CUI / CDI NIST SP 800-171 Onboarding - University of Arizona · 2017. 10. 12. · “Green”...

9
CUI / CDI NIST SP 800-171 Onboarding Ini$al informa$on for Principal Inves$gators working with data requiring NIST SP 800-171 controls Updated: October 12, 2017 Ques$ons can be submiIed to: [email protected]

Transcript of CUI / CDI NIST SP 800-171 Onboarding - University of Arizona · 2017. 10. 12. · “Green”...

Page 1: CUI / CDI NIST SP 800-171 Onboarding - University of Arizona · 2017. 10. 12. · “Green” versus “Red” machines Green Machines • An asset that can locally store, process,

CUI / CDI NIST SP 800-171

Onboarding Ini$alinforma$onforPrincipalInves$gatorsworking

withdatarequiringNISTSP800-171controls

Updated:October12,2017

Ques$onscanbesubmiIedto:[email protected]

Page 2: CUI / CDI NIST SP 800-171 Onboarding - University of Arizona · 2017. 10. 12. · “Green” versus “Red” machines Green Machines • An asset that can locally store, process,

2

Outline

1.  WhatisCUI/CDI/NISTSP800-171?2.  “Green”versus“Red”machines3.  AWSGovCloudEnvironmentOverview4.  GovCloudS3BucketApplicaPon5.  CUI“Green”Laptop6.  ConPnuousMonitoringOverview

Page 3: CUI / CDI NIST SP 800-171 Onboarding - University of Arizona · 2017. 10. 12. · “Green” versus “Red” machines Green Machines • An asset that can locally store, process,

3

WhatisCUI/CDI/NIST800-171?

ControlledUnclassifiedInformaPon(CUI)ExecuPvebranchdatadesignaPonfordatarequiringsafeguardinganddisseminaPoncontrolstoprotecttheabilityofthefederalgovernmenttosuccessfullycarryoutitsdesignatedmissionsandbusinessoperaPons.CoveredDefenseInformaPon(CDI)Datathatiscollected,developed,received,transmi_ed,used,orstoredbyoronbehalfofthecontractorinsupportoftheperformanceofaDoDcontract.DFARS252.204-7012promulgatesCDIasCUI.NISTSP800-171Defines109securitycontrolsforprotecPngtheconfidenPalityofCUI.ThesecontrolsaremappedtothemediumsetofNIST800-53confidenPalitycontrols.

Page 4: CUI / CDI NIST SP 800-171 Onboarding - University of Arizona · 2017. 10. 12. · “Green” versus “Red” machines Green Machines • An asset that can locally store, process,

4

“Green”versus“Red”machines

GreenMachines

•  Anassetthatcanlocallystore,process,ortransmitCUI,orprovidesecurityprotecPonforsuchcomponents

•  Greenmachinesaremanagedassetsthatarein-scopeforall109controlsintheNISTSP800-171.

RedMachines•  Anassetthatdoesnotlocally

store,process,ortransmitCUI,orprovidesecurityprotecPonforsuchcomponents

•  RedmachinesareunmanagedassetsthatmayaccesstheGovCloudenvironmentbygoingthroughaterminalhost.

Page 5: CUI / CDI NIST SP 800-171 Onboarding - University of Arizona · 2017. 10. 12. · “Green” versus “Red” machines Green Machines • An asset that can locally store, process,

5

AWSGovCloudEnvironmentOverview

AmazonWebServicesGovCloud•  AmazonWebServices(AWS)offersreliableandscalablecloudRAM/

CPUservices•  TheGovCloudregionofAWSoffersNISTSP800-171compliantsecurity

ofthecloud–  UAissPllresponsibleforNISTSP800-171complianceinthecloud

AWSGovCloudComputeEnvironment•  LinuxorWindows•  Customstorage/RAM/CPU/applicaPoninstallaPons•  Canbeturnedoffwhennotbeingused(tosaveRAM/CPUcosts)

Page 6: CUI / CDI NIST SP 800-171 Onboarding - University of Arizona · 2017. 10. 12. · “Green” versus “Red” machines Green Machines • An asset that can locally store, process,
Page 7: CUI / CDI NIST SP 800-171 Onboarding - University of Arizona · 2017. 10. 12. · “Green” versus “Red” machines Green Machines • An asset that can locally store, process,

7

GovCloudS3BucketApplica$on

AmazonSimpleStorageService(S3)•  AmazonS3storesdataasobjectswithinresourcescalled“buckets”•  WehaveconfiguredourS3bucketstoencryptdataatrestaccording

toFIPS140-2,Level2,requirements

S3Bucket“DropBox”ApplicaPon•  UAdevelopedapplicaPonthatsitsontopofS3bucketthatallowsa

projectsponsortoconnectandretrievedataviatwo-factorauthenPcaPon•  SponsorisrequiredtohaveaNetID,whichiscreatedaspartofa

DesignatedCampusColleague(DCC)requestusingthespecialized“SponsoredResearchAuthenPcaPon”(SRA)subtype•  SRADCCaccountscanberequestedbydepartmentsaferfollowingallapplicableExportControlprocesses

Page 8: CUI / CDI NIST SP 800-171 Onboarding - University of Arizona · 2017. 10. 12. · “Green” versus “Red” machines Green Machines • An asset that can locally store, process,

8

CUI“Green”Laptop

CUI“Green”Laptop•  Capableoflocallystoring,processing,andtransmigngCUIdata•  In-scopeforall109controlsoftheNISTSP800-171•  TobeusedforCUIworkonly•  USBportsshouldnotbeuPlizedunlessthedeviceisspecifically

authorizedbytheprojectTechnologyControlPlan(TCP)•  RunsWindows10withNISTSP800-171requiredsecurityhardening•  RequestedthroughdepartmentalITStaff

Page 9: CUI / CDI NIST SP 800-171 Onboarding - University of Arizona · 2017. 10. 12. · “Green” versus “Red” machines Green Machines • An asset that can locally store, process,

9

Con$nuousMonitoring

Requirements•  Allassetsthatstore,process,ortransmitCUIdata,orprovidesecurity

forsuchcomponentsarerequiredtobeconPnuouslymonitoredforsecurityincidents•  Thereisarequired72hourreporPngwindowforreporPngcyber

incidentsCurrentConfiguraPon•  AllassetshaveSplunkagentssendlogstoacentralaggregatorinthe

AWSGovCloudenvironment•  LogsareconPnuouslymonitoredbyanexternalSecurityOperaPons

Center(SOC)•  AlertsareescalatedtotheUAOperaPonsteam