DoD_Instruction_8500.2 _Information_Assurance_Implementation.pdf

PDF 413 KB Posted

Attached to
OPERATIONAL TEST AND EVALUATION SERVICES (OTES) Federal contract opportunity
Solicitation number
FA7046-11-R-0003
Issued by
Department of the Air Force Materiel Command Test Center

About this file

DoD_Instruction_8500.2 _Information_Assurance_Implementation

View the file

Other files for this federal contract opportunity

Other files attached to OPERATIONAL TEST AND EVALUATION SERVICES (OTES), newest first.
File Type Posted
FA7046-11-R-0003-0004.doc DOC document
OTES TO 0003 Amendment 3 - 14 Oct 11.doc DOC document
OTES TO 0003 Amendment 3 - 14 Oct 11.doc DOC document
OTES_RFP_Amendment 2 - 14 Oct 11.doc DOC document
PWS TO_01_Nuclear_Space Amendment 2 - 14 Oct 11.docx DOCX document
OTES Final RFP-PPI QuestionsResponses 14 Oct 11.xls XLS spreadsheet
Section L Amendment 2 - 14 Oct 11.docx DOCX document
Amendment 1Section L 10-7.docx DOCX document
ppi_tool.accdb —
Amendment 1OTES_QASP 10-7.docx DOCX document
AFTECMAN99-101.pdf PDF
Amendment 1 PWS Oct 7.docx DOCX document
Amendment 1 RFP.doc DOC document
Form_4.pdf PDF
Form_6.pdf PDF
Form_2.pdf PDF
Form_1.pdf PDF
Form_5.xfdl XFDL file
Final_ TO_02_Det_5_Bomber_Test_Division.docx DOCX document
Final_Sample_TO_03 JSPDS.docx DOCX document
Form_6.xfdl XFDL file
DRAFT OTES Responses.xlsx XLSX spreadsheet
form_1.xfdl XFDL file
Final_TO_01_Nuclear_Space.docx DOCX document
Form_2.xfdl XFDL file
FINAL OTES_QASP.docx DOCX document
Source_Interested Parties List.xlsx XLSX spreadsheet
JSPDS Task Order 15_Jul_11_AFL.docx DOCX document
AFI_33-200 _Information_Assurance_Program.pdf PDF
OTES CDRLs 27 Jun 11.docx DOCX document
CJCS_Instruction_3170.01G_Joint_Capabilities_Intergration_ _Development_System.pdf PDF
Det 5 Bomber Test Division TO_7_15_11_AFL.docx DOCX document
AFI_16-1002 _Modeling_ _Simulation_(M S)_Support_to_Acquisition.pdf PDF
AFI_33-100 _User_Responsibilities_ _Guidance_for_Information_Systems.pdf PDF
DoD_Instruction_5000.2 _Operation_of_the_Defense_Acquisition_System.pdf PDF
513408p CBRN DoD Implementation Directive.pdf PDF
AFOTEC_OT E_Guide _6th_Edition.pdf PDF
AFMAN_63-119 _Certification_of_System_Readiness_for_Dedicated_Operational_Test_ _Evaluation.pdf PDF
AFI_63-101 _Acquisition_ _Sustainment_Life_Cycle_Management.pdf PDF
DD254.docx DOCX document
AFOTEC_OT_of_IA_Guide _2nd_Edition.pdf PDF
OTES PWS 25_ Jul_ 11_AFL_A.docx DOCX document
TO Nuclear Space 15_JUL_11_AFL.docx DOCX document
AFOTEC_99-101 _Conduct_of_Operational_Test_ _Evaluation.pdf PDF
OTES QASP 2 Aug 11.docx DOCX document
AFI_99-103 _Capabilities-based_Test_ _Evaluation.pdf PDF
Defense_Acquisition_Guidebook_(DAG).pdf PDF
DoD_Directive_5000.1 _The_Defense_Acquisition_System.pdf PDF
DoD_5400.7R _DoD_Freedom_of_Information_Act_(FOIA)_Program _AF_Supplement.pdf PDF
AFOTECPAM_99-104 _AFOTEC_Operational_Suitability_Test_ _Evaluation_Guide.pdf PDF
Show all 50

OPERATIONAL TEST AND EVALUATION SERVICES (OTES) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Department of Defense

INSTRUCTION

NUMBER 8500.2

February 6, 2003

ASD(C3I)

SUBJECT: Information Assurance (IA) Implementation

References: (a) DoD Directive 8500.1, "Information Assurance," October 24, 2002

(b) DoD 5025.1-M, "DoD Directives System Procedures," current edition

(c) National Security Telecommunications and Information Systems

Security Instruction (NSTISSI) No. 4009, "National Information Systems Security Glossary," September 2000 1

(d) DoD Directive 8000.1, "Management of DoD Information Resources and Information Technology," February 27, 2002

(e) through (ah), see enclosure 1

1. PURPOSE

This Instruction:

1.1. Implements policy, assigns responsibilities, and prescribes procedures for applying integrated, layered protection of the DoD information systems and networks under reference (a).

1.2. Authorizes the publication of DoD 8500.2-H, consistent with DoD 5025.1-M (reference (b)).

1 Available at http://www.nstissc.gov/html/library.htm

../pdf2/d85001p.pdf ../pdf2/p50251m.pdf ../pdf2/d80001p.pdf

2. APPLICABILITY AND SCOPE

This Instruction applies to the Office of the Secretary of Defense, the Military Departments, the Chairman of the Joint Chiefs of Staff, the Combatant Commands, the Inspector General of the Department of Defense, the Defense Agencies, the DoD Field Activities, and all other organizational entities in the Department of Defense (hereafter referred to collectively as "the DoD Components").

3. DEFINITIONS

Terms used in this Instruction are defined in reference (c) or enclosure 2.

4. POLICY

This Instruction implements the policies established in DoD Directive 8500.1 (reference (a)).

5. RESPONSIBILITIES

5.1. The Assistant Secretary of Defense for Command, Control, Communications, and Intelligence, as the DoD Chief Information Officer, shall:

5.1.1. Oversee implementation of this Instruction.

5.1.2. Ensure the adjudication of conflicts or disagreements among the DoD Components regarding interconnection of DoD information systems through the Global Information Grid (GIG) waiver process defined in DoD Directive 8000.1 and the DoD CIO Executive Board Charter (references (d) and (e)).

5.1.3. Manage the Defense-wide Information Assurance Program (DIAP) office that shall:

5.1.3.1. Maintain liaison with the office of the Intelligence Community (IC) Chief Information Officer (CIO) to ensure continuous coordination of DoD and IC IA activities and programs.

5.1.3.2. Coordinate and advocate resources for IA enterprise solutions.

5.1.3.3. Develop and maintain a Defense-wide view of IA resources that supports DoD Component and enterprise IA resource program decisions.

DODI 8500.2, February 6, 2003

5.1.3.4. Develop a capability for enterprise-wide analysis of DoD Component IA programs based upon objective criteria, and provide an annual IA assessment to the DoD CIO that addresses the elements outlined in enclosure 3 of this Instruction.

5.1.3.5. Publish the DoD CIO Annual IA Report.

5.1.3.6. In coordination with the OUSD (Acquisition, Technology, and Logistics (AT&L)), ensure the DoD acquisition process incorporates IA planning consistent with the Clinger-Cohen Act of 1996 and DoD Directive 8500.1 (references

(f) and (a)).

5.1.3.7. In coordination with the OUSD(AT&L) and the DoD Components, establish a DoD core curriculum for IA training and awareness.

5.1.3.8. In coordination with the OUSD(Personnel and Readiness), establish IA skills certification standards, as required.

5.1.3.9. Provide oversight of DoD IA education, training, and awareness activities.

5.2. The Chairman of the Joint Chiefs of Staff shall:

5.2.1. Ensure, in coordination with the ASD(C3I), the validation of IA requirements for systems supporting Joint and Combined operations through the Joint Requirements Oversight Council (JROC).

5.2.2. Integrate IA readiness into the Chairman's Readiness System (reference (g)) and the Joint Quarterly Readiness Review (JQRR) process command, control, communications, and computer (C4) joint functional area.

5.2.3. Provide guidance and ensure IA is integrated into joint plans and operations consistent with policy guidance from the President and the Secretary of Defense.

5.2.4. Develop and coordinate Joint IA policies and guidance.

5.2.5. Develop IA doctrinal concepts for integration into joint doctrine.

5.2.6. Appoint a Joint Staff DISN Designated Approving Authority (DAA).

5.3. The Commander, United States Strategic Command shall coordinate and direct DoD-wide computer network defense (CND) operations responsibilities (operational component of IA) in accordance with DoD Instruction O-8530.2 (reference (h)).

5.4. The Director, Defense Information Systems Agency shall:

5.4.1. Establish connection requirements and manage connection approval processes for the Defense Information Systems Network (DISN) (e.g., the Secret Internet Protocol Router Network, the Non-Classified Internet Protocol Router Network, and the DISN Video Services Global). The DISN connection approval processes will address connection of DoD information systems, coalition partner information systems, and contractor support or commercial partner information systems.

5.4.2. Ensure the establishment, development, and maintenance of a DoD ports and protocols management process for registration of port and protocol usage by all DoD information systems, applications, and services connected to the GIG.

5.4.3. Serve as a DISN DAA.

5.4.4. Establish and maintain the Information Assurance Support Environment (IASE) according to DoD Directive 8500.1 (reference (a)) and the Information Assurance Technology Analysis Center (IATAC) according to DoD Directive 3200.12.

(reference (i)).

5.4.5. Develop and provide IA training and awareness products, and a distributive training capability to support product delivery.

5.5. The Director, Defense Intelligence Agency shall:

5.5.1. Establish connection requirements and manage connection approval processes for the Joint Worldwide Intelligence Communications System (JWICS). The JWICS connection approval process will address DoD information systems, coalition partner information systems, and contractor support or commercial partner information systems.

5.5.2. Develop, implement, and maintain the IA certification and accreditation process for DoD non-cryptologic sensitive compartmented information (SCI) to include DoD Intelligence Information System (DoDIIS) IT systems, and networks to include

JWICS.

5.5.3. Serve as a DISN DAA.

5.6. The Director, National Security Agency shall:

5.6.1. Approve all applications of cryptographic algorithms for the protection of confidentiality, integrity, or availability of classified information.

5.6.2. Approve all cryptographic devices used to protect classified information.

5.6.3. Generate Protection Profiles for IA and IA-enabled IT products used in DoD information systems based on Common Criteria (reference (j)), and coordinate the generation and review of these Profiles within the National Information Assurance Partnership (NIAP) framework.

5.6.4. Engage the IA Industry and DoD user community to foster development, evaluation, and deployment of IA solutions that satisfy the guidance contained in this Instruction.

5.6.5. Provide IA and information system security engineering (ISSE) services to the DoD Components, to include describing information protection needs, defining and designing system security to meet those needs, and assessing the effectiveness of system security.

5.6.6. Maintain, update, and disseminate the Information Assurance Technical Framework (IATF) (reference (k)) in coordination with the National Institute for Standards and Technology (NIST).

5.6.7. Serve as a DISN DAA.

5.6.8. Manage the DoD IA Scholarship Program in accordance with Pub. L.

106-398 (reference (l)).

5.7. The Heads of the DoD Components shall:

5.7.1. As Information Owners:

5.7.1.1. Establish information classification, sensitivity, and need-to-know for DoD Component-specific information.

5.7.1.2. Ensure that security classification guidance is issued and maintained and that such guidance is sufficient to address classification thresholds for compiled information in accordance with DoD 5200.1-R (reference (m)).

5.7.1.3. Assign mission assurance categories to DoD Component-specific DoD information systems according to the guidelines provided in enclosure 4 of this Instruction.

5.7.2. Ensure that IA requirements are addressed and visible in all investment portfolios and investment programs incorporating DoD information systems.

5.7.3. Ensure that ISSE is employed in the acquisition of all automated information system (AIS) applications under their responsibility.

5.7.4. Ensure DoD information systems acquire and employ IA solutions in accordance with enclosures 3 and 4 of this Instruction.

5.7.5. Appoint DAAs according to DoD Directive 8500.1 (reference (a)) and ensure they accredit each DoD information system according to the DoD Instruction

5200.40 (reference (n)).

5.7.6. Share research and technology, techniques, and lessons learned relating to IA with other DoD Components and the DIAP office.

5.7.7. Ensure that IA awareness, training, education, and professionalization are provided to all military and civilian personnel, including contractors, commensurate with their respective responsibilities for developing, using, operating, administering, maintaining, and retiring DoD information systems in accordance with Deputy Secretary of Defense guidance (references (o) and (p)).

5.7.8. Provide for an IA monitoring and testing capability according to DoD Directive 4640.6 (reference (q)) and applicable laws and regulations.

5.7.9. Provide for vulnerability mitigation and an incident response and reporting capability to:

5.7.9.1. Comply with DoD-directed mitigations in vulnerability alerts and provide support to computer network defense, as directed in DoD Instruction O-8530.2 (reference (h)).

5.7.9.2. Limit damage and restore effective service following a computer incident.

5.7.9.3. Collect and retain audit data to support technical analysis relating to misuse, penetration reconstruction, or other investigations, and provide this data to appropriate law enforcement or other investigating agencies.

5.7.10. Ensure that contracts include requirements to protect DoD sensitive information, and that the contracts are monitored for compliance.

5.7.11. Ensure that access to all DoD information systems and to specified types of information (e.g., intelligence, proprietary) under their purview is granted only on a need-to-know basis according to DoD Directive 8500.1 (reference (a)), and that all personnel having access are appropriately cleared or qualified under the provisions of DoD 5200.2-R (reference (r)).

5.7.12. Ensure that Public Key Infrastructure (PKI) implementation within DoD Component-owned or -controlled DoD information systems complies with guidance, as established.

5.7.13. Ensure implementation of the DoD ports and protocols management process according to guidance, as established.

5.7.14. Ensure that all biometrics technology intended for integration into DoD information and weapon systems is coordinated with the DoD Biometrics Management Office and acquired according to DoD policy and procedures, as established.

5.7.15. Ensure that appropriate notice of privacy rights and security responsibilities are provided to all individuals accessing DoD Component-owned or -controlled DoD information systems.

5.7.16. Ensure that DoD Component-owned or -controlled DoD information systems are assessed for IA vulnerabilities on a regular basis, and that appropriate IA solutions to eliminate or otherwise mitigate identified vulnerabilities are implemented.

5.7.17. Designate individuals authorized to receive code-signing certificates and ensure that such designations are kept to a minimum consistent with operational requirements.

5.7.18. Ensure that IA solutions do not unnecessarily restrict the use of assistive technology by individuals with disabilities or access to or use of information and data by individuals with disabilities in accordance with sections 501, 504, and 508 of the Rehabilitation Act of 1973 (29 U.S.C. 791, 794, and 794d) (reference (s)).

5.8. Each Designated Approving Authority, in addition to satisfying all responsibilities of an Authorized User, shall:

5.8.1. Ensure that IA is incorporated as an element of DoD information system life-cycle management processes.

5.8.2. For DoD information systems or enclaves under his or her purview, ensure that all IA-related positions are assigned in writing, include a statement of IA responsibilities, and that appointees to positions receive appropriate IA training.

5.8.3. Ensure that all Information Assurance Managers (IAMs), in addition to meeting all access requirements specified in paragraph 4.8., DoD Directive 8500.1, (reference (a)), are U.S. citizens.

5.8.4. Grant DoD information systems under his or her purview formal accreditation to operate according to the DoD IA certification and accreditation process (reference (h)).

5.8.5. Ensure that IA-related events or configuration changes that may impact accreditation are reported to affected parties, such as Information Owners and DAAs of interconnected DoD information systems.

5.9. Each IA Manager, in addition to satisfying all responsibilities of an Authorized User, shall:

5.9.1. Develop and maintain an organization or DoD information system-level IA program that identifies IA architecture, IA requirements, IA objectives and policies; IA personnel; and IA processes and procedures.

5.9.2. Ensure that information ownership responsibilities are established for each DoD information system, to include accountability, access approvals, and special handling requirements.

5.9.3. Ensure the development and maintenance of IA certification documentation according to DoD Instruction 5200.40 (reference (n)) by reviewing and endorsing such documentation, and recommending action to the DAA.

5.9.4. Maintain a repository for all IA certification and accreditation documentation and modifications.

5.9.5. Ensure that IA Officers (IAOs) are appointed in writing, as required, and provide oversight to ensure that they are following established IA policies and procedures. In addition to meeting all access requirements specified in DoD Directive 8500.1, paragraph 4.8. (reference (a)), all newly appointed IAOs shall be U.S. citizens.

Foreign nationals who are direct or indirect hires and are currently appointed as IAOs may continue in these positions provided they satisfy the provisions of DoD Directive 8500.1, paragraph 4.8. (reference (a)); are under the supervision of an IAM who is a U.S.

citizen; and are approved in writing by the DAA. When circumstances warrant, a single individual who is a U.S. citizen may fill both the IAM and the IAO roles.

5.9.6. Ensure that all IAOs and privileged users receive the necessary technical and IA training, education, and certification to carry out their IA duties.

5.9.7. Ensure that compliance monitoring occurs, and review the results of such monitoring.

5.9.8. Ensure that IA inspections, tests, and reviews are coordinated.

5.9.9. Ensure that all IA management review items are tracked and reported.

5.9.10. Ensure that incidents are properly reported to the DAA and the DoD reporting chain, as required, and that responses to IA-related alerts are coordinated.

5.9.11. Act as the primary IA technical advisor to the DAA and formally notify the DAA of any changes impacting the DoD information system's IA posture.

5.10. Each IA Officer, in addition to satisfying all responsibilities of an Authorized User, shall assist the IAM in meeting the duties and responsibilities outlined in paragraph 5.9., above, and:

5.10.1. Ensure that all users have the requisite security clearances and supervisory need-to-know authorization, and are aware of their IA responsibilities before being granted access to the DoD information system.

5.10.2. In coordination with the IAM, initiate protective or corrective measures when an IA incident or vulnerability is discovered.

5.10.3. Ensure that IA and IA-enabled software, hardware, and firmware comply with appropriate security configuration guidelines.

5.10.4. Ensure that DoD information system recovery processes are monitored and that IA features and procedures are properly restored.

5.10.5. Ensure that all DoD information system IA-related documentation is current and accessible to properly authorized individuals.

5.10.6. Implement and enforce all DoD information system IA policies and procedures, as defined by its security certification and accreditation documentation.

5.11. Each Privileged User with IA responsibilities (e.g. System Administrator), in addition to satisfying all responsibilities of an Authorized User, shall:

5.11.1. Configure and operate IA and IA-enabled technology according to DoD information system IA policies and procedures and notify the IAO of any changes that might adversely impact IA.

5.11.2. Establish and manage authorized user accounts for DoD information systems, including configuring access controls to enable access to authorized information and removing authorizations when access is no longer needed.

5.12. Authorized Users shall:

5.12.1. Hold a U.S. Government security clearance commensurate with the level of access granted.

5.12.2. Access only that data, control information, software, hardware, and firmware for which they are authorized access and have a need-to-know, and assume only those roles and privileges for which they are authorized.

5.12.3. Immediately report all IA-related events and potential threats and vulnerabilities involving a DoD information system to the appropriate IAO.

5.12.4. Protect authenticators commensurate with the classification or sensitivity of the information accessed and share authenticators or accounts only with authorized personnel. Report any compromise or suspected compromise of an authenticator of an authenticator to the appropriate IAO.

5.12.5. Ensure that system media and output are properly marked, controlled, stored, transported, and destroyed based on classification or sensitivity and need-to-know.

5.12.6. Protect terminals or workstations from unauthorized access.

5.12.7. Inform the IAO when access to a particular DoD information system is no longer required (e.g., completion of project, transfer, retirement, resignation).

5.12.8. Observe policies and procedures governing the secure operation and authorized use of a DoD information system.

5.12.9. Use the DoD information system only for authorized purposes.

5.12.10. Not unilaterally bypass, strain, or test IA mechanisms. If IA mechanisms must be bypassed, users shall coordinate the procedure with the IAO and receive written approval from the IAM.

5.12.11. Not introduce or use unauthorized software, firmware, or hardware on the DoD information system.

5.12.12. Not relocate or change DoD information system equipment or the network connectivity of equipment without proper IA authorization.

6. PROCEDURES

Implementation procedures are in enclosures 3 and 4.

7. EFFECTIVE DATE:

This Instruction is effective immediately.

Enclosures - 4 E1. References, continued E2. Definitions E3. Information Assurance (IA) Program Implementation E4. Baseline Information Assurance Levels

E1. ENCLOSURE 1

REFERENCES, continued

(e) "DoD Chief Information Officer Executive Board Charter," March 31, 2000

(f) Public Law 104-106, "Division E of the Clinger-Cohen Act of 1996"

(g) CJCS Instruction 3401.01B, "Chairman's Readiness System," 1 July 19992

(h) DoD Instruction O-8530.2, "Support to Computer Network Defense," March 9, 2001

(i) DoD Directive 3200.12, "DoD Scientific and Technical Information (STI) Program

(STIP)," February 11, 1998

(j) Common Criteria version 2.1, ISO International Standard 15408, or latest release3

(k) "Information Assurance Technical Framework (IATF)," National Security Agency, Release 3.1, September 2002, or latest release4

(l) Public Law 106-398, "Section 922 of the National Defense Authorization Act for Fiscal Year 2001"

(m) DoD 5200.1-R, "DoD Information Security Program," January 1997

(n) DoD Instruction 5200.40, "DoD Information Technology Security Certification and

Accreditation Process (DITSCAP)," December 30, 1997

(o) Deputy Secretary of Defense Memorandum, "Implementation of the

Recommendations of the Information Assurance and Information Technology Integrated Process Team on Training, Certification, and Personnel Management in the Department of Defense," July 14, 20005

(p) USD(P&R) and ASD(C3I) Memorandum, "Information Assurance (IA) Training and Certification," June 29, 19986

(q) DoD Directive 4640.6, "Communications Security Telephone Monitoring and Recording," June 26, 1981

(r) DoD 5200.2-R, "DoD Personnel Security Program Regulation," January 1987

(s) 29 U.S.C. 791, 794, and 794d, "Rehabilitation Act of 1973"

(t) Joint Publication 1-02, "Department of Defense Dictionary of Military and

Associated Terms," 12 April 2001 (as amended through 7 May 2002)

2 Available at http://www.dtic.mil/doctrine/cjcsidirectives.htm

3 Available at http://www.commoncriteria.org

4 Available at http://www.iatf.net

5 Available at http://iase.disa.mil/

6 Available at http://iase.disa.mil/

DODI 8500.2, February 6, 2003

13 ENCLOSURE 1

../pdf2/d320012p.pdf ../pdf2/p52001r.pdf ../pdf2/i520040p.pdf ../pdf2/d46406p.pdf ../pdf2/p52002r.pdf

(u) DoD Directive 5000.1, "The Defense Acquisition System," October 23, 2000

(v) OMB Circular A-130, "Management of Federal Information Resources, Transmittal

4," November 30, 20007

(w) JROCM 134-01, "Capstone Requirements Document Global Information Grid," 30 August 20018

(x) DoD Memorandum, "Policy Guidance for the Use of Mobile Code Technologies in Department of Defense (DoD) Information Systems," November 7, 20009

(y) DoD Directive 5230.9, "Clearance of DoD Information for Public Release," April 9,

(z) Section 552a of title 5, United States Code, "The Privacy Act of 1974"

(aa) Section 278g-3 of title 15, United States Code, "Computer Security Act of 1987"

(ab) DoD 5400.7-R, "DoD Freedom of Information Act Program," September 4, 1998

(ac) Section 552 of title 5, United States Code, "Freedom of Information Act"

(ad) DoD Directive 5210.83, "Department of Defense Unclassified Controlled Nuclear

(ae) DoD Directive 5230.25, "Withholding of Unclassified Technical Data from Public

Disclosure," November 6, 1984

(af) DCID 6/5, Policy for Protectin of Certian Non-SCI Sources and Methods

Information (SAMI), 12 February 2001

(ag) Public Law 104-13, "Paperwork Reduction Act" (Chapter 35 of title 44, United

States Code)

(ah) National Security Telecommunications and Information Systems Security Policy

(NSTISSP) No. 11, "National Policy Governing the Acquisition of Information Assurance (IA) and IA-Enabled Information Technology Products," January 200010

(ai) DoD Information Management (IM) Strategic Plan, version 2.0, October 19, 199911

(aj) DoD Directive C-5200.5, "Communications Security (COMSEC) (U)," April 21, 7 Available at http://iase.disa.mil/ Available at http://iase.disa.mil/

8 Available from CRD Executive Agent, U.S. Joint Forces Command (ATTN: J61).

9 Available at http://iase.disa.mil/

10 Available at http://www.nstissc.gov/html/library.htm

11 Available at http://iase.disa.mil/

DODI 8500.2, February 6, 2003

14 ENCLOSURE 1

../pdf2/d50001p.pdf ../pdf2/d52309p.pdf ../pdf2/p54007rp.pdf ../pdf2/d521083p.pdf ../pdf2/d523025p.pdf

E2. ENCLOSURE 2

DEFINITIONS

E2.1.1. Application. Software program that performs a specific function directly for a user and can be executed without access to system control, monitoring, or administrative privileges. Examples include office automation, electronic mail, web services, and major functional or mission software programs (DoD Directive 8500.1, reference (a)).

E2.1.2. Authorized User. Any appropriately cleared individual with a requirement to access a DoD information system in order to perform or assist in a lawful and authorized governmental function (reference (a)).

E2.1.3. Common Criteria. The International Common Criteria for Information Technology Security Evaluation (CC) defines general concepts and principles of information technology (IT) security evaluation and presents a general model of evaluation. It presents constructs for expressing IT security objectives, for selecting and defining IT security requirements, and for writing high-level specifications for products and systems (reference (j)).

E2.1.4. Community Risk. Probability that a particular vulnerability will be exploited within an interacting population and adversely impact some members of that population (reference (a)).

E2.1.5. Computer Network. The constituent element of an enclave responsible for connecting computing environments by providing short-haul data transport capabilities, such as local or campus area networks, or long-haul data transport capabilities, such as operational, metropolitan or wide area and backbone networks (reference (a)).

E2.1.6. Computing Environment. A computer workstation or server (host) and its operating system, peripherals, and applications (reference (a)).

E2.1.7. Computing Facility. A room, building, or section of a building that houses key IT assets, such as application servers, network management servers, domain name servers, switches, firewalls, routers, and intrusion detection systems. Computing facilities have physical and environmental security requirements identified in IA controls that focus on both the availability and confidentiality of the information processed. (See also "facility.")

15 ENCLOSURE 2

E2.1.8. Confidentiality Level. Applicable to DoD information systems, the confidentiality level is primarily used to establish acceptable access factors, such as requirements for individual security clearances or background investigations, access approvals, and need-to-know determinations; interconnection controls and approvals; and acceptable methods by which users may access the system (e.g., intranet, Internet, wireless). The Department of Defense has three defined confidentiality levels:

classified, sensitive, and public.

E2.1.9. Connection Approval. Formal authorization to interconnect information systems (reference (a)).

E2.1.10. Data. Representation of facts, concepts, or instructions in a formalized manner suitable for communication, interpretation, or processing by humans or by automatic means. Any representations, such as characters or analog quantities, to which meaning is or might be assigned (Joint Publication 1-02, reference (t)).

E2.1.11. Defense-in-Depth. The DoD approach for establishing an adequate IA posture in a shared-risk environment that allows for shared mitigation through: the integration of people, technology, and operations; the layering of IA solutions within and among IT assets; and the selection of IA solutions based on their relative level of robustness (reference (a)).

E2.1.12. Defense Information System Network (DISN). The DoD consolidated worldwide enterprise-level telecommunications infrastructure that provides the end-to-end information transfer network for supporting military operations (reference (a)).

E2.1.13. Designated Approving Authority (DAA). The official with the authority to formally assume responsibility for operating a system at an acceptable level of risk.

This term is synonymous with Designated Accrediting Authority and Delegated Accrediting Authority (reference (a)).

E2.1.14. Discretionary Access Control (DAC). A means of restricting access to an object (e.g., files, data entities) based on the identity and need-to-know of a subject (e.g., user, process) and/or groups to which the object belongs. The controls are discretionary in the sense that a subject with certain access permission is capable of passing that permission (perhaps indirectly) to any other subject (unless restrained by a mandatory access control).

E2.1.15. DISN Designated Approving Authority (DISN DAA). One of four DAAs responsible for operating the DISN at an acceptable level of risk. The four DISN DAAs

16 ENCLOSURE 2

are the Directors of the Defense Information Systems Agency (DISA), the Defense Intelligence Agency (DIA), the National Security Agency (NSA), and the Director of the Joint Staff (delegated to Joint Staff Director for Command, Control, Communications, and Computer Systems (J-6)) (reference (a)).

E2.1.16. DMZ (Demilitarized Zone). Perimeter network that adds an extra layer of protection between internal and external networks by enforcing the internal network's IA policy for external information exchange. A DMZ, also called a "screened subnet," provides external, untrusted sources with restricted access to releasable information while shielding the internal networks from outside attacks (reference (a)).

E2.1.17. DoD Information System. Set of information resources organized for the collection, storage, processing, maintenance, use, sharing, dissemination, disposition, display, or transmission of information. Includes AIS applications, enclaves, outsourced IT-based processes, and platform IT interconnections (NSTISSI No. 4009, reference (c) modified to include the four DoD categories).

E2.1.17.1. Automated Information System (AIS) Application. For DoD information assurance purposes, an AIS application is the product or deliverable of an acquisition program, such as those described in DoD Directive 5000.1. (reference (u)).

An AIS application performs clearly defined functions for which there are readily identifiable security considerations and needs that are addressed as part of the acquisition. An AIS application may be a single software application (e.g., Integrated Consumable Items Support (ICIS)); multiple software applications that are related to a single mission (e.g., payroll or personnel); or a combination of software and hardware performing a specific support function across a range of missions (e.g., Global Command and Control System (GCCS), Defense Messaging System (DMS)). AIS applications are deployed to enclaves for operations, and have their operational security needs assumed by the enclave. Note: An AIS application is analogous to a "major application," as defined in OMB A-130 (reference (v)); however, this term is not used in order to avoid confusion with the DoD acquisition category of Major Automated Information System (MAIS).

E2.1.17.2. Enclave. Collection of computing environments connected by one or more internal networks under the control of a single authority and security policy, including personnel and physical security. Enclaves always assume the highest mission assurance category and security classification of the AIS applications or outsourced IT-based processes they support, and derive their security needs from those systems.

They provide standard IA capabilities, such as boundary defense, incident detection and response, and key management, and also deliver common applications, such as office automation and electronic mail. Enclaves are analogous to general support systems as

17 ENCLOSURE 2

defined in OMB A-130 (reference (v)). Enclaves may be specific to an organization or a mission, and the computing environments may be organized by physical proximity or by function independent of location. Examples of enclaves include local area networks and the applications they host, backbone networks, and data processing centers.

E2.1.17.3. Outsourced IT-based Process. For DoD IA purposes, an outsourced IT-based process is a general term used to refer to outsourced business processes supported by private sector information systems, outsourced information technologies, or outsourced information services. An outsourced IT-based process performs clearly defined functions for which there are readily identifiable security considerations and needs that are addressed in both acquisition and operations.

E2.1.17.4. Platform IT Interconnection. For DoD IA purposes, platform IT interconnection refers to network access to platform IT. Platform IT interconnection has readily identifiable security considerations and needs that must be addressed in both acquisition, and operations. Platform IT refers to computer resources, both hardware and software, that are physically part of, dedicated to, or essential in real time to the mission performance of special purpose systems such as weapons, training simulators, diagnostic test and maintenance equipment, calibration equipment, equipment used in the research and development of weapons systems, medical technologies, transport vehicles, buildings, and utility distribution systems such as water and electric. Examples of platform IT interconnections that impose security considerations include:

communications interfaces for data exchanges with enclaves for mission planning or execution, remote administration, and remote upgrade or reconfiguration (reference (a)).

E2.1.18. Enclave Boundary. The point at which an enclave's internal network service layer connects to an external network's service layer.

E2.1.19. Evaluation Assurance Level (EAL). One of seven increasingly rigorous packages of assurance requirements from CC (Common Criteria (IS 15408)) Part 3.

Each numbered package represents a point on the CC's predefined assurance scale. An EAL can be considered a level of confidence in the security functions of an IT product or system.

E2.1.20. Facility. A room, building, or section of a building that houses workstations and peripherals. Facilities have physical and environmental security requirements identified in IA controls that focus on confidentiality of the information processed or displayed. (See also "computing facility.")

E2.1.21. Global Information Grid (GIG). Globally interconnected, end-to-end set of information capabilities, associated processes, and personnel for collecting, 18 ENCLOSURE 2 processing, storing, disseminating, and managing information on demand to warfighters, policy makers, and support personnel. The GIG includes all owned and leased communications and computing systems and services, software (including applications), data, security services, and other associated services necessary to achieve Information Superiority. It also includes National Security Systems (NSS) as defined in section 5142 of the Clinger-Cohen Act of 1996 (reference (f)). The GIG supports all DoD, National Security, and related Intelligence Community (IC) missions and functions (strategic, operational, tactical, and business) in war and in peace. The GIG provides capabilities from all operating locations (bases, posts, camps, stations, facilities, mobile platforms, and deployed sites). The GIG provides interfaces to coalition, allied, and non-DoD users and systems. Non-GIG IT is stand-alone, self-contained, or embedded IT that is not or will not be connected to the enterprise network. The GIG includes any system, equipment, software, or service that meets one or more of the following criteria:

E2.1.21.1. Transmits information to, receives information from, routes information among, or interchanges information among other equipment, software, and services.

E2.1.21.2. Provides retention, organization, visualization, information assurance, or disposition of data, information, and/or knowledge received from or transmitted to other equipment, software, and services.

E2.1.21.3. Processes data or information for use by other equipment, software, and services (JROCM 134-01, reference (w), format revised).

E2.1.22. Information. Any communication or representation of knowledge such as facts, data, or opinion in any medium or form, including textual, numerical, graphic, cartographic, narrative, or audiovisual forms (DoD Directive 8000.1, reference (d)).

E2.1.23. Information Assurance (IA). Measures that protect and defend information and information systems by ensuring their availability, integrity, authentication, confidentiality, and non-repudiation. This includes providing for restoration of information systems by incorporating protection, detection, and reaction capabilities (reference (a)).

E2.1.24. IA Architecture. An abstract expression of IA solutions that assigns and portrays IA roles, and behavior among a set of IT assets, and prescribes rules for interaction and interconnection. An IA architecture may be expressed at one of three levels: DoD information system-wide, DoD Component-wide, or Defense-wide. DoD Component-wide and Defense-wide IA architectures provide a uniform and systematic

19 ENCLOSURE 2

way to assess and specify IA across multiple, interconnecting DoD information systems and to ensure that they take advantage of supporting IA infrastructures.

E2.1.25. IA Certification and Accreditation (IA C&A). The standard DoD approach for identifying information security requirements, providing security solutions, and managing the security of DoD information systems.

E2.1.26. IA Control. An objective IA condition of integrity, availability, or confidentiality achieved through the application of specific safeguards or through the regulation of specific activities that is expressed in a specified format (i.e., a control number, a control name, control text, and a control class). Specific management, personnel, operational, and technical controls are applied to each DoD information system to achieve an appropriate level of integrity, availability, and confidentiality in accordance with OMB Circular A-130 (reference (v)).

E2.1.27. IA Manager (IAM). The individual responsible for the information assurance program of a DoD information system or organization. While the term IAM is favored within the Department of Defense, it may be used interchangeably with the IA title Information Systems Security Manager (ISSM).

E2.1.28. IA Officer (IAO). An individual responsible to the IAM for ensuring that the appropriate operational IA posture is maintained for a DoD information system or organization. While the term IAO is favored within the Department of Defense, it may be used interchangeably with other IA titles (e.g., Information Systems Security Officer, Information Systems Security Custodian, Network Security Officer, or Terminal Area Security Officer).

E2.1.29. IA Product. Product or technology whose primary purpose is to provide security services (e.g., confidentiality, authentication, integrity, access control or non-repudiation of data); correct known vulnerabilities; and/or provide layered defense against various categories of non-authorized or malicious penetrations of information systems or networks. Examples include such products as data/network encryptors, firewalls, and intrusion detection devices (reference (a)).

E2.1.30. IA-Enabled Product. Product or technology whose primary role is not security, but which provides security services as an associated feature of its intended operating capabilities. Examples include such products as security-enabled web browsers, screening routers, trusted operating systems, and security-enabled messaging systems (reference (a)).

20 ENCLOSURE 2

E2.1.31. IA Support Environment (IASE). A web-based resource providing access to current DoD and Federal IA and IA-related policy and guidance, including recent and pending legislation.

E2.1.32. IA Technology Analysis Center (IATAC). A formally chartered DoD institution that helps researchers, engineers, and program managers locate, analyze, use, and exchange scientific and technical information about information assurance.

E2.1.33. Information Owner. Official with statutory or operational authority for specified information and responsibility for establishing the controls for its generation, collection, processing, dissemination, and disposal (reference (a)).

E2.1.34. Information System Security Engineering (ISSE). An engineering process that captures and refines information protection requirements and ensures their integration into IT acquisition processes through purposeful security design or configuration.

E2.1.35. Information Technology (IT). Any equipment or interconnected system or subsystem of equipment that is used in the automatic acquisition, storage, manipulation, management, movement, control, display, switching, interchange, transmission or reception of data or information by the DoD Component. For purposes of the preceding sentence, equipment is used by a DoD Component if the equipment is used by the DoD Component directly or is used by a contractor under a contract with the DoD Component that (1) requires the use of such equipment, or (2) requires the use, to a significant extent, of such equipment in the performance of a service or the furnishing of a product. The term "information technology" includes computers, ancillary equipment, software, firmware and similar procedures, services (including support services), and related resources. Notwithstanding the above, the term "information technology" does not include any equipment that is acquired by a Federal contractor incidental to a Federal contract.

E2.1.36. IT Position Category. Applicable to unclassified DoD information systems, a designator that indicates the level of IT access required to execute the responsibilities of the position based on the potential for an individual assigned to the position to adversely impact DoD missions or functions. Position categories include:

IT-I (Privileged), IT-II (Limited Privileged) and IT-III (Non-Privileged), as defined in DoD 5200.2-R (reference (r)). Investigative requirements for each category vary, depending on role and whether the incumbent is a U.S. military member, U.S. civilian government employee, U.S. civilian contractor, or a foreign national. The term IT

21 ENCLOSURE 2

Position is synonymous with the older term Automated Data Processing (ADP) Position (reference (a)).

E2.1.37. Key IT Assets. For availability or continuity planning purposes, those IT assets that support mission or business essential functions or the uninterrupted operation of the enclave. Examples include IT assets supporting MAC I or MAC II AIS applications; network operations (e.g., switches, hubs, routers, name servers, network management software, remote access servers, proxy servers, mail servers); and IA (e.g., firewalls, intrusion detection systems, key management systems, vulnerability assessment applications).

E2.1.38. Mission Assurance Category. Applicable to DoD information systems, the mission assurance category reflects the importance of information relative to the achievement of DoD goals and objectives, particularly the warfighters' combat mission.

Mission assurance categories are primarily used to determine the requirements for availability and integrity. The Department of Defense has three defined mission assurance categories:

E2.1.38.1. Mission Assurance Category I (MAC I). Systems handling information that is determined to be vital to the operational readiness or mission effectiveness of deployed and contingency forces in terms of both content and timeliness. The consequences of loss of integrity or availability of a MAC I system are unacceptable and could include the immediate and sustained loss of mission effectiveness. Mission Assurance Category I systems require the most stringent protection measures.

E2.1.38.2. Mission Assurance Category II (MAC II). Systems handling information that is important to the support of deployed and contingency forces. The consequences of loss of integrity are unacceptable. Loss of availability is difficult to deal with and can only be tolerated for a short time. The consequences could include delay or degradation in providing important support services or commodities that may seriously impact mission effectiveness or operational readiness. Mission Assurance Category II systems require additional safeguards beyond best practices to ensure assurance.

E2.1.38.3. Mission Assurance Category III (MAC III). Systems handling information that is necessary for the conduct of day-to-day business, but does not materially affect support to deployed or contingency forces in the short-term. The consequences of loss of integrity or availability can be tolerated or overcome without significant impacts on mission effectiveness or operational readiness. The consequences could include the delay or degradation of services or commodities

22 ENCLOSURE 2

enabling routine activities. Mission Assurance Category III systems require protective measures, techniques, or procedures generally commensurate with commercial best practices (reference (a)).

E2.1.39. Mobile Code. Software modules obtained from remote systems, transferred across a network, and then downloaded and executed on local systems without explicit installation or execution by the recipient (reference (a)).

E2.1.40. National Information Assurance Partnership (NIAP). Joint initiative between NSA and NIST responsible for security testing needs of both IT consumers and producers and promoting the development of technically sound security requirements for IT products and systems and appropriate measures for evaluating those products and systems (reference (a)).

E2.1.41. Need-to-Know. Necessity for access to, or knowledge or possession of, specific official DoD information required to carry out official duties (reference (a)).

E2.1.42. Need-to-Know Determination. Decision made by an authorized holder of official information that a prospective recipient requires access to specific official information to carry out official duties (reference (a)).

E2.1.43. Official DoD Information. All information that is in the custody and control of the Department of Defense, relates to information in the custody and control of the Department, or was acquired by DoD employees as part of their official duties or because of their official status within the Department (reference (a)).

E2.1.44. Privileged User. An authorized user who has access to system control, monitoring, or administration functions.

E2.1.45. Public Information. Official DoD information that has been reviewed and approved for public release by the information owner in accordance with DoD Directive

5230.9 (reference (y)).

E2.1.46. Remote Access. Enclave-level access for authorized users that are external to the enclave that is established through a controlled access point at the enclave boundary.

E2.1.47. Robustness. A characterization of the strength of a security function, mechanism, service or solution, and the assurance (or confidence) that it is implemented and functioning correctly. The Department of Defense has three levels of robustness:

23 ENCLOSURE 2

E2.1.47.1. High Robustness. Security services and mechanisms that provide the most stringent protection and rigorous security countermeasures.

E2.1.47.2. Medium Robustness. Security services and mechanisms that provide for layering of additional safeguards above good commercial practices.

E2.1.47.3. Basic Robustness. Security services and mechanisms that equate to best commercial practices (reference (a)).

E2.1.48. Safeguard

E2.1.48.1. A protection included to counteract a known or expected condition.

E2.1.48.2. An incorporated countermeasure or set of countermeasures within a base release.

E2.1.49. Security Target. Set of security requirements and specifications to be used as the basis for evaluation of an identified IA or IA-enabled product and its associated administrator and user guidance documentation.

E2.1.50. Sensitive Compartmented Information (SCI). Classified information concerning or derived from intelligence sources, methods, or analytical processes, that is required to be handled within formal access control systems established by the Director of Central Intelligence (reference (a)).

E2.1.51. Sensitive Information. Information, the loss, misuse, or unauthorized access to or modification of, could adversely affect the national interest or the conduct of Federal programs, or the privacy to which individuals are entitled under Section 552a of title 5, United States Code, "The Privacy Act" (reference (z)), but which has not been specifically authorized under criteria established by Executive order or an Act of Congress to be kept secret in the interest of national defense or foreign policy.

(Section 278g-3 of title 15, United States Code, "The Computer Security Act of 1987" (reference (aa)). Examples of sensitive information include, but are not limited to information in DoD payroll, finance, logistics, and personnel management systems.

Sensitive information sub-categories include, but are not limited to, the following:

E2.1.51.1. For Official Use Only (FOUO). In accordance with DoD 5400.7-R (reference (ab)), DoD information exempted from mandatory public disclosure under the Freedom of Information Act (FOIA) (reference (ac)).

24 ENCLOSURE 2

E2.1.51.2. Privacy Data. Any record that is contained in a system of records as defined in the Privacy Act of 1974 (5 U.S.C. 552a) (reference (z)) and information the disclosure of which would constitute an unwarranted invasion of personal privacy.

E2.1.51.3. DoD Unclassified Controlled Nuclear Information (DoD UCNI).

Unclassified Information on security measures (including security plans, procedures, and equipment) for the physical protection of DoD Special Nuclear Material (SNM), equipment, or facilities in accordance with DoD Directive 5210.83 (reference (ad)).

Information is Designated DoD UCNI only when it is determined that its unauthorized disclosure could reasonably be expected to have a significant adverse effect on the health and safety of the public or the common defense and security by increasing significantly the likelihood of the illegal production of nuclear weapons or the theft, diversion, or sabotage of DoD SNM, equipment, or facilities.

E2.1.51.4. Unclassified Technical Data. Data that is not classified but is subject to export control and is withheld from public disclosure according to DoD Directive 5230.25 (reference (ae)).

E2.1.51.5. Proprietary Information. Information that is provided by a source or sources under the condition that it not be released to other sources.

E2.1.51.6. Foreign Government Information. Information that originated from a foreign government and that is not classified CONFIDENTIAL or higher, but must be protected in accordance with DoD 5200.1-R (reference (m)).

E2.1.51.7. Department of State Sensitive But Unclassified…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .