CS_Information_Protection_Policy - Attachment II.pdf

PDF 9 KB Posted

Attached to
New Reactor Control Room Simulator and Improving the General Electric Simulator Federal contract opportunity
Solicitation number
RS-38-10-702
Issued by
Nuclear Regulatory Commission Central Office

About this file

Computer Security Information Protection Policy - Attachment II

View the file

Other files for this federal contract opportunity

Other files attached to New Reactor Control Room Simulator and Improving the General Electric Simulator, newest first.
File Type Posted
RS-38-10-702.doc DOC document
RS-38-10-702-Amendment No. 03.pdf PDF
RulesOfBehavior - Attachment VII.pdf PDF
GESampleSubr- Attachment - VIII.pdf PDF
LaptopPolicy - attachment V.pdf PDF
NRC-Pwd-Warn-Banr-Guid-Attachment VI.pdf PDF
General_Laptop_Configuration_Std - Attachment IV.pdf PDF
DataAtRestEncryptionPolicy - Attachment III.pdf PDF
RS-38-10-702_GEQuestions12-15-2009.doc DOC document
GEIo- Attachment I.pdf PDF
SF30-Amendment No. 02.PDF PDF
RS-38-10-702-Amendment No. 01.pdf PDF
RS-38-10-702 Solicitation.PDF PDF
Show all 13

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Enclosure

COMPUTER SECURITY INFORMATION PROTECTION POLICY

The Office of Management and Budget (OMB) has released memoranda stating that specific actions should be taken to enable protection of agency sensitive information. OMB Memorandum M-06-16, of June 23, 2006, “Protection of Sensitive Agency Information,” states that all remote access to agency systems and all mobile devices with access to agency systems and information institute a “time-out” function that requires re-authentication after 30 minutes of inactivity.

The OMB Memorandum M-06-19, of July 12, 2006, “Reporting Incidents Involving Personally Identifiable Information and Incorporating the Cost for Security in Agency Information Technology Investments,” and OMB Memorandum M-00-07, of February 28, 2000, "Incorporating and Funding Security in Information Systems Investments," state that agencies must integrate security and privacy requirements into information system investments and must fund security and privacy over the lifecycle of each system undergoing development, modernization, or enhancement. In addition, the memoranda state that agencies need to ensure that operational systems meet applicable security requirements for security significant isolated or wide-spread weaknesses identified by the agency Inspector General, the Government Accountability Office, or during privacy program reviews and those specific funds are proposed for development, modernization, or enhancement efforts to correct the deficiencies.

The following Nuclear Regulatory Commission (NRC) policy reflects the needs expressed above and applies to all NRC employees, contractors, vendors, and agents (users) having access to any system that resides at any NRC facility or contractor facility, having access to the NRC network, or storing any public or non-public NRC information. This policy also applies to all Information Technology (IT) systems operated by the NRC, or operated by a contractor or outside entity on behalf of the NRC. System owners are office directors, regional administrators, and Office of Information Services division directors.

Policy

Remote access to any system that processes non-public NRC information shall be constrained by a “time-out” function that requires re-authentication after 30 minutes of inactivity.

Mobile device access to any non-public NRC information shall be constrained by a “time-out” function that requires re-authentication after 30 minutes of inactivity.

System owners shall include the funding required to implement and maintain throughout the system life cycle applicable IT security requirements in all capital investment requests that include computer processing of NRC information.

System owners shall ensure that operational systems meet applicable security requirements for security significant isolated or wide-spread weaknesses identified by the NRC Inspector General, the Government Accountability Office, or during privacy program reviews.

System owners shall allocate specific funds for the development, modernization, or enhancement efforts required to correct IT security deficiencies identified for their system(s).

File details come from the government source that posted it. Updated .