36 MAC Pt. 1, R. 14.1
Risk Assessments
Cite as 36 Miss. Admin. Code Pt. 1, R. 14.1
Risk Assessments
A. Each agency must periodically assess the risk to agency operations resulting from the
operation of agency systems and the associated processing, storage, or transmission
of data.
B. Each agency must conduct a risk assessment that considers threats, vulnerabilities,
likelihood, and impact to agency operations and assets, individuals, other
organizations, and state government.
1. Identify threats and vulnerabilities to agency systems.
i.
An inventory of all hardware, software, and user access must be
established and maintained as an agency experiences any substantive
change. Please refer to Part 1, Chapter 2, 2.1 System and Physical
Device Inventory.
2. Identify threats and vulnerabilities from third parties, including, but not
limited to, third parties who operate systems on behalf of the agency and/or
process, store, or transmit information on behalf of the agency.
i.
Identify all third parties which provide functionality to the
organization via either hardware or software. Agencies will inventory
and document the data and network resource access that all third
parties are provided access.
ii.
Determine the sensitivity of data that each third party is provided
access to and incorporate said access into its risk assessment.
iii.
Define the legal and regulatory standards that the data accessible to the
third party is subject to and establish contracts or other Service Level
Agreements to describe the ability and expectation of the vendor to
satisfy the applicable standard.
iv.
Monitor and ensure (to the extent possible) that the third party meets
the expectations of any agreement or contractual obligation regarding
information security and/or privacy.
3. Determine the likelihood and magnitude of harm from unauthorized access,
use, disclosure, disruption, modification, loss, or destruction of/to the system
and/or the information it processes, stores, or transmits, and any related
information.
4. Determine the likelihood and impact of adverse effects on individuals arising
from the collection and/or processing of personally identifiable information
(PII).
i.
ITS recommends agencies conduct privacy impact and/or privacy risk
assessments to help determine the likelihood and impact of adverse
effects for PII. A privacy risk and/or privacy impact assessment
evaluates the risks, controls, and consequences associated with
collecting, maintaining, using, and/or disclosing personally identifiable
information (within and outside of the agency) so that the agency can
make informed decisions regarding risk mitigation, protection of the
data, and compliance with applicable legal requirements and best
practices.
5. Integrate risk assessment results and risk management decisions from the
agency and mission or business process perspectives with system-level risk
assessments.
6. Document risk assessment results in appropriate agency security and privacy
plans.
7. Respond to findings from security and privacy assessments, monitoring, and
audits in accordance with agency risk tolerance and update the risk assessment
as needed.
8. Review and update the risk assessment, as needed, in accordance with agency
risk tolerance based on security and privacy assessments, monitoring, and
audits; supply chain issues; security incidents or breaches; changes in law,
executive orders, directives, regulations, policies, standards, or guidelines; and
changes to and/or availability of new technologies, individuals, external
parties, and assets in accordance with agency risk tolerance.
C. Each agency must perform automated vulnerability scans for vulnerabilities in agency
systems and applications periodically and when new vulnerabilities affecting those
systems and applications are identified.
1. Perform automated vulnerability scans of internal agency assets on a monthly,
or more frequent, basis. Conduct both authenticated and unauthenticated
scans, using a SCAP-compliant vulnerability scanning tool. The agency must
maintain the results of vulnerability scans for a period of at least one year.
2. Perform automated vulnerability scans of externally exposed agency assets
using a SCAP-compliant vulnerability scanning tool. Perform scans on a
monthly, or more frequent, basis. The agency must maintain the results of
vulnerability scans for a period of at least one year.
D. Each agency must remediate detected vulnerabilities on a monthly, or more frequent,
basis, based on the remediation process.