|
|
|
| |
Water Resources Discipline |
From: |
Garry E. Neverdon 07/30/2003 08:15 AM |
To: |
WRD System Administrators |
cc: |
Katherine Lins/WRD/USGS/DOI@USGS |
Subject: | Security Information Update for WRD System Administrators |
To: WRD System Administrators
From: Garry Neverdon, Chief, System Support Unit, DIS Program Office
Subject: Security Information Update for WRD System Administrators
This memorandum will provide information on Information Technology (IT) security issues and answer some frequently asked questions concerning security activities within the U.S. Geological Survey (USGS). In order to put a framework around recent IT security activities, on December 17, 2002, the President signed into law the E-Government Act (P.L. 107-347) which includes Title III, the Federal Information Security Management Act (FISMA). This Act permanently reauthorized the framework laid out in the Government Information Security Reform Act of 2000 (GISRA), which expired in November 2002.
In addition to annual reporting of security activities as they relate to Federal programs, FISMA includes new provisions aimed at further strengthening the security of the Federal government.s information and information systems, such as the development of minimum standards for agency systems. These standards are provided by the National Institute of Standards and Technology (NIST) and the National Security Agency (NSA). In accordance with NIST/NSA guidance, NT TAC created security template configurations for Microsoft Windows 2000 and XP operating systems which are available at: http://nttac.usgs.gov/index.asp?url=os/xp/xppro/post/xptemplate.html
FISMA directly associates program funding with a requirement for an annual agency report to OMB on program security. Therefore, the amount of funding received will depend on achieving the correct level of security within the mission program. In addition, FISMA requires OMB to report to Congress on the security status of each agency, which would include all programs. As part of the reporting activity, USGS is required to provide set of security documents, using NIST guidelines, for each mission program. The security weaknesses identified in those documents are outlined in a plan of actions and milestones (POA&M) report. The Department of Interior requires and update to this report monthly, describing the security improvements made for each mission application. As you know, NWIS is identified as a USGS mission application and each NWIS site is required to complete their portion of the NWIS Security Plan documentation, by the deadline of August 30, 2003, to address all outstanding security issues.
As defined in FISMA, .information security. means protecting information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide: Integrity, which means guarding against improper information modification or destruction, and includes ensuring information non-repudiation and authenticity; Confidentiality, which means preserving authorized restrictions on access and disclosure, including means for protecting personal privacy and proprietary information; and Availability, which means ensuring timely and reliable access to and use of information."
In addition to FISMA, general security direction found in OMB Circular A-130, the Computer Security Act of 1987 and others, define in detail, the best practices for information security within the Federal government.
Frequently Asked Questions (FAQ)
How are we affected by Department of Homeland Security (DHS) guidance
regarding how to adjust operations for the different threat advisory
levels?
To date, we have not received specific guidance from DHS on IT
security as it corresponds to various threat levels. However, the
Federal Computer Incident Response Center (FedCIRC) is a DHS agency,
which provides general computer security information online at
http://www.fedcirc.gov
A DMZ to Protect Public Access Hosts?
A demilitarized zone (DMZ)
is a safe zone between the public and the internal network that provides
containment in the event that the public server is compromised. DOI
requires a DMZ for publicly accessed computers. Essentially, this means
that any publicly accessed system (ftp server, web server, etc.) will
have to be segregated from science center local area networks by use of
a firewall. DOI accepted the USGS request to use Cisco routers with
firewall software.
Servers accessed via SSH or USGS VPN solutions from the Internet are not considered publicly accessible. Cooperator access to servers using SSH has been approved by the BITSM as long as the Memorandum of Understanding addresses the need for secure cooperator devices.
DOI/SAIC/KPMG Security Audits and Scans?
There are two vendors
charged with scanning the USGS networks, SAIC and KPMG. SAIC is working
with the DOI Chief Information Officer in an effort to improve overall
IT security at each bureau. As a result of the last SAIC scan, a very
small percentage of the Bureau.s computer systems were identified as
potentially vulnerable. KPMG is working with the Office of the Inspector
General (OIG) to audit the USGS financial system processes, which
includes IT security.
Are Continuity of Operations (COO) Plans required?
All science
centers must have a COO plan. A COO plan is a required document, which
details how a science center will react to an emergency in order to
maintain service to the public. It includes such things as names and
home phone numbers for people responsible for operating and/or
recovering mission critical computer systems, databases, receivers,
communications lines, and the like. It also includes information on
alternate/emergency office locations and back-up systems. NIST special
publication 800-34 Contingency Planning Guide for Information Technology
Systems provides a template for creating this document, which is located
at http://csrc.nist.gov/publications/nistpubs/index.html
Are Microsoft Software Update Services (SUS) needed?
Currently,
when a critical patch, recommended patch, or updated driver is made
available by Microsoft (via http://windowsupdate.microsoft.com),
some system administrators download and install them on each workstation
and server, as appropriate. Often, these patches exceed 10 MB each, and
it isn.t unusual for Microsoft to post one or more new patches per week.
Hence, downloading patches to each machine, in every science center
affects the Bureau.s network performance by increasing traffic through
the Internet portals. A Microsoft SUS server provides one download
point for Microsoft patches, which in turn, will update other computers
in the network. SUS documentation and instructions can be found at http://nttac.usgs.gov/index.asp?url=security/tools/mssus/microsoft_SUS.htm
In order to remove most patch-related traffic from the Bureau's Internet portals and wide-area network, Sam Martinez and Scott McEwen have proposed installing and managing SUS servers in each region. The Central Region is currently testing the concept, and early results are promising.
Move Web Resources to NatWeb?
As per ITAC and Office of Information
guidance, the use of NatWeb will remove the need for science centers to
serve web information to the public and provide a secure and reliable
solution to present web content. Additional information on NatWeb can
be found at http://natweb.usgs.gov/
Why am I involved with the NWIS Security Plan?
The Office of
Management and Budget (OMB) has classified NWIS as an information
technology major application system. As such, NWIS is required to
annually submit an Exhibit 300 business case to OMB for approval in
order to expend funds. Each Exhibit 300 is scored and IT systems not
receiving an adequate score are placed at risk. In order to achieve an
adequate score, the IT system must be Certified and Accredited (C&A) as
required under OMB Circular A-130. Each NWIS site maintains the
distributed responsibility for providing security to the NWIS
application.
Are wireless networks safe?
Wireless local area networks (WLAN.s)
present a security challenge. All Federal computers are classified as
"sensitive systems". Therefore, since wireless technology use radio
waves, encryption is required for this transmission. In addition, there
are other areas of security concerns with this technology. Security
details can be found at http://csrc.nist.gov/publications/nistpubs/index.html
under special publication 800-46 Wireless Network Security: 802.11,
Bluetooth, and Handheld Devices.
Bureau guidance for securing WLAN's is under review. However, it is expected that DOI will institute a policy in the near future that will forbid the use of WLAN.s.
New DOI Anti-Virus Software?
DOI plans to solicit quotes for a
single DOI-wide anti-virus package for all desktops, laptops, servers,
firewalls, SMTP gateways, Internet gateways, and e-mail. Award is
expected before October 1, 2003. It is not clear how this will affect
USGS.
Identification of USGS Security Teams & Personnel The Geographic Information Office (GIO) is still relatively new, and as such, is still being organized. There are currently two different groups within the GIO tasked security responsibilities . the Bureau IT Security Manager.s Office (BITSM) and the IT Security Operations Team (ITSOT). There.s still a vacancy for the Bureau IT Security Manager. The BITSM is responsible for establishing security policy for the bureau. The ITSOT is responsible for the implementation and operation of bureau policy.
Address questions or comments to |
|