DoDI_8500.01.pdf

PDF 351 KB Posted

Attached to
DRAFT* Special Operations Forces Global Logistics Support Services (SOF GLSS) Federal contract opportunity
Solicitation number
H92254-16-R-0001
Issued by
United States Special Operations Command

About this file

PWS App Doc 14

View the file

Other files for this federal contract opportunity

Other files attached to DRAFT* Special Operations Forces Global Logistics Support Services (SOF GLSS), newest first.
File Type Posted
RFP_Att_2_-_DD_254 _rev_03_(tracked_changes).pdf PDF
WD_15-2187rev1_(Ft_Campbell _KY).pdf PDF
WD_99-0316rev45_(Nationwide).pdf PDF
WD_15-4389rev2_(Camp_Lejeune _NC).pdf PDF
WD_15-5635rev2_(Camp_Pendleton _Coronado _CA).pdf PDF
One-on-One_Attendee_Roster.pdf PDF
RFP_Att_13_-_List_of_Applicable_CBAs_and_WDs _rev_2_(tracked_changes).pdf PDF
WD_15-2003rev1_(Birmingham _AL).pdf PDF
TO_TIM_Attendee_Roster.pdf PDF
WD_05-2531rev17_(Utah).pdf PDF
WD_05-2567rev21_(Ft_Lewis _WA).pdf PDF
WD_15-2141rev2_(HAAF _GA).pdf PDF
CBA_(Ft_Walton_Beach _FL).pdf PDF
RFP_Att_2_-_DD_FM_254_rev_2.pdf PDF
RFP_Att_10_-_Enterprise_Budget_Template _rev_2_DRFP_notional.xlsx XLSX spreadsheet
WD_05-3033rev17_(Ft_Walton_Beach _FL).pdf PDF
RFP_Att_13_-_List_of_Applicable_CBAs_and_WDs_rev_1.pdf PDF
RFP_Att_12_-_Q A_Template.xlsx XLSX spreadsheet
RFP_Att_13_-_List_of_Applicable_CBAs_and_WDs.pdf PDF
CBA_(Ft_Walton_Beach _FL).pdf PDF
Attachment_List_rev_3.xlsx XLSX spreadsheet
RFP_Att_10_-_Enterprise_Budget_Template _rev_1.xlsx XLSX spreadsheet
One-on-One_Attendee_Roster.pdf PDF
RFP_Att_13_-_CBA_(Bluegrass_Station _KY).pdf PDF
H92254-16-R-0001_(DRAFT)_rev_2.docx DOCX document
RFP_Att_2_-_DD_254_rev_1.pdf PDF
RFP_Att_10_-_Enterprise_Budget_Template _rev_1.xlsx XLSX spreadsheet
H92254-16-R-0001_(DRAFT)_rev_1.docx DOCX document
RFP_Att_16_-_WD_15-2221rev2_(Lexington _KY).pdf PDF
RFP_Att_16_-_WD_15-2221rev2_(Lexington _KY).pdf PDF
Attachment_List.xlsx XLSX spreadsheet
RFP_Att_10_-_Enterprise_Budget_Template.xlsx XLSX spreadsheet
DoD_4160.21-M.pdf PDF
Attachment_List.xlsx XLSX spreadsheet
DoDM_5105.21_Vol_1.pdf PDF
DoDM_5200.01_Vol_3.pdf PDF
DoDM_5100.76.pdf PDF
RFP_Att_13_-_CBA_(Bluegrass_Station _KY).pdf PDF
RFP_Att_15_-_WD_05-3033rev17_(Ft_Walton_Beach _FL).pdf PDF
DCMA_Instruction_8210.1C.pdf PDF
DoD_5220.22-M.pdf PDF
USSOCOM_Manual_380-1.pdf PDF
DoDI_6055.07.pdf PDF
DoD_8570.01-M.pdf PDF
DoD_4140.65-M.pdf PDF
RFP_Att_12_-_Q A_Template.xlsx XLSX spreadsheet
DoDI_8551.01.pdf PDF
MIL-STD-129R.pdf PDF
RFP_Att_10_-_Enterprise_Budget_Template.xlsx XLSX spreadsheet
DoD_4140.27-M.pdf PDF
Show all 50

DRAFT* Special Operations Forces Global Logistics Support Services (SOF GLSS) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Department of Defense

INSTRUCTION

NUMBER 8500.01

March 14, 2014

DoD CIO

SUBJECT: Cybersecurity

References: See Enclosure 1

1. PURPOSE. This instruction:

a. Reissues and renames DoD Directive (DoDD) 8500.01E (Reference (a)) as a DoD Instruction (DoDI) pursuant to the authority in DoDD 5144.02 (Reference (b)) to establish a DoD cybersecurity program to protect and defend DoD information and information technology

(IT).

b. Incorporates and cancels DoDI 8500.02 (Reference (c)), DoDD C-5200.19 (Reference (d)), DoDI 8552.01 (Reference (e)), Assistant Secretary of Defense for Networks and Information Integration (ASD(NII))/DoD Chief Information Officer (DoD CIO) Memorandums (References (f) through (k)), and Directive-type Memorandum (DTM) 08-060 (Reference (l)).

c. Establishes the positions of DoD principal authorizing official (PAO) (formerly known as principal accrediting authority) and the DoD Senior Information Security Officer (SISO) (formerly known as the Senior Information Assurance Officer) and continues the DoD Information Security Risk Management Committee (DoD ISRMC) (formerly known as the Defense Information Systems Network (DISN)/Global Information Grid (GIG) Flag Panel).

d. Adopts the term “cybersecurity” as it is defined in National Security Presidential Directive-54/Homeland Security Presidential Directive-23 (Reference (m)) to be used throughout DoD instead of the term “information assurance (IA).”

2. APPLICABILITY

a. This instruction applies to:

(1) OSD, the Military Departments, the Office of the Chairman of the Joint Chiefs of Staff (CJCS) and the Joint Staff, the Combatant Commands, the Office of the Inspector General of the DoD, the Defense Agencies, the DoD Field Activities, and all other organizational entities within the DoD (referred to collectively in this instruction as the “DoD Components”).

DoDI 8500.01, March 14, 2014

(2) All DoD IT.

(3) All DoD information in electronic format.

(4) Special access program (SAP) information technology, other than SAP ISs handling sensitive compartmented information (SCI) material.

b. Nothing in this instruction alters or supersedes the existing authorities and policies of the Director of National Intelligence (DNI) regarding the protection of SCI as directed by Executive Order 12333 (Reference (n)) and other laws and regulations.

3. POLICY. It is DoD policy that:

a. Risk Management

(1) DoD will implement a multi-tiered cybersecurity risk management process to protect U.S. interests, DoD operational capabilities, and DoD individuals, organizations, and assets from the DoD Information Enterprise level, through the DoD Component level, down to the IS level as described in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-39 (Reference (o)) and Committee on National Security Systems (CNSS) Policy (CNSSP) 22 (Reference (p)).

(2) Risks associated with vulnerabilities inherent in IT, global sourcing and distribution, and adversary threats to DoD use of cyberspace must be considered in DoD employment of capabilities to achieve objectives in military, intelligence, and business operations.

(3) All DoD IT will be assigned to, and governed by, a DoD Component cybersecurity program that manages risk commensurate with the importance of supported missions and the value of potentially affected information or assets.

(4) Risk management will be addressed as early as possible in the acquisition of IT and in an integrated manner across the IT life cycle.

(5) Documentation regarding the security posture of DoD IS and PIT systems will be made available to promote reciprocity as described in DoDI 8510.01 (Reference (q)) and to assist authorizing officials (AOs) (formerly known as designated approving or accrediting authorities) from other organizations in making credible, risk-based decisions regarding the acceptance and use of systems and the information that they process, store, or transmit.

b. Operational Resilience. DoD IT will be planned, developed, tested, implemented, evaluated, and operated to ensure that:

(1) Information and services are available to authorized users whenever and wherever required according to mission needs, priorities, and changing roles and responsibilities.

(2) Security posture, from individual device or software object to aggregated systems of systems, is sensed, correlated, and made visible to mission owners, network operators, and to the DoD Information Enterprise consistent with DoDD 8000.01 (Reference (r)).

(3) Whenever possible, technology components (e.g., hardware and software) have the ability to reconfigure, optimize, self-defend, and recover with little or no human intervention.

Attempts made to reconfigure, self-defend, and recover should produce an incident audit trail.

c. Integration and Interoperability

(1) Cybersecurity must be fully integrated into system life cycles and will be a visible element of organizational, joint, and DoD Component IT portfolios.

(2) Interoperability will be achieved through adherence to DoD architecture principles, adopting a standards-based approach, and by all DoD Components sharing the level of risk necessary to achieve mission success.

(3) All interconnections of DoD IT will be managed to minimize shared risk by ensuring that the security posture of one system is not undermined by vulnerabilities of interconnected systems.

d. Cyberspace Defense. Cyberspace defense will be employed to protect, detect, characterize, counter, and mitigate unauthorized activity and vulnerabilities on DoD information networks. Cyberspace defense information will be shared with all appropriately cleared and authorized personnel in support of DoD enterprise-wide situational awareness.

e. Performance

(1) Implementation of cybersecurity will be overseen and governed through the integrated decision structures and processes described in this instruction.

(2) Performance will be measured, assessed for effectiveness, and managed relative to contributions to mission outcomes and strategic goals and objectives, in accordance with Sections 11103 and 11313 of Title 40, United States Code (U.S.C.) (Reference (s)).

(3) Data will be collected to support reporting and cybersecurity management activities across the system life cycle.

(4) Standardized IT tools, methods, and processes will be used to the greatest extent possible to eliminate duplicate costs and to focus resources on creating technologically mature and verified solutions.

f. DoD Information. All DoD information in electronic format will be given an appropriate level of confidentiality, integrity, and availability that reflects the importance of both information sharing and protection.

g. Identity Assurance

(1) Identity assurance must be used to ensure strong identification, authentication, and eliminate anonymity in DoD IS and PIT systems.

(2) DoD will public key-enable DoD ISs and implement a DoD-wide Public Key Infrastructure (PKI) solution that will be managed by the DoD PKI Program Management Office in accordance with DoDI 8520.02 (Reference (t)).

(3) Biometrics used in support of identity assurance will be managed in accordance with

DoDD 8521.01 (Reference (u)).

h. Information Technology

(1) All IT that receives, processes, stores, displays, or transmits DoD information will be acquired, configured, operated, maintained, and disposed of consistent with applicable DoD cybersecurity policies, standards, and architectures.

(2) Risks associated with global sourcing and distribution, weaknesses or flaws inherent in the IT, and vulnerabilities introduced through faulty design, configuration, or use will be managed, mitigated, and monitored as appropriate.

(3) Cybersecurity requirements must be identified and included throughout the lifecycle of systems including acquisition, design, development, developmental testing, operational testing, integration, implementation, operation, upgrade, or replacement of all DoD IT supporting DoD tasks and missions.

i. Cybersecurity Workforce

(1) Cybersecurity workforce functions must be identified and managed, and personnel performing cybersecurity functions will be appropriately screened in accordance with this instruction and DoD 5200.2-R (Reference (v)), and qualified in accordance with DoDD 8570.01 (Reference (w)) and supporting issuances.

(2) Qualified cybersecurity personnel must be identified and integrated into all phases of the system development life cycle.

j. Mission Partners

(1) Capabilities built to support cybersecurity objectives that are shared with mission partners will be consistent with guidance contained in Reference (r) and governed through integrated decision structures and processes described in this instruction.

(2) DoD-originated and DoD-provided information residing on mission partner ISs must be properly and adequately safeguarded, with documented agreements indicating required levels of protection.

4. RESPONSIBILITIES. See Enclosure 2.

5. PROCEDURES. See Enclosure 3.

6. INFORMATION COLLECTION REQUIREMENTS. The DoD Federal Information Security Management Act (FISMA) Annual Report with Quarterly Updates, referred to in paragraphs 1v and 13q of Enclosure 2 and paragraph 12i of Enclosure 3 of this instruction, has been assigned report control symbol DD-CIO(A,Q)2296 in accordance with the procedures in DTM 12-004 (Reference (x)) and DoD 8910.1-M (Reference (y)).

7. RELEASABILITY. Unlimited. This instruction is approved for public release and is available on the Internet from the DoD Issuances Website at http://www.dtic.mil/whs/directives.

8. EFFECTIVE DATE. This instruction:

a. Is effective March 14, 2014.

b. Must be reissued, cancelled, or certified current within 5 years of its publication to be considered current in accordance with DoDI 5025.01 (Reference (z)).

c. Will expire effective March 14, 2024 and be removed from the DoD Issuances Website if it hasn’t been reissued or cancelled in accordance with Reference (z).

Teresa M. Takai DoD Chief Information Officer

Enclosures

1. References

2. Responsibilities

3. Procedures Glossary

DoDI 8500.02, March 14, 2014

CONTENTS 6

TABLE OF CONTENTS

ENCLOSURE 1: REFERENCES

ENCLOSURE 2: RESPONSIBILITIES

DoD CIO

DIRECTOR, DISA

USD(AT&L)

DEPUTY ASSISTANT SECRETARY OF DEFENSE FOR DT&E (DASD(DT&E))

DOT&E

USD(P)

USD(P&R)

USD(I)

DIRNSA/CHCSS

DIRECTOR, DEFENSE SECURITY SERVICE (DSS)

DIRECTOR, DIA

DEPUTY CHIEF MANAGEMENT OFFICER (DCMO)

OSD AND DoD COMPONENT HEADS

CJCS

COMMANDER, USSTRATCOM

ENCLOSURE 3: PROCEDURES

INTRODUCTION

RISK MANAGEMENT

OPERATIONAL RESILIENCE

INTEGRATION AND INTEROPERABILITY

CYBERSPACE DEFENSE

PERFORMANCE

DoD INFORMATION

IDENTITY ASSURANCE

INFORMATION TECHNOLOGY

CYBERSECURITY WORKFORCE

MISSION PARTNERS

DoD SISO DoD COMPONENT CIOs DoD RISK EXECUTIVE FUNCTION

PAO

AO

ISOs OF DoD IT

ISSM

ISSO

PRIVILEGED USERS (E.G. SYSTEM ADMINISTRATOR)

AUTHORIZED USERS

CONTENTS 7

GLOSSARY

PART I. ABBREVIATIONS AND ACRONYMS

PART II. DEFINITIONS

FIGURE

1. Three-Tiered Approach to Risk Management

2. DoD Information Technology

ENCLOSURE 1 8

ENCLOSURE 1

REFERENCES

(a) DoD Directive 8500.01, “Information Assurance (IA),” October 4, 2002 (hereby cancelled)

(b) DoD Directive 5144.02, “DoD Chief Information Officer (DoD CIO),” April 22, 2013

(c) DoD Instruction 8500.2, “Information Assurance (IA) Implementation,” February 6, 2003

(hereby cancelled)

(d) DoD Directive C-5200.19, “Control of Compromising Emanations (U),” May 16, 1995

(hereby cancelled)

(e) DoD Instruction 8552.01, “Use of Mobile Code Technologies in DoD Information

Systems,” October 23, 2006 (hereby cancelled)

(f) Assistant Secretary of Defense for Networks and Information Integration/DoD Chief

Information Officer Memorandum, “Disposition of Unclassified DoD Computer Hard Drives,” June 4, 2001 (hereby cancelled)

(g) Assistant Secretary of Defense for Networks and Information Integration/DoD Chief Information Officer Memorandum, “Certification and Accreditation Requirements for DoD-wide Managed Enterprise Services Procurements,” June 22, 2006 (hereby cancelled)

(h) Assistant Secretary of Defense for Networks and Information Integration/DoD Chief Information Officer Memorandum, “Use of Peer-to-Peer (P2P) File-Sharing Applications Across DoD,” November 23, 2004 (hereby cancelled)

(i) Assistant Secretary of Defense for Networks and Information Integration/DoD Chief Information Officer Memorandum, “Department of Defense (DoD) Guidance on Protecting Personally Identifiable Information (PII),” August 18, 2006 (hereby cancelled)

(j) Assistant Secretary of Defense for Networks and Information Integration/DoD Chief Information Officer Memorandum, “Encryption of Sensitive Unclassified Data At Rest on Mobile Computing Devices and Removable Storage Media,” July 3, 2007 (hereby cancelled)

(k) Assistant Secretary of Defense for Networks and Information Integration/DoD Chief Information Officer Memorandum, “Protection of Sensitive Department of Defense (DoD) Data at Rest On Portable Computing Devices,” April 18, 2006 (hereby cancelled)

(l) Directive-type Memorandum 08-060, “Policy on Use of Department of Defense (DoD) Information Systems — Standard Consent Banner and User Agreement,” May 9, 2008, as amended (hereby cancelled)

(m) National Security Presidential Directive-54/Homeland Security Presidential Directive-23, “Cybersecurity Policy,” January 8, 20081

(n) Executive Order 12333, “United States Intelligence Activities,” as amended

(o) National Institute of Standards and Technology Special Publication 800-39, “Managing

Information Security Risk: Organization, Mission, and Information System View,” current edition

(p) Committee on National Security Systems Policy 22, “Policy on Information Assurance Risk Management for National Security Systems,” January 2012, as amended

1 Document is classified TOP SECRET. To obtain a copy, fax a request to the Homeland Security Council Executive Secretary at 202-456-5158 and the National Security Council’s Senior Director for Records and Access Management at 202-456-9200.

ENCLOSURE 1 9

(q) DoD Instruction 8510.01, “Risk Management Framework (RMF) for DoD Information Technology (IT),” March 12, 2014

(r) DoD Directive 8000.01, “Management of the Department of Defense Information Enterprise,” February 10, 2009

(s) Title 40, United States Code

(t) DoD Instruction 8520.02, “Public Key Infrastructure (PKI) and Public Key (PK)

Enabling,” May 24, 2011

(u) DoD Directive 8521.01E, “Department of Defense Biometrics,” February 21, 2008

(v) DoD 5200.2-R, “Personnel Security Program,” January 1, 1987, as amended

(w) DoD Directive 8570.01, “Information Assurance (IA) Training, Certification, and

Workforce Management,” August 15, 2004

(x) Directive-type Memorandum 12-004, “DoD Internal Information Collections,” April 24, 2012, as amended

(y) DoD 8910.1-M, “DoD Procedures for Management of Information Requirements,”

June 30, 1998

(z) DoD Instruction 5025.01, “DoD Directives Program,” September 26, 2012, as amended

(aa) Title 44, United States Code

(ab) DoD Directive 5230.11, “Disclosure of Classified Military Information to Foreign

Governments and International Organizations,” June 16, 1992

(ac) DoD Directive 8115.01, “Information Technology Portfolio Management,” October 10,

(ad) DoD Instruction 5205.13, “Defense Industrial Base (DIB) Cyber Security/Information

Assurance (CS/IA) Activities,” January 29, 2010

(ae) DoD Directive 3020.40, “DoD Policy and Responsibilities for Critical Infrastructure,”

January 14, 2010, as amended

(af) Deputy Secretary of Defense Memorandum, “Delegation of Authority to Negotiate and

Conclude International Agreements on Cooperation in Information Assurance and Computer Network Defense,” March 5, 20022

(ag) DoD Directive 5530.3, “International Agreements,” June 11, 1987, as amended

(ah) Joint DoD/Intelligence Community memorandum, “Establishment of a Department of

Defense (DoD)/Intelligence Community (IC) Unified Cross Domain Management Office (UCDMO),” July 15, 2006

(ai) Unified Cross Domain Management Office Charter, March 21, 2007

(aj) Assistant Secretary of Defense for Networks and Information Integration/DoD Chief

Information Officer Memorandum/Commander, U.S. Strategic Command Memorandum, “Establishment of the Department of Defense Enterprise-wide Information Assurance and Computer Network Defense Solutions Steering Group,” September 11, 2003

(ak) National Security Directive 42, “National Policy for the Security of National Security Telecommunications and Information Systems,” July 5, 1990

(al) Office of Management and Budget Circular A-130, “Management of Federal Information Resources,” as amended

(am) Chairman of the Joint Chiefs of Staff Instruction 6211.02, “Defense Information System Network (DISN) Responsibilities,” current edition

(an) DoD Instruction 8551.1, “Ports, Protocols, and Services Management (PPSM),” August 13, 2 Requests for copies can be forwarded to the DoD CIO.

ENCLOSURE 1 10

(ao) DoD Instruction 8100.04, “DoD Unified Capabilities (UC),” December 9, 2010

(ap) Charter Defense Information Systems Network Security Accreditation Working Group, March 26, 20042

(aq) Defense Information System Network Global Information Grid Flag Panel Charter, April 2012, as amended2

(ar) DoD Directive 5134.01, “Under Secretary of Defense for Acquisition, Technology, and Logistics (USD(AT&L)),” December 9, 2005, as amended

(as) DoD Instruction 3200.12, “DoD Scientific and Technical Information Program (STIP),” August 22, 2013

(at) DoD Instruction 8580.1, “Information Assurance (IA) in the Defense Acquisition System,” July 9, 2004

(au) DoD Directive 5000.01, “The Defense Acquisition System,” May 12, 2003

(av) Interim DoD Instruction 5000.02, “Operation of the Defense Acquisition System,”

November 25, 2013

(aw) DoD Instruction 4630.8, “Procedures for Interoperability and Supportability of Information

Technology (IT) and National Security Systems (NSS),” June 30, 2004

(ax) Section 1043 of Public Law 106-65, “Information Assurance Initiative,” October 5, 1999

(ay) DoD Instruction 5200.39, “Critical Program Information (CPI) Protection within the

Department of Defense,” July 16, 2008, as amended

(az) DoD Instruction 5134.16, “Deputy Assistant Secretary of Defense for Systems Engineering

(DASD(SE)),” August 19, 2011

(ba) DoD 8570.01-M, “Information Assurance Workforce Improvement Program,”

December 19, 2005, as amended

(bb) DoD Instruction 5134.17, “Deputy Assistant Secretary of Defense for Developmental Test and Evaluation (DASD(DT&E)),” October 25, 2011

(bc) Director, Operational Test and Evaluation Memorandum, “Procedures for Operational Test and Evaluation of Information Assurance in Acquisition Programs,” January 21, 20093

(bd) Director, Operational Test and Evaluation Memorandum, “Clarification of Procedures for

Operational Test and Evaluation of Information Assurance in Acquisition Programs,” November 4, 20104

(be) Director, Operational Test and Evaluation Memorandum, “Test and Evaluation of Information Assurance in Acquisition Programs,” February 1, 2013

(bf) DoD Directive 5100.20, “National Security Agency/Central Security Service (NSA/CSS),” January 26, 2010

(bg) Committee on National Security Systems Policy 11, “National Policy Governing the Acquisition of Information Assurance (IA) and IA-Enabled Information Technology Products,” June 2013, as amended

(bh) Title 10, United States Code

(bi) Committee on National Security Systems Policy 15, “National Information Assurance

Policy on the Use of Public Standards for the Secure Sharing of Information Among National Security Systems,” October 1, 2012

(bj) DoD 5220.22-M, “National Industrial Security Program Operating Manual,” February 28, 2006, as amended

3 Available at http://www.dote.osd.mil/pub/policies/2009/20090121Procedure_forOTEofIAinAcqPrograms.pdf.

4 Avalable at http://www.dote.osd.mil/pub/policies/2010/20101104Clarification_ofProcedures_forOTE_ofIA_inAcq Progs.pdf.

ENCLOSURE 1 11

(bk) DoD Directive O-8530.1, “Computer Network Defense (CND),” January 8, 2001

(bl) DoD Instruction O-8530.2, “Support to Computer Network Defense (CND),” March 9,

(bm) DoD Instruction 5200.44, “Protection of Mission Critical Functions to Achieve Trusted

Systems and Networks (TSN),” November 5, 2012

(bn) DoD Instruction 8560.01, “Communications Security (COMSEC) Monitoring and

Information Assurance (IA) Readiness Testing,” October 9, 2007

(bo) DoD Manual 5200.01, Volume 3, “DoD Information Security Program: Protection of

Classified Information,” February 24, 2012, as amended

(bp) DoD Manual 5200.01, Volume 4, “DoD Information Security Program: Controlled

Unclassified Information (CUI),” February 24, 2012

(bq) DoD 5400.11-R, “Department of Defense Privacy Program,” May 14, 2007

(br) Committee on National Security Systems Instruction 1010, “24 x 7 Computer Incident

Response Capability (CIRC) on National Security Systems,” October 3, 2012

(bs) DoD Manual 5200.01, Volume 1, “DoD Information Security Program: Overview, Classification, and Declassification,” February 24, 2012

(bt) DoD Instruction 1400.25, Volume 731, “DoD Civilian Personnel Management System:

Suitability and Fitness Adjudication For Civilian Employees,” August 24, 2012

(bu) Title 29, United States Code

(bv) National Institute of Standards and Technology Special Publication 800-34, Revision 1, “Contingency Planning Guide for Federal Information Systems,” current edition

(bw) DoD 5200.08-R, “Physical Security Program,” April 9, 2007, as amended

(bx) DoD Chief Information Officer Memorandum, “Cross Domain Support Element (CDSE)

Responsibilities,” October 11, 2011

(by) DoD Manual 5200.01, Volume 2, “DoD Information Security Program: Marking of

Classified Information,” February 24, 2012, as amended

(bz) DoD 5220.22-R, “Industrial Security Regulation,” April 12, 1985

(ca) Committee on National Security Systems Policy 300, “National Policy on Control of

Compromising Emanations,” April 2004, as amended

(cb) Committee on National Security Systems Instruction 7000, “TEMPEST Countermeasures for Facilities,” May 2004, as amended

(cc) DoD Directive 5015.2, “DoD Records Management Program,” March 6, 2000

(cd) Unified Command Plan, current edition

(ce) Chairman of the Joint Chiefs of Staff Instruction 6510.01, “Information Assurance (IA) and

Support to Computer Network Defense (CND),” February 9, 2011, as amended

(cf) National Institute of Standards and Technology Special Publication 800-30, “Guide for

Conducting Risk Assessments,” current edition

(cg) DoD Directive 5105.53, “Director of Administration and Management (DA&M),”

February 26, 2008

(ch) National Institute of Standards and Technology Special Publication 800-37, “Guide for

Applying the Risk Management Framework to Federal Information Systems,” current edition

(ci) Committee on National Security Systems Instruction 1253, “Security Categorization and Control Selection for National Security Systems,” March 15, 2012, as amended

ENCLOSURE 1 12

(cj) National Institute of Standards and Technology Special Publication 800-53, “Recommended Security Controls for Federal Information Systems and Organizations,” current edition

(ck) National Institute of Standards and Technology Special Publication 800-53A, “Guide for Assessing the Security Controls in Federal Information Systems,” current edition

(cl) Section 806 of the Ike Skelton National Defense Authorization Act for Fiscal Year 2011, January 7, 2011

(cm) DoD Directive 3020.26, “Department of Defense Continuity Programs,” January 9, 2009

(cn) Secretary of Defense Memorandum, “Maintaining Readiness to Operate in Cyberspace

Domain,” December 7, 2012

(co) DoD Instruction 8523.01, “Communications Security (COMSEC),” April 22, 2008

(cp) National Institute of Standards and Technology Special Publication 800-126, “The

Technical Specification for Security Content Automation Protocol (SCAP): SCAP Version 1.0,” current edition

(cq) DoD O-8530.01-M, “Department of Defense Computer Network Defense (CND) Service Provider Certification and Accreditation Program,” December 17, 2003

(cr) DoD Instruction 8410.02, “NetOps for the Global Information Grid (GIG),” December 19,

(cs) National Institute of Standards and Technology Special Publication 800-137, “Information Security Continuous Monitoring,” current edition

(ct) DoD Instruction 8520.03, “Identity Authentication for Information Systems,” May 13,

(cu) DoD Directive 5505.13E, “DoD Executive Agent (EA) for the DoD Cyber Crime Center (DC3),” March 1, 2010

(cv) DoD Instruction 5240.26, “Countering Espionage, International Terrorism, and the Counterintelligence (CI) Insider Threat,” May 4, 2012, as amended

(cw) Chairman of the Joint Chiefs of Staff Instruction 3170.01, “Joint Capabilities Integration and Development System,” January 10, 2012

(cx) DoD Directive 7045.14, “The Planning, Programming, Budgeting, and Execution (PPBE) Process,” January 25, 2013

(cy) DoD Chief Information Officer Memorandum, “Department of Defense Chief Information Officer Executive Board Charter,” July 7, 2005

(cz) DoD Instruction 5200.01, “DoD Information Security Program and Protection of Sensitive Compartmented Information,” October 9, 2008, as amended

(da) DoD Instruction 8320.02, “Sharing Data Information, and Technology (IT) Services in the Department of Defense,” August 5, 2013

(db) DoD 8320.02-G, “Guidance for Implementing Net-Centric Data Sharing,” April 12, 2006

(dc) DoD Directive 5230.09, “Clearance of DoD Information for Public Release,” August 22,

(dd) DoD Instruction 8582.01, “Security of Unclassified DoD Information on Non-DoD

Information Systems,” June 6, 2012

(de) DoD Instruction 5400.16, “DoD Privacy Impact Assessment (PIA) Guidance,”

February 12, 2009

(df) DoD 8580.02-R, “DoD Health Information Security Regulation,” July 12, 2007

(dg) DoD Manual 5205.02, “DoD Operations Security (OPSEC) Program Manual,”

November 3, 2008

ENCLOSURE 1 13

(dh) DoD Instruction 8550.01, “DoD Internet Services and Internet-Based Capabilities,” September 11, 2012

(di) Under Secretary of Defense for Acquisition, Technology, and Logistics Memorandum, “Document Streamlining Program Protection Plan,” July 18, 2011

(dj) Section 811 of Public Law 106-398, “National Defense Authorization Fiscal Year 2001,” October 30, 2000

(dk) DoD Instruction 8581.01, “Information Assurance (IA) Policy for Space Systems Used by the Department of Defense,” June 8, 2010

(dl) Committee on National Security Systems Instruction 4004.1, “Destruction and Emergency Protection Procedures for COMSEC and Classified Material,” August 2006, as amended

(dm) National Institute of Standards and Technology Special Publication 800-88, “Guidelines for Media Sanitization,” current edition

(dn) DoD Architecture Framework Version 2.02, August 20105

(do) DoD Instruction 5000.64, “Accountability and Management of DoD Equipment and Other

Accountable Property,” May 19, 2011

(dp) DoD Instruction 2030.08, “Implementation of Trade Security Controls (TSC) for Transfers of DoD U.S. Munitions List (USML) and Commerce Control List (CCL) Personal Property to Parties Outside DoD Control,” May 23, 2006

(dq) DoD Instruction 1035.01, “Telework Policy,” April 4, 2012

(dr) National Institute of Standards and Technology Special Publication 800-114, “Users Guide to Securing External Devices for Telework and Remote Access,” current edition

(ds) National Institute of Standards and Technology Special Publication 800-147, “Basic

Input/Output System (BIOS) Protection Guidelines,” current edition

(dt) Assistant Secretary of Defense for Networks and Information Integration/DoD Chief

Information Officer, “Coalition Public Key Infrastructure, X.509 Certificate Policy,” current edition

(du) DoD Directive 5230.20, “Visits and Assignments of Foreign Nationals,” June 22, 2005

(dv) DoD Instruction 5230.27, “Presentation of DoD-Related Scientific and Technical Papers at

Meetings,” October 6, 1987

(dw) DoD Instruction 2040.02, “International Transfers of Technology, Articles, and Services,”

July 10, 2008

(dx) DoD Instruction 1100.22, “Policy and Procedures for Determining Workforce Mix,”

April 12, 2010

(dy) DoD Directive 5205.02E, “DoD Operations Security (OPSEC) Program,” June 20, 2012

(dz) Committee on National Security Systems Instruction Number 4009, “National Information

Assurance (IA) Glossary,” April 26, 2010, as amended

(ea) Joint Publication 1-02, “DoD Dictionary of Military and Associated Terms,” current edition

(eb) National Institute of Standards and Technology Special Publication 800-63, “Electronic

Authentication Guideline,” current edition

5 Available at http://dodcio.defense.gov/dodaf20.aspx.

ENCLOSURE 2 14

ENCLOSURE 2

RESPONSIBILITIES

1. DoD CIO. The DoD CIO:

a. Monitors, evaluates, and provides advice to the Secretary of Defense regarding all DoD cybersecurity activities and oversees implementation of this instruction.

b. Develops and establishes DoD cybersecurity policy and guidance consistent with this instruction and in accordance with applicable federal law and regulations.

c. Appoints a DoD SISO in accordance with section 3541 of Title 44, U.S.C. (Reference (aa)).

d. Coordinates with the Under Secretary of Defense for Policy (USD(P)) to ensure that cybersecurity strategies and policies are aligned with overarching DoD cyberspace policy and, in accordance with DoDD 5230.11 (Reference (ab)), support policies relating to the disclosure of classified military information to foreign governments and international organizations.

e. Coordinates with the Under Secretary of Defense for Personnel and Readiness (USD(P&R)) to:

(1) Ensure personnel identity policies and cybersecurity policies and capabilities are aligned and mutually supportive.

(2) Develop cybersecurity workforce management policies and capabilities to support identification and qualifications for a professional cybersecurity workforce.

f. Coordinates with the Under Secretary of Defense for Intelligence (USD(I)) to ensure that cybersecurity policies and capabilities are aligned with and mutually supportive of personnel, physical, industrial, information, and operations security policies and capabilities.

g. Coordinates with NIST in development of cybersecurity-related standards and guidelines.

h. Maintains a formal coordination process with the Intelligence Community (IC) Chief Information Officer (CIO) to ensure proper protection of IC information within DoD, reciprocity of IS authorization and cybersecurity risk management processes, and alignment of cybersecurity.

i. Coordinates with the Under Secretary of Defense for Acquisition, Technology, and Logistics (USD(AT&L)) to ensure that cybersecurity responsibilities are integrated into processes for DoD acquisition programs, including research and development.

ENCLOSURE 2 15

j. Coordinates with the Director, Operational Test and Evaluation (DOT&E) to ensure that cybersecurity responsibilities are integrated into the operational testing and evaluation for DoD acquisition programs.

k. Coordinates and advocates resources for DoD-wide cybersecurity solutions, including overseeing appropriations allocated to the DoD cybersecurity program.

l. Appoints a PAO for DoD ISs and PIT systems governed by the Enterprise Information Environment Mission Area (MA) (EIEMA) as described in DoDD 8115.01 (Reference (ac)).

m. Coordinates with the DoD MA owners to ensure that cybersecurity responsibilities are addressed for all DoD IT.

n. Coordinates with the USD(P) and USD(I) on integrating Defense Industrial Base (DIB) cybersecurity threat information-sharing activities and enhancing DoD and DIB cyber situational awareness in accordance with DoDI 5205.13 (Reference (ad)) and in support of DoDD 3020.40 (Reference (ae)).

o. Develops policy for negotiating, performing, and concluding agreements with international partners to engage in cooperative international cybersecurity activities, in coordination with the USD(P), USD(I), and the Director, National Security Agency (NSA)/Chief, Central Security Service (DIRNSA/CHCSS).

p. Negotiates and concludes agreements with international partners to engage in cooperative international cybersecurity and cyberspace defense activities, according to authority described in Deputy Secretary of Defense Memorandum (Reference (af)) and subject to the provisions of DoDD 5530.3 (Reference (ag)), in coordination with the:

(1) USD(P).

(2) General Counsel of the Department of Defense.

(3) Under Secretary of Defense (Comptroller)/Chief Financial Officer, Department of

Defense.

(4) USD(I), when such agreements materially affect cleared industry.

(5) CJCS.

q. Establishes policy for the life cycle management of cross-domain (CD) solutions (CDSs).

This policy will address shared risk, in coordination with the IC CIO and with the direct support from the DoD/IC Unified Cross Domain Management Office (UCDMO) in accordance with Joint DoD/IC Memorandum (Reference (ah)) and the UCDMO Charter (Reference (ai)).

ENCLOSURE 2 16

r. Develops and implements policy regarding continuous monitoring of DoD IT with direct support from NSA/CSS and Defense Information Systems Agency (DISA), and input from the other DoD Components.

s. Appoints a military officer in the grade of O-6 or an equivalent civilian employee as the Defense IA Security Accreditation Working Group (DSAWG) Chair.

t. Develops and implements policy for cybersecurity workforce awareness, education, training, and qualification in coordination with the USD(P&R).

u. Maintains a Defense-wide view of cybersecurity resources that supports national, organizational, joint, and DoD Component cybersecurity program planning.

v. Conducts an annual assessment of DoD Component cybersecurity programs as required by section 3545 of Reference (aa).

w. Co-chairs the Enterprise-wide IA and Computer Network Defense Solutions Steering

Group (ESSG) in accordance with the ASD(NII)/DoD CIO/Commander, U.S. Strategic Command Memorandum (Reference (aj)).

x. Ensures that compromising emanations (i.e., TEMPEST) countermeasures implemented within DoD comply with current national policies.

y. Ensures compliance with the requirements of National Security Directive 42 (Reference

(ak)) and collaborate with the DIRNSA/CHCSS on the performance of DIRNSA/CHCSS duties, pursuant to Reference (ak), as the National Manager for National Security Telecommunications and Information Systems Security.

2. DIRECTOR, DISA. Under the authority, direction, and control of the DoD CIO and in addition to the responsibilities in section 13 of this enclosure, the Director, DISA:

a. Develops, implements, and, in coordination with Commander, U.S. Strategic Command (USSTRATCOM), manages cybersecurity for the DISN, consistent with this instruction and its supporting guidance.

b. Develops and maintains control correlation identifiers (CCIs), security requirements guides (SRGs), security technical implementation guides (STIGs), and mobile code risk categories and usage guides that implement and are consistent with DoD cybersecurity policies, standards, architectures, security controls, and validation procedures, with the support of the NSA/CSS, using input from stakeholders, and using automation whenever possible.

c. Develops or acquires solutions that support cybersecurity objectives for use throughout DoD via the ESSG process in accordance with Reference (aj).

d. Establishes and maintains the IA Support Environment (IASE) in accordance with

ENCLOSURE 2 17

Office of Management and Budget Circular A-130 (Reference (al)) as the DoD knowledge repository for cybersecurity related policy, guidance, and information.

e. Oversees and maintains the connection approval process in accordance with CJCS Instruction (CJCSI) 6211.02 (Reference (am)), CD connection policy as issued by DoD CIO, DoDI 8551.01 (Reference (an)), and DoDI 8100.04 (Reference (ao)) for the DISN (e.g., the Secret Internet Protocol Router Network (SIPRNet) and the Non-Classified Internet Protocol Router Network (NIPRNet)) in coordination with the DSAWG (Reference (ap)) and DoD ISRMC (Reference (aq)), when appropriate.

f. Facilitates multinational information sharing efforts, as well as information sharing between the DoD Components and eligible foreign nations in support of approved international cybersecurity and cyberspace defense agreements.

g. Supports training, exercises, workforce development, network evaluation, and other efforts to build international partner cybersecurity and cyberspace defense capacity.

h. Provides enterprise CD services compliant with the UCDMO-managed CDS Baseline List of validated solutions posted on the SIPRNet and the Joint Worldwide Intelligence Communications System (JWICS) UCDMO Intelink sites. Working with UCDMO, integrates new CD requirements into DoD Enterprise CD services.

i. Ensures the continued development and maintenance of guidance and standards procedures to catalog, regulate, and control the use and management of Internet protocols, data services, and associated ports on DoD networks, in accordance with Reference (an).

j. Develops and provides cybersecurity training and awareness products and a distributive training capability to support the DoD Components in accordance with Reference (w) and post the training materials on the IASE Website (http://iase.disa.mil/).

k. Conducts command cyber readiness inspections and operational risk assessments in support of USSTRATCOM.

l. Coordinates with the USD(I) to ensure command cyber readiness inspection guidance and metrics provide a unity of effort among the security disciplines (i.e., personnel, physical, industrial, information, operations, and cybersecurity).

3. USD(AT&L). The USD(AT&L):

a. Integrates policies established in this instruction and its supporting guidance into acquisition policy, regulations, and guidance consistent with DoDD 5134.01 (Reference (ar)).

b. Through the Assistant Secretary of Defense for Research and Engineering, monitors and oversees all DoD cybersecurity research and engineering investments, including research at the

NSA.

ENCLOSURE 2 18

c. Integrates cybersecurity assessments into developmental testing and evaluation.

d. Establishes and maintains the Cybersecurity and Information Assurance Center (formerly IA Technology Analysis Center) in accordance with DoDI 3200.12 (Reference (as)).

e. Ensures that the DoD acquisition process incorporates cybersecurity planning, implementation, testing, and evaluation consistent with Reference (q), DoDI 8580.01 (Reference (at)), DoDD 5000.01 (Reference (au)), DoDI 5000.02 (Reference (av)), DoDI 4630.8 (Reference (aw)), section 1043 of Public Law 106-65 (Reference (ax)), and this instruction, in coordination with the DoD CIO.

f. Assists with acquisition-related (e.g., research, development, test and evaluation (T&E)) agreements, and international cybersecurity and cyberspace defense negotiations and agreements, in accordance with Reference (ag), as needed.

g. Ensures that PIT systems included in acquisition programs are designated, categorized, and have their authorization boundaries defined according to the guidelines provided in Reference (q).

h. Ensures that policy and procedures for developing program protection plans (PPPs) required by DoDI 5200.39 (Reference (ay)) address cybersecurity in accordance with this instruction.

i. Defines, develops, and integrates systems security engineering (SSE) into the systems engineering workforce and curriculum in accordance with DoDI 5134.16 (Reference (az)).

j. Ensures that acquisition community personnel with IT development responsibilities are qualified in accordance with Reference (w) and DoD 8570.01-M (Reference (ba)).

k. Coordinates with the DoD Test Resource Management Center (TRMC) for establishment of developmental T&E (DT&E) specific cybersecurity architectures and requirements.

4. DEPUTY ASSISTANT SECRETARY OF DEFENSE FOR DT&E (DASD(DT&E)). Under the authority, direction, and control of the USD(AT&L), the DASD(DT&E):

a. Exercises oversight responsibility for developmental test planning in support of interoperability and cybersecurity for programs acquiring DoD IS and PIT systems in accordance with DoDI 5134.17 (Reference (bb)).

b. Establishes procedures to ensure that cognizant DT&E authorities for acquisition programs verify that adequate DT&E to support cybersecurity is planned, resourced, documented, and can be executed in a timely manner prior to approval of program documents.

ENCLOSURE 2 19

5. DOT&E. The DOT&E:

a. Develops and provides policy for cybersecurity testing and evaluation during operational evaluations within DoD, including, but not limited to the DOT&E Memorandum (Reference (bc)) describing the cybersecurity testing process, clarified by updates in the DOT&E Memorandums (References (bd) and (be)).

b. Conducts independent cybersecurity assessments during operational test and evaluation (OT&E) for systems under acquisition and reports the findings as part of the acquisition process.

c. Oversees cybersecurity assessments by test agencies during both acquisition and exercise events as mandated by relevant statutory requirements.

d. Reviews and approves cybersecurity OT&E documentation for all IT, IS, PIT, and special interest programs as required.

6. USD(P). The USD(P):

a. Coordinates with the DoD CIO to ensure that cybersecurity strategies, policies, and capabilities are aligned with overarching DoD cyberspace policy, and are supportive of policies and capabilities relating to the disclosure of classified military information to foreign governments and international organizations in accordance with Reference (ab).

b. Coordinates with the DoD CIO on international cybersecurity and cyberspace defense strategies and policies, as well as the negotiating, performing, and concluding agreements with international partners to engage in cooperative, international cybersecurity and cyberspace defense activities in accordance with Reference (af).

c. Coordinates with the DoD CIO on enhancing DoD and DIB cyber situational awareness in accordance with Reference (ad) and in support of Reference (ae).

7. USD(P&R). The USD(P&R) supports implementation of cybersecurity requirements for effective manning, management, and readiness assessment of the cybersecurity workforce in accordance with References (w) and (ba).

8. USD(I). The USD(I):

a. Coordinates with the DoD CIO on development and implementation of cybersecurity policy, guidance, procedures, and controls related to personnel, physical, industrial, information and operations security.

ENCLOSURE 2 20

b. Coordinates with the DoD CIO and the USD(P) on intelligence-related international cybersecurity and cyberspace defense strategies, policies, and agreements with international partners.

c. Appoints the PAO for DoD ISs and PIT systems governed by the DoD portion of the Intelligence Mission Area (DIMA) as described in Reference (ac).

9. DIRNSA/CHCSS. Under the authority, direction, and control of the USD(I), and in addition to the cybersecurity-related responsibilities in DoDD 5100.20 (Reference (bf)) and the responsibilities in section 13 of this enclosure, the DIRNSA/CHCSS:

a. Supports the DoD CIO by providing cybersecurity architecture and mechanisms to support Defense military, intelligence, and business functions, including but not limited to cryptography, PKI, and IS security engineering services.

b. Evaluates or validates security implementation specifications described in this instruction.

c. Provides cybersecurity support to the DoD Components in order to assess threats to, and vulnerabilities of, information technologies.

d. Engages the cybersecurity industry and DoD user community to foster development, evaluation, and deployment of cybersecurity solutions that satisfy the guidance in this instruction.

e. Provides SSE services to the DoD Components, including describing information protection needs, properly selecting and implementing appropriate security controls, and assessing the effectiveness of system security.

f. Supports the development of NIST publications and provides engineering support and other technical assistance for their implementation within DoD.

g. Develops SSE training and qualification programs and oversees continuing education requirements for all trained IS security engineers and cybersecurity architects throughout DoD in accordance with Reference (ba).

h. Serves as the DoD focal point for the National IA Partnership and establishes criteria and processes for evaluating and validating all IA and IA-enabled products in accordance with CNSSP 11 (Reference (bg)).

i. Develops and issues security implementation specifications for the configuration of IA-and IA-enabled products (e.g., security configuration guides) and supports DISA in the development of SRGs and STIGs.

ENCLOSURE 2 21

j. Serves as the DoD focal point for cybersecurity cryptographic research and development in accordance with Assistant Secretary of Defense for Research and Engineering direction and in coordination with the Director, Defense Advanced Research Projects Agency.

k. Manages the DoD IA Scholarship Program in accordance with sections 2200-2200f of

Title 10, U.S.C. (Reference (bh)).

l. Plans, designs, manages, and executes the development and implementation of the key management infrastructure within DoD in coordination with DoD CIO.

m. Plans, designs, and manages the development and implementation of PKI within DoD, in coordination with DoD CIO and DISA.

n. Approves all applications of cryptographic algorithms for the protection of classified information.

o. Approves all cryptography used to protect classified information in accordance with

CNSSP 15 (Reference (bi)).

p. Develops, implements, and manages a cybersecurity program for layered protection of

DoD cryptographic SCI systems and a cybersecurity education, training, and awareness program for users and administrators of DoD cryptographic SCI systems in accordance with applicable DoD and DNI policies and guidance.

q. Conducts risk assessments of mobile code technologies, recommends the assignment of mobile code technologies to specific risk categories, and provides technical advice and assistance in the development of countermeasures to identified risks associated with specific mobile code technology implementations.

10. DIRECTOR, DEFENSE SECURITY SERVICE (DSS). Under the authority, direction, and control of the USD(I) and in addition to the responsibilities in section 13 of this enclosure, the Director, DSS, monitors and oversees IS security practices of DoD contractors and vendors processing classified DoD information in accordance with DoD 5220.22M (Reference (bj)), and DoDD O-8530.1 (Reference (bk)), and DoDI O-8530.2 (Reference (bl)).

11. DIRECTOR, DEFENSE INTELLIGENCE AGENCY (DIA). Under the authority, direction, and control of the USD(I) and in addition to the responsibilities in section 13 of this enclosure, the Director, DIA:

a. Provides finished intelligence, including threat assessments, in support of cybersecurity activities.

b. Develops, implements, and manages a cybersecurity program for DoD non-cryptographic SCI systems, including the DoD Intelligence IS (DoDIIS) and JWICS.

ENCLOSURE 2 22

12. DEPUTY CHIEF MANAGEMENT OFFICER (DCMO). The DCMO appoints the PAO for DoD ISs and PIT systems governed by the Business Mission Area (BMA), as described in Section 2222 of Reference (aa).

13. DoD COMPONENT HEADS. The DoD Component heads:

a. Ensure that IT under their purview complies with this instruction.

b. Ensure that cybersecurity requirements are addressed and visible in all capability portfolios, IT life-cycle management processes, and investment programs incorporating IT.

c. Appoint an AO for all DoD IS and PIT systems under their purview and ensure all DoD ISs and PIT systems are authorized in accordance with Reference (q).

d. Ensure that PIT systems are identified, designated as such, and centrally registered at the DoD Component level.

e. Ensure that SSE and trusted systems and networks (TSN) processes, tools, and techniques described in DoDI 5200.44 (Reference (bm)) are used in the acquisition of all applicable IT under their purview.

f. Ensure that organizational solutions that support cybersecurity objectives acquired and developed via the ESSG process in accordance with Reference (aj) are implemented when possible, and participate in the ESSG process to ensure capabilities acquired or developed meet organizational requirements.

g. Provide for a cybersecurity monitoring and testing capability in accordance with DoDI

8560.01 (Reference (bn)) and other applicable laws and regulations.

h. Provide for vulnerability mitigation and incident response and reporting capabilities in order to:

(1) Comply with mitigations as directed by Commander, USSTRATCOM orders, or other directives such as alerts and bulletins and provide support to cyberspace defense, in accordance with Reference (bl).

(2) Limit damage and restore effective service following an incident.

(3) Collect and keep audit data to support technical analysis relating to misuse, penetration, or other incidents involving IT under their purview, and provide this data to appropriate law enforcement (LE) or other investigating agencies.

(4) Establish procedures to ensure prompt management action and reporting in accordance with:

ENCLOSURE 2 23

(a) DoD Manual (DoDM) 5200.01, Volume 3 (Reference (bo)) for an actual or potential compromise of classified information.

(b) DoDM 5200.01, Volume 4 (Reference (bp)) for an actual or potential unauthorized disclosure of controlled unclassified information (CUI) (e.g., proprietary information, LE information).

(c) Reference (bj) when such losses occur on cleared contractor systems.

(d) DoD 5400.11-R (Reference (bq)) for a loss or unauthorized disclosure of personally identifiable information (PII) or other Privacy Act information.

(5) Comply with CNSS Instruction (CNSSI) 1010 (Reference (br)).

i. Ensure that contracts and other agreements include specific requirements to provide cybersecurity for DoD information and the IT used to process that information in accordance with this instruction.

j. Ensure that all personnel with access to DoD IT are appropriately cleared and qualified under the provisions of Reference (v) and that access to all DoD IT processing specified types of information (e.g., collateral, SCI, CUI) under their purview is authorized in accordance with the provisions of Reference (bo) and DoDM 5200.01, Volume 1 (Reference (bs)) or Reference (bp).

k. Ensure that personnel occupying cybersecurity positions are:

(1) Assigned…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .