28.00, Designation to Paul Cunningham
Rescinded By:
28.00A, Designation Order No. 00-28.00A to Emery Csulak on Jul 01, 2019
Document text
Text extracted from the attached file. Refer to the original document for the authoritative version.
Section 1
DEPARTMENT OF ENERGY
DESIGNATION ORDER NO. 00-28.00
TO PAUL CUNNINGHAM
1. DESIGNATION. Pursuant to the Under Secretary’s (for Management and Performance)
Redelegation Order to the Chief Information Officer (CIO), I designate Paul Cunningham
to serve as the Department of Energy’s (DOE) Chief Information Security Officer, as that
title and its responsibilities are described in section 3554 (a) (3) (A) of the Federal
Information Security Modernization Act (FISMA) of 2014 (Public Law 113-283), and to
have the authority to take the following actions:
A. Carry out the CIO’s responsibilities under FISMA which are:
1. Developing and maintaining a DOE-wide information security
program as required by section 3554(b) of FISMA;
2. Developing and maintaining information security policies,
procedures and control techniques to address all applicable
requirements, including those issued under section 3553 of Public
Law 113-283 and section 11331 of title 40;
3. Training and overseeing personnel with significant responsibilities
for information security with respect to such responsibilities; and
4. Assisting senior DOE officials concerning their responsibilities to
provide information security for the information and information
systems that support the operations and assets under their control,
including through—
(a) assessing the risk and magnitude of the harm that could result
from the unauthorized access, use, disclosure, disruption,
modification, or destruction of such information or information
systems;
(b) determining the levels of information security appropriate to
protect such information and information systems in
accordance with standards promulgated under section 11331 of
title 40, for information security classifications and related
requirements;
(c) implementing policies and procedures to cost-effectively
reduce risks to an acceptable level; and
(d) periodically testing and evaluating information security
controls and techniques to ensure that they are effectively
implemented.
2. RESCISSION. None.
3. LIMITATION.
3.1. This designation covers all parts of DOE, except the Federal Energy Regulatory
Commission.
3.2 In exercising the designated authority in this Order, the designee shall be
governed by the rules and regulations of the Department of Energy and the
policies and procedures prescribed by the Secretary of Energy or Deputy
Secretary of Energy.
4. AUTHORITY TO REDESIGNATE. This designation may not be redesignated and can
only be redelegated by the CIO.
5. DURATION AND EFFECTIVE DATE.
5.1 All actions pursuant to any authority delegated prior to this Order or pursuant to
any authority delegated by this Order taken prior to and in effect on the date of
this Order are ratified and remain in force as if taken under this Order, unless or
until rescinded, amended, or superseded.
5.2 A copy of this Order shall be provided to DOE’s Office of Management.
5.3 This Order is effective March 25, 2016.
_________________________
Michael Johnson
Chief Information Officer