Bidders Library Cybersecurity - DoDI 8500 01.pdf

PDF 536 KB Posted

Attached to
TEC II Services RFP Federal contract opportunity
Solicitation number
HC102821R0006
Issued by
Defense Information Systems Agency

About this file

This request for proposal from the Defense Information Systems Agency solicits test, evaluation, and certification services for the Joint Interoperability Test Command. The services required include testing and certification of information systems, platforms, and equipment to verify interoperability, integration, and functionality across all domains prior to deployment. Proposals are due by July 28, 2022 and the period of performance for the awarded contract is expected to be five years from date of award.

View the file

Other files for this federal contract opportunity

Other files attached to TEC II Services RFP, newest first.
File Type Posted
HC102821R0006 Conformed Through amendment 0008.pdf PDF
HC102821R0006 Conformed Through amendment 0007.pdf PDF
HC102821R0006 Conformed Through amendment 0006.pdf PDF
HC102821R0006 Conformed through amendment 0002.pdf PDF
HC102821R00060002.pdf PDF
Bidders Library DODI 5000 02.pdf PDF
Bidders Library Security - ISOO Handbook.pdf PDF
Bidders Library Security - DoDM 5200 01 Vol 1.pdf PDF
Bidders Library Security - DISAI 240-115-04.pdf PDF
Bidders Library Security - DISAI 240-110-35.pdf PDF
Bidders Library Operational Test and Evaluation - JITC OTE Guidebook v2 0.docx DOCX document
Bidders Library Operational Test and Evaluation - DoTE MEMO 10-19-2010.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 10-18-2010.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 6-16-2003.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 04-03-2018.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 1-21-2015.pdf PDF
Bidders Library JITC Instructions - JITCI 100-50-01.pdf PDF
Bidders Library JITC Instructions - JITCI 210-20-02.pdf PDF
Bidders Library JITC Instructions - JITCI 210-15-01.pdf PDF
Bidders Library JITC Instructions - JITCI 200-05-07.pdf PDF
Bidders Library Interoperability Test and Evaluation - JITC Notional Guide for Action Officers.pdf PDF
Bidders Library Interoperability Test and Evaluation - JITC Fact Sheet.pdf PDF
Bidders Library Interoperability Test and Evaluation - DODI 8551 01.pdf PDF
Bidders Library Interoperability Test and Evaluation - DoD 8570 01-M.pdf PDF
Bidders Library DoD Policy Instruction and Guidance - DoDI 4000 19.pdf PDF
Bidders Library DoD Policy Instruction and Guidance - DoDD 510035.pdf PDF
Bidders Library DoD Policy Instruction and Guidance - DoD Net Centric Service Strategy.pdf PDF
Bidders Library DISA - DISA Mandatory Contractor Training as of 20201110.xlsx XLSX spreadsheet
Bidders Library Cybersecurity - DoDI 8510 01.pdf PDF
Bidders Library Security - DISAI 240-110-8.pdf PDF
Bidders Library Cybersecurity - DOD Cybersecurity TE Guidebook.pdf PDF
TEC II Bidders Library List.xlsx XLSX spreadsheet
Bidders Library Security - ICD 705.pdf PDF
Bidders Library Security - ICD 700.pdf PDF
Bidders Library Security - FHU Visitor Access Policy.pdf PDF
Bidders Library Security - DoD 5220 22.pdf PDF
Bidders Library Security - DISAI 240-115-10.pdf PDF
Bidders Library Security - DISAI 240-110-40.pdf PDF
Bidders Library Security - DISAI 100-50-16.pdf PDF
Bidders Library Operational Test and Evaluation - OTA Memo 5-31-2019.pdf PDF
Bidders Library Operational Test and Evaluation - DOTE Memo 9-25-2019.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 5-5-2010.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 01-06-2010.pdf PDF
Bidders Library Operational Test and Evaluation - DISAI 640-195-1.pdf PDF
Bidders Library JITC Instructions - JITCI 650-70-01.pdf PDF
Bidders Library JITC Instructions - JITCI 240-110-04.pdf PDF
Bidders Library JITC Instructions - JITCI 240-110-08.pdf PDF
Bidders Library JITC Instructions - JITCI 240-110-05.pdf PDF
Bidders Library JITC Instructions - JITCI 100-55-01.pdf PDF
Bidders Library Interoperability Test and Evaluation - UCR 2013.pdf PDF
Show all 50

TEC II Services RFP has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Department of Defense

INSTRUCTION

NUMBER 8500.01

March 14, 2014

Incorporating Change 1, Effective October 7, 2019

DoD CIO

SUBJECT: Cybersecurity

References: See Enclosure 1

1. PURPOSE. This instruction:

a. Reissues and renames DoD Directive (DoDD) 8500.01E (Reference (a)) as a DoD Instruction (DoDI) pursuant to the authority in DoDD 5144.02 (Reference (b)) to establish a DoD cybersecurity program to protect and defend DoD information and information technology

(IT).

b. Incorporates and cancels DoDI 8500.02 (Reference (c)), DoDD C-5200.19 (Reference (d)), DoDI 8552.01 (Reference (e)), Assistant Secretary of Defense for Networks and Information Integration (ASD(NII))/DoD Chief Information Officer (DoD CIO) Memorandums (References (f) through (k)), and Directive-type Memorandum 08-060 (Reference (l)).

c. Establishes the positions of DoD principal authorizing official (PAO) and the DoD Senior Information Security Officer (SISO) and continues the DoD Information Security Risk Management Committee (DoD ISRMC).

d. Adopts the term “cybersecurity” as it is defined in National Security Presidential Directive-54/Homeland Security Presidential Directive-23 (Reference (m)) to be used throughout DoD instead of the term “information assurance (IA).”

2. APPLICABILITY

a. This instruction applies to:

(1) OSD, the Military Departments, the Office of the Chairman of the Joint Chiefs of Staff (CJCS) and the Joint Staff, the Combatant Commands, the Office of the Inspector General of the DoD, the Defense Agencies, the DoD Field Activities, and all other organizational entities within the DoD (referred to collectively in this instruction as the “DoD Components”).

DoDI 8500.01, March 14, 2014

Change 1, 10/07/2019 2

(2) All DoD IT.

(3) All DoD information in electronic format.

(4) Special access program (SAP) information technology, other than SAP ISs handling sensitive compartmented information (SCI) material.

b. Nothing in this instruction alters or supersedes the existing authorities and policies of the Director of National Intelligence (DNI) regarding the protection of SCI as directed by Executive Order 12333 (Reference (n)) and other laws and regulations.

3. POLICY. It is DoD policy that:

a. Risk Management

(1) DoD will implement a multi-tiered cybersecurity risk management process to protect U.S. interests, DoD operational capabilities, and DoD individuals, organizations, and assets from the DoD Information Enterprise level, through the DoD Component level, down to the IS level as described in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-39 (Reference (o)) and Committee on National Security Systems (CNSS) Policy (CNSSP) 22 (Reference (p)).

(2) Risks associated with vulnerabilities inherent in IT, global sourcing and distribution, and adversary threats to DoD use of cyberspace must be considered in DoD employment of capabilities to achieve objectives in military, intelligence, and business operations.

(3) All DoD IT will be assigned to, and governed by, a DoD Component cybersecurity program that manages risk commensurate with the importance of supported missions and the value of potentially affected information or assets.

(4) Risk management will be addressed as early as possible in the acquisition of IT and in an integrated manner across the IT life cycle.

(5) Documentation regarding the security posture of DoD IS and PIT systems will be made available to promote reciprocity as described in DoDI 8510.01 (Reference (q)) and to assist authorizing officials (AOs) from other organizations in making credible, risk-based decisions regarding the acceptance and use of systems and the information that they process, store, or transmit.

b. Operational Resilience. DoD IT will be planned, developed, tested, implemented, evaluated, and operated to ensure that:

(1) Information and services are available to authorized users whenever and wherever required according to mission needs, priorities, and changing roles and responsibilities.

Change 1, 10/07/2019 3

(2) Security posture, from individual device or software object to aggregated systems of systems, is sensed, correlated, and made visible to mission owners, network operators, and to the DoD Information Enterprise consistent with DoDD 8000.01 (Reference (r)).

(3) Whenever possible, technology components (e.g., hardware and software) have the ability to reconfigure, optimize, self-defend, and recover with little or no human intervention.

Attempts made to reconfigure, self-defend, and recover should produce an incident audit trail.

c. Integration and Interoperability

(1) Cybersecurity must be fully integrated into system life cycles and will be a visible element of organizational, joint, and DoD Component IT portfolios.

(2) Interoperability will be achieved through adherence to DoD architecture principles, adopting a standards-based approach, and by all DoD Components sharing the level of risk necessary to achieve mission success.

(3) All interconnections of DoD IT will be managed to minimize shared risk by ensuring that the security posture of one system is not undermined by vulnerabilities of interconnected systems.

d. Cyberspace Defense. Cyberspace defense actions are taken within cyberspace to defeat specific threats that have breached or are threatening to beach system cybersecurity measures.

Actions include detecting, characterizing, countering, mitigating threats, (e.g., malware, unauthorized activity, and vulnerabilities) and restoring systems to a secure configuration as described in Joint Publication 3-12 (Reference (s)).

e. Performance

(1) Implementation of cybersecurity will be overseen and governed through the integrated decision structures and processes described in this instruction.

(2) Performance will be measured, assessed for effectiveness, and managed relative to contributions to mission outcomes and strategic goals and objectives, in accordance with Sections 11103 and 11313 of Title 40, United States Code (U.S.C.) (Reference (t)).

(3) Data will be collected to support reporting and cybersecurity management activities across the system life cycle.

(4) Standardized IT tools, methods, and processes will be used to the greatest extent possible to eliminate duplicate costs and to focus resources on creating technologically mature and verified solutions.

f. DoD Information. All DoD information in electronic format will be given an appropriate level of confidentiality, integrity, and availability that reflects the importance of both information sharing and protection.

Change 1, 10/07/2019 4

g. Identity Assurance

(1) Identity assurance must be used to ensure strong identification, authentication, and eliminate anonymity in DoD IS and PIT systems.

(2) DoD will public key-enable DoD ISs and implement a DoD-wide Public Key Infrastructure (PKI) solution that will be managed by the DoD PKI Program Management Office in accordance with DoDI 8520.02 (Reference (u)).

(3) Biometrics used in support of identity assurance will be managed in accordance with

DoDD 8521.01 (Reference (v)).

h. Information Technology

(1) All IT that receives, processes, stores, displays, or transmits DoD information will be acquired, configured, operated, maintained, and disposed of consistent with applicable DoD cybersecurity policies, standards, and architectures.

(2) Risks associated with global sourcing and distribution, weaknesses or flaws inherent in the IT, and vulnerabilities introduced through faulty design, configuration, or use will be managed, mitigated, and monitored as appropriate.

(3) Cybersecurity requirements must be identified and included throughout the lifecycle of systems including acquisition, design, development, developmental testing, operational testing, integration, implementation, operation, upgrade, or replacement of all DoD IT supporting DoD tasks and missions.

i. Cybersecurity Workforce

(1) Cybersecurity workforce functions must be identified and managed, and personnel performing cybersecurity functions will be appropriately screened in accordance with this instruction and DoD Manual (DoDM) 5200.2 (Reference (w)), and qualified in accordance with DoDD 8140.01 (Reference (x)) and supporting issuances.

(2) Qualified cybersecurity personnel must be identified and integrated into all phases of the system development life cycle.

j. Mission Partners

(1) Capabilities built to support cybersecurity objectives that are shared with mission partners will be consistent with guidance contained in Reference (r) and governed through integrated decision structures and processes described in this instruction.

(2) DoD-originated and DoD-provided information residing on mission partner ISs must be properly and adequately safeguarded, with documented agreements indicating required levels of protection.

Change 1, 10/07/2019 5

4. RESPONSIBILITIES. See Enclosure 2.

5. PROCEDURES. See Enclosure 3.

6. RELEASABILITY. Cleared for public release. This instruction is available on the Directives Division Website at https://www.esd.whs.mil/DD/.

7. SUMMARY OF CHANGE 1. The changes to this issuance are administrative and:

a. Update organizational titles, references, and internet addresses.

b. Update the description of cyberspace defense in accordance with Reference (s).

c. Require cybersecurity scorecard reporting be accomplished in accordance with the March 22, 2019 DoD CIO Memorandum (Reference (y)).

d. Require systems processing controlled unclassified information (CUI) be categorized at no less than the moderate confidentiality impact level in accordance with Part 2002 of Title 32, Code of Federal Regulations (Reference (z)).

e. Change the Defense Security Service to the Defense Counterintelligence and Security Agency (DCSA) and the United States Strategic Command (USSTRATCOM) to the United States Cyber Command (USCYBERCOM) in accordance with the August 15, 2017 Presidential Memorandum.

8. EFFECTIVE DATE. This instruction is effective March 14, 2014.

Teresa M. Takai DoD Chief Information Officer

Enclosures

1. References

2. Responsibilities

3. Procedures

Glossary

DoDI 8500.02, March 14, 2014

Change 1, 10/07/2019 6 CONTENTS

TABLE OF CONTENTS

ENCLOSURE 1: REFERENCES

ENCLOSURE 2: RESPONSIBILITIES

DoD CIO

DIRECTOR, DISA

USD(AT&L)

DEPUTY ASSISTANT SECRETARY OF DEFENSE FOR DT&E (DASD(DT&E))

DOT&E

USD(P)

USD(P&R)

USD(I)

DIRNSA/CHCSS

DIRECTOR, DCSA

DIRECTOR, DIA

CHIEF MANAGEMENT OFFICER OF THE DEPARTMENT OF DEFENSE

OSD AND DoD COMPONENT HEADS

CJCS

COMMANDER, USCYBERCOM

ENCLOSURE 3: PROCEDURES

INTRODUCTION

RISK MANAGEMENT

OPERATIONAL RESILIENCE

INTEGRATION AND INTEROPERABILITY

CYBERSPACE DEFENSE

PERFORMANCE

DoD INFORMATION

IDENTITY ASSURANCE

INFORMATION TECHNOLOGY

CYBERSECURITY WORKFORCE

MISSION PARTNERS

DoD SISO DoD COMPONENT CIOs DoD RISK EXECUTIVE FUNCTION

PAO

AO

ISOs OF DoD IT

ISSM

ISSO

PRIVILEGED USERS (E.G. SYSTEM ADMINISTRATOR)

AUTHORIZED USERS

Change 1, 10/07/2019 7 CONTENTS

GLOSSARY

PART I. ABBREVIATIONS AND ACRONYMS

PART II. DEFINITIONS

FIGURE

1. Three-Tiered Approach to Risk Management

2. DoD Information Technology

Change 1, 10/07/2019 8 ENCLOSURE 1

ENCLOSURE 1

REFERENCES

(a) DoD Directive 8500.01, “Information Assurance (IA),” October 4, 2002 (hereby cancelled)

(b) DoD Directive 5144.02, “DoD Chief Information Officer (DoD CIO),” November 21, 2014, as amended

(c) DoD Instruction 8500.2, “Information Assurance (IA) Implementation,” February 6, 2003

(hereby cancelled)

(d) DoD Directive C-5200.19, “Control of Compromising Emanations (U),” May 16, 1995

(hereby cancelled)

(e) DoD Instruction 8552.01, “Use of Mobile Code Technologies in DoD Information

Systems,” October 23, 2006 (hereby cancelled)

(f) Assistant Secretary of Defense for Networks and Information Integration/DoD Chief

Information Officer Memorandum, “Disposition of Unclassified DoD Computer Hard Drives,” June 4, 2001 (hereby cancelled)

(g) Assistant Secretary of Defense for Networks and Information Integration/DoD Chief Information Officer Memorandum, “Certification and Accreditation Requirements for DoD-wide Managed Enterprise Services Procurements,” June 22, 2006 (hereby cancelled)

(h) Assistant Secretary of Defense for Networks and Information Integration/DoD Chief Information Officer Memorandum, “Use of Peer-to-Peer (P2P) File-Sharing Applications Across DoD,” November 23, 2004 (hereby cancelled)

(i) Assistant Secretary of Defense for Networks and Information Integration/DoD Chief Information Officer Memorandum, “Department of Defense (DoD) Guidance on Protecting Personally Identifiable Information (PII),” August 18, 2006 (hereby cancelled)

(j) Assistant Secretary of Defense for Networks and Information Integration/DoD Chief Information Officer Memorandum, “Encryption of Sensitive Unclassified Data At Rest on Mobile Computing Devices and Removable Storage Media,” July 3, 2007 (hereby cancelled)

(k) Assistant Secretary of Defense for Networks and Information Integration/DoD Chief Information Officer Memorandum, “Protection of Sensitive Department of Defense (DoD) Data at Rest On Portable Computing Devices,” April 18, 2006 (hereby cancelled)

(l) Directive-type Memorandum 08-060, “Policy on Use of Department of Defense (DoD) Information Systems — Standard Consent Banner and User Agreement,” May 9, 2008, as amended (hereby cancelled)

(m) National Security Presidential Directive-54/Homeland Security Presidential Directive-23, “Cybersecurity Policy,” January 8, 20081

(n) Executive Order 12333, “United States Intelligence Activities,” as amended

(o) National Institute of Standards and Technology Special Publication 800-39, “Managing

Information Security Risk: Organization, Mission, and Information System View,” current edition

1 Document is classified TOP SECRET. To obtain a copy, fax a request to the Homeland Security Council Executive Secretary at 202-456-5158 and the National Security Council’s Senior Director for Records and Access Management at 202-456-9200.

Change 1, 10/07/2019 9 ENCLOSURE 1

(p) Committee on National Security Systems Policy 22, “Cybersecurity Risk Management Policy,” August, 2016

(q) DoD Instruction 8510.01, “Risk Management Framework (RMF) for DoD Information Technology (IT),” March 12, 2014, as amended

(r) DoD Directive 8000.01, “Management of the Department of Defense Information Enterprise,” March 17, 2016, as amended

(s) Joint Publication 3-12, “Cyberspace Operations,” June 8, 2018

(t) Title 40, United States Code

(u) DoD Instruction 8520.02, “Public Key Infrastructure (PKI) and Public Key (PK)

Enabling,” May 24, 2011

(v) DoD Directive 8521.01E, “DoD Biometrics,” January 13, 2016, as amended

(w) DoD Manual 5200.02, “Procedures for the Personnel Security Program (PSP),” April 3,

(x) DoD Directive 8140.01, “Cyberspace Workforce Management,” August 11,2015, as ammended

(y) DoD Chief Information Officer Memorandum, “DoD Cyber Hygiene Scorecard –

Supplemental Guidance,” March 22, 20192

(z) Title 32, Part 2002, Code of Federal Regulations

(aa) Title 44, United States Code

(ab) DoD Directive 5230.11, “Disclosure of Classified Military Information to Foreign

Governments and International Organizations,” June 16, 1992

(ac) DoD Directive 8115.01, “Information Technology Portfolio Management,” October 10,

(ad) DoD Instruction 5205.13, “Defense Industrial Base (DIB) Cybersecurity (CS) Activities,”

January 29, 2010, as amended

(ae) DoD Directive 3020.40, “Mission Assurance (MA),” November 29, 2016, as amended

(af) Deputy Secretary of Defense Memorandum, “Delegation of Authority to Negotiate and

Conclude International Agreements on Cooperation in Information Assurance and Computer Network Defense,” March 5, 20023

(ag) DoD Directive 5530.3, “International Agreements,” June 11, 1987, as amended

(ah) DoD Instruction 8540.01, “Cross Domain (CS) Policy), May 8, 2015, as amended

(ai) National Security Directive 42, “National Policy for the Security of National Security

Telecommunications and Information Systems,” July 5, 1990

(aj) Office of Management and Budget Circular A-130, “Management of Federal Information

Resources,” as amended

(ak) DoD Instruction 8010.01, “Department of Defense Information Network (DODIN)

Transport,” September 10, 2018

(al) DoD Instruction 8551.01, “Ports, Protocols, and Services Management (PPSM),” May 28, 2014, as amended

(am) DoD Instruction 8100.04, “DoD Unified Capabilities (UC),” December 9, 2010

(an) Defense Security/Cybersecurity Authorization Working Group (DSAWG) Charter, April 8, 20164

2 https://dodcio.defense.gov/Library/ 3 Requests for copies can be forwarded to the DoD CIO.

4 https://dodcio.defense.gov/Library/

Change 1, 10/07/2019 10 ENCLOSURE 1

(ao) Department of Defense Information Security Risk Management Charter, May, 2016, as amended5

(ap) DoD Directive 5134.01, “Under Secretary of Defense for Acquisition, Technology, and Logistics (USD(AT&L)),” December 9, 2005, as amended

(aq) DoD Instruction 3200.12, “DoD Scientific and Technical Information Program (STIP),” August 22, 2013, as amended

(ar) DoD Instruction 8580.1, “Information Assurance (IA) in the Defense Acquisition System,” July 9, 2004

(as) DoD Directive 5000.01, “The Defense Acquisition System,” May 12, 2003, as amended

(at) DoD Instruction 5000.02, “Operation of the Defense Acquisition System,” January 7, 2015, as amended

(au) DoD Instruction 8330.01, “Interoperability of Information Technology (IT), Including

National Security Systems (NSS),” May 21, 2014, as amended

(av) Section 1043 of Public Law 106-65, “Information Assurance Initiative,” October 5, 1999

(aw) DoD Instruction 5200.39, “Critical Program Information (CPI) Identification and Protection within Research, Development, Test, and Evaluation (RDT&E),” May 28, 2015, as amended

(ax) DoD Instruction 5134.16, “Deputy Assistant Secretary of Defense for Systems Engineering (DASD(SE)),” August 19, 2011, as amended

(ay) DoD Manual 8570.01, “Information Assurance Workforce Improvement Program,” December 19, 2005, as amended

(az) DoD Instruction 5134.17, “Deputy Assistant Secretary of Defense for Developmental Test and Evaluation (DASD(DT&E)),” October 25, 2011, as amended

(ba) Director, Operational Test and Evaluation Memorandum, “Procedures for Operational Test and Evaluation of Cybersecurity in Acquisition Programs,” April 3, 20186

(bb) DoD Directive 5100.20, “National Security Agency/Central Security Service (NSA/CSS),” January 26, 2010

(bc) Committee on National Security Systems Policy 11, “National Policy Governing the Acquisition of Information Assurance (IA) and IA-Enabled Information Technology Products,” June 10, 2013, as amended

(bd) Title 10, United States Code

(be) Committee on National Security Systems Policy 15, “Use of Public Standards for

Information Sharing,” October 20, 2016

(bf) DoD 5220.22-M, “National Industrial Security Program Operating Manual,” February 28, 2006, as amended

(bg) DoD Instruction 8530.01, “Cybersecurity Activities Support to DoD Information Network

Operations,” March 7, 2016

(bh) DoD Instruction 5200.44, “Protection of Mission Critical Functions to Achieve Trusted

Systems and Networks (TSN),” November 5, 2012, as amended

(bi) DoD Instruction 8560.01, “Communications Security (COMSEC) Monitoring,” August 22, 5 Requests for copies can be forwarded to the DoD CIO.

6 Available at https://www.dote.osd.mil/pub/policies/2018/20180403ProcsForOTEofCybersecurityInAcqProgs(17092).pdf.

Change 1, 10/07/2019 11 ENCLOSURE 1

(bj) DoD Manual 5200.01, Volume 3, “DoD Information Security Program: Protection of Classified Information,” February 24, 2012, as amended

(bk) DoD Manual 5200.01, Volume 4, “DoD Information Security Program: Controlled Unclassified Information (CUI),” February 24, 2012, as amended

(bl) DoD 5400.11-R, “Department of Defense Privacy Program,” May 14, 2007

(bm) Committee on National Security Systems Instruction 1010, “Cyber Incident Response,”

December 16, 2016

(bn) DoD Manual 5200.01, Volume 1, “DoD Information Security Program: Overview, Classification, and Declassification,” February 24, 2012, as amended

(bo) DoD Instruction 1400.25, Volume 731, “DoD Civilian Personnel Management System:

Suitability and Fitness Adjudication For Civilian Employees,” August 24, 2012

(bp) Title 29, United States Code

(bq) National Institute of Standards and Technology Special Publication 800-34, Revision 1, “Contingency Planning Guide for Federal Information Systems,” current edition

(br) DoD 5200.08-R, “Physical Security Program,” April 9, 2007, as amended

(bs) DoD Manual 5200.01, Volume 2, “DoD Information Security Program: Marking of

Classified Information,” February 24, 2012, as amended

(bt) DoD 5220.22-R, “Industrial Security Regulation,” April 12, 1985

(bu) Committee on National Security Systems Policy 300, “National Policy on Control of

Compromising Emanations,” January 11, 2006, as amended

(bv) Committee on National Security Systems Instruction 7000, “TEMPEST Countermeasures for Facilities,” May 2004, as amended

(bw) DoD Instruction 5015.02, “DoD Records Management Program,” August 17, 2017

(bx) Unified Command Plan, current edition

(by) National Institute of Standards and Technology Special Publication 800-30, “Guide for

Conducting Risk Assessments,” current edition

(bz) DoD Directive 5105.53, “Director of Administration and Management (DA&M),”

February 26, 2008

(ca) National Institute of Standards and Technology Special Publication 800-37, “Guide for

Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach,” current edition

(cb) Committee on National Security Systems Instruction 1253, “Security Categorization and Control Selection for National Security Systems,” March 27, 2014

(cc) National Institute of Standards and Technology Special Publication 800-53, “Security and Privacy Controls for Federal Information Systems and Organizations,” current edition

(cd) National Institute of Standards and Technology Special Publication 800-53A, “Guide for Assessing the Security and Privacy Controls in Federal Information Systems and Organizations,” current edition

(ce) Section 806 of the Ike Skelton National Defense Authorization Act for Fiscal Year 2011, January 7, 2011

(cf) DoD Directive 3020.26, “DoD Continuity Programs,” February 14, 2018

(cg) Secretary of Defense Memorandum, “Maintaining Readiness to Operate in Cyberspace

Domain,” December 7, 2012

(ch) DoD Instruction 8523.01, “Communications Security (COMSEC),” April 22, 2008

Change 1, 10/07/2019 12 ENCLOSURE 1

(ci) National Institute of Standards and Technology Special Publication 800-126, “The Technical Specification for Security Content Automation Protocol (SCAP): SCAP Version 1.1,” current edition

(cj) National Institute of Standards and Technology Special Publication 800-137, “Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations,” current edition

(ck) DoD Instruction 8520.03, “Identity Authentication for Information Systems,” May 13, 2011, as amended

(cl) DoD Directive 5505.13E, “DoD Executive Agent (EA) for the DoD Cyber Crime Center (DC3),” March 1, 2010, as amended

(cm) DoD Instruction 5240.26, “Countering Espionage, International Terrorism, and the Counterintelligence (CI) Insider Threat,” May 4, 2012, as amended

(cn) Chairman of the Joint Chiefs of Staff Instruction 5123.01H, “Charter of the Joint Requirements Oversight Council (JROC) and Implementation of the Joint Capabilities Integration and Development System (JCIDS),” August 31, 2018

(co) DoD Directive 7045.14, “The Planning, Programming, Budgeting, and Execution (PPBE) Process,” January 25, 2013, as amended

(cp) DoD Chief Information Officer Memorandum, “Department of Defense Chief Information Officer Executive Board Charter,” February, 12, 2012

(cq) DoD Instruction 5200.01, “DoD Information Security Program and Protection of Sensitive Compartmented Information,” April 21, 2016, as amended

(cr) DoD Instruction 8320.02, “Sharing Data Information, and Technology (IT) Services in the Department of Defense,” August 5, 2013

(cs) DoD Instruction 8320.07, “Implementing Sharing of Data, Information, and Information Technology (IT) Services in the Department of Defense,” August 3, 2015, as amended

(ct) DoD Instruction 5230.09, “Clearance of DoD Information for Public Release,” January 25,

(cu) DoD Instruction 8582.01, “Security of Unclassified DoD Information on Non-DoD Information Systems,” June 6, 2012, as amended

(cv) DoD Instruction 5400.16, “DoD Privacy Impact Assessment (PIA) Guidance,” July 14, 2015, as amended

(cw) DoD 8580.02 Instruction, “Security of Individually Identifiable Health Information in DoD Health Care Programs,” August 12, 2015

(cx) DoD Manual 5205.02, “DoD Operations Security (OPSEC) Program Manual,” November 3, 2008, as amended

(cy) DoD Instruction 8170.01, “Online Information Management and Electronic Messaging,” January 2, 2019

(cz) Under Secretary of Defense for Acquisition, Technology, and Logistics Memorandum, “Document Streamlining Program Protection Plan,” July 18, 2011

(da) Section 811 of Public Law 106-398, “National Defense Authorization Fiscal Year 2001,” October 30, 2000

(db) Committee on National Security Systems Policy No. 12, “Cybersecurity Policy for Space Systems Used to Support National Security Missions,” February 6, 2018

(dc) Committee on National Security Systems Instruction 4004.1, “Destruction and Emergency Protection Procedures for COMSEC and Classified Material,” January 10, 2008

Change 1, 10/07/2019 13 ENCLOSURE 1

(dd) National Institute of Standards and Technology Special Publication 800-88, “Guidelines for Media Sanitization,” current edition

(de) DoD Architecture Framework Version 2.02, August 20107

(df) DoD Instruction 5000.64, “Accountability and Management of DoD Equipment and Other

Accountable Property,” April 27, 2017, as ammended

(dg) DoD Instruction 2030.08, “Implementation of Trade Security Controls (TSC) for Transfers of DoD U.S. Munitions List (USML) and Commerce Control List (CCL) Personal Property to Parties Outside DoD Control,” February 19, 2015, as ammended

(dh) DoD Instruction 1035.01, “Telework Policy,” April 4, 2012

(di) National Institute of Standards and Technology Special Publication 800-114, “Users Guide to Telework and Bring Your Own Device (BYOD) Security,” current edition

(dj) National Institute of Standards and Technology Special Publication 800-147, “BIOS

Protection Guidelines for Servers,” current edition

(dk) Assistant Secretary of Defense for Networks and Information Integration/DoD Chief

Information Officer, “Coalition Public Key Infrastructure, X.509 Certificate Policy,” current edition

(dl) DoD Directive 5230.20, “Visits and Assignments of Foreign Nationals,” June 22, 2005

(dm) DoD Instruction 5230.27, “Presentation of DoD-Related Scientific and Technical Papers at

Meetings,” November 18, 2016, as amended

(dn) DoD Instruction 2040.02, “International Transfers of Technology, Articles, and Services,”

March 27, 2014, as amended

(do) DoD Instruction 1100.22, “Policy and Procedures for Determining Workforce Mix,”

April 12, 2010, as amended

(dp) DoD Directive 5205.02E, “DoD Operations Security (OPSEC) Program,” June 20, 2012, as amended

(dq) Committee on National Security Systems Instruction Number 4009, “Committee on

National Security Systems (CNSS) Glossary,” April 6, 2015

(dr) Office of the Chairman of the Joint Chiefs of Staff, “DoD Dictionary of Military and

Associated Terms,” current edition

(ds) Presidential Memorandum, “Elevation of U.S. Cyber Command to a Unified Combatant

Command,” August 15, 2017

7 Available at https://dodcio.defense.gov/Library/DoD-Architecture-Framework/

Change 1, 10/07/2019 14 ENCLOSURE 2

ENCLOSURE 2

RESPONSIBILITIES

1. DoD CIO. The DoD CIO:

a. Monitors, evaluates, and provides adv ice to the Secretary of Defense regarding all DoD cybersecurity activities and oversees implementation of this instruction.

b. Develops and establishes DoD cybersecurity policy and guidance consistent with this instruction and in accordance with applicable federal law and regulations.

c. Appoints a DoD SISO in accordance with section 3554 of Title 44, U.S.C. (Reference (aa)).

d. Coordinates with the Under Secretary of Defense for Policy (USD(P)) to ensure that cybersecurity strategies and policies are aligned with overarching DoD cyberspace policy and, in accordance with DoDD 5230.11 (Reference (ab)), support policies relating to the disclosure of classified military information to foreign governments and international organizations.

e. Coordinates with the Under Secretary of Defense for Personnel and Readiness (USD(P&R)) to:

(1) Ensure personnel identity policies and cybersecurity policies and capabilities are aligned and mutually supportive.

(2) Develop cybersecurity workforce management policies and capabilities to support identification and qualifications for a professional cybersecurity workforce.

f. Coordinates with the Under Secretary of Defense for Intelligence (USD(I)) to ensure that cybersecurity policies and capabilities are aligned with and mutually supportive of personnel, physical, industrial, information, and operations security policies and capabilities.

g. Coordinates with NIST in development of cybersecurity-related standards and guidelines.

h. Maintains a formal coordination process with the Intelligence Community (IC) Chief Information Officer (CIO) to ensure proper protection of IC information within DoD, reciprocity of IS authorization and cybersecurity risk management processes, and alignment of cybersecurity.

i. Coordinates with the Under Secretary of Defense for Acquisition, Technology, and Logistics (USD(AT&L)) to ensure that cybersecurity responsibilities are integrated into processes for DoD acquisition programs, including research and development.

Change 1, 10/07/2019 15 ENCLOSURE 2

j. Coordinates with the Director, Operational Test and Evaluation (DOT&E) to ensure that cybersecurity responsibilities are integrated into the operational testing and evaluation for DoD acquisition programs.

k. Coordinates and advocates resources for DoD-wide cybersecurity solutions, including overseeing appropriations allocated to the DoD cybersecurity program.

l. Appoints a PAO for DoD ISs and PIT systems governed by the Enterprise Information Environment Mission Area (EIEMA) as described in DoDD 8115.01 (Reference (ac)).

m. Coordinates with the DoD mission area owners to ensure that cybersecurity responsibilities are addressed for all DoD IT.

n. Coordinates with the USD(P) and USD(I) on integrating Defense Industrial Base (DIB) cybersecurity threat information-sharing activities and enhancing DoD and DIB cyber situational awareness in accordance with DoDI 5205.13 (Reference (ad)) and in support of DoDD 3020.40 (Reference (ae)).

o. Develops policy for negotiating, performing, and concluding agreements with international partners to engage in cooperative international cybersecurity activities, in coordination with the USD(P), USD(I), and the Director, National Security Agency (NSA)/Chief, Central Security Service (DIRNSA/CHCSS).

p. Negotiates and concludes agreements with international partners to engage in cooperative international cybersecurity and cyberspace defense activities, according to authority described in Deputy Secretary of Defense Memorandum (Reference (af)) and subject to the provisions of DoDD 5530.3 (Reference (ag)), in coordination with the:

(1) USD(P).

(2) General Counsel of the Department of Defense.

(3) Under Secretary of Defense (Comptroller)/Chief Financial Officer, Department of

Defense.

(4) USD(I), when such agreements materially affect cleared industry.

(5) CJCS.

q. Establishes policy for the life cycle management of cross-domain (CD) solutions (CDSs) in accordance with DoDI 8540.01 (Reference (ah).

r. Develops and implements policy regarding continuous monitoring of DoD IT with direct support from NSA/CSS and Defense Information Systems Agency (DISA), and input from the other DoD Components.

Change 1, 10/07/2019 16 ENCLOSURE 2

s. Appoints a military officer in the grade of O-6 or an equivalent civilian employee as the Defense Security/Cybersecurity Authorization Working Group (DSAWG) Chair.

t. Develops and implements policy for cybersecurity workforce awareness, education, training, and qualification in coordination with the USD(P&R).

u. Maintains a Defense-wide view of cybersecurity resources that supports national, organizational, joint, and DoD Component cybersecurity program planning.

v. Conducts an annual assessment of DoD Component cybersecurity programs as required by section 3555 of Reference (aa).

w. Co-chairs the Enterprise-wide Cybersecurity Solutions Steering Group (ESSG).

x. Ensures that compromising emanations (i.e., TEMPEST) countermeasures implemented within DoD comply with current national policies.

y. Ensures compliance with the requirements of National Security Directive 42 (Reference

(ai)) and collaborate with the DIRNSA/CHCSS on the performance of DIRNSA/CHCSS duties, pursuant to Reference (ai), as the National Manager for National Security Telecommunications and Information Systems Security.

2. DIRECTOR, DISA. Under the authority, direction, and control of the DoD CIO and in addition to the responsibilities in section 13 of this enclosure, the Director, DISA:

a. Develops, implements, and, in coordination with Commander, USCYBERCOM, manages cybersecurity for the DISN, consistent with this instruction and its supporting guidance.

b. Develops and maintains control correlation identifiers (CCIs), security requirements guides (SRGs), security technical implementation guides (STIGs), and mobile code risk categories and usage guides that implement and are consistent with DoD cybersecurity policies, standards, architectures, security controls, and validation procedures, with the support of the NSA/CSS, using input from stakeholders, and using automation whenever possible.

c. Develops or acquires solutions that support cybersecurity objectives for use throughout DoD via the ESSG.

d. Establishes and maintains the DoD Cyber Exchange in accordance with Office of Management and Budget Circular A-130 (Reference (aj)) as the DoD knowledge repository for cybersecurity related policy, guidance, and information.

e. Oversees and maintains the connection approval process in accordance with DoDI

8010.01 (Reference (ak)), CD connection policy in accordance with Reference (ah), DoDI

8551.01 (Reference (al)), and DoDI 8100.04 (Reference (am)) for the DISN (e.g., the Secret Internet Protocol Router Network (SIPRNet) and the Non-Classified Internet Protocol Router

Change 1, 10/07/2019 17 ENCLOSURE 2

Network (NIPRNet)) in coordination with the DSAWG (Reference (an)) and DoD ISRMC (Reference (ao)), when appropriate.

f. Facilitates multinational information sharing efforts, as well as information sharing between the DoD Components and eligible foreign nations in support of approved international cybersecurity and cyberspace defense agreements.

g. Supports training, exercises, workforce development, network evaluation, and other efforts to build international partner cybersecurity and cyberspace defense capacity.

h. Provides enterprise CD services compliant with Reference (ah).

i. Ensures the continued development and maintenance of guidance and standards procedures to catalog, regulate, and control the use and management of Internet protocols, data services, and associated ports on DoD networks, in accordance with Reference (al).

j. Develops and provides cybersecurity training and awareness products and a distributive training capability to support the DoD Components in accordance with Reference (x) and post the training materials on the DoD Cyber Exchange Website (https://public.cyber.mil/).

k. Conducts command cyber readiness inspections and operational risk assessments in support of USCYBERCOM.

l. Coordinates with the USD(I) to ensure command cyber readiness inspection guidance and metrics provide a unity of effort among the security disciplines (i.e., personnel, physical, industrial, information, operations, and cybersecurity).

3. USD(AT&L). The USD(AT&L):

a. Integrates policies established in this instruction and its supporting guidance into acquisition policy, regulations, and guidance consistent with DoDD 5134.01 (Reference (ap)).

b. Through the Assistant Secretary of Defense for Research and Engineering, monitors and oversees all DoD cybersecurity research and engineering investments, including research at the

NSA.

c. Integrates cybersecurity assessments into developmental testing and evaluation.

d. Establishes and maintains the Cybersecurity and Information Assurance Center in accordance with DoDI 3200.12 (Reference (aq)).

e. Ensures that the DoD acquisition process incorporates cybersecurity planning, implementation, testing, and evaluation consistent with Reference (q), DoDI 8580.01 (Reference (ar)), DoDD 5000.01 (Reference (as)), DoDI 5000.02 (Reference (at)), DoDI 8330.01 (Reference

Change 1, 10/07/2019 18 ENCLOSURE 2

(au)), section 1043 of Public Law 106-65 (Reference (av)), and this instruction, in coordination with the DoD CIO.

f. Assists with acquisition-related (e.g., research, development, test and evaluation (T&E)) agreements, and international cybersecurity and cyberspace defense negotiations and agreements, in accordance with Reference (ag), as needed.

g. Ensures that PIT systems included in acquisition programs are designated, categorized, and have their authorization boundaries defined according to the guidelines provided in Reference (q).

h. Ensures that policy and procedures for developing program protection plans (PPPs) required by DoDI 5200.39 (Reference (aw)) address cybersecurity in accordance with this instruction.

i. Defines, develops, and integrates systems security engineering (SSE) into the systems engineering workforce and curriculum in accordance with DoDI 5134.16 (Reference (ax)).

j. Ensures that acquisition community personnel with IT development responsibilities are qualified in accordance with Reference (x) and DoD 8570.01-M (Reference (ay)).

k. Coordinates with the DoD Test Resource Management Center for establishment of developmental T&E (DT&E) specific cybersecurity architectures and requirements.

4. DEPUTY ASSISTANT SECRETARY OF DEFENSE FOR DT&E (DASD(DT&E)). Under the authority, direction, and control of the USD(AT&L), the DASD(DT&E):

a. Exercises oversight responsibility for developmental test planning in support of interoperability and cybersecurity for programs acquiring DoD IS and PIT systems in accordance with DoDI 5134.17 (Reference (az)).

b. Establishes procedures to ensure that cognizant DT&E authorities for acquisition programs verify that adequate DT&E to support cybersecurity is planned, resourced, documented, and can be executed in a timely manner prior to approval of program documents.

5. DOT&E. The DOT&E:

a. Develops and provides policy for cybersecurity testing and evaluation during operational evaluations within DoD, including, but not limited to the DOT&E Memorandum (Reference (ba)) describing the cybersecurity testing process.

b. Conducts independent cybersecurity assessments during operational test and evaluation (OT&E) for systems under acquisition and reports the findings as part of the acquisition process.

Change 1, 10/07/2019 19 ENCLOSURE 2

c. Oversees cybersecurity assessments by test agencies during both acquisition and exercise events as mandated by relevant statutory requirements.

d. Reviews and approves cybersecurity OT&E documentation for all IT, IS, PIT, and special interest programs as required.

6. USD(P). The USD(P):

a. Coordinates with the DoD CIO to ensure that cybersecurity strategies, policies, and capabilities are aligned with overarching DoD cyberspace policy, and are supportive of policies and capabilities relating to the disclosure of classified military information to foreign governments and international organizations in accordance with Reference (ab).

b. Coordinates with the DoD CIO on international cybersecurity and cyberspace defense strategies and policies, as well as the negotiating, performing, and concluding agreements with international partners to engage in cooperative, international cybersecurity and cyberspace defense activities in accordance with Reference (af).

c. Coordinates with the DoD CIO on enhancing DoD and DIB cyber situational awareness in accordance with Reference (ad) and in support of Reference (ae).

7. USD(P&R). The USD(P&R) supports implementation of cybersecurity requirements for effective manning, management, and readiness assessment of the cybersecurity workforce in accordance with References (x) and (ax).

8. USD(I). The USD(I):

a. Coordinates with the DoD CIO on development and implementation of cybersecurity policy, guidance, procedures, and controls related to personnel, physical, industrial, information and operations security.

b. Coordinates with the DoD CIO and the USD(P) on intelligence-related international cybersecurity and cyberspace defense strategies, policies, and agreements with international partners.

c. Appoints the PAO for DoD ISs and PIT systems governed by the DoD portion of the Intelligence Mission Area (DIMA) as described in Reference (ac).

9. DIRNSA/CHCSS. Under the authority, direction, and control of the USD(I), and in addition to the cybersecurity-related responsibilities in DoDD 5100.20 (Reference (bb)) and the responsibilities in section 13 of this enclosure, the DIRNSA/CHCSS:

Change 1, 10/07/2019 20 ENCLOSURE 2

a. Supports the DoD CIO by providing cybersecurity architecture and mechanisms to support Defense military, intelligence, and business functions, including but not limited to cryptography, PKI, and IS security engineering services.

b. Evaluates or validates security implementation specifications described in this instruction.

c. Provides cybersecurity support to the DoD Components in order to assess threats to, and vulnerabilities of, information technologies.

d. Engages the cybersecurity industry and DoD user community to foster development, evaluation, and deployment of cybersecurity solutions that satisfy the guidance in this instruction.

e. Provides SSE services to the DoD Components, including describing information protection needs, properly selecting and implementing appropriate security controls, and assessing the effectiveness of system security.

f. Supports the development of NIST publications and provides engineering support and other technical assistance for their implementation within DoD.

g. Develops SSE training and qualification programs and oversees continuing education requirements for all trained IS security engineers and cybersecurity architects throughout DoD in accordance with Reference (ax).

h. Serves as the DoD focal point for the National IA Partnership and establishes criteria and processes for evaluating and validating all IA and IA-enabled products in accordance with CNSSP 11 (Reference (bc)).

i. Develops and issues security implementation specifications for the configuration of IA-and IA-enabled products (e.g., security configuration guides) and supports DISA in the development of SRGs and STIGs.

j. Serves as the DoD focal point for cybersecurity cryptographic research and development in accordance with Assistant Secretary of Defense for Research and Engineering direction and in coordination with the Director, Defense Advanced Research Projects Agency.

k. Manages the DoD Cyber Scholarship Program in accordance with sections 2200-2200f of

Title 10, U.S.C. (Reference (bd)).

l. Plans, designs, manages, and executes the development and implementation of the key management infrastructure within DoD in coordination with DoD CIO.

m. Plans, designs, and manages the development and implementation of PKI within DoD, in coordination with DoD CIO and DISA.

RE 2

n. Approves all applications of cryptographic algorithms for the protection of classified information.

o. Approves all cryptography used to protect classified information in accordance with

CNSSP 15 (Reference (be)).

p. Develops, implements, and manages a cybersecurity program for layered protection of

DoD cryptographic SCI systems and a cybersecurity education, training, and awareness program for users and administrators of DoD cryptographic SCI systems in accordance with applicable DoD and DNI policies and guidance.

q. Conducts risk assessments of mobile code technologies, recommends the assignment of mobile code technologies to specific risk categories, and provides technical advice and assistance in the development of countermeasures to identified risks associated with specific mobile code technology implementations.

10. DIRECTOR, DCSA. Under the authority, direction, and control of the USD(I) and in addition to the responsibilities in section 13 of this enclosure, the Director, DCSA, monitors and oversees IS security practices of DoD contractors and vendors processing classified DoD information in accordance with DoD 5220.22M (Reference (bf)) and DoDI 8530.01 (Reference (bg)).

11. DIRECTOR, DEFENSE INTELLIGENCE AGENCY (DIA). Under the authority, direction, and control of the USD(I) and in addition to the responsibilities in section 13 of this enclosure, the Director, DIA:

a. Provides finished intelligence, including threat assessments, in support of cybersecurity activities.

b. Develops, implements, and manages a cybersecurity program for DoD non-cryptographic SCI systems, including the DoD Intelligence IS and Joint Worldwide Intelligence Communications System.

12. CHIEF MANAGEMENT OFFICER OF THE DEPARTMENT OF DEFENSE. The Chief Management Officer of the Department of Defense appoints the PAO for DoD ISs and PIT systems governed by the Business Mission Area (BMA), as described in Section 2222 of Reference (aa).

13. DoD COMPONENT HEADS. The DoD Component heads:

a. Ensure that IT under their purview complies with this instruction.

Change 1, 10/07/2019 21 ENCLOSU

Change 1, 10/07/2019 22 ENCLOSURE 2

b. Ensure that cybersecurity requirements are addressed and visible in all capability portfolios, IT life-cycle management processes, and investment programs incorporating IT.

c. Appoint an AO for all DoD IS and PIT systems under their purview and ensure all DoD ISs and PIT systems are authorized in accordance with Reference (q).

d. Ensure that PIT systems are identified, designated as such, and centrally registered at the DoD Component level.

e. Ensure that SSE and trusted systems and networks (TSN) processes, tools, and techniques described in DoDI 5200.44 (Reference (bh)) are used in the acquisition of all applicable IT under their purview.

f. Ensure that organizational solutions that support cybersecurity objectives acquired and developed via the ESSG process are implemented when possible, and participate in the ESSG process to ensure capabilities acquired or developed meet organizational requirements.

g. Provide for a cybersecurity monitoring and testing capability in accordance with DoDI

8560.01 (Reference (bi)) and other applicable laws and regulations.

h. Provide for vulnerability mitigation and incident response and reporting capabilities in order to:

(1) Comply with mitigations as directed by Commander, USCYBERCOM orders, or other directives such as alerts and bulletins and provide support to cyberspace defense, in accordance with Reference (bg).

(2) Limit damage and restore effective service following an incident.

(3) Collect and keep audit data to support technical analysis relating to misuse, penetration, or other incidents involving IT under their purview, and provide this data to appropriate law enforcement (LE) or other investigating agencies.

(4) Establish procedures to ensure prompt management action and reporting in accordance with:

(a) DoDM 5200.01, Volume 3 (Reference (bj)) for an actual or potential compromise of classified information.

(b) DoDM 5200.01, Volume 4 (Reference (bk)) for an actual or potential unauthorized disclosure of CUI (e.g., proprietary information, LE information).

(c) Reference (bf) when such losses occur on cleared contractor systems.

(d) DoD 5400.11-R (Reference (bl)) for a loss or unauthorized disclosure of personally identifiable information (PII) or other Privacy Act information.

Change 1, 10/07/2019 23 ENCLOSURE 2

(5) Comply with CNSS Instruction (CNSSI) 1010 (Reference (bm)).

i. Ensure that contracts and other agreements include specific requirements to provide cybersecurity for DoD information and the IT used to process that information in accordance with this instruction.

j. Ensure that all personnel with access to DoD IT are appropriately cleared and qualified under the provisions of Reference (w) and that access to all DoD IT processing specified types of information (e.g., collateral, SCI, CUI) under their purview is authorized in accordance with the provisions of Reference (bj) and DoDM 5200.01, Volume 1 (Reference (bn)) or Reference (bk).

k. Ensure that personnel occupying cybersecurity positions are:

(1) Assigned in writing.

(2) Trained and qualified in accordance with References (x) and (ay).

(3) Assigned a position designation using the criteria found in Reference (w) and DoDI

1400.25 Vol. 731 (Reference (bo)). The position designation will be documented in the Defense Civilian Personnel Data System.

(4) Meet the associated suitability and fitness requirements.

l. Cybersecurity training and awareness products developed by DISA will be used to meet the baseline user awareness training required by Reference (x). DoD Components will provide additional cybersecurity orientation, training, and awareness programs to reinforce the objectives of the DoD Enterprise cybersecurity awareness programs to authorized users of ISs. This includes conducting additional in-depth training on DoD Component-specific topics.

m. Ensure that appropriate notice of privacy rights and monitoring policies are provided to all individuals accessing DoD Component-owned or controlled DoD ISs.

n. Ensure that cybersecurity solutions do not unnecessarily restrict the use of assistive technology by individuals with disabilities or access to or use of information and data by individuals with disabilities in accordance with sections 791, 794, and 794d of Title 29, U.S.C.

(Reference (bp)).

o. Conduct vulnerability assessments, Blue Team vulnerability evaluations and intrusion assessments, cybersecurity inspections, and Red Team operations (using internal or external capabilities) to provide a systemic view of enclave and IS…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .