SSO_Toolkit_CONOPS.pdf
PDF 1 MB Posted
- Attached to
- Enterprise Architecture (EACOE) Quick Start Federal contract opportunity
- Solicitation number
- HB0001-18-R-0003
- Issued by
- Department of Defense Cyber Command
About this file
SSO_Toolkit_CONOPS
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| SSO_Automation_Automation_Vision.pdf | ||
| J6_forms.pdf | ||
| ServiceNow_SOW_General_Provisions.pdf | ||
| Language_Immersion_Trip_February_2015.pdf | ||
| SCI_ATTESTATION.pdf | ||
| SCI_Pre_Screen_Questionaire_DEC_2017.pdf | ||
| USCC_Non-Disclosure_Agreement.pdf | ||
| dd254_SNOW.pdf | ||
| HR_Toolkit_Conops__Task_Management.pdf | ||
| FORM_4414_Rev_12-2013_fillable_(Savable).pdf | ||
| Resume_Template.pdf | ||
| ACS_050515_eform.pdf | ||
| dd2875_(blank).pdf | ||
| SIP_050515_eform.pdf | ||
| SCI_Reporting_Memo.pdf | ||
| Foreign_Travel_Questionnaire.pdf | ||
| CS_050515_eform.pdf | ||
| SSO_Toolkit_SOW.pdf | ||
| SF312.pdf | ||
| Past_Performance_Template.pdf | ||
| HR_Toolkit_SOW.pdf | ||
| Questionaire_Response_Attachment_20180119.pdf | ||
| 10-SIP_Instructions.pdf | ||
| Religious_Mission_Trip_February_2015.pdf | ||
| HR_Toolkit_Process_Flows_Final.pdf | ||
| Asset_Config_Management_SOW.pdf | ||
| US_Cyber_Command_Pre_Screen_Notice_20180308.pdf |
Show all 27
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
UNCLASSIFIED//FOR OFFICIAL USE ONLY
w 3
CONCEPT OF 6
OPERATIONS FOR 7
US Cyber Command 8
Special Security Office Task Management Tool 9
Version 0.1 10
March 29, 2018 11
3/29/2018 UNCLASSIFIED//FOR OFFICIAL USE ONLY Page 2 of 32
Version Date
Comments Author
.1 03/29/18 Initial Version E. Wojciechowski
3/29/2018 UNCLASSIFIED//FOR OFFICIAL USE ONLY Page 3 of 32
TABLE OF CONTENTS
Contents 1
CONCEPT OF OPERATIONS FOR ................................................................................................... 1 2
TABLE OF CONTENTS ...................................................................................................................... 3 3
1. (U//FOUO) Executive Summary .......................................................................................... 4 4
2. (U//FOUO) CONOPS Scope ................................................................................................ 4 5
2.1. (U//FOUO) Identification ..................................................................................................... 5 6
2.2. (U//FOUO) Document security ............................................................................................ 5 7
2.3. (U//FOUO) System security ................................................................................................. 5 8
3. (U//FOUO) Current system or situation ............................................................................... 5 9
3.1. (U//FOUO) Background, objectives, and scope ................................................................... 5 10
3.2. (U//FOUO) Operational policies and constraints ................................................................. 6 11
3.3. (U//FOUO) Description of current system or situation ........................................................ 7 12
3.4. (U//FOUO) System User Classes ....................................................................................... 13 13
3.5. (U//FOUO) Support concept ............................................................................................... 15 14
4. (U//FOUO) Analysis of the proposed system ..................................................................... 15 15
4.1. (U//FOUO) Summary of advantages .................................................................................. 15 16
4.2. (U//FOUO) Summary of disadvantages or limitations ....................................................... 16 17
4.3. (U//FOUO) Alternatives and trade-offs considered ............................................................ 16 18
5. (U//FOUO) Concept for a new or modified system ........................................................... 16 19
5.1. (U//FOUO) Description of the new or modified system .................................................... 16 20
5.2. (U//FOUO) Support concept ............................................................................................... 20 21
5.3. (U//FOUO) Operational scenarios ...................................................................................... 23 22
6. (U//FOUO) Summary of impacts ....................................................................................... 28 23
6.1. (U//FOUO) Operational impacts ........................................................................................ 28 24
6.2. (U//FOUO) Organizational impacts .................................................................................... 28 25
6.3. (U//FOUO) Impacts during development ........................................................................... 29 26
7. (U//FOUO) Notes ............................................................................................................... 29 27
8. (U//FOUO) Appendices ...................................................................................................... 30 28
Appendix A: Acronyms .......................................................................................................................... 31 29
Page 4 of 32 UNCLASSIFIED//FOR OFFICIAL USE ONLY
1. (U//FOUO) Executive Summary 31
(U//FOUO) US CYBER COMMAND’s (USCYBERCOM) primary location is co-33 located within the National Security Agency (NSA) at Ft. Meade, Maryland. All 34 individuals who will be working at USCYBERCOM’s offices must go through a two 35 step process before being granted approval for both physical and network access to 36
USCYBERCOM facilities and networks. All personnel must first have a current security 37 clearance level of Top Secret/ Sensitive Compartmented Information with a Counter 38
Intelligence Polygraph (TS/SCI with CI/Poly). After USCYBERCOM verifies or 39 approves the security clearance for the individual, NSA then makes a determination as to 40 granting access to the NSA facilities and networks. Once both these actions are fully 41 adjudicated, an individual is granted access to both NSA facilities and 42
NSA/USCYBERCOM networks. This is a lengthy process that can take several months 43 to years for full resolution. Currently, this process is primarily manual. This Special 44
Security Office (SSO) CONOPS presents a vision for automating the multiple forms that 45 an individual must complete in order to obtain both the security clearance and access 46 approval. Automating this data collection will be the first step of increasing the 47 automation of the security clearance and access approval processes as well as other 48 processes with the SSO. It is anticipated that automating the data collection will 49 potentially reduce the time to obtain approval to work at USCYBERCOM through 50 improved data integrity and reduction of multiple manual data entry processes on both 51 the in-bound individual as well as the SSO staff. Additionally, this automation will 52 provide transparency to the command leadership through automated reporting of the 53 status of security clearance processes. USCYBERCOM’s security office will leapfrog 54 into the 21st century with a set of tools to support moving at the speed of cyber for 55 security processing. 56
2. (U//FOUO) CONOPS Scope 58
(U//FOUO) In addition to the National Background Investigations Bureau Electronic Questionnaires 60 for Investigations Processing (e-QIP), USCBYERCOM also requires additional information specific to 61
USCYBERCOM to be submitted by individuals who will be working at USCYBERCOM facilities (In-62 bound individuals). This CONOP is limited to the automated tools required that will support a single 63 data entry of all required information by an in-bound individual who will be working at 64
USCYBERCOM1. 65
1 This CONOPS does not replace the current e-QIP. e-QIP is still required and integration with e-QIP tool while desire is not required as part of the solution.
Page 5 of 32 UNCLASSIFIED//FOR OFFICIAL USE ONLY
2.1. (U//FOUO) Identification 68
2.2. (U//FOUO) Document security 70
(U//FOUO) All information documented herein shall be classified as “Unclassified, For 72
Official Use Only” (U/OFUO). 73
2.3. (U//FOUO) System security 75
(U/FOUO) The primary end users of this system are both individuals who currently do 77 not have an affiliation with USCYBERCOM (in-bound individuals) as well as 78
USCYBERCOM Security and Counter Intelligence, Special Security Office (SSO) 79 users. Based upon these two different user groups, the system will be available through 80 both the Internet (grey space) and within the NSA/USCBYERCOM intranet (both Top 81
Secret and Unclassified environments). It is anticipated that data will be required to be 82 exchanged between all these security environments. The data that is being collected will 83 contain “Personally Identifiable Information (PII2). Applying the Risk Management 84
Framework controls, it is anticipated that these systems will have a Confidentiality 85 rating of high, Integrity rating of high and an availability rating of medium. The system 86 must have security controls implemented consistent with these anticipated ratings. 87
3. (U//FOUO) Current system or situation 89
3.1. (U//FOUO) Background, objectives, and scope 91
(U/FOUO) The mission of the SSO is: “…responsible for the protection of 93
USCYBERCOM information, people and facilities. The SSO Division integrates 94 personnel and physical security disciplines with counterintelligence programs to 95 achieve a security in depth posture that manages the risks arrayed USCYBERCOM 96 extraordinary sensitive and fragile mission….” 97
(U//FOUO) SSO is currently hampered in its ability to fully meet the mission and vision 98 as stated due to a reliance upon manual data entry into multiple disconnected existing 99 systems, manual tools and processes. As USCYBERCOM continues to increase staffing 100 levels and the corresponding security activities, a reliance upon manual tools and 101 processes will adversely impact the SSO’s ability to manage the anticipated staffing levels. 102
Additionally, providing leadership with timely information regarding current staffing 103 security actions, is a staff intensive, manual effort and represents data that is aged and 104
2 It is anticipated that this system will be covered under the same SORN as the J1 Human Resources Toolkit and will not require a separate SORN.
Page 6 of 32 UNCLASSIFIED//FOR OFFICIAL USE ONLY often not actionable. 105
. 106
(U//FOUO) The scope of this CONOPS is to document the first phase of what is 107 envisioned to be a multi-phase project to bring automation to the SSO processes. This 108 first phase is to provide a tool to enable in-bound individuals to enter all required 109 information to support the USCYBERCOM/NSA security clearance and access 110 processes a single time. The system will collect all required data once, and then route 111 this information to the corresponding offices for processing and generate the necessary 112 forms (either electronic or paper) as required. In the collection of the user’s data, 113 corresponding technology will be leveraged to increase the accuracy of the information 114 entered by the user through the use of real-time chat, knowledge management 115
Frequently Asked Questions tailored to each data element requested and systematic 116 exchanges with the applicant that can be automatically tracked. The technology 117 solution is intended to support the current internal USCYBERCOM SSO user 118 community and the J1 manpower personnel directorate (MPR) and leadership within 119 each Directorates. The solution is intended to function in a complementary capacity to 120 existing internal and external systems. The optimal solution will minimize manual data 121 entry/manual data reporting while maximizing data integrity between these other 122 systems. 123
3.2. (U//FOUO) Operational policies and constraints 126
(U//FOUO) USCYBERCOM is a joint command with representatives from all military 127 services, other intelligence community agencies as well as civilian staff. All individuals 128 who will be stationed at and working at USCYBERCOM are required to comply with the 129 security policies of both USCYBERCOM and NSA. In developing this CONOP the 130 following policies have been used in guiding the content of this document: 131
a) DoD Directive 5124.02 “Under Secretary of Defense for Personnel and Readiness 133
(USD(P&R)),” June 23, 2008 134
b) DoD Directive 1400.25, “DoD Civilian Personnel Management Systems,” 135
November 25, 1996, http://dtic.mil/whs/directives/corres/CPM_table2.html 136
c) Subtitle III of Title 40, United States Code 137
d) Title 10, United States Code 138
e) DoD Directive 8115.01, “Information Technology Portfolio Management,” 139
October 10, 2005 140
f) DoD Directive 8000.01, “Management of the Department of Defense 141
Information Enterprise,” February 10, 2009 142 http://dtic.mil/whs/directives/corres/CPM_table2.html
Page 7 of 32 UNCLASSIFIED//FOR OFFICIAL USE ONLY
g) Office of the Deputy Chief Management Officer 143
Website, http://dcmo.defense.gov 144
h) DoD Instruction 5025.01, “DoD Directives Program,” September 26, 2012 as 145 amended 146
i) DoD Instruction 8510.01, “Risk Management Framework (RMF) for DoD 147
Information Technology(IT),” March 12, 2014, Incorporating change 1, Effective 148
May 24, 2016 149
j) DoD Instruction 5000.02, “Operation of the Defense Acquisitions System,” 150
January 7, 2015 151
k) DoD Directive 8500.01E “Information Assurance (IA),” April 23, 2007 152
l) DoD Manual 5200.01 – Volume 1, “DoD Information Security Program: 153
Overview, Classification, and Declassification,” February 24, 2012 154
m) National Institutes of Standards and Technology, Special Publication 800-53, 155
Rev 4 156
n) Section 552a of Title 5, United States Code, (also known as “The Privacy Act of 157
1974,” as amended) 158
o) DoD 5400.11, Department of Defense Privacy Program,” October 29, 2014 159
p) DoD Instruction 8910.01, “Information Collection and Reporting,” May 19, 2014 160
q) National Security Agency/Central Security Services (NSA/CSS), Security Policy Series 5 161
r) NSA/CSS Policy 5-1, Personnel Security Requirements for Members of the Service 162
Cryptologic Components Assigned or Detailed within NSA/CSS 163
3.3. (U//FOUO) Description of current system or situation 165
3.3.1. (U//FOUO) Operational environment 167
(U//FOUO) The current operational environment is a patchwork of primarily 168 disconnected systems and manual processes coupled with a dependency upon a 169 complex of external systems. The SSO currently relies upon a combination of physical 170 paper forms, email and MS Excel spreadsheets to track personnel security actions and 171 email to obtain status updates that are then manually entered into the Excel 172 spreadsheet. This method does not capture elapsed time within any one action or 173 within one individual or group. Providing any type of meaningful reports, such as 174 trend analysis, outstanding actions or number of priority actions as examples, is 175 challenging and results, when possible, are often delayed due to the manual efforts 176 required. 177
3.3.2. (U//FOUO) System Components 179 http://dcmo.defense.gov/
Page 8 of 32 UNCLASSIFIED//FOR OFFICIAL USE ONLY
(U//FOUO) In its role as the source of personnel security adjudication for the 181
USCYBERCOM, the SSO has organizational interactions across the command of 182
USCYBERCOM as well as working with other federal civilian agencies, commercial 183 financial reporting agencies as well as external military services related to personnel 184 security decisions. Some of these external agencies include the Federal Bureau of 185
Investigations, National Security Agency, commercial credit reporting agencies and 186 others. 187
3.3.3. (U//FOUO) Interfaces to external systems or procedures 190
(U/FOUO) In the performance of its mission, the SSO interacts with several data 191 processing systems that are external to USCYBERCOM. These systems are the official 192 records related to the in-bound individual or provide commercial reporting services 193 regarding the individual. Some of these external agencies and systems include the 194
Federal Bureau of Investigation National Criminal Information Center, National 195
Security Agency, financial reporting agencies such as Experian, TransUnion and others3. 196
In many instances, data is manually copied from these external systems to either a paper 197 file, manual data entry to another system or into office collaboration applications 198 maintained by the SSO. 199
3.3.4. (U//FOUO) Capabilities 204
(U//FOUO) The SSO along with the CDG/MI and J1, jointly participated in a series of 206 meetings from October through December 2016 and again in March 2018 with the 207 objective of identifying initial set of functionalities of the SSO Task Management Tool. 208
The team identified the following mission areas requiring support by the automated 209 tool: 210
Single Consolidated Data Entry for all personnel assigned to work at USCYBERCOM 211
Automated generation of “on-boarding” forms based upon above data entry 212
Automated workflow of security adjudication process 213
Automated data reporting 214
(U//FOUO) At the highest level of abstraction, J1 has identified a need for an automated 216 task management tool that would: 217 support the capture and tracking of work requests, 219 set prioritization of work requests through the application of business rules, 220 give assignment of work requests to “qualified and available staff”; and, 221
3 Integration with these other external agencies or commercial services is not included in the initial phase 1 scope.
Page 9 of 32 UNCLASSIFIED//FOR OFFICIAL USE ONLY provide robust real-time reporting capabilities. 222
(U//FOUO) (U//FOUO) Figure 1 SSO Task Management System Components illustrates a high 225 level notional concept of a work management foundational tool. This tool provides 226 generic work management capabilities that are configured based upon specific business 227 rules. The key concept is that the deployment of this tool supporting the SSO processes 228 and internal tracking is based upon configuration of native functionality within the 229
COTS software application rather than creating a custom application. Key features of 230 this work management foundational tool include: 231
Work Queue – backlog of work requests that need to be completed 233
User Queue – listing of users and their associated profiles 234
Business rules – defines the attributes of a work item, logic for prioritizing work 235 and expected timeframes for completion of work item or work step 236
User Assignment Rules – based upon user profile, matches available user to work 237 item and assigns work item to either individual user or group of users 238
Routing Rule – defines the activities that must be accomplished and the sequence 239 of steps to be performed based upon the type of work item. 240
Page 10 of 32 UNCLASSIFIED//FOR OFFICIAL USE ONLY
Business Application Layer
New Staff Inbound
Visitor Access Request
(VAR)
Periodic Security Reinvestigation
Contractor Security Renewal
Outbound
Security Office Events
Workflow/Task Management Processes
API
Task Management Application
Work Queue User Queue
Business Rules
User Assignment
Rules
Create/Update Work Item
Work Request
Routing Rules
More Steps EndNO
YES
(U//FOUO) Figure 1 SSO Task Management System Components 243
Page 11 of 32 UNCLASSIFIED//FOR OFFICIAL USE ONLY
3.3.5. (U//FOUO) Performance characteristics, 247
(U//FOUO) The nature of the work that SSO performs is of a medium-volume high-249 interaction nature. Low-volume in terms of the total number of security actions 250 performed each year. High-interaction in that multiple individuals are required to 251 complete any one security action. The table below provides estimated number of security 252 actions required to be supported by the proposed tool each year. 253
Mission Annual Projected Transactions – Low
Annual Projected Transactions –
High
New Staff – Inbound 1.500 15,000
VAR
Periodic Security Re-evaluation
Contractor Security Renewal
Outbound (U//FOUO) Table 1Volume Projections 255
3.3.6. (U//FOUO) Quality 256
Quality is a multidimensional aspect within the final solution. The following 257 identifies the critical aspects that must be included within the delivery of the 258 final solution. 259
3.3.6.1. (U//FOUO) Reliability: 261 defined as the ability of the software to consistently perform 262 according to its specifications. J1 requires that the application 263 perform according to the agreed upon specifications with no 264 critical defects ( a defect for which there is no system work 265 around). 266
3.3.6.2. (U//FOUO) Maintainability: 268 defined as the ease with which a system can be maintained and 269 corrected. Software industry recognizes four different types of 270 maintenance as noted below. Regardless of the types of 271 maintenance, the implementation of these maintenance activities 272 should not impact the production availability of the system to the 273 user community and be able to be performed during routine 274 maintenance times. 275
3.3.6.2.1. (U//FOUO) Adaptive: 277
Page 12 of 32 UNCLASSIFIED//FOR OFFICIAL USE ONLY modifying the system to cope with changes in the software 278 environment (system patches, application of STIGs, 279 application upgrades) 280
3.3.6.2.2. (U//FOUO) Perfective: 282 implementing new or changed user requirements which 283 concern functional enhancements to the software 284
3.3.6.2.3. (U//FOUO) Corrective: 286 diagnosing and fixing errors 287
3.3.6.2.4. (U//FOUO) Preventative: 289 increasing software maintainability or reliability to prevent 290 problems in the future 291
3.3.6.3. (U//FOUO) Availability: 293 defined as the percentage of time the application is available and 294 functioning for the end user. SSO requires an availability time of 295
99% Monday through Friday, 06:00 – 21:00 EST. 296
3.3.6.4. (U//FOUO) Portability: 298
There are several aspects to the applicability of software 299 portability. 300
3.3.6.4.1. (U//FOUO) Multiple operating systems support: 302
Ability to operate the software in different operating system 303 environments. The Command requires that the workflow 304 tool be able to be supported by current operating systems, 305 including standard PC desktops and servers, as well as 306 mobile computing platforms, such as Android, IOS and 307 other standards4. 308
3.3.6.4.2. (U//FOUO) Network security classification portability: 310
USCYBERCOM utilizes multiple networks, NIPRNet, 311
SIPRNet, NSANet, The work management tool should 312 support developing a business application in one 313 environment and then deploying in multiple network 314
4 (U//FOUO) While mobile computing platforms are not currently supported, the SSO work management tool should not preclude supporting mobile computing when implemented in the USCYBERCOM environment.
Page 13 of 32 UNCLASSIFIED//FOR OFFICIAL USE ONLY environments without requiring additional development 315 coding or configuration efforts. 316
3.3.6.5. (U//FOUO) Usability: 318
The work management tool shall comply with W3C usability 319 standards for end user interface design and with section 508 320 standards. Response times for end user displays shall be in the 321 range of page loading between 3 – 6 seconds. 322
3.3.7. (U//FOUO) Security: 324
The work management tool will comply with the Risk Management 325
Framework (RMF) 2.0 standards consistent with the RMF rating assigned 326 by the CDG J65 Information Assurance Manager once the system design 327 is finalized. 328
3.3.8. (U//FOUO) Privacy: 330
The work management tool will comply with the Privacy Act of 1974, as 331 amended. 332
3.3.9. (U//FOUO) Continuity of Operations: 334
SSO recognizes that in the event that a Continuity of Operations Plan 335
(COOP) is required to be implemented, mission applications must be 336 prioritized relative to the order in which specific missions are supported. 337
Accordingly, in order to continue the overall mission of USCYBERCOM, 338
SSO requires that the task management application must be restored no 339 later than two (2) calendar days after the initiation of a COOP. 340
3.4. (U//FOUO) System User Classes 342
(U//FOUO) The SSO work management tool will be utilized by multiple classes of users. 344
During the initial phase the following classes of users are anticipated to use the SSO 345 work management system: 346
User
Class
Attributes Access Restrictions
New
Staff -
Inboun
Individual who is assigned to be working at
Individual can only access their own record.
User can view and update
Page 14 of 32 UNCLASSIFIED//FOR OFFICIAL USE ONLY
User
Class
Attributes Access Restrictions d USCYBERCOM
Individual may or may not already have an active security clearance own record.
User can print own record at their local computer
User can email their own record to the primary email address within their record
SSO
admini strator
Manages SSO user access and SSO work queues, Grants non-SSO users access to limited SSO data fields
Grants access to SSO reports
Can access any SSO record, SSO work queue
Ability to delete SSO records
Limited view access to J1
HR individual’s records
SSO
Users
Can view SSO record based upon security group privileges
Can update SSO related data fields
Access to SSO work queues
Can view SSO predefined reports, can create own reports
Limited view access to J1
HR individual’s records
J1 HR
user
Individuals assigned to J1 HR group
J1HR limited view of
SSO information associated with a current or new inbound who will become an
USCYBERCOM
Page 15 of 32 UNCLASSIFIED//FOR OFFICIAL USE ONLY
User
Class
Attributes Access Restrictions employee.
J1HR can not view records associated with
USCYBERCOM
contractors, other IC staff members, i.e. DIA staff, NSA, FBI, CIA, NGA, etc.
(U//FOUO) Table 2 User Attribute Table 349
3.5. (U//FOUO) Support concept 351
(U//FOUO) In the current manual process of utilizing Excel spreadsheets and email, SSO 353 is providing all support for this process. There are multiple interactions with each of the 354
Directorates, CDG,CMFs, external agencies and the senior level, however it is SSO’s 355 responsibility to manage, track and report on the results of these processes. With the 356 implementation of this new system, support will be provided by the J6 organization. 357
4. (U//FOUO) Analysis of the proposed system 358
4.1. (U//FOUO) Summary of advantages 360
(U//FOUO) The implementation of the SSO work management tool as envisioned 362 within this CONOPS delivers the following advantages to not only the SSO, but to 363
USCYBERCOM overall. 364
1. Improved accuracy of the initial security forms submitted by the in bound 366 individuals, through the use of the products capabilities, Frequently Asked 367
Questions, real-time chat, dynamic form logic to require additional 368 information based upon specific answers. 369
2. Electronic data exchange of in-bound individual’s data to other systems, 370 eliminating physically rekeying data. 371
3. Reduced security clearance processing time due to the improved accuracy 372 of the submitted completed forms. 373
4. Improved user experience through the elimination of required redundant 374 information across multiple forms. 375
Page 16 of 32 UNCLASSIFIED//FOR OFFICIAL USE ONLY
5. Work load balancing across SSO staff through real time reporting of 376 work backlogs. 377
6. Trend analysis identifying current organizational delays impacting 378 personnel actions. 379
7. Real Time reporting on SSO actions. 380
8. Improved transparency of SSO to internal USCYBERCOM leadership through 381 automated reporting capabilities. 382
9. Automatic tracking of durations each action remains within each step and/or 383 organization for each process. 384
4.2. (U//FOUO) Summary of disadvantages or limitations 387
(U//FOUO) The solution proposed does not cross network boundaries. This means that 389
SSO will continue to have to use current manual processes to transfer across network 390 boundaries into systems resident on other network. 391
4.3. (U//FOUO) Alternatives and trade-offs considered 395
USCYBERCOM has already made a strategic decision to procure ServiceNow. This 397
CONOPS is following the guidance to utilize ServiceNow. 398
5. (U//FOUO) Concept for a new or modified system 400
5.1. (U//FOUO) Description of the new or modified system5 402
(U//FOUO) The implementation of the SSO’s task management tool will significantly 404 change and enhance the SSO’s current business practices while improving the overall 405 timeliness of the mission of the SSO. The sections below document these envisioned 406 changes. 407
5.1.1. (U//FOUO) Operational environment 409
(U//FOUO) With the implementation of SSO’s task management tool, the operational 411
5 For a description of the basic requirements of the underlying workflow system, reference the “Concept of Operations for US
CYBER COMMAND Human Resources Information System,” version 1.0, dated February 14, 2017.
Page 17 of 32 UNCLASSIFIED//FOR OFFICIAL USE ONLY environment will significantly change. The SSO will no longer be dependent upon 412 physical paper forms, MS Excel and email for tracking personnel actions and obtaining 413 status from the different directorates. SSO, as well as all users of the tool, will be able to 414 obtain real-time updates on the status of personnel security actions from this automated 415 tool. All users will be able to see what actions have been completed, and what actions 416 still remain to be done. Users will be able to identify if the action is not being worked 417 and will be prompted to follow up, accordingly. 418
Additionally, because the quality of the initial security forms submitted by the user will 419 be increased time required for contacting the in-bound individual to correct information 420 will be reduce. Additionally, with the elimination of rekeying of data into multiple 421 different systems used by the SSO the overall time required to adjudicate a security 422 clearance will be reduced. 423
Additionally, SSO will be able to provide actionable real-time reports on personnel 425 security actions to J0. Time spent within each step of the process and by each directorate 426 will be discretely captured, enabling detailed reporting. Historical trends will be 427 automatically documented. This historical information can uncover potential slowdowns 428 and/or stoppages in processes. Root cause analysis can be performed to remediate either 429 through additional user training or process changes. 430
Page 18 of 32 UNCLASSIFIED//FOR OFFICIAL USE ONLY
5.1.2. (U//FOUO) System Components 434
(U//FOUO) The system will be built using the Commercial Off The Shelf (COTS) product ServiceNow 436 and its Now Platform custom application feature. The diagram below is a conceptual view of the 437 envisioned environment as it is deployed for production use. 438
MADO Application (exists today)
D M
Z
INBOUND
External Applicant Application Portal
(Future)
J1 HR Application (Future)
INTERNET Unclassified
Top Secret
Commercial Credit
Reporting
NCIC E-QIP
SSO Application (Future)
SSO Application (Future)
D M
Z Applicant
Server
(U//FOUO) Figure 2 SSO Task Management Notional Environment 441
5.1.2.1. Security Enclaves: 442
The system will be deployed across three unique security 444 enclaves: unfettered Internet, NSA NIPRNET unclassified 445
Page 19 of 32 UNCLASSIFIED//FOR OFFICIAL USE ONLY environment and NSANET Top Secret environments. 446
5.1.2.2. Applications 447
The system will be comprised of a combination of multiple ServiceNow 448 instances within the unclassified and Top Secret environments. Additionally, a 449 custom application portal will be built to allow authorized external users access 450 to the security forms. An applicant application server will be built to facilitate 451 communications between the applicant portal and the SSO ServiceNow 452 application within the DMZ. 453
ServiceNow applications: Within each security enclave there will be a single 455
ServiceNow installation, with multiple applications running within each 456
ServiceNow instance. These ServiceNow applications will include native 457
ServiceNow applications, such as ITSM applications, as well as custom 458 applications built using the ServiceNow Now Application custom application 459 feature. 460
MADO Application is a NSA application that this used to manage the NSA 462 building and network access granting processes. 463
5.1.3. (U//FOUO) Interfaces to external systems or procedures 465
(U//FOUO) As noted in (U//FOUO) Figure 2 SSO Task Management Notional 467
Environment, SSO interacts with multiple internal and external systems in the 468 completion of its mission. The proposed system will eventually interface to multiple 469 internal and external systems. Some of these systems include: 470 e-QIP: OPM Electronic Questionnaires for Investigations Processing 471
NCIC: FBI National Crime Information Center 472
Commercial Credit Reporting: external commercial agencies, such as 473
Transunion, Experian and others 474
MADO: NSA custom internal application 475
5.1.4. (U//FOUO) Capabilities 477
(U//FOUO) In addition to the capabilities identified in the “Concept of Operations for 479
US CYBER COMMAND Human Resources Information System,” version 1.0, dated 480
February 14, 2017, the SSO task management system will utilize the following 481
ServiceNow features: 482
Feature Use Scenario
1 Chat Establish a chat session
Page 20 of 32 UNCLASSIFIED//FOR OFFICIAL USE ONLY
Feature Use Scenario between an in-bound individual and a SME within SSO to answer questions regarding completion of the in-bounds profile
2 Knowledge
Management
Build field specific FAQs associated to the required fields the in-bound individual must answer on the in-bounds profile
3 Mobile Enables in-bound individuals to complete the in-bounds profile on mobile devices
4 E-Mail integration Automate email communication with in-bound individual based upon set of conditions.
Must be able to consume in-bound email to update status of individual’s profile
5 Workflow Automate activities and predefined actions based upon specific triggers, such as passage of time, or specific states (U//FOUO)Table 3 SSO Application Capabilities 484
5.2. (U//FOUO) Support concept 487
(U//FOUO) The support of the new task management system is a cross organizational 489 effort, requiring the expertise of multiple directorates to successfully implement. 490
(U//FOUO) The table below documents the proposed responsibilities of each 491 directorate for supporting the development, implementation and maintenance of the 492 task management system. 493
Page 21 of 32 UNCLASSIFIED//FOR OFFICIAL USE ONLY
Support Task Performing directorates
Description
Technical installation and maintenance of task management environments/application
CDG J6 – System
Administrators, technical team
Install software, apply patches and STIGS, ensure security controls are maintained per the system security plan. (Note anticipate three (3) environments: development, training, production). Upgrade application and underlying software as required
Monitor/Manage system performance
CDG J6 – system administrator
Monitor application storage, database optimization, ensure adequate storage available.
Implementing new/changed business processes
SSO
CDG J6
SSO is responsible for identifying the new and/or changed business processes.
CDG J6 is responsible for working with SSO to document changes and implement within the task management application.
Correcting defects within the application
SSO
CDG J6
SSO is responsible for confirming that identified discrepancy is a defect in the implementation.
Once confirmed, SSO is responsible for prioritizing backlog and target implementation date for correction.
CDG J6 will implement the correction per the prioritization and implementation of the backlog by SSO.
Page 22 of 32 UNCLASSIFIED//FOR OFFICIAL USE ONLY
End User Training/End
User Manual
SSO
CDG J6
SSO is responsible for providing subject matter expertise relating to the business processes and their implementation within the system. SSO will also perform the end user training based on the materials developed by CDG
J6.
CDG J6 is responsible for providing technical SME to answer questions related to how the system works.
CDG J6 is also is responsible for developing the training curriculum and delivery method(s)
User Acceptance Testing SSO SSO will define the criteria that will determine a successful implementation of the task management application. Using the success criteria, SSO will create, document and perform independent user acceptance testing of the developed application, prior to the application being deployed in production environment.
Application Support
System Administrator
Training/System
Administrator Manual
CDG/J6/Vendor CDG/J6 will be responsible for providing the system administrators with training on the maintenance of the application environment.
Additionally, the vendor does provide training tailored to system administrators.
(U//FOUO) Table 9 Operational Support Providers 497
Page 23 of 32 UNCLASSIFIED//FOR OFFICIAL USE ONLY
5.3. (U//FOUO) Operational scenarios 501
(U//FOUO) The following provides examples of how the SSO work management tool 503 would operate in sample new member in-bound scenario. 504
USCYBERCOM New In-Bound Process Flow
SS
O
In -B o u n d
M em b er
Sy st em
Notification of new individual starting
Send individual email with userid to access user profile site
Send individual email with password to user profile site
Individual accesses online profile site Updates profile
Researches FAQ for fields
Chat Session with SSO SME
Signs completed profile
SME Chat session
Create userid & password
Profile Complete
Yes
Send Reminder email
> 7 days last update
No
Yes
> 14 days last update
No
Send Still interested email
Yes
Off page A
Off page B
Off page C
WAITNo
Off page D
NOTE: Box numbers are to facilitate common reference and NOT sequence number
Update Last Update field to current date
(U//FOUO) Figure 3 New In-Bound Page 1 506
Page 24 of 32 UNCLASSIFIED//FOR OFFICIAL USE ONLY
USCYBERCOM New In-Bound Process Flow
SS
O
N ew
M em be r
Sy st em
Off page A
Off page B
Receives Still Interested Email Reply
Still Interested
Set Profile Status = Closed
Suspend Account
NO
>90 Suspended
Account
Delete Account
Wait
Yes
No
Off page C
Profile Accurate
Yes
Export data to other Security Clearance
System(s) Yes
Off page D
Set Profile Status = Signed
Reset Profile Status = Open
Send email detailing
Corrections
No
Reset Signature
Start security workflow
TBD
20 21
262523
NOTE: Box numbers are to facilitate common reference and NOT sequence number
(U//FOUO) Figure 4 New In-Bound Page 2 510
Step
Step Title Comments
1 Notification of new individual starting Multiple triggers for this step
Civilian employee: J1 ServiceNow Process flow –
Inbounds – this would only be for USCYBERCOM future employees
Military in-bound: could be triggered by Fourth
Estate Manpower Tracking System (FMTS)
Military in-bound: direct notification by local
Page 25 of 32 UNCLASSIFIED//FOR OFFICIAL USE ONLY
Step
Step Title Comments commander
Contractor: email notification from either the contractor officer representative (COR) or contractor security officer
Other IC: email notification from sending agencies security officer
Other: email notification
System should track attributes of the affiliation with
USCBYERCOM
2 Create userid & password These individuals will most likely not be in the
USCYBERCOM Active Directory. Need to create a userid and password for the user to access the applicant portal to complete user profile/forms. SSO would create the userid and password
3 Email in-bound with userid Send separate emails to in-bound user email address. One email with userid, second with password.
4 Email in-bound with password Send separate emails to in-bound user email address. One email with userid, second with password.
9 Individual accesses online profile site User logs on and changes password.
10 Updates Profile User starts process of updating their individual profile.
Required information based upon consolidation of data elements from security forms. Dynamic fields add/ required based upon answers to specific questions.
5 Researches FAQ for fields User is able to research field specific FAQs to clarify what information is required.
6 Chat session with SSO SME User initiates request to establish a chat session with SSO
SME
16 SSO SME Chat Session User is able to initiate a chat session with a SSO SME to get clarification/answers to any user questions regarding the information required
11 Profile complete Decision step in process flow
15 Signs Completed profile If user has completed all required fields, user signs profile.
Signing the profile will add the record to the SSO work queue
12 >7 days last update Test to see if the last update of the user’s record is greater than seven (7) days
14 If the answer to step 12 is no, Wait System takes not action
13 If the answer to step 12 is Yes Decision step in process flow
7 Send reminder email If the time since last update is less than 14 days, send a reminder email that profile still needs to be completed
Page 26 of 32 UNCLASSIFIED//FOR OFFICIAL USE ONLY
Step
Step Title Comments
8 Send “Still interested” email If more than 14 days since last update, send formatted email that has yes/no check box to indicate if user is still interested in completing profile. User can complete check box and send email back to system to update record.
Off Page “A” Continuation of “A” process flow
17 Profile Accurate Decision step in process flow
18 Export data to security clearance systems Create data extract file that can be consumed by other data processing systems within NSA/USCYBERCOM or external systems
19 Start security workflow TBD There will be additional SSO workflow steps that have yet to be defined.
20 Send email detailing corrections After reviewing the profile, a determination is made that the in-bound profile is not accurate. Send email to user notifying them of corrections required to their profile
21 Reset profile status = Open Update the in-bound users record to a state of “open” to allow user to make changes to their profile record
22 Reset signature Reset the signature field to all the in-bound to re-sign their profile after they have completed the information
Off Page “B” Continuation of “B” process flow
23 Receives “Still Interested” email reply System receives and processes the response from the in-bound users.
24 Still Interested Decision step in process flow
25 Set Profile satus = “Closed” If the email answer is “not interested”, then set the status of the profile record to “Closed”. Prevents further updates to the record by the user.
26 Suspend Account Set the in-bound user’s account to “suspended”. Disables the user account preventing future access.
27 >90 days suspended account Test to determine how long user account has been suspended
28 Wait If user account has been suspended less than 90 days, leave account in “suspended” status
30 Delete Account If user account has been suspended more than 90 days, delete the in-bound user account
Off Page “D” Continuation of “B” process flow
29 Set Profile status = “Signed” Update the status of the in-bound profile record to “signed” preventing the user from making any other changes to their profile
Off Page “C” Off page connector
31 Update “Last Update field” to current date
Update “Last Update field” to current date
(U//FOUO) Table 4 In-Bound Process Flow Description 514
Page 27 of 32 UNCLASSIFIED//FOR OFFICIAL USE ONLY
Page 28 of 32 UNCLASSIFIED//FOR OFFICIAL USE ONLY
6. (U//FOUO) Summary of impacts 520
6.1. (U//FOUO) Operational impacts 522
(U//FOUO) Addressing the post-deployment of the phase 1of the SSO Task 524
Management tool, the operational impacts will primarily affect the SSO and J1 525 organizations. The implementation of this tool will required revised standard operating 526 procedures within the SSO organization for processing security clearance requests. The 527
J1 will now be able to track SSO activities from within the same application thereby 528 improving communications between the J1 and SSO and with individuals applying for 529 positions within USCYBERCOM. Additionally, the J0 will now be able to obtain real-530 time reports on across both the SSO and J1. These reports can present the leadership 531 with an integrated view of personnel actions between these two organizations. 532
6.2. (U//FOUO) Organizational impacts 534
(U//FOUO) In addition to the operational impacts upon SSO and J1, there will also be an 536 impact upon the CDG J6 organization as related to the architects, system engineers as 537 well as developer community. The procurement and implementation of a new COTS 538 product, will require elements within the CDG J6 to become trained in the capabilities of 539 this technology, the proper configuration and maintenance of the application as well as 540 new application development techniques. 541
Page 29 of 32 UNCLASSIFIED//FOR OFFICIAL USE ONLY
6.3. (U//FOUO) Impacts during development 545
(U//FOUO) The successful acquisition, installation, development and implementation of 547 any new application requires support from a large cross section of the organization. This 548 success will require commitment of resources to this endeavor, including supporting 549 regular status meetings, detailed working sessions to flesh out and document the detail 550 functionality and business rules as well supporting testing and end-user training. The 551 periods and duration of when each type of resource will be required can be mitigated to 552 large degree through project planning. The table below outlines the organizational 553 commitments required and anticipated activities. 554
Organization Anticipated Activities Notes
CDG/ACQ Contract award to procure both the software and implementation services
J8 Obligate funding to support contract award
SSO Subject Matter Expertise Availability will correlate to processes to be implemented
J6 System Administrators Install, configure and maintain COTS software
(patches, STIGS, etc.)
J6 Application Configuration and Development
J615 Information Assurance
CDG/MI Project Manager
(U//FOUO) Table 11 Organizational Impacts 557
7. (U//FOUO) Notes 559
The SSO task management tool will consolidate the data fields of the following forms into a single 560 data collection application. From this consolidated data collection and repository, the task 561 management tool will be able to generate the forms when required. The following is a list of the 562 forms whose data collection will be consolidated into the SSO task management tool: 563
1. Questionnaire for National Security Positions 565
2. Security In-Processing Form (instructions and procedures) 566
Page 30 of 32 UNCLASSIFIED//FOR OFFICIAL USE ONLY
3. SCI Pre-Screening Interview 567
4. Personnel Screening Interview Questionnaire 568
5. Supplemental Security In-Processing Form for Religious Missions 569
6. Supplemental Security In-Processing Form for Language Immersion Trips 570
8. (U//FOUO) Appendices 573
(U//FOUO) The following appendices contain the forms noted above. 575
Page 31 of 32 UNCLASSIFIED//FOR OFFICIAL USE ONLY
Appendix A: Acronyms
Acronym Full Name
AFDW Air Force District of Washington
AFPC Air Force Personnel Center
API Application Programming Interface
C4 Command, Control, Communications, Computers
C4IT Command, Control, Communications, Computers and Information Technology
CDG MI Capabilities Development Group Mission Integration
CIO Chief Information Officer
COCOM Combatant Command
CONOPS Concept of Operations
COS Chief of Staff
COTS Commercial Off-The-Shelf
DB Database
DCOS Deputy Chief of Staff
DCPDS Department of Defense Civilian Personnel System
E915 Automated routing and tracking tool supporting the coordination and approval of documentation and taskers
FBI Federal Bureau of Investigations
FMTS Fourth Estate Manpower Tracking System
GOFO General Officer Flag Officer
J1 Personnel and Manpower
J2 Intelligence
J3 Operations
J4 Logistics
J5 Plans and Policy
J6 Operations Architecture & C4/CIO Support
J7 Exercises and Joint Force Deployment
J8 Capability and Resource Integration
JCS Joint Chiefs of staff
MPR Manpower Personnel Representative
NCIC FBI National Crime Information Center
NIPRNet Nonsecure Internet Protocol Router Network
NSA National Security Agency
SIPRNet SECRET Internet Protocol Router Network
SORN System of Record Notice
SSO Staff Security Officer
USAF United States Air Force
USCG United States Coast Guard
USCYBERCOM United States Cyber Command
Page 32 of 32 UNCLASSIFIED//FOR OFFICIAL USE ONLY
USSTRATCOM United States Strategic Command
File details come from the government source that posted it.