|Developing Security Plans at USAID Missions|
|January 23, 2001|
|CIO Council Security Practices Subcommittee (SPS)|
|United States Agency for International Development (USAID) Bureau for Management, Information Resources Management (M/IRM), Information Systems Security Team|
|1.7||Level of BSP|
|1.8||Security Processes or other Framework(s) Supported|
Security Process Framework:
In the SSE CMM Framework:
In the OMB A-130 Appendix III, Section A:
|Not to be completed by the drafter|
|1.10||Points of Contact|
|Government BSP Owner:
|2.0||What This BSP Does|
|This BSP provides
instructions for USAID missions to develop security plans for general
support systems and major applications within the cyber-security
assistance visit process. USAID IRM security has developed an office
automation tool (security
plan template) to assist with the security plan development. The tool
is a Word 97 document and is designed to meet the requirements of OMB
Circular A-130, Appendix III. The tool was constructed before NIST Special
Publication 800-18 was made available.
The security plan template provides sample text throughout the document that is to be modified to identify the specific security specifications of the system or application being defined. The title of each section requiring modification contains highlighted text denoting an imbedded comment. Moving the mouse arrow over the highlighted text causes a comment box to appear with information identifying or clarifying the requirements for that section. Users are to modify each section with security specifications specific to their systems or applications based on the requirements identified in the comments.
A list of files associated with the automated tool is contained in Section 4.4 of this BSP, under the heading ‘Tools’. A brief description is also included to help users (System/Application Owners) in creating their own specific security plan.
|2.2||Requirements for this BSP|
Appendix III, Section A.3a.3
"Review of Security Controls. Review the security controls in each system when significant modifications are made to the system, but at least every three years. The scope and frequency of the review should be commensurate with the acceptable level of risk for the system. Depending on the potential risk and magnitude of harm that could occur, consider identifying a deficiency pursuant to OMB Circular No. A-123, "Management Accountability and Control" and the Federal Managers' Financial Integrity Act (FMFIA), if there is no assignment of security responsibility, no security plan, or no authorization to process for a system."
correspondence from an organization expressing appreciation for raising
security posture at their location through the use of this Risk Assessment
Subj: COMPUTER SECURITY TEAM VISIT
Source: David Bayer, USAID Peru Executive Office
If you have the opportunity to have the Information Systems Security Officer (ISSO) Jim Craft and his Risk Assessment Program Area Manager, Rodney Murphy, visit your Mission with their team of computer security experts, then take advantage of it. They did one hell of a job during their February visit with us at USAID/Peru in getting us up to speed and raising our level of consciousness about security issues. This is not to say that our dedicated IRM staff, led by Systems Manager, Lucho Figueroa, have not been working their hearts out to get us into shape, but it is a real injection of energy to have professional people like Jim, Rodney, John Zoble, Mike Reiter and Steve Bui come in and sit down to review your Computer Security Program and Computer Contingency Plan with you.
In addition, they trained some 80 employees to become aware of computer security pitfalls.
And last but not least, they have given us some key advice and methods for closing out some computer security audit issues which are not only USAID/Peru exposures but endemic to all Missions worldwide.
Computer security is becoming an important issue in for USAID and all organizations. In this environment, new security standards and having a formal security program in each overseas Mission is very important.
USAID/Peru was selected as a Beta site to define the model/templates for the Computer Security Program to be applied in all overseas Missions.
Starting February 19 to February 25, during five workdays, a Computer Security Team belonging to the IRM/ Security Group was in Lima. The team had five members. Jim Craft acted as the team Leader.
Computer Security is a dynamic activity and demands coordination and permanent follow-up. The Computer Security Team's role in the implementation of the Computer Security Program in each Mission is critical. Computer Security activity involves the entire USAID organization, starting from Washington and reaching out worldwide to all Missions. If one Mission security system fails, it endangers the entire USAID organization.
|3.0||What This BSP Is|
|3.1||Description of BSP|
|A standard format for presenting the results of the security planning process at any USAID site is described here, along with a library of reference material. These resources are to be combined to produce a durable approach to the security needs of USAID Mission locations throughout the world.|
Using the sample document of the cyber-security assist visit In-Briefing presentation and the information gathered during the planning activities, develop a comprehensive In-Briefing to be presented to the appropriate management/staff of the organization undergoing the Risk Assessment Review.
Step 1. Identify the systems and applications that require Security Plan documentation.
Step 2. Apply the security plan template to each system and application identified for Security Plan documentation. Users modify each section of the template with security specifications particular to their systems or applications based on the requirements identified in the ‘comments’ section of the template. (The title of each section requiring modification contains highlighted text signaling an attached comment. By moving the mouse arrow over the highlighted text, a comment box will appear with specific information identifying or clarifying the requirements for that section).
Complete a Security Compliance Checklist for each file server identified in the security planning document. These Security Compliance Checklists contain specific requirements associated with the operating system software configuration on each server.
Complete an Emergency Readiness Evaluation checklist for each system/application being evaluated. The Emergency Readiness Evaluation checklist is used to verify the status of Continuity of Operations Planning associated with the system/application.
The process builds a security plan for each USAID general support system and major application that will meet the requirements specified by OMB A-130 Appendix III, associated with security plans.
|3.2||Relationship to Other BSPs|
|The cyber-security assistance visit process comprises several sub-processes, one of which is the development of a Security Plan. More relationships will be added as additional BSPs are submitted.|
|4.0||How To Use This BSP|
|Having the Administrator of the system being reviewed work closely with the Risk Assessment team members in developing the Security Plan can enhance the efficiency of this process.|
|4.2||Implementation Resource Estimates|
Operating System Administrator or knowledge equivalent.
Time per System/Application: Depends on the size of the system; approximately 40 hours to complete the Security Plan template, the Security Compliance checklist, and the Emergency Readiness Evaluation checklist.
Preparation Time up-front: Depends on the time required to identify systems and applications, and to gather the requisite security specifications information for each system and application; approximately 40 hours for each system and application.
|4.3||Performance Goals and Indicators (Metrics)|
Goal: To eliminate the security vulnerabilities associated with the
configuration of the organization’s systems/applications and develop a
security plan to maintain the proper security posture for these
Performance Goal: To develop a Security Plan for all USAID general support and major applications.
Outcome Goal: Security Plans developed during a Risk Assessment Review will comply with OMB A-130 Appendix III.
Output goal: An OMB A-130 Appendix III compliant Security Plan.
General Objective: To identify and document the security posture of the USAID general support systems and major applications. This information can assist Senior Management in making appropriate security related decisions.
Performance Indicator: Document the existence of a Security Plan for each USAID general support and major application.
|The tools used to
perform the BSP for Security Plan Development within the Risk Assessment
|A||Executive Overview and Briefing|
|Editor's Note: See Appendix A *.ppt briefing|
|NIST Special Publication 800-18 (.pdf format)|
|The United States Agency for International Development (USAID) has contracted for general IRM support with Computer Sciences Corporation (CSC) under the Agency's Principle Resource for Information Management Enterprisewide (PRIME) contract (GS00K96AJD0012) with FEDSIM. USAID obtains its information system security support from CSC under the PRIME contract using the Performance Work Statement (PWS) at Appendix C *.doc.|
|Not yet evaluated|
|BSP 0002, Version 1.0 was reviewed after conducting cyber-assistance visits to Phnom Penh, Cambodia and Manila, Philippines during November and December 2000. Review determined need to revise time estimates in Section 4.2, from 4 hours to 40 hours.|