Effective August 23, 2012, Handbook AS-805, Information Security, is revised. The July 2012 edition has been updated to reflect the following:
n Align responsibilities of IT managers with current organization.
n Update responsibilities for contracting officers and contracting officer representatives.
n Add generic architectural standards.
n Update information security training requirements.
n Clarify requirements for protecting nonpublic Postal Service™ information.
n Clarify requirements for removal of nonpublic Postal Service information from Postal Service or business partner premises.
n Update the protection requirements for contracts.
n Clarify the concept of a risk-based information security framework.
n Address the usage of social media.
n Address source code requirements and the separation of duties of software developers.
n Update requirements for USB flash drives.
n Update the requirements associated with the development, system integration test, and customer acceptance test environments and the regular testing security systems and processes.
n Address special account management.
n Address single sign-on.
n Remove references to the Access Control Facility 2.
n Update hardening and encryption requirements.
n Update the requirements for disaster recovery and incident reports.
n Implement Office of Inspector General audit findings.
n Implement SOX recommendations.
n Implement payment card industry requirements.
n Describe the implementation of the Data Loss Prevention program.
n Update the wireless baseline requirements.
n Add consensus audit guidelines to address the continuing monitoring requirements delineated in National Institute of Standards and Technology Special Publication 800-53.
n Move the definition of what constitutes a significant change and the criteria for recertification to Handbook AS-805-A, Information Resource Certification and Accreditation (C&A) Process.
Handbook AS-805 is now available on the Postal Service PolicyNet website:
n Go to http://blue.usps.gov.
n Under “Essential Links” in the left-hand column, click PolicyNet.
n On the PolicyNet page, click HBKs.
(The direct URL for the Postal Service PolicyNet website is http://blue.usps.gov/cpim.) The direct URL for Handbook AS-805 (July 2012) is http://about.usps.com/handbooks/as805.pdf (PDF version) http://about.usps.com/handbooks/as805/welcome.htm (HTML 508-compliant version).
Note: Offices should update references/links to Handbook AS-805 in local documents.
— Corporate Information Security,
Chief Information Officer, 8-23-12