United States Department of Agriculture
Research, Education, and Economics

ARS * CSREES * ERS * NASS
Policies and Procedures

 

 

Title: ARS Information Systems Security Program
Number:  253.3-ARS
Date: August 19, 1998
Originating Office: Information Technology Division, Network Operations Branch, AFM/ARS
This Replaces: EMS 3200, dated 9/30/94
Distribution: ARS Headquarters, Areas, Locations

 

 

 

This P&P establishes the policy supporting program goals, and the assignment of responsibilities for the management, implementation, and operation of the ARS Information Systems Security Program.



Table of Contents

1. Authorities
2. Background
3. Applicability
4. Information Systems Security Program Objectives
5. Information Systems Security Program Elements
6. Policy
7. Summary of Responsibilities
     Senior Information Resources Management Officer (SIRMO):
     ISSP Officer
     Deputy Administrators, Associate Deputy Administrators, Headquarters Staffs, Administrative Financial Management (AFM) Divisions, and Area Directors
     Area Administrative Officers, With Assistance from Location Coordinators
     Area Deputy Security Officers
     Location Security Points of Contact
     All Users of Automated Information Systems
8. Glossary


 

1.    Authorities

The Privacy Act of 1974; Federal Managers Financial Integrity Act of 1983; PL 100-235, “The Computer Security Act of 1987;” OMB Circular A-130, Appendix III, “Security of Federal Automated Information Systems;” OMB Circular A-123, “Internal Control Systems;” OMB Circular A-127, “Financial Management Systems;” Departmental Regulation (DR) 3140-1, “USDA Information System Security (ISS) Policy.”

 

2.    Background

The use of distributed information systems to store, process, and communicate sensitive information and the integration of computer and telecommunication technologies have made information systems security more complex. The benefits of using this technology must be accompanied by the implementation of an information systems security program (ISSP) that reduces the associated security risks to an acceptable level.

 

3.    Applicability

The policies and associated information systems security standards and guidelines will apply to all ARS organizational elements and to other components of USDA having data resident on ARS computer systems. They also apply to all other personnel who have responsibility for operating automated information systems of ARS or who have access to ARS data or equipment.

 

4.    Information Systems Security Program Objectives

The objectives of the ARS ISSP are to:

 

5.    Information Systems Security Program Elements

The ISSP is a balanced combination of management and staff actions, operational activities, and technological control measures. The following ISSP elements will be addressed in more detail in the forthcoming ARS Information Systems Security Manual, 253.3-ARS:

 

6.    Policy

It is the policy of ARS to establish and maintain an effective ISSP that complies with applicable Federal and Department information systems security policies and addresses ARS requirements for confidentiality, integrity, and availability.

 

7.    Summary of Responsibilities

ARS information systems security responsibilities are implemented through, but not limited to, the following:

Senior Information Resources Management Officer (SIRMO):

ISSP Officer

Deputy Administrators, Associate Deputy Administrators, Headquarters Staffs, Administrative Financial Management (AFM) Divisions, and Area Directors

Area Administrative Officers, With Assistance from Location Coordinators

Area Deputy Security Officers

Location Security Points of Contact

All Users of Automated Information Systems

 

8.    Glossary

Accreditation. Authorization and approval of a certified automated information system to process sensitive data.

Administrative Security. The security discipline which focuses on those planning and procedural measures associated with the implementation and administration of the computer security program.

ARS Security Requirements Committee. An ad hoc Information Security Committee designated by the SIRMO and determined by the security matter being addressed.

Automated Information System. The organized combination of ADP equipment, software, and established methods and procedures designed to collect, process, and communicate data or information supporting specific administrative, mission, or program requirements. This includes application systems, databases, and management information systems.

Automated Information Systems Security. The managerial, technical, and physical safeguards used to ensure the confidentiality, integrity, and availability of sensitive information processed by or transmitted through Federal automated information systems.

Certification. Technical evaluation of automated information systems, made as part of and in support of the accreditation process, that establishes the extent to which a particular automated information system or network design and implementation meet pre-specified security requirements.

Communications Security. The security implemented to ensure that only authorized users are able to access the system from a remote location.

Confidentiality. Ensuring that sensitive information is kept private and is accessible only by authorized personnel who have a need to know.

Data. A representation of facts, concepts, or instructions in a formalized manner suitable for communication, interpretation, or processing by manual or automated means.

Equipment Security. The security of the hardware components of a system.

ID. User Identification Code

Information. Any communication or representation of knowledge such as facts, data, or opinions, including numerical, graphic, or narrative maintained in any medium or form, including computerized databases, paper, microfilm, or magnetic tape.

Information System. The organized collection, processing, maintenance, transmission, and dissemination of information in accordance with defined procedures.

IRM. Information Resources Management

ISSP. Information Systems Security Program

ITD. Information Technology Division

NFC. National Finance Center

NITC. National Information Technology Center

OMB. Office of Management and Budget

Personnel Security. The procedures established to ensure that all personnel who have access to sensitive information have the required authorities and clearance.

Physical Security. Procedures required for the protection of the structures housing automated information systems and related equipment from damage by accident, fire, or environmental hazards.

Risk Analysis. An evaluation of automated information systems assets and vulnerabilities to establish an expected loss from certain events based on estimated probabilities of the occurrence of these events. Identifies potential threats and their probability of occurrence and proposes safeguards to combat these threats.

Risk Management. The total process to identify, control, and minimize the impact of uncertain events. The process facilitates the management of security risks by each level of management throughout the system life cycle. The approval process consists of three elements: risk analysis, certification, and approval.

Sensitive Information. Information that requires protection because of the risk and magnitude of loss or harm that could result from inadvertent or deliberate disclosure, alteration, or destruction of the information. The term includes information whose improper use or disclosure could adversely affect proprietary data, the ability of an agency to accomplish its mission, records about individuals requiring protection under the Privacy Act, and information not releasable under the Freedom of Information Act.

SIRMO. Senior Information Resources Management Officer. The designated official responsible for carrying out the IRM functions assigned to the Agency by the Paperwork Reduction Act. The Director of ITD is designated as the ARS SIRMO.

Software and Data Security. The security of operating systems software, applications software, and database files and the information they contain.

    /s/

FLOYD P. HORN
Administrator
Agricultural Research Service