• Title: Information Security Controls Standard, SS-17-001 Information Security Controls
  • Effective Date: 7/1/2017
  • Review Date: 02/26/2026

Purpose

In accordance with the Information Security Control Policy, each agency operating within a Shared Services Environment is responsible for ensuring that applicable NIST SP 800-53, Security and Privacy Controls for Information Systems and Organizations (current published version), aligned to the State-adopted baseline, are implemented and operated effectively. This standard establishes responsibilities for security controls per application and/or system operating within a Shared Services Environment, including systems hosted in Third-Party and cloud-based environments. The standard also establishes the minimum baseline for periodic security control reviews, assessments, and technical testing as well as audits by the State Department of Audits and Accounts (DOAA). 

Scope and Authority

  • O.C.G.A 50-25-4(a)(9) – State Government, Georgia Technology, General Powers
  • O.C.G.A 50-25-4(a)(20) - State Government, Georgia Technology, General Powers
  • O.C.G.A. 50-25-4(a)(27) – State Government, Georgia Technology, General Powers
  • O.C.G.A 50-25-4(a)(28) State Government, Georgia Technology General Powers
  • PS-08-005 Enterprise Information Security Policy 
  • PM-04-001 Information Technology Policies, Standard Guidelines

Terms and Definitions

  • Agency - every state department, agency, board, bureau, commission, and authority but shall not include any agency within the judicial or legislative branch of state government, the Georgia Department of Defense, departments headed by elected constitutional officers of the state, or the University System of Georgia and shall also not include any authority statutorily required to effectuate the provisions of Part 4 of Article 9 of Title 11. 
  • Service Integrators/ Managed Service Integrators (MSI) - company that is responsible for coordinating and overseeing the delivery of technology services to state agencies by multiple service providers. 
  • Service Provider/Third Party Service Provider – contractor, service provider, consultant or any other individual and/or organization external to state government providing services or behalf of, for, or as an agent of state government.
  • Shared Services Environment - dedicated unit (including people, processes and technologies) that is structured as a centralized point of service and is focused on defined business functions and providing services for multiple agencies.

Standard

This standard applies to systems hosted on-premise, within shared State facilities, or in cloud-based environments including Software as a Service (SaaS), Platform as a Service (PaaS), and Infrastructure as a Service (IaaS), as well as systems operated by third-party service providers.

Agencies and Service Providers (including Managed Service Integrators (MSI)) shall comply with all applicable security controls outlined within the standard in accordance with NIST SP 800-53, Security and Privacy Controls for Information Systems and Organizations (current published version). 

Security controls shall be categorized, consistent with NIST SP 800-53 guidance, as Common Controls, Hybrid Controls or System-Specific Controls.

Control categorization shall be documented within system-level security documentation.

The applicable control families are listed below:

Technical ControlsOperational ControlsManagerial Controls
AC - Access ControlAT - Awareness Training

CA - Security Assessment

/Authorization

AU - Audit & AccountabilityCM - Configuration ManagementPL - Planning
IA - Identification & AuthenticationCP - Contingency PlanningRA - RiskAssessment
SC - System & Communication ProtectionIR - Incident ResponseSA - System& Services Acquisition
SI - System & InformationIntegrityMA - MaintenancePM – Program Management
 MP - Media ProtectionPT – PII Processing & Transparency
 PE - Physical & Environmental ProtectionSR – Supply Chain Risk Management
 PS - Personnel Security 

The Information Security Control Responsibility Model – Shared Services Hosting Models (Figure A-1) below, provides a perspective of shared responsibilities for Agencies, Service Providers, and MSI across the State’s IT enterprise. It also defines responsibility across hosting models, including Third-Party and Cloud-Based Hosting Models.

Although an agency may not have technical responsibility for certain controls under Shared Services Hosting Models, the agency retains ultimate accountability for compliance requirements.

For systems where security is provisioned, implemented, and maintained solely by agency staff, Figure A-1 responsibility allocations do not apply; however, this standard and other enterprise IT standards remain applicable. 

Figure A-1: Information Security Control Responsibility Model – Shared Services Hosting Models 

 

Information Security Control Responsibility Model

EXEMPTIONS

Agencies may request an exemption from the implementation of any enterprise information technology policy or standard by submitting an exemption form to [email protected]. The exemption must be approved by the State Chief Information Officer (CIO) with review by the State Chief Information Security Officer. 

In each case, the agency or vendor must include such items as: 

  • Control(s) and standard(s) for which exception is being requested 
  • Business justification and impact for the exception 
  • Appropriate risk assessment associated with non-compliance 
  • Safeguards planned or implemented to mitigate risks (compensating controls) 
  • Residual risks 
  • Specific timeframe/duration to evaluate progress toward compliance 
  • Management or Agency leadership approval (to include the following: Business function owner, CIO, CISO/ISO/designated security representative, Agency Head, or delegate/Executive Director) 

An exemption request cannot be reviewed unless all residual risks have been identified and the Agency leadership has provided approval, indicating acceptance of these risks. Exemption requests must be re-evaluated periodically, and extension requests are required after one year.

RELATED ENTERPRISE POLICIES, STANDARDS AND GUIDELINES

Risk Management Framework Standard (SS-08-041)

Information Security Infrastructure Standard (SS-08-005)

Independent Security Assessments Standard (SS-08-042)

REFERENCES

  • NIST SP 800-53, Security and Privacy Controls for Information Systems and Organizations (current published version)
  • FIPS 199, Standards for Security Categorization of Federal Information and Information Systems