. Information Protection and Integrity
(1) Labeling of Workstations. All computer workstations, whether stand-alone or networked, must display a DoJ-approved Warning Banner before processing is allowed.
These banners can be displayed either as an electronic banner, notice, or a physical label.
Example: “WARNING! This computer system is the property of the United States Department of Justice. The Department may monitor any activity on the system and search and retrieve any information stored within the system. By accessing and using this computer, you are consenting to such monitoring and information retrieval for law enforcement and other purposes. Users should have no expectation of privacy as to any communication on or information stored within the system, including information stored on the network and stored locally on the hard drive or other media in use with this unit (e.g., floppy drives, CD-ROMS, etc.).”
Chapter 2, Page 7
(2) SBU Workstations. Systems not authorized to process CLASSIFIED information must include the following in the Warning Banner:
“THIS SYSTEM IS NOT AUTHORIZED FOR CLASSIFIED
PROCESSING”
(3) CLASSIFIED Workstations. Warning Banners for CLASSIFIED workstations must be determined by DoJ’s Department Security Officer (DSO) and will conform to labeling practices for classified systems and the Justice Management Division (JMD), Security and Emergency Planning Staff.
(4) Labeling of Documents and Media. All documents and electronic media containing SENSITIVE information must be clearly labeled or marked with its contents as specified in Subsection (9) Control of Output. The label should reflect one of the following:
• SENSITIVE BUT UNCLASSIFIED (SBU)
• SENSITIVE - Limited Official Use (SENS-LOU)
• SENSITIVE - LOU
• Limited Official Use (LOU)
• Bureau SENSITIVE (BOP SENSITIVE or BOP SENS)
• Extremely SENSITIVE Information (ESI)
• Department of Justice SENSITIVE (DOJ SENSITIVE)
• Privacy Act Protected Information (PAPI)
• Law Enforcement SENSITIVE
• Bureau SENSITIVE
Bureau employees may not use National Security Information (NSI) terms, such as CONFIDENTIAL, to denote special handling unless specifically instructed to do so.
(5) E-mail Security. Persons authorized to use the Bureau’s e-mail system must abide by local information security policies and this PS. Persons may not knowingly send software viruses or other inappropriate materials through the e-mail system and will report such incidents to the local ISO.
(a) E-mail Forwarding. Staff may not configure their e-mail account (via rules or macro instructions) to forward messages automatically to, or through, non-Bureau or non-DoJ computer systems.
Chapter 2, Page 8
(b) Disclosure Statement. E-mail addressed internally or externally of the Bureau should include a statement regarding the possibility of SENSITIVE information contained in the message:
“This message is intended for official use and may contain SENSITIVE information. If this message contains SENSITIVE information, it should be properly delivered, labeled, stored, and disposed of according to policy.”
(6) FAX Security
(a) CLASSIFIED. CLASSIFIED information must be transmitted only with equipment operating with National Security Administration’s (NSA) approved encryption and authorized by the DoJ DSO.
(b) Other. All facsimile transmissions, both CLASSIFIED and SBU, must be preceded by a cover page. The cover page will contain:
• The sensitivity category (i.e. CLASSIFIED or
SBU).
• The name, office, voice, and fax telephone numbers of the recipient and sender.
• A warning banner with instructions to the recipient if the facsimile was received in error.
(7) Voice Communications
(a) Social Engineering. Bureau employees may not discuss SENSITIVE information with unknown persons or persons without a valid need-to-know.
Employees must be on guard against providing information that would not normally be provided.
Staff should never reveal their passwords to anyone.
(b) Disseminating Information. SENSITIVE information may not be discussed or disseminated to other employees without a valid need-to-know. Only the CEO or Public Information Officer (PIO) can authorize inquiries and responses to the news
Chapter 2, Page 9 media.
(8) Controlling Electronic Media
(a) Access Controls. Electronic media must be controlled commensurate with the type of information it contains.
1. Fixed Disks (Hard Drives).
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .