26. DRAFT - Template_DHA RMF System Authorization Boundary.pdf
PDF 990 KB Posted
- Attached to
- Charleston Consolidated Storage Distribution Center Federal contract opportunity
- Solicitation number
- Not on record
About this file
This document contains a draft system authorization boundary diagram template for the Defense Health Agency Risk Management Framework. The template provides requirements and guidance for creating system authorization boundary diagrams, including depicting accreditation boundaries, system components, network devices, servers, workstations, printers, and connections. Key details to include on diagrams are unique host identifiers, equipment inventory, operating systems, server and device types, IP addresses, and network flows. The template also provides device icon examples and instructions for representing groups of like devices. A sample diagram using the template is included, showing an authorization boundary for a hypothetical system with servers, workstations, printers, and network devices across multiple buildings.
View the file
Other files for this federal contract opportunity
Show all 37
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DHA RMF SYSTEM AUTHORIZATION BOUNDARY DIAGRAM REQUIREMENTS
Per the DISN Connection Process Guide (CPG), section 3.8 - Customer Network Enclave Topology Diagram Requirements, the System Boundary Diagram(s) must clearly show the boundary and the systems to be tested.
Minimum requirements for Detailed Architecture Diagram/Network Topology (If bullets are not applicable to your System, identify the System that it is inherited from):
Revision history page be populated with the latest date of change.
eMASS System Name & eMASS ID
Date of last update
Clearly delineate accreditation boundaries
Identify the city and state where the component are located and building names and numbers (if applicable)
All ISs must be identified with a Unique Host Identifier (UHI). The UHI can be the hostname or IP address (full or shortened with last 2 octets).
ISs should be traceable to the Detailed Hardware Inventory list.
Identify equipment inventory (to include the most recent configuration including any enclave boundary firewalls, Intrusion Detection Systems (IDS), premise router, routers, switches, backside connections, Internet Protocol (IP) addresses, encryption devices, Cross Domain Solutions (CDS)
Identify any connections to other systems/networks/enclaves
Each system or group of systems displayed on the diagram requires:
UHI
Type of system (e.g Workstation, Database/Web/File Server, Switch, Router, Printer)
Make and model of hardware
Operating System/IOS with version number
Each server component shown on the diagram must include the type of server (e.g. Database, Web, File, etc.)
Each server type can be represented by one icon.
For example, if there are 15 web servers and 10 database servers, only one icons is necessary for each server type.
One icon would be used to represent the web servers with the number 15 in parenthesis and one icon would be used to represent the database servers with the number 10 in parenthesis.
Groups of servers can be represented using a subnet/host/IP range.
Workstation subnets can be represented using a range of IP addresses, icons for individual workstations are not required
Each workstation type can be represented by one icon.
For example, if there are 15 Windows 10 workstations and 10 Windows 8 workstations, only one icons is necessary for each workstation type.
One icon would be used to represent the Windows 10 with the number 10 in parenthesis and one icon would be used to represent the Windows 8 workstations with the number
10 in parenthesis.
Groups of workstations can be represented using a subnet/host/IP range.
Printer subnets can be represented using a range of IP addresses, icons for individual printers are not required
Perimeter devices within the authorization boundary that control inbound and outbound access must be clearly identified
Components within the authorization boundary supporting remote access must be clearly identified
Wireless devices within the authorization boundary must be clearly identified
Diagram(s) must have a legend and be legible. The flow of information to, from, and through all connections, host IP addresses, and CCSD number, if known must be shown
Rev. # Description Date Drawn By 1 Creation 3/25/2021 Carmeshia Miller
REVISIONS
REVISIONS
ZONE REV DESCRIPTION DATE APPROVED
Symbol Count Description
Legend Subtitle
Legend
1 Print server
1 Server
1 Email server
1 Database server
1 Web server
Application server
1 File server
1 Firewall
1 Printer
1 Switch
1 Router
1 PC
1 Laptop computer
Multi-function device
1 Bridge
Wireless access point
Content management server
1 Proxy server
1 Router.132
1 ATM switch.134
Communications Link
Ethernet
ACCREDITATION BOUNDARY
(Shaded in Red)
DRAWN BY
CARMESHIA MILLER
REVISED
4/16/2021
TITLE
System Name (Acronym)
DATE
12/10/2018
File Server
Exchange/Email Server
Server
Web Server
Database Server
Print Server
Application Server
DEVICE ICONS - SERVER DEVICE ICONS - NETWORK
DEVICE ICONS – WORKSTATION
& PRINTERS
Firewall
Printer
SwitchRouter
PC/Workstation
Laptop
Multi-Function Device
Bridge
Wireless Access Point
Content Manager Server
Proxy Server
NOTE: You may add or remove devices as applicable.
NIPRNet
Router
Switch
Room # XXX
MHS, .MIL,
MJAD, NIPR
XXXXX System Authorization Boundary
For Official Use Only (FOUO)
For Official Use Only (FOUO) text
TITLE
System Name (Acronym)
DESCRIPTION
Add boundary description and details here.
NOTE:
ALL ITEMS IN RED SHOULD BE MODIFIED TO BE
SPECIFIC TO YOUR BOUNDARY. IF THE ITEM.DEVICE
DOES NOT APPLY, DELETE IT.
DHA Firewall eMASS ID#: XXXX
Symbol Count Description
Legend Subtitle
Legend
Management server
Database server
1 Firewall
1 PC
Laptop computer
1 Printer.140
Wireless access point.143
1 Router.132
ATM
switch.134
1 Web server
System Acronym Authorization Boundary
XXXXX-DB02 –
SQL Database
Microsoft SQL 2013 IP Address: 192.168.6.2
SL150 Tape Library Storage
IP Address: 192.168.5.2
XXXXX-OSB – Backups Server Oracle S7
Solaris 11.4 IP Address: 192.168.5.4
XXXXX-DB03 – Backups Server
SPARC V440
Solaris 10 IP Address: 192.168.5.3
Virtual
XXXXX-DIDM1
Identity Management Srvr Solaris 10 1/13
192.168.6.4
Windows 10 (20) IP Addresses: 192.168.1.1-20
Windows 10 (15)
IP Addresses: 192.168.2.1-15
HP LaserJet X 5 IP Addresses: 192.168.3.1-5
Windows 8 (10)
IP Addresses: 192.168.4.1-10
Room 1002
Room 1001 Room 1003
XXXXX-WS01-
IIS/Web Svr
Microsoft Server 2016 IP Address: 192.168.6.3
Switch
Switch
Switch
Router
ACCREDITATION
BOUNDARY
(Shaded in Red)
| DHA RMF System Authorization Boundary -Template.vsdx |
| System Authorization Boundary Requirements |
| Revison History |
| Devices & Key |
| DHA RMF Network Diagram/Boundary Template |
File details come from the government source that posted it. Updated .