Docsity
Docsity

Prepare for your exams
Prepare for your exams

Study with the several resources on Docsity


Earn points to download
Earn points to download

Earn points by helping other students or get them with a premium plan


Guidelines and tips
Guidelines and tips

Information Security Guide for CoSSaR at the University of Washington, Study notes of Computer Networks

An Information Security Guide for the Center for Collaborative Systems for Security, Safety, and Regional Resilience (CoSSaR) at the University of Washington. It provides guidance on handling sensitive information that requires protection against unauthorized disclosure, including information designated “Sensitive But Unclassified” (SBU) under current control programs, which will ultimately be transitioned to protect information under the new Controlled Unclassified Information (CUI) regime. The guide provides direction for identifying and properly handling the three categories of CUI/SBU information most likely to be encountered by the CoSSaR community.

Typology: Study notes

2022/2023

Uploaded on 05/11/2023

carlick
carlick 🇺🇸

4.2

(11)

276 documents

1 / 32

Toggle sidebar

This page cannot be seen from the preview

Don't miss anything!

bg1
The Center for Collaborative Systems for
Security, Safety, and Regional Resilience
AT THE UNIVERSITY OF WASHINGTON
Information Security Guide
August 15, 2015
Controlled Unclassified Information (CUI) Guidance
Issued and Approved by:
Dr. Mark Haselkorn, PhD. Director of CoSSaR
August 15, 2015
Date
pf3
pf4
pf5
pf8
pf9
pfa
pfd
pfe
pff
pf12
pf13
pf14
pf15
pf16
pf17
pf18
pf19
pf1a
pf1b
pf1c
pf1d
pf1e
pf1f
pf20

Partial preview of the text

Download Information Security Guide for CoSSaR at the University of Washington and more Study notes Computer Networks in PDF only on Docsity!

The Center for Collaborative Systems for

Security, Safety, and Regional Resilience

AT THE UNIVERSITY OF WASHINGTON

Information Security Guide

August 15 , 2015

Controlled Unclassified Information (CUI) Guidance

Issued and Approved by: Dr. Mark Haselkorn, PhD. Director of CoSSaR August 15 , 2015 Date

i Table 1 : Version Control Version Change Effective Date Version 1.0 Initial Version 8 - 15 - 2015 Table 2 : Table of Changes Version # Date Section Paragraph Description

  • 1 GENERAL List of Tables ...................................................................................................................iv
    • 1.1 PURPOSE..........................................................................................................
    • 1.2 AUTHORITY
    • 1.3 SCOPE AND APPLICABILITY
    • 1.4 EFFECTIVE DATE AND IMPLEMENTATION....................................................
    • 1.5 OFFICE OF PRIMARY RESPONSIBILITY
  • 2 POLICY
    • 2.1 GENERAL
    • 2.2 REASON FOR CONTROL
    • 2.3 CONTROL BY COMPILATION
  • 3 RELEASE OF INFORMATION.................................................................................
    • 3.1 PUBLIC RELEASE
    • 3.2 CONTROLLED UNCLASSIFIED INFORMATION..............................................
  • 4 INFORMATION HANDLING.....................................................................................
    • 4.1 GENERAL HANDLING REQUIREMENTS
    • 4.2 DOCUMENT MARKING
      • 4.2.1 UNCLASSIFIED (U)
      • 4.2.2 FOR OFFICIAL USE ONLY (FOUO)
      • 4.2.3 LAW ENFORCEMENT SENSITIVE (LES)
      • 4.2.4 SENSITIVE SECURITY INFORMATION (SSI)
      • 4.2.5 ORIGINATION INFORMATION
      • 4.2.6 REMOVAL OF CUI MARKINGS AND DESIGNATION
    • 4.3 TRANSMISSION OF CUI/SBU INFORMATION iii
      • 4.3.1 MAIL
      • 4.3.2 VOICE, DATA, AND FAX
      • 4.3.3 ENCRYPTION
      • 4.3.4 UNENCRYPTED FILES
      • 4.3.5 PUBLIC WEBSITES
    • 4.4 RELEASE TO ELIGIBLE STAKEHOLDERS
    • 4.5 DESTRUCTION
    • 4.6 INCIDENT REPORTING
  • 5 General Guidance, “FOR OFFICIAL USE ONLY”
  • 6 General Guidance, “Law Enforcement Sensitive”
  • 7 General Guidance, “Sensitive Security Information”
  • APPENDIX A: Information Controlled as “For Official Use Only”
  • APPENDIX B: Law Enforcement Sensitive (LES) Information
  • DEFINITIONS

iv

List of Tables

Table 1: Version Control ................................................................................................ i Table 2: Table of Changes ............................................................................................. i Table 3: FOUO General Guidance .............................................................................. 13 Table 4: LES General Guidance ................................................................................. 15 Table 5: SSI General Guidance .................................................................................. 17

1.2 AUTHORITY

This guide is approved by the Director of the Center for Collaborative, Safety, Security, and Regional Resilience at the University of Washington. It is issued to provide guidance to Federally directed CoSSaR activities in accordance with Executive Order 13556, Department of Homeland Security Management Directive Numbers 11042.1 and 11056.1, Department of Defense Manual Number 5200.01 (Volume 4), 49 CFR 1520.5, and University of Washington security directives.

1.3 SCOPE AND APPLICABILITY

This document provides security guidance for the use of CUI/SBU information associated with the CoSSaR program. This guide and reference authorities (listed in Section 1.2) shall be cited as the basis for recognizing, categorizing, marking, handling, processing, transmitting, and disseminating of CUI/SBU and materials. If a conflict exists between this guide and reference authorities, the reference authority takes precedence.

1.4 EFFECTIVE DATE AND IMPLEMENTATION

This guide is effective immediately upon release.

1.5 OFFICE OF PRIMARY RESPONSIBILITY

The Office of Primary Responsibility (OPR) for this guide is: Program Manager Center for Collaborative, Safety, Security, and Regional Resilience (CoSSaR) 310 Sieg Hall, Box 352315 University of Washington Seattle, WA 98195 Phone: (206) 543- 4640 Fax: (206) 543- 8858 E-Mail: CoSSaR@uw.edu The office of secondary responsibility for this guide is: University Facility Security Officer 1013 NE 40th St., Box 355640 Seattle, WA 98105 Phone: (206) 543- 1315 Fax: (206) 543- 1732 E-Mail: uwfso@uw.edu

2 POLICY

2.1 GENERAL

One goal of CoSSaR is to produce relevant analytic products for Puget Sound area stakeholders that may be disseminated to the widest audience possible at the uncontrolled UNCLASSIFIED level. In the conduct of their work, CoSSaR researchers may, however, be given CUI/SBU information - or they may create it by compilation. To properly control information, it is essential for researchers to recognize CUI/SBU information. When gathering information, it is required that CoSSaR researchers document when the information they receive is CUI/SBU information. All information marked as CUI/SBU by any Federal agency shall be marked and handled in accordance with this Information Security Guide within the CoSSaR project. It is the responsibility of each CoSSaR researcher to ask if information gathered in verbal interviews is either uncontrolled or CUI/SBU information. Department of Homeland Security (DHS) Management Directive 11042.1 states “Any DHS employee, detailee, or contractor, can mark information falling within one or more of the categories as FOUO.” Therefore, acting as grantees or contractors to DHS, CoSSaR researchers may designate information falling into the categories below as “FOUO” to maintain protection of the information. Additionally, “DHS Officials occupying supervisory or managerial positions are authorized to designate other information, not listed and originating under their jurisdiction, as FOUO.” If CoSSaR personnel believe that information meets the criteria for CUI/SBU information, the material should be sent to the sponsor team via DHS using approved CUI/SBU information transmission methods (see section 4.3) for final determination. In the interim, the material shall be protected as if it were CUI/SBU information until a final determination is made by DHS.

3 RELEASE OF INFORMATION

3.1 PUBLIC RELEASE

This guide is designated UNCLASSIFIED and subject to public release under the Federal Freedom of Information Act and Washington RCW Chapter 42.56 Public Records Act.

3.2 CONTROLLED UNCLASSIFIED INFORMATION

Executive Order 13556 "Controlled Unclassified Information" established the CUI program, which is a system that standardizes and simplifies the way the Executive branch handles unclassified information that requires safeguarding or dissemination controls, pursuant to and consistent with applicable law, regulations, and government- wide policies. Although President Obama signed Executive Order 13556 in 2009, many Federal agencies have yet to complete the transition to the CUI standard. As a result, much of the guidance for the previous “Sensitive But Unclassified” (SBU) regime remains in place. This guide applies to certain types of CUI/SBU information for which Executive Branch agencies require applications of controls and protective measures for a variety of reasons. FOUO and LES are designations applied by DHS to CUI/SBU information, which may be exempt from mandatory release to the public under Section 552 of Title 5, U.S.C., “Freedom of Information Act (FOIA)” or “The Privacy Act”. SSI is the designation applied by DHS to CUI/SBU information obtained or developed in the conduct of security activities as defined in 49 C.F.R. Section 1520.5.

4 INFORMATION HANDLING

4.1 GENERAL HANDLING REQUIREMENTS

  1. No security clearance is needed for access to CUI/SBU information; however, the recipient must have a ‘need to know’ the information.
  2. During working hours, reasonable steps should be taken to minimize risk of access by unauthorized personnel. CUI/SBU information shall be placed in an out-of-sight location if the work area is accessible to persons who do not have a need for the information. During nonworking hours, the materials shall be stored in locked desks, file cabinets, bookcases, locked rooms, or similar items. CUI/SBU information should not be stored with classified information unless there is a correlation. a. When removed from an authorized storage location and persons without a need- to-know are present, or where casual observation would reveal CUI/SBU information to unauthorized persons, a “FOR OFFICIAL USE ONLY” or “Sensitive Security Information” cover sheet will be used to prevent unauthorized or inadvertent disclosure. (For further information on cover sheets see Sections 4.2.2, 4.2.3, and 4.2.4.) b. When forwarding CUI/SBU information, a FOUO or SSI cover sheet should be placed on top of the transmittal letter, memorandum, or document.
  3. Unauthorized disclosure of CUI/SBU information doesn't constitute a security violation, but the releasing agency should be informed of any unauthorized disclosure. The unauthorized disclosure of CUI/SBU information protected by the Privacy Act may result in criminal sanctions.
  4. To obtain further guidance regarding For Official Use Only (FOUO) and Law Enforcement Sensitive (LES) refer to DHS Management Directive Number 11042.1.
  5. To obtain further guidance regarding the handling of Sensitive Security Information (SSI) refer to DHS Management Directive Number 11056.1.

other personnel who do not have a valid need-to-know without prior approval of an authorized DHS official. 4.2.3 LAW ENFORCEMENT SENSITIVE (LES) In unclassified documents containing LES information, the phrase “Law Enforcement Sensitive” shall accompany the phrase “FOR OFFICIAL USE ONLY” at the bottom of the outside of the front cover, the title page (if there is one), and the outside of the back cover (if there is one). Each page containing FOUO-LES information shall be marked “FOR OFFICIAL USE ONLY Law Enforcement Sensitive” at the bottom. Portions of unclassified documents that contain FOUO-LES information shall be marked with the parenthetical notation “(FOUO-LES)” at the beginning of the portion. If an unclassified portion of a classified document contains FOUO-LES information, the portion marking (U//FOUO-LES) shall be used. The cover sheet of each document containing LES should be marked with the following warning: (U) WARNING: LAW ENFORCEMENT SENSITIVE. The information in this document marked FOUO-LES is the property of the Department of Homeland Security and may be distributed within the Federal Government (and its contractors) to law enforcement, public safety and protection, and intelligence officials and individuals with a need to know. Distribution to other entities without prior DHS authorization is prohibited. Precautions shall be taken to ensure this information is stored and destroyed in a manner that precludes unauthorized access. Information bearing the FOUO-LES marking may not be used in legal proceedings without prior authorization from the originator. Recipients are prohibited from posting information marked FOUO-LES on a website or unclassified network.

4.2.4 SENSITIVE SECURITY INFORMATION (SSI)

To identify unclassified information with an “SSI” caveat in a title, heading, paragraph, or bullet, precede the portion with “(U//SSI)”. If a document contains “(U)”, “U//FOUO”, “(U//LES)”, and “(U//SSI)”, the overall classification of the document is “UNCLASSIFIED// LAW ENFORCEMENT SENSITIVE and SENSITIVE SECURITY INFORMATION”. Individual paragraphs and sections properly marked as “Unclassified” or “(U)” may be shared freely, but other information properly marked as FOUO, LES, or SSI within a document can only be shared with authorized recipients who have a valid “need-to- know”. The cover sheet of each document containing SSI should be marked with the following warning: (U) WARNING: This record contains SENSITIVE SECURITY INFORMATION that is controlled under 49 CFR parts 15 and 1520. No part of this record may be disclosed to persons without a “need to know”, as defined in 49 CFR parts 15 and 1520, except with the written permission of the Administrator of the Transportation Security Administration or the Secretary of Transportation. Unauthorized release may result in civil penalty or other action. For U.S. government agencies, public disclosure is governed by 5 U.S.C. 552 and 49 CFR parts 15 and 1520. 4.2.5 ORIGINATION INFORMATION Designator or originator information & markings, downgrading instructions, & date/event markings are not required on FOUO, LES, or SSI documents. 4.2.6 REMOVAL OF CUI MARKINGS AND DESIGNATION Removal of CUI/SBU information markings can only be accomplished by the originator or other competent authority. DO NOT remove any CUI/SBU information markings

4.3.5 PUBLIC WEBSITES

CUI/SBU information should not be posted to public websites. a. SSI may be posted on approved government-controlled or – sponsored encrypted or otherwise protected portals, such as the Homeland Security Information Network (HSIN), USCG HomePort, or TSA’s WebBoards. Such posting shall be in accordance with guidance published or approved by the TSA SSI Office and appropriate IT security offices.

4.4 RELEASE TO ELIGIBLE STAKEHOLDERS

CoSSaR may disseminate CUI/SBU information to its employees and subcontractors who have a need for the information to complete work assigned in connection with CoSSaR projects. CoSSaR seeks to provide its CUI/SBU information-designated analytic products the widest distribution among Puget Sound area stakeholders with a legitimate “need to know”. a. The CoSSaR Program Manager will seek permission from its DHS sponsor team to release reports containing CUI/SBU information to each individual stakeholder requesting the information. b. The CoSSaR Project Manager will also comply with University procedures for the release of CUI/SBU information by submitting a University Access Request Form to release CUI/SBU information to regional stakeholders. C. The CoSSaR Project Manager will maintain a log recording the release of all CoSSaR products and reports containing CUI/SBU information to third parties.

4.5 DESTRUCTION

Hard copy CUI/SBU materials will be destroyed by shredding, burning, pulping, or pulverizing, sufficient to assure destruction beyond recognition and reconstruction. After destruction, materials may be disposed of with normal waste.

Electronic storage media shall be sanitized appropriately by overwriting or degaussing. After destruction, materials may be disposed of with normal waste. Paper products containing CUI/SBU materials will not be disposed of in regular trash or recycling receptacles unless the materials have first been destroyed as specified above.

4.6 INCIDENT REPORTING

The loss, compromise, suspected compromise, or unauthorized disclosure of CUI/SBU information will be reported to the CoSSaR program’s DHS sponsor team and the University of Washington Office of Sponsored Programs within one business day of the discovery of the incident. Incidents on UW IT systems will also be reported to the University Facility Security Officer at 206- 543 - 1315 or uwfso@uw.edu via the system’s Information Technology Manager (http://ciso.washington.edu/report/ ). Coordinate reporting through the HCDE IT Manager for incidents on the HCDE server or the APL IT Manager for incidents on APL-hosted servers. Suspicious or inappropriate requests for CUI/SBU information by any means (e.g., email or verbally) shall be reported to the DHS sponsor team via the CoSSaR Program Manager and the UW Office of Sponsored Programs. If the disclosure or compromise could result in physical harm to an individual(s) or the compromise of a planned ongoing operation, additional notifications to appropriate DHS management personnel will be made without delay. In the event of an unauthorized disclosure, CoSSaR will request an inquiry by the University Facility Security Officer to determine the cause and effect of the incident and suggested corrective actions to prevent recurrence.

FOIA (5 USC 552) Exemption 7: Law enforcement information

FOUO-

LES

See Law Enforcement Sensitive Matrix for further guidance FOIA (5 USC 552) Exemption 8: Matters/information for regulators or supervisors of financial institutions

FOUO

FOIA (5 USC 552) Exemption 9: Geological information and data, including maps, concerning wells

FOUO

Privacy Act (5 USC 552a) § (j)(2): Material reporting investigative efforts pertaining to the enforcement of criminal law, including efforts to prevent, control, or reduce crime or to apprehend criminals.

FOUO-

LES

See Law Enforcement Sensitive Matrix for further guidance International and domestic information protected by treaty, statute, regulation, or other agreement.

FOUO

Information that could result in physical risk to personnel.

FOUO

System security data revealing the security posture of a system. FOUO For example: threat assessments, system security plans, contingency plans, risk management plans, Business Impact Analysis studies, etc… Information that reveals security vulnerabilities, whether to persons, systems, or facilities. SSI See Sensitive Security Information Matrix for further guidance

6 General Guidance, “Law Enforcement Sensitive”

The following matrix has been compiled to assist CoSSaR personnel to recognize information that requires control as “Law Enforcement Sensitive”. The list contains abridged descriptions. Appendix B contains the full descriptions of Law Enforcement Sensitive exclusions to the FOIA as delineated by the US Department of Justice. Table 4 : LES General Guidance Law Enforcement Sensitive – Exemption 7 of FOIA ( 5 USC 552) Topic Marking Remarks Information that could reasonably be expected to interfere with enforcement proceedings

FOUO-

LES

Information that would deprive a person of a right to a fair trial or an impartial adjudication

FOUO-

LES

Information that could reasonably be expected to constitute an unwarranted invasion of personal privacy

FOUO-

LES

Information that could reasonably be expected to disclose the identity of a confidential source

FOUO-

LES

Including a State, local, or foreign agency or authority or any private institution which furnished information on a confidential basis, and, in the case of a record or information compiled by a criminal law enforcement authority in the course of a criminal investigation, or by an agency conducting a lawful national security intelligence investigation,