1 Office of Information and Technology (OI&T) Field Security Operations Field Security Service
Dec 18, 2015
1
Office of Information and Technology (OI&T)
Field Security OperationsField Security Service
Office of Information and Technology (OI&T)
Field Security OperationsField Security Service
2
OverviewOverview
Field Security OperationsInformation ProtectionQuestions and Answers
3
Office of Information and Technology
Office of Information and Technology
Field Security Operations
4
Director ofIT Field Security Operations
Technical SecurityOfficers (TSO)
Division
Continuity of Operation Planning
(COOP) Division
Information Security OfficersDivision
OI&T Field Security OperationsOI&T Field Security Operations
Data Center ISOSupportDivision
Region 1 Region 3 Region 4 Region 5Region 2
Network 1, 2,3, 4 & 5
POs
Network 12, 15, 16, 17 & 23
POsSOC
VBANCA
VACOAAC
Network 6, 7,8, 9, 10 & 11
POs
Network 18, 19, 20, 21 & 22
POs
CriticalInfrastructure
ProtectionService
Security Project Management
Office
IT Field Security Service
Enterprise Security
Solutions Service (SCMS
& TIS)
5
Office of Information and Technology
Office of Information and Technology
Field Security Service
6
Field Security Service MissionField Security Service Mission
The mission of the OI&T Field Security Service (FSS) is to ensure the privacy, confidentiality, integrity, and availability of VA information assets associated with the services offered by the Department of Veterans Affairs. In addition, FSS provides assurance that cost effective security controls are in place to protect automated systems from financial fraud, waste, and abuse.
7
Field Security ServiceField Security Service
Enterprise Technical Security
Officer (TSO)
Continuity of Operation Planning
(COOP) Division
Information Security OfficersDivision
Data CenterSupportDivision
Region 1 Region 3 Region 4 Region 5Region 2
Network 1, 2,3, 4 & 5
POsNetwork 12,
15, 16, 17 & 23 POsSOC
VBANCA
VACOAAC
Network 6, 7,8, 9, 10 & 11
POs
Network 18, 19, 20, 21 & 22
POs
IT Field Security Service
Region TSO Region TSO Region TSO Region TSO Region TSO
8
IT BoundariesIT Boundaries
REGION 1
REGION 2
Puerto Rico
Hawaii
Alaska
REGION 4
19
1
2
4
5
6
10
9
7
8
16
17
15
23 12
11
20
21
22 18
8
21 20
3
REGION 3
Guam
Philippines
21
21
VISN Location
RDPC Location
9
Field Security Service Leadership Team
Field Security Service Leadership Team
Region 1 ISO (Supervisor)John White
Region 2 ISO (Supervisor)Alan Mattson
Region 3 ISO (Supervisor)Barbara Smith
Region 4 ISO (Supervisor)Alan Papier
Region 5 ISO (Supervisor)Dennis Smith
IT FSS Director (Supervisor)Randy Ledsome
Network 6 ISO (Team Lead)
VACANTSteve Blackwell (Acting)
Network 7 ISO (Team Lead)
Greg WalkerNetwork 8 ISO (Team
Lead)Dale Bogle
Network 9 ISO (Team Lead)
Chris VaracalliNetwork 10 ISO (Team
Lead)Kristin Steel
Network 11 ISO (Team Lead)
VACANTMark Latendresse
(Acting)
Network 1 ISO (Team Lead)
Tim ODonnellNetwork 2 ISO (Team
Lead)Chafica Angeli
Network 3 ISO (Team Lead)
Alan Papier (Acting)Network 4 ISO (Team
Lead)Starr Washington
Network 5 ISO (Team Lead)
Michael Barnes
Network 12 ISO (Team Lead)
Steve DeyoeNetwork 15 ISO (Team
Lead)VACANT
Terry Taylor (Acting)Network 16 ISO (Team
Lead)Dan Cleaver
Network 17 ISO (Team Lead)
Diane DixonNetwork 23 ISO (Team
Lead)Craig Heitz
Network VBA – St Petersburg ISO (Team
Lead)Jessica Lewis
Network VBA – St Paul ISO (Team Lead)
Connie HammNetwork VBA – San Diego
ISO (Team Lead)Patrice Volante
Network VACO ISO (Team Lead)
Louise Lovett-RobinsonNCA ISO
Judi Huffman
Network 18 ISO (Team Lead)
Steve KerbyNetwork 19 ISO (Team
Lead)Armando Diaz De LeonNetwork 20 ISO (Team
Lead)Michael Sutherland
Network 21 ISO (Team Lead)
Mary EbnerNetwork 22 ISO (Team
Lead)Doug Foster
Note: This presentation only includes staff in Team Lead and Supervisor positions.
IT COOP (Team Lead)
Don Sheehan
10
ISO StandardizationISO Standardization
Position Descriptions (including series and grades)
Performance StandardsRoles and ResponsibilitiesGuidance and ProcedureTraining and Education
11
Office of Information and Technology
Office of Information and Technology
Information Protection
12
Laptop EncryptionSmart Phone/Blackberry
Encryption
Email and Document Security
Removable Media and Storage Security
Network Transmission Security
Remote Access Security
InformationProtection
Technical Controls
Operational Controls
Management Controls
• Training • Human Resources• Standard Operating
Procedures
• Policy• Directives• Memoranda
Information ProtectionInformation Protection
13
\
Information Protection Technology Summary
User Removable Media and Storage
Smart Phones/Blackberry Devices
Technical Solution
Only authorized UsersAnd devices
Only GovernmentFurnished devices;
Encrypted; password protected
Network TransmissionsNo clear text;
Encrypted dataTransmissions
Layered approach to provideComprehensive information protectionof VA sensitive data
Control data storage andtransmission
Email and DocumentsPKI, Internet Gateway Scans,
RMS - Full document control.
Remote Access
Reduce VPN access;Scan all equipment
connecting to VA network - RESCUE
Security Issue
14
SummarySummary
Field Security Operations and Field Security Service
Information Protection
Information Protection is EVERYONE’s Responsibility!