ARIZONA DEPARTMENT OF ADMINISTRATION AGENCY POLICY StateofArizona P6000:StateSharedHostedDataCenter(SHDC) INFRASTRUCTURECONTINGENCYPLANNING DOCUMENT NU MBER: P6000 EFFECTIVE DA TE: JULY 2,2021 REVISION: 1.3 1. AUTHORITY ToeffectuatethemissionandpurposesoftheArizonaDepartmentofAdministration(ADOA),the Agencyshallestablishacoordinatedplanandprogramforinformationtechnology(IT)implementedand maintainedthroughpolicies,standardsandprocedures(PSPs)asauthorizedbyArizonaRevised Statutes(A.R.S.)§18-104. 2. PURPOSE Thepurposeofthispolicyistominimizetheriskofsystemandserviceunavailabilityduetoavarietyof disruptionsbyprovidingeffectiveandefficientsolutionstoenhancesystemavailability.[National InstituteofStandardsandTechnology(NIST)800-34]. 3. SCOPE 3.1. ThispolicyappliestoallDivisionsofADOAandITintegrationsand/ordataexchangewiththird partiesthatperformfunctions,activitiesorservicesfororonbehalfoftheAgencyoritsDivisions throughtheStateSharedHostedDataCenter(SHDC).Applicabilityofthispolicytothirdpartiesis governedbycontractualagreementsenteredintobetweenADOAandthethirdparty/parties. 3.1.1. ApplicationtoSystems-Thispolicyshallapplytoallstateinformationsystems. CategorizationofsystemsisdefinedwithinPolicy8120,InformationSecurityProgram. 3.1.2. ApplicationtoThirdParties-ThisPolicyshallapplytoallADOAvendorsandcontractors providinggoodsandservicestotheADOAandtothirdparties,includingother Governmentbodies. 4. ROLESA NDR ESPONSIBILITIES Page1 of1 0 Date: ARIZONA DEPARTMENT OF ADMINISTRATION AGENCY POLICY StateofArizona Note:Thetypesofteamsrequiredarebasedonthedefinitionofservicesavailabletotheagencies. 4.1. StateChiefInformationOfficer(CIO)shall: 4.1.1. BeultimatelyresponsibleforthecorrectandthoroughcompletionofStatewideIT PSPsthroughoutallstateBUs. 4.2. ChiefOperatingOfficer(COO),CloudOPSDirector,StateSharedHostedDataCenter(SHDC) Managershall: 4.2.1. OverseethemanagementandoperationoftheStateSharedHostedDataCenter; 4.2.2. Makedecisions,withrespectto,theapplicationofStatepoliciesandArizonaRevised StatutestotheStateSharedHostedDataCenter; 4.2.3. Betheultimateauthoritytoensurethatcontractedservicedeliveryandsupport commitmentsaremet,includingbutnotlimitedto,makingdecisionsregardingspending levels,acceptablerisk,andinteragencycoordinationofserviceeventsanddecisions requiringtheirconcurrence;and 4.2.4. LeadtheStateSharedHostedDataCentermanagementteaminitsaccomplishmentof specificresponsibilitiescriticaltothedeliveryandsupportofStateSharedHostedData Centerservices. 4.3. ADOADisasterRecoveryManagershall: 4.3.1. Conductperiodicriskassessments,includingbutnotlimitedto,naturaldisasters, man-madedisasters,anddisruptionsaffectingtechnologyassets. 4.3.2. Establishandmaintaincontingencyplansincluding,butnotlimitedto,business continuityandincidentrecoveryplansconsistentwithStatepoliciesandA.R.S.§ 18-104(c); 4.3.3. CollaboratewiththeADOAChiefOperatingOfficer,inthecoordinationofrecovery activitiesforadeclareddisaster; 4.3.4. Establishandmaintainincidentrecoveryeducationandtrainingprogramsnecessaryto ensurethereadinessofpersonnelrequiredtosupportdisasterrecoveryactivities; 4.3.5. Conductperiodicreviewsandtestsofshutdownandrecoveryprocedures,businessrisks, emergencyprocedures,anddatabackupprocedures;and Page2 of1 0 Date: ARIZONA DEPARTMENT OF ADMINISTRATION AGENCY POLICY StateofArizona 4.3.6. Ensurethatallcontingencyplans,includingbutnotlimitedto,businesscontinuityand incidentrecoveryplansandrelateddocumentsorartifactsareunderconfiguration changecontrolandintegratedwiththedisruptionmanagementprocess. 5. POLICY TheprincipalobjectiveofContingencyPlanningistoadoptindustrybestpracticestodatacenter operationsthatwillensuretherecoveryofdepartmentalandagencyfunctionsthatmustbecontinued throughout,orresumedafteradisruptionofnormalactivitiesfromanunforeseenevent,disasteror emergencyinterruptinginformationsystemsandbusinessoperations. 5.1. BusinessImpactAnalysis(BIA)- CloudOpsDirectorandStateSharedHostedDCManager,and ADOADisasterRecoveryManagershallconductanannualbusinessimpactanalysis,withagency BUs,ontheirinformationsystemsbeinghostedintheSharedHostedDataCenter.[(NIST)800-34] 5.1.1. IdentifySupportedBUProcesses-ADOADisasterRecoveryManagershallidentify supportedBUprocessesandrecoverycriticality.ImpacttoBUprocesseswillbe categorized(Low,Moderate,High)forconfidentiality,integrity,andavailability.(FIPS PUB199) 5.1.2. IdentifyOutageImpacts-ADOADisasterRecoveryManagershallidentifyoutageimpacts andestimateddowntime.DowntimeshouldreflectthemaximumtimethataBUcan toleratewhilestillmaintainingthemissionatanacceptablelevelofservice. 5.1.3. IdentifyResourceRequirements-BUsandADOADisasterRecoveryManagershall identifyresourcerequirements.Recoveryeffortsrequireanevaluationofresources requiredtoresumemission/businessprocesses.Resourcesmayincludefacilities, personnel,equipment,software,datafiles,systemcomponents,andvitalrecords. 5.1.4. IdentifyRecoveryPriorities-BUsandADOADisasterRecoveryManagershallidentify recoveryprioritiesforsystems.EachsystemorBUprocessshallbeanalyzedandthe MaximumTolerableDowntime(MTD),RecoveryTimeObjective(RTO),andRecovery PointObjective(RPO)determinedforeach. 5.2. AnnualRiskAssessment-ChiefOperatingOfficer(COO),CloudOPSDirectorshallconductand documentannualriskassessmentstoidentify,estimate,andprioritizerisktoBUoperations.Risks mayinclude,butarenotlimitedto,naturaldisasters,man-madedisasters,anddisruptions Page3 of1 0 Date: ARIZONA DEPARTMENT OF ADMINISTRATION AGENCY POLICY StateofArizona causedbyinformationtechnologyassets.Prioritywillbegiventorisksthatareestimatedtohave thegreatestpotentialimpactandthehighestprobabilityofoccurrence.[(NIST)800-30] 5.3. RiskManagement/BusinessContinuityPlan-ADOADisasterRecoveryManagershallmanageall identifiedhigh-priorityrisksbydeveloping,documenting,andtestingcomprehensiveBusiness ContinuityPlans.TheBusinessImpactAnalysisandRiskAssessmentrepresentthefoundationof theBusinessContinuityPlan.[(NIST)800-34] 5.3.1. IdentifyPreventiveControls-StateSharedHostedDataCenterManagershallidentify preventivecontrolsthataddressthemostsignificantareasofriskidentifiedbytheRisk Assessment.Eachpreventivecontrolshallbeanalyzedintermsofeffectiveness, practicalityandcosteffectiveness.Preventivecontrolsidentifiedaseffectiveandefficient willbeincludedintheBusinessContinuityPlan.[(NIST)800-34] 5.3.2. CreateContingencyStrategies-ADOADisasterRecoveryManagershallidentify contingencystrategiesandalternativestoaddresshigh-priorityrisks.Thesestrategies include,butarenotlimitedto:Backupandrecoveryofdataand;Alternatesites.[(NIST) 800-34] 5.3.3. StateInformationSystemBackup-BUsandADOADisasterRecoveryManagershall: Conductbackupsofdata/informationcontainedinthestateinformationsystem,and stateinformationsystemdocumentationincludingsecurity-relateddocumentationwithin theStateSharedHostedDataCenter’sdefinedfrequencyconsistentwithRPO/RTOs definedincontractedSLAs/OLAs;and[NIST800-53CP-9][HIPAA164.308(7)(ii)(A)] a)Protecttheconfidentiality,integrity,andavailabilityofthebackup informationatstoragelocations. 5.3.4. TestingforReliability/Integrity-ADOADisasterRecoveryManagershallensure recoverabilityofdatawrittentomediaandstoredoffsiteannuallytoverifymedia reliabilityandinformationintegrity.[NIST800-53CP-9(1)][IRSPub1075] 5.3.5. InformationSystemRecoveryandReconstitution-StateSharedHostedDataCenter Manager,withdirectionfromthedataowner,shallprovidefortherecoveryand reconstitutionofthestateinformationsystemafteradisruption,compromise,orfailure tothecontractedRPO.[NIST800-53CP-10] 5.3.6. TransactionRecovery–StateSharedHostedDataCenterManager,withdirectionfrom thedataownerandbasedontheRPO,shallimplementstateinformationsystemsto Page4 of1 0 Date: ARIZONA DEPARTMENT OF ADMINISTRATION AGENCY POLICY StateofArizona performtransactionrecoveryforanysystemthatistransaction-based.[NIST800-53 CP-10(2)][IRSPub1075] 5.3.7. AlternateStorageSite-StateSharedHostedDataCenterManagershallestablishan alternatestoragesiteincludingnecessaryagreementstopermitthestorageandrecovery ofinformationsystembackupinformationandensurethatthealternativestoragesite providesinformationsecuritysafeguardsequivalenttothoseoftheprimarysite.[NIST 800-53CP-6] 5.3.8. SeparationfromPrimarySite-Thealternativesiteshallbeseparatedfromtheprimary sitetoreducesusceptibilitytothesamehazards.[NIST800-53CP-6(1)][IRSPub1075] 5.3.9. Accessibility- StateSharedHostedDataCenterManagershallidentifypotential accessibilityproblemstothealternatestoragesiteintheeventofanarea-widedisruption ordisasterandoutlineexplicitmitigationactions.[NIST800-53CP-6(3)][IRSPub1075] 5.3.10. PriorityofService-BUsandStateSharedHostedDataCenterManagerwillworkto developalternatestoragesitecomponentsasapartofservicelevelagreements(SLAs) andorganizationallevelagreements(OLAs)thatspecifiesstorageprovisioningin accordancewiththeorganization’savailabilityrequirements.[NIST800-53CP-7(3)][IRS Pub1075] 5.3.11. A lternateProcessingSite-BUsandStateSharedHostedDataCenterManagershall: [NIST800-53CP-7][IRSPub1075] a) Establishanalternateprocessingsiteincludingnecessaryagreementsto permitthetransferandresumptionofstateinformationsystem operationsforessentialmissions/businessfunctionswiththeState SharedHostedDataCenter’sdefinedtimeperiodconsistentwithRPOs andRTOswhentheprimaryprocesscapabilitiesareunavailable; b) Ensurethatequipmentandsuppliestotransferandresumeoperations areavailableatthealternatesiteorcontractsareinplacetosupport deliverytothesiteintimetosupporttheStateSharedHostedData Centerdefinedperiodfortransfer/resumption; c) Ensureallservicelevelsaremetwhileatthealternatedatacentersite, inaccordancewithagencyserviceagreementsandtothebestofthe secondarysite’scapabilities,forthedurationoftheincident;and d) Ensurethatthealternateprocessingsiteprovidesinformationsecurity safeguardssimilarorequivalenttothatoftheprimarysite. Page5 of1 0 Date: ARIZONA DEPARTMENT OF ADMINISTRATION AGENCY POLICY StateofArizona 5.3.12. SeparationfromPrimarySite-BUsandStateSharedHostedDataCenterManagershall identifyanalternativeprocessingsitethatisseparatedfromtheprimarysitetoreduce susceptibilitytothesamethreats.[NIST800-53CP-7(1)][IRSPub1075] 5.3.13. Accessibility-StateSharedHostedDataCenterManagershallidentifypotential accessibilityproblemstothealternateprocessingsiteintheeventofanarea-wide disruptionordisasterandoutlineexplicitmitigationactions.[NIST800-53CP-7(2)][IRS Pub1075] 5.3.14. PriorityofService-StateSharedHostedDataCenterManagershalldevelopalternative processingsiteagreementsthatcontainpriorityofserviceprovisionsinaccordancewith theorganization’savailabilityrequirements.[NIST800-53CP-7(3)][IRSPub1075] 5.4. IncidentRecoveryPlan(IRP)-StateSharedHostedDataCenterManagershalldevelopan IncidentRecoveryplanthataddressesphysicaldisruptionsthatrequirerelocationofIT equipment,processes,ordatastorage. 5.4.1. ContinuityofOperationsPlan(COOP)-CloudOpsDirectorandStateSharedHostedDC ManagershalldevelopaContinuityofOperationsPlanwiththeBUtoensurethatmission essentialfunctions(MEF)arerestoredfollowingdisruptionsthatrequirerelocationofIT equipment,processes,ordatastorage. 5.4.2. InformationSystemContingencyPlan(ISCP)-CloudOpsDirectorandStateShared HostedDCManagershalldevelopanInformationSystemContingencyPlanthatensures allidentifiedBUprocessesarerestoredfollowingdisruptionsthatmayormaynotinclude relocationofITequipment,processes,ordatastorage. 5.4.3. CrisisManagementPlan(CMP)-AgenciesshallcoordinatewiththeSharedHostedData CenterTeamtodevelopaCrisisManagementPlanthatincludes: a. Adatabasewithnames,phone/page/fax/cellularnumbers,e-mailandpostal addressesofeveryoneontheteam. b.Assignedrolesandproceduresforeveryoneonthecrisisteam. c. Amultimediadatabasewithcriticalinformationontheorganization’sassets, personnelandservicesthatcanbequicklyaccessedandanalyzed. d.Ameansforteammemberstoaccessthedatabaseandcollaborateremotely. e.ACrisisCommunicationPlanthataddressescommunicationswithpersonneland thepublicatlarge. Page6 of1 0 Date: ARIZONA DEPARTMENT OF ADMINISTRATION 5.5. AGENCY POLICY StateofArizona DevelopContingencyPlans-AgenciesshallcoordinatewiththeSharedHostedDataCenterTeam todevelopcontingencyplansforeachhigh-priorityriskthat:[NIST800-53CP-2][Health InsurancePortabilityandProtectionAct(HIPAA)164.308(a)(7)(i),164.308(a)(7)(ii)(b), 164.308(a)(7)(ii)(c),164.310(a)(2)(i)] a) Identifiesessentialmissionandbusinessfunctionsandtheassociated contingencyrequirements; b) ProvidesRecoveryPointObjective(RPO)andRecoveryTimeObjective(RTO) restorationprioritiesandmetricsbasedonServiceLevelAgreements(SLA); c) Addressescontingencyroles,responsibilities,assignedindividualswithcontact information; d) Addressesmaintainingessentialmissionsandbusinessfunctionsdespitean informationsystemdisruption,compromise,orfailure; e) Addresseseventual,fullinformationsystemsrestorationwithoutdeterioration ofthesecuritysafeguardsoriginallyplannedandimplemented; f) Addressesresumptionofessentialmissionsandbusinessfunctionswithinatime framespecifiedbytheADOACIOandbasedonmissionneeds,applicable regulations,andapplicablecontractsandagreementswithexternalBUsorother organizations.[NIST800-53CP-2(3)]; g) Identifiescriticalinformationsystemassetssupportingorganizationalmissions andbusinessfunctions;[NIST800-53CP-2(8)][HIPAA164.308(a)(7)(ii)€]; h) Includesproceduresforobtainingnecessaryelectronicprotectedhealth informationduringanemergency[HIPAA164.312(a)(2)(ii)];and i) IsreviewedandapprovedbyADOACOOandAssistantDirector/StateData CenterManager. 5.5.1. ContingencyPlanCoordination-CloudOpsDirectorandStateSharedHostedDC Managershallrecommendandcoordinatethedevelopmentofthecontingencyplanfor eachstateinformationsystemwithorganizationalelementsresponsibleforrelatedplans. [NIST800-53CP-2(1)][InternalRevenueService(IRS)Pub1075] 5.6. ContingencyTraining-CloudOpsDirectorandStateSharedHostedDCManagershallprovide contingencytrainingtostateinformationsystemusersconsistentwithassignedrolesand responsibilitiesbeforeauthorizingaccess,whenrequiredbystateinformationsystemchanges, andannuallythereafter.[NIST800-53CP-3] Page7 of1 0 Date: ARIZONA DEPARTMENT OF ADMINISTRATION 5.7. AGENCY POLICY StateofArizona TestContingencyPlan-CloudOpsDirectorandStateSharedHostedDCManagershalltestthe contingencyplanforthestateinformationsystemannuallytodeterminetheeffectivenessofthe planandtheorganizationalreadinesstoexecutetheplan,reviewthecontingencyplantest results,andinitiatecorrectiveactionorimprovements,asnecessary.[NIST800-53CP-4][HIPAA 164.308(a)(7)(ii)(D)] 5.7.1. ContingencyPlanTestCoordination-CloudOpsDirectorandStateSharedHostedDC Managershallcoordinatecontingencyplantestingforeachstateinformationsystemwith organizationalelementsresponsibleforrelatedplans.[NIST800-53CP-4(1)][IRSPub 1075] 5.8. ManageContingencyPlans-StateSharedHostedDataCentershall:[NIST800-53CP-2] a) DistributecontingencyplanstokeyStateSharedHostedDataCentersupport personnel,andappropriateStateSharedHostedDataCenterserviceproviders andpartners; b) Coordinatecontingencyplanningactivitieswithincidenthandlingactivities; c) ReviewcontingencyplansannuallybasedontheannualRiskAssessmentand anychangesintheBusinessImpactAnalysistoinsurethatitcomprehensively addressesallhigh-priorityrisks; d) Revisecontingencyplansasnecessarytoaddresschangestotheorganization, stateinformationsystems,operationalenvironmentorproblemsencountered duringplanimplementation,executionortesting; e) Communicatecontingencyplanchangestokeycontingencypersonneland organizationalelements;and f) 6. Protectcontingencyplansfromunauthorizeddisclosureandmodification. DEFINITIONSA NDA BBREVIATIONS RefertothePSPGlossaryofTermslocatedontheADOA-ASETwebsite. 7. REFERENCES 7.1. StatewidePolicyFrameworkP1050-ITPOLICIES,STANDARDS&PROCEDURESPROGRAM 7.2. StatewidePolicyFramework8120,InformationSecurityProgram Page8 of1 0 Date: ARIZONA DEPARTMENT OF ADMINISTRATION 7.3. AGENCY POLICY StateofArizona NationalInstituteofStandardsandTechnology(NIST)SpecialPublication800-30(SP800-30). GuideforConductingRiskAssessments 7.4. NationalInstituteofStandardsandTechnology(NIST)SpecialPublication800-34Rev.1(SP800- 34).ContingencyPlanningGuideforFederalInformationSystems 7.5. NationalInstituteofStandardsandTechnology(NIST)SpecialPublication800-53Rev.4(SP800- 53).RecommendedSecurityControlsforFederalInformationSystems 7.6. NationalInstituteofStandardsandTechnology(NIST)SpecialPublication800-84(SP800-84). GuidetoTest,Training,andExerciseProgramsforITPlansandCapabilities 7.7. FederalEmergencyManagementAgency(FEMA)ContinuityGuidanceCircular1(CGC1), ContinuityGuidanceforNon-FederalEntities(States,Territories,Tribal,andLocalGovernment JurisdictionsandPrivateSectorOrganizations),January21,2009 7.8. FederalEmergencyManagementAgency(FEMA)NationalResponseFramework(NRF),2nd Edition,May2013 7.9. FBICriminalJusticeInformationServices(CJIS)SecurityPolicyVersion5.906/01/2020 IRSPublication1075,TaxInformationSecurityGuidelinesforFederal,State,andLocalAgencies: SafeguardsforProtectingFederalTaxReturnsandReturnInformation,2010. 7.10. 8. ATTACHMENTS None. 9. REVISIONH ISTORY Date Change Revision Signature 07/10/2014 InitialRelease 1.0 AaronSandeen,StateCIOand DeputyDirector Page9 of1 0 Date: ARIZONA DEPARTMENT OF ADMINISTRATION AGENCY POLICY 10/11/2016 UpdatedalltheSecurityStatutes StateofArizona 1.0 MorganReed,StateCIOand DeputyDirector 06/21/2021 Copiedintonewformatand reviewedfornecessaryrevisions 1.2 RandyWheaton 06/21/2021 Maderevisionstoreferencesand agency/SHDCteamcollaboration onDisasterRecoveryprocedures, addedIRSPub1075andFBI CriminalJusticeInformation Services(C JIS)references. 7/2/2021 Approved 1.3 RandyWheaton J.R.Sloan,StateCIO Page1 0of1 0 Date: