Information Security Acceptable Risk Safeguards Manual (Pub. 100-25), § 50.2.8

Assurance

Last amended: 2014Year: 2014Length: 957 wordsOfficial source
50.2.8-Assurance (Rev.2, Issued: 03-07-14, Effective: 04-07-14, Implementation: 03-09-15, October 6, 2014- VMS to Implement the Client Letter Work) Two fundamental components affecting the trustworthiness of information systems are security functionality and security assurance. Security functionality is typically defined in terms of the security features, functions, mechanisms, services, procedures, and architectures implemented within organizational information systems or the environments in which those systems operate. Security assurance is the measure of confidence that the security functionality is implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system—thus possessing the capability to accurately mediate and enforce established security policies. Security controls address both security functionality and security assurance. Some controls focus primarily on security functionality (e.g., PE-3, Physical Access Control; IA-2, Identification and Authentication; SC-13, Cryptographic Protection; AC-2, Account Management). Other controls focus primarily on security assurance (e.g., CA-2, Security Assessment; SA-17, Developer Security Architecture and Design; CM-3, Configuration Change Control). Finally, certain security controls can support security functionality and assurance (e.g., RA-5, Vulnerability Scanning; SC-3, Security Function Isolation; AC-25, Reference Monitor). Security controls related to functionality are combined to develop a security capability with the assurance-related controls implemented to provide a degree of confidence in the capability within the organizational risk tolerance. The CMSRs specify assurance-related controls with an “A” in the controls header to identify the security controls that have assurance-related characteristics or properties (i.e., assurance- related controls). Assurance-related controls are discussed in greater detail in NIST SP 800-53 (as amended), Appendix E, Assurance and Trustworthiness, to include the allocation of such controls to security control baselines. There is no summary table provided in the NIST SP 800-53 Appendix E for the Program Management (PM) family or the Privacy families since PM and Privacy controls are not associated with any particular security control baseline. 50.3 Assessment Procedures (Rev.2, Issued: 03-07-14, Effective: 04-07-14, Implementation: 03-09-15, October 6, 2014- VMS to Implement the Client Letter Work) The Assessment Procedures, including Assessment Objectives, and Assessment Methods and Objects, help determine if the security control implementations in the information system are effective (i.e., implemented correctly, operating as intended, and producing the desired outcome). They provide a foundation to support the security assessment and authorization process. The Assessment Procedure consists of a set of procedural steps that are designated to achieve one or more objectives by applying methods to assessment objects. CMS Information Security (IS) Acceptable Risk Safeguards (ARS) Page 14 50.3.1 Assessment Objective (Rev.2, Issued: 03-07-14, Effective: 04-07-14, Implementation: 03-09-15, October 6, 2014- VMS to Implement the Client Letter Work) The Assessment Objectives include a set of determination statements (“Determine if…”) related to the particular security control under assessment. The determination statements are closely linked to the content of the security control (i.e., the security control functionality) to ensure traceability of assessment results back to the fundamental control requirements. Assessment Objectives establish the expectations for security control assessments based on the assurance requirements defined in the security control. The assessment expectations provide assessors with important reference points for the level of assurance (i.e., grounds for confidence) needed for the determination of security control effectiveness. Each of the Assessment Objective determination statements is either traceable to requirements within the baseline or enhancement security control. This ensures that all aspects of the security control are fully assessed and that any weaknesses or deficiencies in the control can be identified, and corrective actions taken (usually in the form of a Plan of Actions and Milestones [POA&M]). 50.3.2 Assessment Methods and Objects (Rev.2, Issued: 03-07-14, Effective: 04-07-14, Implementation: 03-09-15, October 6, 2014- VMS to Implement the Client Letter Work) The assessment methods define the nature of the assessor’s actions and include Examine, Interview, and Test. The assessment object identifies the specific item being assessed including specifications, mechanism, activities, and individuals. The application of an assessment procedure to a security control produces assessment findings. These assessment findings are subsequently used in helping to determine the overall effectiveness of the control. 60.0 References (Rev.2, Issued: 03-07-14, Effective: 04-07-14, Implementation: 03-09-15, October 6, 2014- VMS to Implement the Client Letter Work) The CMS information security and privacy assurance program and ARS were developed in accordance with Federal mandates and CMS requirements for the handling and processing of CMS’ information and information systems. A list of applicable laws across the program is provided below: • Public Law 74-271, Social Security Act, as amended http://www.ssa.gov/OP_Home/ssact/ssact.htm. • Public Law 93-579, The Privacy Act of 1974, as amended http://www.justice.gov/opcl/privstat.htm CMS Information Security (IS) Acceptable Risk Safeguards (ARS) Page 15 • Public Law 104-13, Paperwork Reduction Act of 1995, as amended http://www.fws.gov/policy/library/rgpl104-13.pdf • Public Law 108–173, Medicare Prescription Drug, Improvement, and Modernization Act of 2003 (MMA), SEC. 912: Requirements for Information Security for Medicare Administrative Contractors http://www.gpo.gov/fdsys/pkg/BILLS-108hr1enr/pdf/BILLS-108hr1enr.pdf • Code of Federal Regulations (CFR), Regulation 5 CFR Part 731 – Suitability, http://ecfr.gpoaccess.gov/cgi/t/text/text- idx?c=ecfr&rgn=div5&view=text&node=5:2.0.1.1.7&idno=5 • United States Code Title 44 Chapter 33—Disposal of Records http://www.archives.gov/about/laws/disposal-of-records.html • GAO-09-232G, Federal Information System Controls Audit Manual (FISCAM), February 2, 2009 http://www.gao.gov/new.items/d09232g.pdf • OMB Circulars can be found at the CMS web site or at: http://www.whitehouse.gov/omb/circulars/index.html • Homeland Security Presidential Directives can be found at: http://www.dhs.gov/xabout/laws/. • Executive Orders can be found at: http://www.archives.gov/federal-register/executive-orders/disposition.html • A list of NIST special publications and FIPS publications can be found at: http://csrc.nist.gov/publications/ • The most recent Internal Revenue Service publication 1075 can be found at: http://www.irs.gov/pub/irs-pdf/p1075.pdf • HHS-OCIO Policy for Information Systems Security and Privacy, dated July 7, 2011 http://www.hhs.gov/ocio/policy/index.html#Security • HHS-OCIO Policy for Information Systems Security and Privacy Handbook, dated July 7, 2011 (available upon request via mailto:ciso@cms.hhs.gov) Additional CMS documents were used as references in the development of this manual. The CMS information security web site at http://www.cms.gov/Research-Statistics-Data-and- Systems/CMS-Information-Technology/InformationSecurity/ provides a list of applicable CMS documents across the information assurance program.
Information Security Acceptable Risk Safeguards Manual (Pub. 100-25), § 50.2.8: Assurance | Justis AI