General_Laptop_Configuration_Std - Attachment IV.pdf

PDF 71 KB Posted

Attached to
New Reactor Control Room Simulator and Improving the General Electric Simulator Federal contract opportunity
Solicitation number
RS-38-10-702
Issued by
Nuclear Regulatory Commission Central Office

About this file

Computer Security Standard - Attachment IV

View the file

Other files for this federal contract opportunity

Other files attached to New Reactor Control Room Simulator and Improving the General Electric Simulator, newest first.
File Type Posted
RS-38-10-702.doc DOC document
RS-38-10-702-Amendment No. 03.pdf PDF
DataAtRestEncryptionPolicy - Attachment III.pdf PDF
RS-38-10-702_GEQuestions12-15-2009.doc DOC document
GEIo- Attachment I.pdf PDF
CS_Information_Protection_Policy - Attachment II.pdf PDF
SF30-Amendment No. 02.PDF PDF
RulesOfBehavior - Attachment VII.pdf PDF
GESampleSubr- Attachment - VIII.pdf PDF
LaptopPolicy - attachment V.pdf PDF
NRC-Pwd-Warn-Banr-Guid-Attachment VI.pdf PDF
RS-38-10-702-Amendment No. 01.pdf PDF
RS-38-10-702 Solicitation.PDF PDF
Show all 13

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Nuclear Regulatory Commission Computer Security Office

Computer Security Standard

Office Instruction: CSO-STD-1004

Office Instruction Title: General Laptop Configuration Standard

Revision Number: 1.6

Effective Date: November 30, 2009

Primary Contacts: Kathy Lyons-Burke, SITSO

Responsible Organization: CSO/PST

Summary of Changes: CSO-STD-1004, “General Laptop Configuration Standard,” provides the minimal standard that must be applied to NRC general laptops and desktops.

Training: Mandatory training for all laptop and stand-alone desktop ISSOs.

ADAMS Accession No.: ML090400032

Computer Security Standard

CSO-STD-1004

NRC General Laptop Configuration Standard

1 PURPOSE

CSO-STD-1004, Nuclear Regulatory Commission (NRC) General Laptop Configuration Standard provides configuration settings for general laptop security controls that serve to minimize the probability of NRC sensitive information compromise. This standard is not to be used for Safeguards Information (SGI) or classified information processing. A system’s sensitivity is determined based upon the highest level of sensitivity that resides within the system. Sensitive information used within NRC falls within three major categories: Classified Information, Safeguards Information (SGI), and Other Sensitive Unclassified Information Not SGI (OSUINS). OSUINS is information that is not classified and not SGI; however, a compromise of the confidentiality, integrity, or availability of the information could cause an adverse effect on NRC operations, NRC assets, or individuals. Sensitive Unclassified Non- Safeguards Information (SUNSI) defines information that is sensitive from a confidentiality perspective only and is a subset of OSUINS.

Employees are prohibited from processing Sensitive Unclassified Non-Safeguards Information (SUNSI) on home computers unless connected to and working within Citrix, the NRC broadband remote access system (reference NRC Yellow Announcement YA-08-0021). This configuration standard is intended to be used by system administrators and information system security officers (ISSOs) that have the required knowledge, skills, and abilities to apply configuration settings to a Microsoft Windows computer. All general laptops must meet all federally mandated and NRC-defined security requirements.

2 GENERAL REQUIREMENTS

As stated in the NRC laptop security policy, all NRC laptops owned, managed, and/or operated by the NRC or by other parties on behalf of the NRC, and are used for OSUINS, must comply with this standard. All system users must have signed and observe the rules of behavior specified in the NRC Rules of Behavior for Secure Computer Use. All users must complete the IT security awareness course and the NSIR information security awareness course annually.

These general laptops are not intended to directly interface with the NRC operational environment and must only connect through a remote interface.

2.1 Laptop Restrictions

Use of an NRC laptop for remote access must be approved by the user’s division director or above prior to use.

The laptop must not be used for NRC webmail access when using the wireless capability.

Establishing a hardwired and a wireless connection at the same time is prohibited.

CSO Standard CSO-STD-1004 Page 2

2.1.1 International Travel

Laptops dedicated to international travel must be the only laptops used for international travel and should not be used for other purposes.

If the laptop is to be used for international travel, all sensitive information must be removed from the laptop before the trip and the laptop should be completely wiped and reconfigured after the trip. Information should not be stored locally on the international laptop. An image of the laptop should be created before the trip with all current configurations.

2.1.2 Use Outside NRC Facilities

OSUINS must be encrypted using cryptography approved by NRC for OSUINS whenever the system is removed from the NRC storage or use location. Common security practices must be followed whenever this system is removed from NRC storage or use location to include maintaining control of the system, being aware of surroundings during use, and not allowing unauthorized users access to the system or data. Please refer to Management Directives 12.1, 12.5, and 12.6 for approved physical security practices related to the laptop.

2.2 Definitions

Critical Updates – This includes fixes for security defects in operating systems and applications as well as current anti-virus definitions and other intrusion detection and prevention information.

Privileged user – User with one or more of the following functions:

• System Administrator

• Computer Operator

• System Engineer (i.e., user with control of the operating system or specific application software)

• Network Administrator

• Database Administrator

• User who controls user passwords and access level

2.3 Laptop Software

This section identifies the software that is required to be installed on the laptop as well as software that may be installed to perform general NRC business functions.

All products that perform cryptographic functions must be FIPS 140-2 validated, operated in FIPS mode, and use a moderate key strength.

2.3.1 Required Software

Table 2-1 Required General Laptop Software and Availability identifies the required software for NRC general laptops. The most recent service packs and other critical updates must be applied at installation. See the laptop security policy for the required frequency for future critical updates.

CSO Standard CSO-STD-1004 Page 3

Table 2-1 Required General Laptop Software and Availability

Software Product Availability

Microsoft Windows XP or Vista Operating System Purchase required

Internet Explorer – latest stable version Licensed with Microsoft Windows XP and Vista

Symantec Endpoint Protection version 11 Each user may install on one computer in addition to their NRC desktop

SecureZIP 8.2 Purchase required

NRC Remote Access Citrix ICA Web client Download from the NRC remote access website (https://access1.nrc.gov)

WinMagic’s SecureDoc Client full-disk encryption http://www.winmagic.com/corporate_info/contact_us.html Purchase required

Adobe Flash Player – latest stable version Free download from http://www.adobe.com/

2.3.2 Optional Software

Table 2-2 Optional General Laptop Software and Availability identifies optional software for NRC general laptops. Other appropriately licensed software may also be used on the laptop. The most recent service packs and other critical updates must be applied at installation. See the laptop security policy for the required frequency for future critical updates.

Table 2-2 Optional General Laptop Software and Availability

Software Product Availability

Microsoft Office Professional 2003 Purchase required

Adobe Acrobat Reader - latest stable version Free download from http://www.adobe.com/

QuickTime - latest version Free download from http://www.apple.com/quicktime/

Java RunTime Environment - latest stable version Free download from http://www.java.com/en/

Microsoft Visio Viewer 2007 Free download from http://www.microsoft.com/downloads/

Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats

Licensed with Microsoft Office Professional 2003 https://access1.nrc.gov/ http://www.winmagic.com/corporate_info/contact_us.html http://www.adobe.com/ http://www.adobe.com/ http://www.apple.com/quicktime/ http://www.java.com/en/ http://www.microsoft.com/downloads/

CSO Standard CSO-STD-1004 Page 4

2.3.3 Optional Laptop Hardware

Optional hardware includes cellular network based wireless, such as those provided by T- Mobile, Verizon, AT&T, and Sprint, as well as wireless capabilities used in compliance with the wireless router standard (CSO-STD-1801). For information about costs and coverage by cellular network providers, please contact the Office of Information Services telecommunications staff. The telecommunications staff contact information can be found at:

http://www.internal.nrc.gov/ois/it-infrastructure/telecommunications/index.html

3 SPECIFIC REQUIREMENTS

The following sections provide specific configuration settings that must be applied.

3.1 Operating System Settings

The following settings are required:

• Passwords must comply with CSO-STD-0001, “NRC Strong Password Standard.”

• An administrator account must be created to perform tasks that require privileged user access. The account must require authentication using a strong password.

• A user account without administrator privileges must be created to perform general user activities (e.g., browsing, email). The account must require authentication using a strong password.

• Automatic updates must be turned on.

• All current patches and security updates must be applied.

• All current device drivers must be installed.

• The screen saver must require re-authentication and must be enabled within 15 minutes or less of inactivity.

• The system must only use FIPS 140-2 validated encryption operated in FIPS mode.

Remember that all browsers use encryption and must meet this requirement.

• Built-in accounts:

• Default account names must be changed to a different name that is less obvious.

• All accounts must require authentication using a strong password.

• Administrative accounts:

▪ The description field must be deleted. A new description may be entered.

• Guest accounts:

▪ The description field must be deleted. A new description may be entered.

▪ User cannot change password must be turned on.

▪ Password never expires must be turned on.

▪ Account must be disabled.

• All other built-in accounts must be disabled.

• The creation of a memory dump file by the Dr. Watson program must be disabled.

• The following message text for users attempting to log on must be used:

USE OF THIS COMPUTER CONSTITUTES A CONSENT TO MONITORING

http://www.internal.nrc.gov/ois/it-infrastructure/telecommunications/index.html

CSO Standard CSO-STD-1004 Page 5

This computer system is for official or authorized use only. Federal computer systems are subject to monitoring for maintenance, to preserve system integrity and security, and for other official purposes. You should not expect privacy, nor protection of privileged communication with your personal attorney, regarding information you create, send, receive, use, or store on this system.

If monitoring reveals possible evidence of violation of criminal statutes, this evidence and any related information, including your identification, may be provided to law enforcement officials, including the Office of the Inspector General. Anyone who violates security regulations or makes unauthorized use of Federal computer systems is subject to criminal prosecution and/or disciplinary action.

UNAUTHORIZED ACCESS PROHIBITED BY LAW - TITLE 18 U.S. CODE SECTION

Public Law 99-474 provides that anyone who accesses a Federal computer system without authorization and by means of such conduct obtains, alters, damages, destroys, or discloses information, or prevents authorized use of information on the computer, shall be subject to fine or imprisonment, or both.

REPORT ANY UNAUTHORIZED USE TO COMPUTER SECURITY AND THE

INSPECTOR GENERAL

• The following message title for users attempting to log on must be used:

UNAUTHORIZED ACCESS PROHIBITED BY LAW

• The following Administrative Tools Services must be disabled:

• Error Reporting Service

• Help and Support

• NetMeeting Remote Desktop Sharing

• Portable Media Serial Number

• Remote Desktop Help Session Manager

• Zero Configuration

• Terminal Services

• Error reporting to Microsoft when applications crash must be disabled

• FDCC-compliant settings from the most current FDCC security policies must be applied

(NRC-approved wireless devices and connections identified in this specification are permitted by NRC)

• Bluetooth must be disabled from the BIOS

• The BIOS password must be set to prevent inadvertent modifications to BIOS settings

The following settings are optional; however, selecting other settings may result in technical difficulties interoperating with NRC networks and systems:

• Enable notepad edit of files with the following extensions: JS, JSE, OTF, REG, SCT, SHB, SHS, VBE, VBS, WSC, WSF, and WSH

CSO Standard CSO-STD-1004 Page 6

• File extensions may be visible

3.2 Internet Explorer Settings

The following settings are required:

• Phishing filter must be turned on

• Join Customer Experience Improvement Program must be turned off

• Check for server certificate revocation must be turned on

• The browser must be operated in FIPS mode using FIPS validated encryption algorithms

The following settings are optional; however, selecting other settings may result in difficulties interoperating with NRC networks and systems:

• Activate Clear Type should be turned on

• English should be turned on

• Google should be selected as the default search provider

3.3 Symantec Endpoint Protection Version 11

The following settings are required:

• AntiVirus and AntiSpyware must be turned on

• Proactive Threat Protection must be turned on

• Network Threat Protection must be turned on

• The latest virus, firewall, and IPS signature files must be installed

• Block all traffic until the firewall starts and after the firewall stops must be turned on

3.4 SecureZIP

The following settings are required:

• When digital certificates are used, the SecureZip installation must use only NRC-approved digital certificates

• The software must be configured to only operate in FIPS 140 mode

3.5 NRC Remote Access Citrix ICA Web client

The following settings are required:

• Only the NRC-provided configuration may be used

3.6 WinMagic’s SecureDoc Client Version 4.3

The following settings are required:

• Authentication must be required using strong passwords

CSO Standard CSO-STD-1004 Page 7

• Full disk encryption must be used

3.7 Wireless Networking Requirements

The following settings are required:

• The wireless capability must be enabled ONLY for the provider network or CSO-STD-1801 compliant network and must not use other networks (e.g., hotel wireless networks, hotspots)

• Automatic connections must be disabled

• Connections must require authentication

• Access to the device configuration manager must be disabled for users

• Wireless software/firmware updates must be applied manually, but the system should check for updates daily

CSO Standard CSO-STD-1004 Page 8

CSO-STD-1004 Change History

Date Version Description of Changes Method Used to Announce &

Distribute

Training

04-Dec-08 1.0 Initial Release CSO web page 11-Feb-09 1.1 Reconciled clarity issues CSO web page 17-Jul-09 1.2 Updated wireless and anti-malware software information CSO web page

27-Jul-09 1.3 Removed references to specific wireless cards, clarified use of Symantec installation CD, and clarified SecureDoc password synchronization.

CSO web page Mandatory training provided to all NRC ISSOs.

24-Aug-09 1.4 Convert to standard format and added requirement for Adobe Flash to ensure iLearn training courses can be completed

CSO web page

01-Oct-09 1.4 Removed sensitivity markings CSO web page and ISSO forum

02-Nov-09 1.5 Modified to include home wireless router use

CSO web page and

16-Nov-09 1.6 Modified to reference the strong password standard

CSO web page and

1 PURPOSE
2 GENERAL REQUIREMENTS
2.1 Laptop Restrictions
2.1.1 International Travel
2.1.2 Use Outside NRC Facilities
2.2 Definitions
2.3 Laptop Software
2.3.1 Required Software
2.3.2 Optional Software
2.3.3 Optional Laptop Hardware
3 SPECIFIC REQUIREMENTS
3.1 Operating System Settings
3.2 Internet Explorer Settings
3.3 Symantec Endpoint Protection Version 11
3.4 SecureZIP
3.5 NRC Remote Access Citrix ICA Web client
3.6 WinMagic’s SecureDoc Client Version 4.3
3.7 Wireless Networking Requirements

File details come from the government source that posted it. Updated .