SECURITY CONTROLS

TABLE OF CONTENTS         

                    DM 3575

                                                                                                 

                                                                                    Page

 

Chapter­ 15 – General Information

 

1          Purpose                                                                                 2         

2          Cancellation                                                                       2         

3          References                                                                           2         

4          Scope                                                                                    3         

5          Abbreviations                                                                     3                     

                                                                       

3575-001

Part I – Security Controls in the Systems Development Life Cycle

 

1          Background                                                                        1         

2          Policy                                                                                     5         

3          Procedures                                                                           5         

4          Responsibilities                                                                    20                   

 

Table

 

1          Interconnectivity Security Agreement

 

 

 

 

 

 

                                                          U.S. Department of Agriculture

                                                                                         Washington, D.C.                                                                                                                                                                               

 

DEPARTMENTAL MANUAL

 

    NUMBER:

  3575-000

 

 

 SUBJECT:

  Security Controls

 

DATE:  May 27, 2005

 

OPI:  OCIO, Cyber Security

                                                                                                                                               

CHAPTER 15

GENERAL INFORMATION

 

 

1          PURPOSE

 

This Departmental Manual chapter defines security control requirements in terms of System Rules, Access, Management, Technical and Environmental Controls, Audits and Compliance, Security Performance Measures and Security Controls in the Systems Life Cycle (SLC)/Systems Development Life Cycle (SDLC). 

 

Part 1, specifies those security controls to be used in conjunction with the SLC/SDLC.

 

 

2          CANCELLATION

 

            This Departmental Manual will be in effect until superceded.

 

 

3          REFERENCES

 

Records Management by Federal Agencies, 44 U.S. Chapter 21, 29, 31;

 

Disposal of Records, 44 U.S.C. Chapter 33;

 

DR 3080-001 Records Management;

 

36 CFR Part 1234, Management of Electronic Records;

 

36 CFR Part 1228 Expanding Transfer Options for Electronic Records;

 

DR 3080-1, Records Disposition; and

 

CS-030, Cyber Security Updated Guidance on Certification and Accreditation of USDA IT Systems. 

 

 

4          SCOPE

 

This manual applies to all USDA agencies, programs, teams,

organizations, appointees, employees and other activities.

 

 

5          ABBREVIATIONS

 

AIS                  Automated Information System(s)

CIO                Chief Information Officer

CPIC              Capital Planning and Investment Control

CS                   Cyber Security

IRM                 Information Resources Management

ISSO               Information Systems Security Officer

ISSPM             Information Systems Security Program Manager

IT                     Information Technology

NIST                National Institute of Standards and Technology

OCIO             Office of the Chief Information Officer

OMB               Office of Management and Budget

PIA                 Privacy Impact Assessment

SDLC              System Development Life Cycle

SLC                 System Life Cycle

SOR                System of Records Notice

USDA             United States Department of Agriculture