Attachment_1_-_PPS_Security_and_Privacy_v2.pdf
PDF 2 MB Posted
- Attached to
- PPS Client Case Management BPA Federal contract opportunity
- Solicitation number
- USCA19R0062
- Issued by
- The Judicial Branch
About this file
Attachment 1 - PPS Security and Privacy v2
View the file
Other files for this federal contract opportunity
Show all 22
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Security and Privacy Compliance Mapping The PPS-CCM platform shall be compliant with all relevant security controls outlined in the Federal Information Processing Standard (FIPS), the Federal Information Security Management Act (FISMA) and Federal Risk and Authorization Management Program (FedRAMP) to include, but not limited to, the ability of the federal government to perform a security certification and accreditation process to obtain an authorization to operate that will be signed by the federal principal without delay to system deployment. The system shall be FedRAMP High compliant (i.e., High Confidentiality, Moderate Integrity, and Moderate Availability), Judiciary Information Security Framework (JISF) High compliant, and Criminal Justice Information Services (CJIS) Security Policy v5.8, Section 5 compliant.
Specific JISF security and privacy requirements for the PPS-CM platform solution are specified in Exhibit A: PPS-CCM JISF Safeguard Risk Categories and Impacts to the RFP. Criminal Justice Information Services (CJIS) Security polices mapping to the FIPS are specified in Exhibit B: Criminal Justice Information Services (CJIS) Security Policy v5.8 Mapping.
The Judiciary Information Security Framework (JISF) addresses the activities of each of the six steps of the Judiciary’s Security Risk Management Framework, see below in Figure 1.
Figure 1: Judiciary Security Risk Management Framework (SRMF)
The six steps of the Security Risk Management Framework are:
Step 1
CATEGORIES
Information System
Step 2
SELECT
Security Controls
Step 6
MONITOR
Security Controls
Step 5
AUTHORIZE
Information System
Step 3
IMPLEMENT
Security Controls
Step 4
ASSESS
Security Controls
Security Risk
Management Framework
Step 1: Categorize the information system and the information processed, stored, and transmitted by that system based on the potential impact to the Judiciary should the system suffer an incident. The greater the negative impact, the higher the system impact rating.
Step 2: Select baseline security controls for the system and tailor controls as needed based on impact levels, and the operating environment determined in Step 1.
Step 3: Implement security controls using sound information system and security engineering methodologies.
Step 4: Assess security controls to determine the extent to which they are implemented correctly and operating as intended to meet the security requirements for the system.
Step 5: Authorize operation of the information system if operational risks are acceptable.
Step 6: Monitor security controls on an ongoing basis to identify any changes to the information system or its operating environment that may affect control effectiveness.
The Framework Guide covers these six steps in detail, including what should be accomplished by the end of each step before continuing. It is recommended that you follow along in the Framework Guide as you review this document.
The results of each step are recorded in the SSP, thus completing the SSP and periodically updating it.
JISF Security controls have a well-defined organization and structure. Modeled on the controls identified in NIST SP 800-53 Rev. 4, April 2013 (updated January 22, 2015), Security and Privacy Controls for Federal Information Systems and Organizations. The security controls are organized into eighteen families distributed among the following three classes:
Management safeguards focus on the management of risk and the management of information system security.
Operational safeguards are primarily implemented and executed by people (as opposed to systems).
Technical safeguards are primarily implemented and executed by the information system through mechanisms contained in the hardware, software, or firmware components of the system.
Table 1: Security Safeguard Identifiers, Families, and Classes
Identifier Family Class AC Access Control Technical AT Awareness and Training Operational AU Audit and Accountability Technical CA Security Assessment and Authorization Management CM Configuration Management Operational CP Contingency Planning Operational IA Identification and Authentication Technical IR Incident Response Operational
MA Maintenance Operational
MP Media Protection Operational PE Physical and Environmental Protection Operational PL Planning Management PM Program Management Management PS Personnel Security Operational RA Risk Assessment Management SA System and Services Acquisition Management SC System and Communications
Protection Technical
SI System and Information Integrity Operational
Figure 2: FedRAM and JISF Security Control Alignment
Information system risk categorization is based on the potential risk-impact to the Judiciary should events occur that jeopardize the information, or the information systems needed to accomplish its mission, protect its assets, fulfill its regulatory responsibilities, maintain its day-to-day functions, and protect individuals. Security safeguards applied to each system should be commensurate with the potential impact of a loss of confidentiality, integrity, or availability. Consider the following:
Confidentiality – How important is it to ensure that information is accessible only to those authorized to have access?
Integrity –What would be the impact to the Judiciary’s mission if the information was improperly modified or destroyed?
AC: Access Control AU: Audit and Accountability
IA: Identification and Authentication
SC: System and Communications Protection
AT: Awareness and Training
CA
Security Assessment and Authorization
CM: Configuration Management
CP: Contingency Planning
IR: Incident Response MA: Maintenance
PL: PlanningPE: Physical and Environmental Protection
MP: Media Protection
PM: Program Management
PS: Personnel Security RA: Risk Assessment
SA: System and Services Acquisition
SI: System and Information Integrity
JISFFedRAMP Technical Operational Management
Security Control Identifiers, Families, and Classes
Security Classes
Availability – How much performance degradation or system downtime can be tolerated?
There are three levels of risk impact (High, Moderate, and Low) based on a system’s confidentiality, integrity, and availability categorization. For the Judiciary, there are three Judiciary categories that are separately assessed: Confidentiality (C), Integrity (I), and Availability (Av).
Each type of information used in the system is assessed to determine the C-I-A risk impact that applies to that information type. In Table 2 below, the types of information being handled by the system are identified. Using Table 3, “Risk-Based Confidentiality-Integrity-Availability (C-I-A) Categorization,” of the Guide to Implementing the Judiciary Information Security Framework, the C-I-A risk impact category for each type of information is determined.
Table 2: Information Type Processed by PPS-CCM
Information Type Confidentiality Risk Impact Level
Integrity Risk Impact Level
PII High Moderate Financial Low Low Criminal Surveillance and Investigative
High Moderate
Table 3: PPS-CCM platform solution Risk Categorization
System Risk Categorization Impact Level Confidentiality High
Integrity Moderate Availability Moderate
Exhibit A: PPS-CCM JISF Controls and Impacts
Control Name & Number Control Description
Impact Level H M L
Access Control
AC-1
Access Control Policy and Procedures
The organization:
a. Develops, documents, and disseminates to organization-defined personnel or roles:
1. An access control policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
2. Procedures to facilitate the implementation of the access control policy and associated access controls; and
b. Reviews and updates the current:
1. Access control policy periodically (not to exceed annually); and
2. Access control procedures periodically (not to exceed annually).
Yes Yes Yes
AC-2
Account Management
The organization:
a. Identifies and selects the following types of information system accounts to support organizational missions/business functions: Account types may include individual, group, system, application, guest/anonymous, and temporary and others as deemed appropriate;
b. Assigns account managers for information system accounts;
c. Establishes conditions for group and role membership;
d. Specifies authorized users of the information system, group and role membership, and access authorizations (i.e., privileges) and other attributes (as required) for each account;
e. Requires approvals by specifically identified personnel or roles that can give approval for requests to create information system accounts;
f. Creates, enables, modifies, disables, and removes information system accounts in accordance with documented procedures;
g. Monitors the use of information system accounts;
h. Notifies account managers:
1. When accounts are no longer required;
2. When users are terminated or transferred; and
3. When individual information system usage or need-to-know changes;
i. Authorizes access to the information system based on:
1. A valid access authorization;
2. Intended system usage; and
3. Other attributes as required by the organization or associated missions/business functions;
j. Reviews accounts for compliance with account management requirements at least annually; and
k. Establishes a process for reissuing shared/group account credentials (if deployed) when individuals are removed from the group
Yes Yes Yes
AC-2 (1)
Account Management
AUTOMATED SYSTEM
ACCOUNT MANAGEMENT
The organization employs automated mechanisms to support the management of information system accounts. Yes Yes Opt
AC-2 (2)
Account Management
REMOVAL OF TEMPORARY
/ EMERGENCY ACCOUNTS
The information system automatically disables temporary and emergency accounts after a maximum of 60 days. Yes Yes Opt
AC-2 (3)
Account Management
DISABLE INACTIVE
ACCOUNTS
The information system automatically disables inactive accounts after a maximum of 90 days. Yes Yes Opt
Framework Guide, Appendix B v2.5d
Control Name & Number Control Description
Impact Level H M L
AC-2 (4)
Account Management
AUTOMATED AUDIT
ACTIONS
The information system automatically audits account creation, modification, enabling, disabling, and removal actions, and notifies specific identified personnel. Yes Yes Opt
AC-2 (5)
Account Management
INACTIVITY LOGOUT
The organization requires that users log out when the time-period of inactivity exceeds 15 minutes. Yes Opt Opt
AC-2 (6)
Account Management
DYNAMIC PRIVILEGE
MANAGEMENT
The information system implements the following dynamic privilege management capabilities: Dynamic privilege management capabilities include user accounts that are granted run-time access control decisions.
Opt Opt Opt
AC-2 (7)
Account Management
ROLE-BASED SCHEMES
The organization:
a. Establishes and administers privileged user accounts in accordance with a role-based access scheme that organizes allowed information system access and privileges into roles;
b. Monitors privileged role assignments; and
c. Takes specifically defined actions (e.g., rescind, reduce authorized permissions) when privileged role assignments are no longer appropriate.
Yes Yes Opt
AC-2 (8)
Account Management
DYNAMIC ACCOUNT
CREATION
The information system creates only those system accounts that have been defined in advance dynamically. Opt Opt Opt
AC-2 (9)
Account Management
RESTRICTIONS ON USE OF
SHARED GROUPS /
ACCOUNTS
The organization only permits the use of shared/group accounts that meet conditions defined and documented in advance.
Opt Opt Opt
AC-2 (10)
Account Management
GROUP ACCOUNT
CREDENTIAL TERMINATION
The information system terminates shared/group account credentials when members leave the group. Opt Opt Opt
AC-2 (11)
Account Management
USAGE CONDITIONS
The information system enforces restrictions on accounts that include pre-determined days; time of day, duration, and other circumstances for certain pre-defined information system accounts.
Yes Opt Opt
AC-2 (12)
Account Management
ACCOUNT MONITORING /
ATYPICAL USAGE
The organization:
a. Monitors information system accounts for atypical usage as defined for the system;
and
b. Reports atypical usage of information system accounts to their IT security officer.
Yes Yes Opt
AC-2 (13)
Account Management
DISABLE ACCOUNTS FOR
HIGH-RISK INDIVIDUALS
The organization disables accounts of users posing a significant risk within 30 minutes of discovery of the risk. Yes Opt Opt
AC-3
Access Enforcement
The information system enforces approved authorizations for logical access to information and system resources in accordance with applicable access control policies. Yes Yes Yes
AC-3 (1)
Access Enforcement
RESTRICTED ACCESS TO
PRIVILEGED FUNCTIONS
Withdrawn: Incorporated into AC-6.
AC-3 (2)
Access Enforcement
DUAL AUTHORIZATION
The information system enforces dual authorization for defined privileged commands and/or other organization-defined actions. Opt Opt Opt
Control Name & Number Control Description
Impact Level H M L
AC-3 (3)
Access Enforcement
MANDATORY ACCESS
CONTROL
The information system enforces a mandatory access control policy (e.g., nondiscretionary, attribute based) over all subjects and objects where the policy specifies that:
a. The policy is uniformly enforced across all subjects and objects within the boundary of the information system;
b. A subject that has been granted access to information is constrained from doing any of the following:
1. Passing the information to unauthorized subjects or objects;
2. Granting its privileges to other subjects;
3. Changing one or more security attributes on subjects, objects, the information system, or information system components;
4. Choosing the security attributes and attribute values to be associated with newly created or modified objects; or
5. Changing the rules governing access control; and
c. Certain subjects defined by the organization may explicitly be granted trusted privileges such that they are not limited by some or all of the above constraints.
Opt Opt Opt
AC-3 (4)
Access Enforcement
DISCRETIONARY ACCESS
CONTROL
The information system enforces a Discretionary Access Control (DAC) policy over defined subjects and objects where the policy specifies that a subject that has been granted access to information can do one or more of the following:
a. Pass the information to any other subjects or objects;
b. Grant its privileges to other subjects;
c. Change security attributes on subjects, objects, the information system, or the information system’s components;
d. Choose the security attributes to be associated with newly created or revised objects; or
e. Change the rules governing access control.
Opt Opt Opt
AC-3 (5)
Access Enforcement
SECURITY-RELEVANT
INFORMATION
The information system prevents access to organization-defined, security-relevant information except during secure, non-operable system states. Opt Opt Opt
AC-3 (6)
Access Enforcement
PROTECTION OF USER AND
SYSTEM INFORMATION
Withdrawn: Incorporated into MP-4 and SC-28.
AC-3 (7)
Access Enforcement
ROLE-BASED ACCESS
CONTROL
The information system enforces a role-based access control policy over defined subjects and objects and controls access based upon organization-defined roles and users authorized to assume such role.
Opt Opt Opt
AC-3 (8)
Access Enforcement
REVOCATION OF ACCESS
AUTHORIZATIONS
The information system enforces the revocation of access authorizations resulting from changes to the security attributes of subjects and objects based on organization-defined rules governing the timing of revocations of access authorizations.
Opt Opt Opt
AC-3 (9)
Access Enforcement
CONTROLLED RELEASE
The information system does not release information outside of the established system boundary unless:
a. The receiving organization-defined information system or system component provides organization-defined security safeguards; and
b. Organization-defined security safeguards are used to validate the appropriateness of the information designated for release.
Opt Opt Opt
AC-3 (10)
Access Enforcement
AUDITED OVERRIDE OF
ACCESS CONTROL
MECHANISMS
The organization employs an audited override of automated access control mechanisms under specific organization-predefined conditions.
Opt Opt Opt
AC-4
Information Flow Enforcement
The information system enforces approved authorizations for controlling the flow of information within the system and between interconnected systems based on applicable information flow control policy (e.g., using proxies, gateways, firewalls, and routers).
Yes Yes Opt
Control Name & Number Control Description
Impact Level H M L
AC-4 (1)
Information Flow Enforcement
OBJECT SECURITY
ATTRIBUTES
The information system uses explicit domain-membership associated with internal information, source, and destination objects to enforce restrictive information flow control policies as a basis for flow control decisions.
Opt Opt Opt
AC-4 (2)
Information Flow Enforcement
PROCESSING DOMAINS
The information system uses protected processing domains (e.g., domain type-enforcement) to enforce information flow control as a basis for flow control decisions. Opt Opt Opt
AC-4 (3)
Information Flow Enforcement
DYNAMIC INFORMATION
FLOW CONTROL
The information system enforces dynamic information flow control based on policy that allows or disallows information flows based on changing conditions or operational configurations.
Opt Opt Opt
AC-4 (4)
Information Flow Enforcement
CONTENT CHECK
ENCRYPTED INFORMATION
The information system prevents encrypted information from bypassing content-checking mechanisms by decrypting the information, blocking the flow of the encrypted information, terminating communications sessions attempting to pass encrypted information, or by other methods as determined by the organization.
Opt Opt Opt
AC-4 (5)
Information Flow Enforcement
EMBEDDED DATA TYPES
The information system enforces organization-defined limitations on embedding data types within other data types. Opt Opt Opt
AC-4 (6)
Information Flow Enforcement
METADATA
The information system enforces information flow control based on organization-defined metadata. Opt Opt Opt
AC-4 (7)
Information Flow Enforcement
ONE-WAY FLOW
MECHANISMS
The information system enforces organization-defined one-way information flows using hardware mechanisms. Opt Opt Opt
AC-4 (8)
Information Flow Enforcement
SECURITY POLICY FILTERS
The information system enforces information flow control using organization-defined security policy filters as a basis for flow control decisions for organization-defined information flows.
Opt Opt Opt
AC-4 (9)
Information Flow Enforcement
HUMAN REVIEWS
The information system enforces the use of human reviews for organization-defined information flows under the following conditions: when the information system is not capable of making an information flow control decision.
Opt Opt Opt
AC-4 (10)
Information Flow Enforcement
ENABLE / DISABLE
SECURITY POLICY FILTERS
The information system provides the capability for privileged administrators to enable/disable organization-defined security policy filters under the following conditions:
such as those specifically defined by the organization.
Opt Opt Opt
AC-4 (11)
Information Flow Enforcement
CONFIGURATION OF
SECURITY POLICY FILTERS
The information system provides the capability for privileged administrators to configure organization-defined security policy filters to support different security policies. Opt Opt Opt
AC-4 (12)
Information Flow Enforcement
DATA TYPE IDENTIFIERS
The information system, when transferring information between different security domains, uses data type specification and usage to validate data essential for information flow decisions.
Opt Opt Opt
AC-4 (13)
Information Flow Enforcement
DECOMPOSITION INTO
POLICY-RELEVANT
SUBCOMPONENTS
The information system, when transferring information between different security domains, decomposes information into organization-defined policy-relevant subcomponents for submission to policy enforcement mechanisms. Opt Opt Opt
AC-4 (14)
Information Flow Enforcement
SECURITY POLICY FILTER
CONSTRAINTS
The information system, when transferring information between different security domains, implements policy filters that restrict data to printable ASCII characters, prohibit special characters, and/or limit excessive field sizes requiring fully enumerated formats that constrain data structure and content.
Opt Opt Opt
AC-4 (15)
Information Flow Enforcement
DETECTION OF
UNSANCTIONED
INFORMATION
The information system, when transferring information between different security domains, examines the information for the presence of unsanctioned information (e.g., obscenities) and prohibits the transfer of such information in accordance with the organization-defined security policy.
Opt Opt Opt
Control Name & Number Control Description
Impact Level H M L
AC-4 (16)
Information Flow Enforcement
INFORMATION TRANSFERS
ON INTERCONNECTED
SYSTEMS
Withdrawn: Incorporated into AC-4.
AC-4 (17)
Information Flow Enforcement
DOMAIN AUTHENTICATION
The information system uniquely identifies and authenticates source and destination points by traits that may include organization, system, application, and individual for information transfer.
Opt Opt Opt
AC-4 (18)
Information Flow Enforcement
SECURITY ATTRIBUTE
BINDING
The information system binds security attributes to information using binding techniques as defined by the judiciary organization to facilitate information flow policy enforcement. Opt Opt Opt
AC-4 (19)
Information Flow Enforcement
VALIDATION OF METADATA
The information system, when transferring information between different security domains, applies the same security policy filtering to metadata as it applies to data payloads.
Opt Opt Opt
AC-4 (20)
Information Flow Enforcement
APPROVED SOLUTIONS
The organization employs organization-defined solutions in approved configurations to control the flow of organization-defined information across security domains. Opt Opt Opt
AC-4 (21)
Information Flow Enforcement
PHYSICAL / LOGICAL
SEPARATION OF
INFORMATION FLOWS
The information system separates information flows logically or physically using organization-defined mechanisms and/or techniques to accomplish organization-required separation of information types. Opt Opt Opt
AC-4 (22)
Information Flow Enforcement
ACCESS ONLY
The information system provides access from a single device to computing platforms, applications, or data residing on multiple different security domains, while preventing any information flow between the different security domains.
Opt Opt Opt
AC-5
Separation of Duties
The organization:
a. Separates duties of individuals as appropriate, to prevent malicious activity without collusion;
b. Documents separation of duties of individuals; and
c. Defines information system access authorizations to support separation of duties
(e.g., role-based access control).
Yes Yes Opt
AC-6
Least Privilege
The organization employs the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with organizational missions and business functions.
Yes Yes Opt
AC-6 (1)
Least Privilege
AUTHORIZE ACCESS TO
SECURITY FUNCTIONS
The organization explicitly authorizes access to organization-defined security functions (deployed in hardware, software, and firmware) and security-relevant information. Yes Yes Opt
AC-6 (2)
Least Privilege
NON-PRIVILEGED ACCESS
FOR NON-SECURITY
FUNCTIONS
The organization requires that users of information system accounts, or roles, with privileged access to organization-defined security functions or security-relevant information, use non-privileged accounts or roles, when accessing non-security functions. Yes Yes Opt
AC-6 (3)
Least Privilege
NETWORK ACCESS TO
PRIVILEGED COMMANDS
The organization authorizes network access to only organization-defined privileged commands and only for specifically defined reasons and documents the rationale for such access in the security plan for the information system.
Yes Opt Opt
AC-6 (4)
Least Privilege
SEPARATE PROCESSING
DOMAINS
The information system provides separate processing domains to enable finer-grained allocation of user privileges (e.g., virtualization methodologies). Opt Opt Opt
AC-6 (5)
Least Privilege
PRIVILEGED ACCOUNTS
The organization restricts privileged accounts on the information system (e.g., root and administrator) to those with a mission need. Yes Yes Opt
Control Name & Number Control Description
Impact Level H M L
AC-6 (6)
Least Privilege
PRIVILEGED ACCESS BY
NON-ORGANIZATIONAL
USERS
The organization prohibits privileged access to the information system by non-organizational users.
Opt Opt Opt
AC-6 (7)
Least Privilege
REVIEW OF USER
PRIVILEGES
The organization:
a. Reviews annually the privileges assigned to organization-defined roles or classes of users to validate the need for such privileges; and
b. Reassigns or removes privileges, if necessary, to correctly reflect organizational mission/business needs.
Yes Yes Opt
AC-6 (8)
Least Privilege
PRIVILEGE LEVELS FOR
CODE EXECUTION
The information system prevents organization-defined software from executing at higher privilege levels than users executing the software. Opt Opt Opt
AC-6 (9)
Least Privilege
AUDITING USE OF
PRIVILEGED FUNCTIONS
The information system audits the execution of privileged functions.
Yes Yes Opt
AC-6 (10)
Least Privilege
PROHIBIT NON-PRIVILEGED
USERS FROM EXECUTING
PRIVILEGED FUNCTIONS
The information system prevents non-privileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures. Yes Yes Opt
AC-7
Unsuccessful Login Attempts
The information system:
a. Enforces a limit of 10 consecutive invalid access attempts by a user during a 30-minute time period for Low and Moderate systems, and enforces a limit of 6 consecutive invalid access attempts by a user during a 30-minute time period for High security category systems, and
b. Automatically locks the account/node for 1 hour for Low and Moderate systems and locks the account/node until released by an administrator for High security category systems when the maximum number of unsuccessful attempts is exceeded.
Yes Yes Yes
AC-7 (1)
Unsuccessful Login Attempts
AUTOMATIC ACCOUNT
LOCK
Withdrawn: Incorporated into AC-7.
AC-7 (2)
Unsuccessful Login Attempts
PURGE/WIPE MOBILE
DEVICE
The information system purges/wipes information from non-encrypted mobile devices accessed via login based on organization-defined purging/wiping requirements/techniques after 10 consecutive, unsuccessful device logon attempts.
Control Name & Number Control Description
Impact Level H M L
AC-8
System Use Notification
The information system:
a. Displays to users an organization-defined system use notification message or banner before granting access to the system that provides privacy and security notices consistent with approved practices (e.g., applicable federal laws, judiciary orders, directives, policies, regulations, standards, and guidance) and states that:
1. Users are accessing a U.S. Government information system;
2. Information system usage may be monitored, recorded, and subject to audit;
3. Unauthorized use of the information system is prohibited and subject to criminal and civil penalties; and
4. Use of the information system indicates consent to monitoring and recording;
b. Retains the notification message or banner on the screen until users acknowledge the usage conditions and take explicit actions to log on to or further access the information system; and
c. For publicly accessible systems:
1. Displays system use information (e.g. notification of conditions), before granting further access;
2. Displays references, if any, to monitoring, recording, or auditing that are consistent with privacy accommodations for such systems that generally prohibit those activities; and
3. Includes a description of the authorized uses of the system.
Yes Yes Yes
AC-9
Previous Logon (Access) Notification
The information system notifies the user, upon successful logon (access) to the system, of the date and time of the last logon (access). Opt Opt Opt
AC-9 (1)
Previous Logon (Access) Notification
UNSUCCESSFUL LOGONS
The information system notifies the user, upon successful logon/access, of the number of unsuccessful logon/access attempts since the last successful logon/access. Opt Opt Opt
AC-9 (2)
Previous Logon (Access) Notification
SUCCESSFUL /
UNSUCCESSFUL LOGONS
The information system notifies the user of the number of unsuccessful logon/access attempts during the previous 24-hour time period.
Opt Opt Opt
AC-9 (3)
Previous Logon (Access) Notification
NOTIFICATION OF
ACCOUNT CHANGES
The information system notifies the user of changes to organization-defined security-related characteristics/parameters of the user’s account during an organization-defined time period. Opt Opt Opt
AC-9 (4)
Previous Logon (Access) Notification
ADDITIONAL LOGON
INFORMATION
The information system notifies the user, upon successful logon (access), of the following additional information: (e.g., location of last logon) in addition to the date and time of the last logon (access). Opt Opt Opt
AC-10
Concurrent Session Control
The information system limits the number of concurrent sessions for each user account to 1, unless explicitly authorized by the system owner. Yes Opt Opt
AC-11
Session Lock
The information system:
a. Prevents further access to the system by initiating a session lock after 15 minutes of inactivity or upon receiving a request from a user; and
b. Retains the session lock until the user reestablishes access using established identification and authentication procedures.
Yes Yes Opt
AC-11 (1)
Session Lock
PATTERN-HIDING DISPLAYS
The information system conceals, via the session lock, information previously visible on the display with a publicly viewable image. Yes Yes Opt
AC-12
Session Termination
The information system automatically terminates a user session after organization-defined conditions or trigger events requiring session disconnect. Yes Yes Opt
Control Name & Number Control Description
Impact Level H M L
AC-12 (1)
Session Termination
USER-INITIATED LOGOUTS /
MESSAGE DISPLAYS
The information system:
a. Provides a logout capability for user-initiated communications sessions whenever authentication is used to gain access to organization-defined information resources;
and
b. Displays an explicit logout message to users indicating the reliable termination of authenticated communications sessions.
Opt Opt Opt
AC-13
Supervision and Review – Access Control
Withdrawn: Incorporated into AC-2 and AU-6.
AC-14
Permitted Actions Without Identification or Authentication
The organization:
a. Identifies specific user actions that can be performed on the information system without identification or authentication consistent with organizational missions/business functions; and
b. Documents and provides supporting rationale in the security plan for the information system, user actions not requiring identification or authentication.
Yes Yes Yes
AC-14 (1)
Permitted Actions Without Identification or Authentication
NECESSARY USES
Withdrawn: Incorporated into AC-14.
AC-15
Automated Marking
Withdrawn: Incorporated into MP-3. --- --- ---
AC-16
Security Attributes
The organization:
a. Provides the means to associate organization-defined types of security attributes having organization-defined security attribute values with information in storage, in process, and/or in transmission;
b. Ensures that the security attribute associations are made and retained with the information;
c. Establishes the permitted organization-defined security attributes for organization-defined information systems; and
d. Determines the permitted organization-defined values or ranges for each of the established security attributes.
Opt Opt Opt
AC-16 (1)
Security Attributes
DYNAMIC ATTRIBUTE
ASSOCIATION
The information system dynamically associates security attributes with organization-defined subjects and objects in accordance with an identified security policy as information is created and combined.
Opt Opt Opt
AC-16 (2)
Security Attributes
ATTRIBUTE VALUE
CHANGES BY AUTHORIZED
INDIVIDUALS
The information system provides authorized individuals (or processes acting on behalf of individuals) the capability to define or change the value of associated security attributes.
Opt Opt Opt
AC-16 (3)
Security Attributes
MAINTENANCE OF
ATTRIBUTE ASSOCIATIONS
BY INFORMATION SYSTEM
The information system maintains the association and integrity of (e.g., binding) organization-defined security attributes to information with sufficient assurance that the information-attribute association can be used as the basis for automated access control or information flow decisions.
Opt Opt Opt
AC-16 (4)
Security Attributes
ASSOCIATION OF
ATTRIBUTES BY
AUTHORIZED INDIVIDUALS
The information system supports the association of authorized users with the security attributes of the information by authorized individuals (or processes acting on behalf of individuals). Opt Opt Opt
AC-16 (5)
Security Attributes
ATTRIBUTE DISPLAYS FOR
OUTPUT DEVICES
The information system displays security attributes in human-readable form on each object that the system transmits to output devices to identify an organization-defined set of special dissemination, handling, or distribution instructions using organization-defined, human-readable, standard naming conventions.
Control Name & Number Control Description
Impact Level H M L
AC-16 (6)
Security Attributes
MAINTENANCE OF
ATTRIBUTE ASSOCIATION
BY ORGANIZATION
The organization allows personnel to associate, and maintain the association of security attributes with subjects and objects in accordance with organization-defined security policies. Opt Opt Opt
AC-16 (7)
Security Attributes
CONSISTENT ATTRIBUTE
INTERPRETATION
The organization provides a consistent interpretation of security attributes transmitted between distributed information system components. Opt Opt Opt
AC-16 (8)
Security Attributes
ASSOCIATION TECHNIQUES
/ TECHNOLOGIES
The information system implements organization-defined techniques or technologies with an organization-defined level of assurance in associating security attributes to information. Opt Opt Opt
AC-16 (9)
Security Attributes
ATTRIBUTE
REASSIGNMENT
The organization ensures that security attributes associated with information are reassigned only via re-grading mechanisms validated using organization-defined techniques or procedures approved by the judiciary organization.
Opt Opt Opt
AC-16 (10)
Security Attributes
ATTRIBUTE
CONFIGURATION BY
AUTHORIZED INDIVIDUALS
The information system provides authorized individuals the capability to define or change the type and value of security attributes available for association with subjects and objects. Opt Opt Opt
AC-17
Remote Access
The organization:
a. Establishes and documents usage restrictions, configuration/connection requirements, and implementation guidance for each type of remote access allowed;
and
b. Authorizes remote access to the information system prior to allowing such connections.
Yes Yes Yes
AC-17 (1)
Remote Access
AUTOMATED MONITORING /
CONTROL
The information system monitors and controls remote access methods.
Yes Yes Opt
AC-17 (2)
Remote Access
PROTECTION OF
CONFIDENTIALITY /
INTEGRITY USING
ENCRYPTION
The information system implements cryptographic mechanisms to protect the confidentiality and integrity of remote access sessions.
Yes Yes Opt
AC-17 (3)
Remote Access
MANAGED ACCESS
CONTROL POINTS
The information system routes all remote accesses through a limited number of managed network access control points. Yes Yes Opt
AC-17 (4)
Remote Access
PRIVILEGED COMMANDS /
ACCESS
The organization:
a. Authorizes the execution of privileged commands and access to security-relevant information via remote access only security-relevant information via remote access only for compelling mission needs; and
b. Documents the rationale for such access in the security plan for the information system.
Yes Yes Opt
AC-17 (5)
Remote Access
ATTRIBUTE DISPLAYS FOR
OUTPUT DEVICES
Withdrawn: Incorporated into SI-4.
AC-17 (6)
Remote Access
PROTECTION OF
INFORMATION
The organization ensures that users protect information about remote access mechanisms from unauthorized use and disclosure. Opt Opt Opt
AC-17 (7)
Remote Access
CONSISTENT ATTRIBUTE
INTERPRETATION
Withdrawn: Incorporated into AC-3 (10).
Control Name & Number Control Description
Impact Level H M L
AC-17 (8)
Remote Access
ASSOCIATION TECHNIQUES
/ TECHNOLOGIES
Withdrawn: Incorporated into CM-7.
AC-17 (9)
Remote Access
DISCONNECT / DISABLE
ACCESS
The organization provides the capability to expeditiously disconnect or disable remote access to the information system within 15 minutes. Opt Opt Opt
AC-18
Wireless Access
The organization:
a. Establishes usage restrictions, configuration/connection requirements, and implementation guidance for wireless access; and
b. Authorizes wireless access to the information system prior to allowing such connections.
Yes Yes Yes
AC-18 (1)
Wireless Access
AUTHENTICATION AND
ENCRYPTION
The information system protects wireless access to the system using authentication of either users or devices, and encryption. Yes Yes Opt
AC-18 (2)
Wireless Access
MONITORING
UNAUTHORIZED
CONNECTIONS
Withdrawn: Incorporated into SI-4.
AC-18 (3)
Wireless Access
DISABLE WIRELESS
NETWORKING
The organization disables, when not intended for use, wireless networking capabilities internally embedded within information system components prior to issuance and deployment.
Opt Opt Opt
AC-18 (4)
Wireless Access
RESTRICT
CONFIGURATIONS
BY USERS
The organization identifies and explicitly authorizes users allowed to independently configure wireless networking capabilities.
Yes Opt Opt
AC-18 (5)
Wireless Access
ANTENNAS /
TRANSMISSION POWER
LEVELS
The organization selects radio antennas and calibrates transmission power levels to reduce the probability that usable signals can be received outside of organization-controlled boundaries. Yes Opt Opt
AC-19
Access Control for Mobile Devices
The organization:
a. Establishes usage restrictions, configuration requirements, connection requirements, and implementation guidance for organization-controlled mobile devices; and
b. Authorizes the connection of mobile devices to organizational information systems.
Yes Yes Yes
AC-19 (1)
Access Control for Mobile Devices
USE OF WRITABLE /
PORTABLE STORAGE
DEVICES
Withdrawn: Incorporated into MP-7.
AC-19 (2)
Access Control for Mobile Devices
USE OF PERSONALLY
OWNED PORTABLE
STORAGE DEVICES
Withdrawn: Incorporated into MP-7.
AC-19 (3)
Access Control for Mobile Devices
USE OF PORTABLE
STORAGE DEVICES WITH
NO IDENTIFIABLE OWNER
Withdrawn: Incorporated into MP-7.
Control Name & Number Control Description
Impact Level H M L
AC-19 (4)
Access Control for Mobile Devices
RESTRICTIONS FOR
CLASSIFIED INFORMATION
The organization:
a. Prohibits the use of unclassified mobile devices in facilities containing information systems processing, storing, or transmitting classified information unless specifically permitted by the authorizing official; and
b. Enforces the following restrictions on individuals permitted by the authorizing official to use unclassified mobile devices in facilities containing information systems processing, storing, or transmitting classified information:
1. Connection of unclassified mobile devices to classified information systems is prohibited;
2. Connection of unclassified mobile devices to unclassified information systems requires approval from the authorizing official;
3. Use of internal or external modems or wireless interfaces within the unclassified mobile devices is prohibited; and
4. Unclassified mobile devices and the information stored on those devices are subject to random reviews and inspections by organization-defined security officials, and if classified information is found, the incident handling policy is followed.
c. Restricts the connection of classified mobile devices to classified information systems in accordance with organization-defined security policies.
Opt Opt Opt
AC-19 (5)
Access Control for Mobile Devices
FULL-DEVICE / CONTAINER-
BASED ENCRYPTION
The organization employs a form of encryption (e.g., full device or container) to protect the confidentiality and integrity of information on mobile devices identified by the judiciary organization. Yes Yes Opt
AC-20
Use of External Information Systems
The organization establishes terms and conditions, consistent with any trust relationships established with other organizations owning, operating, and/or maintaining external information systems, allowing authorized individuals to:
a. Access the information system from external information systems; and
b. Process, store, or transmit organization-controlled information using external information systems.
Yes Yes Yes
AC-20 (1)
Use of External Information Systems
LIMITS ON AUTHORIZED
USE
The organization permits authorized individuals to use an external information system to access the information system or to process, store, or transmit organization-controlled information only when the organization:
a. Verifies the implementation of required security controls on the external system as specified in the organization’s information security policy and security plan; or
b. Retains approved information system connection or processing agreements with the organizational entity hosting the external information system.
Yes Yes Opt
AC-20 (2)
Use of External Information Systems
PORTABLE STORAGE
DEVICES
The organization restricts or prohibits the use of organization-controlled portable storage devices by authorized individuals on external information systems.
Yes Yes Opt
AC-20 (3)
Use of External Information Systems
NON-ORGANIZATIONALLY
OWNED SYSTEMS /
COMPONENTS/ DEVICES
The organization restricts or prohibits the use of non-organizationally owned information systems, system components, or devices to process, store, or transmit organizational information. Opt Opt Opt
AC-20 (4)
Use of External Information Systems
NETWORK ACCESSIBLE
STORAGE DEVICES
The organization prohibits the use of organization-defined network accessible storage devices in external information systems.
Control Name & Number Control Description
Impact Level H M L
AC-21
Information Sharing
The organization:
a. Facilitates information sharing by enabling authorized users to determine whether access authorizations assigned to the sharing partner match the access restrictions on the information for organization-defined circumstances where user discretion is required; and
b. Employs either automated mechanisms or manual processes to assist users in making information sharing/collaboration decisions.
Yes Yes Opt
AC-21 (1)
Information Sharing
AUTOMATED DECISION
SUPPORT
The information system enforces information-sharing decisions by authorized users based on access authorizations of sharing partners and access restrictions on information to be shared.
Opt Opt Opt
AC-21 (2)
Information Sharing
INFORMATION SEARCH
AND RETRIEVAL
The information system implements information search and retrieval services that enforce organization-defined information sharing restrictions. Opt Opt Opt
AC-22
Publicly Accessible Content
The organization:
a. Designates individuals authorized to post information onto a publicly accessible information system;
b. Trains authorized individuals to ensure that publicly accessible information does not contain nonpublic information;
c. Reviews the proposed content of information prior to posting onto the publicly accessible information system to ensure that nonpublic information is not included;
and
d. Reviews the content on the publicly accessible information system for nonpublic information periodically (at least quarterly), and removes such information, if discovered.
Yes Yes Yes
AC-23
Data Mining Protection
The organization employs data mining prevention and detection techniques for organization-defined data storage objects to adequately detect and protect against data mining.
Opt Opt Opt
AC-24
Access Control Decisions
The organization establishes procedures to ensure organization-defined access control decisions are applied to each access request prior to access enforcement. Opt Opt Opt
AC-24 (1)
Access Control Decisions
TRANSMIT ACCESS
AUTHORIZATION
INFORMATION
The information system transmits organization-defined access authorization information using organization-defined security safeguards to organization-defined information systems that enforce access control decisions. Opt Opt Opt
AC-24 (2)
Access Control Decisions
NO USER OR PROCESS
IDENTITY
The information system enforces access control decisions based on organization-defined security attributes that do not include the identity of the user or process acting on behalf of the user.
Opt Opt Opt
AC-25
Reference Monitor
The information system implements a reference monitor for organization-defined access control policies that is tamperproof, always invoked, and small enough to be subject to analysis and testing, the completeness of which can be assured.
Control Name & Number Control Description
Impact Level H M L
Awareness and Training
AT-1
Security Awareness and Training Policy and Procedures
The organization:
a. Develops, documents, and disseminates to organization-defined personnel or roles:
1. A security awareness and training policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
2. Procedures to facilitate the implementation of the security awareness and training policy and associated security awareness and training controls; and
b. Reviews and updates the current:
1. Security awareness and training policy periodically (not to exceed annually); and
2. Security awareness and training procedures periodically (not to exceed annually).
Yes Yes Yes
AT-2
Security Awareness Training
The organization provides basic security awareness training to information system users (including managers, senior executives, and contractors):
a. As part of initial training for new users;
b. When required by information system changes; and
c. Periodically (at least annually) thereafter.
Yes Yes Yes
AT-2 (1)
Security Awareness Training
PRACTICAL EXERCISES
The organization includes practical exercises in security awareness training that simulate actual cyber-attacks. Opt Opt Opt
AT-2 (2)
Security Awareness Training
INSIDER THREAT
The organization includes security awareness training on recognizing and reporting potential indicators of insider threat. Yes Yes Opt
AT-3
Role-Based Security Training
The organization provides role-based security training to personnel with assigned security roles and responsibilities:
a. Before authorizing access to the information system or performing assigned duties;
b. When required by information system changes; and
c. Periodically (at least annually) thereafter.
Yes Yes Yes
AT-3 (1)
Role Based Security Training
ENVIRONMENTAL
CONTROLS
The organization provides employees with initial and periodic (at least annual) training in the employment and operation of environmental controls. Opt Opt Opt
AT-3 (2)
Role Based Security Training
PHYSICAL SECURITY
CONTROLS
The organization provides employees with initial and periodic (at least annual) training in the employment and operation of physical security controls. Opt Opt Opt
AT-3 (3)
Role Based Security Training
PRACTICAL EXERCISES
The organization includes practical exercises in security training that reinforce training objectives (e.g., training for software developers that include simulated cyber-attacks such as buffer overflow or SQL injection, etc.).
Opt Opt Opt
AT-3 (4)
Role Based Security Training
SUSPICIOUS
COMMUNICATIONS AND
ANOMALOUS SYSTEM
BEHAVIOR
The organization provides training to its personnel on general indicators of malicious code to recognize suspicious communications and anomalous behavior in organizational information systems. Opt Opt Opt
AT-4
Security Training Records
The organization:
a. Documents and monitors individual information system security training activities including basic security awareness training and specific information system security training; and
b. Retains individual training records for at least 5 years.
Yes Yes Yes
AT-5
Contacts with Security Groups and Associations
Withdrawn: Incorporated into PM-15.
Control Name & Number Control Description
Impact Level H M L
Audit and Accountability
AU-1
Audit and Accountability Policy and Procedures
The organization:
a. Develops, documents, and disseminates to organization-defined personnel or roles:
1. An audit and accountability policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
2. Procedures to facilitate the implementation of the audit and accountability policy and associated audit and accountability controls; and
b. Reviews and updates the current:
1. Audit and accountability policy periodically (not to exceed annually); and
2. Audit and accountability procedures periodically (not to exceed annually).
Yes Yes Yes
AU-2
Audit Events
The organization:
a. Determines that the information system is capable of auditing the following events: failed logon attempts, successful logons; and access to sealed electronic documents;
b. Coordinates the security audit function with other organizational entities requiring audit-related information to enhance mutual support and to help guide the selection of auditable events;
c. Provides a rationale for why the auditable events are deemed to be adequate to support after-the-fact investigations of security incidents; and
d. Determines that the following events are to be audited within the information system:
organization-defined audited events (the subset of the auditable events defined in AU-2 a.) along with the frequency of (or situation requiring) auditing for each identified event.
Yes Yes Yes
AU-2 (1)
Audit Events
COMPILATION OF AUDIT
RECORDS FROM MULTIPLE
SOURCES
Withdrawn: Incorporated into AU-12.
AU-2 (2)
Audit Events
SELECTION OF AUDIT
EVENTS BY COMPONENT
Withdrawn: Incorporated into AU-12.
AU-2 (3)
Audit Events
REVIEWS AND UPDATES
The organization reviews and updates the audited events periodically (recommended at least annually). Yes Yes Opt
AU-2 (4)
Audit Events
PRIVILEGED FUNCTIONS
Withdrawn: Incorporated into AC-6 (9).
AU-3
Content of Audit Records
The information system generates audit records containing information that establishes what type of event occurred, when the event occurred, where the event occurred, the source of the event, the outcome of the event, and the identity of any individuals or subjects associated with the…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it.