Archive

NAP-14.1C, NNSA Baseline Cyber Security Program

Implement DOE O 205.1A, Department of Energy Cyber Security Management, and TMR-0, DOE Cyber Security Program Foundation in the National Nuclear Security Administration (NNSA) and all Elements under its cognizance.
NAP-14.1C 5-2-08.pdf912.03KB
Version history and related documents
Document text

Text extracted from the attached file. Refer to the original document for the authoritative version.

Section 1

AVAILABLE ONLINE AT: INITIATED BY: http://hq.na.gov Office of the Chief Information Officer NNSA POLICY LETTER Approved: 05-02-08 NNSA BASELINE CYBER SECURITY PROGRAM NATIONAL NUCLEAR SECURITY ADMINISTRATION Office of the Chief Information Officer NAP 14.1-C ii NAP 14.1-C 05-02-08 This page intentionally left blank. NAP 14.1-C iii 05-02-08 Table of Contents GENERAL OVERVIEW CHAPTER I. NNSA PCSP OVERVIEW I-1 CHAPTER II. MANAGEMENT STRUCTURE AND RESPONSIBILITIES II-1 CHAPTER III. CONFIGURATION MANAGEMENT III-1 CHAPTER IV. CYBER SECURITY PROGRAM PLAN IV-1 CHAPTER V. INFORMATION GROUPS V-1 CHAPTER VI. NNSA CYBER SECURITY PROGRAM DEVIATIONS VI-1 CHAPTER VII. INCIDENT MANAGEMENT VII-1 CHAPTER VIII. INFORMATION CONDITION (INFOCON) VIII-1 CHAPTER IX. PLAN OF ACTIONS AND MILESTONES IX-1 CHAPTER X. VULNERABILITY MANAGEMENT X-1 CHAPTER XI. PORTABLE COMPUTING DEVICES XI-1 CHAPTER XII. PASSWORD GENERATION, PROTECTION, AND USE XII-1 CHAPTER XIII. WIRELESS TECHNOLOGIES XIII-1 CHAPTER XIV. REMOTE ACCESS XIV-1 CHAPTER XV. CONTINGENCY PLANNING XV-1 CHAPTER XVI. CLEARING, PURGING, AND DESTROYING MEDIA XVI-1 CHAPTER XVII. SENSITIVE UNCLASSIFIED INFORMATION XVII-1 CHAPTER XVIII. PEER-TO-PEER (P2P) NETWORKING XVIII-1 CHAPTER XIX. FOREIGN NATIONAL ACCESS XIX-1 CHAPTER XX. NNSA INTER-SITE NETWORK INTERCONNECTION APPROVAL PROCESS, APPROVAL AUTHORITY, AND CONNECTION REQUIREMENTS XX-1 Appendices APPENDIX A: ACRONYMS A-1 APPENDIX B: GLOSSARY B-1 APPENDIX C: CONTRACTORS REQUIREMENTS DOCUMENT C-1 APPENDIX D: RECOMMENDED ACTIONS FOR INFOCON LEVELS D-1 APPENDIX E: FACTORS INFLUENCING INFOCON E-1 APPENDIX F: OPERATIONAL IMPACT ASSESSMENT F-1 APPENDIX G: CONTINGENCY PLAN STRUCTURE G-1 APPENDIX H: RISK ASSESSMENT METHODOLOGY H-1 APPENDIX I: SAMPLE MEMORANDUM OF UNDERSTANDING (MOU) I-1 APPENDIX J: SAMPLE NNSA INTERCONNECTION SECURITY AGREEMENT J-1 iv NAP 14.1-C 05-02-08 Figures FIGURE VII-1. NNSA CYBER SECURITY INCIDENT REPORTING PROCESS VII-5 FIGURE VII-2. NNSA PII CYBER SECURITY INCIDENT REPORTING PROCESS VII-6 FIGURE VII-3. NNSA PII MANAGEMENT – LOST OR STOLEN DATA PROCESS FLOW VII-7 FIGURE XX-1. INTERCONNECTIVITY PROCESS FLOW XX-7 Tables TABLE VII-1. REQUIRED TIME FRAME FOR REPORTING INCIDENTS OF SECURITY CONCERN BASED ON IMPACT MEASUREMENT INDEX VII-2 TABLE VII-2. REQUIRED TIME FRAME FOR REPORTING CYBER SECURITY INCIDENTS TO THE INFORMATION ASSURANCE RESPONSE CENTER (IARC) VII-5 TABLE VIII-1. INFOCON LEVELS VII-3 TABLE XVI-1. APPROVED PROCESSES FOR MANAGING STORAGE MEDIA XVI-8 TABLE XVI-2. APPROVED PROCESSES FOR MANAGING ELECTRONIC MEMORY DEVICES XVI-9 TABLE XVI-3. APPROVED PROCESSES FOR MANAGING HARDWARE XVI-10 NAP 14.1-C 1 05-02-08 NNSA BASELINE CYBER SECURITY PROGRAM OVERVIEW 1. PURPOSE. a. Implement DOE O 205.1A, Department of Energy Cyber Security Management, and TMR-0, DOE Cyber Security Program Foundation in the National Nuclear Security Administration (NNSA) and all Elements under its cognizance. b. Establish an NNSA Program Cyber Security Plan (PCSP) that systematically integrates cyber security into management and work practices at all levels in the NNSA so that missions are accomplished while appropriately protecting all information on information systems.

Section 2

c. Establish requirements and assign responsibilities within the NNSA PCSP for protecting information on information systems. d. Ensure the NNSA PCSP is consistent with, and achieves the objectives of Executive Orders, National Security Directives, DOE Orders and Manuals, and Federal regulations. e. Establish a NNSA cyber security process that addresses program requirements, defines protection measures, provides cyber security planning, and implements the NNSA PCSP. f. Implement requirements in Public Law (PUB.L.) 100-235 (1987), the Federal Information Security Management Act of 2002 (FISMA), Presidential Directives and Executive Orders, Office of Management and Budget (OMB) directives, National Institute of Standards and Technology (NIST) Federal Information Processing Standards (FIPS), Departmental policies, and the DOE CIO Cyber Security Technical and Management Requirements (TMRs). 2. CANCELLATIONS. This NNSA Policy replaces NNSA Policy Letters (NAPs) 14.1-B, 14.2-B, 14.3-A, 14.4-A, 14.5-A, 14.6-A, 14.7A, 14.8A, 14.9A, 14.10A. 14.11-A, 14.12, 14.13, 14.14, 14.15, and 14.16. 3. APPLICABILITY. This NAP applies to all NNSA entities, Federal or contractors, that collect, create, process, transmit, store, and disseminate information on automated information systems for the NNSA. NNSA Elements. NNSA Headquarters (HQ) Site, Organizations, Service Centers, Site Offices, NNSA contractors, and subcontractors are hereafter referred to as NNSA Elements or sites. This NAP applies to all NNSA Elements. a. Information System. This NAP applies to any information system that collects, creates, processes, transmits, stores, and disseminates unclassified or classified 2 NAP 14.1-C 05-02-08 NNSA information. This NAP applies to any information system lifecycle, including the development of new information systems, the incorporation of information systems into an infrastructure, the incorporation of information systems outside the infrastructure, the development of prototype information systems, the reconfiguration or upgrade of existing systems, and legacy systems. In this document, the term(s) "information system," “cyber system,” or "system," are used to define any information system or network used to collect, create, process, transmit, store, or disseminate data owned by, for, or on behalf of, NNSA or DOE. b. Exclusions. (1) The Deputy Administrator for Naval Reactors shall, in accordance with the responsibilities and authorities assigned by Executive Order 12344, set forth in Public Law 106-65 of October 5, 1999, 50 U.S.C. 2406, and to ensure consistency throughout the joint Navy and DOE Organization of the Naval Reactors Propulsion Program, implement and oversee all requirements and practices pertaining to this Order for activities under the Deputy Administrators cognizance. (2) The NNSA PCSP does not apply to Sensitive Compartmented Information (SCI) information systems located at NNSA sites. SCI systems must comply with Director, Central Intelligence Directives (DCIDs), or Intelligence Community Directives (ICDs) security policies. The DOE Office of Intelligence and Counterintelligence approves operation of these information systems.

Section 3

(3) Implementation. A plan for the implementation of this NAP must be completed within 60 days after modification of the site’s contract to include this NAP. A plan for implementation of this NAP within an NNSA Federal organization must be completed within 60 days after issuance of this NAP. The implementation plan must include, at a minimum, the program activity to be modified and created; the starting date of revision or development; the estimated due date; and the responsible party for the stated activity. This implementation plan shall not exceed three years from the date of formal approval of the implementation plan. The implementation plan must be approved by the local NNSA Designating Approval Authority (DAA). This means that the NNSA Element’s Cyber Security Program (CSP) must comply with all requirements set forth in this NAP. Further, all information systems as defined in the Glossary must be protected in accordance with the requirements set forth in this NAP. 4. BACKGROUND. The loss or compromise of information entrusted to NNSA or its contractors may affect the National Security, the Nation's economic competitive position, the environment, NNSA missions, and other citizens of the United States. All NAP 14.1-C 3 05-02-08 information collected, created, processed, transmitted, stored, or disseminated by, or on behalf of, the NNSA on automated information systems requires some level of protection. Loss or compromise of information entrusted to NNSA or its contractors may affect the nation's economic competitive position, the environment, the National Security, NNSA missions, or the citizens of the United States. The risk management approach defined in the NNSA CSP provides for the graded, cost-effective protection of information systems containing unclassified or classified information. The NNSA NAP 14 series, NNSA Threat Statement, the NNSA Risk Assessment document, and the NNSA CSP comprises the NNSA PCSP. The NNSA PCSP systematically integrates cyber security into management and work practices at all levels in the NNSA so that missions are accomplished while appropriately protecting all information on information systems; establishes requirements and responsibilities for protecting information on information systems for the purpose of maintaining National Security and ensuring the continuity of NNSA operations; and ensures that NNSA cyber security is consistent with, and achieves the objectives of all applicable Executive Orders, National Security Directives, DOE Orders and Manuals, and Federal regulations. a. The PCSP is implemented through a CSPP for each NNSA Element. b. Risk management is a process that considers the prevailing NNSA threat analysis, the attributes of the information being protected, the effect of countermeasures in place and planned, and the remaining vulnerability of the processing environment (residual risk). c. The PCSP establishes minimum protection requirements based on the Consequences of Loss (CoL) of confidentiality, integrity, and availability of all information. d. Protection requirements for all information systems are documented in Information System Security Plans (ISSPs). e. The PCSP is consistent with other NNSA Directives and DOE Orders, Manuals, and Technical and Management Requirements that provide specific security requirements for information systems, including communications systems, transmission systems, as well as classified and unclassified matter through administrative procedures, logical access, and physical security requirements.

Section 4

f. The NNSA PCSP implements the following DOE cyber security policies and guidelines: • DOE P 205.1, Departmental Cyber Security Management Policy • DOE O 205.1A, Department of Energy Cyber Security Management • DOE M 205.1-4, National Security System Manual • DOE N 206.5, Response and Notification Procedures for Data Breaches Involving Personally Identifiable Information • DOE CIO TMR-0, DOE Cyber Security Program Foundation • DOE CIO TMR-4, Vulnerability Management 4 NAP 14.1-C 05-02-08 • DOE CIO TMR-6, Plan of Action and Milestones • DOE CIO TMR-8, Configuration Management • DOE CIO TMR-12, Wireless Devices and Information Systems • DOE CIO TMR-13, Portable and Mobile Devices • DOE CIO TMR-14, External Information Systems • DOE CIO TMR-18, Peer-to-Peer (P2P) Networking 5. REQUIREMENTS. NNSA Elements must implement and manage a risk-based CSP. Risk-based approaches, procedures, and other means must be used to evaluate and verify effectiveness of cyber security measures, identify areas requiring improvement, and validate implemented improvements. The following paragraphs address these approaches and procedures. a. Protection Measures. Protection measures for all NNSA information systems must conform to the protection measures described in the NNSA PCSP, the NNSA Element’s CSPP, and the ISSP. (1) Protection measures may be strengthened based on an assessment of unique local threat(s) or the local evaluation of CoL. (2) All Governmental information and any non-Governmental information on an NNSA information system must be considered when determining the system’s protection measures. b. Information Groups. An NNSA Information Group contains all information that requires similar protection or is similar in content, use, or sensitivity. All NNSA information must be identified as part of an NNSA-approved Information Group. Chapter V contains the definition of NNSA Information Groups and the mapping between the Information Groups and DOE cyber security enclave classes. Chapter XVII further details what information is considered to be Sensitive Unclassified Information (SUI), including Personally Identifiable Information (PII). c. Classified Information Access. Access to classified information must be granted only to persons with the appropriate access authorization and Need-to-Know in the performance of their duties according to NNSA policies and DOE M 470.4-4, Information Security. The individual disseminating the information is responsible for determining the recipient’s Need-to-Know in accordance with the site’s processes and NNSA policies and guidance. d. Unclassified Information Access. Access to unclassified information must be granted to only those persons who have the appropriate access authorization and Need-to-Know for the information in the performance of their duties. The individual disseminating the information is responsible for determining the recipient’s Need-to-Know in accordance with the site’s processes and NNSA NAP 14.1-C 5 05-02-08 policies and guidance. e. Knowledge and Resources. All NNSA Element personnel must possess the knowledge, skills, equipment, and resources to fulfill their cyber security responsibilities under both normal and emergency conditions. The primary roles and responsibilities of all applicable NNSA Element personnel are described in Chapter II.

Section 5

f. Facility Clearance and Registration. NNSA Elements with classified information systems must obtain prior approval access through the Facility Clearance and Registration Process, as outlined in DOE M 470.4-1, Safeguards and Security Program Planning and Management. g. Risk Management Process. The NNSA Element must implement the risk management process and requirements described in Appendix H. h. Configuration Management. The NNSA Element must implement NNSA Configuration Management (CM) policies and processes for all NNSA information systems within the Element, as described in Chapter III. i. Cyber Security Program Plan (CSPP). The NNSA Element must implement the CSPP processes and requirements described in Chapter IV. j. Deviations. Any deviation from the NNSA cyber security requirements and pr Serves as the DAA for all information systems whose perimeter or presence as described in an ISSP is wholly contained (Federal or contractor) under the cognizance of the NNSA Service Center. The Service Center Director/Manager’s DAA approval authority may be delegated to another Federal employee of the Service Center, or through a memorandum of agreement, to NNSA Federal employees at the NNSA Headquarters Site or a Site Office. Processes must be documented and approved, as described in Chapter VI. k. Incident Management. NNSA Elements must implement established requirements and responsibilities for cyber security incident preparation, prevention, warnings, reporting, and recovery from cyber security incidents involving NNSA information systems. l. INFOCON. NNSA Elements must implement established requirements and guidance for standardized procedures and responsibilities for authorizing and communicating Information Conditions (INFOCONs) within the Element, and to or from the NNSA Office of the Chief Information Officer (OCIO). m. Plan of Actions and Milestones (POA&M). NNSA Elements must implement established requirements for tracking and mitigation of CSP and system-level weaknesses identified at specific NNSA sites. n. Vulnerability Management. NNSA Elements must implement established NAP 14.1 -C 05-02-08 requirements for the development of a vulnerability management program, to include patch management procedures, for NNSA information systems. o. Foreign National Access. NNSA Elements must implement established requirements for allowing Foreign National Access to NNSA information systems to include, but not be limited to, computers, networks, associated servers, data storage devices, and portable or mobile devices. p. Portable Computing Devices. NNSA Elements must implement established requirements for the use of non-Government owned or Government-owned computing devices for NNSA and all organizations under its cognizance. q. Password Protection. NNSA Elements must implement established requirements for the generation, protection, and use of passwords to support authentication when accessing classified and unclassified NNSA information systems, applications, and resources. r. Wireless, Remote. and Peer-to-Peer (P2P) Networking Technolopies. NNSA Elements must establish minimum security controls as appropriate to protect NNSA information systems, applications, and software, when implementing wireless, remote, and P2P technologies. 6. DEFINITIONS. The Glossary in Appendix B defines the acronyms, abbreviations, and terms used in this document. 7. CONTACTS. Questions concerning this NAP should be directed to the Cyber Security Program Manager (CSPM), at 202-586-9728.

Section 6

BY ORDER OF THE ADMINISTRATOR: THOMAS P. D ' A G O S ~ O Administrator NAP 14.1-C I-1 05-02-08 CHAPTER I. NNSA PCSP OVERVIEW 1. INTRODUCTION. The requirements of the NNSA PCSP, as detailed in this NAP, apply to any information system or network that is used to collect, create, process, transmit, store, or disseminate information for the NNSA. The NNSA PCSP implements National and Departmental cyber security policies. 2. PCSP MANAGEMENT. While cyber security is everybody’s responsibility, there are several positions that have key roles in the NNSA PCSP. They are: 1) the CSPM; 2) the DAA; 3) the Information System Security Office Manager (ISOM); 4) the Information Systems Security Site Manager (ISSM); 5) the Information System Owner (ISO); and 6) the Information System Security Officer (ISSO). The roles and responsibilities for these positions are described in Chapter II. 3. CYBER SECURITY PROGRAM PLAN. Implementation of the NNSA PCSP is documented in a CSPP. A CSPP must be prepared for each NNSA Element, unless the Element is covered under another CSPP. The CSPP is the document that outlines the policies, procedures, and practices of an Element’s CSP. The CSPP is a management- level document that details the Element’s policies, procedures, and practices for ensuring effective cyber security. It also explains the site, or application-specific environment, missions, and threats. The policies, procedures, practices, environments, missions, and threats that are applicable to systems and major applications at the Enterprise level are documented in the NNSA Element’s CSPPs. 4. MINIMUM INFORMATION SYSTEM SECURITY CONFIGURATIONS. The NNSA PCSP requires all NNSA Elements to implement and maintain NNSA-approved minimum security configurations. The minimum security configurations for unclassified and classified information systems, as determined by the system categorization process, are listed in NAP 14.2-C, NNSA Certification and Accreditation (C&A) Process, Chapter III. Each NNSA Element must implement NNSA-specified or NNSA-approved monitoring capabilities to ensure that protection features defined in the approved minimum security configurations are maintained in the system. If the minimum security configuration cannot be implemented, this must be stated in the Risk Assessment for the system. The monitoring capability must provide continuous review and reporting of the status of the minimum security configuration specified for each information system. The monitoring capability must provide the ability to continuously detect and manage changes in software used in the information system components. If an information system cannot implement an NNSA-approved minimum information system security configuration due to operational or mission requirements, a new minimum security configuration must be developed and approved by NNSA CSPM. The minimum security configuration must provides assurance that all security measures I-2 NAP 14.1-C 05-02-08 are implemented and maintained in the information system, documented in the ISSP, and approved by the local NNSA DAA. 5. CERTIFICATION AND ACCREDITATION. The NNSA PCSP implements the National and Departmental requirements for the C&A of all information systems. The NNSA PCSP requires that each information system be accredited every three (3) years, or when significant changes have been made to the system, the system environment, the threat, or cyber security requirements, in response to changes in the NNSA PCSP. Each information system must receive an accreditation, i.e., approval to operate (ATO) or an interim approval to operate (IATO), before beginning operational activities. NAP 14.2- C, NNSA C&A Process, sets forth the requirements for the C&A program.

Section 7

6. INFORMATION SYSTEM SECURITY PLAN (ISSP). All information systems processing information at a site must be included as part of an ISSP, and they must receive an ATO or IATO before production. The ISSP is the basis for C&A process. The ISSP documents the security environment in which the information system exists, such as the cyber security requirements needed to protect the information on the system, and implementation of the cyber security requirements for formal accreditation of the information system. The ISSP must be tailored to address the characteristics of the information system, operational requirements, security policy, and prudent risk management throughout the system's lifecycle as conditions change. Required information for the ISSP is thoroughly described in NAP 14.2-C, NNSA C&A Process. NAP 14.1-C II-1 05-02-08 CHAPTER II. MANAGEMENT STRUCTURE AND RESPONSIBILITIES 1. INTRODUCTION. The NNSA PCSP is managed through a multi-tiered structure. The structure includes a CSPM, DAA, ISOM, ISSM, and an ISSO at NNSA Headquarters (HQ). ISOM(s), ISSM(s), and ISSO(s) are located at the NNSA Service Centers and NNSA Site Offices. The ISSMs and ISSOs may also be located at contractor locations. The structure also includes NNSA Enterprise Systems and Major Application Program Managers, Certification Agents (CAs), system owners, application owners, data owners, data stewards, and users of the systems. This chapter describes the roles and responsibilities of the individuals involved in the NNSA PCSP. 2. RESPONSIBILITIES. a. Administrator, National Nuclear Security Administration: (1) Retains ultimate accountability for cyber security and accepts the residual risk that exists within each of the NNSA Elements through the approval of the NNSA PCSP. (2) Appoints the NNSA CSPM, who is the focal point for cyber security within the NNSA. b. Associate Administrator for The Chief of Defense Nuclear Security: The Associate Administrator for the Chief of Defense Nuclear Security is responsible for the strategic direction and management of the cyber security program. c. NNSA Chief Information Officer (CIO). The CIO is responsible for the NNSA CSP and for overseeing security requirements. The CIO’s responsibilities include: (1) Ensures that cyber security is integrated into all policies and procedures used to plan, procure, develop, implement and manage the NNSA infrastructure and systems. (2) Ensures that cyber security is integrated into the NNSA Enterprise Architecture. (3) Ensures that architectures are consistent with current and planned computing and communication assets within the NNSA Enterprise. (4) Recommends a qualified person to the NNSA Administrator to fill the position of CSPM. (5) Makes and disseminates to NNSA sites determinations on the INFOCON for NNSA. II-2 NAP 14.1-C 05-02-08 d. Cyber Security Program Manager. The CSPM is responsible for managing the CSP within NNSA. The CSPM is required to spend a minimum of one week at each NNSA field location. (1) Serves as the DAA for all classified and unclassified information systems where perimeter or presence as described in an ISSP is wholly contained within the NNSA HQ Site and within contractor or subcontractor facilities under the cognizance of the NNSA HQ Site. The DAA may be delegated to another individual who must be a Federal employee of the Office of the NNSA CIO. The DAA’s authority may be assigned to other NNSA DAAs. All CSPM delegations and assignments by the CSPM must be documented in the NNSA HQ Site CSPP.

Section 8

(2) Approves the NNSA HQ Site CSPP. The CSPP approval authority may be delegated to another individual who must be a Federal employee of the Office of the NNSA CIO Element. (3) Ensures the appointment of an ISOM responsible for oversight of the implementation of the NNSA PCSP at the NNSA HQ Site, as well as at each contractor and subcontractor organization under the cognizance of NNSA HQ. Note that the ISOM and DAA for the NNSA HQ Site may be the same individual. (4) Ensures the appointment of an ISSO for each information system at the NNSA HQ Site. (5) Ensures the appointment of an ISSM to be responsible for developing and implementing the CSPP at the NNSA HQ Site. (6) Ensures the appointment of an ISSM to be responsible for ensuring the development and implementation of the CSPP in each contractor and subcontractor organization under the cognizance of the NNSA HQ Site. (7) Ensures that the NNSA PCSP is implemented at NNSA HQ Site. (8) Ensures that all NNSA HQ Site personnel that use information systems and systems data are aware of and fulfill their duties as described in the NNSA PCSP. (9) Approves all NNSA CSPPs from contractors and subcontractors under the cognizance of NNSA HQ. (10) Ensures that oversight reviews of all contractor and subcontractor sites (facilities) under the cognizance of NNSA HQ are conducted in accordance with the Survey (oversight) program defined in DOE M 470.4- 1. Also ensures that processes and programs allowing access to NAP 14.1-C II-3 05-02-08 information systems by Foreign Nationals are assessed as part of these reviews. (11) Ensures adequate resources are allocated to the HQ Site CSP. (12) Ensures that the effectiveness of the NNSA HQ Site CSP is monitored through self-assessments and reviews. (13) Ensures that the NNSA HQ Site DAAs, ISSMs, ISSOs, users, and System Administrators are trained in their specific duties, and the technologies for which they have responsibilities. (14) Ensures the implementation of the NNSA PCSP throughout NNSA. (15) Serves as the NNSA primary point of contact (POC) for cyber security. (16) Represents the NNSA PCSP before Federal, private, and public organizations concerned with protecting unclassified and classified Government information. (17) Serves as the DAA for all NNSA Enterprise information systems or Major Applications and other information systems or major applications with a perimeter or presence on different or multiple sites. This DAA authority may be assigned to other NNSA DAAs. All CSPM delegations and assignments must be documented. Ensures development and coordination of corrective actions plans involving NNSA Enterprise systems in response to issues identified by other Federal agencies (e.g., Office of Independent Oversight), peer reviews, and self-assessments. (18) Develops, coordinates, disseminates, and maintains NNSA NAPs and guidance on all aspects of the NNSA PCSP, including coordination with telecommunications security, TEMPEST, and Public Key Infrastructure (PKI) programs. (19) Annually reviews, and updates, as necessary, the NNSA Threat Statement, NNSA Cyber Risk Assessment, NNSA PCSP, and any NNSA-approved minimum information system configuration standards. (20) Establishes and coordinates NNSA cyber security training, education, and awareness programs. (21) Ensures that education in NNSA cyber security policies and practices is available to NNSA DAAs, ISOMs, ISSMs, ISSOs, Certification Agents (CAs), and system administrators. Ensures that this training is presented on a semi-annual basis.

Section 9

II-4 NAP 14.1-C 05-02-08 (22) Maintains an NNSA information assurance response capability. This capability maintains and coordinates NNSA cyber incident response procedures to provide timely assistance and system vulnerability information, watch and warning capabilities, analysis, and assistance reviews to all NNSA Elements. (23) Evaluates incident reports for NNSA Computer Network Attack (CNA), and Computer Network Exploitation (CNE) situations. (24) Recommends changes in NNSA INFOCON to the NNSA CIO. (25) Through the most rapid means possible, notifies NNSA Elements, through the cognizant DAAs, when the NNSA INFOCON is changed. (26) Provides copies of approved CSPPs to other organizations, as required in NNSA policies. (27) Monitors compliance and effectiveness of the PCSP through program reviews, budget reviews, self-assessments, management assessments, performance metrics and analysis, analysis of the results of peer reviews, vulnerability analysis, and independent oversight evaluations. (28) Coordinates with the Office of HSS, Office of Defense Nuclear Security, Nuclear Safeguards and Security Program Organization, and Office of Independent Oversight on monitoring implementation of the PCSP, through joint review of self-assessment and oversight documentation. (29) Coordinates with the DOE Office of Intelligence and Counterintelligence on cyber security matters that affect SCI systems at NNSA facilities. (30) Identifies NNSA cyber security resource requirements to ensure sufficient resources are planned and budgeted. (31) Coordinates with the NNSA Office of Planning, Programming, Budgeting, and Evaluation and the Chief Financial Officer (CFO) on budgets and expenditures related to NNSA cyber security. (32) Manages a cyber security technology development program to support the NNSA PCSP and to periodically brief NNSA Program Managers, DAAs, ISOMs, and ISSMs, on activities and results of the program. (33) Approves secure remote diagnostic and maintenance facilities proposed for use with information systems that process classified information for the HQ Element. NAP 14.1-C II-5 05-02-08 (34) Manages NNSA-wide cyber security incident reporting and response activities, in coordination with the Office of HSS, DOE Office of Associate Chief Information Officer (AOCIO) for Cyber Security, Defense Nuclear Security, the Nuclear Safeguards and Security organization, Office of Intelligence and Counterintelligence, or Office of Inspector General (OIG), as circumstances warrant. (35) Addresses differences and resolves conflicts between the NNSA program and the DOE-M 470.4-1 program. (36) Coordinates with the Office of HSS and the DOE Office of Associate CIO for Cyber Security on cyber security policy and the NNSA PCSP. (37) Coordinates, as needed, with DOE Office of Intelligence and Counterintelligence on: (a) Matters relating to policy and technical planning of counterintelligence activities. (b) Counterintelligence investigative activities. (c) Counterintelligence inspections, including evaluation of the CSP. (d) Counterintelligence threat information. (e) Matters related to the cyber threat. (38) Coordinates, as needed, with the DOE Office of the Inspector General (IG), on IG investigation activities involving NNSA information systems. (39) Coordinates, as needed, with the DOE Office of HSS on HSS inspection activities involving NNSA information systems.

Section 10

(40) Reports changes in ISOM and DAA appointments to all ISOMs and DAAs. (41) Supports, maintains, and coordinates an advice and assistance capability for use by any DAA, ISOM, or ISSM within NNSA. This capability includes the review of information systems protection measures as requested by the Element. (42) Approves NNSA cyber security waivers and exceptions. (43) Approves minimum security configurations for use in all NNSA Elements. II-6 NAP 14.1-C 05-02-08 e. Service Center Director: (1) Assumes responsibility and accountability for the NNSA Service Center CSP. (2) Serves as the DAA for all classified and unclassified information systems whose perimeter or presence as described in an ISSP is wholly contained (Federal or contractor) under the cognizance of the NNSA Service Center. The Service Center Director or Manager’s DAA approval authority may be delegated to another Federal employee of the Service Center, or through a memorandum of agreement, to NNSA Federal employees at the NNSA HQ Site or a Site Office. (3) Appoints in writing an ISOM responsible for oversight of the implementation of the NNSA PCSP in each NNSA Element (including the Service Center), under the cognizance of the NNSA Service Center. The DAA and ISOM responsibilities may be filled by one person. (4) Appoints in writing an ISSM responsible for oversight of implementation of the NNSA PCSP in the Service Center and each contractor and subcontractor organization under the cognizance of the NNSA Service Center. (5) Ensures development, implementation, and maintenance of a CSPP for the Service Center. (6) Ensures development and implementation of the CSPP at each contractor and subcontractor site under the cognizance of the Service Center. (7) Ensures that all Service Center personnel that use information systems and the information on the systems are aware of and fulfill their duties as described in the PCSP and the CSSP. (8) Ensures monitoring of cyber security effectiveness through self- assessments and reviews. (9) Ensures that adequate resources hosted within the Service Center are allocated for the conduct of the Service Center CSP and applicable Enterprise System Major Applications. (10) Ensures that Service Center DAAs, ISOMs, ISSMs, ISSOs, users, and System Administrators are trained in their specific duties and the technologies for which they have responsibilities. NAP 14.1-C II-7 05-02-08 f. Site Office Manager: (1) If the Site Office is not covered in another CSPP, ensures the development, implementation, and maintenance of a CSPP for the Site Office. (2) Assumes responsibility and accountability for the Site Office CSPs. g. DAA’s Representative (1) Serves as the DAA for all information systems whose perimeter or presence as described in an ISSP is wholly contained within an NNSA Site (Federal or contractor), under the cognizance of the NNSA Site Office. The Site Office Manager’s DAA approval authority may be delegated to other employees of the Site Office, or through a memorandum of agreement, to Federal employees of another Site Office or the NNSA Service Center. Note that this does not apply to HQ. (2) Under the cognizance of the NNSA Service Center, appoints in writing an ISOM responsible for oversight of implementation of the NNSA PCSP in each NNSA Element. The DAA and ISOM responsibilities may be filled by separate individuals.

Section 11

(3) Ensures the appointment of an ISSM responsible for developing and implementing the CSPP in the Site Office, unless the Site Office receives cyber security services from the Service Center. (4) Ensures the appointment of an ISSM responsible for developing and implementing the CSPP in each NNSA Element under their cognizance. (5) Ensures each information system in the Site Office has an appointed ISSO. (6) Ensures that all Site Office personnel that use information systems and system data are aware of and fulfill their duties. (7) Approves all NNSA CSPPs from NNSA Elements under the cognizance of the Site Office Manager. (8) Ensures that oversight reviews of all sites under the cognizance of the Site Office Manager are conducted in accordance with the Survey (oversight) program defined in DOE M 470.4-1. Ensures the process and program allowing access to information systems by Foreign Nationals is assessed as part of these reviews. (9) Under the ISOM’s purview, ensures adequate resources are allocated to the Site Office CSP and are applicable Enterprise System and Major Applications. II-8 NAP 14.1-C 05-02-08 (10) Monitors effectiveness of cyber security through self-assessments and reviews. (11) Ensures that Site Office DAAs, ISOMs, ISSMs, ISSOs, users, and System Administrators are trained in their specific duties and the technologies for which they have responsibilities. h. Contractors. Appendix C, Contractor Requirements Document (CRD), describes the responsibilities of contractors. i. Designated Approving Authority. The DAA is a Federal employee who has the authority to grant formal accreditation to operate, withdraw accreditation, suspend operations, grant IATOs, or grant variances when circumstances warrant. The approval shall be a written, dated statement of accreditation that sets forth clearly any conditions or restrictions to system operation. The DAA is the only individual who may accept all risks for systems under their cognizance. The DAA can delegate any of the following responsibilities to a DAA Representative (Rep), except the authority to grant accreditations or IATOs. DAAs are responsible and accountable for the security of the information and systems that the DAA accredits. Responsibilities of the DAA include: (1) Ensures that each system is properly accredited based on a) its environment and sensitivity levels, and b) a review and approval of security safeguards and the issuance of written accreditation statements. (2) Ensures that PCSP implementation within operating units under their cognizance. (3) Ensures that documentation is maintained for all information system accreditations under their purview. (4) Ensures that all appropriate roles and responsibilities are accomplished as required for each information system. (5) Ensures that operational information system security policies are promulgated for each system, project, program, and site for which the DAA has approval authority. (6) Should the DAA choose to accredit a system that does not have all security requirements implemented due to fiscal or operational restraints, the DAA may choose to accredit the system in accordance with interim approval criteria as stated in NAP 14.2-C, NNSA C&A Process, or accept any additional risk and issue a full approval to operate for the system. (7) Recommends approval for waivers and exceptions and forwarding such information to the CSPM as appropriate. NAP 14.1-C II-9 05-02-08

Section 12

(8) The DAA will ensure when a security patch cannot be applied. He or she must approve the Deviations Process and provide a copy to HQ. (9) Disseminates INFOCON status changes received from the CSPM. (10) Approves P2P applications during the C&A process. (11) Approves alternatives to tamper indicating devices for portable mobile devices. (12) Approves all products or software used to perform clearing, sanitization, or destruction of storage media. (13) Completes NNSA-sponsored DAA training within three (3) months of assuming the DAA position. The ISOM-designated Field DAA’s Representative must attend a two-week assignment at NNSA HQ. (14) Participates in an ongoing NNSA cyber security training and awareness program. (15) Ensures that Security Testing and Evaluation (ST&E) procedures are completed and documented. (16) Maintains appropriate system accreditation documentation. (17) Evaluates threats and vulnerabilities to ascertain whether additional safeguards are needed. (18) Ensures that all risks not mitigated are documented for DAA acceptance, and the Plans of Actions and Milestones (POA&M) are created, if applicable. (19) Ensures that a record of all security-related vulnerabilities and incidents is maintained. (20) Ensures that certification is accomplished for each NNSA information system, network, and application under their responsibility. (21) Evaluates certification documentation as required during C&A activities. (22) Ensures that all ISSMs and ISSOs receive technical and security education and training to carry out their duties. (23) Assesses changes in a system, its environment, and operational needs that could affect the accreditation. (24) Oversees and reviews periodically system security to accommodate possible changes that may have taken place. II-10 NAP 14.1-C 05-02-08 (25) Approves incident reporting procedures developed by the ISSM. (26) Determines the Levels of Concern (LOC) for confidentiality, integrity, and availability for the data on a system. (27) Ensures consideration and acknowledgement of counterintelligence activities during the C&A process. (28) Approves system disposal plans and procedures. j. Information System Security Officer Manager (ISOM). The ISOM is a Federal employee responsible for ensuring that operational security is maintained for information systems under the DAA’s cognizance throughout the life cycle of the systems. The ISOM is also responsible for coordinating security-related incident communications between the site, the Information Assurance Response Center (IARC), and NNSA HQ. The ISOM must have a working knowledge of system functions, cyber security policies, and cyber security protection measures. If an ISOM is not appointed, the DAA assumes the ISOM responsibilities, which may be delegated to a DAA Rep. Responsibilities of the ISOM include: (1) Evaluates security plans and ensures systems are operated, maintained, and disposed of in accordance with internal security policies and practices outlined in the ISSP. (2) Reports all security-related incidents to the IARC and DAA. (3) Initiates protective or corrective measures when a security incident or vulnerability is discovered. (4) Provides monthly incident status reports to the DAA and IARC. (5) Follows procedures approved by the DAA for authorizing software, hardware, and firmware use before implementation on the system. (6) Conducts periodic reviews to ensure compliance with the CSPP and ISSPs.

Section 13

k. Information Systems Security Site Manager (ISSM). The ISSM is a Federal employee appointed by the NNSA Element manager to be responsible for development of the Element’s CSPP and implementation of the Element’s CSP. The ISSM must have a working knowledge of system functions, cyber security policies, and cyber security protection measures. Any of the following duties may be delegated to an Alternate or Assistant ISSM. (1) Maintains record copies of the Element’s CSPP and ensures that the record copy of each ISSP is maintained for systems under their cognizance. NAP 14.1-C II-11 05-02-08 (2) Ensures appointments in writing of ISSOs for information systems operated by the NNSA Element and ensures that each ISSO and System Administrator is aware of and fulfills their cyber security duties as described in the PCSP and the Element’s CSPP. ISSOs are responsible to the ISSM for fulfilling their duties. (3) Ensures the development, documentation, and presentation of information systems security education, awareness, and training activities for Element management, cyber security personnel, application owners, data stewards, and users. (4) Ensures that users are trained on the information system cyber security features, operation, and safeguards prior to being allowed access to the system. (5) Ensures that training is available for ISSOs and System Administrators for information systems, cyber security requirements, operations, safeguards, Information Condition (INFOCON), and incident handling procedures. (6) Establishes, documents, and monitors the Element’s CSP implementation and ensures Element compliance with the NNSA PCSP. Upon completion of each assessment or review, the ISSM must ensure that a corrective action plan (CAP) is prepared and implemented for all findings or vulnerabilities. (7) Identifies and documents, in coordination with the organization’s Operations Security (OPSEC) program and Counterintelligence programs, Element-specific threats to information systems, and information at the site. (8) Develops and documents additional or modified protection measures for those threats and identifies any site-wide protection measures and practices that apply to all site systems. (9) Obtains approvals for modified protection measures from the DAA. (10) Ensures that the CSPP is coordinated with other site plans and programs to include: Disaster Recovery; Site Safeguards and Security Plan (SSSP) or Site Security Plan; Classified Matter Protection and Control; Physical Security; Personnel Security; Telecommunications Security; TEMPEST; Technical Surveillance Countermeasures; Operations Security; and Nuclear Materials Control and Accountability. (11) Ensures development of procedures to implement the Element’s CSP on all information systems. II-12 NAP 14.1-C 05-02-08 (12) If appointed as the CA, certifies to the cognizant DAA that the protection requirements described in the C&A Package for each information system have been implemented and are operational. (13) Ensures that the cognizant DAA is notified when the information system is no longer needed, or when changes occur that might affect the accreditation of the information system. (14) Participates in CSPM-sponsored cyber security training within three (3) months of their appointment. (15) Ensures development, documentation, and presentation of cyber security training for escorts in information systems operational areas.

Section 14

(16) Ensures that a DAA-approved overwrite method is used for clearing and sanitization, and that a review has been completed of the results of overwrites to verify that the method used completely overwrote all classified or sensitive information. (17) Ensures that each information system user acknowledges, in writing or electronically, their responsibility (Code of Conduct) for the security of information systems and information. (18) Communicates individual incident reports to the ISOM to allow the DAA to meet their reporting schedule. (19) Ensures examination and documentation of suspected cyber security incidents, categorization of incidents as Type 1, Type 2, or No Incident, and retention of documentation. (20) Ensures analyses of and corrective actions for incidents and findings with status reporting to the DAA. (21) Conducts self-assessments in accordance with the NNSA PCSP. (22) Ensures that each individual responsible for major applications within the NNSA Element is aware of and fulfills their cyber security duties, as described in the PCSP and the Element’s CSPP. (23) Recommends changes in the NNSA Element INFOCON status to the DAA. l. Information System Owner. The information system owner (ISO) is the person or Element responsible for acquiring, operating, or upgrading an information system. The ISO coordinates all aspects of the system for which they are responsible, from initial concept, through development, to implementation and system maintenance. The ISO is also responsible for identifying all information on the NAP 14.1-C II-13 05-02-08 system and is involved with FIPS – level determinations. The information system owner: (1) Ensures the preparation of the ISSP and the system C&A package. (2) Ensures the C&A of all information systems under their cognizance. (3) Ensures implementation of protection measures documented in the ISSP for each information system for which they are the ISSO. (4) Ensures that privileged users are granted access to information system resources based on the least privilege principle. (5) Identifies, in coordination with the ISSM, and documents in the ISSP, unique threats to information systems for which they are responsible. (6) Ensures that the CoL of confidentiality, integrity, and availability for the information is determined prior to use of an information system during the C&A process. (7) Notifies the ISSM of any changes to the CoL of confidentiality, integrity, and availability for the system. (8) Documents any special protection requirements identified by the application owner, data owner, or data steward and ensures that these requirements are included within the protection measures implemented in the information system. (9) For each information system for which they serve as the ISSO, ensures the information system is covered by an ISSP. (10) Maintains a copy of the ISSP for each information system for which they are the ISSO. (11) Ensures that all information system security-related documentation is current and accessible to properly authorized individuals. (12) Ensures the implementation of procedures as defined in the Element CSPP and the ISSP for each information system for which they are the ISSO. (13) Ensures that system recovery processes are monitored to ensure that security features and procedures are properly restored. (14) Ensures that the cognizant ISSM is notified when an information system is no longer needed or when changes occur that might affect the accreditation of the information system.

Section 15

II-14 NAP 14.1-C 05-02-08 (15) Ensures that information access controls and cyber protection measures are implemented for each information system as described by its ISSP. (16) Ensures that users and Systems Administrators are properly trained in information system security by identifying cyber security training needs and the personnel who need to attend the cyber security training program. (17) Conducts cyber security reviews and tests to ensure that cyber security features and controls are functioning and effective. (18) Participates in the ISSM’s self-assessment and training programs. (19) Ensures that risk assessment is completed for information systems for which they are responsible. (20) Communicates individual incident reports to the ISSM to allow the ISSM to meet their reporting schedule. (21) Ensures the implementation of all applicable protection measures for each information system for which they are responsible. (22) Ensures that unauthorized personnel are not granted use of, or access to, the information system. (23) Report immediately all security incidents and potential vulnerabilities involving the information to the appropriate ISSM. m. Information System Security Officer (ISSO). The following roles and responsibilities apply to all information systems for which the ISSO is responsible. The ISSP may be a privileged user. Multiple information systems may be assigned to a single ISSO. (1) Ensures implementation of protection measures documented in the ISSP for each information system for which they are the ISSO. (2) Ensures that privileged users are granted access to information system resources based on the least privilege principle. (3) Identifies, in coordination with the ISSM, and documents in the ISSP, unique threats to information systems for which they are responsible. (4) Ensures that the CoL of confidentiality, integrity, and availability for the information is determined prior to use of an information system during the C&A process. (5) Notifies the ISSM of any changes to the CoL of confidentiality, integrity, and availability for the system. NAP 14.1-C II-15 05-02-08 (6) Documents any special protection requirements identified by the application owner, data owner, or data steward and ensures that these requirements are included within the protection measures implemented in the information system. (7) Ensures each information system for which they are the ISSO is covered by an ISSP. (8) Maintains a copy of the ISSP for each information system for which they are the ISSO. (9) Ensures that all information system security-related documentation is current and accessible to properly authorized individuals. (10) Ensures the implementation of procedures as defined in the Element CSPP and the ISSP for each information system for which they are the ISSO. (11) Ensures that system recovery processes are monitored to ensure that security features and procedures are properly restored. (12) Ensures that the cognizant ISSM is notified when an information system is no longer needed, or when the changes occur that might affect the accreditation of the information system. (13) Ensures that information access controls and cyber protection measures are implemented for each information system as described by its ISSP. (14) Ensures that users and Systems Administrators are properly trained in information system security by identifying cyber security training needs and the personnel who need to attend the cyber security training program.

Section 16

(15) Conducts cyber security reviews and tests to ensure that cyber security features and controls are functioning and effective. (16) Participates in the ISSM’s self-assessment and training programs. (17) Ensures that risk assessment is completed for information systems for which they are responsible. (18) Communicates individual incident reports to the ISSM to allow the ISSM to meet their reporting schedule. (19) Ensures the implementation of all applicable protection measures for each information system for which they are responsible. (20) Ensures that unauthorized personnel are not granted use of, or access to, the information system. II-16 NAP 14.1-C 05-02-08 (21) Report immediately all security incidents and potential vulnerabilities involving the information to the appropriate ISSM. n. Enterprise System and Major Application Manager. The following items apply only to the Enterprise System and Major Application: (1) Ensures adequate resources are allocated for cyber security of the system or application. (2) Monitors the effectiveness of cyber security through self-assessments and reviews. (3) Ensures the development and maintenance of the Enterprise ISSP and the system certification and accreditation package. (4) Coordinates the ISSP with the involved NNSA Element managers. (5) Coordinates the ISSP with the Element’s ISSM. (6) Ensures the NNSA Elements’ ISSM, ISSO, users, and System Administrators involved with the Enterprise System and Major Application are trained in their specific duties and responsibilities with respect to the Enterprise System and Major Application. (7) Ensures that the record copy of the Enterprise System and Major Application ISSP is maintained. (8) Ensures the distribution, as needed, of the Enterprise System and Major Application ISSP to other NNSA Elements. o. Application Owners and Data Stewards. These roles and responsibilities apply to all information systems. (1) Determine and declares the sensitivity of the information prior to the information being created, processed, stored, transferred, or accessed on the information system. (2) Identify unique threats to their information and ensure that this information is forwarded to the ISSO and ISSM. (3) Advise the ISSO of any special confidentiality, integrity, or availability protection requirements for the information. (4) Ensure that the information is processed only on a system that is approved at a level appropriate to protect the information. NAP 14.1-C II-17 05-02-08 (5) Determine and document the data and application(s) essential to fulfill the organizational mission, and ensure that requirements for contingencies are determined, implemented, and tested. (6) Approve access to their information. (7) Ensure applications and/or data supporting Critical Infrastructure or Key Resources are identified. (8) Provide resources to support implementation and testing of contingency plans for the application data. (9) Provide resources to support Business Continuity for the application data. p. Users. The roles and responsibilities apply to all cyber assets. (1) Comply with the requirements of the NNSA PCSP, the NNSA Element’s CSPP, and the information system ISSP. (2) Be aware of, and knowledgeable about, their responsibilities in regard to information systems security.

Section 17

(3) Ensure that any authentication mechanisms, including passwords, issued for the control of their access to information and information systems, are not shared and are protected at the same level of protection applied to the information to which it permits access, and report any compromise or suspected compromise of an authenticator to the appropriate ISSO. Note that this approach would not apply for RSA tokens. (4) Be responsible and accountable for their actions on an information system. (5) Acknowledge, via electronic signature or in writing, their responsibilities (Code of Conduct) for protecting information systems and classified information. (6) Participate in training on the information system's prescribed security restrictions and safeguards before initial access to a system. Additionally, participate in an ongoing security education, training, and awareness program. (7) Immediately report all security incidents and potential threats and vulnerabilities involving the information system to the appropriate personnel. (8) Ensure that system media and system output are properly classified, marked, controlled, and stored. II-18 NAP 14.1-C 05-02-08 (9) Protect terminals from unauthorized access, as described in the information system ISSP. (10) Inform the ISSO when access to a particular information system is no longer required, for example, completion of a project, transfer, retirement, or resignation. (11) Observe rules and regulations governing the secure operation and authorized use of information systems. (12) Use the information system only for official government business or other activities authorized by NNSA or the NNSA Element manager. (13) Receive electronic or written permission from the DAA before any attempt to bypass or test security mechanisms. q. Privileged Users and System Administrators. (1) All privileged users must be responsible for all requirements stated for general users. (2) Privileged users are responsible to ensure that user access to the information system’s resources and information is based on the least privilege principle. (3) All privileged users must: (a) Be U.S. citizens, unless otherwise approved in accordance with the approved NNSA Element ISPP or in writing by the cognizant DAA. Foreign Nationals are explicitly prohibited from being privileged users on classified systems (b) Possess approvals of Need-to-Know for all information on the system. (c) Possess an Access Authorization sufficient for access to the highest classification and most restrictive category of data processed on the information system. (d) Use unique identifiers as described in the information system ISSP. (e) Protect the root or super-user authenticator at the highest level of data it secures. (f) Be responsible for all super-user or root actions under their account. NAP 14.1-C II-19 05-02-08 (g) Report any and all security relevant information system problems to the ISSO. (h) Use the special access or privileges granted only to perform authorized tasks and functions. r. Certification Agent (CA)/Certifier. The Certification Agent, or Certifier, is designated to perform security certification. The ISSM may fulfill the role of the CA. General duties of the Certifier include: (1) Ensures that risk assessments and security evaluations are completed prior to information system, network, and application certification.

Section 18

(2) Certifies the extent to which systems, networks and applications meet prescribed security requirements. (3) Prepares the certification report and, upon the completion of certification, forwards the report to the DAA through the CA, if the ISSM is not the CA, with their recommendation on accreditation. (4) Ensures Corrective Action Plans (CAPs) are prepared. (5) Maintains and provides other records and reports of certification activities, as necessary. (6) Reviews all information contained in the ISSP. (7) Conducts a comprehensive evaluation of the technical and non-technical security features of an information system and other safeguards made in support of the accreditation process to establish the extent to which a particular design and implementation meets a set of specified security requirements. (8) Submits recommendations on C&A package to the DAA. II-20 NAP 14.1-C 05-02-08 This page left intentionally blank. NAP 14.1-C III-1 05-02-08 CHAPTER III. CONFIGURATION MANAGEMENT 1. INTRODUCTION. Configuration Management (CM) applies administration, technical direction, and surveillance to identify and document functional and physical characteristics of a configuration item, to control changes, record and report change processing and implementation, and to verify compliance with specified requirements. Configuration management implements measures to ensure that protection features specified in NNSA-approved minimum information system security configurations are implemented in the system and maintained in the instantiation of system components by applying a level of discipline and control to the process of system maintenance and modification. The minimum set of security controls for unclassified and classified information systems, as determined by the system categorization, is detailed in NAP 14.2-C, Chapter III, NNSA Certification and Accreditation (C&A) Process. 2. REQUIREMENTS. The NNSA Element must implement the following NNSA CM processes for all information systems within the Element. a. Design documentation and any acquisition specifications that must identify the minimum security configuration for the information system, or applicable components of the information system requiring security configurations when being purchased. If it is necessary to develop alternative minimum security configurations due to operational or mission requirements, the new configuration must be selected from recognized sources of checklist-producing organizations, including NIST1, the National Security Agency (NSA)2, the DISA Security Technical Implementation Guides (STIGs), and the Center for Internet Security (CIS) benchmarks3. Such alternative configurations must be approved by the cognizant DAA. b. The Element’s CM procedures for maintaining documentation, tracking changes, approving configuration changes, and implementing vulnerability and patch management shall be described in the Element CSPP. c. The minimum set of security controls identified for an information system must be described in CM documentation which includes ISSPs, Contingency Plans, ST&E Procedures, user and administrative guidance, and system component inventories. 1 1 The NIST checklist repository is located at http://checklists.nist.gov/ . 2 The NSA’s checklists are available at http://www.nsa.gov/ia/. 3 CIS’s site is http://www.cisecurity.org/. III-2 NAP 14.1-C 05-02-08

Section 19

d. The Element’s CM procedures, monitoring capability to continuously detect and manage software changes, roles and responsibilities, and configuration identifiers shall be documented in a Configuration Management Plan(s) (CMP). The CMP shall describe the methodology and procedures used for configuration controls to include at a minimum, the following: (1) Identification of the roles and responsibilities for change approval or disapproval. (2) Information system and configuration item unique identification and labeling. (3) Configuration change identification, tracking, control, and history. (4) Configuration auditing and status accounting. (5) Vulnerability and patch management. (6) Security configuration checklist for operating system software, application software, and hardware platforms. (7) Documentation of the methodology and tools used to monitor configuration changes. e. Documentation of Minimum Security Configurations requires implementation of the minimum set of security controls is addressed, as required by the system’s security categorization. These controls are listed in NAP 14.2-C, NNSA Certification and Accreditation (C&A) Process. f. Organizations using Microsoft Windows XP and plan to upgrade to Vista must adopt the security configurations developed by the National Institute of Standards and Technology (NIST), the Department of Defense (DOD) and the Department of Homeland Security (DHS). g. If it is necessary to develop alternative minimum security configurations due operational or mission requirements, the new configuration must be selected from recognized sources of checklist-producing organizations, including NIST4, the National Security Agency (NSA)5, the DISA Security Technical Implementation Guides (STIGs), and the Center for Internet Security (CIS) benchmarks6. Such alternative configurations must be approved by the cognizant DAA. 2 4 The NIST checklist repository is located at http://checklists.nist.gov/ . 5 The NSA’s checklists are available at http://www.nsa.gov/ia/. 6 CIS’s site is http://www.cisecurity.org/. NAP 14.1-C IV-1 05-02-08 CHAPTER IV. CYBER SECURITY PROGRAM PLAN 1. INTRODUCTION. The NNSA CSPP is the document that outlines the policies, procedures, and practices of an organization's (e.g., an NNSA site) CSP—classified and unclassified. The CSPP is a top-level, stand-alone program document at the management level and details the organization's policies, procedures, and practices for ensuring effective cyber security. It also explains the organization's specific environment, missions, and threats. The CSPP will be integrated with other program plans in the Element, such as Site Safeguards and Security Plan (SSSP), and the Information Resource Management (IRM) plans. 2. CSPP CONTENTS. The CSPP must describe how the organization implements the NNSA PCSP. The CSPP must explain the organization’s specific environment, missions, and threats and describe the policies, procedures, and practices for ensuring effective cyber security. If the following requirements can be met with existing organization policies or procedures, they should be summarized and referenced in the CSPP and a copy attached to the CSPP. a. Environment. Describe the site’s mission, objectives, and security environment. b. Information Types and Groups. Identify the Information Types and/or Groups. See Chapter V for a description of the Information Types and/or Groups handled by the site.

Section 20

c. Site Unique Threats. Reference or document any threat or threat assessments used as the basis for its threat environment, such as the NNSA Threat Assessment, OPSEC Threat Assessments, and Site Unique Threats. d. Roles and Responsibilities. Define the cyber security roles and responsibilities for the site, such as the ISSM, ISSO, system administrator, Certification Agent, and general user. Cyber security training requirements for all participants are provided in CNSSD-500 Information Assurance (IA) Education, Training, and Awareness - dated August 2006; and NSTISSD-501 National Training Program for Information Systems Security (INFOSEC) Professionals - dated 16 November 1992. e. Program and Project Controls and Accountability. Describe the method for tracking the site's implementation of the NNSA PCSP in terms of cost and schedule. f. Plan of Actions and Milestones (POA&M). Describe the site’s process for tracking system-level weaknesses to include corrective action plans to track the completion of milestones. http://www.cnss.gov/Assets/pdf/CNSSD_500.pdf http://www.cnss.gov/Assets/pdf/nstissd_501.pdf IV-2 NAP 14.1-C 05-02-08 g. Information Systems. Reference an inventory of information systems: accredited, in the accreditation process, and not accredited. h. C&A Program. Describe the site’s information system C&A process to include processes for additional instantiations of accredited systems. Include (ISSP) format requirements. i. Equipment and Software Management. (1) Configuration Management. (a) Describe the site’s CM policies and procedures. (b) Identify any NNSA-approved minimum information system security configurations implemented in the Element’s information systems. (c) Describe the site’s process for identifying and managing information system configurations that cannot apply NNSA- approved minimum information system security configurations due to operational or mission requirements. (d) Describe the site’s process for planning, documenting, and managing system interconnections to include: i. Purpose and baseline configuration of the interconnection. ii. Methods used to meet the security requirements of interconnected systems and/or adjudicate security implementation differences between the systems. iii. Processes for mutual configuration management, change notification, maintenance, incident response, and operation of the interconnection. iv. Process for governing the creation, maintenance, and approval of Interconnection Agreements. (2) Equipment Maintenance. Describe the maintenance policies and procedures, including the introduction of vendor maintenance hardware, software and firmware, and the management of remote maintenance activities. (3) Sanitization – Clearing, Purging, and Destruction. Describe the Element’s management, operational, technical, and assurance controls for sanitization. NAP 14.1-C IV-3 05-02-08 Provide the DAA-approved process for the following: (a) Clearing, purging, and destroying information system storage media, memory devices, and other related hardware components. (b) Reuse of information storage media, memory devices, and other related hardware components at a lower classification or sensitivity level. j. Decommissioning. Describe the procedures for decommissioning information systems. k. Incident Handling. Describe the composition of the site incident response team, contact methods, such as telephone numbers, pagers, cell phones, e-mail, and incident handling and reporting procedures.

Section 21

l. Information Condition. Describe the process for establishing, changing, and reporting the site's INFOCON status. Describe the site's response measures for each INFOCON level. Describe the incident warning and advisory response process for the site. m. Security Monitoring. Describe the site’s security monitoring policies, processes, and procedures, including how monitoring is used to mitigate risks to the site. Describe the site’s processes and procedures for detecting and managing intrusion detection at the desktop, network, and site levels. n. Security Coordination. Describe the site’s process and procedures to ensure coordination with other security programs, such as physical security; personnel security; Technical Surveillance Countermeasures (TSCM); TEMPEST; Classified Matter Protection and Control (CMPC); Protected Transmission System (PTS); Operations Security (OPSEC); and Computer Security (COMSEC). o. Malicious Code. Describe the site’s process and procedures to address malicious code incidents (e.g., incidents handled at the boundary, at desktops, and at selected locations), the mechanisms employed, and frequency of updating anti- malicious code software throughout the site. p. Denial of Service and/or Continuity of Service. Describe the business impact analysis (BIA) process for identifying those information systems and networks that have a low tolerance for disruption or unavailability (system criticality), and the procedures and mechanisms that will be employed to limit and recover from such disruption or unavailability. IV-4 NAP 14.1-C 05-02-08 q. Internet Security. Describe the site’s Internet use policy, method of securing the site’s network from external threats via the Internet connection, policies and procedures for reviews of Web page and server content, as well as Web page and server monitoring policy. r. E-mail. Describe the site’s e-mail policy, including controls for the use of offsite e-mail. s. Component and Output Marking and Labeling. Describe the site’s policy for marking and labeling the sensitivity or classification levels of computers, computer equipment, media storage devices, and computer output. t. Clear Text Password Management. Describe the site’s program for the elimination of clear text passwords from existing and future information systems. u. Data Backup and Restoration. Describe the site’s policies for data backup and restoration. v. Disaster Recovery Program. Describe the site's disaster recovery program, including integration of information systems, Continuity of Service plans, and the procedures for regular testing of continuity of operations and contingency plans. w. Output and Display Device Access. Describe the site's policies for controlling access to system output and display devices. x. Portable Hardware and Software Technical Reviews. Describe the process for performing technical reviews of the hardware and software components of portable computers that are taken or used outside the U.S. or may have been under the control of a non-U.S. Government organization. y. Portable Computing Devices. Describe the policies and procedures for managing the use of portable computing devices in all areas of the site. z. External Information Systems. Describe the policies and procedures for managing the use of external information systems in all areas of the site.

Section 22

aa. Wireless Information Systems. Describe the policies and procedures for managing installation and use of Radio Frequency (RF) and Infrared (IR) systems in all areas of the site. ab. Risk Management. Describe the site's process for risk management for all information systems and information system components. ac. Remote Access. Describe management, operational, technical, and assurance controls for remote access. NAP 14.1-C IV-5 05-02-08 ad. Training. Describe the process for cyber security training and awareness programs, including who must receive training and how frequently re-training will occur. Describe the methodology being used for training, such as briefings or e-mail. Identify those positions requiring training, and identify by title or position those responsible for overseeing training activities at the site. ae. Performance Assessment. Describe the site’s process and metrics employed to assess compliance with the CSPP and the process for evolving these metrics. Describe the site's peer review and self-assessment processes, including frequency of reviews, the process for selecting peer review members, qualifications required of the prospective individuals or entities, and who is responsible for selecting peer review participants. af. Plan Change Management. Describe the update frequency for the CSPP and the process for updating the plan. ag. Downloading Unclassified Files from an Unclassified System. Describe the procedure for downloading unclassified data from classified system. IV-6 NAP 14.1-C 05-02-08 This page intentionally left blank. NAP 14.1-C V-1 05-02-08 CHAPTER V. INFORMATION GROUPS 1. INTRODUCTION. Unclassified Information and National Security Information Groups contain all information that requires similar protection or is similar in content or use. The following have been defined for use in assessing the cyber threats to information, and for use in defining the minimum protection criteria. a. Unclassified Information Types. (1) Open, Public, and Unrestricted Access. Information that requires no protection from disclosure, such as information approved for public release. (2) Unclassified Protected. Unclassified information that has been determined by the data owner or data steward to require additional protection due to its sensitive subject matter or impact to Departmental or organizational missions. (3) Unclassified Mandatory Protection and SUI. Information requiring additional protections as mandated by policy or laws, such as the following: (a) Privacy Act information. (b) Agreements between DOE, NNSA, its contractors, and other entities, such as commercial organizations or foreign governments, i.e., Cooperative Research and Development Agreement (CRADA). (c) Proprietary information (but not third party proprietary). (d) Unclassified Controlled Nuclear Information (UCNI). (e) Export-controlled information (ECI). (f) Naval Nuclear Propulsion Information (NNPI). (g) Military and dual use information, such as the Critical Military Technology and Materials list identified by the Department of Defense (DOD). (h) Nonproliferation information. (i) Official Use Only. (j) Personally Identifiable Information (PII) – Refer to Chapter XVII for a complete definition of PII. V-2 NAP 14.1-C 05-02-08 b. National Security Systems Information Groups.

Section 23

(1) Confidential or Secret Non-Nuclear Weapons. Information classified Confidential National Security Information, Confidential Restricted Data, Confidential Formerly Restricted Data, Secret National Security Information, or Secret Formerly Restricted Data and does not contain any nuclear weapons data but may contain information related to uranium enrichment. (2) Secret Restricted Non-Nuclear Weapons Data. Information classified Secret Restricted Data and does not contain any nuclear weapons data, but it may contain information related to uranium enrichment or other Secret Restricted Data. (3) Confidential Restricted Data Sigmas 1 through 13, and 15, and 20. Information classified as Confidential and identified as Restricted Data, Formerly Restricted Data, or is related to nuclear weapons. This information is further marked with at least one of the sigma categories 1 through 13. (a) Sigmas 1 and 2. Theory of operation or complete design of hydrodynamic, nuclear, fission weapons or their unique components. This includes the high explosive system with its detonators and firing unit, pit system, and nuclear initiation system as they pertain to weapon design and theory. (b) Sigmas 3, 4, 5, 9, 10, 11, 12, and 13, 15 and 20. Manufacturing and utilization information not comprehensively revealing the theory of operation or design of the physics package; information inherent in pre-shot and post-shot activities necessary in the testing of atomic weapons or devices; production rate and/or stockpile quantities of nuclear weapons and their components; general studies not directly related to the design or performance of specific weapons or weapons systems such as reliability studies, fusing studies, damage studies, aerodynamic studies; chemistry metallurgy, and processing of materials peculiar to the field of atomic weapons or nuclear explosive devices; Information concerning inertial confinement fusion that reveals or is indicative of weapon data; Theory of operation or complete design of the nuclear energy converter, energy director, or other nuclear directed energy weapon outside the radiation case of the nuclear source but within the envelope of the nuclear directed energy weapon concept; and manufacturing and utilization information for nuclear energy converters, directors, or other nuclear directed energy weapon outside the nuclear source radiation case, not comprehensively revealing the theory of operation or design of the nuclear directed energy weapon concept. NAP 14.1-C V-3 05-02-08 (4) Secret Restricted Data Sigmas 1 through 13.. Information classified as Secret and identified as Restricted Data and related to nuclear weapons. This information is further marked with at least one of the Sigma categories 1 through 13, 15, and 20. (a) Sigmas 1 and 2. Theory of operation or complete design of hydrodynamic, nuclear, fission weapons or their unique components. This includes the high explosive system with its detonators and firing unit, pit system, and nuclear initiation system as they pertain to weapon design and theory.

Section 24

(b) Sigmas 3, 4, 5, 9, 10, 11, 12, and 13. Manufacturing and utilization information not comprehensively revealing the theory of operation or design of the physics package; information inherent in pre-shot and post-shot activities necessary in the testing of atomic weapons or devices; production rate and/or stockpile quantities of nuclear weapons and their components; general studies not directly related to the design or performance of specific weapons or weapons systems – reliability studies, fusing studies, damage studies, and aerodynamic studies; chemistry and metallurgy, and processing of materials peculiar to the field of atomic weapons or nuclear explosive devices; information concerning inertial confinement fusion that reveals or is indicative of weapon data; theory of operation or complete design of the nuclear energy converter, energy director, or other nuclear directed energy weapon outside the radiation case of the nuclear source but within the envelope of the nuclear directed energy weapon concept; and manufacturing and utilization information for nuclear energy converters, directors, or other nuclear directed energy weapon outside the nuclear source radiation case, not comprehensively revealing the theory of operation or design of the nuclear directed energy weapon concept. (c) Sigma 15. The category of sensitive information concerning design and function of nuclear weapons use control systems, features, and their components. This includes use control information for passive and active systems. (d) Sigma 20. The category of nuclear weapon data that pertains to sensitive improvised nuclear device information. (5) Secret Restricted Data Sigma 14. Information that is classified as Secret and identified as Restricted Data or is related to nuclear weapons. Sigma 14 is the category of sensitive information concerning the vulnerability of nuclear weapons to deliberate unauthorized nuclear detonation. V-4 NAP 14.1-C 05-02-08 (6) Top Secret. Information classified Top Secret NSI, Top Secret FRD, or Top Secret Restricted Data that does not pertain to Nuclear Weapons. (7) Top Secret Restricted Data. Nuclear Weapon information classified Top Secret. (8) Special Information Groups. These Information Groups contain Confidential or Secret Restricted Data (or other National Security data) that the US Government, DOE, or NNSA have determined that special or additional protection is necessary. NAP 14.1-C VI-1 05-02-08 CHAPTER VI. NNSA CYBER SECURITY PROGRAM DEVIATIONS 1. INTRODUCTION. This chapter describes the types of deviations, such as variances, waivers, and exceptions, required justifications, and the process for obtaining deviations from the NNSA PCSP requirements. 2. CRITERIA AND PROCESSES. All approved deviations, as described below, must be documented in the ISSP for the information system, the SSSP, or the Site Security Plan, as appropriate. a. Variances. Variances are approved conditions that technically vary from a NNSA PCSP requirement but afford equivalent levels of protection. (1) Variance requests must be submitted in writing to the DAA. The variance request must include a detailed description of the requirement(s) and rationale. The variance documentation must be referenced in the ISSP. (2) The cognizant DAA will review and approve in writing, or the cognizant DAA will disapprove with comments and recommendations.

Section 25

(3) Variances may be approved for up to three (3) years and documented in the ISSP, but they must be submitted for reconsideration whenever the information system is accredited or re-accredited. b. Waivers. Waivers are approved, non-standard conditions that deviate from a NNSA PCSP requirement, which, if uncompensated, would create a potential or real cyber security vulnerability. Waivers require implementation of compensatory measures that will be in effect for the duration of the waiver. (1) Waiver requests and supporting documentation must be submitted in writing to the cognizant DAA for review. (2) Documentation supporting the waiver request must identify the requirement(s) to be waived, indicate the compensatory measures implemented, and, if appropriate, indicate that performance testing has been completed to validate the compensatory measures. (3) The DAA will forward the waiver request and documented recommendation for approval to the NNSA CSPM. (4) The NNSA CSPM will approve or disapprove the waiver request and provide a final decision in writing to the cognizant DAA. (5) The cognizant DAA will notify the ISSM. VI-2 NAP 14.1-C 05-02-08 (6) Approved waivers may remain in effect for up to the expiration of the C&A, which may be less than two years to a maximum of three years. Approved waivers must be referenced in the ISSP. If an extension is necessary, the waiver request must be re-submitted. c. Exceptions. Exceptions are approved deviations from an NNSA PCSP requirement that creates a security vulnerability. Exceptions shall only be approved when correction of the condition is not feasible or cost effective and compensatory measures are inadequate to preclude the acceptance of risk by the cognizant DAA. (1) Requests for exceptions and supporting documentation must be submitted in writing to the cognizant DAA for review. (2) Documentation supporting the exception request must identify the requirement(s) that cannot be met, indicate any compensatory measures implemented, and, if appropriate, indicate that performance testing has been completed to validate the compensatory measures. (3) The DAA will forward the exception request and documented recommendation for approval to the NNSA CSPM. (4) Exceptions must be documented in the ISSP. (5) The NNSA CSPM, or higher authority, will approve or disapprove the exception request and provide a final decision in writing to the cognizant DAA. (6) The cognizant DAA will notify the ISSM. (7) Approved exceptions may remain in effect for one year. (8) The cognizant DAA must review and validate the need for each exception. NAP 14.1-C VII-1 05-02-08 CHAPTER VII. INCIDENT MANAGEMENT 1. INTRODUCTION. This chapter establishes the minimum criteria and processes for reporting and responding to cyber security incidents involving NNSA information systems. 2. REPORTING CRITERIA AND PROCESSES. a. Reportable Cyber Security Incidents. The site’s CSPP must document the processes for reporting cyber security incidents that are IMI-1 and IMI-2. Cyber security-related incidents must be coordinated with Safeguards and Security. In addition, cyber security-related incidents must be reported that meet one or more of the following criteria: (1) Incidents of Security Concern. Report the cyber security aspects of the following Incidents of Security Concern involving National Security Systems, as adapted from DOE M 470.4-1, Safeguards and Security Program Planning and Management.

Section 26

(a) Impact Measurement Index (IMI-1). Report incidents that pose an immediate danger or short-term threat to National Security interests and/or critical NNSA or DOE assets, that potentially create a serious security situation, or that create high media visibility interest. The following cyber security incidents must be reported according to the procedures in this NAP, in addition to the reporting requirements in DOE M 470.4-1. These incidents must be reported within one working hour of discovery. (i) Confirmed or suspected loss, theft, diversion, or unauthorized release of Weapon Data contained in an information system or on cyber media. (ii) Confirmed or suspected loss, theft, diversion, unauthorized release of TOP SECRET information or Special Access Program (SAP) information contained in an information system or on cyber media. (iii) Confirmed or suspected intrusions, hacking, or break-ins into NNSA information systems containing TOP SECRET or SAP information. (b) Impact Measurement Index (IMI-2). Report incidents that pose a near- or long-term threat to National Security interests and/or critical NNSA or DOE assets, or incidents that potentially create a crisis or dangerous situation. The following cyber security incidents must be reported according to the procedures in this VII-2 NAP 14.1-C 05-02-08 NAP, in addition to any other reporting. These incidents must be reported within eight working hours of discovery. (i) Confirmed or suspected intrusions, hacks, or break-ins into NNSA information systems or cyber media, containing Confidential Non-Nuclear Weapons Information or Secret Restricted Data Information. (ii) Confirmed or suspected intrusions, hacking, or break-ins into NNSA information systems or cyber media containing Confidential Non-Nuclear Weapons Information or Secret Restricted Data Information. (iii) Loss of classified information that must be reported to other Government agencies or foreign associates. (iv) The loss of any DOE classified information involving NNSA information systems or cyber media, which requires State or local government or other Federal agency notification. (c) Impact Measurement Index (IMI-3). Report incidents that pose long-term threats to NNSA or DOE security interests, or incidents that could potentially degrade the overall effectiveness of the NNSA or the Department's protection programs. The following cyber security incidents must be reported according to the procedures in this NAP, in addition to any other reporting. These incidents must be reported within eight working hours of discovery. (i) Confirmed or suspected unauthorized disclosure, loss or potential loss of CONFIDENTIAL matter via intrusions, hacking, or break-ins into NNSA information systems or cyber media. (ii) Confirmed or suspected unauthorized disclosure, loss/potential loss of Unclassified Mandatory Protection Information via intrusions, hacking, or break-ins into NNSA information systems or loss/potential loss of cyber media. Table VII-1 on the following page provides the incident reporting requirements for Incidents of Security based on the IMI. NAP 14.1-C VII-3 05-02-08 Table VII-1. Required Time Frame for Reporting Incidents of Security Concern Based on Impact Measurement Index IMI Designation Time Frame IMI-1 Within 1 working hour of discovery IMI-2 Within 8 working hours of discovery IMI-3 Within 8 working hours of discovery

Section 27

(2) Incidents of NNSA Cyber Security Concern. These incidents must be reported based on the Type and System Impact Category, as defined below. Incidents may be, but are not limited to, the result of cyber security alerts received and investigated by the site. (a) Type 1 incidents are successful incidents that potentially create serious breaches of DOE and/or NNSA cyber security, or have the potential to generate negative media interest. The following are the currently defined Type 1 incidents. (i) Compromise or Intrusion. All unintentional or intentional instances of system compromise or intrusion by unauthorized persons must be reported, including user- level compromises, root (administrator) compromises, and instances in which users exceed privilege levels. (ii) Web Site Defacement. All instances of a defaced Web site must be reported. (iii) Malicious Code. All instances of successful large network site-wide infection, or persistent attempts at infection by malicious code, such as viruses, Trojan horses, or worms, must be reported. (iv) Denial of Service. Intentional or unintentional denial of service (successful or persistent attempts) that affects or threatens to affect a critical service, or that denies access to all or one or more large portions of a network, must be reported. (v) Critical Infrastructure Protection (CIP). Any activity that adversely affects an asset identified as critical infrastructure must be reported. NNSA CIP assets are determined by the NNSA Administrator. (vi) Unauthorized Use. Unauthorized use should be construed as any activity that adversely affects an information system’s normal, baseline performance and/or is not recognized as being related to NNSA’s mission. For VII-4 NAP 14.1-C 05-02-08 example, unauthorized use can be using a DOE or NNSA computer to obtain Government data without authorization. Unauthorized use can involve using systems to break the law. Unauthorized use includes, but is not limited to, port scanning that excessively degrades performance. Note that these activities may only be performed when authorized by the DAA: IP (Internet protocol) spoofing; network reconnaissance; monitoring; hacking into servers; running traffic-generating applications that generate unnecessary network broadcast storms or drive large amounts of traffic to computers; or using illegal (or misusing copyrighted) software images, applications, data, and music. (b) Type 2 incidents are attempted incidents that pose potential long- term threats to DOE and/or NNSA cyber security interests, or that may degrade the overall effectiveness of the Department’s cyber security posture. The following are the currently defined Type 2 incidents. (i) Attempted Intrusion. A significant and/or persistent attempted intrusion that stands out above the daily activity or noise level, as determined by the system owner, and that would result in unauthorized access (compromise) if the system were not protected. (ii) Reconnaissance Activity. Persistent surveillance and resource mapping probes and scans that stand out above the daily activity or noise level and represent activity that is designed to collect information about vulnerabilities in a network and map network resources and available services.

Section 28

b. System Impact Categories. System impact categories characterize the potential impact of incidents that compromise DOE or NNSA information and information systems. Such incidents may impact DOE or NNSA operations, assets, individuals, missions, or reputations. System impact categories identify the level of sensitivity and criticality of information and information systems by assessing the impact of the LOC, integrity, and availability. Performing this impact analysis is a fundamental step in risk assessment. Each of the security objectives, such as confidentiality, integrity, and availability, is assessed according to categories in Table VII-2 on the following page. (1) Low Impact. Loss of system confidentiality, integrity, and availability could be expected to have a limited adverse effect on DOE or NNSA operations, assets, or individuals, requiring minor corrective actions or repairs. NAP 14.1-C VII-5 05-02-08 (2) Moderate Impact. Loss of system confidentiality, integrity, and availability could be expected to have a serious adverse effect on DOE or NNSA operations, assets, or individuals, including significant degradation or major damage, requiring extensive corrective actions or repairs. (3) High impact. Loss of system confidentiality, integrity, and availability could be expected to have a severe or catastrophic adverse effect on DOE and NNSA operations, assets, or individuals. The incident could cause the loss of mission capability for a period that poses a threat to human life or results in the loss of major assets. Table V11-2. Required Time Frame for Reporting Cyber Security Incidents to the Information Assurance Response Center (IARC) System Impact Category Incident Type Low Moderate High Type 1 Within 4 hours Within 1 hour Within 1 hour Type 2 Within 1 week Within 24 hours Within 24 hours Personally Identifiable Information (PII)* Within 35 minutes Within 35 minutes Within 35 minutes * Based on mandated reporting requirements for PII, all suspected or confirmed incidents involving PII must be reported within 35 minutes regardless of the Type or System Impact. See definition and examples in Appendix XVIII for further clarification. Figure VII-1 illustrates the process for reporting NNSA cyber security incidents. For PII, see Figures VII-2 and VII-3. VII-6 NAP 14.1-C 05-02-08 Figure VII-1. NNSA Cyber Security Incident Reporting Process NAP 14.1-C VII-7 05-02-08 Figure VII-2. NNSA PII Cyber Security Incident Reporting Process VII-8 NAP 14.1-C 05-02-08 Figure VII-3. NNSA PII Management – Lost or Stolen Data Process Flow c. The cognizant ISOM must be notified within 24 hours of discovery of an incident by the NNSA site. Monthly reports on the status of incident resolution, whether or not any reportable, successful, or attempted incidents have occurred during the month, must also be transmitted to the ISOM. d. Cyber Security Incident Report Content. The content and format of an incident report will be specified by the IARC. At a minimum, incident reports must include date(s), time(s), type, source, corrective actions taken, if any, resources affected, site impact, and site point-of-contact. Sources may vary depending on the type of attack, but may include Internet Protocol (IP) address, e-mail address, or other identifying source characteristics. Additional content may be specified by the DAA and/or IARC, as incident situations change.

Section 29

e. Incidents Involving PII. All suspected or confirmed cyber security incidents involving PII as defined in Appendix B, Definitions, must be reported to the NAP 14.1-C VII-9 05-02-08 IARC within 35 minutes of discovery. Discovery is defined as the moment that the CSSM or their staff have determined that a reported incident could involve PII. This notification can be verbal or written via e-mail. As additional information is discovered pertaining to the incident, the impacted site must provide IARC with the updated information within 35 minutes. Note that if a primary impacted site has solicited the assistance of another secondary site during the investigation, the primary site has the responsibility for reporting all information to the IARC. f. Archiving Cyber Security Incident Information. Sites must store all information related to a reportable incident, as defined in paragraph 2.a of this chapter for at least one year. Storage methods, including custody, must comply with applicable evidentiary requirements for possible future law enforcement use. g. Counterintelligence Reporting. Events identified in DOE O 475.1, Counterintelligence Program, must be reported by the IARC to the Office of Intelligence and Counterintelligence (OICI), in accordance with the reporting procedures in DOE O 475.1. h. Automated Systems. Automated systems may be used to implement these protocols. 3. CIAC CYBER SECURITY ALERTS. Cyber security alerts issued by CIAC shall be investigated, analyzed, and reported as an incident. Positive feedback from the sites is required in response to an alert, and the incident reporting mechanism provides the necessary information. VII-10 NAP 14.1-C 05-02-08 This page intentionally left blank. NAP 14.1-C VIII-1 05-02-08 CHAPTER VIII. INFORMATION CONDITION (INFOCON) 1. INTRODUCTION. This chapter describes the minimum preparations and actions required to react uniformly to warnings of cyber security incidents, heighten or reduce the cyber defensive posture, defend against computer network attacks, and mitigate sustained damage to NNSA information and infrastructure, including computer and telecommunications networks and systems. The INFOCON is a comprehensive defense posture and response based on the status of information systems, NNSA operations, and intelligence assessments of adversary capabilities and intent. The INFOCON system impacts all personnel who use NNSA information systems, protects systems while supporting mission accomplishment, and coordinates the overall defensive effort through adherence to standards. The INFOCON system presents a structured, coordinated approach to react to adversarial attacks on NNSA information, computer systems, and networks and systems. While all systems are vulnerable to some degree, factors such as low-cost, readily available information technology, increased system connectivity, and remote access capability make Computer Network Attack (CNA) an attractive option to an adversary. CNA is defined as “operations to disrupt, deny, degrade, or destroy information resident in computers and computer networks, or the computers and networks themselves.” INFOCON also outlines countermeasures to scanning, probing, and other suspicious activity, unauthorized access, and data browsing. NNSA INFOCON measures focus on computer network-based protective measures due to the unique nature of CNA. Each level reflects a defensive posture based on the risk to NNSA operations through the disruption of information systems and networks.

Section 30

2. CRITERIA AND PROCESSES. a. Each NNSA site's INFOCON response measure must be documented in the site’s CSPP. b. INFOCON procedures must be well integrated with the site’s Security Condition (SECON) procedures, emergency procedures, Continuity of Operations plans, and incident handling processes. c. Cyber security incidents must be reported as described in Chapter VII. d. DAAs may evaluate their situation and recommend changes in the INFOCON to the NNSA Site Manager for sites under their cognizance; however, the INFOCON must remain at least at high as the current INFOCON directed by NNSA. If the NNSA Site Manager agrees to the recommended change in INFOCON status, the DAA must report the change to the CSPM within 4 hours. e. The CSPM will notify DAA when the NNSA INFOCON is changed, through the most rapid means available, and must notify the CSPM if recommended or directed INFOCON response measures conflict with organization or mission priorities within 2 hours of NNSA determination of INFOCON response measures. f. The DAA must disseminate INFOCON information within their organization and VIII-2 NAP 14.1-C 05-02-08 to organizations under their cognizance, through the most rapid means available. 3. NNSA INFOCON. Several critical assumptions were made about the nature of CNA and Computer Network Exploit (CNE) in developing the NNSA INFOCON system. Understanding these assumptions is essential to effective implementation of this system. a. Shared Risk. In today’s network-centric environment, risk assumed by one NNSA site is risk shared by all. Unlike most other security activities, a successful network intrusion in one NNSA location may, in many cases, facilitate access at other locations. This necessitates a common understanding of the situation and responses associated with the declared NNSA INFOCON. These actions must be carried out concurrently at all NNSA locations for an effective defense. b. Advance Preparation. Preparation is key, given the speed and reduced signature of CNA and CNE. Protective measures must be planned, prepared, exercised, and often executed well in advance of an attack. Preventive measures are emphasized in INFOCON responses because there may be little time to react effectively during the attack. Prevention of system compromise is preferable but may not be achievable. c. Anonymity of Attacker. Attributing the attack to its ultimate source, if possible, will normally not occur until after the attack has been executed. This limits the range and type of options available to INFOCON decision makers. To effectively operate in this environment, knowledge of the adversary’s identity cannot be a prerequisite to execution of defensive strategies and tactics. d. Characterization of the Attack. Distinguishing between hacks, attacks, system anomalies, and operator error may be difficult. The most prudent approach is to assume malicious intent until an event is assessed otherwise. See Chapter VII for various assessments to consider. e. INFOCON Levels. The NNSA INFOCON system presents a structured, coordinated approach to defend against and react to adversarial attacks on NNSA information, computer systems, and telecommunication networks and systems. The NNSA INFOCON system identifies the five levels of CNA and CNE conditions within NNSA, as shown in Table VIII-1. Table VIII-1. INFOCON Levels NAP 14.1-C VIII-3 05-02-08 INFOCON Level Description RED (Critical)

Section 31

Successful information system attack(s) detected that impact NNSA operations such as a Type 1 compromise and/or intrusion or DOS, with a moderate or high impact. Widespread incidents that undermine ability to function effectively. Significant risk of mission failure. Computer Network Attack against national infrastructure or National Security element. YELLOW (Elevated) Indications and warnings (I&W) indicate targeting of specific system, location, unit, or operation. Significant level of network probes, scans, or activities detected, indicating a pattern of concentrated reconnaissance. Network penetration or DOS attempted with no impact to NNSA or DOE operations, such as Type 2 attempted intrusion with a low impact. Incident occurs at NNSA site that affects an NNSA Enterprise System, or it may impact another NNSA site, such as a Type 1 compromise and/or intrusion with a low impact. Intelligence indicates imminent attack against NNSA or DOE site. BLUE (Guarded) I&W indicate general threat. Regional events occurring that affect U.S .interests and are likely to affect NNSA interests. May involve potential adversaries with suspected or known CNA capability. Information system probes, scans, or other activities detected indicating a pattern of surveillance, such as Type 2 reconnaissance activity with a moderate or high impact. Nation-or Internet-wide computer network exploits, such as a Type 1 Web site defacement, malicious code, or denial of service (DOS), with an impact of low. Increased and/or more predictable threat events. Incident occurs at NNSA or DOE site. GREEN (Normal) No significant activity. Normal operations. Network penetration or denial of service attempted with no impact to NNSA, DOE, or site operations such as Type 2 reconnaissance activity or intrusion attempts with a low impact. Minimal attack success, successfully counteracted, such as a Type 1 unauthorized use with a low impact. General threat unpredictable. 4. INFOCON ACTIVITIES. VIII-4 NAP 14.1-C 05-02-08 a. Determining the INFOCON. There are three broad categories of factors that influence the INFOCON: operational, technical, and intelligence, including foreign intelligence and law enforcement intelligence. Some factors may fall into more than one category. The INFOCON level is based on significant changes in one or more of them. Appendix C describes several factors that may be considered when determining the INFOCON. The decision to change the INFOCON should be tempered by the overall operational and security context at that time. For example, an intruder could gain unauthorized access and not cause damage to systems or data. This may only warrant INFOCON BLUE or GREEN during peacetime, but it may warrant INFOCON ORANGE during a crisis. Also, the incident may warrant a high INFOCON at the affected site but not throughout the NNSA as a whole. b. Declaring INFOCONs. The NNSA CSPM will recommend changes in NNSA INFOCON to the NNSA CIO, who is responsible for declaring an NNSA INFOCON. Assimilation and evaluation of information to assess the CNA and CNE situation NNSA-wide will be a collaborative effort coordinated by the CSPM. c. Managers of NNSA sites are responsible for assessing the situation and establishing the proper INFOCON, based on evaluation of all relevant factors. See Appendix D and E for criteria and guidance, respectively. NNSA site managers may change the INFOCON of their organizations or site(s); however, they must remain at least as high as the current INFOCON directed by NNSA. Managers changing the INFOCON of their organization or site(s) must report to the CSPM using the same reporting format described in paragraph 4.d of this chapter.

Section 32

d. Response Measures. Ideally, CNA/CNE operations will be based on advanced warning of an attack. Measures should be commensurate with the risk, the adversary’s assessed capability and intent, and mission requirements. Over- aggressive countermeasures may result in self-inflicted degradation of system performance and communication ability, which may contribute to the adversary’s objectives. Managers must also consider what impact of imposing a higher INFOCON for their organization will have on connectivity with computer networks and systems of other NNSA sites and operations. Managers will notify the CSPM, through the cognizant ISOM, if recommended or directed response measures conflict with organization or mission priorities. Regardless of the INFOCON level declared at the affected site, it is incumbent upon the affected site to report all unauthorized accesses in a timely manner, in accordance with the NNSA PCSP. Each NNSA site shall have documented procedures to guide their responses and ensure these procedures are well integrated with other site SECON, emergency procedures, and Continuity of Operations plans. See Appendix D and E for recommended action activities. NAP 14.1-C VIII-5 05-02-08 e. Reporting. Reporting of cyber security incidents must be accomplished as described in Chapter VII. Note, however, that INFOCONs assess potential and/or actual impact to NNSA operations and must be reported as follows: (1) Reporting Channels. NNSA sites must report INFOCON changes to the NNSA CSPM and the cognizant DAA. (2) Reporting Frequency. NNSA sites must report INFOCON changes for their sites no later than 4 working hours after the INFOCON has changed. Provide whatever information is available at the time and indicate information that is unknown or unavailable. Information missing from the initial report will be forwarded in a follow-up report within 24 hours of the initial report. (3) Report Formats. Reports of changes in INFOCON should be accompanied by an operational assessment of the situation, when appropriate. Appendix E outlines a process for assessing the operational impact of a CNA. Report contents shall include, as a minimum: (a) For all INFOCONs: Organization and location, date and time of report, current INFOCON, reason for declaration of this INFOCON, response actions taken, and POC name and contact information. (b) INFOCON YELLOW and Higher. All of the above, plus U. S. Computer Emergency Response Team (CERT) or NNSA IARC Number (IARC will report to CIAC) and Law Enforcement Agency (LEA) case number, with POC name and contact information, when available. (c) INFOCON ORANGE and Higher: All of the above, plus system(s) affected; degree to which operational functions are affected; impact (actual and/or potential) on current and planned missions; and/or general capabilities; restoration priorities; and workarounds. f. Dissemination of NNSA INFOCON. The CSPM will notify the DAA when the NNSA INFOCON is changed, through the most rapid means available. The DAA sites must notify the CSPM, if recommended or directed INFOCON response measures conflict with organizational or mission priorities, within two (2) hours of NNSA determination of INFOCON response measures. NNSA sites are responsible for rapid dissemination of the INFOCON information within their organization, and to contractor organizations under their cognizance. Notification will include the following information: (1) Date and time of report.

Section 33

(2) Current INFOCON. VIII-6 NAP 14.1-C 05-02-08 (3) Reason for declaration of this INFOCON that includes a detailed description of the causal activities and Type and System-Impact Category. (4) Current and planned operation(s) or capabilities, units and/or organizations, networks, systems, applications, or data assessed to be impacted or at risk. (5) Recommended or NNSA-directed actions. (6) References to relevant technical advisories and intelligence assessments (7) POC information. (8) Information that may assist sites in their response times. See Appendices D and E. 5. RELATIONSHIP OF INFOCON TO OTHER ALERT SYSTEMS. The INFOCON and SECON may complement each other. The INFOCON may be changed based on the national or global situation, the intelligence community’s level of concern, or other factors. Likewise, a change in INFOCON may prompt a corresponding change in other alert systems. EXERCISES. INFOCON procedures shall be practiced at all NNSA sites as part of their self- assessment program to include operational impact assessments. See Appendix D and E.. NAP 14.1-C IX-1 05-02-08 CHAPTER IX. PLAN OF ACTIONS AND MILESTONES. 1. INTRODUCTION. This chapter documents the minimum requirements for establishing a management tracking tool for the documentation and correction of security program and system-level findings and incidents. The primary intent of the Plan of Action and Milestones (POA&M) is to assist NNSA management with tracking and mitigating program weaknesses. Additionally, the POA&M assists external regulatory agencies with oversight responsibilities. A finding is a determined vulnerability pertaining to technology, operations, and/or people that allow compromise to an organization’s information or associated information systems. Findings are identified through various activities, such as risk management, self assessment, audits, and ST&E processes. All NNSA Elements must develop, document, and implement POA&M policies and procedures consistent with the following requirements and commensurate with the level of security required for the organization’s environment and specific needs. This chapter is compliant with DOE TMR-6, Plan of Action and Milestones. 2. CRITERIA AND PROCESSES. a. POA&M Content Requirements. Each NNSA Element must define a site-specific POA&M process in their respective CSPPs. The Element’s POA&M documentation must include the following information, at a minimum: (1) Reporting all program and system-level findings identified by the Office of HSS, the General Accounting Office (GAO), the Office of Inspector General (OIG), and other outside external regulatory agencies. Findings or incidents identified by internal assessment activities, security reviews, or operations are tracked by the POA&M at the determination of the DAA. (2) Tracking program and system-level findings with open Corrective Action Plans (CAPs). (3) Validating and associated documentation of closure for each POA&M finding. (4) Integration of the POA&M process with the internal self-assessment program. (5) Identification of the office or organization responsible for tracking and reporting of POA&M information to the NNSA OCIO, on at least a quarterly basis. IX-2 NAP 14.1-C 05-02-08 (6) Process used to assess POA&M activities on at least a quarterly basis.

Section 34

(7) Once the POA&M has been reported, changes are allowed to be made to the original description of the finding, key milestones, schedule completion dates, or source under the direction of the DAA. Notations for any modifications to the original entry are to be made separately, and identified as “Changes to Milestones.” (8) POA&M Reports are to be marked and protected as appropriate; at a minimum, reports are to be considered Official Use Only (OUO). b. Corrective Action Plans. Not all identified findings tracked in the POA&M will have corresponding CAPs. Note, however, that all findings will have associated mitigation milestones tracked within the POA&M. Each NNSA Element must document CAPs at a minimum for any cyber security-related finding identified by the Office of Inspector General and the Office of HSS. If the finding has not been closed within a year of its determination, the NNSA CSPM or cognizant DAA may require that other program or system-level findings be documented in the CAP, based on its impact. c. CAP Content. For documented cyber-security-related findings, and for program and/or system-level weaknesses that require corrective action plans, CAP must contain, at a minimum, the following content: (1) A brief overview and summary of the identified weakness, vulnerability, or finding. (2) Root cause analysis, addressing any systemic program weaknesses. (3) Mitigation and resolution and recurrence prevention strategies. (4) Office or organization responsible for remediation. (5) Resource requirements and expected costs associated with remediation. For system-level POA&Ms, the unique project identifier and project name from the OMB Exhibit 300 or Exhibit 53, where applicable; and for Exhibit 53 systems, the security costs must also be included. (6) Scheduled start and completion date. (7) At least one major milestone and estimated completion date. NAP 14.1-C IX-3 05-02-08 d. CAP Requirements. In addition to documenting the CAP, as outlined above, the responsible office or organization must also complete the following activities for each CAP. (1) Risk assessment and acceptance, approval, and communication to impacted organizations and personnel. (2) Track and update implementation status for each CAP milestone, as directed by the cognizant DAA. (3) Verify and document the closure of each CAP milestone. (4) Coordinate the independent validation of milestone completions as directed by the cognizant DAA. e. POA&M Reports. In accordance with FISMA requirements, NNSA Elements (to include the NNSA HQ Element, must develop, implement, and manage POA&Ms for all cyber security weaknesses and vulnerabilities requiring corrective action, whether or not a CAP has been prepared. POA&M Reports must contain, at a minimum, the following content: (1) A brief overview and summary of the identified weakness, vulnerability, or finding. (2) Office or organization responsible for remediation. (3) Scheduled start and completion date. (4) At least one major milestone and completion date. (5) Reported closure of findings and milestones, as validated by someone other than the individual responsible for documenting and tracking the milestones. The POA&M must include the following: (a) Date of closure. (b) Finding or milestone closure validated? (Yes or No). (c) Name, position, and title of validating individual. (d) Date of validation. f. POA&M Assessment Requirements. IX-4 NAP 14.1-C 05-02-08

Section 35

(1) POA&M-related activities must be tracked, reviewed, and prioritized on at least a quarterly basis. Reviews must include verification that all applicable findings are being tracked and managed. (2) An assessment of POA&M activities must be conducted when there are changes in organizational roles responsible for POA&M activities; when new Departmental guidance is issued; and/or new findings are identified via an audit, internal review, or self-assessment. g. Minimum POA&M Reporting Requirements. (1) POA&M Reports must include program-and system-level findings identified by the Office of HSS, the GAO, the OIG, and other outside external regulatory agencies, as well as any findings and/or weaknesses identified by internal assessment activities or security reviews. (2) POA&M Reports must include required documentation needed for each system-level finding, such as self-assessments, risk assessments, security plans, certification and accreditation, and contingency plans. (3) POA&M Reports must include closed findings and milestones for up to one year after formal and validated closure. (4) NNSA Elements required to report remediation progress on findings and milestones as required by the cognizant DAA, but they are not to report less frequently than quarterly as required by the Office of Management and Budget (OMB). NAP 14.1-C X-1 05-02-08 CHAPTER X. VULNERABILITY MANAGEMENT 1. INTRODUCTION. This chapter establishes the minimum requirements for developing a vulnerability management program, including patch management, for NNSA information systems. Vulnerability management is a measurable, proactive process implemented to secure information systems and to improve regulatory compliance posture. Patch management is one method for addressing vulnerabilities. Note that, because not all vulnerabilities have applicable patches, it is essential that security controls, such as remediations, be implemented based on an analysis of possible vulnerabilities associated with an information system. In addition, such controls help to mitigate the impact of a successful exploitation of an unknown vulnerability. This chapter applies to all NNSA Elements that operate and manage information systems that collect, create, process, transmit, store, and/or disseminate unclassified and classified NNSA information. 2. CRITERIA AND PROCESSES. a. Cyber Security Program Plan. Each NNSA Element must address the following vulnerability management program Elements in its site CSPP. (1) Vulnerability management activities, including processes for analyzing, detecting, communicating, and remediating vulnerabilities, as well as interfaces to incident management and configuration processes. (2) The roles and responsibilities of all key personnel responsible for decisions and activities regarding vulnerability management. (3) Awareness, training, and education requirements for all key personnel responsible for vulnerability management activities. b. Vulnerability Management Program. Each NNSA Element must implement a vulnerability management program that addresses at a minimum the following requirements: (1) Identification, analysis, and dissemination of vulnerability information. (2) An inventory of information technology resources, including hardware, operating systems, and software applications, used in the organization. (3) Remediation strategies and processes. (4) Prioritization of vulnerability remediation or mitigations.

Section 36

(5) A standardized vulnerability naming scheme. (6) Vulnerability documentation to include POA&M Reports and incident management, as required. X-2 NAP 14.1-C 05-02-08 (7) Metrics for testing the effectiveness of the vulnerability management program. (8) Communication and coordination processes, including internal and external reporting of vulnerabilities and remediation. (9) A process for identifying, documenting, and communicating lessons- learned regarding vulnerability scanning processes and remediation. (10) Risk-based standards establishing scan frequency, techniques, and technologies. (11) A documented vulnerability scanning process that includes the following at a minimum. (a) Organizational element(s) responsible for conducting vulnerability scanning activities. (b) Frequency of scanning activities; critical assets and servers must be scanned quarterly. (c) Identification and prioritization of scanning targets. (d) Alternate examination methodologies for resources for which operations and production cannot be interrupted. (e) Identification of resources that cannot be scanned from a central network location. c. Patch Management Process. Each NNSA operating unit must implement a patch management process that includes at a minimum the following requirements: (1) Patch prioritization based on criticality of system, network, and specialized tooling. (2) Testing procedures for patch installation. (3) Procedures for automated and manual patch deployment. (4) Identification of those resources that cannot be patched from a central network location. (5) Patch installation verification processes and methods. (6) Documentation of residual risk acceptance and integration with CM processes. (7) Scheduling to ensure that all assets are scanned twice annually, and critical assets and servers are scanned quarterly. NAP 14.1-C XI-1 05-02-08 CHAPTER XI. PORTABLE COMPUTING DEVICES RESERVED – THIS CHAPTER WILL BE DEVELOPED AT A LATER DATE. XI-2 NAP 14.1-C 05-02-08 This page intentionally left blank. . NAP 14.1-C XII-1 05-02-08 CHAPTER XII. PASSWORD GENERATION, PROTECTION, AND USE 1. INTRODUCTION. This chapter establishes minimum criteria and processes for the generation, protection, and use of passwords to support authentication when accessing classified and unclassified NNSA information systems, applications, and resources. This chapter applies to any multi-user information system at a NNSA site that collects, stores, transmits, or processes unclassified or classified information, and uses passwords to authenticate users or applications. 2. CRITERIA AND PROCESSES. a. Password Generation and Verification. Password generation or verification software must ensure that passwords are generated using the following features: (1) Passwords contain at least eight non-blank characters. (2) Passwords contain a combination of letters, preferably a mixture of upper and lowercase numbers, and at least one special character within the first seven positions, provided such passwords are allowed by the operating system or application. (3) Passwords used on information systems that collect, store, transmit, or process classified information must be machine generated, or use DAA- approved alternative methods of authenticating users or generating passwords. (4) Passwords employed by a user on unclassified information systems must be different than passwords employed by the same user on classified information systems.

Section 37

(5) Two-factor authentication should be required for all privileged users, accounts, and actions. b. Password Protection. (1) Passwords used to access information systems processing classified data must be protected at a level commensurate with the classification level and most restrictive category of the information to which they allow access. (2) Passwords used to access information systems processing unclassified data must be protected in accordance with the information with the highest impact level for confidentiality or integrity on the system to which they allow access. XII-2 NAP 14.1-C 05-02-08 (3) Passwords must not: (a) Contain the User Account Identifier (User ID). (b) Contain any common English dictionary word, spelled forward or backwards; dictionaries for other languages may also be used if justified by risk and cost benefit analysis, as documented in the approved ISSP or the CSPP. (c) Employ common names, including the name of any fictional character or place, spelled forward or backwards. (d) Contain any commonly used numbers, such as the employee serial number, Social Security number, birth date, or telephone number associated with the user of the password. (e) Contain any simple pattern of letters or numbers, such as “qwertyxx” or “xyz123xx.” (4) In cases of user-created passwords on unclassified information systems, ensure through verification software and training that selected passwords are consistent with password requirements listed in paragraphs 2a. and b. above. (5) When an information system cannot prevent a password from being echoed, as in a half-duplex connection, an overprint mask must be printed before the password is entered to conceal the typed password. (6) Individuals must not: (a) Share passwords except in emergency circumstances or when there is an overriding operational necessity, as described in the information system's approved ISSP or the site’s CSPP. (b) Enable applications to retain passwords for subsequent reuse, except as described in the information system's approved ISSP. (c) Create their passwords if the password is used for access to classified information. (d) Use group passwords, such as a single password used by a group of users, without some other mechanism that can assure accountability, such as separate and unique network User ID. NAP 14.1-C XII-3 05-02-08 (e) Share group passwords outside the group of authorized users. Group passwords must be changed when any individual in the group is no longer authorized to access the information system where the group password is used. Group passwords must never be reused. c. Standard Passwords. User software, including operating systems and other security-relevant software, may be supplied with standard identifiers, such as System, Test, and Master, and passwords already enrolled in the system. Passwords for all standard identifiers must be changed before allowing the general user population access to the information system. These passwords must be changed after a new system version is installed or after other action is taken that might result in restoration of these standard passwords. d. Password Changing. Passwords must be changed: (1) At least every 6 months. (2) Immediately, but within one business day, after a password has been shared, compromised, or after the user suspects that a password has been compromised. (3) On direction from management or the DAA.

Section 38

e. Administration. The information system, application, or resource where passwords are used for user authentication must, where technically feasible, ensure: (1) Five consecutive failed attempts to provide a legitimate password for an access request results in an access lockout. The process for restoration of an account must be documented or referenced in the approved ISSP. (2) The user password, whether user-selected or automatically generated, is rejected if the password does not meet the criteria in this chapter. (3) Before expiration or lockout will occur, individuals are notified that their passwords are about to expire and must be changed. (4) Any file, folder, database, or other collection of one or more user passwords is protected from access by unauthorized individuals. (5) Periodic monthly or quarterly validation of conformance to password policy, as directed by site policy. f. Clear Text Passwords. The use of clear text passwords must be eliminated from all information systems, applications, and resources. XII-4 NAP 14.1-C 05-02-08 (1) Each NNSA Element’s CSPP shall include a plan, with schedules and milestones, to eliminate the use of clear text, reusable passwords from existing electronic information systems and resources. (2) Each NNSA Element shall develop procedures to ensure that clear text, reusable passwords are removed from new information systems, applications, and resources before the systems, applications, or resources are placed into production use. (3) Other mitigation strategies must be in place and must automatically result in a POA&M. g. Pass-phrase and Entropy-based Passwords. In situations where Pass phrases or entropy-based passwords are used, password generation or verification software must ensure that such passwords meet the following criteria. h. Pass phrases must contain 25 or more characters and at least 2 special characters, and must not begin or end with a special character. i. Password generation based on an entropy approach must comply with the guidance for a Level 1 Authentication Mechanism as described in NIST SP 800- 63, Electronic Authentication Guideline: Recommendations of the National Institute of Standards and Technology 3. CRITERIA AND PROCESSES FOR PRIVILEGED USERS a. Privileged Users. Privileged Users are individuals who have access to system control, monitoring, or administration function, such as system administrators, information system security officers, maintainers, and system programmers. b. Privileged accounts. Privileged accounts are accounts belonging to Privileged Users. Privileged accounts are created for users to perform privileged functions only; that is, privileged users use non-privileged accounts for all non-privileged functions. The use of mandatory multi-factor authentication process is required for system administrator and privileged user access to systems where passwords are used as one authentication method. . NAP 14.1-C XIII-1 05-02-08 CHAPTER XIII. WIRELESS TECHNOLOGIES

Section 39

1. INTRODUCTION. This chapter establishes the minimum security controls that are to be enforced by NNSA sites using wireless technologies to ensure that security risks posed by wireless applications, devices, and network implementations are analyzed appropriately, and controlled. This chapter applies to any wireless technologies that collect, store, transmit, process, create, or disseminate unclassified or classified NNSA information. In addition, this chapter applies to any wireless technology lifecycle, including development of new wireless applications, incorporation of wireless devices into an infrastructure, incorporation of wireless devices outside the infrastructure, development of prototype wireless technologies, and the reconfiguration or upgrade of existing wireless technologies and legacy systems. Land mobile radios, one-way receive- only devices, and mobile satellite services are excluded from this chapter. 2. CRITERIA AND PROCESSES. In order to ensure that security risks posed by wireless technologies are sufficiently analyzed and appropriately controlled, NNSA sites must establish a systematic process for managing risks posed by wireless technologies, and ensure that the process is described fully in their CSPP. The process must: a. Identify the roles and responsibilities of all personnel responsible for the decision whether to incorporate wireless into the environment, including personnel responsible for telecommunications; TEMPEST; Protected Transmission Systems (PTS); and Technical Surveillance Countermeasures (TSCM) program compliance. b. Evaluate the business needs for deploying wireless technologies, to include cost- benefit analysis, and whether more secure technologies, such as expansion of the wired network, are feasible. c. Include a risk assessment to evaluate risks to the confidentiality, integrity, and availability of site information resources, in the context of exposing information to the hazards associated with utilizing wireless networking devices, and the entire spatial volume through which the transmitted signal is capable of being received. National Institute of Standards and Technology (NIST) Special Publication (SP) 800-48, Wireless Network Security 802.1, Bluetooth and Handheld Devices, may be used to assist in decision making. d. Ensure that risks for connecting to site LANs are evaluated, and security controls are in place to protect systems and LANs. e. Evaluate planned wireless networking applications, with respect to specific wireless technologies, physical location on site, proximity to sensitive or classified information processing areas, connectivity of wireless devices to site computers and networks, and the Information Groups and information systems connected to wireless information systems. XIII-2 NAP 14.1-C 05-02-08 f. Identify specific security mechanisms implemented through technical, operational, management, and assurance controls that will ensure risk is maintained at an acceptable level, and the schedule for testing such controls to ensure they operate as intended. At a minimum, these controls must: (1) Require semi-annual performance reviews to ensure accuracy of access point inventory, security of configurations, or identification of unauthorized devices. (2) Require proper installation and physical control of all access points. (3) Ensure NIC and access-point firmware is up-to-date. (4) Ensure that only authorized people can reset the access points.

Section 40

(5) Assign strong passwords to access points. In addition, access points must be administered via the site’s wired network, or locally via the access point’s built-in COM ports. (6) Utilize static IP addresses for clients and access points. (7) Ensure the capability to detect transmissions by unauthorized access points and/or wireless clients is in place and operational before authorized use. (8) Require the regular application of patches and security enhancements. (9) Adopt strong encryption methods that encompass end-to-end encryption of information as it passes throughout the wireless network. Use Type II or III products to encrypt transmission of information to or from non- National Security Systems. (10) Address the DOE TEMPEST/Technical Security Countermeasures (TSCM) concerns, such as wireless, audio, video, and infrared, when allowing operation of these devices in security areas. g. NNSA Elements utilizing wireless technologies accredited for use with National Security Systems must implement, at a minimum, the following controls: (1) The wireless device must not be used to download or load any shareware, extraneous software, or unauthorized freeware. (2) The wireless device must not be synchronized with any unclassified system. NAP 14.1-C XIII-3 05-02-08 (3) Wireless networks must support security for voice, data, and control channel information, only via approved Type 1 encryption for all modes of operation. (4) Wireless networks must be monitored to detect unencrypted signals transmitted from areas where classified information is being electronically stored, processed, or transmitted, to ensure that unauthorized signals are not transmitted beyond approved boundaries. (5) Wireless networks must use security mechanisms compatible and interoperable with those mechanisms used on wired voice and data telecommunication networks and computing devices. (6) Wireless networks must implement identification and authentication measures at both the device and network level. XIII-4 NAP 14.1-C 05-02-08 This page intentionally left blank. NAP 14.1-C XIV-1 05-02-08 CHAPTER XIV. REMOTE ACCESS 1. INTRODUCTION. Remote access is defined as accessing an information system, at the system or application level, from a location outside the confines of a network, as defined in each site’s CSPP. This chapter does not address risks associated with or criteria and processes specific to wireless networks and devices. Criteria and processes for these are addressed in Chapter XI. Remote access to NNSA information and systems can promote cost-effective benefits to the NNSA mission and workforce. At the same time, remote access can introduce significant risk to those systems. Federal law and implementing policies require agencies to develop, document, and implement programs to assess the risk and magnitude of harm that could result from the unauthorized access, use, disclosure, disruption, modification, or destruction of information and information systems that support agency operations and assets. The remote system used to access a NNSA information system may not have been evaluated through the NNSA PCSP C&A process; therefore, its security policy is unknown. Based upon documented risk assessments, agencies must provide adequate security to maintain an acceptable level of risk to agency operations and assets. 2. CRITERIA AND PROCESSES.

Section 41

a. All NNSA sites must develop and implement policies, processes, and procedures to govern remote access of NNSA information systems by users utilizing NNSA and non-NNSA owned equipment. These processes and procedures are documented as part of the site’s CSPP. All policies, processes, and procedures must address the following: (1) Use of Government- and non-Government-owned computers to access remotely NNSA information resources or information. (2) Protection of information on non-Government-owned computers. (3) Prohibition by the Department of Commerce of export from the United States of any encryption program or algorithm in excess of 128 bits. (4) ISSP modifications, when remote access capabilities are to be introduced into legacy applications or systems. (5) Additional security measures required for remote access to SUI, as defined in Appendix B, Glossary. XIV-2 NAP 14.1-C 05-02-08 (6) National Security Systems. Remote access to any DOE and/or NNSA National Security System is authorized via approved methods, such as Type I encryption. The NNSA Element will ensure that only personnel with access authorization and Need-to-Know can access National Security Systems. The risk associated with remote access shall be documented in the relevant ISSP and in the Risk Assessment. Personnel accessing these systems shall be trained, and training shall be documented as required by the ISSP. (7) Management Controls on Remote Access must describe: (a) Boundary Protection Services and automated tools, such as firewalls, virtual private networks, encryption, intrusion detection, anti-virus software, audit log analysis provided to manage remote access services and detect intrusions and/or intrusion attempts. (b) Procedures to report and respond to remote access security incidents. (c) Rules of behavior and operations and consequences for violating remote access policies and procedures, including prohibition of entering classified information on any computing resource not approved for such information. (d) Specific security and awareness training for those authorized to use remote access services to access information in all Information Groups, except the Open Public Access Information Group, and those who perform system administration duties. (e) Process(es) to perform a risk assessment if new threats are introduced by allowing remote access to NNSA information and systems, including trusted and non-trusted environments. (f) Procedures to ensure that management’s initial and periodic approval of operational need of each user’s remote access capability is obtained. (g) Procedures to ensure NNSA systems are protected from malicious code on equipment used for remote access. (h) Process for organizations and users to obtain approval from system owners and data custodians prior to implementing remote network access. (i) Processes to ensure that remote access services are controlled, and that user profiles are managed to reflect user job responsibilities. NAP 14.1-C XIV-3 05-02-08 (j) Processes to ensure periodic reviews and random security evaluations of remote access security controls. (k) Processes to ensure that remote access issues, vulnerabilities, requirements, and technology changes are incorporated into training for all affected NNSA and contractor personnel, including, as appropriate, the permitted extent of personal use. (l) Remote access requirements in the ISSP of the system being accessed remotely.

Section 42

(8) Operational Controls on Remote Access must describe the following: (a) Minimum requirements for operating systems and application software for users who use non-NNSA owned equipment to connect remotely to NNSA networks, for access to all Information Groups, except the Open Public Access Information Group. (b) Procedures for obtaining user commitment to the understanding and acknowledgement of minimum requirements and remote access rules of behavior, through user signatures on a User Responsibility Statement that includes requirements for remote access. (c) Procedures for remote access of NNSA systems from wireless Internet systems in coffee shops, public libraries, or in other such public locations. (9) Technical Controls. Develop or define and describe the following: (a) Acceptable levels and types of authentication, and personal identification for remote access. i. Two-factor authentication, where one of the factors is provided separately from the computer gaining access, such as a RSA token or biometric solution. ii. Clear-text, reusable passwords for remote access are prohibited. Legacy systems that use clear text passwords are prohibited from participating in remote access. (b) Establishment of a trusted path prior to transmission of data in all Information Groups except the Open Public Access Information Group. (c) Time-out function for remote access requiring user re- authentication after user inactivity of 15 minutes for unclassified systems, and 10 minutes for National Security Systems. XIV-4 NAP 14.1-C 05-02-08 (d) Minimum requirements for the operating system and application software and for controlling and safeguarding Government-issued cryptographic keying material on all equipment used for remote access. (e) Standard minimum security configurations for all information systems. b. Significant Changes. Owners and operators of interconnected applications and systems must be apprised of any significant change to interconnection agreements. Any site’s application or system that uses remote access for which the above criteria are not met must be documented as a weakness in applicable CAPs and POA&Ms. NAP 14.1-C XV-1 05-02-08 CHAPTER XV. CONTINGENCY PLANNING 1. INTRODUCTION. Information systems are essential to NNSA mission success; therefore, it is critical that the services provided by these systems be able to operate effectively without excessive interruption. Contingency planning refers to a coordinated strategy involving plans, procedures, and technical measures that enable recovery of systems operations and data after a disruption. Contingency planning generally includes either restoring operations at an alternate location, using alternate equipment, or reverting to a manual process. NNSA recognizes one contingency plan may cover multiple systems, such as one plan that would cover all unclassified desktops. 2. CONTINGENCY PLANNING. The NNSA Contingency Planning Process consists of the following six progressive steps that must be accomplished during the NNSA C&A process. a. Site Planning Policy Statement. The site’s Contingency Planning Policy Statement must define the site’s overall contingency objectives; establish the framework; define contingency planning responsibilities and the criteria; safety of personnel; extent of damage to the site, facility, or system; criticality of the system to the site’s mission; and anticipated disruption for activating the contingency plan(s). Major Elements to be covered in the statement are roles and responsibilities, resource requirements, training requirements, exercise and test schedules, plan maintenance schedule, frequency of backups, storage of backup media, and compliance with NNSA policy.

Section 43

b. Business Impact Analyses (BIAs). The site shall conduct BIAs to identify systems that provide services critical to site operations and prioritize these systems and their components. These BIAs are to provide sufficient information to enable the Contingency Plan Coordinator (CPC) to fully characterize system requirements, processes, and interdependencies to determine contingency requirements and priorities. The purposes of the BIA are to correlate specific systems and components with the critical services that they provide and, based on that information, to characterize the consequences of a disruption to the system components. (1) A BIA for any system designated a Critical Infrastructure or Key Resource may be limited to a determination of critical components required to maintain essential operation of these systems. (2) BIAs for the remaining systems under the purview of the site must include all elements of the BIA. (3) Identify critical information system resources. XV-2 NAP 14.1-C 05-02-08 (4) Identify data on the systems and specify protection measures of the data based on level of confidentiality or classification, such as encryption of backups or secure storage. (5) Identify data users, providers, and flows. (6) Identify system components and infrastructure, such as electric power, servers, routers, authentication servers, required to extract or enter data. (7) Identify disruption impacts and allowable outage times. (8) Identify magnitude of expected disruptions from site-level plans, such as Disaster Recovery, Continuity of Operations, and Occupant Emergency Plans, to determine the threats from natural, human, or environmental sources. (9) Identify the maximum allowable time the system or system component may be unavailable before it prevents a mission-essential function from being performed. (10) Identify any related or dependent systems and processes that will be disrupted by the unavailability of the system. (11) Identify the point in time where the cost of system inoperability and the cost of restoration are equal. (12) Develop recovery priorities. (13) Use data obtained from previous activities to prioritize recovery for systems and system components. (14) Determine recovery timeline for each system component. (15) Initiate preparation of POA&Ms for any systems that are prioritized below current funding capabilities. c. Preventive Controls. Identify measures taken or to be taken to reduce the effects of system disruptions. (1) Identify the vulnerabilities to natural, human, or environmental threats. (2) Develop mitigation strategies to reduce or eliminate impacts to system components, in priority order, based on the BIAs. (3) Update POA&Ms as necessary for any system that is prioritized below current funding capabilities. NAP 14.1-C XV-3 05-02-08 d. Recovery Strategies. Develop thorough recovery strategies to ensure that the system may be recovered as effectively and as quickly as needed following a disruption. (1) Identify threats and/or vulnerabilities that could not be mitigated. (2) Develop recovery strategies, such as Alternate Sites, Hot Sites, Mirrored Sites, rapid equipment replacement, and/or reallocation of existing site equipment, based on the disruption impacts and the allowable outage times from the BIAs.

Section 44

(3) Note that different types of contingency situations will necessitate different readily available staff with particular skills. The plan should identify those personnel or teams to accomplish the decision making, coordination, administrative, and technical functions required for contingency plan execution, such as: (a) Management (b) Damage Assessment (c) Alternate Site Recovery and Coordination (d) Hardware Salvage (e) Data Recovery (f) Database Recovery (g) Application Recovery (h) LAN and/or WAN Recovery (i) Telecommunications (j) Network Operations Recovery (k) Software and Data Recovery (l) System Software (m) Operating System Administration (n) System Recovery (o) Server Recovery (p) Administrative Support XV-4 NAP 14.1-C 05-02-08 (q) Original Site Restoration and Salvage Coordination (r) Test (s) Procurement (equipment and supplies) (t) Physical and Personnel Security (u) Transportation and Relocation (v) Media Relations (w) Legal Affairs (4) Update the POA&M as necessary to include resource requirements to implement this portion of the CP. e. Testing, Training, and Exercises. Testing the plan identifies planning gaps. Exercises identify planning and implementation gaps, whereas training prepares recovery personnel for plan activation. These activities improve plan effectiveness and overall site preparedness. (1) Testing a CP involves the definition of a scenario, test objectives, and criteria that must be met to successfully complete the test of each CP element. (2) The results of all testing must be documented in a test report. (3) Test reports for Critical Infrastructure and Key Resources must be forwarded to the Office of the NNSA CIO through the SOM or SCD, as applicable. (4) Testing may take four forms, as follows: (a) Structured Walkthrough. The most basic type of test. A Structured Walkthrough takes place in a group meeting type of setting, where the main goal is to confirm that critical personnel from all areas are familiar with the BCP – provides an orientation. This test does not usually involve the entire organization, nor does it test the team’s ability to execute it. (b) Tabletop Exercise. This takes place in a classroom-type environment and emulates particular recovery scenarios. During NAP 14.1-C XV-5 05-02-08 plan development, tabletop exercises are conducted on portions of the plan to detect and correct initial errors and misconceptions. Tabletop exercises also provide familiarity for recovery personnel throughout the lifecycle of the system. At a minimum, a Tabletop Exercise of CPs for all systems must be conducted annually, when a Functional Exercise is not conducted. (c) Functional Exercise. This takes place in a simulated environment and utilizes physical testing of procedures, alternate equipment, and alternate locations, to ensure the correctness of procedures, capability of recovery personnel, and technical capabilities of equipment. A Functional Exercise of Critical Infrastructure and Key Resource CP must be conducted annually. All Moderate and High category information systems should undergo a Functional Exercise at least every 2 years to include elements of Notification and Activation, Recovery, and Reconstitution, as a minimum. (d) Full-Scale Exercise. The most comprehensive test is the Full- Scale Exercise, also known as the Operational Exercise. During this test, all or most of the BCP is put into action. The main goal is to simulate an actual recovery situation as closely as possible. The exercise will evolve and develop just as they would in an actual crisis.

Section 45

(5) Training. Recovery personnel must be trained to understand the CP and their applicable role. This training will be accomplished annually and as part of changes to the CP. The following plan elements shall be included in training: (a) Purpose of the plan. (b) Cross-team coordination and communication. (c) Reporting procedures. (d) Security requirements. (e) Team-specific processes such as notification and activation, recovery, and reconstitution. (f) Individual responsibilities in contingency processes. (6) POA&M Update. Update the POA&M as necessary, to include resource requirements to implement this portion of the CP. XV-6 NAP 14.1-C 05-02-08 f. Plan Maintenance. The plan is a living document that is reviewed and updated annually to remain current with system enhancements, results of plan testing, team staffing changes, and changes in NNSA priorities. The CP shall be a configuration item and maintained as part of the ISSP. A change to the system or its environment, which includes CP elements, requires the modified ISSP to be approved prior to implementing the changes. 3. CONTINGENCY PLAN DEVELOPMENT. The CP contains detailed roles, responsibilities, teams, and procedures associated with restoring an IT system following a disruption. The CP should document technical capabilities designed to support contingency operations and be tailored to the site and its requirements. A site-level CP may be written to describe processes that are common to all CPs, with system-specific detail as addendums or separate contingency plans; however, plans should provide quick and clear directions in the event that personnel unfamiliar with the plan or the systems are called on to perform recovery operations. Plans should be clear, concise, and easy to implement in an emergency. Where possible, checklists and step-by-step procedures should be used. a. Introduction. The Introduction includes background and contextual information that makes the plan easier to understand, implement, and maintain, and to orient the reader to the type and location of information contained in the plan. (1) Purpose. This subparagraph establishes the reason for writing the plan. (2) Applicability. The organization(s) impacted by the CP is documented, and the relationship to any other plans supporting or supported by the plan, such as Emergency Management Plans, is described. b. Scope. This paragraph discusses the issues, situations, and conditions addressed and not addressed in the CP. The types of contingency situations the plan is intended to cover should be discussed. These situations may range from a temporary loss of commercial power to disaster recovery operations. The system, location(s) for the system or system components covered, and any assumptions are described. c. References and Requirements. This subparagraph identifies the NNSA, Program, and site requirements for contingency planning. d. Record of Changes. This subparagraph describes the configuration history of the CP by recording dates, version, and reason for CP changes. e. Concept of Operations. The Concept of Operations (CONOPS) element provides additional details about the system, planning framework, response activities, recovery activities, and resumption activities. NAP 14.1-C XV-7 05-02-08 f. System Description. The system description should include system architecture, location(s), internal and external connections, security components, and any other technical detail that would assist contingency teams in understanding the system configuration and operation.

Section 46

(1) Line of Succession. The order of succession identifies the personnel responsible for assuming authority in the event the designated person is unavailable. (2) Responsibilities. This subparagraph describes the overall structure of the contingency teams. Coordination mechanisms and requirements, as well as an overview of team member roles and responsibilities are also described. g. Notification and Activation. The Notification and Activation element defines the initial actions to be accomplished to notify personnel, assess damage, and implement the plan once a disruption or emergency has been detected or is expected. h. Notification Procedures. The method(s) of notification of each team member must take into account the possibilities of widespread disasters, the ability to contact personnel on short notice during and after business hours, and the necessity to contact alternate personnel. Personnel to be notified may be listed in an appendix that identifies the person, their team position, home address, telephone number, pager number, cell phone number, and personal and business e-mail address. Notifications to interconnected systems staff, internal or external to the site, would also be made. These POCs are identified in the ISSP Memorandum of Agreement (MOA)/System Interconnect (SIA) Agreement, but should also be listed in the CP for ease of use when needed. i. Damage Assessment. In order to appropriately implement the CP, the nature and extent of damage must be assessed as early as possible. Personnel performing damage assessment must be sufficiently trained in their part(s) of these procedures that performance can be accomplished without written procedures available. Specific damage assessment procedures may be unique to each system, but the following areas must be addressed: (1) The cause of the emergency or disruption. (2) The potential for additional disruptions or damage. (3) Area affected by the emergency. (4) Status of physical infrastructure, such as structural integrity of the building or room, electric power availability, HVAC, and telecommunications. XV-8 NAP 14.1-C 05-02-08 (5) Inventory and functional status of system components. (6) Type of damage to system components, such as water, fire and heat, physical, and electric surge. (7) System components to be replaced. (8) Estimated time required to restore normal system operation. j. Plan Activation. The CPC evaluates the result of the damage assessment against the plan activation criteria and determines the strategy to be used if the plan is to be activated. The detailed activation criteria are located in this paragraph of the plan, and it covers personnel safety, extent of damage to the facility, extent of damage to the system, criticality to the site’s mission, and anticipated duration of disruption. k. Recovery. The Recovery element includes the operations that begin after the CP has been activated, damage assessment has been completed, if possible, personnel have been notified, and appropriate teams have been mobilized. Recovery activities focus on contingency measures to execute temporary processing capabilities, repair damage to the original system, and restore operational capabilities at the original or new facility. Upon completion of the Recovery Phase, the system will be operational and performing the functions designated in the plan.

Section 47

l. Recovery Sequence. The sequence of recovery activities should reflect the system’s allowable outage time to avoid significant impacts to related systems and their application. Procedures should be written in a stepwise, sequential format so that system components can be restored in a logical manner. The most critical items to restoring service and the system foundation items should be recovered first. Procedures must include coordination activities with other teams or external organizations that are dependent on completion of certain steps, such as when time frames are not being met, a step has been completed that allows another team to proceed, or when items must be procured. m. Recovery Procedures. Recovery procedures are to be written that allow personnel unfamiliar with the site, facility, or system configuration to perform the recovery. Recovery procedures are to include date and time of step completion and the name of the team member who completed it. Particular procedures are to be assigned to the appropriate recovery team and address the following: (1) Obtaining approval to access damaged facilities or areas. (2) Notifying internal and external organizations associated with the system. (3) Obtaining office supplies and work space. NAP 14.1-C XV-9 05-02-08 (4) Obtaining and installing hardware. (5) Obtaining backup media. (6) Restoring operating and application software. (7) Restoring system and application data. (8) Testing system functionality and security. (9) Notification to user(s). (10) Operating alternate equipment. n. Reconstitution. Once the original or new site or facility is restored to the level that it can support the system and its normal processes, the system may be transitioned back to the original or to the new site and/or facility. Until the primary system is restored and tested, the alternate system should continue to be operated. o. The CP should specify teams responsible for restoring or replacing both the facility and the system. The following major activities are addressed: (1) Ensuring adequate infrastructure support, such as electric power, water, telecommunications, security, environmental controls, office equipment, and supplies. (2) Establishing connectivity and interfaces with network components and external systems. (3) Installing system hardware, software, and firmware. This activity should include detailed restoration procedures similar to those followed in Recovery. (4) Testing system operations and security to ensure full functionality. (5) Backing up operational data on the contingency system and uploading to restored system. (6) Shutting down the alternate system. (7) Terminating contingency operations. (8) Securing, removing, and/or relocating all sensitive materials at the alternate site. (9) Arranging for recovery personnel to return to the original facility. XV-10 NAP 14.1-C 05-02-08 4. CONTINGENCY PLAN STRUCTURE. The structure of a CP is based on the importance of systems for which the plan is written. The following paragraphs describe the mandatory CP elements based on the designation of the system. Refer to Appendix G, Contingency Plan Structure. a. Critical Infrastructure. Critical Infrastructure CPs must address each of the elements described in paragraph 3 in sufficient detail to allow technically competent personnel unfamiliar with the system to create and operate the system in a different location.

Section 48

b. Key Resources. Key Resource CPs must address each of the elements indicated in the following paragraph in sufficient detail for personnel familiar with the system to create and operate the system in a different location. (1) Introduction (3.a) (2) Scope (3.b) (3) Concept of Operations (3.c) (4) Notification and Activation (3.d) (5) Recovery Procedures (3.e) (6) Reconstitution (3.f) c. Remaining Systems. All other system CPs must address each of the elements, as indicated in the paragraphs below in sufficient detail for personnel who normally operate the systems to restore operations. (1) Introduction (3.a) (2) Scope (3.b) (3) Concept of Operations (3.c.) (4) System Description (3.c.(1)) (5) Line of Succession (3.c.(3)) (6) Notification and Activation (7) Notification Procedures (3.d.(1)) (8) Plan Activation (3.d.(3)) (9) Recovery Procedures NAP 14.1-C XV-11 05-02-08 (10) Hardware Installation (3.e.(2)(d)) (11) Backup Media (3.e.(2)(e)) (12) Software Restoration (3.e.(2)(f)) (13) Functional and Security Testing (3.e.(2)(h)) (14) User Notification (3.e.(2)(i)) (15) Operating Equipment (3.e.(2)(j) (16) Reconstitution (17) Infrastructure Support (3.f.(1)) (18) Internal and External Networking (3.f.(3)) (19) Functional and Security Testing (3.f.(4)) XV-12 NAP 14.1-C 05-02-08 This page intentionally left blank. NAP14.1-C XVI-1 05-02-08 CHAPTER XVI. CLEARING, PURGING, AND DESTROYING MEDIA 1. INTRODUCTION. This chapter establishes NNSA policy requirements and responsibilities for clearing, purging, and destroying NNSA information system storage media, memory devices, and other related hardware, hereafter referred to as storage media. Specifically, this chapter provides the following: a. Instructions for clearing, purging, and destroying storage media to preserve the confidentiality of the stored information. b. Instructions for handling classified storage media that will be reused in controlled environments. c. Instructions for sanitizing storage media that has become contaminated with classified or unclassified sensitive information. d. Direction to ensure that no unauthorized information can be retrieved from unclassified NNSA and DOE computer equipment, and storage media that is to be transferred or declared surplus. e. Direction to ensure that all NNSA Element personnel are made aware of requirements for clearing, purging, and destroying information system storage media, memory devices, and related hardware. 2. CRITERIA AND PROCESSES. a. Approved Processes. NNSA-approved processes for clearing, purging, and destroying information system storage media, memory devices, and related hardware that have been used to process, store, or contain unclassified or classified information are listed in the following paragraphs. Decisions to clear, purge, or destroy information system storage media, memory, and other related hardware must be based on the confidentiality of the most sensitive information ever recorded on the storage media. Implementation of these processes and plans for clearing, purging, and destroying information system storage media must be documented in the appropriate CSPPs, including the requirement for documented methods for independently verifying the clearing and purging results. b. CSPP. The CSPP must identify or reference procedures used for the sanitization (clearing, purging, and destruction) that implement the concepts and processes listed below.

Section 49

(1) Maintenance on equipment and tools used for clearing, purging, and destruction is regularly scheduled and performed to ensure proper operation and calibration. (2) All maintenance on equipment and tools used for clearing, purging, and destruction are thoroughly documented. XVI-2 NAP 14.1-C 05-02-08 (3) Systems media and storage hardware are purged before release to personnel without authorization to access the information, including Need-to-Know, on the media or hardware. (4) Processes for handling and control of media, electronic devices, and hardware prior to clearing, purging, or destruction are documented and followed. (5) Storage media used in SUI processing is tracked and controlled until it is purged or destroyed. (6) The storage media must be tracked and destroyed if the confidentiality impact is moderate or high, unclassified information is located in bad sectors, or the storage media cannot be cleared or purged. (7) Storage media that has been used in classified processing and is no longer being used or needed for archiving is tracked and controlled until it is destroyed, and the destruction is documented as required by the DOE Classified Matter Protection and Control (CMPC) program. (8) Sanitization procedures, software, equipment and tools, and special processes are identified, documented and approved by the DAA. (9) Decision and handling processes regarding reuse of classified storage media at lower classification level(s) include formal risk and cost analyses and testing and are documented and justified. (10) Requirements for removing information from storage media, memory devices, and related hardware are to be included in the training and awareness program and reviewed with all users on a regular basis. (11) Personnel performing or verifying clearing, purging, or destruction of storage media, memory devices, and other hardware are to be trained in equipment and tool operation, approved techniques, and procedures. (12) No fewer than 20 percent of the purged media are sampled on a controlled, random basis to verify the purging process has been successfully completed. (13) Verification is conducted by individuals other than those performing the purging processes. (14) The completion and verification of the purging process is documented. c. Minimum Sanitization Criteria. Table XVII-1 through Table XVII-3 outline the basic sanitization processes and tools based on different technologies and media types. NAP14.1-C XVI-3 05-02-08 (1) NSA/CSS Manual 9-12/20 or subsequent update may be used as a supplement for these processes. (2) NIST SP 800-88, Guidelines for Media Sanitization, or subsequent update may be used as a supplement for these processes. (3) Refer technologies and media types not listed in the tables or references through the NNSA CSPM to DOE OCIO for defining clearing, purging, and destroying processes. d. Unclassified Storage Media Processes. (1) In addition to the clearing processes listed in Tables XVI-1 through XVI- 3, processes to clear unclassified storage media are to include the following: (2) Storage media hosting Government information is to be cleared if it will be reused by a potential user who has a different authority for access, including Need-to-Know, or in a system that contains information whose Security Category (confidentiality, impact) is the same or higher.

Section 50

(3) Only overwriting software and hardware that are compatible with media to be overwritten and approved by the DAA will be used. Care should be used to ensure a match of software and hardware to the media, considering the make, model, and manufacturing date of the media. (4) One-pass overwrites are sufficient for clearing storage media that does not contain SUI. If the storage media contains SUI, three-pass overwrites must be performed. (5) Individuals performing unclassified storage media clearing must certify and document successful completion of the process to include the following: (a) Purpose of clearing (reuse or release). (b) Storage media unique identifiers, such as serial number, make, and model. (c) The Information Type with the highest confidentiality impact hosted on the media prior to clearing. (d) The procedure used. (e) The date, the printed name, and signature of the certifying individual. (6) All unclassified storage media will not be released to the public. XVI-4 NAP 14.1-C 05-02-08 (7) Individuals performing unclassified storage media purging must certify that the purging process has been successfully completed by affixing a label to the storage media. At a minimum, the label must document the following: (a) Storage media unique identifiers, such as serial number, make, and model. (b) The Information Type with the highest confidentiality impact hosted on the storage media prior to purging. (c) Purpose of purging. (d) The procedure used. (e) The date, printed name, and signature of the certifying individual. (f) Storage media that cannot be purged must be destroyed. e. Classified Storage Media Processes. (1) In addition to the clearing processes listed in Tables XVI-1 through Table XVI-3, processes to clear classified storage media must include the following: (2) Storage media that will be reused on a different system for the same or more restrictive Information Group or a potential user has a different Need-to-Know must be cleared. (3) Only overwriting software and hardware that are compatible with media to be overwritten and approved by the DAA will be used. (4) Cleared storage media that has been used in classified processing must be protected commensurate with the highest Information Group it has ever contained. The media must be handled in accordance with applicable DOE Classified Matter Protection and Control processes. (5) Individuals involved in clearing classified storage media must certify and document the successful completion of the process to include: (a) Storage media unique identifiers, such as serial number, make, and model, and ACREM accountability number. (b) Most restrictive Information Group hosted prior to clearing. (c) Purpose for clearing. (d) The procedure used. NAP14.1-C XVI-5 05-02-08 (e) The date, the printed name, and the signature of the certifying individual. (6) In addition to the purging processes listed in Tables XVI-1 through XVI- 3, processes to purge classified storage media are to include the following. (a) Classified storage media that cannot be reused at a lower level must be destroyed. (b) Classified storage media that has been purged may not be donated, sold, or released from the DOE environment to outside organizations. (c) Individuals performing purging of classified storage media must certify the process has been successfully completed by affixing a label to the storage media. At a minimum, the label must document the following:

Section 51

(i) Storage media unique identifiers, such as serial number, make, and model. (ii) Most restrictive Information Group hosted prior to purging. (iii) Purpose of purging. (iv) A statement that the storage media contains no classified information. (v) The procedure used. (vi) The date, printed name, and signature of the certifying individual. f. Special Circumstances. The use of storage media in a lower classification is described below. (1) Reusing Classified Storage Media. (a) The decision to reuse storage media at a lower classification level may be acceptable if formal risk and cost analyses are conducted, and the results of these analyses and testing of the implemented procedures verify that the National Security of the United States is not adversely affected. Testing, risk and cost analysis procedures must be documented in the site’s approved CSPP. (b) Reuse of storage media must be identified in the ISSP of the system where the media is used and the media must be tracked and controlled until it is purged or destroyed. XVI-6 NAP 14.1-C 05-02-08 (c) Classified storage media that will not be reused at a lower classified level must be destroyed. (d) The storage media must be purged by overwriting the entire storage media using the three-pass process described in Table XVI-1 of this document. (e) The software used is to provide information about sectors overwritten and bad sectors that cannot be overwritten. (f) Quality controls are to be documented and deployed for review of overwrite process results and verification that all the classified information was completely overwritten (g) Storage media must be destroyed if classified information is located in bad sectors or the storage media cannot be purged. (h) Individuals performing purging of the classified storage media planned for reuse must certify the process has been successfully completed by affixing a label to the storage media. At a minimum, the label must document the following: (i) Storage media unique identifiers, such as serial number, make, and model, and ACREM accountability number. (ii) Most restrictive Information Group hosted prior to purging. (iii) Purpose of purging. (iv) A statement that the storage media contains no classified information. (v) The procedure used. (vi) The date, printed name, and signature of the CA. (2) Purging Partially Contaminated Storage Media. Areas of non-removable and removable storage media partially contaminated with an information type of a higher confidentiality impact or more restrictive Information Group may be purged using the three-pass process described in Table XVI-1 and continue use in its current information system in the following situations: (a) When the classified storage media is contaminated with relatively small amounts of information from a more restrictive Information Group (less than 0.1 percent of the capacity of the non-removable storage media). (b) When unclassified storage media is contaminated with relatively small amounts of unclassified information with a confidentiality NAP14.1-C XVI-7 05-02-08 impact of moderate or high (non-Public) (less than 0.1 percent of the capacity of the non-removable storage media). (c) The software used to overwrite contaminated storage media must overwrite all contaminated locations, including temporary data file locations, file slack, free space, and directories; provide confirmation of overwrite of specified areas and of successful completion; and provide information about sectors overwritten and bad sectors that cannot be overwritten.

Section 52

(d) Quality controls are to be documented and deployed for review of overwrite process results and verification that all the contaminating information was completely overwritten. (e) Storage media must be destroyed if classified information is located in bad sectors, or the storage media cannot be purged. (f) Records to be maintained, as a minimum, are listed below. (i) Storage media unique identifiers, such as serial number, make, and model. (ii) Contaminating Information Group. (iii) Purpose of purging. (iv) A statement that the storage media no longer contains the Information Group. (v) The procedure used. (vi) The date, printed name, and signature of the certifying individual. Table XVII-1 shows the approved processes for clearing, purging, and destroying storage media. Table XVI-1. Approved Processes for Managing Storage Media Media Type Clearing‡ Purging‡ Destroying‡ Magnetic Tapes XVI-8 NAP 14.1-C 05-02-08 Media Type Clearing‡ Purging‡ Destroying‡ Type I 1, 2, or 3 1, 2, 3, or 4 5 Type II 1, 2, or 3 2, 3, or 4 5 Type III 2 or 3 3 or 4 5 Magnetic Disks Floppies, Zip drives 1, 2, 3, or 4 X 5 Bernoulli Boxes 1, 2, 3, or 4 X 5 Removable Hard Disks 1, 2, 3, or 4 1, 2, 3, or 4 5 or 6 Non-removable Hard Disks 4 1, 2, 3, or 4 5 or 6 Optical Disks Magneto-optical: Read Only X X 4 Write Once, Read Many (WORM) X X 4 Read Many, Write Many X X 4 Other Floptical X X 5 Helical-scan Tapes X X 5 Cartridges X X 5 Optical X X 5 CD-R, -RW, -ROM X X 5 or 7 DVD X X 5 or 7 ‡ Numbers in the table refer to the processes listed. § All degaussing products used to clear or sanitize media must be certified by the National Security Agency (NSA), and be listed on the Degausser Products List of the NSA Information Systems Security Products and Services Catalogue. Processes: † Degauss with a Type 1 degausser.§ 1. Degauss with a Type 2 degausser.§ 2. Degauss with a Type 3 degausser.§ 3. Overwrite all locations with a pseudorandom pattern twice and then with a known pattern. 4. Pulverize, smelt, incinerate, disintegrate, or use other appropriate mechanisms to ensure media are physically destroyed. 5. Remove the entire recording surfaces by sanding or applying acid. 6. Grind surface of CD or DVD to ensure the entire recording surface is removed. Only NSA Group D equipment and associated processes approved for the specific media may be used. X. No process authorized. Table XVII-2 illustrates the approved processes for clearing, purging, and destroying electronic memory devices. NAP14.1-C XVI-9 05-02-08 Table XVI-2. Approved Processes for Managing Electronic Memory Devices Media Type Clearing‡ Purging‡ Destroying‡ Magnetic Bubble Memory 2 1 or 2 10 Magnetic Core Memory 2 1 or 2 10 Magnetic Plated Wire 2 2 and 3 10 Magnetic-Resistive Memory 2 X 10 Read-Only Memory (ROM) X X 10 (see 11) Random Access Memory (RAM) (Volatile) 2 or 4 4, then 9 10 Programmable ROM (PROM) X X 10 Erasable PROM (UV PROM) 6 6, then 2 and 9 10 Electrically Alterable PROM (EAPROM) 8 7, then 2 and 9 10 Electrically Erasable PROM (EEPROM) 2 8, then 2 and 9 10 Flash Erasable PROM (FEPROM) 8 8, then 2 and 9 10 ‡Numbers in the table refer to the processes listed. § All degaussing products used to clear or sanitize media must be certified by the National Security Agency (NSA) and be listed on the Degausser Products List of the NSA Information Systems Security Products and Services Catalogue. Processes: ‡

Section 53

1. Degauss with a NSA approved Type III degausser.§ 2. Overwrite all locations with a pseudorandom pattern twice and then with a known pattern. 3. Purging is not authorized if data resided in same location for more than 72 hours; sanitization is not complete until each overwrite has resided in memory for a period longer than the classified data resided in memory. 4. Remove all power, including batteries and capacitor power supplies, from RAM circuit board. 5. Perform an ultraviolet erase according to manufacturer’s recommendation. 6. Perform an ultraviolet erase according to manufacturer’s recommendation, but increase time requirements by a factor of 3. 7. Pulse all gates. 8. Perform a full chip purge/ erase (see manufacturer’s data sheet for procedure). 9. Check with ISSO to determine whether additional processes are required. 10. Pulverize, smelt, incinerate, disintegrate, or use other appropriate mechanisms to ensure media are physically destroyed. 11. Destruction required only if ROM contained a classified algorithm or classified data. X. No process authorized. Table XVII-3 shows the approved processes for clearing, purging, or destroying hardware. Table XVI-3. Approved Processes for Managing Hardware Media Type Clearing‡ Purging‡ Destroying‡ XVI-10 NAP 14.1-C 05-02-08 Media Type Clearing‡ Purging‡ Destroying‡ Printer Ribbons 6 6 6 Platens X 1 6 Toner Cartridges 5 5 X Laser Drums 3 3 6 Cathode-Ray Tubes (If there is Classified Burn-In) X 6 6 Fax Machines 4 4 6 Cell Phones 7 X 6 Personal Digital Assistant (PDA) (Palm, Pocket PC, etc.) 7 X 6 Routers/Copy machines 7 X 6 All other storage media devices X X 6 ‡Numbers in the table refer to the processes listed. Processes: † 1. Chemically clean so no visible trace of data remains. 2. Print at least five pages of randomly generated unclassified data. The pages should not include any blank spaces or solid black areas. 3. Print three blank copies. If unable to get a clean output, print an unclassified test pattern or black copy; then run three blank copies. 4. For fax machines that have memory and other storage media incorporated, treat each component per processes listed in tables 1 and 2 of this chapter. 5. Upon completion of copying or facsimile processing of classified material, users are required to run ten (10) blank copies to ensure the removal of all classified materials from processing device. 6. Pulverize, smelt, incinerate, disintegrate, or use other appropriate mechanisms to ensure the media is physically destroyed. 7. Manually delete all information, then perform a full manufacturers reset to reset the instrument back to factory default settings. X. Not applicable. Note: All copies printed for clearing and sanitization purposes must be destroyed as classified waste. NAP14.1-C XVII-1 05-02-08 CHAPTER XVII. SENSITIVE UNCLASSIFIED INFORMATION 1. INTRODUCTION. This chapter describes the terms Sensitive Unclassified Information (SUI), including Personally Identifiable Information (PII) as defined by DOE. NAP 14.2-C, NNSA Certification and Accreditation (C&A) Process, establishes the minimum security criteria and processes for protecting this type of information. All NNSA Elements must develop, document, and implement policies for protecting SUI, including PII. 2. CRITERIA AND PROCESSES. To ensure that SUI, including PII, on NNSA information systems is appropriately managed, each NNSA site must establish policies and procedures that address the following:

Section 54

a. Sensitive Unclassified Information. SUI is defined as unclassified information requiring protection mandated by policy or laws, such as OUO; Export Control Information (ECI); Unclassified Controlled Nuclear Information (UCNI); Naval Nuclear Power Information (NNPI); Personally Identifiable Information (PII); and other information specifically designated as requiring SUI protection. Extensions of the definition of SUI must be documented in the Element’s CSPP and ISSP. The OMB definition of PII is included below. This definition is not to be modified by Senior DOE Management or its elements. Senior DOE Management should interpret this definition by applying the working examples of what is and what is not considered PII, provided in Appendix B, to identify PII within their organizations. b. Personally Identifiable Information (PII) (as defined by OMB). Personally Identifiable Information (PII) is any information about an individual maintained by an Agency, including but not limited to, education, financial transactions, medical history, and criminal or employment history and information which can be used to distinguish or trace an individual’s identity, such as their name, social security numbers, date and place of birth, mother’s maiden name, biometric records, including any other personal information that is linked or linkable to an individual. In some instances, PII overlaps with Privacy Act information. XVII-2 NAP 14.1-C 05-02-08 This page intentionally left blank. NAP 14.1-C XVIII-1 05-02-08 CHAPTER XVIII. PEER-TO-PEER (P2P) NETWORKING 1. INTRODUCTION. Peer-to-peer (P2P) technology, services, and applications are useful but introduce significant risks that must be mitigated to maintain the security of DOE systems and networks. All NNSA Elements must use a risk-based approach when evaluating the possible use of P2P technologies, as well as address the following minimum security requirements. 2. CRITERIA AND PROCESSES. NNSA Elements must develop and implement risk- based policies and procedures that govern the consideration and possible implementation of P2P technologies in accordance with the following security criteria: a. The default condition is that P2P applications, technology, or services are not to be used on DOE systems that contain or process SUI. b. P2P applications are prohibited from being employed in any National Security System. c. If the application of P2P technology or service is required to meet programmatic or mission requirements, then each application of the technology must be justified and approved by the DAA during the C&A process. At a minimum, the justification must include: (1) Description of the P2P protocol(s) and application(s). (2) Risk assessments for systems where P2P technology or services are to be used. (3) Identification of controls at the system and network levels to detect improper use and attempted evasion of security controls. d. If a NNSA Element does implement P2P technology based on a DAA-approved justification, the following management and technical security controls (at a minimum) are to be addressed and implemented for applications, system components, and networks that are part of, or may come in contact with, P2P technologies or services. Implemented controls are to be documented and tested in all associated ISSPs during the C&A process. (1) Technical controls that do not allow the P2P server-client applications to automatically reply (Pongs) to broadcasts for locating another server- client (Pings).

Section 55

(2) Management controls describing the rules of behavior for users. XVIII-2 NAP 14.1-C 05-02-08 (3) Protocols specific to P2P server-client applications are not passed between systems or on the network unless specifically authorized in an ISA for each system hosting a P2P server-client application. (4) Firewall rules and access control lists (ACL) must be specifically established to allow, should be restrictive to specific systems, and be appropriately documented. (5) Technical controls that provide the capability for boundary protection services to detect and block unauthorized P2P applications, services, and software ports. (6) Need-to-Know and access authorizations are enforced and implemented as required for the Information Groups and security categorization of the affected system. (7) Technical controls that limit operation of a server-client application to downloading (pull), and that does not accept remote writing to the system disk hosting the P2P application from another system or system component (push). (8) Technical controls that limit ports authorized for use be P2P applications. P2P is denied/disabled on all systems and must be specifically approved to be enabled. NAP 14.1-C XIX-1 05-02-08 CHAPTER XIX. FOREIGN NATIONAL ACCESS 1. INTRODUCTION. This chapter establishes the requirements for defining Foreign National Access to NNSA information and the information systems that contain such information. Information systems include, but are not limited to, computers, networks, associated servers, data storage devices, and portable and mobile devices. A process for defining Foreign National Access to NNSA information systems is needed to enforce access restrictions based on Need-to-Know, therefore providing adequate protection to information assets. All NNSA Elements must develop, document, and implement policies pertaining to information system access by Foreign Nationals, as dictated by the following criteria. Further, such policies must be commensurate with the level of security required for the organization’s environment and specific needs. 2. CRITERIA AND PROCESSES. To ensure that Foreign National Access to NNSA information systems is managed appropriately in an effort to reduce the risk of unauthorized access to information assets, each NNSA Element must establish policies and procedures that include the following criteria, at a minimum. a. Roles and responsibilities of personnel involved in approving, implementing, and monitoring Foreign National Access to NNSA information systems. b. Specific requirements for approval, documentation, and review of Foreign National Access to information systems as required by DOE O 142.3, Unclassified Foreign Visits and Assignments, and DOE O 142.1, Classified Visits Involving Foreign Nationals. c. Access to National Security systems by Foreign Nationals must include an access approval by the system owner via the processes detailed in DOE O 142.1. d. Policies specifying the use, or prohibition, of Foreign National-owned computing equipment connected to NNSA information systems. Such equipment includes computer systems, external computing devices, and electronic media. e. Policies describing the screening process for Foreign National Access to NNSA information systems dependent on the security category of the information system, the information type, and the level of access required by the Foreign National, such as general user, privileged user, or System Administrator.

Section 56

XIX-2 NAP 14.1-C 05-02-08 f. Access to SUI systems by Foreign Nationals must include the following: (1) If a general user, a background screening that includes a Human Resources Background Check and a National Agency Check. (2) If a privileged user, a background screening that includes a Human Resources Background Check and a National Agency Check with Inquiries. (3) Processes for monitoring and evaluating the effectiveness of Foreign National Access policies and procedures. (4) Policies prohibiting Foreign National use of non-DOE equipment to access National Security systems. 3. CYBER SECURITY PROGRAM PLANS. Each NNSA Element must document policies for allowing Foreign National Access to NNSA information systems consistent with the following criteria in their site CSPP. a. Access to information systems by Foreign Nationals must be approved and documented. b. Approval documentation must identify the applicable security plan, as required by DOE O 142.1 and/or DOE O 142.3, the information and information systems(s) to which access is granted, and the time period of access. c. The official accountable for the access approval decision is to be identified in the documentation. d. Access is granted based on a documented risk assessment and identification of access controls. e. The approved risk assessment must be referenced in the security plan, and the specific information system access controls must be documented in the security plan. f. The risk assessment must address certain security factors, such as type of security area where work will be accomplished or visited, sensitivity of all information accessible during the work or visit, and Foreign National affiliation with sensitive countries or countries identified as state sponsors of terrorism. In addition, the risk assessment must address the results of subject matter expert (SME) reviews as required by DOE O 142.3. g. Procedures for reviewing and managing Foreign National Access to NNSA information systems must be documented. The procedures must include: NAP 14.1-C XIX-3 05-02-08 (1) Documenting, monitoring, and tracking Foreign National Access to NNSA information systems. (2) Auditing Foreign National Access to NNSA information systems consistent with the documented risk assessment. (3) Security incident reporting and resolution

Something wrong with this record? Tell us