Archives of Directives

Rescinded

28.00, Designation to Paul Cunningham

00-28_CIO-Chf_Info_Sec_Ofcr.pdf39.62KB
Document text

Text extracted from the attached file. Refer to the original document for the authoritative version.

Section 1

DEPARTMENT OF ENERGY DESIGNATION ORDER NO. 00-28.00 TO PAUL CUNNINGHAM 1. DESIGNATION. Pursuant to the Under Secretary’s (for Management and Performance) Redelegation Order to the Chief Information Officer (CIO), I designate Paul Cunningham to serve as the Department of Energy’s (DOE) Chief Information Security Officer, as that title and its responsibilities are described in section 3554 (a) (3) (A) of the Federal Information Security Modernization Act (FISMA) of 2014 (Public Law 113-283), and to have the authority to take the following actions: A. Carry out the CIO’s responsibilities under FISMA which are: 1. Developing and maintaining a DOE-wide information security program as required by section 3554(b) of FISMA; 2. Developing and maintaining information security policies, procedures and control techniques to address all applicable requirements, including those issued under section 3553 of Public Law 113-283 and section 11331 of title 40; 3. Training and overseeing personnel with significant responsibilities for information security with respect to such responsibilities; and 4. Assisting senior DOE officials concerning their responsibilities to provide information security for the information and information systems that support the operations and assets under their control, including through— (a) assessing the risk and magnitude of the harm that could result from the unauthorized access, use, disclosure, disruption, modification, or destruction of such information or information systems; (b) determining the levels of information security appropriate to protect such information and information systems in accordance with standards promulgated under section 11331 of title 40, for information security classifications and related requirements; (c) implementing policies and procedures to cost-effectively reduce risks to an acceptable level; and (d) periodically testing and evaluating information security controls and techniques to ensure that they are effectively implemented. 2. RESCISSION. None. 3. LIMITATION. 3.1. This designation covers all parts of DOE, except the Federal Energy Regulatory Commission. 3.2 In exercising the designated authority in this Order, the designee shall be governed by the rules and regulations of the Department of Energy and the policies and procedures prescribed by the Secretary of Energy or Deputy Secretary of Energy. 4. AUTHORITY TO REDESIGNATE. This designation may not be redesignated and can only be redelegated by the CIO. 5. DURATION AND EFFECTIVE DATE. 5.1 All actions pursuant to any authority delegated prior to this Order or pursuant to any authority delegated by this Order taken prior to and in effect on the date of this Order are ratified and remain in force as if taken under this Order, unless or until rescinded, amended, or superseded. 5.2 A copy of this Order shall be provided to DOE’s Office of Management. 5.3 This Order is effective March 25, 2016. _________________________ Michael Johnson Chief Information Officer

Something wrong with this record? Tell us