|
Integrated Systems is responsible for developing and implementing enterprise wide
Security Architecture, Certification and Accreditation. Specific tasks include:
- Development of the NARA Systems Security Plan in compliance with NIST SP 800-18.
- Assessing IT technology for security related operational issues.
- Development of a Contingency Plan in compliance with NIST SP 800-34.
- Meeting the Federal Information Security Management Act (FISMA) requirements for assessment of the risk and magnitude of damage that could result from unauthorized access, use, disclosure, disruption, modification or destruction of information and information systems that support the operations and assets of NARA in compliance with NIST SP 800-30 (Risk Assessment).
- Directing the NARA security team in reviewing NARA program planning guidance reflecting the requirements of FISMA and the NIST OMB A-130 Certification and Accreditation Guidance.
- Development of the NARA Risk Management Plan that takes into account the performance measure guidance using OMB’s high level performance measures and establish the processes for program specific, second tier measures.
- Specific measures include but are not limited to:
- Incident Warning and Responsible guidance
- Cooperative independent verification and validation
- Providing Security assistance to team working with programs and sites;
- Continuing maintenance of corrective plans of action and milestones and integrate performance measures into POI &M process; and Integrating security into the life cycle planning and funding of information technology
|