afgm 2019_32-02.pdf
PDF 282 KB Posted
- Attached to
- Upgrade Direct Digital Control (DDC) System Federal contract opportunity
- Solicitation number
- W50S8V20B0004
- Issued by
- Department of the Army National Guard
About this file
This solicitation seeks services to upgrade a Direct Digital Control system. The West Virginia Air National Guard requires upgrading the DDC system at the 167th Air Wing to a value between $100,000 and $250,000. This 100% set-aside for Woman-Owned Small Businesses has a NAICS code of 238220 and small business size standard of $16.5M. The bid opening will be on June 29, 2020 at 2:00 PM EST, with award made to the responsible bidder providing the most advantageous price.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| W50S8V20B0004.pdf | ||
| UFC 4_010_06_.pdf | ||
| Request For Information Form - Upgrade Direct Digital Control System.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DEPARTMENT OF THE AIR FORCE
HEADQUARTERS UNITED STATES AIR FORCE
WASHINGTON, DC
AFGM2019-32-02
5 September 2019
MEMORANDUM FOR DISTRIBUTION C
MAJCOMs/FOAs/DRUs
FROM: HQ USAF/A4
1030 Air Force Pentagon Washington DC 20330-1030
SUBJECT: Air Force Guidance Memorandum, Civil Engineer Control Systems Cybersecurity
ACCESSIBILITY: Publication and forms are available on the e-Publishing website at www.e-Publishing.af.mil for downloading or ordering.
RELEASIBILITY: There are no releasability restrictions on this publication.
OPR: AF/A4CF, Facilities Division
By Order of the Secretary of the Air Force, this Air Force Guidance Memorandum immediately establishes cybersecurity policy for Civil Engineer-owned, operated, or maintained control systems (hereinafter referred to as “control systems (CS)”). This Memorandum details the unique operational characteristics of CS, outlines roles and responsibilities for managing risk under the Risk Management Framework (RMF), and implements policy for securing and mitigating cybersecurity risk to CS.
This Guidance Memorandum applies to all Air Force military, civilian, and contractor personnel under contract to the Department of Defense (DoD) who develop, acquire, deliver, use, operate, manage, or maintain CS (to include Air National Guard and Air Force Reserves).
Compliance with this Memorandum is mandatory. To the extent its direction is inconsistent with other Air Force publications, the information herein prevails, in accordance with Air Force Instruction (AFI) 33-360, Publications and Forms Management. Refer recommended changes and questions about this publication to the Office of Primary Responsibility using AF Form 847, Recommendation for Change of Publication, routed through chain of command. The authorities to waive wing/unit level requirements in this publication are identified with a Tier (“T-0, T-1, T-2, T-3”) number following the compliance statement. See AFI 33-360 for a description of the authorities associated with the Tier numbers. Submit requests for waivers through the chain of command to the appropriate Tier waiver approval authority, or alternately, to the requestors commander for non-tiered compliance items.
http://www.e-publishing.af.mil/ http://static.e-publishing.af.mil/production/1/saf_aa/publication/afi33-360/afi33-360.pdf
Ensure all records created as a result of processes prescribed in this publication are maintained in accordance with Air Force Manual (AFMAN) 33-363, Management of Records, and disposed of in accordance with the Air Force Records Disposition Schedule located in the Air Force Records Information Management System. This Memorandum becomes void after one year has elapsed from the date of this Memorandum, or upon the publication of a new Instruction permanently establishing the guidance, whichever is earlier.
WARREN D. BERRY, Lieutenant General, USAF DCS/Logistics, Engineering & Force Protection
Chapter 1
OVERVIEW
1.1. Control Systems Background.
1.1.1. Operational Technology1 has become ubiquitous and integrated into every piece of modern life. Throughout the Air Force, CS (a subset of operational technology) are extensively used to monitor, operate, and/or control equipment, infrastructure, and their associated devices (e.g., power generation and distribution, air conditioning, water and wastewater plants, natural gas distribution).
1.1.1.1. CS can take various forms according to size, complexity, function, or configuration. Some types of CS may exist as building automation systems, energy management control systems, or industrial control systems. Industrial control systems can be further divided to include supervisory control and data acquisition systems, distributed control systems, programmable logic controllers, and others.
1.1.2. CS support nearly all aspects of Air Force core mission areas; by extension, if the CS can be compromised, so can the mission(s) they support (Figure 1). Unmitigated vulnerabilities can be exploited by adversaries; (1) potentially leading to mission failure, extended operational impacts, and physical damage to critical infrastructure, or (2) providing an attack vector into the broader Air Force network and business systems.2
Figure 1: Mission Dependency on Infrastructure
1.1.3. When applying IT security controls and solutions to CS environments, one must take special precaution to ensure both operational and cybersecurity considerations are balanced due to the unique nature of CS. Security controls and solutions must be (1) used to the fullest extent possible without sacrificing CS performance and reliability, (2) tailored to the specific CS environment, and (3) verified to ensure the CS operates correctly after the solutions and controls are applied.
1.1.4. Because of the increased presence of cyberspace within the Civil Engineer portfolio, the Civil Engineer community is a stakeholder (along with mission owners and cyber
1 Operational Technology is defined in the Air Force Information Dominance Flight Plan (published February 2017) and has since been defined in National Institute of Standards and Technology Special Publication (NIST SP) 800-53r5 (draft), Security and Privacy Controls for Information Systems and Organizations. Note: Also referred to as “Platform Information Technology (PIT)” 2 Figure 1 depicts how an adversary could disrupt, degrade, or deny a mission by targeting the foundational infrastructure.
https://csrc.nist.gov/csrc/media/publications/sp/800-53/rev-5/draft/documents/sp800-53r5-draft.pdf defenders) in mitigating the rising threats posed to infrastructure and supporting CS as part of Civil Engineer’s mission to establish, operate, maintain, and protect installations.
Cyber risk management has become a critical element of Civil Engineer’s efforts to ensure infrastructure is always available to support the Air Force mission.
1.2. Scope. This Guidance Memorandum supplements existing policies, such as Department of Defense Instruction (DoDI) 8500.01, Cybersecurity and DoD’s RMF (outlined in DoDI 8510.01 and AFI 17-101), by providing more explanatory guidance on security measures and responsibility specifically for CS.
Per the Air Force Chief Information Security Officer’s (SAF/CNZ) Authorizing Official (AO) appointment letter as required by AFI 17-101, “the CE CS boundary includes Air Force CE-owned, -operated, or -maintained Operational Technology (OT) designated as Platform IT (PIT) according to the definition in DoDI 8500.01, Cybersecurity and consistent with NIST SP 800-82 Rev. 2, Guide to Industrial Control Systems (ICS) Security. The CE CS boundary also includes IT that directly supports the operation, maintenance, and security of the logically-segmented, CE CS network enclave (e.g., Community of Interest Network Enclave (COINE)).” Examples of what is encompassed in the authorization boundary includes, but is not limited to, the following types of systems (e.g., points, devices, control panels, means of connectivity, software, controllers, workstations, servers, etc.):
1.2.1. Supervisory Control and Data Acquisition systems
1.2.1.1. Protective relays (microprocessor-based)
1.2.1.2. Cathodic protection systems
1.2.1.3. Natural gas distribution systems
1.2.1.4. Power generation systems, including renewable systems
1.2.1.5. Water/wastewater distribution systems
1.2.1.6. Water/wastewater treatment systems
1.2.2. Building Automation Systems
1.2.2.1. Energy Management Control Systems
1.2.2.2. Advanced Meter Reading Systems
1.2.2.3. Interior/exterior lighting controls
1.2.3. Life Safety systems3
1.2.3.1. Fire Alarm Reporting Systems
1.2.3.2. Fire Suppression Systems
1.2.3.3. Facility Mass Notification Systems
1.2.4. Utility Monitoring and Control Systems
1.2.4.1. Electrical distribution systems
1.2.4.2. Generator monitoring systems
1.2.5. Airfield control systems
1.2.5.1. Airfield Lighting Control Systems4
1.2.5.2. Aircraft Arresting Systems
1.2.5.3. Runway Ice Detection Systems
1.2.5.4. Bird abatement systems
1.2.5.5. Ramp lighting control systems
3 Life Safety systems are CS that must function reliably, safely, and meet applicable codes and standards. Life Safety systems protect personnel against undue risk of fire, environmental, and/or other hazards that could potentially result in loss of life.
4 Airfield Lighting systems are CS that must function reliably, safely, and meet applicable codes and standards. Airfield lighting systems protect personnel against undue risk of fire, environmental, and/or other hazards that could potentially result in loss of life.
http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/850001_2014.pdf http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/850001_2014.pdf http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/851001_2014.pdf http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/851001_2014.pdf http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afi17-101/afi17-101.pdf
1.2.6. Traffic Control Systems
1.2.6.1. Drop-arm barriers
1.2.6.2. Pop-up barriers
1.2.6.3. Traffic signal systems
1.2.7. Intrusion Detection Systems5
1.2.8. CS network enclave
1.2.9. The Civil Engineer CS boundary does not include Depot CS, Satellite CS, or instruments used to support the depot maintenance mission, nor does it include CE Platforms (i.e., other cyberspace systems not defined by the CE IT or CE CS boundaries, such as Rapid Airfield Damage Assessment System (RADAS), Explosive Ordnance Disposal (EOD) robots).
1.2.10. Additionally, AFI 32-9005 para 5.4.2, Real Property Accountability and Reporting provides further distinction for which control system components are considered Real Property Installed Equipment versus Equipment.
5 Refer to AFI 32-9005 for specific information on which intrusion detection systems fall under Civil Engineer ownership.
https://static.e-publishing.af.mil/production/1/af_a4/publication/afi32-9005/afi32-9005.pdf https://static.e-publishing.af.mil/production/1/af_a4/publication/afi32-9005/afi32-9005.pdf
Chapter 2
ROLES AND RESPONSIBILITIES
2.1. The Director of Civil Engineers (AF/A4C). Responsible for organizing, training and equipping the engineering force along with providing policy and oversight for the planning, development, construction, maintenance, utilities and environmental quality of Air Force bases worldwide. (T-1).
2.2. Air Force Installation and Mission Support Center (AFIMSC). AFIMSC/RM (Resource Management Directorate) develops the funding line and distributes funding for execution. (T-1).
2.3. Authorizing Official (AO). Appointed by SAF/CN per AFI 17-101, and responsible for managing the risk of CS and may tailor controls to balance security and availability. (T-1).
2.4. Security Controls Assessor (SCA). Appointed by SAF/CNZ per AFI 17-101, and responsible for making assessment determinations and authorization recommendations to the AO.
(T-1).
2.5. Air Force Civil Engineer Center (AFCEC).
2.5.1. AFCEC will ensure incorporation of cybersecurity requirements and costs into all phases of each Directorate’s activities and products (see para 3.3). This shall include, but is not limited to, a process of review on the effectiveness of holding design agents accountable for AFCEC-managed requirements. (T-1).
2.5.2. AFCEC/COO (Operations Maintenance Division) is the execution organization directly supporting the AO and SCA for active duty installations: providing technical guidance on CS cybersecurity, assisting installations, and conducting scheduled, pre-arranged installation visits to:
2.5.2.1. Establish RMF authorization processes in Civil Engineers for CS aligned with RMF roles (para 2.3-2.4, 2.7-2.9) and para 3.2, in coordination with the AO. (T-1).
2.5.2.2. Perform RMF activities: establish Security Control Baseline, perform risk assessments, identify mitigations, validate Authorization to Operate (ATO) packages for SCA review and AO signature, and process entries into eMASS. (T-1).
2.5.2.3. In coordination with the installation’s Comm Squadron, install a CS network enclave (see para 3.4) at the installation-level in a prioritized manner and ensure the network enclave is processed into ITIPS per AFI 17-101. (T-1).
2.5.2.4. In coordination with the installation’s Civil Engineer Squadron, Comm Squadron, and system vendor, migrate AO-approved CS into the installed, CS network enclave in a prioritized manner (see para 3.4). (T-1).
2.5.3. AFCEC/COO is responsible for outlining a standardized template to collect a CE-enterprise inventory of CS (see para 3.1). (T-1).
2.5.4. AFCEC/COO is responsible for managing the Engineering Change Request process for newly-purchased, upgraded, or existing control systems. (T-1).
2.6. Base Civil Engineer. Responsible for maintaining the operations and ensuring the cybersecurity posture of CS at the installation (T-1)., and shall ensure:
2.6.1. An Information System Owner (ISO) is appointed for installation-level CS per AFI 17-101 para 1.2.4, since CS is not centrally managed. (T-1).
http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afi17-101/afi17-101.pdf http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afi17-101/afi17-101.pdf
2.6.1.1. Identify an ISO for CS prior to the current ISO vacating the position. (T-1).
2.6.1.2. Provide AFCEC/COO the names of current control system ISO(s) (see para 2.6.1) and Information Security System Manager(s) (ISSM) (see para 2.7.5). (T-2).
2.6.2. Mitigation and remediation of identified vulnerabilities. (T-1).
2.6.2.1. Develop requirements and prioritize for replacement of CS, as appropriate. (T- 1).
2.6.3. Coordination to provide physical and IT administrative access to the necessary facilities and systems required to support sanctioned CS cybersecurity activities (e.g., assessments, mitigation, data collection, inventory, etc.). (T-2).
2.6.4. Inventory of installation-level CS is current, accurate, and collected no less than annually (see para 3.1). (T-0).
2.6.5. Incident Response and System Recovery/Contingency Plans are in place as outlined in para 4.5. (T-0).
2.7. Information System Owner (ISO).
2.7.1. Ensure execution of the ISO responsibilities are satisfied for CE-owned, operated, and maintained CS per AFI 17-101.6 (T-1).
2.7.2. Follow the RMF authorization process identified by the SCA (para 3.2) for CS.
(T-1).
2.7.3. Ensure the Security Control Baseline, established by AFCEC/COO (para 2.5.2.2), is implemented. (T-1).
2.7.4. Ensure policies in this Memorandum are satisfied. (T-1).
2.7.5. Appoint an ISSM at the installation for CS per AFI 17-101 para 2.13.4 to support and assist the ISO. (T-1).
2.8. Information System Security Manager (ISSM).
2.8.1. Ensure the ISSM responsibilities are satisfied for CE-owned, operated, and maintained CS per AFI 17-101. (T-1).
2.8.2. Support the ISO in ensuring the policies in this Memorandum are satisfied. (T-1).
2.9. Information System Security Officer (ISSO).
2.9.1. Ensure the ISSO responsibilities are satisfied for CE-owned, operated, and maintained CS per AFI 17-101. (T-1).
2.9.2. Support the ISO and ISSM in ensuring the policies in this Memorandum are satisfied.
(T-1).
2.10. Air National Guard and Air Force Reserve. HQ NGB/A4 and HQ AFRC/A4 will provide support and supplemental guidance as required. (T-1).
6 Until there is a centralized program management office for CS in the Air Force, Program Manager duties cannot be fulfilled (specifically those stated in AFI 17-101 para 2.13.2).
http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afi17-101/afi17-101.pdf http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afi17-101/afi17-101.pdf http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afi17-101/afi17-101.pdf
Chapter 3
CYBERSECURITY IMPLEMENTATION
3.1. CS Inventory. Civil Engineer units shall annually conduct and continuously maintain accurate inventories of all the installation’s CS and associated components. (T-0).
3.1.1. The inventory shall contain each instance of a CS (per the types listed in para 1.2) at the installation down to topology Tier Level 2 based on the CS architecture topology diagram and definitions in Unified Facilities Criteria (UFC) 4-010-06, Appendix E. Use the standardized inventory template provided by AFCEC/COO (see para 2.5.3). (T-1).
3.1.2. The ISO, ISSM, and/or ISSO shall track any new systems or system modifications and document them in the installation’s CS inventory per NIST SP 800-53r5 (draft) para
3.5 and this Guidance Memorandum’s para 3.1. (T-0).
3.2. Risk Management Framework.
3.2.1. Civil Engineer units are required to transition from the Defense Information Assurance Certification and Accreditation Program (DIACAP) to RMF and comply with the ATO requirements for authorization of CS (outlined in para 2.5.2.1 and Air Force RMF policy, AFI 17-101). (T-0).
3.2.2. All newly-initiated authorization packages for CS shall be aligned with RMF, as outlined in para 2.5.2.1. (T-0).
3.2.3. Refer to Chapter 2 for the RMF responsibilities translated for CS.
3.3. Construction, Repair, or Energy Requirements.
3.3.1. Presently, acquisition of CS is a decentralized process in the Air Force. There is currently no program management-like office assigned to centrally acquire, test, deploy, or support life cycle management of CS. Until such time, the Civil Engineer unit and AFCEC project managers will work together with design agents and vendors to accurately define cybersecurity requirements and prioritize CS acquisitions with cybersecurity measures incorporated into the design of the system. (T-2). For any new acquisition or replacement of CS at a Tier Level 2 or above (as defined by UFC 4-010-06), consult AFCEC/COO for design reviews, proposals, quotes, statements of work, etc. (T-2).
3.3.2. Projects and third party financing (e.g., military construction, Energy Savings Performance Contracts (ESPC), Utility Energy Service Contracts (UESC), microgrids, Environmental Security Technology Certification Programs (ESTCP), Advanced Meter Reading Systems (AMRS), etc.) must follow existing standards and policies to incorporate cybersecurity and associated costs into all phases of product/service delivery: contract language, design, development, test and evaluation, integration, execution, construction, operation, maintenance, sustainment, upgrade, or replacement. These existing standards and policies include Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, this Guidance Memorandum, UFC 4-010-06, NIST SP 800-82r2, NIST SP 800-53r5 (draft), and the best practices from the Department of Homeland Security (DHS)’s Cyber Security Procurement Language for Control Systems (https://ics-cert.us cert.gov/sites/default /files/documents/Procurement_Language_Rev4_100809_S508C.pdf). (T-1).
3.3.3. Add newly-installed or acquired CS to the installation’s inventory (para 3.1).
(T-0).
https://www.wbdg.org/ffc/dod/unified-facilities-criteria-ufc/ufc-4-010-06 https://csrc.nist.gov/csrc/media/publications/sp/800-53/rev-5/draft/documents/sp800-53r5-draft.pdf https://csrc.nist.gov/csrc/media/publications/sp/800-53/rev-5/draft/documents/sp800-53r5-draft.pdf http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afi17-101/afi17-101.pdf https://www.wbdg.org/ffc/dod/unified-facilities-criteria-ufc/ufc-4-010-06 https://www.acq.osd.mil/dpap/dars/dfars/html/current/252204.htm https://www.acq.osd.mil/dpap/dars/dfars/html/current/252204.htm https://www.wbdg.org/ffc/dod/unified-facilities-criteria-ufc/ufc-4-010-06 https://csrc.nist.gov/csrc/media/publications/sp/800-53/rev-5/draft/documents/sp800-53r5-draft.pdf https://ics-cert.us-cert.gov/sites/default/files/documents/Procurement_Language_Rev4_100809_S508C.pdf https://ics-cert.us-cert.gov/sites/default/files/documents/Procurement_Language_Rev4_100809_S508C.pdf
3.3.4. Ensure contract language requires the use of government-owned assets (e.g., computer, tablet) for CS maintenance. (T-0).
3.3.5. Ensure contract language requires on-site maintenance (see para 3.9). (T-1).
3.3.6. Ensure contract language prohibits the connection of removable media (refer to para 3.11) to a CS or CS network enclave other than as described in para 3.9.6. (T-1).
3.3.7. Ensure contract language requires the vendor(s) to provide (1) copies of operator, administrator, and/or maintenance manuals, (2) copies of the system’s topology, hardware/ software inventory, and configuration, as well as (3) training and associated materials.
(T-2).
3.3.8. Ensure contract language requires the vendor(s) to perform an initial security assessment, a scan of vulnerabilities, to provide a copy of the scan results, and to mitigate the identified vulnerabilities prior to final acceptance by the Air Force. (T-1).
3.3.9. Before installing or modifying CS, projects and contracts must (1) fund the initial cost for assessment and authorization of the CS under the RMF process, (2) provide sufficient documentation to enable the Air Force to finalize the authorization (see para 3.2), and (3) obtain approved authorization package. Involve the base ISO in the process. (T-1).
3.3.10. Additionally, Utilities Privatization contracts must include the DFARS 252.204- 7012 clause and follow standards specified in NIST SP 800-171r1, DoDI 4170.11, and additional cybersecurity direction stated in the Office of the Under Secretary of Defense for Acquisition and Sustainment (OUSD (A&S)) memo, Supplemental Guidance for the Utilities Privatization Program, 07 February 2019. (T-0).
3.3.11. For energy projects, follow cybersecurity guidance stated in the Office of the Assistant Secretary of Defense for Energy, Installations, and Environment (OASD (EI&E)) memo Installation Energy Plans – Energy Resilience and Cybersecurity Update, 30 May 2018. (T-0).
3.4. Connectivity. Most CS across the Air Force currently rely on the Air Force Network, its inherited enterprise services, and a variety of other forms of connectivity for uninterrupted operational function of the system. The goal is to consolidate all CS into a single connectivity architecture. Recognizing the disparate system requirements and connectivity landscape, adhere to the tiered approach outlined in this para. All CS not in the current state (para 3.4.1), protected by a network enclave (para 3.4.2), or approved through exemption (para 3.4.3) are subject to disconnection from the network.
3.4.1. Current State.
3.4.1.1. Until AFCEC/COO installs CS network enclaves (para 3.4.2) at the installation, the Civil Engineer unit will monitor their systems’ security controls. In order to prepare for the CS network enclave deployment and the CS to be migrated into the enclave, all CS must go through the authorization process (see para 3.2). (T-1).
3.4.1.2. Once the network enclave is deployed at the installation, follow the policy stated in para 3.4.2. (T-1).
3.4.1.3. CS are not allowed to connect to the SIPRNet. (T-1).
3.4.2. Network Enclave. Through the SAF/CN-appointed authorization boundary, the Civil Engineers have designed type-authorized, AO-sanctioned CS network enclaves.
These enclaves logically-segregate CS on the Air Force Network to provide secure access to enterprise services and a defendable and monitored network environment for CS to https://www.acq.osd.mil/dpap/dars/dfars/html/current/252204.htm https://www.acq.osd.mil/dpap/dars/dfars/html/current/252204.htm https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171r1.pdf https://www.acq.osd.mil/dodsc/library/dodi-4170-11-installation.pdf operate. In a prioritized manner, in coordination with the Comm Squadron, AFCEC/COO shall visit bases to deploy installation-level, CS network enclaves. (T-1).
3.4.2.1. If a CS network enclave has been deployed to an installation:
3.4.2.1.1. AO-approved CS (see para 3.2) must (1) be migrated into the CS network enclave by AFCEC/COO in coordination with the installation’s Civil Engineer Squadron, Comm Squadron, and system vendor and must (2) be eliminated from all other connectivity. (T-1).
3.4.2.1.2. CS without AO approval must go through the authorization process (see para 3.2) to be migrated into the CS network enclave. (T-1).
3.4.2.1.3. The Civil Engineer unit, specifically the ISO, ISSM, and ISSO (para 2.7 – 2.9), shall continue to monitor their systems’ security controls. (T-1).
3.4.2.2. If a CS network enclave has not been deployed to an installation, adhere to the policy outlined in para 3.4.1. (T-1).
3.4.3. Exceptions. If there is a need to have a different form of connectivity other than the CS network enclave (para 3.4.2) due to the function of the system or mission criticality concerns, the owner must submit a justification to AFCEC/COO for AO approval. (T-1).
An exception may also be directed at the AO’s discretion. Additionally, follow the criteria listed below:
3.4.3.1. Stand-alone systems. A system could remain stand-alone due to (1) mission criticality concerns, (2) existing vulnerabilities that cannot be mitigated, or (3) if the CS is a Life Safety system (para 1.2.3) or an Airfield Lighting Control System (para 1.2.5.1).
3.4.3.1.1. Stand-alone systems must provide security, system administration, and authorization at the same level of service as the Air Force Network. (T-1).
3.4.3.1.2. A monitoring strategy of the system’s security controls must be in place as part of the authorization requirement. Automated monitoring is preferred, but a method of regular monitoring is required. (T-1).
3.4.3.1.3. The ISO must handle the monitoring of the stand-alone system’s security controls with support of the ISSM. (T-1).
3.4.3.2. Stand-alone networks. Where stand-alone network architecture (e.g., air-gapped) is approved to be used for CS, the Air Force requirements for network security, continuous monitoring, and security protections found in the Air Force Network must still be provided by the installation’s stand-alone network design and the network operator. (T-1).
3.4.3.3. Modems. Modem connections require Air Force Enterprise AO approval and an Approval to Connect per AFI 17-101. (T-1).
3.4.3.4. Radio Frequency (e.g., Wi-Fi, cellular, Bluetooth, satellite). Using unlicensed frequencies under Federal Communications Commission Title 47 Part 15 is not allowed. (T-0). Do not procure new CS using a Part 15 radio frequency device.
(T-0). OCONUS installations shall also comply with applicable Host Nation rules, laws, policies, and agreements. (T-0). Verify radio frequency spectrum certification compliance with installation’s Spectrum Manager for any radio frequency devices currently in use. (T-2). Per DoDI 8420.01, Commercial Wireless Local-Area Network (WLAN) Devices, Systems, and Technologies, DoD requires non-licensed devices http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afi17-101/afi17-101.pdf https://www.ecfr.gov/cgi-bin/text-idx?SID=1b3056c426adb49468b037e29ac87950&mc=true&node=pt47.1.15&rgn=div5 http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/842001_dodi_2017.pdf?ver=2017-11-03-092912-313 http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/842001_dodi_2017.pdf?ver=2017-11-03-092912-313 operating in the United States and its possessions to be registered with the local spectrum management office. (T-0). When purchasing new devices, also follow para
3.3. (T-1).
3.4.3.4.1. If (1) an existing CS needs to continue using radio frequency devices to transmit and/or receive data or (2) a CS not owned by the installation requires radio frequency (e.g., cellular tower leasing), ensure the system complies with AFI 17-220, Spectrum Management, uses dedicated frequencies per National Telecommunications Information Administration Chapter 7 and Chapter 4, and is approved by the installation’s Spectrum Manager before seeking a waiver approval. (T-1). Check radio frequency devices to ensure data transmission is encrypted “end-to-end” over an assured channel; the device is aligned to the sensitivity of the data; and the device is validated under the “Cryptographic Module Validation Program” specified in FIPS PUB 140-2, Security Requirements for Cryptographic Modules, Overall Level 1 or Level 2, as dictated by the data’s sensitivity. (T-1).
3.4.3.4.2. Any data transmitted by Wi-Fi devices, services, and technologies shall follow IEEE Standard 802.11-2016 per DoD Directive (DoDD) 8100.02, DoDI 8420.01, NIST SP 800-97, and DHS’s Guide to Securing Networks for Wi-Fi (https://www.us-cert.gov/sites/default/files/publications/A_Guide_to_Securing _Networks_for_Wi-Fi.pdf). (T-0).
3.4.3.4.3. CS authorization will not be approved for systems using Bluetooth.
(T-1).
3.4.3.4.4. For all other use of radio frequency, approval is required before the purchase, testing, deployment, and usage of the system. (T-1).
3.4.3.5. Commercial Internet & Services. All commercial Internet connections are prohibited unless approved by the AO and the DoD Chief Information Officer has granted a DoD Information Network (DoDIN) waiver. (T-0). Unauthorized connections will result in a Denial of Authorization to Operate (DATO).
3.4.3.5.1. DoDIN Waiver Process. Under DoDI 8500.01 and DoDI 8510.01, the DoD Chief Information Officer grants DoDIN waivers for procurement and use of non-Defense Information Systems Network (DISN) commercial services when in the best interest of the DoD and when Defense Information Systems Agency (DISA) services cannot support mission requirements. Visit the DISA site for the DoDIN Waiver Process (http://disa.mil/network-services/enterprise-connections/connection-approval).
3.4.4. Unnecessary Protocols. Any form of connectivity or communication protocol that is not used, not necessary for the function of the system, and not explicitly approved shall be disabled across all components of the CS down to the end device. (T-0).
3.4.5. Encryption. Use minimum approved encryption standard as determined by AFCEC/COO. (T-1). The use of higher and more complex encryption standards are encouraged, but must be coordinated with AFCEC/COO. (T-1).
3.5. Continuous Monitoring & Incident Response. Further roles and responsibilities are still being determined for coordination with cyber defenders for incident response of control systems, as well as for a Cybersecurity Service Provider (CSSP) and an operations watch floor for automated continuous monitoring of control systems.
http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afi17-220/afi17-220.pdf http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afi17-220/afi17-220.pdf https://www.ntia.doc.gov/page/2011/manual-regulations-and-procedures-federal-radio-frequency-management-redbook https://www.ntia.doc.gov/page/2011/manual-regulations-and-procedures-federal-radio-frequency-management-redbook http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf https://standards.ieee.org/findstds/standard/802.11-2016.html http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodd/810002p.pdf http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/842001_dodi_2017.pdf?ver=2017-11-03-092912-313 http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/842001_dodi_2017.pdf?ver=2017-11-03-092912-313 http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-97.pdf https://www.us-cert.gov/sites/default/files/publications/A_Guide_to_Securing_Networks_for_Wi-Fi.pdf https://www.us-cert.gov/sites/default/files/publications/A_Guide_to_Securing http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/850001_2014.pdf http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/851001_2014.pdf http://disa.mil/network-services/enterprise-connections/connection-approval
3.6. Hardware.
3.6.1. Hubs. The use of hubs is not permitted. (T-1). Where used in legacy systems, plan and program for their replacement to switches (para 3.6.2) utilizing the DISA Approved Products List (https://aplits.disa.mil/apl/) and AFCEC/COO for further guidance. (T-1).
3.6.2. Switches. The use of switches within the CS environment shall be kept to a minimum and are required to be “managed” switches. (T-1). If used, switches shall be configured to restrict port access to the CS. (T-0). Where used in legacy systems, plan and program for their replacement utilizing the DISA Approved Products List and AFCEC/COO for further guidance. (T-1).
3.6.2.1. Switches shall have physical security measures (refer to para 4.3). (T-1).
Ensure switches are stored in a locked, secure area/cabinet, and add necessary tamper-proof features to restrict access to these devices. (T-2).
3.6.3. Servers. Rack mounted servers are preferred over towers or stand-alone cases. Use of the Network-Centric Solutions-2 (NETCENTS-2) contract vehicle is required for servers and client workstations. (T-1).
3.6.4. For any device that has a Security Technical Implementation Guide applicable to them, follow the guide to apply the proper security controls and configurations. (T-1).
3.7. Software.
3.7.1. Use whitelisting software as a preferred mitigation approach per National Security Agency’s (NSA) Guidelines for Application Whitelisting Industrial Control Systems. (T-1).
3.7.2. Upgrading and patching software is required for operating systems and CS applications. (T-1). Adhere to para 3.8 and the following:
3.7.2.1. Upgrade and maintain CS operating systems to the most current operating system available along with patch level as approved by DISA and the Air Force. (T-1).
3.7.2.2. Review the Standard Desktop Configuration SharePoint site (https://org2.eis.af.mil/sites/20760/3/1/1/SDC/default.aspx) for the most current operating system versions and builds. (T-1).
3.7.3. When the CS operating system cannot be upgraded, a Plan of Actions and Milestones must be documented and approved through the RMF process (refer to para 3.2) to appropriately manage the resulting security risk or to provide remediation that eliminates the risk. (T-1).
3.7.3.1. Once approved through the RMF process, submit waiver requests to SAF/CN at usaf.pentagon.saf-cn.mbx.saf-cn-workflow@mail.mil. (T-1). Approved SAF/CN waivers are posted on the SAF/CN “Cybersecurity Server 2003 Compliance” site (https:
//cs2.eis.af.mil/sites/13057/a6s/afcks/compliance/server2003compliance/default.aspx).
3.7.4. Ports / Services. Because the specific function of dedicated CS devices shall be determined and documented, all ports and input/output devices that are unnecessary must be identified. (T-0).
3.7.4.1. Disable all unused ports and services on CS devices after testing to ensure the CS’s operation is not affected. (T-0).
3.7.4.2. Ensure that unused ports and services remain disabled. (T-0).
3.7.4.3. Follow the standards listed on DISA’s Guide for Ports, Protocols, and Service Management (https://www.disa.mil/network-services/Enterprise-Connections https://aplits.disa.mil/apl/ https://aplits.disa.mil/apl/ https://aplits.disa.mil/apl/ https://apps.nsa.gov/iaarchive/customcf/openAttachment.cfm?FilePath=/iad/library/ia-guidance/security-configuration/industrial-control-systems/assets/public/upload/Guidelines-for-Application-Whitelisting-Industrial-Control-Systems.pdf&WpKes=aF6woL7fQp3dJieWeqzhUsw9Fekr3xteZCGmLh https://apps.nsa.gov/iaarchive/customcf/openAttachment.cfm?FilePath=/iad/library/ia-guidance/security-configuration/industrial-control-systems/assets/public/upload/Guidelines-for-Application-Whitelisting-Industrial-Control-Systems.pdf&WpKes=aF6woL7fQp3dJieWeqzhUsw9Fekr3xteZCGmLh https://org2.eis.af.mil/sites/20760/3/1/1/SDC/default.aspx https://cs2.eis.af.mil/sites/13057/a6s/afcks/compliance/server2003compliance/default.aspx https://www.disa.mil/network-services/Enterprise-Connections/PPSM https://www.disa.mil/network-services/Enterprise-Connections/PPSM https://www.disa.mil/network-services/Enterprise-Connections
/PPSM). (T-1).
3.7.5. Uninstall software, programs, applications, and services that are unused and not strictly necessary for operation or maintenance of the CS (e.g., games, chat/messaging services, office productivity suites, etc.). Eliminate these applications from back-up or recovery software. (T-0).
3.8. Patch Management.
3.8.1. ISSM and ISSO work with the CS vendor to (1) determine a patch schedule for the CS and (2) ensure patches are validated and tested to verify safe operation of the CS after patching. (T-0). Installations are not expected to procure separate testbed environments.
3.8.2. Systems shall be patched or updated only with digitally-signed or hashed software from trusted authoritative sources. (T-0).
3.8.3. See para 3.9 for procedures for on-site maintenance. (T-0).
3.8.4. For further guidance on patch management, refer to NSA’s Guidelines for Configuration / Patch Management in Industrial Control Systems (https://www.iad.gov/iad/library/ia-guidance/tech-briefs/guidelines-for-configuration-and-patch-management-in-industrial-control-systems.cfm). (T-2).
3.8.5. Review the current CYBERCOM Information Assurance Vulnerability Management (https://www.cybercom.mil/J3/IAVM/SitePages/Home.aspx) notices against the CS’s current operating system to ensure appropriate patches against vulnerabilities are met.
(T-2).
3.9. On-site Maintenance.
3.9.1. Ensure personnel and/or vendors conducting on-site maintenance of CS (to include patching or upgrading software) are verified and qualified. (T-0).
3.9.2. Escort and oversee on-site maintenance activities to ensure there is no operational impact or interruption to the CS. (T-0).
3.9.3. Ensure CS maintenance and repair is performed and logged in a timely manner.
Vendors performing on-site maintenance shall sign in/out with the ISO using AF Form 1109, Visitor Register Log. (T-0). Vendor shall leave a copy of their maintenance service record with the ISO detailing the work done on the CS and any repairs. (T-0).
3.9.4. Provide and enforce the use of only government-owned assets (e.g., computer, tablet) to connect to CS and CS network enclaves for maintenance or other authorized uses. (T-0).
3.9.5. Government-owned maintenance assets must be maintained by the Civil Engineers and remain in government control. (T-1). These maintenance assets must adhere to the following restrictions:
3.9.5.1. Maintain the cybersecurity practices and procedures required for NIPRNet machines. (T-1).
3.9.5.2. Uninstall any programs, applications, and services not strictly necessary (as further stated in para 3.7.5). (T-0).
3.9.5.3. Disable any Wi-Fi, cameras, or microphones, preferably at the hardware or physical level. (This is not applicable to (1) cameras or microphones installed for physical security purposes or (2) intrusion detection systems that rely on this audio and visual information). (T-1).
https://www.iad.gov/iad/library/ia-guidance/tech-briefs/guidelines-for-configuration-and-patch-management-in-industrial-control-systems.cfm https://www.iad.gov/iad/library/ia-guidance/tech-briefs/guidelines-for-configuration-and-patch-management-in-industrial-control-systems.cfm https://www.cybercom.mil/J3/IAVM/SitePages/Home.aspx
3.9.6. On-site maintenance using a government-owned asset shall be accomplished using the following procedures:
3.9.6.1. Download digitally-signed or hashed software from trusted authoritative sources to a CD/DVD. (T-1).
3.9.6.2. Scan the CD/DVD on a computer that has scanning signatures to ensure it is malware-free. (T-1).
3.9.6.3. Insert the CD/DVD into a government-owned asset (see para 3.9.5) to perform maintenance activity. (T-1).
3.9.6.4. After upgrading the system, destroy the CD/DVD media to ensure it cannot be used in another device per AFMAN 17-1301, Computer Security (COMPUSEC).
(T-1).
3.9.7. For existing contracts that do not allow maintenance using government-owned assets and until contract language is updated (see para 3.3), ensure assets used by vendors and service personnel are thoroughly scanned for viruses and malware and have anti-virus software enabled before the asset is allowed to connect to a CS or related infrastructure, as stated in NIST SP 800-46r2 (particularly para 2.0 and 5.4), Guide to Enterprise Telework, Remote Access, and Bring Your Own Device (BYOD) Security. (T-0).
3.9.8. Further on-site maintenance requirements can be found in NIST SP 800-82r2.
3.10. Remote Maintenance. When on-site maintenance and support (see para 3.9) cannot be accommodated, remote maintenance access to CS is allowed as an option of last resort only and if included as part of the Security Control Baseline implemented for the CS (see para 2.5.2.2).
(T-0). If remote maintenance is employed, adhere to the following:
3.10.1. All remote maintenance events shall also be sanctioned by the ISO to be logged, monitored, and reviewed in order to verify legitimacy and necessity of access. (T-0).
Furthermore, the allotted time, initial time of access, and reason for access shall be coordinated between the ISO and the vendor. (T-0).
3.10.2. Remote maintenance of the CS shall be of limited duration – allowed only for the time necessary to accomplish the established maintenance task. (T-0).
3.10.3. Any remote maintenance of the CS outside of the pre-arranged window shall be blocked by disabling the modem or by other technical means. (T-0).
3.10.4. Any remote maintenance activities that involve patching or upgrading software must follow additional guidelines outlined in para 3.7 and 3.8. (T-0).
3.10.5. Follow security measures recommended in NIST SP 800-46r2, NIST SP 800-82r2, and DHS’s Configuring and Managing Remote Access for Industrial Control Systems (https://ics-cert.us-cert.gov/sites/default/files/recommended_practices/RP_Managing_ Remote_Access_S508NC.pdf) such as requiring encryption and token-based, multi-factor authentication. (T-1).
3.10.6. Other remote maintenance of the CS not meeting these specifications is prohibited.
(T-0).
3.11. Solid State Devices and Removable Media. As recommended by NIST SP 800-82r2, removable media is not to be connected to a CS or CS network enclave other than as described in para 3.9.6. (T-1). Provisions shall be made to prohibit the connection of unauthorized items, including vendor-owned devices. (T-0). Modify any existing service contracts to comply. (T-2).
3.11.1. In the instance Solid State Hard Drives, Thumb Drives, Dongles, DVDs, CDs, and http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afman17-1301/afman17-1301.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-46r2.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-46r2.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-82r2.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-46r2.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-82r2.pdf https://ics-cert.us-cert.gov/sites/default/files/recommended_practices/RP_Managing_Remote_Access_S508NC.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-82r2.pdf other removable media and storage devices are connected to a CS or CS network enclave, ensure compliance with requirements outlined in USCYBERCOM CTO 10-084 and Air Force Network Operations Center NETOPS Tasking Order 2008-323-001. (T-1).
3.12. Handheld Personal Devices. The use of Personal Data Assistants, Portable Electronic Devices, or other handheld devices (e.g., smart phones) to access, monitor or control CS is not authorized. (T-1). The discovery of such a connection can result in issuance of a DATO and thus disconnection from the network.
3.13. Technical Support.
3.13.1. Contact the AFCEC Reachback Center at (850) 283-6995 or by e-mail at AFCEC.RBC@us.af.mil.
3.13.2. For specific CS-related technical support and guidance, AFCEC/COO supports the RMF risk assessment of and implements the network enclave for CS at active duty installations.
3.13.2.1. For RMF support, contact (850) 238-1214 or (850) 238-9132, or by e-mail at afcec.comi.ics@us.af.mil.
3.13.2.2. For CS network enclave technical support, contact (850) 238-1214 or (850) 238-9132, or by e-mail at afcec.comi.icshelpdesk@us.af.mil.
3.13.3. HQ NGB/A4 and HQ AFRC/A4 will provide technical support and guidance as required.
https://www.cybercom.mil/J3/order/CTO/CTO_10_084.pdf mailto:AFCEC.RBC@us.af.mil mailto:afcec.comi.ics@us.af.mil mailto:afcec.comi.icshelpdesk@us.af.mil
Chapter 4
CONTROL SYSTEMS CYBER HYGIENE
A modified list of foundational cyber hygiene requirements to follow and frequently review is listed below. Additionally, the technical references listed in Chapter 6 provide comprehensive protection procedures.
4.1. Before clicking on links or system prompts, stop, think, and check if it is expected, valid, and trusted. (T-2). Be cautious of any messages received that contain a hyperlink even if it seems to be from a friend or a trusted organization. (T-2).
4.2. Password / User Accounts.
4.2.1. Ensure all personnel are educated on their responsibility for password/account protection. (T-0).
4.2.2. Eliminate the use of default usernames and passwords. Additionally, all new passwords will follow requirements in DoDI 8520.03, Identity Authentication for Information Systems and AFMAN 17-1301 para 8.5. (T-0).
4.2.3. Do not share passwords. (T-1). In the event of a compromised password, change the password immediately. (T-1).
4.2.4. Review all user accounts and delete those accounts that are unused or no longer necessary. (T-0).
4.2.5. Apply the “principle of least privilege” to limit to authorized users on an as-needed basis with permissions pertinent to the users’ role. (T-0).
4.2.6. Authentication mechanisms and lock out controls shall not be diminished. (T-1).
4.2.7. Foreign Nationals may be provisioned with accounts per AFI 17-130, Air Force Cybersecurity Program Management, para 4.5.
4.3. Physical Access Control.
4.3.1. Store computers and interfaces that support the CS in a secure space, where physical access can be restricted to only those who require it. (T-0).
4.3.2. Abide by strict access control protocols to prevent unauthorized physical access to all components of the CS (particularly focusing on control nodes) and the unauthorized introduction of new hardware, infrastructure, and communications interfaces where feasible. (T-0).
4.3.3. Document who has control over the CS equipment locations (e.g., electrical, mechanical, communications rooms). (T-0).
4.3.4. Document and confirm the physical security of CS and components in the inventory (refer to para 3.1). (T-0).
4.4. Data Storage and Disposal.
4.4.1. Apply security techniques such as encryption and/or cryptographic hashes to CS data storage and communications where determined appropriate by ISO and local policy.
(T-1).
4.4.2. Frequent backups of CS data shall be conducted, maintained, and properly stored.
Store copies of data, configuration backups, and recovery disk(s) in a secure location for http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/852003p.pdf http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/852003p.pdf http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afman17-1301/afman17-1301.pdf http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afi17-130/afi17-130.pdf http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afi17-130/afi17-130.pdf business continuity and disaster recovery. (T-0).
4.4.3. When a CS is no longer required, the ISO shall take appropriate action to ensure the system and its data is properly disposed per established procedures detailed in NIST SP 800-53r5 (draft) para 3.11 MP-6, NIST SP 800-82r2 para 6.2.10, and AFMAN 17-1301 chapter 6. (T-1).
4.5. Response, Recovery, and Contingency Plans.
4.5.1. Ensure response plans (Incident Response/Business Continuity), recovery plans (Incident Recovery/Disaster Recovery), and contingency plans are in place and managed per NIST SP 800-82r2 para 6.2.6 and 6.2.8. (T-0). Develop Response, Recovery, and Contingency plans if they do not currently exist. (T-0).
4.5.2. Plans shall contain specific tactics, techniques, and procedures for when adversarial activity is detected. (T-0). Such a plan may include disconnecting all Internet connections, running a properly scoped search for malware, disabling affected user accounts, isolating suspect systems, and an immediate 100 percent password reset (refer to para 4.2). The plan may also define escalation triggers and actions, including incident response, investigation, and public affairs activities.
See DoD’s Advanced Cyber Industrial Control System Tactics, Techniques, and Procedures (ACI TTP) for Department of Defense (DoD) Industrial Control Systems (ICS) (https://www.acq.osd.mil/eie/Downloads/IE/ACI%20TTP%20for%20DoD%20ICS_Rev_2 _(Final).pdf) for examples of applicable procedures to be considered to use for tailoring to installation-specific conditions. (T-2).
4.5.3. Ensure plans are tested and reviewed annually at a minimum, and updated as necessary. (T-1).
4.5.4. If the appropriate plans do not exist, personnel shall be aware of their responsibilities in case of an incident. (T-0).
4.5.5. Have a system recovery and contingency plans in place, including having recovery disk(s) and source configuration backups ready to restore systems to known good states.
(T-0). Additionally, ensure the ability to revert to manual operations in the instance connection is lost or if a system is “blacklisted.” (T-1).
4.6. Register at US-CERT (https://www.us-cert.gov/) to receive security alerts, tips, and other updates. (T-3).
4.7. Activate the “Alerts” and “Advisories” settings for ICS-CERT (https://ics-cert.us-cert.gov/) secure messages on CS. (T-3).
http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-82r2.pdf http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afman17-1301/afman17-1301.pdf http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afman17-1301/afman17-1301.pdf http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-82r2.pdf https://www.acq.osd.mil/eie/Downloads/IE/ACI%20TTP%20for%20DoD%20ICS_Rev_2_(Final).pdf https://www.acq.osd.mil/eie/Downloads/IE/ACI%20TTP%20for%20DoD%20ICS_Rev_2_(Final).pdf https://www.us-cert.gov/ https://www.us-cert.gov/ https://ics-cert.us-cert.gov/…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .