Is a waiver possible for the FDCC implementation?
Since HHS has worked extensively with NIH to tailor the NIH FDCC configuration, any waivers would need to be very strongly supported and documented, based on testing, to include a justification on why FDCC is not possible due to technical limitations and conflict with mission requirements. Waivers must be supported by the IC ISSO and require the approved of the NIH and HHS CISO. See the NIH Information Security web site at http://irm.cit.nih.gov/security/FDCC_Waivers.doc for more complete information.
Since HHS has worked extensively with NIH to tailor the NIH FDCC configuration, any waivers would need to be very strongly supported and documented, based on testing, to include a justification on why FDCC is not possible due to technical limitations and conflict with mission requirements. Waivers must be supported by the IC ISSO and require the approved of the NIH and HHS CISO. See the NIH Information Security web site at http://ocio.nih.gov/security/FDCC_Waiver_Form.pdf for more complete information.