Skip navigation
U.S. flag

An official website of the United States government

Here’s how you know

Dot gov

The .gov means it’s official.
Federal government websites often end in .gov or .mil. Before sharing sensitive information, make sure you’re on a federal government site.

Https

The site is secure.
The https:// ensures that you are connecting to the official website and that any information you provide is encrypted and transmitted securely.

  • Food Safety
    • Recalls & Public Health Alerts
      • Report a Problem with Food
        • Additional Recalls
      • Annual Recall Summaries
        • Summary of Recall Cases in Calendar Year 2012
        • Summary of Recall Cases in Calendar Year 2013
        • Summary of Recall Cases in Calendar Year 2014
        • Summary of Recall Cases in Calendar Year 2015
        • Summary of Recall Cases in Calendar Year 2016
        • Summary of Recall Cases in Calendar Year 2017
        • Summary of Recall Cases in Calendar Year 2018
        • Summary of Recall Cases in Calendar Year 2019
        • Summary of Recall Cases in Calendar Year 2020
        • Summary of Recall Cases in Calendar Year 2021
    • Food Safety Stats
      • Consumer Research
    • Foodborne Illness and Disease
      • Illnesses and Pathogens
        • Campylobacter
          • Campylobacter En Español
        • Clostridium botulinum
        • Escherichia coli O157:H7
        • Parasites and Foodborne Illness
        • Salmonella Questions and Answers
      • Resources for Public Health Partners
        • State Departments of Public Health
      • Outbreaks
        • Outbreak Investigations: Prevention
        • Outbreak Investigations: Response
    • Safe Food Handling and Preparation
      • Food Safety Basics
        • Additives in Meat and Poultry Products
        • Appliance Thermometers
        • Asar a la parrilla y seguridad alimentaria
        • Cleanliness Helps Prevent Foodborne Illness
        • Cooking for Groups
        • Cooking with Microwave Ovens
        • Cutting Boards
        • Deep Fat Frying
        • Doneness Versus Safety
        • Food Allergies
        • Glossary of Packaging Terms
        • Grilling Food Safely
        • Grilling and Food Safety
        • High Altitude Cooking
        • How Temperatures Affect Food
        • How to Find the USDA Establishment Number
        • Importing Meat, Poultry & Egg Products US
        • Inspection for Food Safety: The Basics
        • Irradiation and Food Safety FAQ
        • Keeping "Bag" Lunches Safe
        • Keeping Food Safe During an Emergency
        • Kitchen Thermometers
        • Mail Order Food Safety
        • Meat and Poultry Labeling Terms
        • Meat and Poultry Packaging Materials
        • Natural Flavors on Meat and Poultry Labels
        • Safe Handling of Take-Out Foods
        • Slaughter Inspection 101
        • Slow Cookers and Food Safety
        • Smoking Meat and Poultry
        • Tailgating Food Safety Q & A
        • Understanding FSIS Food Recalls
        • Water in Meat & Poultry
        • Danger Zone 40F - 140F
        • Food Product Dating
        • Freezing and Food Safety
        • Leftovers and Food Safety
        • Molds on Food: Are They Dangerous?
          • Hongos en los Alimentos: ¿Son Peligrosos?
        • Refrigeration
        • Safe Temperature Chart
        • Shelf-Stable Food
        • Steps to Keep Food Safe
        • The Big Thaw — Safe Defrosting Methods
        • The Color of Meat and Poultry
        • Washing Food: Does it Promote Food Safety?
        • Food Safety While Hiking, Camping & Boating
        • Seguridad Alimentaria Durante Caminatas, Campamentos y Paseos en Bote
      • Meat
        • Bacon and Food Safety
        • Bagre de la Granja a la Mesa
        • Beef From Farm To Table
        • Bison from Farm to Table
        • Carne de res ablandada mecánicamente
        • Catfish from Farm to Table
        • Color of Cooked Ground Beef as It Relates to Doneness
        • Corned Beef
        • Door-to-Door Meat Sales
        • Fresh Pork from Farm to Table
        • Goat from Farm to Table
        • Ground Beef and Food Safety
        • Hams and Food Safety
        • Hot Dogs & Food Safety
        • Jerky
        • Lamb From Farm to Table
        • Mechanically Tenderized Beef
        • Rabbit From Farm to Table
        • Roasting Those "Other" Holiday Meats
        • Sausages and Food Safety
        • Veal from Farm to Table
        • Yersiniosis and Chitterlings Tips
      • Poultry
        • Chicken From Farm to Table
        • Chicken Liver
        • Duck and Goose from Farm to Table
        • Hock Locks and Other Accoutrements
        • Is Pink Turkey Meat Safe?
        • Let's Talk Turkey Roasting
        • Poultry Processing: Questions & Answers
        • Poultry: Basting, Brining, and Marinating
        • Stuffing and Food Safety
        • The Poultry Label Says "Fresh"
        • Turduckens Require Safe Food Handling
        • Turkey Basics: Handling Cooked Dinners
        • Turkey Basics: Safe Cooking
        • Turkey Basics: Safe Thawing
        • Turkey Basics: Stuffing
        • Turkey from Farm to Table
        • Turkey: Alternate Routes to the Table
      • Eggs
        • Egg Products and Food Safety
        • Shell Eggs from Farm to Table
      • Emergencies
        • A Consumer's Guide to Food Safety: Severe Storms and Hurricanes
        • Fires and Food Safety
        • Keep Your Food Safe During Emergencies
        • Removing Odors from Refrigerators and Freezers
      • USDA Meat and Poultry Hotline
      • Brochures & Publications
    • Food Defense and Emergency Response
      • Emergency Response
      • Continuity of Operations (COOP)
      • Food Defense
        • Risk Mitigation Tool
        • Food Defense Considerations for Transportation of FSIS-Regulated Products
        • Food Defense Tools, Resources and Training
        • Functional Food Defense Plans
        • International Food Defense
  • Science & Data
    • Research Priorities
    • Data Sets & Visualizations
      • Microbiology
        • Baseline Microbiology Data Reports
        • Microbiological Testing Program for RTE Meat and Poultry Products
          • Tables & Results Microbiological Testing Program for RTE Meat
          • Tables & Results: Microbiological Testing Program Pasteurized Egg Products
          • Aggregate Salmonella Categorization of Raw Chicken Parts, NRTE Comminuted Poultry, Young Chicken Carcass and Young Turkey Carcass Establishments Using Moving Windows
          • Salmonella Initiative Program Criteria
            • Quarterly Sampling Reports on Antimicrobial Resistance
            • Quarterly Sampling Reports on Raw Beef Products
            • Quarterly Sampling Reports on Ready-to-eat Products and Egg Products
            • Quarterly Sampling Reports on Salmonella
            • Salmonella Action Plan: A One and Two Year Update
            • Salmonella Categorization of Individual Establishments for Poultry Products
        • Microbiological Testing Program for Escherichia coli O157:H7 and non-O157 Shiga toxin-producing Escherichia coli (STEC)
          • Year-to-Date Totals: Testing of Raw Ground Beef Component (RGBC) Samples for E. coli O157:H7 and non-O157 Shiga toxin-producing E. coli (STEC)
          • Annual Report for STEC in Raw Ground Beef or Veal and Raw Ground Beef or Veal Components
          • Individual E. coli Positive Results for Raw Ground Beef (RGB) and RGB Components 2017
          • Individual E. coli Positive Results for Raw Ground Beef (RGB) and RGB Components 2018
          • Individual E. coli Positive Results for Raw Ground Beef (RGB) and RGB Components 2016
          • Individual E. coli Positive Results for Raw Ground Beef (RGB) and RGB Components 2015
          • Year-to-Date 2018 Totals: Results of Raw Ground Beef Component (RGBC) Samples for E. coli O157:H7 and non-O157 Shiga toxin-producing E. coli (STEC):
        • National Antimicrobial Resistance Monitoring System (NARMS)
        • Salmonella Verification Testing Program Monthly Posting
      • Residue Chemistry
      • Humane Handling Data
      • Laboratory Sampling Data
        • Egg Product Testing, Years 1995-2017
      • Inspection Task Data
    • Scientific Reports
      • Public Health Regulations (PHR)
        • FSIS Data Analysis and Reporting: Public Health Regulations FY 2022
        • FSIS Data Analysis and Reporting: Public Health Regulations FY 2021
        • FSIS Data Analysis and Reporting: Public Health Regulations FY 2016
        • FSIS Data Analysis and Reporting: Public Health Regulations FY 2017
        • FSIS Data Analysis and Reporting: Public Health Regulations FY 2018
        • FSIS Data Analysis and Reporting: Public Health Regulations FY 2019
        • FSIS Data Analysis and Reporting: Public Health Regulations FY 2020
        • FSIS Data Analysis and Reporting: Public Health Regulations FY 2023
      • Interagency Food Safety Analytics Collaboration (IFSAC)
    • Laboratories & Procedures
      • Accredited Laboratory Program
        • Key Facts: ISO Accreditation
      • FSIS Laboratories
        • Requesting Bacterial Isolates from FSIS
    • Risk Assessments
    • Sampling Program
      • Raw Pork Products Exploratory Sampling Program
      • Sampling Results for FSIS Regulated Products
    • Journal Publications
  • Policy
    • Food Safety Acts
      • Federal Meat Inspection Act
      • Poultry Products Inspection Act
      • Egg Products Inspection Act
      • Humane Methods of Slaughter Act
    • FSIS Guidelines
    • Directives & Notices
      • FSIS Notices
      • FSIS Directives
    • Petitions
    • Federal Register & Rulemaking
      • Federal Register Notices
      • Federal Register Rules
      • Executive Orders, Small Business Protection Laws & Other Guidance
      • Regulatory Priorities
    • Advisory Committees
      • National Advisory Committee on Meat and Poultry Inspection (NACMPI)
      • National Advisory Committee on Microbiological Criteria For Foods (NACMCF)
        • 2021-2023 National Advisory Committee on Microbiological Criteria For Foods (NACMCF)
        • NACMCF 2022 Subcommittee
        • 2018-2020 National Advisory Committee on Microbiological Criteria For Foods (NACMCF)
  • Inspection
    • Inspection Programs
      • Inspection of Meat Products
        • Humane Handling Ombudsman
        • Modernization of Swine Slaughter Inspection
      • Inspection of Poultry Products
        • Reducing Salmonella in Poultry
          • Pilot Projects: Salmonella Control Strategies
          • Proposed Regulatory Framework to Reduce Salmonella Illnesses Attributable to Poultry
            • Component 1
            • Component 2
            • Component 3
          • Salmonella By the Numbers
          • Salmonella KPI
          • Salmonella Risk Assessments
        • Modernization of Poultry Slaughter Inspection
      • Inspection of Egg Products
      • Inspection of Siluriformes
    • Compliance Guidance
      • Significant Guidance
      • HACCP
        • HACCP-Based-Inspection Models Project
          • New Poultry Inspection System (NPIS)
          • HIMP Redesign Achievement of Performance Standards Young Chicken Plants
          • List of HIMP Participating Plants
        • HACCP Validation
      • PHIS
        • PHIS: Historical Information
      • Retail Guidance
      • Small & Very Small Plant Guidance
        • Appealing Inspection Decisions
        • Food Safety Resources for Small and Very Small Plant Outreach: Order Form
        • Small Plant Help Desk
        • Small Plant Help Desk Form
      • Microbial Risk
        • Listeria Monocytogenes
        • Salmonella
        • Shiga Toxin-Producing E.Coli (STEC) and E. Coli O157:H7
        • Specified Risk Material
          • BSE Rules Being Strictly Enforced
        • Guidance for Controlling Listeria monocytogenes (Lm) in Retail Delicatessens - Best Practice Tips for Deli Operators
      • Specified Risk Material Resources
      • Food Safety Assessments Tools
      • Recall Process
      • Sanitation Performance Standards Compliance Guide
      • Labeling
        • Basics of Labeling
        • Claims Guidance
        • Nonfood Compounds
          • Compounds Used for Construction and Repair in Federally Inspected Meat and Poultry Plants
          • Criteria Used by the Former Compounds and Packaging Branch for Evaluating Nonfood Compounds and Proprietary Substances
        • Ingredients Guidance
        • Label Submission and Approval System (LSAS)
          • Integration of Paper Label Applications into the Label Submission and Approval System (LSAS)
        • Labeling Policies
          • Human Food Made with Cultured Animal Cells
          • Regulations for Package Dating
          • Comprehensive List of Reasons for Label Modifications and Returns
          • Questions and Answers Concerning the Recently Published Generic Labeling Final Rule
        • Labeling Procedures
          • Information Required For Requesting a Temporary Approval
          • 10 Most Common Mistakes And How to Avoid Them
          • Label Submission Checklist
          • Labeling Situations That Can Not Have a Temporary Approval
          • Labeling and Establishment Responsibilities
          • Ten Most Commonly Asked Labeling Questions
          • Trans Fat Declarations in the Nutrition Facts Panel on Product Labeling
      • New Technology
        • Cooperative Agreements FY 2003
        • Cooperative Agreements FY 2004
        • Cooperative Agreements FY 2005
        • Food Safety Technologies FY 2003
        • Food Safety Technologies FY 2004
        • Food Safety Technologies FY 2005
        • NOL for Non-O157 STEC Test Methods
        • New Technology Information Table
      • Humane Handling
    • Import & Export
      • Import & Export Library
        • Eligible Foreign Establishments
        • U.S. Establishments by Country
          • Australia Eligible Establishments
          • Brazil Export Eligible Establishments
          • Egypt Export Eligible Establishments
          • Gibraltar Export Eligible Establishments
          • Israel Export Eligible Establishments
          • Japan (Casings) Export Eligible Establishments
          • Japan (Cold Storage Facilities) Export Eligible Establishments
          • Mexico Export Eligible Establishments
          • Russia (Beef) Export Eligible Establishments
          • Russia (Pork) Export Eligible Establishments
          • Russia (Poultry) Export Eligible Establishments
          • Russia (Prepared Products) Export Eligible Establishments
          • South Africa Eligible Establishments
      • Import Guidance
        • FSIS Import Procedures for Meat, Poultry & Egg Products
        • FSIS Import Reinspection
        • Sourcing Egg Products and Shell Eggs From Foreign Countries
      • Export Guidance
      • Equivalence
      • PHIS Components
      • International Reports
        • Foreign Audit Reports
        • Import and Export Data
    • Regulatory Enforcement
      • Humane Handling Enforcement
      • Quarterly Enforcement Reports
        • Quarterly Enforcement Reports (Narrative, Archived v1)
        • Quarterly Enforcement Reports (Narrative, Archived v2)
        • Quarterly Enforcement Reports (Narrative, Archived v3)
        • Quarterly Enforcement Reports (Narrative, Archived v4)
      • FSIS Policies on Regulatory Decisions
    • Inspection Training & Videos
      • Inspection & Mission Training
      • Meat, Poultry and Egg Product Inspection Videos
      • Regulatory Education Video Seminars
    • Apply for Grant of Inspection
      • Grants & Financial Options
    • State Inspection Programs
      • Cooperative Interstate Shipping Program
        • Cooperative Interstate Shipment (CIS) Establishments
      • Guidance Documents for State and Local Agencies
      • States With and Without Inspection Programs
      • Reviews of State Programs
    • Establishments
      • FSIS Inspected Establishments
      • Meat, Poultry and Egg Product Inspection Directory
    • Inspection Forms
  • About FSIS
    • History
    • Leadership & Organizational Structure
    • Strategic Planning
      • FSIS Enterprise Governance Decision Making Process
    • Core Values
    • Food Safety & Agency Partners
      • Memoranda of Understanding (MOU)
    • Freedom of Information Act (FOIA)
      • FSIS Adjudications
      • FSIS FOIA Reading Room
      • Frequently Requested Records
      • Making a Freedom of Information Act (FOIA) Request
    • Federal Employee Viewpoint Survey (FEVS)
  • Contact Us
    • FSIS Offices
      • Office for Food Safety (OFS)
      • Office of the Administrator (OA)
      • Office of Field Operations (OFO)
      • Office of Investigation, Enforcement, and Audit (OIEA)
      • Office of Public Health Science (OPHS)
      • Office of Policy and Program Development (OPPD)
      • Office of the Chief Financial Officer (OCFO)
      • Office of International Coordination (OIC)
      • Office of Employee Experience and Development (OEED)
      • Office of the Chief Information Officer (OCIO)
      • Office of Management (OM)
      • Office of Public Affairs and Consumer Education (OPACE)
      • Internal Affairs (IA)
      • Office of Planning Analysis Risk Management (OPARM)
      • Civil Rights Staff
    • FSIS Department Emails
    • State Contacts
    • askFSIS
      • Having Trouble with the Webform
    • Pregúntele a Karen
  • Careers
    • Apply for a Job
    • Job Opportunities
    • Who Works for Us
      • Dr. Summer Addo — an Unexpected Career Path
      • Dr. Jeanetta Tankson Shares Her Passion for Science and Food Safety
      • Micheall Myrie - Visual Information Specialist and AAFE Award Winner
      • DDM Jeffery Jacobsen Ensures Meat is Safe and Cooks it, Too!
      • CSI Sherri Rodriguez: Thankful for FSIS and Friends
      • Stephen Whatley Celebrates 50 Years of Federal Service
      • Stevie Hretz Enjoys Putting “Humans First!”
      • Archives
    • Career Profiles
      • Administrative Positions
      • Compliance Investigator Positions
      • Consumer Safety Inspector
      • Food Inspector
      • Professional Positions
      • Public Health Veterinarian (PHV)
      • Scientific Positions
    • Incentives
      • Federal Employee Benefits Summary
    • Employment Programs
    • Food Inspector Apprenticeship Programs
    • Professional with Disabilities
  • News & Events
    • Events & Meetings
      • Officials' Calendar of Meetings
      • Food Safety Education Month
    • News & Press Releases
      • News Feeds & Subscriptions
    • Publications
    • Branding & Toolkits
  • Employees
    • HR Policies & Systems
      • Forms
      • Performance Management
      • Understanding Your Benefits
        • Emergency Backup Dependent Care (EBDC) Program
    • FSIS Safety
      • COVID-19 Pandemic Resources
        • Information about Face Coverings/Masks and Face Shields
      • Workplace Violence
    • Onboarding
      • New Hire Training
    • Agency Awards & Achievements
    • Professional Development Opportunities
      • OFO Workforce Investment Initiative Pilot Program
    • Facilities and Services
    • Employee Bargaining
    • Civil Rights
    • Employee News & Stories
    • FSIS Snapshots
      • January 2023 Snapshots
      • December 2022 Snapshots
      • September 2022 Snapshots
      • August 2022 Snapshots
      • November 2022 Snapshots
      • July 2022 Snapshots
      • October 2022 Snapshots
      • June 2022 Snapshots
      • May 2022 Snapshots
      • April 2022 Snapshots
      • March 2022 Snapshots
      • February 2022 Snapshots
      • January 2022 Snapshots
      • December 2021 Snapshots
      • November 2021 Snapshots
      • October 2021 Snapshots
      • September 2021 Snapshots
      • August 2021 Snapshots
      • July 2021 Snapshots
      • June 2021 Snapshots
    • Submit Your Stories
    • Meet Pickle-Eating Champ, CSI Joe Smith
    • Supervisors Make All the Difference!
    • Disability: Part of the Equity Equation
    • Archives
      • ARCHIVE: National Preparedness Month - Cyber Security for Remote Work
      • ARCHIVE: National Preparedness Month: Occupant Emergency Planning
      • ARCHIVE: Message from Leadership — Women’s Equality Day
      • ARCHIVE: Managing Heat Risk in Hot Weather
      • ARCHIVE: New Netflix Show Features USDA and FSIS
      • ARCHIVE: Asian American, Native Hawaiian and Pacific Islander Heritage Month — Advancing Leaders Through Collaboration
      • ARCHIVE: Thank You for Your Public Service
      • ARCHIVE: World Veterinary Day — Recognizing the Resilience of FSIS Veterinarians
      • ARCHIVE: Two Hero Inspectors Provide Potentially Life-Saving CPR to a Plant Employee
      • ARCHIVE: Hero Inspector Saves a Life While on the Road
      • ARCHIVE: Administrative Professionals Day — Thank You
      • ARCHIVE: Chief Information Security Officer Marvin Lykes Recognized for Operational Excellence
      • ARCHIVE: Women’s History Month: Women Providing Healing, Promoting Hope
      • ARCHIVE: Alameda District Awards Petaluma Circuit Inspectors Recognition Coins
      • ARCHIVE: Collaborating in the Caribbean — Bringing Awareness About African Swine Fever
      • ARCHIVE: Message from Leadership — Be an Advocate for Public Health
      • ARCHIVE: Message from Leadership — Honoring Dr. Martin Luther King Jr.
      • ARCHIVE: In Their Own Words: The 2021 Administrator’s Awards for Excellence Winners Speak Out
      • ARCHIVE: CSI Koffi Hoenou – From Togolese Teacher to U.S. Citizen
      • ARCHIVE: Dearborn, Mich., Circuit Inspectors Receive Collaborative Coins
      • ARCHIVE: Don’t Invite Foodborne Illness to the Party
      • ARCHIVE: Inspection for Ritual Meat and Poultry Slaughter
      • ARCHIVE: Thanksgiving Message from Leadership
      • ARCHIVE: Make a Difference for You and Your Colleagues – Respond to FEVS by Dec. 3
      • ARCHIVE: American Indian/Alaskan Native Heritage Month — Together Towards Tomorrow
      • ARCHIVE: Federal State Audit Staff Twice Honored for Supporting Military Staff
      • ARCHIVE: Veterans Day Messages from FSIS Leadership
      • ARCHIVE: Food Inspector Apprenticeship Programs for Veterans
      • ARCHIVE: Disability Employment Awareness Month — America’s Recovery: Powered by Inclusion
      • ARCHIVE: Helping Today’s Inspectors Be Tomorrow’s Leaders with Tuition Reimbursement
      • ARCHIVE: Dr. Geraldine Vidal-Covas Embraces Her Hispanic Heritage, Encourages All
      • ARCHIVE: National Preparedness Month – Home Go Kits & Pets
      • ARCHIVE: Mask Requirements Updated for FSIS Employees
      • ARCHIVE: Modernizing Egg Inspection
      • ARCHIVE: FSIS Recognized Twice for 2020 Food Safety Education Efforts
      • ARCHIVE: Four Steps to Good Mental Health
      • ARCHIVE: Building Relationships at Work
      • ARCHIVE: Pride Month and USDA’s Commitment to Inclusion
      • ARCHIVE: Honoring the Dedicated Public Servants of FSIS
      • ARCHIVE: Asian American and Pacific Islander Contributions to Our Nation’s History
      • ARCHIVE: USDA Vaccination Heroes Do Their Part for America
      • ARCHIVE: Remembering Their Sacrifice: Jean Hillery, Tom Quadros and Bill Shaline

Food Safety and Inspection Service

  • About FSIS
  • Contact Us
  • Careers
  • News & Events
  • Employees
  • Food Safety
  • Science & Data
  • Policy
  • Inspection
  • Recalls
  • Search
  • Full Menu
ALERT: Wild Cajun Meals LLC Recalls Frozen,… See more details
Page Hero
  • Policy
    • Food Safety Acts
      • Federal Meat Inspection Act
      • Poultry Products Inspection Act
      • Egg Products Inspection Act
      • Humane Methods of Slaughter Act
    • FSIS Guidelines
    • Directives & Notices
      • FSIS Notices
      • FSIS Directives
    • Petitions
    • Federal Register & Rulemaking
      • Federal Register Notices
      • Federal Register Rules
      • Executive Orders, Small Business Protection Laws & Other Guidance
      • Regulatory Priorities
    • Advisory Committees
      • National Advisory Committee on Meat and Poultry Inspection (NACMPI)
      • National Advisory Committee on Microbiological Criteria For Foods (NACMCF)
Subscribe for Updates
Ask FSIS

askFSIS

Find answers to questions on inspection-related policies, programs, systems, and procedures.
Find An Answer
Document in circle icon

Participate in Creating Standards

FSIS invites the food safety community to participate in establishing standards for our food safety policies and services. Join us for public meetings or respond to comment requests.
Learn More

Configuration Management of Security Controls for Information Systems - Revision 2

FSIS directive 1306.3
Series Type 1,000 Series: FSIS Infrastructure
Issue Date May 03, 2016
Full Directive
1306.3.pdf

I. PURPOSE

This directive lists configuration management (CM) of security controls for information system requirements as stated in the National Institute of Science and Technology (NIST) Special Publication (SP), Revision 4, Security and Privacy Controls for Federal Information Systems and Organizations, and provides general information concerning how the Office of the Chief Information Officer (OCIO) implements them. This revision updates references and security controls required by the NIST.

II. CANCELLATION

FSIS Directive 1306.3, Revision 1, Configuration Management (CM) of Security Controls for Information Systems, 12/13/12

III. BACKGROUND

A. CM is a process of reviewing and controlling the components of an Information Technology (IT) system to ensure that they are well defined and cannot be changed without proper justification and full knowledge of the consequences. CM ensures that the hardware, software, communications services, and documentation for a system can be accurately determined at any time.

B. OCIO CM provides the processes, tools, and reports used by the Agency to record and update changes to software systems, processes, and hardware. These changes include information versions and updates that have been applied to installed software packages and the locations and network addresses of hardware devices.

C. FSIS ensures information security controls are in place to protect FSIS information systems and data in compliance with Public Law 107-347, Title III, E-Government Act of 2002; Public Law 93-579, Privacy Act of 1974, as amended; and USDA regulations.

D. Public Law 113-283 was signed into law by the President as the Federal Information Security Modernization Act of 2014 (FISMA). The goals of FISMA include the development of a comprehensive framework to protect the Government’s information, operations, and assets. FISMA assigns specific responsibilities to Federal agencies, and particularly to the NIST and the Office of Management and Budget (OMB), to strengthen information technology (IT) system security. In particular, FISMA requires the head of each agency to implement policies and procedures to cost-effectively reduce information security risks to an acceptable level. All information systems within FSIS require certification and accreditation before they become operational. The certification and accreditation process is a vital component of the overall security program.

E. NIST SP 800-53, Revision 4, Security and Privacy Controls for Federal Information Systems and Organizations, outlines the controls addressed by CM. The selection and employment of appropriate security controls for an information system is an important task that can have major implications on the operations and assets of an organization. To adhere to the NIST SP 800-53, Revision 4, FSIS has established and is responsible for meeting the requirements stated in section V. of this directive.

IV. ROLES AND RESPONSIBILITIES

All requirements in this directive are the responsibility of OCIO unless otherwise stated.

A. OCIO. Supports and promotes CM throughout the Agency.

B. OCIO Information System Security Program Manager (ISSPM). Ensures collaboration among organizational entities and compliance of the CM controls.

C. OCIO Security Operations Center and Quality Assurance and Policy Branch.

  1. Ensures all maintenance adheres to this directive; and
  2. Ensures the integrity of information systems and provides effective controls on the tools, techniques, mechanisms, and personnel used.

D. FSIS Divisions and Branches.

  1. Assist with supporting and implementing the systems configuration; and
  2. Ensure CM processes are implemented and maintained.

E. FSIS System Owners. System owners may be from program areas outside of OCIO.

  1. Approve change requests prior to submitting them to the Change Control Board (CCB);
  2. Identify and eliminate unnecessary ports and services; and
  3. Participate in the development of detailed operating procedures to satisfy appropriate CM security controls.

F. System Users. All employees, to include program areas outside of OCIO, contractors, other Federal agencies, state and local governments, and authorized private organizations or individuals who use FSIS IT resources are to:

  1. Be knowledgeable of CM and the requirements in section V. of this directive; and
  2. Ensure their duties are performed in accordance with section V. of this directive.

V. NIST SP 800-53, REVISION 4 REQUIREMENTS

A. Baseline Configuration.

1. Establish, document, and maintain a current baseline configuration of the information system;

2. Ensure the baseline configuration of the information system is consistent with the USDA and FSIS Enterprise Architecture (EA);

3. Update the baseline configuration of the information system as an integral part of information system component installations;

4. Review and update the baseline configuration of the information system:

  • a. At least annually;
  • b. When required, significant changes, corrective actions, or vulnerabilities that are identified with current baseline are to go through the Agency configuration control board process defined in the CCB directive; and
  • c. As an integral part of information system component installations and upgrades.

5. Employ automated mechanisms to maintain an up-to-date, complete, accurate, and readily available baseline configuration of the information system. This requirement is only applicable to HIGH systems. The categorization of “HIGH,” “MODERATE,” or “LOW” is defined in Federal Information Processing Standards (FIPS) Publication (PUB) 199, Standards for Security Categorization of Federal Information and Information Systems;

6. Retain older versions of baseline configuration as deemed necessary to support baseline rollback;

7. Issue only FSIS dedicated foreign travel electronic devices (DFTEDs) (i.e., laptops, portable electronic storage devices, smartphones, etc.) to individuals traveling to locations that the organization deems to be of significant risk;

8. Ensure DFTEDs are not connected to the FSIS network upon return from foreign travel or locations that the organization deems to be of significant risk; and

9. Ensure DFTEDs are returned to the Service Desk within 10 business days upon return from foreign travel or significant risk areas.

B. Configuration Change Control.

1. Determine, authorize, document, and control changes to information systems that are configuration controlled;

2. Retain and review records of configuration-controlled changes to the system;

3. Audit activities associated with configuration changes to the information system;

4. Coordinate and provide oversight for configuration change control activities through the Agency or system CCB as defined in the CCB Charter or as needed by change requests;

5. Employ automated mechanisms (on HIGH systems only) that:

  • a. Document proposed changes;
  • b. Notify appropriate approval authorities;
  • c. Highlight approvals not received;
  • d. Inhibit change until necessary approvals are received;
  • e. Document completed changes; and
  • f. Notify authorized designated personnel when approved changes to the information system are completed.

6. Test, validate, and document changes to the information system before implementing the changes on the operational system.

C. Security Impact Analysis.

  1. Analyze changes to the information system for potential security impacts prior to implementation as part of the change approval process; and
  2. Analyze new software for security flaws in a separate test environment before installation in an operational environment. This requirement is only applicable to HIGH systems.

D. Access Restrictions for Change.

  1. Define, document, approve, and enforce physical and logical access restrictions associated with changes to the information system;
  2. Employ automated mechanisms to enforce access restrictions and support auditing of the enforcement actions. This requirement is only applicable to HIGH systems;
  3. Conduct audits of information system changes at least annually as defined in the System Security Plan (SSP) and when indications so warrant, to determine whether unauthorized changes have occurred. This requirement is only applicable to HIGH systems; and
  4. Prevent the installation of software programs as defined in the SSP that are not signed with a certificate that is recognized and approved by the organization. This requirement is only applicable to HIGH systems.

E. Configuration Settings.

  1. Establish mandatory configuration settings for IT products employed within the information system using baselines from the NIST National Checklist Program (NCP) as modified by the Department. When baselines are not available, contact the vendor for recommendations;
  2. Implement configuration settings;
  3. Identify, document, and approve exceptions from the mandatory configuration settings for individual components within the information system based on explicit operational requirements;
  4. Monitor and control changes to the configuration settings in accordance with organizational policies and procedures;
  5. Employ automated mechanisms to centrally manage, apply, and verify configuration settings. This requirement is only applicable to HIGH systems; and
  6. Employ automated mechanisms to respond to unauthorized changes to baselines. This requirement is only applicable to HIGH systems.

F. Least Functionality.

  1. Configure information systems to provide only essential capabilities and specifically prohibit or restrict the use of functions, ports, protocols, or services as defined in the SSP;
  2. Review information systems at least monthly to identify and eliminate unnecessary functions, ports, protocols, or services;
  3. Employ automated mechanisms to prevent program execution in accordance with the SSP. This requirement is only applicable to HIGH systems;
  4. Develop and maintain a defined list of active programs authorized to be executed on the information system as defined in the SSP;
  5. Employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs on the information system; and
  6. Review and update the list of authorized software programs at least annually.

G. Information System Component Inventory.

1. Develop, document, and maintain a current inventory of information system components and ownership information that:

  • a. . Accurately reflects the current information system;
  • b. Is consistent with the authorization boundary;
  • c. Is at the level of granularity deemed necessary for tracking and reporting;
  • d. Includes information deemed necessary to achieve effective property accountability (e.g., item, barcode, manufacturer, type, name, serial number, version number, logical location, configuration, or more at component discretion); and
  • e. Is available for review and audit by designated organization officials.

2. Update the information system component inventory as an integral part of component installations, removals, and information system updates;

3. Employ automated mechanisms to maintain an up-to-date, complete, accurate, and readily available inventory of information system components. This requirement is only applicable to HIGH systems;

4. Employ automated mechanisms at least monthly to detect the addition of unauthorized components and devices into the information system and disable network access by such components and devices or notify designated organizational officials. This requirement is only applicable to HIGH systems;

5. Include in property accountability the following information for information system components. This requirement is only applicable to HIGH systems:

  • a. A means for identification by a minimum of position and role; and
  • b. Individuals responsible for administering the information system components.

6. Verify that all components within the authorization boundary of the information system are either inventoried as a part of the system or recognized by another system as a component within that system.

H. CM Plan. Develop, document, and implement a configuration management plan for the information system that:

  1. Addresses roles, responsibilities, and CM processes and procedures;
  2. Defines the configuration items for the information system and when in the system development life cycle, places these configuration items under CM; and
  3. Establishes the means for identifying configuration items throughout the system development life cycle and a process for managing the configuration of the configuration items.

I. Software Usage Restrictions.

  1. Use software and associated documentation in accordance with contract agreements and copyright laws;
  2. Track the use of software and associated documentation protected by quantity licenses to control copying and distribution; and
  3. Control and document the use of peer-to-peer file sharing technology to ensure that this capability is not used for the unauthorized distribution, display, performance, or reproduction of copyrighted work.

J. User-Installed Software

  1. Establish policies governing the installation of software by users;
  2. Enforce software installation policies through monthly system scans; and
  3. Monitor policy compliance at least annually.

VI. PENALTIES AND DISCIPLINARY ACTIONS FOR NON-COMPLIANCE

FSIS Directive 1300.7, Managing Information Technology (IT) Resources, sets forth the FSIS policies, procedures, and standards on employee responsibilities and conduct relative to the use of computers and telecommunications equipment. In addition, FSIS Directive 4735.3, Employee Responsibilities and Conduct, outlines the disciplinary action that FSIS may take when an employee fails to fulfill responsibilities or adhere to standards of conduct.

VII. QUESTIONS

A. For questions regarding CM, contact the Agency ISSPM at: FSIS_Information_Security@fsis.usda.gov.

B. USDA Departmental directives are located at: http://www.ocio.usda.gov/policy-directives-records-forms.

C. FSIS Directives and Notices are located at: http://www.fsis.usda.gov/wps/portal/fsis/topics/regulations.

  • USDA.gov
  • USA.gov
  • Whitehouse.gov
  • About Us
  • Our Performance
  • Information Quality & Publishing Schedule
  • Visit OIG
  • FOIA
  • Accessibility Statement
  • Privacy Policy
  • Non-Discrimination Statement
  • Plain Writing
  • No FEAR
  • Significant Guidance

Food Safety and Inspection Service

  • Pinterest
  • Twitter
  • Facebook
  • GovDelivery
  • Instagram
  • Flickr
  • YouTube
  • Linked In
  • RSS
.

Start your search

Popular Topics

Recalls Import & Export FSIS Directives FSIS Guidelines Petitions