Attachment_1_-_PPS_Security_and_Privacy_v2.pdf

PDF 2 MB Posted

Attached to
PPS Client Case Management BPA Federal contract opportunity
Solicitation number
USCA19R0062
Issued by
The Judicial Branch

About this file

Attachment 1 - PPS Security and Privacy v2

View the file

Other files for this federal contract opportunity

Other files attached to PPS Client Case Management BPA, newest first.
File Type Posted
USCA19R0062_Q&A_Clarifications.docx DOCX document
USCA19R0062-0002.pdf PDF
USCA19R0062_-_Summary_of_Changes.docx DOCX document
USCA19BPAC1010_v2.pdf PDF
Attachment_A_-_BPA_Pricing_v2.xlsx XLSX spreadsheet
Attachment_B_-_Requirements_Traceability_Matrix_v2.xlsx XLSX spreadsheet
USCA19BPAC1009_v2.pdf PDF
Attachment_4_-_RTM_for_IOC_v2.xlsx XLSX spreadsheet
USCA19R0062_Questions_and_Answers.docx DOCX document
Attachment_C_-_Past_Performance_Questionnaire_v2.docx DOCX document
USCA19R0062-0001.pdf PDF
Attachment_A_-_BPA_Pricing.xlsx XLSX spreadsheet
Attachment_B_-_Requirements_Traceability_Matrix.xlsx XLSX spreadsheet
Attachment_D_-_Demonstrations.docx DOCX document
Attachment_C_-_Past_Performance_Questionnaire.docx DOCX document
Attachment_2_-_Current_PPS_Portfolio_Interfaces.xlsx XLSX spreadsheet
USCA19BPAC1009.pdf PDF
Attachment_3_-_PPS-CCMS_Roadmap.pdf PDF
USCA19R0062.pdf PDF
USCA19BPAC1010.pdf PDF
Attachment_1_-_PPS_Security_and_Privacy.pdf PDF
Attachment_4_-_RTM_for_IOC.xlsx XLSX spreadsheet
Show all 22

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Security and Privacy Compliance Mapping The PPS-CCM platform shall be compliant with all relevant security controls outlined in the Federal Information Processing Standard (FIPS), the Federal Information Security Management Act (FISMA) and Federal Risk and Authorization Management Program (FedRAMP) to include, but not limited to, the ability of the federal government to perform a security certification and accreditation process to obtain an authorization to operate that will be signed by the federal principal without delay to system deployment. The system shall be FedRAMP High compliant (i.e., High Confidentiality, Moderate Integrity, and Moderate Availability), Judiciary Information Security Framework (JISF) High compliant, and Criminal Justice Information Services (CJIS) Security Policy v5.8, Section 5 compliant.

Specific JISF security and privacy requirements for the PPS-CM platform solution are specified in Exhibit A: PPS-CCM JISF Safeguard Risk Categories and Impacts to the RFP. Criminal Justice Information Services (CJIS) Security polices mapping to the FIPS are specified in Exhibit B: Criminal Justice Information Services (CJIS) Security Policy v5.8 Mapping.

The Judiciary Information Security Framework (JISF) addresses the activities of each of the six steps of the Judiciary’s Security Risk Management Framework, see below in Figure 1.

Figure 1: Judiciary Security Risk Management Framework (SRMF)

The six steps of the Security Risk Management Framework are:

Step 1

CATEGORIES

Information System

Step 2

SELECT

Security Controls

Step 6

MONITOR

Security Controls

Step 5

AUTHORIZE

Information System

Step 3

IMPLEMENT

Security Controls

Step 4

ASSESS

Security Controls

Security Risk

Management Framework

Step 1: Categorize the information system and the information processed, stored, and transmitted by that system based on the potential impact to the Judiciary should the system suffer an incident. The greater the negative impact, the higher the system impact rating.

Step 2: Select baseline security controls for the system and tailor controls as needed based on impact levels, and the operating environment determined in Step 1.

Step 3: Implement security controls using sound information system and security engineering methodologies.

Step 4: Assess security controls to determine the extent to which they are implemented correctly and operating as intended to meet the security requirements for the system.

Step 5: Authorize operation of the information system if operational risks are acceptable.

Step 6: Monitor security controls on an ongoing basis to identify any changes to the information system or its operating environment that may affect control effectiveness.

The Framework Guide covers these six steps in detail, including what should be accomplished by the end of each step before continuing. It is recommended that you follow along in the Framework Guide as you review this document.

The results of each step are recorded in the SSP, thus completing the SSP and periodically updating it.

JISF Security controls have a well-defined organization and structure. Modeled on the controls identified in NIST SP 800-53 Rev. 4, April 2013 (updated January 22, 2015), Security and Privacy Controls for Federal Information Systems and Organizations. The security controls are organized into eighteen families distributed among the following three classes:

Management safeguards focus on the management of risk and the management of information system security.

Operational safeguards are primarily implemented and executed by people (as opposed to systems).

Technical safeguards are primarily implemented and executed by the information system through mechanisms contained in the hardware, software, or firmware components of the system.

Table 1: Security Safeguard Identifiers, Families, and Classes

Identifier Family Class AC Access Control Technical AT Awareness and Training Operational AU Audit and Accountability Technical CA Security Assessment and Authorization Management CM Configuration Management Operational CP Contingency Planning Operational IA Identification and Authentication Technical IR Incident Response Operational

MA Maintenance Operational

MP Media Protection Operational PE Physical and Environmental Protection Operational PL Planning Management PM Program Management Management PS Personnel Security Operational RA Risk Assessment Management SA System and Services Acquisition Management SC System and Communications

Protection Technical

SI System and Information Integrity Operational

Figure 2: FedRAM and JISF Security Control Alignment

Information system risk categorization is based on the potential risk-impact to the Judiciary should events occur that jeopardize the information, or the information systems needed to accomplish its mission, protect its assets, fulfill its regulatory responsibilities, maintain its day-to-day functions, and protect individuals. Security safeguards applied to each system should be commensurate with the potential impact of a loss of confidentiality, integrity, or availability. Consider the following:

Confidentiality – How important is it to ensure that information is accessible only to those authorized to have access?

Integrity –What would be the impact to the Judiciary’s mission if the information was improperly modified or destroyed?

AC: Access Control AU: Audit and Accountability

IA: Identification and Authentication

SC: System and Communications Protection

AT: Awareness and Training

CA

Security Assessment and Authorization

CM: Configuration Management

CP: Contingency Planning

IR: Incident Response MA: Maintenance

PL: PlanningPE: Physical and Environmental Protection

MP: Media Protection

PM: Program Management

PS: Personnel Security RA: Risk Assessment

SA: System and Services Acquisition

SI: System and Information Integrity

JISFFedRAMP Technical Operational Management

Security Control Identifiers, Families, and Classes

Security Classes

Availability – How much performance degradation or system downtime can be tolerated?

There are three levels of risk impact (High, Moderate, and Low) based on a system’s confidentiality, integrity, and availability categorization. For the Judiciary, there are three Judiciary categories that are separately assessed: Confidentiality (C), Integrity (I), and Availability (Av).

Each type of information used in the system is assessed to determine the C-I-A risk impact that applies to that information type. In Table 2 below, the types of information being handled by the system are identified. Using Table 3, “Risk-Based Confidentiality-Integrity-Availability (C-I-A) Categorization,” of the Guide to Implementing the Judiciary Information Security Framework, the C-I-A risk impact category for each type of information is determined.

Table 2: Information Type Processed by PPS-CCM

Information Type Confidentiality Risk Impact Level

Integrity Risk Impact Level

PII High Moderate Financial Low Low Criminal Surveillance and Investigative

High Moderate

Table 3: PPS-CCM platform solution Risk Categorization

System Risk Categorization Impact Level Confidentiality High

Integrity Moderate Availability Moderate

Exhibit A: PPS-CCM JISF Controls and Impacts

Control Name & Number Control Description

Impact Level H M L

Access Control

AC-1

Access Control Policy and Procedures

The organization:

a. Develops, documents, and disseminates to organization-defined personnel or roles:

1. An access control policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and

2. Procedures to facilitate the implementation of the access control policy and associated access controls; and

b. Reviews and updates the current:

1. Access control policy periodically (not to exceed annually); and

2. Access control procedures periodically (not to exceed annually).

Yes Yes Yes

AC-2

Account Management

The organization:

a. Identifies and selects the following types of information system accounts to support organizational missions/business functions: Account types may include individual, group, system, application, guest/anonymous, and temporary and others as deemed appropriate;

b. Assigns account managers for information system accounts;

c. Establishes conditions for group and role membership;

d. Specifies authorized users of the information system, group and role membership, and access authorizations (i.e., privileges) and other attributes (as required) for each account;

e. Requires approvals by specifically identified personnel or roles that can give approval for requests to create information system accounts;

f. Creates, enables, modifies, disables, and removes information system accounts in accordance with documented procedures;

g. Monitors the use of information system accounts;

h. Notifies account managers:

1. When accounts are no longer required;

2. When users are terminated or transferred; and

3. When individual information system usage or need-to-know changes;

i. Authorizes access to the information system based on:

1. A valid access authorization;

2. Intended system usage; and

3. Other attributes as required by the organization or associated missions/business functions;

j. Reviews accounts for compliance with account management requirements at least annually; and

k. Establishes a process for reissuing shared/group account credentials (if deployed) when individuals are removed from the group

Yes Yes Yes

AC-2 (1)

Account Management

AUTOMATED SYSTEM

ACCOUNT MANAGEMENT

The organization employs automated mechanisms to support the management of information system accounts. Yes Yes Opt

AC-2 (2)

Account Management

REMOVAL OF TEMPORARY

/ EMERGENCY ACCOUNTS

The information system automatically disables temporary and emergency accounts after a maximum of 60 days. Yes Yes Opt

AC-2 (3)

Account Management

DISABLE INACTIVE

ACCOUNTS

The information system automatically disables inactive accounts after a maximum of 90 days. Yes Yes Opt

Framework Guide, Appendix B v2.5d

Control Name & Number Control Description

Impact Level H M L

AC-2 (4)

Account Management

AUTOMATED AUDIT

ACTIONS

The information system automatically audits account creation, modification, enabling, disabling, and removal actions, and notifies specific identified personnel. Yes Yes Opt

AC-2 (5)

Account Management

INACTIVITY LOGOUT

The organization requires that users log out when the time-period of inactivity exceeds 15 minutes. Yes Opt Opt

AC-2 (6)

Account Management

DYNAMIC PRIVILEGE

MANAGEMENT

The information system implements the following dynamic privilege management capabilities: Dynamic privilege management capabilities include user accounts that are granted run-time access control decisions.

Opt Opt Opt

AC-2 (7)

Account Management

ROLE-BASED SCHEMES

The organization:

a. Establishes and administers privileged user accounts in accordance with a role-based access scheme that organizes allowed information system access and privileges into roles;

b. Monitors privileged role assignments; and

c. Takes specifically defined actions (e.g., rescind, reduce authorized permissions) when privileged role assignments are no longer appropriate.

Yes Yes Opt

AC-2 (8)

Account Management

DYNAMIC ACCOUNT

CREATION

The information system creates only those system accounts that have been defined in advance dynamically. Opt Opt Opt

AC-2 (9)

Account Management

RESTRICTIONS ON USE OF

SHARED GROUPS /

ACCOUNTS

The organization only permits the use of shared/group accounts that meet conditions defined and documented in advance.

Opt Opt Opt

AC-2 (10)

Account Management

GROUP ACCOUNT

CREDENTIAL TERMINATION

The information system terminates shared/group account credentials when members leave the group. Opt Opt Opt

AC-2 (11)

Account Management

USAGE CONDITIONS

The information system enforces restrictions on accounts that include pre-determined days; time of day, duration, and other circumstances for certain pre-defined information system accounts.

Yes Opt Opt

AC-2 (12)

Account Management

ACCOUNT MONITORING /

ATYPICAL USAGE

The organization:

a. Monitors information system accounts for atypical usage as defined for the system;

and

b. Reports atypical usage of information system accounts to their IT security officer.

Yes Yes Opt

AC-2 (13)

Account Management

DISABLE ACCOUNTS FOR

HIGH-RISK INDIVIDUALS

The organization disables accounts of users posing a significant risk within 30 minutes of discovery of the risk. Yes Opt Opt

AC-3

Access Enforcement

The information system enforces approved authorizations for logical access to information and system resources in accordance with applicable access control policies. Yes Yes Yes

AC-3 (1)

Access Enforcement

RESTRICTED ACCESS TO

PRIVILEGED FUNCTIONS

Withdrawn: Incorporated into AC-6.

AC-3 (2)

Access Enforcement

DUAL AUTHORIZATION

The information system enforces dual authorization for defined privileged commands and/or other organization-defined actions. Opt Opt Opt

Control Name & Number Control Description

Impact Level H M L

AC-3 (3)

Access Enforcement

MANDATORY ACCESS

CONTROL

The information system enforces a mandatory access control policy (e.g., nondiscretionary, attribute based) over all subjects and objects where the policy specifies that:

a. The policy is uniformly enforced across all subjects and objects within the boundary of the information system;

b. A subject that has been granted access to information is constrained from doing any of the following:

1. Passing the information to unauthorized subjects or objects;

2. Granting its privileges to other subjects;

3. Changing one or more security attributes on subjects, objects, the information system, or information system components;

4. Choosing the security attributes and attribute values to be associated with newly created or modified objects; or

5. Changing the rules governing access control; and

c. Certain subjects defined by the organization may explicitly be granted trusted privileges such that they are not limited by some or all of the above constraints.

Opt Opt Opt

AC-3 (4)

Access Enforcement

DISCRETIONARY ACCESS

CONTROL

The information system enforces a Discretionary Access Control (DAC) policy over defined subjects and objects where the policy specifies that a subject that has been granted access to information can do one or more of the following:

a. Pass the information to any other subjects or objects;

b. Grant its privileges to other subjects;

c. Change security attributes on subjects, objects, the information system, or the information system’s components;

d. Choose the security attributes to be associated with newly created or revised objects; or

e. Change the rules governing access control.

Opt Opt Opt

AC-3 (5)

Access Enforcement

SECURITY-RELEVANT

INFORMATION

The information system prevents access to organization-defined, security-relevant information except during secure, non-operable system states. Opt Opt Opt

AC-3 (6)

Access Enforcement

PROTECTION OF USER AND

SYSTEM INFORMATION

Withdrawn: Incorporated into MP-4 and SC-28.

AC-3 (7)

Access Enforcement

ROLE-BASED ACCESS

CONTROL

The information system enforces a role-based access control policy over defined subjects and objects and controls access based upon organization-defined roles and users authorized to assume such role.

Opt Opt Opt

AC-3 (8)

Access Enforcement

REVOCATION OF ACCESS

AUTHORIZATIONS

The information system enforces the revocation of access authorizations resulting from changes to the security attributes of subjects and objects based on organization-defined rules governing the timing of revocations of access authorizations.

Opt Opt Opt

AC-3 (9)

Access Enforcement

CONTROLLED RELEASE

The information system does not release information outside of the established system boundary unless:

a. The receiving organization-defined information system or system component provides organization-defined security safeguards; and

b. Organization-defined security safeguards are used to validate the appropriateness of the information designated for release.

Opt Opt Opt

AC-3 (10)

Access Enforcement

AUDITED OVERRIDE OF

ACCESS CONTROL

MECHANISMS

The organization employs an audited override of automated access control mechanisms under specific organization-predefined conditions.

Opt Opt Opt

AC-4

Information Flow Enforcement

The information system enforces approved authorizations for controlling the flow of information within the system and between interconnected systems based on applicable information flow control policy (e.g., using proxies, gateways, firewalls, and routers).

Yes Yes Opt

Control Name & Number Control Description

Impact Level H M L

AC-4 (1)

Information Flow Enforcement

OBJECT SECURITY

ATTRIBUTES

The information system uses explicit domain-membership associated with internal information, source, and destination objects to enforce restrictive information flow control policies as a basis for flow control decisions.

Opt Opt Opt

AC-4 (2)

Information Flow Enforcement

PROCESSING DOMAINS

The information system uses protected processing domains (e.g., domain type-enforcement) to enforce information flow control as a basis for flow control decisions. Opt Opt Opt

AC-4 (3)

Information Flow Enforcement

DYNAMIC INFORMATION

FLOW CONTROL

The information system enforces dynamic information flow control based on policy that allows or disallows information flows based on changing conditions or operational configurations.

Opt Opt Opt

AC-4 (4)

Information Flow Enforcement

CONTENT CHECK

ENCRYPTED INFORMATION

The information system prevents encrypted information from bypassing content-checking mechanisms by decrypting the information, blocking the flow of the encrypted information, terminating communications sessions attempting to pass encrypted information, or by other methods as determined by the organization.

Opt Opt Opt

AC-4 (5)

Information Flow Enforcement

EMBEDDED DATA TYPES

The information system enforces organization-defined limitations on embedding data types within other data types. Opt Opt Opt

AC-4 (6)

Information Flow Enforcement

METADATA

The information system enforces information flow control based on organization-defined metadata. Opt Opt Opt

AC-4 (7)

Information Flow Enforcement

ONE-WAY FLOW

MECHANISMS

The information system enforces organization-defined one-way information flows using hardware mechanisms. Opt Opt Opt

AC-4 (8)

Information Flow Enforcement

SECURITY POLICY FILTERS

The information system enforces information flow control using organization-defined security policy filters as a basis for flow control decisions for organization-defined information flows.

Opt Opt Opt

AC-4 (9)

Information Flow Enforcement

HUMAN REVIEWS

The information system enforces the use of human reviews for organization-defined information flows under the following conditions: when the information system is not capable of making an information flow control decision.

Opt Opt Opt

AC-4 (10)

Information Flow Enforcement

ENABLE / DISABLE

SECURITY POLICY FILTERS

The information system provides the capability for privileged administrators to enable/disable organization-defined security policy filters under the following conditions:

such as those specifically defined by the organization.

Opt Opt Opt

AC-4 (11)

Information Flow Enforcement

CONFIGURATION OF

SECURITY POLICY FILTERS

The information system provides the capability for privileged administrators to configure organization-defined security policy filters to support different security policies. Opt Opt Opt

AC-4 (12)

Information Flow Enforcement

DATA TYPE IDENTIFIERS

The information system, when transferring information between different security domains, uses data type specification and usage to validate data essential for information flow decisions.

Opt Opt Opt

AC-4 (13)

Information Flow Enforcement

DECOMPOSITION INTO

POLICY-RELEVANT

SUBCOMPONENTS

The information system, when transferring information between different security domains, decomposes information into organization-defined policy-relevant subcomponents for submission to policy enforcement mechanisms. Opt Opt Opt

AC-4 (14)

Information Flow Enforcement

SECURITY POLICY FILTER

CONSTRAINTS

The information system, when transferring information between different security domains, implements policy filters that restrict data to printable ASCII characters, prohibit special characters, and/or limit excessive field sizes requiring fully enumerated formats that constrain data structure and content.

Opt Opt Opt

AC-4 (15)

Information Flow Enforcement

DETECTION OF

UNSANCTIONED

INFORMATION

The information system, when transferring information between different security domains, examines the information for the presence of unsanctioned information (e.g., obscenities) and prohibits the transfer of such information in accordance with the organization-defined security policy.

Opt Opt Opt

Control Name & Number Control Description

Impact Level H M L

AC-4 (16)

Information Flow Enforcement

INFORMATION TRANSFERS

ON INTERCONNECTED

SYSTEMS

Withdrawn: Incorporated into AC-4.

AC-4 (17)

Information Flow Enforcement

DOMAIN AUTHENTICATION

The information system uniquely identifies and authenticates source and destination points by traits that may include organization, system, application, and individual for information transfer.

Opt Opt Opt

AC-4 (18)

Information Flow Enforcement

SECURITY ATTRIBUTE

BINDING

The information system binds security attributes to information using binding techniques as defined by the judiciary organization to facilitate information flow policy enforcement. Opt Opt Opt

AC-4 (19)

Information Flow Enforcement

VALIDATION OF METADATA

The information system, when transferring information between different security domains, applies the same security policy filtering to metadata as it applies to data payloads.

Opt Opt Opt

AC-4 (20)

Information Flow Enforcement

APPROVED SOLUTIONS

The organization employs organization-defined solutions in approved configurations to control the flow of organization-defined information across security domains. Opt Opt Opt

AC-4 (21)

Information Flow Enforcement

PHYSICAL / LOGICAL

SEPARATION OF

INFORMATION FLOWS

The information system separates information flows logically or physically using organization-defined mechanisms and/or techniques to accomplish organization-required separation of information types. Opt Opt Opt

AC-4 (22)

Information Flow Enforcement

ACCESS ONLY

The information system provides access from a single device to computing platforms, applications, or data residing on multiple different security domains, while preventing any information flow between the different security domains.

Opt Opt Opt

AC-5

Separation of Duties

The organization:

a. Separates duties of individuals as appropriate, to prevent malicious activity without collusion;

b. Documents separation of duties of individuals; and

c. Defines information system access authorizations to support separation of duties

(e.g., role-based access control).

Yes Yes Opt

AC-6

Least Privilege

The organization employs the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with organizational missions and business functions.

Yes Yes Opt

AC-6 (1)

Least Privilege

AUTHORIZE ACCESS TO

SECURITY FUNCTIONS

The organization explicitly authorizes access to organization-defined security functions (deployed in hardware, software, and firmware) and security-relevant information. Yes Yes Opt

AC-6 (2)

Least Privilege

NON-PRIVILEGED ACCESS

FOR NON-SECURITY

FUNCTIONS

The organization requires that users of information system accounts, or roles, with privileged access to organization-defined security functions or security-relevant information, use non-privileged accounts or roles, when accessing non-security functions. Yes Yes Opt

AC-6 (3)

Least Privilege

NETWORK ACCESS TO

PRIVILEGED COMMANDS

The organization authorizes network access to only organization-defined privileged commands and only for specifically defined reasons and documents the rationale for such access in the security plan for the information system.

Yes Opt Opt

AC-6 (4)

Least Privilege

SEPARATE PROCESSING

DOMAINS

The information system provides separate processing domains to enable finer-grained allocation of user privileges (e.g., virtualization methodologies). Opt Opt Opt

AC-6 (5)

Least Privilege

PRIVILEGED ACCOUNTS

The organization restricts privileged accounts on the information system (e.g., root and administrator) to those with a mission need. Yes Yes Opt

Control Name & Number Control Description

Impact Level H M L

AC-6 (6)

Least Privilege

PRIVILEGED ACCESS BY

NON-ORGANIZATIONAL

USERS

The organization prohibits privileged access to the information system by non-organizational users.

Opt Opt Opt

AC-6 (7)

Least Privilege

REVIEW OF USER

PRIVILEGES

The organization:

a. Reviews annually the privileges assigned to organization-defined roles or classes of users to validate the need for such privileges; and

b. Reassigns or removes privileges, if necessary, to correctly reflect organizational mission/business needs.

Yes Yes Opt

AC-6 (8)

Least Privilege

PRIVILEGE LEVELS FOR

CODE EXECUTION

The information system prevents organization-defined software from executing at higher privilege levels than users executing the software. Opt Opt Opt

AC-6 (9)

Least Privilege

AUDITING USE OF

PRIVILEGED FUNCTIONS

The information system audits the execution of privileged functions.

Yes Yes Opt

AC-6 (10)

Least Privilege

PROHIBIT NON-PRIVILEGED

USERS FROM EXECUTING

PRIVILEGED FUNCTIONS

The information system prevents non-privileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures. Yes Yes Opt

AC-7

Unsuccessful Login Attempts

The information system:

a. Enforces a limit of 10 consecutive invalid access attempts by a user during a 30-minute time period for Low and Moderate systems, and enforces a limit of 6 consecutive invalid access attempts by a user during a 30-minute time period for High security category systems, and

b. Automatically locks the account/node for 1 hour for Low and Moderate systems and locks the account/node until released by an administrator for High security category systems when the maximum number of unsuccessful attempts is exceeded.

Yes Yes Yes

AC-7 (1)

Unsuccessful Login Attempts

AUTOMATIC ACCOUNT

LOCK

Withdrawn: Incorporated into AC-7.

AC-7 (2)

Unsuccessful Login Attempts

PURGE/WIPE MOBILE

DEVICE

The information system purges/wipes information from non-encrypted mobile devices accessed via login based on organization-defined purging/wiping requirements/techniques after 10 consecutive, unsuccessful device logon attempts.

Control Name & Number Control Description

Impact Level H M L

AC-8

System Use Notification

The information system:

a. Displays to users an organization-defined system use notification message or banner before granting access to the system that provides privacy and security notices consistent with approved practices (e.g., applicable federal laws, judiciary orders, directives, policies, regulations, standards, and guidance) and states that:

1. Users are accessing a U.S. Government information system;

2. Information system usage may be monitored, recorded, and subject to audit;

3. Unauthorized use of the information system is prohibited and subject to criminal and civil penalties; and

4. Use of the information system indicates consent to monitoring and recording;

b. Retains the notification message or banner on the screen until users acknowledge the usage conditions and take explicit actions to log on to or further access the information system; and

c. For publicly accessible systems:

1. Displays system use information (e.g. notification of conditions), before granting further access;

2. Displays references, if any, to monitoring, recording, or auditing that are consistent with privacy accommodations for such systems that generally prohibit those activities; and

3. Includes a description of the authorized uses of the system.

Yes Yes Yes

AC-9

Previous Logon (Access) Notification

The information system notifies the user, upon successful logon (access) to the system, of the date and time of the last logon (access). Opt Opt Opt

AC-9 (1)

Previous Logon (Access) Notification

UNSUCCESSFUL LOGONS

The information system notifies the user, upon successful logon/access, of the number of unsuccessful logon/access attempts since the last successful logon/access. Opt Opt Opt

AC-9 (2)

Previous Logon (Access) Notification

SUCCESSFUL /

UNSUCCESSFUL LOGONS

The information system notifies the user of the number of unsuccessful logon/access attempts during the previous 24-hour time period.

Opt Opt Opt

AC-9 (3)

Previous Logon (Access) Notification

NOTIFICATION OF

ACCOUNT CHANGES

The information system notifies the user of changes to organization-defined security-related characteristics/parameters of the user’s account during an organization-defined time period. Opt Opt Opt

AC-9 (4)

Previous Logon (Access) Notification

ADDITIONAL LOGON

INFORMATION

The information system notifies the user, upon successful logon (access), of the following additional information: (e.g., location of last logon) in addition to the date and time of the last logon (access). Opt Opt Opt

AC-10

Concurrent Session Control

The information system limits the number of concurrent sessions for each user account to 1, unless explicitly authorized by the system owner. Yes Opt Opt

AC-11

Session Lock

The information system:

a. Prevents further access to the system by initiating a session lock after 15 minutes of inactivity or upon receiving a request from a user; and

b. Retains the session lock until the user reestablishes access using established identification and authentication procedures.

Yes Yes Opt

AC-11 (1)

Session Lock

PATTERN-HIDING DISPLAYS

The information system conceals, via the session lock, information previously visible on the display with a publicly viewable image. Yes Yes Opt

AC-12

Session Termination

The information system automatically terminates a user session after organization-defined conditions or trigger events requiring session disconnect. Yes Yes Opt

Control Name & Number Control Description

Impact Level H M L

AC-12 (1)

Session Termination

USER-INITIATED LOGOUTS /

MESSAGE DISPLAYS

The information system:

a. Provides a logout capability for user-initiated communications sessions whenever authentication is used to gain access to organization-defined information resources;

and

b. Displays an explicit logout message to users indicating the reliable termination of authenticated communications sessions.

Opt Opt Opt

AC-13

Supervision and Review – Access Control

Withdrawn: Incorporated into AC-2 and AU-6.

AC-14

Permitted Actions Without Identification or Authentication

The organization:

a. Identifies specific user actions that can be performed on the information system without identification or authentication consistent with organizational missions/business functions; and

b. Documents and provides supporting rationale in the security plan for the information system, user actions not requiring identification or authentication.

Yes Yes Yes

AC-14 (1)

Permitted Actions Without Identification or Authentication

NECESSARY USES

Withdrawn: Incorporated into AC-14.

AC-15

Automated Marking

Withdrawn: Incorporated into MP-3. --- --- ---

AC-16

Security Attributes

The organization:

a. Provides the means to associate organization-defined types of security attributes having organization-defined security attribute values with information in storage, in process, and/or in transmission;

b. Ensures that the security attribute associations are made and retained with the information;

c. Establishes the permitted organization-defined security attributes for organization-defined information systems; and

d. Determines the permitted organization-defined values or ranges for each of the established security attributes.

Opt Opt Opt

AC-16 (1)

Security Attributes

DYNAMIC ATTRIBUTE

ASSOCIATION

The information system dynamically associates security attributes with organization-defined subjects and objects in accordance with an identified security policy as information is created and combined.

Opt Opt Opt

AC-16 (2)

Security Attributes

ATTRIBUTE VALUE

CHANGES BY AUTHORIZED

INDIVIDUALS

The information system provides authorized individuals (or processes acting on behalf of individuals) the capability to define or change the value of associated security attributes.

Opt Opt Opt

AC-16 (3)

Security Attributes

MAINTENANCE OF

ATTRIBUTE ASSOCIATIONS

BY INFORMATION SYSTEM

The information system maintains the association and integrity of (e.g., binding) organization-defined security attributes to information with sufficient assurance that the information-attribute association can be used as the basis for automated access control or information flow decisions.

Opt Opt Opt

AC-16 (4)

Security Attributes

ASSOCIATION OF

ATTRIBUTES BY

AUTHORIZED INDIVIDUALS

The information system supports the association of authorized users with the security attributes of the information by authorized individuals (or processes acting on behalf of individuals). Opt Opt Opt

AC-16 (5)

Security Attributes

ATTRIBUTE DISPLAYS FOR

OUTPUT DEVICES

The information system displays security attributes in human-readable form on each object that the system transmits to output devices to identify an organization-defined set of special dissemination, handling, or distribution instructions using organization-defined, human-readable, standard naming conventions.

Control Name & Number Control Description

Impact Level H M L

AC-16 (6)

Security Attributes

MAINTENANCE OF

ATTRIBUTE ASSOCIATION

BY ORGANIZATION

The organization allows personnel to associate, and maintain the association of security attributes with subjects and objects in accordance with organization-defined security policies. Opt Opt Opt

AC-16 (7)

Security Attributes

CONSISTENT ATTRIBUTE

INTERPRETATION

The organization provides a consistent interpretation of security attributes transmitted between distributed information system components. Opt Opt Opt

AC-16 (8)

Security Attributes

ASSOCIATION TECHNIQUES

/ TECHNOLOGIES

The information system implements organization-defined techniques or technologies with an organization-defined level of assurance in associating security attributes to information. Opt Opt Opt

AC-16 (9)

Security Attributes

ATTRIBUTE

REASSIGNMENT

The organization ensures that security attributes associated with information are reassigned only via re-grading mechanisms validated using organization-defined techniques or procedures approved by the judiciary organization.

Opt Opt Opt

AC-16 (10)

Security Attributes

ATTRIBUTE

CONFIGURATION BY

AUTHORIZED INDIVIDUALS

The information system provides authorized individuals the capability to define or change the type and value of security attributes available for association with subjects and objects. Opt Opt Opt

AC-17

Remote Access

The organization:

a. Establishes and documents usage restrictions, configuration/connection requirements, and implementation guidance for each type of remote access allowed;

and

b. Authorizes remote access to the information system prior to allowing such connections.

Yes Yes Yes

AC-17 (1)

Remote Access

AUTOMATED MONITORING /

CONTROL

The information system monitors and controls remote access methods.

Yes Yes Opt

AC-17 (2)

Remote Access

PROTECTION OF

CONFIDENTIALITY /

INTEGRITY USING

ENCRYPTION

The information system implements cryptographic mechanisms to protect the confidentiality and integrity of remote access sessions.

Yes Yes Opt

AC-17 (3)

Remote Access

MANAGED ACCESS

CONTROL POINTS

The information system routes all remote accesses through a limited number of managed network access control points. Yes Yes Opt

AC-17 (4)

Remote Access

PRIVILEGED COMMANDS /

ACCESS

The organization:

a. Authorizes the execution of privileged commands and access to security-relevant information via remote access only security-relevant information via remote access only for compelling mission needs; and

b. Documents the rationale for such access in the security plan for the information system.

Yes Yes Opt

AC-17 (5)

Remote Access

ATTRIBUTE DISPLAYS FOR

OUTPUT DEVICES

Withdrawn: Incorporated into SI-4.

AC-17 (6)

Remote Access

PROTECTION OF

INFORMATION

The organization ensures that users protect information about remote access mechanisms from unauthorized use and disclosure. Opt Opt Opt

AC-17 (7)

Remote Access

CONSISTENT ATTRIBUTE

INTERPRETATION

Withdrawn: Incorporated into AC-3 (10).

Control Name & Number Control Description

Impact Level H M L

AC-17 (8)

Remote Access

ASSOCIATION TECHNIQUES

/ TECHNOLOGIES

Withdrawn: Incorporated into CM-7.

AC-17 (9)

Remote Access

DISCONNECT / DISABLE

ACCESS

The organization provides the capability to expeditiously disconnect or disable remote access to the information system within 15 minutes. Opt Opt Opt

AC-18

Wireless Access

The organization:

a. Establishes usage restrictions, configuration/connection requirements, and implementation guidance for wireless access; and

b. Authorizes wireless access to the information system prior to allowing such connections.

Yes Yes Yes

AC-18 (1)

Wireless Access

AUTHENTICATION AND

ENCRYPTION

The information system protects wireless access to the system using authentication of either users or devices, and encryption. Yes Yes Opt

AC-18 (2)

Wireless Access

MONITORING

UNAUTHORIZED

CONNECTIONS

Withdrawn: Incorporated into SI-4.

AC-18 (3)

Wireless Access

DISABLE WIRELESS

NETWORKING

The organization disables, when not intended for use, wireless networking capabilities internally embedded within information system components prior to issuance and deployment.

Opt Opt Opt

AC-18 (4)

Wireless Access

RESTRICT

CONFIGURATIONS

BY USERS

The organization identifies and explicitly authorizes users allowed to independently configure wireless networking capabilities.

Yes Opt Opt

AC-18 (5)

Wireless Access

ANTENNAS /

TRANSMISSION POWER

LEVELS

The organization selects radio antennas and calibrates transmission power levels to reduce the probability that usable signals can be received outside of organization-controlled boundaries. Yes Opt Opt

AC-19

Access Control for Mobile Devices

The organization:

a. Establishes usage restrictions, configuration requirements, connection requirements, and implementation guidance for organization-controlled mobile devices; and

b. Authorizes the connection of mobile devices to organizational information systems.

Yes Yes Yes

AC-19 (1)

Access Control for Mobile Devices

USE OF WRITABLE /

PORTABLE STORAGE

DEVICES

Withdrawn: Incorporated into MP-7.

AC-19 (2)

Access Control for Mobile Devices

USE OF PERSONALLY

OWNED PORTABLE

STORAGE DEVICES

Withdrawn: Incorporated into MP-7.

AC-19 (3)

Access Control for Mobile Devices

USE OF PORTABLE

STORAGE DEVICES WITH

NO IDENTIFIABLE OWNER

Withdrawn: Incorporated into MP-7.

Control Name & Number Control Description

Impact Level H M L

AC-19 (4)

Access Control for Mobile Devices

RESTRICTIONS FOR

CLASSIFIED INFORMATION

The organization:

a. Prohibits the use of unclassified mobile devices in facilities containing information systems processing, storing, or transmitting classified information unless specifically permitted by the authorizing official; and

b. Enforces the following restrictions on individuals permitted by the authorizing official to use unclassified mobile devices in facilities containing information systems processing, storing, or transmitting classified information:

1. Connection of unclassified mobile devices to classified information systems is prohibited;

2. Connection of unclassified mobile devices to unclassified information systems requires approval from the authorizing official;

3. Use of internal or external modems or wireless interfaces within the unclassified mobile devices is prohibited; and

4. Unclassified mobile devices and the information stored on those devices are subject to random reviews and inspections by organization-defined security officials, and if classified information is found, the incident handling policy is followed.

c. Restricts the connection of classified mobile devices to classified information systems in accordance with organization-defined security policies.

Opt Opt Opt

AC-19 (5)

Access Control for Mobile Devices

FULL-DEVICE / CONTAINER-

BASED ENCRYPTION

The organization employs a form of encryption (e.g., full device or container) to protect the confidentiality and integrity of information on mobile devices identified by the judiciary organization. Yes Yes Opt

AC-20

Use of External Information Systems

The organization establishes terms and conditions, consistent with any trust relationships established with other organizations owning, operating, and/or maintaining external information systems, allowing authorized individuals to:

a. Access the information system from external information systems; and

b. Process, store, or transmit organization-controlled information using external information systems.

Yes Yes Yes

AC-20 (1)

Use of External Information Systems

LIMITS ON AUTHORIZED

USE

The organization permits authorized individuals to use an external information system to access the information system or to process, store, or transmit organization-controlled information only when the organization:

a. Verifies the implementation of required security controls on the external system as specified in the organization’s information security policy and security plan; or

b. Retains approved information system connection or processing agreements with the organizational entity hosting the external information system.

Yes Yes Opt

AC-20 (2)

Use of External Information Systems

PORTABLE STORAGE

DEVICES

The organization restricts or prohibits the use of organization-controlled portable storage devices by authorized individuals on external information systems.

Yes Yes Opt

AC-20 (3)

Use of External Information Systems

NON-ORGANIZATIONALLY

OWNED SYSTEMS /

COMPONENTS/ DEVICES

The organization restricts or prohibits the use of non-organizationally owned information systems, system components, or devices to process, store, or transmit organizational information. Opt Opt Opt

AC-20 (4)

Use of External Information Systems

NETWORK ACCESSIBLE

STORAGE DEVICES

The organization prohibits the use of organization-defined network accessible storage devices in external information systems.

Control Name & Number Control Description

Impact Level H M L

AC-21

Information Sharing

The organization:

a. Facilitates information sharing by enabling authorized users to determine whether access authorizations assigned to the sharing partner match the access restrictions on the information for organization-defined circumstances where user discretion is required; and

b. Employs either automated mechanisms or manual processes to assist users in making information sharing/collaboration decisions.

Yes Yes Opt

AC-21 (1)

Information Sharing

AUTOMATED DECISION

SUPPORT

The information system enforces information-sharing decisions by authorized users based on access authorizations of sharing partners and access restrictions on information to be shared.

Opt Opt Opt

AC-21 (2)

Information Sharing

INFORMATION SEARCH

AND RETRIEVAL

The information system implements information search and retrieval services that enforce organization-defined information sharing restrictions. Opt Opt Opt

AC-22

Publicly Accessible Content

The organization:

a. Designates individuals authorized to post information onto a publicly accessible information system;

b. Trains authorized individuals to ensure that publicly accessible information does not contain nonpublic information;

c. Reviews the proposed content of information prior to posting onto the publicly accessible information system to ensure that nonpublic information is not included;

and

d. Reviews the content on the publicly accessible information system for nonpublic information periodically (at least quarterly), and removes such information, if discovered.

Yes Yes Yes

AC-23

Data Mining Protection

The organization employs data mining prevention and detection techniques for organization-defined data storage objects to adequately detect and protect against data mining.

Opt Opt Opt

AC-24

Access Control Decisions

The organization establishes procedures to ensure organization-defined access control decisions are applied to each access request prior to access enforcement. Opt Opt Opt

AC-24 (1)

Access Control Decisions

TRANSMIT ACCESS

AUTHORIZATION

INFORMATION

The information system transmits organization-defined access authorization information using organization-defined security safeguards to organization-defined information systems that enforce access control decisions. Opt Opt Opt

AC-24 (2)

Access Control Decisions

NO USER OR PROCESS

IDENTITY

The information system enforces access control decisions based on organization-defined security attributes that do not include the identity of the user or process acting on behalf of the user.

Opt Opt Opt

AC-25

Reference Monitor

The information system implements a reference monitor for organization-defined access control policies that is tamperproof, always invoked, and small enough to be subject to analysis and testing, the completeness of which can be assured.

Control Name & Number Control Description

Impact Level H M L

Awareness and Training

AT-1

Security Awareness and Training Policy and Procedures

The organization:

a. Develops, documents, and disseminates to organization-defined personnel or roles:

1. A security awareness and training policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and

2. Procedures to facilitate the implementation of the security awareness and training policy and associated security awareness and training controls; and

b. Reviews and updates the current:

1. Security awareness and training policy periodically (not to exceed annually); and

2. Security awareness and training procedures periodically (not to exceed annually).

Yes Yes Yes

AT-2

Security Awareness Training

The organization provides basic security awareness training to information system users (including managers, senior executives, and contractors):

a. As part of initial training for new users;

b. When required by information system changes; and

c. Periodically (at least annually) thereafter.

Yes Yes Yes

AT-2 (1)

Security Awareness Training

PRACTICAL EXERCISES

The organization includes practical exercises in security awareness training that simulate actual cyber-attacks. Opt Opt Opt

AT-2 (2)

Security Awareness Training

INSIDER THREAT

The organization includes security awareness training on recognizing and reporting potential indicators of insider threat. Yes Yes Opt

AT-3

Role-Based Security Training

The organization provides role-based security training to personnel with assigned security roles and responsibilities:

a. Before authorizing access to the information system or performing assigned duties;

b. When required by information system changes; and

c. Periodically (at least annually) thereafter.

Yes Yes Yes

AT-3 (1)

Role Based Security Training

ENVIRONMENTAL

CONTROLS

The organization provides employees with initial and periodic (at least annual) training in the employment and operation of environmental controls. Opt Opt Opt

AT-3 (2)

Role Based Security Training

PHYSICAL SECURITY

CONTROLS

The organization provides employees with initial and periodic (at least annual) training in the employment and operation of physical security controls. Opt Opt Opt

AT-3 (3)

Role Based Security Training

PRACTICAL EXERCISES

The organization includes practical exercises in security training that reinforce training objectives (e.g., training for software developers that include simulated cyber-attacks such as buffer overflow or SQL injection, etc.).

Opt Opt Opt

AT-3 (4)

Role Based Security Training

SUSPICIOUS

COMMUNICATIONS AND

ANOMALOUS SYSTEM

BEHAVIOR

The organization provides training to its personnel on general indicators of malicious code to recognize suspicious communications and anomalous behavior in organizational information systems. Opt Opt Opt

AT-4

Security Training Records

The organization:

a. Documents and monitors individual information system security training activities including basic security awareness training and specific information system security training; and

b. Retains individual training records for at least 5 years.

Yes Yes Yes

AT-5

Contacts with Security Groups and Associations

Withdrawn: Incorporated into PM-15.

Control Name & Number Control Description

Impact Level H M L

Audit and Accountability

AU-1

Audit and Accountability Policy and Procedures

The organization:

a. Develops, documents, and disseminates to organization-defined personnel or roles:

1. An audit and accountability policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and

2. Procedures to facilitate the implementation of the audit and accountability policy and associated audit and accountability controls; and

b. Reviews and updates the current:

1. Audit and accountability policy periodically (not to exceed annually); and

2. Audit and accountability procedures periodically (not to exceed annually).

Yes Yes Yes

AU-2

Audit Events

The organization:

a. Determines that the information system is capable of auditing the following events: failed logon attempts, successful logons; and access to sealed electronic documents;

b. Coordinates the security audit function with other organizational entities requiring audit-related information to enhance mutual support and to help guide the selection of auditable events;

c. Provides a rationale for why the auditable events are deemed to be adequate to support after-the-fact investigations of security incidents; and

d. Determines that the following events are to be audited within the information system:

organization-defined audited events (the subset of the auditable events defined in AU-2 a.) along with the frequency of (or situation requiring) auditing for each identified event.

Yes Yes Yes

AU-2 (1)

Audit Events

COMPILATION OF AUDIT

RECORDS FROM MULTIPLE

SOURCES

Withdrawn: Incorporated into AU-12.

AU-2 (2)

Audit Events

SELECTION OF AUDIT

EVENTS BY COMPONENT

Withdrawn: Incorporated into AU-12.

AU-2 (3)

Audit Events

REVIEWS AND UPDATES

The organization reviews and updates the audited events periodically (recommended at least annually). Yes Yes Opt

AU-2 (4)

Audit Events

PRIVILEGED FUNCTIONS

Withdrawn: Incorporated into AC-6 (9).

AU-3

Content of Audit Records

The information system generates audit records containing information that establishes what type of event occurred, when the event occurred, where the event occurred, the source of the event, the outcome of the event, and the identity of any individuals or subjects associated with the…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.