[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Mail]  [Sign-in]  [Setup]  [Help]  [Register] 

"The Bondi Beach Jihad: Sharia Supremacism and Jew Hatred, Again"

"This Is How We Win a New Cold War With China"

"How Europe Fell Behind"

"The Epstein Conspiracy in Plain Sight"

Saint Nicholas The Real St. Nick

Will Atheists in China Starve Due to No Fish to Eat?

A Thirteen State Solution for the Holy Land?

US Sends new Missle to a Pacific ally, angering China and Russia Moscow and Peoking

DeaTh noTice ... Freerepublic --- lasT Monday JR died

"‘We Are Not the Crazy Ones’: AOC Protests Too Much"

"Rep. Comer to Newsmax: No Evidence Biden Approved Autopen Use"

"Donald Trump Has Broken the Progressive Ratchet"

"America Must Slash Red Tape to Make Nuclear Power Great Again!!"

"Why the DemocRATZ Activist Class Couldn’t Celebrate the Cease-Fire They Demanded"

Antifa Calls for CIVIL WAR!

British Police Make an Arrest...of a White Child Fishing in the Thames

"Sanctuary" Horde ASSAULTS Chicago... ELITE Marines SMASH Illegals Without Mercy

Trump hosts roundtable on ANTIFA

What's happening in Britain. Is happening in Ireland. The whole of Western Europe.

"The One About the Illegal Immigrant School Superintendent"

CouldnÂ’t believe he let me pet him at the end (Rhino)

Cops Go HANDS ON For Speaking At Meeting!

POWERFUL: Charlie Kirk's final speech delivered in South Korea 9/6/25

2026 in Bible Prophecy

2.4 Billion exposed to excessive heat

🔴 LIVE CHICAGO PORTLAND ICE IMMIGRATION DETENTION CENTER 24/7 PROTEST 9/28/2025

Young Conservative Proves Leftist Protesters Wrong

England is on the Brink of Civil War!

Charlie Kirk Shocks Florida State University With The TRUTH

IRL Confronting Protesters Outside UN Trump Meeting

The UK Revolution Has Started... Brit's Want Their Country Back

Inside Paris Dangerous ANTIFA Riots

Rioters STORM Chicago ICE HQ... "Deportation Unit" SCRAPES Invaders Off The Sidewalk

She Decoded A Specific Part In The Bible

Muslim College Student DUMBFOUNDED as Charlie Kirk Lists The Facts About Hamas

Charlie Kirk EVISCERATES Black Students After They OPENLY Support “Anti-White Racism” HEATED DEBATE

"Trump Rips U.N. as Useless During General Assembly Address: ‘Empty Words’"

Charlie Kirk VS the Wokies at University of Tennessee

Charlie Kirk Takes on 3 Professors & a Teacher

British leftist student tells Charlie Kirk facts are unfair

The 2 Billion View Video: Charlie Kirk's Most Viewed Clips of 2024

Antifa is now officially a terrorist organization.

The Greatness of Charlie Kirk: An Eyewitness Account of His Life and Martyrdom

Charlie Kirk Takes on Army of Libs at California's UCR

DR. ALVEDA KING: REST IN PEACE CHARLIE KIRK

Steven Bonnell wants to murder Americans he disagrees with

What the fagots LGBTQ really means

I watched Charlie Kirk get assassinated. This is my experience.

Elon Musk Delivers Stunning Remarks At Historic UK March (Tommy Robinson)

"Transcript: Mrs. Erika Kirk Delivers Public Address: ‘His Movement Will Go On’"


Status: Not Logged In; Sign In

Corrupt Government
See other Corrupt Government Articles

Title: CMS memo Approved and Signed by Marilyn Tevenner, Accepting Security Risk of Untested Obamacare Website to Authorize Activation (27 Sep 2013)
Source: scribd
URL Source: http://www.scribd.com/doc/180387053 ... thorize-Activation-27-Sep-2013
Published: Oct 30, 2013
Author: CMS/Marilyn Tavenner
Post Date: 2013-10-30 22:52:50 by nolu chan
Keywords: Tavenner, security memo, obamacare
Views: 2607
Comments: 2

http://www.scribd.com/doc/180387053/CMS-memo-Approved-and-Signed-by-Marilyn-Tavenner-Accepting-Security-Risk-of-Untested-Obamacare-Website-to-Authorize-Activation-27-Sep-2013

CMS memo Approved and Signed by Marilyn Tavenner, Accepting Security Risk of Untested Obamacare Website to Authorize Activation (27 Sep 2013)

Post Comment   Private Reply   Ignore Thread  


TopPage UpFull ThreadPage DownBottom/Latest

#1. To: All (#0)

DATE:

TO: Marilyn Tavenner

FROM: James Kerr, Consortium Administrator for Medicare Health Plans Operations,
Henry Chao, Deputy Chief Information Officer & Office of Information Services Deputy Director

SUBJECT: Federally Facilitated Marketplace-DECISION

ISSUE:

The Federal Information Security Management Act (FISMA) requires that the various Federally Facilitated Marketplace (FFM) systems - Enterprise and Eligibility (E&E), Financial Management (FM), and Plan Management (PM) successfully undergo a Security Control Assessment (SCA). Due to system readiness issues, the SCA was only partly completed. This constitutes a risk that must be accepted and mitigated to support the Marketplace Day 1 operations.

BACKGROUND

CMS utilizes independent and specialized contractors to test the security readiness of its systems. Testing of the Marketplace has been on-going since inception as part of the CMS Expedited Life-Cycle process with the latest security testing occurring in September of 2013. As with all new systems which are pending launch, there are inherent security risks with not having all code tested in a single environment, finally, the system requires rapid development and release of hot-fixes and patches so it is not always available or stable during the duration of testing.

From a security perspective, the aspects of the system that were not tested due to the ongoing development, exposed a level of uncertainty that can be deemed as a high risk for FFM. Although throughout the three rounds of SCA testing all of the security controls have been tested on different versions of the system, the security contractor has not been able to test all of the security controls in one complete version of the system.

The risk associated with issuing an ATO for the FFM will be reduced by instituting a two-part mitigation plan.

First, CMS will implement the following security processes for the first year of operation of FFM:

  • Establish a dedicated security team under the Chief Information Officer (CIO) to monitor, track and ensure the mitigation plan activities are completed. The CIO and the Chief Information Security Officer (CISO) will report weekly on the progress to the Health Reform Operations Board;

  • Monitor and perform weekly testing of all border devices, including internet facing web servers;

  • Conduct daily/weekly scans using the CISO's continuous monitoring tools

  • Conduct a full SCA test on FFM (E&E, FM and PM) in a stable environment where all security controls can be tested within 60/90 days of going live on October 1st.

Second, CMS will migrate the Marketplace systems to CMS' Virtual Data Center (VDC) environment in Ql-2014. This environment has been through a foil security assessment and has an authority to operate.

RECOMMENDATION:

Issue an Authority-to-Operate (ATO) for six months and implement the mitigation plan. The six- month period will allow the Marketplace to normalize its development activities while enabling the security team to closely monitor activities and perform a complete SCA.

Approved Marilyn Tavenner Date SEP 27 2013

Disapproved

Attachment: Federally Facilitated Marketplace Decision Memo Risk Acknowledgment Signature Page

- - - - -

CMS
CENTERS FOR MEDICARE & MEDICAID SERVICES

DEPARTMENT OF HEALTH & HUMAN SERVICES
Centers for Medicare & Medicaid Services
7500 Security Boulevard, Mail Stop
Baltimore, Maryland 21244-1850

Federally Facilitated Marketplace Decision Memo Risk Acknowledgment Signature Page

We acknowledge the level of risk the Agency is accepting in the Federally Facilitated Marketplace (FFM). The mitigation plan does not reduce the risk to the FFM system itself going into operation on October 1,2013. However, the added protections do reduce the risk to the overall Marketplace operations and will ensure that the FFM system is completely tested within the next 6 months.

Reviewer Teresa Fryer - - Date 9-27-2013

Reviewer Tony Trenkle - - Date 9-27-2013

Reviewer Michelle Snyder - - Date 9-27-2013

nolu chan  posted on  2013-10-30   22:53:56 ET  Reply   Trace   Private Reply  


#2. To: All (#0)

www.cnn.com/2013/10/30/politics/obamacare-sebelius/index.html

Sebelius: 'I apologize, I'm accountable' for Obamacare website problems

By Tom Cohen, CNN
updated 9:31 PM EDT, Wed October 30, 2013

[snip]

Security questions

Republican Rep. Mike Rogers of Michigan, who chairs the House Intelligence Committee, accused Sebelius of putting the private information of Americans at risk by failing to properly test security measures on the website.

"This is a completely unacceptable level of security," he said. "You know it's not secure."

Sebelius responded that testing occurs regularly, and she told Rogers she would get back to him on whether any end-to-end security test of the entire system has ever occurred. Rogers responded that he knows there have been no such comprehensive security tests.

Memo warned of high security risk at health care website

An internal government memo, obtained by CNN on Wednesday and written days before the website opened, warned of a "high" security risk because of a lack of testing.

"Due to system readiness issues, the (security control assessment) was only partly completed," said the Centers for Medicare and Medicaid Services memo. "This constitutes a risk that must be accepted and mitigated to support the Marketplace Day 1 operations."

At Wednesday's hearing, Sebelius said an independent security non-profit, Mitre Corporation, assessed the HealthCare.org system and "did not raise flags about going ahead." A mitigation plan was being implemented, Sebelius added.

In an exclusive interview with CNN last week, Sebelius said Obama didn't know of the problems with the Affordable Care Act's website -- even though insurance companies had complained and the site crashed during a pre-launch test run -- until after its launch.

A senior administration official told CNN that, nowadays, Obama gets a "nightly readout" on the available statistics related to the Affordable Care Act and work to improve the HealthCare.gov website. According to the official, White House Chief of Staff Denis McDonough talks to the President about the issue multiple times a day.

More: What else could go wrong with Obamacare?

CNN's Joe Johns, Gloria Borger, Kevin Bohn, Mariano Castillo, Lisa Desjardins and Z. Byron Wolf contributed to this report.

nolu chan  posted on  2013-10-30   23:01:20 ET  Reply   Trace   Private Reply  


TopPage UpFull ThreadPage DownBottom/Latest

[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Mail]  [Sign-in]  [Setup]  [Help]  [Register] 

Please report web page problems, questions and comments to webmaster@libertysflame.com