SSO_Toolkit_SOW.pdf

PDF 1 MB Posted

Attached to
Enterprise Architecture (EACOE) Quick Start Federal contract opportunity
Solicitation number
HB0001-18-R-0003
Issued by
Department of Defense Cyber Command

About this file

SSO_Toolkit_SOW

View the file

Other files for this federal contract opportunity

Other files attached to Enterprise Architecture (EACOE) Quick Start, newest first.
File Type Posted
SSO_Automation_Automation_Vision.pdf PDF
J6_forms.pdf PDF
ServiceNow_SOW_General_Provisions.pdf PDF
Language_Immersion_Trip_February_2015.pdf PDF
SCI_ATTESTATION.pdf PDF
SCI_Pre_Screen_Questionaire_DEC_2017.pdf PDF
USCC_Non-Disclosure_Agreement.pdf PDF
dd254_SNOW.pdf PDF
SSO_Toolkit_CONOPS.pdf PDF
HR_Toolkit_Conops__Task_Management.pdf PDF
FORM_4414_Rev_12-2013_fillable_(Savable).pdf PDF
SF312.pdf PDF
Past_Performance_Template.pdf PDF
HR_Toolkit_SOW.pdf PDF
Questionaire_Response_Attachment_20180119.pdf PDF
10-SIP_Instructions.pdf PDF
Religious_Mission_Trip_February_2015.pdf PDF
HR_Toolkit_Process_Flows_Final.pdf PDF
Asset_Config_Management_SOW.pdf PDF
US_Cyber_Command_Pre_Screen_Notice_20180308.pdf PDF
Resume_Template.pdf PDF
ACS_050515_eform.pdf PDF
dd2875_(blank).pdf PDF
SIP_050515_eform.pdf PDF
SCI_Reporting_Memo.pdf PDF
Foreign_Travel_Questionnaire.pdf PDF
CS_050515_eform.pdf PDF
Show all 27

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

UNCLASSIFIED//FOR OFFICIAL USE ONLY

w

CONCEPT OF

OPERATIONS FOR

US Cyber Command

Special Security Office Task Management Tool

Version 0.2

April 2, 2018

DRAFT

3/29/2018 UNCLASSIFIED//FOR OFFICIAL USE ONLY Page 2 of 31

THIS PAGE INTENTIONALLY LEFT BLANK 2

3/29/2018 UNCLASSIFIED//FOR OFFICIAL USE ONLY Page 3 of 31

TABLE OF CONTENTS

Contents 1

CONCEPT OF OPERATIONS FOR ................................................................................................... 1 2

TABLE OF CONTENTS ...................................................................................................................... 3 3

1. (U//FOUO) Executive Summary .......................................................................................... 4 4

2. (U//FOUO) CONOPS Scope ................................................................................................ 4 5

2.1. (U//FOUO) Identification ..................................................................................................... 5 6

2.2. (U//FOUO) Document security ............................................................................................ 5 7

2.3. (U//FOUO) System security ................................................................................................. 5 8

3. (U//FOUO) Current system or situation ............................................................................... 5 9

3.1. (U//FOUO) Background, objectives, and scope ................................................................... 5 10

3.2. (U//FOUO) Operational policies and constraints ................................................................. 6 11

3.3. (U//FOUO) Description of current system or situation ........................................................ 7 12

3.4. (U//FOUO) System User Classes ....................................................................................... 13 13

3.5. (U//FOUO) Support concept ............................................................................................... 15 14

4. (U//FOUO) Analysis of the proposed system ..................................................................... 15 15

4.1. (U//FOUO) Summary of advantages .................................................................................. 15 16

4.2. (U//FOUO) Summary of disadvantages or limitations ....................................................... 16 17

4.3. (U//FOUO) Alternatives and trade-offs considered ............................................................ 16 18

5. (U//FOUO) Concept for a new or modified system ........................................................... 16 19

5.1. (U//FOUO) Description of the new or modified system .................................................... 16 20

5.2. (U//FOUO) Support concept ............................................................................................... 20 21

5.3. (U//FOUO) Operational scenarios ...................................................................................... 23 22

6. (U//FOUO) Summary of impacts ....................................................................................... 28 23

6.1. (U//FOUO) Operational impacts ........................................................................................ 28 24

6.2. (U//FOUO) Organizational impacts .................................................................................... 28 25

6.3. (U//FOUO) Impacts during development ........................................................................... 29 26

7. (U//FOUO) Notes ............................................................................................................... 29 27

8. (U//FOUO) Appendices ...................................................................................................... 30 28

Appendix A: Acronyms .......................................................................................................................... 31 29

Page 4 of 31 UNCLASSIFIED//FOR OFFICIAL USE ONLY

1. (U//FOUO) Executive Summary 31

(U//FOUO) US CYBER COMMAND’s (USCYBERCOM) primary location is co-33 located within the National Security Agency (NSA) at Ft. Meade, Maryland. All 34 individuals who will be working at USCYBERCOM’s offices must go through a two 35 step process before being granted approval for both physical and network access to 36

USCYBERCOM facilities and networks. All personnel must first have a current security 37 clearance level of Top Secret/ Sensitive Compartmented Information with a Counter 38

Intelligence Polygraph (TS/SCI with CI/Poly). After USCYBERCOM verifies or 39 approves the security clearance for the individual, NSA then makes a determination as to 40 granting access to the NSA facilities and networks. Once both these actions are fully 41 adjudicated, an individual is granted access to both NSA facilities and 42

NSA/USCYBERCOM networks. This is a lengthy process that can take several months 43 to years for full resolution. Currently, this process is primarily manual. This Special 44

Security Office (SSO) CONOPS presents a vision for automating the multiple forms that 45 an individual must complete in order to obtain both the security clearance and access 46 approval. Automating this data collection will be the first step of increasing the 47 automation of the security clearance and access approval processes as well as other 48 processes with the SSO. It is anticipated that automating the data collection will 49 potentially reduce the time to obtain approval to work at USCYBERCOM through 50 improved data integrity and reduction of multiple manual data entry processes on both 51 the in-bound individual as well as the SSO staff. Additionally, this automation will 52 provide transparency to the command leadership through automated reporting of the 53 status of security clearance processes. USCYBERCOM’s security office will leapfrog 54 into the 21st century with a set of tools to support moving at the speed of cyber for 55 security processing. 56

2. (U//FOUO) CONOPS Scope 58

(U//FOUO) In addition to the National Background Investigations Bureau Electronic Questionnaires 60 for Investigations Processing (e-QIP), USCBYERCOM also requires additional information specific to 61

USCYBERCOM to be submitted by individuals who will be working at USCYBERCOM facilities (In-62 bound individuals). This CONOP is limited to the automated tools required that will support a single 63 data entry of all required information by an in-bound individual who will be working at 64

USCYBERCOM1. 65

1 This CONOPS does not replace the current e-QIP. e-QIP is still required and integration with e-QIP tool while desire is not required as part of the solution.

Page 5 of 31 UNCLASSIFIED//FOR OFFICIAL USE ONLY

2.1. (U//FOUO) Identification 68

2.2. (U//FOUO) Document security 70

(U//FOUO) All information documented herein shall be classified as “Unclassified, For 72

Official Use Only” (U/OFUO). 73

2.3. (U//FOUO) System security 75

(U/FOUO) The primary end users of this system are both individuals who currently do 77 not have an affiliation with USCYBERCOM (in-bound individuals) as well as 78

USCYBERCOM Security and Counter Intelligence, Special Security Office (SSO) 79 users. Based upon these two different user groups, the system will be available through 80 both the Internet (grey space) and within the NSA/USCBYERCOM intranet (both Top 81

Secret and Unclassified environments). It is anticipated that data will be required to be 82 exchanged between all these security environments. The data that is being collected will 83 contain “Personally Identifiable Information (PII2). Applying the Risk Management 84

Framework controls, it is anticipated that these systems will have a Confidentiality 85 rating of high, Integrity rating of high and an availability rating of medium. The system 86 must have security controls implemented consistent with these anticipated ratings. 87

3. (U//FOUO) Current system or situation 89

3.1. (U//FOUO) Background, objectives, and scope 91

(U/FOUO) The mission of the SSO is: “…responsible for the protection of 93

USCYBERCOM information, people and facilities. The SSO Division integrates 94 personnel and physical security disciplines with counterintelligence programs to 95 achieve a security in depth posture that manages the risks arrayed USCYBERCOM 96 extraordinary sensitive and fragile mission….” 97

(U//FOUO) SSO is currently hampered in its ability to fully meet the mission and vision 98 as stated due to a reliance upon manual data entry into multiple disconnected existing 99 systems, manual tools and processes. As USCYBERCOM continues to increase staffing 100 levels and the corresponding security activities, a reliance upon manual tools and 101 processes will adversely impact the SSO’s ability to manage the anticipated staffing levels. 102

Additionally, providing leadership with timely information regarding current staffing 103 security actions, is a staff intensive, manual effort and represents data that is aged and 104

2 It is anticipated that this system will be covered under the same SORN as the J1 Human Resources Toolkit and will not require a separate SORN.

Page 6 of 31 UNCLASSIFIED//FOR OFFICIAL USE ONLY often not actionable. 105

. 106

(U//FOUO) The scope of this CONOPS is to document the first phase of what is 107 envisioned to be a multi-phase project to bring automation to the SSO processes. This 108 first phase is to provide a tool to enable in-bound individuals to enter all required 109 information to support the USCYBERCOM/NSA security clearance and access 110 processes a single time. The system will collect all required data once, and then route 111 this information to the corresponding offices for processing and generate the necessary 112 forms (either electronic or paper) as required. In the collection of the user’s data, 113 corresponding technology will be leveraged to increase the accuracy of the information 114 entered by the user through the use of real-time chat, knowledge management 115

Frequently Asked Questions tailored to each data element requested and systematic 116 exchanges with the applicant that can be automatically tracked. The technology 117 solution is intended to support the current internal USCYBERCOM SSO user 118 community and the J1 manpower personnel directorate (MPR) and leadership within 119 each Directorates. The solution is intended to function in a complementary capacity to 120 existing internal and external systems. The optimal solution will minimize manual data 121 entry/manual data reporting while maximizing data integrity between these other 122 systems. 123

3.2. (U//FOUO) Operational policies and constraints 126

(U//FOUO) USCYBERCOM is a joint command with representatives from all military 127 services, other intelligence community agencies as well as civilian staff. All individuals 128 who will be stationed at and working at USCYBERCOM are required to comply with the 129 security policies of both USCYBERCOM and NSA. In developing this CONOP the 130 following policies have been used in guiding the content of this document: 131

a) DoD Directive 5124.02 “Under Secretary of Defense for Personnel and Readiness 133

(USD(P&R)),” June 23, 2008 134

b) DoD Directive 1400.25, “DoD Civilian Personnel Management Systems,” 135

November 25, 1996, http://dtic.mil/whs/directives/corres/CPM_table2.html 136

c) Subtitle III of Title 40, United States Code 137

d) Title 10, United States Code 138

e) DoD Directive 8115.01, “Information Technology Portfolio Management,” 139

October 10, 2005 140

f) DoD Directive 8000.01, “Management of the Department of Defense 141

Information Enterprise,” February 10, 2009 142 http://dtic.mil/whs/directives/corres/CPM_table2.html

Page 7 of 31 UNCLASSIFIED//FOR OFFICIAL USE ONLY

g) Office of the Deputy Chief Management Officer 143

Website, http://dcmo.defense.gov 144

h) DoD Instruction 5025.01, “DoD Directives Program,” September 26, 2012 as 145 amended 146

i) DoD Instruction 8510.01, “Risk Management Framework (RMF) for DoD 147

Information Technology(IT),” March 12, 2014, Incorporating change 1, Effective 148

May 24, 2016 149

j) DoD Instruction 5000.02, “Operation of the Defense Acquisitions System,” 150

January 7, 2015 151

k) DoD Directive 8500.01E “Information Assurance (IA),” April 23, 2007 152

l) DoD Manual 5200.01 – Volume 1, “DoD Information Security Program: 153

Overview, Classification, and Declassification,” February 24, 2012 154

m) National Institutes of Standards and Technology, Special Publication 800-53, 155

Rev 4 156

n) Section 552a of Title 5, United States Code, (also known as “The Privacy Act of 157

1974,” as amended) 158

o) DoD 5400.11, Department of Defense Privacy Program,” October 29, 2014 159

p) DoD Instruction 8910.01, “Information Collection and Reporting,” May 19, 2014 160

q) National Security Agency/Central Security Services (NSA/CSS), Security Policy Series 5 161

r) NSA/CSS Policy 5-1, Personnel Security Requirements for Members of the Service 162

Cryptologic Components Assigned or Detailed within NSA/CSS 163

3.3. (U//FOUO) Description of current system or situation 165

3.3.1. (U//FOUO) Operational environment 167

(U//FOUO) The current operational environment is a patchwork of primarily 168 disconnected systems and manual processes coupled with a dependency upon a 169 complex of external systems. The SSO currently relies upon a combination of physical 170 paper forms, email and MS Excel spreadsheets to track personnel security actions and 171 email to obtain status updates that are then manually entered into the Excel 172 spreadsheet. This method does not capture elapsed time within any one action or 173 within one individual or group. Providing any type of meaningful reports, such as 174 trend analysis, outstanding actions or number of priority actions as examples, is 175 challenging and results, when possible, are often delayed due to the manual efforts 176 required. 177

3.3.2. (U//FOUO) System Components 179 http://dcmo.defense.gov/

Page 8 of 31 UNCLASSIFIED//FOR OFFICIAL USE ONLY

(U//FOUO) In its personnel security role for the USCYBERCOM, the SSO has 181 organizational interactions across the command of USCYBERCOM as well as working 182 with other federal civilian agencies, as well as external military services related to 183 personnel security decisions. Some of these external agencies include the Federal 184

Bureau of Investigations, National Security Agency, Central Adjudication Facilities, 185 and others. 186

3.3.3. (U//FOUO) Interfaces to external systems or procedures 189

(U/FOUO) In the performance of its mission, the SSO interacts with several data 190 processing systems that are external to USCYBERCOM. These systems are the official 191 records related to the in-bound individual or provide commercial reporting services 192 regarding the individual. Some of these external agencies and systems include the Joint 193

Verification System (JVS), Joint Personnel Adjudication System (JPAS), Electronic 194

Questionnaires for Investigations Processing (e-QIP), Public record checks, and others. 195

3. In many instances, data is manually copied from these external systems to either a 196 paper file, manual data entry to another system or into office collaboration applications 197 maintained by the SSO. 198

3.3.4. (U//FOUO) Capabilities 203

(U//FOUO) The SSO along with the CDG/MI and J1, jointly participated in a series of 205 meetings from October through December 2016 and again in March 2018 with the 206 objective of identifying initial set of functionalities of the SSO Task Management Tool. 207

The team identified the following mission areas requiring support by the automated 208 tool: 209

Single Consolidated Data Entry for all personnel assigned to work at USCYBERCOM 210

Automated generation of “on-boarding” forms based upon above data entry 211

Automated workflow of security review process 212

Automated data reporting 213

(U//FOUO) At the highest level of abstraction, J1 has identified a need for an automated 215 task management tool that would: 216 support the capture and tracking of work requests, 218 set prioritization of work requests through the application of business rules, 219 give assignment of work requests to “qualified and available staff”; and, 220 provide robust real-time reporting capabilities. 221

3 Integration with these other external agencies or commercial services is not included in the initial phase 1 scope.

Page 9 of 31 UNCLASSIFIED//FOR OFFICIAL USE ONLY

(U//FOUO) (U//FOUO) Figure 1 SSO Task Management System Components illustrates a high 224 level notional concept of a work management foundational tool. This tool provides 225 generic work management capabilities that are configured based upon specific business 226 rules. The key concept is that the deployment of this tool supporting the SSO processes 227 and internal tracking is based upon configuration of native functionality within the 228

COTS software application rather than creating a custom application. Key features of 229 this work management foundational tool include: 230

Work Queue – backlog of work requests that need to be completed 232

User Queue – listing of users and their associated profiles 233

Business rules – defines the attributes of a work item, logic for prioritizing work 234 and expected timeframes for completion of work item or work step 235

User Assignment Rules – based upon user profile, matches available user to work 236 item and assigns work item to either individual user or group of users 237

Routing Rule – defines the activities that must be accomplished and the sequence 238 of steps to be performed based upon the type of work item. 239

Page 10 of 31 UNCLASSIFIED//FOR OFFICIAL USE ONLY

Business Application Layer

Daily Operations:

Background Investigation Clearance Adjudication Polygraph Examination NSA Access Approval

Daily Operations

Visitor Access Request Reinvestigation Reporting and Incidents Event Management Clearance Verification Edit: Contractor Security Renewal to Industrial Security Management Outbound/Out-Processing

Security Office Events

Workflow/Task Management Processes

API

Task Management Application

Work Queue User Queue

Business Rules

User Assignment

Rules

Create/Update Work Item

Work Request

Routing Rules

More Steps EndNO

YES

(U//FOUO) Figure 1 SSO Task Management System Components 243

Page 11 of 31 UNCLASSIFIED//FOR OFFICIAL USE ONLY

3.3.5. (U//FOUO) Performance characteristics, 247

(U//FOUO) The nature of the work that SSO performs is of a medium-volume high-249 interaction nature. Low-volume in terms of the total number of security actions 250 performed each year. High-interaction in that multiple individuals are required to 251 complete any one security action. The table below provides estimated number of security 252 actions required to be supported by the proposed tool each year. 253

Category Objective Annual Projected Transactions –

Low

Annual Projected Transactions –

High

Onboarding Background Investigation

30 200

Onboarding Clearance Adjudication 100 500

Onboarding Polygraph Examination 1000 3000

Onboarding NSA Access 1500 3500

Daily Operations Visitor Access Request 600 3000

Daily Operations Reinvestigation 500 1500

Daily Operations Reporting and Incidents 200 600

Daily Operations Event Management 10 50

Daily Operations Clearance Verification 1000 6000

Daily Operations Industrial Security –

DD 254

50 150

Daily Operations Out-Processing 600 1200 (U//FOUO) Table 1Volume Projections 255

3.3.6. (U//FOUO) Quality 256

Quality is a multidimensional aspect within the final solution. The following 257 identifies the critical aspects that must be included within the delivery of the 258 final solution. 259

3.3.6.1. (U//FOUO) Reliability: 261 defined as the ability of the software to consistently perform 262 according to its specifications. J1 requires that the application 263 perform according to the agreed upon specifications with no 264 critical defects (a defect for which there is no system work 265 around). 266

3.3.6.2. (U//FOUO) Maintainability: 268 defined as the ease with which a system can be maintained and 269 corrected. Software industry recognizes four different types of 270 maintenance as noted below. Regardless of the types of 271

Page 12 of 31 UNCLASSIFIED//FOR OFFICIAL USE ONLY maintenance, the implementation of these maintenance activities 272 should not impact the production availability of the system to the 273 user community and be able to be performed during routine 274 maintenance times. 275

3.3.6.2.1. (U//FOUO) Adaptive: 277 modifying the system to cope with changes in the software 278 environment (system patches, application of STIGs, 279 application upgrades) 280

3.3.6.2.2. (U//FOUO) Perfective: 282 implementing new or changed user requirements which 283 concern functional enhancements to the software 284

3.3.6.2.3. (U//FOUO) Corrective: 286 diagnosing and fixing errors 287

3.3.6.2.4. (U//FOUO) Preventative: 289 increasing software maintainability or reliability to prevent 290 problems in the future 291

3.3.6.3. (U//FOUO) Availability: 293 defined as the percentage of time the application is available and 294 functioning for the end user. SSO requires an availability time of 295

99% Monday through Friday, 06:00 – 21:00 EST. 296

3.3.6.4. (U//FOUO) Portability: 298

There are several aspects to the applicability of software 299 portability. 300

3.3.6.4.1. (U//FOUO) Multiple operating systems support: 302

Ability to operate the software in different operating system 303 environments. The Command requires that the workflow 304 tool be able to be supported by current operating systems, 305 including standard PC desktops and servers, as well as 306 mobile computing platforms, such as Android, IOS and 307 other standards4. 308

4 (U//FOUO) While mobile computing platforms are not currently supported, the SSO work management tool should not preclude supporting mobile computing when implemented in the USCYBERCOM environment.

Page 13 of 31 UNCLASSIFIED//FOR OFFICIAL USE ONLY

3.3.6.4.2. (U//FOUO) Network security classification portability: 310

USCYBERCOM utilizes multiple networks, NIPRNet, 311

SIPRNet, NSANet, The work management tool should 312 support developing a business application in one 313 environment and then deploying in multiple network 314 environments without requiring additional development 315 coding or configuration efforts. 316

3.3.6.5. (U//FOUO) Usability: 318

The work management tool shall comply with W3C usability 319 standards for end user interface design and with section 508 320 standards. Response times for end user displays shall be in the 321 range of page loading between 3 – 6 seconds. 322

3.3.7. (U//FOUO) Security: 324

The work management tool will comply with the Risk Management 325

Framework (RMF) 2.0 standards consistent with the RMF rating assigned 326 by the CDG J65 Information Assurance Manager once the system design 327 is finalized. 328

3.3.8. (U//FOUO) Privacy: 330

The work management tool will comply with the Privacy Act of 1974, as 331 amended. 332

3.3.9. (U//FOUO) Continuity of Operations: 334

SSO recognizes that in the event that a Continuity of Operations Plan 335

(COOP) is required to be implemented, mission applications must be 336 prioritized relative to the order in which specific missions are supported. 337

Accordingly, in order to continue the overall mission of USCYBERCOM, 338

SSO requires that the task management application must be restored no 339 later than two (2) calendar days after the initiation of a COOP. 340

3.4. (U//FOUO) System User Classes 342

(U//FOUO) The SSO work management tool will be utilized by multiple classes of users. 344

During the initial phase the following classes of users are anticipated to use the SSO 345 work management system: 346

Page 14 of 31 UNCLASSIFIED//FOR OFFICIAL USE ONLY

User Class Attributes Access Restrictions

New Staff - Inbound Individual who is assigned to be working at USCYBERCOM

Individual may or may not already have an active security clearance

Individual can only access their own record.

User can view and update own record.

(Once submitted user cannot delete previously reported information)

User can print own record at their local computer

User can email their own record to the primary email address within their record

SSO administrator Manages SSO user access and

SSO work queues, Grants non-SSO users access to limited SSO data fields

Grants access to SSO reports

Can access any SSO record, SSO work queue

Ability to delete SSO records

Limited view access to J1 HR individual’s records

SSO Users Can view SSO record based upon security group privileges

Can update SSO related data fields

Access to SSO work queues

Can view SSO predefined reports, can create own reports

Limited view access to J1 HR individual’s records

J1 HR user Individuals assigned to J1 HR group

J1HR limited view of SSO information associated with a current or new inbound who will become an

USCYBERCOM employee.

J1HR can not view records associated with USCYBERCOM contractors, other

IC staff members, i.e. DIA staff, NSA, FBI, CIA, NGA, etc.

Chief of Staff View statuses of all personnel in their directorate

Specific J1 and SSO information

Page 15 of 31 UNCLASSIFIED//FOR OFFICIAL USE ONLY

User Class Attributes Access Restrictions

View reports on timelines and trends

(U//FOUO) Table 2 User Attribute Table 349

3.5. (U//FOUO) Support concept 351

(U//FOUO) In the current manual process of utilizing Excel spreadsheets and email, SSO 353 is providing all support for this process. There are multiple interactions with each of the 354

Directorates, CDG,CMFs, external agencies and the senior level, however it is SSO’s 355 responsibility to manage, track and report on the results of these processes. With the 356 implementation of this new system, support will be provided by the J6 organization. 357

4. (U//FOUO) Analysis of the proposed system 358

4.1. (U//FOUO) Summary of advantages 360

(U//FOUO) The implementation of the SSO work management tool as envisioned 362 within this CONOPS delivers the following advantages to not only the SSO, but to 363

USCYBERCOM overall. 364

1. Improved accuracy of the initial security forms submitted by the in bound 366 individuals, through the use of the products capabilities, Frequently Asked 367

Questions, real-time chat, email integration, dynamic form logic to require 368 additional information based upon specific answers. 369

2. Electronic data exchange of in-bound individual’s data to other systems, 370 eliminating physically rekeying data. 371

3. Reduced security clearance processing time due to the improved accuracy 372 of the submitted completed forms and a more efficient process. 373

4. Improved user experience through the elimination of required redundant 374 information across multiple forms. 375

5. Work load balancing across SSO staff through real time reporting of 376 work backlogs. 377

6. Trend analysis identifying current organizational delays impacting 378 personnel actions. 379

Page 16 of 31 UNCLASSIFIED//FOR OFFICIAL USE ONLY

7. Real Time reporting on SSO actions. 380

8. Improved transparency of SSO to internal USCYBERCOM leadership through 381 automated reporting capabilities. 382

9. Automatic tracking of durations each action remains within each step and/or 383 organization for each process. 384

4.2. (U//FOUO) Summary of disadvantages or limitations 387

(U//FOUO) The solution proposed does not cross network boundaries. This means that 389

SSO will continue to have to use current manual processes to transfer across network 390 boundaries into systems resident on other network. 391

4.3. (U//FOUO) Alternatives and trade-offs considered 395

USCYBERCOM has already made a strategic decision to procure ServiceNow. This 397

CONOPS is following the guidance to utilize ServiceNow. 398

5. (U//FOUO) Concept for a new or modified system 400

5.1. (U//FOUO) Description of the new or modified system5 402

(U//FOUO) The implementation of the SSO’s task management tool will significantly 404 change and enhance the SSO’s current business practices while improving the overall 405 timeliness of the mission of the SSO. The sections below document these envisioned 406 changes. 407

5.1.1. (U//FOUO) Operational environment 409

(U//FOUO) With the implementation of SSO’s task management tool, the operational 411 environment will significantly change. The SSO will no longer be dependent upon 412 physical paper forms, MS Excel and email for tracking personnel actions and obtaining 413 status from the different directorates. SSO, as well as all users of the tool, will be able to 414 obtain real-time updates on the status of personnel security actions from this automated 415 tool. All users will be able to see what actions have been completed, and what actions 416

5 For a description of the basic requirements of the underlying workflow system, reference the “Concept of Operations for US

CYBER COMMAND Human Resources Information System,” version 1.0, dated February 14, 2017.

Page 17 of 31 UNCLASSIFIED//FOR OFFICIAL USE ONLY still remain to be done. Users will be able to identify if the action is not being worked 417 and will be prompted to follow up, accordingly. 418

Additionally, because the quality of the initial security forms submitted by the user will 419 be increased, time required for contacting the in-bound individual to correct information 420 will be reduced. Additionally, with the elimination of rekeying of data into multiple 421 different systems used by the SSO the overall time required to process through security 422 clearance will be reduced. 423

Additionally, SSO will be able to provide actionable real-time reports on personnel 425 security actions to J0. Time spent within each step of the process and by each directorate 426 will be discretely captured, enabling detailed reporting. Historical trends will be 427 automatically documented. This historical information can uncover potential slowdowns 428 and/or stoppages in processes. Root cause analysis can be performed to remediate either 429 through additional user training or process changes. 430

Page 18 of 31 UNCLASSIFIED//FOR OFFICIAL USE ONLY

5.1.2. (U//FOUO) System Components 434

(U//FOUO) The system will be built using the Commercial Off The Shelf (COTS) product ServiceNow 436 and its Now Platform custom application feature. The diagram below is a conceptual view of the 437 envisioned environment as it is deployed for production use. 438

MADO Application (exists today)

D M

Z

INBOUND

External Applicant Application Portal

(Future)

J1 HR Application (Future)

INTERNET Unclassified

Top Secret

Commercial Credit

Reporting

NCIC E-QIP

SSO Application (Future)

SSO Application (Future)

D M

Z Applicant

Server

(U//FOUO) Figure 2 SSO Task Management Notional Environment 441

5.1.2.1. Security Enclaves: 442

The system will be deployed across three unique security 444 enclaves: unfettered Internet, NSA NIPRNET unclassified 445

Page 19 of 31 UNCLASSIFIED//FOR OFFICIAL USE ONLY environment and NSANET Top Secret environments. 446

5.1.2.2. Applications 447

The system will be comprised of a combination of multiple ServiceNow 448 instances within the unclassified and Top Secret environments. Additionally, a 449 custom application portal will be built to allow authorized external users access 450 to the security forms. An applicant application server will be built to facilitate 451 communications between the applicant portal and the SSO ServiceNow 452 application within the DMZ. 453

ServiceNow applications: Within each security enclave there will be a single 455

ServiceNow installation, with multiple applications running within each 456

ServiceNow instance. These ServiceNow applications will include native 457

ServiceNow applications, such as ITSM applications, as well as custom 458 applications built using the ServiceNow Now Application custom application 459 feature. 460

MADO Application is a NSA application that this used to manage the NSA 462 building and network access granting processes. 463

5.1.3. (U//FOUO) Interfaces to external systems or procedures 465

(U//FOUO) As noted in (U//FOUO) Figure 2 SSO Task Management Notional 467

Environment, SSO interacts with multiple internal and external systems in the 468 completion of its mission. The proposed system will eventually interface to multiple 469 internal and external systems. Some of these systems include: 470 e-QIP: OPM Electronic Questionnaires for Investigations Processing 471

NCIC: FBI National Crime Information Center 472

Commercial Credit Reporting: external commercial agencies, such as 473

Transunion, Experian and others 474

MADO: NSA custom internal application 475

5.1.4. (U//FOUO) Capabilities 477

(U//FOUO) In addition to the capabilities identified in the “Concept of Operations for 479

US CYBER COMMAND Human Resources Information System,” version 1.0, dated 480

February 14, 2017, the SSO task management system will utilize the following 481

ServiceNow features: 482

Feature Use Scenario

1 Chat Establish a chat session

Page 20 of 31 UNCLASSIFIED//FOR OFFICIAL USE ONLY

Feature Use Scenario between an in-bound individual and a SME within SSO to answer questions regarding completion of the in-bounds profile

2 Knowledge

Management

Build field specific FAQs associated to the required fields the in-bound individual must answer on the in-bounds profile

3 Mobile Enables in-bound individuals to complete the in-bounds profile on mobile devices

4 E-Mail integration Automate email communication with in-bound individual based upon set of conditions.

Must be able to consume in-bound email to update status of individual’s profile

5 Workflow Automate activities and predefined actions based upon specific triggers, such as passage of time, or specific states (U//FOUO)Table 3 SSO Application Capabilities 484

5.2. (U//FOUO) Support concept 487

(U//FOUO) The support of the new task management system is a cross organizational 489 effort, requiring the expertise of multiple directorates to successfully implement. 490

(U//FOUO) The table below documents the proposed responsibilities of each 491 directorate for supporting the development, implementation and maintenance of the 492 task management system. 493

Page 21 of 31 UNCLASSIFIED//FOR OFFICIAL USE ONLY

Support Task Performing directorates

Description

Technical installation and maintenance of task management environments/application

CDG J6 – System

Administrators, technical team

Install software, apply patches and STIGS, ensure security controls are maintained per the system security plan. (Note anticipate three (3) environments: development, training, production). Upgrade application and underlying software as required

Monitor/Manage system performance

CDG J6 – system administrator

Monitor application storage, database optimization, ensure adequate storage available.

Implementing new/changed business processes

SSO

CDG J6

SSO is responsible for identifying the new and/or changed business processes.

CDG J6 is responsible for working with SSO to document changes and implement within the task management application.

Correcting defects within the application

SSO

CDG J6

SSO is responsible for confirming that identified discrepancy is a defect in the implementation.

Once confirmed, SSO is responsible for prioritizing backlog and target implementation date for correction.

CDG J6 will implement the correction per the prioritization and implementation of the backlog by SSO.

Page 22 of 31 UNCLASSIFIED//FOR OFFICIAL USE ONLY

End User Training/End

User Manual

SSO

CDG J6

SSO is responsible for providing subject matter expertise relating to the business processes and their implementation within the system. SSO will also perform the end user training based on the materials developed by CDG

J6.

CDG J6 is responsible for providing technical SME to answer questions related to how the system works.

CDG J6 is also is responsible for developing the training curriculum and delivery method(s)

User Acceptance Testing SSO SSO will define the criteria that will determine a successful implementation of the task management application. Using the success criteria, SSO will create, document and perform independent user acceptance testing of the developed application, prior to the application being deployed in production environment.

Application Support

System Administrator

Training/System

Administrator Manual

CDG/J6/Vendor CDG/J6 will be responsible for providing the system administrators with training on the maintenance of the application environment.

Additionally, the vendor does provide training tailored to system administrators.

(U//FOUO) Table 9 Operational Support Providers 497

Page 23 of 31 UNCLASSIFIED//FOR OFFICIAL USE ONLY

5.3. (U//FOUO) Operational scenarios 501

(U//FOUO) The following provides examples of how the SSO work management tool 503 would operate in sample new member in-bound scenario. 504

USCYBERCOM New In-Bound Process Flow

SS

O

In -B o u n d

M em b er

Sy st em

Notification of new individual starting

Send individual email with userid to access user profile site

Send individual email with password to user profile site

Individual accesses online profile site Updates profile

Researches FAQ for fields

Chat Session with SSO SME

Signs completed profile

SME Chat session

Create userid & password

Profile Complete

Yes

Send Reminder email

> 7 days last update

No

Yes

> 14 days last update

No

Send Still interested email

Yes

Off page A

Off page B

Off page C

WAITNo

Off page D

NOTE: Box numbers are to facilitate common reference and NOT sequence number

Update Last Update field to current date

(U//FOUO) Figure 3 New In-Bound Page 1 506

Page 24 of 31 UNCLASSIFIED//FOR OFFICIAL USE ONLY

USCYBERCOM New In-Bound Process Flow

SS

O

N ew

M em be r

Sy st em

Off page A

Off page B

Receives Still Interested Email Reply

Still Interested

Set Profile Status = Closed

Suspend Account

NO

>90 Suspended

Account

Delete Account

Wait

Yes

No

Off page C

Profile Accurate

Yes

Export data to other Security Clearance

System(s) Yes

Off page D

Set Profile Status = Signed

Reset Profile Status = Open

Send email detailing

Corrections

No

Reset Signature

Start security workflow

TBD

20 21

262523

NOTE: Box numbers are to facilitate common reference and NOT sequence number

(U//FOUO) Figure 4 New In-Bound Page 2 510

Step

Step Title Comments

1 Notification of new individual starting Multiple triggers for this step

Civilian employee: J1 ServiceNow Process flow –

Inbounds – this would only be for USCYBERCOM future employees

Military in-bound: could be triggered by Fourth

Estate Manpower Tracking System (FMTS)

Military in-bound: direct notification by local

Page 25 of 31 UNCLASSIFIED//FOR OFFICIAL USE ONLY

Step

Step Title Comments commander

Contractor: email notification from either the contractor officer representative (COR) or contractor security officer

Other IC: email notification from sending agencies security officer

Other: email notification

System should track attributes of the affiliation with

USCBYERCOM

2 Create userid & password These individuals will most likely not be in the

USCYBERCOM Active Directory. Need to create a userid and password for the user to access the applicant portal to complete user profile/forms. SSO would create the userid and password

3 Email in-bound with userid Send separate emails to in-bound user email address. One email with userid, second with password.

4 Email in-bound with password Send separate emails to in-bound user email address. One email with userid, second with password.

9 Individual accesses online profile site User logs on and changes password.

10 Updates Profile User starts process of updating their individual profile.

Required information based upon consolidation of data elements from security forms. Dynamic fields add/ required based upon answers to specific questions.

5 Researches FAQ for fields User is able to research field specific FAQs to clarify what information is required.

6 Chat session with SSO SME User initiates request to establish a chat session with SSO

SME

16 SSO SME Chat Session User is able to initiate a chat session with a SSO SME to get clarification/answers to any user questions regarding the information required

11 Profile complete Decision step in process flow

15 Signs Completed profile If user has completed all required fields, user signs profile.

Signing the profile will add the record to the SSO work queue

12 >7 days last update Test to see if the last update of the user’s record is greater than seven (7) days

14 If the answer to step 12 is no, Wait System takes not action

13 If the answer to step 12 is Yes Decision step in process flow

7 Send reminder email If the time since last update is less than 14 days, send a reminder email that profile still needs to be completed

Page 26 of 31 UNCLASSIFIED//FOR OFFICIAL USE ONLY

Step Title Comments

8 Send “Still interested” email If more than 14 days since last update, send formatted email that has yes/no check box to indicate if user is still interested in completing profile. User can complete check box and send email back to system to update record.

Off Page “A” Continuation of “A” process flow

17 Review for Accuracy SSO reviews the questions for indicators or unresolved issues

17.1 Return to User Return specific questions or response to user for more information

17.2 Initial Profile Complete SSO certifies as complete

17.3 Input Security Status SSO verifies individuals current status and security needs

17.31 Initiate Background Investigation If BI doesn’t exist or is out of scope

17.32 Initiate Clearance Adjudication If no adjudication or current adjudication insufficient

17.33 Initiate Polygraph Examination If poly is out of scope or not conducted

17.34 Initiate Pre-Screen Interview Everyone requires an interview prior to submission

17.4 Return questions to user Through the BI, Clearance, Poly, and Interview new information may surface that requires updates to the questions

17.5 Final Profile Complete Affiliate has completed all of the tasks required for submission to NSA for access

18 Export data to security clearance systems Create data extract file that can be consumed by other data processing systems within NSA/USCYBERCOM or external systems

19 Update Status Update the status of NSA processing as information becomes available, may need to initiate BI, Clr, poly depending on timelines

20 Send email detailing corrections After reviewing the profile, a determination is made that the in-bound profile is not accurate. Send email to user notifying them of corrections required to their profile

21 Reset profile status = Open Update the in-bound users record to a state of “open” to allow user to make changes to their profile record

22 Reset signature Reset the signature field to all the in-bound to re-sign their profile after they have completed the information

Off Page “B” Continuation of “B” process flow

23 Receives “Still Interested” email reply System receives and processes the response from the in-bound users.

24 Still Interested Decision step in process flow

25 Set Profile satus = “Closed” If the email answer is “not interested”, then set the status of the profile record to “Closed”. Prevents further updates to the record by the user.

26 Suspend Account Set the in-bound user’s account to “suspended”. Disables

Page 27 of 31 UNCLASSIFIED//FOR OFFICIAL USE ONLY

Step Title Comments the user account preventing future access.

27 >90 days suspended account Test to determine how long user account has been suspended

28 Wait If user account has been suspended less than 90 days, leave account in “suspended” status

30 Delete Account If user account has been suspended more than 90 days, delete the in-bound user account

Off Page “D” Continuation of “B” process flow

29 Set Profile status = “Signed” Update the status of the in-bound profile record to “signed” preventing the user from making any other changes to their profile

Off Page “C” Off page connector

31 Update “Last Update field” to current date

Update “Last Update field” to current date

(U//FOUO) Table 4 In-Bound Process Flow Description 514

Page 28 of 31 UNCLASSIFIED//FOR OFFICIAL USE ONLY

6. (U//FOUO) Summary of impacts 520

6.1. (U//FOUO) Operational impacts 522

(U//FOUO) Addressing the post-deployment of the phase 1of the SSO Task 524

Management tool, the operational impacts will primarily affect the SSO and J1 525 organizations. The implementation of this tool will required revised standard operating 526 procedures within the SSO organization for processing security clearance requests. The 527

J1 will now be able to track SSO activities from within the same application thereby 528 improving communications between the J1 and SSO and with individuals applying for 529 positions within USCYBERCOM. Additionally, the J0 will now be able to obtain real-530 time reports on across both the SSO and J1. These reports can present the leadership 531 with an integrated view of personnel actions between these two organizations. 532

6.2. (U//FOUO) Organizational impacts 534

(U//FOUO) In addition to the operational impacts upon SSO and J1, there will also be an 536 impact upon the CDG J6 organization as related to the architects, system engineers as 537 well as developer community. The procurement and implementation of a new COTS 538 product, will require elements within the CDG J6 to become trained in the capabilities of 539 this technology, the proper configuration and maintenance of the application as well as 540 new application development techniques. 541

Page 29 of 31 UNCLASSIFIED//FOR OFFICIAL USE ONLY

6.3. (U//FOUO) Impacts during development 545

(U//FOUO) The successful acquisition, installation, development and implementation of 547 any new application requires support from a large cross section of the organization. This 548 success will require commitment of resources to this endeavor, including supporting 549 regular status meetings, detailed working sessions to flesh out and document the detail 550 functionality and business rules as well supporting testing and end-user training. The 551 periods and duration of when each type of resource will be required can be mitigated to 552 large degree through project planning. The table below outlines the organizational 553 commitments required and anticipated activities. 554

Organization Anticipated Activities Notes

CDG/ACQ Contract award to procure both the software and implementation services

J8 Obligate funding to support contract award

SSO Subject Matter Expertise Availability will correlate to processes to be implemented

J6 System Administrators Install, configure and maintain COTS software

(patches, STIGS, etc.)

J6 Application Configuration and Development

J615 Information Assurance

CDG/MI Project Manager

(U//FOUO) Table 11 Organizational Impacts 557

7. (U//FOUO) Notes 559

The SSO task management tool will consolidate the data fields of the following forms into a single 560 data collection application. From this consolidated data collection and repository, the task 561 management tool will be able to generate the forms when required. The following is a list of the 562 forms whose data collection will be consolidated into the SSO task management tool: 563

Page 30 of 31 UNCLASSIFIED//FOR OFFICIAL USE ONLY

Form Name Form File Name

1. Security In-Processing Form (instructions and procedures) file name: 10-SIP Instructions

2. Military Additional Contact Sheet (ACS) ACS_050515_eform

ACS_050515_eform

3. System Authorization Access Request (SAAR) dd2875 (blank)

4. Foreign Travel Questionnaire Foreign Travel Questionnaire

5. SENSITIVE COMPARTMENTED INFORMATION

NONDISCLOSURE AGREEMENT

FORM 4414_Rev_12-2013_fillable (Savable)

6. USCC J6 In/Out-Process Information Sheet J6 forms

7. Supplemental Security In-Processing Form for

Language Immersion Trips

Language Immersion Trip_February 2015

8.

9. explanation(s) to the US Cyber Command Special

Security Office Pre-Screen Interview Questionnaire

(USCYBERCOM SSO Form 2)

Questionaire Response Attachment 20180119

10. Supplemental Security In-Processing Form for

Religious Missions Religious Mission Trip_February 2015

11. SCI ATTESTATION SCI ATTESTATION

12. US CYBER COMMAND SPECIAL SECURITY

OFFICE PRE-SCREEN INTERVIEW

QUESTIONAIRE

SCI Pre Screen Questionaire DEC 2017

13. Sensitive Compartmented Information (SCI)

Reporting Responsibilities SCI Reporting Memo

14. CLASSIFIED INFORMATION NONDISCLOSURE

AGREEMENT

SF312

15. Security In-Processing (SIP) Form SIP_050515_eform

16. Sensitive Compartmented Information Pre-Screen

Interview Purpose and Statement of Rights US Cyber Command Pre Screen Notice 20180308

8. (U//FOUO) Appendices 570

(U//FOUO) The following appendices contain the forms noted above. 572

Page 31 of 31 UNCLASSIFIED//FOR OFFICIAL USE ONLY

Appendix A: Acronyms

Acronym Full Name

AFDW Air Force District of Washington

AFPC Air Force Personnel Center

API Application Programming Interface

C4 Command, Control, Communications, Computers

C4IT Command, Control, Communications, Computers and Information Technology

CDG MI Capabilities Development Group Mission Integration

CIO Chief Information Officer

COCOM Combatant Command

CONOPS Concept of Operations

COS Chief of Staff

COTS Commercial Off-The-Shelf

DB Database

DCOS Deputy Chief of Staff

E915 Automated routing and tracking tool supporting the coordination and approval of documentation and taskers

FBI Federal Bureau of Investigations

FMTS Fourth Estate Manpower Tracking System

GOFO General Officer Flag Officer

J1 Personnel and Manpower

J2 Intelligence

J3 Operations

J4 Logistics

J5 Plans and Policy

J6 Operations Architecture & C4/CIO Support

J7 Exercises and Joint Force Deployment

J8 Capability and Resource Integration

JCS Joint Chiefs of staff

MPR Manpower Personnel Representative

NCIC FBI National Crime Information Center

NIPRNet Nonsecure Internet Protocol Router Network

NSA National Security Agency

SIPRNet SECRET Internet Protocol Router Network

SORN System of Record Notice

SSO Special Security Office

USAF United States Air Force

USCG United States Coast Guard

USCYBERCOM United States Cyber Command

USSTRATCOM United States Strategic Command

File details come from the government source that posted it.