Bindinglaw

US · guidance

BOP Program Statement 8051.05 § 3

INFORMATION TECHNOLOGY GENERAL CONTROLS

activein force · 2026-09-03 – presentact-effective-date

FPI systems and business data integrity must be protected at all times. Critical systems must be

properly secured in locations that address environmental issues, such as power and ventilation,

fire prevention, and disaster recovery.

a. Computer Room and Data Closet Access. Each computer room and data closet must have a

secure lock on the door; access is restricted to authorized staff. An Access Control List is posted

at the entrance to these spaces. Under no circumstances may doors to these spaces be left open

unattended.

b. Environmental Conditions. Environmental conditions must be monitored to prevent

damage. Each location or data center ensures that environmental control equipment is installed to

maintain industry-recommended temperatures and relative humidity.

c. Computer Room Construction. The Program Statement Factory Construction and

Activation Manual – FPI contains detailed specifications for new computer room construction.

Staff at existing institutions ensure new computer rooms comply with these standards.

d. Data Management. System backups are performed frequently. Backup data is stored at

offsite secure locations or in the cloud in an availability zone separate from the original source

data. SAs must be familiar with backup software and procedures used to restore data.

e. Systems and Software Maintenance. Hardware, operating system, and application updates

are applied in a timely manner. Operating system and application patches are tested and

documented using non-critical or non-production systems before being applied to any production

system.

f. Access Control. Access control procedures protect systems from unauthorized physical and

logical access. They ensure or validate that a system user has received proper clearance and has

8051.05 9/3/2026 PROPERTY OF US GOVERNMENT 3

supervisory approval before access, and that control measures are documented. Access control

procedures apply to any means of access to FPI’s systems and to any system owned by FPI.

g. System Refresh. MISB establishes a hardware/software refresh cycle to distribute the costs

of replacing aging hardware and software over several years. Funding is requested in each fiscal

year cycle, subject to approval by FPI corporate management and FPI’s Board of Directors.

h. System Development Life Cycle (SLDC)/Change Control. FPI complies with SDLC and

change control policies defined by the DOJ.

i. Audit/Program Review. MISB ensures applicable general control and Information

Technology Systems Standards (ITSS) security standards are followed through periodic internal

reviews.

j. SAs. MISB directs SAs providing IT support at factory locations and in the Central Office.

SAs also participate in temporary duty assignments away from their primary support locations in

direct support of FPI operations. The SA serves as the Information Security Officer (ISO) for the

FPI factories they support. Their security responsibilities are defined by the DOJ to the extent

they do not violate segregation of duty policies. The FPI Chief ISO in the Central Office has

overall security oversight within FPI, as delegated by the Chief Information Officer.

History

PS 8051.05 dated 2026-09-03

Provenance

Source
bop.gov
Retrieved
2026-09-20
Edition
bop-ps-2026-09-20
Content hash
783773e680b1d68ddb91fed78f86db8940bb0d4cc71619279486cc3e8f8552ab
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.