NAP-14.2C, NNSA Certification and Accreditation (C&A) Process for Information Systems
Establish requirements for a NNSA Certification and Accreditation (C&A) process that incorporates national level requirements and applies them consistently across all NNSA elements.
Cancels:
NAP-14.7A, Confidential/Secret Non-Nuclear Weapons Data Information Group Protection on May 05, 2008
NAP-14.8A, Secret Restricted Non-Nuclear Weapons Data Information Group Protection Profile on May 05, 2008
NAP-14.9A, Confidential Restricted Data, Sigmas 1 Through 13 Information Group Protection Profile on May 05, 2008
NAP-14.10A, Secret Restricted Data, Sigmas 1-13 and 15 Information Group Protection Profile on May 05, 2008
NAP-14.14, Top Secret Information Group Protection Profile on May 05, 2008
NAP-14.2B, Baseline Cyber Security Requirements on May 05, 2008
Version history and related documents
Document text
Text extracted from the attached file. Refer to the original document for the authoritative version.
Section 1
NNSA POLICY LETTER
NAP 14.2-C
Approved: 05-02-08
NNSA CERTIFICATION AND
ACCREDITATION (C&A) PROCESS FOR
INFORMATION SYSTEMS
NATIONAL NUCLEAR SECURITY ADMINISTRATION
Office of Chief Information Officer
AVAILABLE ONLINE AT: INITIATED BY:
http://hq.na.gov Office of the Chief Information Officer
ii NAP 14.2-C
05-02-08
This page left intentionally blank.
NAP 14.2-C iii
05-02-08
Table of Contents
CHAPTER I: NNSA CERTIFICATION AND ACCREDITATION (C&A) PROCESS I-1
1. PURPOSE I-1
2. CANCELLATIONS I-1
3. APPLICABILITY I-1
4. BACKGROUND I-3
5. REQUIREMENTS I-3
6. RESPONSIBILITIES I-5
7. DEFINITIONS I-5
8. CONTACT I-5
CHAPTER II: CONTRACTOR REQUIREMENTS DOCUMENT II-1
1. REQUIREMENTS II-1
CHAPTER III: CERTIFICATION AND ACCREDITATION (C&A) PROCESS III-1
1. INTRODUCTION III-2
3. CERTIFICATION AND ACCREDITATION PROCESS III-5
3. SECURITY CONTROL MONITORING III-17
CHAPTER IV: NNSA MANAGEMENT, OPERATIONAL, AND
TECHNICAL CONTROLS IV-1
CHAPTER V: SECURITY CATEGORY V-1
CHAPTER VI: INFORMATION SYSTEM SECURITY PLAN
AND ACCREDITATION PACKAGE VI-1
1. REQUIREMENTS VI-1
2. INFORMATION SYSTEM SECURITY PLAN VI-1
3. ISSP CONTENTS VI-3
CHAPTER VII: PROTECTION REQUIREMENTS FOR
SENSITIVE UNCLASSIFIED INFORMATION (SUI) VII-1
1. INTRODUCTION VII-1
2. CRITERIA AND PROCESSES VII-1
3. REMOTE ACCESS VII-2
4. MANAGEMENT OF PII ON PORTABLE/MOBILE
DEVICES AND REMOVABLE MEDIA VII-2
Figures
FIGURE III-1. PHASE 1 CHECKLIST 12
FIGURE III-2. VERIFICATION PACKAGE CONTENTS 15
FIGURE III-3. PHASE 3 CHECKLIST 16
FIGURE III-4. PHASE 4 CHECKLIST 18
Tables
TABLE III-1. COL OF CONFIDENTIALITY 7
TABLE III-2. COL OF INTEGRITY 7
TABLE III-3. COL OF AVAILABILITY 7
TABLE III-4. COL OF CONFIDENTIALITY, INTEGRITY, AND AVAILABILITY 8
TABLE III-5. POTENTIAL IMPACT FOR CONFIDENTIALITY, INTEGRITY, AND AVAILABILITY 8
TABLE III-6. LEVELS OF CONCERN FOR UNCLASSIFIED INFORMATION 9
Appendices
APPENDIX A: ACRONYMS A-1
APPENDIX B: GLOSSARY B-1
iv NAP 14.2-C
05-02-08
This page left intentionally blank.
NAP 14.2-C I-1
05-02-08
CHAPTER I: NNSA CERTIFICATION AND ACCREDITATION PROCESS
1. PURPOSE. Establish requirements for a NNSA Certification and Accreditation (C&A)
process that incorporates national level requirements and applies them consistently across
all NNSA elements.
2. CANCELLATIONS. This NNSA Policy replaces NAPs 14.3A, 14.4A, 14.5A, 14.6A,
14.7A, 14.8A, 14.9A, 14.10A, 14.11A, 14.14, and 14.15.
3. APPLICABILITY. This NNSA Policy Letter (NAP) applies to all NNSA entities,
Federal and contractor, that collect, create, process, transmit, store, and disseminate
information on automated information systems for NNSA.
a. NNSA Elements. NNSA Headquarters Organizations, Site Offices, Service
Center, NNSA contractors, and subcontractors are, hereafter, referred to as NNSA
elements.
Section 2
b. Scope. This NAP applies to any information system that collects, creates,
processes, transmits, stores, and disseminates unclassified or classified NNSA
data. This NAP applies to any information system life cycle, including the
development of new information systems, the incorporation of information
systems into an infrastructure, the incorporation of information systems outside
the infrastructure, the development of prototype information systems, the
reconfiguration or upgrade of existing systems, and legacy systems. In this
document, the term(s) "information system,” “cyber system,” or "system" are
used to mean any resource that is used to collect, create, process, transmit, store,
or disseminate data owned by, for, or on behalf of NNSA or DOE, as determined
by the cognizant DAA.
c. Deviations. Deviations from the requirements prescribed in this NAP must be
processed as described in NAP 14.1-C, NNSA Baseline Cyber Security Program.
d. Exclusions.
(1) The Deputy Administrator for Naval Reactors shall, in accordance with
the responsibilities and authorities assigned by Executive Order 12344 (set
forth in Public Law 106-65 of October 5, 1999 [50 U.S.C. 2406]) and to
ensure consistency throughout the joint Navy and DOE Organization of
the Naval Reactors Propulsion Program, implement and oversee all
requirements and practices pertaining to this policy for activities under the
Deputy Administrators cognizance.
(2) These requirements do not apply to systems processing Sensitive
Compartmented Information (SCI) located at NNSA sites. SCI must be
protected in accordance with the appropriate intelligence community
policies and directives.
I-2 NAP 14.2-C
05-02-08
e. Site/Facility Management Contractors. Except for the exclusions in paragraph 3d,
the Contractor Requirements Document (CRD), Chapter II, sets forth
requirements of this policy that will apply to site/facility management contractors
whose contracts include the CRD.
The CRD must be included in site/facility management contracts that provide
automated access to NNSA information or information systems.
The CRD does not automatically apply other than site/facility management
contractors. Any application of requirements of this policy to other than
site/facility management contractors will be communicated separately.
As the laws, regulations, and DOE and NNSA directives clause of site/facility
management contracts states, regardless of the performer of the work, site/facility
management contractors with the CRD incorporated into their contracts are
responsible for compliance with the requirements of the CRD.
Affected site/facility management contractors are responsible for flowing down
the requirements of the CRD to subcontractors at any tier to the extent necessary
to ensure the site/facility management contractors’ compliance with the
requirements.
Contractors must not flow down requirements to subcontractors unnecessarily or
imprudently. That is, contractors will: –
Ensure that they and their subcontractors comply with the requirements of the
CRD; and
Incur only costs that would be incurred by a prudent person in the conduct of
competitive business.
Section 3
f. Implementation. A plan for the implementation of this NAP must be completed
within 60 days of a site’s contract to include this NAP. A plan for the
implementation of this NAP within an NNSA Federal organization must be
completed within 60 days after issuance of this NAP. The implementation plan
must include, at a minimum, the program activity to be modified/created; the
starting date of revision/development; the estimated due date; and the responsible
party for the stated activity. This implementation plan schedule shall not exceed
three years from the latest accreditation date for any system prior to the effective
date of this NAP.
(1) Existing Accredited Information Systems. All current and valid
information system accreditations may continue in effect until the
accreditation expires or re-accreditation is necessary. Re-accreditation of
these systems must conform to the NNSA C&A process outlined in this
policy.
NAP 14.2-C I-3
05-02-08
(2) Information Systems in Progress. Information systems that have begun
the C&A process before release of this NAP may be accredited under the
previous requirements. These systems will remain accredited until re-
accreditation is required, either because the systems have passed the 3-
year accreditation expiration date or because a security-significant change
has been made to the information system or its environment (i.e., physical,
logical, or operational). Re-accreditation must conform to the NNSA
C&A process outlined in this policy.
(3) Non-Accredited Information Systems. Information systems that require
initial accreditation, or re-accreditation outside of (1) and (2) above, must
be certified and accredited in accordance with the NNSA C&A process
outlined in this policy.
4. BACKGROUND. This NAP documents the requirements for C&A in an effort to
provide a comprehensive and consistent approach to C&A for all NNSA classified and
unclassified information systems. C&A is the process of identification, formal
assessment (certification), acceptance (accreditation), and continued operation of system
security controls that protect information systems and information stored or processed on
those systems. This process encompasses the system’s life cycle to assure that the risk of
operating a system is recognized, evaluated, and accepted. The C&A process implements
the concept of “adequate security,” or security commensurate with risk, including the
magnitude of harm resulting from the unauthorized access, use, disclosure, disruption,
modification, or destruction of information. The proper implementation of the NNSA
C&A process will ensure that all applicable requirements have been integrated into the
development and operational processes. All NNSA information systems must have a
complete C&A prior to going operational (i.e., processing live data).
This document addresses the requirements of the DOE and NNSA to ensure that adequate
security controls are provided for all information systems. Additionally, this document
provides guidance for the implementation of DOE M 205.1-4. Implementing the
minimum security controls of this NAP will allow NNSA cyber systems to operate at an
acceptable risk level.
5. REQUIREMENTS.
a. Each General Support System (GSS) or Major Application (MA) and minor
applications must be accredited or have an Interim Approval to Operate (IATO)
from the Designated Approving Authority (DAA) before any NNSA information
is processed, created, and/or transmitted on the system.
Section 4
b. Each information system must be re-accredited at least every three years or
whenever a security-significant change is to be made to the information system or
its environment (i.e., physical, logical, or operational).
I-4 NAP 14.2-C
05-02-08
c. The C&A activities must comply with the procedures described in Chapter III,
NNSA C&A Process.
d. Each information system shall be accredited using one of the following forms of
accreditation.
(1) System Accreditation. An accreditation method used for a single
information system operating under a single Information System Security
Plan (ISSP). Accreditation is based on certification of the information
system.
(2) Site Accreditation. An accreditation method used to accredit multiple
instances of an information system where all instantiations (i.e.,
installations) of the information system are to be operated in equivalent or
more stringent operational environments. The DAA may approve a Site
(i.e., “Master”) ISSP to cover all such information systems. The
information systems covered by a Site ISSP may range from personal
computers up to and including multi-user information components and
local area networks that meet the criteria for a Site ISSP approach. The
authority to operate additional instantiations under the ISSP is based on
successful completion of the follow-on processes described in the ISSP.
The DAA must accredit the first information system under the Site ISSP,
and delegate subsequent accreditations. The CSSM must certify that all
other individual information systems to be operated under the Site ISSP
meet the conditions of the approved Master ISSP. This certification, in
effect, accredits the individual information systems to operate under the
Site ISSP.
(a) The information system’s certification documentation must contain
the information system’s identification and location, and must
include a statement signed by the CSSM certifying that the
information system implements the requirements in the Site ISSP.
(b) All information systems certified under a Site ISSP remain
certified until significant changes are made to the Site ISSP, or
three years have elapsed since the information system was
certified.
(3) Type Accreditation. An accreditation method used to accredit multiple
connections to one network, where the connections are located at different
sites but a single DAA is responsible for the entire network. Each
connection must be implemented using the same ISSP. Accreditation is
based on the approval of processes for testing and certifying additional
connections. The authority to operate additional connections under the
ISSP is based on successful completion of the follow-on processes
described in the ISSP.
NAP 14.2-C
05-02-08
e. Security Test and Evaluation (ST&E) plans must be developed for each
information system and each information system's controls as described by the
ST&E process in Chapter IV.
f. A minimum set of securiw controls, as determined by the system categorization
process, must be implemented on all NNSA systems to appropriately protect
informati on.
g- The DAA must:
(1) AppmvetheISSPpriortethebeghingofthecontrolassessmentand
updated as a result of deficiencies identified during the ST&E process.
2 Approve the ST&E Plan prior to the start of the ST&E process.
h. Smsi tive Unclassified Information (SUT), including Personally Identifiable
Information (PII), must be appropriately protected as described in NAP 1 4.1 -C,
Bareline Cyber Security Program.
Section 5
6 . RESPONSIBILITIES. Roles and responsibilities for all activities in this document are
described m NAP 1 4.1 -C, hWSA BmeJine Cyber Seczcrily Program.
7. DEFINITIONS. See NAP 14.1 -C, Bmeline Cybw Securiv Program,
8. CONTACT. Questions concerning this NAP should be directed through the cognizant
DAA t~ the NNSA Cyber Security Program Manager (CSPM), at 202-586-9728.
THOMAS P. D ~ G O S T ~ ~ ~ O
Administrator
I-6 NAP 14.2-C
05-02-08
This page left intentionally blank.
NAP 14.2-C II-1
05-02-08
CHAPTER II: CONTRACTOR REQUIREMENTS DOCUMENT
This Contractor Requirements Document (CRD) establishes the requirements for NNSA
contractors with access to NNSA and DOE information systems. Contractors must comply with
the requirements listed in the CRD. The contractor will ensure that it and its subcontractors cost-
effectively comply with the requirements of this CRD.
Regardless of the performer of the work, the contractor is responsible for complying with and
flowing down the requirements of this CRD to subcontractors at any tier to the extent necessary
to ensure the contractor’s compliance with the requirements. In doing so, the contractor must
not unnecessarily or imprudently flow down requirements to subcontractors. That is, the
contractor will ensure that it and its subcontractors comply with the requirements of this CRD
and incur only those costs that would be incurred by a prudent person in the conduct of
competitive business.
1. REQUIREMENTS. A plan for the implementation of this NAP must be completed
within 60 days after modification of the site’s contract to include this CRD. The
implementation plan must include, at a minimum, the program activity to be
modified/created; the starting date of revision/development; the estimated due date; and
the responsible party for the stated activity. This implementation plan schedule shall not
exceed three years from the latest accreditation date for any system prior to the effective
date of this NAP.
a. Existing Accredited Information Systems. All current and valid information
system accreditations may continue in effect until the accreditation expires or re-
accreditation is necessary. Re-accreditation of these systems must conform to the
NNSA C&A process outlined in this policy.
b. Information Systems in Progress. Information systems that have begun the C&A
process before release of this NAP may be accredited under the previous
requirements. These systems will remain accredited until re-accreditation is
required, either because the systems have passed the 3-year accreditation
expiration date or because a security-significant change has been made to the
information system or its environment (i.e., physical, logical, or operational). Re-
accreditation must conform to the NNSA C&A process outlined in this policy.
c. Non-Accredited Information Systems. Information systems that required no
previous accreditation (e.g., legacy systems) must be certified and accredited in
accordance with the NNSA C&A process outlined in this policy.
2. All General Support Systems (GSSs), Major Applications (MA), and minor applications
managed and/or operated by an NNSA element must be accredited or have an Interim
Approval to Operate (IATO) before any information is processed, created, stored, and/or
transmitted, as described in this policy.
II-2 NAP 14.2-C
05-02-08
Section 6
3. All information systems managed and/or operated by an NNSA element must be re-
accredited at least every three years or whenever a security-significant change is to be
made to an information system or its environment (i.e., physical, logical, or operational).
4. The contractor must follow the C&A activities as described in this NAP.
5. All information systems managed and/or operated by an NNSA element shall be
accredited using one of the following forms of accreditation.
a. System accreditation. An accreditation method used for a single information
system operating under a single ISSP. Accreditation is based on information
system certification.
b. Site accreditation. An accreditation method used to accredit multiple instances of
an information system where all instantiations (i.e., installations) of the
information system are to be operated in equivalent or more stringent operational
environments. The DAA may approve a Site (i.e., “Master”) ISSP to cover all
such information systems. The information systems covered by a Site ISSP may
range from personal computers up to and including multi-user information
components and local area networks that meet the criteria for a Site ISSP
approach. The authority to operate additional instantiations under the ISSP is
based on successful completion of the follow-on processes described in the ISSP.
The DAA must accredit the first information system under the Site ISSP. The
ISSM must certify that all other individual information systems to be operated
under the Site ISSP meet the conditions of the approved Site ISSP. This
certification, in effect, accredits the individual information systems to operate
under the Site ISSP.
(1) The information system’s certification documentation must contain the
information system’s identification and location, and must include a
statement signed by the ISSM certifying that the information system
implements the requirements in the Site ISSP.
(2) All information systems certified under a Site ISSP remain certified until
significant changes are made to the Site ISSP, or three years have elapsed
since the information system was certified.
c. Type Accreditation. An accreditation method used to accredit multiple
connections to one network, where the connections are located at different sites
but a single DAA is responsible for the entire network. Each connection must be
implemented using the same ISSP. Accreditation is based on the approval of
processes for testing and certifying additional connections. The authority to
operate additional connections under the ISSP is based on successful completion
of the follow-on processes described in the ISSP.
6. The accreditation decision for each information system must be supported by C&A
documentation as described in Chapter III of this document.
NAP 14.2-C II-3
05-02-08
7. The contractor must develop Security Test and Evaluation (ST&E) plans for each
information system. Each information system’s control implementation is assessed as
described in Chapter IV.
8. A minimum set of security controls, as determined by the system categorization process,
must be implemented on all NSA systems to appropriately protect information.
9. The DAA must:
a. Approve the ISSP prior to the beginning of the control assessment and updated as
a result of deficiencies identified during the ST&E process and
b. Approve the ST&E Plan prior to the start of the ST&E process.
Section 7
10. Contractor must implement the minimum set of security controls as determined by the
system categorization process for each information system to appropriately protect
information that is processed, and stored, on unclassified and classified information
systems.
11. The contractor must appropriately protect Sensitive Unclassified Information (SUI),
including Personally Identifiable Information (PII), as described in NAP 14.1-C, NNSA
Baseline Cyber Security Program.
12. The contractor must document training requirements for all contractor personnel
involved in C&A activities
II-4 NAP 14.2-C
05-02-08
This page left intentionally blank.
NAP 14.2-C III-1
05-02-08
CHAPTER III: CERTIFICATION AND ACCREDITATION (C&A) PROCESS
National Nuclear Security Administration
(NNSA)
Office of the Chief Information Officer
III-2 NAP 14.2-C
05-02-08
1. INTRODUCTION.
This document is designed to implement applicable national-level and DOE requirements in the
C&A of all NNSA systems and applications. This document is intended to provide a
comprehensive and uniform approach for C&A.
Ideally, the C&A process should be integrated into the system development life cycle during the
capital planning and investment control process. During development, the ISSP should be
written and the initial risk assessment completed in order to provide an assessment of the
possible risks to the system. Additionally, the security-related documents listed in Appendix A
through C of this document must be completed as appropriate during this process.
Every NNSA system and major and minor application must have official approval to operate
(ATO). This approval can consist of a formal accreditation which is valid for up to three years
or until a security-significant change occurs, or the approval can be an Interim Approval to
Operate (IATO), which is only valid for a maximum of six months. An IATO can be granted by
the DAA provided DAA-approved protection measures are in place and functioning during the
period of the IATO.
Scope
This document addresses the NNSA C&A process as adopted by the NNSA OCIO. Within this
document, the four phases of C&A are detailed as well as supporting checklists and templates to
be used during the process. This document must be used by all NNSA elements.
Outcome
The C&A methodology outlined in this document provides NNSA system owners and program
managers with uniform guidance on how to their information systems are certified and
accredited. Proper use of the C&A methodology will assure NNSA that the level of security
implemented and controls in place adequately protect assets given an acceptable level of residual
risk. NNSA will benefit from the C&A activities performed on information systems in the
following ways:
• Formal approval to operate
• Standard security environment through utilization of baseline security requirements
• Clearly defined system boundaries
• Documented security plans
• Defined and tested contingency plans
• Established configuration management processes
• Heightened information security awareness
Validated security controls
Measured levels of risk based on identified threats and vulnerabilities
Defined security roles and responsibilities
NAP 14.2-C III-3
05-02-08
Structure
Section 8
This document is organized into three major sections. Section 1 introduces the NNSA C&A
Process. Section 2 provides a reference to the roles and responsibilities of the key parties
involved in the C&A process. Section 3 describes the C&A process. A checklist has been
included at the end of each phase. These checklists are designed to provide a quick reference for
all participants in the process.
Special Consideration - Interim Approval To Operate (IATO)
An IATO may be deemed necessary by the Designated Approving Authority (DAA) if there is
an overarching mission need to place a new system into operation or continue processing on an
existing system.
IATO Request Process
The IATO Request process is a structured approach to monitor the effectiveness of the security
controls in the information system during the IATO period. Consequently, the IATO Request
submitted by the ISSM is used by the authorizing official to monitor the progress of correcting
any deficiencies noted during the security certification, if that was the reason for the IATO.
NNSA elements must maintain a copy of the IATO approval for record keeping, as well as for
forwarding to appropriate personnel upon request.
All deficiencies noted during the certification process that will be used as the basis for the IATO
must be tracked in the system POA&M that is forwarded to the DAA with the IATO request.
Reportable Conditions must be resolved within 180 days. Before a deficiency can be considered
resolved, sites must provide their cognizant DAAs with verification documentation and formally
request concurrence.
Interim Authority to Test (IATT)
Another option for interim processing is an Interim Authority to Test (IATT). If a system needs
to be operational during the development phase, the DAA may approve an IATT for a maximum
of six (6) months. In this case, the system developers and the DAA will agree via formal
documentation as to what information groups can be processed on the system during the IATT as
well as what security controls (i.e., management, operational, and technical), are temporarily
required until the system can be successfully certified.
Final Accreditation
In accordance with OMB policy, an information system is not considered to have received its
final accreditation during the period of IATO. When the reason for the IATO has been resolved,
and any identified security-related deficiencies have been adequately addressed, the interim
authorization should be lifted and the information system accredited to operate.
III-4 NAP 14.2-C
05-02-08
2. ROLES AND RESPONSIBILITIES.
The majority of roles and responsibilities for key participants in the NNSA C&A process are
detailed in NAP 14.1-C, NNSA Baseline Cyber Security Program. Additional roles are described
below.
Certification Team (CT)
The CT is responsible for conducting the certification activities. The CT is responsible for
coordinating C&A activities and consolidating the final C&A package. The team will determine
if the security controls are correctly implemented and effective. The CT will make this
determination after receiving input from the ST&E Team.
Security Test and Evaluation (ST&E) Team
The ST&E team, whose membership must include the system’s ISSO, is responsible for
performing the ST&E on the system and validating that the controls on the system are present
and operating in accordance with the ISSP.
Section 9
The ST&E team must include one member who is independent of the system under evaluation in
the sense that they should not have (a) been the developers of the system nor (b) be a privileged
user of the system. In order to ensure independence and competence, the ST&E team and its
technical qualifications must be approved by the Certification Agent (CA) prior to the
commencement of the C&A process.
The results of the ST&E, together with the rest of the certification package, will be presented by
the ISSO to the CA so that they can make an accurate determination of the risk to the system,
and thus provide an informed accreditation recommendation to the DAA.
Program Manager and System Owner
The program manager (if applicable) and system owner represent the interest of the user
community and the information system throughout the system’s life cycle. The program
manager is responsible for the system during initial development and acquisition and is
concerned with cost, schedule and performance issues. The system owner assumes
responsibility for the system after delivery and installation and is responsible for system
operation, system maintenance, and disposal. Together they are responsible for ensuring the
system is deployed and operated according to the security controls documented in the ISSP and
are also responsible for seeing that system users and security support personnel receive the
requisite security training.
The program manager and system owner will ensure that the C&A effort is coordinated and
provide the necessary resources and information to the CT. They will ensure the preparation of
the certification package before it is presented to the CA.
NAP 14.2-C III-5
05-02-08
3. CERTIFICATION AND ACCREDITATION PROCESS.
Phase 1: Pre-Certification
Phase 1 involves gathering information about the system to be certified, determining the scope of
the certification effort, validating the initial ISSP for the system (if available), performing the
initial validation of the risk assessment and system security controls, and determining the C&A
schedule. During phase 1, the system owner or program manager will establish the certification
schedule in coordination with all appropriate stakeholders.
Step 1: Define the System and Scope of the C&A Effort
During this phase, the CT gathers all available system information (e.g., design documents,
system descriptions, graphics, system plans, and approved Interconnection Security Agreement)
in order to get a comprehensive system description and to define the scope of the C&A effort.
Defining the system involves identifying the software, hardware, and communications
equipment within the system boundary which may impact security in order to understand what
needs to be examined for the C&A effort.
An information system is a set of information resources organized for the collection, storage,
processing, maintenance, use, sharing, dissemination, disposition, display, or transmission of
information. The process of uniquely assigning information resources to an information system
defines the security accreditation boundary for that system. NNSA elements have flexibility in
determining what constitutes an information system (i.e., major application or general support
system) and the resulting security accreditation boundary that is associated with that information
system. Both major applications and general support systems will be treated as an information
system (i.e., “system”) and will undergo the certification and accreditation process described in
NAP 14.2-C.
Section 10
A general support system is an interconnected set of information resources. Such a system can
be, for example, a local area network (LAN) including smart terminals that supports a branch
office, an agency-wide backbone, a communications network, a departmental data processing
enter including its operating system and utilities, a tactical radio network, or a shared
information processing service organization. Normally, the purpose of a general support system
is to provide processing or communications support.
A major application is an information system(s) that perform clearly defined functions for which
there are readily identifiable security considerations and needs (e.g., an electronic funds transfer
system). A major application comprises many components (e.g., hardware, software, and
telecommunications components) that provide a common functionality. Major applications
require special attention to security because of the risk and magnitude of the harm resulting from
the loss, misuse, or unauthorized access to or modification of the information in the application.
Note: All Federal applications require some level of protection. Certain applications, because of
the information in them, however, require special management oversight and should be treated as
III-6 NAP 14.2-C
05-02-08
major. Adequate security for other applications should be provided by security of the systems in
which they operate. [From Appendix III, OMB A-130]. A software application alone without
hardware and the supporting operating system is insufficient for consideration as an accreditation
boundary. For example, a certification and accreditation Information System Security Plan
(ISSP) for a major application could include a vulnerability management application, along with
its supporting operating system(s) and hardware component(s).
During Phase 1 the C&A key participants (e.g., DAA, CA, the program manager, the system
owner, the certification team, the CSSO, other officials in the NNSA element or department that
have an interest in the system) will agree on the scope and schedule for C&A activities. The CA
must approve of the ST&E team and ensure they are technically competent prior to the
commencement of the rest of the C&A process.
Determine the Security/System Categorization
Since the potential impact levels for the confidentiality, integrity, and availability security
objectives may not be identical for an information system, the high water mark concept is used to
determine the impact level of the information system. Thus, a low-impact system is defined as
an information system in which all three of the security objectives are low. A moderate-impact
system is an information system in which at least one of the security objectives is moderate and
no security objective is high. And finally, a high-impact system is an information system in
which at least one security objective is high. Once the overall impact level of the information
system is determined, the minimum set of security control can be selected from the baseline
controls in Chapter IV..
National Security Systems
For national security systems, the certification team must use the methodology defined below for
determining the system categorization (i.e., Control Baseline) based on the information system
boundary, identification of information group(s), and Consequences of Loss (CoL) for
Confidentiality.
Section 11
National security information is grouped (information group) based on sensitivity
(classification level, category, and need-to-know). The following paragraph describes the
information groups in increasing order of sensitivity (Top Secret Restricted Data considered
the most sensitive). National Security Systems must be categorized based on the most
sensitive information group they contain and the impact/CoL if the confidentiality, integrity
and/or availability of the information is lost. The impact is determined through a CoL concept
that ranks the perceived value of each information group in terms of confidentiality, integrity,
and availability.
Consequences of Loss – Classified Information.
Tables III-1 through Table III-3 describe the criteria used to determine the CoL to
confidentiality, integrity, and availability for all classified information. Table III-4 provides
the results of the evaluation of impact of loss for each national security information group and
represents the minimum CoL value for each information group.
NAP 14.2-C III-7
05-02-08
Table III-1. CoL of Confidentiality
Consequences
of Loss Confidentiality
High Unauthorized, premature, or partial disclosure may have a grave effect on
National security, Senior DOE Management, DOE, or National interests.
Moderate
Serious damage to National security will result if confidentiality is lost;
Information requiring protection mandated by policy, laws, or agreements
between DOE, its contractors, and other entities, such as commercial
organizations or foreign Governments; Information designated as mission-
essential; or Unauthorized, premature, or partial disclosure may have an
adverse effect on site-level interests.
Low
Damage to National security will result if confidentiality is lost; Information
designated as sensitive by the data owner; or Unauthorized, premature, or
partial disclosure may have an adverse effect on organizational interests.
Table III-2. CoL of Integrity
Consequences
of Loss Integrity
High Loss of integrity will have a serious effect on National-level interests or Loss of
integrity will have a serious effect on confidentiality.
Moderate
A degree of integrity required for mission accomplishment, but not absolute; Bodily
injury might result from loss of integrity; or Loss of integrity will have an adverse
effect on organizational-level interests.
Low Loss of integrity impacts only the missions of site- or office-level organization.
Table III-3. CoL of Availability
Consequences
of Loss Availability
High
Loss of life might result from loss of availability; Information must always be
available upon request, with no tolerance for delay; Loss of availability will have an
adverse effect on National-level interests; Federal requirement (i.e., requirement
for Material Control and Accountability (MC&A) inventory); or Loss of availability
will have an adverse effect on confidentiality.
Moderate
Information must be readily available with minimum tolerance for delay; Bodily
injury might result from loss of availability; or Loss of availability will have an
adverse effect on organizational-level interests.
Low Information must be available with flexible tolerance for delay.
III-8 NAP 14.2-C
05-02-08
Note: In this context, “High – no tolerance for delay” means no delay; “Moderate – minimum
tolerance for delay" means a delay of seconds to hours; and “Low – flexible tolerance for delay”
means a delay of days to weeks
Section 12
Table III-4. CoL of Confidentiality, Integrity, and Availability
Information Group Loss of
Confidentiality Loss of Integrity Loss of Availability
Confidential and
Secret Information*
Moderate Low Low
Secret** and Top
Secret Information
High Low Low
* Includes SRD, Sigmas 1, 2, 3, 4, 5, 9, 10, 11, 12, 13. 15 and 20 are grouped as moderate.
** Includes SRD, Sigmas 14.
1
Sigmas 6, 7, and 8 are not currently in use.
NOTE: The levels in this table are the minimum values allowed by NNSA Senior Management
or the operating unit may assign a higher level of consequence for any or all of the information
groups.
Unclassified Information Systems and Major Applications
To determine the security categorization for unclassified information systems and major
applications, the levels of risk must first be identified for confidentiality, integrity, and
availability. FIPS PUB 199 provides guidance for assigning security categorization factors for
information processed on Federal systems. Each factor is assigned a level of low, moderate, or
high. Confidentiality provides assurance that the system data is protected from disclosure to
unauthorized personnel, processes, or devices. Integrity provides assurance that the data
processed by the system is protected from unauthorized, unanticipated, or unintentional
modification or destruction. Availability provides assurance that the system data and resources
will be available to authorized users on a timely and reliable basis.
The format for documenting the security categorization is as follows: CATEGORIZATION
= [(confidentiality, Potential Impact), (integrity, Potential Impact ), (availability, Potential
Impact.)]
Table III-5 below provides guidance on how to determine which risk-level of concern should be
assigned to confidentiality, integrity, and availability.
NAP 14.2-C III-9
05-02-08
Table III-5. Potential Impact for Confidentiality, Integrity, and Availability
Risk Level
Low Moderate High
Confidentiality
Preserving authorized
restrictions on
information access and
disclosure, including
means for protecting
personal privacy and
proprietary information.
[44 U.S.C §3542]
The unauthorized
disclosure of information
could be expected to
have a limited adverse
effect on agency
operations (including
mission, functions,
image, or reputation),
agency assets, or
individuals. A loss of
confidentiality could be
expected to cause a
negative outcome or
result in limited damage
to operations or assets,
requiring minor corrective
repairs.
The unauthorized
disclosure of information
could be expected to have
a serious adverse effect
on agency operations
(including mission,
functions, image, or
reputation), agency
assets, or individuals. A
loss of confidentiality
could be expected to
cause significant
degradation in mission
capability, place the
agency at a significant
disadvantage, or result in
major damage to assets,
requiring extensive
corrective actions or
repairs.
The unauthorized
disclosure of information
could be expected to have
a severe or catastrophic
adverse effect on agency
operations (including
mission, functions, image,
or reputation), agency
assets, or individuals. A
loss of confidentiality
could be expected to
cause a loss of mission
capability for a period that
poses a threat to human
life, or results in a loss of
major assets.
Integrity
Guarding against
improper information
modification,
destruction, and
includes ensuring
information non-
repudiation and
authenticity.
Section 13
[44 U.S.C. §3542]
The unauthorized
modification or
destruction of information
could be expected to
have a limited adverse
effect on agency
operations (including
mission, functions,
image, or reputation),
agency assets, or
individuals. A loss of
integrity could be
expected to cause a
negative outcome or
result in limited damage
to operations or assets,
requiring minor corrective
actions or repairs.
The unauthorized
modification or destruction
of information could be
expected to have a
serious adverse effect on
agency operations
(including mission,
functions, image, or
reputation), agency
assets, or individuals. A
loss of integrity could be
expected to cause
significant degradation in
mission capability, place
the agency at a significant
disadvantage, or result in
major damage to assets,
requiring extensive
corrective actions or
repairs.
The unauthorized
modification or destruction
of information could be
expected to have a
severe or catastrophic
adverse effect on agency
operations (including
mission, functions, image,
or reputation), agency
assets, or individuals. A
loss of integrity could be
expected to cause a loss
of mission capability for a
period that poses a threat
to human life, or results in
a loss of major assets.
Availability
Ensuring timely and
reliable access to and
The disruption of access
to information could be
expected to have a
limited adverse effect on
agency operations
(including mission,
The disruption of access
to information could be
expected to have a
serious adverse effect on
agency operations
(including mission,
The disruption of access
to information could be
expected to have a
severe or catastrophic
adverse effect on agency
operations (including
III-10 NAP 14.2-C
05-02-08
Risk Level
Low Moderate High
use of information.
[44 U.S.C. §3542]
functions, image, or
reputation), agency
assets, or individuals. A
loss of availability could
be expected to cause a
negative outcome or
result in limited damage
to operations or assets,
requiring minor corrective
repairs.
functions, image, or
reputation), agency
assets, or individuals. A
loss of availability could be
expected to cause
significant degradation in
mission capability, place
the agency at a significant
disadvantage, or result in
major damage to assets,
requiring extensive
corrective actions or
repairs.
mission, functions, image,
or reputation), agency
assets, or individuals. A
loss of availability could
be expected to cause a
loss of mission capability
for a period that poses a
threat to human life, or
results in a loss of major
assets.
There are three information groups used to define unclassified information. They are Open,
Public, Unrestricted Access; Unclassified Protected; and Unclassified Mandatory Protection.
Table III-6 provides information regarding the minimum LoC for the confidentiality of
unclassified information, along with their assigned Protection Indices. Sites are to determine the
levels of concern for integrity and availability.
Table III-6. Levels of Concern for Unclassified Information
Information Group Definition LoC
Open, Public,
Unrestricted Access
Information requires no protection from
disclosure; e.g., approved for public release
Low
Unclassified Protected Information designated as requiring protection
by the data owner or data steward.
Low
Unclassified Mandatory
Protection/SUI
Unclassified information requiring protection
mandated by policy or laws. See NAP 14.1-C.
Moderate
Section 14
Step 2: Identify Security Controls
The security controls include management, operational, assurance, and technical controls for the
system, as it will be operated, as well as environmental controls and physical security controls.
During this step, the minimum set (baseline) of security controls that should be present on the
system are identified and documented in the ISSP. The system categorization is used to select a
minimum set of security controls from Chapter IV, as appropriate. Security controls that
uniquely support the confidentiality, integrity, or availability security objectives may be
downgraded to the corresponding control in a lower baseline (or appropriately modified or
eliminated if not defined in a lower baseline) if, and only if the downgrading action: (i) is
consistent with the security categorization for the corresponding security objectives of
confidentiality, integrity, or availability before moving to the high water mark; (ii) is supported
NAP 14.2-C III-11
05-02-08
by an organizational assessment of risk; and (iii) does not affect the security-relevant
information within the information system.
The following security controls are potential (although not all-inclusive) candidates for
downgrading: (i) for confidentiality [AC-15, MA-3 (3), MP-3, MP-6, PE-5, SC-4, SC-9]; (ii) for
integrity [SC-8]; and (iii) for availability [CP-2, CP-3, CP-4, CP-6, CP-7, CP-8, MA-6, PE-9,
PE-10, PE-11, PE-13, PE-15, SC-6].
A risk review of the security physical, logical, and operational environment is conducted to
identify any system or site unique threats/ vulnerabilities as well as identify any operational
security practices required by the system owner/ data owner/ steward. Adjustments are made to
the minimum set of security controls by identifying additional/ new security controls that will
mitigate those threats/ vulnerabilities and/or implement the operational practices required by the
system owner/ data owner/ steward. These additional controls may be selected (and modified as
needed) from the security controls in Chapter IV, or new security controls may be created to
satisfy these additional requirements.
Additionally, system privacy implications are reviewed to include preparation of a Privacy
Impact Assessment (PIA) for externally facing (publicly accessible) systems that contain
privacy information and additional requirements needed to secure the system at the proper
security/system categorization.
Step 3: Conduct a Privacy Impact Assessment (PIA) if required
If a PIA is required, it must be completed as detailed in “DOE Procedures for Conducting
Privacy Impact Assessments”. A PIA is required whenever the system contains data covered
under the Privacy Act of 1974 (Public Law 93-579), September, 1975, if the system is external
facing.
Step 4: Review the ISSP
The ISSP provides a system description, a list of the security requirements for the system, and
explains how the system security controls are implemented. The initial ISSP should be created
during system development as part of the security requirements definition for the system. ISSPs
should be updated whenever changes are made to the security posture of the system. See
Chapter V for an outline of the ISSPs required contents.
Section 15
During this step, the existing ISSP should be reviewed by the system owner and CT to ensure
that it describes the security controls required for the system. The CT will also verify that the
control implementations described are appropriate for the security/system categorization and that
the ISSP provides information about any user organizations, both internal and external, that
connect to the system. If the system does interconnect with other systems or organizations not
under the operational control of the sponsoring organization, details about the security controls
on those connections shall be documented in an Interconnection Security Agreement (ISA).
III-12 NAP 14.2-C
05-02-08
Step 5: Review the Initial Risk Assessment
After the ISSP is reviewed, the initial risk assessment should be inspected to ensure that it
identifies all apparent threats and vulnerabilities in the information system and is consistent with
the guidance provided in the NNSA risk management methodology as described in NAP 14.1-C,
NNSA Baseline Cyber Security Program. The risk assessment should also determine the overall
level of risk present on the system given the type of data the system processes, the security
controls on the system, and the system’s operating environment. The risk assessment is
completed before the system is fielded to verify that the security requirements specified during
development have been met. Risk assessments shall be updated every time there is a change to
the security controls on the system that might affect the residual risk to the system.
Step 6: Review the ISA
If this system will be connected to other information systems under the responsibility of another
certifying or accrediting authority, the requirements for connectivity with the other system must
be identified. The ISA is started during the Initiation Phase of the System Development Life
Cycle (SDLC) and is refined during the Acquisition/Development Phase. However, the ISA may
not be completed until the actual system Implementation Phase. Additional requirements on
ISAs are contained in NAP 14.1-C, Chapter XXI.
Step 7: Negotiation
After steps 1 through 4 are complete, all the participants, including the program manager, the
system owner, and CT will review the extent and scope of the planned C&A effort. The
participants should review the security/system categorization for the system and ensure that it is
appropriate. At this point, a schedule is set forth for the remaining steps in the C&A effort.
After successful negotiation, the DAA approves the security plan.
The checklist in Figure III-1 on the following page provides a quick reference of all activities
that should take place during Phase 1 of the C&A process.
Figure III-1. Phase 1 Checklist
Phase 1 Checklist
Has the scope of the C&A effort been defined?
Has the security/system categorization been determined and documented?
Have the Minimum Set of Security Controls been identified?
Have any additional controls been identified?
Has a review of the approved ISA been done?
Has a PIA been conducted, if required?
NAP 14.2-C III-13
05-02-08
Has the Information System Security Plan been reviewed?
Has the Risk Assessment been reviewed?
Has the DAA approved the ISSP?
Have any deviations (if applicable) been approved?
Phase 2: Verification
Section 16
During the Verification phase, the ST&E team will conduct the testing to evaluate the
effectiveness of the security controls on the information system, and then use the results of the
ST&E to update the risk assessment and the ISSP, if necessary. The results of this phase will be
documented in the final certification package. The certification package will then be presented
to the DAA for a final accreditation decision.
Step 1: Conduct a Security Test and Evaluation (ST&E)
All controls identified in each ISSP are to be subjected to security control assessment
procedure(s) during the C&A process to evaluate the status of control implementation with
respect to security requirements and effectiveness.
• Under a “System”, “Site”, or “Type” form of accreditation, each control must be
subjected to a ST&E process.
• Accreditation of additional instantiations (i.e., additional equivalent
installations) may be based on a subset of the ST&E procedures used for the
first instance. This subset, which is identified in the ST&E Procedures and
approved by the DAA, must provide for overall assurance that future
instantiations are equivalently implemented to the first instance.
• The ST&E procedure(s) used for the assessment/evaluation of a control for each
additional instance must not be modified from those used to evaluate the first
instance.
ST&E consists of three steps: creating the ST&E Plan, executing the test procedures, and
documenting the results in the ST&E Report with recommended countermeasures.
Create the ST&E Plan
When developing the plan, testing objectives and ST&E procedure(s) shall be derived from the
security controls identified in Phase 1. Each ST&E procedure, at a minimum, verifies that the
security control is in effect and correctly implements the explicitly identified criteria in the
control statement. ST&E procedure(s) must be developed for each control identified in the ISSP.
III-14 NAP 14.2-C
05-02-08
Each ST&E procedure must identify the specific control and associated assessment method(s)
used to evaluate the control and support the determination of the security control effectiveness.
The following assessment methods will be used for the assessment of both unclassified and
national security systems.
• Interview: Focused discussions with individuals or groups to facilitate
understanding, achieve clarification, or obtain evidence.
• Examine: Checking, inspecting, reviewing, observing, studying, or analyzing
one or more assessment objects to facilitate understanding, achieve clarification,
or obtain evidence.
• Test: Exercising one or more assessment objects under specific conditions to
compare actual with expected behavior.
Chapter VI, Security Category, describes the expected levels of assurances for the different
impact levels (Low Baseline. Moderate Baseline, High Baseline) that must be used to guide the
level of testing effort required for each impact level.
Execute the Test Plan
After the ST&E plan has been approved by the CA and the DAA, the test procedures in the plan
shall be executed. An important part of the ST&E is a validated Contingency Plan and the
careful review of security-related documentation, such as the risk assessment, PIA, ISSP, and the
Contingency Plan in accordance with NNSA policy. Validation is achieved through (a) a table-
top exercise, or exercising the plan and (b) documenting the results. These documents should be
reviewed to ensure that they are 1) developed in accordance with the appropriate NNSA and
Federal requirements, and 2) that they are up-to-date and usable for their intended purpose.
Section 17
Expected Results
The expected results of the ST&E procedure must assure that all controls are specified,
implemented, and operational consistent with the functional requirements of the control
statement.
Create the ST&E Report and Recommend Countermeasures
After the testing activities are complete, the results from the testing should be documented in a
ST&E report. The report should identify which controls are implemented effectively, which
controls are implemented partially, and which controls are either not implemented, or are
ineffective. These results will be used as input to update the risk assessment.
After the ST&E report is complete, the system owner and the program manager should discuss
the appropriate countermeasures to be implemented. These countermeasures should address any
security requirements that were found to be not implemented or ineffective. Countermeasures
NAP 14.2-C III-15
05-02-08
may be implemented immediately or may be included as part of a remediation plan and schedule
for an IATO, or the situation may be accepted by the DAA.
Step 2: Conduct a Risk Evaluation
This step involves using the results from the ST&E Report to determine the remaining risk for
the system once corrective actions have been implemented to address results from the ST&E.
Any necessary updates to the system’s risk must be included in the form of an addendum to the
system’s original risk evaluation. Risk should be determined for both individual test results and
the overall system or application. This risk determination will be included as part of the
certification package.
Step 3: Update the ISSP and ISA
The ISSP will be updated to reflect any additional security controls or implementation changes
as a result of the ST&E activities and the final risk assessment. Updates should also be made in
the approved ISA and, if required, the PIA.
Step 4: Document Certification Findings
Once the certification activities are complete, the ST&E team will document the results from the
certification process in a ST&E Report. This report will annotate the results and any relevant
security issues identified during certification activities. These results will be compiled along
with the other certification documents into a certification package and forwarded to the CA for
review
Note: The ISSM and CA may be the same person. If they are not, then the certification package
must be submitted to the ISSM by the CA. Figure III-2 shows the Verification Package contents.
Phase 2: Verification Package
Completed ST&E Report
Approved ISSP including ISAs
Completed PIA (if applicable)
Completed SOR Notice if required
Updated Risk Assessment
Figure III-2. Verification Package Contents
III-16 NAP 14.2-C
05-02-08
The CA will evaluate the risks and issues presented in the certification package. The CA then
develops a Certification Statement that states the extent to which the system meets documented
security requirements. As part of the Certification Statement, the CA also provides a
recommendation for an accreditation decision The ISSM then submits the certification statement
to the DAA.
Phase 3: Validation of Certification/Accreditation Decision
Section 18
During the final step of Phase 3, the DAA will review the ST&E Report, weigh the residual risk,
and decide whether to issue an accreditation or to deny accreditation. Based on an evaluation of
residual risk, the ISSM’s recommendation, the DAA will make a risk-based decision to grant
system accreditation or to deny system accreditation because the risks to the system are not at an
acceptable level. The accreditation decision will be documented in the final accreditation
package, which consists of the accreditation letter and supporting documentation.
The following checklist in Figure III-3 provides a reminder of all the actions that should take
place during Phase 3 of the C&A process.
Phase 3 Checklist
Has the ST&E Plan been created and approved?
Has security testing been performed?
Have Privacy Implications been reviewed (if required)?
Has the approved ISA been reviewed?
Has the ST&E Report been written?
Has the Risk Evaluation been updated if required?
If the ISSP has been updated, has the updated plan been approved by the DAA?
Have the certification findings been documented?
Has the certification package been forwarded to the ISSM?
Has the ISSM reviewed the ST&E Report and forwarded it to the DAA?
Has the DAA issued an accreditation decision?
If so, has the DAA returned the C&A package to the ISSM?
Figure III-3. Phase 3 Checklist
NAP 14.2-C III-17
05-02-08
Phase 4: Post-Accreditation Phase
During the post-accreditation phase, the system configuration will be managed to ensure that
changes to the system are monitored, that they do not adversely affect the security posture of the
system, and to facilitate follow-on C&A activities. Periodic testing (at least annually for critical
infrastructure and key resources, and annually for all others) of the Contingency Plan and
selected security controls is a necessary component of the Post-Accreditation Phase.
Configuration Management
Once the system or majo0r application has been officially accredited, the system owner must
maintain configuration control over the system to ensure that the security posture of the system
is not threatened by authorized or unauthorized changes to system software or hardware.
Security-relevant changes that are implemented are documented in the ISSP , design
documentation (for software code changes), and/or the inventory list (for hardware and/or
software changes). Security-significant changes (e.g., security-relevant software version
changes, and operating system changes.), as determined by the DAA, will require re-
accreditation activities to ensure that the system has not incurred additional risk.
Configuration Management and Control
The purpose of this task is to define and document a baseline system configuration and document
and assess proposed and actual changes to the information system. This task is composed of two
sub-tasks.
• Documentation of the Information System Changes. The system owner ensures
that proposed and actual changes to the system are documented , and compares
these to the baseline configuration.
• Security Impact Analysis. The system owner ensures that each proposed or
actual changes to the system are analyzed to determine the security impact.
4. SECURITY CONTROL MONITORING.
The purpose of this task is to detect unauthorized changes to the system configuration through
monitoring and annual assessment of a selected set of controls. This task is completed via three
sub-tasks.
Section 19
• Security Control Selection. The ISSO ensures the selection of the technical,
operational, assurance, and management security controls for monitoring and
annual assessment. The selection of controls must be approved by the DAA.
• Selected Security Control Assessment. The ISSO ensures the assessment of
any controls designated in the ISSP as needing monitoring and performance of
self-assessments annually on the remaining controls.
III-18 NAP 14.2-C
05-02-08
• Status Reporting. The ISSO ensures that significant changes to the security
posture of the information system are reported through the ISSM to the DAA.
Reaccreditation
Federal regulations mandate that systems be re-accredited every three (3) years or when security-
significant changes are made to the system configuration. Program managers and system owners
should keep this in mind when planning system changes. If the system is not significantly
altered, the system owner should begin the C&A process for re-accreditation in a timely fashion
to ensure that the process is complete before the three-year anniversary of the system
accreditation has passed. The Figure III-4 on the following page shows the checklist of all the
actions that should take place during Phase 4 of the C&A process.
Phase 4 Checklist
Has the system owner maintained configuration control?
Have all security-relevant changes to the system been approved by the DAA ?
Have the hardware and software inventories been updated every time the system
configuration changed?
If major system changes have been implemented, has the system been re-accredited in
its new configuration?
Is the three-year anniversary of the system accreditation approaching? If so, have
plans for resources been made to begin the re-accreditation process?
Figure III-4. Phase 4 Checklist
NAP 14.2-C A-1
05-02-08
APPENDIX A
ACCREDITATION LETTER SAMPLE
Security Accreditation Decision Letter (Authorization to Operate)
From: Authorizing Official Date:
To: ISSM
Subject: Security Accreditation Decision for [INFORMATION SYSTEM]
After reviewing the results of the security certification of the [INFORMATION SYSTEM] and
its constituent system-level components (if applicable) located at [LOCATION] and the
supporting evidence provided in the associated security accreditation package (including the
current ISSP and the Security Testing and Evaluation report), I have determined that the risk to
agency operations, agency assets, or individuals resulting from the operation of the information
system is acceptable. Accordingly, I am issuing an authorization to operate the information
system at the Control Baseline in its existing operating environment. The information system is
accredited without any significant restrictions or limitations. This security accreditation is my
formal declaration that adequate security controls have been implemented in the information
system and that a satisfactory level of security is present in the system. The security
accreditation of the information system will remain in effect as long as: (i) the required security
status reports for the system are submitted to this office every [TIME PERIOD]; (ii) any
vulnerabilities reported during the continuous monitoring process do not result in additional
agency-level risk which is deemed unacceptable; and (iii) the system has not exceeded the
maximum allowable time period between security accreditations in accordance with Federal or
agency policy. A copy of this letter with all supporting security C&A documentation should be
retained for the period of the system’s accreditation.
Section 20
Signature
Title
Enclosures
A-2 NAP 14.2-C
05-02-08
This page intentionally left blank.
NAP 14.2-C B-1
05-02-08
APPENDIX B
SAMPLE SECURITY ACCREDITATION DECISION LETTER
INTERIM AUTHORIZATION TO OPERATE (IATO)
Date:
From: Authorizing Official
To: ISSM
Subject: Security Accreditation Decision for [INFORMATION SYSTEM]
After reviewing the results of the security certification of the [INFORMATION SYSTEM] and
its constituent system-level components (if applicable) located at [LOCATION] and the
supporting evidence provided in the associated security accreditation package (including the
current ISSP and the Security Test and Evaluation Report, I have determined that there is an
overarching need to place the information system into operation or continue its operation due to
mission necessity. Accordingly, I am issuing an interim authorization to operate the information
system at the Control Baseline in its existing operating environment. An interim authorization is
a limited authorization to operate the information system under specific terms and conditions for
a limited period of time. The information system is not considered accredited during the period
of limited authorization to operate. The terms and conditions of this limited authorization are
described in Appendix A, Accreditation Letter Sample. A process must be established
immediately to monitor the effectiveness of the security controls in the information system
during the period of limited authorization. Monitoring activities should focus on the specific
areas of concern identified during the security certification. Significant changes in the security
state of the information system during the period of limited authorization should be reported
immediately. This interim authorization to operate the information system is valid for [TIME
PERIOD]. The limited authorization will remain in effect during that time period as long as: (i)
the required security status reports for the system are submitted to this office every [TIME
PERIOD]; (ii) any vulnerabilities reported during the continuous monitoring process do not
result in additional agency-level risk which is deemed unacceptable; and (iii) continued progress
is being made in the system’s progress toward full accreditation. At the end of the period of
limited authorization, the information system must be authorized to operate or the authorization
for further operation will be denied. This office will monitor the schedule submitted with the
request for interim approval during the period of limited authorization. A copy of this letter with
all supporting security C&A documentation must be retained with the system documentation
until the system has achieved final accreditation.
Signature
Title
Enclosures
B-2 NAP 14.2-C
05-02-08
This page intentionally left blank.
NAP 14.2-C C-1
05-02-08
APPENDIX C
SAMPLE INTERCONNECTION SECURITY AGREEMENT
Purpose – The purpose of this ISA is to identify and document to all signatories
satisfaction:
1. Existing risks and mitigation strategies for all of the systems being
interconnected, regardless of whether they are General Support Systems (GSS)
or Major Applications (MA). Note: Any automated process that relies on
Information Technology (IT) must be considered either a GSS or a MA.
2. Any additional risks and mitigation strategies introduced through the
interconnection of systems not under the operation control of the sponsoring
agency.
Section 21
3. Identification of systems participating in the interconnection,.
4. Appropriate levels of assurance to the satisfaction of all signatories that the
documented risk and mitigation strategies are operating as stated and are
effective.
5. Documentation of responsibilities and processes for mutual incident response
and reporting; mutual management, maintenance, operation, and configuration
management of the interface; and disconnection and re-connection of the
systems.
INTERCONNECTION STATEMENT OF REQUIREMENTS – This section should contain:
A clear description of the systems covered by this agreement;
Each system’s intended purpose and target community;
Data sensitivity (i.e., classification)
A description of the interconnection, including a graphic representation of the
interconnection, the purpose of the interconnection, and a clear description of
the authorities under which all of the systems operate. This includes
statutory/regulatory requirements, project goals, and should also clearly state the
responsible management units and system owners, and DAAs;
This agreement shall be reviewed on an annual basis and amended whenever a security-
relevant change to the systems concerned are planned. A change log and a new
signature page should be attached whenever these events occur.
SYSTEM SECURITY CONSIDERATIONS – General information, data descriptions and
data/work flows should be documented in this section as well as risks and mitigation strategies
C-2 NAP 14.2-C
05-02-08
so that a clear picture is presented to each participant of any residual risk. To that end, the
following documents shall be included (where data sensitivity allows) with the ISA:
Risk Assessments – A copy of the Risk Assessment for each system shall become an
appendix to this agreement.
Security Test and Evaluation Plan/Report – Security Test and Evaluation Plans and
subsequent reports for systems included in this agreement shall be amended by all
participants to include the details of the agreement.
Security Assurance –Applicable Certification & Accreditation/Interim Authority to
Operate
Executive Summaries/Sign-Off – An Executive summary shall be prepared that is tied
directly to the portion of the ISA that contains all appropriate signatures. Conditions for
revocation of an ISA authority shall appear in this area as well.
NAP 14.2-C IV-1
05-02-08
CHAPTER IV: NNSA MANAGEMENT, OPERATIONAL, AND TECHNICAL
CONTROLS
This is the NNSA implementation of the DOE CIO TMR-1. The selection and specification of
security controls for an information system is accomplished as part of a Department-wide
information security program that involves the management of organizational risk—that is, the
risk associated with the operation of an information system. The management of organizational
risk is a key element in the Department’s information security program and provides an effective
framework for selecting the appropriate security controls for an information system—the
security controls necessary to protect the operations and assets of the organization.
Managing organizational risk includes several important activities: (i) assessing risk; (ii)
conducting cost-benefit analyses; (iii) selecting, implementing, and assessing security controls;
and (iv) formally authorizing the information system for operation (also known as security
accreditation). The risk-based approach to security control selection and specification considers
effectiveness, efficiency, and constraints due to applicable laws, Directives, Executive Orders,
policies, standards, or regulations.
Section 22
This NNSA NAP implements National Institute of Standards and Technology (NIST) Federal
Information Processing Standards (FIPS) Publication (PUB) 199, Standards for Security
Categorization of Federal Information and Information Systems; FIPS PUB 200, Minimum
Security Requirements for Federal Information and Information Systems; NIST Special
Publication (SP) 800-53, Revision 1, Recommended Security Controls for Federal Information
Systems, and the DOE cyber security program criteria for the implementation of management,
operational, and technical controls for information systems, DOE M 205.1-4.
This NAP defines NNSA requirements and recommended controls for information systems. The
NNSA implementation of these security controls are based on the recommendations of the NIST
SP 800-53, Revision 1 and the CNSS recommendations. The criteria are described by security
control baseline (i.e., low, moderate, and high). Supplemental issue-specific NAPs provide more
detail on some of the requirements and include processes for implementing the controls.
This NAP follows the NIST SP 800-53, Revision 1, structure utilizing the control Classes,
Families, and Identifiers as shown in Table D-1. To uniquely identify each control, a numeric
identifier is appended to the Family identifier to indicate that control within the Family. For
example, PL-1 represents control number 1 within the Planning Family.
”SPECIAL” INFORMATION SYSTEMS. Extensive technical protection measures may be
inappropriate and unnecessarily expensive for some information systems (e.g., single-user
standalone systems, and legacy systems). The DAA will determine which of the management,
operational and technical controls contained in this NAP are to be applied to those systems in the
NNSA Elements.
IV-2 NAP 14.2-C
05-02-08
PROTECTION REQUIREMENTS FOR SENSITIVE UNCLASSIFIED INFORMATION
(SUI). A comprehensive listing of NNSA requirements for the protection of SUI, including
Personally Identifiable Information (PII) is not possible within the context of this chapter. See
Chapter VII for additional requirements for the protection of SUI. Table IV-1 provides a listing
of all cyber classes, families, and identifiers.
Table IV-1. Cyber Security Control Classes, Families and Identifiers
Class Family Identifier
Management Risk Assessment RA
Management Planning PL
Management System and Services Acquisition SA
Management Certification, Accreditation, and Security
Assessment
CA
Operational Personnel Security PS
Operational Physical and Environmental Protection PE
Operational Contingency Planning CP
Operational Configuration Management CM
Operational Maintenance MA
Operational System and Information Integrity SI
Operational Media Protection MP
Operational Incident Response IR
Operational Awareness and Training AT
Technical Identification and Authentication IA
Technical Access Control AC
Technical Audit and Accountability AU
Technical System and Communications Protection SC
The requirements provide a unified and consistent approach to security controls to be addressed
in the NNSA element’s Cyber Security Program Plan (CSPP) and ISSPs.
NAP 14.2-C IV-3
05-02-08
An NNSA Element may specify and implement additional requirements in its CSPP to address
specific risks, vulnerabilities, or threats within its operating unit.
REQUIREMENTS
Managing Organizational Risk
Section 23
Each NNSA Element is to document its approach to managing organizational risk through the
organization’s CSPP. NNSA Element Managers are responsible for developing, documenting in
the CSPP, and implementing policies and processes to develop an acceptable control baseline for
each information system appropriate to the impact level of the system (see Chapter VI, Security
Category). The CSPP will also describe the risk management or mission impact rationale for all
criteria not fully addressed in the implementation policies.
The following activities related to managing organizational risk in the NNSA Element are
paramount to an effective information security program and can be applied through the CSPP to
both new and legacy information systems within the context of the System Development Life
Cycle and the DOE Enterprise Architecture.
• Categorize information systems and the information resident within the system based on an
impact analysis using Table 6 in Chapter III.
• Select an initial set of security controls (i.e., baseline) for the information system as a
starting point for the risk assessment process, based on the FIPS 199 security categorization
and the minimum security requirements defined in this document.
• Document the set of security controls ISSP for the information system including the NNSA
Element’s justification for any refinements or adjustments to the initial set of controls.
• Implement the security controls in the information system. For existing systems, some or all
of the security controls selected may already be in place.
• Assess the security controls using appropriate methods and procedures to determine the
extent to which the controls are implemented correctly, operating as intended, and producing
the desired outcome with respect to meeting the security requirements for the system.
• Authorize information system processing (or for legacy systems, authorize continued system
processing) based upon a determination of the risk to organizational operations,
organizational assets, or to individuals resulting from the operation of the information system
and the decision that this risk is acceptable.
• Monitor and assess selected security controls in the information system on a continuous
basis including documenting changes to the system, conducting security impact analyses of
the associated changes, and reporting the security status of the system to appropriate
organizational officials on a regular basis.
IV-4 NAP 14.2-C
05-02-08
The following conventions are used in this Chapter:
• At the beginning of each Family section, a table is inserted which provides a summary of
the controls required for that Family for each category of information system. Detailed
information for each of the controls follows that table.
• Supplemental guidance is provided for the controls. In some cases, supplemental
guidance is also provided for Control Enhancements. This information is provided for
additional clarification of the intent of the control.
• Following each control’s requirements statements is a table summarizing the controls
required for Low, Moderate, or High information systems. Where there is one table, the
controls apply to both classified and unclassified systems. Where there are two lines to
the table, the controls noted on the shaded line apply to classified systems; the controls
noted on the unshaded line apply to unclassified systems. (See control AC-10 for an
example.)
Section 24
NAP 14.2-C IV-5
05-02-08
FAMILY: ACCESS CONTROL CLASS: TECHNICAL
The cyber security roles defined in the NNSA PCSP are responsible for managing and coordinating
access controls within the operating unit and ensuring implementation and compliance with the
following Access Control policy for each information system in the NNSA Element.
Access Control Policy. Access control measures are designed to limit access to information
system resources to authorized users, programs, processes, or other systems and to manage
authorities and privileges granted to each user of the information system or application. These
measures must include maintenance of 1) the association between a user identifier and an
authenticator; 2) user authorizations and privileges; 3) user access to objects; 4) authority to
grant access to objects and subjects; 5) authority to add, modify, and remove objects and
subjects, 6) temporary and emergency accounts must be terminated within 24 hours, and 7)
automatically disable inactive accounts within 3 months of the last use.
Access Controls
Protection Index
Control
Number Control Name
Low Moderate High
AC-1 Access Control Policy and
Procedures
AC-1 AC-1 AC-1
AC-2 Account Management AC-2
(1)(2)(3)(4)
AC-2
(1)(2)(3)(4)(5)
AC-2
(1)(2)(3)(4)(5)
AC-3 Access Enforcement AC-3 AC-3 (1)(2)(3) AC-3 (1)(2)(3)
AC-4 Information Flow
Enforcement
AC-4 AC-4 (1)(2) AC-4 (1) (2)
AC-5 Separation of Duties AC-5 AC-5 AC-5
AC-6 Least Privilege AC-6 AC-6 (1) AC-6 (1)
AC-7 Unsuccessful Logon
Attempts
AC-7 AC-7 AC-7
AC-8 System Use Notification AC-8 AC-8 AC-8
AC-9 Previous Logon Notification Not required at this time. NNSA Elements may elect,
at their discretion, to ensure that information systems
notify the user, upon successful logon, of the last
logon and the number of unsuccessful logon attempts
since the last successful logon.
IV-6 NAP 14.2-C
05-02-08
Access Controls
Protection Index
Control
Number Control Name
Low Moderate High
AC-10 AC-10 AC-10 Concurrent Session
Control
Not required
Not Required AC-10 (1)
AC-11 Session Lock AC-11 AC-11 AC-11
AC-12 Session Termination AC-12 AC-12 (1) AC-12 (1)
AC-13 Supervision and Review –
Access Control
AC-13 AC-13 (1) AC-13 (1)
AC-14 Permitted Actions without
Identification and
Authentication
AC-14 AC-14 (1) AC-14 (1)
AC-15 AC-15 AC-15 AC-15 Automated Marking
Not Required AC-15 AC-15
AC-16 Automated Labeling Not required at this time. NNSA Elements may elect,
at their discretion, to ensure that information in
storage, in process, or in transmission is appropriately
labeled by an information system.
AC-17 Remote Access AC-
17(1)
AC-17
(1)(2)(3)(4)(5)(6)
AC-17
(1)(2)(3)(4)(5)(6)(7)
AC-18 Wireless Access
Restrictions
AC-18 AC-18 (1)(2)(3)(4) AC-18
(1)(2)(3)(4)
AC-19 Access Control for Portable
and Mobile Devices
AC-19 AC-19 (1) AC-19 (1)
AC-20 Personally Owned
Information Systems
AC-20 AC-20 (1) AC-20 (1)
AC-21 Confidentiality of Data at
Rest
AC-21 AC-21 AC-21
AC-22 Distinct Levels of Access AC-22 AC-22 AC-22
NAP 14.2-C IV-7
05-02-08
AC-1 ACCESS CONTROL POLICY AND PROCEDURES
Control: NNSA Elements must develop, disseminate, and periodically review/update:
a. A formal, documented, access control policy that addresses purpose, scope, roles,
responsibilities, management commitment, coordination among organizational entities,
and compliance; and
Section 25
b. Formal, documented procedures to facilitate the implementation of the access control
policy and associated access controls.
Supplemental Guidance: The access control policy and procedures are consistent with
applicable laws, Executive Orders, directives, policies, regulations, standards, and
guidance. The access control policy can be included as part of the general information
security policy for the organization. Access control procedures can be developed for the
security program in general, and for a particular information system, when required.
Control Enhancements: None.
LOW
AC-1 MOD
AC-1 HIGH
AC-1
AC-2 ACCOUNT MANAGEMENT
Control: Manage information system accounts, including establishing, activating, modifying,
reviewing, disabling, and removing accounts. The NNSA Element will:
a. Review information system accounts at least annually.
b. Identify authorized users of the information system and specify access rights/privileges.
c. Require proper identification for requests to establish information system accounts and
approves all such requests.
d. Authorize and monitor the use of guest/anonymous accounts and remove, disable, or
otherwise secures unnecessary account.
e. Notify account managers when information system users are terminated or transferred
and associated accounts are removed, disabled, or otherwise secured.
f. Notify account managers when users’ information system usage or need-to-know/need--
to-share changes.
Supplemental Guidance: Account management includes the identification of account
types (i.e., individual, group, and system), establishment of conditions for group
membership, and assignment of associated authorizations. The organization should
IV-8 NAP 14.2-C
05-02-08
consider the following aspects when granting access to the information and information
systems: (i) A valid need-to-know/ need-to share that is determined by assigned official
duties and satisfying all personnel security criteria; and (ii) Intended system usage.
Control Enhancements:
(1) The organization employs automated mechanisms to support the management of
information system accounts.
(2) The information system automatically terminates temporary and emergency accounts
after 24 hours.
(3) The information system automatically disables inactive accounts no later than 3 months
after the last use.
(4) The organization employs automated mechanisms to audit account creation,
modification, disabling, and termination actions and to notify, as required, appropriate
individuals.
(5) The organization establishes and administers all privileged user accounts in accordance
with a role-based access scheme that organizes all system and network privileges into
roles (e.g., key management, network, system administration, database administration,
Web administration).
LOW
AC-2(1)(2)(3)(4) MOD
AC-2(1)(2)(3)(4)(5) HIGH
AC-2(1)(2)(3)(4)(5)
AC-3 ACCESS ENFORCEMENT
Control: Enforce assigned authorizations for controlling access to the system in accordance
with applicable policy.
Section 26
Supplemental Guidance: Access control policies (e.g., identity-based policies, role-based
policies, rule-based policies) and associated access enforcement mechanisms (e.g., access control
lists, access control matrices, cryptography) are employed by organizations to control access
between users (or processes acting on behalf of users) and objects (e.g., devices, files, records,
processes, programs, domains) in the information system. In addition to controlling access at the
information system level, access enforcement mechanisms are employed at the application level,
when necessary, to provide increased information security for the organization. Consideration is
given to the implementation of a controlled, audited, and manual override of automated
mechanisms in the event of emergencies or other serious events. If encryption of stored
information is employed as an access enforcement mechanism, the cryptography used is FIPS
140-2 (as amended) compliant or NSA Type-1 Related security Control: SC13.
Control Enhancements:
NAP 14.2-C IV-9
05-02-08
(1) The information system restricts access to privileged functions (deployed in hardware,
software, and firmware) and security-relevant information to explicitly authorized
personnel.
Enhancement Supplemental Guidance: Explicitly authorized personnel include, for
example, security administrators, system and network administrators, and other
privileged users. Privileged users are individuals who have access to system control,
monitoring, or administration functions (e.g., system administrators, information system
security officers, maintainers, system programmers).
(2) The Mandatory Access Control (MAC), and/or Discretionary Access Control (DAC),
and/or Role Based Access Control (RBAC) policies of the information system are
implemented and configured to ensure only authorized users are able to perform security
functions.
(3) The MAC, DAC, and/or RBAC policies of the information system and/or Operating
System (OS) are implemented and configured to protect security relevant objects from
unauthorized access, modification, and deletion. In the case of applications which
enforce the security policy but are outside the protections of a trusted OS, the application
must maintain the ability to protect itself.
LOW AC-3 MOD AC-3 (1)(2)(3) HIGH AC-3 (1)(2)(3)
AC-4 INFORMATION FLOW ENFORCEMENT
Control: Enforce assigned authorizations for controlling the flow of information within the
system and between interconnected systems, as well as between shared components that
transmit data at different levels, such as RD and NSI, in accordance with applicable policy.
Supplemental Guidance: Information flow control regulates where information is allowed to
travel within an information system and between information systems (as opposed to who is
allowed to access the information) and without explicit regard to subsequent accesses to that
information. Related security Control: SC7.
Control Enhancements:
(1) The information system implements information flow control enforcement using protected
processing domains (e.g., domain type enforcement) as a basis for flow control decisions.
(2) The information system implements information flow control enforcement using dynamic
security policy mechanisms as a basis for flow control decisions. For further information on
these policy mechanisms, refer to the Supplemental Guidance paragraphs for the control.
Section 27
IV-10 NAP 14.2-C
05-02-08
LOW
AC-4 MOD
AC-4 (1)(2) HIGH
AC-4 (1)(2)
AC-5 SEPARATION OF DUTIES
Control: Enforce separation of duties through assigned access privileges. The NNSA Element
separates duties as needed to eliminate conflicts of interest in the responsibilities and duties of
individuals. Access control software resides on the information system that prevents users from
having all of the necessary authority or information access to perform fraudulent activity without
collusion.
Supplemental Guidance: Examples of separation of duties include: (i) mission functions and
distinct information system support functions are divided among different individuals/roles; (ii)
different individuals perform information system support functions (e.g., system management,
systems programming, quality assurance/testing, configuration management, and network
security); and (iii) security personnel who administer access control functions do not administer
audit functions. Through the use of access control software or site processes and procedures, users
are prevented from having all of the necessary authority or information access to perform
fraudulent activity without collusion.
Control Enhancements: None.
LOW AC-5 MOD AC-5 HIGH AC-5
AC-6 LEAST PRIVILEGE
Control: The information system enforces the most restrictive set of rights/privileges or accesses
needed by users (or processes acting on behalf of users) for the performance of specified tasks.
Supplemental Guidance: The organization employs the concept of least privilege for specific
duties and information systems (including specific ports, protocols, and services) in accordance
with risk assessments as necessary to adequately mitigate risk to organizational operations,
organizational assets, and individuals.
Control Enhancement:
(1) The organization ensures that privileged accounts are created for users to perform
privileged functions only; that is, privileged users use non-privileged accounts for all
non--privileged functions.
Enhancement Supplemental Guidance: For example, SUDO for UNIX and Run
As for a Windows system.
NAP 14.2-C IV-11
05-02-08
LOW AC-6 (1) MOD AC-6 (1) HIGH AC-6 (1)
AC-7 UNSUCCESSFUL LOGIN ATTEMPTS
Control: Document in ISSPs and enforce a limit of no more than three consecutive invalid
access attempts by a user during a two-hour time period. The information system must
automatically lock the account/node for 15 minutes (or until authorized to be unlocked), or
delays the next login prompt when the maximum number of unsuccessful attempts is exceeded.
This control also applies to remote access logon attempts.
Supplemental Guidance: Due to the potential for denial of service, automatic lockouts initiated by
the information system are usually temporary and automatically release after a predetermined time
period.
Control Enhancements: None
LOW AC-7 MOD AC-7 HIGH AC-7
AC-8 SYSTEM USE NOTIFICATION
Control: Display an approved system-use notification message before granting system access
informing potential users that:
a. The user is accessing a U.S. Government information system;
b. System usage may be monitored, recorded, and subject to audit;
c. Unauthorized use of the system is prohibited and subject to criminal and civil penalties;
and
d. Use of the system indicates consent to monitoring and recording.
Section 28
The system use notification message provides appropriate privacy and security notices (based on
associated privacy and security policies or summaries) and remains on the screen until the user
takes explicit actions to log on to the information system.
Supplemental Guidance: The following notice must be displayed:
**WARNING**WARNING**WARNING**WARNING**WARNING**
This is a Department of Energy (DOE) computer system. DOE computer systems are provided
for the processing of official U.S. Government information only. All data contained within
DOE computer systems is owned by the DOE, and may be audited, intercepted, recorded, read,
copied, or captured in any manner and disclosed in any manner, by authorized personnel.
THERE IS NO RIGHT OF PRIVACY IN THIS SYSTEM. System personnel may disclose
any potential evidence of crime found on DOE computer systems to appropriate authorities.
IV-12 NAP 14.2-C
05-02-08
USE OF THIS SYSTEM BY ANY USER, AUTHORIZED OR UNAUTHORIZED,
CONSTITUTES CONSENT TO THIS AUDITING, INTERCEPTION, RECORDING,
READING, COPYING, CAPTURING, and DISCLOSURE OF COMPUTER ACTIVITY.
**WARNING**WARNING**WARNING**WARNING**WARNING**
Control Enhancements: None.
LOW
AC-8 MOD
AC-8 HIGH
AC-8
AC-9 PREVIOUS LOGON NOTIFICATION
Control: If technically feasible, the information system notifies the user, upon successful logon,
of the date and time of the last logon.
Supplemental Guidance: None
Control Enhancement:
(1) If technically feasible, the information system notifies the user, upon successful logon, of
the number of unsuccessful logon attempts since the last successful logon.
LOW Not required MOD Not required HIGH Not required
AC-10 CONCURRENT SESSION CONTROL
Control: Limit the number of concurrent sessions for any user to one session.
Supplemental Guidance: Concurrent sessions are when a user accesses an information system once
and invokes multiple sessions. Concurrent logons are when a user accesses an information system
more than once from a logon/login perspective.
Control Enhancements:
(1) DAAs may make local determinations on the types of accounts (i.e., privileged) to which this
applies.
LOW Not required MOD AC-10 HIGH AC-10
LOW
Not required MOD
Not required HIGH
AC-10(1)
AC-11 SESSION LOCK
NAP 14.2-C IV-13
05-02-08
Control: Prevent further access to the system by initiating a session lock after 10 minutes of
inactivity, and the session lock remains in effect until the user reestablishes access using
appropriate identification and authentication procedures.
Supplemental Guidance: Users can directly initiate session lock mechanisms. A session lock is
not a substitute for logging out of the information system.
Control Enhancements: None
LOW AC-11 MOD AC-11 HIGH AC-11
AC-12 SESSION TERMINATION
Control: Automatically terminate a remote session after a period of inactivity specified in the
system’s ISSP.
Supplemental Guidance: A remote session is initiated whenever an organizational information
system is accessed by a user (or an information system) communicating through an external, non-
organization-controlled network (e.g., the Internet).
Control Enhancements:
(1) Automatic session termination applies to remote sessions.
LOW AC-12 MOD AC-12(1) HIGH AC-12(1)
AC-13 SUPERVISION AND REVIEW — ACCESS CONTROL
Control: Supervise and review the activities of users with respect to the enforcement and usage
of information system access controls.
Section 29
Supplemental Guidance: The organization reviews audit records (e.g., user activity logs) for
inappropriate activities in accordance with organizational policies. The organization investigates
any unusual information system-related activities and periodically reviews changes to access
authorizations. The organization reviews more frequently the activities of users with significant
information system roles and responsibilities. The extent of the audit record reviews is based on
the Trust Levels of the information system. For example, for low-impact systems, it is not
intended that security logs be reviewed frequently for every workstation, but rather at central
points such as a Web proxy or e-mail servers and when specific circumstances warrant review of
other audit records.
Control Enhancement:
IV-14 NAP 14.2-C
05-02-08
(1) The organization employs automated mechanisms to facilitate the review of user
activities.
LOW AC-13 MOD AC-13(1) HIGH AC-13(1)
AC-14 PERMITTED ACTIONS WITHOUT IDENTIFICATION OR AUTHENTICATION
Control: Identify and document specific user actions that can be performed on the information
system without identification or authentication.
Supplemental Guidance: The organization allows limited user activity without identification
and authentication for public Web sites or other publicly available information systems (e.g.,
individuals accessing a Federal information system at http://www.firstgov.gov). Related
security Control: IA2.
Control Enhancement:
(1) The organization permits actions to be performed without identification and authentication
only to the extent necessary to accomplish mission objectives (e.g., a weapons system).
LOW
AC-14 MOD
AC-14 (1) HIGH
AC-14 (1)
AC-15 MARKING
Control: Mark output using standard naming conventions to identify any special dissemination,
handling, or distribution instructions.
Supplemental Guidance: The user or the system marks all output from the system (classified
data and data requiring special handling) to reflect the classification and sensitivity of the data
(e.g., classification level, classification category, and handling caveats). Markings shall be
retained with the data. Markings will be in accordance with DOE M 470.4-4.
Control Enhancements: None
LOW AC-15 MOD AC-15 HIGH AC-15
LOW Not required MOD AC-15 HIGH AC-15
AC-16 AUTOMATED LABELING
Control: The information system appropriately labels information in storage, in process, and in
transmission. Information labeling is accomplished in accordance with:
NAP 14.2-C IV-15
05-02-08
a. Access control requirements;
b. Special dissemination, handling, or distribution instructions; or
c. As otherwise required to enforce information system security policy.
Supplemental Guidance: Automated labeling refers to labels employed on internal data
structures (e.g., records, files) within the information system.
Control Enhancements:
(1) Data released by a producer shall either be explicitly or implicitly labeled. If the data is
of a different classification or sensitivity than the source (e.g., session window) from
which it was extracted, then the producer shall take some explicit action to associate the
correct label with the data.
(2) Implicit labels are generally based on the classification and sensitivity level of the
communications session over which the data is sent, and are employed when the value of
explicit labels associated with the data cannot be trusted.
Section 30
LOW Not required MOD Not required HIGH Not required
AC-17 REMOTE ACCESS
Control: Document, monitor, and control all methods of remote access (e.g., dial-up, Internet)
to the information system including remote access for privileged functions. Appropriate
organization officials authorize each remote access method for the information system and
authorize only the necessary users for each access method.
Supplemental Guidance: Remote access is any access to an organizational information system by a
user (or an information system) communicating through an external, non-organization-controlled
network (e.g., the Internet). Examples of remote access methods include dial-up, broadband, and
wireless. Remote access controls are applicable to information systems other than public Web
servers or systems specifically designed for public access. The organization restricts access
achieved through dial-up connections (e.g., limiting dial-up access based upon source or request) or
protects against unauthorized connections or subversion of authorized connections (e.g., using
virtual private network technology).
Control Enhancements:
(1) The organization employs automated mechanisms to facilitate the monitoring and control of
remote access methods. Policies and procedures of the user control group must be followed.
(2) The organization uses cryptography to protect the confidentiality and integrity of remote
access sessions.
IV-16 NAP 14.2-C
05-02-08
(3) The organization controls all remote accesses through a limited number of managed access
control points.
(4) The organization permits remote access for privileged functions only for compelling
operational needs and documents the rationale for such access in the security plan for the
information system.
(5) The information system restricts all remote access sessions by privileged users to those with
strong authentication. Related to IA2.
Enhancement Supplemental Guidance: Strong authentication is defined as the
information system employs a multifactor authentication process and/or device to
generate a onetime password that is highly resistant to replay attacks.
(6) The organization ensures that users protect information about the remote access mechanisms
from unauthorized use and disclosure.
(7) The organization ensures that remote sessions for privileged user functions employ
additional security measures and that each remote session is comprehensively audited.
Enhancement Supplemental Guidance: Additional security measures are typically above
and beyond standard bulk or session layer encryption (e.g., Secure Shell (SSH), or
Virtual Private Networking with blocking mode enabled.
LOW AC-17 (1) MOD AC-17
(1)(2)(3)(4)(5)(6)
HIGH AC-17
(1)(2)(3)(4)(5)(6)(7)
AC-18 WIRELESS ACCESS RESTRICTIONS
Control: Establish usage restrictions and implementation guidance for wireless technologies and
document, monitor, and control wireless access to the information system.
Supplemental Guidance: None
Control Enhancements:
(1) The organization uses authentication and encryption to protect wireless access to the
information system.
Enhancement Supplemental Guidance: The appropriate level of encryption strength will
be selected based on the classification and/or sensitivity of the data.
(2) The organization scans for unauthorized wireless access points quarterly and takes
appropriate action if such an access point is discovered.
Section 31
NAP 14.2-C IV-17
05-02-08
(3) The organization ensures that wireless computing and networking capabilities within all
IT resources are implemented in accordance with organizational wireless policies and
technical guidelines.
(4) Wireless computing capabilities are not independently configured by end users, except
through the use of approved scripts. Unused wireless computing and networking
capabilities internally embedded in interconnected IT assets are normally disabled by
changing factory defaults, settings or configurations prior to issue to end users.
LOW AC-18 MOD AC-18 (1)(2)(3)(4) HIGH AC-18 (1)(2)(3)(4)
AC-19 ACCESS CONTROL FOR PORTABLE AND MOBILE DEVICES
Control: Establish usage restrictions and implementation guidance for portable and mobile
devices and document, monitor, and control device access to organizational information systems.
Supplemental Guidance: Portable and mobile devices (e.g., notebook computers, personal
digital assistants, cellular telephones, and other computing and communications devices with
network connectivity and the capability of periodically operating in different physical locations)
are only allowed access to organizational information systems in accordance with
organizational security policies and procedures. Security policies and procedures include
device identification and authentication, implementation of mandatory protective software (e.g.,
malicious code detection, firewall), configuration management, scanning devices for malicious
code, updating virus protection software, scanning for critical software updates and patches,
conducting primary operating system (and possibly other resident software) integrity checks,
and disabling unnecessary hardware (e.g., wireless, infrared). Related security controls: MP4
and MP5.
Control Enhancement:
(1) Employ removable hard drives or cryptography to protect information on portable and
mobile devices.
LOW AC-19 MOD AC-19(1) HIGH AC-19(1)
AC-20 USE OF EXTERNAL INFORMATION SYSTEMS
Control: Restrict the use of external information systems or components for official U.S.
Government business involving the processing, storage, or transmission of Federal information.
Supplemental Guidance: External information systems are information systems or components of
information systems that are outside of the accreditation boundary established by the
organization and for which the organization typically has no direct control over the application
of required security controls or the assessment of security control effectiveness. External
information systems include, but are not limited to, personally owned information systems (e.g.,
IV-18 NAP 14.2-C
05-02-08
computers, cellular telephones, or personal digital assistants); privately owned computing and
communications devices resident in commercial or public facilities (e.g., hotels, convention
centers, or airports); information systems owned or controlled by non-Federal Governmental
organizations; and Federal information systems that are not owned by, operated by, or under the
direct control of the organization.
Section 32
Authorized individuals include organizational personnel, contractors, or any other individuals
with authorized access to the organizational information system. This control does not apply to
the use of external information systems to access organizational information systems and
information that are intended for public access (e.g., individuals accessing Federal information
through public interfaces to organizational information systems). The organization establishes
terms and conditions for the use of external information systems in accordance with
organizational security policies and procedures. The terms and conditions address as a
minimum; (i) the types of applications that can be accessed on the organizational information
system from the external information system; and (ii) the maximum trust level and security
impact category of information that can be processed, stored, and transmitted on the external
information system.
Control Enhancement:
(1) Prohibit authorized individuals from using an external information system to access the
Element’s information system or to process, store, or transmit organization controlled
information except in situations where the organization:
(a) Can verify the employment of required security controls on the external system as
specified in the organization’s information security policy and system security plan;
or
(b) Has approved information system connection or processing agreements with the
organizational entity hosting the external information system; or
(c) The Element’s system being accessed has protections in place to mitigate
deficiencies on the connecting system.
LOW AC-20 MOD AC-20 (1) HIGH AC-20 (1)
AC-21 CONFIDENTIALITY OF DATA AT REST
Control: Encrypt data at rest if required by the information owner or Departmental policy.
Supplemental Guidance: None
Control Enhancements: None
NAP 14.2-C IV-19
05-02-08
LOW AC-21 MOD AC-21 HIGH AC-21
AC-22 DISTINCT LEVELS OF ACCESS
Control: Provide at least three distinct levels of access, regardless of user interface, to all internal
classified, sensitive, and unclassified information.
a. Open access to general information that is accessible to all authorized users with network
access. Access does not require an audit transaction.
b. Controlled access to information that is accessible to all authorized users upon the
presentation of an individual authenticator. Access is recorded in an audit transaction.
c. Restricted access to need-to-know information that is accessible only to an authorized
community. Authorized users must present an individual authenticator and have either a
demonstrated or validated need-to-know. All access to need-to-know information and all
failed access attempts are recorded in audit transactions.
Supplemental Guidance: None
Control Enhancements: None.
LOW AC-22 MOD AC-22 HIGH AC-22
FAMILY: AWARENESS AND TRAINING CLASS: OPERATIONAL
Cyber security awareness consists of reminders that focus the user’s attention on the concept of
cyber security in the user’s daily routine. Awareness provides a general cognizance or
mindfulness of one’s actions, and the consequences of those actions. Cyber security training
develops skills and knowledge so computer users can perform their jobs more securely and build
in-depth knowledge, producing relevant and necessary security skills and competencies in those
who access or manage NNSA information and resources.
Section 33
Training Policy. Once granted legitimate access, authenticated users are expected to use
information system resources and information only in accordance with the organizational
security policy. In order for this to be possible, these users must be adequately trained both to
understand the purpose and need for security controls and to be able to make secure decisions
with respect to their discretionary actions. Authenticated users of the system must be adequately
trained, enabling them to (1) effectively implement organizational security policies with respect
to their discretionary actions and (2) support the need for non-discretionary controls
implemented to enforce these policies prior to being granted access to information.
IV-20 NAP 14.2-C
05-02-08
Awareness and Training
Control Baselines Control
Number Control Name
Low Moderate High
AT-1 Security Awareness and Training Policy
and Procedures
AT-1 AT-1 AT-1
AT-2 Security Awareness AT-2 AT-2 AT-2
AT-3 Security Training AT-3 AT-3 AT-3
AT-4 Security Training Records AT-4 AT-4 AT-4
AT-5 Contact with Security Groups and
Associations
Not required at this time.
AT-1 SECURITY AWARENESS AND TRAINING POLICY AND PROCEDURES
Control: Develop, document, disseminate, and periodically review and/or update:
a. A formal, documented, security awareness and training policy that addresses purpose, scope,
roles, responsibilities, management commitment, coordination among organizational entities,
and compliance; and
b. Formal, documented procedures to facilitate the implementation of the security awareness
and training policy and associated security awareness and training controls.
Supplemental Guidance: The security awareness and training policy and procedures are
consistent with applicable laws, Executive Orders, directives, policies, regulations,
standards, and guidance. The security awareness and training policy can be included as
part of the general information security policy for the organization. Security awareness
and training procedures can be developed for the security program in general, and for a
particular information system, when required.
Control Enhancements: None.
LOW
AT-1 MOD
AT-1 HIGH
AT-1
AT-2 SECURITY AWARENESS
Control: Provide security awareness training within 30 days to all information system users
(including managers and senior executives) before authorizing access to the system, when
required by system changes, and at least annually thereafter. This instruction must present a core
NAP 14.2-C IV-21
05-02-08
set of generic cyber security terms and concepts for all personnel (Federal employees and
contractors) as a baseline for role=based learning, expands on those basic concepts, and provides
a mechanism for students to relate and apply the information learned on the job.
Supplemental Guidance: The organization determines the appropriate content of security awareness
training based on the specific requirements of the organization and the information systems to which
personnel have authorized access.
Control Enhancements: None.
LOW
AT-2 MOD
AT-2 HIGH
AT-2
AT-3 SECURITY TRAINING
Control: Identify personnel with significant information cyber security roles and responsibilities,
document those roles and responsibilities, and provides appropriate cyber security training
before authorizing access to the system. Establish and, at least bi-annually (every two years),
execute training plans for these personnel covering the training topics described in NIST SP 800-
16, Information Technology Security Training Requirements: A Role- and Performance-Based
Model.
Section 34
Supplemental Guidance: The organization determines the appropriate content of security training
based on the specific requirements of the organization and the information systems to which
personnel have authorized access. In addition, the organization provides system managers, system
and network administrators, and other personnel having access to system-level software, adequate
technical training to perform their assigned duties.
Control Enhancements: None.
LOW AT-3 MOD AT-3 HIGH AT-3
AT-4 SECURITY TRAINING RECORDS
Control: Document and monitor individual information system security training activities
including basic security awareness training and specific information system security training.
Supplemental Guidance: None
Control Enhancements: None.
LOW
AT-4 MOD
AT-4 HIGH
AT-4
IV-22 NAP 14.2-C
05-02-08
AT-5 CONTACTS WITH SECURITY GROUPS AND ASSOCIATIONS
Control: Establish and maintain contacts with special interest groups, specialized forums,
professional associations, news groups, and/or peer groups of security professionals in
similar organizations to stay up to date with the latest recommended security practices,
techniques, and technologies and to share the latest security related information including
threats, vulnerabilities, and incidents.
Supplemental Guidance: To facilitate ongoing security education and training for organizational
personnel in an environment of rapid technology changes and dynamic threats, the organization
establishes and institutionalizes contacts with selected groups and associations within the
security community. The groups and associations selected are in keeping with the organization’s
mission requirements. Information sharing activities regarding threats, vulnerabilities, and
incidents related to information systems are consistent with applicable laws, Executive Orders,
directives, policies, regulations, standards, and guidance.
Control Enhancements: None.
LOW Not required MOD Not required HIGH Not required
FAMILY: AUDIT AND ACCOUNTABILITY CLASS: TECHNICAL
Audit trails maintain a record of system activity by system or application processes and by user
activity. In conjunction with appropriate tools and procedures, audit trails can support individual
accountability, a means to reconstruct events, detect intrusions, and identify problems. System audit
trails, or event logs, provide a record of events in support of activities to monitor and enforce the
information system security policy.
Audit and Accountability
Control Baselines Control
Number Control Name
Low Moderate High
AU-1 Audit and Accountability AU-1 AU-1 AU-1
NAP 14.2-C IV-23
05-02-08
Audit and Accountability
Control Baselines Control
Number Control Name
Low Moderate High
Policy and Procedures
AU-2 Auditable Events AU-2 AU-2 AU-2 (1)(2)
AU-3 Content of Audit Records AU-3 AU-3 (1) AU-3 (1) (2)
AU-4 Audit Storage Capacity AU-4 AU-4 AU-4
AU-5 Response to Audit
Processing Failures
AU-5 AU-5(1) AU-5 (1)(2)
AU-6 Audit Monitoring, Analysis,
and Reporting
AU-6 AU-6 (1) AU-6 (1)(2)(3)
AU-7 Audit Reduction and Report
Generation
AU-7 AU-7 (1) AU-7 (1)
AU-8 Time Stamps AU-8 AU-8 AU-8 (1)
AU-9 Protection of Audit
Information
AU-9 AU-9 (1) AU-9 (1)
AU-10 Non-repudiation AU-10 AU-10 AU-10
AU-11 Audit Retention AU-11 AU-11(1) AU-11(1)
AU-12 Session Audit Not required. (See information at AU-12.)
Section 35
AU-1 AUDIT AND ACCOUNTABILITY POLICY AND PROCEDURES
Control: Document, disseminate, and periodically review and/or update:
a. A formal, documented, audit and accountability policy that addresses purpose, scope,
roles, responsibilities, management commitment, coordination among organizational
entities, and compliance; and
b. Formal documented procedures to facilitate the implementation of the audit and
accountability policy and associated audit and accountability controls.
Supplemental Guidance: The audit and accountability policy can be included as part of
the general information security policy for the organization. Audit and accountability
procedures can be developed for the security program in general, and for a particular
information system, when required.
IV-24 NAP 14.2-C
05-02-08
Control Enhancements: None
LOW AU-1 MOD AU-1 HIGH AU-1
AU-2 AUDITABLE EVENTS
Control:
As a minimum, the following auditable events must be captured:
o Start-up and shutdown of the audit functions;
o Successful use of the user security attribute administration functions
o All attempted uses of the user security attribute administration functions
o Identification of which user security attributes have been modified
o Successful and unsuccessful logons and logoffs
o Unsuccessful access to security relevant files including creating, opening, closing,
modifying, and deleting those files
o Changes in user authenticators
o Blocking or blacklisting user IDs, terminals, or access ports
o Denial of access for excessive logon attempts
o System access by privileged users (privileged activities at the system (either physical or
logical consoles) and other system-level access by privileged users). Users will not have
administrative privileges to local systems, unless the systems are standalone.
o Starting and ending times for each access to the system.
Supplemental Guidance: The purpose of this control is to identify important events which
need to be audited as significant and relevant to the security of the information system.
Audit records can be generated at various levels of abstraction, including at the packet
level as information traverse the network. Selecting the right level of abstraction for
audit record generation is a critical aspect of an audit capability and can facilitate the
identification of root causes to problems. Additionally, the security audit function is
coordinated with the network health and status monitoring function to enhance the
mutual support between the two functions.
Control Enhancements:
NAP 14.2-C IV-25
05-02-08
(1) The information system provides the capability to compile audit records from multiple
components throughout the system into a system wide (logical or physical), time correlated
audit trail.
(2) The information system provides the capability to manage the selection of events to be
audited by individual components of the system.
(3) The organization periodically reviews and updates the list of organization-defined auditable
events.
LOW AU-2 MOD AU-2 HIGH AU-2 (1) (2)
AU-3 CONTENT OF AUDIT RECORDS
Control: Capture sufficient information in audit records to establish date and time of the event,
what events occurred, the sources of the events, and the outcomes of the events.
Section 36
Supplemental Guidance: Examples of audit record content includes: (i) date and time of the
event; (ii) the component of the information system (e.g., software component, hardware
component) where the event occurred; (iii) type of event; (iv) user and/or subject identity; and
(v) the outcome (success or failure) of the event. Auditable events are defined under AU2.
Control Enhancements:
(1) The information system provides the capability to include additional, more detailed
information in the audit records for audit events identified by type, location, or subject.
(2) The information system provides the capability to centrally manage the content of audit
records generated by individual components throughout the system.
LOW AU-3 MOD AU-3 (1) HIGH AU-3 (1) (2)
AU-4 AUDIT STORAGE CAPACITY
Control: Allocate sufficient audit record storage capacity and configure auditing to prevent such
capacity being exceeded. Records that exceed the storage capacilty can be backed up to a
different file.
Supplemental Guidance: The organization provides sufficient audit storage capacity, taking into
account the auditing to be performed and the online audit processing requirements. Related
security controls: AU2, AU5, AU6, AU7 and SI4.
Control Enhancements: None.
IV-26 NAP 14.2-C
05-02-08
LOW
AU-4 MOD
AU-4 HIGH
AU-4
AU-5 RESPONSE TO AUDIT PROCESSING FAILURES
Control: In the event of an audit failure or 80% of audit storage capacity being reach, alert
appropriate organization officials and take the additional actions specified by the system’s
ISSP; e.g., shut down the system, overwrite oldest audit records, stop generating audit records.
Supplemental Guidance: Audit processing failures include, for example, software and/or
hardware errors, failures in the audit capturing mechanisms, and audit storage capacity being
reached or exceeded. Related security Control: AU4.
Control Enhancements:
(1) The information system provides a warning when allocated audit record storage volume reaches
[Assignment: the percentage of maximum audit record storage capacity, as specified in the
information system SSP].
(2) The information system provides a real-time alert when the audit failure events occur:
[Assignment: audit failure events requiring real-time alerts, as specified in the information
system SSP].
LOW AU-5 MOD AU-5(1) HIGH AU-5 (1) (2)
AU-6 AUDIT MONITORING, ANALYSIS, AND REPORTING
Control: Regularly review and/or analyze information system audit records for indications
of inappropriate or unusual activity, investigate suspicious activity or suspected violations,
report findings to appropriate officials, and take necessary actions.
Supplemental Guidance: Organizations increase the level of audit monitoring and analysis
activity within the information system whenever there is an indication of increased risk to
organizational operations, organizational assets, or individuals based on law enforcement
information, intelligence information, or other credible sources of information.
Control Enhancements:
(1) The organization reviews the audit records at least on a weekly basis and reports findings to
appropriate officials, and takes necessary actions.
NAP 14.2-C IV-27
05-02-08
(2) The organization employs automated mechanisms to immediately alert security personnel of
inappropriate or unusual activities with security implications.
Section 37
(3) The organization employs automated mechanisms to integrate audit monitoring, analysis,
and reporting into an overall process for investigation and response to suspicious
activities.
(4) The information system provides the ability for an administrator to set alert thresholds for all
auditable events.
Enhancement Supplemental Guidance: Alert thresholds should be measured in terms of a
utilization level maintained for a defined time period. Short spikes in the system health
metrics should not normally be cause for alarm, rather abnormal levels over time should
be cause for alarm.
(5) The information system enforces configurable thresholds to determine whether or not all
network traffic can be handled and controlled. If a threshold has been met, the system shall
process existing traffic until the threshold has been reduced before accepting new traffic for
processing.
LOW AU-6 MOD AU-6 (1) HIGH AU-6 (1) (2) (3) (4) (5)
AU-7 AUDIT REDUCTION AND REPORT GENERATION
Control: Provide an audit reduction and report generation capability for each information system.
Note that it may not be possible to perform reduction of audit logs on all machines, especially on
embedded systems.
Supplemental Guidance: Audit reduction, review, and reporting tools support after the fact
investigations of security incidents without altering original audit records.
Control Enhancements:
(1) The information system provides the capability to automatically process audit records for
events of interest based upon selectable, event criteria.
LOW AU-7 MOD AU-7 (1) HIGH AU-7 (1)
AU-8 TIME STAMPS
Control: Provide time stamps for use in audit record generation.
IV-28 NAP 14.2-C
05-02-08
Supplemental Guidance: Time stamps (including date and time) of audit records are generated
using internal system clocks.
Control Enhancements:
(1) The organization synchronizes internal information system clocks quarterly.
LOW AU-8 MOD AU-8 HIGH AU-8 (1)
AU-9 PROTECTION OF AUDIT INFORMATION
Control: Protect system audit information and audit tools from unauthorized access,
modification, and deletion.
Supplemental Guidance: Audit information includes all information (e.g., audit records, audit
settings, and audit reports) needed to successfully audit information system activity.
Control Enhancement:
(1) The information system will back up the audit records not less than weekly onto a
different system or media than the system being audited.
LOW AU-9 MOD AU-9 (1) HIGH AU-9 (1)
AU-10 NONREPUDIATION
Control: The information system provides the capability to determine whether a given individual
took a particular action.
Supplemental Guidance: Examples of particular actions taken by individuals include creating
information, sending a message, approving information (e.g., indicating concurrence or signing a
contract), and receiving a message. Nonrepudiation protects against later false claims by an
individual of not having taken a specific action. Nonrepudiation protects individuals against
later claims by an author of not having authored a particular document, a sender of not having
transmitted a message, a receiver of not having received a message, or a signatory of not having
signed a document. Nonrepudiation services can be used to determine if information originated
from an individual, or if an individual took specific actions (e.g., sending an e-mail, signing a
contract, approving a procurement request) or received specific information. Non-repudiation
services are obtained by employing various techniques or mechanisms (e.g., digital signatures,
digital message receipts, time stamps).
Section 38
Control Enhancements:
(1) The information system associates the identity of the data producer with the data itself.
NAP 14.2-C IV-29
05-02-08
Enhancement Supplemental Guidance: Supports audit requirements that allow appropriate
authorities the means to identify who produced the data.
(2) The information system validates the binding of the producer's identity to the data.
Enhancement Supplemental Guidance: This mitigates the risk that data is modified between
production and review. A typical approach is validation of a cryptographic checksum.
(3) The information system will maintain reviewer and/or releaser identity and credentials
within the chain of custody, as well as the integrity of data labels and markings for all
information that is reviewed and/or released.
Enhancement Supplemental Guidance: If the reviewer is a human or if the review function
is automated but separate from the release and/or transfer function, then the information
system associates the identity of the reviewer of the data to be released with the data itself
and the data’s label and marking. In the case of a human reviewer, this requirement provides
appropriate authorities the means to identify who reviewed and released the data, and in the
case of automated reviewers, this helps ensure that only the approved review function was
employed.
(4) The information system validates the binding of the reviewer’s identity to the data and label
and marking at the transfer and/or release point prior to release and/or transfer to another
domain.
Enhancement Supplemental Guidance: This mitigates the risk that data is modified
between review and transfer and/or release.
LOW
AU-10 MOD
AU-10 HIGH
AU-10
AU-11 AUDIT RECORD RETENTION
Control: Retain audit records for the time period specified in the system’s ISSP and as
consistent with Departmental and National Archives and Records Administration retention
periods, to provide support for after-the-fact investigations of security incidents and to meet
regulatory and organizational information retention requirements.
Supplemental Guidance: The organization retains audit records until it is determined that they
are no longer needed for administrative, legal, audit, or other operational purposes. This
includes, for example, retention and availability of audit records relative to Freedom of
Information Act (FOIA) requests, subpoena, and law enforcement actions. Standard
categorizations of audit records relative to such types of actions and standard response processes
for each type of action are developed and disseminated. Audit retention time period will be in
accordance with Federal Laws, Statutes, and national policy.
IV-30 NAP 14.2-C
05-02-08
Control Enhancements:
(1) The organization retains audit records for at least 6 months.
LOW AU-11 MOD AU-11 (1) HIGH AU-11 (1)
AU-12 SESSION AUDIT
Control: The information system has the ability to remotely view, listen to, log, and capture all
content related to a specific user in real time.
Supplemental Guidance: There are legal issues related to this ability, and thus it should be
developed, integrated, and used under the guidance of legal counsel.
Control Enhancements:
(1) The information system provides the ability to capture the entire session data associated with
a user in real-time.
(2) The information system has the ability to initiate the audit processes at system startup.
Section 39
LOW Not required MOD Not required HIGH Not required
FAMILY: CERTIFICATION, ACCREDITATION, AND SECURITY ASSESSMENTS CLASS:
MANAGEMENT
C&A is the process of formal assessment, testing (certification), and acceptance (accreditation)
of system security controls that protect information systems and data stored in and processed by
those systems. It is a process that encompasses the system’s life cycle and ensures that the risk
of operating a system is recognized, evaluated, and accepted. The C&A process implements the
concept of “adequate security,” or security commensurate with risk, including the magnitude of
harm resulting from the unauthorized access, use, disclosure, disruption, modification, or
destruction of information.
Certification, Accreditation, and Security Assessment
Control Baselines Control
Number Control Name
Low Moderate High
NAP 14.2-C IV-31
05-02-08
Certification, Accreditation, and Security Assessment
CA-1
Certification, Accreditation, and
Security Assessment Policies and
Procedures
CA-1 CA-1 CA-1
CA-2 Security Assessments CA-2 CA-2 CA-2
CA-3 Information System Connections CA-3 CA-3 CA-3
CA-4 Security Certification CA-4(1) CA-4(1) CA-4 (1)
CA-5 Plan of Action and Milestones CA-5 CA-5 CA-5
CA-6 Security Accreditation CA-6 CA-6 CA-6
CA-7 Continuous Monitoring CA-7 CA-7 (1) CA-7
(1)(2)
CA-1 CERTIFICATION, ACCREDITATION, AND SECURITY ASSESSMENT POLICIES AND
PROCEDURES
Control: Develop, disseminate, and periodically review and/or update:
a. Formal, documented, security assessment and C&A policies that address purpose, scope,
roles, responsibilities, management commitment, coordination among organizational entities,
and compliance; and
b. Formal, documented procedures to facilitate the implementation of the security assessment
and C&A policies and associated assessment, certification, and accreditation controls.
Supplemental Guidance: The security assessment and C&A policies and procedures are
consistent with applicable laws, Executive Orders, directives, policies, regulations,
standards, and guidance. The organization, in concert with the DAA, defines what
constitutes a significant change to the information system to achieve consistent security
reaccreditations.
Control Enhancements: None.
LOW
CA-1 MOD
CA-1 HIGH
CA-1
IV-32 NAP 14.2-C
05-02-08
CA-2 SECURITY ASSESSMENTS
Control: Conduct an assessment of the security controls in the information system at least
annually to determine the extent to which the controls are implemented correctly, operating as
intended, and producing the desired outcome with respect to meeting the security requirements
for the system.
Supplemental Guidance: This control is intended to support the FISMA requirement that the
management, operational, and technical controls in each information system contained in the
inventory of major information systems and applications be assessed with a frequency depending
on risk, but no less than annually. To satisfy the annual FISMA assessment requirement,
organizations can draw upon the security control assessment results from any of the following
sources, including but not limited to: (i) security certifications conducted as part of an
information system accreditation or reaccreditation process (see CA4); (ii) continuous
monitoring activities (see CA7); or (iii) testing and evaluation of the information system as part
of the ongoing system development life cycle process (provided that the testing and evaluation
results are current and relevant to the determination of security control effectiveness).
Section 40
Related security controls: CA4, CA6, CA7 and SA11.
Control Enhancements: None.
LOW
CA-2 MOD
CA-2 HIGH
CA-2
CA-3 INFORMATION SYSTEM INTERCONNECTIONS
Control: Explicitly authorize all interconnections between information systems, as well as
between shared components that transmit data at different levels, such as RD and NSI, from
different certification or accreditation boundaries through the use of system connection
agreements (where applicable) and monitor and/or control the system interconnections on an
ongoing basis.
Supplemental Guidance: Since security categorizations apply to individual information systems,
as well as the enterprise NNSA Elements should carefully consider the risks that may be
introduced when systems are connected to other information systems with different security
requirements and security controls, both within the organization and external to the organization.
Risk considerations also include information systems sharing the same networks. Related
security controls: SC7 and SA9.
Control Enhancements: None.
LOW CA-3 MOD CA-3 HIGH CA-3
NAP 14.2-C IV-33
05-02-08
CA-4 SECURITY CERTIFICATION
Control: Perform an assessment of the security controls in the information system to determine
the extent to which the controls are implemented correctly, operating as intended, and producing
the desired outcome with respect to meeting the security requirements for the system.
Supplemental Guidance: A security certification is conducted by the organization in support of
the requirement for accrediting the information system. The security certification is a key factor
in all security accreditation (i.e., authorization) decisions and is integrated into and spans the
system development life cycle. The organization assesses all security controls in an information
system during the initial security accreditation. Subsequent to the initial accreditation and in
accordance with OMB policy, the organization assesses a subset of the controls annually during
continuous monitoring (see CA7). The organization can use the current year’s assessment
results obtained during security certification to meet the annual FISMA assessment.
Control Enhancement:
(1) Employ a certification agent or certification team to conduct an assessment of the
security controls in the information system.
Enhancement Supplemental Guidance: A certification agent or certification team is any
individual or group capable of conducting an impartial assessment of an organizational
information system.
LOW CA-4 (1) MOD CA-4 (1) HIGH CA-4 (1)
CA-5 PLAN OF ACTION AND MILESTONES
Control: Based on DAA determination, develop a plan of action and milestones (POA&M) for
the information system that documents the organization’s planned, implemented, and evaluated
remedial actions to correct deficiencies and to reduce or eliminate known vulnerabilities in the
system. The POA&M must be updated quarterly.
Supplemental Guidance: If the DAA considers it necessary, the plan of action and milestones
updates are based on the findings from security control assessments, security impact analyses,
and continuous monitoring activities. OMB FISMA reporting guidance contains instructions
regarding organizational plans of action and milestones.
Control Enhancements: None.
LOW
CA-5 MOD
CA-5 HIGH
CA-5
IV-34 NAP 14.2-C
05-02-08
CA-6 SECURITY ACCREDITATION
Section 41
Control: Authorize (i.e., accredit) the information system for processing before operations and
update the authorization at least every three years or when there is a significant change to the
system.
Supplemental Guidance: Security assessments conducted in support of security accreditations
are called security certifications. The security accreditation of an information system is not a
static process. Related security controls: CA2, CA4 and CA7.
Control Enhancements: None.
LOW
CA-6 MOD
CA-6 HIGH
CA-6
CA-7 CONTINUOUS MONITORING
Control: Continuously monitor the effectiveness and adequacy of security controls in the
information system.. As a minimum, those security controls that are volatile or critical to
protecting the information system are assessed at least annually. Testing of critical infrastructure
and key resources must be accomplished annually; bi-annual testing must be accomplished for
all other resources.
Supplemental Guidance: The organization assesses all security controls in an information
system during the initial security accreditation. Subsequent to the initial accreditation and in
accordance with national policy, the organization assesses a subset of the controls annually
during continuous monitoring. The selection of an appropriate subset of security controls is
based on: (i) the security categorization of the information system and risk to the information
system; (ii) the specific security controls selected and employed by the organization to protect
the information system; and (iii) the level of assurance (or grounds for confidence) that the
organization must have in determining the effectiveness of the security controls in the
information system.
The organization can use the current year’s assessment results obtained during continuous
monitoring to meet the annual FISMA assessment requirement (see CA2). This control is
closely related to and mutually supportive of the activities required in monitoring configuration
changes to the information system. A rigorous and well executed continuous monitoring process
significantly reduces the level of effort required for the reaccreditation of the information
system. Related security controls: CA2, CA4, CA5, CA6 and CM4.
Control Enhancements:
(1) The organization employs a certification agent or certification team to monitor the
security controls in the information system on an ongoing basis.
NAP 14.2-C IV-35
05-02-08
(2) The organization will plan, schedule, and conduct performance testing that includes
periodic, unannounced in-depth monitoring and specific penetration testing to ensure
compliance with all vulnerability mitigation procedures.
LOW CA-7 MOD CA-7 (1) HIGH CA-7 (1)(2)
FAMILY: CONFIGURATION MANAGEMENT CLASS: OPERATIONAL
Configuration Management. Measures to ensure the protection features specified in information
system security configurations are implemented in the system and maintained in the instantiation
of system components by applying a level of discipline and control to the process of system
maintenance and modification. A configuration management process must be implemented to
detect any changes in system hardware, software, and firmware components that will modify or
deviate from the approved minimum information system security configuration standard or the
level of risk accepted by the DAA.
Configuration Management
Control Baselines Control
Number Control Name
Section 42
Low Moderate High
CM-1
Configuration Management
Policy and Procedures
CM-1 CM-1 CM-1
CM-2 Baseline Configuration CM-2 CM-2 (1) CM-2 (1) (2)
CM-3 Configuration Change Control CM-3 CM-3 (2)(3) CM-3 (1)(2)(3)
CM-4 Monitoring Configuration
Changes
CM-4 CM-4 CM-4
CM-5 Access Restrictions for Change CM-5 CM-5 (1)(2)(4) CM-5 (1)(2)(3)
CM-6 Configuration Settings CM-6 CM-6 (2) CM-6 (1)(2)
CM-7 Least Functionality CM-7 CM-7 (1)(2) CM-7 (1)(2)
CM-8 Information System
Component Inventory
CM-8 CM-8 (1) CM-8 (1)(2)
IV-36 NAP 14.2-C
05-02-08
CM-1 CONFIGURATION MANAGEMENT POLICY AND PROCEDURES
Control: Develop, disseminate, and periodically review and/or update:
a. A formal, documented, configuration management policy that addresses purpose, scope,
roles, responsibilities, management commitment, coordination among organizational
entities, compliance and the establishment of an entity to enforce the policy (i.e.,
Configuration Control Board); and
b. Formal, documented procedures to facilitate the implementation of the configuration
management policy and associated configuration management controls.
Supplemental Guidance: The configuration management policy and procedures are
consistent with applicable laws, Executive Orders, directives, policies, regulations,
standards, and guidance. The configuration management policy can be included as part
of the general information security policy for the organization. Configuration
management procedures can be developed for the security program in general, and for a
particular information system, when required.
Control Enhancements: None.
LOW
CM-1 MOD
CM-1 HIGH
CM-1
CM-2 BASELINE CONFIGURATION
Control: Develops, document, and maintain a current baseline configuration of the information
system and an inventory of the system’s constituent components.
Supplemental Guidance: This control establishes a baseline configuration for the information
system. The baseline configuration provides information about a particular component’s
makeup (e.g., the standard software load for a workstation or notebook computer including
updated patch information) and the component’s logical placement within the information
system architecture. The baseline configuration also provides the organization with a well
defined and documented specification to which the information system is built and deviations, if
required, are documented in support of mission needs and/or objectives. Related security
controls: CM6, CM8.
Control Enhancements:
(1) The organization updates the baseline configuration of the information system as an integral
part of information system component installations.
(2) The organization employs automated mechanisms to maintain an up-to-date, complete,
accurate, and readily available baseline configuration of the information system.
NAP 14.2-C IV-37
05-02-08
LOW
CM-2 MOD
CM-2 (1) HIGH
CM-2 (1)(2)
CM-3 CONFIGURATION CHANGE CONTROL
Control: Document and control configuration changes to the information system. The
organization includes emergency changes in the configuration change control process, including
changes resulting from the remediation of flaws. The approvals to implement a change to the
information system include successful results from the security analysis of the change. The
organization audits activities associated with configuration changes to the information system.
Section 43
Supplemental Guidance: Configuration change control involves the systematic proposal,
justification, implementation, test and/or evaluation, review, and disposition of changes to the
information system, including upgrades and modifications. Configuration change control
includes changes to the configuration settings for information technology products (e.g.,
operating systems, firewalls, routers). Related security controls: CM4, CM6, and SI2.
Control Enhancements:
(1) The organization employs automated mechanisms to:
(a) Document proposed changes to the information system;
(b) Notify appropriate approval authorities;
(c) Highlight approvals that have not been received in a timely manner;
(d) Inhibit change until necessary approvals are received; and
(e) Document completed changes to the information system.
(2) The organization establishes a CM control board, which includes the Information System
Security Manager (ISSM), or Information System Security Officer (ISSO) as a member(s).
(3) All National Security Systems (NSS) are under the control of a chartered configuration
control board (CCB) that meets regularly. The CCB reviews and approves all proposed
information system changes, to include interconnections to other information systems.
LOW
CM-3 MOD
CM-3 (2)(3) HIGH
CM-3 (1)(2)(3)
CM-4 MONITORING CONFIGURATION CHANGES
Control: Monitor changes to the information system by conducting security impact analyses to
determine the effects of the changes. After the information system is changed (including
IV-38 NAP 14.2-C
05-02-08
upgrades and modifications), the organization checks the security features to verify that the
features are still functioning properly. The organization audits activities associated with
configuration changes to the information system.
Supplemental Guidance: Prior to change implementation, and as part of the change approval
process, the Information System Security Manager (ISSM), or Information System Security
Officer (ISSO) analyzes changes to the information system for potential security impacts.
Monitoring configuration changes and conducting security impact analyses are important
elements with regard to the ongoing assessment of security controls in the information system.
Related security Control: CA7.
Control Enhancements: None.
LOW
CM-4 MOD
CM-4 HIGH
CM-4
CM-5 ACCESS RESTRICTIONS FOR CHANGE
Control: Approve individual access privileges and enforce physical and logical access
restrictions associated with changes to the information system; and generate, retain, and review
records reflecting all such changes.
Supplemental Guidance: Planned or unplanned changes to the hardware, software, and/or
firmware components of the information system can have significant effects on the overall
security of the system. Accordingly, only qualified and authorized individuals obtain access
to information system components for purposes of initiating changes, including upgrades, and
modifications.
Control Enhancements:
(1) The organization employs automated mechanisms to enforce access restrictions and support
auditing of the enforcement actions.
(2) The organization limits and periodically reviews system developer privileges to change code
and system data directly within a production environment.
(3) The organization limits system developer privileges to change code and system data directly
within a production environment and reevaluates them on a 90 day cycle.
Section 44
(4) System libraries are managed and maintained to protect privileged programs and to prevent
or minimize the introduction of unauthorized code.
LOW CM-5 MOD CM-5(1)(2)(4) HIGH C M-5 (1)(2)(3)(4)
CM-6 CONFIGURATION SETTINGS
NAP 14.2-C IV-39
05-02-08
Control:
a. Establish mandatory configuration settings for information technology products employed
within the information system, where possible. See the Supplemental Guidance.
b. Configure the security settings of information technology products to the most restrictive
mode consistent with operational requirements;
c. Document the configuration settings; and
d. Enforce the configuration settings in all components of the information system.
Supplemental Guidance: Configuration settings are the configurable parameters of the
information assurance products that comprise the information system. Organizations
monitor and control changes to the configuration settings in accordance with
organizational policies and procedures. FISMA reporting instructions provide guidance
on configuration requirements for Federal information systems. Related security
controls: CM2, CM3, and SI4.
Control Enhancements:
(1) The organization employs automated mechanisms to centrally manage, apply, and verify
configuration settings.
(2) The information system and any modifications to the system baseline must demonstrate
conformance to security configuration technical implementation guides prior to being
introduced into a production environment.
LOW
CM-6 MOD
CM-6 (2) HIGH
CM-6 (1)(2)
CM-7 LEAST FUNCTIONALITY
Control: Configure the information system to provide only essential capabilities and document
in the system’s ISSP specific prohibitions and/or restrictions upon the use of functions, ports,
protocols, and/or services. The organization configures the information system to provide only
essential capabilities and specifically prohibits and/or restricts the use of the following functions,
ports, protocols, and/or services: [Assignment: organization-defined list of prohibited and/or
restricted functions, ports, protocols, and/or services documented in the information system
SSP].
Supplemental Guidance: Information systems are capable of providing a wide variety of
functions and services. Some of the functions and services, provided by default, may not be
necessary to support essential organizational operations (e.g., key missions, functions).
IV-40 NAP 14.2-C
05-02-08
Additionally, it is sometimes convenient to provide multiple services from a single component of
an information system, but doing so increases risk over limiting the services provided by any one
component. The functions and services provided by information systems, or individual
components of information are carefully reviewed to determine which functions and services are
candidates for elimination (e.g., Voice Over Internet Protocol, Instant Messaging, File Transfer
Protocol, Hyper Text Transfer Protocol, file sharing systems).
Control Enhancements:
(1) The organization reviews the information system at least annually to identify and eliminate
unnecessary functions, ports, protocols, and/or services.
(2) The information system complies with ports, protocols, and services guidance and
organizational registration requirements.
LOW CM-7 MOD CM-7 (1)(2) HIGH CM-7 (1)(2)
CM-8 INFORMATION SYSTEM COMPONENT INVENTORY
Section 45
Control: Develop, document, and maintain a current inventory of the components of the
information system and relevant ownership information.
Supplemental Guidance: The inventory of information system components includes any
information determined to be necessary by the organization to achieve effective property
accountability (e.g., manufacturer, model number, serial number, software license information,
system and/or component owner). The component inventory is consistent with the accreditation
boundary of the information system. Related security controls: CM2 and CM6.
Control Enhancements:
(1) The organization updates the inventory of information system components as an integral part
of component installations.
(2) The organization employs automated mechanisms to help maintain an up-to-date, complete,
accurate, and readily available inventory of information system components.
LOW CM-8 MOD CM-8 (1) HIGH CM-8 (1)(2)
FAMILY: CONTINGENCY PLANNING AND DISASTER RECOVERY CLASS: OPERATIONAL
NAP 14.2-C IV-41
05-02-08
Contingency Planning details the necessary procedures required to protect the continuing
performance of core business functions and services, including information and information
system services, during an outage.
Contingency Planning
Control Baselines Control
Number Control Name
Low Moderate High
CP-1 Contingency Planning Policy and
Procedures
CP-1 CP-1 (1) CP-1 (1)
CP-2 Contingency Plan CP-2* CP-2 (1)(2)* CP-2 (1)(2)(3)*
CP-3 Contingency Training CP-3 CP-3 (1) CP-3 (1)(2)
CP-4 Contingency Plan Testing CP-4 CP-4(1) CP-4 (1)*
CP-5 Contingency Plan Update CP-5 CP-5 CP-5
CP-6 Alternate Storage Sites Not Required CP-6 (1)(3) CP-6
(1)(2)(3)(4)(5)
CP-7 Alternate Processing Site Not Required CP-7
(1)(2)(3)
CP-7
(1)(2)(3)(4)(5)
CP-8 Telecommunications Services Not Required CP-8 (1)(2) CP-8 (1)(2)(3)(4)
CP-9 Information System Backup CP-9 CP-9 (1)(4) CP-9 (1)(2)(3)(4)
CP-10 Information System Recovery
and Reconstitution
CP-10 (2) CP-10 (1)(2) CP-10 (1)(2)(3)
CP-1 CONTINGENCY PLANNING AND DISASTER RECOVERY POLICY AND PROCEDURES
Control: Develop, disseminate, and periodically review and update:
a. A formal, documented, contingency and disaster recovery planning policy that addresses
purpose, scope, roles, responsibilities, management commitment, coordination among
organizational entities, and compliance; and
b. Formal, documented procedures to facilitate the implementation of the contingency and
disaster recovery planning policy and associated contingency planning controls.
Supplemental Guidance: The contingency and disaster recovery planning policy and
procedures are consistent with applicable Federal laws, directives, policies, regulations,
standards, and guidance. The contingency and disaster recovery planning policy can be
IV-42 NAP 14.2-C
05-02-08
included as part of the general information security policy for the organization.
Contingency planning procedures can be developed for the security program in general,
and for a particular information system, when required.
Control Enhancement:
(1) The organization develops and implements procedures to assure the appropriate physical
and technical protection of the backup and restoration hardware, firmware, and software,
such as router tables, compilers, and other security related system software.
LOW CP-1 MOD CP-1 (1) HIGH CP-1 (1)
CP-2 CONTINGENCY AND DISASTER RECOVERY PLAN
Section 46
Control: Develop and implement a contingency plan and disaster recovery plan for each
information system addressing contingency roles, responsibilities, assigned individuals
with contact information, and activities associated with restoring the system after a
disruption or failure. Designated officials within the organization review and approve the
contingency plan and distribute copies of the plan to key contingency personnel.
Supplemental Guidance: None
Control Enhancements:
(1) The organization coordinates contingency plan development with organizational elements
responsible for related plans.
Enhancement Supplemental Guidance: Examples of related plans include Business
Continuity Plan, Disaster Recovery Plan, Continuity of Operations Plan, Business
Recovery Plan, Incident Response Plan, and Emergency Action Plan.
(2) The organization conducts capacity planning so that necessary capacity for information
processing, telecommunications, and environmental support exists during crisis situations.
(3) The organization explicitly identifies mission and business essential functions and
establishes associated restoration priorities and metrics. These activities must be linked to
the BIA process.
* For systems with a level of concern for availability of HIGH:
(4) The organization plans and provides sufficient capacity to support partial restoration of
mission or business essential functions.
NAP 14.2-C IV-43
05-02-08
(5) The organization plans and provides for the smooth transfer of all mission or business
essential functions to alternate processing or facilities with little or no loss of operational
continuity. Continuity is sustained through restoration to primary processing or facilities.
LOW CP-2* MOD CP-2 (1)(2)* HIGH CP-2(1)(2)(3)*
CP-3 CONTINGENCY AND DISASTER RECOVERY TRAINING
Control: Train personnel in their contingency and disaster recovery roles and responsibilities
with respect to the information system and provide refresher training at least annually.
Supplemental Guidance: None.
Control Enhancements:
(1) The organization incorporates simulated events into contingency and disaster recovery
training to facilitate effective response by personnel in crisis situations.
(2) The organization employs automated mechanisms to provide a more thorough and realistic
training environment.
LOW CP-3 MOD CP-3 (1) HIGH CP-3 (1)(2)
CP-4 CONTINGENCY PLAN TESTING AND EXERCISES
Control: The organization:
a. Test and/or exercise the contingency and disaster recovery plans for the information system
at least annually using organization—defined tests and/or exercises to determine the plans’
effectiveness and the organization’s readiness to execute the plan; and
b. Review the contingency plan test and exercise results, and initiate corrective actions.
Supplemental Guidance: There are several methods for testing and/or exercising
contingency and disaster recovery plans to identify potential weaknesses (e.g., full-scale
testing, functional and/or tabletop exercises). Testing and/or exercises also include a
determination of the effects on organizational operations and assets (e.g., reduction in
mission capability) and individuals arising due to operations in accordance with the plan.
Control Enhancements:
(1) The organization coordinates contingency and disaster recovery plan testing and/or
exercises with organizational elements responsible for related plans.
Section 47
IV-44 NAP 14.2-C
05-02-08
Enhancement Supplemental Guidance: Examples of related plans include Business
Continuity Plan, Continuity of Operations Plan, Business Recovery Plan, Incident Response
Plan, and Emergency Action Plan.
* For systems with a level of concern for availability of HIGH:
(2) The organization tests and/or exercises the contingency and disaster recovery plans at the
alternate processing site to familiarize personnel with the facility and available resources
and to evaluate the site’s capabilities to support operations.
(3) It is recommended that the organization employ automated mechanisms to more
thoroughly and effectively test and/or exercise the contingency and disaster recovery
plans by providing more complete coverage of contingency issues, selecting more
realistic test and/or exercise scenarios and environments, and more effectively stressing
the information system and supported missions.
(4) The organization exercises this plan on a semiannual basis.
LOW CP-4* MOD CP-4 (1)* HIGH CP-4 (1)*
CP-5 CONTINGENCY DISASTER RECOVERY PLAN UPDATE
Control: Review the contingency and disaster recovery plans for the information system at least
annually and revise the plan to address system and/or organizational changes or problems
encountered during plan implementation, execution, or testing.
Supplemental Guidance: Organizational changes include changes in mission, functions, or
business processes supported by the information system.
Control Enhancements: None.
LOW
CP-5 MOD
CP-5 HIGH
CP-5
CP-6 ALTERNATE STORAGE SITE
Control: If required by the system owners and the Business Impact Analysis, identify an
alternate storage site and initiate necessary agreements to permit the storage of information
system backup information. Ensure that the frequency of information system backups and the
transfer rate of backup information to the alternate storage site (if so designated) are consistent
with the organization’s recovery time objectives and recovery point objectives.
Control Enhancements:
NAP 14.2-C IV-45
05-02-08
(1) The organization identifies an alternate storage site that is geographically separated from the
primary storage site so as not to be susceptible to the same hazards.
(2) The organization configures the alternate storage site to facilitate timely and effective
recovery operations.
(3) The organization identifies potential accessibility problems to the alternate storage site in the
event of an area-wide disruption or disaster and outlines explicit mitigation actions.
(4) The organization performs daily data backups and stores recovery media offsite at a location
that affords protection of the data in accordance with its confidentiality, integrity, and
availability levels.
(5) The organization accomplishes data backup by maintaining a redundant secondary system,
not collocated, that can be activated without loss of data or disruption to the operation.
(6) The organization will consider alternative procedures, such as secure transmission of the
data to an appropriate offsite location if regular offsite backup is not feasible.
LOW Not Required MOD CP-6 (1)(3) HIGH CP-6 (1)(2)(3)(4)(5)
CP-7 ALTERNATE PROCESSING SITE
Section 48
Control: If required by the Business Impact Analysis, identify an alternate processing site and
initiate necessary agreements to permit the resumption of information system operations for
critical mission and/or business functions within the organization-defined time period when the
primary processing capabilities are unavailable. Ensure that the timeframes to resume
information system operations are consistent with organization-established recovery time
objectives.
Supplemental Guidance: None
Control Enhancements:
(1) The organization identifies an alternate processing site that is geographically separated from
the primary processing site so as not to be susceptible to the same hazards.
(2) The organization identifies potential accessibility problems to the alternate processing site in
the event of an area-wide disruption or disaster and outlines explicit mitigation actions.
(3) The organization develops alternate processing site agreements that contain priority-of--
service provisions in accordance with the organization’s availability requirements.
(4) The organization fully configures the alternate processing site so that it is ready to be used as
the operational site supporting a minimum required operational capability.
IV-46 NAP 14.2-C
05-02-08
(5) The organization ensures that the alternate site provides security measures, to include
boundary defense and user connectivity and access controls, equivalent to the primary site.
LOW Not Required MOD CP-7 (1)(2)(3) HIGH CP-7 (1)(2)(3)(4)(5)
CP-8 TELECOMMUNICATIONS SERVICES
Control: Identify primary and alternate telecommunications services to support the information
system and initiate necessary agreements to permit the resumption of system operations for
critical mission and/or business functions in a timely manner, as specified by the operating unit,
when the primary telecommunications capabilities are unavailable.
Supplemental Guidance: In the event that the primary and/or alternate telecommunications
services are provided by a common carrier, the organization requests Telecommunications
Service Priority (TSP) for all telecommunications services used for national security emergency
preparedness.
Control Enhancements:
(1) The organization develops primary and alternate telecommunications service agreements that
contain priority-of-service provisions in accordance with the organization’s availability
requirements.
(2) The organization obtains alternate telecommunications services that do not share a single
point of failure with primary telecommunications services.
(3) The organization obtains alternate telecommunications service providers that are sufficiently
separated from primary service providers so as not to be susceptible to the same hazards.
(4) The organization requires primary and alternate telecommunications service providers to
have adequate contingency plans.
LOW Not Required MOD CP-8 (1) HIGH CP-8 (1)(2)(3)(4)
CP-9 INFORMATION SYSTEM BACKUP
Control: Conduct backups of user-level and system-level information (including system state
information) contained in the information system at least annually and store backup
information at an appropriately secured location if required by the Business Impact Analysis.
The NNSA Element ensures that the frequency of information system backups and the
transfer rate of backup information to alternate storage sites (if so designated) are consistent
with the organization’s recovery time objectives and recovery point objectives.
Section 49
NAP 14.2-C IV-47
05-02-08
Supplemental Guidance: While integrity and availability are the primary concerns for system
backup information, protecting backup information from unauthorized disclosure is also an
important consideration depending on the type of information residing on the backup media
and the associated risk level. An organizational assessment of risk guides the use of encryption
for backup information. The protection of system backup information while in transit is
beyond the scope of this control. Related security controls: MP4 and MP5.
Control Enhancements:
(1) The organization tests backup information annually to verify media reliability and
information integrity.
(2) The organization selectively uses backup information in the restoration of information
system functions as part of contingency plan and disaster recovery testing.
(3) The organization stores backup copies of the operating system and other critical information
system software in a separate facility or in a fire-rated container that is not collocated with
the operational software.
(4) The organization protects system backup information from unauthorized modification. The
organization employs appropriate mechanisms (e.g., digital signatures, cryptographic hashes)
to protect the integrity of information system backups.
LOW
CP-9 MOD
CP-9 (1)(4) HIGH
CP-9 (1)(2)(3)(4)
CP-10 INFORMATION SYSTEM RECOVERY AND RECONSTITUTION
Control: Employ mechanisms with supporting procedures to allow the information system to be
recovered and reconstituted to a known secure state after a disruption or failure.
Supplemental Guidance: Information system recovery and reconstitution to a known secure
state means that all system parameters (either default or organization-established) are set to
secure values, security-critical patches are reinstalled, security-related configuration settings are
reestablished, system documentation and operating procedures are available, application and
system software is reinstalled and configured with secure settings, information from the most
recent, known secure backups is loaded, and the system is fully tested.
Control Enhancements:
(1) The organization includes a full recovery and reconstitution of the information system as part
of contingency plan and disaster recovery testing.
(2) The organization documents circumstances that can inhibit a recovery to a known, secure
state and implements the appropriate mitigating controls.
IV-48 NAP 14.2-C
05-02-08
(3) Information systems that are transaction-based (e.g., database management systems,
transaction processing systems) will implement transaction rollback and transaction
journaling, or technical equivalents.
LOW CP-10 (2) MOD CP-10 (1)(2) HIGH CP-10 (1)(2)(3)
FAMILY: IDENTIFICATION AND AUTHENTICATION CLASS: TECHNICAL
Identification and authentication is a technical measure that prevents unauthorized people (or
unauthorized processes) from entering an information system. Access control usually requires
that the system be able to identify and differentiate among users. All NNSA information
systems must have a means to enforce user accountability, so that system activity (both
authorized and unauthorized) can be traced to a specific user. To facilitate user accountability,
all information systems must implement a method of user identification and authentication. The
user identification tells the system who the user is. The authentication mechanism provides an
added level of assurance that the user really is who they say they are. Authentication consists of
something a user knows (such as a password), something the user has (such as a token or smart
card), or something the user is (such as a fingerprint). User identification and authentication also
can enforce separation of duties.
Section 50
The following is NNSA policy:
• All information systems require distinct user IDs that are unique to each user or group for
user identification.
• All information systems require an authentication mechanism that is unique to each user
or group, such as but not limited to; passwords, one-time passwords, biometrics, or
public-key infrastructure certificates for primary access to all information and
information system resources. The implementation or technology used should provide
access security commensurate with the level of sensitivity assigned to the resource (i.e.,
information, devices or systems).
• All information systems and associated equipment that rely on passwords as the means to
authenticate users must implement effective password management in accordance with
the Element’s CSPP.
Identification and Authentication
Control Baselines Control
Number Control Name
Low Moderate High
NAP 14.2-C IV-49
05-02-08
Identification and Authentication
Control Baselines Control
Number Control Name
Low Moderate High
IA-1 Identification and
Authentication Policy and
Procedures
IA-1 IA-1 IA-1
IA-2 User Identification and
Authentication
IA-2 (1)(4) IA-2
(2)(3)(4)(5)
IA-2 (2)(3)(4)(5)
IA-3 (1) IA-3 (2) IA-3 Device Identification and
Authentication
Not Required
IA-3 IA-3
IA-4 Identifier Management IA-4 IA-4 (1)(2) IA-4 (1)(2)
IA-5 Authenticator Management IA-5 (1)(2)(3)(4) IA-5
(1)(2)(3)(4)
IA-5
(1)(2)(3)(4)(5)
IA-6 Authenticator Feedback IA-6 IA-6 IA-6
IA-7 Cryptographic Module
Authentication
IA-7 IA-7 IA-7
IA-1 IDENTIFICATION AND AUTHENTICATION POLICY AND PROCEDURES
Control: Develop, disseminate, and periodically review and update:
a. A formal, documented, identification and authentication policy that addresses purpose,
scope, roles, responsibilities, management commitment, coordination among organizational
entities, and compliance; and
b. Formal, documented procedures to facilitate the implementation of the identification and
authentication policy and associated identification and authentication controls.
Supplemental Guidance: Identification and authentication procedures can be developed for the
security program in general, and for a particular information system, when required. Users take
reasonable measures to safeguard authenticators including maintaining possession of their
individual authenticators, not loaning or sharing authenticators with others, and reporting lost or
compromised authenticators where technically feasible.
Control Enhancements: None.
LOW IA-1 MOD IA-1 HIGH IA-1
IV-50 NAP 14.2-C
05-02-08
IA-2 USER IDENTIFICATION AND AUTHENTICATION
Control: Uniquely identify and authenticate users (or processes acting on behalf of users) on
all information systems, where technically feasible.
Supplemental Guidance: Authentication of user identities is accomplished through the use of
passwords, tokens, biometrics, or in the case of multifactor authentication, some combination
thereof. Remote access is any access to an organizational information system by a user (or an
information system) communicating through an external, non-organization-controlled network
(e.g., the Internet). Local access is any access to an organizational information system by a user
(or an information system) communicating through an internal organization-controlled network
(e.g., local area network) or directly to a device without the use of a network. Related security
controls: AC-14 and AC-17.
Section 51
Control Enhancements:
(1) The information system employs passwords and/or PINs for local and remote system access.
(2) The information systems employ a multifactor authentication process or device that
generates a onetime password, for local system access.
Enhancement Supplemental Guidance: Multifactor authentication could include soft
tokens, hard tokens, scratch card, or grid cards, that generate one time passwords. One
time passwords could include the type one gets from time synchronous devices (e.g.,
SecurID) from challenge response devices, or from the protocol handshake that underlies
PKI.
(3) The information system employs a multifactor authentication process or device, that
generates a onetime password, for remote system access, where one of the factors is separate
from the system being used to gain access.
Enhancement Supplemental Guidance: The additional phrase is intended to eliminate
concepts such as soft tokens. This is intended to address an OMB0616 requirement for
remotely accessing systems containing PII, (there is no NSS exception).
(4) If passwords and/or PINs are employed they shall be compliant with the Element’s CSPP..
(5) If certificate-based authentication is employed it shall be compliant with the applicable
control enhancements in IA5.
LOW IA-2 (1)(4) MOD IA-2 (2)(3)(4)(5) HIGH IA-2 (2)(3)(4)(5)
NAP 14.2-C IV-51
05-02-08
IA-3 DEVICE IDENTIFICATION AND AUTHENTICATION
Control: The information system identifies and authenticates specific devices before
establishing a connection.
Supplemental Guidance: The information system typically uses either shared known information
(e.g., physical address or TCP/IP address), organizational authentication solution (e.g., IEEE 802.1x
and Extensible Authentication Protocol (EAP) or a Radius server with EAP-Transport Layer
Security (TLS) authentication) to identify and authenticate devices on local and/or wide area
networks. The required strength of the device authentication mechanism is determined by the LoC
of the information system with higher risk levels requiring stronger authentication. For remote
access via VPN, the VPN server is considered the information system which handles the
identification and authentication of remote devices.
Control Enhancements:
(1) The information system employs bidirectional authentication that is cryptographically based
between devices before establishing remote communication connections.
(2) The information system employs bidirectional authentication that is cryptographically based
(or uses authorized PTS) between devices before establishing remote or local communication
connections.
LOW Not Required MOD IA-3 (1) HIGH IA-3 (2)
LOW Not Required MOD IA-3 HIGH IA-3
IA-4 IDENTIFIER MANAGEMENT
Control: Manage user identifiers by:
a. Uniquely identifying each user;
b. Verifying the identity of each user;
c. Receiving authorization to issue a user identifier from an appropriate organization official;
d. Issuing the user identifier to the intended party;
e. Disabling the user identifier after the period of inactivity noted in the site CSPP; and
f. Archiving user identifiers.
g. Establish separate unique identifier for privileged accounts and actions.
IV-52 NAP 14.2-C
05-02-08
Supplemental Guidance: Identifier management is not applicable to shared information system
accounts (e.g., guest and anonymous accounts).
Section 52
Control Enhancements:
(1) NNSA Elements require that registration to receive a user ID include authorization by a
supervisor or sponsor (or management designee), and be done in person before a designated
registration authority.
(2) The organization requires documentary evidence of a user’s identity to be presented to the
registration authority.
LOW IA-4 MOD IA-4 (1)(2) HIGH IA-4 (1)(2)
IA-5 AUTHENTICATOR MANAGEMENT
Control: Manage information system authenticators by:
a. Defining initial authenticator content;
b. Establishing administrative procedures for initial authenticator distribution, for lost
and/or compromised, or damaged authenticators, and for revoking authenticators;
c. Changing default authenticators upon information system installation; and
d. Changing and/or refreshing authenticators at least annually
Supplemental Guidance: Information system authenticators include, for example,
tokens, PKI certificates, biometrics, passwords, and key cards. Complies with all
applicable laws, statutes, national policies and related E-authentication initiatives,
authentication of public users accessing Federal information systems (and associated
authenticator management) may also be required to protect nonpublic or privacy-related
information.
Control Enhancements:
(1) Information systems utilizing a logon ID and password for user identification and
authentication enforce the following for reusable passwords:
(a) Password complexity is not less than a case sensitive, 8-character mix of upper
case letters, lower case letters, numbers, and special characters (one of which
must be in the first seven positions), including at least one of each (e.g.,
emPagd2!). (Document in a system’s ISSP if a system is incapable of meeting
this requirement.)
NAP 14.2-C IV-53
05-02-08
(b) At least four characters must be changed when a new password is created.
(c) Passwords are encrypted both for storage and for transmission, where technically
feasible.
(d) Enforces password minimum and maximum lifetime restrictions; and
(e) Prohibits password reuse for a specified number [NNSA Element defined] of
generations.
Enhancement Supplemental Guidance: Deployed/tactical systems with limited data
input capabilities implement the password policy to the extent possible.
(2) The organization ensures that passwords are protected commensurate with the classification
or sensitivity of the information accessed.
(3) The organization ensures that policy prohibits passwords from being embedded in access
scripts or stored on function keys.
(4) Information systems utilizing PKI-based authentication:
(a) Validates certificates by constructing a certification path to a trusted certificate
authority;
(b) Establishes user control of the corresponding private key; and
(c) Maps the authenticated identity to the user account.
(5) The organization employs automated tools to validate that the passwords are sufficiently
strong to resist cracking and other types of attacks intended to discover a user’s
password.
Enhancement Supplemental Guidance: These tools may only be employed under the
auspices of the DAA. This type of testing can be accomplished in association with RA5.
LOW IA-5 (1)(2)(3)(4) MOD IA-5 (1)(2)(3)(4) HIGH IA-5 (1)(2)(3)(4)(5)
IA-6 AUTHENTICATOR FEEDBACK
Control: The information system obscures feedback of authentication information during the
authentication process to protect the information from possible exploitation/use by unauthorized
individuals.
Section 53
Supplemental Guidance: The feedback from the information system does not provide
information that would allow an unauthorized user to compromise the authentication
IV-54 NAP 14.2-C
05-02-08
mechanism. Displaying asterisks when a user types in a password is an example of
obscuring feedback of authentication information
Control Enhancements: None.
LOW
IA-6 MOD
IA-6 HIGH
IA-6
IA-7 CRYPTOGRAPHIC MODULE AUTHENTICATION
Control: If used, the information system employs authentication methods that meet the
requirements of applicable laws, Executive Orders, directives, policies, regulations, standards,
and guidance for authentication to a cryptographic module.
Supplemental Guidance: None.
Control Enhancements: None.
LOW IA-7 MOD IA-7 HIGH IA-7
FAMILY: INCIDENT RESPONSE CLASS: OPERATIONAL
An incident response capability is a mechanism through which an NNSA Element’s system
owners and Information System Security Officers are kept informed of system vulnerability
advisories from the US-Computer Emergency Readiness Team (US-CERT), software vendors,
and other sources. The capability also coordinates with responsible incident response
capabilities regarding the handling and reporting of incidents involving systems under the NNSA
Element’s responsibility. An incident response capability may consist of one or more persons
(such as the Information System Security Officer or CIO), who ensure that vulnerability
advisories are communicated to system owners.
Incident Response
Control Baselines Control
Number Control Name
Low Moderate High
IR-1 Incident Response Policy and
Procedures
IR-1 IR-1 IR-1
IR-2 Incident Response Training IR-2 IR-2 IR-2 (1)(2)
IR-3 Incident Response Testing Not Required IR-3 IR-3 (1)
NAP 14.2-C IV-55
05-02-08
Incident Response
Control Baselines Control
Number Control Name
Low Moderate High
IR-4 Incident Handling IR-4 IR-4 (1) IR-4 (1)
IR-5 Incident Monitoring IR-5 IR-5 (1) IR-5 (1)
IR-6 Incident Reporting IR-6 IR-6 (1) IR-6 (1)
IR-7 Incident Response Assistance IR-7 IR-7 (1) IR-7 (1)
IR-1 INCIDENT RESPONSE POLICY AND PROCEDURES
Control: Develop, disseminate, and periodically review/update:
a. A formal, documented, incident response policy that addresses purpose, scope, roles,
responsibilities, management commitment, coordination among organizational entities, and
compliance; and
b. Formal, documented procedures to facilitate the implementation of the incident response
policy and associated incident response controls.
Supplemental Guidance: The incident response policy can be included as part of the
general information security policy for the organization. Incident response procedures
can be developed for the security program in general, and for a particular information
system, when required.
Control Enhancement: None
LOW IR-1 MOD IR-1 HIGH IR-1
IR-2 INCIDENT RESPONSE TRAINING
Control: Train personnel in their incident response roles and responsibilities with respect to the
information system and provide refresher training at least annually.
Supplemental Guidance: None.
Control Enhancements:
(1) The organization incorporates simulated events into incident response training to
facilitate effective response by personnel in crisis situations.
IV-56 NAP 14.2-C
05-02-08
(2) The organization employs automate mechanisms to provide a more thorough and realistic
training environment.
Section 54
LOW IR-2 MOD IR-2 HIGH IR-2 (1)(2)
IR-3 INCIDENT RESPONSE TESTING AND EXERCISES
Control: Test and/or exercise the incident response capability for the information system at
least annually using the tests and exercises defined in the ISSP to determine the incident
response effectiveness and document the results.
Supplemental Guidance: None
Control Enhancements:
(1) The organization employs automated mechanisms to more thoroughly and effectively
test/exercise the incident response capability.
Enhancement Supplemental Guidance: Automated mechanisms can provide the ability to more
thoroughly and effectively test or exercise the capability by providing more complete coverage
of incident response issues, selecting more realistic test/exercise scenarios and environments,
and more effectively stressing the response capability.
LOW IR-3 MOD IR-3 HIGH IR-3 (1)
IR-4 INCIDENT HANDLING
Control: Implement an incident handling capability for security incidents that includes
preparation, detection and analysis, evidence preservation, containment, eradication, and
recovery.
Supplemental Guidance: Incident-related information can be obtained from a variety of sources
including, but not limited to, audit monitoring, network monitoring, physical access monitoring, and
user/administrator reports. Related security controls: AU-6 and PE-6.
Control Enhancement:
(1) The organization employs automated mechanisms to support the incident handling process.
LOW
IR-4 MOD
IR-4 (1) HIGH
IR-4 (1)
NAP 14.2-C IV-57
05-02-08
IR-5 INCIDENT MONITORING
Control: Track and document information system security incidents on an ongoing basis.
Supplemental Guidance: None.
Control Enhancement:
(1) The organization employs automated mechanisms to assist in the tracking of security
incidents and in the collection and analysis of incident information.
LOW
IR-5 MOD
IR-5 (1) HIGH
IR-5 (1)
IR-6 INCIDENT REPORTING
Control: Promptly report incident information to appropriate authorities.
Supplemental Guidance: The types of incident information reported, the content and timeliness of
the reports, and the list of designated reporting authorities or organizations are consisted with
applicable laws, Executive Orders, directives, policies, regulations, standards, and guidance. In
addition to incident information, weaknesses and vulnerabilities in the information system are
reports to appropriate organizational officials in a timely manner to prevent security incidents.
Control Enhancement:
(1) The organization employs automated mechanisms to assist in the reporting of security
incidents.
LOW
IR-6 MOD
IR-6 (1) HIGH
IR-6 (1)
IR-7 INCIDENT RESPONSE ASSISTANCE
Control: Provide an incident response support resource (internal or external incident response
capability support) that offers advice and assistance to users of the information systems for the
handling and reporting of security incidents. The support resource is an integral part of the
organization’s incident response capability.
Supplemental Guidance: Possible implementations of incident response support resources in an
organization include a help desk or an assistance group and access to forensics services, when
required.
Control Enhancement:
IV-58 NAP 14.2-C
05-02-08
(1) The organization employs automated mechanisms to increase the availability of incident
response related information and support.
Section 55
LOW IR-7 MOD IR-7 (1) HIGH IR-7 (1)
FAMILY: MAINTENANCE CLASS: OPERATIONAL
These are controls to ensure that maintenance activities are controlled and monitored to ensure
that the confidentiality, integrity or availability of the information is not compromised.
Maintenance
Control Baselines Control
Number Control Name
Low Moderate High
MA-1 System Maintenance Policy and
Procedures
MA-1 MA-1 MA-1
MA-2 Periodic Maintenance MA-2 MA-2 (1) MA-2 (1) (2)
MA-3 Maintenance Tools MA-3 (2) MA-3
(1)(2)(3)(4)
MA-3
(1)(2)(3)(4)
MA-4 Remote Maintenance MA-4
(1)(2)(3)(4)
MA-4
(1)(2)(3)(4)
MA-4
(1)(2)(3)(4)(5)
MA-5 Maintenance Personnel MA-5 (1)(4) MA-5
(1)(2)(3)(4)
MA-5
(1)(2)(3)(4)
MA-6 Timely Maintenance Not Required MA-6 (1) MA-6 (2)
MA-1 SYSTEM MAINTENANCE POLICY AND PROCEDURES
Control: Develop, disseminate, and periodically review/update:
a. A formal, documented, information system maintenance policy that addresses purpose,
scope, roles, responsibilities, management commitment, coordination among organizational
entities, and compliance; and
b. Formal, documented procedures to facilitate the implementation of the information system
maintenance policy and associated system maintenance controls.
Supplemental Guidance: The information system maintenance policy can be included as
part of the general information security policy for the organization. System maintenance
NAP 14.2-C IV-59
05-02-08
procedures can be developed for the security program in general, and for a particular
information system, when required.
Control Enhancements: None.
LOW
MA-1 MOD
MA-1 HIGH
MA-1
MA-2 CONTROLLED MAINTENANCE
Control:
a. The organization schedules, performs, documents, and reviews records of routine
preventative and regular maintenance (including repairs) on the components of the
information system in accordance with manufacturer or vendor specifications and/or
organizational requirements.
b. All maintenance activities to include routine, scheduled maintenance and repairs are
controlled; whether performed on site or remotely and whether the equipment is serviced on
site or removed to another location.
c. The ISSM approves the removal of information system or information system components
that processed sensitive or classified information from the site when repairs are necessary.
d. If the information system or component of the system requires offsite repair, the organization
removes all information from associated media using approved procedures.
e. After maintenance is performed on the information system, the organization checks all
potentially impacted security controls to verify that the controls are still functioning
properly.
Supplemental Guidance: None
Control Enhancements:
(1) The organization maintains maintenance records for the information system that include:
(a) The date and time of maintenance;
(b) Name of the individual performing the maintenance;
(c) Name of escort, if necessary;
(d) A description of the maintenance performed; and
IV-60 NAP 14.2-C
05-02-08
(e) A list of equipment removed or replaced (including identification numbers, if
applicable).
(2) The organization employs automated mechanisms to schedule and conduct maintenance as
required, and to create up-to-date, accurate, complete, and available records of all
maintenance actions, both needed and completed.
LOW MA-2 MOD MA-2 (1) HIGH MA-2 (1)(2)
Section 56
MA-3 MAINTENANCE TOOLS
Control: Approve, control, and monitor the use of information system maintenance tools
and maintain the tools on an ongoing basis.
Supplemental Guidance: The intent of this control is to address hardware and software
brought into the information system specifically for diagnostic/repair actions (e.g., a
hardware or software packet sniffer that is introduced for the purpose of a particular
maintenance activity). Hardware and/or software components that may support
information system maintenance, yet are a part of the system (e.g., the software
implementing “ping,” “ls,” “ipconfig,” or the hardware and software implementing the
monitoring port of an Ethernet switch) are not covered by this control.
Control Enhancements:
(1) The organization inspects all maintenance tools carried into a facility by maintenance
personnel for obvious improper modifications.
Enhancement Supplemental Guidance: Maintenance tools include, for example,
diagnostic and test equipment used to conduct maintenance on the information system.
(2) The organization checks all media containing diagnostic and test programs for malicious
code before the media are used in the information system.
(3) The organization checks all maintenance equipment with the capability of retaining
information so that no organizational information is written on the equipment or the
equipment is appropriately sanitized before release. In the event the equipment cannot be
sanitized, the equipment remains within the facility or is destroyed, unless an appropriate
organization official explicitly auth