raft-tech / TANF-app

Repo for development of a new TANF Data Reporting System
Other
17 stars 4 forks source link

As TDP SO/TL, I need a basic security awareness training developed for IS users (AT-02) #953

Closed ADPennington closed 2 years ago

ADPennington commented 3 years ago

This training will satisfy Security Control AT-02 (Security Awareness Training).

SO = System Owner TL = Tech Lead IS = Infosec

The organization provides basic security awareness training to information system(IS) users (including managers, senior executives, and contractors): a. As part of initial training for new users; b. When required by information system changes; and c. [At least every 365 days] thereafter.

The content should:

For CSP Only AT-2(c) [at least annually]

Related controls: AT-01 (security training policy), AT-03 (role-based security), and AT-04 (security training record-keeping) may need to be satisfied in the future. If so, perhaps worthwhile to consider these as we're building strategy to satisfy AT-02.

ACs:

ADPennington commented 3 years ago

reached out to Penyin on 6/1 to ask if there are other ACF program offices with system-specific training models we could review.

ADPennington commented 3 years ago

stub comment for research findings:

re: provide a basic understanding of the need for information security

re: user actions to maintain security and to respond to suspected security incidents

links to relevant hhs+ acf rules/policies/resources

re: certificates

valcollignon commented 2 years ago

@ADPennington - where does this ticket stand? It's been in "Next Sprint Backlog" since May 21. Can this move back to backlog until we're ready for it? CC: @lfrohlich

lfrohlich commented 2 years ago

I moved it back to product backlog

stevenino commented 2 years ago

Will be discussed at the next IPT meeting. Not required for v1

lfrohlich commented 2 years ago

Per IPT 4/6/22 -- HHS trainings should be sufficient. Alex and Thomas will need to submit certificates annually.

ADPennington commented 2 years ago

Per IPT 4/6/22 -- HHS trainings should be sufficient. Alex and Thomas will need to submit certificates annually.

recommend we write a security control implementation statement relevant to AT series and store it here with the others. cc: @lfrohlich @stevenino

stevenino commented 2 years ago

Per IPT 4/6/22 -- HHS trainings should be sufficient. Alex and Thomas will need to submit certificates annually.

recommend we write a security control implementation statement relevant to AT series and store it here with the others. cc: @lfrohlich @stevenino

Would that be an AC for this ticket or can we close this ticket now as not required?

ADPennington commented 2 years ago

Per IPT 4/6/22 -- HHS trainings should be sufficient. Alex and Thomas will need to submit certificates annually.

recommend we write a security control implementation statement relevant to AT series and store it here with the others. cc: @lfrohlich @stevenino

Would that be an AC for this ticket or can we close this ticket now as not required?

i updated ACs @stevenino.