The file's text, extracted by GovTribe without its formatting.
SDMS Attachment 2
APPLICABLE STANDARDS AND REFERENCES
| Documentation |
| URL |
| Description |
ENTERPRISE STRATEGY
| DoD CIO Net-Centric Data Strategy |
| http://dodcio.defense.gov/Portals/0/documents/Net-Centric-Data-Strategy-2003-05-092.pdf |
| This document describes the Net-Centric Data Strategy for the Department of Defense (DoD), including DoD intelligence agencies and functions. It describes a vision for a net-centric environment and the data goals for achieving that vision. It defines approaches and actions that DoD personnel will have to take as users—whether in a role as consumers and producers of data or as system and application programmers. |
| DoD CIO Net-Centric Services Strategy |
| http://dodcio.defense.gov/Portals/0/documents/DoD_NetCentricServicesStrategy.pdf |
| The DoD Net-Centric Services Strategy (NCSS) [R1313] builds upon the DoD Net-Centric Data Strategy's (May 2003) goals of making data assets visible, accessible, and understandable. The NCSS establishes services as the preferred means by which data producers and capability providers can make their data assets and capabilities available across the DoD and beyond. It also establishes services as the preferred means by which consumers can access and use these data assets and capabilities. |
| DODI 8320.02, Data Sharing in a Net-Centric Department of Defense |
| http://www.dtic.mil/whs/directives/corres/pdf/832002p.pdf |
| Establishes policies and responsibilities to implement data sharing, IAW DoD Chief Information Officer Memorandum, “DoD Net-Centric Data Strategy,” May 9, 2003, throughout the Department of Defense. Directs the use of resources to implement data sharing among information capabilities, services, processes, and personnel interconnected within the Global Information Grid (GIG), as defined in DoD Directive 8100.1, “Global Information Grid (GIG) Overarching Policy,” September 19, 2002. |
| DoD Discovery Metadata Specification (DDMS) |
| http://metadata.ces.mil/dse/irs/DDMS/ |
| Visibility, accessibility, and understandability are the high priority goals of the DoD Net-Centric Data Strategy. Of these goals, visibility and discovery are intimately linked. Visibility of a resource is, in a practical sense, useless, if the resource is not easily discoverable. With the express purpose of supporting the visibility goal of the DoD Net-Centric Data Strategy, the DDMS specifies a set of information fields that are to be used to describe any data or service asset, i.e., resource, that is to be made discoverable to the Enterprise, and it serves as a reference for programmers, architects, and engineers by laying a foundation for Discovery Services. |
| CJCSI 6211.02D, Defense Information Systems Network Responsibilities |
| http://www.dtic.mil/cjcs_directives/cdata/unlimit/6211_02.pdf |
| This instruction establishes policy and responsibilities for the connection of information systems (ISs) (e.g., applications, enclaves, or outsourced processes) and unified capabilities (UC) products to the DISN provided transport (including data, voice, and video) and access to information services transmitted over the DISN (including data, voice, video, and cross-domain). |
| CJCSI 6212.01F, Interoperability and Supportability of Information Technology and National Security Systems |
| http://www.dtic.mil/cjcs_directives/cdata/unlimit/6212_01.pdf |
| Establishes policies and procedures for developing, coordinating, reviewing, and approving Information Technology (IT) and National Security System (NSS) Interoperability and Supportability (I&S) needs. Establishes procedures to perform I&S Certification of Joint Capabilities Integration and Development System (JCIDS) Acquisition Category (ACAT) programs and systems. Defines the five elements of the Net-Ready Key Performance Parameter (NR-KPP). Provides guidance for NR-KPP development and assessment. |
| Netcentric Enterprise Solutions for Interoperability (NESI) |
| https://nesix.spawar.navy.mil/home.html |
| NESI is a body of architectural and engineering knowledge that guides the design, implementation, maintenance, evolution, and use of the Information Technology (IT) portion of net-centric solutions for defense application. |
| DoDI 8330.01 Interoperability of Information Technology (IT), Including National Security Systems (NSS) |
| http://www.dtic.mil/whs/directives/corres/pdf/833001p.pdf |
| Establishes policy, assigns responsibilities, and provides direction for certifying the interoperability of IT and NSS pursuant to sections 2222, 2223, and 2224 of Title 10, United States Code (Reference (c)). Establishes a capability-focused, architecture-based approach for interoperability analysis. Establishes the governing policy and responsibilities for interoperability requirements development, test, certification and prerequisite for connection of IT, including NSS (referred to in this instruction as “IT”). Defines a doctrine, organization, training, materiel, leadership and education, personnel, facilities, and policy (DOTMLPF-P) approach to enhance life-cycle interoperability of IT. Establishes the requirement for enterprise services to be certified for interoperability. Incorporates and cancels DoDD 4630.05, DoDI 4630.8, and DoD Chief Information Officer (CIO) memorandum (References (d), (e), and (f)). |
| Joint Vision 2020 |
| http://www.fraw.org.uk/files/peace/us_dod_2000.pdf |
| Strategic Guidance: Joint Vision 2020 builds upon and extends the conceptual template established by Joint Vision 2010 to guide the continuing transformation of America’s Armed Forces. |
ENTERPRISE ARCHITECTURE
| DoD Global Information Grid Architectural Vision |
| http://www.dtic.mil/cgi-bin/GetTRDoc?AD=ADA484389&Location=U2&doc=GetTRDoc |
| The security challenges of the 21st century are characterized by change and uncertainty. Operations vary widely and partners cannot be anticipated. However, we are confronting that uncertainty by becoming more agile. Greater levels of agility rest upon leveraging the power of information – the centerpiece of today's Defense transformation to net-centric operations (NCO). Our forces must have access to timely and trusted information. And, we must be able to quickly and seamlessly share information with our partners, both known and unanticipated. The GIG Architectural Vision is key to creating the information sharing environment and will be critical to transformation to NCO. |
| Department of Defense Architecture Framework (DoDAF) Ver2.02 Aug 2010 |
| http://dodcio.defense.gov/TodayinCIO/DoDArchitectureFramework.aspx |
| The Department of Defense Architecture Framework (DoDAF), Version 2.0 is the overarching, comprehensive framework and conceptual model enabling the development of architectures to facilitate the ability of Department of Defense (DoD) managers at all levels to make key decisions more effectively through organized information sharing across the Department, Joint Capability Areas (JCAs), Mission, Component, and Program boundaries. The DoDAF serves as one of the principal pillars supporting the DoD Chief Information Officer (CIO) in his responsibilities for development and maintenance of architectures required under the Clinger-Cohen Act. DoDAF is prescribed for the use and development of Architectural Descriptions in the Department. It also provides extensive guidance on the development of architectures supporting the adoption and execution of Net-centric services within the Department. |
| AFPD 33-4, Information Technology Governance |
| http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afpd33-4/afpd33-4.pdf |
| This directive establishes the AF policy for IT Governance to fulfill the AF CIO responsibilities established in federal laws and DoD issuances and the AF IT Governance Executive Board, which will oversee existing IT investment councils, boards, and working groups throughout the IT lifecycle to effectively and efficiently deliver capabilities to users. This directive focuses on aligning IT policy, CIO policy, and capabilities management with doctrine, statutory, and regulatory guidelines that govern accountability and oversight over IT requirements to resource allocation, program development, test, and deployment and operations under the direction and authority of the AF IT Governance Executive Board chaired by the AF CIO. |
| AFI 33-401, AIR FORCE ARCHITECTING |
| http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afi33-401/afi33-401.pdf |
This Air Force Instruction (AFI) implements Air Force Policy Directive (AFPD) 33-4, Enterprise Architecting. This instruction describes the federation of Air Force architectures and its concept for federated architecture development, its associated business rules, governance, and the roles and responsibilities for appropriate Air Force organizations.
| GiG Technical Guidance Federation GIG-F |
| https://gtg.csd.disa.mil/uam/registration/register |
| The GIG Technical Guidance Federation (GTG-F) is a suite of software applications on the NIPRNet and SIPRNet (June 2012) that provides technical guidance across the Enterprise to achieve net-ready, interoperable, and supportable GIG systems. The GTG-F assists program managers, portfolio managers, engineers and others in answering two questions critical to any Information Technology (IT) or National Security Systems (NSS): (1) Where does the IT or NSS fit, as both a provider and consumer, into the GIG with regard to End-to-End technical performance, access to data and services, and interoperability; (2) What must an IT or NSS do to ensure technical interoperability with the GIG. The GTG-F content provides the technical information to various users in addressing and resolving technical issues needed to meet functional requirements (i.e., features and capabilities) of the GIG. This GTG-F content consists of and is based on GIG net-centric IT standards, associated profiles, engineering best practices and reference implementation specifications. |
SYSTEMS ENGINEERING
| Business and Enterprise Systems (BES) Process Directory |
| https://acc.dau.mil/bes |
| The BES Process Directory (BPD) is a life cycle management and systems engineering process based on the Integrated Defense Acquisition, Technology, and Logistics Life Cycle Management System; as tailored for Information Technology (IT) systems via the Defense Acquisition Process Model for Incrementally Fielded Software Intensive Programs |
| AFI 10-601, Capabilities-Based Requirements Development |
| http://static.e-publishing.af.mil/production/1/af_a3_5/publication/afi10-601/afi10-601.pdf |
| The primary intent of this instruction is to facilitate timely development and fielding of affordable and sustainable operational systems needed by the combatant commander. The primary goal is to fulfill stated defense strategy needs with effects based, capabilities-focused materiel and non-materiel solutions. These solutions must be well integrated to provide suitable, safe, and interoperable increments of capability that are affordable throughout the life cycle. |
| AFI 63-101, Integrated Life Cycle Management |
| http://static.e-publishing.af.mil/production/1/saf_aq/publication/afi63-101_20-101/afi63-101_20-101.pdf |
| The purpose of this instruction is to implement direction from the Secretary of the Air Force as outlined in Air Force Policy Directive (AFPD) 63-1/20-1, Acquisition and Sustainment Life Cycle Management. The primary mission of the Integrated Life Cycle Management (ILCM) Enterprise is to provide seamless governance, transparency and integration of all aspects of weapons systems acquisition and sustainment management. |
| AFI 99-103, Capabilities-Based Test and Evaluation |
| http://static.e-publishing.af.mil/production/1/af_te/publication/afi99-103/afi99-103.pdf |
| It describes the planning, conduct, and reporting of cost effective test and evaluation (T&E) programs as an efficient continuum of integrated testing known as seamless verification. The overarching functions of T&E are to mature sys-tem designs, manage risks, identify and help resolve deficiencies as early as possible, and ensure systems are operationally mission capable (i.e., effective and suitable). The Air Force T&E community plans for and conducts integrated testing as an efficient continuum known as seamless verification in collaboration with the requirements and acquisition communities. |
DoD Open Technology Development Guidebook
This roadmap outlines a plan to implement Open Technology Development practices, policies and procedures within the DoD.
| Industry Best Practices in Achieving Service Oriented Architecture (SOA) |
| http://www.sei.cmu.edu/library/assets/soabest.pdf |
| This document was developed under the Net-Centric Operations Industry Forum charter to provide industry advisory services to the Department of Defense (DoD), Chief Information Officer (CIO). It presents a list of industry best practices in achieving Service Oriented Architecture (SOA). |
INFORMATION ASSURANCE
| ICD 503, IT Systems Security, Risk Management, Certification and Accreditation |
| http://www.dni.gov/files/documents/ICD/ICD_503.pdf |
| This ICD focuses on a more holistic and strategic process for the risk management of information technology systems, and on processes and procedures designed to develop trust across the intelligence community information technology enterprise through the use of common standards and reciprocally accepted certification and accreditation decisions. |
| DoDI 8500.01 Cybersecurity |
| http://www.dtic.mil/whs/directives/corres/pdf/850001_2014.pdf |
| Establishes policy and assigns responsibilities to achieve Department of Defense (DoD) Information Assurance (IA) through a defense-in-depth approach that integrates the capabilities of personnel, operations, and technology, and supports the evolution to network centric warfare. |
| DoD 8570.01, Information Assurance Training, Certification, and Workforce Management |
| http://www.dtic.mil/whs/directives/corres/pdf/857001p.pdf |
| Establishes policy and assigns responsibilities for Department of Defense (DoD) Information Assurance (IA) training, certification, and workforce management. |
| DoD 8570.01-M, Information Assurance Workforce Improvement Program |
| http://www.dtic.mil/whs/directives/corres/pdf/857001m.pdf |
| Provides guidance for the identification and categorization of positions and certification of personnel conducting Information Assurance (IA) functions within the DoD workforce supporting the DoD Global Information Grid (GIG) per DoD Instruction 8500.2. The DoD IA Workforce includes, but is not limited to, all individuals performing any of the IA functions described in this Manual. Additional chapters focusing on personnel performing specialized IA functions including certification and accreditation (C&A) and vulnerability assessment will be published as changes to this Manual. |
| DoDI 8510.01,Risk Management Framework (RMF) for DoD Information Technology (IT) |
| http://www.dtic.mil/whs/directives/corres/pdf/851001_2014.pdf |
| Provides procedural guidance for the reciprocal acceptance of authorization decisions and artifacts within DoD, and between DoD and other federal agencies, for the authorization and connection of information systems (ISs). |
| AFI 33-200, Information Assurance |
| http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afi33-200/afi33-200.pdf |
| This AFI provides general direction for implementation of IA and management of IA programs according to AFPD 33-2. Compliance ensures appropriate measures are taken to ensure the availability, integrity, and confidentiality of Air Force ISs and the information they process. |
| AFI 33-210, AF Certification and Accreditation Program (AFCAP) |
| http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afi33-210/afi33-210.pdf |
| This AFI implements DIACAP for authorizing the operation of Air Force ISs consistent with federal, DoD, and Air Force policies. It is used to ensure IA for all Air Force procured Information Systems, and Guest systems operating on or accessed from the AF-GIG. |
| Security Technical Implementation Guides (STIGs) |
| http://iase.disa.mil/stigs/Pages/index.aspx |
| The Security Technical Implementation Guides (STIGs) and the NSA Guides are the configuration standards for DOD IA and IA-enabled devices/systems. The STIGs contain technical guidance to "lock down" information systems/software that might otherwise be vulnerable to a malicious computer attack. |
| Air Force Guidance Memorandum (AFGM), End-of-Support Software Risk Management |
| http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afgm2015-33-01/afgm2015-33-01.pdf |
| This Guidance Memorandum supersedes AFGM 2014-33-03, Microsoft Windows XP End-of-Life, and highlights current policies and SAF/CIO A6 authorities to mitigate cybersecurity vulnerabilities introduced by unsupported software. Compliance with this Memorandum is mandatory. |
| AFMAN 33-282, COMPUTER SECURITY (COMPUSEC) |
| http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afman33-282/afman33-282.pdf |
| This AFMAN implements Computer Security in support of AFPD 33-2, Information Assurance Program and AFI 33-200, IA Management Computer Security (COMPUSEC) is defined within the IA Portion of AFI 33-200. |
| AFMAN 33-285, Cybersecurity Workforce Improvement Program |
| http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afman33-285/afman33-285.pdf |
| This rewrite identifies cybersecurity baseline certification requirements for the AF cybersecurity workforce; stipulates minimum certification requirements for various cyber roles and risk management positions; sets qualifications criteria; clarifies the cybersecurity-coding position process; and codifies the waiver policy for baseline certification requirements. |
| DoDI 8540.01, Cross Domain (CD) Policy |
| http://www.dtic.mil/whs/directives/corres/pdf/854001p.pdf |
| Establishes policy, assigns responsibilities, and identifies procedures for the interconnection of information systems (ISs) of different security domains using CD solutions (CDSs) IAW the authority in DoD Directive (DoDD) 5144.02 |
| DoDI 8520.02 Public Key Infrastructure (PKI) and Public Key (PK) Enabling |
| http://www.dtic.mil/whs/directives/corres/pdf/852002p.pdf |
| This instruction establishes and implements policy, assign responsibilities, and prescribe procedures for developing and implementing a DoD-wide PKI and enhancing the security of DoD information systems by enabling these systems to use PKI for authentication, digital signatures, and encryption. |
INFORMATION TECHNOLOGY STANDARDS
| Federal Information Processing Standards (FIPS) |
| http://www.nist.gov/itl/fipscurrent.cfm |
| Under the Information Technology Management Reform Act (Public Law 104-106), the Secretary of Commerce approves standards and guidelines that are developed by the National Institute of Standards and Technology (NIST) for Federal computer systems. These standards and guidelines are issued by NIST as Federal Information Processing Standards (FIPS) for use government-wide. NIST develops FIPS when there are compelling Federal government requirements such as for security and interoperability and there are no acceptable industry standards or solutions. |
| IEEE/EIA 12207.0, "Standard for Information Technology |
| http://www.ieee.org/ |
| IEEE/EIA 12207.0, "Standard for Information Technology – Software Life Cycle Processes", is a standard that establishes a common framework for software life cycle process. This standard officially replaced MIL-STD-498 for the development of DoD software systems in May 1998.[1] Other NATO nations may have adopted the standard informally or in parallel with MIL-STD-498.This standard defines a comprehensive set of processes that cover the entire life-cycle of a software system—from the time a concept is made to the retirement of the software. The standard defines a set of processes, which are in turn defined in terms of activities. The activities are broken down into a set of tasks. The processes are defined in three broad categories: Primary Life Cycle Processes, Supporting Life Cycle Processes, and Organizational Life Cycle Processes. |
| DoDD 8000.01 Management of the Department of Defense Information Enterprise |
| http://www.dtic.mil/whs/directives/corres/pdf/800001p.pdf |
| Provides direction on creating an information advantage for DoD personnel and mission partners, and establishing and defining roles for CIOs at various levels within the Department of Defense |
| AFI 10-208 Air Force Continuity of Operations (COOP) Program |
| http://www.fas.org/irp/doddir/usaf/afi10-208.pdf |
| This Instruction implements Air Force Policy Directive (AFPD) 10-2, Readiness, and is consistent with AFPD 10-8, Homeland Security. It describes policy and requirements for implementing DODI 3020.42, Defense Continuity Plan Development, and DODI O-3020.43, Emergency Management and Incident Command of the Pentagon Facilities; DODI O-3000.08 Balanced Survivability Assessments (BSAs); and O-DODI 5110.11, Raven Rock Mountain Complex (RRMC). |
| US Government Configuration Baseline (USGCB) |
| http://usgcb.nist.gov/ |
| The United States Government Configuration Baseline (USGCB) is a Federal government-wide initiative that provides guidance to agencies on what should be done to improve and maintain an effective configuration settings focusing primarily on security. The USGCB baseline evolved from the Federal Desktop Core Configuration mandate. USGCB continues to be one of the most successful government IT programs aimed at helping to increase security, reduce costs, and accelerate the adoption of new government technologies, while creating a more managed desktop environment. |
| DoD Mobile Application Strategy |
| http://www.defense.gov/news/dodmobilitystrategy.pdf |
| It is intended to align the progress of various mobile device pilots and initiatives across DoD under common objectives, ensuring that the warfighter benefits from such activities and aligns with efforts composing the Joint Information Environment. |
| ISO/IEC 20000 |
| http://www.iso.org/iso/home.html |
| ISO/IEC 20000 is an international standard for IT Service Management (ITSM). It allows IT organizations to ensure the alignment between ITSM processes and their overall organization strategy. It requires the service provider to plan, establish, implement, operate, monitor, review, maintain and improve a service management system (SMS). ISO/IEC 20000 consist of 5 separate documents, ISO/IEC 20000-1 through 20000-5 |
QUALITY ASSURANCE
| AFPD 33-3, Information Management |
| http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afpd33-3/afpd33-3.pdf |
| This policy directive establishes Air Force policy for the management of information assets (all forms of data and content), across all AF information sources, as both a strategic resource and corporate asset supporting the warfighter during mission and support operations. |
| AFMAN 33-363, Management of Records |
| http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afman33-363/afman33-363.pdf |
| This manual implements DoDD 5015.2, DoD Records Management Program, and Air Force Policy Directive (AFPD) 33-3, Information Management. It establishes the requirement to use the Air Force Records Information Management System (AFRIMS); establishes guidelines for managing all records (regardless of media); and defines methods and the format for record storage, file procedures, converting paper records to other media or vice versa, and outlines the minimum to comply with records management legal and policy requirements. |
| DoD Instruction 5015.02, DoD Records Management Program |
| http://www.dtic.mil/whs/directives/corres/pdf/501502p.pdf |
| Establishes policy and assigns responsibilities for the management of DoD records in all media, including electronic |
| AFI 33-364, Records Disposition – Procedures and Responsibilities |
| http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afi33-364/afi33-364.pdf |
| This instruction implements Air Force Policy Directive (AFPD) 33-3, Information Management, by listing program objectives and responsibilities, guiding personnel in disposing of special types of records, retiring or transferring records using staging areas, and retrieving information from inactive records. |
| DoDI 5230.24, Distribution Statements on Technical Documents |
| http://www.dtic.mil/dtic/pdf/customer/STINFOdata/DoDD_523024.pdf |
| This Directive updates policies and procedures for marking technical documents, including production, engineering, and logistics information, to denote the extent to which they are available for distribution, release, and dissemination without additional approvals or authorizations. |
| AFI 61-204, Disseminating Scientific and Technical Information |
| http://static.e-publishing.af.mil/production/1/saf_aq/publication/afi61-204/afi61-204.pdf |
| This instruction updates the procedures for identifying export-controlled technical data and releasing export-controlled technical data to certified recipients and clarifies the use of the Militarily Critical Technologies List. It establishes procedures for the disposal of technical documents. |
| AFMAN 33-152 Communications and Information |
| http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afman33-152/afman33-152.pdf |
| This instruction implements Air Force Policy Directive (AFPD) 33-1, Information Resources Management, AFPD 33-2, Information Assurance (IA) Program, and identifies policies and procedures for the use of cyberspace support systems/services and compliance requirements of Secretary of the Air Force, Chief of Warfighting Integration and Chief Information Officer (SAF/CIO A6) managed programs. These programs ensure availability, interoperability, and maintainability of cyberspace support systems/services in support of Air Force mission readiness and warfighting capabilities. |
| AFMAN 33-402 - Service Development and Delivery Process (SDDP) |
| http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afman33-402/afman33-402.pdf |
| This Air Force Manual (AFMAN) provides guidance for the definition, design, acquisition, implementation and delivery of Business Mission Area (BMA) capabilities using the Service Development and Delivery Process (SDDP). The SDDP is end user-centric to better align the assistance required by an end user to address a process-based problem across a holistic set of Doctrine, Organization, Training, Materiel, Leadership and Education, Personnel, Facilities, and Policy (DOTMLPF-P) solutions. The SDDP details the processes and procedures by which Information Technology (IT) capabilities supporting Air Force (AF) processes are identified, defined, developed and delivered in a way that ensures IT capabilities are necessary, and maximize the potential for successful implementation of IT investments. The SDDP is applicable to large and small scale problems and can be used to implement IT capabilities of all sizes and types. |
| AFMAN 33-153 Information Technology (IT) Asset Management (ITAM) |
| http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afman33-153/afman33-153.pdf |
| This is a total revision to replace and incorporate Air Force Instruction (AFI) 33-112, Information Technology Hardware Asset Management, and AFI 33-114, Software Management, into a single IT asset management manual. This revision incorporates the PWCS asset management portions of AFI 33-106, Managing High Frequency Radios, Personal Wireless Communications Systems, and the Military Affiliate Radio System, to remove that guidance; and identifies Tiered waiver authorities for unit level compliance items. |
| DoDD 5205.02E, Operations Security (OPSEC) Program |
| http://www.dtic.mil/whs/directives/corres/pdf/520502e.pdf |
| Underscores the importance of OPSEC and how it is integrated as a core military capability within Information Operations (IO) that must be followed in daily application of military operations. |
| AFI 10-701, Operations Security (OPSEC) |
| http://static.e-publishing.af.mil/production/1/af_a3_5/publication/afi10-701/afi10-701.pdf |
| This publication provides guidance for all Air Force personnel (military and civilian) and supporting contractors in implementing, maintaining and executing OPSEC programs. It describes the OPSEC process and discusses integration of OPSEC into Air Force plans, operations and support activities. |
| DoD Manual 5200.01, DoD Information Security Program: Overview, Classification, and Declassification, V1-V4 |
| http://www.dtic.mil/whs/directives/corres/pdf/520001_vol1.pdf |
| The purpose of this manual is to implement policy, assign responsibilities, and provide procedures for the designation, marking, protection, and dissemination of controlled unclassified information (CUI) and classified information, including information categorized as collateral, sensitive compartmented information (SCI), and Special Access Program (SAP). |
| DoD 5220.22-M, National Industrial Security Program Operating Manual |
| http://www.dss.mil/documents/odaa/nispom2006-5220.pdf |
| This Manual is issued IAW the National Industrial Security Program (NISP). It prescribes the requirements, restrictions, and other safeguards to prevent unauthorized disclosure of classified information. The Manual controls the authorized disclosure of classified information released by U.S. Government Executive Branch Departments and Agencies to their contractors. It also prescribes the procedures, requirements, restrictions, and other safeguards to protect special classes of classified information, including Restricted Data (RD), Formerly Restricted Data (FRD), intelligence sources and methods information, Sensitive Compartmented Information (SCI), and Special Access Program (SAP) information. These procedures are applicable to licensees, grantees, and certificate holders to the extent legally and practically possible within the constraints of applicable law and the Code of Federal Regulations. |
| Section 508 of the Rehabilitation Act of 1973 |
| http://www.opm.gov/html/508-textOfLaw.asp |
| On August 7, 1998, President Clinton signed into law the Rehabilitation Act Amendments of 1998 which covers access to federally funded programs and services. The law strengthens section 508 of the Rehabilitation Act and requires access to electronic and information technology provided by the Federal government. The law applies to all Federal agencies when they develop, procure, maintain, or use electronic and information technology. Federal agencies must ensure that this technology is accessible to employees and members of the public with disabilities to the extent it does not pose an "undue burden." Section 508 speaks to various means for disseminating information, including computers, software, and electronic office equipment. It applies to, but is not solely focused on, Federal pages on the Internet or the World Wide Web. |
| DoDI 1100.22 Policy and Procedures For Determining Workforce Mix |
| http://www.dtic.mil/whs/directives/corres/pdf/110022p.pdf |
| IAW DoD Directive 5124.02, this Instruction establishes policy, assigns responsibilities, and prescribes procedures for determining the appropriate mix of manpower and private sector support. It implements policy established in DoDD 1100.4 and incorporates and cancels DoDI 3020.37. This Instruction provides manpower mix criteria and guidance for risk assessments to be used to identify and justify activities that are inherently governmental (IG); commercial (exempt from private sector performance); and commercial (subject to private sector performance). It reconciles and consolidates the definitions and examples of IG from section 306 of title 5, U.S.C.; sections 501 (note), 1115, and 1116 of title 31, U.S.C., Attachment A of OMB Circular A-76; and Subparts 2 and 7.503(c) of the FAR into a set of criteria for Defense-wide use. This Instruction also implements aspects of sections 113, 188(b), 129a, and 2463 of title 10, U.S.C., and reissues and cancels DoDI 1100.22. |
| DoDD 8320.1 Data Administration |
| https://acc.dau.mil/adl/en-US/33650/file/6823/DoDD83201%20Data%20Admin.pdf |
| This Instruction applies to the administration and standardization of DoD standard data elements generated within the functional areas of audit and criminal investigations for DoD. It also applies to the administration of DoD standard and non-standard data elements generated, stored, or used by the DoD. Data elements will be administered in ways that provide accurate, reliable, and easily accessible data throughout the DoD, while minimizing cost and redundancy. Data elements will be standardized to meet the requirements for data sharing and interoperability throughout the DoD. Data administration will be encouraged and promoted within the DoD. |
| AFI 33-332, Air Force Privacy and Civil Liberties Program |
| http://static.e-publishing.af.mil/production/1/saf_cio_a6/publication/afi33-332/afi33-332.pdf |
| Records that are retrieved by name or other personal identifier of a U.S. citizen or alien lawfully admitted for permanent residence are subject to Privacy Act requirements and are referred to as a Privacy Act system of records. The Air Force must publish SORNs in the Federal Register, describing the collection of information for new, changed or deleted systems to inform the public and give them a 30 day opportunity to comment before implementing or changing the system. |
| AFI 31-501, Personnel Security Program Management |
| http://static.e-publishing.af.mil/production/1/af_a4_7/publication/afi31-501/afi31-501.pdf |
| Use this instruction with the DOD Regulation 5200.2-R and AFPD 31-5 to implement the personnel security program. This instruction requires collecting and maintaining information protected by the Privacy Act of 1974 authorized by Executive Orders 9397, 9838, 10450, 11652, and 12968; and 5 United States Code (U.S.C.) 7513, 7532, 7533; 10 U.S.C. 8013. |
| AFI 16-1404, Air Force Information Security Program |
| http://static.e-publishing.af.mil/production/1/saf_aa/publication/afi16-1404/afi16-1404.pdf |
| This publication implements Air Force Policy Directive (AFPD) 16-14, Security Enterprise Governance; Department of Defense (DoD) Directive 5210.50, Management of Serious Security Incidents Involving Classfied Information, DoD Instruction (DoDI) 5210.02, Access and Dissemination of RD and FRD, DoDI 5210.83, DoD Unclassified Controlled Nuclear Information (UCNI), DoD Manual (DoDM) 5200.01, DoD Information Security Program, Volume 1, Volume 2, Volume 3, and Volume 4; and DoDm 5200.45, Instructions for Developing Security Classification Guides. |
| Federal Information Security Management Act (FISMA) 2002 |
| http://www.dhs.gov/federal-information-security-management-act-fisma |
| FISMA was enacted as part of the E-Government Act of 2002 to “provide a comprehensive framework for ensuring the effectiveness of information security controls over information resources that support Federal operations and assets,” and also to “provide for development and maintenance of minimum controls required to protect Federal information and information systems.” |
FISMA requires Federal agencies to:
•designate a Chief Information Officer (CIO), •delegate to the CIO authority to ensure compliance with the requirements imposed by FISMA, •implement an information security program, •report on the adequacy and effectiveness of its information security policies, procedures, and practices, •participate in annual independent evaluations of the information security program and practices, and •develop and maintain an inventory of the agency’s major information systems.
FISMA requires the Director of the Office of Management and Budget (OMB) to ensure the operation of a central Federal information security incident center. FISMA makes the National Institute of Standards and Technology (NIST) responsible for “developing standards, guidelines, and associated methods and techniques” for information systems used or operated by an agency or contractor, excluding national security systems.
| ISO/IEC 19770-2, Software Tagging |
| http://www.iso.org/iso/catalogue_detail.htm?csnumber=53670 |
| ISO/IEC 19770-2:2009 establishes specifications for tagging software to optimize its identification and management. (http://en.wikipedia.org/wiki/ISO/IEC_19770) |
FAR CLAUSES
| DFARS 252.227-7015 Technical Data Commercial Items |
| http://farsite.hill.af.mil/reghtml/regs/far2afmcfars/fardfars/dfars/Dfars252_227.htm#P1079_80393 |
| Provides the Government specific license rights in technical data pertaining to commercial items or processes. DoD may use, modify, reproduce, release, perform, display, or disclose data only within the Government. The data may not be used to manufacture additional quantities of the commercial items and, except for emergency repair or overhaul and for covered Government support contractors, may not be released or disclosed to, or used by, third parties without the contractor's written permission. |
| DFARS 252.227-7014 Rights in Noncommercial Computer Software |
| http://farsite.hill.af.mil/reghtml/regs/far2afmcfars/fardfars/dfars/Dfars252_227.htm#P683_47378 |
| Guidance on rights in technical data and computer software small business innovation research (SBIR) program. |
| DFARS 252.227-7017 Identification and Assertion of Use, Release, or Disclosure Restrictions |
| http://farsite.hill.af.mil/reghtml/regs/far2afmcfars/fardfars/dfars/Dfars252_227.htm#P1182_92447 |
| Provides requirements for the identification and assertion of technical data. |
| DFARS 252.227-7013 Rights in Technical Data---Non-commercial Items |
| http://farsite.hill.af.mil/reghtml/regs/far2afmcfars/fardfars/dfars/Dfars252_227.htm#P295_15657 |
| Provides guidelines for rights in technical data on non-commercial items |