Need a Information System Security Officer (ISSO)
Budget: ₹100 – ₹400 INR
the ISSO (Information System Security Officer) has several important responsibilities related to the security of information systems within the US Department of Health and Human Services (HHS). Some of the key responsibilities include:
Enterprise Performance Life Cycle (EPLC)/Authorization to Operate (ATO)/Interim Authorization to Test (IATT) Support: This involves working with the System Owner (SO), Business Owner (BO), and the OS Chief Information Security Officer (CISO) to ensure that the appropriate security controls are in place based on the FIPS 199 security categorization. The ISSO also assists with the preparation and submission of Assessment & Authorization (A&A), Authorization to Operate (ATO), and Interim Authorization to Test (IATT) packages for CISO approval.
System Management: The ISSO monitors the information system to ensure that IT security notices and advisories are distributed to appropriate personnel. They also ensure that all security patches are installed in a timely manner and review system-level reports, audit logs, and vulnerability scan reports. Additionally, the ISSO participates in change control/configuration management to determine the security impact of proposed or actual changes to the system or its environment.
Account Management: The ISSO assists with implementing the concept of separation of duties and ensuring that logical access controls and account lockout controls are in place. They also enforce strong passwords, limit failed login attempts, and periodically review audit logs regarding account management activities.
Risk Management: The ISSO helps to maintain an appropriate operational security posture for the information system by executing the SGRC tasks as listed in NIST SP 800-37. They also ensure that security-event monitoring technologies are used for all systems and networks, that all incoming and outgoing connections are made through a firewall, and that security risks are identified.
Incident Management: The ISSO assists with notifying the OS CISO of actual or suspected computer-security incidents, including PII and PHI breaches. They serve as an OS focal point for IT security and privacy incident reporting and subsequent resolution through coordination with the Incident Response (IR) POC/IR team and SO. Additionally, they participate in the development/updating of Incident Response plans, procedures, and reports.
Security Guidance/Analysis: The ISSO reviews contracts for systems under the OS CISO’s control to ensure that IT security is appropriately addressed in contract language. They also serve as a principal advisor/security Subject Matter Expert (SME) on matters involving the security of an information system.
Continuous Monitoring: The ISSO assists with ensuring that proper backup procedures for all system and network information are in place and are performed on a regular basis. They also conduct annual assessments of security controls and participate in Continuous Diagnostic and Mitigation (CDM) control assessments and related activities. Additionally, they review/update security documentation and review system-level reports, audit logs, and vulnerability scan reports on a continuous basis.
These responsibilities are based on federal guidance such as FIPS, NIST, and OMB, and are further outlined in HHS security policies.
Enterprise Performance Life Cycle (EPLC)/Authorization to Operate (ATO)/Interim Authorization to Test (IATT) Support: This involves working with the System Owner (SO), Business Owner (BO), and the OS Chief Information Security Officer (CISO) to ensure that the appropriate security controls are in place based on the FIPS 199 security categorization. The ISSO also assists with the preparation and submission of Assessment & Authorization (A&A), Authorization to Operate (ATO), and Interim Authorization to Test (IATT) packages for CISO approval.
System Management: The ISSO monitors the information system to ensure that IT security notices and advisories are distributed to appropriate personnel. They also ensure that all security patches are installed in a timely manner and review system-level reports, audit logs, and vulnerability scan reports. Additionally, the ISSO participates in change control/configuration management to determine the security impact of proposed or actual changes to the system or its environment.
Account Management: The ISSO assists with implementing the concept of separation of duties and ensuring that logical access controls and account lockout controls are in place. They also enforce strong passwords, limit failed login attempts, and periodically review audit logs regarding account management activities.
Risk Management: The ISSO helps to maintain an appropriate operational security posture for the information system by executing the SGRC tasks as listed in NIST SP 800-37. They also ensure that security-event monitoring technologies are used for all systems and networks, that all incoming and outgoing connections are made through a firewall, and that security risks are identified.
Incident Management: The ISSO assists with notifying the OS CISO of actual or suspected computer-security incidents, including PII and PHI breaches. They serve as an OS focal point for IT security and privacy incident reporting and subsequent resolution through coordination with the Incident Response (IR) POC/IR team and SO. Additionally, they participate in the development/updating of Incident Response plans, procedures, and reports.
Security Guidance/Analysis: The ISSO reviews contracts for systems under the OS CISO’s control to ensure that IT security is appropriately addressed in contract language. They also serve as a principal advisor/security Subject Matter Expert (SME) on matters involving the security of an information system.
Continuous Monitoring: The ISSO assists with ensuring that proper backup procedures for all system and network information are in place and are performed on a regular basis. They also conduct annual assessments of security controls and participate in Continuous Diagnostic and Mitigation (CDM) control assessments and related activities. Additionally, they review/update security documentation and review system-level reports, audit logs, and vulnerability scan reports on a continuous basis.
These responsibilities are based on federal guidance such as FIPS, NIST, and OMB, and are further outlined in HHS security policies.