AFOTEC_OT_of_IA_Guide _2nd_Edition.pdf

PDF 903 KB Posted

Attached to
OPERATIONAL TEST AND EVALUATION SERVICES (OTES) Federal contract opportunity
Solicitation number
FA7046-11-R-0003
Issued by
Department of the Air Force Materiel Command Test Center

About this file

AFOTEC_OT_of_IA_Guide _2nd_Edition

View the file

Other files for this federal contract opportunity

Other files attached to OPERATIONAL TEST AND EVALUATION SERVICES (OTES), newest first.
File Type Posted
FA7046-11-R-0003-0004.doc DOC document
OTES TO 0003 Amendment 3 - 14 Oct 11.doc DOC document
OTES TO 0003 Amendment 3 - 14 Oct 11.doc DOC document
OTES_RFP_Amendment 2 - 14 Oct 11.doc DOC document
PWS TO_01_Nuclear_Space Amendment 2 - 14 Oct 11.docx DOCX document
OTES Final RFP-PPI QuestionsResponses 14 Oct 11.xls XLS spreadsheet
Section L Amendment 2 - 14 Oct 11.docx DOCX document
Amendment 1Section L 10-7.docx DOCX document
ppi_tool.accdb —
Amendment 1OTES_QASP 10-7.docx DOCX document
AFTECMAN99-101.pdf PDF
Amendment 1 PWS Oct 7.docx DOCX document
Amendment 1 RFP.doc DOC document
Form_4.pdf PDF
Form_6.pdf PDF
Form_2.pdf PDF
Form_1.pdf PDF
Form_5.xfdl XFDL file
Final_ TO_02_Det_5_Bomber_Test_Division.docx DOCX document
Final_Sample_TO_03 JSPDS.docx DOCX document
Form_2.xfdl XFDL file
Form_6.xfdl XFDL file
DRAFT OTES Responses.xlsx XLSX spreadsheet
form_1.xfdl XFDL file
Final_TO_01_Nuclear_Space.docx DOCX document
FINAL OTES_QASP.docx DOCX document
Source_Interested Parties List.xlsx XLSX spreadsheet
JSPDS Task Order 15_Jul_11_AFL.docx DOCX document
AFI_33-200 _Information_Assurance_Program.pdf PDF
OTES CDRLs 27 Jun 11.docx DOCX document
CJCS_Instruction_3170.01G_Joint_Capabilities_Intergration_ _Development_System.pdf PDF
OTES PWS 25_ Jul_ 11_AFL_A.docx DOCX document
TO Nuclear Space 15_JUL_11_AFL.docx DOCX document
AFOTEC_99-101 _Conduct_of_Operational_Test_ _Evaluation.pdf PDF
OTES QASP 2 Aug 11.docx DOCX document
AFI_99-103 _Capabilities-based_Test_ _Evaluation.pdf PDF
Defense_Acquisition_Guidebook_(DAG).pdf PDF
DoD_Directive_5000.1 _The_Defense_Acquisition_System.pdf PDF
DoD_5400.7R _DoD_Freedom_of_Information_Act_(FOIA)_Program _AF_Supplement.pdf PDF
Det 5 Bomber Test Division TO_7_15_11_AFL.docx DOCX document
AFI_16-1002 _Modeling_ _Simulation_(M S)_Support_to_Acquisition.pdf PDF
AFI_33-100 _User_Responsibilities_ _Guidance_for_Information_Systems.pdf PDF
DoD_Instruction_5000.2 _Operation_of_the_Defense_Acquisition_System.pdf PDF
513408p CBRN DoD Implementation Directive.pdf PDF
AFOTEC_OT E_Guide _6th_Edition.pdf PDF
AFMAN_63-119 _Certification_of_System_Readiness_for_Dedicated_Operational_Test_ _Evaluation.pdf PDF
AFI_63-101 _Acquisition_ _Sustainment_Life_Cycle_Management.pdf PDF
DD254.docx DOCX document
DoD_Instruction_8500.2 _Information_Assurance_Implementation.pdf PDF
AFOTECPAM_99-104 _AFOTEC_Operational_Suitability_Test_ _Evaluation_Guide.pdf PDF
Show all 50

OPERATIONAL TEST AND EVALUATION SERVICES (OTES) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PREPARED BY:

AIR FORCE OPERATIONAL TEST AND EVALUATION CENTER

DIRECTOR OF COMMUNICATIONS

AFOTEC OPERATIONAL TESTING (OT)

OF INFORMATION ASSURANCE (IA) GUIDE

nd

Edition

1 July 2009

Refer requests for copies of the OT of IA Guide to AFOTEC/A6, 8500 Gibson Blvd SE, Kirtland AFB, NM

87117-5558

Page Intentionally Left Blank

FORWARD

The AFOTEC OT of IA Guide captures the best practices and corporate knowledge we have gained to effectively and efficiently test and evaluate information assurance.

Specifically, the guide:

Provides organizational-specific information for use across AFOTEC.

Outlines the processes, procedures, checklists, and techniques for addressing information assurance during the various phases of OT&E.

Information assurance shall be evaluated during OT&E for acquisition programs tested by

AFOTEC. Federal Law and DoD Directives require incorporation of information assurance into all phases of an acquisition program’s lifecycle. AFOTEC personnel will work with the respective program offices during early influence to ensure that operational test of information assurance is fully integrated into the test process from its inception. As a Special Interest Item (SII), it is incumbent upon AFOTEC to convey the criticality of the

SII to every test program we conduct in addition to those we support. Test directors will coordinate with the program office and applicable external agencies to accomplish comprehensive information assurance testing and incorporate the IA evaluation into the operational effectiveness and suitability rating of the system under test.

AFOTEC is known for comprehensive, well written test reports that speak directly to the primary issue of a system’s operational effectiveness and suitability. The guidance and samples will assist the test community by providing a solid foundation to accurately plan, test, and evaluate information assurance. Additionally, the OT of IA Guide amplifies

Director, Operational Test and Evaluation’s Procedures for Operational Test and

Evaluation of Information Assurance in Acquisition Programs (21 January 2009).

Stephen T. Sargeant

Major General, USAF

Commander

Record of Changes

Change # Date of Change Title of Change

SUMMARY OF CHANGES:

Incorporates approved Standardized IA Planning and Reporting in OT&E; updated example test plan entries; added additional example test plan entries for Intelligence

Community Directive 503 systems; updated example DMAP entries; added additional example DMAP entries for Intelligence Community Directive 503 systems; incorporated dual rating process to distinguish developer IA control shortfalls from system owner IA control shortfalls; added appendix with standardized IA test report examples for DoDI

8500.2 and Intelligence Community Directive 503 systems; added appendix of acronyms;

added considerations unique to Platform Information Technology (PIT) systems.

FUTURE CHANGES TO THE OT&E GUIDE:

Submit recommendations for future changes to the AFOTEC OT of IA Guide to

AFOTEC/A6 via e-mail.

i

TABLE OF CONTENTS

1. PURPOSE

2. BACKGROUND

3. APPLICABILITY AND SCOPE

4. GENERAL APPROACH

5. IA REQUIREMENTS AND REFERENCES

6. AFOTEC IA OPERATIONAL TESTING PROCESS PURPOSE

6.1 Early Influence

6.2 Initial Test Planning

6.3 Operational Test Planning

6.4 Operational Test Execution and Reporting

6.5 Test Closeout

APPENDICES

APPENDIX A – REFERENCES ....................................................................... A-1

APPENDIX B – GLOSSARY OF IA TERMS . ................................................ B-1 APPENDIX C – ACRONYM LIST . .................................................................. C-1

APPENDIX D – IA-RELATED TEST CAPABILITIES ................................ C-1

APPENDIX E – IA CHECKLIST. ...................................................................... D-1 APPENDIX F – SAMPLE TEST PLAN ENTRIES . ....................................... E-1 APPENDIX G – SAMPLE DMAP ENTRIES. .................................................. F-1

APPENDIX H – IA REPORT SAMPLES . ....................................................... G-1

GUIDANCE FOR OPERATIONAL TESTING

OF INFORMATION ASSURANCE

1 Purpose The Operational Test of Information Assurance (OT of IA) Guide provides

AFOTEC with a consistent approach for assessing and evaluating information assurance

(IA) during operational test activities that aligns with current Department of Defense and

Air Force IA policy and guidance. DoDD 8500.01 defines IA as measures that protect and defend information and information systems by ensuring availability, integrity, authentication, confidentiality and non-repudiation. These measures include providing for restoration of information systems by incorporating protection, detection and reaction capabilities and by providing for Continuity of Operations (COOP). The OT of IA Guide also provides consistency when assessing and evaluating IA of systems developed to

Intelligence Community Directive (ICD) 503 requirements.

2 Background In March 2008, the AFOTEC/CC tasked the Director of Communications

(A6) with codifying AFOTEC’s operational test process for IA. A6, working with representatives from the Intelligence, Analysis and Assessments Directorate (A2A9), Operations Directorate (A3), the Plans and Program Directorate (A5A8), Detachment 3 and Detachment 4, developed the OT of IA guide to describe AFOTEC’s approach to operationally testing IA. In March 2009, A6 was tasked to revise the AFOTEC OT of IA

Guide to incorporate lessons learned and the results of efforts to standardize IA planning and reporting in OT&E. AFOTEC recognizes information and networks must be protected from attack while using technology to link military systems and forces, therefore, AFOTEC considers IA a Special Interest Item and takes the following steps to implement the DOT&E Special Interest Item on IA.

3 Applicability and Scope The OT of IA Guide applies to all AFOTEC Directorates and

Detachments and covers all phases of operational test.

A6 is AFOTEC’s center of excellence for operational testing of IA and is responsible for maintaining the AFOTEC OT of IA Guide. A3 and the gaining Detachment will ensure

IA test requirements are considered for each program during the early influence phase of involvement. Each Detachment will assign IA Subject Matter Expert(s) (SME) to provide the Test Director (TD) IA testing guidance and support during all phases of

OT&E. A6 will provide A3 and Detachment IA SMEs additional technical guidance as needed. IA SME qualifications are described in DoD 8570.01-M, Information Assurance

Workforce Improvement Program Manual. Additional information on IA qualifications is located in IA Requirements and References (Paragraph 5).

4 General Approach AFOTEC, in conjunction with the service OTAs and Joint

Interoperability Test Command (JITC), will ensure adequate IA testing for applicable acquisition systems according to DOT&E IA procedures. AFOTEC will collaborate with applicable external agencies ensuring IA is assessed as early as possible in the acquisition cycle to determine vulnerabilities, risks and mitigating actions. AFOTEC may use integrated developmental test (DT) data to assess and identify significant IA residual risks. When applicable, assessing IA as part of operational assessments (OA) provides insight into progress toward operational effectiveness, operational suitability and system readiness for OT&E. IA evaluations conducted as part of an OT&E will be used in determining operational effectiveness, suitability and overall mission capability. The IA assessment focuses on evaluating the impact of the system’s IA attributes on operational effectiveness, suitability and survivability. Information assurance assessments are accomplished by determining the vulnerabilities and risk associated with the system under test (SUT) or system-of-systems (SoS) under test. The evaluation of IA will reveal the capabilities and limitations of the system’s IA posture and the effectiveness of the applicable IA controls. The evaluation includes protection, detection, reaction and restoration/COOP capabilities and limitations in the presence of realistic information operations (IO) threats and countermeasures (as feasible) using assessment teams to conduct a system vulnerability assessment and penetration testing.

5 IA Requirements and References The program office ensures the system complies with all applicable DoD, Chairman Joint Chiefs of Staff (CJCS), Air Force and Federal

IA policies, regulations and standards. Because of the complexities of IA operational testing in acquisition, AFOTEC/A3 and each Detachment will identify at least one DoD

8570.01-M certified level two IA Management (IAM) subject matter expert (SME) to support testing. AFOTEC mission requirements will dictate the actual number of level two certifications allocated. A6 requires three IA SMEs certified level three under DoD

8570.01. Additional detachment and A6 level three certifications will be considered on a case-by-case basis. Certified IA Technical (IAT) and IAMs will possess the required fundamental IA control knowledge to assess protection, detection, reaction and restoration/COOP capabilities during OT&E against validated threats. The IATs and

IAMs will also help the TD characterize the mission impacts from successful attacks. A listing of applicable references is provided in Appendix A.

6 AFOTEC IA Operational Testing Process

AFOTEC’s test process aligns with the

DOT&E Procedures for Operational Test and Evaluation of Information Assurance in

Acquisition Programs, 21 January 2009. All acquisition programs on the OSD T&E

Oversight list must follow the DOT&E procedures for operational testing of IA, unless they are self-contained systems that do not connect to the Global Information Grid (GIG) and/or National Institute of Standards and Technology (NIST) systems. Commonly, these systems are referred to as Platform Information Technology (PIT) systems. If a program office is considering having their system designated as PIT, they must submit a request to Air Force Network Integration Center (AFNIC)/EV, formerly the Air Force

Communications Agency (AFCA)/EV. While PIT systems have reduced IA requirements compared to GIG-connected systems, they still have IA testing needs and are not waivered for all IA considerations. For PIT systems, AFOTEC IA personnel will review the system’s IA strategy, certification and accreditation efforts and all IA-related developmental testing. AFOTEC’s test team will then make a determination as to whether or not the system’s IA efforts are sufficient and what additional operational testing is required.

The proper conduct of IA testing of acquisition programs requires a collaborative team effort. In general, A3 and the gaining Detachment review documents for required IA verbiage and transition the program to the Detachment after Involvement Determination.

The Detachment IA SME reviews and assists the program office efforts to implement IA

For MOT&E, follow the lead OTA test process as governed by the Memorandum of Agreement on Multi-

Service Operational Test and Evaluation (MOT&E) and Operational Suitability Terminology and

Definitions, Oct 08. The lead OTA should determine which agency to use for conducting vulnerability and penetration testing on Mission Assurance Category (MAC) I, MAC II and MAC III Classified or Sensitive systems.

for their program and to develop/review testable measures. Additionally, IA SMEs assist with conducting IA assessments, coordinating support from external agencies and posting applicable program-related IA documentation on the AFOTEC Management Information

Network. A6 will provide support and guidance in all phases.

6.1 Early Influence

6.1.1 The gaining Detachment, with the assistance of A3O and A6, will use the

DOT&E Procedures for OT&E of IA to determine if the policy applies to the particular program. Early IA activities by the gaining Detachment and A3O include validating that the Program Management Office (PMO) has initiated the DoD Information Assurance Certification and Accreditation Process

(DIACAP). The gaining Detachment, A3O and A6 will develop an understanding of user requirements for the SUT to operate in a secure and net-centric environment. A3O will validate that the PMO has entered the SUT into the AFNIC’s Electronic Information Technology Data Repository (EITDR) for

Air Force managed systems, or other approved database such as the Enterprise

Mission Assurance Support Service (eMASS).

6.1.2 The gaining Detachment IA SME, A3O and A6 confirm Mission Assurance

Category (MAC) and Confidentiality Level (CL) are documented by the program office and user in the IA strategy and Joint Capabilities Integration and Development System (JCIDS) documentation, respectively. A3O and the gaining Detachment IA SME will confirm the adequacy of applicable certification and accreditation documentation, the program’s information support plan (ISP), system CONOPS, Test Evaluation Strategy, TEMP and the

DIACAP Implementation Plan (DIP).

6.1.3 Identifying applicable IA controls for an information system is a critical activity in both the DIACAP and the OT&E process . There are four basic steps in assigning the IA controls: determining the type of information or weapon system (embedded, C4ISR, Automated Information System [AIS], Platform Information Technology products/weapons systems) that have interconnections to external information systems or networks); determining the

MAC and CL for the information system; identifying the baseline IA controls;

and augmenting/modifying baseline IA controls to ensure identification of measures to support operational testing. All IA SMEs should obtain read only permissions in the EITDR to view the Security, Interoperability, Supportability, Sustainability and Usability (SISSU) tab/information for the

SUT to gain insight into the PMO status of these four steps. Information assurance controls in the EITDR are based on MAC and CL should mirror the

DoDI 8500.2 IA controls.

6.1.4 The Detachment IA SME will follow the processes outlined in the AFOTEC

OT&E Guide with support from A3O to develop an initial test design for

OT&E events and resource requirements. In developing the Evaluation

Summary, IA may be incorporated in several ways. If the SUT’s primary function is to provide IA or Computer Network Defense (CND), consider developing an IA critical operational issue (COI). IA may also be a measure of effectiveness (MOE), a measure of suitability (MOS) and/or an operational

See CJCSI 6212.01 for a description of the ISP.

Systems subject to ICD 503 also use the terms ―Level of Concern‖, ―Protection Level‖ and ‖Security

Features and Assurances‖.

capability (OC) with associated measures across applicable COIs. Align measures (Appendices D and E) under applicable COIs. Identify any operational conditions applicable to IA.

6.1.5 In developing a TES/TEMP input, the Detachment IA SME and A3O will include certification strategies (or risk reduction efforts) for IA, as applicable.

The assessment teams should be identified in part II of the TEMP and the assessment resources should be identified in part V. In particular, while conducting an Operational IA vulnerability assessment, all MAC I and II systems and sensitive or classified MAC III systems require a technical and non-technical assessment of technology, people, policy and processes.

Technical assessments include vulnerability assessments using approved assessment tools and penetration testing. Non-technical assessments focus on

IA strategy, certification status and implementation of IA policy and processes.

These same systems require a protection, detection, reaction and restoration/COOP evaluation for an OT&E. Organizations to conduct these assessments/evaluations for DoD 8500 systems include the Service information warfare centers, JITC or National Security Agency (NSA).

When arranging technical testing for ICD 503 systems, ensure that the agency is certified by the

Defense Intelligence Agency (DIA) to perform these tests. The assessment teams should also be invited to participate in all integrated test team (ITT) meetings to ensure required penetration testing/vulnerability assessments are completed prior to IOT&E. The TES/TEMP should also include resource requirements in the resource section (TEMP, part V).

6.1.6 If an early operational assessment is planned, the Detachment IA SME will address IA control implementation progress, IA documentation, IA design and

IA test assets.

6.2 Initial Test Planning (All actions will be conducted by the Detachment IA SME)

6.2.1 Identify and contact the appointed SUT IAM. Review PMO implementation and validation of assigned IA Controls. The DIP execution, validation activities, IT Security Plan of Action and Milestones (POA&M) and the

DIACAP Scorecard are also reviewed.

6.2.2 Plan to assess or evaluate IA control implementation to determine the system’s ability to meet the IA capabilities. Evaluation of the IA controls is easily adaptable to risk management/assessment and provides criteria for entering the dedicated phase of OT&E. The system must conform to the IA controls to receive its interim authorization to operate (IATO) or authority to operate

(ATO), a readiness entrance criterion for OT&E.

6.2.3 Use actual developmental test and evaluation (DT&E) results when appropriate. Record DT&E results according to the criteria and protocols specified in the validation procedure and include these as parts of the comprehensive DIACAP package, along with any artifacts produced during the validation (e.g., output from automated test tools or screen shots that depict aspects of system configuration).

6.2.4 Identify IA test capability requirements (Appendix D) and potential test venues/simulated scenarios.

The 92 Information Operations Squadron at the 688th Information Operations Wing, performs vulnerability assessments and the 57 IAS at the Air Force Warfare Center, is developing an IA Technical

Assessment (penetration test team) capability that may support these efforts. NSA primarily supports exercises and assessments of other government agencies (acquisition program support is very limited). See

Appendix D for contact information.

6.2.5 Review tasks the PMO will perform to achieve test readiness certification, particularly those tasks related to IA certification of the system. Determine which tasks and deliverables require status monitoring and assign actions through ITT meetings as applicable.

6.2.6 Monitor the preparation of an IT Security POA&M.

6.2.7 Ensure the ITT charter includes IA-related roles and responsibilities.

6.3 Operational Test Planning

6.3.1 Refine the IA operational test measures and evaluation criteria or identify standards (Appendix F). Contact the selected assessment/evaluation team to participate in the test planning process to scope the test. Ensure the assessment team capabilities are commensurate with the threat and expected risks for the program. Begin coordinating approval for IA test teams to access the SUT.

Coordination and approval timelines for Sensitive Compartmented Information

(SCI) level systems may require additional clearances and coordination through the lead OTA. Update test resource plan and TEMP to include costs associated with the assessment team vulnerability/penetration testing. Use the checklist in Appendix E. Use Appendix F as a basis for developing the operational test plan and Appendix G for data management and analysis plan

(DMAP) development.

6.3.2 For programs on DOT&E oversight, obtain informal DOT&E action officer coordination/concurrence to use available DT&E IA data. If DOT&E concurs, use DT&E IA data during Operational Test Readiness Review (OTRR) including electronic warfare (e.g., jamming) and anti-tamper countermeasures

(see AFMAN 63-119, Certification of System Readiness for Dedicated

Operational Testing). Review DIACAP package for status of the assigned

DoDI 8500.2 IA controls. Use the appropriate IA Test Support Checklist available via the link provided in Appendix A.

6.3.3 Detachment IA SME will confirm status of DIACAP package, IATO or ATO memo from designated accrediting authority (DAA) via Certification Authority as entrance criteria for OTRR.

6.4 Operational Test Execution and Reporting

6.4.1 For all test events other than OT&E, conduct assessment according to actions identified in Step 4 of the DOT&E Procedures for Operational Test and

Evaluation of Information Assurance in Acquisition Programs and follow measures detailed in the test plan. Apply measures and evaluation criteria as explained in Appendix F.

6.4.2 For all OT&E events, conduct an evaluation in the operational environment as feasible. Reference Steps 4 through 6 of the DOT&E Procedures for

Operational Test and Evaluation of Information Assurance in Acquisition

Programs and as detailed in the test plan (see Appendix F for examples).

6.4.3 Report results by aggregating external assessment reports, including applicable

DT&E data, into AFOTEC’s final report (see Appendix H for examples).

Develop test team estimate of the level of IA risk to include operational interoperability and key interface protocols. Test team estimates are reported under the net-ready key performance parameter or under IA specific measures, as appropriate.

6.5 Test Closeout

The TD, with assistance of the Detachment IA SME, will submit IA operational testing lessons learned and best practices.

A-1

APPENDIX A - REFERENCES

1 Key IA Documents

a) DOT&E Procedures for Operational Test and Evaluation of Information

Assurance in Acquisition Programs, 21 Jan 2009

b) DoDI 5000.02, Operation of the Defense Acquisition System, 2 Dec 2008

c) DoDD 8500.01, Information Assurance (IA), 9 Jul 2004

d) DoDI 8500.2, Information Assurance (IA) Implementation, 6 Feb 2003

e) DoDI 8580.1, Information Assurance (IA) in the Defense Acquisition System, 9 Jul 2004

f) DoDD 8581.1E, Information Assurance (IA) Policy for Space Systems Used by the Department of Defense, 21 Jun 2005

g) National Institute of Standards and Technology (NIST) special publication

(SP) 800-series (multiple publications/dates)

h) Intelligence Community Directive (ICD) 503, Intelligence Community

Information Technology Systems Security: Risk Management, Certification and Accreditation, 15 Sep 2008

i) AF 33-series publications (multiple publications/dates)

j) AFI 99-103, Capabilities-Based Test and Evaluation, 26 Feb 2008

k) Chairman Joint Chiefs of Staff Instruction (CJCSI) 6212.01E, Interoperability and Supportability of Information Technology and National Security Systems, 8 Mar 2006

2 Key IA Operational Test Planning Documents

a) DoDI 8510.01, DoD Information Assurance Certification and Accreditation

Process (DIACAP), 28 Nov 2007 (for acquisition program management and test activities)

b) AFMAN 63-119, Certification of System Readiness for Dedicated

Operational Testing, 20 Jun 2008, Attachment 10, Information Technology

(IT) and National Security Systems (NSS)

c) CJCSI 3170.1, Joint Capabilities Integration and Development System, 11

May 2005

d) CJCSI 6510.01, Information Assurance (IA) and Computer Network Defense

(CND), 15 Aug 2007

e) Defense Acquisition Guidebook (DAG), sections 4.4.15, 7.2, 7.5 and 9.9.2

(multiple chapterss/dates, for system development and testing considerations)

f) JCIDS documents (multiple publications/dates, for IA requirements)

g) AFPD 10-20, Air Force Defensive Counterinformation (DCI) Operations, 1

Oct 1998

h) AFDD 2-5, Information Operationsand system CONOPS (11 Jan 2005, for operational scenarios)

i) AFI 10-2001, Defensive Counterinformation Planning, Operations and

Assessment, 4 Oct 2001

3 IA Technical Framework (IATF) Integrated architecture products described in the

DoD Architecture Framework (DoDAF) are found at: https://dars1.army.mil

4 IA-Related Test Capabilities As identified in Appendix D.

https://dars1.army.mil/

A-2

5 IA-Related Courses These courses can be accessed online at:

http://iac.dtic.mil/iatac/training.html and https://golearn.csd.disa.mil. IA-specific training, education and certification are governed by DoDD 8570.01, Information

Assurance Training, Certification, and Workforce Management, 15 Aug 2004

(certified current as of 23 Apr 2007) and DoDD 8570.01M, Information Assurance

Workforce Improvement Program, 19 Dec 2005, Change 1, 15 May 2008.

6 Key IA Websites.

a) IA Test Support Checklists: Access available through the AFOTEC portal, Communications (A6), A6 Information Assurance Division, IA OT&E Branch or

(https://infonet.afotec.af.mil/directorates/a6/a6m/IA%20OT_E%20Branch.cfm)

b) IA document library (http://iase.disa.mil/index2.html)

c) IA technology analysis center (http://iac.dtic.mil/iatac/)

d) DIACAP Knowledge Service (https://diacap.iaportal.navy.mil)

e) IA Community of Practice

(https://afkm.wpafb.af.mil/ASPs/CoP/OpenCoP.asp?Filter=OO-SC-IA-01)

f) Defense Acquisition Guidebook, select Chapter 7.5 for IA

(https://akss.dau.mil/dag/DoD5000.asp?view=functional) http://iac.dtic.mil/iatac/training.html https://golearn.csd.disa.mil/ https://www.my.af.mil/gcss-af/USAF/ep/globalTab.do?channelPageId=s6925EC13330E0FB5E044080020E329A9&parentCategoryId=p6925EC14A21B0FB5E044080020E329A9 https://www.my.af.mil/gcss-af/USAF/ep/browse.do?categoryId=p6925EC14A21B0FB5E044080020E329A9&channelPageId=s6925EC13330E0FB5E044080020E329A9&parentCategoryId=p6925EC14A21B0FB5E044080020E329A9 https://www.my.af.mil/gcss-af/USAF/ep/browse.do?programId=t6925EC2ACC770FB5E044080020E329A9&channelPageId=s6925EC13330E0FB5E044080020E329A9&parentCategoryId=p6925EC14A21B0FB5E044080020E329A9 https://infonet.afotec.af.mil/directorates/a6/a6m/IA%20OT_E%20Branch.cfm http://iase.disa.mil/index2.html http://iac.dtic.mil/iatac/ https://diacap.iaportal.navy.mil/ https://afkm.wpafb.af.mil/ASPs/CoP/OpenCoP.asp?Filter=OO-SC-IA-01 https://akss.dau.mil/dag/DoD5000.asp?view=functional

B-1

APPENDIX B - GLOSSARY OF IA TERMS

Accreditation Decision. A formal statement by a designated accrediting authority (DAA) regarding acceptance of the risk associated with operating a DoD information system (IS) and expressed as an authorization to operate (ATO), interim ATO (IATO)or denial of

ATO (DATO). The accreditation decision may be issued in hard copy with a traditional signature or issued electronically, signed with a DoD public key infrastructure (PKI)-certified digital signature.

Adequate Security. Security commensurate with the risk and magnitude of harm resulting from the loss, misuse or unauthorized access to or modification of information.

Adequate security includes assuring DoD information systems operate effectively and provide appropriate confidentiality, integrity and availability, through implementation of assigned IA Controls. The DoD methodology for determining assigned IA Controls is defined in DoDI 8500.1 and the baseline DoD management, personnel, operational and technical IA Controls are established in DoDI 8500.2

Artifacts. System policies, documentation, plans, test procedures, test results and other evidence that express or enforce the information assurance (IA) posture of the DoD IS.

They make up the certification and accreditation (C&A) information and provide evidence of compliance with the assigned IA controls.

Assigned IA Controls. The set of IA controls a given DoD IS must address to achieve an adequate IA posture. Consist of baseline IA controls plus any augmenting IA controls.

Augmenting IA Controls. IA controls that augment baseline IA controls to address special security needs or unique requirements (e.g., cross security domain solutions, health information portability, privacy, etc.) of the IS(s) to which they apply.

Augmenting IA controls may originate from a mission area (MA), a DoD Component, a

Community of Interest or a local system. Augmenting IA controls must neither contradict nor negate DoD baseline IA controls and must not degrade interoperability across the DoD Enterprise.

Authorization Termination Date (ATD). The date assigned by the DAA indicating when an ATO or IATO expires.

Authorization to Operate (ATO). Authorization granted by a designated accrediting authority (DAA) for a DoD IS to process, store or transmit information. An ATO indicates a DoD IS has adequately implemented all assigned IA controls to the point where residual risk is acceptable to the DAA. ATOs may be issued for up to 3 years.

Baseline IA Controls. The minimum set of IA controls that must be addressed to achieve adequate security. Baseline IA controls are prescribed by DoDI 8500.2 (Reference (d)) based on mission assurance category (MAC) and confidentiality level (CL).

Certification. For the purpose of the OT of IA guide, a comprehensive evaluation and validation of a DoD IS to establish the degree to which it complies with assigned IA controls based on standardized procedures.

B-2

Certification Determination. A Certifying Authority’s (CA) determination of the degree to which a system complies with assigned IA controls based on validation results. It identifies and assesses the residual risk with operating a system and the costs to correct or mitigate IA security weaknesses as documented in the Information Technology (IT)

Security POA&M.

Certifying Authority (CA). The senior official having the authority and responsibility for the certification of ISs governed by a DoD Component IA program.

Communities of Interest. The inclusive term used to describe groups of individuals who share information relative to common goals, interests, missions or business processes.

Confidentiality Level (CL). Applicable to DoD information systems, the confidentiality level is primarily used to establish acceptable access factors, such as requirements for individual security clearances or background investigations, access approvals and need-to-know determinations; interconnection controls and approvals; and acceptable methods by which users may access the system (e.g., intranet, Internet, wireless). The DoD has three defined confidentiality levels: classified, sensitive and public.

Denial of Authorization to Operate (DATO). A DAA decision that a DoD IS cannot operate because of an inadequate IA design, failure to adequately implement assigned IA controls or other lack of adequate security. If the system is already operational, the operation of the system is halted.

Designated Approval Authority (DAA). The official with the authority to formally assume responsibility for operating a system at an acceptable level of risk. The term is synonymous with designated accrediting authority.

Developer. Entity responsible for designing and implementing the acquisition system.

The developer must make sure their system is designed with the best information assurance practices as dictated by DoD and Federal Government policy. The developer will make sure all hardware and software elements conform to recognized standards (e.g., Federal Information Processing Standards [FIPS], National Information Assurance

Partnership [NIAP]) prior to the system being placed in operation.

DIACAP Implementation Plan (DIP). Contains the IS’s assigned IA controls. The plan also includes the implementation status, responsible entities, resources and the estimated completion date for each assigned IA control. The plan may reference applicable supporting implementation material and artifacts.

DIACAP Knowledge Service (KS). A web-based repository of information and tools for implementing the DIACAP, which is maintained through the DIACAP Technical

Advisory Group (TAG).

DIACAP Package. The collection of documents or collection of data objects generated through DIACAP implementation for an IS. A DIACAP package is developed through implementing the activities of the DIACAP and maintained throughout a system’s life cycle. Information from the package is made available as needed to support an accreditation or other decision such as a connection approval.

B-3

DIACAP Scorecard. A summary report that succinctly conveys information on the IA posture of a DoD IS in a format that can be exchanged electronically. It shows the implementation status of a DoD IS’s assigned IA controls (i.e., compliant (C), non compliant (NC) or not applicable (NA)) as well as the C&A status.

DIACAP Team. Comprised of the individuals responsible for implementing the

DIACAP for a specific DoD IS. At a minimum the DIACAP Team includes the DAA, the CA, the DoD IS program manager (PM) or system manager (SM), the DoD IS IA manager (IAM), IA officer (IAO) and a user representative (UR) or their representatives.

DIACAP Technical Advisory Group (TAG). A formally chartered body established by the Assistant Secretary of Defense for Networks and Information Integration/DoD Chief

Information Officer. Examines and address common C&A issues, including changes to the baseline IA controls across the DoD Component IA programs, IA Communities of

Interest and other GIG entities. The DIACAP TAG also maintains configuration control and management of the DIACAP and all its supporting content on the DIACAP KS.

DoD-Controlled IS. An IS that is established only for DoD purposes, dedicated to DoD processing and is effectively under DoD configuration control (e.g., Net-Centric

Enterprise Services).

DoD Information Assurance Certification and Accreditation Process (DIACAP). The

DoD process for identifying, implementing, validating, certifying and managing IA capabilities and services, expressed as IA controls. Authorizes the operation of DoD ISs, including testing in a live environment, in accordance with statutory, Federal and DoD requirements.

Global Information Grid (GIG). The globally connected, end-to-end set of information capabilities, associated processes and personnel for collecting, processing, storing, disseminating and managing information on demand to warfighters, policy makers and support personnel.

Implementation Procedures. Procedures describing the required steps and guidance for implementing DoD IA controls. Implementation procedures are found in the DIACAP

KS.

Information Assurance (IA). Measures that protect and defend information and information systems by ensuring their availability, integrity, authentication, confidentiality and non-repudiation. These measures include providing for restoration of information systems by incorporating protection, detection and reaction capabilities.

Availability. Timely, reliable access to data and information services for authorized users.

Integrity. Quality of an information system reflecting the logical correctness and reliability of the operating system. The logical completeness of the hardware and software implementing the protection mechanisms and the consistency of the data structures and occurrence of the stored data.

B-4

Authentication. Security measures designed to establish the validity of a transmission, message or originator. A means of verifying an individual’s authorization to receive specific categories of information.

Confidentiality. Assurance that information is not disclosed to unauthorized entities or processes.

Non-repudiation. Assurance the sender of data is provided with proof of delivery and the recipient is provided with proof of the sender’s identity, so neither can later deny having processed the data.

Restoration. (capability) to restore the information system to a fully functional and trusted state.

Protection. (capability) to keep information systems away from intentional, unintentional and natural threats; preclude an adversary from gaining access to information for the purpose of destroying, corrupting or manipulating such information; deny use of information systems to access, manipulate and transmit mission-essential information.

Detection. (capability) to discover threat activity within information systems, such as initial intrusions, during the threat activity or post-activity.

Reaction. (capability) to respond to threat activity within information systems when detected and mitigate the consequences by taking appropriate action.

IA Certification and Accreditation. The standard DoD approach for identifying information security requirements, providing security solutions and managing the security of DoD information systems.

IA Control. An objective IA condition of integrity, availability or confidentiality achieved through the application of specific safeguards or through the regulation of specific activities that is expressed in a specified format (i.e., a control number, a control name, control text and a control class). Specific management, personnel, operational and technical controls are applied to each DoD information system to achieve an appropriate level of integrity, availability and confidentiality.

IA-Enabled Information Technology Product. Product or technology whose primary role is not security, but which provides security services as an associated feature of its intended operating capabilities. Examples include such products as security-enabled web browsers, screening routers, trusted operating systems and security-enabled messaging systems.

IA Manager (IAM). The individual responsible for the information assurance program of a DoD information system or organization. While the term IAM is favored within the

DoD, it may be used interchangeably with the IA title Information Systems Security

Manager (ISSM).

IA Product. Product or technology whose primary purpose is to provide security services

(e.g., confidentiality, authentication, integrity, access control, nonrepudiation of data), B-5 correct known vulnerabilities and provide layered defense against various categories of non-authorized or malicious penetrations of information systems or networks. Examples include such products as data encryptors, firewalls and intrusion detection devices.

Impact Code. A code indicating the consequences of a non-compliant IA control. It is an indicator of the impact associated with exploitation of the IA control.

High Impact Code. The absence or incorrect implementation of the IA control may have a severe or catastrophic effect on system operations, management, or information sharing. Exploitation of the weakness may result in the destruction of information resources and/or the complete loss of mission capability.

Medium Impact Code. The absence or incorrect implementation of the IA control may have a serious adverse effect on system operations, management, or information sharing. Exploitation of the weakness may result in loss of information resources and/or the significant degradation of mission capability.

Low Impact Code. The absence or incorrect implementation of the IA control may have a limited adverse effect on system operations, management, or information sharing. Exploitation of the weakness may result in temporary loss of information resources and/or limit the effectiveness of mission capability.

Information System (IS). Set of information resources organized for the collection, storage, processing, maintenance, use, sharing, dissemination, disposition, display or transmission of information.

Information Technology (IT). See Information System.

Interim Authorization to Operate (IATO). A temporary authorization to operate a DoD

IS under the conditions or constraints enumerated in the accreditation decision.

IT Security Plan of Action and Milestones (POA&M). A permanent record identifying tasks to be accomplished in order to resolve security weaknesses. Required for any accreditation decision that requires corrective actions, it specifies resources required to accomplish the tasks enumerated in the plan and milestones for completing the tasks.

Also used to document DAA-accepted non-compliant IA controls and baseline IA controls that are not applicable. An IT Security POA&M may be active or inactive throughout a system’s life cycle as weaknesses are newly identified or closed.

Mission Area (MA). A defined area of responsibility with functions and processes that contribute to mission accomplishment.

Mission Assurance. A process to ensure that assigned tasks or duties can be performed in accordance with the intended purpose or plan. It is a summation of the activities and measures taken to ensure that required capabilities and all supporting infrastructures are available to the DoD to carry out the National Military Strategy. It links numerous risk management program activities and security related functions—such as force protection;

antiterrorism; critical infrastructure protection; information assurance; continuity of operations; chemical, biological, radiological, nuclear, and high-explosive defense;

readiness; and installation preparedness—to create the synergistic effect required for

B-6

DoD to mobilize, deploy, support, and sustain military operations throughout the continuum of operations.

Mission Assurance Category (MAC). Applicable to DoD systems, the mission assurance category reflects the importance of information relative to the achievement of DoD goals and objectives, particularly the warfighters' combat mission. Mission assurance categories are primarily used to determine the requirements for availability and integrity.

The DoD has three defined mission assurance categories:

Mission Assurance Category I (MAC I). Systems handling information that is determined to be vital to the operational readiness or mission effectiveness of deployed and contingency forces in terms of both content and timeliness. The consequences of loss of integrity or availability of a MAC I system are unacceptable and could include the immediate and sustained loss of mission effectiveness. MAC I systems require the most stringent protection measures.

Mission Assurance Category II (MAC II). Systems handling information that is important to the support of deployed and contingency forces. The consequences of loss of integrity are unacceptable. Loss of availability is difficult to deal with and can only be tolerated for a short time. The consequences could include delay or degradation in providing important support services or commodities that may seriously impact mission effectiveness or operational readiness. MAC II systems require additional safeguards beyond best practices to ensure adequate assurance.

Mission Assurance Category III (MAC III). Systems handling information that is necessary for the conduct of day-to-day business, but does not materially affect support to deployed or contingency forces in the short-term. The consequences of loss of integrity or availability can be tolerated or overcome without significant impacts on mission effectiveness or operational readiness. The consequences could include the delay or degradation of services or commodities enabling routine activities. MAC III systems require protective measures, techniques or procedures generally commensurate with commercial best practices.

Net-Centric. Relating to or representing the attributes of net-centricity. Net-centricity is a robust, globally interconnected network environment (including infrastructure, systems, processes and people) in which data is shared timely and seamlessly among users, applications and platforms. Net-centricity enables substantially improved military situational awareness and significantly shortened decision making cycles. Net-centric capabilities enable network-centric operations and net-centric warfare.

Platform Information Technology (PIT). PIT refers to computer hardware and software resources that are physically part of, dedicated to or essential in real time to the mission performance of special purpose systems (weapons, training simulators, diagnostic test and maintenance equipment, medical technologies, transport vehicles, etc.). PIT systems reside on a platform performing a war-fighting mission or performing a special-purpose mission. PIT may be physically part of the platform on which it resides, may be stand-alone and may have an interconnection to other PIT (known as a ―PIT-to-PIT

Interconnection‖ or ―PITI‖). PIT does not refer collectively to all IT aboard a platform, but rather to a specific IT system or IT component performing a special-purpose mission.

B-7

Program Management Office (PMO). The organization with responsibility for and authority to accomplish program or system objectives for development, production and sustainment to meet the user’s operational needs.

Residual Risk. Portion of risk remaining after security measures have been applied.

Stand-Alone Information System. An information system operating independently of and without interconnection to any other information system.

System Assurance. The justified measure of confidence that the system functions as intended and is free of exploitable vulnerabilities, either intentionally or unintentionally designed or inserted as part of the system at any time during the life cycle.

System of Systems (SoS). A set or arrangement of interdependent systems related or connected to provide a given capability. The loss of any part of the system will degrade the performance or capabilities of the whole. An example of a SoS could be interdependent information systems. While individual systems within the SoS may be developed to satisfy the peculiar needs of a given user group (like a specific Service or agency) the information they share is so important the loss of a single system may deprive other systems of the data needed to achieve even minimal capabilities.

System Owner. Entity that manages and operates the system in its intended working environment. System owner includes senior leadership, information assurance professionals, system administrators and users. The system owner will make sure proper policies and procedures are established to conform to DoD and Federal Government information assurance guidance during the entire life cycle of the system.

Validation. Activity applied throughout the system’s life cycle to confirm or establish by testing, evaluation, examination, investigation or competent evidence a DoD IS’s assigned IA controls are implemented correctly and are effective in their application.

Validation Procedure. Preparatory steps and conditions, actual validation steps, expected results and criteria and protocols for recording actual results that are used for validating

IA controls. May include associated supporting background material, sample results or links to automated testing tools.

Web Services. Self-describing, self-contained, modular units of software application logic that provide defined business functionality. Web services are consumable software services that typically include some combination of business logic and data. Web services can be aggregated to establish a larger workflow or business transaction.

Inherently, the architectural components of Web services support messaging, service descriptions, registries and loosely coupled interoperability.

C-1

APPENDIX C - ACRONMS

ACRONYM MEANING

AFOTEC Air Force Operational Test and Evaluation Center

ACTFAST

Air Traffic Control Communications Test Facility and Avionics

Systems Test

AFCA Air Force Communications Agency

AFNIC Air Force Network Integration Center

AFWC Air Force Warfare Center

AIS Automated Information System

ATAF AFOTEC Test & Analysis Facility

ATD Authorization Termination Date

ATO Authority to Operate

C Compliant

C&A Certification and Accreditation

C2ISR Command and Control, Intelligence, Surveillance and Reconnaissance

C4ISR

Command, Control, Communications, Computers, Intelligence, Surveillance and Reconnaissance

CA Certifying Authority

CCB Configuration Control Board

CDD Capability Development Document

CENTER Consolidated Enterprise Network T&E Range

CERT Computer Emergency Response Team

CIA Confidentiality, Integrity and Availability

CINC Commander in Chief

CJCS Chairman, Joint Chiefs of Staff

CJCSI Chairman, Joint Chiefs of Staff Instruction

CL Confidentiality Level

CM Configuration Management

CND Computer Network Defense

CNO Computer Network Operation

CNSSI Committee on National Security Systems Instruction

COA Course of Action

COI Critical Operational Issue

COMSEC Communications Security

CONOPS Concept of Operations

COOP Continuity of Operations

COTS Commercial Off The Shelf

CPD Capability Production Document

CT Core Team

DAA Designated Accrediting Authority/Designated Approval Authority

C-2

DAG Defense Acquisition Guidebook

DATO Denial of Authority to Operate

DCI Director, Central Intelligence or Defensive Counterinformation

DCID Director, Central Intelligence Directive

Det Detachment

DIA Defense Intelligence Agency

DIACAP DoD Information Assurance Certification and Accreditation Process

DIP DIACAP Implementation Plan

DISA Defense Information Systems Agency

DISN Defense Information Switched Network

DITSCAP

DoD Information Technology Security Certification and Accreditation

Process

DMAP Data Management and Analysis Plan

DoD Department of Defense

DoDAF DoD Architecture Framework

DoDD Department of Defense Directive

DoDI Department of Defense Instruction

DOT&E Director, Operational Test and Evaluation

DRP Disaster Recovery Plan

DT Developmental Test

DT&E Developmental Test and Evaluation

ECD Estimated Completion Date

EITDR Electronic Information Technology Data Repository eMASS Enterprise Mission Assurance Support Service

EOA Early Operational Assessment

EWS Electronic Warfare Squadron

FIPS Federal Information Processing Standards

FOUO For Official Use Only

FTP File Transfer Protocol

GIG Global Information Grid

GOTS Government Off The Shelf

I&A Identification and Authentication

IA Information Assurance

IAM IA Manager

IAO IA Officer

IAT IA Technical

IATAC Information Assurance Technology Analysis Center

IATF IA Technical Framework

IATO Interim Authorization to Operate

IAVA Information Assurance Vulnerability Alert

IAVM Information Assurance Vulnerability Management

C-3

ICD Intelligence Community Directive

ID Identification

IDS Intrusion Detection System

INFOCON Information Operation Condition

IO Information Operations

IOS Information Operations Squadron

IO-Sim Information Operation Simulation

IOT&E Initial Operational Test and Evaluation

IOW Information Operations Wing

IS Information System

ISP Information Support Plan

ISSM Information Systems Security Manager

ISSO Information Systems Security Officer

IT Information Technology

ITT Integrated Test Team

JCIDS Joint Capabilities Integration and Development System

JIAL Joint Information Assurance Laboratory

JITC Joint Interoperability Test…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .