Category Archives: ISO 27001

ISO 27001 Lead Auditor Training Class scheduled for online learning

Mastering the audit of an Information Security Management System (ISMS) based on ISO/IEC 27001

4 1/2 days from August 17th through August 20th, 2020

Summary | Go to Enrollment Form

This five-day intensive course enables participants to develop the necessary expertise to audit an Information Security Management System (ISMS) and to manage a team of auditors by applying widely recognized audit principles, procedures and techniques.

  • During this training, the participant will acquire the necessary knowledge and skills to proficiently plan and perform internal and external audits in compliance with ISO 19011 the certification process according to ISO 17011.
  • Based on practical exercises, the participant will develop the skills (mastering audit techniques) and competencies (managing audit teams and audit program, communicating with customers, conflict resolution, etc.) necessary to efficiently conduct an audit.

Certified Course

Who should attend?

  • Internal auditors
  • Auditors wanting to perform and lead Information Security Management System (ISMS) certification audits
  • Project managers or consultants wanting to master the Information Security Management System audit process
  • CxO and Senior Managers responsible for the IT governance of an enterprise and the management of its risks
  • Members of an information security team
  • Expert advisors in information technology
  • Technical experts wanting to prepare for an Information security audit function

Learning objectives

  • To acquire the expertise to perform an ISO/IEC 27001 internal audit following ISO 19011 guidelines
  • To acquire the expertise to perform an ISO/IEC 27001 certification audit following ISO 19011 guidelines and the specifications of ISO 17021 and ISO 27006
  • To acquire the necessary expertise  to manage an ISMS audit team
  • To understand the operation of an ISO/IEC 27001 conformant information security management system
  • To understand the relationship between an Information Security Management System, including risk management, controls and compliance with the requirements of different stakeholders of the organization
  • To improve the ability to analyze the internal and external environment of an organization, its risk assessment and audit decision-making

Course Agenda Go to Enrollment Form

Day 1: Introduction to Information Security Management System (ISMS) concepts as required by ISO/IEC 27001

  • Normative, regulatory and legal framework related to information security
  • Fundamental principles of information security
  • ISO/IEC 27001 certification process
  • Information Security Management System (ISMS)
  • Detailed presentation of the clauses 4 to 8 of ISO/IEC 27001

Day 2: Planning and Initiating an ISO/IEC 27001 audit

  • Fundamental audit concepts and principles
  • Audit approach based on evidence and on risk
  • Preparation of an ISO/IEC 27001 certification audit
  • ISMS documentation audit
  • Conducting an opening meeting

Day 3: Conducting an ISO/IEC 27001 audit

  • Communication during the audit
  • Audit procedures: observation, document review, interview, sampling techniques, technical verification, corroboration and evaluation
  • Audit test plans
  • Formulation of audit findings
  • Documenting nonconformities

Day 4: Concluding and ensuring the follow-up of an ISO/IEC 27001 audit

  • Audit documentation
  • Quality review
  • Conducting a closing meeting and conclusion of an ISO/IEC 27001 audit
  • Evaluation of corrective action plans
  • ISO/IEC 27001 Surveillance audit
  • Internal audit management program

Day 5: Certification Exam (Flexible schedule)

  • 8 am to 11:30 am (online)

Prerequisites

PECB Certified ISO/IEC 27001 Foundation Certification or basic knowledge of  ISO/IEC 27001 is recommended.

Educational approach

  • This training is based on both theory and practice:
    • Sessions of lectures illustrated with examples based on real cases
    • Practical exercises based on a full case study including role playings and oral presentations
    • Review exercises to assist the exam preparation
    • Practice test similar to the certification exam

Examination and Certification

  • The “PECB Certified ISO/IEC 27001 Lead Auditor” exam fully meets the requirements of the PECB Examination and Certification Programme (ECP). The exam covers the following competence domains:
    • Domain 1: Fundamental principles and concepts of information security
    • Domain 2: Information Security Management System (ISMS)
    • Domain 3: Fundamental audit concepts and principles
    • Domain 4: Preparation of an ISO/IEC 27001 audit
    • Domain 5: Conducting an 27001 audit
    • Domain 6: Closing an ISO/IEC 27001 audit
    • Domain 7: Managing an ISO/IEC 27001 audit program
  • The “PECB Certified ISO/IEC 27001 Lead Auditor” exam is available in different languages (the complete list of languages can be found in the examination application form)
  • Duration: 3 hours
  • For more information about the exam, refer to the section on PECB Certified ISO/IEC 27001 Lead Auditor Exam
  • After successfully completing the exam, participants can apply for the credentials of PECB Certified ISO/IEC 27001 Provisional Auditor, PECB Certified ISO/IEC 27001 Auditor or PECB Certified ISO/IEC 27001 Lead Auditor depending on their level of experience.  Those credentials are available for internal and external auditors
  • A certificate will be issued to participants who successfully pass the exam and comply with all the other requirements related to the selected credential
  • For more information about PECB Certified ISO/IEC 27001 certifications and the PECB certification process, refer to the section on ISO/IEC 27001 certifications

General Information

  • Certification fees are included in the exam price
  • A student manual containing over 450 pages of information and practical examples will be distributed to participants
  • A participation certificate of 31 CPD (Continuing Professional Development) credits will be issued to participants
  • In case of failure of the exam, participants are allowed to retake the exam for free under certain conditions

Location:

Online via Join.me

Fee: $1,750.00

Go to Enrollment Form

Risk Assessments and Management Methods for ISO Management Systems

Important enhancements have been made to the QMSCAPA™ software module for Risk Assessments and Management.

The QMSCAPA Risk Assessment (RA) module consist of:

  • Table of Risk Assessments (current and historical assessments)
    • A sub-table of specific aspects of the risk assessments
    • A look-up table of the risk impact values with regard to the
      • Probability (P) {likelihood}
      • Severity (S) {impact}
      • Detection (D) {overall detection ability reduces risk
    • Five user-defined boundaries, e.g. Very Low, Low, Medium, High, Very High.

The impact values are used to calculate the Risk Priority Number (RPN) for each aspect.

RPN = (P * S * D)

The module is developed around the concepts typically found in a Failure Mode Effects Analysis (FMEA).

The single-user version of QMSCAPA software may be downloaded free of charge, simply click here to join the QMSCAPA users-group.

The Risk Assessments browse table can store a large number of current and/or historical assessments.

  1. The browse window contains sort tabs for instant viewing of data according to the key value of the Tab.
  2. Risk assessments can be performed and recorded for virtually any type of risk related to the organization, relevant interested parties, product, service, staff, logistics, transportation, and cost, including environmental, health and safety.
  3. View RiskAspects button: Opens a sub-table of related aspects to the highlighted risk assessment may be viewed, added, edited or deleted as needed.
  4. RIP icon button: Access the Relevant Interested Parties table (RIP).
  5. Print Assessment button: Use the button to print a Risk Assessment, which includes all aspects and impacts recorded.
  6. Copy Assessment or Template button: The copy button control copies the currently highlight assessment record.
  7. The tab 10) Templates applies a filter that only shows the Risk Assessments designed to be templates.

The Risk Aspect module form is configured with 4 main Tabs or sections:

  1. The General Tab contains information about the failure (generic for incident, breach, non-conformance). The assessment calculation tool (pre and post mitigation results) is designed for rating or assessing a specific aspect of the Risk identified and associated in the Risk Assessment Table. Therefore, a one to many relationship exist between the Risk (parent table) and the Aspects (child table).
  2. Tab 2) contains fields for additional consequences.
  3. Tab 3) contains fields for mitigation or risk treatment actions.
  4. Tab 3) contains a method of generating risk impact statement based upon availability, confidentiality, integrity and financial effect.

1) General tab

(A) In the form image below/right, Describe the failure and the failure mode.

(B) Describe what may cause the failure and the failure effect.

(C) The impact values for calculating the Risk Priority Number (RPN) (pre-mitigation treatments); see the look-up table for impact values:

  • RPN = Probability (P) * Severity (S) * Detection

(D) The impact values for calculating the Risk Priority Number (RPN) (post-mitigation treatments);

(E) Look-up Tables for Response to Risk Aspect and the current/last Status of the Risk Aspect.

(F) The RPN can report the pre or post-mitigation action [√] RPN Post Mitigation Action is check-box.

Additional QMSCAPA risk assessment and management information has been published at qmscapa.net.

Report on Lightweight Cryptography

NIST recently announced the release of NISTIR 8114, Report on Lightweight Cryptography.

Link to the NISTIR 8114 document (PDF format) from the NIST Library website:
http://nvlpubs.nist.gov/nistpubs/ir/2017/NIST.IR.8114.pdf

Link to NISTIR 8114 located on the CSRC NISTIR page:
<http://csrc.nist.gov/publications/PubsNISTIRs.html#NIST-IR-8114>

This report provides an overview of lightweight cryptography, summarizes the findings of NIST’s lightweight cryptography project, and outlines NIST’s plans for the standardization of lightweight algorithms.

Announcement by:

NIST Computer Security Division (Attn: Pat O’Reilly)

Information Security Requirements for Controlled Unclassified Information (CUI)

 ISO 27001 Information Security Management System (ISMS) provides essential framework for compliance to NIST 800-171

Controlled Unclassified Information (CUI) supports federal missions and business functions that affect the economic and national security interests of the United States. Non-federal organizations (e.g. colleges, universities, state, local and tribal governments, federal contractors and subcontractors) often process, store, or transmit CUI.

Executive Order 13556, as issued November 10, 2010, designated the National Archives and Records Administration (NARA) as the Executive Agent to implement the CUI program. NIST Special Publication 800-171 defines the security requirements for protecting CUI in non-federal information systems and organizations.

Security Requirements for Protecting the Confidentiality of CUI

NIST Special Publication 800-171 contains fourteen families of security requirements (including basic and derived requirements) 18 for protecting the confidentiality of CUI in nonfederal information systems and organizations.

The security controls from NIST Special Publication 800-53 associated with the basic and derived requirements are also listed in Appendix D. Organizations can use Special Publication 800-53 to obtain additional, non-prescriptive information related to the CUI security requirements (e.g., supplemental guidance related to each of the referenced security controls, mapping tables to ISO/ IEC 27001 ISMS, Annex A (security objective & controls), and a catalog of optional controls that can be used to help specify additional CUI requirements if needed).

The security requirements identified in 800-171 are intended to be applied to the non-federal organization’s general-purpose internal information systems that are processing, storing, or transmitting CUI. Some specialized systems such as medical devices, Computer Numerical Control (CNC) machines, or industrial control systems may have restrictions or limitations on the application of certain CUI requirements and may be granted waivers or exemptions from the requirements by the federal agency providing oversight.

NIST 800-171 REQUIREMENTS

1 ACCESS CONTROL

Basic Security Requirements:

1.1 Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).

1.2 Limit information system access to the types of transactions and functions that authorized users are permitted to execute.

Derived Security Requirements:

1.3 Control the flow of CUI in accordance with approved authorizations.

1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion.

1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts.

1.6 Use non-privileged accounts or roles when accessing nonsecurity functions.

1.7 Prevent non-privileged users from executing privileged functions and audit the execution of such functions.

1.8 Limit unsuccessful logon attempts.

1.9 Provide privacy and security notices consistent with applicable CUI rules.

1.10 Use session lock with pattern-hiding displays to prevent access/viewing of data after period of inactivity.

1.11 Terminate (automatically) a user session after a defined condition.

1.12 Monitor and control remote access sessions.

1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.

1.14 Route remote access via managed access control points.

1.15 Authorize remote execution of privileged commands and remote access to security-relevant information.

1.16 Authorize wireless access prior to allowing such connections.

1.17 Protect wireless access using authentication and encryption.

1.18 Control connection of mobile devices.

1.19 Encrypt CUI on mobile devices.

1.20 Verify and control/limit connections to and use of external information systems.

1.21 Limit use of organizational portable storage devices on external information systems.

1.22 Control information posted or processed on publicly accessible information systems.

2 AWARENESS AND TRAINING

Basic Security Requirements:

2.1 Ensure that managers, systems administrators, and users of organizational information systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of organizational information systems.

2.2 Ensure that organizational personnel are adequately trained to carry out their assigned information security-related duties and responsibilities.

Derived Security Requirements:

2.3 Provide security awareness training on recognizing and reporting potential indicators of insider threat.

3 AUDIT AND ACCOUNTABILITY

Basic Security Requirements:

3.1 Create, protect, and retain information system audit records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful, unauthorized, or inappropriate information system activity.

3.2 Ensure that the actions of individual information system users can be uniquely traced to those users so they can be held accountable for their actions.

Derived Security Requirements:

3.3 Review and update audited events.

3.4 Alert in the event of an audit process failure.

3.5 Correlate audit review, analysis, and reporting processes for investigation and response to indications of inappropriate, suspicious, or unusual activity.

3.6 Provide audit reduction and report generation to support on-demand analysis and reporting.

3.7 Provide an information system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.

3.8 Protect audit information and audit tools from unauthorized access, modification, and deletion.

3.9 Limit management of audit functionality to a subset of privileged users.

4 CONFIGURATION MANAGEMENT

Basic Security Requirements:

4.1 Establish and maintain baseline configurations and inventories of organizational information systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.

4.2 Establish and enforce security configuration settings for information technology products employed in organizational information systems.

Derived Security Requirements:

4.3 Track, review, approve/disapprove, and audit changes to information systems.

4.4 Analyze the security impact of changes prior to implementation.

4.5 Define, document, approve, and enforce physical and logical access restrictions associated with changes to the information system.

4.6 Employ the principle of least functionality by configuring the information system to provide only essential capabilities.

4.7 Restrict, disable, and prevent the use of nonessential programs, functions, ports, protocols, and services.

4.8 Apply deny-by-exception (blacklist) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.

4.9 Control and monitor user-installed software.

5 IDENTIFICATION AND AUTHENTICATION

Basic Security Requirements:

5.1 Identify information system users, processes acting on behalf of users, or devices.

5.2 Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.

Derived Security Requirements:

5.3 Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.

5.4 Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.

5.5 Prevent reuse of identifiers for a defined period.

5.6 Disable identifiers after a defined period of inactivity.

5.7 Enforce a minimum password complexity and change of characters when new passwords are created.

5.8 Prohibit password reuse for a specified number of generations.

5.9 Allow temporary password use for system logons with an immediate change to a permanent password.

5.10 Store and transmit only encrypted representation of passwords.

5.11 Obscure feedback of authentication information.

6 INCIDENT RESPONSE

Basic Security Requirements:

6.1 Establish an operational incident-handling capability for organizational information systems that includes adequate preparation, detection, analysis, containment, recovery, and user response activities.

6.2 Track, document, and report incidents to appropriate officials and/or authorities both internal and external to the organization.

Derived Security Requirements:

6.3 Test the organizational incident response capability.

7 MAINTENANCE

Basic Security Requirements:

7.1 Perform maintenance on organizational information systems.24

7.2 Provide effective controls on the tools, techniques, mechanisms, and personnel used to conduct information system maintenance.

Derived Security Requirements:

7.3 Ensure equipment removed for off-site maintenance is sanitized of any CUI.

7.4 Check media containing diagnostic and test programs for malicious code before the media are used in the information system.

7.5 Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.

7.6 Supervise the maintenance activities of maintenance personnel without required access authorization.

8 MEDIA PROTECTION

Basic Security Requirements:

8.1 Protect (i.e., physically control and securely store) information system media containing CUI, both paper and digital.

8.2 Limit access to CUI on information system media to authorized users.

8.3 Sanitize or destroy information system media containing CUI before disposal or release for reuse.

Derived Security Requirements:

8.4 Mark media with necessary CUI markings and distribution limitations.25

8.5 Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas.

8.6 Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.

8.7 Control the use of removable media on information system components.

8.8 Prohibit the use of portable storage devices when such devices have no identifiable owner.

8.9 Protect the confidentiality of backup CUI at storage locations.

9 PERSONNEL SECURITY

Basic Security Requirements:

9.1 Screen individuals prior to authorizing access to information systems containing CUI.

9.2 Ensure that CUI and information systems containing CUI are protected during and after personnel actions such as terminations and transfers.

Derived Security Requirements: None.

10 PHYSICAL PROTECTION

Basic Security Requirements:

10.1 Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.

10.2 Protect and monitor the physical facility and support infrastructure for those information systems.

Derived Security Requirements:

10.3 Escort visitors and monitor visitor activity.

10.4 Maintain audit logs of physical access.

10.5 Control and manage physical access devices.

10.6 Enforce safeguarding measures for CUI at alternate work sites (e.g., telework sites).

11 RISK ASSESSMENT

Basic Security Requirements:

11.1 Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational information systems and the associated processing, storage, or transmission of CUI.

Derived Security Requirements:

11.2 Scan for vulnerabilities in the information system and applications periodically and when new vulnerabilities affecting the system are identified.

11.3 Remediate vulnerabilities in accordance with assessments of risk.

12 SECURITY ASSESSMENT

Basic Security Requirements:

12.1 Periodically assess the security controls in organizational information systems to determine if the controls are effective in their application.

12.2 Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational information systems.

12.3 Monitor information system security controls on an ongoing basis to ensure the continued effectiveness of the controls.

Derived Security Requirements: None.

13 SYSTEM AND COMMUNICATIONS PROTECTION

Basic Security Requirements:

13.1 Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.

13.2 Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational information systems.

Derived Security Requirements:

13.3 Separate user functionality from information system management functionality.

13.4 Prevent unauthorized and unintended information transfer via shared system resources.

13.5 Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.

13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).

13.7 Prevent remote devices from simultaneously establishing non-remote connections with the information system and communicating via some other connection to resources in external networks.

13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.

13.9 Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.

13.10 Establish and manage cryptographic keys for cryptography employed in the information system.

13.11 Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.

13.12 Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.

13.13 Control and monitor the use of mobile code.

13.14 Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.

13.15 Protect the authenticity of communications sessions.

13.16 Protect the confidentiality of CUI at rest.

14 SYSTEM AND INFORMATION INTEGRITY

Basic Security Requirements:

14.1 Identify, report, and correct information and information system flaws in a timely manner.

14.2 Provide protection from malicious code at appropriate locations within organizational information systems.

14.3 Monitor information system security alerts and advisories and take appropriate actions in response.

Derived Security Requirements:

14.4 Update malicious code protection mechanisms when new releases are available.

14.5 Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.

14.6 Monitor the information system including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.

14.7 Identify unauthorized use of the information system.

NIST 800-171 SECURITY FAMILIES

(14 DERIVED FROM 800-53)

NIST 800-53 R4 SECURITY FAMILIES

Access Control Access Control
Awareness and Training Awareness and Training
Audit and Accountability Audit and Accountability
Configuration Management Configuration Management
(Not required by NIST 800-171) Contingency Planning
Identification and Authentication Identification and Authentication
Incident Response Incident Response
Maintenance Maintenance
Media Protection Media Protection
Personnel Security Personnel Security
Physical Protection Physical Protection and Environmental Protection
(Not required by NIST 800-171) Planning
(Not required by NIST 800-171) Program Management
Risk Assessment Risk Assessment
Security Assessment Security Assessment and Authorization
System and Communications Protection System and Communications Protection
System and Information Integrity System and Information Integrity
(Not required by NIST 800-171) System and Services Acquisitions

The development of the CUI security requirements and the expectation of federal agencies in working with nonfederal entities include:

  • Nonfederal organizations have information technology infrastructures in place, and are not necessarily developing or acquiring information systems specifically for the purpose of processing, storing, or transmitting CUI;
  • Nonfederal organizations have specific safeguarding measures in place to protect their information which may also be sufficient to satisfy the CUI security requirements;
  • Nonfederal organizations can implement a variety of potential security solutions either directly or through the use of managed services, to satisfy CUI security requirements; and
  • Nonfederal organizations may not have the necessary organizational structure or resources to satisfy every CUI security requirement and may implement alternative, but equally effective, security measures to compensate for the inability to satisfy a particular requirement.

We have a Program to assist Suppliers to the Federal Government with meeting the requirements for Compliance with Executive Order 13556 and NIST 800-171

Our professional services include assisting with:

  • Initial Risk Assessments for Controlled Unclassied Information (CUI)
  • Preparation of a CUI Security Plan and Statement of Applicability
  • Preparation of Policies, Procedures and Control Objectives
  • Personnel Awareness Training
  • Auditing for Compliance to NIST 800-171 and ISO 27001

Contact Us | Request a Proposal

ISO 27001 ISMS for Controlled Unclassified Information (CUI)

 Information Security Management for Controlled Unclassified Information (CUI)

Controlled Unclassified Information (CUI) supports federal missions and business functions that affect the economic and national security interests of the United States. Non-federal organizations (e.g. colleges, universities, state, local and tribal governments, federal contractors and subcontractors) often process, store, or transmit CUI.

Executive Order 13556, as issued November 10, 2010, designated the National Archives and Records Administration (NARA) as the Executive Agent to implement the CUI program. NIST Special Publication 800-171 defines the security requirements for protecting CUI in non-federal information systems and organizations.

Security Requirements for Protecting the Confidentiality of CUI

NIST Special Publication 800-171 contains fourteen families of security requirements (including basic and derived requirements) 18 for protecting the confidentiality of CUI in nonfederal information systems and organizations.

The security controls from NIST Special Publication 800-53 associated with the basic and derived requirements are also listed in Appendix D. Organizations can use Special Publication 800-53 to obtain additional, non-prescriptive information related to the CUI security requirements (e.g., supplemental guidance related to each of the referenced security controls, mapping tables to ISO/ IEC 27001 Information Security Management System (ISMS), Annex A (security objective & controls), and a catalog of optional controls that can be used to help specify additional CUI requirements if needed).

The security requirements identified in 800-171 are intended to be applied to the non-federal organization’s general-purpose internal information systems that are processing, storing, or transmitting CUI. Some specialized systems such as medical devices, Computer Numerical Control (CNC) machines, or industrial control systems may have restrictions or limitations on the application of certain CUI requirements and may be granted waivers or exemptions from the requirements by the federal agency providing oversight.

NIST 800-171 REQUIREMENTS

1 ACCESS CONTROL

Basic Security Requirements:

1.1 Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).

1.2 Limit information system access to the types of transactions and functions that authorized users are permitted to execute.

Derived Security Requirements:

1.3 Control the flow of CUI in accordance with approved authorizations.

1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion.

1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts.

1.6 Use non-privileged accounts or roles when accessing nonsecurity functions.

1.7 Prevent non-privileged users from executing privileged functions and audit the execution of such functions.

1.8 Limit unsuccessful logon attempts.

1.9 Provide privacy and security notices consistent with applicable CUI rules.

1.10 Use session lock with pattern-hiding displays to prevent access/viewing of data after period of inactivity.

1.11 Terminate (automatically) a user session after a defined condition.

1.12 Monitor and control remote access sessions.

1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.

1.14 Route remote access via managed access control points.

1.15 Authorize remote execution of privileged commands and remote access to security-relevant information.

1.16 Authorize wireless access prior to allowing such connections.

1.17 Protect wireless access using authentication and encryption.

1.18 Control connection of mobile devices.

1.19 Encrypt CUI on mobile devices.

1.20 Verify and control/limit connections to and use of external information systems.

1.21 Limit use of organizational portable storage devices on external information systems.

1.22 Control information posted or processed on publicly accessible information systems.

2 AWARENESS AND TRAINING

Basic Security Requirements:

2.1 Ensure that managers, systems administrators, and users of organizational information systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of organizational information systems.

2.2 Ensure that organizational personnel are adequately trained to carry out their assigned information security-related duties and responsibilities.

Derived Security Requirements:

2.3 Provide security awareness training on recognizing and reporting potential indicators of insider threat.

3 AUDIT AND ACCOUNTABILITY

Basic Security Requirements:

3.1 Create, protect, and retain information system audit records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful, unauthorized, or inappropriate information system activity.

3.2 Ensure that the actions of individual information system users can be uniquely traced to those users so they can be held accountable for their actions.

Derived Security Requirements:

3.3 Review and update audited events.

3.4 Alert in the event of an audit process failure.

3.5 Correlate audit review, analysis, and reporting processes for investigation and response to indications of inappropriate, suspicious, or unusual activity.

3.6 Provide audit reduction and report generation to support on-demand analysis and reporting.

3.7 Provide an information system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.

3.8 Protect audit information and audit tools from unauthorized access, modification, and deletion.

3.9 Limit management of audit functionality to a subset of privileged users.

4 CONFIGURATION MANAGEMENT

Basic Security Requirements:

4.1 Establish and maintain baseline configurations and inventories of organizational information systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.

4.2 Establish and enforce security configuration settings for information technology products employed in organizational information systems.

Derived Security Requirements:

4.3 Track, review, approve/disapprove, and audit changes to information systems.

4.4 Analyze the security impact of changes prior to implementation.

4.5 Define, document, approve, and enforce physical and logical access restrictions associated with changes to the information system.

4.6 Employ the principle of least functionality by configuring the information system to provide only essential capabilities.

4.7 Restrict, disable, and prevent the use of nonessential programs, functions, ports, protocols, and services.

4.8 Apply deny-by-exception (blacklist) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.

4.9 Control and monitor user-installed software.

5 IDENTIFICATION AND AUTHENTICATION

Basic Security Requirements:

5.1 Identify information system users, processes acting on behalf of users, or devices.

5.2 Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.

Derived Security Requirements:

5.3 Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.

5.4 Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.

5.5 Prevent reuse of identifiers for a defined period.

5.6 Disable identifiers after a defined period of inactivity.

5.7 Enforce a minimum password complexity and change of characters when new passwords are created.

5.8 Prohibit password reuse for a specified number of generations.

5.9 Allow temporary password use for system logons with an immediate change to a permanent password.

5.10 Store and transmit only encrypted representation of passwords.

5.11 Obscure feedback of authentication information.

6 INCIDENT RESPONSE

Basic Security Requirements:

6.1 Establish an operational incident-handling capability for organizational information systems that includes adequate preparation, detection, analysis, containment, recovery, and user response activities.

6.2 Track, document, and report incidents to appropriate officials and/or authorities both internal and external to the organization.

Derived Security Requirements:

6.3 Test the organizational incident response capability.

7 MAINTENANCE

Basic Security Requirements:

7.1 Perform maintenance on organizational information systems.24

7.2 Provide effective controls on the tools, techniques, mechanisms, and personnel used to conduct information system maintenance.

Derived Security Requirements:

7.3 Ensure equipment removed for off-site maintenance is sanitized of any CUI.

7.4 Check media containing diagnostic and test programs for malicious code before the media are used in the information system.

7.5 Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.

7.6 Supervise the maintenance activities of maintenance personnel without required access authorization.

8 MEDIA PROTECTION

Basic Security Requirements:

8.1 Protect (i.e., physically control and securely store) information system media containing CUI, both paper and digital.

8.2 Limit access to CUI on information system media to authorized users.

8.3 Sanitize or destroy information system media containing CUI before disposal or release for reuse.

Derived Security Requirements:

8.4 Mark media with necessary CUI markings and distribution limitations.25

8.5 Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas.

8.6 Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.

8.7 Control the use of removable media on information system components.

8.8 Prohibit the use of portable storage devices when such devices have no identifiable owner.

8.9 Protect the confidentiality of backup CUI at storage locations.

9 PERSONNEL SECURITY

Basic Security Requirements:

9.1 Screen individuals prior to authorizing access to information systems containing CUI.

9.2 Ensure that CUI and information systems containing CUI are protected during and after personnel actions such as terminations and transfers.

Derived Security Requirements: None.

10 PHYSICAL PROTECTION

Basic Security Requirements:

10.1 Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.

10.2 Protect and monitor the physical facility and support infrastructure for those information systems.

Derived Security Requirements:

10.3 Escort visitors and monitor visitor activity.

10.4 Maintain audit logs of physical access.

10.5 Control and manage physical access devices.

10.6 Enforce safeguarding measures for CUI at alternate work sites (e.g., telework sites).

11 RISK ASSESSMENT

Basic Security Requirements:

11.1 Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational information systems and the associated processing, storage, or transmission of CUI.

Derived Security Requirements:

11.2 Scan for vulnerabilities in the information system and applications periodically and when new vulnerabilities affecting the system are identified.

11.3 Remediate vulnerabilities in accordance with assessments of risk.

12 SECURITY ASSESSMENT

Basic Security Requirements:

12.1 Periodically assess the security controls in organizational information systems to determine if the controls are effective in their application.

12.2 Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational information systems.

12.3 Monitor information system security controls on an ongoing basis to ensure the continued effectiveness of the controls.

Derived Security Requirements: None.

13 SYSTEM AND COMMUNICATIONS PROTECTION

Basic Security Requirements:

13.1 Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.

13.2 Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational information systems.

Derived Security Requirements:

13.3 Separate user functionality from information system management functionality.

13.4 Prevent unauthorized and unintended information transfer via shared system resources.

13.5 Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.

13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).

13.7 Prevent remote devices from simultaneously establishing non-remote connections with the information system and communicating via some other connection to resources in external networks.

13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.

13.9 Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.

13.10 Establish and manage cryptographic keys for cryptography employed in the information system.

13.11 Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.

13.12 Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.

13.13 Control and monitor the use of mobile code.

13.14 Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.

13.15 Protect the authenticity of communications sessions.

13.16 Protect the confidentiality of CUI at rest.

14 SYSTEM AND INFORMATION INTEGRITY

Basic Security Requirements:

14.1 Identify, report, and correct information and information system flaws in a timely manner.

14.2 Provide protection from malicious code at appropriate locations within organizational information systems.

14.3 Monitor information system security alerts and advisories and take appropriate actions in response.

Derived Security Requirements:

14.4 Update malicious code protection mechanisms when new releases are available.

14.5 Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.

14.6 Monitor the information system including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.

14.7 Identify unauthorized use of the information system.

NIST 800-171 SECURITY FAMILIES

(14 DERIVED FROM 800-53)

NIST 800-53 R4 SECURITY FAMILIES

Access Control Access Control
Awareness and Training Awareness and Training
Audit and Accountability Audit and Accountability
Configuration Management Configuration Management
(Not required by NIST 800-171) Contingency Planning
Identification and Authentication Identification and Authentication
Incident Response Incident Response
Maintenance Maintenance
Media Protection Media Protection
Personnel Security Personnel Security
Physical Protection Physical Protection and Environmental Protection
(Not required by NIST 800-171) Planning
(Not required by NIST 800-171) Program Management
Risk Assessment Risk Assessment
Security Assessment Security Assessment and Authorization
System and Communications Protection System and Communications Protection
System and Information Integrity System and Information Integrity
(Not required by NIST 800-171) System and Services Acquisitions

The development of the CUI security requirements and the expectation of federal agencies in working with nonfederal entities include:

  • Nonfederal organizations have information technology infrastructures in place, and are not necessarily developing or acquiring information systems specifically for the purpose of processing, storing, or transmitting CUI;
  • Nonfederal organizations have specific safeguarding measures in place to protect their information which may also be sufficient to satisfy the CUI security requirements;
  • Nonfederal organizations can implement a variety of potential security solutions either directly or through the use of managed services, to satisfy CUI security requirements; and
  • Nonfederal organizations may not have the necessary organizational structure or resources to satisfy every CUI security requirement and may implement alternative, but equally effective, security measures to compensate for the inability to satisfy a particular requirement.

We have a Program to assist Suppliers to the Federal Government with meeting the requirements for Compliance with Executive Order 13556 and NIST 800-171

Our professional services include assisting with:

  • Initial Risk Assessments for Controlled Unclassied Information (CUI)
  • Preparation of a CUI Security Plan and Statement of Applicability
  • Preparation of Policies, Procedures and Control Objectives
  • Personnel Awareness Training
  • Auditing for Compliance to NIST 800-171 and ISO 27001

Contact Us | Request a Proposal

Could a well-designed ISO 27001 Information Security Management System save $1,700,000.00?

Alaska Medicaid Settles HIPAA Security Case for $1,700,000

The Alaska Department of Health and Social Services (DHSS), the State Medicaid agency, has agreed to pay the U.S. Department of Health and Human Services’ (HHS) $1,700,000 to settle potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule.  Alaska DHSS has also agreed to take corrective action to properly safeguard the electronic protected health information (ePHI) of their Medicaid beneficiaries.  This is OCR’s first HIPAA enforcement action of a State agency and we expect organizations to comply with their obligations under these rules regardless of whether they are private or public entities.

The HHS Office for Civil Rights (OCR) began its investigation following a breach report submitted by Alaska DHHS as required by the Health Information Technology for Economic and Clinical Health (HITECH) Act.  The report indicated that a portable electronic storage device (USB hard drive) possibly containing ePHI was stolen from the vehicle of a DHHS employee.  Over the course of the investigation, OCR found that DHHS did not have adequate policies and procedures in place to safeguard ePHI.  Further, DHHS had not completed a risk analysis, implemented sufficient risk management measures, completed security training for its workforce members, implemented device and media controls, or addressed device and media encryption as required by the HIPAA Security Rule.

In addition to the $1,700,000 settlement, the agreement includes a corrective action plan that requires Alaska DHHS to review, revise, and maintain policies and procedures to ensure compliance with HIPAA Security Rule.  A monitor will report back to OCR regularly on the State’s ongoing compliance efforts.

The HHS Resolution Agreement can be found on the OCR website at http://www.hhs.gov/ocr/privacy/hipaa/enforcement/examples/alaska-agreement.html

Could a well-designed ISO 27001 Information Security Management System save $1,700,000.00?