SSO_Toolkit_CONOPS_final.pdf
PDF 1 MB Posted
- Attached to
- ServiceNow Federal contract opportunity
- Solicitation number
- HB0001-18-R-0012
- Issued by
- Department of Defense Cyber Command
About this file
SSO Toolkit CONOPS final
View the file
Other files for this federal contract opportunity
Show all 29
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
CONCEPT OF
OPERATIONS FOR
US Cyber Command
Special Security Office Task Management Tool
Version 1.0
May 11, 2018
SSO Toolkit Page 2 of 32
Version Date
Comments Author
.1 03/29/18 Initial Version E. Wojciechowski
.2 04/02/18 Incorporate comments from SSO A. Wuornos, E. Wojciechowski
1.0 5/11/18 Incorporate comments from SSO Update figures 4 & 5 and table 4;
Updated section 5.1.4 add two factor authentication
B. Wuornos, E. Wojciechowski
SSO Toolkit Page 3 of 32
TABLE OF CONTENTS
Contents 1
CONCEPT OF OPERATIONS FOR ................................................................................................... 1 2
TABLE OF CONTENTS ...................................................................................................................... 3 3
1. Executive Summary .............................................................................................................. 4 4
2. CONOPS Scope .................................................................................................................... 4 5
2.1. Identification ......................................................................................................................... 5 6
2.2. Document security ................................................................................................................ 5 7
2.3. System security ..................................................................................................................... 5 8
3. Current system or situation ................................................................................................... 5 9
3.1. Background, objectives, and scope ....................................................................................... 5 10
3.2. Operational policies and constraints ..................................................................................... 6 11
3.3. Description of current system or situation ............................................................................ 7 12
3.4. System User Classes ........................................................................................................... 13 13
3.5. Support concept .................................................................................................................. 15 14
4. Analysis of the proposed system ........................................................................................ 15 15
4.1. Summary of advantages ...................................................................................................... 15 16
4.2. Summary of disadvantages or limitations ........................................................................... 16 17
4.3. Alternatives and trade-offs considered ............................................................................... 16 18
5. Concept for a new or modified system ............................................................................... 16 19
5.1. Description of the new or modified system ........................................................................ 16 20
5.2. Support concept .................................................................................................................. 20 21
5.3. Operational scenarios .......................................................................................................... 23 22
6. Summary of impacts ........................................................................................................... 29 23
6.1. Operational impacts ............................................................................................................ 29 24
6.2. Organizational impacts ....................................................................................................... 29 25
6.3. Impacts during development ............................................................................................... 30 26
7. Notes ................................................................................................................................... 30 27
8. Appendices .......................................................................................................................... 31 28
Appendix A: Acronyms .......................................................................................................................... 32 29
SSO Toolkit
1. Executive Summary
US CYBER COMMAND’s (USCYBERCOM) primary location is co-located within the
National Security Agency (NSA) at Ft. Meade, Maryland. All individuals who will be working at USCYBERCOM’s offices must go through a two step process before being granted approval for both physical and network access to USCYBERCOM facilities and networks. All personnel must first have a current security clearance level of Top Secret/
Sensitive Compartmented Information with a Counter Intelligence Polygraph (TS/SCI with CI/Poly). After USCYBERCOM verifies or approves the security clearance for the individual, NSA then makes a determination as to granting access to the NSA facilities and networks. Once both these actions are fully adjudicated, an individual is granted access to both NSA facilities and NSA/USCYBERCOM networks. This is a lengthy process that can take several months to years for full resolution. Currently, this process is primarily manual. This Special Security Office (SSO) CONOPS presents a vision for automating the multiple forms that an individual must complete in order to obtain both the security clearance and access approval. Automating this data collection will be the first step of increasing the automation of the security clearance and access approval processes as well as other processes with the SSO. It is anticipated that automating the data collection will potentially reduce the time to obtain approval to work at
USCYBERCOM through improved data integrity and reduction of multiple manual data entry processes on both the in-bound individual as well as the SSO staff. Additionally, this automation will provide transparency to the command leadership through automated reporting of the status of security clearance processes. USCYBERCOM’s security office will leapfrog into the 21st century with a set of tools to support moving at the speed of cyber for security processing.
2. CONOPS Scope
In addition to the National Background Investigations Bureau Electronic Questionnaires for
Investigations Processing (e-QIP), USCBYERCOM also requires additional information specific to
USCYBERCOM to be submitted by individuals who will be working at USCYBERCOM facilities (In-bound individuals). This CONOP is limited to the automated tools required that will support a single data entry of all required information by an in-bound individual who will be working at
USCYBERCOM1.
1 This CONOPS does not replace the current e-QIP. e-QIP is still required and integration with e-QIP tool while desire is not required as part of the solution.
2.1. Identification
2.2. Document security
All information documented herein shall be classified as “Unclassified, For Official
Use Only” (U/OFUO).
2.3. System security
The primary end users of this system are both individuals who currently do not have an affiliation with USCYBERCOM (in-bound individuals) as well as USCYBERCOM
Security and Counter Intelligence, Special Security Office (SSO) users. Based upon these two different user groups, the system will be available through both the Internet
(grey space) and within the NSA/USCBYERCOM intranet (both Top Secret and
Unclassified environments). It is anticipated that data will be required to be exchanged between all these security environments. The data that is being collected will contain
“Personally Identifiable Information (PII2). Applying the Risk Management Framework controls, it is anticipated that these systems will have a Confidentiality rating of high, Integrity rating of high and an availability rating of medium. The system must have security controls implemented consistent with these anticipated ratings.
3. Current system or situation
3.1. Background, objectives, and scope
The mission of the SSO is: “…responsible for the protection of USCYBERCOM information, people and facilities. The SSO Division integrates personnel and physical security disciplines with counterintelligence programs to achieve a security in depth posture that manages the risks arrayed USCYBERCOM extraordinary sensitive and fragile mission….”
SSO is currently hampered in its ability to fully meet the mission and vision as stated due to a reliance upon manual data entry into multiple disconnected existing systems, manual tools and processes. As USCYBERCOM continues to increase staffing levels and the corresponding security activities, a reliance upon manual tools and processes will adversely impact the SSO’s ability to manage the anticipated staffing levels.
2 It is anticipated that this system will be covered under the same SORN as the J1 Human Resources Toolkit and will not require a separate SORN.
Additionally, providing leadership with timely information regarding current staffing security actions, is a staff intensive, manual effort and represents data that is aged and often not actionable.
The scope of this CONOPS is to document the first phase of what is envisioned to be a multi-phase project to bring automation to the SSO processes. This first phase is to provide a tool to enable in-bound individuals to enter all required information to support the USCYBERCOM/NSA security clearance and access processes a single time. The system will collect all required data once, and then route this information to the corresponding offices for processing and generate the necessary forms (either electronic or paper) as required. In the collection of the user’s data, corresponding technology will be leveraged to increase the accuracy of the information entered by the user through the use of real-time chat, knowledge management Frequently Asked Questions tailored to each data element requested and systematic exchanges with the applicant that can be automatically tracked. The technology solution is intended to support the current internal USCYBERCOM SSO user community and the J1 manpower personnel directorate (MPR) and leadership within each Directorates. The solution is intended to function in a complementary capacity to existing internal and external systems. The optimal solution will minimize manual data entry/manual data reporting while maximizing data integrity between these other systems.
3.2. Operational policies and constraints
USCYBERCOM is a joint command with representatives from all military services, other intelligence community agencies as well as civilian staff. All individuals who will be stationed at and working at USCYBERCOM are required to comply with the security policies of both USCYBERCOM and NSA. In developing this CONOP the following policies have been used in guiding the content of this document:
a) DoD Directive 5124.02 “Under Secretary of Defense for Personnel and Readiness
(USD(P&R)),” June 23, 2008
b) DoD Directive 1400.25, “DoD Civilian Personnel Management Systems,”
November 25, 1996, http://dtic.mil/whs/directives/corres/CPM_table2.html
c) Subtitle III of Title 40, United States Code
d) Title 10, United States Code
e) DoD Directive 8115.01, “Information Technology Portfolio Management,”
October 10, 2005
f) DoD Directive 8000.01, “Management of the Department of Defense http://dtic.mil/whs/directives/corres/CPM_table2.html
Information Enterprise,” February 10, 2009
g) Office of the Deputy Chief Management Officer
Website, http://dcmo.defense.gov
h) DoD Instruction 5025.01, “DoD Directives Program,” September 26, 2012 as amended
i) DoD Instruction 8510.01, “Risk Management Framework (RMF) for DoD
Information Technology(IT),” March 12, 2014, Incorporating change 1, Effective
May 24, 2016
j) DoD Instruction 5000.02, “Operation of the Defense Acquisitions System,”
January 7, 2015
k) DoD Directive 8500.01E “Information Assurance (IA),” April 23, 2007
l) DoD Manual 5200.01 – Volume 1, “DoD Information Security Program:
Overview, Classification, and Declassification,” February 24, 2012
m) National Institutes of Standards and Technology, Special Publication 800-53, Rev 4
n) Section 552a of Title 5, United States Code, (also known as “The Privacy Act of
1974,” as amended)
o) DoD 5400.11, Department of Defense Privacy Program,” October 29, 2014
p) DoD Instruction 8910.01, “Information Collection and Reporting,” May 19, 2014
q) National Security Agency/Central Security Services (NSA/CSS), Security Policy Series 5
r) NSA/CSS Policy 5-1, Personnel Security Requirements for Members of the Service
Cryptologic Components Assigned or Detailed within NSA/CSS
3.3. Description of current system or situation
3.3.1. Operational environment
The current operational environment is a patchwork of primarily disconnected systems and manual processes coupled with a dependency upon a complex of external systems. The SSO currently relies upon a combination of physical paper forms, email and MS Excel spreadsheets to track personnel security actions and email to obtain status updates that are then manually entered into the Excel spreadsheet. This method does not capture elapsed time within any one action or within one individual or group.
Providing any type of meaningful reports, such as trend analysis, outstanding actions or number of priority actions as examples, is challenging and results, when possible, are often delayed due to the manual efforts required.
3.3.2. System Components
http://dcmo.defense.gov/
In its personnel security role for the USCYBERCOM, the SSO has organizational interactions across the command of USCYBERCOM as well as working with other federal civilian agencies, as well as external military services related to personnel security decisions. Some of these external agencies include the Federal Bureau of
Investigations, National Security Agency, Central Adjudication Facilities, and others.
3.3.3. Interfaces to external systems or procedures
In the performance of its mission, the SSO interacts with several data processing systems that are external to USCYBERCOM. These systems are the official records related to the in-bound individual or provide commercial reporting services regarding the individual. Some of these external agencies and systems include the Joint
Verification System (JVS), Joint Personnel Adjudication System (JPAS), Electronic
Questionnaires for Investigations Processing (e-QIP), Public record checks, and others.
3. In many instances, data is manually copied from these external systems to either a paper file, manual data entry to another system or into office collaboration applications maintained by the SSO.
3.3.4. Capabilities
The SSO along with the CDG/MI and J1, jointly participated in a series of meetings from October through December 2016 and again in March 2018 with the objective of identifying initial set of functionalities of the SSO Task Management Tool. The team identified the following mission areas requiring support by the automated tool:
Single Consolidated Data Entry for all personnel assigned to work at USCYBERCOM
Automated generation of “on-boarding” forms based upon above data entry
Automated workflow of security review process
Automated data reporting
At the highest level of abstraction, J1 has identified a need for an automated task management tool that would:
support the capture and tracking of work requests, set prioritization of work requests through the application of business rules, give assignment of work requests to “qualified and available staff”; and, provide robust real-time reporting capabilities.
3 Integration with these other external agencies or commercial services is not included in the initial phase 1 scope.
Figure 1 SSO Task Management System Components illustrates a high level notional concept of a work management foundational tool. This tool provides generic work management capabilities that are configured based upon specific business rules. The key concept is that the deployment of this tool supporting the SSO processes and internal tracking is based upon configuration of native functionality within the COTS software application rather than creating a custom application. Key features of this work management foundational tool include:
Work Queue – backlog of work requests that need to be completed
User Queue – listing of users and their associated profiles
Business rules – defines the attributes of a work item, logic for prioritizing work and expected timeframes for completion of work item or work step
User Assignment Rules – based upon user profile, matches available user to work item and assigns work item to either individual user or group of users
Routing Rule – defines the activities that must be accomplished and the sequence of steps to be performed based upon the type of work item.
Business Application Layer
Daily Operations:
Background Investigation Clearance Adjudication Polygraph Examination NSA Access Approval
Daily Operations
Visitor Access Request Reinvestigation Reporting and Incidents Event Management Clearance Verification Edit: Contractor Security Renewal to Industrial Security Management Outbound/Out-Processing
Security Office Events
Workflow/Task Management Processes
API
Task Management Application
Work Queue User Queue
Business Rules
User Assignment
Rules
Create/Update Work Item
Work Request
Routing Rules
More Steps EndNO
YES
Figure 1 SSO Task Management System Components
3.3.5. Performance characteristics, The nature of the work that SSO performs is of a medium-volume high-interaction nature. Low-volume in terms of the total number of security actions performed each year. High-interaction in that multiple individuals are required to complete any one security action. The table below provides estimated number of security actions required to be supported by the proposed tool each year.
Category Objective Annual Projected Transactions –
Low
Annual Projected Transactions –
High
Onboarding Background Investigation
30 200
Onboarding Clearance Adjudication 100 500
Onboarding Polygraph Examination 1000 3000
Onboarding NSA Access 1500 3500
Daily Operations Visitor Access Request 600 3000
Daily Operations Reinvestigation 500 1500
Daily Operations Reporting and Incidents 200 600
Daily Operations Event Management 10 50
Daily Operations Clearance Verification 1000 6000
Daily Operations Industrial Security –
DD 254
50 150
Daily Operations Out-Processing 600 1200 Table 1Volume Projections
3.3.6. Quality
Quality is a multidimensional aspect within the final solution. The following identifies the critical aspects that must be included within the delivery of the final solution.
3.3.6.1. Reliability:
defined as the ability of the software to consistently perform according to its specifications. J1 requires that the application perform according to the agreed upon specifications with no critical defects (a defect for which there is no system work around).
3.3.6.2. Maintainability:
defined as the ease with which a system can be maintained and corrected. Software industry recognizes four different types of maintenance as noted below. Regardless of the types of maintenance, the implementation of these maintenance activities should not impact the production availability of the system to the user community and be able to be performed during routine maintenance times.
3.3.6.2.1. Adaptive:
modifying the system to cope with changes in the software environment (system patches, application of STIGs, application upgrades)
3.3.6.2.2. Perfective:
implementing new or changed user requirements which concern functional enhancements to the software
3.3.6.2.3. Corrective:
diagnosing and fixing errors
3.3.6.2.4. Preventative:
increasing software maintainability or reliability to prevent problems in the future
3.3.6.3. Availability:
defined as the percentage of time the application is available and functioning for the end user. SSO requires an availability time of
99% Monday through Friday, 06:00 – 21:00 EST.
3.3.6.4. Portability:
There are several aspects to the applicability of software portability.
3.3.6.4.1. Multiple operating systems support:
Ability to operate the software in different operating system environments. The Command requires that the workflow tool be able to be supported by current operating systems, including standard PC desktops and servers, as well as mobile computing platforms, such as Android, IOS and other standards4.
4 While mobile computing platforms are not currently supported, the SSO work management tool should
3.3.6.4.2. Network security classification portability:
USCYBERCOM utilizes multiple networks, NIPRNet, SIPRNet, NSANet, The work management tool should support developing a business application in one environment and then deploying in multiple network environments without requiring additional development coding or configuration efforts.
3.3.6.5. Usability:
The work management tool shall comply with W3C usability standards for end user interface design and with section 508 standards. Response times for end user displays shall be in the range of page loading between 3 – 6 seconds.
3.3.7. Security:
The work management tool will comply with the Risk Management
Framework (RMF) 2.0 standards consistent with the RMF rating assigned by the CDG J65 Information Assurance Manager once the system design is finalized.
3.3.8. Privacy:
The work management tool will comply with the Privacy Act of 1974, as amended.
3.3.9. Continuity of Operations:
SSO recognizes that in the event that a Continuity of Operations Plan
(COOP) is required to be implemented, mission applications must be prioritized relative to the order in which specific missions are supported.
Accordingly, in order to continue the overall mission of USCYBERCOM, SSO requires that the task management application must be restored no later than two (2) calendar days after the initiation of a COOP.
3.4. System User Classes
The SSO work management tool will be utilized by multiple classes of users. During the initial phase the following classes of users are anticipated to use the SSO work management system:
not preclude supporting mobile computing when implemented in the USCYBERCOM environment.
User Class Attributes Access Restrictions
New Staff - Inbound Individual who is assigned to be working at USCYBERCOM
Individual may or may not already have an active security clearance
Individual can only access their own record.
User can view and update own record.
(Once submitted user cannot delete previously reported information)
User can print own record at their local computer
User can email their own record to the primary email address within their record
SSO administrator Manages SSO user access and
SSO work queues, Grants non-SSO users access to limited SSO data fields
Grants access to SSO reports
Can access any SSO record, SSO work queue
Ability to delete SSO records
Limited view access to J1 HR individual’s records
SSO Users Can view SSO record based upon security group privileges
Can update SSO related data fields
Access to SSO work queues
Can view SSO predefined reports, can create own reports
Limited view access to J1 HR individual’s records
J1 HR user Individuals assigned to J1 HR group
J1HR limited view of SSO information associated with a current or new inbound who will become an
USCYBERCOM employee.
J1HR can not view records associated with USCYBERCOM contractors, other
IC staff members, i.e. DIA staff, NSA, FBI, CIA, NGA, etc.
User Class Attributes Access Restrictions
Chief of Staff View statuses of all personnel in their directorate
View reports on timelines and trends
Specific J1 and SSO information
Table 2 User Attribute Table
3.5. Support concept
In the current manual process of utilizing Excel spreadsheets and email, SSO is providing all support for this process. There are multiple interactions with each of the Directorates, CDG,CMFs, external agencies and the senior level, however it is SSO’s responsibility to manage, track and report on the results of these processes. With the implementation of this new system, support will be provided by the J6 organization.
4. Analysis of the proposed system
4.1. Summary of advantages
The implementation of the SSO work management tool as envisioned within this
CONOPS delivers the following advantages to not only the SSO, but to
USCYBERCOM overall.
1. Improved accuracy of the initial security forms submitted by the in bound individuals, through the use of the products capabilities, Frequently Asked
Questions, real-time chat, email integration, dynamic form logic to require additional information based upon specific answers.
2. Electronic data exchange of in-bound individual’s data to other systems, eliminating physically rekeying data.
3. Reduced security clearance processing time due to the improved accuracy of the submitted completed forms and a more efficient process.
4. Improved user experience through the elimination of required redundant information across multiple forms.
5. Work load balancing across SSO staff through real time reporting of work backlogs.
6. Trend analysis identifying current organizational delays impacting personnel actions.
7. Real Time reporting on SSO actions.
8. Improved transparency of SSO to internal USCYBERCOM leadership through automated reporting capabilities.
9. Automatic tracking of durations each action remains within each step and/or organization for each process.
4.2. Summary of disadvantages or limitations
The solution proposed does not cross network boundaries. This means that SSO will continue to have to use current manual processes to transfer across network boundaries into systems resident on other network.
4.3. Alternatives and trade-offs considered
USCYBERCOM has already made a strategic decision to procure ServiceNow. This
CONOPS is following the guidance to utilize ServiceNow.
5. Concept for a new or modified system
5.1. Description of the new or modified system5
The implementation of the SSO’s task management tool will significantly change and enhance the SSO’s current business practices while improving the overall timeliness of the mission of the SSO. The sections below document these envisioned changes.
5.1.1. Operational environment
With the implementation of SSO’s task management tool, the operational environment will significantly change. The SSO will no longer be dependent upon physical paper forms, MS Excel and email for tracking personnel actions and obtaining status from the different directorates. SSO, as well as all users of the tool, will be able to obtain real-time
5 For a description of the basic requirements of the underlying workflow system, reference the “Concept of Operations for US
CYBER COMMAND Human Resources Information System,” version 1.0, dated February 14, 2017.
updates on the status of personnel security actions from this automated tool. All users will be able to see what actions have been completed, and what actions still remain to be done. Users will be able to identify if the action is not being worked and will be prompted to follow up, accordingly.
Additionally, because the quality of the initial security forms submitted by the user will be increased, time required for contacting the in-bound individual to correct information will be reduced. Additionally, with the elimination of rekeying of data into multiple different systems used by the SSO the overall time required to process through security clearance will be reduced.
Additionally, SSO will be able to provide actionable real-time reports on personnel security actions to J0. Time spent within each step of the process and by each directorate will be discretely captured, enabling detailed reporting. Historical trends will be automatically documented. This historical information can uncover potential slowdowns and/or stoppages in processes. Root cause analysis can be performed to remediate either through additional user training or process changes.
5.1.2. System Components
The system will be built using the Commercial Off The Shelf (COTS) product ServiceNow and its
Now Platform custom application feature. The diagram below is a conceptual view of the envisioned environment as it is deployed for production use.
MADO Application (exists today)
D M
Z
INBOUND
External Applicant Application Portal
(Future)
J1 HR Application (Future)
INTERNET Unclassified
Top Secret
Commercial Credit
Reporting
NCIC E-QIP
SSO Application (Future)
SSO Application (Future)
D M
Z
Applicant
Server
Figure 2 SSO Task Management Notional Environment
5.1.2.1. Security Enclaves:
The system will be deployed across three unique security enclaves: unfettered Internet, NSA NIPRNET unclassified environment and NSANET Top Secret environments.
5.1.2.2. Applications
The system will be comprised of a combination of multiple ServiceNow instances within the unclassified and Top Secret environments. Additionally, a custom application portal will be built to allow authorized external users access to the security forms. An applicant application server will be built to facilitate communications between the applicant portal and the SSO ServiceNow application within the DMZ.
ServiceNow applications: Within each security enclave there will be a single
ServiceNow installation, with multiple applications running within each
ServiceNow instance. These ServiceNow applications will include native
ServiceNow applications, such as ITSM applications, as well as custom applications built using the ServiceNow Now Application custom application feature.
MADO Application is a NSA application that this used to manage the NSA building and network access granting processes.
5.1.3. Interfaces to external systems or procedures
As noted in Figure 2 SSO Task Management Notional Environment, SSO interacts with multiple internal and external systems in the completion of its mission. The proposed system will eventually interface to multiple internal and external systems.
Some of these systems include:
e-QIP: OPM Electronic Questionnaires for Investigations Processing
NCIC: FBI National Crime Information Center
Commercial Credit Reporting: external commercial agencies, such as
Transunion, Experian and others
MADO: NSA custom internal application
5.1.4. Capabilities
In addition to the capabilities identified in the “Concept of Operations for US CYBER
COMMAND Human Resources Information System,” version 1.0, dated February 14, 2017, the SSO task management system will utilize the following ServiceNow features:
Feature Use Scenario
1 Chat Establish a chat session
Feature Use Scenario between an in-bound individual and a SME within SSO to answer questions regarding completion of the in-bounds profile
2 Knowledge
Management
Build field specific FAQs associated to the required fields the in-bound individual must answer on the in-bounds profile
3 Mobile Enables in-bound individuals to complete the in-bounds profile on mobile devices
4 E-Mail integration Automate email communication with in-bound individual based upon set of conditions.
Must be able to consume in-bound email to update status of individual’s profile
5 Workflow Automate activities and predefined actions based upon specific triggers, such as passage of time, or specific states
6 Two Factor
Authentication
Users who do not log on via a PKI or CAC must utilize an alternative two factor authentication method to complete logon to the application.
Table 3 SSO Application Capabilities
5.2. Support concept
The support of the new task management system is a cross organizational effort, requiring the expertise of multiple directorates to successfully implement.
The table below documents the proposed responsibilities of each directorate for supporting the development, implementation and maintenance of the task management system.
Support Task Performing directorates
Description
Technical installation and maintenance of task management environments/application
CDG J6 – System
Administrators, technical team
Install software, apply patches and STIGS, ensure security controls are maintained per the system security plan. (Note anticipate three (3) environments: development, training, production). Upgrade application and underlying software as required
Monitor/Manage system performance
CDG J6 – system administrator
Monitor application storage, database optimization, ensure adequate storage available.
Implementing new/changed business processes
SSO
CDG J6
SSO is responsible for identifying the new and/or changed business processes.
CDG J6 is responsible for working with SSO to document changes and implement within the task management application.
Correcting defects within the application
SSO
CDG J6
SSO is responsible for confirming that identified discrepancy is a defect in the implementation.
Once confirmed, SSO is responsible for prioritizing backlog and target implementation date for correction.
CDG J6 will implement the correction per the prioritization and implementation of the backlog by SSO.
End User Training/End
User Manual
SSO
CDG J6
SSO is responsible for providing subject matter expertise relating to the business processes and their implementation within the system. SSO will also perform the end user training based on the materials developed by CDG
J6.
CDG J6 is responsible for providing technical SME to answer questions related to how the system works.
CDG J6 is also is responsible for developing the training curriculum and delivery method(s)
User Acceptance Testing SSO SSO will define the criteria that will determine a successful implementation of the task management application. Using the success criteria, SSO will create, document and perform independent user acceptance testing of the developed application, prior to the application being deployed in production environment.
Application Support
System Administrator
Training/System
Administrator Manual
CDG/J6/Vendor CDG/J6 will be responsible for providing the system administrators with training on the maintenance of the application environment.
Additionally, the vendor does provide training tailored to system administrators.
Table 9 Operational Support Providers
5.3. Operational scenarios
The following provides examples of how the SSO work management tool would operate in sample new member in-bound scenario.
USCYBERCOM New In-Bound Process Flow
SS
O
In -B o u n d
M em b er
Sy st em
Notification of new individual starting
Send individual email with userid to access user profile site
Send individual email with password to user profile site
Individual accesses online profile site Updates profile
Researches FAQ for fields
Chat Session with SSO SME
Signs completed profile
SME Chat session
Create userid & password
Profile Complete
Yes
Send Reminder email
> 7 days last update
No
Yes
> 14 days last update
No
Send Still interested email
Yes
Off page A
Off page B
Off page C
WAITNo
Off page D
NOTE: Box numbers are to facilitate common reference and NOT sequence number
Update Last Update field to current date
Figure 3 New In-Bound Page 1
USCYBERCOM New In-Bound Process Flow
SS
O
N ew
M em be r
Sy st em
Off page A
Off page B
Receives Still Interested Email Reply
Still Interested
Set Profile Status = Closed
Suspend Account
NO
>90 Suspended
Account
Delete Account
Wait
Yes
No
Off page C
Profile Accurate
Yes
SSO Certifies as Complete
Yes
Off page D
Set Profile Status = Signed
Reset Profile Status = Open
Send email detailing
Updates Req d
No
Reset Signature
Input Security Status
17.2
20 21
17.3
262523
NOTE: Box numbers are to facilitate common reference and NOT sequence number
Off page E
Figure 4 New In-Bound Page 2
USCYBERCOM New In-Bound Process Flow
SS
O
N e w
M em b er
Sy st em
Initiate Background Investigation
Initiate Clearance
Adjudication
Initiate Polygraph
Examination
Go To Item 20
Team Chief Review
Yes
No
Off page E
17.31
NOTE: Box numbers are to facilitate common reference and NOT sequence number
17.32
17.33
Initiate Prescreen Interview
17.34
Applicant Updates
Req d
Update Status to Complete
17.5
17.4
17.51
Export Data
( U//FOUO) Figure 5 New In-Bound Page 3
Step
Step Title Comments
1 Notification of new individual starting Multiple triggers for this step
Civilian employee: J1 ServiceNow Process flow –
Inbounds – this would only be for USCYBERCOM future employees
Military in-bound: could be triggered by Fourth
Estate Manpower Tracking System (FMTS)
Military in-bound: direct notification by local commander
Contractor: email notification from either the contractor officer representative (COR) or contractor security officer
Other IC: email notification from sending agencies security officer
Other: email notification
System should track attributes of the affiliation with
USCBYERCOM
2 Create userid & password These individuals will most likely not be in the
USCYBERCOM Active Directory. Need to create a userid and password for the user to access the applicant portal to complete user profile/forms. SSO would create the userid and password
3 Email in-bound with userid Send separate emails to in-bound user email address. One email with userid, second with password.
4 Email in-bound with password Send separate emails to in-bound user email address. One email with userid, second with password.
9 Individual accesses online profile site User logs on and changes password.
10 Updates Profile User starts process of updating their individual profile.
Required information based upon consolidation of data elements from security forms. Dynamic fields add/ required based upon answers to specific questions.
5 Researches FAQ for fields User is able to research field specific FAQs to clarify what information is required.
6 Chat session with SSO SME User initiates request to establish a chat session with SSO
SME
16 SSO SME Chat Session User is able to initiate a chat session with a SSO SME to get clarification/answers to any user questions regarding the information required
11 Profile complete Decision step in process flow
Step
Step Title Comments
15 Signs Completed profile If user has completed all required fields, user signs profile.
Signing the profile will add the record to the SSO work queue
12 >7 days last update Test to see if the last update of the user’s record is greater than seven (7) days
14 If the answer to step 12 is no, Wait System takes not action
13 If the answer to step 12 is Yes Decision step in process flow
7 Send reminder email If the time since last update is less than 14 days, send a reminder email that profile still needs to be completed
8 Send “Still interested” email If more than 14 days since last update, send formatted email that has yes/no check box to indicate if user is still interested in completing profile. User can complete check box and send email back to system to update record.
Off Page “A” Continuation of “A” process flow
17 Review for Accuracy SSO reviews the questions for indicators or unresolved issues
17.1 Return to User Return specific questions or response to user for more information
17.2 Initial Profile Complete SSO certifies as complete
17.3 Input Security Status SSO verifies individuals current status and security needs
17.31 Initiate Background Investigation If BI doesn’t exist or is out of scope
17.32 Initiate Clearance Adjudication If no adjudication or current adjudication insufficient
17.33 Initiate Polygraph Examination If poly is out of scope or not conducted
17.34 Initiate Pre-Screen Interview Everyone requires an interview prior to submission
17.4 Return questions to user Through the BI, Clearance, Poly, and Interview new information may surface that requires updates to the questions
17.5 Team Chief Review SSO sends complete information for review to Team Chief
17.51 Final Profile Complete Affiliate has completed all of the tasks required for submission to NSA for access
18 Export data to security clearance systems Create data extract file that can be consumed by other data processing systems within NSA/USCYBERCOM or external systems
19 Update Status Update the status of NSA processing as information becomes available, may need to initiate BI, Clr, poly depending on timelines
20 Send email detailing corrections After reviewing the profile, a determination is made that the in-bound profile is not accurate. Send email to user notifying them of corrections required to their profile
21 Reset profile status = Open Update the in-bound users record to a state of “open” to allow user to make changes to their profile record
Step
Step Title Comments
22 Reset signature Reset the signature field to all the in-bound to re-sign their profile after they have completed the information
Off Page “B” Continuation of “B” process flow
23 Receives “Still Interested” email reply System receives and processes the response from the in-bound users.
24 Still Interested Decision step in process flow
25 Set Profile status = “Closed” If the email answer is “not interested”, then set the status of the profile record to “Closed”. Prevents further updates to the record by the user.
26 Suspend Account Set the in-bound user’s account to “suspended”. Disables the user account preventing future access.
27 >90 days suspended account Test to determine how long user account has been suspended
28 Wait If user account has been suspended less than 90 days, leave account in “suspended” status
30 Delete Account If user account has been suspended more than 90 days, delete the in-bound user account
Off Page “D” Continuation of “B” process flow
29 Set Profile status = “Signed” Update the status of the in-bound profile record to “signed” preventing the user from making any other changes to their profile
Off Page “C” Off page connector
31 Update “Last Update field” to current date
Update “Last Update field” to current date
Table 4 In-Bound Process Flow Description
6. Summary of impacts
6.1. Operational impacts
Addressing the post-deployment of the phase 1of the SSO Task Management tool, the operational impacts will primarily affect the SSO and J1 organizations. The implementation of this tool will required revised standard operating procedures within the SSO organization for processing security clearance requests. The J1 will now be able to track SSO activities from within the same application thereby improving communications between the J1 and SSO and with individuals applying for positions within USCYBERCOM. Additionally, the J0 will now be able to obtain real-time reports on across both the SSO and J1. These reports can present the leadership with an integrated view of personnel actions between these two organizations.
6.2. Organizational impacts
In addition to the operational impacts upon SSO and J1, there will also be an impact upon the CDG J6 organization as related to the architects, system engineers as well as developer community. The procurement and implementation of a new COTS product, will require elements within the CDG J6 to become trained in the capabilities of this technology, the proper configuration and maintenance of the application as well as new application development techniques.
6.3. Impacts during development
The successful acquisition, installation, development and implementation of any new application requires support from a large cross section of the organization. This success will require commitment of resources to this endeavor, including supporting regular status meetings, detailed working sessions to flesh out and document the detail functionality and business rules as well supporting testing and end-user training. The periods and duration of when each type of resource will be required can be mitigated to large degree through project planning. The table below outlines the organizational commitments required and anticipated activities.
Organization Anticipated Activities Notes
CDG/ACQ Contract award to procure both the software and implementation services
J8 Obligate funding to support contract award
SSO Subject Matter Expertise Availability will correlate to processes to be implemented
J6 System Administrators Install, configure and maintain COTS software
(patches, STIGS, etc.)
J6 Application Configuration and Development
J615 Information Assurance
CDG/MI Project Manager
Table 11 Organizational Impacts
7. Notes
The SSO task management tool will consolidate the data fields of the following forms into a single data collection application. From this consolidated data collection and repository, the task management tool will be able to generate the forms when required. The following is a list of the forms whose data collection will be consolidated into the SSO task management tool:
Form Name Form File Name
1. Security In-Processing Form (instructions and procedures) file name: 10-SIP Instructions
2. Military Additional Contact Sheet (ACS) ACS_050515_eform
ACS_050515_eform
3. System Authorization Access Request (SAAR) dd2875 (blank)
4. Foreign Travel Questionnaire Foreign Travel Questionnaire
5. SENSITIVE COMPARTMENTED INFORMATION
NONDISCLOSURE AGREEMENT
FORM 4414_Rev_12-2013_fillable (Savable)
6. USCC J6 In/Out-Process Information Sheet J6 forms
7. Supplemental Security In-Processing Form for
Language Immersion Trips
Language Immersion Trip_February 2015
8.
9. explanation(s) to the US Cyber Command Special
Security Office Pre-Screen Interview Questionnaire
(USCYBERCOM SSO Form 2)
Questionaire Response Attachment 20180119
10. Supplemental Security In-Processing Form for
Religious Missions Religious Mission Trip_February 2015
11. SCI ATTESTATION SCI ATTESTATION
12. US CYBER COMMAND SPECIAL SECURITY
OFFICE PRE-SCREEN INTERVIEW
QUESTIONAIRE
SCI Pre Screen Questionaire DEC 2017
13. Sensitive Compartmented Information (SCI)
Reporting Responsibilities SCI Reporting Memo
14. CLASSIFIED INFORMATION NONDISCLOSURE
AGREEMENT
SF312
15. Security In-Processing (SIP) Form SIP_050515_eform
16. Sensitive Compartmented Information Pre-Screen
Interview Purpose and Statement of Rights US Cyber Command Pre Screen Notice 20180308
8. Appendices
The following appendices contain the forms noted above.
Appendix A: Acronyms
Acronym Full Name
AFDW Air Force District of Washington
AFPC Air Force Personnel Center
API Application Programming Interface
C4 Command, Control, Communications, Computers
C4IT Command, Control, Communications, Computers and Information Technology
CDG MI Capabilities Development Group Mission Integration
CIO Chief Information Officer
COCOM Combatant Command
CONOPS Concept of Operations
COS Chief of Staff
COTS Commercial Off-The-Shelf
DB Database
DCOS Deputy Chief of Staff
E915 Automated routing and tracking tool supporting the coordination and approval of documentation and taskers
FBI Federal Bureau of Investigations
FMTS Fourth Estate Manpower Tracking System
GOFO General Officer Flag Officer
J1 Personnel and Manpower
J2 Intelligence
J3 Operations
J4 Logistics
J5 Plans and Policy
J6 Operations Architecture & C4/CIO Support
J7 Exercises and Joint Force Deployment
J8 Capability and Resource Integration
JCS Joint Chiefs of staff
MPR Manpower Personnel Representative
NCIC FBI National Crime Information Center
NIPRNet Nonsecure Internet Protocol Router Network
NSA National Security Agency
SIPRNet SECRET Internet Protocol Router Network
SORN System of Record Notice
SSO Special Security Office
USAF United States Air Force
USCG United States Coast Guard
USCYBERCOM United States Cyber Command
USSTRATCOM United States Strategic Command
File details come from the government source that posted it. Updated .