08.11.2012 Views

Evaluation of Department of State Information Security Program ...

Evaluation of Department of State Information Security Program ...

Evaluation of Department of State Information Security Program ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

UNCLASSIFIED<br />

Appendix C. Systems With Invalid Authority To Operate<br />

As part <strong>of</strong> the security authorization testing, we requested the most recent authorities to<br />

operate (ATOs) for the sample <strong>of</strong> 30 systems. The ATO is the final security authorization<br />

decision from the designated authorizing <strong>of</strong>ficial to the information system. Per National<br />

Institute <strong>of</strong> Standards and Technology Special Publication 800-37, 1 the authorization decision<br />

document contains the following information: authorization decision, terms and conditions for<br />

the authorization, and authorization termination date.<br />

Table 1. Systems With Invalid Authority To Operate<br />

Bureau Name Package Type FIPS<br />

Name No. Categorization<br />

EUR EXTRANET 1140 UNCL L<br />

IO USEVI 2412 UNCL L<br />

IRM TEDS 593 CL H<br />

IRM WINAD 633 UNCL M<br />

IRM TDS 719 CL H<br />

IRM WebPASS 744 UNCL M<br />

IRM SMART-C 2744 CL H<br />

L IDMAS 647 UNCL H<br />

IRM OpenNet 633 UNCL M<br />

IRM ClassNet 631 CL H<br />

Legend<br />

Bureaus System Classification and<br />

Categorization<br />

EUR-Bureau <strong>of</strong> European Affairs CL- Classified Network<br />

IO-Bureau <strong>of</strong> International Organization Affairs UNCL- Unclassified Network<br />

IRM- Bureau <strong>of</strong> <strong>Information</strong> Resource Management H- High Impact<br />

L- Office <strong>of</strong> the Legal Advisor M- Moderate Impact<br />

1<br />

NIST SP 800-37, Guide for Applying the Risk Management Framework to Federal <strong>Information</strong> Systems, Feb<br />

2010<br />

47<br />

UNCLASSIFIED

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!