Update: The Department has adopted SITSD policy, with additions where applicable as it pertains to CJI. The objective for role based has been slow due to positions being reclassified across the executive making it difficult for automation of role based via MIM.
Objectives
-
Continue to develop information security policies for all National Institute of Standards and Technology (NIST) families.
Update: This objective is an ongoing and permanent process
-
Continue to implement NIST security controls that ensure the security, privacy, availability, and integrity of data and systems.
Update: This objective is an ongoing and permanent process
-
Ensure access to data and systems is appropriate, allowing access only for those with a legitimate need.
Update: This objective is an ongoing and permanent process
-
Work with department HR staff to develop staff roles that will be used when granting role-based security as with the Enterprise FIM and MIM process.
Update: This objective is an ongoing and permanent process