Appendix D IA Cert.pdf
PDF 648 KB Posted
- Attached to
- Draft Solicitation for Sustainment Modernization Services Federal contract opportunity
- Solicitation number
- W911QX23R0004
About this file
This draft solicitation seeks sustainment modernization services for the U.S. Army Combat Capabilities Development Command Data Analysis Center. The purpose of the draft is to gather industry feedback on the requirements prior to releasing a final solicitation. Questions, feedback, and comments on the draft must be submitted by email to the specified contracting officer's representative by February 21, 2023. No award will result from this draft solicitation, which was issued to obtain input before finalizing requirements for sustainment modernization services to support the Data Analysis Center's mission.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Wage Determinatins (Harford County).pdf | ||
| Wage Determinations (Coryell County).pdf | ||
| DD1423 A0001.pdf | ||
| Appendix A Overall Equipment List.docx | DOCX document | |
| SBPCD Worksheet.xlsx | XLSX spreadsheet | |
| DD1423 A0005.pdf | ||
| Appendix F Call Forward.docx | DOCX document | |
| Appendix C Inventory of CAP and GFP.xlsx | XLSX spreadsheet | |
| Appendix G RCM Feedback Format.docx | DOCX document | |
| Wage Determinations (Pierce County).pdf | ||
| DD1423 A0004.pdf | ||
| DD1423 A0006.pdf | ||
| Appendix B MAR.docm.docx | DOCX document | |
| Appendix E Performance Requirements Summary.docx | DOCX document | |
| Cost Model.xlsx | XLSX spreadsheet | |
| Draft Solicitation W911QX23R0004 (2).pdf | ||
| Wage Determinations (El Paso).pdf | ||
| DD1423 A0003.pdf | ||
| DD1423 A0002.pdf | ||
| Basic PWS.docx | DOCX document | |
| Anticipated LCATS.docx | DOCX document |
Show all 21
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
UNCLASSIFIED
UNCLASSIFIED
Information Assurance
Best Business Practice (IA BBP)
U.S. Army CIO/G-6
Cyber Directorate
INFORMATION ASSURANCE (IA)
TRAINING AND CERTIFICATION
Version 5.0 (update)
March 2012
05-PR-M-0002 Issuance date: 28 FEB 2006
Update: 30 MAR 2012
Next Update: 10 APR 2013
INFORMATION ASSURANCE (IA) TRAINING AND CERTIFICATION
VERSION 5.0
1. Overview:
The IA workforce focuses on the operation and management of IA capabilities for Department of Defense (DoD) systems and networks. IA ensures that adequate security measures and established IA policies and procedures are applied to all Information Systems (IS) and networks. The IA workforce includes all privileged users, specialty positions, and IA managers who perform any of the functions described in DoD 8570.01-M, Change 2 Chapters 3 - 5 and 10-11 across all occupational specialties, or whether the duty is performed full-time or part-time as an additional/embedded duty (DoD 8570.01-M par C1.4.4.4). The IA training audience includes military, civilian, contractors and foreign nationals in Deployed and Generating Forces’ organizations. Foreign nationals fall in two categories (contractor or civilian). A checklist to aid in determining if your duties are part of the IA workforce is included in this BBP (table 2). All new Department of Civilian hires appointed to IA positions must meet qualification requirements within 6 months. Contractor certification and training requirements shall be addressed in all contracts that include acquisition of IA services.
Existing contracts must be modified to specify baseline certification requirements. The DoD 8570.01- M, Change 3 paragraph C2.1.7 states: The IA workforce training and certification program establishes a baseline of validated (tested) knowledge that is relevant, recognized, and accepted across the Department of Defense. All IA workforce personnel requiring a certification voucher and appointed in Cyber Security (IA) positions shall be registered on the Army Training and Certification Tracking System at https://atc.us.army.mil. Personnel in Information Assurance Technical (IAT levels, Computer Network Defense-Service Provider (CND-SP) positions except for CND-SP Manager (CND-SPM) category are also required to obtain computing environment certifications or a certificate of training if working technical functions. The A+ certification can be used as a baseline and computing environment certification if the organization’s manager accepts it as the required certification for their network/computing environment.
IA Workforce personnel in technical, specialty, and management positions must complete the required Continuing Professional Education credits annually and pay their annual dues as required by the certifying body to maintain certification status. Personnel who have been in the position over 1 year and have not attained qualification status shall be evaluated for reassignment in a non-IA position and noted in their performance evaluation.
Training and Certification requirements for the IA workforce, technical, specialty, and management levels described in DoD 8570.01-M, change 3 are listed in this BBP. IA Workforce personnel who have completed the Information Assurance Fundamentals on the Signal Center website can earn 40 hours of Continuing Professional Education Credits for their CISSP and CompTIA certifications . The individual receives one CPE credit for each hour completed.
The Army e-Learning program, comprised of commercial off-the-shelf computer-based and Web-based Distant Learning courseware, is the preferred method for all Army organizations to accomplish workforce training in information technology (IT), information assurance, foreign languages, and selected mandatory training requirements.
Note**Certification/certified denotes baseline and computing environment certifications throughout this document. Qualified denotes that the individual has the required documents (duty appointment letter, Privilege Access Agreement, met certification requirements and completed the On the Job training for their category and level.
https://atc.us.army.mil/
05-PR-M-0002 Issuance date: 28 FEB 2006
2. Changes to IA Policy:
a. The changes to the duties and responsibilities for the Information Assurance Support Officer were effective on 1 July 2011. Certification vouchers are no longer provided for personnel listed on appointment letters as IASO (Information Assurance Security Officer or Information Assurance Support Officer.
b. Soldiers in Military Occupational Specialty (MOS) 25B and 25U skill level one (SL1) shall operate and perform IA functions under the direct supervision of a certified IA professional. Soldiers in MOS 25B and 25U receive the required basic training through an eight week curriculum through their Advance Initial Training.
c. The Computing Environment certification can now be obtained through commercial certification testing or through training that map to the job functions required by the organization managers. .
3. References:
a. DoD Directive 8570.01 (DoDD 8570.01) Information Assurance Training, Certification, and Workforce Management, 15 August 2004.
b. DoD 8570.01-M– Information Assurance Workforce Improvement Program, dated 19 December 2005, Change 3, 24 January 2012.
c. Memorandum: Manpower and Reserve Affairs, Payment of Expenses to Obtain Professional Credentials for Army Civilian Employees, 20 June 2003.
d. AR 25-2 – Information Assurance, 24 October 2007, Rapid Action Revision 23 March 2009.
e. AR 25-1 – Army Knowledge Management and Information Technology, 4 December 2008
f. Memorandum: Information Assurance (IA) Training and Certification Tracking System, 8 August
g. DoD Acquisition Regulations System (DFARS) 48 CFR Parts 239 and 252 RIN 0750-AF52, Supplement; Information Assurance Contractor Training and Certification (DFARS Case 2006-D023
3. Point(s) of Contact (POC):
Cyber Directorate – Training and Certification
Phyllis Bailey Phyllis.e.Bailey2.civ@mail.mil, 703-545-1698 Group email address ciog-6.netcomiawip.inbox@mail.mil mailto:phyllis.e.bailey2.civ@mail.mil
05-PR-M-0002 Issuance date: 28 FEB 2006
4. Administrative Requirements:
a. IA training and certification requirements must be completed within 6 months of assignment to IA duties. Sustainment training is required as needed to keep the IA professional proficient in their job duties All individuals performing technical functions must sign a Privileged Access Agreement (PAA) and Non- Disclosure Agreement (NDA). The PAA/NDA and duty appointment letter templates are located on the Army Training and Certification Tracking System under the document link. The duty appointment letter template is located at appendix E as well.
b. The Army e-Learning modules (Army e-Learning Program) for IA training are available via the AKO portal at Uhttps://www.us.army.mil U. Contractors who require access to Army e-Learning for IA training will send their request through their Government Point of Contact (POC). They must also register on the Army Training Certification Tracking System (ATCTS), HUhttps://atc.us.army.mil UH and have their duty appointment letter and PAA/NDU (if applicable) uploaded into their profile. The Army e-Learning Program Contractor Info sheet is found at HUhttps://atc.us.army.mil UH under the document link and the Signal Center of Excellence, Ft Gordon website at HUhttps://ia.signal.army.mil UH under Courses. Completion of the Army e-Learning Program Test-preps alone will not be accepted as course completion - all modules must be taken. To generate end of module certificates, you must “Enroll” in each Learning Program course. There are various Learning Programs in the Baseline Certification folder in Army e-Learning. Enrollment procedures are found at HUhttps://atc.us.army.mil UH under the document link.
c. The IA workforce shall ensure that their profile data and IA training and certification information in the Army Training and Certification Tracking System (ATCTS) is current. New IA workforce personnel will register at https://atc.us.army.mil at the time of appointment. IA workforce personnel must release their certifications to the Defense Workforce Certification Web Application website (DWCA) at Hhttps://www.dmdc.osd.mil/appj/dwc/index.jsp H. and document their certifications in the ATCTS.
d. Each Army organization shall program for funding the Annual Maintenance Fees during the Program
Objective Memorandum (POM) cycle. Only the maintenance fee will be paid for the highest certification. The ISC (2) concentrations (if required for the appointed position) will be paid as well if funding is available.
e. IA workforce personnel (military and civilians) are encouraged to pursue educational opportunities through the IA Scholarship Program (IASP) to obtain advanced degrees with IA concentrations. Additional information about the IASP can be found on the ATCTS website under Web Links.
5. Description of tables:
a. Table 1, How to Register in ATCTS
b. Table 2: IA Workforce determination checklist
c. Table 3: IA Workforce DOD Approved Certification List.
d. Table 4: Qualified requirement table
e. Table 5: IA Training and Certification Requirements matrix.
https://ia.signal.army.mil/ https://www.dmdc.osd.mil/appj/dwc/index.jsp
05-PR-M-0002 Issuance date: 28 FEB 2006
Table 1: ATCTS Registration
1. How to register in ATCTS:
a. Go to https://atc.us.army.mil.
b. Go to Registration Information and click on HURegister on this Web Site (Click Here) UH.
c. Fill in all the fields then click “Register.” Make sure you use a valid AKO email address and add your enterprise email as your alternate if you have one.
d. The system will send an access code to your AKO email address.
e. Once you receive your access code, log back into the system and answer the job function questionnaire. (The site is CAC only)
f. Your Technical I-III or Management I-III or Specialty profile will be created along with a training plan.
Do not skip this step; it allows you to see your minimum training requirements and baseline certification(s) required for your position function.
https://www.iastar.net/army/register.php
05-PR-M-0002 Issuance date: 28 FEB 2006
Table 2: IA Workforce Determination Checklist
Name
Email Address
Company Phone
Questions – Please respond to the questions below
QUESTION - Must answer YES to one or more questions to be part of the workforce. YES/NO
1. Do you have an Privilege Access Agreement/NDU on file and in ATCTS
2. Do you log on with a systems administrator account on a Government system? (Alternate Smart Card)
3. Do you create user accounts or modify user permissions or roles for other users on a
Government application, workstation, server, or network?
4. Do you have the permissions and capability to install software on a Government server, workstation, or network device?
5. Do you manage or otherwise have permissions to modify network devices for Government networks?
6. Do you have the permissions and capability to install hardware on Government computer systems?
7. Do you have the permissions and capability to install peripherals on Government computer systems?
8. Do you have permissions to access and/or modify a database for a Government owned application on a Government computer system?
9. Do you have the capability to delete or otherwise modify user accounts on Government systems?
10. Are you responsible for maintenance, repair, or related upkeep of Government-owned computer or IT-related hardware at your site or installation?
11. Can you perform system upgrades or modifications on Government computer systems?
12. Can you perform network scans (e.g., STAT, RETINA) on Government computer systems?
13. Can you perform surveillance or monitoring on Government computer systems?
14. Do you move, install, or uninstall applications on Government computer systems?
15. Do you create, initiate, or otherwise enact system, database, or application backup or restoration activities on Government owned application, workstation, server, or network?
16. Are you an integral part of the design process or the development of IA Systems?
17. Are you a Computer Network Defense Service Provider?
18. Are you a member of the Red Team, Blue Team, or C& A Team?
18. Do you approve, create and implement programs to ensure that systems, network, and data users are aware of, understand, and follow IA policies and procedures for your command
19. Do create, approve and provide amplifying IA guidance that must be adhered to by your command and your subordinate commands
20. Are you the Information Assurance Manager/Information Assurance Program Manager/ Chief Information Officer/DAA/ for your command
21. Do you ensure that IA requirements are integrated into the Continuity of Operations Plan
22. Do you assist in/prepare IA certification and accreditation documentation
23. Do you allocate resources to achieve and maintain an acceptable level of security and to remedy security deficiencies?
05-PR-M-0002 Issuance date: 28 FEB 2006
Table 3: UDoD Approved Baseline Certifications
* The Associate of (ISC)² is for those who do not meet the professional experience requirements for the CISSP. The Associate status is good for a maximum of six years from the date you are notified by (ISC)² that you have passed the examination. Within that timeframe, you will need to earn the required experience and submit the required endorsement form for certification as a CISSP.
***Computing Environment (CE) certification (vendor exam or certificate of training) required for IAT levels, CND levels and IASAE levels personnel who are working technical function.
05-PR-M-0002 Issuance date: 28 FEB 2006
Table 4: Qualified requirement Table (must complete all within 6 months of appointment to be fully qualified)
Category Qualification 1 Qualification 2 Qualification 3 Qualification 4 Qualification 5 Qualification 6
IAT Baseline Certification Computing Environment Certification Or certificate
On-the-Job Training Duty appointment Letter
Privilege Access Agreement
Complete training requirements in paragraph 10
IAM Baseline Certification Duty appointment letter
Complete training requirements in paragraph 8
IASAE Baseline Certification Duty appointment letter
Complete training paragraph 12
CND-SP Baseline Certification Computing Environment Certification Or certificate
On-the-Job Training Duty appointment Letter
Privilege Access Agreement
Complete training paragraph 11
8. Management Levels: All must obtain a baseline certification
a. Management Level I (IAM-I): Complete qualification requirements within 6 months (see table 4) of
IA appointment. Complete all Army e-Learning Program minimum training requirements prior to enrollment in an Army IT/IA schoolhouse, Army Mobile Training Team (MTT) IA course and/or vendor specific IA training hosted by the Army. Contractors cannot fill IAMI positions at the Major Subordinate Command (MSC) and Installation levels, (25-2, paragraph 3-3f). See AR 25-2 for Information Technology level requirement.
Minimum Training Requirements:
(1). Information Assurance Fundamentals (IAF) Course Online (https://ia.signal.army.mil/courses.asp) IAW AR 25-2, 4-3(a)(5)(a).
(2). Army e-Learning Program – (HCIO/G-6 Security+ (SY0-301) (10 modules) –
(3). Army e-Learning Program – CIO/G-6 /Cyber Security IA/IT >Baseline Certification
Training>Certification and Accreditation – one module: ID# 206761_eng (Only if pursuing a CAP certification)
Certification Requirements:
The IAM-I personnel shall attain one of the Management Level I baseline certifications listed in Table 3. The type of baseline certification will be determined by the IA professional’s supervisor during the performance evaluation process.
file:///C:/Users/wrightdm.DAHQ/AppData/Local/Microsoft/Windows/Temporary%20Internet%20Files/Content.Outlook/W6CEMJQ2/(https:/ia.signal.army.mil/courses.asp)
05-PR-M-0002 Issuance date: 28 FEB 2006
b. Management Level II (IAM-II). Management Level II (IAM-II): Major Subordinate Commands
(MSC)/Network Enterprise Center (NEC) Program Managed (PM) organizations/Information Assurance Manager (IAM)/ Agent of the Certification Authority (ACA) and other associated IA titles working IAMII functions. IAM II personnel shall not be designated at the Battalion or Company levels. Must complete qualification requirements within 6 months of IA appointment (see table 4). Complete all Army e-Learning Program minimum training requirements prior to enrollment in an Army IT/IA schoolhouse, Army Mobile Training Team IA course and/or vendor specific IA training hosted by the Army. The following courses are equivalent to the minimum training requirements for IA Managers in IAM-II and IAM-III positions: CNSS 4011 certificate course or the National Defense University, Information Resources Management College (IRMC) Advanced Management Program completion. See AR 25-2 for Information Technology level requirement.
IAW AR 25-2, para 4-3a(1)(b)
(2). Army e-Learning Program - CIO/G-6 /Cyber Security IA/IT Training>Certified Information Systems Security Professional (CISSP) modules– 10 modules – IAW AR 25-2, para 4-3a(1)(b).
(3). Army e-Learning Program- CIO/G-6 /Cyber Security IA/IT Training>Certified Information Security
Manager (CISM) modules- 9 modules (if pursuing CISM certification).
(4). Army e-Learning Program – CIO/G-6 /Cyber Security IA/IT Training >Baseline Certification
Training>Certification and Accreditation – one module: ID# 206761_eng (if pursuing a CAP certification) H
The IAM-II personnel shall attain one of the Management Level II baseline certifications listed in Table 3. The completion of certification testing is required.
c. Management Level III (IAM-III): Operational Signal Theater Command/Functional Chief Information Office, Program Executive Office and AC/ASCC/DRU Information Assurance Program Manager (IAPM), Certification Authority (CA) and other associated IA titles performing IAM III functions: Complete the qualification requirements within 6 months of IA Appointment (see table 4). Complete all Army e-Learning Program minimum training requirements prior to enrollment in an Army IT/IA schoolhouse, Army Mobile Training Team IA course and/or vendor specific IA training hosted by the Army. AR 25-2 for Information Technology level requirement.
(2). Army e-Learning Program - CIO/G-6 /Cyber Security IA/IT Training>Certified Information Systems Security Professional (CISSP) modules – 10 modules. IAW AR 25-2, para 4-3a(1)(b).
Manager (CISM) modules- 9 modules (if pursuing CISM voucher and certification).
https://ia.signal.army.mil/courses.asp
05-PR-M-0002 Issuance date: 28 FEB 2006
The IAM-III personnel shall attain one of the Management Level III baseline certifications listed in Table 3.
The completion of certification testing is required.
9. Designated Accrediting Authority (DAA): DAAs performing other management functions such as IAM-II or IAM-III, must also meet the training and certification requirements for those categories and levels.
Complete the minimum training upon DAA appointment by Army CIO/G6. The DAA must be a U.S. citizen and have a level of authority commensurate with accepting, in writing, the risk of operating IS under his/her purview.
(1). Complete the Army specific DAA training module. DAAs shall access this module through the Army’s Virtual Training Website at https://iatraining.us.army.mil. This is only a training module and does not satisfy the DAA’s certification requirement.
(2). DAA Certification: Complete the DoD DAA computer-based training (CBT) located on the Army’s Virtual Training website at HUhttps://iatraining.us.army.mil UH. The completion will be imported into the DAA’s ATCTS profile upon completion of the Army’s 10 question test. The certificate of completion will be maintained as part of the DAA’s official personnel file. The DoD DAA CBT is the DAA’s certification and must be revalidated every 3 years.
10. Technical Levels: All must obtain a baseline and computing environment certification or certificate of training for the operating system(s) and/or security related tools/devices they support as required by their employing organization, DoD 8570.01-M, Change 3 para C3.2.4.8.3.
a. Technical Level I (IAT-I): System Administrator (SA)/ Network Administrator (NA)/Information Assurance Network Manager (IANM)/Information Assurance Network Officer (IANO) and other associated IA titles working IAT-I functions. Complete the qualification requirements within 6 months of IA appointment 9 (see table 4). Complete all Army e-Learning Program minimum training requirements prior to enrollment in an Army IT/IA schoolhouse, Army MTT IA course and/or vendor specific IA training hosted by the Army. AR 25-2 for Information Technology level requirement.
(2). Army E-Learning: Network+ 2009 CIO/G-6 /Cyber Security IA/IT Training>CompTIA Network+
2009 (11 modules and Test-prep).
(3) Required For A+ Certification: Army e-Learning Program- CompTIA A+ modules
(a). 220-701, CIO/G-6 /Cyber Security IA/IT Training>Baseline Certification Training>NEW: A+ Certification-220-701 & 220-702 – 2009 Edition> CIO G-6 NETCOM IA 220-701-A+ Essentials 2009 (7 modules and Test-prep).
(b). 220-702, CIO/G-6 /Cyber Security IA/IT, >Baseline Certification Training>NEW: A+
Certification – 220-701 & 220-702 – 2009 Edition> CIO G-6 NETCOM IA 220-702- A+ Practical Application 2009 (5 modules and Test-prep).
https://iatraining.us.army.mil/ https://iatraining.us.army.mil/
05-PR-M-0002 Issuance date: 28 FEB 2006
(4). Completion of an On-the-Job Training (OJT) skills practical evaluation to meet functional requirements of DoD 8570.01-M. This requirement must be validated by the individual’s supervisor or manager. An example of an OJT checklist can be found on the ATCTS website under Compliance Information.
IAT-I personnel shall attain one of the Technical Level I baseline certifications listed in Table 3. The completion of commercial certification testing or certificate of training is required per the guidance from the organization’s management.. IAT-I personnel shall attain the appropriate computing environment certification or certificate of training as required by their employing organization (DoD 8570.01-M par C3.2.4.8.3). The A+ certification test consists of two tests and requires two certification vouchers. The Network+ certification test is one test.
b. Technical Level II (IAT-II): System Administrator (SA)/ Network Administrator (NA)/Information
Assurance Network Manager (IANM)/Information Assurance Network Officer (IANO) and other associated IA titles working IAT-II functions. Complete the qualification requirements within 6 months of IA appointment (see table 4). Complete all Army e-Learning Program minimum training requirements prior to enrollment in an Army IT/IA schoolhouse, Army MTT IA course and/or vendor specific IA training hosted by the Army. IANM and IANOs manage groups of networks below the Army Command level. SA and NAs manage the Information Systems. See AR 25-2 for Information Technology level requirement.
(2). Army e-Learning Program – CIO/G-6 /Cyber Security IA/IT Training > (CIO/G-6 SECURITY PLUS UH (SY0-301) (10 modules).
(3). Level II Schoolhouse, one week Security+ training course. Schedule and classroom sites located at HUhttps://ia.signal.army.mil UH. – Students must register through the Army Training Requirements and Resources Systems (ATRRS) – https://www.atrrs.army.mil. Request registration through your organization’s training coordinator.
(4). Completion of an On-the-Job Training skills practical evaluation to meet functional requirements of DoD 8570.01-M, Change 3. paragraph C.3.2.3.2. This requirement must be validated by the individual’s supervisor/manager.
The IAT-II personnel shall attain one of the Technical Level II baseline certifications listed in Table 3. The completion of commercial certification testing or certificate of training is required per the guidance from the organization’s management. The type of certification will be determined by the IA professional’s supervisor during the performance evaluation process. Technical Level II personnel will also obtain the appropriate computing environment certification/s required by their employing organization (DoD 8570.01-M, Change 2 par C3.2.4.8.3).
https://ia.signal.army.mil/courses.asp javascript:cf_http_hook_fullpath(%22https://psparmybe.skillport.com:443/_scusarmy_od_cgi/odisapi.dll?cmd=LPSummaryWebPage&objname=lp34&assetType=_ss_lp&isLP=1&sessionid=%22+escape(%22doris.wright-5TC9DULVO%22)+%22%22,0,%20'',%20'') javascript:cf_http_hook_fullpath(%22https://psparmybe.skillport.com:443/_scusarmy_od_cgi/odisapi.dll?cmd=LPSummaryWebPage&objname=lp34&assetType=_ss_lp&isLP=1&sessionid=%22+escape(%22doris.wright-5TC9DULVO%22)+%22%22,0,%20'',%20'') http://ia.gordon.army.mil/
05-PR-M-0002 Issuance date: 28 FEB 2006
c. Technical Level III (IAT-III): System Administrator (SA)/ Network Administrator (NA)/Information Assurance Network Manager (IANM)/Information Assurance Network Officer (IANO) and other associated IA titles working IAT-III functions. Complete the qualification requirements within 6 months of IA appointment (see table 4). Complete all Army e-Learning Program minimum training requirements prior to enrollment in an Army IT/IA schoolhouse, Army MTT IA course and/or vendor specific IA training hosted by the Army. IANM and IANOs manage groups of networks below the Army Command level. SAs and NAs manage the Information Systems. All personnel in IAT-III positions must attain a commercial certification instead of a certificate of training. See AR 25-2 for Information Technology level requirement.
Minimum Training Requirements
(2). Army e-Learning Program – (CIO/G-6 /Cyber Security IA/IT Training)>Baseline Certification Training> Certified Information Systems Security Professional (CISSP) modules – 10 modules.
(3). Completion of an On-the-Job Training skills practical evaluation to meet functional requirements of DoD 8570.01-M, Change 3. paragraph C.3.2.3.2. This requirement must be validated by the individual’s supervisor/manager.
IAT-III personnel shall attain one of the Technical Level III certifications listed in Table 3. The completion of certification testing is required. Technical Level III personnel shall attain the appropriate computing environment certification required by their employing organization (DoD 8570.01-M change 3 par C3.2.4.8.3).
11. Computer Network Defense Service Providers Specialty: CND Service Providers typically work within the Network Operations Centers (NOC), Network Operations Security Centers (NOSC), Computer Security Incident Response Teams (CSIRTs), Computer Incident Response Teams (CIRTs), or Computer Emergency Response Teams (CERTs).
CND-SP specialty personnel shall attain:
The appropriate baseline IA certification (technical or management).
The appropriate CE certification or certificate of training as required by their employing organization.
The appropriate specialty certification.
Certifications are not cumulative. Higher certifications do not satisfy the certification for the specific CND-SP category.
a. CND-SP Analyst (CND-A): Complete the qualification requirements within 6 months of IA appointment (see table 4). The CND-A must be able to work on a specific number of CND systems but analyze events within the NE or enclave. Complete all Army e-Learning Program minimum training requirements prior to enrollment in an Army IT/IA schoolhouse, Army MTT IA course and/or vendor specific IA training hosted by the Army (if applicable). The CND-A typically has mastery of IAT Level I
05-PR-M-0002 Issuance date: 28 FEB 2006 and IAT Level II, CE and/or NE with applicable certification, works under supervision, and typically reports to a Computer Network Defense-Service Provider Manager (CND-SPM).
(2). Army e-Learning Program - HUCIO/G-6 /Cyber Security IA/IT Training>Baseline Certification Training>UH, GIAC Technical Modules. (16 modules).
(3). Army e-Learning Program – CIO/G-6 /Cyber Security IA/IT Training>Baseline Certificaton
Training>CIO/G6 NETCOM Ethical Hacker (11 modules). This can be completed in lieu of the GIAC Technical Modules if pursuing a CEH certification.
(4). Complete an On-the-Job Training skills practical evaluation to meet functional requirements of DoD 8570.01-M, Change 3. paragraph C.3.2.3.2. This requirement must be validated by the individual’s
CND-SPM.
The CND-A personnel shall attain one of the IAT-I or IAT-II and CND baseline certifications listed in Table 3.
The IAT certification is dependent upon the environment the CND-A manages (CE, NE, and Enclave). The completion of commercial certification testing is required. CND-A personnel will also attain the appropriate computing environment certification or certificate of training.
b. CND-SP Infrastructure Support (CND-IS): Complete the qualification requirements within 6 months of IA appointment (see table 4). The CND-IS must have significant knowledge of particular networking technologies, operating systems, and CND tools, tactics, techniques, and procedures which are part of the systems they support. Their actions are usually authorized and controlled by policies and established procedures. They must complete all Army e-Learning Program minimum training requirements prior to enrollment in an Army IT/IA schoolhouse, Army MTT IA course and/or vendor specific IA training hosted by the Army (if applicable). The CND-IS usually has mastery of IAT Level I and IAT Level II, CE and/or NE with applicable certification, works under supervision, and typically reports to a
(2). Army e-Learning Program - HUCIO/G-6 /Cyber Security IA/IT Training>Baseline Certification
Training>UH, GIAC Technical Modules. (16 modules).
(3). Army e-Learning Program – CIO/G-6 /Cyber Security IA/IT Training>Baseline Certificaton
Training>CIO/G6 NETCOM Ethical Hacker (11 modules). This can be completed in lieu of the GIAC Technical Modules if pursuing a CEH certification.
DoD 8570.01-M, Change 3. paragraph C.3.2.3.2. This requirement must be validated by the individual’s https://usarmy.skillport.com/skillportfe/newskills/newskills.cfm?selectedTab=1&pathInfo=%2F%5Fassignments%2Fg162%2Fg1387&rpathinfo=/USARMY_CC/g1387 https://usarmy.skillport.com/skillportfe/newskills/newskills.cfm?selectedTab=1&pathInfo=%2F%5Fassignments%2Fg162%2Fg1387&rpathinfo=/USARMY_CC/g1387 https://ia.signal.army.mil/courses.asp https://usarmy.skillport.com/skillportfe/newskills/newskills.cfm?selectedTab=1&pathInfo=%2F%5Fassignments%2Fg162%2Fg1387&rpathinfo=/USARMY_CC/g1387 https://usarmy.skillport.com/skillportfe/newskills/newskills.cfm?selectedTab=1&pathInfo=%2F%5Fassignments%2Fg162%2Fg1387&rpathinfo=/USARMY_CC/g1387
05-PR-M-0002 Issuance date: 28 FEB 2006
CND-IS personnel shall attain one of the IAT-I or IAT-II and CND baseline certifications listed in Table 3. The IAT certification is dependent upon the environment the CND-IS manages (CE, NE, Enclave). The completion of certification testing is required. CND-IS personnel will also obtain the appropriate computing environment certification or certificate of training.
c. CND-SP Incident Responder/Reporter (CND-IR): Complete the qualification requirements within 6 months of IA appointment (see table 4). The CND-IR must have significant knowledge of particular CND tools, tactics, techniques, and procedures which support the tracking, management, analysis, and resolution of incidents. They must complete all Army e-Learning Program minimum training requirements prior to enrollment in an Army IT/IA schoolhouse, Army Mobile Training Team IA course and/or vendor specific IA training hosted by the Army (if applicable). The CND-IR typically has mastery of IAT Level I, II, or III CE, NE and/or enclave with applicable certification, works under supervision, and typically reports to a CND-SPM.
(2). Army e-Learning Program - CIO/G-6 /Cyber Security IA/IT Training>Baseline Certificaton
Training>GIAC Technical Modules. (16 modules).
(3). Army e-Learning Program – CIO/G-6 /Cyber Security IA/IT Training>Baseline Certificaton
Training>CIO/G6 NETCOM Ethical Hacker (11 modules). This can be completed in lieu of the GIAC Technical Modules if pursuing a CEH certification.
(4). Incident Handling ( HUhttps://iatraining.us.army.mil UH)
(5). Complete an On-the-Job Training skills practical evaluation to meet functional requirements of
DoD 8570.01-M, Change 3. paragraph C.3.2.3.2. This requirement must be validated by the individual’s
CND-IR personnel shall attain one of the IAT-I, II, or III and CND baseline certifications listed in Table 3. The IAT certification is dependent upon the environment the CND-IR manages (CE, NE, Enclave). The completion of certification testing is required. CND-IR personnel will also attain the appropriate computing environment certification or certificate of training.
d. CND-SP Auditor (CND-AU): Complete the qualification requirements within six (6) months of
IA appointment (see table 4). CND-AU personnel perform assessments of systems and networks within the NE or enclave and identify where those systems/networks deviate from acceptable configurations, enclave policy, or local policy. They must complete all Army e-Learning Program minimum training requirements prior to enrollment in an Army IT/IA schoolhouse, Army Mobile Training Team IA course and/or vendor specific IA training hosted by the Army (if applicable). The CND-AU typically has mastery of IAT Level I or IAT Level-II or IAT-III CE, NE and/or enclave with applicable certification, works under supervision, and typically reports to CND-SPM.
https://iatraining.us.army.mil/
05-PR-M-0002 Issuance date: 28 FEB 2006
IAW AR 25-2, para 4-3a(1)(b).
(2). Army e-Learning Program: HUA CIO/G-6 /Cyber Security IA/IT Training>Baseline Certificaton Training>UH, HUGIAC Systems and Network Auditor (GSNA) UH. (1 module). Course ID: FIN0232.
(3). Army e-Learning Program – CIO/G-6 /Cyber Security IA/IT Training>Baseline Certificaton
Training>CIO/G6 NETCOM Ethical Hacker (11 modules). This can be completed in lieu of the GSNA modules if pursuing a CEH certification.
DoD 8570.01-M, Change 3. paragraph C.3.2.3.2. This requirement must be validated by the individual CND-
SPM.
CND-AU personnel shall attain one of the IAT-I, IAT-II, or IAT-III level and CND baseline certifications listed in Table 3. The IAT certification level is dependent on the environment the CND-AU manages (CE, NE, Enclave). The completion of certification testing is required. CND-AU personnel will also attain the appropriate computing environment certification or certificate of training.
e. Computer Network Defense Service Provider Manager (CND–SPM) - complete the qualification requirements within 6 months of IA appointment (see table 4). The CND-SPM oversees the CND-SP operations within their organization. CND-SPMs are responsible for producing guidance for their NE or enclave, assisting with risk assessments and risk management for organizations within their NE or enclave, and are responsible for managing the technical classifications within their organization. They supervise technicians within their organization. They must complete all Army e-Learning Program minimum training requirements prior to enrollment in an Army IT/IA schoolhouse, Army Mobile Training Team IA course and/or vendor specific IA training hosted by the Army (if applicable). The CND-SPM usually has mastery of IAM Level I or IAM Level II CE and/or NE knowledge and skills with applicable certification and works under supervision and typically reports to a Computer Network Defense senior manager or USSTRATCOM.
(2). Army e-Learning Program - CIO/G-6 /Cyber Security IA/IT Training>Baseline Certificaton Training>Certified Information Systems Security Professional (CISSP) modules – 10 modules.
Manager (CISM) modules- 9 modules (if pursuing CISM certification).
CND-SPM personnel shall attain one of the IA management and CND baseline certifications listed in Table 3.
The IAM certification is dependent upon the environment the CND-SPM manages (CE, NE, Enclave). The completion of commercial certification testing is required.
https://usarmy.skillport.com/skillportfe/newskills/newskills.cfm?selectedTab=1&pathInfo=%2F%5Fassignments%2Fg162%2Fg1387&rpathinfo=/USARMY_CC/g1387 https://usarmy.skillport.com/skillportfe/newskills/newskills.cfm?selectedTab=1&pathInfo=%2F%5Fassignments%2Fg162%2Fg1387&rpathinfo=/USARMY_CC/g1387 javascript:cf_http_hook_fullpath(%22https://psparmybe.skillport.com:443/_scusarmy_od_cgi/odisapi.dll?cmd=LPSummaryWebPage&objname=lp39&assetType=_ss_lp&isLP=1&sessionid=%22+escape(%22doris.wright-YYLAY8CH8%22)+%22%22,0,%20'',%20'')
05-PR-M-0002 Issuance date: 28 FEB 2006
12. Information Assurance System Architect and Engineer (IASAE) Specialty
This Specialty comprises IASAE Levels I, II, and III. Complete the qualification requirements within six (6) months of IA Appointment (see table 4). All new hires must be certified within 6 months of appointment.
Persons responsible for performing any of these functions, regardless of the occupational title (Engineer, Scientist, Computer Specialist, manager, pilot, infantry officer, etc.) shall be identified as part of the IA workforce. Personnel required to perform any IASAE specialty IA function(s) at any level must be certified to the highest level of function(s) performed. IASAEs that also perform IAT functions must also attain the appropriate computing environment certification and complete the IAT level requirements prior to being granted unsupervised privileged access. They must complete all Army e-Learning Program minimum training requirements prior to enrollment in an Army IT/IA schoolhouse, Army Mobile Training Team IA course and/or vendor specific IA training hosted by the Army (if applicable). Local Nationals or Foreign Nationals may be conditionally assigned to IASAE Level II but may not be assigned to IASAE Level III positions.
a. IASAE Level I personnel are responsible for the design, development, implementation, and/or integration of an IA architecture, system, or system component for use within their CE. Incumbents ensure that IA related IS will be functional and secure within the CE.
(2). Army e-Learning Program – CIO/G-6 /Cyber Security IA/IT Training>Baseline Certificaton
Training>Certified Information Systems Security CISSP modules – 10 modules.
Certification Requirements IASAE Level I personnel shall attain one of the baseline certifications listed in Table 3 for their level. If performing technical (IAT) functions they are required to attain a technical level certification listed in Table 3 and Computing Environment certification or certificate of training. The IAT level baseline certification is dependent upon the environment the IASAE-I manage (CE, NE, and Enclave).
b. IASAE Level II personnel are responsible for the design, development, implementation, and/or integration of an IA architecture, system, or system component for use within the NE. Incumbents ensure that IA related IS will be functional and secure within the NE. Complete the qualification requirements within six (6) months of IA Appointment (see table 4).
Training>> Certified Information Systems Security CISSP modules – 10 modules.
05-PR-M-0002 Issuance date: 28 FEB 2006
Certification Requirements
IASAE Level II personnel will obtain one of the certifications listed in Table 3 for their level. If performing technical (IAT) functions they shall obtain a technical level baseline certification listed in Table 3 and Computing Environment certification or certificate of training. The IAT level certification is dependent upon the environment the IASAE II manages (CE, NE, Enclave).
c. IASAE Level III personnel are responsible for the design, development, implementation, and/or integration of an IA architecture, system, or system component for use within CE, NE, and enclave environments. They ensure the architecture and design of Information Systems is functional and secure.
This may include designs for program of record systems and special purpose environments with platform IT interconnectivity.
IASAE Level III personnel may also be responsible for system or network designs that encompass multiple CE and/or NE to include those with differing data protection/classification requirements.
Complete the qualification requirements within six (6) months of IA Appointment (see table 4).
Training>> Certified Information Systems Security CISSP modules – 10 modules
IASAE Level III shall obtain one of the baseline certifications listed in Table 3 for their level. If they perform technical (IAT) functions they will also be required to obtain a technical level certification listed in Table 3 and Computing Environment certification or certificate of training. The IAT level baseline certification is dependent upon the environment the IASAE-III manages (CE, NE, Enclave). The type of certification will be determined by the IA professional’s supervisor during the performance evaluation process.
05-PR-M-0002 Issuance date: 28 FEB 2006
Table 5: Training and Certification Matrix
UIA Mgmt I –III UIA Tech I – III UCNDSP: CND-A, CND-IS, CND- IR, CND-AU and CND-SPM
UIASAE I-III
Training Requirement 1
IA Fundamentals online course
(ALL)
IA Fundamentals online course
(ALL)
IA Fundamentals online course
(ALL)
IA Fundamentals online course (ALL)
Training Requirement 2
IAMI: Security Plus (Army e-
Learning Program) or Certification and Accreditation Army e-Learning modules (if pursuing CAP)
IAMII –III: CISSP (Army e-
Learning Program) or Certification and Accreditation Army e-Learning modules (if pursuing CAP) or Certified
Information Security Manager modules
IAMII - CISSP (Army e-Learning
Program) or Certification and
Accreditation Army e-Learning modules (if pursuing CAP) or Certified Information Security
Manager modules
IAT I: CompTIA Network+
2009 for the Network+ cert or
CompTIA A+ 220 701 and 702 for A+ cert (Army e-Learning
Program)
IAT II: Security Plus (Army e- Learning Program) and
Security+ Level II Schoolhouse Course
IAT III: CISSP (Army e-
Learning Program)
CND-A, CND-IS, CND-IR, CND-
AU: GIAC Technical Modules or
GIAC Systems and Network Auditor (Army e-Learning
Program)
CND-SPM: CISSP (Army e- Learning Program) or Certified Information Security Manager modules
All CND-SP categories except CND-SP Managers: CIO/G6 NETCOM Ethical Hacker if pursuing the Certified Ethical Hacker certification
CISSP (Army e-Learning Program) (ALL)
Certification (from approved list)
Yes (IA Certification within 6 months)
**Certification requirements must be included in contracts**
Yes (IA Certification within 6 months)
**Certification requirements must be included in contracts**
Yes (IA Certification within 6 months)
**Certification requirements must be included in contracts**
Yes (IA Certification within 6 months)
**Certification requirements must be included in contracts**
CE Certification or certificate of training for the operating system(s) and/or security related tools/devices
NO Yes (within 6 months of appointment of IA position)
Yes (except CND-SPM) (within 6 months of appointment of
IA position)
NO
Maintain Certification Status
Yes (as required by certification) Yes (as required by certification) Yes (as required by certification) Yes (as required by certification)
Continuous Education or
Sustainment Training
Yes (as required by certification) Yes (as required by certification) Yes (as required by certification) Yes (as required by certification)
Privileged Access Agreement Required
NO Yes Yes NO
EExperience IAM I: Usually an entry level management position with 2 to 5 or more years of management experience
IATI: IAT I: Normally has 0 to 5 or more years of experience in IA technology or a related field
URecommended years of experience in CND technology or a related field:
CND-A: at least 2 CND-IR: at least 5 CND-AU: at least 2
UIASAE I: Usually an entry level IASAE position with 0 or more years of IASAE experience.
Experience IAMII: Usually has at least 5 years of management experience
IAT II: Normally has at least 3 years in IA technology or a related area
CND-IS: Recommended at least 4 years of experience supporting
CND and/or network systems and technology
IASAE II: Usually has at least 5 years of IASAE experience.
Experience IAM III: Usually has at least 10 years of management experience
IAT III: Normally has at least 7 years experience in IA technology or a related area.
CND-SPM: Recommended at least 4 years of experience in
CND management or a related field
IASAE III: Usually has at least 10 years of IASAE experience
05-PR-M-0002 Issuance date: 28 FEB 2006
**Note: Denotes requirements for contractor personnel
13. Supporting information assurance roles:
a. Information Assurance Support Officer (IASO): The role of the IASO is to provide Information Assurance oversight, guidance and support to the general user in accordance with the requirements for the Command’s Information Assurance Program. The functions are listed in the memorandum: Changes to the Title, Responsibilities and Certification Requirements for Information Assurance Security Officers signed by the Army CIO/G6 dated June 7, 2011.
Training Requirement: Information Assurance Fundamentals (IAF) Course Online (https://ia.signal.army.mil/courses.asp ).
b. The Information Management Officer (IMO). IMO functions are covered under AR 25-1 and DA Pam 25-1-1. If an individual works as an IMO and performs IA functions, the appointment letter, appendix D, will be annotated as such (e.g. IMO/SA, etc). The duty title will designate the type of training needed.
c. Power User Personnel with this title shall have limited administrative privileges to only their computer. There is no certification requirement with this title. The Information Assurance Fundamental course located on the Signal Center website shall be completed along with their annual IA Awareness training. Personnel do not need to have an appointment letter for this position. Power Users are not counted as part of the IA workforce. Power Users have rights to perform limited functions (i.e.: turn on wireless, connect to network printers). This position is selectable in ATCTS.
14. IA Awareness Training: Initial and annual IA awareness training for users is mandatory. The trained and aware employee is the first and most vital line of defense in protecting Information and Information Systems. This training shall be documented by the organization. The DoD IA Awareness Computer Based Training at https://ia.signal.army.mil shall be completed by all users with network access. Users shall complete the training module and the 10 question Army test to receive full credit.
15. Proficiency training: To sustain proficiency and meet vendor required continuing professional education (CPE) requirements. IA workforce personnel can enroll in courses at various locations online and vendor provided. One place for this training is the recorded instructor-led training through the DoD Virtual Training Environment (VTE) which provides on-line labs. These course completions are tracked in ATCTS and can count as continuing education points towards some or most of the commercial baseline certifications. Courses on the Army Virtual Training website (https://iatraining.us.army.mil) are a good source for proficiency training. Users shall register with their AKO email address in order for course completions to transfer into their ATCTS account. User shall obtain at least 20-30 sustainment hours annually through on-line or classroom courses.
a. Proficiency training includes (but is not limited to):
(1) 1- week Network Manager Course at Fort Gordon
(2) 14-day CND advance course
(3) DoD VTE training at HUhttps://www.vte.cert.org.
(4) Army e-Learning courses at https://usarmy.skillport.com. This site can be access through AKO as well.
https://ia.signal.army.mil/ https://iatraining.us.army.mil/ https://www.vte.cert.org/ https://usarmy.skillport.com/
05-PR-M-0002 Issuance date: 28 FEB 2006
c. VTE training courses mapping to baseline certification is noted below: This is an on-line training platform that provides instructor-led classroom training and labs. VTE it is not a substitute for the Army e- Learning Program requirements for the Army Minimum Required Training.
(1). (ISC)2 TM CISSP ® Prep Version 2 (IAM-II, IAM-III, CND-SP Manager, All IASE) (2). CompTIA Network+ Prep (IAT-I) (3). CompTIA Security+ Prep (SY0-301 (IAM-I and IAT-II) (4). IAT Level I Additional Resources (IAT-I)
(5). IATII Additional Resources (IAT-I/IAT-II)
(6). Fundamentals of Incident Handling (7). Hardening Windows Operating Systems
(8) DISA HBSS Manager training
17. Qualifications:
a. Current: IA Technical and IA Managers with more than 6 months in an IA position shall be fully qualified. See table 4 for qualified requirements.
b. Newly appointed IA positions (civilians and military only) must become fully qualified within 6 months of being hired. .
c. Contractor personnel must be baseline certified upon hire in an IA/IT position. Contractors shall be appointed as well. Contractors shall attain a computing environment certification or certificate of training within 6 months of hire if working on an IA/IT contract. The government organization or government POC responsible for the Network environment will determine the type of training or computing environment certification requirement upon contract award.
18. Definitions:
a. Privileged access: Authorized access that provides a capability to alter the properties, behavior, or control of the information system or network. It includes, but is not limited to, any of the following types of access: (a) “Super user,” “root,” or equivalent access, such as access to the control functions of the information system or network, administration of user accounts, and so forth; (b) Access to change control parameters (for example, routing tables, path priorities, addresses) of router, multiplexers, and other key information system or network equipment or software; (c) Ability and authority to control and change program files, and other users’ access to data; (d) Direct access (also called unmediated access) to functions at the operating-system level that would permit system controls to be bypassed or changed; or (e) Access and authority…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .