Attachment_5_-_OST_CBI_Plan_V1.pdf

PDF 469 KB Posted

Attached to
Economic, Environmental, and Regulatory Analytical and Evaluation and Support Federal contract opportunity
Solicitation number
SOL-CI-17-00102
Issued by
Environmental Protection Agency Cincinatti Procurement Operations Division

About this file

Office of Science and Technology Confidential Business Information Application Security Plan

View the file

Other files for this federal contract opportunity

Other files attached to Economic, Environmental, and Regulatory Analytical and Evaluation and Support, newest first.
File Type Posted
FInal Notice of Intent to Sole Source ICF 3-24-23.docx DOCX document
Sol_SOL-CI-17-00102_Amd_0001.pdf PDF
Amendment_1_-_SOL-CI-17-00102.docx DOCX document
Attachment_7_-_Client_Letter.docx DOCX document
Sol_SOL-CI-17-00102.pdf PDF
Attachment_8_-_PPQ.docx DOCX document
Attachment_1_-_PWS_Final.DOCX DOCX document
Attachment_6_-_CO_Added_Clauses_2-6-18.docx DOCX document
Attachment_3_-_Reports_of_Work.docx DOCX document
Attachment_2_-_QASP.docx DOCX document
Attachment_4_-_Labor_Classifications_-_Copy.docx DOCX document
Show all 11

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Office of Science & Technology Confidential Business Information (OST-CBI) Application Security Plan

U.S. Environmental Protection Agency Office of Water

Office of Science & Technology

August 1, 2011

ATTACHMENT 5

SOL-CI-17-00102

OST-CBI Application Security Plan August I, 20II

SECTION 1.0 APPLICATION DESCRIPTION AND BACKGROUND INFORMATION

1.1 Application Description and Acronym

Office of Science and Technology (OST) Confidential Business Information (CBI)

1.2 Responsible Office

U.S. Environmental Protection Agency (EPA)

OST

1200 Pennsylvania Avenue Washington, DC 20460

1.3 Category

Major Application

1.4 Points of Contact

Security Plan Author

Document Control Officer

(DCO)

Application Owner

CTS Zone Representative

ISO

Name: M. Ahmar Siddiqui Office: U.S. EPA, OST

1200 Pennsylvania Avenue, N.W.

Washington, DC 20460

Phone: (202) 566-1044 E-Mail: siddiqui.ahmar@epa.gov

Office: U.S. EPA, OST

1200 Pennsylvania Avenue, N.W.

Washington, DC 20460

E-Mail: siddiqui.ahmar@.epa.gov

Office: U.S. EPA, OST

1200 Pennsylvania Avenue, N.W.

Washington, DC 20460

E-Mail: siddiqui.ahmar@epa.gov

Name: Willie Abney Office: U.S. EPA, OEI

1200 Pennsylvania Avenue, N.W.

Washington, DC 20460

Phone: (202) 566-1366 E-Mail: abney.willie@epa.gov

Name: Terry Howard Office: U.S. EPA, OW

1200 Pennsylvania Avenue, N.W.

Washington, DC 20460

Phone: (202) 564-0385 E-M ail: howard.tem@epa.gov mailto:siddiqui.ahmar@epa.gov mailto:ui.ahmar@epa.gov mailto:abney.willie@epa.gov mailto:howard.tem@epa.gov

OST-CBI Application Security Plan August 1, 2011

Primary Organization Head Name: Nancy Stoner

1200 Pennsylvania Avenue, N.W.

Washington, DC 20460

Phone: (202) 564-5700 E-Mail: stoner.nancy@epa.gov

Authorizing Official Name: Mike Shapiro

1200 Pennsylvania Avenue, N.W.

Washington, DC 20460

E-Mail: shapiro.mike@epa.gov

1.5 Operational Status

Operation/Maintenance Phase.

1.6 Application Purpose

The OST-CBI application is the process that OST's Engineering and Analysis Division (EAD) uses for protecting confidential business information while handling and analyzing that information. Confidential Business Information (CBI) is any information received or generated by EPA or its contractors, where the information originator declares it to be confidential in accordance with 40 CFR Part 2 Subpart B. These documents may be paper or computer-based (e.g., compact disks, diskettes, computer files). OST may protect other information if releasing it could inadvertently disclose CBI; this information would be protected as equivalent to CBI.

EAD uses CBI to develop regulations under the Clean Water Act. In particular, EAD uses CBI (trade secrets, intellectual property, commercial, financial, and other information) to determine the effectiveness of wastewater treatment technologies. EAD also uses CBI to determine operational and economic impacts on the affected industries. Data managed under the OST-CBI application are critical to OST's mission.

1.7 Application Location and Architecture

In the past, the OST-CBI application consisted of two components: 1) paper and removable media CBI, and

2) mainframe CBI. The mainframe CBI component is not currently used. Additionally, the use of mainframe CBI requires special approval from the EAD Director. The two components of the OST-CBI application are described below.

Paper and Removable Media CBI: The paper and removable media CBI component refers to hard copies of OST-CBI and OST-CBI contained in computer files on removable media. CBI is not intentionally stored on computer hard drives; some software may automatically back-up data to prevent loss of data during computer "crashes." Examples of paper and computer documents that may contain CBI include the following:

• trip reports to industry facilities,

• questionnaires completed by facilities,

• code number lists used to mask CBI,

• electronic spreadsheets,

• electronic databases,

• facility process diagrams, and

• cost information.

mailto:stoner.nancy@epa.gov mailto:shapiro.mike@epa.gov

Paper and removable media CBI are located within EAD office space (i.e., individual offices, cubicles, and the CBI file room) within EPA headquarters at the following address:

EPA West Building 1301 Constitution Avenue, NW 6th Floor Washington, D.C. 20460

EAD has protocols for accessing, handling, and tracking paper and removable media CBI - see Protecting

Confidential Business Information in the Engineering and Analysis Division -Procedures and Rules, dated August 1, 2011 (see Appendix A). Hereafter, those protocols are referred to as the CBI Procedures and Rules.

Mainframe CBI: Mainframe CBI refers to the OST-CBI that could be stored (under special circumstances) on the IBM mainframe system at EPA's National Computer Center (NCC) at Research Triangle Park

(RTP), NC.

1.8 General Support System Information

PCs are considered as the support system for OST-CBI because they are required to view and manipulate removable media CBI. Additionally, the DCO uses the CBI Management System (CBIMS) to manage CBI materials.

PC Workstations -Required to access removable media CBI: Employees do not need computers to read paper CBI. However, employees must use PCs to access data on removable media CBI. Most of these PCs use the Windows XP operating system. Each PC has USB ports and a CD-ROM or DVD-ROM drive to allow media to be removed and secured when it's not being used.

PCs connected to CTS's LAN may be used to access CBI on removable media. The CTS security plan prescribes protocols to prevent unauthorized access to the LAN and PCs connected to the network. Section 1.4 above provides the OWCTS Zone Representative contact information.

CBI Management System (CBIMS) -The DCO uses the CBIMS application to help him manage the

OST-CBI application. It replaced the CBI Tracking System (CBITS) that was placed into operation in 1993. Data from the old CBITS application were used to populate the new CBIMS application. EAD conducted a CBI inventory in 2004 to help baseline the new system.

CBIMS provides the following functions:

• Logging and tracking of CBI documents.

• Access control assistance with respect to CBI documents and EAD office space.1

1 In other words, CBIMS helps the DCO determine whether individuals can receive CBI documents or if they should lose access to EAD office space. CBIMS does not directly control access.

NOTE: As of March 4, 2004, all OST-CBI was removed from the mainframe.

Additionally, use of the mainframe to store or process OST-CBI is no longer permitted, except under special circumstances. Therefore, mainframe CBI will not be discussed further in this security plan.

If mission needs require use of the mainframe to store or process CBI, the EAD Director may grant permission, in consultation with the DCO. As a starting point for determining security measures, the DCO would review a previous OST-CBI Application Security Plan, dated June 10, 2003; this is the last plan that addressed mainframe CBI.

OST-CBI Application Security Plan August 1,, 2011

• Tracking of an individual's CBI clearance.

• Various reporting functions (e.g., access lists; an individual's CBI inventory; lists of CBI documents that have been transferred, archived, or destroyed; etc.)

1.9 System Interconnection and Information Sharing

The CBI Procedures and Rules describe how EPA employees and contractors may receive access to the OST-CBI application. Under special circumstances, other agencies may be granted access to the OST-CBI application. Employees from non-EPA agencies must receive written authorization from appropriate OW management before accessing the application. The authorization must address the conditions for their access. For example, they must follow the same rules of behavior as EPA employees and sign non-disclosure agreements.

network.

Data from the OST-CBI application are not linked to other databases or shared through a computer

1.10 Applicable Laws, Regulations, and Standards

·The laws, regulations, and standards that apply to OST-CBI and this security plan include the following:

• Federal Water Pollution Control Act (i.e., the Clean Water Act)

• 40 CFR Part 2 Subpart B, "Confidentiality of Business Information"

• Computer Security Act of 1987

• OMB Circular A-130, "Management of Federal Information Resources"

• National Institute of Standards and Technology (NIST) SP800-18, Guide for Developing Security

Plans for Information Technology Systems, December 1998

1.11 General Description of Sensitivity (NIST SPS00-53: RA-2 (Core))

The Standards for Security Categorization of Federal Information and Information Systems (FIPS PUB I 99), the Recommended Security Controls for Federal Information Systems (NIST SPB00-53), and the Guide for Mapping Types of Information and Information Systems to Security Objectives and Risk Levels (NIST SPB00-60) describe information sensitivity in terms of confidentiality, integrity, and availability. The manual also explains how to determine the sensitivity level of low, moderate, or high for each term. Sensitivity of the OST-CBI application is summarized in the table below.

Security Categorization

Confidentiality I Integrity I Availability Moderate I Moderate I Moderate

The inadvertent disclosure of data managed under the OST-CBI application could cause competitive harm to the business or industry providing the information. It could also embarrass EPA, thereby impairing its ability to obtain necessary information for the effluent guidelines program or other EPA programs. The confidentiality requirements for CBI are moderate.

Data integrity must be protected to ensure EAD develops effluent limitation guidelines and other rules based on complete and accurate information. Compromised data integrity can undermine the defensibility of rulemakings. Data from the OST-CBI application typically become part of the administrative record for EPA rulemakings. The integrity requirements for official Agency records are moderate.

The OST-CBI application must be available to allow OST to perform analyses in a timely manner.

Compromised availability could result in delays that could prevent meeting court-ordered deadlines for promulgating rules. Missing those deadlines can result in litigation. The availability requirements are moderate for information that could result in litigation if it were not available.

1.12 OST-CBI "Major Application" Designation

The Office of Water identified OST-CBI as a major application using the definitions specified by OMB Circular A-130, "Management of Federal Information Resources." These definitions are provided below:

• An '"application' means the use of information resources (information and information technology) to satisfy a specific set of user requirements."

• A "'major application' means an application that requires special attention to security due to the risk and magnitude of the harm resulting from the loss, misuse, or unauthorized access to or modification of the information in the application. Note: All Federal applications require some level of protection.

Certain applications, because of the information in them, however, require special management oversight and should be treated as major. Adequate security for other applications should be provided by security of the systems in which they operate."

OST-CBI is an application because OST (specifically the EAD user) uses CBI (i.e., information) to perform supporting analyses for the effluent guidelines program (i.e., uses the information to satisfy a specific set of user requirements). Additionally, information technology (e.g., PCs and business processes) is used to manage and use the information. OST-CBI is a major application because of its moderate sensitivity as discussed in the previous section.

SECTION 2.0 MANAGEMENT CONTROLS

2.1 Risk Assessment and Management (NIST SP800...53: RA-3)

The overall vulnerability of paper and removable media CBI is considered to be low. EAD follows standard operating procedures as prescribed in the CBI Procedures and Rules. Additionally, a DCO is assigned the responsibility for tracking paper and removable media CBI and training staff on the appropriate use and protection of CBI. The DCO uses CBIMS to help manage the application's security. Automated badge access to EAD spaces is limited only to staff that have had the appropriate awareness training for protecting the OST-CBI application.

Vulnerability to hackers is non-existent for paper CBI because it cannot be accessed from a computer or computer network. ·

Hacker vulnerability for removable media CBI is expected to be low because it is only loaded onto PCs when needed. When removable media CBI is not in use, it is removed from the PC and secured. At that point, the CBI is not accessible from a computer or a computer network. When the medium is loaded onto a computer, several security measures help protect the removable media CBI along with the permanently-mounted media (e.g., the hard drive). These measures include using a firewall, an intrusion detection system, and dynamic IP addresses.

Workstations are only permitted to have one LAN connection. Additionally, operational policies include prohibiting users from storing CBI on their workstation hard drives and LAN drives and require them to shut-down their workstations at the end of the work day.

2.2 Review of Security Controls (NIST SP800-53: CA-2 (Core))

The DCO, EAD Management, and others (i.e., EAD in general) reviewed the OST-CBI Application since its last plan became effective on March 27, 2008. The findings and actions taken are discussed below.

Finding Action Taken CBI Procedures and Rules. EAD determined its CBI Procedures and Rules, authorized March 27, 2008 needed updating to allow for limited use of electronic receipt mechanisms with CBI.

The previous CBI Procedures and Rules was modified as described in Section 2.3 to allow the use of EPA's Central Data Exchange (CDX) to electronically manage CBI collection and routing.

2.3 Rules of Behavior (NIST SP800-53: PL-4)

Personnel with access to the OST-CBI application and its data have been trained how to protect it. Each user has been given the rules and procedures that relate to their responsibilities. The CBI Procedures and Rules (see Appendix A) reflect the actions identified during the review of security controls.

SECTION 3.0. OPERATIONAL CONTROLS

3.1 Personnel Security (NIST SP800-53: PS-1)

EAD has established procedures for receiving access to the OST-CBI application. These procedures are described in the CBI Procedures and Rules.

3.1.1 Background Checks (NIST SP800-53: PS-3)

Federal employees are subjected to background investigation through Office of Personnel Management

(OPM) upon being hired.

Contractor personnel may be subject to pre-employment screening and background checks by the contractor. However, current contracts used by EAD do not require background checks for contractor employees who handle CBI.

3.1.2 Specialized Training (NIST SPS00-53: AT-1)

Potential users must receive CBI awareness training before they receive access to the OST-CBI application and its data. The document control officer (DCO) provides this training and also oversees periodic review and testing. Certification must be renewed biannually for EAD staff and attorneys of the Office of General Counsel's Water Law Office (OGC/WL0).2 Certification must be renewed annually for others. Certification requires signing a Confidentiality Agreement.

3.1.3 Separation of Duties (NIST SPS00-53: AC-5 (Core))

EAD implemented procedural controls to help prevent unauthorized or unnecessary access to the OST-CBI application. These controls are reflected in CBI Procedures and Rules, Appendix A. For example, the DCO may not grant access to CBI for a project unless the potential user is assigned (by their supervisor) to the project.

3.1.4 Least Privilege (NIST SP800-53: AC-6)

OST-CBI users only access relevant CBI documents to perform their jobs. The rules of behavior require the DCO to keep appropriate records that adequately justify each user's access. Additionally, CBIMS will not allow a CBI document to be logged to a user that is not assigned to the relevant project.

3.1.5 User Accountability (NIST SPS00-53: PL-4)

CBI users are required to sign-out CBI as described in the CBI Procedures and Rules. The DCO tracks documents that are signed-out by each user in CBIMS. Users are responsible for CBI in their possession. Annual CBI inventory reviews and security inspections help promote user accountability.

3.1.6 Termination (NIST SPS00-53: PS-4 (Core))

There are two types of termination procedures: friendly and unfriendly. For friendly terminations the following occurs:

• the employee's supervisor performs an informal exit interview;

• the employee's supervisor must notify the appropriate personnel to remove the employee's access to the OST-CBI application; and

• the employee must return CBI, keys, and badges.

2 On December 29, 2003, the EAD Director granted OGC/WLO attorneys privileges and responsibilities equivalent to those of EAD staff.

For unfriendly terminations, the following occurs:

• an effort is made to collect CBI, keys, and badges;

• if they are still onsite, the employee is escorted offsite; and

• the employee's supervisor must notify the appropriate personnel to revoke all access to the OST-

CBI application immediately.

3.2 Physical and Environmental Protections

3.2.1 Physical Protection (NIST SP800-53: AC-1, PE-1, PE-2 (Core), PE-3 (Core))

Paper and removable media CBI are located within EAD spaces on the 6th Floor of the EPA West Building within EAD spaces at EPA Headquarters. EAD staff stores paper and removable media CBI within locking cabinets. Additionally, an automatic card reader system controls access to the locking doors for EAD spaces. An EPA or contractor employee assigned to EPA Headquarters may receive card reader access if the employee routinely works on an EAD project or the EAD Director determines it is reasonable for the individual to have access to EAD space.3 For either case, the DCO administers a CBI awareness briefing; each employee must also complete and sign a Confidentiality Agreement cleared by the DCO. Most employees receive 24/7 access. Some employees have access only during regular business hours.

Security guards control access to EPA Headquarters, including the EPA West Building. EPA employees require their employee badges or other acceptable pho.to identification to enter EPA headquarters without assistance.

Non-employees must present acceptable photo identification and be signed-in at a guard-controlled entrance and escorted by an EPA employee. The security guards monitor the facility at all times.

3.2.2 Environmental Protection (NIST SP800-53: PE-13(1), PE-14)

EAD spaces have the environmental protections of a typical office building. For example, EAD spaces are temperature controlled and a wet-pipe fire suppression system is installed.

3.3 Input/Output Controls (NIST SP800-53: PL-)

Input/output controls help protect OST-CBI data from being lost, stolen, or inappropriately disclosed. The CBI Procedures and Rules delineate procedures for the following CBI activities:

• receipt

• labeling

• tracking

• storage

• generation

• transmission

• reproduction

• destruction

Staff that need help understanding or implementing the procedures are encouraged to contact the DCO.

The CBI Procedures and Rules lists his phone number. All staff cleared to access OST-CBI receive these rules.

Additionally, this security plan and the CBI Procedures and Rules are available on OST's intranet.

3 For example, the Director determined it is reasonable to allow employees from the Standards and Health Protection Division to pass through Room 6231/6233 so that they could have easy access to the Ariel Rios building and public transportation.

3.3.1 Unauthorized Disclosure of CBI (NIST SPS00-53: IR-1, IR-4, IR-6 (Core))

In the event that CBI is released, inappropriately transmitted, or discovered missing, the CBI Procedures and Rules enumerate procedures to contain the disclosure. In short, requirements exist for reporting the incident to the DCO and Deputy Division Director or Division Director. In addition, there are requirements to limit further disclosures, investigate the circumstances leading to the release of CBI, and report findings to the Division Director.

The CBI Procedures and Rules also contain procedures for the Division Director, who is required to report the unauthorized disclosure to the CBI provider and the senior management of the Office of Water. If the investigation leads to recommend changes in the OST-CBI Security Plan, the Division Director will assign staff to assess the recommended changes and implement them, as appropriate.

3.4 Contractor Use of CBI

3.4.1 "On-Site" Contractors (NIST SPS00-53:AT-1, AT-2 (Core), AT-3 (Core), AT-4 (Core))

Contractors working on-site at EPA Headquarters generally do not require access to CBI to perform their duties. However, this security plan would directly apply to the contractor if they need access to EAD office spaces or CBI.

If access to EAD office space is needed, the contractor is required to take a CBI Awareness Briefing and sign a Confidentiality Agreement. If the contractor requires access to the CBI itself (and the Division Director agrees), they would need to pass the CBI Awareness Test and sign a Confidentiality Agreement.

3.4.2 EAD Program Support Contractors (NIST SPS00..53: AT-1)

Contractors that support EAD programs generally do not work on-site at EPA headquarters. In general, each EAD contractor organization is required to have a CBI security plan that is equivalent to this plan (i.e., the OST-CBI Application Security Plan). As noted in the DCO's rules of behavior, the DCO is responsible for certifying the equivalence of a contractor's CBI security plan.

3.5 Continuation of Operations (COOP) Planning (NIST SPS00-53:CP-1)

The Continuity of Operations Plan for the Office of Science and Technology (dated January 2003) provides guidance on what to do in the event of an emergency to continue OST's mission. The COOP assumes the following:

• "The emergency will be limited to a 30-day period"

• "The event will require the physical relocation [of OST operations] from current [OST] facilities"

• "Confidential Business Information for the Effluent Guidelines program [(i.e., OST-CBI)] currently secured on the sixth floor connecting wing of EPA headquarters building would not be relocated during a 30-day emergency. These materials would remain in [the] currently secured area."

The "materials" mentioned in the COOP assumptions are the paper and removable CBI covered in this security plan.

3.5.1 Contingency Planning (NIST SPS00-53: CP-1, CP-2(1) (Core), CP-3 (Core), CP-4(1) (Core))

The Contingency Planning Guide for Information Technology Systems (NIST SP800-34), dated June 2002, provides guidance on contingency planning. The Contingency Plan for the OST-CBI application can be found in Appendix B. ·

3.6 Data Integrity Controls (NIST SPS00-53: PL-4)

The CBI Procedures and Rules describe procedures to protect paper and removable media CBI from accidental or malicious alteration or destruction. Specifically, there are procedures for protecting CBI that is contained on rewritable media.

3.7 Documentation (NIST SPS00-53: PL-1)

Once approved, the OST-CBI Security Planning Package will be used to manage the OST-CBI application.

It consists of the following:

• Section l: Assignment of Responsibility

• Section 2: This security plan, including the Rules of Behavior and the Contingency Plan

• Section 3: Periodic Security Control Reviews

• Section 4: Authorization to Process

Other directly relevant documentation includes:

• Confidentiality Agreements for each OST-CBI user

• Confidentiality Awareness Tests for each appropriate OST-CBI user

• Confidential Business Information Management System (CBIMS) - User's Guide, April 15, 2004

• CBIMS-generated reports

• Continuity of Operations Plan for the Office of Science and Technology, January 2003

3.8 Security Awareness and Training (NIST SPS00-53: AT-1, AT-2 (Core), AT-3 (Core), AT-4 (Core))

Receipt of CBI Security Awareness Training is a condition for receiving access to CBI. CBI Security Training is given by the DCO on an as-needed basis. Users that are EAD staff or OGC/WLO attorneys must take refresher training biannually. Others must take the refresher annually. The DCO also conducts other activities to promote security for OST-CBI. These activities are included in the DCO's rules of behavior.

SECTION 4.0 TECHNICAL CONTROLS

4.1 User Identification and Authentication (NIST SP800-53: IA-1)

Other than visual identification, there are no user identification and authentication controls for accessing CBI within EAD.

4.2 Authorization and Access Controls (NIST SP800-53: AC-1, AC-3(1) (Core), AC-6)

EAD implements the protocols within this security plan and its appendices to limit access to CBI. The

DCO conducts training, audits, and inspections to help ensure that CBI is only used by those who are properly cleared and have a legitimate need for using the CBI. For example, facilities are advised to send their CBI directly to either the EAD DCO or a contractor DCO, as appropriate. Before the DCO assigns the CBI to a user, they verify whether the user is assigned to the appropriate project and has an active CBI clearance. The CBIMS application helps the DCO determine whether these conditions are met.

Additionally, the DCO's rules of behavior were written to explicitly include conditions for granting and accounting for access. These rules of behavior also include conditions for reviewing each user's need to maintain access.

4.3 Public Access (NIST SP-800-53: AC-1)

The public is not authorized to access the OST-CBI application. Section 2.1 describes measures taken to minimize unauthorized access to paper and removable media CBI.

4.4 Audit Trail Mechanisms (NIST SP800-53: AU-2 (Core), AU-3, AU-8, AU-9)

For every document transaction, the CBIMS application creates an entry in the audit trail table.

SECTION 5.0 ABBREVIATIONS

CBI Confidential Business Information CBIMS Confidential Business Information Management System COOP Continuation of Operations Plan DCO Document Control Officer EAD Engineering & Analvsis Division EPA Environmental Protection Agency IMO Information Management Officer ISO Information Security Officer LAN Local Area Network OEI Office of Environmental Information OGC/WLO Office of General Counsel/Water Law Office OST Office of Science & Technology OWOW Office of Wetlands, Oceans, and Watersheds

SECTION 6.0 REFERENCES

• 40 CFR Part 2 Subpart B, "Confidentiality of Business Information"

• Computer Security Act of 1987

• EPA Information Security Manual 2195A

• Federal Water Pollution Control Act (i.e., the Clean Water Act)

• FIPS PUB 199, Standards for Security Categorization of Federal Information and Information Systems

• NIST SP800-18, Guide for developing Security Plans for Information Technology Systems, December

• NIST SP800-34, The Contingency Planning Guide for Information Technology Systems

• NIST SP800-53, Recommended Security Controls for Federal Information Systems

• NIST SP800-60, Guide for Mapping Types of Information and Information Systems to Security Objectives and Risk Levels

• OMB Circular A-130, "Management of Federal Information Resources"

• Continuity of Operations Plan for the Office of Science and Technology, January 2003

Appendix A

Protecting Confidential Business Information (CBI) In the Engineering and Analysis Division (EAD)

Procedures and Rules

U.S. Environmental Protection Agency Office of Water

August 1, 2011

Protecting CBI in EAD - Procedures and Rules August 1, 2011

1.0 INTRODUCTION

1.1 AUDIENCE

Who should follow these standard operating procedures (SOPs)? These SOPs for protecting confidential business information (CBI) are written for Government and contractor employees working with the Engineering Analysis Division (EAD) and working at EPA Headquarters.

1.2 BACKGROUND

Why is EAD's use of Confidential Business Information (CBI) important? EAD uses CBI (i.e., trade secrets, intellectual property, commercial, financial, and other information) to develop regulations under the Clean Water Act. Specifically, EAD uses CBI to determine the effectiveness of wastewater treatment technologies and to determine operational and economic impacts on the affected industries. Use of CBI is critical to EAD's mission.

Why is protecting CBI important? EPA is legally obligated to protect CBI. The inadvertent disclosure of CBI could cause competitive harm to the business or industry providing the information. It could also embarrass EPA, thereby impairing its ability to obtain necessary information for the effluent guidelines program or other EPA programs.

1.3 PRIME RESPONSIBILITIES

What are 119-' responsibilities for protecting CBI? Your prime responsibilities for protecting CBI are presented below.

The standard operating procedures and rules of behavior (presented in the following sections) were derived from the above prime responsibilities. It is extremely important that you adhere to all of these standard operating procedures and rules of behavior: failure to do so can result in disciplinary action, with penalties ranging up to and including dismissal. Willful unauthorized disclosure of CBI can lead to a fine up to $1,000 and/or imprisonment for up to one year. '

I'm not sure what I need to do for certain aspects of handling CBI. What should I do? You should ask the DCO, your supervisor, or your project manager for help.

A - 2

PRIME RESPONSIBILITIES

For Protecting CBI

1. Do not allow unauthorized disclosure or unauthorized modification of CBI.

2. Keep track of all CBI that is assigned to you.

Protecting CBI in EAD - Procedures and Rules August I, 20II

2.0 STANDARD OPERATING PROCEDURES

2.I ACCESS TO CBI

How do I get cleared for access to CBI materials?

If you are an EAD employee or an Office of General Counsel - Water Law Office (OGCIWLO) attorney:

1. You must be assigned to the project related to the CBI you need to use.

2. You must pass the CBI Awareness Test and sign a confidentiality agreement.

Note: Your access privileges will expire two years from the day you signed the Confidentiality

Agreement unless you pass another CBI Awareness Test and sign a new Confidentiality Agreement.

If you are not an EAD employee or an OGCIWLO attorney:

1. You must request (in writing) that the EAD Director grant you access to EAD's CBI. In your request, you must describe the CBI you need, explain why you need it, and state how long you need access to it.

2. The EAD Director may impose certain conditions for your use of the requested CBI.

3. You must pass the CBI Awareness Test and sign a confidentiality agreement.

Note: Your access privileges will expire within one year from the day you signed the

2.2 IDENTIFICATION OF CBI

How do I know if certain information is CBI? There are several ways to identify CBI. The following are some examples:

• A logged CBI document will have a cover sheet that plainly identifies it as CBI (see Figure 1 below).

• CBI documents derived from other types of CBI will be plainly marked.

• Correspondence from a facility will identify enclosed materials as "confidential," "proprietary,"

"trade secret," or use other similar words.

• During discussions or site visits, a facility representative may identify certain information as CBI.

• Survey responses may indicate that the provided information is CBI.

The above list is not all-inclusive. If you are not sure whether certain information is CBI, ask your supervisor or project manager to help.

A - 3 l!AMl!DF 1.;SSlVDJFtt:fi {Pla ,....-) usm;s JJAME D.\Ill (hll9t•d) (I...,.) r"JUT

])A'tg:TO Cl&fIR.AL O:t JllU x:ax

DCO

mmAL

=xxxxx xxn=x "''"""""' :cxx nns

Protecting CBI in EAD - Procedures and Rules

Figure la. CBI Coversheet (old)

CONl:lIDF.NTIAL BUSINESS JNFORMATlON

TlW..._,.•ill iloc:•-a1 wmt:ml11t C8s1'Wit IBnlCHrl•,_r_d_ oklllHdaacbr.r ttn.·w...., ALU jCWA

U".JVU ,.m:r..y .a.dowC'""A Ulifllln:dll·hlnnlalur..-.. IDUf lft"mll• llllt 1._rt.d hi! nutNb:

r111 •-tbr an111: .....trt u-U.11.c_ nn M·•pw11tililrfimaptn·su01&• •r 1.p·_,.m:rur af 111 11- ..,...... .t d..rC:W.A:<"..m!!Rd...t•l it.t:u•ai• u:o..t:dnpr.nlllnw ..:h!ll

-;o..-.11f •ll•Jct19-.-.dbdpl1-rf ••:..tii.i..raalf-l'!IP'ID" l.iiiihii'la,1dlMdDaL

• • • IFA NON·Clll CLl!AllEV Pi;:RSON ENTERS YOl.'RQIFICF, • • • TJm:..DOCL'MTh"I' MUST Bil PL\CBD FACE DOWN, OOVllltED Oil FILED

• •• WHEN 11lAVINO i'OUR.Ol'Flc;E 1'0R.A SHOR.T Tl\ffi, ' • •

DOCUMENT MUST BE IN A l.OC".!UiD FILE CABINET. OR DESK

• • • \Vll!lM U!AVINO TIJC Ol'l'IC.I< l'OllA f.E}\.l'llJ'x" l'tRJOD ' • • OR ATT.HE.END 01' THEDA'f,

• ' • TillS :OOCUMEN'l' MUST BEJIA-...0 DEL!Vl!RED.

THIS DQ(.'.lJMer.IT WIST BE Pl.ACEJ) Bf>'WND TWO Ul\'ELS ot'LOCIC$ ...

'W11EN !TMOVESllb'n\'EEN OST omCES

IF TH!SlJOC\IMENT .Jr> FOUND llNA'ffi:NOfil), IT .MUST BBJ£TllR.'.itED TO 1llEOCO

• • • ONLY TllE EAD 1)00 IS AOIBORlZEl> TO MAKE.A COMPLETE COPY OF l1DSDOCIJMENT, EXCEPT FOR A DOCUMEl'IT GRE.\TED WITHJN EAD

• WHICJI MAY BE COPIED BY ffiE OJUGlNA.1lJR

A - 4

I I

Figure lb. CBI Coversheet (new)

Confidential Business Information 00 NOT DETACHnuscOVERSffEET

>11'f Ol"H.B:siNb 1 1.((:- No t .,.-r/1.)1 AQ ur:PA tw- 1uqw¥

1 = !._':': ::: '.--------- ··-------1 L- -- l - ---·-------·---·-------------..--..J

Thil <loomnon1 Conlidmi:1Bumm.1nfonnolion ollliintdmid<t lheC!nnWa1crA<t

(CWA).

lfY<>•,..iUfbllydiid""CWA &mn...1.r......uonio""J •<>i to ,,,.,;,,.ill"" may ,,.,_lial>lowidorl8U.SC. lf0< •poinil>!o:6nnpt1>Sl. OOO tmdlur lmpruan11M01t fo,. up lo <m.a -. In addifa111, dioolo...., of C'tl.'A Canfidon6al Dooin.0. lnf- 01t<rt Wiololian oflhop......iumdted.aboWmsyauii;OC1you10 ditapjimry:ldion witll-J!l...nnging 1lP tolll1d illdudmg diB111in>J.

Ifyou fmm<l llW doc!mienl lllllltundo>il, plO-n:.ilm i1ta Ill• interi!I@ Anal)W DiviJi<in; O«ument Conb\'11 Oftker

(202 "-'6-1000

• Co\w\bii f:lliifonon-Oll d.e.,.dpman ...,)'OlA" offi<•.

• Wheo """inii rwr ofl.ko fQr.1uloart limo, Jod U\i•®':""""11 io n file oabiri01 ordnt.

• Wll<R loo'i>$ }Vllf o1l>T •l"'1$11iyperiod "'•I lilo •no of 111<! dny, lock CU.1locwnmt bcltindtwo level» oflocb.

DO NOTUF.TACH rms COVl. SHEF.T

Confidential Business Information

I created a document that contains CBI derivedfrom other sources. Should I mark the document as CBI? YES -you must clearly mark the CBI you derive from other sources as CBI. Depending on the intended use of the document, you may want to have the DCO log it into CBI Management System (CBIMS). For example, you may not want informal notes or internal draft documents to be logged.

However, EAD generated CBI should be logged if it is transferred to another organization (e.g., a contractor). Additionally, you must store your derived CBI in your CBI Working Folder (see Section 2.6).

The DCO, your supervisor, or your project manager can help you determine what CBI materials need to be logged.

A - 5

Protecting CBI in EAD - Procedures and Rules August 1, 20]]

2.3 RECEIPT & TRANSMISSION

Before a facility sends me CBI, what precautions should I advise them to take? You should advise them to do the following:

• clearly mark the information that they claim is CBI,

• "double envelope" their CBI as described in Section 2.6,

• identify facility points-of-contact who are allowed to discuss the CBI,

• address CBI-containing packages to the DC0,1 and

• send the package in a manner that can be tracked (e.g., FedEx).

Additionally, you should advise the facility against sending their CBI using e-mail or fax machines.

What if I'm receiving CBI from one of my support contractors? CBI from a support contractor does not need to be received through the DCO because they are required to follow a security plan that is similar to the OST-CBI Plan. Before you receive CBI from a support contractor, they will have logged the transfer into their tracking system and will have prepared a transmittal sheet. You will eventually return this transmittal to the contractor DCO after you receive the CBI. However, you still need to have the DCO log the CBI as described below.

May I use e-mail, faxes, computer networks, or other similar means to receive CBI? MAYBE - if you take certain precautions, you may electronically receive CBI by using EPA's Central Data Exchange (CDX), operated by the Office of Environmental Information (OEI). If you choose to use CDX, you must specify the following to OEI and its contractors while outlining your information collection mechanism requirements:

1. You require that the data flow be encrypted at all times, beginning with the CBI provider and continuing until receipt by EAD or EAD's contractor, using, at a minimum, standard CDX procedures for encryption that comply with the Cross-Media Electronic Report Regulation

(CROMERR).

2. You require that the encrypted CBI be either turned over to the DCO on removable media or redirected to secure server space owned by a contractor with an approved CBI Plan.

3. You require that the decryption software for the CBI being collected by CDX be used only by users authorized to view the collected CBI.

What do I do when I receive CBI? You must ensure that CBI you receive gets logged into CBIMS. The following is the process that you and the DCO follow to allow proper tracking of CBI documents.

I. The CBI arrives.

2. You take it to the DCO as soon as possible.

3. The DCO logs it into CBIMS.

4. The DCO properly labels the CBI so it is easily identified as CBI. This labeling includes the

CBIMS document number. Labeling includes the use of CBIMS-generated cover sheets. If the CBI is contained on removable media for computers (e.g., CDs, DVD, diskettes, etc.), the DCO marks the media with the CBIMS document number and labels it with "Confidential Business Information."

5. If the CBI is from an EAD contractor, the DCO will complete the contractor-provided transmittal form that accompanied the CBI and return it to the contractor.

6. The DCO returns the CBI to you.

How do I transfer CBI outside EAD? CBI may be transferred only to an organization that has adequate procedures and facilities for protecting CBI from unauthorized disclosure, as identified by the DCO. For

1 CBI from a facility must be sent to either the EAD DCO or the DCO for one of EAD's support contractors. CBI should not be sent directly to staff. ·

A - 6

Protecting CBI in EAD - Procedures and Rules August l,2011 example, an EAD contractor could be one of these facilities. Only the DCO may transfer CBI to another organization. The following is the process for transferring CBI to a CBI-cleared organization:

1. You take the CBI to the DCO for transfer.

2. The DCO verifies the receiving organization is cleared to receive CBI.

3. The DCO claims custody of the document. In other words, it is no longer on your CBIMS inventory.

4. The DCO logs the transfer into CBIMS.

5. The DCO prepares a transmittal sheet and packages the CBI in an appropriately marked envelope

(e.g., "Confidential Business Information -For Addressee Only").

6. The DCO places the envelope into another envelope.

7. The DCO sends the package using a service that provides tracking information for the package.

8. When the recipient receives the CBI package, they fax a copy of the completed transmittal sheet to the DCO for confirmation.

May I use e-mail, faxes, computer networks, or other similar means to transmit CBI? NO -currently, these electronic means are prohibited for transmitting CBI.

May I use e-mail, faxes, or other similar messages to transmit non-CBI files derived from CBI?

MAYBE - if you take certain precautions by following the procedure below, you may transmit non-CBI files that were derived from CBI. In this context, "derived from" refers to files created from a data source identified as CBI. As an example, if you have a spreadsheet or table containing CBI and then mask, combine, or remove information so that the resulting file no longer discloses CBI, then you have a "non- CBI file derived from CBI." Examples of non-CBI files derived from CBI include scrubbed spreadsheets, in which facility-identifying data have been removed, and aggregated records, in which characteristics of groups of facilities are identified, but facility-specific CBI was removed. To generate and transmit non- CBI files derived from CBI, follow the procedure below.

1. You review the file to verify no CBI is hidden in the file. Be aware that some computer documents may have multiple layers that may not be immediately obvious (e.g., spreadsheets).

Additionally, you need to verify no CBI is contained in a file's "undo" history. This process can be helped by the use of plug-in software for Microsoft Office applications which can reveal the formatting codes used and may reveal hidden data. If you are not sure whether certain information is CBI, ask your supervisor or project manager for help.

2. After reviewing the file, you take a copy of the file to the DCO. Do not e-mail this file.

3. The DCO reviews the file to verify it contains no hidden information.2

4. Once the DCO helps you verify no CBI is hidden in your file, you compose a memo-to-file (the project file) that references the file (or files) being transmitted. You must include the following statement in the memo: "I have reviewed the referenced files and certify that they contain no Confidential Business Information." Do not e-mail the file until the DCO verifies receipt of the memo-to-file.

5. The DCO maintains a copy of the file and the memo.

2.4 USE

When I'm using CBI, what precautions should I take to prevent eavesdropping? You must verify that your location will allow reasonable protection of the CBI that you are using. For example, private or semi-private offices are generally acceptable for using CBI. (If you are in a cubicle, you should consider using a conference room to discuss CBI.) Conversely, unacceptable locations include airports, airplanes, hotel lobbies, and other public places.

I'm preparing a ''public," non-CBI document that is derived from CBI. What steps do I need to take to prevent disclosing CBI? While you are composing the document, avoid using information that can be used

2 The DCO may delegate this review to an appropriately qualified person.

A - 7 that could lead to the disclosure of CBI. When you've completed the document, follow the procedure below to verify no CBI is present in the document.

1. You review the file to verify no CBI is hidden in it. Be aware that some computer documents may have multiple layers that may not be immediately obvious (e.g., spreadsheets). Additionally, you

• need to verify no CBI is contained in a file's "undo" history. This process can be helped by the use of plug-in software for Microsoft Office applications which can reveal the formatting codes used and may reveal hidden data. If you are not sure whether certain information is CBI, ask your supervisor or project manager for help.

2. After reviewing the file, you take a copy of the file to the DCO. Do not e-mail this file.

3. The DCO reviews the file to verify it contains no hidden information. The DCO does not assess the content to determine if it is CBI.

4. Once the DCO helps you verify no CBI is hidden in your file, you compose a memo to the project file that references the file(s) being transmitted. You must include the following statement in the memo: "I have reviewed the referenced files and certify that they contain no Confidential Business Information."

5. You give the memo-to-file to the project manager. You must also give a copy to the DCO. Do not publicly distribute the document until the DCO verifies receipt of the memo-to-file.

May EAD, OGCIWLO, and other CBI-cleared EPA staff borrow CBI that is assigned to me? NO -you may not allow other CBI-cleared EPA staff to borrow CBI assigned to you. However, you may allow CBI that is assigned to you to be transferred to other CBI-cleared staff, as described in Section 2.6. You can do this by taking your CBI to the DCO and asking him to re-assign your CBI to your CBI-cleared colleague.

If your colleague later decides to return the CBI to you, he can do so by initiating another document transfer by the DCO.

May I make copies of CBI documents or files? NO -you may not make complete copies of CBI documents, including computer files. If you need a complete copy of a CBI document or file, contact the DCO. The DCO will make the copy and log the copy into CBIMS.

May I copy portions of CBI documents or files? YES -you may copy excerpts or portions of a CBI document or file. Remember, however, to treat any such copies as CBI and protect them accordingly.

Do I need to take any special precautions when using CBI on rewritable media (e.g., "memory sticks' ?

YES - when you are using rewritable media to manipulate CBI, you should use a copy of the CBI.

Whenever practical, original CBI data files should be kept on "permanent" media (e.g., CD-R, DVD-R, etc.).

May I discuss CBI on the telephone? NOT BEST - do not discuss CBI on the telephone unless it is absolutely necessary. A better alternative would be to discuss information that has been "sanitized." For example, you could refer to the facility by its code number and not its name.

If you must discuss CBI on the telephone, take the following precautions:

• Do not discuss CBI on a conference or speakerphone call where there is no reasonable control of who can eavesdrop. For example, you may not discuss CBI on conference calls using "dial-in" conference lines.

• If your office is a cubicle, use a phone in a conference room.

• If you need to discuss CBI with the facility that provided it, speak only to the person that the facility identified as a contact.

3 For a definition of and examples of "non-CBI derived from CBI," see section 2.3; specifically, see the question, "May I use e-mail, faxes, or other similar messages to transmit non-CBI files derived from CBI?"

A - 8

Protecting CBI in EAD - Procedures and Rules August I, 20l1

What must I do when I chair a meeting that uses CBI? If you chair a meeting that uses CBI, you have the following additional responsibilities before and after the meeting:

Before the meeting ...

• Verify all participants have a valid CBI clearance and are assigned to the relevant project. (The DCO can help you verify whether a participant has a valid clearance.) If one of the participants is from a facility that provided the CBI, that person is automatically cleared, but only for the CBI they provided.

• Verify that the meeting location will allow reasonable protection of the CBI that will be discussed.

For example, the meeting area can be a conference room with closing doors.

• Remind the participants that CBI will be used in the meeting. Also, remind them that they are responsible for protecting CBI from unauthorized disclosure.

After the meeting ...

• Verify all CBI that was distributed during the meeting is collected. Ifa participant needs to keep any of the CBI materials, the materials must be appropriately loaned or transferred. (See above).

• Verify that all CBI is removed from the meeting area. For example, no CBI should be on a blackboard, a flipchart, or in a trashcan.

What precautions do I take when I print CBI? After you send CBI to a printer, you must immediately go to the printer to prevent an unauthorized person from viewing or picking-up the document. 4

When I was printing or copying CBI, there was a malfunction. What should I do? If you have printer or copier problems that involve CBI, you must retrieve the printed waste (e.g., waste from paper jams).

Printed waste that contains CBI must be returned to the DCO for destruction. Be sure all printed waste is removed from the machine before leaving it.

What do I need to do before I travel with CBI? You are strongly discouraged from traveling with CBI outside EPA Headquarters. However, if your mission requires it, you may travel with CBI, if you send an e-mail message to the DCO that contains the following information (see next page):

I. The titles and CBIMS Numbers 5 of the CBI documents or files you are taking.

Note: You may only travel with CBI that is logged into CBIMS unless it is CBI that you are collecting while on travel (e.g., site visits).

2. The locations where you will be using the CBI.

3. The reason you need to travel with the CBI.

4. The date when you'll return the CBI to EPA Headquarters.

Note: You must also send your project manager and supervisor a copy of the above e-mail.

How do I "double envelope" CBI? Follow the procedure below to double envelope CBI.

I. ·Seal the document or media within an envelope and clearly mark it with the words "Confidential

Business Information -To Be Opened by the Addressee Only."

2. Mark this envelope with the Addressee's Name, Address, and Telephone Number.

3. Seal the above envelope into another larger envelope that is marked with the Addressee's Name, Address, and Telephone Number.

4 Some CTS network printers will allow you to securely print CBI by using a Personal Identification Number (PIN).

For instructions about using this feature with your network printer, please see the following link:

https://cts.supportportal.com/ics/support/default.asp?dept!D=23011 5 Most documents logged before December 2003 will not have a CBIMS Number. If there is no CBIMS Number for the document, use the CBITS Number (i.e., the number from the old CBI Tracking System).

A - 9

When traveling with CBI, what precautions must I take? You must take the following precautions:

I. The CBI must be double enveloped. You are the addressee unless you are delivering the CBI to transfer it to another organization.

2. When you are enroute with CBI, you must always keep it in your direct possession. For example, do not check CBI with your luggage.

3. When you are not using the CBI, store it as described in Section 2.5.

When I carry CBI outside EAD office space, what precautions should I take? You must take the following precautions:

I . The CBI must be double enveloped. You are the addressee unless you are delivering the CBI to transfer it to another organization.

2. When you are en route with CBI, you must always keep it in your direct possession.

2.5 STORAGE

Where must I store my CBI? You must store CBI in a locked cabinet, separate from your non-CBI files.

The locked cabinet must be located in an office space that is access-controlled by a card reader or within an…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.