36 MAC Pt. 1, R. 15.1

Cybersecurity Assessments

Year: 2026Length: 1,041 wordsOfficial source

Cite as 36 Miss. Admin. Code Pt. 1, R. 15.1

Cybersecurity Assessments A. Each agency must conduct a comprehensive cybersecurity assessment at least once every two years to evaluate the security controls in agency systems to determine if the controls are effective in their application and to identify the current security posture of its information systems and the agency. Cybersecurity assessments must also include external parties, including, but not limited to, service providers, contractors/third parties, etc. who operate systems on behalf of the agency and/or process, store, or transmit information on behalf of the agency. 1. Each agency must employ an ITS-approved independent, impartial third-party provider to conduct the comprehensive cybersecurity assessment. Comprehensive cybersecurity assessments must include at minimum the below and should be modeled from all guidelines specified in the Comprehensive Cybersecurity Assessment Guidelines document that can be found on the ITS website. i. Perform an assessment of the security controls in the information systems and their environment of operation to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting established security requirements. ii. Incorporate results from other types of assessment activities such as vulnerability scanning and system monitoring, to maintain the security and privacy posture of systems during the system life cycle. iii. Perform external and internal penetration tests to identify vulnerabilities and attack vectors that can be used to exploit agency systems. a. Penetration testing must be appropriate to the size, complexity, and maturity of the agency environment. Penetration testing activities include scope, such as network, web application, Application Programming Interface (API), hosted services, and physical premise control. 1. Cloud-based services which are identified as a component of agency business functionality must be included in Security Assessments. This includes cloud- based backup solutions, user access control platforms (e.g. Microsoft 365), file-sharing and storage platforms (e.g. SharePoint, Box), and other Content Management Systems (e.g. AWS, Akamai). b. Penetration testing must occur from outside the agency’s network perimeter (i.e., outside the agency's firewall but inside the Enterprise State Network’s security border) as well as from within the agency’s boundaries (i.e., on the internal agency network) to simulate both outsider and insider attacks. Penetration testing helps determine the minimum set of controls required to reduce and maintain risk at an acceptable level. c. Control and monitor any user or system accounts that are used to simulate both outsider and insider attacks to ensure they are only being used for legitimate purposes and are removed or restored to normal function after testing is completed. d. Validate security measures after each penetration test. If deemed necessary, modify rulesets and capabilities to detect the techniques used during testing. e. Validated vulnerabilities discovered during the penetration tests must be documented and mitigated in a timely manner. 1. Vulnerabilities should be prioritized based on the criticality of both the vulnerability and the system/application. f. Penetration tests should include a full scope of blended attacks, such as wireless, client-based, and web application attacks. g. Agencies which develop in-house applications that have a defined development cycle will create a test bed that mimics a production environment for specific penetration tests attacks against elements that are not typically tested in production, such as attacks against supervisory control and data acquisition and other control systems. iv. Perform social engineering training campaigns and simulated threats to assess the security posture and employee adherence to established security policies and practices. This may include either email phishing, voice vishing, or a combination of both attacks. Testing should not be designed to target a specific person, but rather target the corporate culture, to include all agency staff. v. Cybersecurity assessments must include applications to ensure key security and privacy requirements are met. Code in the application and supporting infrastructure must be tested for common errors that can compromise the integrity of the production environment when the application is deployed. a. ITS recommends that all new applications have a comprehensive assessment performed by a third-party prior to its release into a production environment. vi. ITS recommends performing advanced persistent threat (APT) assessments to identify weaknesses that could be used in a targeted and/or advanced attack. The goal of an APT is to gain access, escalate privileges, and remain hidden so as to exfiltrate sensitive data. This type of assessment includes a higher level of agency reconnaissance, a more prolonged period of engagement to facilitate a deeper understanding of more complicated attack possibilities, and many times utilizes social engineering. Further, ITS recommends periodically assessing the current environment for indications of an incident such a breach. vii. ITS recommends including tests for the presence of overly permissive network resources which are used to share data. This includes assessment of Access Control Lists and the storage of data in network shares which is identified as sensitive. This may include information and artifacts that would be useful to attackers, including network diagrams, configuration files, older penetration test reports, and backups of emails or documents containing passwords or other information critical to system operation. B. Each agency must develop and implement a plan of action and milestones to document the planned remedial actions to correct weaknesses or deficiencies and reduce or eliminate known vulnerabilities in agency systems. 1. Update plan of action and milestones based on findings from ongoing assessments, audits or reviews, and continuous monitoring activities. C. Each agency must submit all cybersecurity assessment reporting deliverables to ITS. Reporting requirements are included in the Cybersecurity Assessment Reporting Guidelines which can be found on the ITS website. All reporting deliverables from the cybersecurity assessment must be submitted within 90 days of its completion. D. Each agency must monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls. 1. Continuous monitoring efforts facilitate ongoing awareness of threats, vulnerabilities, and information security to support agency risk management decisions. 2. Additional cybersecurity assessments should be performed when there are significant changes to information systems and their environment of operation, new threats and vulnerabilities are identified, or other conditions occur that may impact the security state of the system or its environment. E. Each agency must develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.
36 MAC Pt. 1, R. 15.1: Cybersecurity Assessments | Justis AI