3.7.1.1CYBERSECURITY ADMINISTRATOR GUIDE (CSAG)The Cybersecurity Administrator Guide (CSAG) is an essential document that provides a comprehensive set of step-by-step instructions and procedures for system administrators responsible for the secure operation of a system. The CSAG should include the following sections and requirements:
1. System Overview: A summary of the system, its purpose, and intended use.
2. System Security Configuration: A detailed description of how the server is configured and hardened, adhering to relevant government regulations. This section should include the following:
Server make and model
Operating system version and patch status
Firmware version
IP filtering rules
Disabling of unused services and ports
Logging and auditing configuration (e.g., events logged, log retention period)
Password complexity and identity and access management details
Antivirus/anti-malware software and updates
3. Access Control: Detailed descriptions of the system's access control methods, such as role-based access control (RBAC), authentication, and authorization mechanisms.
4. Account Management: Instructions for managing user and administrator accounts, including account creation, modification, and deletion, as well as password policies and procedures.
5. Incident Response: Procedures for responding to security incidents, including detection, containment, eradication, recovery, and lessons learned.
6. Anti-Malware Configuration: Details on the installation, configuration, and ongoing management of anti-malware software, such as antivirus, anti-spyware, and other security tools.
7. Encryption Recovery Procedures: Instructions for managing encryption keys and passwords, and procedures for recovering encrypted data when necessary.
8. Backup and Recovery procedures: Detailed processes for creating system backups, defining backup schedule, retention policy, and storage locations, as well as recovery procedures for forgotten administrator passwords.
9. Software Supply Chain Risk Management: Any information about the install media used for software/firmware installs or updates, such as batch, serial, date, and URL of download or control information. For physical media, specify the source (i.e., vendor(s) and/or websites), type, and manufacturer for effective software supply chain risk management.