08.11.2012 Views

Evaluation of Department of State Information Security Program ...

Evaluation of Department of State Information Security Program ...

Evaluation of Department of State Information Security Program ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

UNCLASSIFIED<br />

6<br />

<strong>Department</strong> Response to Recommendation 5:<br />

The <strong>Department</strong> agrees with this recommendation because the condition <strong>of</strong> not tracking<br />

(individually) those who need role-based training creates undue risk for the <strong>Department</strong>.<br />

The <strong>Department</strong> will develop a method <strong>of</strong> tracking <strong>of</strong> who needs and who has received<br />

role-based training; comparable to what is available for awareness training (including risk<br />

scoring in iPost).<br />

Recommendation 6: {Section C} We recommend that the Chief <strong>Information</strong> Officer<br />

implement, for <strong>Security</strong> Awareness Training, automated methods to replace the current manual<br />

process to track and enforce the <strong>Department</strong> <strong>of</strong> <strong>State</strong> security awareness policy and to suspend a<br />

user's access to the network if the user has not taken the Cyber <strong>Security</strong> Awareness course<br />

within the required timeframe in accordance with the <strong>Information</strong> Assurance Training Plan.<br />

<strong>Department</strong> Response to Recommendation 6:<br />

The <strong>Department</strong> has conducted a preliminary study <strong>of</strong> compliance with annual<br />

completion <strong>of</strong> the PS-800 training course. These preliminary findings show nearly 100%<br />

<strong>of</strong> those who require training receive training within 30 days <strong>of</strong> the due date. The<br />

<strong>Department</strong> does not consider this level <strong>of</strong> non-compliance to be a material risk to the<br />

security <strong>of</strong> the <strong>Department</strong>.<br />

This is especially true, considering there are several other sources <strong>of</strong> awareness training<br />

including the daily awareness program at login, as well as weekly and quarterly sources.<br />

The OIG proposal to automatically suspend account access (without human intervention)<br />

has a high risk <strong>of</strong> creating serious denial-<strong>of</strong>-service issues and as such, itself poses risks<br />

to the security <strong>of</strong> the <strong>Department</strong>.<br />

The <strong>Department</strong> will conduct a complete assessment <strong>of</strong> compliance in this area and take<br />

appropriate action if a material level <strong>of</strong> non-compliance is indicated.<br />

Recommendation 7: {Section D} We recommend that the Chief <strong>Information</strong> Officer:<br />

• Implement a Plan <strong>of</strong> Action and Milestones (POA&M) tracking process for all ClassNet<br />

security weaknesses as required by Committee on National <strong>Security</strong> Systems Policy<br />

Number 22, <strong>Information</strong> Assurance Risk Management Policy for National <strong>Security</strong><br />

Systems. 13<br />

• Distribute the quarterly POA&M Grade Memorandums to the bureaus' and <strong>of</strong>fices'<br />

senior management (executive director) as required by M-04-25, FY 2004 Reporting<br />

Instructions for the Federal <strong>Information</strong> <strong>Security</strong> Management Act.<br />

13 With regard to POA&Ms this source states "Require a formal Enterprise-level Plan <strong>of</strong> Actions and Milestones<br />

(POA&M) containing: (i) systemic information system and organizational security weaknesses and deficiencies; (ii)<br />

risks relating to the identified weaknesses and deficiencies requiring further mitigation; and (iii) specific actions to<br />

mitigate identified risks." The <strong>Department</strong> believes that our POA&M process for ClassNet meets these<br />

requirements in all material regards.<br />

UNCLASSIFIED<br />

67<br />

UNCLASSIFIED

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!