Example: confidence

Publication 4812 (Rev. 11-2018)

Publication 4812 Contractor Security & Privacy Controls Handling and Protecting Information or Information Systems **This Publication Pertains to IT Assets Owned and Managed at Contractor Sites** Publicationn 4812 (Rev. 10-2019) Catalog Number 54170T Department of the Treasury Internal Revenue Service Highlights of Publication 4812 Publication 4812 is designed to identify security requirements for contractors and any subcontractors supporting the primary contract. It identifies security controls and privacy requirements for contractors (and their subcontractors) who handle or manage Internal Revenue Service (IRS) Sensitive But Unclassified (SBU) information on or from their own information systems or resources.

Highlights of Publication 4812 . Publication 4812 is designed to identify security requirements for contractors and any subcontractors supporting the primary contract.

Tags:

  Publication, 8412, Publication 4812

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of Publication 4812 (Rev. 11-2018)

1 Publication 4812 Contractor Security & Privacy Controls Handling and Protecting Information or Information Systems **This Publication Pertains to IT Assets Owned and Managed at Contractor Sites** Publicationn 4812 (Rev. 10-2019) Catalog Number 54170T Department of the Treasury Internal Revenue Service Highlights of Publication 4812 Publication 4812 is designed to identify security requirements for contractors and any subcontractors supporting the primary contract. It identifies security controls and privacy requirements for contractors (and their subcontractors) who handle or manage Internal Revenue Service (IRS) Sensitive But Unclassified (SBU) information on or from their own information systems or resources.

2 The level of required security and privacy controls may vary depending on the duration, size, and complexity of the contract. Publication 4812 defines basic security and privacy control requirements and standards required of contractors (and contractor employees) when the contract is for services, contractors, and contractor employees who will either: Have access to, develop, operate, host, or maintain IRS SBU information or information systems for tax administration purposes (or provide related services) outside of IRS facilities or outside of the direct control of the Service, and/or Have access to, compile, process, or store IRS SBU information on their own information systems or that of a subcontractor or third-party Service Provider, or that use their own information systems (or that of others) and Electronic Information and Technology (as defined in FAR Part 2) to access, compile, process, or store IRS SBU information while working at an IRS owned or controlled facility.

3 The IRS defines Sensitive But Unclassified (SBU) in IRM is any information which, if lost, stolen, misused, or accessed or altered without proper authorization, may adversely affect the national interest or the conduct of federal programs (including IRS operations), or the privacy to which individuals are entitled under the Privacy Act (5 552a). SBU data includes but is not necessarily limited to: Federal Tax Information (FTI), Personally Identifiable Information (PII), Protected Health Information (PHI), certain procurement information, system vulnerabilities, case selection methodologies, systems information, enforcement procedures, and investigation information. (See Appendix B Glossary for definitions). Live data, which is defined as production data in use.

4 Live means that when changing the data, it changes in production. The data may be extracted for testing, development, etc., in which case, it is no longer live. Generally, SBU data should not be used for testing or training and non-production systems must maintain the same security and privacy controls which protect live data when SBU data is introduced. IRS Publication 4812 Contractor Security & Privacy Controls Table of Contents 1 Background .. 1 2 3 3 Scope .. 4 IRS Security Controls Structure .. 4 IRM Applicability .. 4 IRM Applicability.

5 4 Publication 4812 Applicability .. 5 4 SBU Returns and Return Law Enforcement Sensitive 8 Employee Information .. 8 Personally Identifiable Information .. 8 Other Protected Information .. 8 5 Information and Information 10 6 UNAX and Disclosure of Information .. 11 7 Roles and Responsibilities .. 12 Contracting Officer (CO) .. 12 Contracting Officer s Representative (COR) ..12 Information Technology and Contractor Security Assessments (CSA)..13 Privacy, Governmental Liaison and Disclosure (PGLD).. 13 Agency Wid e Shared Services and Facilities Management and Security Services (AWSS/F MSS) .. 14 Personnel Security (PS).. 14 Project Manager/Task 15 15 Contractor Security Representative (CSR).

6 15 Contractor Employees .. 16 Contractor Program Requirements .. 16 Contractor Security Policies and 16 Contractor Investigative Contractor Training .. 17 Contractor Information Protection .. 18 Rules of Behavior .. 18 8 Contractor Security Assessments (CSA).. 19 Types of Assessments .. 19 IRS Publication 4812 Contractor Security & Privacy Controls Notice of Assessments .. 20 Security Control Scope of 21 Collaboration on Contractor Security Before the At the Time of, or During the Assessment .. 22 After the 23 Continuous Monitoring of Security Controls.

7 23 9 Privacy and Information 24 Security 24 10 Security Control Organization and 25 11 Access Control and Approving Authorization for IT Assets (AC)..27 AC-1 Access Control Policy and AC-2 Account Management .. 27 AC-3 Access Enforcement .. 28 AC-4 Information Flow AC-5 Separation of AC-6 Least Privilege .. 29 AC-7 Unsuccessful Login Attempts .. 30 AC-8 System Use 30 AC-11 Session Lock .. 31 AC-12 Session Termination .. 31 AC-14 Permitted Actions without Identification or Authentication .. 31 AC-17 Remote 31 AC-18 Wireless AC-19 Access Control for Mobile Devices .. 32 AC-20 Use of External Information AC-21 Information Sharing .. 35 AC-22 Publicly Accessible Content.

8 35 12 Awareness and Training (AT)..37 AT-1 SecurityAwarenessand Training Policy and AT-2 SecurityAwareness AT-3 Role Based Security Training .. 37 AT-4 Security Training Records .. 38 13 Audit and Accountability (AU)..39 IRS Publication 4812 Contractor Security & Privacy Controls AU-1 Audit & Accountability Policy and 39 AU-2 Auditable Events .. 39 AU-3 Content of Audit Records .. 40 AU-4 Audit Storage Capacity .. 41 AU-5 Response to Audit Processing Failures .. 41 AU-6 Audit Review, Analysis, and Reporting .. 41 AU-7 Audit Reduction and Report Generation.

9 41 AU-8 Time Stamps .. 42 AU-9 Protection of Audit 42 AU-11 Audit Record Retention .. 42 AU-12 Audit Generation .. 43 14 Security Assessment and Authorization (CA) .. 44 CA-1 Security Assessment and Authorization Policies and Procedures. 44 CA-2 Security Assessments .. 44 CA-3 Information System 44 CA-5 Plan of Action and 45 CA-6 Security 45 CA-7 Continuous Monitoring .. 45 CA-9 Internal System Connections .. 46 15 Configuration Management (CM) .. 47 CM-1 Configuration Management Policy and Procedures .. 47 CM-2 Baseline CM-3 Configuration Change CM-4 SecurityImpact CM-5 Access Restrictions for Change .. 48 CM-6 Configuration 48 CM-7 Least 49 CM-8 Information System Component CM-9 Configuration Management Plan.

10 51 CM-10 Software Usage Restrictions .. 51 CM-11 User-Installed Software .. 51 16 Contingency Planning (CP) .. 52 IRS Publication 4812 Contractor Security & Privacy Controls CP-1 Contingency Planning Policy and Procedures .. 52 CP-2 Contingency Plan .. 52 CP-3 Contingency CP-4 Contingency Plan Testing and CP-6 Alternate Storage Site .. 53 CP-7 Alternate Processing Site .. 53 CP-8 Telecommunications Services .. 54 CP-9 Information System Backup .. 54 CP-10 Information System Recovery and 17 Identification and Authentication (IA) .. 56 IA-1 Identification and Authentication Policy and Procedures.


Related search queries