[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Mail]  [Sign-in]  [Setup]  [Help]  [Register] 

Israel Attacks Iran, Report Says - LIVE Breaking News Coverage

Earth is Scorched with Heat

Antiwar Activists Chant ‘Death to America’ at Event Featuring Chicago Alderman

Vibe Shift

A stream that makes the pleasant Rain sound.

Older Men - Keep One Foot In The Dark Ages

When You Really Want to Meet the Diversity Requirements

CERN to test world's most powerful particle accelerator during April's solar eclipse

Utopian Visionaries Who Won’t Leave People Alone

No - no - no Ain'T going To get away with iT

Pete Buttplug's Butt Plugger Trying to Turn Kids into Faggots

Mark Levin: I'm sick and tired of these attacks

Questioning the Big Bang

James Webb Data Contradicts the Big Bang

Pssst! Don't tell the creationists, but scientists don't have a clue how life began

A fine romance: how humans and chimps just couldn't let go

Early humans had sex with chimps

O’Keefe dons bulletproof vest to extract undercover journalist from NGO camp.

Biblical Contradictions (Alleged)

Catholic Church Praising Lucifer

Raising the Knife

One Of The HARDEST Videos I Had To Make..

Houthi rebels' attack severely damages a Belize-flagged ship in key strait leading to the Red Sea (British Ship)

Chinese Illegal Alien. I'm here for the moneuy

Red Tides Plague Gulf Beaches

Tucker Carlson calls out Nikki Haley, Ben Shapiro, and every other person calling for war:

{Are there 7 Deadly Sins?} I’ve heard people refer to the “7 Deadly Sins,” but I haven’t been able to find that sort of list in Scripture.

Abomination of Desolation | THEORY, BIBLE STUDY

Bible Help

Libertysflame Database Updated

Crush EVERYONE with the Alien Gambit!

Vladimir Putin tells Tucker Carlson US should stop arming Ukraine to end war

Putin hints Moscow and Washington in back-channel talks in revealing Tucker Carlson interview

Trump accuses Fulton County DA Fani Willis of lying in court response to Roman's motion

Mandatory anti-white racism at Disney.

Iceland Volcano Erupts For Third Time In 2 Months, State Of Emergency Declared

Tucker Carlson Interview with Vladamir Putin

How will Ar Mageddon / WW III End?

What on EARTH is going on in Acts 16:11? New Discovery!

2023 Hottest in over 120 Million Years

2024 and beyond in prophecy

Questions

This Speech Just Broke the Internet

This AMAZING Math Formula Will Teach You About God!

The GOSPEL of the ALIENS | Fallen Angels | Giants | Anunnaki

The IMAGE of the BEAST Revealed (REV 13) - WARNING: Not for Everyone

WEF Calls for AI to Replace Voters: ‘Why Do We Need Elections?’

The OCCULT Burger king EXPOSED

PANERA BREAD Antichrist message EXPOSED

The OCCULT Cheesecake Factory EXPOSED


Status: Not Logged In; Sign In

Corrupt Government
See other Corrupt Government Articles

Title: CMS memo Approved and Signed by Marilyn Tevenner, Accepting Security Risk of Untested Obamacare Website to Authorize Activation (27 Sep 2013)
Source: scribd
URL Source: http://www.scribd.com/doc/180387053 ... thorize-Activation-27-Sep-2013
Published: Oct 30, 2013
Author: CMS/Marilyn Tavenner
Post Date: 2013-10-30 22:52:50 by nolu chan
Keywords: Tavenner, security memo, obamacare
Views: 2363
Comments: 2

http://www.scribd.com/doc/180387053/CMS-memo-Approved-and-Signed-by-Marilyn-Tavenner-Accepting-Security-Risk-of-Untested-Obamacare-Website-to-Authorize-Activation-27-Sep-2013

CMS memo Approved and Signed by Marilyn Tavenner, Accepting Security Risk of Untested Obamacare Website to Authorize Activation (27 Sep 2013)

Post Comment   Private Reply   Ignore Thread  


TopPage UpFull ThreadPage DownBottom/Latest

#1. To: All (#0)

DATE:

TO: Marilyn Tavenner

FROM: James Kerr, Consortium Administrator for Medicare Health Plans Operations,
Henry Chao, Deputy Chief Information Officer & Office of Information Services Deputy Director

SUBJECT: Federally Facilitated Marketplace-DECISION

ISSUE:

The Federal Information Security Management Act (FISMA) requires that the various Federally Facilitated Marketplace (FFM) systems - Enterprise and Eligibility (E&E), Financial Management (FM), and Plan Management (PM) successfully undergo a Security Control Assessment (SCA). Due to system readiness issues, the SCA was only partly completed. This constitutes a risk that must be accepted and mitigated to support the Marketplace Day 1 operations.

BACKGROUND

CMS utilizes independent and specialized contractors to test the security readiness of its systems. Testing of the Marketplace has been on-going since inception as part of the CMS Expedited Life-Cycle process with the latest security testing occurring in September of 2013. As with all new systems which are pending launch, there are inherent security risks with not having all code tested in a single environment, finally, the system requires rapid development and release of hot-fixes and patches so it is not always available or stable during the duration of testing.

From a security perspective, the aspects of the system that were not tested due to the ongoing development, exposed a level of uncertainty that can be deemed as a high risk for FFM. Although throughout the three rounds of SCA testing all of the security controls have been tested on different versions of the system, the security contractor has not been able to test all of the security controls in one complete version of the system.

The risk associated with issuing an ATO for the FFM will be reduced by instituting a two-part mitigation plan.

First, CMS will implement the following security processes for the first year of operation of FFM:

  • Establish a dedicated security team under the Chief Information Officer (CIO) to monitor, track and ensure the mitigation plan activities are completed. The CIO and the Chief Information Security Officer (CISO) will report weekly on the progress to the Health Reform Operations Board;

  • Monitor and perform weekly testing of all border devices, including internet facing web servers;

  • Conduct daily/weekly scans using the CISO's continuous monitoring tools

  • Conduct a full SCA test on FFM (E&E, FM and PM) in a stable environment where all security controls can be tested within 60/90 days of going live on October 1st.

Second, CMS will migrate the Marketplace systems to CMS' Virtual Data Center (VDC) environment in Ql-2014. This environment has been through a foil security assessment and has an authority to operate.

RECOMMENDATION:

Issue an Authority-to-Operate (ATO) for six months and implement the mitigation plan. The six- month period will allow the Marketplace to normalize its development activities while enabling the security team to closely monitor activities and perform a complete SCA.

Approved Marilyn Tavenner Date SEP 27 2013

Disapproved

Attachment: Federally Facilitated Marketplace Decision Memo Risk Acknowledgment Signature Page

- - - - -

CMS
CENTERS FOR MEDICARE & MEDICAID SERVICES

DEPARTMENT OF HEALTH & HUMAN SERVICES
Centers for Medicare & Medicaid Services
7500 Security Boulevard, Mail Stop
Baltimore, Maryland 21244-1850

Federally Facilitated Marketplace Decision Memo Risk Acknowledgment Signature Page

We acknowledge the level of risk the Agency is accepting in the Federally Facilitated Marketplace (FFM). The mitigation plan does not reduce the risk to the FFM system itself going into operation on October 1,2013. However, the added protections do reduce the risk to the overall Marketplace operations and will ensure that the FFM system is completely tested within the next 6 months.

Reviewer Teresa Fryer - - Date 9-27-2013

Reviewer Tony Trenkle - - Date 9-27-2013

Reviewer Michelle Snyder - - Date 9-27-2013

nolu chan  posted on  2013-10-30   22:53:56 ET  Reply   Trace   Private Reply  


#2. To: All (#0)

www.cnn.com/2013/10/30/politics/obamacare-sebelius/index.html

Sebelius: 'I apologize, I'm accountable' for Obamacare website problems

By Tom Cohen, CNN
updated 9:31 PM EDT, Wed October 30, 2013

[snip]

Security questions

Republican Rep. Mike Rogers of Michigan, who chairs the House Intelligence Committee, accused Sebelius of putting the private information of Americans at risk by failing to properly test security measures on the website.

"This is a completely unacceptable level of security," he said. "You know it's not secure."

Sebelius responded that testing occurs regularly, and she told Rogers she would get back to him on whether any end-to-end security test of the entire system has ever occurred. Rogers responded that he knows there have been no such comprehensive security tests.

Memo warned of high security risk at health care website

An internal government memo, obtained by CNN on Wednesday and written days before the website opened, warned of a "high" security risk because of a lack of testing.

"Due to system readiness issues, the (security control assessment) was only partly completed," said the Centers for Medicare and Medicaid Services memo. "This constitutes a risk that must be accepted and mitigated to support the Marketplace Day 1 operations."

At Wednesday's hearing, Sebelius said an independent security non-profit, Mitre Corporation, assessed the HealthCare.org system and "did not raise flags about going ahead." A mitigation plan was being implemented, Sebelius added.

In an exclusive interview with CNN last week, Sebelius said Obama didn't know of the problems with the Affordable Care Act's website -- even though insurance companies had complained and the site crashed during a pre-launch test run -- until after its launch.

A senior administration official told CNN that, nowadays, Obama gets a "nightly readout" on the available statistics related to the Affordable Care Act and work to improve the HealthCare.gov website. According to the official, White House Chief of Staff Denis McDonough talks to the President about the issue multiple times a day.

More: What else could go wrong with Obamacare?

CNN's Joe Johns, Gloria Borger, Kevin Bohn, Mariano Castillo, Lisa Desjardins and Z. Byron Wolf contributed to this report.

nolu chan  posted on  2013-10-30   23:01:20 ET  Reply   Trace   Private Reply  


TopPage UpFull ThreadPage DownBottom/Latest

[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Mail]  [Sign-in]  [Setup]  [Help]  [Register] 

Please report web page problems, questions and comments to webmaster@libertysflame.com