36 MAC Pt. 1, R. 15.1
Cybersecurity Assessments
Cite as 36 Miss. Admin. Code Pt. 1, R. 15.1
Cybersecurity Assessments
A. Each agency must conduct a comprehensive cybersecurity assessment at least once
every two years to evaluate the security controls in agency systems to determine if the
controls are effective in their application and to identify the current security posture
of its information systems and the agency. Cybersecurity assessments must also
include external parties, including, but not limited to, service providers,
contractors/third parties, etc. who operate systems on behalf of the agency and/or
process, store, or transmit information on behalf of the agency.
1. Each agency must employ an ITS-approved independent, impartial third-party
provider to conduct the comprehensive cybersecurity assessment.
Comprehensive cybersecurity assessments must include at minimum the
below and should be modeled from all guidelines specified in the
Comprehensive Cybersecurity Assessment Guidelines document that can be
found on the ITS website.
i. Perform an assessment of the security controls in the information
systems and their environment of operation to determine the extent to
which the controls are implemented correctly, operating as intended,
and producing the desired outcome with respect to meeting established
security requirements.
ii. Incorporate results from other types of assessment activities such as
vulnerability scanning and system monitoring, to maintain the security
and privacy posture of systems during the system life cycle.
iii. Perform external and internal penetration tests to identify
vulnerabilities and attack vectors that can be used to exploit agency
systems.
a. Penetration testing must be appropriate to the size, complexity,
and maturity of the agency environment. Penetration testing
activities include scope, such as network, web application,
Application Programming Interface (API), hosted services, and
physical premise control.
1. Cloud-based services which are identified as a
component of agency business functionality must be
included in Security Assessments. This includes cloud-
based backup solutions, user access control platforms
(e.g. Microsoft 365), file-sharing and storage platforms
(e.g. SharePoint, Box), and other Content Management
Systems (e.g. AWS, Akamai).
b. Penetration testing must occur from outside the agency’s
network perimeter (i.e., outside the agency's firewall but inside
the Enterprise State Network’s security border) as well as from
within the agency’s boundaries (i.e., on the internal agency
network) to simulate both outsider and insider attacks.
Penetration testing helps determine the minimum set of
controls required to reduce and maintain risk at an acceptable
level.
c. Control and monitor any user or system accounts that are used
to simulate both outsider and insider attacks to ensure they are
only being used for legitimate purposes and are removed or
restored to normal function after testing is completed.
d. Validate security measures after each penetration test. If
deemed necessary, modify rulesets and capabilities to detect
the techniques used during testing.
e. Validated vulnerabilities discovered during the penetration
tests must be documented and mitigated in a timely manner.
1. Vulnerabilities should be prioritized based on the
criticality of both the vulnerability and the
system/application.
f. Penetration tests should include a full scope of blended attacks,
such as wireless, client-based, and web application attacks.
g. Agencies which develop in-house applications that have a
defined development cycle will create a test bed that mimics a
production environment for specific penetration tests attacks
against elements that are not typically tested in production,
such as attacks against supervisory control and data acquisition
and other control systems.
iv. Perform social engineering training campaigns and simulated threats to
assess the security posture and employee adherence to established
security policies and practices. This may include either email phishing,
voice vishing, or a combination of both attacks. Testing should not be
designed to target a specific person, but rather target the corporate
culture, to include all agency staff.
v. Cybersecurity assessments must include applications to ensure key
security and privacy requirements are met. Code in the application and
supporting infrastructure must be tested for common errors that can
compromise the integrity of the production environment when the
application is deployed.
a. ITS recommends that all new applications have a
comprehensive assessment performed by a third-party prior to
its release into a production environment.
vi. ITS recommends performing advanced persistent threat (APT)
assessments to identify weaknesses that could be used in a targeted
and/or advanced attack. The goal of an APT is to gain access, escalate
privileges, and remain hidden so as to exfiltrate sensitive data. This
type of assessment includes a higher level of agency reconnaissance, a
more prolonged period of engagement to facilitate a deeper
understanding of more complicated attack possibilities, and many
times utilizes social engineering. Further, ITS recommends
periodically assessing the current environment for indications of an
incident such a breach.
vii. ITS recommends including tests for the presence of overly permissive
network resources which are used to share data. This includes
assessment of Access Control Lists and the storage of data in network
shares which is identified as sensitive. This may include information
and artifacts that would be useful to attackers, including network
diagrams, configuration files, older penetration test reports, and
backups of emails or documents containing passwords or other
information critical to system operation.
B. Each agency must develop and implement a plan of action and milestones to
document the planned remedial actions to correct weaknesses or deficiencies and
reduce or eliminate known vulnerabilities in agency systems.
1. Update plan of action and milestones based on findings from ongoing
assessments, audits or reviews, and continuous monitoring activities.
C. Each agency must submit all cybersecurity assessment reporting deliverables to ITS.
Reporting requirements are included in the Cybersecurity Assessment Reporting
Guidelines which can be found on the ITS website. All reporting deliverables from
the cybersecurity assessment must be submitted within 90 days of its completion.
D. Each agency must monitor security controls on an ongoing basis to ensure the
continued effectiveness of the controls.
1. Continuous monitoring efforts facilitate ongoing awareness of threats,
vulnerabilities, and information security to support agency risk management
decisions.
2. Additional cybersecurity assessments should be performed when there are
significant changes to information systems and their environment of
operation, new threats and vulnerabilities are identified, or other conditions
occur that may impact the security state of the system or its environment.
E. Each agency must develop, document, and periodically update system security plans
that describe system boundaries, system environments of operation, how security
requirements are implemented, and the relationships with or connections to other
systems.