CASTLE-CUIG_signed.pdf

PDF 254 KB Posted

Attached to
Cyber Agents for Security Testing and Learning Environments (CASTLE) Federal contract opportunity
Solicitation number
HR001123S0002
Issued by
Defense Advanced Research Projects Agency

About this file

This Controlled Unclassified Information (CUI) guide outlines protection requirements for the Cyber Agents for Security Testing and Learning Environments (CASTLE) program. The CASTLE program seeks to develop AI-enabled cyber agents through the Defense Advanced Research Projects Agency (DARPA) to recognize and respond to advanced persistent threats and enable resilient network operations. The CUI guide identifies CASTLE information requiring protection, such as test results, network user data, penetration testing tools, and models trained on operational Department of Defense systems. It provides marking and dissemination guidance for CASTLE CUI and outlines reporting procedures for unauthorized disclosures. The CUI guide applies to all DARPA and support contractor personnel working on CASTLE and must be followed to properly protect sensitive program information.

View the file

Other files for this federal contract opportunity

Other files attached to Cyber Agents for Security Testing and Learning Environments (CASTLE), newest first.
File Type Posted
HR001123S0002-Amendment-02.pdf PDF
HR001123S0002-Amendment-01.pdf PDF
FCL_Sponsorship_Letter_Instruction_May_2016.pdf PDF
HR001123S0002.pdf PDF
CASTLE_Summary_Chart.pptx PPTX presentation

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Controlled Unclassified Information Guide

Program: Cyber Agents for Security Testing and Learning Environments

(CASTLE)

Program Manager: Mr. Tejas Patel

Program Security Officer: Mr. Troy Blackburn

Date: October, 2022

Version: 1

Mr. Tejas Patel Mr. Troy Blackburn

I2O Program Manager I2O Program Security Officer

Local reproduction of this document is authorized only in its entirety.

FOREWORD

1. DESCRIPTION

2. AUTHORITY

GENERAL

1. PURPOSE

2. APPLICABILITY AND SCOPE

3. OFFICE OF PRIMARY RESPONSIBILITY

4. CONTROLLED UNCLASSIFIED INFORAMTION (CUI) CHALLENGES

5. OPERATION SECURITY (OPSEC)

6. CUI CATAGORIES

7. EXPORT CONTROL RESTRICTED INFORMATION

8. FREEDOM OF INFORMATION ACT (FOIA) EXEMPT INFORMATION

9. DISCLOSURE of CUI

10. CUI PROTECTION REQUIREMENTS

11. NOTIFICATION OF UNAUTHORIZED DISCLOSURE

12. INFORMATION PROTECTION GUIDANCE CHARTS

FOREWORD

1. DESCRIPTION

The Cyber Agents for Security Testing and Learning Environments (CASTLE) program seeks to develop AI-enabled cyber agents to recognize and respond to advanced persistent threats

(APT) and enable mission-resilient network operations. Cyber agents will train in evolving, adversarial environments that are representative of actual networks.

2. AUTHORITY

CUI elements referenced in this guide are under the authority of DoDI 5200.48, “Controlled

Unclassified Information,” March 6, 2020.

1. PURPOSE

a. The purpose of this CUI guide is to ensure the protection of Cyber Agents for

Security Testing and Learning Environments (CASTLE) information IAW DoDI 5200.48.

CASTLE information should be controlled and stored consistent with federal requirements and guidance from the National Institute for Standards and Technology (NIST). Sensitive information does not include information in the public domain.

b. This guide is not for classified national security information as defined in

Executive Order 13526, but identifies specific elements of sensitive information that are unclassified in nature requiring protection. This information is not classified national security information, but it is covered by the legislation at large for the Freedom of Information Act

(FOIA) and the exemptions therein.

2. APPLICABILITY AND SCOPE

This guide applies to all DARPA personnel, support contractors, mission partners, and industrial performers who support CASTLE. This guide should be cited as the basis for identifying, protecting and marking of information and material designated as a type of controlled unclassified information (CUI) associated with CASTLE. As defined at 32 CFR

Section 2002.4(h), CUI is information that the government creates or possesses – or that an entity creates or possesses on behalf of the government that law, regulation or government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls. It is to be used in conjunction with related security classification guides and guidance documents associated with the overall effort of CASTLE, in compliance with Executive Orders and related

DoD guidance. The scope of this guide is based on CASTLE as planned at the date of this guide, and may expand or change as strategic decisions are made over the course of CASTLE project.

DARPA considers that the technology developed in CASTLE technical areas will constitute advances to the state of the art. The development of CASTLE tools and techniques are fundamental research in most cases. CASTLE tools and techniques are not CUI when realized in source code or executable formats, or when documented in written reports, with certain exceptions noted in section 13. Machine learning algorithms are not CUI. Instances of these algorithms and resulting models that have been trained on or configured by CUI data must be treated as CUI. For example, the algorithms required to train and run a neural network are not considered CUI, but the resulting neural network would be CUI if it were trained on a CUI dataset. In the case of CASTLE, a CUI training dataset would be the configuration, vulnerabilities or security posture of an operational DoD network; the resulting trained CASTLE model in this case would be CUI.

3. OFFICE OF PRIMARY RESPONSIBILITY (OPR)

This CUI guide is issued by DARPA. All inquiries concerning content, interpretations, and clarification of this document should be addressed to DARPA at I2Osecurity@darpa.mil with any questions.

4. CONTROLLED UNCLASSIFIED INFORMATION (CUI) CHALLENGES

CUI Challenges: Authorized holders of CUI who, in good faith, believe that a designation of information as CUI within this guide is improper or incorrect, or who believe they have received unmarked CUI, should notify DARPA at I2Osecurity@darpa.mil. Until the challenge is resolved, the challenged CUI, including challenges to unmarked CUI, will continue to be safeguarded and disseminated at the appropriate control level indicated in the markings or presumed category.

5. OPERATIONS SECURITY (OPSEC)

a. OPSEC is a process that identifies and mitigates adversarial risk to our operations by looking at our operations through the eyes of our adversaries. The application of the OPSEC methodology includes identifying critical information, analyzing threats and vulnerabilities, analyzing and assessing adversarial risk, and implementing OPSEC measures that reduce this risk.

b. CASTLE critical information falls under the following index of CUI:

1) Privacy: General Privacy Information (PRVCY)

2) Defense: Controlled Technical Information (CTI)

3) Intelligence: Operations Security (OPSEC)

4) Critical Infrastructure (ISVI)

6. CUI Categories

a. Defense: Controlled Technical Information (CTI). This category relates to technical information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination. Controlled technical information would meet that criteria, if disseminated, for distribution statements B through F using the criteria set forth in DoD

Instruction 5230.24, Distribution Statements on Technical Documents.

b. Privacy: General Privacy. Refers to personal information, or, in some cases, "personally identifiable information," as defined in OMB M-17-12, or "means of identification" as defined in 18 USC 1028(d)(7).

c. Intelligence: Operational Security (OPSEC). Critical information determined to give evidence of the planning and execution of sensitive (frequently classified) government activities after going through a formal systematic vetting process in accordance with

National Security Decision Directive Number 298. This process identifies unclassified information that must be protected. It almost always results from an agency’s official

OPSEC program, or is otherwise commonly approved for use by the CUI Senior Agency

Official.

d. Critical Infrastructure (ISVI). Related to information that if not protected, could result in adverse effects to information systems. Information system means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.

7. EXPORT CONTROL RESTRICTED INFORMATION

a. EAR restrictions may apply to technologies created under CASTLE. It is the responsibility of CASTLE performers to ascertain the potential export controls of their technology.

8. FREEDOM OF INFORMATION ACT (FOIA) EXEMPT INFORMATION

a. The Freedom of Information Act (FOIA), 5 U.S.C. § 552, is a federal law that defines agency records subject to public disclosure, outlines mandatory disclosure procedures, and defines nine exemptions that prohibit certain types of information from being released to the public. In addition to the FOIA, the Code of Federal Regulations (October 2016), 45 CFR § 5.31 specifies the type of information that falls under each of the nine exemptions that preclude release of information to the public under the FOIA. In accordance with 5 U.S.C. § 552(a)(8), DARPA will withhold records or information exempt from disclosure under the FOIA whenever disclosure would harm an interest protected by a FOIA exemption or disclosure is prohibited by law. The most relevant exemptions for CASTLE are listed below; however other exemptions could apply:

1. Exemption 5 – Protects the integrity of the deliberative or policy-making processes within the agency by exempting from mandatory disclosure opinion, conclusions, and recommendations included within inter-agency or intra-agency memoranda or letters.

2. Exemption 6 – Protects information that would constitute a clearly unwarranted invasion of personal privacy of the individuals involved.

9. DISCLOSURE of CUI.

a. Public Disclosure. Information from this CUI guide does not allow automatic public release of this information. DoD information requested by the media or members of the public or proposed for release to the public by DoD civilians or military personnel or their contractors will be processed in accordance with DARPA Instruction 65 and DoD Instructions 5230.09, 5230.29; Volume 3 of DoD Manual 5200.01; and DoD Manual 5400.07, as applicable. Proposed public disclosures of unclassified information shall be submitted using the public release form located at https://www.darpa.mil/work-with-us/contract-management/public-release.

b. Freedom of Information Act (FOIA) Requests. All personnel with knowledge of this

Project must coordinate with the DARPA PSO prior to providing a response to requests for information under the provisions of the FOIA.

c. Proprietary Information (PROPIN). Additional safeguards may become necessary if a contract requires the transfer of PROPIN. The holder of the information must clearly identify any and all PROPIN prior to its disclosure and release, the release will be coordinated with the

PROPIN owner.

d. Foreign Disclosure. Disclosure of DARPA CUI to foreign nationals will be coordinated with the PSO, International Security, and International Cooperation. Disclosure approval must be granted by the Director, SID, who is the Foreign Disclosure Officer for

DARPA.

10. CUI PROTECTION REQUIREMENTS

a. CASTLE CUI (e.g., confidential business information, PII, USPI, vulnerability test results, penetration testing tools controlled under EAR) regardless of media or format, will be protected from disclosure to unauthorized persons or groups, by properly storing in locked offices, cabinets, and drawers in accordance with DoDI 5200.48.

b. CUI may only be processed on DIB systems that are compliant with DFARS 252.204-

7012 requirements as detailed in NIST 800-171.

11. NOTIFICATION OF UNAUTHORIZED DISCLOSURE

a. Personnel must immediately report all unauthorized disclosures or suspected and known security incidents, privacy breaches, and suspicious activities involving CUI to the CASTLE

PSO and PSR at I2Osecurity@darpa.mil.

b. Data breaches of DIB networks and systems involving CASTLE CUI material must be reported IAW DFARS 252.204-7012 requirements. In addition, all breaches must be reported to the DARPA Project contracting officer and program security officer (PSO) upon discovery.

https://www.darpa.mil/work-with-us/contract-management/public-release

12. INFORMATION PROTECTION GUIDANCE CHARTS

These charts are provided to assist in identifying what types of information associated with the CASTLE effort may be sensitive, provide guidance on the relevant markings for this information to control dissemination, and provide guidance on when these dissemination controls no longer apply. If at any time there are questions regarding which category of information something falls under, or what dissemination controls apply, individuals should request guidance from DARPA at I2Osecurity@darpa.mil.

Table 1: CASTLE CUI elements

Element of

Information

Index Category Reason LDC or

Distribution

Statement

Remarks

Pre-decisional budget

Intelligence Operations

Security

(OPSEC)

FAR 2.101

and 3.104

Federal employees

Only (FED ONLY)

FOIA Exemption 5 may be applicable

Personnel Contact

Rosters

Privacy General

Privacy

(PRVCY)

Privacy Act of 1974

Federal Employees and Contractors

Only (FEDCON)

FOIA Exemption 6 may be applicable

Does not apply to university fundamental research performance

Results of

CASTLE tests and evaluations on operational DoD systems (defined in table 3)

Defense Controlled

Technical

Information

(CTI)

DFARS

252.204.70

12 and

DoDI

5230.24

FEDCON Test and evaluation results (e.g., precision, recall, F1 scores) from synthetic cyber ranges created by the DoD or CASTLE performers may be shared without restriction. Test and evaluation results from

DoD systems that are not attributed to those DoD systems may be shared without restriction upon DoD partner or DARPA approval

Network user data incidentally collected by

CASTLE

Privacy General

Privacy

(PRVCY)

Privacy Act of 1974

FEDCON FOIA Exemption 6 may be applicable

Does not apply to university fundamental research performance potentially containing USPI or PII

May be downgraded from CUI once all data is reviewed and USPI and PII is deleted or minimized

Data generated by synthetic users are not

CUI

Penetration testing tools that are controlled by the

EAR under ECCN

5A004

Export

Control

Export controlled

(EXPT)

32 CFR

250.4(A)

FEDCON Performers are individually responsible for identifying which penetration testing tools require export control and will adhere to any export control requirements identified by penetration testing tool vendors

Open source penetration testing tools are not categorized as CUI on this effort

Red, blue, purple team models trained on operational DoD systems

Defense Controlled

Technical

Information

48 CFR

252.204-

FEDCON Trained models on DoD environments that cannot be reasonably attributed to

CTI experiments or information are NOT

CTI

Red, blue, purple team models trained on synthetic network environments are not

CTI

Vulnerabilities discovered in open source or COTS software utilized in operational

DoD systems

Defense Controlled

Technical

Information

48 CFR

252.204-

FEDCON The outputs and work products resulting from application of algorithms to non-militarily relevant target platforms are only considered CTI if they identify vulnerabilities in COTS, GOTS or FOSS software

Protect as CUI until release is approved though the DoD vulnerability equities

Process: www.dc3.mil

Operational DoD system performance metrics

Critical

Infrastructure

Information

Systems

Vulnerability

Information

(ISVI)

44 USC

FEDCON Summarized performance metrics that pertain only to CASTLE tool performance are not CUI when they do not reveal operational DoD systems, their vulnerabilities or configurations

Table 2: CASTLE NOT CUI elements

TA1: Purple Team (Automate instantiation of realistic network environments)

• Purple team data-management plans

• Remotely accessible infrastructure for exercise evaluations

• Instrumented data from purple team execution on university or closed test bed networks

• Network and device event collection on university or closed test bed networks

• RL simulations inside actual networks

• Vulnerability scans and system configurations of university or closed test bed networks

• Open, evolving and adversarial RL environments

• Evaluation data from CASTLE synthetic cyber ranges systems or commercial systems are unclassified

TA2: Blue Team (Learn defensive actions for maintaining operations)

• Standards for implementing agent execution

• API to execute simulated agents

• Approach to formulate defensive agent rewards

• Labeled datasets algorithms and models describing tool behaviors

• Novel data-driven approach to analyze APT behavior

• Intrusion detection tools

TA3: Red Team (Enumerate possible attack paths)

• Open source penetration testing tools obtained by on-campus fundamental research performers

• Curated datasets from university or closed test bed networks as feedback to agent simulations

• Executable code and API for red team agents

• Reward functions for red team automated agents

• Network attack paths on university or closed test bed networks identified by

CASTLE agents

• Publicly available penetration testing tools not subject to export control under EAR

Table 3: Definitions

Operational DoD

System

Systems that process covered defense information as defined by 48 CFR § 252.204-7012 or otherwise require compliance with NIST 800-171 or have been issued a DoD approval to operate or have certified in a self-attestation letter

Performance metrics Any data that contains or reveals the vulnerability, security or compliance posture of a system

DoD Cyber Range/test bed/synthetic cyber ranges

Realistic network environment that is a simulation of operational networks. These network environments do not contain any covered defense information. Synthetic environments may be established within operational DoD systems, but must be logically isolated from network elements that store or process covered defense information

Commercial systems Systems not configured in compliance in NIST 800 171 and do not store or process covered defense information

2022-10-19T16:52:27-0400
PATEL.TEJAS.H.1503317504
2022-10-19T17:10:59-0400
BLACKBURN.TROY.W.1076096780

File details come from the government source that posted it. Updated .