WPC '  ԩeq1u`c* ]ݝnڞn2p];:Ek{̴2EpftQ:4+9}r/:`~(Op~K?BV\ >IUQpkNѠM$o6#EE끍&ÿQtd3F>#*9_t5t1'Rc "Muᣥf6T1rj=6{Js XqMQR~֙/wcCOlTN p]T 4-ǕR,&U\Ztl;gΟ5 nݥ&;xf*éE]}3jD?_f{ % 0 (U:@6!w@W4 1m@0'WzU:X 0#D    !z!UAJ\# 0v#$ A&UN^'o4'[t\UJ\B]o9^ 0DUN 02=H 0AF 0Yh˘ Ba3UNUNb08bbE\ 0C 0sUDU:- 0CgU: b BRW D3t 0 Cm 0J AMG`ԢԢ4 0C 0C= A [DۥZy?^UNsU:^  0 DUNU:5 0JoU:U: 1-UJU:<UNvijmTb(b08U:ڸUJ 0`< 0TU:/*UNYUNUNC 0PU:HUNUNоUNUN1UN AUNLUNUNUN6UNUNUN UNnUNUN UNXUNUNUNBUNUNUN,UNzU:UNUNPU:[UN\U:U:U:U:<U:UN=U:nU:oUNU:UJUN^_U: bEUU:UNVU:U:UNU:-U:.b bUJ(U:rU:U:UNU:UN,`zU:|UJ AMMU:%UJ_UNU:UJ@U:bVb^bfbnbvUJ~U:vUJtn7U:UJOU:dUJrZU:`UJU:U:UJU:?yUJb{U:U:U:UJIU:UJWU:UJU:UJ&bpbx UJDU: UJDU:l UJ  U:  U: UJ ( U: UJG  U:ZUJU:UJ<U:UJ=U:jUJU:UJ9U:bVUJjU:{UJU:UJfU:-UJgU:UJU:UJc~U:aUJU:  A  D+!UJ!"U:"UJ!#k#U:2$UJl$$$$@8'o''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''/oU:_U:77qU:UUg,HP LaserJet 4 Plus/4M PlusHPPCL5E,,,,0 c:\ca\polman\aisfinal\polkey2.%($,@0AZ"Arial Regulare:\dingman\ncsc-029.wmf %%%% %i e%%D%V%%Eφ 3|x%# e37=CIQYag1.a.i.(1)(a)(i)1)a)f:\powerpnt\org2.wmf  BC"  o[X` hp x (#%'0*,.8135@8:<H?AXo CommissionerofCustomsfulfillstheresponsibilitiesofHeadofBureauand  authorizestheimplementationofCustomsAISsecuritysafeguardsbasedonFederalpolicyandguidelines .Reference:TDP7110.HeadofBureau.  BC"  TheprocessownersaredesignatedasAccreditingAuthoritiesfortheCustoms  processesforwhichtheyhaveresponsibility. TheAssistantCommissioner,OIT,performsthefunctionsofPrincipalAccreditingAuthority(PAA)andsharesaccreditingresponsibilitywiththeProcessOwners.Reference:TDP7110.PrincipalAccreditingAuthority(PAA)US Customs AIS Security Policy manual(Final in WP 6.0," ' $David Dingman$0David Dingman,.Computer Security   ,@0AZ"Arial Regular(3$ !  ab '  .(#U%c%%%MINIMUMSECURITYREQUIREMENTS#%y%%U%c-#Ԉ X A7-) xd9E1xAAIS org p Vf$Ӏ  1    0  OMBCircularA130,February8,1996requiresthatsecurityawarenesstrainingmustbe X periodic.TheNISTComputerSecurityTrainingGuidelines,11/89recommendannual 2 refreshertraining,butitisnotarequirement.[NIST500172]F  Z 2CG Times (WN) Regular(-!2Vf$ !  Ӏ  0    Vf$Ӏ  2    9%  <DL!X9ThisCircular'suseoftheterm"materialweakness"shouldnotbeconfusedwithuseofthesame X termbygovernmentauditorstoidentifymanagementcontrolweaknesseswhich,intheiropinion,poseariskorathreattotheinternalcontrolsystemsofanauditedentity,suchasaprogramoroperation.Auditorsarerequiredtoidentifyandreportthosetypesofweaknessesatanylevelofoperationororganization,evenifthemanagementoftheauditedentitywouldnotreporttheweaknessesoutsidetheagency.*:P3 I&mage <=8C HKKKK'C Z 6Times New Roman RegularWPC'x< x< 9!x< 3ƚ`@ @U 1&`@  & &$TNPPMicrosoft PowerPoint & TNPPf & &TNPP ` @ 145--A `&Mt &&&--x0-I--'- $ & &lt---llI--'- $lH & &--t-I--'- $7 & &--p(-I--'- $ & &dl-- -ddI--'- $d@ & & --l-  I--'- $ / & &--p-I--'- $3 & &--b-I--'- $ & &V^---VVI--'- $V2y &  & &--u-P --' &  & &T\---TT--' & &Mty--ytMT--YmTimes New Roman\-.  2  EXECUTIVEDQEJQE%QDTimes New Roman-.  2 ORDERSQKPEK> & &\--"System-\?---' & &it--ti--Times New RomanX-.  !2 NATIONAL SECURITYQQD%QQQE>DKQK%DQTimes New Roman-.  2 DIRECTIVESQ%KDKD&QD> & & \---\b---' & &f--f--Times New RomanX-.  2 W PUBLIC LAWS>QKD&JEQi? & &2:\---\-22--' & &t--t2-- Times New RomanX-.   2 OMBQcKTimes New Roman-.  2 E CIRCULARSK%KJQEQJ? & &\---\'---' & &\--\} 5-T--' & &x -- x-- Times New RomanX-.   2 eFIPS>&>>Times New Roman-.   2 IPUBS>QK> & &H &H --- H--lh$Times New RomanX-.  "2 \TECHNICAL SECURITYDEKPQ&JQE>DKQK%DQTimes New Roman-.  !2 \COMPUTER SECURITYKQc>QEDK>EJQK%EPTimes New RomanX-.  %2 8\INFORMATION SECURITY%Q>QKdQD%QQ>EJQK%EQTimes New Roman-.  *2 \COMMUNICATIONS SECURITYKQcdQQ%KPE%QQ>>EKPK%EQTimes New RomanX-.  2 \ TEMPEST *DEc?D>E8Times New Roman-.  "2 0\PERSONNEL SECURITY>EJ?QPQED>EKPK%EQTimes New RomanX-.  $2 \OPERATIONS SECURITYQ>EJQE%QQ>>EJQK%EQTimes New Roman-.  !2 \PHYSICAL SECURITY>QQ>&JQE>DKQK%DQTimes New RomanX-.  $2 (\INDUSTRIAL SECURITY%QQQ>EJ&QD>EJQK%EQ & &  ---` - --' & & --t - --' & &hp--(-hh --' & & --X - --' & & --l - --' & & T\-- -TT --' & & --P - --' & & --d - --' &  & &T$--$}T5- --' & &&--x0-=--'- $ & &lt---ll=--'- $ lH & &--t-=--'- $ 7 & &--p(-=--'- $  & &dl-- -dd=--'- $ d@ & & --l-  =--'- $ / & &--p-=--'- $ 3 & &--b-=--'- $  & &V^---VV=--'- $ V2y &  & &!H L--L H!V=--, hATimes New RomanX-.  2 yNCSC GUIDELINESQK>KPQ&QDD&QD> & &,@ P---P @,V=--0 `LTimes New Roman-.  2 AGENCY/SERVICEQQDQKQ>DKQ%KDTimes New RomanX-.  2 f (TREASURY)%EJEQ>QKP&Times New Roman-.  2  REGULATIONSKDQQDQE%QQ> & &N ---N V=--l. "Times New RomanX-.  2 ]CUSTOMSKQ>DQd>Times New Roman-.  2 ( REGULATIONSKDQQDQE%QQ> & &%---x0- '--'- $ & &D=L---DDU--'- $5D g & &EBM--B-pEE--'- $Eh" &  & &TNPP & --Level 1Level 2Level 3Level 4Level 5 j :C#  P Figure  2   ݀PolicyHierarchyF  Z 2CG Times (WN) Regular M(  %c%%%MINIMUMSECURITYREQUIREMENTS#%y%%%c# X A7-) xdE1xAWPC'rfrf9!rf9ƚPp @QU }<&Pp & &$TNPPMicrosoft PowerPoint & TNPPf & &TNPP pP  `345-- pP&--(- --' & &x--(x-P--' & & --L -r=--' & &--]-v6--' & &&--o---' & &----yTimes New Roman-.  02 Security Steering CommitteeL<<L<&-D"L-=<<&LD"bDqr%.-<=yTimes New Roman-.  2 2 (Oversight)-jD<=5&DK-. &  & &*RX---XR*yTimes New Roman-.  2 O Commissioner,bDrq&54&DL<="yTimes New Roman-.  %2 NU.S. Customs Serviceb"L""bL5-Dq5"L<<D&=< & &*R---R*yTimes New Roman-.  %2 !Deputy Commissioner,b=KL-D"bDrq&55%DL<="yTimes New Roman-.  %2 JNU.S. Customs Serviceb"L""bL5-Dq5"L<<D&=< & &q2---2qyTimes New Roman-.  $2 aAsst. Commissioner,b55-""cDqq&55&DK=<"yTimes New Roman-.  '2 )EOffice of Informationj--&=<"D-"5L-D<rD-&DKyTimes New Roman-.  2 and TechnologyDLK"[<=KLD&DDD & &w---wyTimes New Roman-. yTimes New Roman-.  *2 ISecurity AdministrationL<<L<&-D"cKr%L&5-<D.%DL & &wV---VwyTimes New Roman-.  2 M Director,b&<=<-D="yTimes New Roman-.  '2 GAIS Security Divisionb5L"K=<L<&-D"b&D&5&DK & &5a--"System-)&GTNPP=5a5a0d40W5aa5 & TNPP---$5aal5l5a$555-$5llv5v5l$555-$5vv55v$555-$555$555-$555$555-$555$5||55|-$555$5qq|5|5q-$555$5ffq5q5f-$555$5\\f5f5\-$555$5QQ\5\5Q-$555$5FFQ5Q5F-$555$5<<F5F5<-$555$511<5<51-$555$5&&1515&-$555$5&5&5-$5 5 5$555-$5  55 $555-$5"5"5$555-$5"",5,5"$555-$5,,7575,$555-$577B5B57$555-$5BBL5L5B$555-$5LLW5W5L$555-$5WWb5b5W$555-$5bbm5m5b$555-$5mmw5w5m$555-$5ww55w$555$555--' & TNPP & TNPP--'-a5yTimes New Roman-. yTimes New Roman-.  32 Field Security AdministratorsS&<&L"K=<L<&-D"bLq&L%5.<D-D=5 & &v>.---)&GTNPP=v>.v6&0d40Wv>..>v & TNPP---$v>v>~~v$&>&>..&-$~>~>~$>>&&-$>>$>>-$>>$>>-$>>$>>-$>>$>>-$>>$>>-$>>$>>-$>>$>>-$>>$>>-$>>$>>-$>>$>>-$>>$>>-$>>$>>-$>>$>>-$>>$>>-$>>$>>-$>>$>>-$>>  $>>-$ > > $>>-$>>$>>-$>>""$>>-$">">**"$z>z>z-$*>*>22*$r>r>zzr-$2>2>992$k>k>rrk-$9>9>AA9$c>c>kkc-$A>A>IIA$[>[>cc[$I>I>[[I--' & TNPP & TNPP--'-.>vyTimes New Roman-.  12 %Security Compliance & ReviewL<<L<&-D"cDqL%&DL<="q"b<D&=byTimes New Roman-.  2  Group (DSOs)j<DLK".bLi5. & & &&N-$PFPF & &-- &  & & Times New Roman-.  '2 N- Systems Engineering%?8+%2],K>8>222>8 '2 N- Computer Operations%Q8]?>%22W>228%8>,Times New Roman-.  -2 - Database Administration%Q8%8?8+2Q>^>,%28%8> '2 - Applications (each)%Q>?28%8>,%282>%Times New Roman-.  2 Z- Communications%Q8]^>>28% 8>+ 2 Z- Field Support%E2>>?>>82% &  & & 2--2 yTimes New Roman-.  $2 Asst. Commissioner,b55-""cDqq&55&DK=<"yTimes New Roman-.   2 )wCFObSjyTimes New Roman-.  -2 (Financial Process Owner)-S&LDK=&D%"S=D<=45"jbL<=- & &2---2yTimes New Roman-.  $2 BAsst. Commissioner,b55-""cDqq&55&DK=<"yTimes New Roman-.  2 )(Other Process-j-L<="S<D=<55yTimes New Roman-.  2 Owners)jbL<<5. & &n &n &qn --$f ii}} & &?d --e ? &  & &Times New Roman-.  <2 #Distributed Systems Access ControlsQ,%8828>8,2W+Q221,,J88&8+Times New Roman-.  -2 Mainframe Access Controlsd18&%2W2P222+,J88 %8,Times New Roman-.  62 !Policy, Procedures, & Standards>8 18?%82188&1,W>2882%8,Times New Roman-.  !2 Technical SupportD228821?8888% &  & &}---??}}}-=\}--' & &--^-M=--' & &px-- 0-pp--' & &TNPP & --(3$ !  'C Z 6Times New Roman Regular($0 ($0 0 (@$0  0` (#(#0 ` (#` (# ` ]Gray MatE d <d d <d d'C Z 6Times New Roman Regular'C Z 6Times New Roman Regular2-  Level 1 Level 2 Level 3 Level 4 Level 51- 5-  '  @@*(#4%c%%%SECURITYINCIDENTSANDVIOLATIONS#%y%%4%c-#Ԉ X A7-) xdE1xA($    >a$"Small Circle"0.. :C#  P Figure  3   .CustomsAISSecurityOrganization  ,@0AZ"Arial Regular(2C$ !  ,@0AZ"Arial Regular#$% X BC"  Ownersofsensitivedatamustensurethatappropriatesafeguardsareemployed  toprotectthedatafromunauthorizedaccessduringthelifeofthedatawhiletheyaretheresponsibleowner.Thisincludesthetransferofthedatabyanymeans,toanotherperson,application,AIS,orprocess . d7777'dxd Level 1 Level 2 Level 3 Level 4 Level 5(2C$ !  ("$ Figure    9:;8A<< c  BC"  o[X` hp x (#%'0*,.8135@8:<H?AXo TheAISSecurityAdministratorisassignedthefunctionalresponsibilitiesofthe  InformationSystemsSecurityOfficer(ISSO)andNetworkSecurityOfficer(NSO). Reference:TDP7110.InformationSystemsSecurityOfficer. V 3C)  A7-) xdEWxA X Q%c%%%Q&&%%cJune1996NN(#U.S.CustomsServiceAISSecurityPolicyManual#T&&&&q##T%y%&&#Ԉ g ̃ Level 1 Level 2 Level 3 Level 4 Level 5($     (2C$ !  @B:A87777E<< c : :C#  Figure3 .WarningBanner P BC"  &&%%o[X` hp x (#%'0*,.8135@8:<H?AXo TheADPSteeringCommittee,SecuritySubcommitteeprovidesauthorityfor  theCustomsAISSecurityProgram. #%y%&&#ԅLevel 1Level 2Level 3Level 4Level 5  BC"  &&%%o[X` hp x (#%'0*,.8135@8:<H?AXo TheDirector,AISSecurityDivision,OIT,isthedesignatedAISSecurity  Officer.    6Times New Roman Regular  BC"  TheAssistantCommissioner(AC),OIT,&&%%ԀperformsthefunctionsoftheSenior  InformationResourcesManagementOfficial(SIRMO)and#%y%&&C#Principal  AccreditingAuthority(PAA) .  TheACisdesignatedasanAccreditingAuthority(AA)forCustomsAISsprocessing,storing,ortransmittingsensitiveinformation.TheProcessOwnersarealsodesignatedasAAsfortheirCustomsprocesses.Reference:TDP7110.PrincipalAccreditingAuthority(PAA)andSeniorInformationResourcesManagementOfficial(SIRMO).,@0AZ"Arial Regular  BC"    &&%%THISISAU.S.CUSTOMSSERVICECOMPUTERNETWORK  SYSTEM.U.S.CUSTOMSSERVICECOMPUTERNETWORKSYSTEMSAREPROVIDEDFORTHEPROCESSINGOFOFFICIALU.S.GOVERNMENTINFORMATIONONLY.ALLDATACONTAINEDONU.S.CUSTOMSSERVICECOMPUTERNETWORKSYSTEMSAREOWNEDORCONTROLLEDBYTHEU.S.CUSTOMSSERVICE,ANDMAY,FORTHEPURPOSEOFPROTECTINGTHERIGHTSANDPROPERTYOFTHEU.S.CUSTOMSSERVICE,BEMONITORED,INTERCEPTED,RECORDED,READ,COPIED,ORCAPTUREDINANYMANNERBYAUTHORIZEDSYSTEMSPERSONNEL.THEREISNORIGHTOFPRIVACYINTHISSYSTEM.SYSTEMSPERSONNELMAYGIVETOLAWENFORCEMENTOFFICIALSANYPOTENTIALEVIDENCEOFCRIMEFOUNDONU.S.CUSTOMSSERVICECOMPUTERNETWORKSYSTEMS.USE    OFTHISSYSTEMBYANYUSER,AUTHORIZEDORUNAUTHORIZED,CONSTITUTESCONSENTTOTHISMONITORING,INTERCEPTION,RECORDING,READING,COPYING,ORCAPTURINGANDDISCLOSURE. #%y%&&*#(3$ !  6Times New Roman Regular,@0AZ"Arial Regular("$ Figure    ,@0AZ"Arial Regular,@0AZ"Arial Regular$359AM]q111.11.1.11.1.1.11.1.1.1.11.1.1.1.1.11.1.1.1.1.1.11.1.1.1.1.1.1.1F  Z 2CG Times (WN) Regular,@0AZ"Arial Regular'C Z 6Times New Roman Regular '  =(#O%c%%%GENERALPOLICY#%y%%O%c-#Ԉ X A7-) xdE1xA M(  %c%%%GENERALPOLICY#%y%%%c# X A7-) xdE1xA '  R%c%%%4(#AISSECURITYLIFECYCLE#%y%%R%c#Ԉ X A7-) xdE1xA M(  %c%%%AISSECURITYLIFECYCLE#%y%%%c# X A7-) xddE1xA3- 4-    *  ^%c%%%^&&%%cA7-) xdEWxA X U.S.CustomsServiceAISSecurityPolicyManualB(#June1996#^%c%&&:#^&&%%c#`&&&&#Ԉ g #`%y%&&#,@0AZ"Arial Regular M(  c%c%%%SECURITYINCIDENTSANDVIOLATIONS#%y%%c%c# X A7-) xdE1xAF  Z 2CG Times (WN) Regular(8c$0  0` (#(#   (,!$0  0` (#(#  ,@0AZ"Arial Regular % '  C(#%c%%%&&%|%cFOREWORD X A7-) xddE1xA 2 #&&&|&-##%y%&&L#'C Z 6Times New Roman Regular'C Z 6Times New Roman Regular'C Z 6Times New Roman Regular '  j%c%%%66C(#GLOSSARY X A7-) xdE1xA((3/Q$ !   d ,@0AZ"Arial Regular'C Z 6Times New Roman Regular'C Z 6Times New Roman Regular M(  %c%%%GLOSSARY#%y%%%c# X A7-) xdE1xA'C Z 6Times New Roman Regular'C Z 6Times New Roman Regular'C Z 6Times New Roman Regular:y  <<= 8C'C Z 6Times New Roman Regular'C Z 6Times New Roman Regular'C Z 6Times New Roman Regular'C Z 6Times New Roman Regular'C Z 6Times New Roman Regular'C Z 6Times New Roman Regular'C Z 6Times New Roman Regular'C Z 6Times New Roman Regular'C Z 6Times New Roman Regular'C Z 6Times New Roman Regular'C Z 6Times New Roman Regular'C Z 6Times New Roman Regular'C Z 6Times New Roman Regular'C Z 6Times New Roman Regular'C Z 6Times New Roman Regular'C Z 6Times New Roman Regular'C Z 6Times New Roman Regular'C Z 6Times New Roman Regular,@0AZ"Arial Regular'C Z 6Times New Roman Regular'C Z 6Times New Roman Regular '  %c%%%  APPENDIXC#%y%%%c# X :A7-) xdE1xA '  A(#%c%%%APPENDIXA#%y%%%c-#Ԉ X A7-) xdE1xA,@0AZ"Arial Regular M(  %c%%%APPENDIXA#%y%%%c# X A7-) xddE1xA'C Z 6Times New Roman Regular,@0AZ"Arial Regular '  %c%%%  APPENDIXB#%y%%%c# X :A7-) xdE1xA,@0AZ"Arial Regular M(  %c%%%APPENDIXB#%y%%%c# X A7-) xdE1xA,@0AZ"Arial Regular,@0AZ"Arial Regular M(  %c%%%APPENDIXC#%y%%%c# X A7-) xdE1xA,@0AZ"Arial Regular'C Z 6Times New Roman Regular '  %c%%%  APPENDIXD#%y%%%c# X :A7-) xdusE1xA,@0AZ"Arial Regular M(  %c%%%APPENDIXD#%y%%%c# X A7-) xd E1xA,@0AZ"Arial Regular'C Z 6Times New Roman Regular '  %c%%%  APPENDIXE#%y%%%c# X :A7-) xdE1xA,@0AZ"Arial RegularF  Z 2CG Times (WN) Regular'C Z 6Times New Roman Regular U 3C)  A7-) xdEWxA X %c%%%&&%%cJune1996NN(#U.S.CustomsServiceAISSecurityPolicyManual#&&&&q##%y%&&#Ԉ g ,@0AZ"Arial RegularIndex-  M(  %c%%%APPENDIXE#%y%%%c# X A7-) xddE1xA,@0AZ"Arial Regular'C Z 6Times New Roman Regular '    %c%%%APPENDIXF#%y%%%c'# X A7-) xdE1xA,@0AZ"Arial Regular M(  %c%%%APPENDIXF#%y%%%c# X A7-) xdE1xA,@0AZ"Arial Regular'C Z 6Times New Roman Regular '  %c%%%  APPENDIXG#%y%%%c# X :A7-) xdE1xA,@0AZ"Arial Regular M(  %c%%%APPENDIXG#%y%%%c# X A7-) xddE1xA,@0AZ"Arial Regular '    %c%%%COMMENT#%y%%%c'# X A7-) xd^E1xABib- Glos- F  Z 2CG Times (WN) Regular,@0AZ"Arial Regular '    %c%%%INDEX#%y%%%c'# X A7-) xdE1xA,@0AZ"Arial Regular M(  %c%%%INDEX#%y%%%c# X A7-) xdE1xA,@0AZ"Arial Regular'C Z 6Times New Roman Regular   *  A7-) xdEWxA X %c%%%&&%%cU.S.CustomsServiceAISSecurityPolicyManualB(#June1996#%c%&&#&&%%c#&&&&q#&&&&Ԉ g #&&&&_##%y%&&#,@0AZ"Arial Regular'C Z 6Times New Roman Regular V 3C)  A7-) xdEWxA X %c%%%&&%%cJune1996NN(#U.S.CustomsServiceAISSecurityPolicyManual#&&&&q##%y%&&#Ԉ g    *  %c%%%&&%%cA7-) xdEWxA X U.S.CustomsServiceAISSecurityPolicyManualB(#June1996#%c%&&:#&&%%c#&&&&#Ԉ g #%y%&&#,@0AZ"Arial RegularF  Z 2CG Times (WN) Regular*:P8A<< C '  %c%%%88C(#CONTENTS#%y%%2%c#Ԉ X A7-) xd^E1xA,@0AZ"Arial RegularF  Z 2CG Times (WN) Regular'C Z 6Times New Roman Regular M(  %c%%%CONTENTS#%y%%%c# X A7-) xdE1xA,@0AZ"Arial RegularF  Z 2CG Times (WN) Regular '  ?(#%c%%%INTRODUCTION#%y%%K%c-#Ԉ X A7-) xdE1xA,@0AZ"Arial RegularC- D- E- F- G- F  Z 2CG Times (WN) Regular M(  %c%%%INTRODUCTION#%y%%%c# X A7-) xdE1xA '  %c%%%  BIBLIOGRAPHY#%y%%%c# X :A7-) xdE1xA,@0AZ"Arial RegularF  Z 2CG Times (WN) Regular j :C#  P Figure  2   ݀PolicyHierarchy M(  %c%%%BIBLIOGRAPHY#%y%%%c# X A7-) xdE1xA '  =(#%c%%%GENERALPOLICY#%y%%O%c-#Ԉ X A7-) xdE1xA,@0AZ"Arial RegularF  Z 2CG Times (WN) Regular M(  %c%%%GENERALPOLICY#%y%%%c# X A7-) xdE1xA,@0AZ"Arial RegularF  Z 2CG Times (WN) Regular  BC"  o[X` hp x (#%'0*,.8135@8:<H?AXo CommissionerofCustomsfulfillstheresponsibilitiesofHeadofBureauand  authorizestheimplementationofCustomsAISsecuritysafeguardsbasedonFederalpolicyandguidelines .Reference:TDP7110.HeadofBureau. :C#  P Figure  3   .CustomsAISSecurityOrganization   P BC"  &&%%o[X` hp x (#%'0*,.8135@8:<H?AXo TheADPSteeringCommittee,SecuritySubcommitteeprovidesauthorityfor  theCustomsAISSecurityProgram. #%y%&&#,@0AZ"Arial RegularF  Z 2CG Times (WN) Regular,@0AZ"Arial Regular  BC"  TheAssistantCommissioner(AC),OIT,&&%%ԀperformsthefunctionsoftheSenior  InformationResourcesManagementOfficial(SIRMO)and#%y%&&C#Principal  AccreditingAuthority(PAA) .  TheACisdesignatedasanAccreditingAuthority(AA)forCustomsAISsprocessing,storing,ortransmittingsensitiveinformation.TheProcessOwnersarealsodesignatedasAAsfortheirCustomsprocesses.Reference:TDP7110.PrincipalAccreditingAuthority(PAA)andSeniorInformationResourcesManagementOfficial(SIRMO).,@0AZ"Arial RegularF  Z 2CG Times (WN) Regular,@0AZ"Arial Regular  BC"  &&%%o[X` hp x (#%'0*,.8135@8:<H?AXo TheDirector,AISSecurityDivision,OIT,isthedesignatedAISSecurity  Officer. F  Z 2CG Times (WN) Regular  BC"  TheprocessownersaredesignatedasAccreditingAuthoritiesfortheCustoms  processesforwhichtheyhaveresponsibility. TheAssistantCommissioner,OIT,performsthefunctionsofPrincipalAccreditingAuthority(PAA)andsharesaccreditingresponsibilitywiththeProcessOwners.Reference:TDP7110.PrincipalAccreditingAuthority(PAA) X BC"  Ownersofsensitivedatamustensurethatappropriatesafeguardsareemployed  toprotectthedatafromunauthorizedaccessduringthelifeofthedatawhiletheyaretheresponsibleowner.Thisincludesthetransferofthedatabyanymeans,toanotherperson,application,AIS,orprocess .,@0AZ"Arial Regular  BC"  o[X` hp x (#%'0*,.8135@8:<H?AXo TheAISSecurityAdministratorisassignedthefunctionalresponsibilitiesofthe  InformationSystemsSecurityOfficer(ISSO)andNetworkSecurityOfficer(NSO). Reference:TDP7110.InformationSystemsSecurityOfficer.,@0AZ"Arial Regular '  %c%%%4(#AISSECURITYLIFECYCLE#%y%%R%c#Ԉ X A7-) xdE1xA,@0AZ"Arial RegularF  Z 2CG Times (WN) Regular M(  %c%%%AISSECURITYLIFECYCLE#%y%%%c# X A7-) xddE1xA,@0AZ"Arial RegularF  Z 2CG Times (WN) Regular '  .(#%c%%%MINIMUMSECURITYREQUIREMENTS#%y%%U%c-#Ԉ X A7-) xd9E1xA,@0AZ"Arial RegularF  Z 2CG Times (WN) Regular M(  %c%%%MINIMUMSECURITYREQUIREMENTS#%y%%%c# X A7-) xdE1xA,@0AZ"Arial RegularF  Z 2CG Times (WN) RegularA- B-   BC"    &&%%THISISAU.S.CUSTOMSSERVICECOMPUTERNETWORK  SYSTEM.U.S.CUSTOMSSERVICECOMPUTERNETWORKSYSTEMSAREPROVIDEDFORTHEPROCESSINGOFOFFICIALU.S.GOVERNMENTINFORMATIONONLY.ALLDATACONTAINEDONU.S.CUSTOMSSERVICECOMPUTERNETWORKSYSTEMSAREOWNEDORCONTROLLEDBYTHEU.S.CUSTOMSSERVICE,ANDMAY,FORTHEPURPOSEOFPROTECTINGTHERIGHTSANDPROPERTYOFTHEU.S.CUSTOMSSERVICE,BEMONITORED,INTERCEPTED,RECORDED,READ,COPIED,ORCAPTUREDINANYMANNERBYAUTHORIZEDSYSTEMSPERSONNEL.THEREISNORIGHTOFPRIVACYINTHISSYSTEM.SYSTEMSPERSONNELMAYGIVETOLAWENFORCEMENTOFFICIALSANYPOTENTIALEVIDENCEOFCRIMEFOUNDONU.S.CUSTOMSSERVICECOMPUTERNETWORKSYSTEMS.USE    OFTHISSYSTEMBYANYUSER,AUTHORIZEDORUNAUTHORIZED,CONSTITUTESCONSENTTOTHISMONITORING,INTERCEPTION,RECORDING,READING,COPYING,ORCAPTURINGANDDISCLOSURE. #%y%&&*#F  Z 2CG Times (WN) Regular : :C#  Figure3 .WarningBanner '  @@*(#%c%%%SECURITYINCIDENTSANDVIOLATIONS#%y%%4%c-#Ԉ X A7-) xdE1xA,@0AZ"Arial RegularF  Z 2CG Times (WN) Regular M(  %c%%%SECURITYINCIDENTSANDVIOLATIONS#%y%%c%c# X A7-) xdE1xA,@0AZ"Arial RegularF  Z 2CG Times (WN) Regular '  %c%%%66C(#GLOSSARY X A7-) xdE1xA,@0AZ"Arial Regular M(  %c%%%GLOSSARY#%y%%%c# X A7-) xdE1xA,@0AZ"Arial RegularF  Z 2CG Times (WN) Regular '  %c%%%  BIBLIOGRAPHY# %y%%%c# X :A7-) xdE1xA,@0AZ"Arial RegularF  Z 2CG Times (WN) Regular M(   %c%%%BIBLIOGRAPHY# %y%%%c# X A7-) xdE1xA,@0AZ"Arial RegularF  Z 2CG Times (WN) Regular '  A(#%c%%%APPENDIXA#%y%%%c-#Ԉ X A7-) xdE1xA,@0AZ"Arial RegularF  Z 2CG Times (WN) Regular M(  %c%%%APPENDIXA#%y%%%c# X A7-) xddE1xA,@0AZ"Arial RegularF  Z 2CG Times (WN) Regular '  %c%%%  APPENDIXB#%y%%%c# X :A7-) xdE1xA,@0AZ"Arial RegularF  Z 2CG Times (WN) Regular M(  %c%%%APPENDIXB#%y%%%c# X A7-) xdE1xA,@0AZ"Arial RegularF  Z 2CG Times (WN) Regular '  %c%%%  APPENDIXC#%y%%%c# X :A7-) xdE1xA,@0AZ"Arial RegularComment- F  Z 2CG Times (WN) Regular M(  %c%%%APPENDIXC#%y%%%c# X A7-) xdE1xA,@0AZ"Arial RegularF  Z 2CG Times (WN) Regular '  !%c%%%  APPENDIXD#"%y%%%c# X :A7-) xdusE1xA,@0AZ"Arial RegularF  Z 2CG Times (WN) Regular M(  $%c%%%APPENDIXD#%%y%%%c# X A7-) xd E1xA,@0AZ"Arial RegularF  Z 2CG Times (WN) Regular '  '%c%%%  APPENDIXE#(%y%%%c# X :A7-) xdE1xA,@0AZ"Arial RegularF  Z 2CG Times (WN) Regular M(  *%c%%%APPENDIXE#+%y%%%c# X A7-) xddE1xA,@0AZ"Arial RegularF  Z 2CG Times (WN) Regular  Vf$Ӏ  1    0  OMBCircularA130A130,February8,1996requiresthatsecurityawareness#awareness#Ԁtraining!training!Ԁmustbe X periodic.TheNISTComputerSecurityTraining!Training!ԀGuidelines,11/89recommendannual 2 refreshertraining!training!,butitisnotarequirement.[NIST500172] '    .%c%%%APPENDIXF#/%y%%%c'# X A7-) xdE1xA,@0AZ"Arial RegularF  Z 2CG Times (WN) Regular M(  1%c%%%APPENDIXF#4%y%%%c# X A7-) xdE1xA,@0AZ"Arial Regular*:P3&OLE 2.0 Box <=8C HKKKK'dxdF  Z 2CG Times (WN) Regular '  6%c%%%  APPENDIXG#7%y%%%c# X :A7-) xdE1xA,@0AZ"Arial RegularF  Z 2CG Times (WN) Regular M(  9%c%%%APPENDIXG#:%y%%%c# X A7-) xddE1xA,@0AZ"Arial RegularF  Z 2CG Times (WN) Regular  Vf$Ӏ  2    9%  <DL!X9ThisCircular'suseoftheterm"materialweakness3)material weakness3"shouldnotbeconfusedwithuseofthesame X termbygovernmentauditorstoidentifymanagementcontrolweaknesseswhich,intheiropinion,poseariskorathreattotheinternalcontrolsystemsofanauditedentity,suchasaprogramoroperation.Auditorsarerequiredtoidentifyandreportthosetypesofweaknessesatanylevelofoperationororganization,evenifthemanagementoftheauditedentitywouldnotreporttheweaknessesoutsidetheagency.?C:\CA\POLMAN\CS-SEAL.TIFWPC,,9,, =}x 96756 35 24231202/1 /0 ?.0./-/?-.,.,-+-+-*,*,)+)+?  )+  (* (* ?()')')'( &( &( &'?%'%'?%'??$&?$&?$&#%#%#%?#%?"$?"$"$?"$?!#!#?!# !# ? "   "? ?? ? "   "  ?!  ?!?  ! p !     ?  ? ? ??  ? ? ?|? ? ??  ?? ??????????  ? ? ? ?? ???? ?? ?????%%????%??&?????.???*????*????+????'??????0??;???1?1???? ?????????????????<? `?? ? ??? ? ?|?<? ?     ??  ??       ??  ??? `? ? ?? ?     ??   ?   ?? ? ?q?   ?<?  ~?? ? ?  ??? ???     ! "???""#?$x??$?$ %? &?? ?& & ?&  (  ( ?? (  (  )?  ?* ? *  *  * ? +  ,  ? ?,?  ,  ,  ,  -? .? . . ?. / ?/ 0?? 0 0 0? 0 1 2? 2 ?2 ?2 ?2 3? 3? 4? ?       ???  ?     ? ?    ? ???                ??     ??  ?              ?     ? ?   ?  ??       ?     ?           ?   ?   ??    ?? ?             ? ?    - ??  . ??  .   /?   ?/              ? ?     ?   ?    ?   ?    ?   ??   ?     ?     ?    ? ? ?? ?    ? ?? ? ??  ? ??  > ??  ??  ? ??     ?   ? ???? ? ?? ? ?  ?   ?? ??????????????8!p!??!???!?"?''~??    ?  ? ?   ?      ?   ?   ? ?           ? ?   ? ?   ? ?      ?      ?     ?  ?     ?      ?   ?  ?   ?  ?   ?    ? ?    ? ?    ? ?     ?            ?     ?    ?    ?     ?      ?                ?     ?                 ?  ?  ?  ?  ?  ?  ?      ?               ? 8     8  ?  0 x  ?  8|  ?  x  ?    ?               ?    ?        ?    ? ?    ?   ? ? ?  ?  ??  ?  ??  ?  ??  ?  ??    ?              ?     ?     ?           ?      ??      ??      ?    ?  ? ?   ?  ?    ?  ?  ?  ?  ?  ?  ?  ?  ?   ??     ??     ?  ?    ?  ?    ?    ?  ?    ?  ??  ? ?  ?  ? ?  ?  ? ?  ?  ? ?  ? ?   ?                            ?      ? ?     ?                                ?                 ?     ?   ?  ?   ?  ?    ?  ?<  ?  ~  ?    ?    ?  ??  ?  ?  ?    ?  ?  ?      ?    ?        ??  ?    ?    ?  ?  ?    ?    ?    ?   ?   ? ? ??   ?? 8 ?? | ?? ? ??   ?? ?  ???   ?? ?   ?? ?   ??    ??     ??    ??    ???    ??    ??    ??    ???    ??    ??    ??    ??    ???  ?  ???    ??    ??    ??  <  ??  ~?  ??     ??     ~??      ??      ??      ??     ??     ?     ?     ?     ?        ?    |              ?     ? ?  ?   ? ?  ? ? <  ? ~?  ? ?  ? ?  ?   ?   ? ?  ? ?  ?  ?  ?  ??  ?    ?   ? ?  ?  ??  ?  ? ? ?  ?? ? ??   ???   ????    ?  ?  0 ?    x ?    ? ?  `        ?    ?? ? ??  ? ? ?  ?? ?    ?     ?     ?     ???   ?  ?? ?  ?  ?  ?  ?  ?  ?  ?  ?  ?  ??  ??  ??  ?  ?  ?  ?  ?    ?   ?? ?  ?     ??????>??>?~??????? ?? ??? ? ?`` ?? ?? ?? ?8 ? ?     ?  ??? ? ???  ???  ?? ? ?   ??   ? ? ? ?  ?       ? ?   ?? ? ? ?? ? ?  ?  ???  >~   ?  ? ?  ? ?? ?  ?  ??? ??  ??? ??? ? ? ? ? ? ? ?? ? ???         ?   ?     ?        @                 ?  ?    ?   ??   ??  ?   ? ?  ?? ???   ???   ??          ?              ? ?   ? ?   ??  ?0? ?  ?  ?   ?   ?          ?   ? ? ?  ?    ? ?  ?? ? ????  ? ? ?   ?   ?  ?    ?    ?               ??  ?  ??  ??  ???  ??  ???  ? ?  ' ?' ? &   ?% ?  %   %  ? %  ?? #   ?# ? ? # ?? ? # ??  " ?  !   !   ! ?  !  ? ? ?    ?   ???  ? ??        ?? ?  ?   <    ?  ?               ?   ??   ?     ? ? ?? ?   ?    ?  ?   ?  ? ?     ?   ?    ?  ?  ?         ? ?  ? ?  ??  ? ?     ? ?  ? ?  ?? ?  ?   ???  ??  ?? ?   ?? ??????? ???  ?? ?????????~? ? ?????  ?? ??? p??? p?? ????  ??    ??              ?? ? ??    ??   ??  ? ? ? ? ? ? ?? <? ? ? ??  ?   ?       ?? ?? ?? ?    ?? ?? ? ?   ? ??? ?? ??   ?  ? ?? ????~??~<?<?    ? < < ? < > ?> ??> ?? ? ? ? ?? ????? ??    ? ?? ?!??!??!?! ?!  `?" " "   ?" 0? # |  # ? |  # ? #  !$  !$ !$?!$ "%? "%"%?"%?#&?#&#&?$&$'$'?$' %(? %(? ?%(&)&)?&)'*?'* ?'*? (+ (+ ?(, ),),*-*-*.+.,/,/,0 -0 -1 .2/2/3041415 ?26 38 ?496<9x# % '  C(#|%c%%%|&&%|%cFOREWORD X A7-) xddE1xA 2 #&&&|&-##%y%&&L#,@0AZ"Arial Regular U 3C)  A7-) xdEWxA X %c%%%&&%%cJune1996NN(#U.S.CustomsServiceAISSecurityPolicyManual#&&&&q##%y%&&#Ԉ g ,@0AZ"Arial Regular   *  A7-) xdEWxA X %c%%%&&%%cU.S.CustomsServiceAISSecurityPolicyManualB(#June1996#%c%&&#&&%%c#&&&&q#&&&&Ԉ g #&&&&_##%y%&&#,@0AZ"Arial Regular '  2%c%%%88C(#CONTENTS#%y%%2%c#Ԉ X A7-) xd^E1xA M(  %c%%%CONTENTS#%y%%%c# X A7-) xdE1xA '  ?(#K%c%%%INTRODUCTION#%y%%K%c-#Ԉ X A7-) xdE1xA M(  %c%%%INTRODUCTION#%y%%%c# X A7-) xdE1xA !  %%XX7NpQNdd7%%%>%%%%]%      &&%%Z&&@  #&&ZF#xx&&AUTOMATEDINFORMATION X @SYSTEMSSECURITYPOLICY#&&xx# &&  0 j>6&"`x0   `(El  ! Vj ! ! (#(# ! ! ! !  ! ! ! !  ! ! ! !  ! ! ! !  ! ! ! !  ! ! ! !  ! ! ! !  ! ! ! !  ! ! ! !  ! ! ! !  ! ! ! !  ! ! ! !  ! ! ! !  ! ! ! !  ! ! ! !  ! ! ! !  ! ! ! !  ! ! ! !  (#(#! ! @77#CISHB140005 "  @&June1996@@  D  B$! DepartmentoftheTreasury'(#OfficeofInformationandTechnology *(# UnitedStatesCustomsServicexx(#AutomatedInformationSystemsSecurityDivision#&& 3#Ԉ  +)$v   @*  J 2 %{%%d%%~%%%%%%%  C(#&&Foreword#&&#Ԉ X A&-) xdE7xA 8 TheU.S.CustomsService,OfficeofInformationandTechnologyAutomatedInformationSystems(AIS)SecurityPolicyManualisintendedforthosewhouseCustomsAISservicesandsystems.InformationthroughoutthemanualsupportstheCustomsmissionbyprovidingdirectionandguidancetoprotectAISresources.Itestablishesuniformpolicies,responsibilities,andauthoritiesforcarryingouttheCustomsAISSecurityProgram.Securityisprovidedforinformationthatiscollected,processed,transmitted,stored,ordistributedforallotheragenciesutilizingCustomsgeneralsupportsystemsandmajorapplications.ThishighlevelpolicymanualsupplementstheAISsecuritypoliciesestablishedbytheU.S.DepartmentoftheTreasury,andisconsistentwithgovernmentwidepolicies,standards,andproceduresissuedbytheOfficeofManagementandBudget%%OEOffice of Management and BudgetO%%,theDepartmentofCommerce,theGeneralServicesAdministration,andtheOfficeofPersonnelManagement%%MCOffice of Personnel ManagementM%%.Additionaldetailedandspecificproceduralguidelines,particulartoCustomsneedsandrequirements,willbeissuedinaniterativefashion,asappropriate.Priorreleasesofthismanual(CISHB140004)aresuperseded.%y%&&AdditionalcopiesmaybeobtainedbysubmittingCustomsFormCF205toU.S.CustomsService, ' Printing&MailTeam,1301ConstitutionAvenue,NW,RoomB338,Washington,DC20229.NonCustomsFederalandcivilagencies,organizations,andmembersofthetradecommunity%%/%trade community/%%maycontacttheirCustomsrepresentative,orobtainthemanualviatheInternet%%!Internetu!!Internetu!%%fromCustomsWorldWideWeb%%-#World Wide Web-%%(WWW)pageontheNationalTechnicalInformationService(NTIS)FedWorld,at   http://fedworld.gov ,asavailable. i #&&%%y #TheU.S.CustomsServicewishestoextendspecialthankstotheFederalBureauofInvestigation%%OEFederal Bureau of Investigation@O%%,InformationSystemsSecurityUnit,forvaluableinputwhichprovidedthebasisforthedevelopmentofthisdocument,totheNationalSecurityAgency%%A7National Security AgencyaA%%fortheirreviewandsuggestions,andtotheU.S.DepartmentoftheTreasury,OfficeofInformationSystemsSecurity,fortheiroversight%%#oversightc#%%andguidance.0  0` (#(#0 ` (#` (#0 (# (#0h(#(#0h(#h(#(original%signd%%signed%byGeorgeJ.Weise) (#(# 0  0` (#(#0 ` (#` (#0 (# (#0h(#(#0h(#h(#0(#(#Commissioner%%)Commissioneri)%% (#(# Distribution%%)Distributioni)%%:G-25  "Y %    @*  J  %{%%{%%%%%    HP@@TT"&&