Delegation of Authorizing Official Office of River Protection (EM)
Document text
Text extracted from the attached file. Refer to the original document for the authoritative version.
Section 1
Department of Energy
Washington, DC 20585
June 9, 2011
MEMORANDUM FOR SCOTT L. SAMUELSON
MANAGER
OFFICE OF RIVER PROTECTION ~ ·
FROM: INES R. TRIA Y ~ /(_ • /f.-A- 7
ASSISTANT SECRETARY FOR
ENVIRONMENTAL MANAGEMENT
SUBJECT: Delegation of Authorizing Official
The Department of Energy Order: DOE 0 205.1 B "Department of Energy Cyber
Security Program" states that Program Secretarial Officers (PSO) will serve as the
Authorizing Official (AO) for all infonnation systems under their purview. Further, it
states that this authority can be further delegated, in accordance with the National
Institute of Standards and Technology (NIST) Special Publication 800-37 rev I, to Senior
Federal officials within the Program elements under their purview.
You are hereby delegated AO responsibilities for classified and unclassified systems
under the management authority of the Office of River Protection (ORP). Further
delegation of this authority is not allowed. In accordance NIST Special Publication
800-37 rev I, you may appoint a federal employee as the AO designated representative.
The AO designated representative may carry out day-to-day duties tasked to the AO and
is empowered to make decisions with regard to planning and the necessary resources
required for authorizing the system. The AO representative can represent the AO, but
cannot accept risk. The AO is the only authorized individual who can accept risk on
behalf of the Department and must sign the authorization granting Authority to Operate.
It is my expectation that the AO or AO designated representative has technical system
knowledge. The AO and AO representative are to: (1) hold a security clearance
(DOE Q); (2) have knowledge of classified threat data; and (3) complete training within 6
months after appointment.
With this Delegation of Authority, you are responsible for the confidentiality, integrity,
and availability of information processed, stored and transmitted over and on IT systems
under your authority. You are authorized to accept risk to these systems. Further, this
delegation includes your authority to grant Authority to Operate or to withdraw Authority
to Operate and to suspend the operation for all classified and unclassified information
systems with operational boundaries that are under the jurisdiction of the ORP.
® Prinlcd wllh soy Ink on rocyclad paper
This memorandum rescinds the delegation of authority for Jonathan A. Dowell, dated
December 30, 2010.
cc: B. Ellison, RL
H. Bell, RL
S. Charboneau, ORP
D. Chung, EMR2
W. Whitley, EM-4.1
T. Hanns, EMR4.1
S. Waisley, EMR 70
J. Beard, EMR 72
S. Wujcik, EMR 72
J. Boone, EMR72
2