Archive

NAP-14.2C, NNSA Certification and Accreditation (C&A) Process for Information Systems

Establish requirements for a NNSA Certification and Accreditation (C&A) process that incorporates national level requirements and applies them consistently across all NNSA elements.
NAP 14-2-C.pdf1.27MB
Version history and related documents
Document text

Text extracted from the attached file. Refer to the original document for the authoritative version.

Section 1

NNSA POLICY LETTER NAP 14.2-C Approved: 05-02-08 NNSA CERTIFICATION AND ACCREDITATION (C&A) PROCESS FOR INFORMATION SYSTEMS NATIONAL NUCLEAR SECURITY ADMINISTRATION Office of Chief Information Officer AVAILABLE ONLINE AT: INITIATED BY: http://hq.na.gov Office of the Chief Information Officer ii NAP 14.2-C 05-02-08 This page left intentionally blank. NAP 14.2-C iii 05-02-08 Table of Contents CHAPTER I: NNSA CERTIFICATION AND ACCREDITATION (C&A) PROCESS I-1 1. PURPOSE I-1 2. CANCELLATIONS I-1 3. APPLICABILITY I-1 4. BACKGROUND I-3 5. REQUIREMENTS I-3 6. RESPONSIBILITIES I-5 7. DEFINITIONS I-5 8. CONTACT I-5 CHAPTER II: CONTRACTOR REQUIREMENTS DOCUMENT II-1 1. REQUIREMENTS II-1 CHAPTER III: CERTIFICATION AND ACCREDITATION (C&A) PROCESS III-1 1. INTRODUCTION III-2 3. CERTIFICATION AND ACCREDITATION PROCESS III-5 3. SECURITY CONTROL MONITORING III-17 CHAPTER IV: NNSA MANAGEMENT, OPERATIONAL, AND TECHNICAL CONTROLS IV-1 CHAPTER V: SECURITY CATEGORY V-1 CHAPTER VI: INFORMATION SYSTEM SECURITY PLAN AND ACCREDITATION PACKAGE VI-1 1. REQUIREMENTS VI-1 2. INFORMATION SYSTEM SECURITY PLAN VI-1 3. ISSP CONTENTS VI-3 CHAPTER VII: PROTECTION REQUIREMENTS FOR SENSITIVE UNCLASSIFIED INFORMATION (SUI) VII-1 1. INTRODUCTION VII-1 2. CRITERIA AND PROCESSES VII-1 3. REMOTE ACCESS VII-2 4. MANAGEMENT OF PII ON PORTABLE/MOBILE DEVICES AND REMOVABLE MEDIA VII-2 Figures FIGURE III-1. PHASE 1 CHECKLIST 12 FIGURE III-2. VERIFICATION PACKAGE CONTENTS 15 FIGURE III-3. PHASE 3 CHECKLIST 16 FIGURE III-4. PHASE 4 CHECKLIST 18 Tables TABLE III-1. COL OF CONFIDENTIALITY 7 TABLE III-2. COL OF INTEGRITY 7 TABLE III-3. COL OF AVAILABILITY 7 TABLE III-4. COL OF CONFIDENTIALITY, INTEGRITY, AND AVAILABILITY 8 TABLE III-5. POTENTIAL IMPACT FOR CONFIDENTIALITY, INTEGRITY, AND AVAILABILITY 8 TABLE III-6. LEVELS OF CONCERN FOR UNCLASSIFIED INFORMATION 9 Appendices APPENDIX A: ACRONYMS A-1 APPENDIX B: GLOSSARY B-1 iv NAP 14.2-C 05-02-08 This page left intentionally blank. NAP 14.2-C I-1 05-02-08 CHAPTER I: NNSA CERTIFICATION AND ACCREDITATION PROCESS 1. PURPOSE. Establish requirements for a NNSA Certification and Accreditation (C&A) process that incorporates national level requirements and applies them consistently across all NNSA elements. 2. CANCELLATIONS. This NNSA Policy replaces NAPs 14.3A, 14.4A, 14.5A, 14.6A, 14.7A, 14.8A, 14.9A, 14.10A, 14.11A, 14.14, and 14.15. 3. APPLICABILITY. This NNSA Policy Letter (NAP) applies to all NNSA entities, Federal and contractor, that collect, create, process, transmit, store, and disseminate information on automated information systems for NNSA. a. NNSA Elements. NNSA Headquarters Organizations, Site Offices, Service Center, NNSA contractors, and subcontractors are, hereafter, referred to as NNSA elements.

Section 2

b. Scope. This NAP applies to any information system that collects, creates, processes, transmits, stores, and disseminates unclassified or classified NNSA data. This NAP applies to any information system life cycle, including the development of new information systems, the incorporation of information systems into an infrastructure, the incorporation of information systems outside the infrastructure, the development of prototype information systems, the reconfiguration or upgrade of existing systems, and legacy systems. In this document, the term(s) "information system,” “cyber system,” or "system" are used to mean any resource that is used to collect, create, process, transmit, store, or disseminate data owned by, for, or on behalf of NNSA or DOE, as determined by the cognizant DAA. c. Deviations. Deviations from the requirements prescribed in this NAP must be processed as described in NAP 14.1-C, NNSA Baseline Cyber Security Program. d. Exclusions. (1) The Deputy Administrator for Naval Reactors shall, in accordance with the responsibilities and authorities assigned by Executive Order 12344 (set forth in Public Law 106-65 of October 5, 1999 [50 U.S.C. 2406]) and to ensure consistency throughout the joint Navy and DOE Organization of the Naval Reactors Propulsion Program, implement and oversee all requirements and practices pertaining to this policy for activities under the Deputy Administrators cognizance. (2) These requirements do not apply to systems processing Sensitive Compartmented Information (SCI) located at NNSA sites. SCI must be protected in accordance with the appropriate intelligence community policies and directives. I-2 NAP 14.2-C 05-02-08 e. Site/Facility Management Contractors. Except for the exclusions in paragraph 3d, the Contractor Requirements Document (CRD), Chapter II, sets forth requirements of this policy that will apply to site/facility management contractors whose contracts include the CRD. The CRD must be included in site/facility management contracts that provide automated access to NNSA information or information systems. The CRD does not automatically apply other than site/facility management contractors. Any application of requirements of this policy to other than site/facility management contractors will be communicated separately. As the laws, regulations, and DOE and NNSA directives clause of site/facility management contracts states, regardless of the performer of the work, site/facility management contractors with the CRD incorporated into their contracts are responsible for compliance with the requirements of the CRD. Affected site/facility management contractors are responsible for flowing down the requirements of the CRD to subcontractors at any tier to the extent necessary to ensure the site/facility management contractors’ compliance with the requirements. Contractors must not flow down requirements to subcontractors unnecessarily or imprudently. That is, contractors will: – Ensure that they and their subcontractors comply with the requirements of the CRD; and Incur only costs that would be incurred by a prudent person in the conduct of competitive business.

Section 3

f. Implementation. A plan for the implementation of this NAP must be completed within 60 days of a site’s contract to include this NAP. A plan for the implementation of this NAP within an NNSA Federal organization must be completed within 60 days after issuance of this NAP. The implementation plan must include, at a minimum, the program activity to be modified/created; the starting date of revision/development; the estimated due date; and the responsible party for the stated activity. This implementation plan schedule shall not exceed three years from the latest accreditation date for any system prior to the effective date of this NAP. (1) Existing Accredited Information Systems. All current and valid information system accreditations may continue in effect until the accreditation expires or re-accreditation is necessary. Re-accreditation of these systems must conform to the NNSA C&A process outlined in this policy. NAP 14.2-C I-3 05-02-08 (2) Information Systems in Progress. Information systems that have begun the C&A process before release of this NAP may be accredited under the previous requirements. These systems will remain accredited until re- accreditation is required, either because the systems have passed the 3- year accreditation expiration date or because a security-significant change has been made to the information system or its environment (i.e., physical, logical, or operational). Re-accreditation must conform to the NNSA C&A process outlined in this policy. (3) Non-Accredited Information Systems. Information systems that require initial accreditation, or re-accreditation outside of (1) and (2) above, must be certified and accredited in accordance with the NNSA C&A process outlined in this policy. 4. BACKGROUND. This NAP documents the requirements for C&A in an effort to provide a comprehensive and consistent approach to C&A for all NNSA classified and unclassified information systems. C&A is the process of identification, formal assessment (certification), acceptance (accreditation), and continued operation of system security controls that protect information systems and information stored or processed on those systems. This process encompasses the system’s life cycle to assure that the risk of operating a system is recognized, evaluated, and accepted. The C&A process implements the concept of “adequate security,” or security commensurate with risk, including the magnitude of harm resulting from the unauthorized access, use, disclosure, disruption, modification, or destruction of information. The proper implementation of the NNSA C&A process will ensure that all applicable requirements have been integrated into the development and operational processes. All NNSA information systems must have a complete C&A prior to going operational (i.e., processing live data). This document addresses the requirements of the DOE and NNSA to ensure that adequate security controls are provided for all information systems. Additionally, this document provides guidance for the implementation of DOE M 205.1-4. Implementing the minimum security controls of this NAP will allow NNSA cyber systems to operate at an acceptable risk level. 5. REQUIREMENTS. a. Each General Support System (GSS) or Major Application (MA) and minor applications must be accredited or have an Interim Approval to Operate (IATO) from the Designated Approving Authority (DAA) before any NNSA information is processed, created, and/or transmitted on the system.

Section 4

b. Each information system must be re-accredited at least every three years or whenever a security-significant change is to be made to the information system or its environment (i.e., physical, logical, or operational). I-4 NAP 14.2-C 05-02-08 c. The C&A activities must comply with the procedures described in Chapter III, NNSA C&A Process. d. Each information system shall be accredited using one of the following forms of accreditation. (1) System Accreditation. An accreditation method used for a single information system operating under a single Information System Security Plan (ISSP). Accreditation is based on certification of the information system. (2) Site Accreditation. An accreditation method used to accredit multiple instances of an information system where all instantiations (i.e., installations) of the information system are to be operated in equivalent or more stringent operational environments. The DAA may approve a Site (i.e., “Master”) ISSP to cover all such information systems. The information systems covered by a Site ISSP may range from personal computers up to and including multi-user information components and local area networks that meet the criteria for a Site ISSP approach. The authority to operate additional instantiations under the ISSP is based on successful completion of the follow-on processes described in the ISSP. The DAA must accredit the first information system under the Site ISSP, and delegate subsequent accreditations. The CSSM must certify that all other individual information systems to be operated under the Site ISSP meet the conditions of the approved Master ISSP. This certification, in effect, accredits the individual information systems to operate under the Site ISSP. (a) The information system’s certification documentation must contain the information system’s identification and location, and must include a statement signed by the CSSM certifying that the information system implements the requirements in the Site ISSP. (b) All information systems certified under a Site ISSP remain certified until significant changes are made to the Site ISSP, or three years have elapsed since the information system was certified. (3) Type Accreditation. An accreditation method used to accredit multiple connections to one network, where the connections are located at different sites but a single DAA is responsible for the entire network. Each connection must be implemented using the same ISSP. Accreditation is based on the approval of processes for testing and certifying additional connections. The authority to operate additional connections under the ISSP is based on successful completion of the follow-on processes described in the ISSP. NAP 14.2-C 05-02-08 e. Security Test and Evaluation (ST&E) plans must be developed for each information system and each information system's controls as described by the ST&E process in Chapter IV. f. A minimum set of securiw controls, as determined by the system categorization process, must be implemented on all NNSA systems to appropriately protect informati on. g- The DAA must: (1) AppmvetheISSPpriortethebeghingofthecontrolassessmentand updated as a result of deficiencies identified during the ST&E process. 2 Approve the ST&E Plan prior to the start of the ST&E process. h. Smsi tive Unclassified Information (SUT), including Personally Identifiable Information (PII), must be appropriately protected as described in NAP 1 4.1 -C, Bareline Cyber Security Program.

Section 5

6 . RESPONSIBILITIES. Roles and responsibilities for all activities in this document are described m NAP 1 4.1 -C, hWSA BmeJine Cyber Seczcrily Program. 7. DEFINITIONS. See NAP 14.1 -C, Bmeline Cybw Securiv Program, 8. CONTACT. Questions concerning this NAP should be directed through the cognizant DAA t~ the NNSA Cyber Security Program Manager (CSPM), at 202-586-9728. THOMAS P. D ~ G O S T ~ ~ ~ O Administrator I-6 NAP 14.2-C 05-02-08 This page left intentionally blank. NAP 14.2-C II-1 05-02-08 CHAPTER II: CONTRACTOR REQUIREMENTS DOCUMENT This Contractor Requirements Document (CRD) establishes the requirements for NNSA contractors with access to NNSA and DOE information systems. Contractors must comply with the requirements listed in the CRD. The contractor will ensure that it and its subcontractors cost- effectively comply with the requirements of this CRD. Regardless of the performer of the work, the contractor is responsible for complying with and flowing down the requirements of this CRD to subcontractors at any tier to the extent necessary to ensure the contractor’s compliance with the requirements. In doing so, the contractor must not unnecessarily or imprudently flow down requirements to subcontractors. That is, the contractor will ensure that it and its subcontractors comply with the requirements of this CRD and incur only those costs that would be incurred by a prudent person in the conduct of competitive business. 1. REQUIREMENTS. A plan for the implementation of this NAP must be completed within 60 days after modification of the site’s contract to include this CRD. The implementation plan must include, at a minimum, the program activity to be modified/created; the starting date of revision/development; the estimated due date; and the responsible party for the stated activity. This implementation plan schedule shall not exceed three years from the latest accreditation date for any system prior to the effective date of this NAP. a. Existing Accredited Information Systems. All current and valid information system accreditations may continue in effect until the accreditation expires or re- accreditation is necessary. Re-accreditation of these systems must conform to the NNSA C&A process outlined in this policy. b. Information Systems in Progress. Information systems that have begun the C&A process before release of this NAP may be accredited under the previous requirements. These systems will remain accredited until re-accreditation is required, either because the systems have passed the 3-year accreditation expiration date or because a security-significant change has been made to the information system or its environment (i.e., physical, logical, or operational). Re- accreditation must conform to the NNSA C&A process outlined in this policy. c. Non-Accredited Information Systems. Information systems that required no previous accreditation (e.g., legacy systems) must be certified and accredited in accordance with the NNSA C&A process outlined in this policy. 2. All General Support Systems (GSSs), Major Applications (MA), and minor applications managed and/or operated by an NNSA element must be accredited or have an Interim Approval to Operate (IATO) before any information is processed, created, stored, and/or transmitted, as described in this policy. II-2 NAP 14.2-C 05-02-08

Section 6

3. All information systems managed and/or operated by an NNSA element must be re- accredited at least every three years or whenever a security-significant change is to be made to an information system or its environment (i.e., physical, logical, or operational). 4. The contractor must follow the C&A activities as described in this NAP. 5. All information systems managed and/or operated by an NNSA element shall be accredited using one of the following forms of accreditation. a. System accreditation. An accreditation method used for a single information system operating under a single ISSP. Accreditation is based on information system certification. b. Site accreditation. An accreditation method used to accredit multiple instances of an information system where all instantiations (i.e., installations) of the information system are to be operated in equivalent or more stringent operational environments. The DAA may approve a Site (i.e., “Master”) ISSP to cover all such information systems. The information systems covered by a Site ISSP may range from personal computers up to and including multi-user information components and local area networks that meet the criteria for a Site ISSP approach. The authority to operate additional instantiations under the ISSP is based on successful completion of the follow-on processes described in the ISSP. The DAA must accredit the first information system under the Site ISSP. The ISSM must certify that all other individual information systems to be operated under the Site ISSP meet the conditions of the approved Site ISSP. This certification, in effect, accredits the individual information systems to operate under the Site ISSP. (1) The information system’s certification documentation must contain the information system’s identification and location, and must include a statement signed by the ISSM certifying that the information system implements the requirements in the Site ISSP. (2) All information systems certified under a Site ISSP remain certified until significant changes are made to the Site ISSP, or three years have elapsed since the information system was certified. c. Type Accreditation. An accreditation method used to accredit multiple connections to one network, where the connections are located at different sites but a single DAA is responsible for the entire network. Each connection must be implemented using the same ISSP. Accreditation is based on the approval of processes for testing and certifying additional connections. The authority to operate additional connections under the ISSP is based on successful completion of the follow-on processes described in the ISSP. 6. The accreditation decision for each information system must be supported by C&A documentation as described in Chapter III of this document. NAP 14.2-C II-3 05-02-08 7. The contractor must develop Security Test and Evaluation (ST&E) plans for each information system. Each information system’s control implementation is assessed as described in Chapter IV. 8. A minimum set of security controls, as determined by the system categorization process, must be implemented on all NSA systems to appropriately protect information. 9. The DAA must: a. Approve the ISSP prior to the beginning of the control assessment and updated as a result of deficiencies identified during the ST&E process and b. Approve the ST&E Plan prior to the start of the ST&E process.

Section 7

10. Contractor must implement the minimum set of security controls as determined by the system categorization process for each information system to appropriately protect information that is processed, and stored, on unclassified and classified information systems. 11. The contractor must appropriately protect Sensitive Unclassified Information (SUI), including Personally Identifiable Information (PII), as described in NAP 14.1-C, NNSA Baseline Cyber Security Program. 12. The contractor must document training requirements for all contractor personnel involved in C&A activities II-4 NAP 14.2-C 05-02-08 This page left intentionally blank. NAP 14.2-C III-1 05-02-08 CHAPTER III: CERTIFICATION AND ACCREDITATION (C&A) PROCESS National Nuclear Security Administration (NNSA) Office of the Chief Information Officer III-2 NAP 14.2-C 05-02-08 1. INTRODUCTION. This document is designed to implement applicable national-level and DOE requirements in the C&A of all NNSA systems and applications. This document is intended to provide a comprehensive and uniform approach for C&A. Ideally, the C&A process should be integrated into the system development life cycle during the capital planning and investment control process. During development, the ISSP should be written and the initial risk assessment completed in order to provide an assessment of the possible risks to the system. Additionally, the security-related documents listed in Appendix A through C of this document must be completed as appropriate during this process. Every NNSA system and major and minor application must have official approval to operate (ATO). This approval can consist of a formal accreditation which is valid for up to three years or until a security-significant change occurs, or the approval can be an Interim Approval to Operate (IATO), which is only valid for a maximum of six months. An IATO can be granted by the DAA provided DAA-approved protection measures are in place and functioning during the period of the IATO. Scope This document addresses the NNSA C&A process as adopted by the NNSA OCIO. Within this document, the four phases of C&A are detailed as well as supporting checklists and templates to be used during the process. This document must be used by all NNSA elements. Outcome The C&A methodology outlined in this document provides NNSA system owners and program managers with uniform guidance on how to their information systems are certified and accredited. Proper use of the C&A methodology will assure NNSA that the level of security implemented and controls in place adequately protect assets given an acceptable level of residual risk. NNSA will benefit from the C&A activities performed on information systems in the following ways: • Formal approval to operate • Standard security environment through utilization of baseline security requirements • Clearly defined system boundaries • Documented security plans • Defined and tested contingency plans • Established configuration management processes • Heightened information security awareness Validated security controls Measured levels of risk based on identified threats and vulnerabilities Defined security roles and responsibilities NAP 14.2-C III-3 05-02-08 Structure

Section 8

This document is organized into three major sections. Section 1 introduces the NNSA C&A Process. Section 2 provides a reference to the roles and responsibilities of the key parties involved in the C&A process. Section 3 describes the C&A process. A checklist has been included at the end of each phase. These checklists are designed to provide a quick reference for all participants in the process. Special Consideration - Interim Approval To Operate (IATO) An IATO may be deemed necessary by the Designated Approving Authority (DAA) if there is an overarching mission need to place a new system into operation or continue processing on an existing system. IATO Request Process The IATO Request process is a structured approach to monitor the effectiveness of the security controls in the information system during the IATO period. Consequently, the IATO Request submitted by the ISSM is used by the authorizing official to monitor the progress of correcting any deficiencies noted during the security certification, if that was the reason for the IATO. NNSA elements must maintain a copy of the IATO approval for record keeping, as well as for forwarding to appropriate personnel upon request. All deficiencies noted during the certification process that will be used as the basis for the IATO must be tracked in the system POA&M that is forwarded to the DAA with the IATO request. Reportable Conditions must be resolved within 180 days. Before a deficiency can be considered resolved, sites must provide their cognizant DAAs with verification documentation and formally request concurrence. Interim Authority to Test (IATT) Another option for interim processing is an Interim Authority to Test (IATT). If a system needs to be operational during the development phase, the DAA may approve an IATT for a maximum of six (6) months. In this case, the system developers and the DAA will agree via formal documentation as to what information groups can be processed on the system during the IATT as well as what security controls (i.e., management, operational, and technical), are temporarily required until the system can be successfully certified. Final Accreditation In accordance with OMB policy, an information system is not considered to have received its final accreditation during the period of IATO. When the reason for the IATO has been resolved, and any identified security-related deficiencies have been adequately addressed, the interim authorization should be lifted and the information system accredited to operate. III-4 NAP 14.2-C 05-02-08 2. ROLES AND RESPONSIBILITIES. The majority of roles and responsibilities for key participants in the NNSA C&A process are detailed in NAP 14.1-C, NNSA Baseline Cyber Security Program. Additional roles are described below. Certification Team (CT) The CT is responsible for conducting the certification activities. The CT is responsible for coordinating C&A activities and consolidating the final C&A package. The team will determine if the security controls are correctly implemented and effective. The CT will make this determination after receiving input from the ST&E Team. Security Test and Evaluation (ST&E) Team The ST&E team, whose membership must include the system’s ISSO, is responsible for performing the ST&E on the system and validating that the controls on the system are present and operating in accordance with the ISSP.

Section 9

The ST&E team must include one member who is independent of the system under evaluation in the sense that they should not have (a) been the developers of the system nor (b) be a privileged user of the system. In order to ensure independence and competence, the ST&E team and its technical qualifications must be approved by the Certification Agent (CA) prior to the commencement of the C&A process. The results of the ST&E, together with the rest of the certification package, will be presented by the ISSO to the CA so that they can make an accurate determination of the risk to the system, and thus provide an informed accreditation recommendation to the DAA. Program Manager and System Owner The program manager (if applicable) and system owner represent the interest of the user community and the information system throughout the system’s life cycle. The program manager is responsible for the system during initial development and acquisition and is concerned with cost, schedule and performance issues. The system owner assumes responsibility for the system after delivery and installation and is responsible for system operation, system maintenance, and disposal. Together they are responsible for ensuring the system is deployed and operated according to the security controls documented in the ISSP and are also responsible for seeing that system users and security support personnel receive the requisite security training. The program manager and system owner will ensure that the C&A effort is coordinated and provide the necessary resources and information to the CT. They will ensure the preparation of the certification package before it is presented to the CA. NAP 14.2-C III-5 05-02-08 3. CERTIFICATION AND ACCREDITATION PROCESS. Phase 1: Pre-Certification Phase 1 involves gathering information about the system to be certified, determining the scope of the certification effort, validating the initial ISSP for the system (if available), performing the initial validation of the risk assessment and system security controls, and determining the C&A schedule. During phase 1, the system owner or program manager will establish the certification schedule in coordination with all appropriate stakeholders. Step 1: Define the System and Scope of the C&A Effort During this phase, the CT gathers all available system information (e.g., design documents, system descriptions, graphics, system plans, and approved Interconnection Security Agreement) in order to get a comprehensive system description and to define the scope of the C&A effort. Defining the system involves identifying the software, hardware, and communications equipment within the system boundary which may impact security in order to understand what needs to be examined for the C&A effort. An information system is a set of information resources organized for the collection, storage, processing, maintenance, use, sharing, dissemination, disposition, display, or transmission of information. The process of uniquely assigning information resources to an information system defines the security accreditation boundary for that system. NNSA elements have flexibility in determining what constitutes an information system (i.e., major application or general support system) and the resulting security accreditation boundary that is associated with that information system. Both major applications and general support systems will be treated as an information system (i.e., “system”) and will undergo the certification and accreditation process described in NAP 14.2-C.

Section 10

A general support system is an interconnected set of information resources. Such a system can be, for example, a local area network (LAN) including smart terminals that supports a branch office, an agency-wide backbone, a communications network, a departmental data processing enter including its operating system and utilities, a tactical radio network, or a shared information processing service organization. Normally, the purpose of a general support system is to provide processing or communications support. A major application is an information system(s) that perform clearly defined functions for which there are readily identifiable security considerations and needs (e.g., an electronic funds transfer system). A major application comprises many components (e.g., hardware, software, and telecommunications components) that provide a common functionality. Major applications require special attention to security because of the risk and magnitude of the harm resulting from the loss, misuse, or unauthorized access to or modification of the information in the application. Note: All Federal applications require some level of protection. Certain applications, because of the information in them, however, require special management oversight and should be treated as III-6 NAP 14.2-C 05-02-08 major. Adequate security for other applications should be provided by security of the systems in which they operate. [From Appendix III, OMB A-130]. A software application alone without hardware and the supporting operating system is insufficient for consideration as an accreditation boundary. For example, a certification and accreditation Information System Security Plan (ISSP) for a major application could include a vulnerability management application, along with its supporting operating system(s) and hardware component(s). During Phase 1 the C&A key participants (e.g., DAA, CA, the program manager, the system owner, the certification team, the CSSO, other officials in the NNSA element or department that have an interest in the system) will agree on the scope and schedule for C&A activities. The CA must approve of the ST&E team and ensure they are technically competent prior to the commencement of the rest of the C&A process. Determine the Security/System Categorization Since the potential impact levels for the confidentiality, integrity, and availability security objectives may not be identical for an information system, the high water mark concept is used to determine the impact level of the information system. Thus, a low-impact system is defined as an information system in which all three of the security objectives are low. A moderate-impact system is an information system in which at least one of the security objectives is moderate and no security objective is high. And finally, a high-impact system is an information system in which at least one security objective is high. Once the overall impact level of the information system is determined, the minimum set of security control can be selected from the baseline controls in Chapter IV.. National Security Systems For national security systems, the certification team must use the methodology defined below for determining the system categorization (i.e., Control Baseline) based on the information system boundary, identification of information group(s), and Consequences of Loss (CoL) for Confidentiality.

Section 11

National security information is grouped (information group) based on sensitivity (classification level, category, and need-to-know). The following paragraph describes the information groups in increasing order of sensitivity (Top Secret Restricted Data considered the most sensitive). National Security Systems must be categorized based on the most sensitive information group they contain and the impact/CoL if the confidentiality, integrity and/or availability of the information is lost. The impact is determined through a CoL concept that ranks the perceived value of each information group in terms of confidentiality, integrity, and availability. Consequences of Loss – Classified Information. Tables III-1 through Table III-3 describe the criteria used to determine the CoL to confidentiality, integrity, and availability for all classified information. Table III-4 provides the results of the evaluation of impact of loss for each national security information group and represents the minimum CoL value for each information group. NAP 14.2-C III-7 05-02-08 Table III-1. CoL of Confidentiality Consequences of Loss Confidentiality High Unauthorized, premature, or partial disclosure may have a grave effect on National security, Senior DOE Management, DOE, or National interests. Moderate Serious damage to National security will result if confidentiality is lost; Information requiring protection mandated by policy, laws, or agreements between DOE, its contractors, and other entities, such as commercial organizations or foreign Governments; Information designated as mission- essential; or Unauthorized, premature, or partial disclosure may have an adverse effect on site-level interests. Low Damage to National security will result if confidentiality is lost; Information designated as sensitive by the data owner; or Unauthorized, premature, or partial disclosure may have an adverse effect on organizational interests. Table III-2. CoL of Integrity Consequences of Loss Integrity High Loss of integrity will have a serious effect on National-level interests or Loss of integrity will have a serious effect on confidentiality. Moderate A degree of integrity required for mission accomplishment, but not absolute; Bodily injury might result from loss of integrity; or Loss of integrity will have an adverse effect on organizational-level interests. Low Loss of integrity impacts only the missions of site- or office-level organization. Table III-3. CoL of Availability Consequences of Loss Availability High Loss of life might result from loss of availability; Information must always be available upon request, with no tolerance for delay; Loss of availability will have an adverse effect on National-level interests; Federal requirement (i.e., requirement for Material Control and Accountability (MC&A) inventory); or Loss of availability will have an adverse effect on confidentiality. Moderate Information must be readily available with minimum tolerance for delay; Bodily injury might result from loss of availability; or Loss of availability will have an adverse effect on organizational-level interests. Low Information must be available with flexible tolerance for delay. III-8 NAP 14.2-C 05-02-08 Note: In this context, “High – no tolerance for delay” means no delay; “Moderate – minimum tolerance for delay" means a delay of seconds to hours; and “Low – flexible tolerance for delay” means a delay of days to weeks

Section 12

Table III-4. CoL of Confidentiality, Integrity, and Availability Information Group Loss of Confidentiality Loss of Integrity Loss of Availability Confidential and Secret Information* Moderate Low Low Secret** and Top Secret Information High Low Low * Includes SRD, Sigmas 1, 2, 3, 4, 5, 9, 10, 11, 12, 13. 15 and 20 are grouped as moderate. ** Includes SRD, Sigmas 14. 1 Sigmas 6, 7, and 8 are not currently in use. NOTE: The levels in this table are the minimum values allowed by NNSA Senior Management or the operating unit may assign a higher level of consequence for any or all of the information groups. Unclassified Information Systems and Major Applications To determine the security categorization for unclassified information systems and major applications, the levels of risk must first be identified for confidentiality, integrity, and availability. FIPS PUB 199 provides guidance for assigning security categorization factors for information processed on Federal systems. Each factor is assigned a level of low, moderate, or high. Confidentiality provides assurance that the system data is protected from disclosure to unauthorized personnel, processes, or devices. Integrity provides assurance that the data processed by the system is protected from unauthorized, unanticipated, or unintentional modification or destruction. Availability provides assurance that the system data and resources will be available to authorized users on a timely and reliable basis. The format for documenting the security categorization is as follows: CATEGORIZATION = [(confidentiality, Potential Impact), (integrity, Potential Impact ), (availability, Potential Impact.)] Table III-5 below provides guidance on how to determine which risk-level of concern should be assigned to confidentiality, integrity, and availability. NAP 14.2-C III-9 05-02-08 Table III-5. Potential Impact for Confidentiality, Integrity, and Availability Risk Level Low Moderate High Confidentiality Preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information. [44 U.S.C §3542] The unauthorized disclosure of information could be expected to have a limited adverse effect on agency operations (including mission, functions, image, or reputation), agency assets, or individuals. A loss of confidentiality could be expected to cause a negative outcome or result in limited damage to operations or assets, requiring minor corrective repairs. The unauthorized disclosure of information could be expected to have a serious adverse effect on agency operations (including mission, functions, image, or reputation), agency assets, or individuals. A loss of confidentiality could be expected to cause significant degradation in mission capability, place the agency at a significant disadvantage, or result in major damage to assets, requiring extensive corrective actions or repairs. The unauthorized disclosure of information could be expected to have a severe or catastrophic adverse effect on agency operations (including mission, functions, image, or reputation), agency assets, or individuals. A loss of confidentiality could be expected to cause a loss of mission capability for a period that poses a threat to human life, or results in a loss of major assets. Integrity Guarding against improper information modification, destruction, and includes ensuring information non- repudiation and authenticity.

Section 13

[44 U.S.C. §3542] The unauthorized modification or destruction of information could be expected to have a limited adverse effect on agency operations (including mission, functions, image, or reputation), agency assets, or individuals. A loss of integrity could be expected to cause a negative outcome or result in limited damage to operations or assets, requiring minor corrective actions or repairs. The unauthorized modification or destruction of information could be expected to have a serious adverse effect on agency operations (including mission, functions, image, or reputation), agency assets, or individuals. A loss of integrity could be expected to cause significant degradation in mission capability, place the agency at a significant disadvantage, or result in major damage to assets, requiring extensive corrective actions or repairs. The unauthorized modification or destruction of information could be expected to have a severe or catastrophic adverse effect on agency operations (including mission, functions, image, or reputation), agency assets, or individuals. A loss of integrity could be expected to cause a loss of mission capability for a period that poses a threat to human life, or results in a loss of major assets. Availability Ensuring timely and reliable access to and The disruption of access to information could be expected to have a limited adverse effect on agency operations (including mission, The disruption of access to information could be expected to have a serious adverse effect on agency operations (including mission, The disruption of access to information could be expected to have a severe or catastrophic adverse effect on agency operations (including III-10 NAP 14.2-C 05-02-08 Risk Level Low Moderate High use of information. [44 U.S.C. §3542] functions, image, or reputation), agency assets, or individuals. A loss of availability could be expected to cause a negative outcome or result in limited damage to operations or assets, requiring minor corrective repairs. functions, image, or reputation), agency assets, or individuals. A loss of availability could be expected to cause significant degradation in mission capability, place the agency at a significant disadvantage, or result in major damage to assets, requiring extensive corrective actions or repairs. mission, functions, image, or reputation), agency assets, or individuals. A loss of availability could be expected to cause a loss of mission capability for a period that poses a threat to human life, or results in a loss of major assets. There are three information groups used to define unclassified information. They are Open, Public, Unrestricted Access; Unclassified Protected; and Unclassified Mandatory Protection. Table III-6 provides information regarding the minimum LoC for the confidentiality of unclassified information, along with their assigned Protection Indices. Sites are to determine the levels of concern for integrity and availability. Table III-6. Levels of Concern for Unclassified Information Information Group Definition LoC Open, Public, Unrestricted Access Information requires no protection from disclosure; e.g., approved for public release Low Unclassified Protected Information designated as requiring protection by the data owner or data steward. Low Unclassified Mandatory Protection/SUI Unclassified information requiring protection mandated by policy or laws. See NAP 14.1-C. Moderate

Section 14

Step 2: Identify Security Controls The security controls include management, operational, assurance, and technical controls for the system, as it will be operated, as well as environmental controls and physical security controls. During this step, the minimum set (baseline) of security controls that should be present on the system are identified and documented in the ISSP. The system categorization is used to select a minimum set of security controls from Chapter IV, as appropriate. Security controls that uniquely support the confidentiality, integrity, or availability security objectives may be downgraded to the corresponding control in a lower baseline (or appropriately modified or eliminated if not defined in a lower baseline) if, and only if the downgrading action: (i) is consistent with the security categorization for the corresponding security objectives of confidentiality, integrity, or availability before moving to the high water mark; (ii) is supported NAP 14.2-C III-11 05-02-08 by an organizational assessment of risk; and (iii) does not affect the security-relevant information within the information system. The following security controls are potential (although not all-inclusive) candidates for downgrading: (i) for confidentiality [AC-15, MA-3 (3), MP-3, MP-6, PE-5, SC-4, SC-9]; (ii) for integrity [SC-8]; and (iii) for availability [CP-2, CP-3, CP-4, CP-6, CP-7, CP-8, MA-6, PE-9, PE-10, PE-11, PE-13, PE-15, SC-6]. A risk review of the security physical, logical, and operational environment is conducted to identify any system or site unique threats/ vulnerabilities as well as identify any operational security practices required by the system owner/ data owner/ steward. Adjustments are made to the minimum set of security controls by identifying additional/ new security controls that will mitigate those threats/ vulnerabilities and/or implement the operational practices required by the system owner/ data owner/ steward. These additional controls may be selected (and modified as needed) from the security controls in Chapter IV, or new security controls may be created to satisfy these additional requirements. Additionally, system privacy implications are reviewed to include preparation of a Privacy Impact Assessment (PIA) for externally facing (publicly accessible) systems that contain privacy information and additional requirements needed to secure the system at the proper security/system categorization. Step 3: Conduct a Privacy Impact Assessment (PIA) if required If a PIA is required, it must be completed as detailed in “DOE Procedures for Conducting Privacy Impact Assessments”. A PIA is required whenever the system contains data covered under the Privacy Act of 1974 (Public Law 93-579), September, 1975, if the system is external facing. Step 4: Review the ISSP The ISSP provides a system description, a list of the security requirements for the system, and explains how the system security controls are implemented. The initial ISSP should be created during system development as part of the security requirements definition for the system. ISSPs should be updated whenever changes are made to the security posture of the system. See Chapter V for an outline of the ISSPs required contents.

Section 15

During this step, the existing ISSP should be reviewed by the system owner and CT to ensure that it describes the security controls required for the system. The CT will also verify that the control implementations described are appropriate for the security/system categorization and that the ISSP provides information about any user organizations, both internal and external, that connect to the system. If the system does interconnect with other systems or organizations not under the operational control of the sponsoring organization, details about the security controls on those connections shall be documented in an Interconnection Security Agreement (ISA). III-12 NAP 14.2-C 05-02-08 Step 5: Review the Initial Risk Assessment After the ISSP is reviewed, the initial risk assessment should be inspected to ensure that it identifies all apparent threats and vulnerabilities in the information system and is consistent with the guidance provided in the NNSA risk management methodology as described in NAP 14.1-C, NNSA Baseline Cyber Security Program. The risk assessment should also determine the overall level of risk present on the system given the type of data the system processes, the security controls on the system, and the system’s operating environment. The risk assessment is completed before the system is fielded to verify that the security requirements specified during development have been met. Risk assessments shall be updated every time there is a change to the security controls on the system that might affect the residual risk to the system. Step 6: Review the ISA If this system will be connected to other information systems under the responsibility of another certifying or accrediting authority, the requirements for connectivity with the other system must be identified. The ISA is started during the Initiation Phase of the System Development Life Cycle (SDLC) and is refined during the Acquisition/Development Phase. However, the ISA may not be completed until the actual system Implementation Phase. Additional requirements on ISAs are contained in NAP 14.1-C, Chapter XXI. Step 7: Negotiation After steps 1 through 4 are complete, all the participants, including the program manager, the system owner, and CT will review the extent and scope of the planned C&A effort. The participants should review the security/system categorization for the system and ensure that it is appropriate. At this point, a schedule is set forth for the remaining steps in the C&A effort. After successful negotiation, the DAA approves the security plan. The checklist in Figure III-1 on the following page provides a quick reference of all activities that should take place during Phase 1 of the C&A process. Figure III-1. Phase 1 Checklist Phase 1 Checklist Has the scope of the C&A effort been defined? Has the security/system categorization been determined and documented? Have the Minimum Set of Security Controls been identified? Have any additional controls been identified? Has a review of the approved ISA been done? Has a PIA been conducted, if required? NAP 14.2-C III-13 05-02-08 Has the Information System Security Plan been reviewed? Has the Risk Assessment been reviewed? Has the DAA approved the ISSP? Have any deviations (if applicable) been approved? Phase 2: Verification

Section 16

During the Verification phase, the ST&E team will conduct the testing to evaluate the effectiveness of the security controls on the information system, and then use the results of the ST&E to update the risk assessment and the ISSP, if necessary. The results of this phase will be documented in the final certification package. The certification package will then be presented to the DAA for a final accreditation decision. Step 1: Conduct a Security Test and Evaluation (ST&E) All controls identified in each ISSP are to be subjected to security control assessment procedure(s) during the C&A process to evaluate the status of control implementation with respect to security requirements and effectiveness. • Under a “System”, “Site”, or “Type” form of accreditation, each control must be subjected to a ST&E process. • Accreditation of additional instantiations (i.e., additional equivalent installations) may be based on a subset of the ST&E procedures used for the first instance. This subset, which is identified in the ST&E Procedures and approved by the DAA, must provide for overall assurance that future instantiations are equivalently implemented to the first instance. • The ST&E procedure(s) used for the assessment/evaluation of a control for each additional instance must not be modified from those used to evaluate the first instance. ST&E consists of three steps: creating the ST&E Plan, executing the test procedures, and documenting the results in the ST&E Report with recommended countermeasures. Create the ST&E Plan When developing the plan, testing objectives and ST&E procedure(s) shall be derived from the security controls identified in Phase 1. Each ST&E procedure, at a minimum, verifies that the security control is in effect and correctly implements the explicitly identified criteria in the control statement. ST&E procedure(s) must be developed for each control identified in the ISSP. III-14 NAP 14.2-C 05-02-08 Each ST&E procedure must identify the specific control and associated assessment method(s) used to evaluate the control and support the determination of the security control effectiveness. The following assessment methods will be used for the assessment of both unclassified and national security systems. • Interview: Focused discussions with individuals or groups to facilitate understanding, achieve clarification, or obtain evidence. • Examine: Checking, inspecting, reviewing, observing, studying, or analyzing one or more assessment objects to facilitate understanding, achieve clarification, or obtain evidence. • Test: Exercising one or more assessment objects under specific conditions to compare actual with expected behavior. Chapter VI, Security Category, describes the expected levels of assurances for the different impact levels (Low Baseline. Moderate Baseline, High Baseline) that must be used to guide the level of testing effort required for each impact level. Execute the Test Plan After the ST&E plan has been approved by the CA and the DAA, the test procedures in the plan shall be executed. An important part of the ST&E is a validated Contingency Plan and the careful review of security-related documentation, such as the risk assessment, PIA, ISSP, and the Contingency Plan in accordance with NNSA policy. Validation is achieved through (a) a table- top exercise, or exercising the plan and (b) documenting the results. These documents should be reviewed to ensure that they are 1) developed in accordance with the appropriate NNSA and Federal requirements, and 2) that they are up-to-date and usable for their intended purpose.

Section 17

Expected Results The expected results of the ST&E procedure must assure that all controls are specified, implemented, and operational consistent with the functional requirements of the control statement. Create the ST&E Report and Recommend Countermeasures After the testing activities are complete, the results from the testing should be documented in a ST&E report. The report should identify which controls are implemented effectively, which controls are implemented partially, and which controls are either not implemented, or are ineffective. These results will be used as input to update the risk assessment. After the ST&E report is complete, the system owner and the program manager should discuss the appropriate countermeasures to be implemented. These countermeasures should address any security requirements that were found to be not implemented or ineffective. Countermeasures NAP 14.2-C III-15 05-02-08 may be implemented immediately or may be included as part of a remediation plan and schedule for an IATO, or the situation may be accepted by the DAA. Step 2: Conduct a Risk Evaluation This step involves using the results from the ST&E Report to determine the remaining risk for the system once corrective actions have been implemented to address results from the ST&E. Any necessary updates to the system’s risk must be included in the form of an addendum to the system’s original risk evaluation. Risk should be determined for both individual test results and the overall system or application. This risk determination will be included as part of the certification package. Step 3: Update the ISSP and ISA The ISSP will be updated to reflect any additional security controls or implementation changes as a result of the ST&E activities and the final risk assessment. Updates should also be made in the approved ISA and, if required, the PIA. Step 4: Document Certification Findings Once the certification activities are complete, the ST&E team will document the results from the certification process in a ST&E Report. This report will annotate the results and any relevant security issues identified during certification activities. These results will be compiled along with the other certification documents into a certification package and forwarded to the CA for review Note: The ISSM and CA may be the same person. If they are not, then the certification package must be submitted to the ISSM by the CA. Figure III-2 shows the Verification Package contents. Phase 2: Verification Package Completed ST&E Report Approved ISSP including ISAs Completed PIA (if applicable) Completed SOR Notice if required Updated Risk Assessment Figure III-2. Verification Package Contents III-16 NAP 14.2-C 05-02-08 The CA will evaluate the risks and issues presented in the certification package. The CA then develops a Certification Statement that states the extent to which the system meets documented security requirements. As part of the Certification Statement, the CA also provides a recommendation for an accreditation decision The ISSM then submits the certification statement to the DAA. Phase 3: Validation of Certification/Accreditation Decision

Section 18

During the final step of Phase 3, the DAA will review the ST&E Report, weigh the residual risk, and decide whether to issue an accreditation or to deny accreditation. Based on an evaluation of residual risk, the ISSM’s recommendation, the DAA will make a risk-based decision to grant system accreditation or to deny system accreditation because the risks to the system are not at an acceptable level. The accreditation decision will be documented in the final accreditation package, which consists of the accreditation letter and supporting documentation. The following checklist in Figure III-3 provides a reminder of all the actions that should take place during Phase 3 of the C&A process. Phase 3 Checklist Has the ST&E Plan been created and approved? Has security testing been performed? Have Privacy Implications been reviewed (if required)? Has the approved ISA been reviewed? Has the ST&E Report been written? Has the Risk Evaluation been updated if required? If the ISSP has been updated, has the updated plan been approved by the DAA? Have the certification findings been documented? Has the certification package been forwarded to the ISSM? Has the ISSM reviewed the ST&E Report and forwarded it to the DAA? Has the DAA issued an accreditation decision? If so, has the DAA returned the C&A package to the ISSM? Figure III-3. Phase 3 Checklist NAP 14.2-C III-17 05-02-08 Phase 4: Post-Accreditation Phase During the post-accreditation phase, the system configuration will be managed to ensure that changes to the system are monitored, that they do not adversely affect the security posture of the system, and to facilitate follow-on C&A activities. Periodic testing (at least annually for critical infrastructure and key resources, and annually for all others) of the Contingency Plan and selected security controls is a necessary component of the Post-Accreditation Phase. Configuration Management Once the system or majo0r application has been officially accredited, the system owner must maintain configuration control over the system to ensure that the security posture of the system is not threatened by authorized or unauthorized changes to system software or hardware. Security-relevant changes that are implemented are documented in the ISSP , design documentation (for software code changes), and/or the inventory list (for hardware and/or software changes). Security-significant changes (e.g., security-relevant software version changes, and operating system changes.), as determined by the DAA, will require re- accreditation activities to ensure that the system has not incurred additional risk. Configuration Management and Control The purpose of this task is to define and document a baseline system configuration and document and assess proposed and actual changes to the information system. This task is composed of two sub-tasks. • Documentation of the Information System Changes. The system owner ensures that proposed and actual changes to the system are documented , and compares these to the baseline configuration. • Security Impact Analysis. The system owner ensures that each proposed or actual changes to the system are analyzed to determine the security impact. 4. SECURITY CONTROL MONITORING. The purpose of this task is to detect unauthorized changes to the system configuration through monitoring and annual assessment of a selected set of controls. This task is completed via three sub-tasks.

Section 19

• Security Control Selection. The ISSO ensures the selection of the technical, operational, assurance, and management security controls for monitoring and annual assessment. The selection of controls must be approved by the DAA. • Selected Security Control Assessment. The ISSO ensures the assessment of any controls designated in the ISSP as needing monitoring and performance of self-assessments annually on the remaining controls. III-18 NAP 14.2-C 05-02-08 • Status Reporting. The ISSO ensures that significant changes to the security posture of the information system are reported through the ISSM to the DAA. Reaccreditation Federal regulations mandate that systems be re-accredited every three (3) years or when security- significant changes are made to the system configuration. Program managers and system owners should keep this in mind when planning system changes. If the system is not significantly altered, the system owner should begin the C&A process for re-accreditation in a timely fashion to ensure that the process is complete before the three-year anniversary of the system accreditation has passed. The Figure III-4 on the following page shows the checklist of all the actions that should take place during Phase 4 of the C&A process. Phase 4 Checklist Has the system owner maintained configuration control? Have all security-relevant changes to the system been approved by the DAA ? Have the hardware and software inventories been updated every time the system configuration changed? If major system changes have been implemented, has the system been re-accredited in its new configuration? Is the three-year anniversary of the system accreditation approaching? If so, have plans for resources been made to begin the re-accreditation process? Figure III-4. Phase 4 Checklist NAP 14.2-C A-1 05-02-08 APPENDIX A ACCREDITATION LETTER SAMPLE Security Accreditation Decision Letter (Authorization to Operate) From: Authorizing Official Date: To: ISSM Subject: Security Accreditation Decision for [INFORMATION SYSTEM] After reviewing the results of the security certification of the [INFORMATION SYSTEM] and its constituent system-level components (if applicable) located at [LOCATION] and the supporting evidence provided in the associated security accreditation package (including the current ISSP and the Security Testing and Evaluation report), I have determined that the risk to agency operations, agency assets, or individuals resulting from the operation of the information system is acceptable. Accordingly, I am issuing an authorization to operate the information system at the Control Baseline in its existing operating environment. The information system is accredited without any significant restrictions or limitations. This security accreditation is my formal declaration that adequate security controls have been implemented in the information system and that a satisfactory level of security is present in the system. The security accreditation of the information system will remain in effect as long as: (i) the required security status reports for the system are submitted to this office every [TIME PERIOD]; (ii) any vulnerabilities reported during the continuous monitoring process do not result in additional agency-level risk which is deemed unacceptable; and (iii) the system has not exceeded the maximum allowable time period between security accreditations in accordance with Federal or agency policy. A copy of this letter with all supporting security C&A documentation should be retained for the period of the system’s accreditation.

Section 20

Signature Title Enclosures A-2 NAP 14.2-C 05-02-08 This page intentionally left blank. NAP 14.2-C B-1 05-02-08 APPENDIX B SAMPLE SECURITY ACCREDITATION DECISION LETTER INTERIM AUTHORIZATION TO OPERATE (IATO) Date: From: Authorizing Official To: ISSM Subject: Security Accreditation Decision for [INFORMATION SYSTEM] After reviewing the results of the security certification of the [INFORMATION SYSTEM] and its constituent system-level components (if applicable) located at [LOCATION] and the supporting evidence provided in the associated security accreditation package (including the current ISSP and the Security Test and Evaluation Report, I have determined that there is an overarching need to place the information system into operation or continue its operation due to mission necessity. Accordingly, I am issuing an interim authorization to operate the information system at the Control Baseline in its existing operating environment. An interim authorization is a limited authorization to operate the information system under specific terms and conditions for a limited period of time. The information system is not considered accredited during the period of limited authorization to operate. The terms and conditions of this limited authorization are described in Appendix A, Accreditation Letter Sample. A process must be established immediately to monitor the effectiveness of the security controls in the information system during the period of limited authorization. Monitoring activities should focus on the specific areas of concern identified during the security certification. Significant changes in the security state of the information system during the period of limited authorization should be reported immediately. This interim authorization to operate the information system is valid for [TIME PERIOD]. The limited authorization will remain in effect during that time period as long as: (i) the required security status reports for the system are submitted to this office every [TIME PERIOD]; (ii) any vulnerabilities reported during the continuous monitoring process do not result in additional agency-level risk which is deemed unacceptable; and (iii) continued progress is being made in the system’s progress toward full accreditation. At the end of the period of limited authorization, the information system must be authorized to operate or the authorization for further operation will be denied. This office will monitor the schedule submitted with the request for interim approval during the period of limited authorization. A copy of this letter with all supporting security C&A documentation must be retained with the system documentation until the system has achieved final accreditation. Signature Title Enclosures B-2 NAP 14.2-C 05-02-08 This page intentionally left blank. NAP 14.2-C C-1 05-02-08 APPENDIX C SAMPLE INTERCONNECTION SECURITY AGREEMENT Purpose – The purpose of this ISA is to identify and document to all signatories satisfaction: 1. Existing risks and mitigation strategies for all of the systems being interconnected, regardless of whether they are General Support Systems (GSS) or Major Applications (MA). Note: Any automated process that relies on Information Technology (IT) must be considered either a GSS or a MA. 2. Any additional risks and mitigation strategies introduced through the interconnection of systems not under the operation control of the sponsoring agency.

Section 21

3. Identification of systems participating in the interconnection,. 4. Appropriate levels of assurance to the satisfaction of all signatories that the documented risk and mitigation strategies are operating as stated and are effective. 5. Documentation of responsibilities and processes for mutual incident response and reporting; mutual management, maintenance, operation, and configuration management of the interface; and disconnection and re-connection of the systems. INTERCONNECTION STATEMENT OF REQUIREMENTS – This section should contain: A clear description of the systems covered by this agreement; Each system’s intended purpose and target community; Data sensitivity (i.e., classification) A description of the interconnection, including a graphic representation of the interconnection, the purpose of the interconnection, and a clear description of the authorities under which all of the systems operate. This includes statutory/regulatory requirements, project goals, and should also clearly state the responsible management units and system owners, and DAAs; This agreement shall be reviewed on an annual basis and amended whenever a security- relevant change to the systems concerned are planned. A change log and a new signature page should be attached whenever these events occur. SYSTEM SECURITY CONSIDERATIONS – General information, data descriptions and data/work flows should be documented in this section as well as risks and mitigation strategies C-2 NAP 14.2-C 05-02-08 so that a clear picture is presented to each participant of any residual risk. To that end, the following documents shall be included (where data sensitivity allows) with the ISA: Risk Assessments – A copy of the Risk Assessment for each system shall become an appendix to this agreement. Security Test and Evaluation Plan/Report – Security Test and Evaluation Plans and subsequent reports for systems included in this agreement shall be amended by all participants to include the details of the agreement. Security Assurance –Applicable Certification & Accreditation/Interim Authority to Operate Executive Summaries/Sign-Off – An Executive summary shall be prepared that is tied directly to the portion of the ISA that contains all appropriate signatures. Conditions for revocation of an ISA authority shall appear in this area as well. NAP 14.2-C IV-1 05-02-08 CHAPTER IV: NNSA MANAGEMENT, OPERATIONAL, AND TECHNICAL CONTROLS This is the NNSA implementation of the DOE CIO TMR-1. The selection and specification of security controls for an information system is accomplished as part of a Department-wide information security program that involves the management of organizational risk—that is, the risk associated with the operation of an information system. The management of organizational risk is a key element in the Department’s information security program and provides an effective framework for selecting the appropriate security controls for an information system—the security controls necessary to protect the operations and assets of the organization. Managing organizational risk includes several important activities: (i) assessing risk; (ii) conducting cost-benefit analyses; (iii) selecting, implementing, and assessing security controls; and (iv) formally authorizing the information system for operation (also known as security accreditation). The risk-based approach to security control selection and specification considers effectiveness, efficiency, and constraints due to applicable laws, Directives, Executive Orders, policies, standards, or regulations.

Section 22

This NNSA NAP implements National Institute of Standards and Technology (NIST) Federal Information Processing Standards (FIPS) Publication (PUB) 199, Standards for Security Categorization of Federal Information and Information Systems; FIPS PUB 200, Minimum Security Requirements for Federal Information and Information Systems; NIST Special Publication (SP) 800-53, Revision 1, Recommended Security Controls for Federal Information Systems, and the DOE cyber security program criteria for the implementation of management, operational, and technical controls for information systems, DOE M 205.1-4. This NAP defines NNSA requirements and recommended controls for information systems. The NNSA implementation of these security controls are based on the recommendations of the NIST SP 800-53, Revision 1 and the CNSS recommendations. The criteria are described by security control baseline (i.e., low, moderate, and high). Supplemental issue-specific NAPs provide more detail on some of the requirements and include processes for implementing the controls. This NAP follows the NIST SP 800-53, Revision 1, structure utilizing the control Classes, Families, and Identifiers as shown in Table D-1. To uniquely identify each control, a numeric identifier is appended to the Family identifier to indicate that control within the Family. For example, PL-1 represents control number 1 within the Planning Family. ”SPECIAL” INFORMATION SYSTEMS. Extensive technical protection measures may be inappropriate and unnecessarily expensive for some information systems (e.g., single-user standalone systems, and legacy systems). The DAA will determine which of the management, operational and technical controls contained in this NAP are to be applied to those systems in the NNSA Elements. IV-2 NAP 14.2-C 05-02-08 PROTECTION REQUIREMENTS FOR SENSITIVE UNCLASSIFIED INFORMATION (SUI). A comprehensive listing of NNSA requirements for the protection of SUI, including Personally Identifiable Information (PII) is not possible within the context of this chapter. See Chapter VII for additional requirements for the protection of SUI. Table IV-1 provides a listing of all cyber classes, families, and identifiers. Table IV-1. Cyber Security Control Classes, Families and Identifiers Class Family Identifier Management Risk Assessment RA Management Planning PL Management System and Services Acquisition SA Management Certification, Accreditation, and Security Assessment CA Operational Personnel Security PS Operational Physical and Environmental Protection PE Operational Contingency Planning CP Operational Configuration Management CM Operational Maintenance MA Operational System and Information Integrity SI Operational Media Protection MP Operational Incident Response IR Operational Awareness and Training AT Technical Identification and Authentication IA Technical Access Control AC Technical Audit and Accountability AU Technical System and Communications Protection SC The requirements provide a unified and consistent approach to security controls to be addressed in the NNSA element’s Cyber Security Program Plan (CSPP) and ISSPs. NAP 14.2-C IV-3 05-02-08 An NNSA Element may specify and implement additional requirements in its CSPP to address specific risks, vulnerabilities, or threats within its operating unit. REQUIREMENTS Managing Organizational Risk

Section 23

Each NNSA Element is to document its approach to managing organizational risk through the organization’s CSPP. NNSA Element Managers are responsible for developing, documenting in the CSPP, and implementing policies and processes to develop an acceptable control baseline for each information system appropriate to the impact level of the system (see Chapter VI, Security Category). The CSPP will also describe the risk management or mission impact rationale for all criteria not fully addressed in the implementation policies. The following activities related to managing organizational risk in the NNSA Element are paramount to an effective information security program and can be applied through the CSPP to both new and legacy information systems within the context of the System Development Life Cycle and the DOE Enterprise Architecture. • Categorize information systems and the information resident within the system based on an impact analysis using Table 6 in Chapter III. • Select an initial set of security controls (i.e., baseline) for the information system as a starting point for the risk assessment process, based on the FIPS 199 security categorization and the minimum security requirements defined in this document. • Document the set of security controls ISSP for the information system including the NNSA Element’s justification for any refinements or adjustments to the initial set of controls. • Implement the security controls in the information system. For existing systems, some or all of the security controls selected may already be in place. • Assess the security controls using appropriate methods and procedures to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system. • Authorize information system processing (or for legacy systems, authorize continued system processing) based upon a determination of the risk to organizational operations, organizational assets, or to individuals resulting from the operation of the information system and the decision that this risk is acceptable. • Monitor and assess selected security controls in the information system on a continuous basis including documenting changes to the system, conducting security impact analyses of the associated changes, and reporting the security status of the system to appropriate organizational officials on a regular basis. IV-4 NAP 14.2-C 05-02-08 The following conventions are used in this Chapter: • At the beginning of each Family section, a table is inserted which provides a summary of the controls required for that Family for each category of information system. Detailed information for each of the controls follows that table. • Supplemental guidance is provided for the controls. In some cases, supplemental guidance is also provided for Control Enhancements. This information is provided for additional clarification of the intent of the control. • Following each control’s requirements statements is a table summarizing the controls required for Low, Moderate, or High information systems. Where there is one table, the controls apply to both classified and unclassified systems. Where there are two lines to the table, the controls noted on the shaded line apply to classified systems; the controls noted on the unshaded line apply to unclassified systems. (See control AC-10 for an example.)

Section 24

NAP 14.2-C IV-5 05-02-08 FAMILY: ACCESS CONTROL CLASS: TECHNICAL The cyber security roles defined in the NNSA PCSP are responsible for managing and coordinating access controls within the operating unit and ensuring implementation and compliance with the following Access Control policy for each information system in the NNSA Element. Access Control Policy. Access control measures are designed to limit access to information system resources to authorized users, programs, processes, or other systems and to manage authorities and privileges granted to each user of the information system or application. These measures must include maintenance of 1) the association between a user identifier and an authenticator; 2) user authorizations and privileges; 3) user access to objects; 4) authority to grant access to objects and subjects; 5) authority to add, modify, and remove objects and subjects, 6) temporary and emergency accounts must be terminated within 24 hours, and 7) automatically disable inactive accounts within 3 months of the last use. Access Controls Protection Index Control Number Control Name Low Moderate High AC-1 Access Control Policy and Procedures AC-1 AC-1 AC-1 AC-2 Account Management AC-2 (1)(2)(3)(4) AC-2 (1)(2)(3)(4)(5) AC-2 (1)(2)(3)(4)(5) AC-3 Access Enforcement AC-3 AC-3 (1)(2)(3) AC-3 (1)(2)(3) AC-4 Information Flow Enforcement AC-4 AC-4 (1)(2) AC-4 (1) (2) AC-5 Separation of Duties AC-5 AC-5 AC-5 AC-6 Least Privilege AC-6 AC-6 (1) AC-6 (1) AC-7 Unsuccessful Logon Attempts AC-7 AC-7 AC-7 AC-8 System Use Notification AC-8 AC-8 AC-8 AC-9 Previous Logon Notification Not required at this time. NNSA Elements may elect, at their discretion, to ensure that information systems notify the user, upon successful logon, of the last logon and the number of unsuccessful logon attempts since the last successful logon. IV-6 NAP 14.2-C 05-02-08 Access Controls Protection Index Control Number Control Name Low Moderate High AC-10 AC-10 AC-10 Concurrent Session Control Not required Not Required AC-10 (1) AC-11 Session Lock AC-11 AC-11 AC-11 AC-12 Session Termination AC-12 AC-12 (1) AC-12 (1) AC-13 Supervision and Review – Access Control AC-13 AC-13 (1) AC-13 (1) AC-14 Permitted Actions without Identification and Authentication AC-14 AC-14 (1) AC-14 (1) AC-15 AC-15 AC-15 AC-15 Automated Marking Not Required AC-15 AC-15 AC-16 Automated Labeling Not required at this time. NNSA Elements may elect, at their discretion, to ensure that information in storage, in process, or in transmission is appropriately labeled by an information system. AC-17 Remote Access AC- 17(1) AC-17 (1)(2)(3)(4)(5)(6) AC-17 (1)(2)(3)(4)(5)(6)(7) AC-18 Wireless Access Restrictions AC-18 AC-18 (1)(2)(3)(4) AC-18 (1)(2)(3)(4) AC-19 Access Control for Portable and Mobile Devices AC-19 AC-19 (1) AC-19 (1) AC-20 Personally Owned Information Systems AC-20 AC-20 (1) AC-20 (1) AC-21 Confidentiality of Data at Rest AC-21 AC-21 AC-21 AC-22 Distinct Levels of Access AC-22 AC-22 AC-22 NAP 14.2-C IV-7 05-02-08 AC-1 ACCESS CONTROL POLICY AND PROCEDURES Control: NNSA Elements must develop, disseminate, and periodically review/update: a. A formal, documented, access control policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and

Section 25

b. Formal, documented procedures to facilitate the implementation of the access control policy and associated access controls. Supplemental Guidance: The access control policy and procedures are consistent with applicable laws, Executive Orders, directives, policies, regulations, standards, and guidance. The access control policy can be included as part of the general information security policy for the organization. Access control procedures can be developed for the security program in general, and for a particular information system, when required. Control Enhancements: None. LOW AC-1 MOD AC-1 HIGH AC-1 AC-2 ACCOUNT MANAGEMENT Control: Manage information system accounts, including establishing, activating, modifying, reviewing, disabling, and removing accounts. The NNSA Element will: a. Review information system accounts at least annually. b. Identify authorized users of the information system and specify access rights/privileges. c. Require proper identification for requests to establish information system accounts and approves all such requests. d. Authorize and monitor the use of guest/anonymous accounts and remove, disable, or otherwise secures unnecessary account. e. Notify account managers when information system users are terminated or transferred and associated accounts are removed, disabled, or otherwise secured. f. Notify account managers when users’ information system usage or need-to-know/need-- to-share changes. Supplemental Guidance: Account management includes the identification of account types (i.e., individual, group, and system), establishment of conditions for group membership, and assignment of associated authorizations. The organization should IV-8 NAP 14.2-C 05-02-08 consider the following aspects when granting access to the information and information systems: (i) A valid need-to-know/ need-to share that is determined by assigned official duties and satisfying all personnel security criteria; and (ii) Intended system usage. Control Enhancements: (1) The organization employs automated mechanisms to support the management of information system accounts. (2) The information system automatically terminates temporary and emergency accounts after 24 hours. (3) The information system automatically disables inactive accounts no later than 3 months after the last use. (4) The organization employs automated mechanisms to audit account creation, modification, disabling, and termination actions and to notify, as required, appropriate individuals. (5) The organization establishes and administers all privileged user accounts in accordance with a role-based access scheme that organizes all system and network privileges into roles (e.g., key management, network, system administration, database administration, Web administration). LOW AC-2(1)(2)(3)(4) MOD AC-2(1)(2)(3)(4)(5) HIGH AC-2(1)(2)(3)(4)(5) AC-3 ACCESS ENFORCEMENT Control: Enforce assigned authorizations for controlling access to the system in accordance with applicable policy.

Section 26

Supplemental Guidance: Access control policies (e.g., identity-based policies, role-based policies, rule-based policies) and associated access enforcement mechanisms (e.g., access control lists, access control matrices, cryptography) are employed by organizations to control access between users (or processes acting on behalf of users) and objects (e.g., devices, files, records, processes, programs, domains) in the information system. In addition to controlling access at the information system level, access enforcement mechanisms are employed at the application level, when necessary, to provide increased information security for the organization. Consideration is given to the implementation of a controlled, audited, and manual override of automated mechanisms in the event of emergencies or other serious events. If encryption of stored information is employed as an access enforcement mechanism, the cryptography used is FIPS 140-2 (as amended) compliant or NSA Type-1 Related security Control: SC13. Control Enhancements: NAP 14.2-C IV-9 05-02-08 (1) The information system restricts access to privileged functions (deployed in hardware, software, and firmware) and security-relevant information to explicitly authorized personnel. Enhancement Supplemental Guidance: Explicitly authorized personnel include, for example, security administrators, system and network administrators, and other privileged users. Privileged users are individuals who have access to system control, monitoring, or administration functions (e.g., system administrators, information system security officers, maintainers, system programmers). (2) The Mandatory Access Control (MAC), and/or Discretionary Access Control (DAC), and/or Role Based Access Control (RBAC) policies of the information system are implemented and configured to ensure only authorized users are able to perform security functions. (3) The MAC, DAC, and/or RBAC policies of the information system and/or Operating System (OS) are implemented and configured to protect security relevant objects from unauthorized access, modification, and deletion. In the case of applications which enforce the security policy but are outside the protections of a trusted OS, the application must maintain the ability to protect itself. LOW AC-3 MOD AC-3 (1)(2)(3) HIGH AC-3 (1)(2)(3) AC-4 INFORMATION FLOW ENFORCEMENT Control: Enforce assigned authorizations for controlling the flow of information within the system and between interconnected systems, as well as between shared components that transmit data at different levels, such as RD and NSI, in accordance with applicable policy. Supplemental Guidance: Information flow control regulates where information is allowed to travel within an information system and between information systems (as opposed to who is allowed to access the information) and without explicit regard to subsequent accesses to that information. Related security Control: SC7. Control Enhancements: (1) The information system implements information flow control enforcement using protected processing domains (e.g., domain type enforcement) as a basis for flow control decisions. (2) The information system implements information flow control enforcement using dynamic security policy mechanisms as a basis for flow control decisions. For further information on these policy mechanisms, refer to the Supplemental Guidance paragraphs for the control.

Section 27

IV-10 NAP 14.2-C 05-02-08 LOW AC-4 MOD AC-4 (1)(2) HIGH AC-4 (1)(2) AC-5 SEPARATION OF DUTIES Control: Enforce separation of duties through assigned access privileges. The NNSA Element separates duties as needed to eliminate conflicts of interest in the responsibilities and duties of individuals. Access control software resides on the information system that prevents users from having all of the necessary authority or information access to perform fraudulent activity without collusion. Supplemental Guidance: Examples of separation of duties include: (i) mission functions and distinct information system support functions are divided among different individuals/roles; (ii) different individuals perform information system support functions (e.g., system management, systems programming, quality assurance/testing, configuration management, and network security); and (iii) security personnel who administer access control functions do not administer audit functions. Through the use of access control software or site processes and procedures, users are prevented from having all of the necessary authority or information access to perform fraudulent activity without collusion. Control Enhancements: None. LOW AC-5 MOD AC-5 HIGH AC-5 AC-6 LEAST PRIVILEGE Control: The information system enforces the most restrictive set of rights/privileges or accesses needed by users (or processes acting on behalf of users) for the performance of specified tasks. Supplemental Guidance: The organization employs the concept of least privilege for specific duties and information systems (including specific ports, protocols, and services) in accordance with risk assessments as necessary to adequately mitigate risk to organizational operations, organizational assets, and individuals. Control Enhancement: (1) The organization ensures that privileged accounts are created for users to perform privileged functions only; that is, privileged users use non-privileged accounts for all non--privileged functions. Enhancement Supplemental Guidance: For example, SUDO for UNIX and Run As for a Windows system. NAP 14.2-C IV-11 05-02-08 LOW AC-6 (1) MOD AC-6 (1) HIGH AC-6 (1) AC-7 UNSUCCESSFUL LOGIN ATTEMPTS Control: Document in ISSPs and enforce a limit of no more than three consecutive invalid access attempts by a user during a two-hour time period. The information system must automatically lock the account/node for 15 minutes (or until authorized to be unlocked), or delays the next login prompt when the maximum number of unsuccessful attempts is exceeded. This control also applies to remote access logon attempts. Supplemental Guidance: Due to the potential for denial of service, automatic lockouts initiated by the information system are usually temporary and automatically release after a predetermined time period. Control Enhancements: None LOW AC-7 MOD AC-7 HIGH AC-7 AC-8 SYSTEM USE NOTIFICATION Control: Display an approved system-use notification message before granting system access informing potential users that: a. The user is accessing a U.S. Government information system; b. System usage may be monitored, recorded, and subject to audit; c. Unauthorized use of the system is prohibited and subject to criminal and civil penalties; and d. Use of the system indicates consent to monitoring and recording.

Section 28

The system use notification message provides appropriate privacy and security notices (based on associated privacy and security policies or summaries) and remains on the screen until the user takes explicit actions to log on to the information system. Supplemental Guidance: The following notice must be displayed: **WARNING**WARNING**WARNING**WARNING**WARNING** This is a Department of Energy (DOE) computer system. DOE computer systems are provided for the processing of official U.S. Government information only. All data contained within DOE computer systems is owned by the DOE, and may be audited, intercepted, recorded, read, copied, or captured in any manner and disclosed in any manner, by authorized personnel. THERE IS NO RIGHT OF PRIVACY IN THIS SYSTEM. System personnel may disclose any potential evidence of crime found on DOE computer systems to appropriate authorities. IV-12 NAP 14.2-C 05-02-08 USE OF THIS SYSTEM BY ANY USER, AUTHORIZED OR UNAUTHORIZED, CONSTITUTES CONSENT TO THIS AUDITING, INTERCEPTION, RECORDING, READING, COPYING, CAPTURING, and DISCLOSURE OF COMPUTER ACTIVITY. **WARNING**WARNING**WARNING**WARNING**WARNING** Control Enhancements: None. LOW AC-8 MOD AC-8 HIGH AC-8 AC-9 PREVIOUS LOGON NOTIFICATION Control: If technically feasible, the information system notifies the user, upon successful logon, of the date and time of the last logon. Supplemental Guidance: None Control Enhancement: (1) If technically feasible, the information system notifies the user, upon successful logon, of the number of unsuccessful logon attempts since the last successful logon. LOW Not required MOD Not required HIGH Not required AC-10 CONCURRENT SESSION CONTROL Control: Limit the number of concurrent sessions for any user to one session. Supplemental Guidance: Concurrent sessions are when a user accesses an information system once and invokes multiple sessions. Concurrent logons are when a user accesses an information system more than once from a logon/login perspective. Control Enhancements: (1) DAAs may make local determinations on the types of accounts (i.e., privileged) to which this applies. LOW Not required MOD AC-10 HIGH AC-10 LOW Not required MOD Not required HIGH AC-10(1) AC-11 SESSION LOCK NAP 14.2-C IV-13 05-02-08 Control: Prevent further access to the system by initiating a session lock after 10 minutes of inactivity, and the session lock remains in effect until the user reestablishes access using appropriate identification and authentication procedures. Supplemental Guidance: Users can directly initiate session lock mechanisms. A session lock is not a substitute for logging out of the information system. Control Enhancements: None LOW AC-11 MOD AC-11 HIGH AC-11 AC-12 SESSION TERMINATION Control: Automatically terminate a remote session after a period of inactivity specified in the system’s ISSP. Supplemental Guidance: A remote session is initiated whenever an organizational information system is accessed by a user (or an information system) communicating through an external, non- organization-controlled network (e.g., the Internet). Control Enhancements: (1) Automatic session termination applies to remote sessions. LOW AC-12 MOD AC-12(1) HIGH AC-12(1) AC-13 SUPERVISION AND REVIEW — ACCESS CONTROL Control: Supervise and review the activities of users with respect to the enforcement and usage of information system access controls.

Section 29

Supplemental Guidance: The organization reviews audit records (e.g., user activity logs) for inappropriate activities in accordance with organizational policies. The organization investigates any unusual information system-related activities and periodically reviews changes to access authorizations. The organization reviews more frequently the activities of users with significant information system roles and responsibilities. The extent of the audit record reviews is based on the Trust Levels of the information system. For example, for low-impact systems, it is not intended that security logs be reviewed frequently for every workstation, but rather at central points such as a Web proxy or e-mail servers and when specific circumstances warrant review of other audit records. Control Enhancement: IV-14 NAP 14.2-C 05-02-08 (1) The organization employs automated mechanisms to facilitate the review of user activities. LOW AC-13 MOD AC-13(1) HIGH AC-13(1) AC-14 PERMITTED ACTIONS WITHOUT IDENTIFICATION OR AUTHENTICATION Control: Identify and document specific user actions that can be performed on the information system without identification or authentication. Supplemental Guidance: The organization allows limited user activity without identification and authentication for public Web sites or other publicly available information systems (e.g., individuals accessing a Federal information system at http://www.firstgov.gov). Related security Control: IA2. Control Enhancement: (1) The organization permits actions to be performed without identification and authentication only to the extent necessary to accomplish mission objectives (e.g., a weapons system). LOW AC-14 MOD AC-14 (1) HIGH AC-14 (1) AC-15 MARKING Control: Mark output using standard naming conventions to identify any special dissemination, handling, or distribution instructions. Supplemental Guidance: The user or the system marks all output from the system (classified data and data requiring special handling) to reflect the classification and sensitivity of the data (e.g., classification level, classification category, and handling caveats). Markings shall be retained with the data. Markings will be in accordance with DOE M 470.4-4. Control Enhancements: None LOW AC-15 MOD AC-15 HIGH AC-15 LOW Not required MOD AC-15 HIGH AC-15 AC-16 AUTOMATED LABELING Control: The information system appropriately labels information in storage, in process, and in transmission. Information labeling is accomplished in accordance with: NAP 14.2-C IV-15 05-02-08 a. Access control requirements; b. Special dissemination, handling, or distribution instructions; or c. As otherwise required to enforce information system security policy. Supplemental Guidance: Automated labeling refers to labels employed on internal data structures (e.g., records, files) within the information system. Control Enhancements: (1) Data released by a producer shall either be explicitly or implicitly labeled. If the data is of a different classification or sensitivity than the source (e.g., session window) from which it was extracted, then the producer shall take some explicit action to associate the correct label with the data. (2) Implicit labels are generally based on the classification and sensitivity level of the communications session over which the data is sent, and are employed when the value of explicit labels associated with the data cannot be trusted.

Section 30

LOW Not required MOD Not required HIGH Not required AC-17 REMOTE ACCESS Control: Document, monitor, and control all methods of remote access (e.g., dial-up, Internet) to the information system including remote access for privileged functions. Appropriate organization officials authorize each remote access method for the information system and authorize only the necessary users for each access method. Supplemental Guidance: Remote access is any access to an organizational information system by a user (or an information system) communicating through an external, non-organization-controlled network (e.g., the Internet). Examples of remote access methods include dial-up, broadband, and wireless. Remote access controls are applicable to information systems other than public Web servers or systems specifically designed for public access. The organization restricts access achieved through dial-up connections (e.g., limiting dial-up access based upon source or request) or protects against unauthorized connections or subversion of authorized connections (e.g., using virtual private network technology). Control Enhancements: (1) The organization employs automated mechanisms to facilitate the monitoring and control of remote access methods. Policies and procedures of the user control group must be followed. (2) The organization uses cryptography to protect the confidentiality and integrity of remote access sessions. IV-16 NAP 14.2-C 05-02-08 (3) The organization controls all remote accesses through a limited number of managed access control points. (4) The organization permits remote access for privileged functions only for compelling operational needs and documents the rationale for such access in the security plan for the information system. (5) The information system restricts all remote access sessions by privileged users to those with strong authentication. Related to IA2. Enhancement Supplemental Guidance: Strong authentication is defined as the information system employs a multifactor authentication process and/or device to generate a onetime password that is highly resistant to replay attacks. (6) The organization ensures that users protect information about the remote access mechanisms from unauthorized use and disclosure. (7) The organization ensures that remote sessions for privileged user functions employ additional security measures and that each remote session is comprehensively audited. Enhancement Supplemental Guidance: Additional security measures are typically above and beyond standard bulk or session layer encryption (e.g., Secure Shell (SSH), or Virtual Private Networking with blocking mode enabled. LOW AC-17 (1) MOD AC-17 (1)(2)(3)(4)(5)(6) HIGH AC-17 (1)(2)(3)(4)(5)(6)(7) AC-18 WIRELESS ACCESS RESTRICTIONS Control: Establish usage restrictions and implementation guidance for wireless technologies and document, monitor, and control wireless access to the information system. Supplemental Guidance: None Control Enhancements: (1) The organization uses authentication and encryption to protect wireless access to the information system. Enhancement Supplemental Guidance: The appropriate level of encryption strength will be selected based on the classification and/or sensitivity of the data. (2) The organization scans for unauthorized wireless access points quarterly and takes appropriate action if such an access point is discovered.

Section 31

NAP 14.2-C IV-17 05-02-08 (3) The organization ensures that wireless computing and networking capabilities within all IT resources are implemented in accordance with organizational wireless policies and technical guidelines. (4) Wireless computing capabilities are not independently configured by end users, except through the use of approved scripts. Unused wireless computing and networking capabilities internally embedded in interconnected IT assets are normally disabled by changing factory defaults, settings or configurations prior to issue to end users. LOW AC-18 MOD AC-18 (1)(2)(3)(4) HIGH AC-18 (1)(2)(3)(4) AC-19 ACCESS CONTROL FOR PORTABLE AND MOBILE DEVICES Control: Establish usage restrictions and implementation guidance for portable and mobile devices and document, monitor, and control device access to organizational information systems. Supplemental Guidance: Portable and mobile devices (e.g., notebook computers, personal digital assistants, cellular telephones, and other computing and communications devices with network connectivity and the capability of periodically operating in different physical locations) are only allowed access to organizational information systems in accordance with organizational security policies and procedures. Security policies and procedures include device identification and authentication, implementation of mandatory protective software (e.g., malicious code detection, firewall), configuration management, scanning devices for malicious code, updating virus protection software, scanning for critical software updates and patches, conducting primary operating system (and possibly other resident software) integrity checks, and disabling unnecessary hardware (e.g., wireless, infrared). Related security controls: MP4 and MP5. Control Enhancement: (1) Employ removable hard drives or cryptography to protect information on portable and mobile devices. LOW AC-19 MOD AC-19(1) HIGH AC-19(1) AC-20 USE OF EXTERNAL INFORMATION SYSTEMS Control: Restrict the use of external information systems or components for official U.S. Government business involving the processing, storage, or transmission of Federal information. Supplemental Guidance: External information systems are information systems or components of information systems that are outside of the accreditation boundary established by the organization and for which the organization typically has no direct control over the application of required security controls or the assessment of security control effectiveness. External information systems include, but are not limited to, personally owned information systems (e.g., IV-18 NAP 14.2-C 05-02-08 computers, cellular telephones, or personal digital assistants); privately owned computing and communications devices resident in commercial or public facilities (e.g., hotels, convention centers, or airports); information systems owned or controlled by non-Federal Governmental organizations; and Federal information systems that are not owned by, operated by, or under the direct control of the organization.

Section 32

Authorized individuals include organizational personnel, contractors, or any other individuals with authorized access to the organizational information system. This control does not apply to the use of external information systems to access organizational information systems and information that are intended for public access (e.g., individuals accessing Federal information through public interfaces to organizational information systems). The organization establishes terms and conditions for the use of external information systems in accordance with organizational security policies and procedures. The terms and conditions address as a minimum; (i) the types of applications that can be accessed on the organizational information system from the external information system; and (ii) the maximum trust level and security impact category of information that can be processed, stored, and transmitted on the external information system. Control Enhancement: (1) Prohibit authorized individuals from using an external information system to access the Element’s information system or to process, store, or transmit organization controlled information except in situations where the organization: (a) Can verify the employment of required security controls on the external system as specified in the organization’s information security policy and system security plan; or (b) Has approved information system connection or processing agreements with the organizational entity hosting the external information system; or (c) The Element’s system being accessed has protections in place to mitigate deficiencies on the connecting system. LOW AC-20 MOD AC-20 (1) HIGH AC-20 (1) AC-21 CONFIDENTIALITY OF DATA AT REST Control: Encrypt data at rest if required by the information owner or Departmental policy. Supplemental Guidance: None Control Enhancements: None NAP 14.2-C IV-19 05-02-08 LOW AC-21 MOD AC-21 HIGH AC-21 AC-22 DISTINCT LEVELS OF ACCESS Control: Provide at least three distinct levels of access, regardless of user interface, to all internal classified, sensitive, and unclassified information. a. Open access to general information that is accessible to all authorized users with network access. Access does not require an audit transaction. b. Controlled access to information that is accessible to all authorized users upon the presentation of an individual authenticator. Access is recorded in an audit transaction. c. Restricted access to need-to-know information that is accessible only to an authorized community. Authorized users must present an individual authenticator and have either a demonstrated or validated need-to-know. All access to need-to-know information and all failed access attempts are recorded in audit transactions. Supplemental Guidance: None Control Enhancements: None. LOW AC-22 MOD AC-22 HIGH AC-22 FAMILY: AWARENESS AND TRAINING CLASS: OPERATIONAL Cyber security awareness consists of reminders that focus the user’s attention on the concept of cyber security in the user’s daily routine. Awareness provides a general cognizance or mindfulness of one’s actions, and the consequences of those actions. Cyber security training develops skills and knowledge so computer users can perform their jobs more securely and build in-depth knowledge, producing relevant and necessary security skills and competencies in those who access or manage NNSA information and resources.

Section 33

Training Policy. Once granted legitimate access, authenticated users are expected to use information system resources and information only in accordance with the organizational security policy. In order for this to be possible, these users must be adequately trained both to understand the purpose and need for security controls and to be able to make secure decisions with respect to their discretionary actions. Authenticated users of the system must be adequately trained, enabling them to (1) effectively implement organizational security policies with respect to their discretionary actions and (2) support the need for non-discretionary controls implemented to enforce these policies prior to being granted access to information. IV-20 NAP 14.2-C 05-02-08 Awareness and Training Control Baselines Control Number Control Name Low Moderate High AT-1 Security Awareness and Training Policy and Procedures AT-1 AT-1 AT-1 AT-2 Security Awareness AT-2 AT-2 AT-2 AT-3 Security Training AT-3 AT-3 AT-3 AT-4 Security Training Records AT-4 AT-4 AT-4 AT-5 Contact with Security Groups and Associations Not required at this time. AT-1 SECURITY AWARENESS AND TRAINING POLICY AND PROCEDURES Control: Develop, document, disseminate, and periodically review and/or update: a. A formal, documented, security awareness and training policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and b. Formal, documented procedures to facilitate the implementation of the security awareness and training policy and associated security awareness and training controls. Supplemental Guidance: The security awareness and training policy and procedures are consistent with applicable laws, Executive Orders, directives, policies, regulations, standards, and guidance. The security awareness and training policy can be included as part of the general information security policy for the organization. Security awareness and training procedures can be developed for the security program in general, and for a particular information system, when required. Control Enhancements: None. LOW AT-1 MOD AT-1 HIGH AT-1 AT-2 SECURITY AWARENESS Control: Provide security awareness training within 30 days to all information system users (including managers and senior executives) before authorizing access to the system, when required by system changes, and at least annually thereafter. This instruction must present a core NAP 14.2-C IV-21 05-02-08 set of generic cyber security terms and concepts for all personnel (Federal employees and contractors) as a baseline for role=based learning, expands on those basic concepts, and provides a mechanism for students to relate and apply the information learned on the job. Supplemental Guidance: The organization determines the appropriate content of security awareness training based on the specific requirements of the organization and the information systems to which personnel have authorized access. Control Enhancements: None. LOW AT-2 MOD AT-2 HIGH AT-2 AT-3 SECURITY TRAINING Control: Identify personnel with significant information cyber security roles and responsibilities, document those roles and responsibilities, and provides appropriate cyber security training before authorizing access to the system. Establish and, at least bi-annually (every two years), execute training plans for these personnel covering the training topics described in NIST SP 800- 16, Information Technology Security Training Requirements: A Role- and Performance-Based Model.

Section 34

Supplemental Guidance: The organization determines the appropriate content of security training based on the specific requirements of the organization and the information systems to which personnel have authorized access. In addition, the organization provides system managers, system and network administrators, and other personnel having access to system-level software, adequate technical training to perform their assigned duties. Control Enhancements: None. LOW AT-3 MOD AT-3 HIGH AT-3 AT-4 SECURITY TRAINING RECORDS Control: Document and monitor individual information system security training activities including basic security awareness training and specific information system security training. Supplemental Guidance: None Control Enhancements: None. LOW AT-4 MOD AT-4 HIGH AT-4 IV-22 NAP 14.2-C 05-02-08 AT-5 CONTACTS WITH SECURITY GROUPS AND ASSOCIATIONS Control: Establish and maintain contacts with special interest groups, specialized forums, professional associations, news groups, and/or peer groups of security professionals in similar organizations to stay up to date with the latest recommended security practices, techniques, and technologies and to share the latest security related information including threats, vulnerabilities, and incidents. Supplemental Guidance: To facilitate ongoing security education and training for organizational personnel in an environment of rapid technology changes and dynamic threats, the organization establishes and institutionalizes contacts with selected groups and associations within the security community. The groups and associations selected are in keeping with the organization’s mission requirements. Information sharing activities regarding threats, vulnerabilities, and incidents related to information systems are consistent with applicable laws, Executive Orders, directives, policies, regulations, standards, and guidance. Control Enhancements: None. LOW Not required MOD Not required HIGH Not required FAMILY: AUDIT AND ACCOUNTABILITY CLASS: TECHNICAL Audit trails maintain a record of system activity by system or application processes and by user activity. In conjunction with appropriate tools and procedures, audit trails can support individual accountability, a means to reconstruct events, detect intrusions, and identify problems. System audit trails, or event logs, provide a record of events in support of activities to monitor and enforce the information system security policy. Audit and Accountability Control Baselines Control Number Control Name Low Moderate High AU-1 Audit and Accountability AU-1 AU-1 AU-1 NAP 14.2-C IV-23 05-02-08 Audit and Accountability Control Baselines Control Number Control Name Low Moderate High Policy and Procedures AU-2 Auditable Events AU-2 AU-2 AU-2 (1)(2) AU-3 Content of Audit Records AU-3 AU-3 (1) AU-3 (1) (2) AU-4 Audit Storage Capacity AU-4 AU-4 AU-4 AU-5 Response to Audit Processing Failures AU-5 AU-5(1) AU-5 (1)(2) AU-6 Audit Monitoring, Analysis, and Reporting AU-6 AU-6 (1) AU-6 (1)(2)(3) AU-7 Audit Reduction and Report Generation AU-7 AU-7 (1) AU-7 (1) AU-8 Time Stamps AU-8 AU-8 AU-8 (1) AU-9 Protection of Audit Information AU-9 AU-9 (1) AU-9 (1) AU-10 Non-repudiation AU-10 AU-10 AU-10 AU-11 Audit Retention AU-11 AU-11(1) AU-11(1) AU-12 Session Audit Not required. (See information at AU-12.)

Section 35

AU-1 AUDIT AND ACCOUNTABILITY POLICY AND PROCEDURES Control: Document, disseminate, and periodically review and/or update: a. A formal, documented, audit and accountability policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and b. Formal documented procedures to facilitate the implementation of the audit and accountability policy and associated audit and accountability controls. Supplemental Guidance: The audit and accountability policy can be included as part of the general information security policy for the organization. Audit and accountability procedures can be developed for the security program in general, and for a particular information system, when required. IV-24 NAP 14.2-C 05-02-08 Control Enhancements: None LOW AU-1 MOD AU-1 HIGH AU-1 AU-2 AUDITABLE EVENTS Control: As a minimum, the following auditable events must be captured: o Start-up and shutdown of the audit functions; o Successful use of the user security attribute administration functions o All attempted uses of the user security attribute administration functions o Identification of which user security attributes have been modified o Successful and unsuccessful logons and logoffs o Unsuccessful access to security relevant files including creating, opening, closing, modifying, and deleting those files o Changes in user authenticators o Blocking or blacklisting user IDs, terminals, or access ports o Denial of access for excessive logon attempts o System access by privileged users (privileged activities at the system (either physical or logical consoles) and other system-level access by privileged users). Users will not have administrative privileges to local systems, unless the systems are standalone. o Starting and ending times for each access to the system. Supplemental Guidance: The purpose of this control is to identify important events which need to be audited as significant and relevant to the security of the information system. Audit records can be generated at various levels of abstraction, including at the packet level as information traverse the network. Selecting the right level of abstraction for audit record generation is a critical aspect of an audit capability and can facilitate the identification of root causes to problems. Additionally, the security audit function is coordinated with the network health and status monitoring function to enhance the mutual support between the two functions. Control Enhancements: NAP 14.2-C IV-25 05-02-08 (1) The information system provides the capability to compile audit records from multiple components throughout the system into a system wide (logical or physical), time correlated audit trail. (2) The information system provides the capability to manage the selection of events to be audited by individual components of the system. (3) The organization periodically reviews and updates the list of organization-defined auditable events. LOW AU-2 MOD AU-2 HIGH AU-2 (1) (2) AU-3 CONTENT OF AUDIT RECORDS Control: Capture sufficient information in audit records to establish date and time of the event, what events occurred, the sources of the events, and the outcomes of the events.

Section 36

Supplemental Guidance: Examples of audit record content includes: (i) date and time of the event; (ii) the component of the information system (e.g., software component, hardware component) where the event occurred; (iii) type of event; (iv) user and/or subject identity; and (v) the outcome (success or failure) of the event. Auditable events are defined under AU2. Control Enhancements: (1) The information system provides the capability to include additional, more detailed information in the audit records for audit events identified by type, location, or subject. (2) The information system provides the capability to centrally manage the content of audit records generated by individual components throughout the system. LOW AU-3 MOD AU-3 (1) HIGH AU-3 (1) (2) AU-4 AUDIT STORAGE CAPACITY Control: Allocate sufficient audit record storage capacity and configure auditing to prevent such capacity being exceeded. Records that exceed the storage capacilty can be backed up to a different file. Supplemental Guidance: The organization provides sufficient audit storage capacity, taking into account the auditing to be performed and the online audit processing requirements. Related security controls: AU2, AU5, AU6, AU7 and SI4. Control Enhancements: None. IV-26 NAP 14.2-C 05-02-08 LOW AU-4 MOD AU-4 HIGH AU-4 AU-5 RESPONSE TO AUDIT PROCESSING FAILURES Control: In the event of an audit failure or 80% of audit storage capacity being reach, alert appropriate organization officials and take the additional actions specified by the system’s ISSP; e.g., shut down the system, overwrite oldest audit records, stop generating audit records. Supplemental Guidance: Audit processing failures include, for example, software and/or hardware errors, failures in the audit capturing mechanisms, and audit storage capacity being reached or exceeded. Related security Control: AU4. Control Enhancements: (1) The information system provides a warning when allocated audit record storage volume reaches [Assignment: the percentage of maximum audit record storage capacity, as specified in the information system SSP]. (2) The information system provides a real-time alert when the audit failure events occur: [Assignment: audit failure events requiring real-time alerts, as specified in the information system SSP]. LOW AU-5 MOD AU-5(1) HIGH AU-5 (1) (2) AU-6 AUDIT MONITORING, ANALYSIS, AND REPORTING Control: Regularly review and/or analyze information system audit records for indications of inappropriate or unusual activity, investigate suspicious activity or suspected violations, report findings to appropriate officials, and take necessary actions. Supplemental Guidance: Organizations increase the level of audit monitoring and analysis activity within the information system whenever there is an indication of increased risk to organizational operations, organizational assets, or individuals based on law enforcement information, intelligence information, or other credible sources of information. Control Enhancements: (1) The organization reviews the audit records at least on a weekly basis and reports findings to appropriate officials, and takes necessary actions. NAP 14.2-C IV-27 05-02-08 (2) The organization employs automated mechanisms to immediately alert security personnel of inappropriate or unusual activities with security implications.

Section 37

(3) The organization employs automated mechanisms to integrate audit monitoring, analysis, and reporting into an overall process for investigation and response to suspicious activities. (4) The information system provides the ability for an administrator to set alert thresholds for all auditable events. Enhancement Supplemental Guidance: Alert thresholds should be measured in terms of a utilization level maintained for a defined time period. Short spikes in the system health metrics should not normally be cause for alarm, rather abnormal levels over time should be cause for alarm. (5) The information system enforces configurable thresholds to determine whether or not all network traffic can be handled and controlled. If a threshold has been met, the system shall process existing traffic until the threshold has been reduced before accepting new traffic for processing. LOW AU-6 MOD AU-6 (1) HIGH AU-6 (1) (2) (3) (4) (5) AU-7 AUDIT REDUCTION AND REPORT GENERATION Control: Provide an audit reduction and report generation capability for each information system. Note that it may not be possible to perform reduction of audit logs on all machines, especially on embedded systems. Supplemental Guidance: Audit reduction, review, and reporting tools support after the fact investigations of security incidents without altering original audit records. Control Enhancements: (1) The information system provides the capability to automatically process audit records for events of interest based upon selectable, event criteria. LOW AU-7 MOD AU-7 (1) HIGH AU-7 (1) AU-8 TIME STAMPS Control: Provide time stamps for use in audit record generation. IV-28 NAP 14.2-C 05-02-08 Supplemental Guidance: Time stamps (including date and time) of audit records are generated using internal system clocks. Control Enhancements: (1) The organization synchronizes internal information system clocks quarterly. LOW AU-8 MOD AU-8 HIGH AU-8 (1) AU-9 PROTECTION OF AUDIT INFORMATION Control: Protect system audit information and audit tools from unauthorized access, modification, and deletion. Supplemental Guidance: Audit information includes all information (e.g., audit records, audit settings, and audit reports) needed to successfully audit information system activity. Control Enhancement: (1) The information system will back up the audit records not less than weekly onto a different system or media than the system being audited. LOW AU-9 MOD AU-9 (1) HIGH AU-9 (1) AU-10 NONREPUDIATION Control: The information system provides the capability to determine whether a given individual took a particular action. Supplemental Guidance: Examples of particular actions taken by individuals include creating information, sending a message, approving information (e.g., indicating concurrence or signing a contract), and receiving a message. Nonrepudiation protects against later false claims by an individual of not having taken a specific action. Nonrepudiation protects individuals against later claims by an author of not having authored a particular document, a sender of not having transmitted a message, a receiver of not having received a message, or a signatory of not having signed a document. Nonrepudiation services can be used to determine if information originated from an individual, or if an individual took specific actions (e.g., sending an e-mail, signing a contract, approving a procurement request) or received specific information. Non-repudiation services are obtained by employing various techniques or mechanisms (e.g., digital signatures, digital message receipts, time stamps).

Section 38

Control Enhancements: (1) The information system associates the identity of the data producer with the data itself. NAP 14.2-C IV-29 05-02-08 Enhancement Supplemental Guidance: Supports audit requirements that allow appropriate authorities the means to identify who produced the data. (2) The information system validates the binding of the producer's identity to the data. Enhancement Supplemental Guidance: This mitigates the risk that data is modified between production and review. A typical approach is validation of a cryptographic checksum. (3) The information system will maintain reviewer and/or releaser identity and credentials within the chain of custody, as well as the integrity of data labels and markings for all information that is reviewed and/or released. Enhancement Supplemental Guidance: If the reviewer is a human or if the review function is automated but separate from the release and/or transfer function, then the information system associates the identity of the reviewer of the data to be released with the data itself and the data’s label and marking. In the case of a human reviewer, this requirement provides appropriate authorities the means to identify who reviewed and released the data, and in the case of automated reviewers, this helps ensure that only the approved review function was employed. (4) The information system validates the binding of the reviewer’s identity to the data and label and marking at the transfer and/or release point prior to release and/or transfer to another domain. Enhancement Supplemental Guidance: This mitigates the risk that data is modified between review and transfer and/or release. LOW AU-10 MOD AU-10 HIGH AU-10 AU-11 AUDIT RECORD RETENTION Control: Retain audit records for the time period specified in the system’s ISSP and as consistent with Departmental and National Archives and Records Administration retention periods, to provide support for after-the-fact investigations of security incidents and to meet regulatory and organizational information retention requirements. Supplemental Guidance: The organization retains audit records until it is determined that they are no longer needed for administrative, legal, audit, or other operational purposes. This includes, for example, retention and availability of audit records relative to Freedom of Information Act (FOIA) requests, subpoena, and law enforcement actions. Standard categorizations of audit records relative to such types of actions and standard response processes for each type of action are developed and disseminated. Audit retention time period will be in accordance with Federal Laws, Statutes, and national policy. IV-30 NAP 14.2-C 05-02-08 Control Enhancements: (1) The organization retains audit records for at least 6 months. LOW AU-11 MOD AU-11 (1) HIGH AU-11 (1) AU-12 SESSION AUDIT Control: The information system has the ability to remotely view, listen to, log, and capture all content related to a specific user in real time. Supplemental Guidance: There are legal issues related to this ability, and thus it should be developed, integrated, and used under the guidance of legal counsel. Control Enhancements: (1) The information system provides the ability to capture the entire session data associated with a user in real-time. (2) The information system has the ability to initiate the audit processes at system startup.

Section 39

LOW Not required MOD Not required HIGH Not required FAMILY: CERTIFICATION, ACCREDITATION, AND SECURITY ASSESSMENTS CLASS: MANAGEMENT C&A is the process of formal assessment, testing (certification), and acceptance (accreditation) of system security controls that protect information systems and data stored in and processed by those systems. It is a process that encompasses the system’s life cycle and ensures that the risk of operating a system is recognized, evaluated, and accepted. The C&A process implements the concept of “adequate security,” or security commensurate with risk, including the magnitude of harm resulting from the unauthorized access, use, disclosure, disruption, modification, or destruction of information. Certification, Accreditation, and Security Assessment Control Baselines Control Number Control Name Low Moderate High NAP 14.2-C IV-31 05-02-08 Certification, Accreditation, and Security Assessment CA-1 Certification, Accreditation, and Security Assessment Policies and Procedures CA-1 CA-1 CA-1 CA-2 Security Assessments CA-2 CA-2 CA-2 CA-3 Information System Connections CA-3 CA-3 CA-3 CA-4 Security Certification CA-4(1) CA-4(1) CA-4 (1) CA-5 Plan of Action and Milestones CA-5 CA-5 CA-5 CA-6 Security Accreditation CA-6 CA-6 CA-6 CA-7 Continuous Monitoring CA-7 CA-7 (1) CA-7 (1)(2) CA-1 CERTIFICATION, ACCREDITATION, AND SECURITY ASSESSMENT POLICIES AND PROCEDURES Control: Develop, disseminate, and periodically review and/or update: a. Formal, documented, security assessment and C&A policies that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and b. Formal, documented procedures to facilitate the implementation of the security assessment and C&A policies and associated assessment, certification, and accreditation controls. Supplemental Guidance: The security assessment and C&A policies and procedures are consistent with applicable laws, Executive Orders, directives, policies, regulations, standards, and guidance. The organization, in concert with the DAA, defines what constitutes a significant change to the information system to achieve consistent security reaccreditations. Control Enhancements: None. LOW CA-1 MOD CA-1 HIGH CA-1 IV-32 NAP 14.2-C 05-02-08 CA-2 SECURITY ASSESSMENTS Control: Conduct an assessment of the security controls in the information system at least annually to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system. Supplemental Guidance: This control is intended to support the FISMA requirement that the management, operational, and technical controls in each information system contained in the inventory of major information systems and applications be assessed with a frequency depending on risk, but no less than annually. To satisfy the annual FISMA assessment requirement, organizations can draw upon the security control assessment results from any of the following sources, including but not limited to: (i) security certifications conducted as part of an information system accreditation or reaccreditation process (see CA4); (ii) continuous monitoring activities (see CA7); or (iii) testing and evaluation of the information system as part of the ongoing system development life cycle process (provided that the testing and evaluation results are current and relevant to the determination of security control effectiveness).

Section 40

Related security controls: CA4, CA6, CA7 and SA11. Control Enhancements: None. LOW CA-2 MOD CA-2 HIGH CA-2 CA-3 INFORMATION SYSTEM INTERCONNECTIONS Control: Explicitly authorize all interconnections between information systems, as well as between shared components that transmit data at different levels, such as RD and NSI, from different certification or accreditation boundaries through the use of system connection agreements (where applicable) and monitor and/or control the system interconnections on an ongoing basis. Supplemental Guidance: Since security categorizations apply to individual information systems, as well as the enterprise NNSA Elements should carefully consider the risks that may be introduced when systems are connected to other information systems with different security requirements and security controls, both within the organization and external to the organization. Risk considerations also include information systems sharing the same networks. Related security controls: SC7 and SA9. Control Enhancements: None. LOW CA-3 MOD CA-3 HIGH CA-3 NAP 14.2-C IV-33 05-02-08 CA-4 SECURITY CERTIFICATION Control: Perform an assessment of the security controls in the information system to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system. Supplemental Guidance: A security certification is conducted by the organization in support of the requirement for accrediting the information system. The security certification is a key factor in all security accreditation (i.e., authorization) decisions and is integrated into and spans the system development life cycle. The organization assesses all security controls in an information system during the initial security accreditation. Subsequent to the initial accreditation and in accordance with OMB policy, the organization assesses a subset of the controls annually during continuous monitoring (see CA7). The organization can use the current year’s assessment results obtained during security certification to meet the annual FISMA assessment. Control Enhancement: (1) Employ a certification agent or certification team to conduct an assessment of the security controls in the information system. Enhancement Supplemental Guidance: A certification agent or certification team is any individual or group capable of conducting an impartial assessment of an organizational information system. LOW CA-4 (1) MOD CA-4 (1) HIGH CA-4 (1) CA-5 PLAN OF ACTION AND MILESTONES Control: Based on DAA determination, develop a plan of action and milestones (POA&M) for the information system that documents the organization’s planned, implemented, and evaluated remedial actions to correct deficiencies and to reduce or eliminate known vulnerabilities in the system. The POA&M must be updated quarterly. Supplemental Guidance: If the DAA considers it necessary, the plan of action and milestones updates are based on the findings from security control assessments, security impact analyses, and continuous monitoring activities. OMB FISMA reporting guidance contains instructions regarding organizational plans of action and milestones. Control Enhancements: None. LOW CA-5 MOD CA-5 HIGH CA-5 IV-34 NAP 14.2-C 05-02-08 CA-6 SECURITY ACCREDITATION

Section 41

Control: Authorize (i.e., accredit) the information system for processing before operations and update the authorization at least every three years or when there is a significant change to the system. Supplemental Guidance: Security assessments conducted in support of security accreditations are called security certifications. The security accreditation of an information system is not a static process. Related security controls: CA2, CA4 and CA7. Control Enhancements: None. LOW CA-6 MOD CA-6 HIGH CA-6 CA-7 CONTINUOUS MONITORING Control: Continuously monitor the effectiveness and adequacy of security controls in the information system.. As a minimum, those security controls that are volatile or critical to protecting the information system are assessed at least annually. Testing of critical infrastructure and key resources must be accomplished annually; bi-annual testing must be accomplished for all other resources. Supplemental Guidance: The organization assesses all security controls in an information system during the initial security accreditation. Subsequent to the initial accreditation and in accordance with national policy, the organization assesses a subset of the controls annually during continuous monitoring. The selection of an appropriate subset of security controls is based on: (i) the security categorization of the information system and risk to the information system; (ii) the specific security controls selected and employed by the organization to protect the information system; and (iii) the level of assurance (or grounds for confidence) that the organization must have in determining the effectiveness of the security controls in the information system. The organization can use the current year’s assessment results obtained during continuous monitoring to meet the annual FISMA assessment requirement (see CA2). This control is closely related to and mutually supportive of the activities required in monitoring configuration changes to the information system. A rigorous and well executed continuous monitoring process significantly reduces the level of effort required for the reaccreditation of the information system. Related security controls: CA2, CA4, CA5, CA6 and CM4. Control Enhancements: (1) The organization employs a certification agent or certification team to monitor the security controls in the information system on an ongoing basis. NAP 14.2-C IV-35 05-02-08 (2) The organization will plan, schedule, and conduct performance testing that includes periodic, unannounced in-depth monitoring and specific penetration testing to ensure compliance with all vulnerability mitigation procedures. LOW CA-7 MOD CA-7 (1) HIGH CA-7 (1)(2) FAMILY: CONFIGURATION MANAGEMENT CLASS: OPERATIONAL Configuration Management. Measures to ensure the protection features specified in information system security configurations are implemented in the system and maintained in the instantiation of system components by applying a level of discipline and control to the process of system maintenance and modification. A configuration management process must be implemented to detect any changes in system hardware, software, and firmware components that will modify or deviate from the approved minimum information system security configuration standard or the level of risk accepted by the DAA. Configuration Management Control Baselines Control Number Control Name

Section 42

Low Moderate High CM-1 Configuration Management Policy and Procedures CM-1 CM-1 CM-1 CM-2 Baseline Configuration CM-2 CM-2 (1) CM-2 (1) (2) CM-3 Configuration Change Control CM-3 CM-3 (2)(3) CM-3 (1)(2)(3) CM-4 Monitoring Configuration Changes CM-4 CM-4 CM-4 CM-5 Access Restrictions for Change CM-5 CM-5 (1)(2)(4) CM-5 (1)(2)(3) CM-6 Configuration Settings CM-6 CM-6 (2) CM-6 (1)(2) CM-7 Least Functionality CM-7 CM-7 (1)(2) CM-7 (1)(2) CM-8 Information System Component Inventory CM-8 CM-8 (1) CM-8 (1)(2) IV-36 NAP 14.2-C 05-02-08 CM-1 CONFIGURATION MANAGEMENT POLICY AND PROCEDURES Control: Develop, disseminate, and periodically review and/or update: a. A formal, documented, configuration management policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, compliance and the establishment of an entity to enforce the policy (i.e., Configuration Control Board); and b. Formal, documented procedures to facilitate the implementation of the configuration management policy and associated configuration management controls. Supplemental Guidance: The configuration management policy and procedures are consistent with applicable laws, Executive Orders, directives, policies, regulations, standards, and guidance. The configuration management policy can be included as part of the general information security policy for the organization. Configuration management procedures can be developed for the security program in general, and for a particular information system, when required. Control Enhancements: None. LOW CM-1 MOD CM-1 HIGH CM-1 CM-2 BASELINE CONFIGURATION Control: Develops, document, and maintain a current baseline configuration of the information system and an inventory of the system’s constituent components. Supplemental Guidance: This control establishes a baseline configuration for the information system. The baseline configuration provides information about a particular component’s makeup (e.g., the standard software load for a workstation or notebook computer including updated patch information) and the component’s logical placement within the information system architecture. The baseline configuration also provides the organization with a well defined and documented specification to which the information system is built and deviations, if required, are documented in support of mission needs and/or objectives. Related security controls: CM6, CM8. Control Enhancements: (1) The organization updates the baseline configuration of the information system as an integral part of information system component installations. (2) The organization employs automated mechanisms to maintain an up-to-date, complete, accurate, and readily available baseline configuration of the information system. NAP 14.2-C IV-37 05-02-08 LOW CM-2 MOD CM-2 (1) HIGH CM-2 (1)(2) CM-3 CONFIGURATION CHANGE CONTROL Control: Document and control configuration changes to the information system. The organization includes emergency changes in the configuration change control process, including changes resulting from the remediation of flaws. The approvals to implement a change to the information system include successful results from the security analysis of the change. The organization audits activities associated with configuration changes to the information system.

Section 43

Supplemental Guidance: Configuration change control involves the systematic proposal, justification, implementation, test and/or evaluation, review, and disposition of changes to the information system, including upgrades and modifications. Configuration change control includes changes to the configuration settings for information technology products (e.g., operating systems, firewalls, routers). Related security controls: CM4, CM6, and SI2. Control Enhancements: (1) The organization employs automated mechanisms to: (a) Document proposed changes to the information system; (b) Notify appropriate approval authorities; (c) Highlight approvals that have not been received in a timely manner; (d) Inhibit change until necessary approvals are received; and (e) Document completed changes to the information system. (2) The organization establishes a CM control board, which includes the Information System Security Manager (ISSM), or Information System Security Officer (ISSO) as a member(s). (3) All National Security Systems (NSS) are under the control of a chartered configuration control board (CCB) that meets regularly. The CCB reviews and approves all proposed information system changes, to include interconnections to other information systems. LOW CM-3 MOD CM-3 (2)(3) HIGH CM-3 (1)(2)(3) CM-4 MONITORING CONFIGURATION CHANGES Control: Monitor changes to the information system by conducting security impact analyses to determine the effects of the changes. After the information system is changed (including IV-38 NAP 14.2-C 05-02-08 upgrades and modifications), the organization checks the security features to verify that the features are still functioning properly. The organization audits activities associated with configuration changes to the information system. Supplemental Guidance: Prior to change implementation, and as part of the change approval process, the Information System Security Manager (ISSM), or Information System Security Officer (ISSO) analyzes changes to the information system for potential security impacts. Monitoring configuration changes and conducting security impact analyses are important elements with regard to the ongoing assessment of security controls in the information system. Related security Control: CA7. Control Enhancements: None. LOW CM-4 MOD CM-4 HIGH CM-4 CM-5 ACCESS RESTRICTIONS FOR CHANGE Control: Approve individual access privileges and enforce physical and logical access restrictions associated with changes to the information system; and generate, retain, and review records reflecting all such changes. Supplemental Guidance: Planned or unplanned changes to the hardware, software, and/or firmware components of the information system can have significant effects on the overall security of the system. Accordingly, only qualified and authorized individuals obtain access to information system components for purposes of initiating changes, including upgrades, and modifications. Control Enhancements: (1) The organization employs automated mechanisms to enforce access restrictions and support auditing of the enforcement actions. (2) The organization limits and periodically reviews system developer privileges to change code and system data directly within a production environment. (3) The organization limits system developer privileges to change code and system data directly within a production environment and reevaluates them on a 90 day cycle.

Section 44

(4) System libraries are managed and maintained to protect privileged programs and to prevent or minimize the introduction of unauthorized code. LOW CM-5 MOD CM-5(1)(2)(4) HIGH C M-5 (1)(2)(3)(4) CM-6 CONFIGURATION SETTINGS NAP 14.2-C IV-39 05-02-08 Control: a. Establish mandatory configuration settings for information technology products employed within the information system, where possible. See the Supplemental Guidance. b. Configure the security settings of information technology products to the most restrictive mode consistent with operational requirements; c. Document the configuration settings; and d. Enforce the configuration settings in all components of the information system. Supplemental Guidance: Configuration settings are the configurable parameters of the information assurance products that comprise the information system. Organizations monitor and control changes to the configuration settings in accordance with organizational policies and procedures. FISMA reporting instructions provide guidance on configuration requirements for Federal information systems. Related security controls: CM2, CM3, and SI4. Control Enhancements: (1) The organization employs automated mechanisms to centrally manage, apply, and verify configuration settings. (2) The information system and any modifications to the system baseline must demonstrate conformance to security configuration technical implementation guides prior to being introduced into a production environment. LOW CM-6 MOD CM-6 (2) HIGH CM-6 (1)(2) CM-7 LEAST FUNCTIONALITY Control: Configure the information system to provide only essential capabilities and document in the system’s ISSP specific prohibitions and/or restrictions upon the use of functions, ports, protocols, and/or services. The organization configures the information system to provide only essential capabilities and specifically prohibits and/or restricts the use of the following functions, ports, protocols, and/or services: [Assignment: organization-defined list of prohibited and/or restricted functions, ports, protocols, and/or services documented in the information system SSP]. Supplemental Guidance: Information systems are capable of providing a wide variety of functions and services. Some of the functions and services, provided by default, may not be necessary to support essential organizational operations (e.g., key missions, functions). IV-40 NAP 14.2-C 05-02-08 Additionally, it is sometimes convenient to provide multiple services from a single component of an information system, but doing so increases risk over limiting the services provided by any one component. The functions and services provided by information systems, or individual components of information are carefully reviewed to determine which functions and services are candidates for elimination (e.g., Voice Over Internet Protocol, Instant Messaging, File Transfer Protocol, Hyper Text Transfer Protocol, file sharing systems). Control Enhancements: (1) The organization reviews the information system at least annually to identify and eliminate unnecessary functions, ports, protocols, and/or services. (2) The information system complies with ports, protocols, and services guidance and organizational registration requirements. LOW CM-7 MOD CM-7 (1)(2) HIGH CM-7 (1)(2) CM-8 INFORMATION SYSTEM COMPONENT INVENTORY

Section 45

Control: Develop, document, and maintain a current inventory of the components of the information system and relevant ownership information. Supplemental Guidance: The inventory of information system components includes any information determined to be necessary by the organization to achieve effective property accountability (e.g., manufacturer, model number, serial number, software license information, system and/or component owner). The component inventory is consistent with the accreditation boundary of the information system. Related security controls: CM2 and CM6. Control Enhancements: (1) The organization updates the inventory of information system components as an integral part of component installations. (2) The organization employs automated mechanisms to help maintain an up-to-date, complete, accurate, and readily available inventory of information system components. LOW CM-8 MOD CM-8 (1) HIGH CM-8 (1)(2) FAMILY: CONTINGENCY PLANNING AND DISASTER RECOVERY CLASS: OPERATIONAL NAP 14.2-C IV-41 05-02-08 Contingency Planning details the necessary procedures required to protect the continuing performance of core business functions and services, including information and information system services, during an outage. Contingency Planning Control Baselines Control Number Control Name Low Moderate High CP-1 Contingency Planning Policy and Procedures CP-1 CP-1 (1) CP-1 (1) CP-2 Contingency Plan CP-2* CP-2 (1)(2)* CP-2 (1)(2)(3)* CP-3 Contingency Training CP-3 CP-3 (1) CP-3 (1)(2) CP-4 Contingency Plan Testing CP-4 CP-4(1) CP-4 (1)* CP-5 Contingency Plan Update CP-5 CP-5 CP-5 CP-6 Alternate Storage Sites Not Required CP-6 (1)(3) CP-6 (1)(2)(3)(4)(5) CP-7 Alternate Processing Site Not Required CP-7 (1)(2)(3) CP-7 (1)(2)(3)(4)(5) CP-8 Telecommunications Services Not Required CP-8 (1)(2) CP-8 (1)(2)(3)(4) CP-9 Information System Backup CP-9 CP-9 (1)(4) CP-9 (1)(2)(3)(4) CP-10 Information System Recovery and Reconstitution CP-10 (2) CP-10 (1)(2) CP-10 (1)(2)(3) CP-1 CONTINGENCY PLANNING AND DISASTER RECOVERY POLICY AND PROCEDURES Control: Develop, disseminate, and periodically review and update: a. A formal, documented, contingency and disaster recovery planning policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and b. Formal, documented procedures to facilitate the implementation of the contingency and disaster recovery planning policy and associated contingency planning controls. Supplemental Guidance: The contingency and disaster recovery planning policy and procedures are consistent with applicable Federal laws, directives, policies, regulations, standards, and guidance. The contingency and disaster recovery planning policy can be IV-42 NAP 14.2-C 05-02-08 included as part of the general information security policy for the organization. Contingency planning procedures can be developed for the security program in general, and for a particular information system, when required. Control Enhancement: (1) The organization develops and implements procedures to assure the appropriate physical and technical protection of the backup and restoration hardware, firmware, and software, such as router tables, compilers, and other security related system software. LOW CP-1 MOD CP-1 (1) HIGH CP-1 (1) CP-2 CONTINGENCY AND DISASTER RECOVERY PLAN

Section 46

Control: Develop and implement a contingency plan and disaster recovery plan for each information system addressing contingency roles, responsibilities, assigned individuals with contact information, and activities associated with restoring the system after a disruption or failure. Designated officials within the organization review and approve the contingency plan and distribute copies of the plan to key contingency personnel. Supplemental Guidance: None Control Enhancements: (1) The organization coordinates contingency plan development with organizational elements responsible for related plans. Enhancement Supplemental Guidance: Examples of related plans include Business Continuity Plan, Disaster Recovery Plan, Continuity of Operations Plan, Business Recovery Plan, Incident Response Plan, and Emergency Action Plan. (2) The organization conducts capacity planning so that necessary capacity for information processing, telecommunications, and environmental support exists during crisis situations. (3) The organization explicitly identifies mission and business essential functions and establishes associated restoration priorities and metrics. These activities must be linked to the BIA process. * For systems with a level of concern for availability of HIGH: (4) The organization plans and provides sufficient capacity to support partial restoration of mission or business essential functions. NAP 14.2-C IV-43 05-02-08 (5) The organization plans and provides for the smooth transfer of all mission or business essential functions to alternate processing or facilities with little or no loss of operational continuity. Continuity is sustained through restoration to primary processing or facilities. LOW CP-2* MOD CP-2 (1)(2)* HIGH CP-2(1)(2)(3)* CP-3 CONTINGENCY AND DISASTER RECOVERY TRAINING Control: Train personnel in their contingency and disaster recovery roles and responsibilities with respect to the information system and provide refresher training at least annually. Supplemental Guidance: None. Control Enhancements: (1) The organization incorporates simulated events into contingency and disaster recovery training to facilitate effective response by personnel in crisis situations. (2) The organization employs automated mechanisms to provide a more thorough and realistic training environment. LOW CP-3 MOD CP-3 (1) HIGH CP-3 (1)(2) CP-4 CONTINGENCY PLAN TESTING AND EXERCISES Control: The organization: a. Test and/or exercise the contingency and disaster recovery plans for the information system at least annually using organization—defined tests and/or exercises to determine the plans’ effectiveness and the organization’s readiness to execute the plan; and b. Review the contingency plan test and exercise results, and initiate corrective actions. Supplemental Guidance: There are several methods for testing and/or exercising contingency and disaster recovery plans to identify potential weaknesses (e.g., full-scale testing, functional and/or tabletop exercises). Testing and/or exercises also include a determination of the effects on organizational operations and assets (e.g., reduction in mission capability) and individuals arising due to operations in accordance with the plan. Control Enhancements: (1) The organization coordinates contingency and disaster recovery plan testing and/or exercises with organizational elements responsible for related plans.

Section 47

IV-44 NAP 14.2-C 05-02-08 Enhancement Supplemental Guidance: Examples of related plans include Business Continuity Plan, Continuity of Operations Plan, Business Recovery Plan, Incident Response Plan, and Emergency Action Plan. * For systems with a level of concern for availability of HIGH: (2) The organization tests and/or exercises the contingency and disaster recovery plans at the alternate processing site to familiarize personnel with the facility and available resources and to evaluate the site’s capabilities to support operations. (3) It is recommended that the organization employ automated mechanisms to more thoroughly and effectively test and/or exercise the contingency and disaster recovery plans by providing more complete coverage of contingency issues, selecting more realistic test and/or exercise scenarios and environments, and more effectively stressing the information system and supported missions. (4) The organization exercises this plan on a semiannual basis. LOW CP-4* MOD CP-4 (1)* HIGH CP-4 (1)* CP-5 CONTINGENCY DISASTER RECOVERY PLAN UPDATE Control: Review the contingency and disaster recovery plans for the information system at least annually and revise the plan to address system and/or organizational changes or problems encountered during plan implementation, execution, or testing. Supplemental Guidance: Organizational changes include changes in mission, functions, or business processes supported by the information system. Control Enhancements: None. LOW CP-5 MOD CP-5 HIGH CP-5 CP-6 ALTERNATE STORAGE SITE Control: If required by the system owners and the Business Impact Analysis, identify an alternate storage site and initiate necessary agreements to permit the storage of information system backup information. Ensure that the frequency of information system backups and the transfer rate of backup information to the alternate storage site (if so designated) are consistent with the organization’s recovery time objectives and recovery point objectives. Control Enhancements: NAP 14.2-C IV-45 05-02-08 (1) The organization identifies an alternate storage site that is geographically separated from the primary storage site so as not to be susceptible to the same hazards. (2) The organization configures the alternate storage site to facilitate timely and effective recovery operations. (3) The organization identifies potential accessibility problems to the alternate storage site in the event of an area-wide disruption or disaster and outlines explicit mitigation actions. (4) The organization performs daily data backups and stores recovery media offsite at a location that affords protection of the data in accordance with its confidentiality, integrity, and availability levels. (5) The organization accomplishes data backup by maintaining a redundant secondary system, not collocated, that can be activated without loss of data or disruption to the operation. (6) The organization will consider alternative procedures, such as secure transmission of the data to an appropriate offsite location if regular offsite backup is not feasible. LOW Not Required MOD CP-6 (1)(3) HIGH CP-6 (1)(2)(3)(4)(5) CP-7 ALTERNATE PROCESSING SITE

Section 48

Control: If required by the Business Impact Analysis, identify an alternate processing site and initiate necessary agreements to permit the resumption of information system operations for critical mission and/or business functions within the organization-defined time period when the primary processing capabilities are unavailable. Ensure that the timeframes to resume information system operations are consistent with organization-established recovery time objectives. Supplemental Guidance: None Control Enhancements: (1) The organization identifies an alternate processing site that is geographically separated from the primary processing site so as not to be susceptible to the same hazards. (2) The organization identifies potential accessibility problems to the alternate processing site in the event of an area-wide disruption or disaster and outlines explicit mitigation actions. (3) The organization develops alternate processing site agreements that contain priority-of-- service provisions in accordance with the organization’s availability requirements. (4) The organization fully configures the alternate processing site so that it is ready to be used as the operational site supporting a minimum required operational capability. IV-46 NAP 14.2-C 05-02-08 (5) The organization ensures that the alternate site provides security measures, to include boundary defense and user connectivity and access controls, equivalent to the primary site. LOW Not Required MOD CP-7 (1)(2)(3) HIGH CP-7 (1)(2)(3)(4)(5) CP-8 TELECOMMUNICATIONS SERVICES Control: Identify primary and alternate telecommunications services to support the information system and initiate necessary agreements to permit the resumption of system operations for critical mission and/or business functions in a timely manner, as specified by the operating unit, when the primary telecommunications capabilities are unavailable. Supplemental Guidance: In the event that the primary and/or alternate telecommunications services are provided by a common carrier, the organization requests Telecommunications Service Priority (TSP) for all telecommunications services used for national security emergency preparedness. Control Enhancements: (1) The organization develops primary and alternate telecommunications service agreements that contain priority-of-service provisions in accordance with the organization’s availability requirements. (2) The organization obtains alternate telecommunications services that do not share a single point of failure with primary telecommunications services. (3) The organization obtains alternate telecommunications service providers that are sufficiently separated from primary service providers so as not to be susceptible to the same hazards. (4) The organization requires primary and alternate telecommunications service providers to have adequate contingency plans. LOW Not Required MOD CP-8 (1) HIGH CP-8 (1)(2)(3)(4) CP-9 INFORMATION SYSTEM BACKUP Control: Conduct backups of user-level and system-level information (including system state information) contained in the information system at least annually and store backup information at an appropriately secured location if required by the Business Impact Analysis. The NNSA Element ensures that the frequency of information system backups and the transfer rate of backup information to alternate storage sites (if so designated) are consistent with the organization’s recovery time objectives and recovery point objectives.

Section 49

NAP 14.2-C IV-47 05-02-08 Supplemental Guidance: While integrity and availability are the primary concerns for system backup information, protecting backup information from unauthorized disclosure is also an important consideration depending on the type of information residing on the backup media and the associated risk level. An organizational assessment of risk guides the use of encryption for backup information. The protection of system backup information while in transit is beyond the scope of this control. Related security controls: MP4 and MP5. Control Enhancements: (1) The organization tests backup information annually to verify media reliability and information integrity. (2) The organization selectively uses backup information in the restoration of information system functions as part of contingency plan and disaster recovery testing. (3) The organization stores backup copies of the operating system and other critical information system software in a separate facility or in a fire-rated container that is not collocated with the operational software. (4) The organization protects system backup information from unauthorized modification. The organization employs appropriate mechanisms (e.g., digital signatures, cryptographic hashes) to protect the integrity of information system backups. LOW CP-9 MOD CP-9 (1)(4) HIGH CP-9 (1)(2)(3)(4) CP-10 INFORMATION SYSTEM RECOVERY AND RECONSTITUTION Control: Employ mechanisms with supporting procedures to allow the information system to be recovered and reconstituted to a known secure state after a disruption or failure. Supplemental Guidance: Information system recovery and reconstitution to a known secure state means that all system parameters (either default or organization-established) are set to secure values, security-critical patches are reinstalled, security-related configuration settings are reestablished, system documentation and operating procedures are available, application and system software is reinstalled and configured with secure settings, information from the most recent, known secure backups is loaded, and the system is fully tested. Control Enhancements: (1) The organization includes a full recovery and reconstitution of the information system as part of contingency plan and disaster recovery testing. (2) The organization documents circumstances that can inhibit a recovery to a known, secure state and implements the appropriate mitigating controls. IV-48 NAP 14.2-C 05-02-08 (3) Information systems that are transaction-based (e.g., database management systems, transaction processing systems) will implement transaction rollback and transaction journaling, or technical equivalents. LOW CP-10 (2) MOD CP-10 (1)(2) HIGH CP-10 (1)(2)(3) FAMILY: IDENTIFICATION AND AUTHENTICATION CLASS: TECHNICAL Identification and authentication is a technical measure that prevents unauthorized people (or unauthorized processes) from entering an information system. Access control usually requires that the system be able to identify and differentiate among users. All NNSA information systems must have a means to enforce user accountability, so that system activity (both authorized and unauthorized) can be traced to a specific user. To facilitate user accountability, all information systems must implement a method of user identification and authentication. The user identification tells the system who the user is. The authentication mechanism provides an added level of assurance that the user really is who they say they are. Authentication consists of something a user knows (such as a password), something the user has (such as a token or smart card), or something the user is (such as a fingerprint). User identification and authentication also can enforce separation of duties.

Section 50

The following is NNSA policy: • All information systems require distinct user IDs that are unique to each user or group for user identification. • All information systems require an authentication mechanism that is unique to each user or group, such as but not limited to; passwords, one-time passwords, biometrics, or public-key infrastructure certificates for primary access to all information and information system resources. The implementation or technology used should provide access security commensurate with the level of sensitivity assigned to the resource (i.e., information, devices or systems). • All information systems and associated equipment that rely on passwords as the means to authenticate users must implement effective password management in accordance with the Element’s CSPP. Identification and Authentication Control Baselines Control Number Control Name Low Moderate High NAP 14.2-C IV-49 05-02-08 Identification and Authentication Control Baselines Control Number Control Name Low Moderate High IA-1 Identification and Authentication Policy and Procedures IA-1 IA-1 IA-1 IA-2 User Identification and Authentication IA-2 (1)(4) IA-2 (2)(3)(4)(5) IA-2 (2)(3)(4)(5) IA-3 (1) IA-3 (2) IA-3 Device Identification and Authentication Not Required IA-3 IA-3 IA-4 Identifier Management IA-4 IA-4 (1)(2) IA-4 (1)(2) IA-5 Authenticator Management IA-5 (1)(2)(3)(4) IA-5 (1)(2)(3)(4) IA-5 (1)(2)(3)(4)(5) IA-6 Authenticator Feedback IA-6 IA-6 IA-6 IA-7 Cryptographic Module Authentication IA-7 IA-7 IA-7 IA-1 IDENTIFICATION AND AUTHENTICATION POLICY AND PROCEDURES Control: Develop, disseminate, and periodically review and update: a. A formal, documented, identification and authentication policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and b. Formal, documented procedures to facilitate the implementation of the identification and authentication policy and associated identification and authentication controls. Supplemental Guidance: Identification and authentication procedures can be developed for the security program in general, and for a particular information system, when required. Users take reasonable measures to safeguard authenticators including maintaining possession of their individual authenticators, not loaning or sharing authenticators with others, and reporting lost or compromised authenticators where technically feasible. Control Enhancements: None. LOW IA-1 MOD IA-1 HIGH IA-1 IV-50 NAP 14.2-C 05-02-08 IA-2 USER IDENTIFICATION AND AUTHENTICATION Control: Uniquely identify and authenticate users (or processes acting on behalf of users) on all information systems, where technically feasible. Supplemental Guidance: Authentication of user identities is accomplished through the use of passwords, tokens, biometrics, or in the case of multifactor authentication, some combination thereof. Remote access is any access to an organizational information system by a user (or an information system) communicating through an external, non-organization-controlled network (e.g., the Internet). Local access is any access to an organizational information system by a user (or an information system) communicating through an internal organization-controlled network (e.g., local area network) or directly to a device without the use of a network. Related security controls: AC-14 and AC-17.

Section 51

Control Enhancements: (1) The information system employs passwords and/or PINs for local and remote system access. (2) The information systems employ a multifactor authentication process or device that generates a onetime password, for local system access. Enhancement Supplemental Guidance: Multifactor authentication could include soft tokens, hard tokens, scratch card, or grid cards, that generate one time passwords. One time passwords could include the type one gets from time synchronous devices (e.g., SecurID) from challenge response devices, or from the protocol handshake that underlies PKI. (3) The information system employs a multifactor authentication process or device, that generates a onetime password, for remote system access, where one of the factors is separate from the system being used to gain access. Enhancement Supplemental Guidance: The additional phrase is intended to eliminate concepts such as soft tokens. This is intended to address an OMB0616 requirement for remotely accessing systems containing PII, (there is no NSS exception). (4) If passwords and/or PINs are employed they shall be compliant with the Element’s CSPP.. (5) If certificate-based authentication is employed it shall be compliant with the applicable control enhancements in IA5. LOW IA-2 (1)(4) MOD IA-2 (2)(3)(4)(5) HIGH IA-2 (2)(3)(4)(5) NAP 14.2-C IV-51 05-02-08 IA-3 DEVICE IDENTIFICATION AND AUTHENTICATION Control: The information system identifies and authenticates specific devices before establishing a connection. Supplemental Guidance: The information system typically uses either shared known information (e.g., physical address or TCP/IP address), organizational authentication solution (e.g., IEEE 802.1x and Extensible Authentication Protocol (EAP) or a Radius server with EAP-Transport Layer Security (TLS) authentication) to identify and authenticate devices on local and/or wide area networks. The required strength of the device authentication mechanism is determined by the LoC of the information system with higher risk levels requiring stronger authentication. For remote access via VPN, the VPN server is considered the information system which handles the identification and authentication of remote devices. Control Enhancements: (1) The information system employs bidirectional authentication that is cryptographically based between devices before establishing remote communication connections. (2) The information system employs bidirectional authentication that is cryptographically based (or uses authorized PTS) between devices before establishing remote or local communication connections. LOW Not Required MOD IA-3 (1) HIGH IA-3 (2) LOW Not Required MOD IA-3 HIGH IA-3 IA-4 IDENTIFIER MANAGEMENT Control: Manage user identifiers by: a. Uniquely identifying each user; b. Verifying the identity of each user; c. Receiving authorization to issue a user identifier from an appropriate organization official; d. Issuing the user identifier to the intended party; e. Disabling the user identifier after the period of inactivity noted in the site CSPP; and f. Archiving user identifiers. g. Establish separate unique identifier for privileged accounts and actions. IV-52 NAP 14.2-C 05-02-08 Supplemental Guidance: Identifier management is not applicable to shared information system accounts (e.g., guest and anonymous accounts).

Section 52

Control Enhancements: (1) NNSA Elements require that registration to receive a user ID include authorization by a supervisor or sponsor (or management designee), and be done in person before a designated registration authority. (2) The organization requires documentary evidence of a user’s identity to be presented to the registration authority. LOW IA-4 MOD IA-4 (1)(2) HIGH IA-4 (1)(2) IA-5 AUTHENTICATOR MANAGEMENT Control: Manage information system authenticators by: a. Defining initial authenticator content; b. Establishing administrative procedures for initial authenticator distribution, for lost and/or compromised, or damaged authenticators, and for revoking authenticators; c. Changing default authenticators upon information system installation; and d. Changing and/or refreshing authenticators at least annually Supplemental Guidance: Information system authenticators include, for example, tokens, PKI certificates, biometrics, passwords, and key cards. Complies with all applicable laws, statutes, national policies and related E-authentication initiatives, authentication of public users accessing Federal information systems (and associated authenticator management) may also be required to protect nonpublic or privacy-related information. Control Enhancements: (1) Information systems utilizing a logon ID and password for user identification and authentication enforce the following for reusable passwords: (a) Password complexity is not less than a case sensitive, 8-character mix of upper case letters, lower case letters, numbers, and special characters (one of which must be in the first seven positions), including at least one of each (e.g., emPagd2!). (Document in a system’s ISSP if a system is incapable of meeting this requirement.) NAP 14.2-C IV-53 05-02-08 (b) At least four characters must be changed when a new password is created. (c) Passwords are encrypted both for storage and for transmission, where technically feasible. (d) Enforces password minimum and maximum lifetime restrictions; and (e) Prohibits password reuse for a specified number [NNSA Element defined] of generations. Enhancement Supplemental Guidance: Deployed/tactical systems with limited data input capabilities implement the password policy to the extent possible. (2) The organization ensures that passwords are protected commensurate with the classification or sensitivity of the information accessed. (3) The organization ensures that policy prohibits passwords from being embedded in access scripts or stored on function keys. (4) Information systems utilizing PKI-based authentication: (a) Validates certificates by constructing a certification path to a trusted certificate authority; (b) Establishes user control of the corresponding private key; and (c) Maps the authenticated identity to the user account. (5) The organization employs automated tools to validate that the passwords are sufficiently strong to resist cracking and other types of attacks intended to discover a user’s password. Enhancement Supplemental Guidance: These tools may only be employed under the auspices of the DAA. This type of testing can be accomplished in association with RA5. LOW IA-5 (1)(2)(3)(4) MOD IA-5 (1)(2)(3)(4) HIGH IA-5 (1)(2)(3)(4)(5) IA-6 AUTHENTICATOR FEEDBACK Control: The information system obscures feedback of authentication information during the authentication process to protect the information from possible exploitation/use by unauthorized individuals.

Section 53

Supplemental Guidance: The feedback from the information system does not provide information that would allow an unauthorized user to compromise the authentication IV-54 NAP 14.2-C 05-02-08 mechanism. Displaying asterisks when a user types in a password is an example of obscuring feedback of authentication information Control Enhancements: None. LOW IA-6 MOD IA-6 HIGH IA-6 IA-7 CRYPTOGRAPHIC MODULE AUTHENTICATION Control: If used, the information system employs authentication methods that meet the requirements of applicable laws, Executive Orders, directives, policies, regulations, standards, and guidance for authentication to a cryptographic module. Supplemental Guidance: None. Control Enhancements: None. LOW IA-7 MOD IA-7 HIGH IA-7 FAMILY: INCIDENT RESPONSE CLASS: OPERATIONAL An incident response capability is a mechanism through which an NNSA Element’s system owners and Information System Security Officers are kept informed of system vulnerability advisories from the US-Computer Emergency Readiness Team (US-CERT), software vendors, and other sources. The capability also coordinates with responsible incident response capabilities regarding the handling and reporting of incidents involving systems under the NNSA Element’s responsibility. An incident response capability may consist of one or more persons (such as the Information System Security Officer or CIO), who ensure that vulnerability advisories are communicated to system owners. Incident Response Control Baselines Control Number Control Name Low Moderate High IR-1 Incident Response Policy and Procedures IR-1 IR-1 IR-1 IR-2 Incident Response Training IR-2 IR-2 IR-2 (1)(2) IR-3 Incident Response Testing Not Required IR-3 IR-3 (1) NAP 14.2-C IV-55 05-02-08 Incident Response Control Baselines Control Number Control Name Low Moderate High IR-4 Incident Handling IR-4 IR-4 (1) IR-4 (1) IR-5 Incident Monitoring IR-5 IR-5 (1) IR-5 (1) IR-6 Incident Reporting IR-6 IR-6 (1) IR-6 (1) IR-7 Incident Response Assistance IR-7 IR-7 (1) IR-7 (1) IR-1 INCIDENT RESPONSE POLICY AND PROCEDURES Control: Develop, disseminate, and periodically review/update: a. A formal, documented, incident response policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and b. Formal, documented procedures to facilitate the implementation of the incident response policy and associated incident response controls. Supplemental Guidance: The incident response policy can be included as part of the general information security policy for the organization. Incident response procedures can be developed for the security program in general, and for a particular information system, when required. Control Enhancement: None LOW IR-1 MOD IR-1 HIGH IR-1 IR-2 INCIDENT RESPONSE TRAINING Control: Train personnel in their incident response roles and responsibilities with respect to the information system and provide refresher training at least annually. Supplemental Guidance: None. Control Enhancements: (1) The organization incorporates simulated events into incident response training to facilitate effective response by personnel in crisis situations. IV-56 NAP 14.2-C 05-02-08 (2) The organization employs automate mechanisms to provide a more thorough and realistic training environment.

Section 54

LOW IR-2 MOD IR-2 HIGH IR-2 (1)(2) IR-3 INCIDENT RESPONSE TESTING AND EXERCISES Control: Test and/or exercise the incident response capability for the information system at least annually using the tests and exercises defined in the ISSP to determine the incident response effectiveness and document the results. Supplemental Guidance: None Control Enhancements: (1) The organization employs automated mechanisms to more thoroughly and effectively test/exercise the incident response capability. Enhancement Supplemental Guidance: Automated mechanisms can provide the ability to more thoroughly and effectively test or exercise the capability by providing more complete coverage of incident response issues, selecting more realistic test/exercise scenarios and environments, and more effectively stressing the response capability. LOW IR-3 MOD IR-3 HIGH IR-3 (1) IR-4 INCIDENT HANDLING Control: Implement an incident handling capability for security incidents that includes preparation, detection and analysis, evidence preservation, containment, eradication, and recovery. Supplemental Guidance: Incident-related information can be obtained from a variety of sources including, but not limited to, audit monitoring, network monitoring, physical access monitoring, and user/administrator reports. Related security controls: AU-6 and PE-6. Control Enhancement: (1) The organization employs automated mechanisms to support the incident handling process. LOW IR-4 MOD IR-4 (1) HIGH IR-4 (1) NAP 14.2-C IV-57 05-02-08 IR-5 INCIDENT MONITORING Control: Track and document information system security incidents on an ongoing basis. Supplemental Guidance: None. Control Enhancement: (1) The organization employs automated mechanisms to assist in the tracking of security incidents and in the collection and analysis of incident information. LOW IR-5 MOD IR-5 (1) HIGH IR-5 (1) IR-6 INCIDENT REPORTING Control: Promptly report incident information to appropriate authorities. Supplemental Guidance: The types of incident information reported, the content and timeliness of the reports, and the list of designated reporting authorities or organizations are consisted with applicable laws, Executive Orders, directives, policies, regulations, standards, and guidance. In addition to incident information, weaknesses and vulnerabilities in the information system are reports to appropriate organizational officials in a timely manner to prevent security incidents. Control Enhancement: (1) The organization employs automated mechanisms to assist in the reporting of security incidents. LOW IR-6 MOD IR-6 (1) HIGH IR-6 (1) IR-7 INCIDENT RESPONSE ASSISTANCE Control: Provide an incident response support resource (internal or external incident response capability support) that offers advice and assistance to users of the information systems for the handling and reporting of security incidents. The support resource is an integral part of the organization’s incident response capability. Supplemental Guidance: Possible implementations of incident response support resources in an organization include a help desk or an assistance group and access to forensics services, when required. Control Enhancement: IV-58 NAP 14.2-C 05-02-08 (1) The organization employs automated mechanisms to increase the availability of incident response related information and support.

Section 55

LOW IR-7 MOD IR-7 (1) HIGH IR-7 (1) FAMILY: MAINTENANCE CLASS: OPERATIONAL These are controls to ensure that maintenance activities are controlled and monitored to ensure that the confidentiality, integrity or availability of the information is not compromised. Maintenance Control Baselines Control Number Control Name Low Moderate High MA-1 System Maintenance Policy and Procedures MA-1 MA-1 MA-1 MA-2 Periodic Maintenance MA-2 MA-2 (1) MA-2 (1) (2) MA-3 Maintenance Tools MA-3 (2) MA-3 (1)(2)(3)(4) MA-3 (1)(2)(3)(4) MA-4 Remote Maintenance MA-4 (1)(2)(3)(4) MA-4 (1)(2)(3)(4) MA-4 (1)(2)(3)(4)(5) MA-5 Maintenance Personnel MA-5 (1)(4) MA-5 (1)(2)(3)(4) MA-5 (1)(2)(3)(4) MA-6 Timely Maintenance Not Required MA-6 (1) MA-6 (2) MA-1 SYSTEM MAINTENANCE POLICY AND PROCEDURES Control: Develop, disseminate, and periodically review/update: a. A formal, documented, information system maintenance policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and b. Formal, documented procedures to facilitate the implementation of the information system maintenance policy and associated system maintenance controls. Supplemental Guidance: The information system maintenance policy can be included as part of the general information security policy for the organization. System maintenance NAP 14.2-C IV-59 05-02-08 procedures can be developed for the security program in general, and for a particular information system, when required. Control Enhancements: None. LOW MA-1 MOD MA-1 HIGH MA-1 MA-2 CONTROLLED MAINTENANCE Control: a. The organization schedules, performs, documents, and reviews records of routine preventative and regular maintenance (including repairs) on the components of the information system in accordance with manufacturer or vendor specifications and/or organizational requirements. b. All maintenance activities to include routine, scheduled maintenance and repairs are controlled; whether performed on site or remotely and whether the equipment is serviced on site or removed to another location. c. The ISSM approves the removal of information system or information system components that processed sensitive or classified information from the site when repairs are necessary. d. If the information system or component of the system requires offsite repair, the organization removes all information from associated media using approved procedures. e. After maintenance is performed on the information system, the organization checks all potentially impacted security controls to verify that the controls are still functioning properly. Supplemental Guidance: None Control Enhancements: (1) The organization maintains maintenance records for the information system that include: (a) The date and time of maintenance; (b) Name of the individual performing the maintenance; (c) Name of escort, if necessary; (d) A description of the maintenance performed; and IV-60 NAP 14.2-C 05-02-08 (e) A list of equipment removed or replaced (including identification numbers, if applicable). (2) The organization employs automated mechanisms to schedule and conduct maintenance as required, and to create up-to-date, accurate, complete, and available records of all maintenance actions, both needed and completed. LOW MA-2 MOD MA-2 (1) HIGH MA-2 (1)(2)

Section 56

MA-3 MAINTENANCE TOOLS Control: Approve, control, and monitor the use of information system maintenance tools and maintain the tools on an ongoing basis. Supplemental Guidance: The intent of this control is to address hardware and software brought into the information system specifically for diagnostic/repair actions (e.g., a hardware or software packet sniffer that is introduced for the purpose of a particular maintenance activity). Hardware and/or software components that may support information system maintenance, yet are a part of the system (e.g., the software implementing “ping,” “ls,” “ipconfig,” or the hardware and software implementing the monitoring port of an Ethernet switch) are not covered by this control. Control Enhancements: (1) The organization inspects all maintenance tools carried into a facility by maintenance personnel for obvious improper modifications. Enhancement Supplemental Guidance: Maintenance tools include, for example, diagnostic and test equipment used to conduct maintenance on the information system. (2) The organization checks all media containing diagnostic and test programs for malicious code before the media are used in the information system. (3) The organization checks all maintenance equipment with the capability of retaining information so that no organizational information is written on the equipment or the equipment is appropriately sanitized before release. In the event the equipment cannot be sanitized, the equipment remains within the facility or is destroyed, unless an appropriate organization official explicitly auth

Something wrong with this record? Tell us