T3151 Attachment 4 - Security Questionnaire.pdf

PDF 3 MB Posted

Attached to
T3151 - Workforce Development Case Management Solution State and local contract opportunity
Solicitation number
25DPP01053
Issued by
New Jersey

About this file

This document is the State of New Jersey Security Due Diligence Third-Party Information Security Questionnaire, published by the New Jersey Cybersecurity and Communications Integration Cell (NJCCIC). The purpose of this questionnaire is to ensure the security and privacy of State of New Jersey information systems and information, regardless of the location or the party responsible for providing the systems, applications, or services. Based on the overall risk rating determined by the NJCCIC, the sponsoring agency will decide if the risk rating is acceptable to proceed for the given engagement. The State may require the submitting organization to implement additional risk mitigation controls prior to any contract or agreement award, depending on the criticality and sensitivity of the information system and information in scope, as well as legal, regulatory, and/or contractual requirements.

The questionnaire covers a comprehensive set of security control areas, including information security program management, compliance, personnel security, security awareness and training, risk management, privacy, asset management, security categorization, data protection, threat management, access management, security engineering and architecture, configuration management, endpoint security, network security, cloud security, vulnerability and patch management, system development and acquisition, and incident response. The submitted questionnaire and supporting documentation will be treated as confidential to the extent permitted by law.

View the file

Other files for this state and local contract opportunity

Other files attached to T3151 - Workforce Development Case Management Solution, newest first.
File Type Posted
T3151 Appendix D - Interface Reference Document.docx DOCX document
T3151 Attachment 3 - Price Sheet 12.20.24~1.xlsx XLSX spreadsheet
T3151 Bid Amendment 2_1.17.25 Rev~2.pdf PDF
T3151 Appendix A - Requirements 8.21.2024.xlsx XLSX spreadsheet
T3151 Appendix B - Program Overview.docx DOCX document
T3151 State Standard Terms and Conditions 2.8.2024.pdf PDF
T3151 Bid Amendment 3 2.10.25~1.pdf PDF
Bid Solicitation Checklist 1.24.2024.pdf PDF
T3151 - Attachment 3 - Price Sheet 7.5.24~1.xlsx XLSX spreadsheet
T3151 Pre-Quote Conference PPT.pptx PPTX presentation
T3151 Workforce Mgt Syst FINAL CLEAN 9.17.24.docx DOCX document
T3151 Updated OHSP Security Questionnaire 12.6.2024~1.pdf PDF
T3151 Workforce Mgt Syst 1.15.25 Final~2.docx DOCX document
T3151 Appendix C - AOSOS Current Architecture.docx DOCX document
T3151 Bid Amendment #1.pdf PDF
T3151 Appendix A - Requirements Final Rev~1.xlsx XLSX spreadsheet
Show all 16

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

State of New Jersey Security Due Diligence Third-Party Information Security Questionnaire

Published by:

New Jersey Cybersecurity and Communications Integration Cell

Bid Solicitation #:

For:

TABLE OF CONTENTS

Confidentiality / Non-Disclosure Agreement Introduction Confidentiality of Third-Party Information Security Questionnaire Submissions About The New Jersey Cybersecurity and Communications Integration Cell (NJCCIC)

SECTION I – DATA ACCESS AND SECURITY CATEGORIZATION

SECTION II – THIRD-PARTY ORGANIZATION INFORMATION

SECTION III – THIRD-PARTY INFORMATION SECURITY PROGRAM

1.0 – Information Security Program Management (PM)

2.0 – Compliance (CP)

3.0 – Personnel Security (PS)

4.0 – Security Awareness and Training (AW)

5.0 – Risk Management (RM)

6.0 – Privacy (PR)

7.0 – Asset Management (AM)

8.0 – Security Categorization (SC)

9.0 – Media and Cryptographic Protection (DP)

10.0 – Access Management, Identity, and Authentication (AC)

11.0 – Security Engineering and Architecture (SE)

12.0 – Configuration Management (CM)

13.0 – Endpoint Security (ES)

14.0 – ICS/SCADA/OT Security (OT)

15.0 – Internet of Things Security (IT)

16.0 – Mobile Device Security (MD)

17.0 – Network Security (NS)

18.0 – Cloud Security (CI)

19.0 – Change Management (CH)

20.0 – Maintenance (MA)

21.0 – Threat Management (TM)

22.0 – Vulnerability and Patch Management (VU)

23.0 – Continuous Monitoring (CO)

24.0 – System Development and Acquisition (SD)

25.0 – Project and Resource Management (PM)

26.0 – Capacity and Performance Management (CA)

27.0 – Third-Party Management (TP)

28.0 – Physical and Environmental Security (PE)

29.0 – Contingency Planning (CT)

30.0 – Incident Response (IR)

SECTION IV – SUPPORTING DOCUMENTATION TO BE SUBMITTED

APPENDIX A – GLOSSARY

CONFIDENTIALITY/NON-DISCLOSURE AGREEMENT

THIS CONFIDENTIALITY/NON-DISCLOSURE AGREEMENT (“Agreement”) is effective as of the date last written below and is by and between the New Jersey Office of Homeland Security and Preparedness (“NJOHSP”) with its principal address at 1200 Negron Drive, Hamilton New Jersey 08691; the Department of the Treasury – Division of Purchase and Property (“Division”), with its principal place of business at 33 West State Street, Trenton New Jersey 08625 (hereinafter collectively referred to as “State”) and , with its principal place of business at , its employees, agents, contractors, and legal representatives (hereinafter referred to as the “Vendor”).

WHEREAS, the Vendor intends to submit a Quote to the State in response to a Bid Solicitation advertised by the Division; and

WHEREAS, the Vendor is required to complete the State of New Jersey Security Due Diligence Third-Party Information Security Questionnaire and provide applicable supporting documents (collectively “Security Questionnaire”) regarding its security and privacy controls and include it with its Quote submitted to the Division; and

WHEREAS, NJOHSP will review the Security Questionnaire to determine whether the Vendor’s security and privacy controls meet the State of New Jersey’s objectives as outlined and documented in the Statewide Information Security Manual and the corresponding requirements in the Bid Solicitation; and

WHEREAS, the State recognizes that the information contained in the Security Questionnaire may contain Confidential Information;

NOW THEREFORE, in consideration of the mutual promises and covenants contained herein, the Vendor and the State do hereby agree as follows:

1. Confidential Information which may be included on the Security Questionnaire means all information, including data, disclosed directly or indirectly, through any means of communication (including in oral, written or digital form) or observation, by or on behalf of the Vendor to or for the benefit of NJOHSP or the Division and all information or data derived there from, that relates to the Vendor’s security and privacy controls as contained or referenced in the Security Questionnaire;

2. Confidential Information shall not include information that: (a) is or becomes a part of the public domain through no act or omission of the other party, except that if the information or data is personally identifying to a person or entity regardless of whether it has become part of the public domain through other means, the other party must maintain full efforts under the Contract to keep it confidential; (b) was in the other party’s lawful possession prior to the disclosure and had not been obtained by the other party either directly or indirectly from the disclosing party; (c) is lawfully disclosed to the other party by a third party without restriction on the disclosure; or (d) is independently developed by the other party;

3. The Vendor acknowledges that the NJOHSP and the Division are public agencies subject to the New Jersey Open Public Records Act, N.J.S.A. 47:1A-1 et seq. (“OPRA”), and the common law Right to Know. OPRA is generally construed in favor of granting public access to documents maintained in the course of its official business;

4. In the event that the NJOHSP or the Division receives an appropriate request pursuant to OPRA and/or the common law Right to Know related to the Vendor’s Security Questionnaire, NJOHSP and the Division agree not to disclose the Confidential Information contained on the Vendor’s Security Questionnaire to a third party;

5. Notwithstanding the requirements of this Agreement, NJOHSP or the Division may release the Security Questionnaire if directed to do so by operation of law, pursuant to a lawfully issued subpoena, or pursuant to a ruling by a court or arbitrator of competent jurisdiction. NJOHSP or the Division shall notify the Vendor, at the address listed above, of such ruling or directive upon being made aware of same;

6. This Agreement shall be governed by the applicable laws, regulations and rules of evidence of the State of New Jersey without reference to conflict of laws principles and any legal action regarding this Agreement shall be filed in the appropriate Division of the New Jersey Superior Court;

7. This is the complete Agreement between the State and the Vendor with respect to the treatment of the Security Questionnaire and shall have no effect on the other components of the Vendor’s submitted Quote; and

8. Any revision to this standard Agreement by the Vendor that was not approved and accepted by the State during the Question and Answer period shall render the Agreement VOID and the Agreement shall have no legal effect. Such revision, however, will not affect NJOHSP’s review of the Security Questionnaire.

IN WITNESSETH WHEREOF, the State and Vendor have executed this Agreement, effective as of the date signed below by the Vendor.

FOR THE STATE OF NEW JERSEY

Michael T. Geraghty Chief Information Security Officer - State of New Jersey Director – NJ Cybersecurity and Communications Integration Cell | NJCCIC Office of Homeland Security and Preparedness

Amy Davis, Acting Director Department of the Treasury Division of Purchase and Property

FOR THE VENDOR

Signature Date

Print Name and Title

INTRODUCTION

The State of New Jersey’s Third-Party Information Security Questionnaire is intended to ensure the security and privacy of State information systems and information, regardless of the location or the party responsible for providing the systems, applications, or services. The Questionnaire is aligned with the controls and security objectives as documented in the Statewide Information Security Manual (SISM) has which been derived from applicable State and federal laws; industry best practices including the National Institute of Standards and Technology (NIST) Cybersecurity Framework for Improving Critical Infrastructure; the Center for Internet Security (CIS) Top 20 Critical Security Controls; the Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM); lessons learned; and other New Jersey State Government business and technology related considerations.

Based on the overall risk rating as determined by the NJCCIC, the sponsoring Agency will determine if the risk rating is acceptable to proceed for the given engagement. Based on the criticality and/or sensitivity of the information system and information in scope, as well as the legal, regulatory, and/or contractual requirements, the State may require the submitting organization to implement additional risk mitigation controls prior to the award of any contract or agreement.

CONFIDENTIALITY OF THIRD-PARTY INFORMATION SECURITY QUESTIONNAIRE SUBMISSIONS

An uncompleted Third-Party Information Security Questionnaire is considered a public document. It may be disseminated via authorized channels and requires no confidentiality protections. A completed Third-Party Information Security Questionnaire along with all supporting documentation would inherently include administrative or technical information regarding computer hardware, software, and networks which, if disclosed would jeopardize computer security of the submitting organization and/or the State of New Jersey.

As such, to the extent permitted by law, all non-public information submitted as part of a completed Third- Party Information Security Questionnaire, including but not limited to supporting documents, records, notes, written comments, reports, or analysis generated in or in the execution of a vendor’s submission shall be treated and deemed as confidential and exempt from public disclosure under the State of New Jersey Open Public Records Act (N.J.S.A. 47:1A-1 et seq.) and the Domestic Security Preparedness Act P.L. 2001, c.246.

ABOUT THE NEW JERSEY CYBERSECURITY AND COMMUNICATIONS INTEGRATION CELL (NJCCIC)

The New Jersey Cybersecurity and Communications Integration Cell is a component organization within the New Jersey Office of Homeland Security and Preparedness (OHSP). The NJCCIC is comprised of OHSP, Office of Information Technology, and New Jersey State Police personnel working in concert to make New Jersey more resilient to cyber threats. As part of its portfolio of duties, the NJCCIC is responsible for conducting information security risk assessments of third parties with access to State of New Jersey information assets.

For more information about the NJCCIC, please visit www.cyber.nj.gov.

https://www.nj.gov/it/docs/ps/NJ_Statewide_Information_Security_Manual.pdf tyqdoob Highlight

SECTION I – DATA ACCESS AND SECURITY CATEGORIZATION – FOR THE STATE OF NEW JERSEY

DATA ACCESS AND SECURITY CATEGORIZATION

Please select the data types that will be generated, accessed, processed, stored, and/or transmitted as part of your engagement with the State of New Jersey. For information on data types and security categorization please refer to Appendix A – Glossary.

Non-Sensitive Data Sensitive Data

Public Data: Personally Identifiable Information:

Criminal Justice Information:

Federal Tax Information:

Electronic Protected Health Information:

Social Security Administration Provided Information:

Cardholder and/or Sensitive Authentication Data:

Other Sensitive Information not listed above:

If you selected Other Sensitive Information, please describe the information below:

SECTION II – THIRD-PARTY ORGANIZATION INFORMATION

THIRD-PARTY ORGANIZATION PROFILE

United States

State:

Zip/Postal Code:

Country:

Organization Name:

Mailing Address:

City:

Organization Website URL:

SUBMITTER’S CONTACT INFORMATION

First Name:

Last Name:

Title:

THIRD-PARTY ORGANIZATION INFORMATION SECURITY OFFICER CONTACT INFORMATION

THIRD-PARTY INFORMATION SECURITY QUESTIONNAIRE

Email Address:

Phone #:

First Name:

Last Name:

Email Address:

Phone #:

Date Submitted:

SECTION III – THIRD-PARTY INFORMATION SECURITY PROGRAM

For each of the control areas below, please provide accurate responses as they apply to your information security program and the scope of the anticipated engagement with the State of New Jersey. You are required to provide answers for all controls and questions as it applies to the scope of your engagement with the State of New Jersey. For any of the control areas or supplemental information questions in which you answer “No” or “N/A” (Not Applicable) please provide additional information explaining your answers in the “Optional - Please provide any additional information” text field. Some control areas include supplemental questions and may require additional documentation to be submitted.

1.0 – INFORMATION SECURITY PROGRAM MANAGEMENT (PM)

1.1 – The organization establishes and maintains a framework to provide assurance that information security strategies are aligned with and support the State's business objectives, are consistent with applicable laws and regulations through adherence to policies and internal controls, and provide assignment of responsibility, all in an effort to manage risk.

Information security program management includes, at a minimum, the following:

• Establishment of a management structure with clear reporting paths and explicit responsibility for information security;

• Creation, maintenance, and communication of information security policies, standards, procedures, and guidelines to include the control areas listed below;

• Development and maintenance of relationships with external organizations to stay abreast of current and emerging security issues and for assistance, when applicable; and

• Independent review of the effectiveness of the organization’s information security program.

Supplemental Information

1.2 – Do you align your information security program following industry standard frameworks such as the NIST CSF, ISO 27001, CIS Top 20, CoBIT? If yes, please list which framework(s) you employ.

1.3 – Describe the process you follow, and how frequently, to review and update your security program and safeguards?

1.4 – If you employ an Exception Management Policy please document the processes for the submission, review, documentation, and the application of exceptions to compliance with established information security policies and standards.

1.5 – Please detail your disciplinary or sanction policy established for personnel and contractors who have violated security policies and procedures?

1.6 – Optional - Please provide any additional information relative to this control area.

2.0 – COMPLIANCE (CP)

2.1 – The organization develops, implements, and governs processes to ensure compliance with all applicable statutory, regulatory, contractual, and internal policy obligations. Ensuring compliance includes, at a minimum:

• Statutory, Regulatory, and Contractual Compliance;

• Security controls oversight; and

• Periodically conducting security assessments.

Supplemental Information

2.2 – Indicate all third-party security audits, and subsequent last audit dates, conducted at your organization to ensure compliance with applicable laws, regulations and contractual requirements.

CJIS

IRS-1075

FISMA

SOC2

PCI-DSS

Social Security Admin.

FedRAMP

Other:

2.3 – Specify all compliance frameworks and standards your organization follows (e.g., GDPR, COBIT, ISO, etc.). Please provide documentation for all IT operational, security, and privacy-related standards, certifications, and/or regulations for which your organization or the intended product/system/application/service is compliant.

2.4 – Optional - Please provide any additional information relative to this control area.

3.0 – PERSONNEL SECURITY (PS)

3.1 – The organization implements processes to ensure all personnel, with access to relevant State information, have the appropriate background, skills, and training to perform their job responsibilities in a competent, professional, and secure manner. Workforce security controls include, at a minimum:

• Position descriptions that include appropriate language regarding each role’s security requirements;

• To the extent permitted by law, employment screening checks are conducted and successfully passed for all personnel prior to beginning work or being granted access to organization information assets;

• Rules of behavior are established and procedures are implemented to ensure personnel are aware of and understand usage policies applicable to the organization’s information and information systems;

• Access reviews are conducted upon personnel transfers and promotions to ensure access levels are appropriate;

• Disabling system access for terminated personnel and collecting all organization owned assets prior to the individual’s departure; and

• Procedures are implemented that ensure all personnel are aware of their duty to protect organizational information assets and their responsibility to immediately report any suspected information security incidents.

Supplemental Information

3.2 – Please describe the screening and background checks you conduct for your workforce (personnel, contractors, and third-parties) that have access to sensitive information (e.g., CJI, FTI, PCI, etc.).

3.3 – Are all personnel required to sign an Acceptable Use Policy (AUP)? If you answered yes, please submit a copy of the AUP. If no, please explain.

3.4 – Describe the procedures the organization follows to govern changes in employment (transfers, promotions, etc.) and/or termination of staff.

3.5 – Optional - Please provide any additional information relative to this control area.

4.0 – SECURITY AWARENESS AND TRAINING (AW)

4.1 – The organization provides periodic and on-going information security awareness and training to ensure personnel are aware of information security risks and threats, understand their responsibilities, and are aware of the statutory, regulatory, contractual, and policy requirements that are intended to protect information systems and State Confidential Information from a loss of confidentiality, integrity, availability and privacy. Security awareness and training includes, at a minimum:

• Personnel are provided with security awareness training upon hire and at least annually, thereafter;

• Security awareness training records are maintained as part of the personnel record;

• Role-based security training is provided to personnel with respect to their duties or responsibilities (e.g. network and systems administrators require specific security training in accordance with their job functions); and

• Individuals are provided with timely information regarding emerging threats, best practices, and new policies, laws, and regulations related to information security.

4.3 – Optional - Please provide any additional information relative to this control area.

4.2 – Describe the security awareness and training program you provide to personnel and contractors to ensure they are aware of information security risks and threats, understand their responsibilities, and are aware of the statutory and policy requirements. Is the training mandatory? How is training by personnel documented and tracked? How often is security awareness training conducted?

Supplemental Information

5.0 – RISK MANAGEMENT (RM)

5.1 – The organization establishes requirements for the identification, assessment, and treatment of information security risks to operations, information, and/or information systems. Risk management requirements shall include, at a minimum:

• Categorizing systems and information based on their criticality and sensitivity;

• Ensuring risks are identified, documented and assigned to appropriate personnel for assessment and treatment;

• Ensuring risk assessments are conducted throughout the lifecycles of information systems to identify, quantify, and prioritize risks against operational and control objectives and to design, implement, and exercise controls that provide reasonable assurance that security objectives will be met; and

• Mitigating risks to an acceptable level and prioritizing remediation actions based on risk criteria and establishing timelines for remediation. Risk treatment may also include the acceptance or transfer of risk.

Supplemental Information

5.2 – Describe the risk management processes you employ that account for the identification, assessment, and treatment of risks that can adversely impact the confidentiality, integrity, and availability of the product/system/application/service. How often are these risk management processes performed?

5.3 – Describe how risks and risk mitigation efforts are evaluated and prioritized. Include details on how you document and verify the results of these risk mitigation processes?

5.4 – Optional - Please provide any additional information relative to this control area.

6.0 – PRIVACY (PR)

6.1 – The organization establishes appropriate processes and safeguards necessary to protect the personally identifiable information (PII) that the organization collects, stores, processes, uses, and transmits on behalf of the State of New Jersey. Privacy controls and processes include, but are not limited to:

• Ensuring only the minimum amount of PII necessary to carry out the business function, and in accordance with applicable laws and regulations, is collected and stored;

• Safeguarding PII through the implementation of administrative, physical, and technical controls (e.g., access controls, encryption and tokenization, etc.); and

• Securely deleting PII when no longer necessary for business or legal purposes.

Supplemental Information

6.2 – Describe your privacy program and detail how it maintains currency with evolving applicable privacy requirements. Please submit a copy of or provide a link to your privacy program.

6.3 – Optional - Please provide any additional information relative to this control area.

7.0 – ASSET MANAGEMENT (AM)

7.1 – The organization implements administrative, technical, and physical controls necessary to safeguard information technology assets from threats to their confidentiality, integrity, or availability, whether internal or external, deliberate or accidental. Asset management controls include, but are not limited to:

• Information technology asset identification and inventory;

• Assigning custodianship of assets; and

• Restricting the use of non-authorized devices.

Supplemental Information

7.2 – Optional - Please provide any additional information relative to this control area.

8.0 – SECURITY CATEGORIZATION (SC)

8.1 – The organization implements processes that classify information and categorize information systems throughout their lifecycles according to their sensitivity and criticality, along with the risks and impact should there be a loss of confidentiality, integrity, availability, or breach of privacy.

Information classification and system categorization includes labeling and handling requirements. Security Categorization controls include, but are not limited to, the following:

• Implementing a data protection policy;

• Classifying data and information systems in accordance with their sensitivity and criticality;

• Masking sensitive data that is displayed or printed; and

• Implementing handling and labeling procedures.

Supplemental Information

8.2 – Optional - Please provide any additional information relative to this control area.

9.0 – MEDIA AND CRYPTOGRAPHIC PROTECTION (DP)

9.1 – The organization establishes controls to ensure data and information, in all forms and mediums, are protected throughout their lifecycles based on their sensitivity, value, and criticality, and the impact that a loss of confidentiality, integrity, availability, and privacy would have on the organization, business partners, or individuals. Media protections include, but are not limited to:

• Media storage/access/transportation;

• Maintenance of sensitive data inventories;

• Application of cryptographic protections;

• Restricting the use of portable storage devices;

• Establishing records retention requirements in accordance with business objectives and statutory and regulatory obligations; and

• Media disposal/sanitization.

Supplemental Information

9.2 – Detail the mechanisms used to secure data at rest, data in transit, and data in use.

9.3 – Describe cryptographic standards and technologies employed to protect sensitive State of New Jersey data. Include details on the encryption or hashing algorithms used, key management processes, use of hardware or software key storage, key fragmentation, etc.

9.4 – Optional - Please provide any additional information relative to this control area.

10.0 – ACCESS MANAGEMENT, IDENTITY, AND AUTHENTICATION (AC)

10.1 – The organization establishes security requirements and ensures appropriate mechanisms are provided for the control, administration, and tracking of access to, and the use of, the organization’s information systems. Access management includes, at a minimum:

• Ensuring the principle of least privilege is applied for specific duties and information systems (including specific functions, ports, protocols, and services) so processes operate at privilege levels no higher than necessary to accomplish required organizational missions and/or functions;

• Implementing account management processes for registration, updates, changes, and de-provisioning of system access;

• Ensuring the principle of least privilege when provisioning access to organizational assets;

• Provisioning access according to an individual’s role and business requirements for such access;

• Implementing the concept of segregation of duties by disseminating tasks and associated privileges for specific sensitive duties among multiple people;

• Establishing and managing unique identifiers (e.g., User-IDs) and secure authenticators (e.g., passwords, biometrics, personal identification numbers, etc.) to support nonrepudiation of activities by users or processes;

• Implementing multi-factor authentication (MFA) requirements for access to sensitive and critical systems, and for remote access to the organization’s systems and information; and

• Conducting periodic reviews of access authorizations and controls.

Supplemental Information

10.2 – Describe your organization’s processes and methods utilized for granting access, reviewing access, and documenting the review. Do you centrally manage access throughout the organization? Explain in detail.

10.3 – Detail your password and authentication policy and standards. Include minimum length, lockout, complexity, timeout period, password history, etc. How are these managed and enforced?

10.4 – Describe the process of controlling and monitoring the use of privileged and administrative accounts within your organization. Is Multi-Factor Authentication (MFA) required for privileged access? Do end-users have local administrator access?

10.5 – If personnel and/or contractors are provided with remote access to your organization’s internal network, please describe the mechanisms used for authentication and authorization. Detail the use of MFA for remote access, if applicable.

10.6 – Optional - Please provide any additional information relative to this control area.

11.0 – SECURITY ENGINEERING AND ARCHITECTURE (SE)

11.1 – The organization employs security engineering and architecture principles for all information technology assets, such that they incorporate industry recognized leading security practices and address applicable statutory and regulatory obligations. Applying security engineering and architecture principles include, at a minimum:

• Implementing configuration standards that are consistent with industry-accepted system hardening standards and addressing known security vulnerabilities for all system components;

• Establishing a defense in-depth security posture that includes layered technical, administrative, and physical controls;

• Incorporating security requirements into the systems throughout their life cycles;

• Delineating physical and logical security boundaries;

• Tailoring security controls to meet organizational and operational needs;

• Performing threat modeling to identify use cases, threat agents, attack vectors, and attack patterns as well as compensating controls and design patterns needed to mitigate risk;

• Implementing controls and procedures to ensure critical systems fail-secure and fail-safe in known states; and

• Ensuring information system clock synchronization across the organization.

Supplemental Information

11.2 – Optional - Please provide any additional information relative to this control area.

12.0 – CONFIGURATION MANAGEMENT (CM)

12.1 – The organization ensures that baseline configuration settings are established and maintained in order to protect the confidentiality, integrity, and availability of all information technology assets.

Secure configuration management includes, but is not limited to:

• Hardening systems through baseline configurations; and

• Configuring systems in accordance with the principle of least privilege to ensure processes operate at privilege levels no higher than necessary to accomplish required functions.

Supplemental Information

12.2 – Describe the processes employed to establish and maintain baseline security configuration settings across your organization. Industry standard configuration and hardening standards include, but are not limited to, CIS Benchmarks, DISA STIGs, and component vendor security configuration guides.

12.3 – Describe the processes and protective technologies employed to verify these security configuration settings are maintained and to detect any attempts to adversely impact the confidentiality, integrity, and availability of components or data in your organization. Protective technologies include, but are not limited to, firewalls, host and network intrusion detection/protection systems, file integrity monitoring, and anti-malware software.

12.4 – Optional - Please provide any additional information relative to this control area.

13.0 – ENDPOINT SECURITY (ES)

13.1 – The organization ensures that endpoint devices are properly configured, and measures are implemented to protect the organization’s information and information systems from a loss of confidentiality, integrity, and availability. Endpoint security includes, at a minimum:

• Maintaining an accurate and updated inventory of endpoint devices;

• Applying security categorizations and implementing commensurate safeguards on endpoints;

• Maintaining currency with operating system and software updates and patches;

• Establishing physical and logical access controls;

• Applying data protection measures (e.g., cryptographic protections);

• Implementing anti-malware software, host-based firewalls, and port and device controls;

• Implementing host intrusion detection and prevention systems (HIDS/HIPS) where applicable;

• Restricting access and/or use of ports and I/O devices; and

• Ensuring audit logging is implemented and logs are reviewed on a continuous basis.

Supplemental Information

13.2 – Describe the standard personnel issued device security configuration/features (Login Password, anti-malware, Full Disk Encryption, Administrative Privileges, Firewall, Auto-lock, etc.).

13.3 – Are all endpoints in or with access to the production environment centrally managed? Explain.

13.4 – Describe how you limit data exfiltration of sensitive data from endpoints in or with access to the production environment.

13.5 – Optional - Please provide any additional information relative to this control area.

14.0 – ICS/SCADA/OT SECURITY (OT)

14.1 – The organization implements controls and processes to ensure risks, including risks to human safety, are accounted for and managed in the use of Industrial Control Systems (ICS), Supervisory Control and Data Acquisition (SCADA) systems, and Operational Technologies (OT). ICS/SCADA/OT Security requires the application of all of the enumerated control areas included here in this document, including, at a minimum:

• Conducting risk assessments prior to implementation and throughout the lifecycles of ICS/SCADA/OT assets;

• Developing policies and standards specific to ICS/SCADA/OT assets;

• Ensuring the secure configuration of ICS/SCADA/OT assets;

• Segmenting ICS/SCADA/OT networks from the rest of the organization’s networks;

• Ensuring least privilege and strong authentication controls are implemented;

• Implementing redundant designs or failover capabilities to prevent business disruption or physical damage; and

• Conducting regular maintenance on ICS/SCADA/OT systems.

Supplemental Information

14.2 – As applicable, list and describe any ICS/SCADA/OT systems used across your organization and detail how those systems are secured physically, administratively, and technically.

14.3 – Optional - Please provide any additional information relative to this control area.

15.0 – INTERNET OF THINGS SECURITY (IT)

15.1 – The organization implements controls and processes to ensure risks are accounted for and managed in the use of Internet of Things (IoT) devices including, but not limited to, physical devices, vehicles, appliances and other items embedded with electronics, software, sensors, actuators, and network connectivity which enables these devices to connect and exchange data. IoT security includes, at a minimum:

• Developing policies and standards specific to IoT assets;

• Ensuring the secure configuration of IoT assets;

• Conducting risk assessments prior to implementation, and throughout the lifecycles of IoT assets;

• Segmenting IoT networks from the rest of the organization’s networks; and

• Ensuring least privilege and strong authentication controls are implemented.

Supplemental Information

15.2 – As applicable, list and describe any IoT devices used across your organization and detail how those devices are secured physically, administratively, and technically. Include information on network segmentation, access and authentication, and security updates.

15.3 – Optional - Please provide any additional information relative to this control area.

16.0 – MOBILE DEVICE SECURITY (MD)

16.1 – The organization establishes administrative, technical, and physical security controls required to effectively manage the risks introduced by mobile devices used for organizational business purposes. Mobile device security includes, at a minimum:

• Establishing requirements for authorization to use mobile devices for organizational business purposes;

• Establishing Bring Your Own Device (BYOD) processes and restrictions;

• Establishing physical and logical access controls;

• Implementing network access restrictions for mobile devices;

• Implementing mobile device management solutions to provide centralized management of mobile devices and to ensure technical security controls (e.g., encryption, authentication, remote-wipe, etc.) are implemented and updated as necessary;

• Establishing approved application stores from which applications can be acquired;

• Establishing lists of approved applications that can be used; and

• Training of mobile device users regarding security and safety.

16.2 – Does your organization allow for BYOD devices to connect to your internal network? If so, how are BYOD managed so they do not introduce additional risks?

16.3 – Optional - Please provide any additional information relative to this control area.

17.0 – NETWORK SECURITY (NS)

17.1 – The organization implements defense-in-depth and least privilege strategies for securing the information technology networks that they operate. To ensure information technology resources are available to authorized network clients and protected from unauthorized access, organizations must:

• Include protection mechanisms for network communications and infrastructure (e.g., layered defenses, denial of service protection, encryption for data in transit, etc.);

• Include protection mechanisms for network boundaries (e.g., limit network access points, implement firewalls, use Internet proxies, restrict split tunneling, etc.);

• Control the flow of information (e.g., deny traffic by default/allow by exception, implement Access Control Lists, etc.); and

• Control access to the organization’s information systems (e.g., network segmentation, network intrusion detection and prevention systems, wireless restrictions, etc.).

Supplemental Information

17.2 – Optional - Please provide any additional information relative to this control area.

18.0 – CLOUD SECURITY (CL)

18.1 – The organization establishes security requirements that govern the use of private, public, and hybrid cloud environments to ensure risks associated with a potential loss of confidentiality, integrity, availability, and privacy are managed. This includes, at a minimum:

• Security is accounted for in the acquisition and development of cloud services;

• The design, configuration, and implementation of cloud-based applications, infrastructure and system interfaces are conducted in accordance with mutually agreed-upon service, security, and capacity-level expectations;

• Security roles and responsibilities for the organization and the cloud provider are delineated and documented; and

• Controls necessary to protect sensitive data in public cloud environments are implemented.

Supplemental Information

18.2 – Optional - Please provide any additional information relative to this control area.

19.0 – CHANGE MANAGEMENT (CH)

19.1 – The organization establishes controls required to ensure change is managed effectively. Organizations must ensure changes are appropriately tested, validated, and documented before implementing any change on a production network.

Change management provides the organization with the ability to handle changes in a controlled, predictable, and repeatable manner, and to identify, assess, and minimize the risks to operations and security. Change management controls include, at a minimum:

• Notifying all stakeholders of changes;

• Conducting a security impact analysis for changes; and

• Verifying security functionality after the changes have been made.

Supplemental Information

19.2 – Describe the change control process as it relates to patches, hot-fixes, upgrades, and configuration changes within your organization. Include information on review of proposed changes.

Include information on timelines used for testing, implementation, and emergency change control.

19.3 – Optional - Please provide any additional information relative to this control area.

20.0 – MAINTENANCE (MA)

20.1 – The organization implements processes and controls to ensure that information assets are properly maintained, thereby minimizing the risks from emerging information security threats and/or the potential loss of confidentiality, integrity, or availability due to system failures. Maintenance security includes, at a minimum:

• Conducting scheduled and timely maintenance;

• Ensuring individuals conducting maintenance operations are qualified and trustworthy; and

• Vetting, escorting, and monitoring third-parties conducting maintenance operations on the organization’s information technology assets.

Supplemental Information

20.2 – Optional - Please provide any additional information relative to this control area.

21.0 – THREAT MANAGEMENT (TM)

21.1 – The organization establishes effective communication protocols and processes to collect and disseminate actionable threat intelligence, thereby providing component units and individuals with the information necessary to effectively manage risk associated with new and emerging threats to the organization’s information technology assets and operations. Threat management includes, at a minimum:

• Developing, implementing, and governing processes and documentation to facilitate the implementation of a threat awareness policy, as well as associated standards, controls and procedures; and

• Subscribing to and receiving relevant threat intelligence information from the US CERT, the organization’s vendors, and other sources as appropriate.

Supplemental Information

21.2 – List and describe the threat intelligence sources you subscribe to or follow in order to keep abreast of potential security vulnerabilities and threats.

21.3 – Optional - Please provide any additional information relative to this control area.

24.5 – Optional - Please provide any additional information relative to this control area.

22.0 – VULNERABILITY AND PATCH MANAGEMENT (VU)

22.1 – The organization implements proactive vulnerability identification, remediation, and patch management practices to minimize the risk of a loss of confidentiality, integrity, and availability of information system, networks, components, and applications. Vulnerability and patch management practices include, at a minimum:

• Prioritizing vulnerability scanning and remediation activities based on the criticality and security categorization of the organization’s systems and information, and the risks associated with a loss of confidentiality, integrity, availability, and/or privacy;

• Maintaining software and operating systems at the latest vendor-supported patch levels;

• Conducting penetration testing and red team exercises; and

• Employing qualified third-parties to conduct Independent vulnerability scanning, penetration testing, and red-team exercises.

22.2 – Describe your network vulnerability scanning and penetration testing process. Who conducts your network penetration testing and vulnerability scans? Are these vulnerability scans and penetration tests both external and internal? How often are vulnerability scans and penetration tests conducted?

22.3 – Describe how patches and vulnerability remediation processes prioritized. How do you document and verify the results of these remediation efforts?

22.4 – As applicable, please provide details on the most recent Application Code Review or Penetration Testing Reports carried out by independent third parties.

22.5 – Optional - Please provide any additional information relative to this control area.

23.0 – CONTINUOUS MONITORING (CO)

23.1 – The organization implements continuous monitoring practices to establish and maintain situational awareness regarding potential threats to the confidentiality, integrity, availability, privacy, and safety of the organization’s information and information systems through timely collection and review of security-related event logs. Continuous monitoring practices include, at a minimum:

• Centralizing the collection and monitoring of event logs;

• Ensuring the content of audit records includes all relevant security event information;

• Protection of audit records from tampering; and

• Detecting, investigating, and responding to incidents discovered through monitoring.

Supplemental Information

23.2 – Describe the processes and technologies used for monitoring, alerting on, and logging of application, system, network, and security events. Include information on retention of logs and how they are reviewed.

23.3 – Optional - Please provide any additional information relative to this control area.

24.0 – SYSTEM DEVELOPMENT AND ACQUISITION (SD)

24.1 – The organization establishes security requirements necessary to ensure that systems and application software programs developed by the organization or third-parties (e.g., vendors, contractors, etc.) perform as intended to maintain information confidentiality, integrity, and availability, and the privacy and safety of individuals. System development and acquisition security practices include, at a minimum:

• Secure coding;

• Separation of development, testing and operational environments;

• Information input restrictions;

• Input data validation;

• Error handling;

• Security testing throughout development;

• Restrictions for access to program source code; and

• Security training of software developers and system implementers.

Supplemental Information

24.2 – As applicable, describe your Software Development Lifecycle (SDLC) including developers’ access to production data, systems, and applications; version control tools used; promotion from development to production, etc.

24.3 – As applicable, describe the processes you use to ensure code is being developed securely.

Include details of the types of code reviews and analysis (e.g., static and dynamic) performed and how threat modeling is incorporated into the design phase of development.

24.4 – As applicable, describe how you monitor for vulnerabilities in dependencies and third-party libraries or code included in the product/system/application/service.

24.5 – Describe how API security is maintained including storage of API keys and support for IP whitelisting for API access.

24.6 – As applicable, for web applications that require authentication as part of the product/system/application/service you’re providing, please describe how you authenticate users. If passwords are used, describe complexity requirements, and how passwords are protected. If SAML, SSO and/or MFA is supported, please describe the available options.

24.7 – As applicable, describe additional user authentication controls including, but not limited to, IP whitelisting and geofencing.

24.8 – As applicable, describe the protective technologies (Web Application Firewalls, Proxies, etc.) that you employ to mitigate web application security risks (e.g., SQLi, XSS, XSRF, etc.).

24.9 – As applicable, describe the training you provide to developers with respect to secure coding practices and system development life cycle.

24.10 – Optional - Please provide any additional information relative to this control area.

25.0 – PROJECT AND RESOURCE MANAGEMENT (PM)

25.1 – The organization ensures that controls necessary to appropriately manage risks are accounted for and implemented throughout the System Development Life Cycle (SDLC). Project and resource management security practices include, at a minimum:

• Defining and implementing security requirements;

• Allocating resources required to protect systems and information; and

• Ensuring security requirements are accounted for throughout the SDLC.

Supplemental Information

25.2 – Optional - Please provide any additional information relative to this control area.

26.0 – CAPACITY AND PERFORMANCE MANAGEMENT (CA)

26.1 – The organization implements processes and controls necessary to protect against avoidable impacts to operations by proactively managing the capacity and performance of its critical technologies and supporting infrastructure. Capacity and performance management practices include, but are not limited to, at a minimum:

• Ensuring the availability, quality, and adequate capacity of compute, storage, memory, and network resources are planned, prepared, and measured to deliver the required system performance and future capacity requirements; and

• Implementing resource priority controls to prevent or limit Denial of Service (DoS) effectiveness.

26.3 – Optional - Please provide any additional information relative to this control area.

Supplemental Information

26.2 – As applicable, describe the processes and controls that are employed to ensure information systems scale appropriately and meet availability needs. Include information on DDoS protections, automated provisioning of resources, high-availability, etc.

27.0 – THIRD-PARTY MANAGEMENT (TP)

27.1 – The organization implements processes and controls to ensure that risks associated with third-parties (e.g., vendors, contractors, business partners, etc.) providing information technology equipment, software, and/or services are minimized or avoided. Third-Party management processes and controls include, at a minimum:

• Tailored acquisition strategies, contracting tools, and procurement methods for the purchase of systems, system components, or system service from suppliers;

• Due diligence security reviews of suppliers and third parties with access to the organization’s systems and sensitive information;

• Third-Party interconnection security; and

• Independent testing and security assessments of supplier technologies and supplier organizations.

Supplemental Information

27.2 – Describe the processes utilized to validate third-party service providers’ compliance with applicable laws, regulations, and contractual requirements.

27.3 – Optional - Please provide any additional information relative to this control area.

28.0 – PHYSICAL AND ENVIRONMENTAL SECURITY (PE)

28.1 – The organization establishes physical and environmental protection procedures that limit access to systems, equipment, and the respective operating environments, to only authorized individuals. The organization ensures appropriate environmental controls in facilities containing information systems and assets, to ensure sufficient environmental conditions exist to avoid preventable hardware failures and service interruptions. Physical and environmental controls include, at a minimum:

• Physical access controls (e.g., locks, security gates and guards, etc.);

• Visitor controls;

• Security monitoring and auditing of physical access;

• Emergency shutoff;

• Emergency power;

• Emergency lighting;

• Fire protection;

• Temperature and humidity controls;

• Water damage protection; and

• Delivery and removal of information assets controls.

Supplemental Information

28.2 – Optional - Please provide any additional information relative to this control area.

29.0 – CONTINGENCY PLANNING (CT)

29.1 – The organization develops, implements, tests, and maintains contingency plans to ensure continuity of operations for all information systems that deliver or support essential or critical business functions on behalf of the organization. Contingency planning includes, at a minimum:

• Backup and recovery strategies;

• Continuity of operations;

• Disaster recovery; and

• Crisis management.

Supplemental Information

29.2 – Describe the processes and plans that are implemented to ensure continuity of operations for your organization.

29.3 – Describe the data and system backup/recovery processes employed and how the security categorization of the information is maintained in backup media. How often are backups tested to verify media reliability and information integrity? What are the recovery point and recovery time objectives?

29.4 – As applicable, if an alternate site(s) has been established for storage, processing, and communications functions as part of the organization’s contingency plan, describe the processes and timelines for failing over.

Is the alternate site considered Hot, Warm, or Cold? Explain how often fail-over processes are tested and how results are documented and reviewed.

29.5 – Optional - Please provide any additional information relative to this control area.

30.0 – INCIDENT RESPONSE (IR)

30.1 – The organization maintains an information security incident response capability that includes adequate preparation, detection, analysis, containment, recovery, and…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .