[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Mail]  [Sign-in]  [Setup]  [Help]  [Register] 

The Victims of Benny Hinn: 30 Years of Spiritual Deception.

Trump Is Planning to Send Kill Teams to Mexico to Take Out Cartel Leaders

The Great Falling Away in the Church is Here | Tim Dilena

How Ridiculous? Blade-Less Swiss Army Knife Debuts As Weapon Laws Tighten

Jewish students beaten with sticks at University of Amsterdam

Terrorists shut down Park Avenue.

Police begin arresting democrats outside Met Gala.

The minute the total solar eclipse appeared over US

Three Types Of People To Mark And Avoid In The Church Today

Are The 4 Horsemen Of The Apocalypse About To Appear?

France sends combat troops to Ukraine battlefront

Facts you may not have heard about Muslims in England.

George Washington University raises the Hamas flag. American Flag has been removed.

Alabama students chant Take A Shower to the Hamas terrorists on campus.

In Day of the Lord, 24 Church Elders with Crowns Join Jesus in His Throne

In Day of the Lord, 24 Church Elders with Crowns Join Jesus in His Throne

Deadly Saltwater and Deadly Fresh Water to Increase

Deadly Cancers to soon Become Thing of the Past?

Plague of deadly New Diseases Continues

[FULL VIDEO] Police release bodycam footage of Monroe County District Attorney Sandra Doorley traffi

Police clash with pro-Palestine protesters on Ohio State University campus

Joe Rogan Experience #2138 - Tucker Carlson

Police Dispersing Student Protesters at USC - Breaking News Coverage (College Protests)

What Passover Means For The New Testament Believer

Are We Closer Than Ever To The Next Pandemic?

War in Ukraine Turns on Russia

what happened during total solar eclipse

Israel Attacks Iran, Report Says - LIVE Breaking News Coverage

Earth is Scorched with Heat

Antiwar Activists Chant ‘Death to America’ at Event Featuring Chicago Alderman

Vibe Shift

A stream that makes the pleasant Rain sound.

Older Men - Keep One Foot In The Dark Ages

When You Really Want to Meet the Diversity Requirements

CERN to test world's most powerful particle accelerator during April's solar eclipse

Utopian Visionaries Who Won’t Leave People Alone

No - no - no Ain'T going To get away with iT

Pete Buttplug's Butt Plugger Trying to Turn Kids into Faggots

Mark Levin: I'm sick and tired of these attacks

Questioning the Big Bang

James Webb Data Contradicts the Big Bang

Pssst! Don't tell the creationists, but scientists don't have a clue how life began

A fine romance: how humans and chimps just couldn't let go

Early humans had sex with chimps

O’Keefe dons bulletproof vest to extract undercover journalist from NGO camp.

Biblical Contradictions (Alleged)

Catholic Church Praising Lucifer

Raising the Knife

One Of The HARDEST Videos I Had To Make..

Houthi rebels' attack severely damages a Belize-flagged ship in key strait leading to the Red Sea (British Ship)


Status: Not Logged In; Sign In

Corrupt Government
See other Corrupt Government Articles

Title: CMS memo Approved and Signed by Marilyn Tevenner, Accepting Security Risk of Untested Obamacare Website to Authorize Activation (27 Sep 2013)
Source: scribd
URL Source: http://www.scribd.com/doc/180387053 ... thorize-Activation-27-Sep-2013
Published: Oct 30, 2013
Author: CMS/Marilyn Tavenner
Post Date: 2013-10-30 22:52:50 by nolu chan
Keywords: Tavenner, security memo, obamacare
Views: 2366
Comments: 2

http://www.scribd.com/doc/180387053/CMS-memo-Approved-and-Signed-by-Marilyn-Tavenner-Accepting-Security-Risk-of-Untested-Obamacare-Website-to-Authorize-Activation-27-Sep-2013

CMS memo Approved and Signed by Marilyn Tavenner, Accepting Security Risk of Untested Obamacare Website to Authorize Activation (27 Sep 2013)

Post Comment   Private Reply   Ignore Thread  


TopPage UpFull ThreadPage DownBottom/Latest

#1. To: All (#0)

DATE:

TO: Marilyn Tavenner

FROM: James Kerr, Consortium Administrator for Medicare Health Plans Operations,
Henry Chao, Deputy Chief Information Officer & Office of Information Services Deputy Director

SUBJECT: Federally Facilitated Marketplace-DECISION

ISSUE:

The Federal Information Security Management Act (FISMA) requires that the various Federally Facilitated Marketplace (FFM) systems - Enterprise and Eligibility (E&E), Financial Management (FM), and Plan Management (PM) successfully undergo a Security Control Assessment (SCA). Due to system readiness issues, the SCA was only partly completed. This constitutes a risk that must be accepted and mitigated to support the Marketplace Day 1 operations.

BACKGROUND

CMS utilizes independent and specialized contractors to test the security readiness of its systems. Testing of the Marketplace has been on-going since inception as part of the CMS Expedited Life-Cycle process with the latest security testing occurring in September of 2013. As with all new systems which are pending launch, there are inherent security risks with not having all code tested in a single environment, finally, the system requires rapid development and release of hot-fixes and patches so it is not always available or stable during the duration of testing.

From a security perspective, the aspects of the system that were not tested due to the ongoing development, exposed a level of uncertainty that can be deemed as a high risk for FFM. Although throughout the three rounds of SCA testing all of the security controls have been tested on different versions of the system, the security contractor has not been able to test all of the security controls in one complete version of the system.

The risk associated with issuing an ATO for the FFM will be reduced by instituting a two-part mitigation plan.

First, CMS will implement the following security processes for the first year of operation of FFM:

  • Establish a dedicated security team under the Chief Information Officer (CIO) to monitor, track and ensure the mitigation plan activities are completed. The CIO and the Chief Information Security Officer (CISO) will report weekly on the progress to the Health Reform Operations Board;

  • Monitor and perform weekly testing of all border devices, including internet facing web servers;

  • Conduct daily/weekly scans using the CISO's continuous monitoring tools

  • Conduct a full SCA test on FFM (E&E, FM and PM) in a stable environment where all security controls can be tested within 60/90 days of going live on October 1st.

Second, CMS will migrate the Marketplace systems to CMS' Virtual Data Center (VDC) environment in Ql-2014. This environment has been through a foil security assessment and has an authority to operate.

RECOMMENDATION:

Issue an Authority-to-Operate (ATO) for six months and implement the mitigation plan. The six- month period will allow the Marketplace to normalize its development activities while enabling the security team to closely monitor activities and perform a complete SCA.

Approved Marilyn Tavenner Date SEP 27 2013

Disapproved

Attachment: Federally Facilitated Marketplace Decision Memo Risk Acknowledgment Signature Page

- - - - -

CMS
CENTERS FOR MEDICARE & MEDICAID SERVICES

DEPARTMENT OF HEALTH & HUMAN SERVICES
Centers for Medicare & Medicaid Services
7500 Security Boulevard, Mail Stop
Baltimore, Maryland 21244-1850

Federally Facilitated Marketplace Decision Memo Risk Acknowledgment Signature Page

We acknowledge the level of risk the Agency is accepting in the Federally Facilitated Marketplace (FFM). The mitigation plan does not reduce the risk to the FFM system itself going into operation on October 1,2013. However, the added protections do reduce the risk to the overall Marketplace operations and will ensure that the FFM system is completely tested within the next 6 months.

Reviewer Teresa Fryer - - Date 9-27-2013

Reviewer Tony Trenkle - - Date 9-27-2013

Reviewer Michelle Snyder - - Date 9-27-2013

nolu chan  posted on  2013-10-30   22:53:56 ET  Reply   Trace   Private Reply  


#2. To: All (#0)

www.cnn.com/2013/10/30/politics/obamacare-sebelius/index.html

Sebelius: 'I apologize, I'm accountable' for Obamacare website problems

By Tom Cohen, CNN
updated 9:31 PM EDT, Wed October 30, 2013

[snip]

Security questions

Republican Rep. Mike Rogers of Michigan, who chairs the House Intelligence Committee, accused Sebelius of putting the private information of Americans at risk by failing to properly test security measures on the website.

"This is a completely unacceptable level of security," he said. "You know it's not secure."

Sebelius responded that testing occurs regularly, and she told Rogers she would get back to him on whether any end-to-end security test of the entire system has ever occurred. Rogers responded that he knows there have been no such comprehensive security tests.

Memo warned of high security risk at health care website

An internal government memo, obtained by CNN on Wednesday and written days before the website opened, warned of a "high" security risk because of a lack of testing.

"Due to system readiness issues, the (security control assessment) was only partly completed," said the Centers for Medicare and Medicaid Services memo. "This constitutes a risk that must be accepted and mitigated to support the Marketplace Day 1 operations."

At Wednesday's hearing, Sebelius said an independent security non-profit, Mitre Corporation, assessed the HealthCare.org system and "did not raise flags about going ahead." A mitigation plan was being implemented, Sebelius added.

In an exclusive interview with CNN last week, Sebelius said Obama didn't know of the problems with the Affordable Care Act's website -- even though insurance companies had complained and the site crashed during a pre-launch test run -- until after its launch.

A senior administration official told CNN that, nowadays, Obama gets a "nightly readout" on the available statistics related to the Affordable Care Act and work to improve the HealthCare.gov website. According to the official, White House Chief of Staff Denis McDonough talks to the President about the issue multiple times a day.

More: What else could go wrong with Obamacare?

CNN's Joe Johns, Gloria Borger, Kevin Bohn, Mariano Castillo, Lisa Desjardins and Z. Byron Wolf contributed to this report.

nolu chan  posted on  2013-10-30   23:01:20 ET  Reply   Trace   Private Reply  


TopPage UpFull ThreadPage DownBottom/Latest

[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Mail]  [Sign-in]  [Setup]  [Help]  [Register] 

Please report web page problems, questions and comments to webmaster@libertysflame.com