NAP-14.1C, NNSA Baseline Cyber Security Program
Implement DOE O 205.1A, Department of Energy Cyber Security Management,
and TMR-0, DOE Cyber Security Program Foundation in the National Nuclear
Security Administration (NNSA) and all Elements under its cognizance.
Associated DOE Directive:
Version history and related documents
Related documents
Document text
Text extracted from the attached file. Refer to the original document for the authoritative version.
Section 1
AVAILABLE ONLINE AT: INITIATED BY:
http://hq.na.gov Office of the Chief Information Officer
NNSA POLICY LETTER
Approved: 05-02-08
NNSA BASELINE CYBER SECURITY
PROGRAM
NATIONAL NUCLEAR SECURITY ADMINISTRATION
Office of the Chief Information Officer
NAP 14.1-C
ii NAP 14.1-C
05-02-08
This page intentionally left blank.
NAP 14.1-C iii
05-02-08
Table of Contents
GENERAL OVERVIEW
CHAPTER I. NNSA PCSP OVERVIEW I-1
CHAPTER II. MANAGEMENT STRUCTURE AND RESPONSIBILITIES II-1
CHAPTER III. CONFIGURATION MANAGEMENT III-1
CHAPTER IV. CYBER SECURITY PROGRAM PLAN IV-1
CHAPTER V. INFORMATION GROUPS V-1
CHAPTER VI. NNSA CYBER SECURITY PROGRAM DEVIATIONS VI-1
CHAPTER VII. INCIDENT MANAGEMENT VII-1
CHAPTER VIII. INFORMATION CONDITION (INFOCON) VIII-1
CHAPTER IX. PLAN OF ACTIONS AND MILESTONES IX-1
CHAPTER X. VULNERABILITY MANAGEMENT X-1
CHAPTER XI. PORTABLE COMPUTING DEVICES XI-1
CHAPTER XII. PASSWORD GENERATION, PROTECTION, AND USE XII-1
CHAPTER XIII. WIRELESS TECHNOLOGIES XIII-1
CHAPTER XIV. REMOTE ACCESS XIV-1
CHAPTER XV. CONTINGENCY PLANNING XV-1
CHAPTER XVI. CLEARING, PURGING, AND DESTROYING MEDIA XVI-1
CHAPTER XVII. SENSITIVE UNCLASSIFIED INFORMATION XVII-1
CHAPTER XVIII. PEER-TO-PEER (P2P) NETWORKING XVIII-1
CHAPTER XIX. FOREIGN NATIONAL ACCESS XIX-1
CHAPTER XX. NNSA INTER-SITE NETWORK INTERCONNECTION APPROVAL
PROCESS, APPROVAL AUTHORITY, AND CONNECTION REQUIREMENTS XX-1
Appendices
APPENDIX A: ACRONYMS A-1
APPENDIX B: GLOSSARY B-1
APPENDIX C: CONTRACTORS REQUIREMENTS DOCUMENT C-1
APPENDIX D: RECOMMENDED ACTIONS FOR INFOCON LEVELS D-1
APPENDIX E: FACTORS INFLUENCING INFOCON E-1
APPENDIX F: OPERATIONAL IMPACT ASSESSMENT F-1
APPENDIX G: CONTINGENCY PLAN STRUCTURE G-1
APPENDIX H: RISK ASSESSMENT METHODOLOGY H-1
APPENDIX I: SAMPLE MEMORANDUM OF UNDERSTANDING (MOU) I-1
APPENDIX J: SAMPLE NNSA INTERCONNECTION SECURITY AGREEMENT J-1
iv NAP 14.1-C
05-02-08
Figures
FIGURE VII-1. NNSA CYBER SECURITY INCIDENT REPORTING PROCESS VII-5
FIGURE VII-2. NNSA PII CYBER SECURITY INCIDENT REPORTING PROCESS VII-6
FIGURE VII-3. NNSA PII MANAGEMENT – LOST OR STOLEN DATA PROCESS FLOW VII-7
FIGURE XX-1. INTERCONNECTIVITY PROCESS FLOW XX-7
Tables
TABLE VII-1. REQUIRED TIME FRAME FOR REPORTING INCIDENTS OF SECURITY
CONCERN BASED ON IMPACT MEASUREMENT INDEX VII-2
TABLE VII-2. REQUIRED TIME FRAME FOR REPORTING CYBER SECURITY INCIDENTS
TO THE INFORMATION ASSURANCE RESPONSE CENTER (IARC) VII-5
TABLE VIII-1. INFOCON LEVELS VII-3
TABLE XVI-1. APPROVED PROCESSES FOR MANAGING STORAGE MEDIA XVI-8
TABLE XVI-2. APPROVED PROCESSES FOR MANAGING ELECTRONIC MEMORY DEVICES XVI-9
TABLE XVI-3. APPROVED PROCESSES FOR MANAGING HARDWARE XVI-10
NAP 14.1-C 1
05-02-08
NNSA BASELINE CYBER SECURITY PROGRAM
OVERVIEW
1. PURPOSE.
a. Implement DOE O 205.1A, Department of Energy Cyber Security Management,
and TMR-0, DOE Cyber Security Program Foundation in the National Nuclear
Security Administration (NNSA) and all Elements under its cognizance.
b. Establish an NNSA Program Cyber Security Plan (PCSP) that systematically
integrates cyber security into management and work practices at all levels in the
NNSA so that missions are accomplished while appropriately protecting all
information on information systems.
Section 2
c. Establish requirements and assign responsibilities within the NNSA PCSP for
protecting information on information systems.
d. Ensure the NNSA PCSP is consistent with, and achieves the objectives of
Executive Orders, National Security Directives, DOE Orders and Manuals, and
Federal regulations.
e. Establish a NNSA cyber security process that addresses program requirements,
defines protection measures, provides cyber security planning, and implements
the NNSA PCSP.
f. Implement requirements in Public Law (PUB.L.) 100-235 (1987), the Federal
Information Security Management Act of 2002 (FISMA), Presidential Directives
and Executive Orders, Office of Management and Budget (OMB) directives,
National Institute of Standards and Technology (NIST) Federal Information
Processing Standards (FIPS), Departmental policies, and the DOE CIO Cyber
Security Technical and Management Requirements (TMRs).
2. CANCELLATIONS. This NNSA Policy replaces NNSA Policy Letters (NAPs) 14.1-B,
14.2-B, 14.3-A, 14.4-A, 14.5-A, 14.6-A, 14.7A, 14.8A, 14.9A, 14.10A. 14.11-A, 14.12,
14.13, 14.14, 14.15, and 14.16.
3. APPLICABILITY. This NAP applies to all NNSA entities, Federal or contractors, that
collect, create, process, transmit, store, and disseminate information on automated
information systems for the NNSA.
NNSA Elements. NNSA Headquarters (HQ) Site, Organizations, Service Centers, Site
Offices, NNSA contractors, and subcontractors are hereafter referred to as NNSA
Elements or sites. This NAP applies to all NNSA Elements.
a. Information System. This NAP applies to any information system that collects,
creates, processes, transmits, stores, and disseminates unclassified or classified
2 NAP 14.1-C
05-02-08
NNSA information. This NAP applies to any information system lifecycle,
including the development of new information systems, the incorporation of
information systems into an infrastructure, the incorporation of information
systems outside the infrastructure, the development of prototype information
systems, the reconfiguration or upgrade of existing systems, and legacy systems.
In this document, the term(s) "information system," “cyber system,” or "system,"
are used to define any information system or network used to collect, create,
process, transmit, store, or disseminate data owned by, for, or on behalf of, NNSA
or DOE.
b. Exclusions.
(1) The Deputy Administrator for Naval Reactors shall, in accordance with
the responsibilities and authorities assigned by Executive Order 12344, set
forth in Public Law 106-65 of October 5, 1999, 50 U.S.C. 2406, and to
ensure consistency throughout the joint Navy and DOE Organization of
the Naval Reactors Propulsion Program, implement and oversee all
requirements and practices pertaining to this Order for activities under the
Deputy Administrators cognizance.
(2) The NNSA PCSP does not apply to Sensitive Compartmented Information
(SCI) information systems located at NNSA sites. SCI systems must
comply with Director, Central Intelligence Directives (DCIDs), or
Intelligence Community Directives (ICDs) security policies. The DOE
Office of Intelligence and Counterintelligence approves operation of these
information systems.
Section 3
(3) Implementation. A plan for the implementation of this NAP must be
completed within 60 days after modification of the site’s contract to
include this NAP. A plan for implementation of this NAP within an
NNSA Federal organization must be completed within 60 days after
issuance of this NAP. The implementation plan must include, at a
minimum, the program activity to be modified and created; the starting
date of revision or development; the estimated due date; and the
responsible party for the stated activity. This implementation plan shall
not exceed three years from the date of formal approval of the
implementation plan. The implementation plan must be approved by the
local NNSA Designating Approval Authority (DAA). This means that the
NNSA Element’s Cyber Security Program (CSP) must comply with all
requirements set forth in this NAP. Further, all information systems as
defined in the Glossary must be protected in accordance with the
requirements set forth in this NAP.
4. BACKGROUND. The loss or compromise of information entrusted to NNSA or its
contractors may affect the National Security, the Nation's economic competitive position,
the environment, NNSA missions, and other citizens of the United States. All
NAP 14.1-C 3
05-02-08
information collected, created, processed, transmitted, stored, or disseminated by, or on
behalf of, the NNSA on automated information systems requires some level of protection.
Loss or compromise of information entrusted to NNSA or its contractors may affect the
nation's economic competitive position, the environment, the National Security, NNSA
missions, or the citizens of the United States. The risk management approach defined in
the NNSA CSP provides for the graded, cost-effective protection of information systems
containing unclassified or classified information.
The NNSA NAP 14 series, NNSA Threat Statement, the NNSA Risk Assessment
document, and the NNSA CSP comprises the NNSA PCSP. The NNSA PCSP
systematically integrates cyber security into management and work practices at all levels
in the NNSA so that missions are accomplished while appropriately protecting all
information on information systems; establishes requirements and responsibilities for
protecting information on information systems for the purpose of maintaining National
Security and ensuring the continuity of NNSA operations; and ensures that NNSA cyber
security is consistent with, and achieves the objectives of all applicable Executive
Orders, National Security Directives, DOE Orders and Manuals, and Federal regulations.
a. The PCSP is implemented through a CSPP for each NNSA Element.
b. Risk management is a process that considers the prevailing NNSA threat analysis,
the attributes of the information being protected, the effect of countermeasures in
place and planned, and the remaining vulnerability of the processing environment
(residual risk).
c. The PCSP establishes minimum protection requirements based on the
Consequences of Loss (CoL) of confidentiality, integrity, and availability of all
information.
d. Protection requirements for all information systems are documented in
Information System Security Plans (ISSPs).
e. The PCSP is consistent with other NNSA Directives and DOE Orders, Manuals,
and Technical and Management Requirements that provide specific security
requirements for information systems, including communications systems,
transmission systems, as well as classified and unclassified matter through
administrative procedures, logical access, and physical security requirements.
Section 4
f. The NNSA PCSP implements the following DOE cyber security policies and
guidelines:
• DOE P 205.1, Departmental Cyber Security Management Policy
• DOE O 205.1A, Department of Energy Cyber Security Management
• DOE M 205.1-4, National Security System Manual
• DOE N 206.5, Response and Notification Procedures for Data Breaches
Involving Personally Identifiable Information
• DOE CIO TMR-0, DOE Cyber Security Program Foundation
• DOE CIO TMR-4, Vulnerability Management
4 NAP 14.1-C
05-02-08
• DOE CIO TMR-6, Plan of Action and Milestones
• DOE CIO TMR-8, Configuration Management
• DOE CIO TMR-12, Wireless Devices and Information Systems
• DOE CIO TMR-13, Portable and Mobile Devices
• DOE CIO TMR-14, External Information Systems
• DOE CIO TMR-18, Peer-to-Peer (P2P) Networking
5. REQUIREMENTS. NNSA Elements must implement and manage a risk-based CSP.
Risk-based approaches, procedures, and other means must be used to evaluate and verify
effectiveness of cyber security measures, identify areas requiring improvement, and
validate implemented improvements. The following paragraphs address these
approaches and procedures.
a. Protection Measures. Protection measures for all NNSA information systems
must conform to the protection measures described in the NNSA PCSP, the
NNSA Element’s CSPP, and the ISSP.
(1) Protection measures may be strengthened based on an assessment of
unique local threat(s) or the local evaluation of CoL.
(2) All Governmental information and any non-Governmental information on
an NNSA information system must be considered when determining the
system’s protection measures.
b. Information Groups. An NNSA Information Group contains all information that
requires similar protection or is similar in content, use, or sensitivity. All NNSA
information must be identified as part of an NNSA-approved Information Group.
Chapter V contains the definition of NNSA Information Groups and the mapping
between the Information Groups and DOE cyber security enclave classes.
Chapter XVII further details what information is considered to be Sensitive
Unclassified Information (SUI), including Personally Identifiable Information
(PII).
c. Classified Information Access. Access to classified information must be granted
only to persons with the appropriate access authorization and Need-to-Know in
the performance of their duties according to NNSA policies and DOE M 470.4-4,
Information Security. The individual disseminating the information is responsible
for determining the recipient’s Need-to-Know in accordance with the site’s
processes and NNSA policies and guidance.
d. Unclassified Information Access. Access to unclassified information must be
granted to only those persons who have the appropriate access authorization and
Need-to-Know for the information in the performance of their duties. The
individual disseminating the information is responsible for determining the
recipient’s Need-to-Know in accordance with the site’s processes and NNSA
NAP 14.1-C 5
05-02-08
policies and guidance.
e. Knowledge and Resources. All NNSA Element personnel must possess the
knowledge, skills, equipment, and resources to fulfill their cyber security
responsibilities under both normal and emergency conditions. The primary roles
and responsibilities of all applicable NNSA Element personnel are described in
Chapter II.
Section 5
f. Facility Clearance and Registration. NNSA Elements with classified information
systems must obtain prior approval access through the Facility Clearance and
Registration Process, as outlined in DOE M 470.4-1, Safeguards and Security
Program Planning and Management.
g. Risk Management Process. The NNSA Element must implement the risk
management process and requirements described in Appendix H.
h. Configuration Management. The NNSA Element must implement NNSA
Configuration Management (CM) policies and processes for all NNSA
information systems within the Element, as described in Chapter III.
i. Cyber Security Program Plan (CSPP). The NNSA Element must implement the
CSPP processes and requirements described in Chapter IV.
j. Deviations. Any deviation from the NNSA cyber security requirements and pr
Serves as the DAA for all information systems whose perimeter or presence as
described in an ISSP is wholly contained (Federal or contractor) under the
cognizance of the NNSA Service Center. The Service Center Director/Manager’s
DAA approval authority may be delegated to another Federal employee of the
Service Center, or through a memorandum of agreement, to NNSA Federal
employees at the NNSA Headquarters Site or a Site Office. Processes must be
documented and approved, as described in Chapter VI.
k. Incident Management. NNSA Elements must implement established
requirements and responsibilities for cyber security incident preparation,
prevention, warnings, reporting, and recovery from cyber security incidents
involving NNSA information systems.
l. INFOCON. NNSA Elements must implement established requirements and
guidance for standardized procedures and responsibilities for authorizing and
communicating Information Conditions (INFOCONs) within the Element, and to
or from the NNSA Office of the Chief Information Officer (OCIO).
m. Plan of Actions and Milestones (POA&M). NNSA Elements must implement
established requirements for tracking and mitigation of CSP and system-level
weaknesses identified at specific NNSA sites.
n. Vulnerability Management. NNSA Elements must implement established
NAP 14.1 -C
05-02-08
requirements for the development of a vulnerability management program, to
include patch management procedures, for NNSA information systems.
o. Foreign National Access. NNSA Elements must implement established
requirements for allowing Foreign National Access to NNSA information systems
to include, but not be limited to, computers, networks, associated servers, data
storage devices, and portable or mobile devices.
p. Portable Computing Devices. NNSA Elements must implement established
requirements for the use of non-Government owned or Government-owned
computing devices for NNSA and all organizations under its cognizance.
q. Password Protection. NNSA Elements must implement established requirements
for the generation, protection, and use of passwords to support authentication
when accessing classified and unclassified NNSA information systems,
applications, and resources.
r. Wireless, Remote. and Peer-to-Peer (P2P) Networking Technolopies. NNSA
Elements must establish minimum security controls as appropriate to protect
NNSA information systems, applications, and software, when implementing
wireless, remote, and P2P technologies.
6. DEFINITIONS. The Glossary in Appendix B defines the acronyms, abbreviations, and
terms used in this document.
7. CONTACTS. Questions concerning this NAP should be directed to the Cyber Security
Program Manager (CSPM), at 202-586-9728.
Section 6
BY ORDER OF THE ADMINISTRATOR:
THOMAS P. D ' A G O S ~ O
Administrator
NAP 14.1-C I-1
05-02-08
CHAPTER I. NNSA PCSP OVERVIEW
1. INTRODUCTION. The requirements of the NNSA PCSP, as detailed in this NAP, apply
to any information system or network that is used to collect, create, process, transmit,
store, or disseminate information for the NNSA. The NNSA PCSP implements National
and Departmental cyber security policies.
2. PCSP MANAGEMENT. While cyber security is everybody’s responsibility, there are
several positions that have key roles in the NNSA PCSP. They are: 1) the CSPM; 2) the
DAA; 3) the Information System Security Office Manager (ISOM); 4) the Information
Systems Security Site Manager (ISSM); 5) the Information System Owner (ISO); and 6)
the Information System Security Officer (ISSO). The roles and responsibilities for these
positions are described in Chapter II.
3. CYBER SECURITY PROGRAM PLAN. Implementation of the NNSA PCSP is
documented in a CSPP. A CSPP must be prepared for each NNSA Element, unless the
Element is covered under another CSPP. The CSPP is the document that outlines the
policies, procedures, and practices of an Element’s CSP. The CSPP is a management-
level document that details the Element’s policies, procedures, and practices for ensuring
effective cyber security. It also explains the site, or application-specific environment,
missions, and threats. The policies, procedures, practices, environments, missions, and
threats that are applicable to systems and major applications at the Enterprise level are
documented in the NNSA Element’s CSPPs.
4. MINIMUM INFORMATION SYSTEM SECURITY CONFIGURATIONS. The NNSA
PCSP requires all NNSA Elements to implement and maintain NNSA-approved
minimum security configurations. The minimum security configurations for unclassified
and classified information systems, as determined by the system categorization process,
are listed in NAP 14.2-C, NNSA Certification and Accreditation (C&A) Process, Chapter
III. Each NNSA Element must implement NNSA-specified or NNSA-approved
monitoring capabilities to ensure that protection features defined in the approved
minimum security configurations are maintained in the system. If the minimum security
configuration cannot be implemented, this must be stated in the Risk Assessment for the
system. The monitoring capability must provide continuous review and reporting of the
status of the minimum security configuration specified for each information system. The
monitoring capability must provide the ability to continuously detect and manage
changes in software used in the information system components.
If an information system cannot implement an NNSA-approved minimum information
system security configuration due to operational or mission requirements, a new
minimum security configuration must be developed and approved by NNSA CSPM.
The minimum security configuration must provides assurance that all security measures
I-2 NAP 14.1-C
05-02-08
are implemented and maintained in the information system, documented in the ISSP, and
approved by the local NNSA DAA.
5. CERTIFICATION AND ACCREDITATION. The NNSA PCSP implements the
National and Departmental requirements for the C&A of all information systems. The
NNSA PCSP requires that each information system be accredited every three (3) years,
or when significant changes have been made to the system, the system environment, the
threat, or cyber security requirements, in response to changes in the NNSA PCSP. Each
information system must receive an accreditation, i.e., approval to operate (ATO) or an
interim approval to operate (IATO), before beginning operational activities. NAP 14.2-
C, NNSA C&A Process, sets forth the requirements for the C&A program.
Section 7
6. INFORMATION SYSTEM SECURITY PLAN (ISSP). All information systems
processing information at a site must be included as part of an ISSP, and they must
receive an ATO or IATO before production. The ISSP is the basis for C&A process.
The ISSP documents the security environment in which the information system exists,
such as the cyber security requirements needed to protect the information on the system,
and implementation of the cyber security requirements for formal accreditation of the
information system. The ISSP must be tailored to address the characteristics of the
information system, operational requirements, security policy, and prudent risk
management throughout the system's lifecycle as conditions change. Required
information for the ISSP is thoroughly described in NAP 14.2-C, NNSA C&A Process.
NAP 14.1-C II-1
05-02-08
CHAPTER II. MANAGEMENT STRUCTURE AND RESPONSIBILITIES
1. INTRODUCTION. The NNSA PCSP is managed through a multi-tiered structure. The
structure includes a CSPM, DAA, ISOM, ISSM, and an ISSO at NNSA Headquarters
(HQ). ISOM(s), ISSM(s), and ISSO(s) are located at the NNSA Service Centers and
NNSA Site Offices. The ISSMs and ISSOs may also be located at contractor locations.
The structure also includes NNSA Enterprise Systems and Major Application Program
Managers, Certification Agents (CAs), system owners, application owners, data owners,
data stewards, and users of the systems. This chapter describes the roles and
responsibilities of the individuals involved in the NNSA PCSP.
2. RESPONSIBILITIES.
a. Administrator, National Nuclear Security Administration:
(1) Retains ultimate accountability for cyber security and accepts the residual
risk that exists within each of the NNSA Elements through the approval of
the NNSA PCSP.
(2) Appoints the NNSA CSPM, who is the focal point for cyber security
within the NNSA.
b. Associate Administrator for The Chief of Defense Nuclear Security: The
Associate Administrator for the Chief of Defense Nuclear Security is responsible
for the strategic direction and management of the cyber security program.
c. NNSA Chief Information Officer (CIO). The CIO is responsible for the NNSA
CSP and for overseeing security requirements. The CIO’s responsibilities
include:
(1) Ensures that cyber security is integrated into all policies and procedures
used to plan, procure, develop, implement and manage the NNSA
infrastructure and systems.
(2) Ensures that cyber security is integrated into the NNSA Enterprise
Architecture.
(3) Ensures that architectures are consistent with current and planned
computing and communication assets within the NNSA Enterprise.
(4) Recommends a qualified person to the NNSA Administrator to fill the
position of CSPM.
(5) Makes and disseminates to NNSA sites determinations on the INFOCON
for NNSA.
II-2 NAP 14.1-C
05-02-08
d. Cyber Security Program Manager. The CSPM is responsible for managing the
CSP within NNSA. The CSPM is required to spend a minimum of one week at
each NNSA field location.
(1) Serves as the DAA for all classified and unclassified information systems
where perimeter or presence as described in an ISSP is wholly contained
within the NNSA HQ Site and within contractor or subcontractor facilities
under the cognizance of the NNSA HQ Site. The DAA may be delegated
to another individual who must be a Federal employee of the Office of the
NNSA CIO. The DAA’s authority may be assigned to other NNSA
DAAs. All CSPM delegations and assignments by the CSPM must be
documented in the NNSA HQ Site CSPP.
Section 8
(2) Approves the NNSA HQ Site CSPP. The CSPP approval authority may
be delegated to another individual who must be a Federal employee of the
Office of the NNSA CIO Element.
(3) Ensures the appointment of an ISOM responsible for oversight of the
implementation of the NNSA PCSP at the NNSA HQ Site, as well as at
each contractor and subcontractor organization under the cognizance of
NNSA HQ. Note that the ISOM and DAA for the NNSA HQ Site may be
the same individual.
(4) Ensures the appointment of an ISSO for each information system at the
NNSA HQ Site.
(5) Ensures the appointment of an ISSM to be responsible for developing and
implementing the CSPP at the NNSA HQ Site.
(6) Ensures the appointment of an ISSM to be responsible for ensuring the
development and implementation of the CSPP in each contractor and
subcontractor organization under the cognizance of the NNSA HQ Site.
(7) Ensures that the NNSA PCSP is implemented at NNSA HQ Site.
(8) Ensures that all NNSA HQ Site personnel that use information systems
and systems data are aware of and fulfill their duties as described in the
NNSA PCSP.
(9) Approves all NNSA CSPPs from contractors and subcontractors under the
cognizance of NNSA HQ.
(10) Ensures that oversight reviews of all contractor and subcontractor sites
(facilities) under the cognizance of NNSA HQ are conducted in
accordance with the Survey (oversight) program defined in DOE M 470.4-
1. Also ensures that processes and programs allowing access to
NAP 14.1-C II-3
05-02-08
information systems by Foreign Nationals are assessed as part of these
reviews.
(11) Ensures adequate resources are allocated to the HQ Site CSP.
(12) Ensures that the effectiveness of the NNSA HQ Site CSP is monitored
through self-assessments and reviews.
(13) Ensures that the NNSA HQ Site DAAs, ISSMs, ISSOs, users, and System
Administrators are trained in their specific duties, and the technologies for
which they have responsibilities.
(14) Ensures the implementation of the NNSA PCSP throughout NNSA.
(15) Serves as the NNSA primary point of contact (POC) for cyber security.
(16) Represents the NNSA PCSP before Federal, private, and public
organizations concerned with protecting unclassified and classified
Government information.
(17) Serves as the DAA for all NNSA Enterprise information systems or Major
Applications and other information systems or major applications with a
perimeter or presence on different or multiple sites. This DAA authority
may be assigned to other NNSA DAAs. All CSPM delegations and
assignments must be documented. Ensures development and coordination
of corrective actions plans involving NNSA Enterprise systems in
response to issues identified by other Federal agencies (e.g., Office of
Independent Oversight), peer reviews, and self-assessments.
(18) Develops, coordinates, disseminates, and maintains NNSA NAPs and
guidance on all aspects of the NNSA PCSP, including coordination with
telecommunications security, TEMPEST, and Public Key Infrastructure
(PKI) programs.
(19) Annually reviews, and updates, as necessary, the NNSA Threat Statement,
NNSA Cyber Risk Assessment, NNSA PCSP, and any NNSA-approved
minimum information system configuration standards.
(20) Establishes and coordinates NNSA cyber security training, education, and
awareness programs.
(21) Ensures that education in NNSA cyber security policies and practices is
available to NNSA DAAs, ISOMs, ISSMs, ISSOs, Certification Agents
(CAs), and system administrators. Ensures that this training is presented
on a semi-annual basis.
Section 9
II-4 NAP 14.1-C
05-02-08
(22) Maintains an NNSA information assurance response capability. This
capability maintains and coordinates NNSA cyber incident response
procedures to provide timely assistance and system vulnerability
information, watch and warning capabilities, analysis, and assistance
reviews to all NNSA Elements.
(23) Evaluates incident reports for NNSA Computer Network Attack (CNA),
and Computer Network Exploitation (CNE) situations.
(24) Recommends changes in NNSA INFOCON to the NNSA CIO.
(25) Through the most rapid means possible, notifies NNSA Elements, through
the cognizant DAAs, when the NNSA INFOCON is changed.
(26) Provides copies of approved CSPPs to other organizations, as required in
NNSA policies.
(27) Monitors compliance and effectiveness of the PCSP through program
reviews, budget reviews, self-assessments, management assessments,
performance metrics and analysis, analysis of the results of peer reviews,
vulnerability analysis, and independent oversight evaluations.
(28) Coordinates with the Office of HSS, Office of Defense Nuclear Security,
Nuclear Safeguards and Security Program Organization, and Office of
Independent Oversight on monitoring implementation of the PCSP,
through joint review of self-assessment and oversight documentation.
(29) Coordinates with the DOE Office of Intelligence and Counterintelligence
on cyber security matters that affect SCI systems at NNSA facilities.
(30) Identifies NNSA cyber security resource requirements to ensure sufficient
resources are planned and budgeted.
(31) Coordinates with the NNSA Office of Planning, Programming, Budgeting,
and Evaluation and the Chief Financial Officer (CFO) on budgets and
expenditures related to NNSA cyber security.
(32) Manages a cyber security technology development program to support the
NNSA PCSP and to periodically brief NNSA Program Managers, DAAs,
ISOMs, and ISSMs, on activities and results of the program.
(33) Approves secure remote diagnostic and maintenance facilities proposed
for use with information systems that process classified information for
the HQ Element.
NAP 14.1-C II-5
05-02-08
(34) Manages NNSA-wide cyber security incident reporting and response
activities, in coordination with the Office of HSS, DOE Office of
Associate Chief Information Officer (AOCIO) for Cyber Security,
Defense Nuclear Security, the Nuclear Safeguards and Security
organization, Office of Intelligence and Counterintelligence, or Office of
Inspector General (OIG), as circumstances warrant.
(35) Addresses differences and resolves conflicts between the NNSA program
and the DOE-M 470.4-1 program.
(36) Coordinates with the Office of HSS and the DOE Office of Associate CIO
for Cyber Security on cyber security policy and the NNSA PCSP.
(37) Coordinates, as needed, with DOE Office of Intelligence and
Counterintelligence on:
(a) Matters relating to policy and technical planning of
counterintelligence activities.
(b) Counterintelligence investigative activities.
(c) Counterintelligence inspections, including evaluation of the CSP.
(d) Counterintelligence threat information.
(e) Matters related to the cyber threat.
(38) Coordinates, as needed, with the DOE Office of the Inspector General
(IG), on IG investigation activities involving NNSA information systems.
(39) Coordinates, as needed, with the DOE Office of HSS on HSS inspection
activities involving NNSA information systems.
Section 10
(40) Reports changes in ISOM and DAA appointments to all ISOMs and
DAAs.
(41) Supports, maintains, and coordinates an advice and assistance capability
for use by any DAA, ISOM, or ISSM within NNSA. This capability
includes the review of information systems protection measures as
requested by the Element.
(42) Approves NNSA cyber security waivers and exceptions.
(43) Approves minimum security configurations for use in all NNSA Elements.
II-6 NAP 14.1-C
05-02-08
e. Service Center Director:
(1) Assumes responsibility and accountability for the NNSA Service Center
CSP.
(2) Serves as the DAA for all classified and unclassified information systems
whose perimeter or presence as described in an ISSP is wholly contained
(Federal or contractor) under the cognizance of the NNSA Service Center.
The Service Center Director or Manager’s DAA approval authority may
be delegated to another Federal employee of the Service Center, or
through a memorandum of agreement, to NNSA Federal employees at the
NNSA HQ Site or a Site Office.
(3) Appoints in writing an ISOM responsible for oversight of the
implementation of the NNSA PCSP in each NNSA Element (including the
Service Center), under the cognizance of the NNSA Service Center. The
DAA and ISOM responsibilities may be filled by one person.
(4) Appoints in writing an ISSM responsible for oversight of implementation
of the NNSA PCSP in the Service Center and each contractor and
subcontractor organization under the cognizance of the NNSA Service
Center.
(5) Ensures development, implementation, and maintenance of a CSPP for the
Service Center.
(6) Ensures development and implementation of the CSPP at each contractor
and subcontractor site under the cognizance of the Service Center.
(7) Ensures that all Service Center personnel that use information systems and
the information on the systems are aware of and fulfill their duties as
described in the PCSP and the CSSP.
(8) Ensures monitoring of cyber security effectiveness through self-
assessments and reviews.
(9) Ensures that adequate resources hosted within the Service Center are
allocated for the conduct of the Service Center CSP and applicable
Enterprise System Major Applications.
(10) Ensures that Service Center DAAs, ISOMs, ISSMs, ISSOs, users, and
System Administrators are trained in their specific duties and the
technologies for which they have responsibilities.
NAP 14.1-C II-7
05-02-08
f. Site Office Manager:
(1) If the Site Office is not covered in another CSPP, ensures the
development, implementation, and maintenance of a CSPP for the Site
Office.
(2) Assumes responsibility and accountability for the Site Office CSPs.
g. DAA’s Representative
(1) Serves as the DAA for all information systems whose perimeter or
presence as described in an ISSP is wholly contained within an NNSA
Site (Federal or contractor), under the cognizance of the NNSA Site
Office. The Site Office Manager’s DAA approval authority may be
delegated to other employees of the Site Office, or through a
memorandum of agreement, to Federal employees of another Site Office
or the NNSA Service Center. Note that this does not apply to HQ.
(2) Under the cognizance of the NNSA Service Center, appoints in writing an
ISOM responsible for oversight of implementation of the NNSA PCSP in
each NNSA Element. The DAA and ISOM responsibilities may be filled
by separate individuals.
Section 11
(3) Ensures the appointment of an ISSM responsible for developing and
implementing the CSPP in the Site Office, unless the Site Office receives
cyber security services from the Service Center.
(4) Ensures the appointment of an ISSM responsible for developing and
implementing the CSPP in each NNSA Element under their cognizance.
(5) Ensures each information system in the Site Office has an appointed
ISSO.
(6) Ensures that all Site Office personnel that use information systems and
system data are aware of and fulfill their duties.
(7) Approves all NNSA CSPPs from NNSA Elements under the cognizance
of the Site Office Manager.
(8) Ensures that oversight reviews of all sites under the cognizance of the Site
Office Manager are conducted in accordance with the Survey (oversight)
program defined in DOE M 470.4-1. Ensures the process and program
allowing access to information systems by Foreign Nationals is assessed
as part of these reviews.
(9) Under the ISOM’s purview, ensures adequate resources are allocated to
the Site Office CSP and are applicable Enterprise System and Major
Applications.
II-8 NAP 14.1-C
05-02-08
(10) Monitors effectiveness of cyber security through self-assessments and
reviews.
(11) Ensures that Site Office DAAs, ISOMs, ISSMs, ISSOs, users, and System
Administrators are trained in their specific duties and the technologies for
which they have responsibilities.
h. Contractors. Appendix C, Contractor Requirements Document (CRD), describes
the responsibilities of contractors.
i. Designated Approving Authority. The DAA is a Federal employee who has the
authority to grant formal accreditation to operate, withdraw accreditation, suspend
operations, grant IATOs, or grant variances when circumstances warrant. The
approval shall be a written, dated statement of accreditation that sets forth clearly
any conditions or restrictions to system operation. The DAA is the only
individual who may accept all risks for systems under their cognizance. The
DAA can delegate any of the following responsibilities to a DAA Representative
(Rep), except the authority to grant accreditations or IATOs. DAAs are
responsible and accountable for the security of the information and systems that
the DAA accredits. Responsibilities of the DAA include:
(1) Ensures that each system is properly accredited based on a) its
environment and sensitivity levels, and b) a review and approval of
security safeguards and the issuance of written accreditation statements.
(2) Ensures that PCSP implementation within operating units under their
cognizance.
(3) Ensures that documentation is maintained for all information system
accreditations under their purview.
(4) Ensures that all appropriate roles and responsibilities are accomplished as
required for each information system.
(5) Ensures that operational information system security policies are
promulgated for each system, project, program, and site for which the
DAA has approval authority.
(6) Should the DAA choose to accredit a system that does not have all
security requirements implemented due to fiscal or operational restraints,
the DAA may choose to accredit the system in accordance with interim
approval criteria as stated in NAP 14.2-C, NNSA C&A Process, or accept
any additional risk and issue a full approval to operate for the system.
(7) Recommends approval for waivers and exceptions and forwarding such
information to the CSPM as appropriate.
NAP 14.1-C II-9
05-02-08
Section 12
(8) The DAA will ensure when a security patch cannot be applied. He or she
must approve the Deviations Process and provide a copy to HQ.
(9) Disseminates INFOCON status changes received from the CSPM.
(10) Approves P2P applications during the C&A process.
(11) Approves alternatives to tamper indicating devices for portable mobile
devices.
(12) Approves all products or software used to perform clearing, sanitization,
or destruction of storage media.
(13) Completes NNSA-sponsored DAA training within three (3) months of
assuming the DAA position. The ISOM-designated Field DAA’s
Representative must attend a two-week assignment at NNSA HQ.
(14) Participates in an ongoing NNSA cyber security training and awareness
program.
(15) Ensures that Security Testing and Evaluation (ST&E) procedures are
completed and documented.
(16) Maintains appropriate system accreditation documentation.
(17) Evaluates threats and vulnerabilities to ascertain whether additional
safeguards are needed.
(18) Ensures that all risks not mitigated are documented for DAA acceptance,
and the Plans of Actions and Milestones (POA&M) are created, if
applicable.
(19) Ensures that a record of all security-related vulnerabilities and incidents is
maintained.
(20) Ensures that certification is accomplished for each NNSA information
system, network, and application under their responsibility.
(21) Evaluates certification documentation as required during C&A activities.
(22) Ensures that all ISSMs and ISSOs receive technical and security education
and training to carry out their duties.
(23) Assesses changes in a system, its environment, and operational needs that
could affect the accreditation.
(24) Oversees and reviews periodically system security to accommodate
possible changes that may have taken place.
II-10 NAP 14.1-C
05-02-08
(25) Approves incident reporting procedures developed by the ISSM.
(26) Determines the Levels of Concern (LOC) for confidentiality, integrity, and
availability for the data on a system.
(27) Ensures consideration and acknowledgement of counterintelligence
activities during the C&A process.
(28) Approves system disposal plans and procedures.
j. Information System Security Officer Manager (ISOM). The ISOM is a Federal
employee responsible for ensuring that operational security is maintained for
information systems under the DAA’s cognizance throughout the life cycle of the
systems. The ISOM is also responsible for coordinating security-related incident
communications between the site, the Information Assurance Response Center
(IARC), and NNSA HQ. The ISOM must have a working knowledge of system
functions, cyber security policies, and cyber security protection measures. If an
ISOM is not appointed, the DAA assumes the ISOM responsibilities, which may
be delegated to a DAA Rep. Responsibilities of the ISOM include:
(1) Evaluates security plans and ensures systems are operated, maintained,
and disposed of in accordance with internal security policies and practices
outlined in the ISSP.
(2) Reports all security-related incidents to the IARC and DAA.
(3) Initiates protective or corrective measures when a security incident or
vulnerability is discovered.
(4) Provides monthly incident status reports to the DAA and IARC.
(5) Follows procedures approved by the DAA for authorizing software,
hardware, and firmware use before implementation on the system.
(6) Conducts periodic reviews to ensure compliance with the CSPP and
ISSPs.
Section 13
k. Information Systems Security Site Manager (ISSM). The ISSM is a Federal
employee appointed by the NNSA Element manager to be responsible for
development of the Element’s CSPP and implementation of the Element’s CSP.
The ISSM must have a working knowledge of system functions, cyber security
policies, and cyber security protection measures. Any of the following duties
may be delegated to an Alternate or Assistant ISSM.
(1) Maintains record copies of the Element’s CSPP and ensures that the
record copy of each ISSP is maintained for systems under their
cognizance.
NAP 14.1-C II-11
05-02-08
(2) Ensures appointments in writing of ISSOs for information systems
operated by the NNSA Element and ensures that each ISSO and System
Administrator is aware of and fulfills their cyber security duties as
described in the PCSP and the Element’s CSPP. ISSOs are responsible to
the ISSM for fulfilling their duties.
(3) Ensures the development, documentation, and presentation of information
systems security education, awareness, and training activities for Element
management, cyber security personnel, application owners, data stewards,
and users.
(4) Ensures that users are trained on the information system cyber security
features, operation, and safeguards prior to being allowed access to the
system.
(5) Ensures that training is available for ISSOs and System Administrators for
information systems, cyber security requirements, operations, safeguards,
Information Condition (INFOCON), and incident handling procedures.
(6) Establishes, documents, and monitors the Element’s CSP implementation
and ensures Element compliance with the NNSA PCSP. Upon completion
of each assessment or review, the ISSM must ensure that a corrective
action plan (CAP) is prepared and implemented for all findings or
vulnerabilities.
(7) Identifies and documents, in coordination with the organization’s
Operations Security (OPSEC) program and Counterintelligence programs,
Element-specific threats to information systems, and information at the
site.
(8) Develops and documents additional or modified protection measures for
those threats and identifies any site-wide protection measures and
practices that apply to all site systems.
(9) Obtains approvals for modified protection measures from the DAA.
(10) Ensures that the CSPP is coordinated with other site plans and programs to
include: Disaster Recovery; Site Safeguards and Security Plan (SSSP) or
Site Security Plan; Classified Matter Protection and Control; Physical
Security; Personnel Security; Telecommunications Security; TEMPEST;
Technical Surveillance Countermeasures; Operations Security; and
Nuclear Materials Control and Accountability.
(11) Ensures development of procedures to implement the Element’s CSP on
all information systems.
II-12 NAP 14.1-C
05-02-08
(12) If appointed as the CA, certifies to the cognizant DAA that the protection
requirements described in the C&A Package for each information system
have been implemented and are operational.
(13) Ensures that the cognizant DAA is notified when the information system
is no longer needed, or when changes occur that might affect the
accreditation of the information system.
(14) Participates in CSPM-sponsored cyber security training within three (3)
months of their appointment.
(15) Ensures development, documentation, and presentation of cyber security
training for escorts in information systems operational areas.
Section 14
(16) Ensures that a DAA-approved overwrite method is used for clearing and
sanitization, and that a review has been completed of the results of
overwrites to verify that the method used completely overwrote all
classified or sensitive information.
(17) Ensures that each information system user acknowledges, in writing or
electronically, their responsibility (Code of Conduct) for the security of
information systems and information.
(18) Communicates individual incident reports to the ISOM to allow the DAA
to meet their reporting schedule.
(19) Ensures examination and documentation of suspected cyber security
incidents, categorization of incidents as Type 1, Type 2, or No Incident,
and retention of documentation.
(20) Ensures analyses of and corrective actions for incidents and findings with
status reporting to the DAA.
(21) Conducts self-assessments in accordance with the NNSA PCSP.
(22) Ensures that each individual responsible for major applications within the
NNSA Element is aware of and fulfills their cyber security duties, as
described in the PCSP and the Element’s CSPP.
(23) Recommends changes in the NNSA Element INFOCON status to the
DAA.
l. Information System Owner. The information system owner (ISO) is the person or
Element responsible for acquiring, operating, or upgrading an information system.
The ISO coordinates all aspects of the system for which they are responsible,
from initial concept, through development, to implementation and system
maintenance. The ISO is also responsible for identifying all information on the
NAP 14.1-C II-13
05-02-08
system and is involved with FIPS – level determinations. The information system
owner:
(1) Ensures the preparation of the ISSP and the system C&A package.
(2) Ensures the C&A of all information systems under their cognizance.
(3) Ensures implementation of protection measures documented in the ISSP
for each information system for which they are the ISSO.
(4) Ensures that privileged users are granted access to information system
resources based on the least privilege principle.
(5) Identifies, in coordination with the ISSM, and documents in the ISSP,
unique threats to information systems for which they are responsible.
(6) Ensures that the CoL of confidentiality, integrity, and availability for the
information is determined prior to use of an information system during the
C&A process.
(7) Notifies the ISSM of any changes to the CoL of confidentiality, integrity,
and availability for the system.
(8) Documents any special protection requirements identified by the
application owner, data owner, or data steward and ensures that these
requirements are included within the protection measures implemented in
the information system.
(9) For each information system for which they serve as the ISSO, ensures the
information system is covered by an ISSP.
(10) Maintains a copy of the ISSP for each information system for which they
are the ISSO.
(11) Ensures that all information system security-related documentation is
current and accessible to properly authorized individuals.
(12) Ensures the implementation of procedures as defined in the Element CSPP
and the ISSP for each information system for which they are the ISSO.
(13) Ensures that system recovery processes are monitored to ensure that
security features and procedures are properly restored.
(14) Ensures that the cognizant ISSM is notified when an information system is
no longer needed or when changes occur that might affect the
accreditation of the information system.
Section 15
II-14 NAP 14.1-C
05-02-08
(15) Ensures that information access controls and cyber protection measures
are implemented for each information system as described by its ISSP.
(16) Ensures that users and Systems Administrators are properly trained in
information system security by identifying cyber security training needs
and the personnel who need to attend the cyber security training program.
(17) Conducts cyber security reviews and tests to ensure that cyber security
features and controls are functioning and effective.
(18) Participates in the ISSM’s self-assessment and training programs.
(19) Ensures that risk assessment is completed for information systems for
which they are responsible.
(20) Communicates individual incident reports to the ISSM to allow the ISSM
to meet their reporting schedule.
(21) Ensures the implementation of all applicable protection measures for each
information system for which they are responsible.
(22) Ensures that unauthorized personnel are not granted use of, or access to,
the information system.
(23) Report immediately all security incidents and potential vulnerabilities
involving the information to the appropriate ISSM.
m. Information System Security Officer (ISSO). The following roles and
responsibilities apply to all information systems for which the ISSO is
responsible. The ISSP may be a privileged user. Multiple information systems
may be assigned to a single ISSO.
(1) Ensures implementation of protection measures documented in the ISSP
for each information system for which they are the ISSO.
(2) Ensures that privileged users are granted access to information system
resources based on the least privilege principle.
(3) Identifies, in coordination with the ISSM, and documents in the ISSP,
unique threats to information systems for which they are responsible.
(4) Ensures that the CoL of confidentiality, integrity, and availability for the
information is determined prior to use of an information system during the
C&A process.
(5) Notifies the ISSM of any changes to the CoL of confidentiality, integrity,
and availability for the system.
NAP 14.1-C II-15
05-02-08
(6) Documents any special protection requirements identified by the
application owner, data owner, or data steward and ensures that these
requirements are included within the protection measures implemented in
the information system.
(7) Ensures each information system for which they are the ISSO is covered
by an ISSP.
(8) Maintains a copy of the ISSP for each information system for which they
are the ISSO.
(9) Ensures that all information system security-related documentation is
current and accessible to properly authorized individuals.
(10) Ensures the implementation of procedures as defined in the Element CSPP
and the ISSP for each information system for which they are the ISSO.
(11) Ensures that system recovery processes are monitored to ensure that
security features and procedures are properly restored.
(12) Ensures that the cognizant ISSM is notified when an information system is
no longer needed, or when the changes occur that might affect the
accreditation of the information system.
(13) Ensures that information access controls and cyber protection measures
are implemented for each information system as described by its ISSP.
(14) Ensures that users and Systems Administrators are properly trained in
information system security by identifying cyber security training needs
and the personnel who need to attend the cyber security training program.
Section 16
(15) Conducts cyber security reviews and tests to ensure that cyber security
features and controls are functioning and effective.
(16) Participates in the ISSM’s self-assessment and training programs.
(17) Ensures that risk assessment is completed for information systems for
which they are responsible.
(18) Communicates individual incident reports to the ISSM to allow the ISSM
to meet their reporting schedule.
(19) Ensures the implementation of all applicable protection measures for each
information system for which they are responsible.
(20) Ensures that unauthorized personnel are not granted use of, or access to,
the information system.
II-16 NAP 14.1-C
05-02-08
(21) Report immediately all security incidents and potential vulnerabilities
involving the information to the appropriate ISSM.
n. Enterprise System and Major Application Manager. The following items apply
only to the Enterprise System and Major Application:
(1) Ensures adequate resources are allocated for cyber security of the system
or application.
(2) Monitors the effectiveness of cyber security through self-assessments and
reviews.
(3) Ensures the development and maintenance of the Enterprise ISSP and the
system certification and accreditation package.
(4) Coordinates the ISSP with the involved NNSA Element managers.
(5) Coordinates the ISSP with the Element’s ISSM.
(6) Ensures the NNSA Elements’ ISSM, ISSO, users, and System
Administrators involved with the Enterprise System and Major
Application are trained in their specific duties and responsibilities with
respect to the Enterprise System and Major Application.
(7) Ensures that the record copy of the Enterprise System and Major
Application ISSP is maintained.
(8) Ensures the distribution, as needed, of the Enterprise System and Major
Application ISSP to other NNSA Elements.
o. Application Owners and Data Stewards. These roles and responsibilities apply to
all information systems.
(1) Determine and declares the sensitivity of the information prior to the
information being created, processed, stored, transferred, or accessed on
the information system.
(2) Identify unique threats to their information and ensure that this
information is forwarded to the ISSO and ISSM.
(3) Advise the ISSO of any special confidentiality, integrity, or availability
protection requirements for the information.
(4) Ensure that the information is processed only on a system that is approved
at a level appropriate to protect the information.
NAP 14.1-C II-17
05-02-08
(5) Determine and document the data and application(s) essential to fulfill the
organizational mission, and ensure that requirements for contingencies are
determined, implemented, and tested.
(6) Approve access to their information.
(7) Ensure applications and/or data supporting Critical Infrastructure or Key
Resources are identified.
(8) Provide resources to support implementation and testing of contingency
plans for the application data.
(9) Provide resources to support Business Continuity for the application data.
p. Users. The roles and responsibilities apply to all cyber assets.
(1) Comply with the requirements of the NNSA PCSP, the NNSA Element’s
CSPP, and the information system ISSP.
(2) Be aware of, and knowledgeable about, their responsibilities in regard to
information systems security.
Section 17
(3) Ensure that any authentication mechanisms, including passwords, issued
for the control of their access to information and information systems, are
not shared and are protected at the same level of protection applied to the
information to which it permits access, and report any compromise or
suspected compromise of an authenticator to the appropriate ISSO. Note
that this approach would not apply for RSA tokens.
(4) Be responsible and accountable for their actions on an information system.
(5) Acknowledge, via electronic signature or in writing, their responsibilities
(Code of Conduct) for protecting information systems and classified
information.
(6) Participate in training on the information system's prescribed security
restrictions and safeguards before initial access to a system. Additionally,
participate in an ongoing security education, training, and awareness
program.
(7) Immediately report all security incidents and potential threats and
vulnerabilities involving the information system to the appropriate
personnel.
(8) Ensure that system media and system output are properly classified,
marked, controlled, and stored.
II-18 NAP 14.1-C
05-02-08
(9) Protect terminals from unauthorized access, as described in the
information system ISSP.
(10) Inform the ISSO when access to a particular information system is no
longer required, for example, completion of a project, transfer, retirement,
or resignation.
(11) Observe rules and regulations governing the secure operation and
authorized use of information systems.
(12) Use the information system only for official government business or other
activities authorized by NNSA or the NNSA Element manager.
(13) Receive electronic or written permission from the DAA before any
attempt to bypass or test security mechanisms.
q. Privileged Users and System Administrators.
(1) All privileged users must be responsible for all requirements stated for
general users.
(2) Privileged users are responsible to ensure that user access to the
information system’s resources and information is based on the least
privilege principle.
(3) All privileged users must:
(a) Be U.S. citizens, unless otherwise approved in accordance with the
approved NNSA Element ISPP or in writing by the cognizant
DAA. Foreign Nationals are explicitly prohibited from being
privileged users on classified systems
(b) Possess approvals of Need-to-Know for all information on the
system.
(c) Possess an Access Authorization sufficient for access to the
highest classification and most restrictive category of data
processed on the information system.
(d) Use unique identifiers as described in the information system
ISSP.
(e) Protect the root or super-user authenticator at the highest level of
data it secures.
(f) Be responsible for all super-user or root actions under their
account.
NAP 14.1-C II-19
05-02-08
(g) Report any and all security relevant information system problems
to the ISSO.
(h) Use the special access or privileges granted only to perform
authorized tasks and functions.
r. Certification Agent (CA)/Certifier. The Certification Agent, or Certifier, is
designated to perform security certification. The ISSM may fulfill the role of the
CA. General duties of the Certifier include:
(1) Ensures that risk assessments and security evaluations are completed prior
to information system, network, and application certification.
Section 18
(2) Certifies the extent to which systems, networks and applications meet
prescribed security requirements.
(3) Prepares the certification report and, upon the completion of certification,
forwards the report to the DAA through the CA, if the ISSM is not the
CA, with their recommendation on accreditation.
(4) Ensures Corrective Action Plans (CAPs) are prepared.
(5) Maintains and provides other records and reports of certification activities,
as necessary.
(6) Reviews all information contained in the ISSP.
(7) Conducts a comprehensive evaluation of the technical and non-technical
security features of an information system and other safeguards made in
support of the accreditation process to establish the extent to which a
particular design and implementation meets a set of specified security
requirements.
(8) Submits recommendations on C&A package to the DAA.
II-20 NAP 14.1-C
05-02-08
This page left intentionally blank.
NAP 14.1-C III-1
05-02-08
CHAPTER III. CONFIGURATION MANAGEMENT
1. INTRODUCTION. Configuration Management (CM) applies administration, technical
direction, and surveillance to identify and document functional and physical
characteristics of a configuration item, to control changes, record and report change
processing and implementation, and to verify compliance with specified requirements.
Configuration management implements measures to ensure that protection features
specified in NNSA-approved minimum information system security configurations are
implemented in the system and maintained in the instantiation of system components by
applying a level of discipline and control to the process of system maintenance and
modification. The minimum set of security controls for unclassified and classified
information systems, as determined by the system categorization, is detailed in NAP
14.2-C, Chapter III, NNSA Certification and Accreditation (C&A) Process.
2. REQUIREMENTS. The NNSA Element must implement the following NNSA CM
processes for all information systems within the Element.
a. Design documentation and any acquisition specifications that must identify the
minimum security configuration for the information system, or applicable
components of the information system requiring security configurations when
being purchased.
If it is necessary to develop alternative minimum security configurations due to
operational or mission requirements, the new configuration must be selected
from recognized sources of checklist-producing organizations, including NIST1,
the National Security Agency (NSA)2, the DISA Security Technical
Implementation Guides (STIGs), and the Center for Internet Security (CIS)
benchmarks3. Such alternative configurations must be approved by the cognizant
DAA.
b. The Element’s CM procedures for maintaining documentation, tracking changes,
approving configuration changes, and implementing vulnerability and patch
management shall be described in the Element CSPP.
c. The minimum set of security controls identified for an information system must
be described in CM documentation which includes ISSPs, Contingency Plans,
ST&E Procedures, user and administrative guidance, and system component
inventories.
1
1 The NIST checklist repository is located at http://checklists.nist.gov/ .
2 The NSA’s checklists are available at http://www.nsa.gov/ia/.
3 CIS’s site is http://www.cisecurity.org/.
III-2 NAP 14.1-C
05-02-08
Section 19
d. The Element’s CM procedures, monitoring capability to continuously detect and
manage software changes, roles and responsibilities, and configuration
identifiers shall be documented in a Configuration Management Plan(s) (CMP).
The CMP shall describe the methodology and procedures used for configuration
controls to include at a minimum, the following:
(1) Identification of the roles and responsibilities for change approval or
disapproval.
(2) Information system and configuration item unique identification and
labeling.
(3) Configuration change identification, tracking, control, and history.
(4) Configuration auditing and status accounting.
(5) Vulnerability and patch management.
(6) Security configuration checklist for operating system software, application
software, and hardware platforms.
(7) Documentation of the methodology and tools used to monitor
configuration changes.
e. Documentation of Minimum Security Configurations requires implementation of
the minimum set of security controls is addressed, as required by the system’s
security categorization. These controls are listed in NAP 14.2-C, NNSA
Certification and Accreditation (C&A) Process.
f. Organizations using Microsoft Windows XP and plan to upgrade to Vista must
adopt the security configurations developed by the National Institute of Standards
and Technology (NIST), the Department of Defense (DOD) and the Department
of Homeland Security (DHS).
g. If it is necessary to develop alternative minimum security configurations due
operational or mission requirements, the new configuration must be selected from
recognized sources of checklist-producing organizations, including NIST4, the
National Security Agency (NSA)5, the DISA Security Technical Implementation
Guides (STIGs), and the Center for Internet Security (CIS) benchmarks6. Such
alternative configurations must be approved by the cognizant DAA.
2
4 The NIST checklist repository is located at http://checklists.nist.gov/ .
5 The NSA’s checklists are available at http://www.nsa.gov/ia/.
6 CIS’s site is http://www.cisecurity.org/.
NAP 14.1-C IV-1
05-02-08
CHAPTER IV. CYBER SECURITY PROGRAM PLAN
1. INTRODUCTION. The NNSA CSPP is the document that outlines the policies,
procedures, and practices of an organization's (e.g., an NNSA site) CSP—classified and
unclassified. The CSPP is a top-level, stand-alone program document at the management
level and details the organization's policies, procedures, and practices for ensuring
effective cyber security. It also explains the organization's specific environment,
missions, and threats. The CSPP will be integrated with other program plans in the
Element, such as Site Safeguards and Security Plan (SSSP), and the Information
Resource Management (IRM) plans.
2. CSPP CONTENTS. The CSPP must describe how the organization implements the
NNSA PCSP. The CSPP must explain the organization’s specific environment, missions,
and threats and describe the policies, procedures, and practices for ensuring effective
cyber security. If the following requirements can be met with existing organization
policies or procedures, they should be summarized and referenced in the CSPP and a
copy attached to the CSPP.
a. Environment. Describe the site’s mission, objectives, and security environment.
b. Information Types and Groups. Identify the Information Types and/or Groups.
See Chapter V for a description of the Information Types and/or Groups handled
by the site.
Section 20
c. Site Unique Threats. Reference or document any threat or threat assessments
used as the basis for its threat environment, such as the NNSA Threat
Assessment, OPSEC Threat Assessments, and Site Unique Threats.
d. Roles and Responsibilities. Define the cyber security roles and responsibilities
for the site, such as the ISSM, ISSO, system administrator, Certification Agent,
and general user. Cyber security training requirements for all participants are
provided in CNSSD-500 Information Assurance (IA) Education, Training, and
Awareness - dated August 2006; and NSTISSD-501 National Training Program
for Information Systems Security (INFOSEC) Professionals - dated 16 November
1992.
e. Program and Project Controls and Accountability. Describe the method for
tracking the site's implementation of the NNSA PCSP in terms of cost and
schedule.
f. Plan of Actions and Milestones (POA&M). Describe the site’s process for
tracking system-level weaknesses to include corrective action plans to track the
completion of milestones.
http://www.cnss.gov/Assets/pdf/CNSSD_500.pdf
http://www.cnss.gov/Assets/pdf/nstissd_501.pdf
IV-2 NAP 14.1-C
05-02-08
g. Information Systems. Reference an inventory of information systems: accredited,
in the accreditation process, and not accredited.
h. C&A Program. Describe the site’s information system C&A process to include
processes for additional instantiations of accredited systems. Include (ISSP)
format requirements.
i. Equipment and Software Management.
(1) Configuration Management.
(a) Describe the site’s CM policies and procedures.
(b) Identify any NNSA-approved minimum information system
security configurations implemented in the Element’s information
systems.
(c) Describe the site’s process for identifying and managing
information system configurations that cannot apply NNSA-
approved minimum information system security configurations due
to operational or mission requirements.
(d) Describe the site’s process for planning, documenting, and
managing system interconnections to include:
i. Purpose and baseline configuration of the interconnection.
ii. Methods used to meet the security requirements of
interconnected systems and/or adjudicate security
implementation differences between the systems.
iii. Processes for mutual configuration management, change
notification, maintenance, incident response, and operation
of the interconnection.
iv. Process for governing the creation, maintenance, and
approval of Interconnection Agreements.
(2) Equipment Maintenance. Describe the maintenance policies and
procedures, including the introduction of vendor maintenance hardware,
software and firmware, and the management of remote maintenance
activities.
(3) Sanitization – Clearing, Purging, and Destruction. Describe the Element’s
management, operational, technical, and assurance controls for
sanitization.
NAP 14.1-C IV-3
05-02-08
Provide the DAA-approved process for the following:
(a) Clearing, purging, and destroying information system storage
media, memory devices, and other related hardware components.
(b) Reuse of information storage media, memory devices, and other
related hardware components at a lower classification or sensitivity
level.
j. Decommissioning. Describe the procedures for decommissioning information
systems.
k. Incident Handling. Describe the composition of the site incident response team,
contact methods, such as telephone numbers, pagers, cell phones, e-mail, and
incident handling and reporting procedures.
Section 21
l. Information Condition. Describe the process for establishing, changing, and
reporting the site's INFOCON status. Describe the site's response measures for
each INFOCON level. Describe the incident warning and advisory response
process for the site.
m. Security Monitoring. Describe the site’s security monitoring policies, processes,
and procedures, including how monitoring is used to mitigate risks to the site.
Describe the site’s processes and procedures for detecting and managing intrusion
detection at the desktop, network, and site levels.
n. Security Coordination. Describe the site’s process and procedures to ensure
coordination with other security programs, such as physical security; personnel
security; Technical Surveillance Countermeasures (TSCM); TEMPEST;
Classified Matter Protection and Control (CMPC); Protected Transmission
System (PTS); Operations Security (OPSEC); and Computer Security
(COMSEC).
o. Malicious Code. Describe the site’s process and procedures to address malicious
code incidents (e.g., incidents handled at the boundary, at desktops, and at
selected locations), the mechanisms employed, and frequency of updating anti-
malicious code software throughout the site.
p. Denial of Service and/or Continuity of Service. Describe the business impact
analysis (BIA) process for identifying those information systems and networks
that have a low tolerance for disruption or unavailability (system criticality), and
the procedures and mechanisms that will be employed to limit and recover from
such disruption or unavailability.
IV-4 NAP 14.1-C
05-02-08
q. Internet Security. Describe the site’s Internet use policy, method of securing the
site’s network from external threats via the Internet connection, policies and
procedures for reviews of Web page and server content, as well as Web page and
server monitoring policy.
r. E-mail. Describe the site’s e-mail policy, including controls for the use of offsite
e-mail.
s. Component and Output Marking and Labeling. Describe the site’s policy for
marking and labeling the sensitivity or classification levels of computers,
computer equipment, media storage devices, and computer output.
t. Clear Text Password Management. Describe the site’s program for the
elimination of clear text passwords from existing and future information systems.
u. Data Backup and Restoration. Describe the site’s policies for data backup and
restoration.
v. Disaster Recovery Program. Describe the site's disaster recovery program,
including integration of information systems, Continuity of Service plans, and the
procedures for regular testing of continuity of operations and contingency plans.
w. Output and Display Device Access. Describe the site's policies for controlling
access to system output and display devices.
x. Portable Hardware and Software Technical Reviews. Describe the process for
performing technical reviews of the hardware and software components of
portable computers that are taken or used outside the U.S. or may have been
under the control of a non-U.S. Government organization.
y. Portable Computing Devices. Describe the policies and procedures for managing
the use of portable computing devices in all areas of the site.
z. External Information Systems. Describe the policies and procedures for
managing the use of external information systems in all areas of the site.
Section 22
aa. Wireless Information Systems. Describe the policies and procedures for
managing installation and use of Radio Frequency (RF) and Infrared (IR) systems
in all areas of the site.
ab. Risk Management. Describe the site's process for risk management for all
information systems and information system components.
ac. Remote Access. Describe management, operational, technical, and assurance
controls for remote access.
NAP 14.1-C IV-5
05-02-08
ad. Training. Describe the process for cyber security training and awareness
programs, including who must receive training and how frequently re-training
will occur. Describe the methodology being used for training, such as briefings
or e-mail. Identify those positions requiring training, and identify by title or
position those responsible for overseeing training activities at the site.
ae. Performance Assessment. Describe the site’s process and metrics employed to
assess compliance with the CSPP and the process for evolving these metrics.
Describe the site's peer review and self-assessment processes, including frequency
of reviews, the process for selecting peer review members, qualifications required
of the prospective individuals or entities, and who is responsible for selecting peer
review participants.
af. Plan Change Management. Describe the update frequency for the CSPP and the
process for updating the plan.
ag. Downloading Unclassified Files from an Unclassified System. Describe the
procedure for downloading unclassified data from classified system.
IV-6 NAP 14.1-C
05-02-08
This page intentionally left blank.
NAP 14.1-C V-1
05-02-08
CHAPTER V. INFORMATION GROUPS
1. INTRODUCTION. Unclassified Information and National Security Information Groups
contain all information that requires similar protection or is similar in content or use. The
following have been defined for use in assessing the cyber threats to information, and for
use in defining the minimum protection criteria.
a. Unclassified Information Types.
(1) Open, Public, and Unrestricted Access. Information that requires no
protection from disclosure, such as information approved for public
release.
(2) Unclassified Protected. Unclassified information that has been determined
by the data owner or data steward to require additional protection due to
its sensitive subject matter or impact to Departmental or organizational
missions.
(3) Unclassified Mandatory Protection and SUI. Information requiring
additional protections as mandated by policy or laws, such as the
following:
(a) Privacy Act information.
(b) Agreements between DOE, NNSA, its contractors, and other
entities, such as commercial organizations or foreign governments,
i.e., Cooperative Research and Development Agreement
(CRADA).
(c) Proprietary information (but not third party proprietary).
(d) Unclassified Controlled Nuclear Information (UCNI).
(e) Export-controlled information (ECI).
(f) Naval Nuclear Propulsion Information (NNPI).
(g) Military and dual use information, such as the Critical Military
Technology and Materials list identified by the Department of
Defense (DOD).
(h) Nonproliferation information.
(i) Official Use Only.
(j) Personally Identifiable Information (PII) – Refer to Chapter XVII
for a complete definition of PII.
V-2 NAP 14.1-C
05-02-08
b. National Security Systems Information Groups.
Section 23
(1) Confidential or Secret Non-Nuclear Weapons. Information classified
Confidential National Security Information, Confidential Restricted Data,
Confidential Formerly Restricted Data, Secret National Security
Information, or Secret Formerly Restricted Data and does not contain any
nuclear weapons data but may contain information related to uranium
enrichment.
(2) Secret Restricted Non-Nuclear Weapons Data. Information classified
Secret Restricted Data and does not contain any nuclear weapons data, but
it may contain information related to uranium enrichment or other Secret
Restricted Data.
(3) Confidential Restricted Data Sigmas 1 through 13, and 15, and 20.
Information classified as Confidential and identified as Restricted Data,
Formerly Restricted Data, or is related to nuclear weapons. This
information is further marked with at least one of the sigma categories 1
through 13.
(a) Sigmas 1 and 2. Theory of operation or complete design of
hydrodynamic, nuclear, fission weapons or their unique
components. This includes the high explosive system with its
detonators and firing unit, pit system, and nuclear initiation system
as they pertain to weapon design and theory.
(b) Sigmas 3, 4, 5, 9, 10, 11, 12, and 13, 15 and 20. Manufacturing
and utilization information not comprehensively revealing the
theory of operation or design of the physics package; information
inherent in pre-shot and post-shot activities necessary in the testing
of atomic weapons or devices; production rate and/or stockpile
quantities of nuclear weapons and their components; general
studies not directly related to the design or performance of specific
weapons or weapons systems such as reliability studies, fusing
studies, damage studies, aerodynamic studies; chemistry
metallurgy, and processing of materials peculiar to the field of
atomic weapons or nuclear explosive devices; Information
concerning inertial confinement fusion that reveals or is indicative
of weapon data; Theory of operation or complete design of the
nuclear energy converter, energy director, or other nuclear directed
energy weapon outside the radiation case of the nuclear source but
within the envelope of the nuclear directed energy weapon
concept; and manufacturing and utilization information for nuclear
energy converters, directors, or other nuclear directed energy
weapon outside the nuclear source radiation case, not
comprehensively revealing the theory of operation or design of the
nuclear directed energy weapon concept.
NAP 14.1-C V-3
05-02-08
(4) Secret Restricted Data Sigmas 1 through 13.. Information classified as
Secret and identified as Restricted Data and related to nuclear weapons.
This information is further marked with at least one of the Sigma
categories 1 through 13, 15, and 20.
(a) Sigmas 1 and 2. Theory of operation or complete design of
hydrodynamic, nuclear, fission weapons or their unique
components. This includes the high explosive system with its
detonators and firing unit, pit system, and nuclear initiation system
as they pertain to weapon design and theory.
Section 24
(b) Sigmas 3, 4, 5, 9, 10, 11, 12, and 13. Manufacturing and
utilization information not comprehensively revealing the theory of
operation or design of the physics package; information inherent in
pre-shot and post-shot activities necessary in the testing of atomic
weapons or devices; production rate and/or stockpile quantities of
nuclear weapons and their components; general studies not directly
related to the design or performance of specific weapons or
weapons systems – reliability studies, fusing studies, damage
studies, and aerodynamic studies; chemistry and metallurgy, and
processing of materials peculiar to the field of atomic weapons or
nuclear explosive devices; information concerning inertial
confinement fusion that reveals or is indicative of weapon data;
theory of operation or complete design of the nuclear energy
converter, energy director, or other nuclear directed energy
weapon outside the radiation case of the nuclear source but within
the envelope of the nuclear directed energy weapon concept; and
manufacturing and utilization information for nuclear energy
converters, directors, or other nuclear directed energy weapon
outside the nuclear source radiation case, not comprehensively
revealing the theory of operation or design of the nuclear directed
energy weapon concept.
(c) Sigma 15. The category of sensitive information concerning
design and function of nuclear weapons use control systems,
features, and their components. This includes use control
information for passive and active systems.
(d) Sigma 20. The category of nuclear weapon data that pertains to
sensitive improvised nuclear device information.
(5) Secret Restricted Data Sigma 14. Information that is classified as Secret
and identified as Restricted Data or is related to nuclear weapons. Sigma
14 is the category of sensitive information concerning the vulnerability of
nuclear weapons to deliberate unauthorized nuclear detonation.
V-4 NAP 14.1-C
05-02-08
(6) Top Secret. Information classified Top Secret NSI, Top Secret FRD, or
Top Secret Restricted Data that does not pertain to Nuclear Weapons.
(7) Top Secret Restricted Data. Nuclear Weapon information classified Top
Secret.
(8) Special Information Groups. These Information Groups contain
Confidential or Secret Restricted Data (or other National Security data)
that the US Government, DOE, or NNSA have determined that special or
additional protection is necessary.
NAP 14.1-C VI-1
05-02-08
CHAPTER VI. NNSA CYBER SECURITY PROGRAM DEVIATIONS
1. INTRODUCTION. This chapter describes the types of deviations, such as variances,
waivers, and exceptions, required justifications, and the process for obtaining deviations
from the NNSA PCSP requirements.
2. CRITERIA AND PROCESSES. All approved deviations, as described below, must be
documented in the ISSP for the information system, the SSSP, or the Site Security Plan,
as appropriate.
a. Variances. Variances are approved conditions that technically vary from a NNSA
PCSP requirement but afford equivalent levels of protection.
(1) Variance requests must be submitted in writing to the DAA. The variance
request must include a detailed description of the requirement(s) and
rationale. The variance documentation must be referenced in the ISSP.
(2) The cognizant DAA will review and approve in writing, or the cognizant
DAA will disapprove with comments and recommendations.
Section 25
(3) Variances may be approved for up to three (3) years and documented in
the ISSP, but they must be submitted for reconsideration whenever the
information system is accredited or re-accredited.
b. Waivers. Waivers are approved, non-standard conditions that deviate from a
NNSA PCSP requirement, which, if uncompensated, would create a potential or
real cyber security vulnerability. Waivers require implementation of
compensatory measures that will be in effect for the duration of the waiver.
(1) Waiver requests and supporting documentation must be submitted in
writing to the cognizant DAA for review.
(2) Documentation supporting the waiver request must identify the
requirement(s) to be waived, indicate the compensatory measures
implemented, and, if appropriate, indicate that performance testing has
been completed to validate the compensatory measures.
(3) The DAA will forward the waiver request and documented
recommendation for approval to the NNSA CSPM.
(4) The NNSA CSPM will approve or disapprove the waiver request and
provide a final decision in writing to the cognizant DAA.
(5) The cognizant DAA will notify the ISSM.
VI-2 NAP 14.1-C
05-02-08
(6) Approved waivers may remain in effect for up to the expiration of the
C&A, which may be less than two years to a maximum of three years.
Approved waivers must be referenced in the ISSP. If an extension is
necessary, the waiver request must be re-submitted.
c. Exceptions. Exceptions are approved deviations from an NNSA PCSP
requirement that creates a security vulnerability. Exceptions shall only be
approved when correction of the condition is not feasible or cost effective and
compensatory measures are inadequate to preclude the acceptance of risk by the
cognizant DAA.
(1) Requests for exceptions and supporting documentation must be submitted
in writing to the cognizant DAA for review.
(2) Documentation supporting the exception request must identify the
requirement(s) that cannot be met, indicate any compensatory measures
implemented, and, if appropriate, indicate that performance testing has
been completed to validate the compensatory measures.
(3) The DAA will forward the exception request and documented
recommendation for approval to the NNSA CSPM.
(4) Exceptions must be documented in the ISSP.
(5) The NNSA CSPM, or higher authority, will approve or disapprove the
exception request and provide a final decision in writing to the cognizant
DAA.
(6) The cognizant DAA will notify the ISSM.
(7) Approved exceptions may remain in effect for one year.
(8) The cognizant DAA must review and validate the need for each exception.
NAP 14.1-C VII-1
05-02-08
CHAPTER VII. INCIDENT MANAGEMENT
1. INTRODUCTION. This chapter establishes the minimum criteria and processes for
reporting and responding to cyber security incidents involving NNSA information
systems.
2. REPORTING CRITERIA AND PROCESSES.
a. Reportable Cyber Security Incidents. The site’s CSPP must document the
processes for reporting cyber security incidents that are IMI-1 and IMI-2. Cyber
security-related incidents must be coordinated with Safeguards and Security. In
addition, cyber security-related incidents must be reported that meet one or more
of the following criteria:
(1) Incidents of Security Concern. Report the cyber security aspects of the
following Incidents of Security Concern involving National Security
Systems, as adapted from DOE M 470.4-1, Safeguards and Security
Program Planning and Management.
Section 26
(a) Impact Measurement Index (IMI-1). Report incidents that pose an
immediate danger or short-term threat to National Security
interests and/or critical NNSA or DOE assets, that potentially
create a serious security situation, or that create high media
visibility interest. The following cyber security incidents must be
reported according to the procedures in this NAP, in addition to the
reporting requirements in DOE M 470.4-1. These incidents must
be reported within one working hour of discovery.
(i) Confirmed or suspected loss, theft, diversion, or
unauthorized release of Weapon Data contained in an
information system or on cyber media.
(ii) Confirmed or suspected loss, theft, diversion, unauthorized
release of TOP SECRET information or Special Access
Program (SAP) information contained in an information
system or on cyber media.
(iii) Confirmed or suspected intrusions, hacking, or break-ins
into NNSA information systems containing TOP SECRET
or SAP information.
(b) Impact Measurement Index (IMI-2). Report incidents that pose a
near- or long-term threat to National Security interests and/or
critical NNSA or DOE assets, or incidents that potentially create a
crisis or dangerous situation. The following cyber security
incidents must be reported according to the procedures in this
VII-2 NAP 14.1-C
05-02-08
NAP, in addition to any other reporting. These incidents must be
reported within eight working hours of discovery.
(i) Confirmed or suspected intrusions, hacks, or break-ins into
NNSA information systems or cyber media, containing
Confidential Non-Nuclear Weapons Information or Secret
Restricted Data Information.
(ii) Confirmed or suspected intrusions, hacking, or break-ins
into NNSA information systems or cyber media containing
Confidential Non-Nuclear Weapons Information or Secret
Restricted Data Information.
(iii) Loss of classified information that must be reported to
other Government agencies or foreign associates.
(iv) The loss of any DOE classified information involving
NNSA information systems or cyber media, which requires
State or local government or other Federal agency
notification.
(c) Impact Measurement Index (IMI-3). Report incidents that pose
long-term threats to NNSA or DOE security interests, or incidents
that could potentially degrade the overall effectiveness of the
NNSA or the Department's protection programs. The following
cyber security incidents must be reported according to the
procedures in this NAP, in addition to any other reporting. These
incidents must be reported within eight working hours of
discovery.
(i) Confirmed or suspected unauthorized disclosure, loss or
potential loss of CONFIDENTIAL matter via intrusions,
hacking, or break-ins into NNSA information systems or
cyber media.
(ii) Confirmed or suspected unauthorized disclosure,
loss/potential loss of Unclassified Mandatory Protection
Information via intrusions, hacking, or break-ins into
NNSA information systems or loss/potential loss of cyber
media.
Table VII-1 on the following page provides the incident reporting
requirements for Incidents of Security based on the IMI.
NAP 14.1-C VII-3
05-02-08
Table VII-1. Required Time Frame for Reporting Incidents of Security
Concern Based on Impact Measurement Index
IMI Designation Time Frame
IMI-1 Within 1 working hour of discovery
IMI-2 Within 8 working hours of discovery
IMI-3 Within 8 working hours of discovery
Section 27
(2) Incidents of NNSA Cyber Security Concern. These incidents must be
reported based on the Type and System Impact Category, as defined
below. Incidents may be, but are not limited to, the result of cyber
security alerts received and investigated by the site.
(a) Type 1 incidents are successful incidents that potentially create
serious breaches of DOE and/or NNSA cyber security, or have the
potential to generate negative media interest. The following are
the currently defined Type 1 incidents.
(i) Compromise or Intrusion. All unintentional or intentional
instances of system compromise or intrusion by
unauthorized persons must be reported, including user-
level compromises, root (administrator) compromises, and
instances in which users exceed privilege levels.
(ii) Web Site Defacement. All instances of a defaced Web site
must be reported.
(iii) Malicious Code. All instances of successful large network
site-wide infection, or persistent attempts at infection by
malicious code, such as viruses, Trojan horses, or worms,
must be reported.
(iv) Denial of Service. Intentional or unintentional denial of
service (successful or persistent attempts) that affects or
threatens to affect a critical service, or that denies access to
all or one or more large portions of a network, must be
reported.
(v) Critical Infrastructure Protection (CIP). Any activity that
adversely affects an asset identified as critical
infrastructure must be reported. NNSA CIP assets are
determined by the NNSA Administrator.
(vi) Unauthorized Use. Unauthorized use should be construed
as any activity that adversely affects an information
system’s normal, baseline performance and/or is not
recognized as being related to NNSA’s mission. For
VII-4 NAP 14.1-C
05-02-08
example, unauthorized use can be using a DOE or NNSA
computer to obtain Government data without authorization.
Unauthorized use can involve using systems to break the
law. Unauthorized use includes, but is not limited to, port
scanning that excessively degrades performance. Note that
these activities may only be performed when authorized by
the DAA: IP (Internet protocol) spoofing; network
reconnaissance; monitoring; hacking into servers; running
traffic-generating applications that generate unnecessary
network broadcast storms or drive large amounts of traffic
to computers; or using illegal (or misusing copyrighted)
software images, applications, data, and music.
(b) Type 2 incidents are attempted incidents that pose potential long-
term threats to DOE and/or NNSA cyber security interests, or that
may degrade the overall effectiveness of the Department’s cyber
security posture. The following are the currently defined Type 2
incidents.
(i) Attempted Intrusion. A significant and/or persistent
attempted intrusion that stands out above the daily activity
or noise level, as determined by the system owner, and that
would result in unauthorized access (compromise) if the
system were not protected.
(ii) Reconnaissance Activity. Persistent surveillance and
resource mapping probes and scans that stand out above the
daily activity or noise level and represent activity that is
designed to collect information about vulnerabilities in a
network and map network resources and available services.
Section 28
b. System Impact Categories. System impact categories characterize the potential
impact of incidents that compromise DOE or NNSA information and information
systems. Such incidents may impact DOE or NNSA operations, assets,
individuals, missions, or reputations. System impact categories identify the level
of sensitivity and criticality of information and information systems by assessing
the impact of the LOC, integrity, and availability. Performing this impact
analysis is a fundamental step in risk assessment. Each of the security objectives,
such as confidentiality, integrity, and availability, is assessed according to
categories in Table VII-2 on the following page.
(1) Low Impact. Loss of system confidentiality, integrity, and availability
could be expected to have a limited adverse effect on DOE or NNSA
operations, assets, or individuals, requiring minor corrective actions or
repairs.
NAP 14.1-C VII-5
05-02-08
(2) Moderate Impact. Loss of system confidentiality, integrity, and
availability could be expected to have a serious adverse effect on DOE or
NNSA operations, assets, or individuals, including significant degradation
or major damage, requiring extensive corrective actions or repairs.
(3) High impact. Loss of system confidentiality, integrity, and availability
could be expected to have a severe or catastrophic adverse effect on DOE
and NNSA operations, assets, or individuals. The incident could cause the
loss of mission capability for a period that poses a threat to human life or
results in the loss of major assets.
Table V11-2. Required Time Frame for Reporting Cyber Security Incidents
to the Information Assurance Response Center (IARC)
System Impact Category
Incident Type Low Moderate High
Type 1 Within 4 hours Within 1 hour Within 1 hour
Type 2 Within 1 week Within 24 hours Within 24 hours
Personally
Identifiable
Information (PII)*
Within 35 minutes Within 35 minutes Within 35 minutes
* Based on mandated reporting requirements for PII, all suspected or confirmed incidents involving PII
must be reported within 35 minutes regardless of the Type or System Impact. See definition and examples
in Appendix XVIII for further clarification.
Figure VII-1 illustrates the process for reporting NNSA cyber security incidents. For
PII, see Figures VII-2 and VII-3.
VII-6 NAP 14.1-C
05-02-08
Figure VII-1. NNSA Cyber Security Incident Reporting Process
NAP 14.1-C VII-7
05-02-08
Figure VII-2. NNSA PII Cyber Security Incident Reporting Process
VII-8 NAP 14.1-C
05-02-08
Figure VII-3. NNSA PII Management – Lost or Stolen Data Process Flow
c. The cognizant ISOM must be notified within 24 hours of discovery of an incident
by the NNSA site. Monthly reports on the status of incident resolution, whether
or not any reportable, successful, or attempted incidents have occurred during the
month, must also be transmitted to the ISOM.
d. Cyber Security Incident Report Content. The content and format of an incident
report will be specified by the IARC. At a minimum, incident reports must
include date(s), time(s), type, source, corrective actions taken, if any, resources
affected, site impact, and site point-of-contact. Sources may vary depending on
the type of attack, but may include Internet Protocol (IP) address, e-mail address,
or other identifying source characteristics. Additional content may be specified
by the DAA and/or IARC, as incident situations change.
Section 29
e. Incidents Involving PII. All suspected or confirmed cyber security incidents
involving PII as defined in Appendix B, Definitions, must be reported to the
NAP 14.1-C VII-9
05-02-08
IARC within 35 minutes of discovery. Discovery is defined as the moment that
the CSSM or their staff have determined that a reported incident could involve
PII. This notification can be verbal or written via e-mail. As additional
information is discovered pertaining to the incident, the impacted site must
provide IARC with the updated information within 35 minutes. Note that if a
primary impacted site has solicited the assistance of another secondary site during
the investigation, the primary site has the responsibility for reporting all
information to the IARC.
f. Archiving Cyber Security Incident Information. Sites must store all information
related to a reportable incident, as defined in paragraph 2.a of this chapter for at
least one year. Storage methods, including custody, must comply with applicable
evidentiary requirements for possible future law enforcement use.
g. Counterintelligence Reporting. Events identified in DOE O 475.1,
Counterintelligence Program, must be reported by the IARC to the Office of
Intelligence and Counterintelligence (OICI), in accordance with the reporting
procedures in DOE O 475.1.
h. Automated Systems. Automated systems may be used to implement these
protocols.
3. CIAC CYBER SECURITY ALERTS. Cyber security alerts issued by CIAC shall be
investigated, analyzed, and reported as an incident. Positive feedback from the sites is
required in response to an alert, and the incident reporting mechanism provides the
necessary information.
VII-10 NAP 14.1-C
05-02-08
This page intentionally left blank.
NAP 14.1-C VIII-1
05-02-08
CHAPTER VIII. INFORMATION CONDITION (INFOCON)
1. INTRODUCTION. This chapter describes the minimum preparations and actions
required to react uniformly to warnings of cyber security incidents, heighten or reduce the
cyber defensive posture, defend against computer network attacks, and mitigate sustained
damage to NNSA information and infrastructure, including computer and
telecommunications networks and systems. The INFOCON is a comprehensive defense
posture and response based on the status of information systems, NNSA operations, and
intelligence assessments of adversary capabilities and intent. The INFOCON system
impacts all personnel who use NNSA information systems, protects systems while
supporting mission accomplishment, and coordinates the overall defensive effort through
adherence to standards.
The INFOCON system presents a structured, coordinated approach to react to adversarial
attacks on NNSA information, computer systems, and networks and systems. While all
systems are vulnerable to some degree, factors such as low-cost, readily available
information technology, increased system connectivity, and remote access capability make
Computer Network Attack (CNA) an attractive option to an adversary. CNA is defined as
“operations to disrupt, deny, degrade, or destroy information resident in computers and
computer networks, or the computers and networks themselves.” INFOCON also outlines
countermeasures to scanning, probing, and other suspicious activity, unauthorized access,
and data browsing. NNSA INFOCON measures focus on computer network-based
protective measures due to the unique nature of CNA. Each level reflects a defensive
posture based on the risk to NNSA operations through the disruption of information
systems and networks.
Section 30
2. CRITERIA AND PROCESSES.
a. Each NNSA site's INFOCON response measure must be documented in the site’s
CSPP.
b. INFOCON procedures must be well integrated with the site’s Security Condition
(SECON) procedures, emergency procedures, Continuity of Operations plans, and
incident handling processes.
c. Cyber security incidents must be reported as described in Chapter VII.
d. DAAs may evaluate their situation and recommend changes in the INFOCON to
the NNSA Site Manager for sites under their cognizance; however, the INFOCON
must remain at least at high as the current INFOCON directed by NNSA. If the
NNSA Site Manager agrees to the recommended change in INFOCON status, the
DAA must report the change to the CSPM within 4 hours.
e. The CSPM will notify DAA when the NNSA INFOCON is changed, through the
most rapid means available, and must notify the CSPM if recommended or
directed INFOCON response measures conflict with organization or mission
priorities within 2 hours of NNSA determination of INFOCON response measures.
f. The DAA must disseminate INFOCON information within their organization and
VIII-2 NAP 14.1-C
05-02-08
to organizations under their cognizance, through the most rapid means available.
3. NNSA INFOCON. Several critical assumptions were made about the nature of CNA and
Computer Network Exploit (CNE) in developing the NNSA INFOCON system.
Understanding these assumptions is essential to effective implementation of this system.
a. Shared Risk. In today’s network-centric environment, risk assumed by one NNSA
site is risk shared by all. Unlike most other security activities, a successful
network intrusion in one NNSA location may, in many cases, facilitate access at
other locations. This necessitates a common understanding of the situation and
responses associated with the declared NNSA INFOCON. These actions must be
carried out concurrently at all NNSA locations for an effective defense.
b. Advance Preparation. Preparation is key, given the speed and reduced signature of
CNA and CNE. Protective measures must be planned, prepared, exercised, and
often executed well in advance of an attack. Preventive measures are emphasized
in INFOCON responses because there may be little time to react effectively during
the attack. Prevention of system compromise is preferable but may not be
achievable.
c. Anonymity of Attacker. Attributing the attack to its ultimate source, if possible,
will normally not occur until after the attack has been executed. This limits the
range and type of options available to INFOCON decision makers. To effectively
operate in this environment, knowledge of the adversary’s identity cannot be a
prerequisite to execution of defensive strategies and tactics.
d. Characterization of the Attack. Distinguishing between hacks, attacks, system
anomalies, and operator error may be difficult. The most prudent approach is to
assume malicious intent until an event is assessed otherwise. See Chapter VII for
various assessments to consider.
e. INFOCON Levels. The NNSA INFOCON system presents a structured,
coordinated approach to defend against and react to adversarial attacks on NNSA
information, computer systems, and telecommunication networks and systems.
The NNSA INFOCON system identifies the five levels of CNA and CNE
conditions within NNSA, as shown in Table VIII-1.
Table VIII-1. INFOCON Levels
NAP 14.1-C VIII-3
05-02-08
INFOCON
Level Description
RED
(Critical)
Section 31
Successful information system attack(s) detected that impact NNSA operations such as a
Type 1 compromise and/or intrusion or DOS, with a moderate or high impact.
Widespread incidents that undermine ability to function effectively.
Significant risk of mission failure.
Computer Network Attack against national infrastructure or National Security element.
YELLOW
(Elevated)
Indications and warnings (I&W) indicate targeting of specific system, location, unit, or
operation.
Significant level of network probes, scans, or activities detected, indicating a pattern of
concentrated reconnaissance.
Network penetration or DOS attempted with no impact to NNSA or DOE operations, such
as Type 2 attempted intrusion with a low impact.
Incident occurs at NNSA site that affects an NNSA Enterprise System, or it may impact
another NNSA site, such as a Type 1 compromise and/or intrusion with a low impact.
Intelligence indicates imminent attack against NNSA or DOE site.
BLUE
(Guarded)
I&W indicate general threat.
Regional events occurring that affect U.S .interests and are likely to affect NNSA interests.
May involve potential adversaries with suspected or known CNA capability.
Information system probes, scans, or other activities detected indicating a pattern of
surveillance, such as Type 2 reconnaissance activity with a moderate or high impact.
Nation-or Internet-wide computer network exploits, such as a Type 1 Web site
defacement, malicious code, or denial of service (DOS), with an impact of low.
Increased and/or more predictable threat events.
Incident occurs at NNSA or DOE site.
GREEN
(Normal)
No significant activity.
Normal operations.
Network penetration or denial of service attempted with no impact to NNSA,
DOE, or site operations such as Type 2 reconnaissance activity or intrusion
attempts with a low impact.
Minimal attack success, successfully counteracted, such as a Type 1 unauthorized use
with a low impact.
General threat unpredictable.
4. INFOCON ACTIVITIES.
VIII-4 NAP 14.1-C
05-02-08
a. Determining the INFOCON. There are three broad categories of factors that
influence the INFOCON: operational, technical, and intelligence, including
foreign intelligence and law enforcement intelligence. Some factors may fall into
more than one category. The INFOCON level is based on significant changes in
one or more of them. Appendix C describes several factors that may be considered
when determining the INFOCON. The decision to change the INFOCON should
be tempered by the overall operational and security context at that time. For
example, an intruder could gain unauthorized access and not cause damage to
systems or data. This may only warrant INFOCON BLUE or GREEN during
peacetime, but it may warrant INFOCON ORANGE during a crisis. Also, the
incident may warrant a high INFOCON at the affected site but not throughout the
NNSA as a whole.
b. Declaring INFOCONs. The NNSA CSPM will recommend changes in NNSA
INFOCON to the NNSA CIO, who is responsible for declaring an NNSA
INFOCON. Assimilation and evaluation of information to assess the CNA and
CNE situation NNSA-wide will be a collaborative effort coordinated by the
CSPM.
c. Managers of NNSA sites are responsible for assessing the situation and
establishing the proper INFOCON, based on evaluation of all relevant factors. See
Appendix D and E for criteria and guidance, respectively. NNSA site managers
may change the INFOCON of their organizations or site(s); however, they must
remain at least as high as the current INFOCON directed by NNSA. Managers
changing the INFOCON of their organization or site(s) must report to the CSPM
using the same reporting format described in paragraph 4.d of this chapter.
Section 32
d. Response Measures. Ideally, CNA/CNE operations will be based on advanced
warning of an attack. Measures should be commensurate with the risk, the
adversary’s assessed capability and intent, and mission requirements. Over-
aggressive countermeasures may result in self-inflicted degradation of system
performance and communication ability, which may contribute to the adversary’s
objectives. Managers must also consider what impact of imposing a higher
INFOCON for their organization will have on connectivity with computer
networks and systems of other NNSA sites and operations. Managers will notify
the CSPM, through the cognizant ISOM, if recommended or directed response
measures conflict with organization or mission priorities. Regardless of the
INFOCON level declared at the affected site, it is incumbent upon the affected site
to report all unauthorized accesses in a timely manner, in accordance with the
NNSA PCSP. Each NNSA site shall have documented procedures to guide their
responses and ensure these procedures are well integrated with other site SECON,
emergency procedures, and Continuity of Operations plans. See Appendix D and
E for recommended action activities.
NAP 14.1-C VIII-5
05-02-08
e. Reporting. Reporting of cyber security incidents must be accomplished as
described in Chapter VII. Note, however, that INFOCONs assess potential and/or
actual impact to NNSA operations and must be reported as follows:
(1) Reporting Channels. NNSA sites must report INFOCON changes to the
NNSA CSPM and the cognizant DAA.
(2) Reporting Frequency. NNSA sites must report INFOCON changes for
their sites no later than 4 working hours after the INFOCON has changed.
Provide whatever information is available at the time and indicate
information that is unknown or unavailable. Information missing from the
initial report will be forwarded in a follow-up report within 24 hours of the
initial report.
(3) Report Formats. Reports of changes in INFOCON should be accompanied
by an operational assessment of the situation, when appropriate. Appendix
E outlines a process for assessing the operational impact of a CNA. Report
contents shall include, as a minimum:
(a) For all INFOCONs: Organization and location, date and time of
report, current INFOCON, reason for declaration of this INFOCON,
response actions taken, and POC name and contact information.
(b) INFOCON YELLOW and Higher. All of the above, plus U. S.
Computer Emergency Response Team (CERT) or NNSA IARC
Number (IARC will report to CIAC) and Law Enforcement Agency
(LEA) case number, with POC name and contact information, when
available.
(c) INFOCON ORANGE and Higher: All of the above, plus system(s)
affected; degree to which operational functions are affected; impact
(actual and/or potential) on current and planned missions; and/or
general capabilities; restoration priorities; and workarounds.
f. Dissemination of NNSA INFOCON. The CSPM will notify the DAA when the
NNSA INFOCON is changed, through the most rapid means available. The DAA
sites must notify the CSPM, if recommended or directed INFOCON response
measures conflict with organizational or mission priorities, within two (2) hours of
NNSA determination of INFOCON response measures. NNSA sites are
responsible for rapid dissemination of the INFOCON information within their
organization, and to contractor organizations under their cognizance. Notification
will include the following information:
(1) Date and time of report.
Section 33
(2) Current INFOCON.
VIII-6 NAP 14.1-C
05-02-08
(3) Reason for declaration of this INFOCON that includes a detailed
description of the causal activities and Type and System-Impact Category.
(4) Current and planned operation(s) or capabilities, units and/or organizations,
networks, systems, applications, or data assessed to be impacted or at risk.
(5) Recommended or NNSA-directed actions.
(6) References to relevant technical advisories and intelligence assessments
(7) POC information.
(8) Information that may assist sites in their response times. See Appendices
D and E.
5. RELATIONSHIP OF INFOCON TO OTHER ALERT SYSTEMS. The INFOCON and
SECON may complement each other. The INFOCON may be changed based on the
national or global situation, the intelligence community’s level of concern, or other
factors. Likewise, a change in INFOCON may prompt a corresponding change in other
alert systems.
EXERCISES. INFOCON procedures shall be practiced at all NNSA sites as part of their self-
assessment program to include operational impact assessments. See Appendix
D and E..
NAP 14.1-C IX-1
05-02-08
CHAPTER IX. PLAN OF ACTIONS AND MILESTONES.
1. INTRODUCTION. This chapter documents the minimum requirements for establishing
a management tracking tool for the documentation and correction of security program
and system-level findings and incidents. The primary intent of the Plan of Action and
Milestones (POA&M) is to assist NNSA management with tracking and mitigating
program weaknesses. Additionally, the POA&M assists external regulatory agencies
with oversight responsibilities.
A finding is a determined vulnerability pertaining to technology, operations, and/or
people that allow compromise to an organization’s information or associated information
systems. Findings are identified through various activities, such as risk management, self
assessment, audits, and ST&E processes.
All NNSA Elements must develop, document, and implement POA&M policies and
procedures consistent with the following requirements and commensurate with the level
of security required for the organization’s environment and specific needs.
This chapter is compliant with DOE TMR-6, Plan of Action and Milestones.
2. CRITERIA AND PROCESSES.
a. POA&M Content Requirements. Each NNSA Element must define a site-specific
POA&M process in their respective CSPPs. The Element’s POA&M
documentation must include the following information, at a minimum:
(1) Reporting all program and system-level findings identified by the Office
of HSS, the General Accounting Office (GAO), the Office of Inspector
General (OIG), and other outside external regulatory agencies. Findings
or incidents identified by internal assessment activities, security reviews,
or operations are tracked by the POA&M at the determination of the
DAA.
(2) Tracking program and system-level findings with open Corrective Action
Plans (CAPs).
(3) Validating and associated documentation of closure for each POA&M
finding.
(4) Integration of the POA&M process with the internal self-assessment
program.
(5) Identification of the office or organization responsible for tracking and
reporting of POA&M information to the NNSA OCIO, on at least a
quarterly basis.
IX-2 NAP 14.1-C
05-02-08
(6) Process used to assess POA&M activities on at least a quarterly basis.
Section 34
(7) Once the POA&M has been reported, changes are allowed to be made to
the original description of the finding, key milestones, schedule
completion dates, or source under the direction of the DAA. Notations for
any modifications to the original entry are to be made separately, and
identified as “Changes to Milestones.”
(8) POA&M Reports are to be marked and protected as appropriate; at a
minimum, reports are to be considered Official Use Only (OUO).
b. Corrective Action Plans. Not all identified findings tracked in the POA&M will
have corresponding CAPs. Note, however, that all findings will have associated
mitigation milestones tracked within the POA&M. Each NNSA Element must
document CAPs at a minimum for any cyber security-related finding identified by
the Office of Inspector General and the Office of HSS. If the finding has not been
closed within a year of its determination, the NNSA CSPM or cognizant DAA
may require that other program or system-level findings be documented in the
CAP, based on its impact.
c. CAP Content. For documented cyber-security-related findings, and for program
and/or system-level weaknesses that require corrective action plans, CAP must
contain, at a minimum, the following content:
(1) A brief overview and summary of the identified weakness, vulnerability,
or finding.
(2) Root cause analysis, addressing any systemic program weaknesses.
(3) Mitigation and resolution and recurrence prevention strategies.
(4) Office or organization responsible for remediation.
(5) Resource requirements and expected costs associated with remediation.
For system-level POA&Ms, the unique project identifier and project name
from the OMB Exhibit 300 or Exhibit 53, where applicable; and for
Exhibit 53 systems, the security costs must also be included.
(6) Scheduled start and completion date.
(7) At least one major milestone and estimated completion date.
NAP 14.1-C IX-3
05-02-08
d. CAP Requirements. In addition to documenting the CAP, as outlined above, the
responsible office or organization must also complete the following activities for
each CAP.
(1) Risk assessment and acceptance, approval, and communication to
impacted organizations and personnel.
(2) Track and update implementation status for each CAP milestone, as
directed by the cognizant DAA.
(3) Verify and document the closure of each CAP milestone.
(4) Coordinate the independent validation of milestone completions as
directed by the cognizant DAA.
e. POA&M Reports. In accordance with FISMA requirements, NNSA Elements (to
include the NNSA HQ Element, must develop, implement, and manage POA&Ms
for all cyber security weaknesses and vulnerabilities requiring corrective action,
whether or not a CAP has been prepared. POA&M Reports must contain, at a
minimum, the following content:
(1) A brief overview and summary of the identified weakness, vulnerability,
or finding.
(2) Office or organization responsible for remediation.
(3) Scheduled start and completion date.
(4) At least one major milestone and completion date.
(5) Reported closure of findings and milestones, as validated by someone
other than the individual responsible for documenting and tracking the
milestones. The POA&M must include the following:
(a) Date of closure.
(b) Finding or milestone closure validated? (Yes or No).
(c) Name, position, and title of validating individual.
(d) Date of validation.
f. POA&M Assessment Requirements.
IX-4 NAP 14.1-C
05-02-08
Section 35
(1) POA&M-related activities must be tracked, reviewed, and prioritized on at
least a quarterly basis. Reviews must include verification that all
applicable findings are being tracked and managed.
(2) An assessment of POA&M activities must be conducted when there are
changes in organizational roles responsible for POA&M activities; when
new Departmental guidance is issued; and/or new findings are identified
via an audit, internal review, or self-assessment.
g. Minimum POA&M Reporting Requirements.
(1) POA&M Reports must include program-and system-level findings
identified by the Office of HSS, the GAO, the OIG, and other outside
external regulatory agencies, as well as any findings and/or weaknesses
identified by internal assessment activities or security reviews.
(2) POA&M Reports must include required documentation needed for each
system-level finding, such as self-assessments, risk assessments, security
plans, certification and accreditation, and contingency plans.
(3) POA&M Reports must include closed findings and milestones for up to
one year after formal and validated closure.
(4) NNSA Elements required to report remediation progress on findings and
milestones as required by the cognizant DAA, but they are not to report
less frequently than quarterly as required by the Office of Management
and Budget (OMB).
NAP 14.1-C X-1
05-02-08
CHAPTER X. VULNERABILITY MANAGEMENT
1. INTRODUCTION. This chapter establishes the minimum requirements for developing a
vulnerability management program, including patch management, for NNSA information
systems. Vulnerability management is a measurable, proactive process implemented to
secure information systems and to improve regulatory compliance posture. Patch
management is one method for addressing vulnerabilities. Note that, because not all
vulnerabilities have applicable patches, it is essential that security controls, such as
remediations, be implemented based on an analysis of possible vulnerabilities associated
with an information system. In addition, such controls help to mitigate the impact of a
successful exploitation of an unknown vulnerability. This chapter applies to all NNSA
Elements that operate and manage information systems that collect, create, process,
transmit, store, and/or disseminate unclassified and classified NNSA information.
2. CRITERIA AND PROCESSES.
a. Cyber Security Program Plan. Each NNSA Element must address the following
vulnerability management program Elements in its site CSPP.
(1) Vulnerability management activities, including processes for analyzing,
detecting, communicating, and remediating vulnerabilities, as well as
interfaces to incident management and configuration processes.
(2) The roles and responsibilities of all key personnel responsible for
decisions and activities regarding vulnerability management.
(3) Awareness, training, and education requirements for all key personnel
responsible for vulnerability management activities.
b. Vulnerability Management Program. Each NNSA Element must implement a
vulnerability management program that addresses at a minimum the following
requirements:
(1) Identification, analysis, and dissemination of vulnerability information.
(2) An inventory of information technology resources, including hardware,
operating systems, and software applications, used in the organization.
(3) Remediation strategies and processes.
(4) Prioritization of vulnerability remediation or mitigations.
Section 36
(5) A standardized vulnerability naming scheme.
(6) Vulnerability documentation to include POA&M Reports and incident
management, as required.
X-2 NAP 14.1-C
05-02-08
(7) Metrics for testing the effectiveness of the vulnerability management
program.
(8) Communication and coordination processes, including internal and
external reporting of vulnerabilities and remediation.
(9) A process for identifying, documenting, and communicating lessons-
learned regarding vulnerability scanning processes and remediation.
(10) Risk-based standards establishing scan frequency, techniques, and
technologies.
(11) A documented vulnerability scanning process that includes the following
at a minimum.
(a) Organizational element(s) responsible for conducting vulnerability
scanning activities.
(b) Frequency of scanning activities; critical assets and servers must
be scanned quarterly.
(c) Identification and prioritization of scanning targets.
(d) Alternate examination methodologies for resources for which
operations and production cannot be interrupted.
(e) Identification of resources that cannot be scanned from a central
network location.
c. Patch Management Process. Each NNSA operating unit must implement a patch
management process that includes at a minimum the following requirements:
(1) Patch prioritization based on criticality of system, network, and
specialized tooling.
(2) Testing procedures for patch installation.
(3) Procedures for automated and manual patch deployment.
(4) Identification of those resources that cannot be patched from a central
network location.
(5) Patch installation verification processes and methods.
(6) Documentation of residual risk acceptance and integration with CM
processes.
(7) Scheduling to ensure that all assets are scanned twice annually, and
critical assets and servers are scanned quarterly.
NAP 14.1-C XI-1
05-02-08
CHAPTER XI. PORTABLE COMPUTING DEVICES
RESERVED – THIS CHAPTER WILL BE DEVELOPED AT A LATER DATE.
XI-2 NAP 14.1-C
05-02-08
This page intentionally left blank.
.
NAP 14.1-C XII-1
05-02-08
CHAPTER XII. PASSWORD GENERATION, PROTECTION, AND USE
1. INTRODUCTION. This chapter establishes minimum criteria and processes for the
generation, protection, and use of passwords to support authentication when accessing
classified and unclassified NNSA information systems, applications, and resources. This
chapter applies to any multi-user information system at a NNSA site that collects, stores,
transmits, or processes unclassified or classified information, and uses passwords to
authenticate users or applications.
2. CRITERIA AND PROCESSES.
a. Password Generation and Verification. Password generation or verification
software must ensure that passwords are generated using the following features:
(1) Passwords contain at least eight non-blank characters.
(2) Passwords contain a combination of letters, preferably a mixture of upper
and lowercase numbers, and at least one special character within the first
seven positions, provided such passwords are allowed by the operating
system or application.
(3) Passwords used on information systems that collect, store, transmit, or
process classified information must be machine generated, or use DAA-
approved alternative methods of authenticating users or generating
passwords.
(4) Passwords employed by a user on unclassified information systems must
be different than passwords employed by the same user on classified
information systems.
Section 37
(5) Two-factor authentication should be required for all privileged users,
accounts, and actions.
b. Password Protection.
(1) Passwords used to access information systems processing classified data
must be protected at a level commensurate with the classification level and
most restrictive category of the information to which they allow access.
(2) Passwords used to access information systems processing unclassified
data must be protected in accordance with the information with the highest
impact level for confidentiality or integrity on the system to which they
allow access.
XII-2 NAP 14.1-C
05-02-08
(3) Passwords must not:
(a) Contain the User Account Identifier (User ID).
(b) Contain any common English dictionary word, spelled forward or
backwards; dictionaries for other languages may also be used if
justified by risk and cost benefit analysis, as documented in the
approved ISSP or the CSPP.
(c) Employ common names, including the name of any fictional
character or place, spelled forward or backwards.
(d) Contain any commonly used numbers, such as the employee serial
number, Social Security number, birth date, or telephone number
associated with the user of the password.
(e) Contain any simple pattern of letters or numbers, such as
“qwertyxx” or “xyz123xx.”
(4) In cases of user-created passwords on unclassified information systems,
ensure through verification software and training that selected passwords
are consistent with password requirements listed in paragraphs 2a. and b.
above.
(5) When an information system cannot prevent a password from being
echoed, as in a half-duplex connection, an overprint mask must be printed
before the password is entered to conceal the typed password.
(6) Individuals must not:
(a) Share passwords except in emergency circumstances or when there
is an overriding operational necessity, as described in the
information system's approved ISSP or the site’s CSPP.
(b) Enable applications to retain passwords for subsequent reuse,
except as described in the information system's approved ISSP.
(c) Create their passwords if the password is used for access to
classified information.
(d) Use group passwords, such as a single password used by a group
of users, without some other mechanism that can assure
accountability, such as separate and unique network User ID.
NAP 14.1-C XII-3
05-02-08
(e) Share group passwords outside the group of authorized users.
Group passwords must be changed when any individual in the
group is no longer authorized to access the information system
where the group password is used. Group passwords must never
be reused.
c. Standard Passwords. User software, including operating systems and other
security-relevant software, may be supplied with standard identifiers, such as
System, Test, and Master, and passwords already enrolled in the system.
Passwords for all standard identifiers must be changed before allowing the
general user population access to the information system. These passwords must
be changed after a new system version is installed or after other action is taken
that might result in restoration of these standard passwords.
d. Password Changing. Passwords must be changed:
(1) At least every 6 months.
(2) Immediately, but within one business day, after a password has been
shared, compromised, or after the user suspects that a password has been
compromised.
(3) On direction from management or the DAA.
Section 38
e. Administration. The information system, application, or resource where
passwords are used for user authentication must, where technically feasible,
ensure:
(1) Five consecutive failed attempts to provide a legitimate password for an
access request results in an access lockout. The process for restoration of
an account must be documented or referenced in the approved ISSP.
(2) The user password, whether user-selected or automatically generated, is
rejected if the password does not meet the criteria in this chapter.
(3) Before expiration or lockout will occur, individuals are notified that their
passwords are about to expire and must be changed.
(4) Any file, folder, database, or other collection of one or more user
passwords is protected from access by unauthorized individuals.
(5) Periodic monthly or quarterly validation of conformance to password
policy, as directed by site policy.
f. Clear Text Passwords. The use of clear text passwords must be eliminated from
all information systems, applications, and resources.
XII-4 NAP 14.1-C
05-02-08
(1) Each NNSA Element’s CSPP shall include a plan, with schedules and
milestones, to eliminate the use of clear text, reusable passwords from
existing electronic information systems and resources.
(2) Each NNSA Element shall develop procedures to ensure that clear text,
reusable passwords are removed from new information systems,
applications, and resources before the systems, applications, or resources
are placed into production use.
(3) Other mitigation strategies must be in place and must automatically result
in a POA&M.
g. Pass-phrase and Entropy-based Passwords. In situations where Pass phrases or
entropy-based passwords are used, password generation or verification software
must ensure that such passwords meet the following criteria.
h. Pass phrases must contain 25 or more characters and at least 2 special characters,
and must not begin or end with a special character.
i. Password generation based on an entropy approach must comply with the
guidance for a Level 1 Authentication Mechanism as described in NIST SP 800-
63, Electronic Authentication Guideline: Recommendations of the National
Institute of Standards and Technology
3. CRITERIA AND PROCESSES FOR PRIVILEGED USERS
a. Privileged Users. Privileged Users are individuals who have access to system
control, monitoring, or administration function, such as system administrators,
information system security officers, maintainers, and system programmers.
b. Privileged accounts. Privileged accounts are accounts belonging to Privileged
Users. Privileged accounts are created for users to perform privileged functions
only; that is, privileged users use non-privileged accounts for all non-privileged
functions.
The use of mandatory multi-factor authentication process is required for system
administrator and privileged user access to systems where passwords are used as one
authentication method.
.
NAP 14.1-C XIII-1
05-02-08
CHAPTER XIII. WIRELESS TECHNOLOGIES
Section 39
1. INTRODUCTION. This chapter establishes the minimum security controls that are to be
enforced by NNSA sites using wireless technologies to ensure that security risks posed
by wireless applications, devices, and network implementations are analyzed
appropriately, and controlled. This chapter applies to any wireless technologies that
collect, store, transmit, process, create, or disseminate unclassified or classified NNSA
information. In addition, this chapter applies to any wireless technology lifecycle,
including development of new wireless applications, incorporation of wireless devices
into an infrastructure, incorporation of wireless devices outside the infrastructure,
development of prototype wireless technologies, and the reconfiguration or upgrade of
existing wireless technologies and legacy systems. Land mobile radios, one-way receive-
only devices, and mobile satellite services are excluded from this chapter.
2. CRITERIA AND PROCESSES. In order to ensure that security risks posed by wireless
technologies are sufficiently analyzed and appropriately controlled, NNSA sites must
establish a systematic process for managing risks posed by wireless technologies, and
ensure that the process is described fully in their CSPP. The process must:
a. Identify the roles and responsibilities of all personnel responsible for the decision
whether to incorporate wireless into the environment, including personnel
responsible for telecommunications; TEMPEST; Protected Transmission Systems
(PTS); and Technical Surveillance Countermeasures (TSCM) program
compliance.
b. Evaluate the business needs for deploying wireless technologies, to include cost-
benefit analysis, and whether more secure technologies, such as expansion of the
wired network, are feasible.
c. Include a risk assessment to evaluate risks to the confidentiality, integrity, and
availability of site information resources, in the context of exposing information
to the hazards associated with utilizing wireless networking devices, and the
entire spatial volume through which the transmitted signal is capable of being
received. National Institute of Standards and Technology (NIST) Special
Publication (SP) 800-48, Wireless Network Security 802.1, Bluetooth and
Handheld Devices, may be used to assist in decision making.
d. Ensure that risks for connecting to site LANs are evaluated, and security controls
are in place to protect systems and LANs.
e. Evaluate planned wireless networking applications, with respect to specific
wireless technologies, physical location on site, proximity to sensitive or
classified information processing areas, connectivity of wireless devices to site
computers and networks, and the Information Groups and information systems
connected to wireless information systems.
XIII-2 NAP 14.1-C
05-02-08
f. Identify specific security mechanisms implemented through technical,
operational, management, and assurance controls that will ensure risk is
maintained at an acceptable level, and the schedule for testing such controls to
ensure they operate as intended. At a minimum, these controls must:
(1) Require semi-annual performance reviews to ensure accuracy of access
point inventory, security of configurations, or identification of
unauthorized devices.
(2) Require proper installation and physical control of all access points.
(3) Ensure NIC and access-point firmware is up-to-date.
(4) Ensure that only authorized people can reset the access points.
Section 40
(5) Assign strong passwords to access points. In addition, access points must
be administered via the site’s wired network, or locally via the access
point’s built-in COM ports.
(6) Utilize static IP addresses for clients and access points.
(7) Ensure the capability to detect transmissions by unauthorized access
points and/or wireless clients is in place and operational before authorized
use.
(8) Require the regular application of patches and security enhancements.
(9) Adopt strong encryption methods that encompass end-to-end encryption
of information as it passes throughout the wireless network. Use Type II
or III products to encrypt transmission of information to or from non-
National Security Systems.
(10) Address the DOE TEMPEST/Technical Security Countermeasures
(TSCM) concerns, such as wireless, audio, video, and infrared, when
allowing operation of these devices in security areas.
g. NNSA Elements utilizing wireless technologies accredited for use with National
Security Systems must implement, at a minimum, the following controls:
(1) The wireless device must not be used to download or load any shareware,
extraneous software, or unauthorized freeware.
(2) The wireless device must not be synchronized with any unclassified
system.
NAP 14.1-C XIII-3
05-02-08
(3) Wireless networks must support security for voice, data, and control
channel information, only via approved Type 1 encryption for all modes
of operation.
(4) Wireless networks must be monitored to detect unencrypted signals
transmitted from areas where classified information is being electronically
stored, processed, or transmitted, to ensure that unauthorized signals are
not transmitted beyond approved boundaries.
(5) Wireless networks must use security mechanisms compatible and
interoperable with those mechanisms used on wired voice and data
telecommunication networks and computing devices.
(6) Wireless networks must implement identification and authentication
measures at both the device and network level.
XIII-4 NAP 14.1-C
05-02-08
This page intentionally left blank.
NAP 14.1-C XIV-1
05-02-08
CHAPTER XIV. REMOTE ACCESS
1. INTRODUCTION. Remote access is defined as accessing an information system, at the
system or application level, from a location outside the confines of a network, as defined
in each site’s CSPP. This chapter does not address risks associated with or criteria and
processes specific to wireless networks and devices. Criteria and processes for these are
addressed in Chapter XI. Remote access to NNSA information and systems can promote
cost-effective benefits to the NNSA mission and workforce. At the same time, remote
access can introduce significant risk to those systems. Federal law and implementing
policies require agencies to develop, document, and implement programs to assess the
risk and magnitude of harm that could result from the unauthorized access, use,
disclosure, disruption, modification, or destruction of information and information
systems that support agency operations and assets. The remote system used to access a
NNSA information system may not have been evaluated through the NNSA PCSP C&A
process; therefore, its security policy is unknown. Based upon documented risk
assessments, agencies must provide adequate security to maintain an acceptable level of
risk to agency operations and assets.
2. CRITERIA AND PROCESSES.
Section 41
a. All NNSA sites must develop and implement policies, processes, and procedures
to govern remote access of NNSA information systems by users utilizing NNSA
and non-NNSA owned equipment. These processes and procedures are
documented as part of the site’s CSPP. All policies, processes, and procedures
must address the following:
(1) Use of Government- and non-Government-owned computers to access
remotely NNSA information resources or information.
(2) Protection of information on non-Government-owned computers.
(3) Prohibition by the Department of Commerce of export from the United
States of any encryption program or algorithm in excess of 128 bits.
(4) ISSP modifications, when remote access capabilities are to be introduced
into legacy applications or systems.
(5) Additional security measures required for remote access to SUI, as defined
in Appendix B, Glossary.
XIV-2 NAP 14.1-C
05-02-08
(6) National Security Systems. Remote access to any DOE and/or NNSA
National Security System is authorized via approved methods, such as
Type I encryption. The NNSA Element will ensure that only personnel
with access authorization and Need-to-Know can access National Security
Systems. The risk associated with remote access shall be documented in
the relevant ISSP and in the Risk Assessment. Personnel accessing these
systems shall be trained, and training shall be documented as required by
the ISSP.
(7) Management Controls on Remote Access must describe:
(a) Boundary Protection Services and automated tools, such as
firewalls, virtual private networks, encryption, intrusion detection,
anti-virus software, audit log analysis provided to manage remote
access services and detect intrusions and/or intrusion attempts.
(b) Procedures to report and respond to remote access security
incidents.
(c) Rules of behavior and operations and consequences for violating
remote access policies and procedures, including prohibition of
entering classified information on any computing resource not
approved for such information.
(d) Specific security and awareness training for those authorized to
use remote access services to access information in all Information
Groups, except the Open Public Access Information Group, and
those who perform system administration duties.
(e) Process(es) to perform a risk assessment if new threats are
introduced by allowing remote access to NNSA information and
systems, including trusted and non-trusted environments.
(f) Procedures to ensure that management’s initial and periodic
approval of operational need of each user’s remote access
capability is obtained.
(g) Procedures to ensure NNSA systems are protected from malicious
code on equipment used for remote access.
(h) Process for organizations and users to obtain approval from system
owners and data custodians prior to implementing remote network
access.
(i) Processes to ensure that remote access services are controlled, and
that user profiles are managed to reflect user job responsibilities.
NAP 14.1-C XIV-3
05-02-08
(j) Processes to ensure periodic reviews and random security
evaluations of remote access security controls.
(k) Processes to ensure that remote access issues, vulnerabilities,
requirements, and technology changes are incorporated into
training for all affected NNSA and contractor personnel, including,
as appropriate, the permitted extent of personal use.
(l) Remote access requirements in the ISSP of the system being
accessed remotely.
Section 42
(8) Operational Controls on Remote Access must describe the following:
(a) Minimum requirements for operating systems and application
software for users who use non-NNSA owned equipment to
connect remotely to NNSA networks, for access to all Information
Groups, except the Open Public Access Information Group.
(b) Procedures for obtaining user commitment to the understanding
and acknowledgement of minimum requirements and remote
access rules of behavior, through user signatures on a User
Responsibility Statement that includes requirements for remote
access.
(c) Procedures for remote access of NNSA systems from wireless
Internet systems in coffee shops, public libraries, or in other such
public locations.
(9) Technical Controls. Develop or define and describe the following:
(a) Acceptable levels and types of authentication, and personal
identification for remote access.
i. Two-factor authentication, where one of the factors is
provided separately from the computer gaining access, such
as a RSA token or biometric solution.
ii. Clear-text, reusable passwords for remote access are
prohibited. Legacy systems that use clear text passwords
are prohibited from participating in remote access.
(b) Establishment of a trusted path prior to transmission of data in all
Information Groups except the Open Public Access Information
Group.
(c) Time-out function for remote access requiring user re-
authentication after user inactivity of 15 minutes for unclassified
systems, and 10 minutes for National Security Systems.
XIV-4 NAP 14.1-C
05-02-08
(d) Minimum requirements for the operating system and application
software and for controlling and safeguarding Government-issued
cryptographic keying material on all equipment used for remote
access.
(e) Standard minimum security configurations for all information
systems.
b. Significant Changes. Owners and operators of interconnected applications and
systems must be apprised of any significant change to interconnection
agreements. Any site’s application or system that uses remote access for which
the above criteria are not met must be documented as a weakness in applicable
CAPs and POA&Ms.
NAP 14.1-C XV-1
05-02-08
CHAPTER XV. CONTINGENCY PLANNING
1. INTRODUCTION. Information systems are essential to NNSA mission success;
therefore, it is critical that the services provided by these systems be able to operate
effectively without excessive interruption. Contingency planning refers to a coordinated
strategy involving plans, procedures, and technical measures that enable recovery of
systems operations and data after a disruption. Contingency planning generally includes
either restoring operations at an alternate location, using alternate equipment, or reverting
to a manual process. NNSA recognizes one contingency plan may cover multiple
systems, such as one plan that would cover all unclassified desktops.
2. CONTINGENCY PLANNING. The NNSA Contingency Planning Process consists of
the following six progressive steps that must be accomplished during the NNSA C&A
process.
a. Site Planning Policy Statement. The site’s Contingency Planning Policy
Statement must define the site’s overall contingency objectives; establish the
framework; define contingency planning responsibilities and the criteria; safety of
personnel; extent of damage to the site, facility, or system; criticality of the
system to the site’s mission; and anticipated disruption for activating the
contingency plan(s). Major Elements to be covered in the statement are roles and
responsibilities, resource requirements, training requirements, exercise and test
schedules, plan maintenance schedule, frequency of backups, storage of backup
media, and compliance with NNSA policy.
Section 43
b. Business Impact Analyses (BIAs). The site shall conduct BIAs to identify
systems that provide services critical to site operations and prioritize these
systems and their components. These BIAs are to provide sufficient information
to enable the Contingency Plan Coordinator (CPC) to fully characterize system
requirements, processes, and interdependencies to determine contingency
requirements and priorities. The purposes of the BIA are to correlate specific
systems and components with the critical services that they provide and, based on
that information, to characterize the consequences of a disruption to the system
components.
(1) A BIA for any system designated a Critical Infrastructure or Key Resource
may be limited to a determination of critical components required to
maintain essential operation of these systems.
(2) BIAs for the remaining systems under the purview of the site must include
all elements of the BIA.
(3) Identify critical information system resources.
XV-2 NAP 14.1-C
05-02-08
(4) Identify data on the systems and specify protection measures of the data
based on level of confidentiality or classification, such as encryption of
backups or secure storage.
(5) Identify data users, providers, and flows.
(6) Identify system components and infrastructure, such as electric power,
servers, routers, authentication servers, required to extract or enter data.
(7) Identify disruption impacts and allowable outage times.
(8) Identify magnitude of expected disruptions from site-level plans, such as
Disaster Recovery, Continuity of Operations, and Occupant Emergency
Plans, to determine the threats from natural, human, or environmental
sources.
(9) Identify the maximum allowable time the system or system component
may be unavailable before it prevents a mission-essential function from
being performed.
(10) Identify any related or dependent systems and processes that will be
disrupted by the unavailability of the system.
(11) Identify the point in time where the cost of system inoperability and the
cost of restoration are equal.
(12) Develop recovery priorities.
(13) Use data obtained from previous activities to prioritize recovery for
systems and system components.
(14) Determine recovery timeline for each system component.
(15) Initiate preparation of POA&Ms for any systems that are prioritized below
current funding capabilities.
c. Preventive Controls. Identify measures taken or to be taken to reduce the effects
of system disruptions.
(1) Identify the vulnerabilities to natural, human, or environmental threats.
(2) Develop mitigation strategies to reduce or eliminate impacts to system
components, in priority order, based on the BIAs.
(3) Update POA&Ms as necessary for any system that is prioritized below
current funding capabilities.
NAP 14.1-C XV-3
05-02-08
d. Recovery Strategies. Develop thorough recovery strategies to ensure that the
system may be recovered as effectively and as quickly as needed following a
disruption.
(1) Identify threats and/or vulnerabilities that could not be mitigated.
(2) Develop recovery strategies, such as Alternate Sites, Hot Sites, Mirrored
Sites, rapid equipment replacement, and/or reallocation of existing site
equipment, based on the disruption impacts and the allowable outage
times from the BIAs.
Section 44
(3) Note that different types of contingency situations will necessitate
different readily available staff with particular skills. The plan should
identify those personnel or teams to accomplish the decision making,
coordination, administrative, and technical functions required for
contingency plan execution, such as:
(a) Management
(b) Damage Assessment
(c) Alternate Site Recovery and Coordination
(d) Hardware Salvage
(e) Data Recovery
(f) Database Recovery
(g) Application Recovery
(h) LAN and/or WAN Recovery
(i) Telecommunications
(j) Network Operations Recovery
(k) Software and Data Recovery
(l) System Software
(m) Operating System Administration
(n) System Recovery
(o) Server Recovery
(p) Administrative Support
XV-4 NAP 14.1-C
05-02-08
(q) Original Site Restoration and Salvage Coordination
(r) Test
(s) Procurement (equipment and supplies)
(t) Physical and Personnel Security
(u) Transportation and Relocation
(v) Media Relations
(w) Legal Affairs
(4) Update the POA&M as necessary to include resource requirements to
implement this portion of the CP.
e. Testing, Training, and Exercises. Testing the plan identifies planning gaps.
Exercises identify planning and implementation gaps, whereas training prepares
recovery personnel for plan activation. These activities improve plan
effectiveness and overall site preparedness.
(1) Testing a CP involves the definition of a scenario, test objectives, and
criteria that must be met to successfully complete the test of each CP
element.
(2) The results of all testing must be documented in a test report.
(3) Test reports for Critical Infrastructure and Key Resources must be
forwarded to the Office of the NNSA CIO through the SOM or SCD, as
applicable.
(4) Testing may take four forms, as follows:
(a) Structured Walkthrough. The most basic type of test. A
Structured Walkthrough takes place in a group meeting type of
setting, where the main goal is to confirm that critical personnel
from all areas are familiar with the BCP – provides an orientation.
This test does not usually involve the entire organization, nor does
it test the team’s ability to execute it.
(b) Tabletop Exercise. This takes place in a classroom-type
environment and emulates particular recovery scenarios. During
NAP 14.1-C XV-5
05-02-08
plan development, tabletop exercises are conducted on portions of
the plan to detect and correct initial errors and misconceptions.
Tabletop exercises also provide familiarity for recovery personnel
throughout the lifecycle of the system. At a minimum, a Tabletop
Exercise of CPs for all systems must be conducted annually, when
a Functional Exercise is not conducted.
(c) Functional Exercise. This takes place in a simulated environment
and utilizes physical testing of procedures, alternate equipment,
and alternate locations, to ensure the correctness of procedures,
capability of recovery personnel, and technical capabilities of
equipment. A Functional Exercise of Critical Infrastructure and
Key Resource CP must be conducted annually. All Moderate and
High category information systems should undergo a Functional
Exercise at least every 2 years to include elements of Notification
and Activation, Recovery, and Reconstitution, as a minimum.
(d) Full-Scale Exercise. The most comprehensive test is the Full-
Scale Exercise, also known as the Operational Exercise. During
this test, all or most of the BCP is put into action. The main goal is
to simulate an actual recovery situation as closely as possible. The
exercise will evolve and develop just as they would in an actual
crisis.
Section 45
(5) Training. Recovery personnel must be trained to understand the CP and
their applicable role. This training will be accomplished annually and as
part of changes to the CP. The following plan elements shall be included
in training:
(a) Purpose of the plan.
(b) Cross-team coordination and communication.
(c) Reporting procedures.
(d) Security requirements.
(e) Team-specific processes such as notification and activation,
recovery, and reconstitution.
(f) Individual responsibilities in contingency processes.
(6) POA&M Update. Update the POA&M as necessary, to include resource
requirements to implement this portion of the CP.
XV-6 NAP 14.1-C
05-02-08
f. Plan Maintenance. The plan is a living document that is reviewed and updated
annually to remain current with system enhancements, results of plan testing,
team staffing changes, and changes in NNSA priorities.
The CP shall be a configuration item and maintained as part of the ISSP. A
change to the system or its environment, which includes CP elements, requires the
modified ISSP to be approved prior to implementing the changes.
3. CONTINGENCY PLAN DEVELOPMENT. The CP contains detailed roles,
responsibilities, teams, and procedures associated with restoring an IT system following a
disruption. The CP should document technical capabilities designed to support
contingency operations and be tailored to the site and its requirements. A site-level CP
may be written to describe processes that are common to all CPs, with system-specific
detail as addendums or separate contingency plans; however, plans should provide quick
and clear directions in the event that personnel unfamiliar with the plan or the systems
are called on to perform recovery operations. Plans should be clear, concise, and easy to
implement in an emergency. Where possible, checklists and step-by-step procedures
should be used.
a. Introduction. The Introduction includes background and contextual information
that makes the plan easier to understand, implement, and maintain, and to orient
the reader to the type and location of information contained in the plan.
(1) Purpose. This subparagraph establishes the reason for writing the plan.
(2) Applicability. The organization(s) impacted by the CP is documented,
and the relationship to any other plans supporting or supported by the
plan, such as Emergency Management Plans, is described.
b. Scope. This paragraph discusses the issues, situations, and conditions addressed
and not addressed in the CP. The types of contingency situations the plan is
intended to cover should be discussed. These situations may range from a
temporary loss of commercial power to disaster recovery operations. The system,
location(s) for the system or system components covered, and any assumptions
are described.
c. References and Requirements. This subparagraph identifies the NNSA, Program,
and site requirements for contingency planning.
d. Record of Changes. This subparagraph describes the configuration history of the
CP by recording dates, version, and reason for CP changes.
e. Concept of Operations. The Concept of Operations (CONOPS) element provides
additional details about the system, planning framework, response activities,
recovery activities, and resumption activities.
NAP 14.1-C XV-7
05-02-08
f. System Description. The system description should include system architecture,
location(s), internal and external connections, security components, and any other
technical detail that would assist contingency teams in understanding the system
configuration and operation.
Section 46
(1) Line of Succession. The order of succession identifies the personnel
responsible for assuming authority in the event the designated person is
unavailable.
(2) Responsibilities. This subparagraph describes the overall structure of the
contingency teams. Coordination mechanisms and requirements, as well
as an overview of team member roles and responsibilities are also
described.
g. Notification and Activation. The Notification and Activation element defines the
initial actions to be accomplished to notify personnel, assess damage, and
implement the plan once a disruption or emergency has been detected or is
expected.
h. Notification Procedures. The method(s) of notification of each team member
must take into account the possibilities of widespread disasters, the ability to
contact personnel on short notice during and after business hours, and the
necessity to contact alternate personnel. Personnel to be notified may be listed in
an appendix that identifies the person, their team position, home address,
telephone number, pager number, cell phone number, and personal and business
e-mail address. Notifications to interconnected systems staff, internal or external
to the site, would also be made. These POCs are identified in the ISSP
Memorandum of Agreement (MOA)/System Interconnect (SIA) Agreement, but
should also be listed in the CP for ease of use when needed.
i. Damage Assessment. In order to appropriately implement the CP, the nature and
extent of damage must be assessed as early as possible. Personnel performing
damage assessment must be sufficiently trained in their part(s) of these
procedures that performance can be accomplished without written procedures
available. Specific damage assessment procedures may be unique to each system,
but the following areas must be addressed:
(1) The cause of the emergency or disruption.
(2) The potential for additional disruptions or damage.
(3) Area affected by the emergency.
(4) Status of physical infrastructure, such as structural integrity of the
building or room, electric power availability, HVAC, and
telecommunications.
XV-8 NAP 14.1-C
05-02-08
(5) Inventory and functional status of system components.
(6) Type of damage to system components, such as water, fire and heat,
physical, and electric surge.
(7) System components to be replaced.
(8) Estimated time required to restore normal system operation.
j. Plan Activation. The CPC evaluates the result of the damage assessment against
the plan activation criteria and determines the strategy to be used if the plan is to
be activated. The detailed activation criteria are located in this paragraph of the
plan, and it covers personnel safety, extent of damage to the facility, extent of
damage to the system, criticality to the site’s mission, and anticipated duration of
disruption.
k. Recovery. The Recovery element includes the operations that begin after the CP
has been activated, damage assessment has been completed, if possible, personnel
have been notified, and appropriate teams have been mobilized. Recovery
activities focus on contingency measures to execute temporary processing
capabilities, repair damage to the original system, and restore operational
capabilities at the original or new facility. Upon completion of the Recovery
Phase, the system will be operational and performing the functions designated in
the plan.
Section 47
l. Recovery Sequence. The sequence of recovery activities should reflect the
system’s allowable outage time to avoid significant impacts to related systems
and their application. Procedures should be written in a stepwise, sequential
format so that system components can be restored in a logical manner. The most
critical items to restoring service and the system foundation items should be
recovered first. Procedures must include coordination activities with other teams
or external organizations that are dependent on completion of certain steps, such
as when time frames are not being met, a step has been completed that allows
another team to proceed, or when items must be procured.
m. Recovery Procedures. Recovery procedures are to be written that allow personnel
unfamiliar with the site, facility, or system configuration to perform the recovery.
Recovery procedures are to include date and time of step completion and the
name of the team member who completed it. Particular procedures are to be
assigned to the appropriate recovery team and address the following:
(1) Obtaining approval to access damaged facilities or areas.
(2) Notifying internal and external organizations associated with the system.
(3) Obtaining office supplies and work space.
NAP 14.1-C XV-9
05-02-08
(4) Obtaining and installing hardware.
(5) Obtaining backup media.
(6) Restoring operating and application software.
(7) Restoring system and application data.
(8) Testing system functionality and security.
(9) Notification to user(s).
(10) Operating alternate equipment.
n. Reconstitution. Once the original or new site or facility is restored to the level
that it can support the system and its normal processes, the system may be
transitioned back to the original or to the new site and/or facility. Until the
primary system is restored and tested, the alternate system should continue to be
operated.
o. The CP should specify teams responsible for restoring or replacing both the
facility and the system. The following major activities are addressed:
(1) Ensuring adequate infrastructure support, such as electric power, water,
telecommunications, security, environmental controls, office equipment,
and supplies.
(2) Establishing connectivity and interfaces with network components and
external systems.
(3) Installing system hardware, software, and firmware. This activity should
include detailed restoration procedures similar to those followed in
Recovery.
(4) Testing system operations and security to ensure full functionality.
(5) Backing up operational data on the contingency system and uploading to
restored system.
(6) Shutting down the alternate system.
(7) Terminating contingency operations.
(8) Securing, removing, and/or relocating all sensitive materials at the
alternate site.
(9) Arranging for recovery personnel to return to the original facility.
XV-10 NAP 14.1-C
05-02-08
4. CONTINGENCY PLAN STRUCTURE. The structure of a CP is based on the
importance of systems for which the plan is written. The following paragraphs describe
the mandatory CP elements based on the designation of the system. Refer to Appendix
G, Contingency Plan Structure.
a. Critical Infrastructure. Critical Infrastructure CPs must address each of the
elements described in paragraph 3 in sufficient detail to allow technically
competent personnel unfamiliar with the system to create and operate the system
in a different location.
Section 48
b. Key Resources. Key Resource CPs must address each of the elements indicated
in the following paragraph in sufficient detail for personnel familiar with the
system to create and operate the system in a different location.
(1) Introduction (3.a)
(2) Scope (3.b)
(3) Concept of Operations (3.c)
(4) Notification and Activation (3.d)
(5) Recovery Procedures (3.e)
(6) Reconstitution (3.f)
c. Remaining Systems. All other system CPs must address each of the elements, as
indicated in the paragraphs below in sufficient detail for personnel who normally
operate the systems to restore operations.
(1) Introduction (3.a)
(2) Scope (3.b)
(3) Concept of Operations (3.c.)
(4) System Description (3.c.(1))
(5) Line of Succession (3.c.(3))
(6) Notification and Activation
(7) Notification Procedures (3.d.(1))
(8) Plan Activation (3.d.(3))
(9) Recovery Procedures
NAP 14.1-C XV-11
05-02-08
(10) Hardware Installation (3.e.(2)(d))
(11) Backup Media (3.e.(2)(e))
(12) Software Restoration (3.e.(2)(f))
(13) Functional and Security Testing (3.e.(2)(h))
(14) User Notification (3.e.(2)(i))
(15) Operating Equipment (3.e.(2)(j)
(16) Reconstitution
(17) Infrastructure Support (3.f.(1))
(18) Internal and External Networking (3.f.(3))
(19) Functional and Security Testing (3.f.(4))
XV-12 NAP 14.1-C
05-02-08
This page intentionally left blank.
NAP14.1-C XVI-1
05-02-08
CHAPTER XVI. CLEARING, PURGING, AND DESTROYING MEDIA
1. INTRODUCTION. This chapter establishes NNSA policy requirements and
responsibilities for clearing, purging, and destroying NNSA information system storage
media, memory devices, and other related hardware, hereafter referred to as storage
media. Specifically, this chapter provides the following:
a. Instructions for clearing, purging, and destroying storage media to preserve the
confidentiality of the stored information.
b. Instructions for handling classified storage media that will be reused in controlled
environments.
c. Instructions for sanitizing storage media that has become contaminated with
classified or unclassified sensitive information.
d. Direction to ensure that no unauthorized information can be retrieved from
unclassified NNSA and DOE computer equipment, and storage media that is to be
transferred or declared surplus.
e. Direction to ensure that all NNSA Element personnel are made aware of
requirements for clearing, purging, and destroying information system storage
media, memory devices, and related hardware.
2. CRITERIA AND PROCESSES.
a. Approved Processes. NNSA-approved processes for clearing, purging, and
destroying information system storage media, memory devices, and related
hardware that have been used to process, store, or contain unclassified or
classified information are listed in the following paragraphs. Decisions to clear,
purge, or destroy information system storage media, memory, and other related
hardware must be based on the confidentiality of the most sensitive information
ever recorded on the storage media. Implementation of these processes and plans
for clearing, purging, and destroying information system storage media must be
documented in the appropriate CSPPs, including the requirement for documented
methods for independently verifying the clearing and purging results.
b. CSPP. The CSPP must identify or reference procedures used for the sanitization
(clearing, purging, and destruction) that implement the concepts and processes
listed below.
Section 49
(1) Maintenance on equipment and tools used for clearing, purging, and
destruction is regularly scheduled and performed to ensure proper
operation and calibration.
(2) All maintenance on equipment and tools used for clearing, purging, and
destruction are thoroughly documented.
XVI-2 NAP 14.1-C
05-02-08
(3) Systems media and storage hardware are purged before release to
personnel without authorization to access the information, including
Need-to-Know, on the media or hardware.
(4) Processes for handling and control of media, electronic devices, and
hardware prior to clearing, purging, or destruction are documented and
followed.
(5) Storage media used in SUI processing is tracked and controlled until it is
purged or destroyed.
(6) The storage media must be tracked and destroyed if the confidentiality
impact is moderate or high, unclassified information is located in bad
sectors, or the storage media cannot be cleared or purged.
(7) Storage media that has been used in classified processing and is no longer
being used or needed for archiving is tracked and controlled until it is
destroyed, and the destruction is documented as required by the DOE
Classified Matter Protection and Control (CMPC) program.
(8) Sanitization procedures, software, equipment and tools, and special
processes are identified, documented and approved by the DAA.
(9) Decision and handling processes regarding reuse of classified storage
media at lower classification level(s) include formal risk and cost analyses
and testing and are documented and justified.
(10) Requirements for removing information from storage media, memory
devices, and related hardware are to be included in the training and
awareness program and reviewed with all users on a regular basis.
(11) Personnel performing or verifying clearing, purging, or destruction of
storage media, memory devices, and other hardware are to be trained in
equipment and tool operation, approved techniques, and procedures.
(12) No fewer than 20 percent of the purged media are sampled on a
controlled, random basis to verify the purging process has been
successfully completed.
(13) Verification is conducted by individuals other than those performing the
purging processes.
(14) The completion and verification of the purging process is documented.
c. Minimum Sanitization Criteria. Table XVII-1 through Table XVII-3 outline the
basic sanitization processes and tools based on different technologies and media
types.
NAP14.1-C XVI-3
05-02-08
(1) NSA/CSS Manual 9-12/20 or subsequent update may be used as a
supplement for these processes.
(2) NIST SP 800-88, Guidelines for Media Sanitization, or subsequent update
may be used as a supplement for these processes.
(3) Refer technologies and media types not listed in the tables or references
through the NNSA CSPM to DOE OCIO for defining clearing, purging,
and destroying processes.
d. Unclassified Storage Media Processes.
(1) In addition to the clearing processes listed in Tables XVI-1 through XVI-
3, processes to clear unclassified storage media are to include the
following:
(2) Storage media hosting Government information is to be cleared if it will
be reused by a potential user who has a different authority for access,
including Need-to-Know, or in a system that contains information whose
Security Category (confidentiality, impact) is the same or higher.
Section 50
(3) Only overwriting software and hardware that are compatible with media to
be overwritten and approved by the DAA will be used. Care should be
used to ensure a match of software and hardware to the media, considering
the make, model, and manufacturing date of the media.
(4) One-pass overwrites are sufficient for clearing storage media that does not
contain SUI. If the storage media contains SUI, three-pass overwrites
must be performed.
(5) Individuals performing unclassified storage media clearing must certify
and document successful completion of the process to include the
following:
(a) Purpose of clearing (reuse or release).
(b) Storage media unique identifiers, such as serial number, make, and
model.
(c) The Information Type with the highest confidentiality impact
hosted on the media prior to clearing.
(d) The procedure used.
(e) The date, the printed name, and signature of the certifying
individual.
(6) All unclassified storage media will not be released to the public.
XVI-4 NAP 14.1-C
05-02-08
(7) Individuals performing unclassified storage media purging must certify
that the purging process has been successfully completed by affixing a
label to the storage media. At a minimum, the label must document the
following:
(a) Storage media unique identifiers, such as serial number, make, and
model.
(b) The Information Type with the highest confidentiality impact
hosted on the storage media prior to purging.
(c) Purpose of purging.
(d) The procedure used.
(e) The date, printed name, and signature of the certifying individual.
(f) Storage media that cannot be purged must be destroyed.
e. Classified Storage Media Processes.
(1) In addition to the clearing processes listed in Tables XVI-1 through Table
XVI-3, processes to clear classified storage media must include the
following:
(2) Storage media that will be reused on a different system for the same or
more restrictive Information Group or a potential user has a different
Need-to-Know must be cleared.
(3) Only overwriting software and hardware that are compatible with media to
be overwritten and approved by the DAA will be used.
(4) Cleared storage media that has been used in classified processing must be
protected commensurate with the highest Information Group it has ever
contained. The media must be handled in accordance with applicable
DOE Classified Matter Protection and Control processes.
(5) Individuals involved in clearing classified storage media must certify and
document the successful completion of the process to include:
(a) Storage media unique identifiers, such as serial number, make, and
model, and ACREM accountability number.
(b) Most restrictive Information Group hosted prior to clearing.
(c) Purpose for clearing.
(d) The procedure used.
NAP14.1-C XVI-5
05-02-08
(e) The date, the printed name, and the signature of the certifying
individual.
(6) In addition to the purging processes listed in Tables XVI-1 through XVI-
3, processes to purge classified storage media are to include the following.
(a) Classified storage media that cannot be reused at a lower level
must be destroyed.
(b) Classified storage media that has been purged may not be donated,
sold, or released from the DOE environment to outside
organizations.
(c) Individuals performing purging of classified storage media must
certify the process has been successfully completed by affixing a
label to the storage media. At a minimum, the label must
document the following:
Section 51
(i) Storage media unique identifiers, such as serial number,
make, and model.
(ii) Most restrictive Information Group hosted prior to purging.
(iii) Purpose of purging.
(iv) A statement that the storage media contains no classified
information.
(v) The procedure used.
(vi) The date, printed name, and signature of the certifying
individual.
f. Special Circumstances. The use of storage media in a lower classification is
described below.
(1) Reusing Classified Storage Media.
(a) The decision to reuse storage media at a lower classification level
may be acceptable if formal risk and cost analyses are conducted,
and the results of these analyses and testing of the implemented
procedures verify that the National Security of the United States is
not adversely affected. Testing, risk and cost analysis procedures
must be documented in the site’s approved CSPP.
(b) Reuse of storage media must be identified in the ISSP of the
system where the media is used and the media must be tracked and
controlled until it is purged or destroyed.
XVI-6 NAP 14.1-C
05-02-08
(c) Classified storage media that will not be reused at a lower
classified level must be destroyed.
(d) The storage media must be purged by overwriting the entire
storage media using the three-pass process described in Table
XVI-1 of this document.
(e) The software used is to provide information about sectors
overwritten and bad sectors that cannot be overwritten.
(f) Quality controls are to be documented and deployed for review of
overwrite process results and verification that all the classified
information was completely overwritten
(g) Storage media must be destroyed if classified information is
located in bad sectors or the storage media cannot be purged.
(h) Individuals performing purging of the classified storage media
planned for reuse must certify the process has been successfully
completed by affixing a label to the storage media. At a minimum,
the label must document the following:
(i) Storage media unique identifiers, such as serial number,
make, and model, and ACREM accountability number.
(ii) Most restrictive Information Group hosted prior to purging.
(iii) Purpose of purging.
(iv) A statement that the storage media contains no classified
information.
(v) The procedure used.
(vi) The date, printed name, and signature of the CA.
(2) Purging Partially Contaminated Storage Media. Areas of non-removable
and removable storage media partially contaminated with an information
type of a higher confidentiality impact or more restrictive Information
Group may be purged using the three-pass process described in Table
XVI-1 and continue use in its current information system in the following
situations:
(a) When the classified storage media is contaminated with relatively
small amounts of information from a more restrictive Information
Group (less than 0.1 percent of the capacity of the non-removable
storage media).
(b) When unclassified storage media is contaminated with relatively
small amounts of unclassified information with a confidentiality
NAP14.1-C XVI-7
05-02-08
impact of moderate or high (non-Public) (less than 0.1 percent of
the capacity of the non-removable storage media).
(c) The software used to overwrite contaminated storage media must
overwrite all contaminated locations, including temporary data file
locations, file slack, free space, and directories; provide
confirmation of overwrite of specified areas and of successful
completion; and provide information about sectors overwritten and
bad sectors that cannot be overwritten.
Section 52
(d) Quality controls are to be documented and deployed for review of
overwrite process results and verification that all the contaminating
information was completely overwritten.
(e) Storage media must be destroyed if classified information is
located in bad sectors, or the storage media cannot be purged.
(f) Records to be maintained, as a minimum, are listed below.
(i) Storage media unique identifiers, such as serial number,
make, and model.
(ii) Contaminating Information Group.
(iii) Purpose of purging.
(iv) A statement that the storage media no longer contains the
Information Group.
(v) The procedure used.
(vi) The date, printed name, and signature of the certifying
individual.
Table XVII-1 shows the approved processes for clearing, purging, and destroying storage media.
Table XVI-1. Approved Processes for Managing Storage Media
Media Type Clearing‡ Purging‡ Destroying‡
Magnetic Tapes
XVI-8 NAP 14.1-C
05-02-08
Media Type Clearing‡ Purging‡ Destroying‡
Type I 1, 2, or 3 1, 2, 3, or 4 5
Type II 1, 2, or 3 2, 3, or 4 5
Type III 2 or 3 3 or 4 5
Magnetic Disks
Floppies, Zip drives 1, 2, 3, or 4 X 5
Bernoulli Boxes 1, 2, 3, or 4 X 5
Removable Hard Disks 1, 2, 3, or 4 1, 2, 3, or 4 5 or 6
Non-removable Hard Disks 4 1, 2, 3, or 4 5 or 6
Optical Disks
Magneto-optical: Read Only X X 4
Write Once, Read Many (WORM) X X 4
Read Many, Write Many X X 4
Other
Floptical X X 5
Helical-scan Tapes X X 5
Cartridges X X 5
Optical X X 5
CD-R, -RW, -ROM X X 5 or 7
DVD X X 5 or 7
‡ Numbers in the table refer to the processes listed.
§ All degaussing products used to clear or sanitize media must be certified by the National Security Agency
(NSA), and be listed on the Degausser Products List of the NSA Information Systems Security Products and
Services Catalogue.
Processes: †
Degauss with a Type 1 degausser.§
1. Degauss with a Type 2 degausser.§
2. Degauss with a Type 3 degausser.§
3. Overwrite all locations with a pseudorandom pattern twice and then with a known pattern.
4. Pulverize, smelt, incinerate, disintegrate, or use other appropriate mechanisms to ensure media are
physically destroyed.
5. Remove the entire recording surfaces by sanding or applying acid.
6. Grind surface of CD or DVD to ensure the entire recording surface is removed. Only NSA Group D
equipment and associated processes approved for the specific media may be used.
X. No process authorized.
Table XVII-2 illustrates the approved processes for clearing, purging, and destroying electronic
memory devices.
NAP14.1-C XVI-9
05-02-08
Table XVI-2. Approved Processes for Managing Electronic Memory Devices
Media Type Clearing‡ Purging‡ Destroying‡
Magnetic Bubble Memory 2 1 or 2 10
Magnetic Core Memory 2 1 or 2 10
Magnetic Plated Wire 2 2 and 3 10
Magnetic-Resistive Memory 2 X 10
Read-Only Memory (ROM) X X 10 (see 11)
Random Access Memory (RAM)
(Volatile) 2 or 4 4, then 9 10
Programmable ROM (PROM) X X 10
Erasable PROM (UV PROM) 6 6, then 2 and
9 10
Electrically Alterable PROM (EAPROM) 8 7, then 2 and
9 10
Electrically Erasable PROM (EEPROM) 2 8, then 2 and
9 10
Flash Erasable PROM (FEPROM) 8 8, then 2 and
9 10
‡Numbers in the table refer to the processes listed.
§ All degaussing products used to clear or sanitize media must be certified by the National Security
Agency (NSA) and be listed on the Degausser Products List of the NSA Information Systems
Security Products and Services Catalogue.
Processes: ‡
Section 53
1. Degauss with a NSA approved Type III degausser.§
2. Overwrite all locations with a pseudorandom pattern twice and then with a known pattern.
3. Purging is not authorized if data resided in same location for more than 72 hours; sanitization is
not complete until each overwrite has resided in memory for a period longer than the classified
data resided in memory.
4. Remove all power, including batteries and capacitor power supplies, from RAM circuit board.
5. Perform an ultraviolet erase according to manufacturer’s recommendation.
6. Perform an ultraviolet erase according to manufacturer’s recommendation, but increase time
requirements by a factor of 3.
7. Pulse all gates.
8. Perform a full chip purge/ erase (see manufacturer’s data sheet for procedure).
9. Check with ISSO to determine whether additional processes are required.
10. Pulverize, smelt, incinerate, disintegrate, or use other appropriate mechanisms to ensure media
are physically destroyed.
11. Destruction required only if ROM contained a classified algorithm or classified data.
X. No process authorized.
Table XVII-3 shows the approved processes for clearing, purging, or destroying hardware.
Table XVI-3. Approved Processes for Managing Hardware
Media Type Clearing‡ Purging‡ Destroying‡
XVI-10 NAP 14.1-C
05-02-08
Media Type Clearing‡ Purging‡ Destroying‡
Printer Ribbons 6 6 6
Platens X 1 6
Toner Cartridges 5 5 X
Laser Drums 3 3 6
Cathode-Ray Tubes (If there is Classified
Burn-In) X 6 6
Fax Machines 4 4 6
Cell Phones 7 X 6
Personal Digital Assistant (PDA) (Palm,
Pocket PC, etc.) 7 X 6
Routers/Copy machines 7 X 6
All other storage media devices X X 6
‡Numbers in the table refer to the processes listed.
Processes:
†
1. Chemically clean so no visible trace of data remains.
2. Print at least five pages of randomly generated unclassified data. The pages should not include
any blank spaces or solid black areas.
3. Print three blank copies. If unable to get a clean output, print an unclassified test pattern or black
copy; then run three blank copies.
4. For fax machines that have memory and other storage media incorporated, treat each component
per processes listed in tables 1 and 2 of this chapter.
5. Upon completion of copying or facsimile processing of classified material, users are required to
run ten (10) blank copies to ensure the removal of all classified materials from processing device.
6. Pulverize, smelt, incinerate, disintegrate, or use other appropriate mechanisms to ensure the
media is physically destroyed.
7. Manually delete all information, then perform a full manufacturers reset to reset the instrument
back to factory default settings.
X. Not applicable.
Note: All copies printed for clearing and sanitization purposes must be destroyed as classified waste.
NAP14.1-C XVII-1
05-02-08
CHAPTER XVII. SENSITIVE UNCLASSIFIED INFORMATION
1. INTRODUCTION. This chapter describes the terms Sensitive Unclassified Information
(SUI), including Personally Identifiable Information (PII) as defined by DOE. NAP
14.2-C, NNSA Certification and Accreditation (C&A) Process, establishes the minimum
security criteria and processes for protecting this type of information. All NNSA
Elements must develop, document, and implement policies for protecting SUI, including
PII.
2. CRITERIA AND PROCESSES. To ensure that SUI, including PII, on NNSA
information systems is appropriately managed, each NNSA site must establish policies
and procedures that address the following:
Section 54
a. Sensitive Unclassified Information. SUI is defined as unclassified information
requiring protection mandated by policy or laws, such as OUO; Export Control
Information (ECI); Unclassified Controlled Nuclear Information (UCNI); Naval
Nuclear Power Information (NNPI); Personally Identifiable Information (PII);
and other information specifically designated as requiring SUI protection.
Extensions of the definition of SUI must be documented in the Element’s CSPP
and ISSP.
The OMB definition of PII is included below. This definition is not to be
modified by Senior DOE Management or its elements. Senior DOE Management
should interpret this definition by applying the working examples of what is and
what is not considered PII, provided in Appendix B, to identify PII within their
organizations.
b. Personally Identifiable Information (PII) (as defined by OMB). Personally
Identifiable Information (PII) is any information about an individual maintained
by an Agency, including but not limited to, education, financial transactions,
medical history, and criminal or employment history and information which can
be used to distinguish or trace an individual’s identity, such as their name,
social security numbers, date and place of birth, mother’s maiden name,
biometric records, including any other personal information that is linked or
linkable to an individual. In some instances, PII overlaps with Privacy Act
information.
XVII-2 NAP 14.1-C
05-02-08
This page intentionally left blank.
NAP 14.1-C XVIII-1
05-02-08
CHAPTER XVIII. PEER-TO-PEER (P2P) NETWORKING
1. INTRODUCTION. Peer-to-peer (P2P) technology, services, and applications are useful
but introduce significant risks that must be mitigated to maintain the security of DOE
systems and networks. All NNSA Elements must use a risk-based approach when
evaluating the possible use of P2P technologies, as well as address the following
minimum security requirements.
2. CRITERIA AND PROCESSES. NNSA Elements must develop and implement risk-
based policies and procedures that govern the consideration and possible implementation
of P2P technologies in accordance with the following security criteria:
a. The default condition is that P2P applications, technology, or services are not to
be used on DOE systems that contain or process SUI.
b. P2P applications are prohibited from being employed in any National Security
System.
c. If the application of P2P technology or service is required to meet programmatic
or mission requirements, then each application of the technology must be justified
and approved by the DAA during the C&A process. At a minimum, the
justification must include:
(1) Description of the P2P protocol(s) and application(s).
(2) Risk assessments for systems where P2P technology or services are to be
used.
(3) Identification of controls at the system and network levels to detect
improper use and attempted evasion of security controls.
d. If a NNSA Element does implement P2P technology based on a DAA-approved
justification, the following management and technical security controls (at a
minimum) are to be addressed and implemented for applications, system
components, and networks that are part of, or may come in contact with, P2P
technologies or services. Implemented controls are to be documented and tested
in all associated ISSPs during the C&A process.
(1) Technical controls that do not allow the P2P server-client applications to
automatically reply (Pongs) to broadcasts for locating another server-
client (Pings).
Section 55
(2) Management controls describing the rules of behavior for users.
XVIII-2 NAP 14.1-C
05-02-08
(3) Protocols specific to P2P server-client applications are not passed between
systems or on the network unless specifically authorized in an ISA for
each system hosting a P2P server-client application.
(4) Firewall rules and access control lists (ACL) must be specifically
established to allow, should be restrictive to specific systems, and be
appropriately documented.
(5) Technical controls that provide the capability for boundary protection
services to detect and block unauthorized P2P applications, services, and
software ports.
(6) Need-to-Know and access authorizations are enforced and implemented as
required for the Information Groups and security categorization of the
affected system.
(7) Technical controls that limit operation of a server-client application to
downloading (pull), and that does not accept remote writing to the system
disk hosting the P2P application from another system or system
component (push).
(8) Technical controls that limit ports authorized for use be P2P applications.
P2P is denied/disabled on all systems and must be specifically approved to
be enabled.
NAP 14.1-C XIX-1
05-02-08
CHAPTER XIX. FOREIGN NATIONAL ACCESS
1. INTRODUCTION. This chapter establishes the requirements for defining Foreign
National Access to NNSA information and the information systems that contain such
information. Information systems include, but are not limited to, computers, networks,
associated servers, data storage devices, and portable and mobile devices. A process for
defining Foreign National Access to NNSA information systems is needed to enforce
access restrictions based on Need-to-Know, therefore providing adequate protection to
information assets. All NNSA Elements must develop, document, and implement
policies pertaining to information system access by Foreign Nationals, as dictated by the
following criteria. Further, such policies must be commensurate with the level of
security required for the organization’s environment and specific needs.
2. CRITERIA AND PROCESSES. To ensure that Foreign National Access to NNSA
information systems is managed appropriately in an effort to reduce the risk of
unauthorized access to information assets, each NNSA Element must establish policies
and procedures that include the following criteria, at a minimum.
a. Roles and responsibilities of personnel involved in approving, implementing, and
monitoring Foreign National Access to NNSA information systems.
b. Specific requirements for approval, documentation, and review of Foreign
National Access to information systems as required by DOE O 142.3,
Unclassified Foreign Visits and Assignments, and DOE O 142.1, Classified Visits
Involving Foreign Nationals.
c. Access to National Security systems by Foreign Nationals must include an access
approval by the system owner via the processes detailed in DOE O 142.1.
d. Policies specifying the use, or prohibition, of Foreign National-owned computing
equipment connected to NNSA information systems. Such equipment includes
computer systems, external computing devices, and electronic media.
e. Policies describing the screening process for Foreign National Access to NNSA
information systems dependent on the security category of the information
system, the information type, and the level of access required by the Foreign
National, such as general user, privileged user, or System Administrator.
Section 56
XIX-2 NAP 14.1-C
05-02-08
f. Access to SUI systems by Foreign Nationals must include the following:
(1) If a general user, a background screening that includes a Human
Resources Background Check and a National Agency Check.
(2) If a privileged user, a background screening that includes a Human
Resources Background Check and a National Agency Check with
Inquiries.
(3) Processes for monitoring and evaluating the effectiveness of Foreign
National Access policies and procedures.
(4) Policies prohibiting Foreign National use of non-DOE equipment to
access National Security systems.
3. CYBER SECURITY PROGRAM PLANS. Each NNSA Element must document
policies for allowing Foreign National Access to NNSA information systems consistent
with the following criteria in their site CSPP.
a. Access to information systems by Foreign Nationals must be approved and
documented.
b. Approval documentation must identify the applicable security plan, as required by
DOE O 142.1 and/or DOE O 142.3, the information and information systems(s) to
which access is granted, and the time period of access.
c. The official accountable for the access approval decision is to be identified in the
documentation.
d. Access is granted based on a documented risk assessment and identification of
access controls.
e. The approved risk assessment must be referenced in the security plan, and the
specific information system access controls must be documented in the security
plan.
f. The risk assessment must address certain security factors, such as type of security
area where work will be accomplished or visited, sensitivity of all information
accessible during the work or visit, and Foreign National affiliation with sensitive
countries or countries identified as state sponsors of terrorism. In addition, the
risk assessment must address the results of subject matter expert (SME) reviews
as required by DOE O 142.3.
g. Procedures for reviewing and managing Foreign National Access to NNSA
information systems must be documented. The procedures must include:
NAP 14.1-C XIX-3
05-02-08
(1) Documenting, monitoring, and tracking Foreign National Access to
NNSA information systems.
(2) Auditing Foreign National Access to NNSA information systems
consistent with the documented risk assessment.
(3) Security incident reporting and resolution