Information Security Controls Standard (SS-17-001)
Topics:
- Title: Information Security Controls Standard, SS-17-001 Information Security Controls
- Effective Date: 7/1/2017
- Review Date: 02/26/2026
Purpose
In accordance with the Information Security Control Policy, each agency operating within a Shared Services Environment is responsible for ensuring that applicable NIST SP 800-53, Security and Privacy Controls for Information Systems and Organizations (current published version), aligned to the State-adopted baseline, are implemented and operated effectively. This standard establishes responsibilities for security controls per application and/or system operating within a Shared Services Environment, including systems hosted in Third-Party and cloud-based environments. The standard also establishes the minimum baseline for periodic security control reviews, assessments, and technical testing as well as audits by the State Department of Audits and Accounts (DOAA).
Scope and Authority
- O.C.G.A 50-25-4(a)(9) – State Government, Georgia Technology, General Powers
- O.C.G.A 50-25-4(a)(20) - State Government, Georgia Technology, General Powers
- O.C.G.A. 50-25-4(a)(27) – State Government, Georgia Technology, General Powers
- O.C.G.A 50-25-4(a)(28) State Government, Georgia Technology General Powers
- PS-08-005 Enterprise Information Security Policy
- PM-04-001 Information Technology Policies, Standard Guidelines
Terms and Definitions
- Agency - every state department, agency, board, bureau, commission, and authority but shall not include any agency within the judicial or legislative branch of state government, the Georgia Department of Defense, departments headed by elected constitutional officers of the state, or the University System of Georgia and shall also not include any authority statutorily required to effectuate the provisions of Part 4 of Article 9 of Title 11.
- Service Integrators/ Managed Service Integrators (MSI) - company that is responsible for coordinating and overseeing the delivery of technology services to state agencies by multiple service providers.
- Service Provider/Third Party Service Provider – contractor, service provider, consultant or any other individual and/or organization external to state government providing services or behalf of, for, or as an agent of state government.
- Shared Services Environment - dedicated unit (including people, processes and technologies) that is structured as a centralized point of service and is focused on defined business functions and providing services for multiple agencies.
Standard
This standard applies to systems hosted on-premise, within shared State facilities, or in cloud-based environments including Software as a Service (SaaS), Platform as a Service (PaaS), and Infrastructure as a Service (IaaS), as well as systems operated by third-party service providers.
Agencies and Service Providers (including Managed Service Integrators (MSI)) shall comply with all applicable security controls outlined within the standard in accordance with NIST SP 800-53, Security and Privacy Controls for Information Systems and Organizations (current published version).
Security controls shall be categorized, consistent with NIST SP 800-53 guidance, as Common Controls, Hybrid Controls or System-Specific Controls.
Control categorization shall be documented within system-level security documentation.
The applicable control families are listed below:
| Technical Controls | Operational Controls | Managerial Controls |
| AC - Access Control | AT - Awareness Training | CA - Security Assessment /Authorization |
| AU - Audit & Accountability | CM - Configuration Management | PL - Planning |
| IA - Identification & Authentication | CP - Contingency Planning | RA - RiskAssessment |
| SC - System & Communication Protection | IR - Incident Response | SA - System& Services Acquisition |
| SI - System & InformationIntegrity | MA - Maintenance | PM – Program Management |
| MP - Media Protection | PT – PII Processing & Transparency | |
| PE - Physical & Environmental Protection | SR – Supply Chain Risk Management | |
| PS - Personnel Security |
The Information Security Control Responsibility Model – Shared Services Hosting Models (Figure A-1) below, provides a perspective of shared responsibilities for Agencies, Service Providers, and MSI across the State’s IT enterprise. It also defines responsibility across hosting models, including Third-Party and Cloud-Based Hosting Models.
Although an agency may not have technical responsibility for certain controls under Shared Services Hosting Models, the agency retains ultimate accountability for compliance requirements.
For systems where security is provisioned, implemented, and maintained solely by agency staff, Figure A-1 responsibility allocations do not apply; however, this standard and other enterprise IT standards remain applicable.
Figure A-1: Information Security Control Responsibility Model – Shared Services Hosting Models
EXEMPTIONS
Agencies may request an exemption from the implementation of any enterprise information technology policy or standard by submitting an exemption form to [email protected]. The exemption must be approved by the State Chief Information Officer (CIO) with review by the State Chief Information Security Officer.
In each case, the agency or vendor must include such items as:
- Control(s) and standard(s) for which exception is being requested
- Business justification and impact for the exception
- Appropriate risk assessment associated with non-compliance
- Safeguards planned or implemented to mitigate risks (compensating controls)
- Residual risks
- Specific timeframe/duration to evaluate progress toward compliance
- Management or Agency leadership approval (to include the following: Business function owner, CIO, CISO/ISO/designated security representative, Agency Head, or delegate/Executive Director)
An exemption request cannot be reviewed unless all residual risks have been identified and the Agency leadership has provided approval, indicating acceptance of these risks. Exemption requests must be re-evaluated periodically, and extension requests are required after one year.
RELATED ENTERPRISE POLICIES, STANDARDS AND GUIDELINES
Risk Management Framework Standard (SS-08-041)
Information Security Infrastructure Standard (SS-08-005)
Independent Security Assessments Standard (SS-08-042)
REFERENCES
- NIST SP 800-53, Security and Privacy Controls for Information Systems and Organizations (current published version)
- FIPS 199, Standards for Security Categorization of Federal Information and Information Systems