Transcription of Certification and Accreditation - about.usps.com
1 Certification and AccreditationPublication 805-A, May 20151 Certification and Accreditation The Postal Service Process For Protecting Its Electronic Information ResourcesPublication 805-A, May 2015 Certification and Accreditation2 PhaseC&A DeliverableNew & Major Information Resource ModificationsRecertificationsService Based Contracts NS & NCAll Other Information ResourcesDeliverablesResponsibleDelivera blesResponsibleDeliverablesResponsibleDe liverablesResponsible2 Information Resource CharacterizationYe sProject sProject sProject sProject sProject sProject sProject sProject SpecsYe sProject sProject sProject sProject PlanYe sProject sProject sProject sProject Security ReviewYe sISSO & USPISIf applicableISSO & USPISYe sISSO & USPIS4 SOPsIf applicableProject applicableProject sProject Training MaterialsIf applicableProject applicableProject sProject PlansYe sProject applicableProject sProject RequestYe sProject sProject sProject sProject PlanYe
2 SProject sProject applicableProject sProject Code ReviewBased on RequirementsProject on Policy RequirementsProject applicableProject on Policy RequirementsProject Testing & ReportYe sProject sProject applicableProject sProject ScanYe sCISOYe sCISOYe sCISOYes for SensitiveCISO6 Penetration TestIf applicableCISOIf applicableCISOIf applicableCISO6 Independent ReviewsIf applicableProject applicableProject applicableProject AssessmentYe sProject sProject sProject sProject Mitigation PlanYes for High/ Mod RiskProject for High/ Moderate RiskProject for High/ Mod RiskProject for High/ Mod RiskISSO6 Evaluation ReportYESISSOYe sISSOYe sISSO6 Certification LetterYESISSO sCertifierYe sCertifier6 Accreditation LetterYESMgr. CISOYe sAccreditorYe sAccreditor6 Risk Acceptance LetterYes for vulner-ability that will not be miti-gatedVP IT and VP Functional Business AreaYes for vulner-ability that will not be miti-gatedVP IT and VP Functional Business AreaYes for vulner-ability that will not be miti-gatedVP IT and VP Functional Business AreaYes for vulner-ability that will not be miti-gatedVP IT and VP Functional Business Area8 Contingency Test ResultsYe sBusiness Relationship Management Portfolio Mgr.
3 & Executive SponsorYe sBusiness Relationship Management Portfolio Mgr. & Executive SponsorYe sBusiness Relationship Management Portfolio Mgr. & Executive Sponsor8 Revised C&A DocumentsAs needed or every 3 yearsISSO & Project needed or every 2 years; annually for PCIISSO & Project MgrAs needed or every 2 years; annually for PCIISSO & Project needed or every 2 yearsISSO & Project RequestYe sProject sProject sProject sProject CertificationYe sProject sProject sProject sProject and Accreditation (C&A) Requirements for Information ResourcesCertification and AccreditationPublication 805-A, May 20153C&A Phases and Major DeliverablesThe C&A process consists of several interrelated phases that are conducted concurrently with the development and deployment of new information resources (technical solutions) and the retirement of existing information resources.
4 Each phase in the C&A process corresponds to a phase in the Technical Solutions Life Cycle using either the Waterfall Development or the Agile Scrum Development objectives of the C&A process are to do the following: Determine sensitivity and criticality of information processed. Define security requirements. Identify and implement security controls and processes. Test security solutions. Evaluate the effectiveness of security controls and processes chosen to protect the information resource, assess threats and vulnerabilities. Obtain management approval for deployment or continued 805-A, May 2015 Certification and Accreditation4 Certification and Accreditation Activities in Conjunction with the Waterfall Development Methodology PhasesPhase 1, Initiate and PlanIn this phase: The proposed technical solution is registered or updated in EIR.
5 The project is planned. An ISSO is assigned. The C&A process is 2, RequirementsIn this phase, the application characteristics are documented including internal and external dependencies, and a Business Impact Assessment (BIA) is conducted to collect privacy-related information, to ensure compliance with privacy laws and regulations, to define sensitivity and criticality of the technical solution, and to determine information security requirements required to protect the technical 3, DesignIn this phase: The design for the technical solution is developed and documented in an architecture diagram. Security specifications are defined for contracts and acquisitions to protect the technical solution commensurate with its business value. Information security controls and processes are identified to satisfy the security requirements defined in the BIA and are documented in a security plan.
6 A site security review is requested (if required).Phase 4, BuildIn the build phase: Information security controls and processes are built (or acquired) and integrated in the information resource. Connectivity requirements are defined. A request is submitted to the Network Connectivity Review Board. Contingency planning is initiated (if required) to address unexpected interruptions to business activities supported by this information 5, Security Integration TestingIn the security integration testing phase, a security test plan is developed and contingency plans are 6, Customer Acceptance TestingIn the customer acceptance testing phase: A security code review is conducted (if required). Security testing is conducted to ensure the security controls and processes implemented in the build phase are effective. The results of the test are documented in a report.
7 Vulnerability scans are run. Penetration testing is conducted (if applicable). Certification and AccreditationPublication 805-A, May 20155 The independent reviews for security code reviews, risk assessments, vulnerability scans, penetration testing, or security test validation are conducted (if required). A risk assessment is conducted and a risk mitigation plan is developed. The ISSR and/or project manager completes the C&A deliverables and submits them to the ISSO. The ISSO evaluates the C&A deliverables and prepares an evaluation report highlighting the risks associated with placing the information resource in production, escalates security concerns or forwards the C&A evaluation report and supporting documentation to the certifier for review. The certifier reviews the C&A evaluation report and the supporting C&A documentation, escalates security concerns or prepares and signs a Certification letter, and forwards the Certification letter and C&A supporting documentation to the accreditor.
8 The accreditor reviews the Certification letter, risk mitigation plan, and the supporting C&A documentation, and takes one of the following actions: [1] escalates security concerns, or [2] prepares and signs a full Accreditation letter and forwards the full Accreditation letter to the vice president functional business area (or executive sponsor if this responsibility is delegated) and vice president IT (or Business Relationship Management portfolio manager if this responsibility is delegated), or [3] prepares and signs a conditional Accreditation with some requirements that must be met within a certain time frame forwards the Conditional Accreditation Letter to the VP IT and the VP functional business area. If the requirements are not met in the indicated time frame, the accreditor will issue a Failure to Comply Letter to the VP IT and the VP functional business area.
9 If a documented vulnerability associated with the medium or high residual risk will not be mitigated, [1] the VP IT and VP functional business area prepare and sign a Risk Acceptance Letter and forward the letter to the accreditor, or [2] if the VP IT and VP functional business area decide not to sign a Risk Acceptance Letter, the accreditor will issue a Failure To Comply 7 Governance ComplianceThe Governance Compliance phase ensures that all deliverables are stored in the TSLC Artifacts Library and that all artifacts meet usps IT SOX and IT governance requirements and controls, and have been approved by the Product Owner/Customer. There are no C&A activities or deliverables for this 8, Release and ProductionAll three approvals ( , Certification , Accreditation , and risk acceptance) are required before deploying the information resource.
10 The project manager deploys the information resource into production with the security controls documented in the security plan and tested in the Security Test and Evaluation (ST&E) and with any restrictions documented in the approval letters. Other activities in Phase 8 are: Testing contingency plans. Maintaining security controls and 805-A, May 2015 Certification and Accreditation6 Periodically testing security controls. Reviewing system and application logs. Updating C&A documentation. Re-initiating the C& 9, RetireThe Retirement phase ensures that appropriate archiving and security measures are taken and documented when decommissioning technology solution or components from the Postal Service Technology Infrastructure. Activities include: Retiring the information resource. Disposing of the data. Sanitizing the equipment and media (if required).