1 Streamlining NMMSS Data Submission James C. Crabtree Office of Health, Safety and Security U.S. Department of Energy May 20, 2009
2 Germantown Challenges NMMSS Production System –DOS/FoxPro to Windows/SQL Server Cyber Security Issues Office of Classification Request –Update Classification Methodology New Set of Physical Security and Operations Procedures New Personnel
3 Data Submission Germantown Transition Challenges Some of the issues – Systems/Software/Equipment – Communicating new mailing addresses, phone numbers, SIMEX routing address, addresses – Distribution of UserIDs and Password – New Cyber Security Plans
4 Current Data Submission Methods for Germantown Classified –Mail –Fax –Bulletin Board System – SecureNet –SIMEX Unclassified –Mail –Fax –Bulletin Board System –Encrypted
5 Mail and Fax for Germantown No real issues New addresses – Call if you need the classified address or fax Unclassified Mail Fax U.S. Department of Energy Attn: NMMSS Program, HS-1.22 Germantown Bldg Independence Ave, SW Washington, DC Mark packages – Media Enclosed Do Not X-Ray
6 Classified –SecureNet, managed by NNSA –If your site/facility has SecureNet, you can submit data and receive reports using SecureNet Unclassified, Encrypted –Entrust –Verisign –Encryption Software that meets Federal Information Processing Standard (FIPS) Level 1 or higher –SafeNet – ProtectPack, one possibility
7 NMMSS Staff Contacts NameTelephone Mary Debbie Mike Pat Smith301- Ron Gary Len Mitch Jim
8 SIMEX NMMSS SIMEX routing address “RHEGGTN “ Sites moving away from using SIMEX Many of the sites have old hardware and software Older sites systems can’t print newer pdf files Currently, Germantown is scanning in reports page by page to transmit them
9 Unclassified Bulletin Board System Software and System Upgrade Cyber Security Issues Other Issues – Communications No Problems at Present
10 Classified Bulletin Board System Software and System Upgrade Cyber Security Issues Document Requirements Other Issues - Connecting and Logging In
11 Classified Bulletin Board System Documents we need from you –Formal letter requesting connection –Full names and clearance of users with access to the remote terminal –Accreditation letter by local approving official –Approved Interconnection Security Agreement (ISA) –Approved Information System Security Plan (ISSP) for your remote terminal
12 Classified Bulletin Board System Issues STE/STU configuration; Exchange STU/STE information Getting New UserIDs and Passwords to Users Getting connection to work Speed of modem connection Getting user logon screen to popup when user connects
13 Future Data Submission to Germantown SIPRNET. Let us know if you are interested. TAC Lanes – for classified data Direct Connection to NMMSS database for classified users Direct internet connection for submitting unclassified data and downloading reports
14 Customer Input About Data Submission Which methods work best? What is feasible for you? What do you see as the best long term options? Contact me with your suggestions Jim Crabtree, – –