Bidders Library Cybersecurity - DoDI 8530 01.pdf

PDF 631 KB Posted

Attached to
TEC II Services RFP Federal contract opportunity
Solicitation number
HC102821R0006
Issued by
Defense Information Systems Agency

About this file

This is a solicitation for test, evaluation, and certification services issued by the Defense Information Systems Agency. The agency is seeking proposals to provide services for the Joint Interoperability Test Command, including testing and certification of information systems, networks, platforms, and applications to validate interoperability and integration with the Department of Defense Information Network. Proposals are due by July 28, 2021. The period of performance for the awarded contract is five years with an estimated total value of $500 million. Small businesses are encouraged to compete.

View the file

Other files for this federal contract opportunity

Other files attached to TEC II Services RFP, newest first.
File Type Posted
HC102821R0006 Conformed Through amendment 0008.pdf PDF
HC102821R0006 Conformed Through amendment 0007.pdf PDF
HC102821R0006 Conformed Through amendment 0006.pdf PDF
HC102821R0006 Conformed through amendment 0002.pdf PDF
HC102821R00060002.pdf PDF
Bidders Library DODI 5000 02.pdf PDF
Bidders Library Security - ISOO Handbook.pdf PDF
Bidders Library Security - DoDM 5200 01 Vol 1.pdf PDF
Bidders Library Security - DISAI 240-115-04.pdf PDF
Bidders Library Security - DISAI 240-110-35.pdf PDF
Bidders Library Operational Test and Evaluation - JITC OTE Guidebook v2 0.docx DOCX document
Bidders Library Operational Test and Evaluation - DoTE MEMO 10-19-2010.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 10-18-2010.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 6-16-2003.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 04-03-2018.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 1-21-2015.pdf PDF
Bidders Library JITC Instructions - JITCI 100-50-01.pdf PDF
Bidders Library JITC Instructions - JITCI 210-20-02.pdf PDF
Bidders Library JITC Instructions - JITCI 210-15-01.pdf PDF
Bidders Library JITC Instructions - JITCI 200-05-07.pdf PDF
Bidders Library Interoperability Test and Evaluation - JITC Notional Guide for Action Officers.pdf PDF
Bidders Library Interoperability Test and Evaluation - JITC Fact Sheet.pdf PDF
Bidders Library Interoperability Test and Evaluation - DODI 8551 01.pdf PDF
Bidders Library Interoperability Test and Evaluation - DoD 8570 01-M.pdf PDF
Bidders Library DoD Policy Instruction and Guidance - DoDI 4000 19.pdf PDF
Bidders Library DoD Policy Instruction and Guidance - DoDD 510035.pdf PDF
Bidders Library DoD Policy Instruction and Guidance - DoD Net Centric Service Strategy.pdf PDF
Bidders Library DISA - DISA Mandatory Contractor Training as of 20201110.xlsx XLSX spreadsheet
Bidders Library Cybersecurity - DoDI 8510 01.pdf PDF
Bidders Library Security - DISAI 240-110-8.pdf PDF
Bidders Library Cybersecurity - DOD Cybersecurity TE Guidebook.pdf PDF
Bidders Library Security - DoDM 5200 01 Vol 3.pdf PDF
Bidders Library Security - DoDM 5200 02.pdf PDF
Bidders Library Security - DoDM 5200 01 Vol 2.pdf PDF
Bidders Library Security - DoDM 5200 48.pdf PDF
Bidders Library Security - DoDD 5230 20.pdf PDF
Bidders Library Security - DoDM 5105 21.pdf PDF
Bidders Library Security - DISAI 240-110-39.pdf PDF
Bidders Library Operational Test and Evaluation - DOTE TEMP Guidebook.pdf PDF
Bidders Library Operational Test and Evaluation - DTM 11-003.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 7-23-2013.pdf PDF
Bidders Library Operational Test and Evaluation - DISA Test and Evaluation Scorecard Template.pptx PPTX presentation
Bidders Library Operational Test and Evaluation - DoDD 5000 01.pdf PDF
Bidders Library JITC Instructions - JITCI 280-120-01.pdf PDF
Bidders Library JITC Instructions - JITCI 640-50-07.pdf PDF
Bidders Library JITC Instructions - JITCI 380-50-02.pdf PDF
Bidders Library JITC Instructions - JITCI 200-50-02.pdf PDF
Bidders Library JITC Instructions - JITCI 200-05-05.pdf PDF
Bidders Library JITC Instructions - JITCI 200-05-06.pdf PDF
HC102821R0006.pdf PDF
Show all 50

TEC II Services RFP has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Department of Defense

INSTRUCTION

NUMBER 8530.01

March 7, 2016

Incorporating Change 1, July 25, 2017

DoD CIO

SUBJECT: Cybersecurity Activities Support to DoD Information Network Operations

References: See Enclosure 1

1. PURPOSE. In accordance with the authority in DoD Directive (DoDD) 5144.02 (Reference (a)), this instruction:

a. Reissues DoDD O-8530.1 (Reference (b)) as a DoD Instruction (DoDI) and incorporates and cancels DoDI O-8530.2 (Reference (c)) to establish policy and assign responsibilities to protect the Department of Defense information network (DODIN) against unauthorized activity, vulnerabilities, or threats.

b. Supports the Joint Information Environment (JIE) concepts as outlined in JIE Operations Concept of Operations (CONOPS) (Reference (d)).

c. Supports the formation of Cyber Mission Forces (CMF), development of the Cyber Force Concept of Operations and Employment, evolution of cyber command and control, cyberspace operations doctrine in Joint Publication 3-12 (Reference (e)), and evolving cyber threats.

d. Supports the Risk Management Framework (RMF) requirements to monitor security controls continuously, determine the security impact of changes to the DODIN and operational environment, and conduct remediation actions as described in DoDI 8510.01 (Reference (f).

e. Cancels Assistant Secretary of Defense for Command, Control, Communications, and Intelligence Memorandum (Reference (g)).

2. APPLICABILITY. This instruction:

a. Applies to OSD, the Military Departments, the Office of the Chairman of the Joint Chiefs of Staff (CJCS) and the Joint Staff, the Combatant Commands, the Office of the Inspector General of the Department of Defense (IG DoD), the Defense Agencies, the DoD Field Activities, and all other organizational entities within the DoD (referred to collectively in this instruction as the “DoD Components”).

DoDI 8530.01, March 7, 2016

Change 1, 07/25/2017 2

b. The United States Coast Guard (USCG). The USCG will adhere to DoD cybersecurity requirements, standards, and policies in this instruction in accordance with the direction in Paragraphs 4a, b, c, and d of the Memorandum of Agreement Between the Department of Defense and the Department of Homeland Security (Reference (cn)).

c. Applies to the DODIN. The DODIN includes DoD information technology (IT) (e.g., DoD-owned or DoD-controlled information systems (ISs), platform information technology (PIT) systems, IT products and services) as defined in DoDI 8500.01 (Reference (h)) and control systems and industrial control systems (ICSs) as defined in National Institute (NIST) Special Publication (SP) 800-82 (Reference (i)) that are owned or operated by or on behalf of DoD Components.

d. Applies to commercial cloud computing services that are subject to the DoD Cloud Computing Security Requirements Guide (Reference (j)), developed by Director, Defense Information Systems Agency (DISA).

e. Applies to cleared defense contractors who operate pursuant to DoD 5220.22-M (Reference (k)) and the National Industrial Security Program (NISP) in accordance with DoDI

5220.22 (Reference (l)), to the extent that its requirements are made applicable through incorporation into contracts.

f. Applies to mission partner systems connected to the DODIN in accordance with, and to the extent set forth in, a contract, memorandum of agreement (MOA), support agreement, or international agreement, subject to and consistent with DoDI 4000.19 (Reference (m) and DoDD

5530.03 (Reference (n)).

g. Does not alter or supersede the existing authorities and policies of the Director of National Intelligence regarding the protection of sensitive compartmented information (SCI) as directed by Executive Order 12333 (Reference (o)) and other laws and regulations.

3. POLICY. It is DoD policy that:

a. DoD protects (i.e., secures and defends) the DODIN and DoD information using key security principles, such as isolation; containment; redundancy; layers of defense; least privilege;

situational awareness; and physical or logical segmentation of networks, services, and applications to allow mission owners and operators, from the tactical to the DoD level, to have confidence in the confidentiality, integrity, and availability of the DODIN and DoD information to make decisions.

b. DoD integrates technical and non-technical capabilities to implement DoD information network operations (DODIN operations) and defensive cyberspace operations (DCO) internal defensive measures directed by global, regional, and DoD Component authorities to protect the DODIN consistent with References (e), (f), and (h).

Change 1, 07/25/2017 3

c. DoD integrates and employs a number of cybersecurity activities to support DODIN operations and DCO internal defensive measures in response to vulnerabilities and threats as described in Reference (e). These activities include:

(1) Vulnerability assessment and analysis.

(2) Vulnerability management.

(3) Malware protection.

(4) Continuous monitoring.

(5) Cyber incident handling.

(6) DODIN user activity monitoring (UAM) for the DoD Insider Threat Program.

(7) Warning intelligence and attack sensing and warning (AS&W).

d. DoD IT will be aligned to DoD network operations and security centers (NOSCs). The NOSC and supporting cybersecurity service provider(s) will provide any required cybersecurity services to aligned systems.

e. DoD designated cybersecurity service providers will be authorized to provide cybersecurity services in accordance with DoD O-8530.01-M (Reference (p)). When cybersecurity services are provided, both the cybersecurity service provider and the system owner security responsibilities will be clearly documented.

f. DoD will help protect the DODIN through criminal or counterintelligence investigations or operations in support of DODIN operations.

g. Compliance with directed cyberspace operations will be a component of individual and unit accountability.

h. Contracts, MOAs, support agreements, international agreements, or other applicable agreements or arrangements governing the interconnection of the DODIN and mission partners’ systems developed in accordance with References (m) and (n) must identify:

(1) Specific DODIN operations responsibilities of DoD and mission partners;

(2) The cybersecurity requirements for the connected mission partners’ systems;

(3) The protection requirements for DoD data resident on mission partner systems; and

(4) Points of contact for mandatory reporting of security incidents.

Change 1, 07/25/2017 4

i. Data on the cybersecurity status of the DODIN and connected mission partner systems will be shared across the DoD enterprise in accordance with Reference (h), DoDI 8410.03 (Reference (q)), and DoDI 8320.02 (Reference (r)) to maintain DODIN situational awareness. DoD will:

(1) Use automated capabilities and processes to display DODIN operations and cybersecurity data, and ensure that the required data effectively satisfies the mission objectives.

(2) Ensure DODIN operations and cybersecurity data are visible, accessible, and understandable, trusted, and interoperable both vertically between superior and subordinate organizations and horizontally across peer organizations and mission partners in accordance with Reference (r).

4. RELEASABILITY. Cleared for public release. This instruction is available on the DoD Issuances Website at http://www.esd.whs.mil/DD/.

5. SUMMARY OF CHANGE 1. The changes to this issuance are administrative and update language to include the United States Coast Guard and references for accuracy.

6. EFFECTIVE DATE. This instruction is effective March 7, 2016.

Enclosures

1. References

2. Responsibilities

3. DoD Component Activities to Protect the DODIN

4. Cybersecurity Integration Into DODIN Operations

Glossary

Change 1, 07/25/2017 5

TABLE OF CONTENTS

ENCLOSURE 1: REFERENCES

ENCLOSURE 2: RESPONSIBILITIES

DoD CHIEF INFORMATION OFFICER (DoD CIO)

DIRECTOR, DISA

USD(AT&L)

ASSISTANT SECRETARY OF DEFENSE FOR RESEARCH AND ENGINEERING

(ASD(R&E))

USD(P)

ASSISTANT SECRETARY OF DEFENSE FOR HOMELAND DEFENSE AND GLOBAL

SECURITY

USD(I)

DIRNSA/CHCSS

DIRECTOR, DIA

DIRECTOR, DSS

DIRECTOR, OPERATIONAL TEST AND EVALUATION (DOT&E)

GENERAL COUNSEL OF THE DEPARTMENT OF DEFENSE (GC DoD) IG DoD DoD COMPONENT HEADS

SECRETARIES OF THE MILITARY DEPARTMENTS

CJCS

CDRUSSTRATCOM

ENCLOSURE 3: DoD COMPONENT ACTIVTIES TO PROTECT THE DODIN

GENERAL

VULNERABILITY ASSESSMENT AND ANALYSIS ACTIVITIES

VULNERABILITY MANAGEMENT PROGRAM

MALWARE PROTECTION PROCESS

ISCM

CYBER INCIDENT HANDLING PROGRAM

DODIN UAM FOR DoD INSIDER THREAT PROGRAM

WARNING INTELLIGENCE AND AS&W

ACCOUNTABILITY

ENCLOSURE 4: CYBERSECURITY INTEGRATION INTO DODIN OPERATIONS

CYBERSECURITY ACTIVITIES INTEGRATION

CYBERSECURITY ACTIVITIES TO PROTECT THE DODIN

CYBERSECURITY SERVICE PROVIDERS

DoD CIO CYBERSECURITY ARCHITECT

Change 1, 07/25/2017 6

GLOSSARY

PART I: ABBREVIATIONS AND ACRONYMS

PART II: DEFINITIONS

FIGURES

1. DODIN Operations, DCO Internal Defensive Measures, and Situational Awareness

2. Notional View of Current and Future Integration of Cybersecurity Activities

Change 1, 07/25/2017 ENCLOSURE 1 7

ENCLOSURE 1

REFERENCES

(a) DoD Directive 5144.02, “DoD Chief Information Officer (DoD CIO),” November 21, 2014

(b) DoD Directive O-8530.1, “Computer Network Defense (CND),” January 8, 2001 (hereby cancelled)

(c) DoD Instruction O-8530.2, “Support to Computer Network Defense (CND),” March 9, 2001 (hereby cancelled)

(d) Joint Information Environment Operations Sponsor Group, “Joint Information

Environment Operations Concept of Operations (JIE Operations CONOPS),” Version 2.0, September 18 20141

(e) Joint Publication 3-12, “Cyberspace Operations,” February 5, 2013

(f) DoD Instruction 8510.01, “Risk Management Framework (RMF) for DoD Information

Technology (IT),” March 12, 2014, as amended

(g) Assistant Secretary of Defense for Command, Control, Communications, and Intelligence

Memorandum, “Guidance for Computer Network Defense Response Actions,” February 26, 2003 (hereby cancelled)

(h) DoD Instruction 8500.01, “Cybersecurity,” March 14, 2014

(i) National Institute of Standards and Technology (NIST) Special Publication 800-82, Revision 2, “Guide to Industrial Control Systems (ICS) Security,” May 20152

(j) Defense of Defense Security Requirements Guide, ”Department of Defense (DoD) Cloud

Computing Security Requirements Guide, ”Version 1, Release 3, March 6, 20173

(k) DoD 5220.22-M, “National Industrial Security Program Operating Manual,” February 28, 2006, as amended

(l) DoD Instruction 5220.22, “National Industrial Security Program (NISP),” March 18, 2011

(m) DoD Instruction 4000.19, “Support Agreements,” April 25, 2013

(n) DoD Directive 5530.3, “International Agreements,” June 11, 1987, as amended

(o) Executive Order 12333, “United States Intelligence Activities,” December 4, 1981, as amended

(p) DoD O-8530.1-M, “Department of Defense Computer Network Defense (CND) Service

Provider Certification and Accreditation Program,” December 17, 2003

(q) DoD Instruction 8410.03, “Network Management (NM),” August 29, 2012

(r) DoD Instruction 8320.02, “Sharing Data, Information, and Information Technology (IT)

Services in the Department of Defense,” August 5, 2013

(s) DoD Directive 8000.01, “Management of the Department of Defense Information

Enterprise (DoD IE)” March 17, 2016

(t) DoD Chief Information Officer, “The DoD Architectural Framework (DoDAF)

Specifications, Version 2.02,” August 2010 4

(u) DoD Directive 5105.19, “Defense Information Systems Agency (DISA),” July 25, 2006

1 JIE CONOPS Version 2.0 can be found on Intelink at: https://dodcioext.osd.mil/SitePages/Initiative_JIE.aspx 2 NIST Special Publications are available at: http://csrc.nist.gov/publications/PubsSPs.html.

3 Cloud Computing Security Requirements Guide is available at:

http://iase.disa.mil/cloud_security/Documents/Forms/Allitems.aspx 4 DoDAF is available at: http://dodcio.defense.gov/Library/DoDArchitectureFramework .aspx

Change 1, 07/25/2017 ENCLOSURE 1 8

(v) DoD Instruction 8330.01, “Interoperability of Information Technology (IT), Including and National Security Systems (NSS),” May 21, 2014

(w) Committee on National Security Systems Policy No. 29, “National Secret Enclave Connection Policy,” May 2013

(x) DoD Directive 5205.16, “The DoD Insider Threat Program,” September 30, 2014, as amended

(y) Presidential Memorandum, “National Insider Threat Policy and Minimum Standards for Executive Branch Insider Threat Programs,” November 21, 2012

(z) Executive Order 13587, “Structural Reforms to Improve the Security of Classified Networks and the Responsible Sharing and Safeguarding of Classified Information,” October 7, 2011

(aa) Committee on National Security Systems Directive (CNSSD) No. 504, “Directive on Protecting National Security Systems from Insider Threat,” February 4, 20145

(ab) Chairman of the Joint Chiefs of Staff Execute Order (EXORD), “Modification (MOD) to EXORD To Implement Cyberspace Operations Command and Control (C2),” 141627ZNovember 20146

(ac) DoD 8570.01-M, “Information Assurance Workforce Improvement Program,” December 19, 2005, as amended

(ad) DoD Directive 5111.1, “Under Secretary of Defense for Policy (USD(P)),” December 8, 1999

(ae) Section 932 of Public Law 113-66, “Authorities, Capabilities, and Oversight of the United States Cyber Command,” December 26, 2013

(af) Deputy Secretary of Defense Memorandum, “Guidance Regarding Cyberspace Roles, Responsibilities, Functions, and Governance within the Department of Defense,” June 9, 2014

(ag) Secretary of Defense Memorandum, “Designation of the DoD Principal Cyber Advisor,” July 17, 2014

(ah) DoD Directive 5143.01, “Under Secretary of Defense for Intelligence (USD(I)),” October 24, 2014, as amended

(ai) Section 142 of Title 10, United States Code

(aj) DoD Directive 5100.20, “National Security Agency/Central Security Service (NSA/CSS),”

January 26, 2010

(ak) DoD Instruction O-3115.07, “Signals Intelligence (SIGINT),” September 15, 2008, as amended

(al) Chairman of the Joint Chiefs of Staff Manual 6510.03, “Department of Defense Cyber Red

Team Certification and Accreditation,” February 28, 2013

(am) DoD Directive 5105.21, “Defense Intelligence Agency (DIA),” March 18, 2008

(an) DoD Directive 5105.42, “Defense Security Service (DSS),” August 3, 2010, as amended

(ao) DoD Manual 5220.22, Volume 3, “National Industrial Security Program: Procedures for

Government Activities Relating to Foreign Ownership, Control or Influence (FOCI), April 17, 2014

5 CNSSD No. 504 can be found on Secret Internet Protocol Router Network (SIPRNET) at:

http://www.iad.nsa.smil.mil/resources/library/cnss_section/pdf/CNSSD_504.pdf 6 CJCS EXORD can be found on Intelink at:

https://intelshare.intelink.sgov.gov/sites/jointstaff/j3/ddgo/cod/Cyber%20C2%20Documents/Forms/Allitems.aspx

Change 1, 07/25/2017 ENCLOSURE 1 9

(ap) DoD Directive 5141.02, “Director of Operational Test and Evaluation (DOT&E),” February 2, 2009

(aq) DoD Instruction 5010.41, “Joint Test and Evaluation (JT&E) Program,” September 12, 2005

(ar) DoD Directive 5145.01, “General Counsel of the Department of Defense (GC DoD),” December 2, 2013, as amended

(as) DoD Instruction 5025.01, “DoD Issuances Program,” August 1, 2016, as amended

(at) DoD Directive 5106.01, “Inspector General of the Department of Defense (IG DoD),”

April 20, 2012, as amended

(au) Chairman of the Joint Chiefs of Staff Notice 3500.01, “2015-2018 Chairman’s Joint

Training Guidance,” October 30, 2014

(av) Deputy Under Secretary of Defense for Acquisition, Technology and Logistics

Memorandum, “Real-Property-related Industrial Control System Cybersecurity,” March 19, 2014

(aw) Subchapter III of Chapter 35 of Title 44, United States Code (also known as the “Federal Information Security Modernization Act (FISMA) of 2014”)

(ax) Appendix III to Office of Management and Budget Circular No. A-130, “Security of Federal Automated Information Resources,” November 28, 2000, as amended

(ay) DoD Manual 8910.01, Volume 1, “DoD Information Collections Manual: Procedures for DoD Internal Information Collections,” June 30, 2014, as amended

(az) Chairman of the Joint Chiefs of Staff Manual 3122.01A, “Joint Operation Planning and Execution System (JOPES) Volume I, Planning Policies and Procedures,” September 29, 20067

(ba) Chairman of the Joint Chiefs of Staff Manual 3122.02D, “Joint Operation Planning and Execution System (JOPES) Volume III, Timed Phased Force and Deployment Data Development and Deployment Execution,” March 17, 2011, as amended

(bb) Joint Publication 3-35, “Deployment and Redeployment Operations,” January 31, 2013

(bc) DoD Directive 3000.06, “Combat Support Agencies (CSAs),” June 27, 2013, as amended

(bd) DoD Manual 5200.01, Volume 3, “DoD Information Security Program: Protection of

Classified Information,” February 24, 2012, as amended

(be) DoD Manual 5200.01, Volume 4, “DoD Information Security Program: Controlled

Unclassified Information (CUI),” February 24, 2012

(bf) DoD Regulation 5400.11-R, “Department of Defense Privacy Program,” May 14, 2007

(bg) DISA Circular 300-110-3, “Defense Information System Network (DISN) Security

Classification Guide (U),” September 27, 20128

(bh) Joint Worldwide Intelligence Communications Systems (JWICS) Security Classification

Guide (SCG),” current version9

(bi) DoD Instruction O-3600.02, “Information Operations (IO) Security Classification

Guidance,” November 28, 2005

7 CJCS Manuals 3122.01A and 3122.02D are available on Intelink at CJCS/JS Directives Electronic Library (SIPRNET) at:

http://intelshare.intelink.sgov.gov/sites/jointstaff/SJS/IMD/Directives/Shared%20Documents/Forms/CJCS%20Man uals.aspx.

8 DISA Publications and Issuances (CAC Required):

https://disa.deps.mil/ext/resource/disa_publications_issuances/default.aspx 9 Classification guide can be found on JWICS at: http://jwics.ic.gov/Security/Documents/JWICS_SCG%20docx.pdf

Change 1, 07/25/2017 ENCLOSURE 1 10

(bj) DoD Directive 5100.03, “Support of the Headquarters of Combatant and Subordinate Unified Commands,” February 9, 2011

(bk) DoD Instruction 3020.41, “Operational Contract Support (OCS),” December 20, 2011, as amended

(bl) DoD Instruction 5000.02, “Operation of the Defense Acquisition System,” January 7, 2015, as amended

(bm) Unified Command Plan, April 6, 2011, as amended10

(bn) Secretary of Defense Memorandum, “Establishment of a Subordinate Unified U.S. Cyber

Command Under U.S. Strategic Command for Military Cyberspace Operations,” June 23, 2009

(bo) Commander, United States Strategic Command (CDRUSSTRATCOM) OPORD “OPERATION GLADIATOR PHOENIX (U),” February 11, 201111

(bp) Chairman of the Joint Chiefs of Staff Instruction 6510.01F, “Information Assurance (IA) and Support to Computer Network Defense (CND),” February 9, 2011

(bq) National Institute of Standards and Technology Special Publication 800-115, “Technical Guide to Information Security Testing and Assessment,” September 2008

(br) Chairman of the Joint Chiefs of Staff Manual 6510.02, “Information Assurance Vulnerability Management (IAVM) Program,” November 5, 201312

(bs) National Institute of Standards and Technology Special Publication 800-40, Revision 3, “Guide to Enterprise Patch Management Technologies,” July 2013

(bt) National Institute of Standards and Technology Special Publication 800-83, Revision 1, “Guide to Malware Incident Prevention and Handling for Desktops and Laptops,” July 2013

(bu) National Institute of Standards and Technology Special Publication 800-137, “Information Security Continuous Monitoring for Federal Information Systems and Organizations,” September 2011

(bv) National Institute of Standards and Technology Special Publication 800-37, Revision 1, “Guide for Applying the Risk Management Framework to Federal Information Systems:

A Security Life Cycle Approach,” February 2010, as amended

(bw) National Institute of Standards and Technology Special Publication 800-39, “Managing Information Security Risk: Organization, Mission, and Information System View,” March 20116

(bx) Chairman of the Joint Chiefs of Staff Manual 6510.01B, “Cyber Incident Handling Program,” July10, 2012

(by) Committee on National Security Systems Instruction No. 1010, “Cyber Incident Response,” December 16, 2016

(bz) National Institute of Standards and Technology Special Publication 800-61, Revision 2, “Computer Security Incident Handling Guide,” August 20126

(ca) DoD Directive 5240.06, “Counterintelligence Awareness and Reporting (CIAR),” May 17, 2011, as amended

10 Available on to authorized users at: https://intellipedia.intelink.sgov.gov/wiki/Unified_Command_Plan/ 11 Available at:

https://www.cybercom.smil.mil/J3/orders/OPORD11_002/STRATCOM%20OPORD%20Op%20Gladiator%20Phoe nix.pdf 12 CJCS Manual is available on Intelink at CJCS/JS Directives Electronic Library (SIPRNET) at:

http://intelshare.intelink.sgov.gov/sites/jointstaff/SJS/IMD/Directives/Shared%20Documents/Forms/CJCS%20Man uals.aspx

Change 1, 07/25/2017 ENCLOSURE 1 11

(cb) Committee on National Security Systems Policy No. 18, “National Policy on Classified Information Spillage,” June 20066

(cc) Committee on National Security Systems Instruction No. 1001, “National Instruction on Classified Information Spillage,” February 20086

(cd) DoD Instruction 5240.26, “Countering Espionage, International Terrorism, and the Counterintelligence (CI) Insider Threat,” May 4, 2012, as amended

(ce) Joint Publication 2-0, “Joint Intelligence,” October 22, 2013

(cf) DoD Directive 8140.01, “Cyberspace Workforce Management,” August 11, 2015

(cg) Defense Information Systems Agency, “Defense Information Systems Network (DISN)

Connection Process Guide (CPG),” current version

(ch) DoD 5220.22-R, “Industrial Security Regulation,” December 4, 1985

(ci) Subpart 4.4 of the Federal Acquisition Regulation

(cj) DoD Instruction 8582.01, “Security of Unclassified DoD Information on Non-DoD

Information Systems,” June 6, 2012

(ck) Defense Federal Acquisition Regulation Supplement 252.204-7012, “Safeguarding of

Unclassified Controlled Technical Information,” current edition

(cl) Committee on National Security Systems Instruction No. 4009, “Committee on National

Security Systems (CNSS) Glossary,” April 6, 2015 13

(cm) Office of the Chairman of the Joint Chiefs of Staff, “DoD Dictionary of Military and Associated Terms,” current edition

(cn) Memorandum of Agreement between the Department of Defense and The Department of Homeland Security Regarding Department of Defense and U.S. Coast Guard Cooperation on Cybersecurity and Cyberspace Operations, January 19, 201714

13Available through the Internet at http://www.cnss.gov 14Available through the Internet at https://dcms.uscg.afpims.mil/Our-Organization/Assistant-Commandant-for- C4IT-CG-6-/The-Office-of-Information-Management-CG-61/Interagency-Agreements/

Change 1, 07/25/2017 ENCLOSURE 2 12

ENCLOSURE 2

RESPONSIBILITIES

1. DoD CHIEF INFORMATION OFFICER (DoD CIO). In accordance with Reference (a), the DoD CIO:

a. Establishes DoD policy and provides guidance and oversight for integrating cybersecurity activities to support DODIN operations and DCO internal defensive measures and to strengthen accountability through the cyberspace operations chain of command to protect the DODIN in coordination with the Under Secretary of Defense for Policy (USD(P)), the Principal Cyber Advisor (PCA), the Under Secretary of Defense for Intelligence (USD(I)), the CJCS, the Director, National Security Agency/Chief, Central Security Service (DIRNSA/CHCSS), and the Commander, U. S. Strategic Command (CDRUSSTRATCOM).

b. Provides strategic management, guidance, and direction to DoD Component efforts to plan, program, budget, develop, and implement the capability to protect the DODIN in coordination with the USD(P) based on the DoD Enterprise Architecture in accordance with DoDD 8000.01 (Reference (s)) and the evolving JIE architecture.

c. Ensures capabilities are developed and incorporated into the DoD Architectural Framework (Reference (t)) in accordance with DoDI 8330.01 (Reference (v)) to protect the

DODIN.

d. Oversees the development and implementation of DoD cybersecurity architectures and capabilities to protect the DODIN, in coordination with CDRUSSTRATCOM.

e. Oversees the DoD Component cybersecurity service provider authorization process and DoD Component compliance with criteria established in Reference (p)

f. Validates in coordination with Director, DISA, cybersecurity standards established by Federal mission partner organizations connected to the DODIN comply with equivalent cybersecurity requirements and to those standards described in Committee on National Security Systems Policy (CNSSP) No. 26 Reference (w).

g. Oversees process and approves requests for the interconnection of mission partners’ systems to the DODIN through a point-to-point connection or a demilitarized zone (DMZ).

(1) Approves the authorized interconnection points to the DODIN for either a mission partner DMZ interconnection (e.g., Federal (FED) DMZ or Releasable (REL) DMZ) or a point-to-point interconnection.

(2) In coordination with DISA, maintains a list of validated non-DoD Federal mission partner organizations that meet the equivalency requirements required of DoD cybersecurity service providers.

Change 1, 07/25/2017 ENCLOSURE 2 13

(3) Provides to mission partners DoD’s requirements for risk tolerance for interconnecting mission partners’ systems and the DODIN.

(4) Ensures that the roles and responsibilities for managing and mission partner interconnection to the DODIN, including cybersecurity requirements, are documented in a contract, MOA, support agreement, or international agreement document. These agreements must be in accordance with References (m) and (n).

h. Coordinates with the USD(I) and the Director, Defense Security Service (DSS), on cybersecurity requirements for the NISP.

i. Coordinates with the Under Secretary of Defense for Acquisition, Technology, and Logistics (USD(AT&L)) and CDRUSSTRATCOM on:

(1) Needs and requirements for DoD-wide research and technology investments and activities to protect the DODIN.

(2) Development of and, where applicable, the acquisition of automated capabilities for DODIN situational awareness that support DODIN operations and DCO internal defensive measures. Capabilities will be consistent with the approved Joint Capabilities Integration and Development System (JCIDS) document.

j. Participates or designates representation on national and Federal Chief Information Officer (CIO) cybersecurity related coordination groups, as required.

k. Develops policy and strategy, including auditing and UAM standards. Helps the USD(P), the USD(I), and the Under Secretary of Defense for Personnel and Readiness (USD(P&R)) develop guidelines and procedures for implementation of standards for the DoD Insider Threat Program in accordance with DoDD 5205.16 (Reference (x)), and contained in Presidential Memorandum (Reference (y)), Executive Order 13587 (Reference (z)), and Committee on National Security Systems Directive (CNSSD) No. 504 (Reference (aa))reference.

l. Develops metrics that will measure the cybersecurity status of the DODIN leveraging existing standards and guidelines for audit and assessment processes in coordination with

CDRUSSTRATCOM.

m. Reviews the cybersecurity posture of systems authorized to operate outside the DODIN.

Such systems will be reviewed, before granting a DODIN waiver to operate outside the DODIN, to ensure that there is an appropriate level of cybersecurity to protect personnel, information, and equipment within the system operating boundary.

n. Participates or designates representation on Federal and DoD cybersecurity-related panels and boards, as required.

Change 1, 07/25/2017 ENCLOSURE 2 14

2. DIRECTOR, DISA. Under the authority, direction, and control of the DoD CIO, and in addition to the responsibilities in section 14 of this enclosure, the Director, DISA:

a. Protects DoD transport and enterprise services in accordance with DoDI 5105.19 (Reference (u)) in coordination with CDRUSSTRATCOM, joint, and DoD Component NOSCs.

b. Plans for, mitigates, and executes DODIN operations and DCO internal defensive measures at the DoD global and DoD enterprise level, as directed by CDRUSSTRATCOM.

c. Serves as the Commander, Joint Forces Headquarters-DODIN (JFHQ-DODIN), a subordinate headquarters under the Commander, United States Cyber Command (CDRUSCYBERCOM) in accordance with CJCS Execute Order (EXORD) (Reference (ab)) that establishes the framework for global DODIN operations.

d. Provides DODIN situational awareness of DISA operated DoD transport and enterprise services, including enterprise network data and analytics for supported DoD Components to measure the impact of changes in the DODIN, such as cybersecurity, availability, and compliance.

e. Provides and maintains a cybersecurity and network defense plan for DoD enterprise transport and enterprise services critical nodes.

f. Supports CDRUSSTRATCOM compliance and operational readiness inspections of the DODIN.

g. Develops, maintains, and implements the general service (GENSER) DoD cybersecurity service provider processes in accordance with Reference (p) and in coordination with the DoD CIO, the CDRUSSTRATCOM, and the Director, Defense Intelligence Agency (DIA).

(1) Maintains the GENSER maturity evaluation criteria found in Reference (p) in coordination with the DoD Component cybersecurity service providers, the CDRUSSTRATCOM, and the DoD CIO.

(2) Functions as the evaluator for GENSER DoD cybersecurity services in accordance with Reference (p).

(3) Conducts evaluation of DoD Component cybersecurity service providers’ services as directed by CDRUSSTRATCOM. Evaluation documents with a recommendation are provided to the CDRUSSTRATCOM to authorize the service provider to offer cybersecurity services for GENSER systems.

(4) Provides cybersecurity services on a subscription basis to any DoD Component organization, Federal department, or Federal agency that does not establish or otherwise subscribe to a DoD GENSER cybersecurity service provider.

Change 1, 07/25/2017 ENCLOSURE 2 15

(5) Provides cybersecurity guides and best practices guidelines for use by DoD and mission partners in coordination with the CDRUSSTRATCOM; the Director, DIA;

DIRNSA/CHCSS; and the DoD CIO.

(6) Verifies DoD cybersecurity service provider qualifications in accordance with DoD 8570.01-M (Reference (ac)) during evaluations or inspections.

(7) Validates Federal mission partner’s capability to provide cybersecurity services and capabilities that are equivalent to those specified in Reference (p) in coordination with DoD CIO.

(a) Maintains a list of validated mission partner organizations with equivalent cybersecurity services and capabilities aligned with mission partner systems connected to the DODIN.

(b) Provides cybersecurity services and capabilities to mission partners connected to the DODIN through a DMZ, such as FED DMZ or REL DMZ, on a subscription basis when requested.

h. Serves as a technical advisor to the DoD CIO for DoD-wide capability requirements to protect the DODIN in coordination with the Director, DIA, DIRNSA/CHCSS, and the

CDRUSSTRATCOM.

3. USD(AT&L). The USD(AT&L) provides oversight of the development and acquisition of capabilities that protect the DODIN. Oversees the development and, where applicable, the acquisition of automated capabilities for DODIN situational awareness that support DODIN operations and DCO internal defensive measures, in coordination with the DoD CIO, DIRNSA/CHCSS, and the CDRUSSTRATCOM. Capabilities will be consistent with the approved JCIDS initial capabilities documents.

4. ASSISTANT SECRETARY OF DEFENSE FOR RESEARCH AND ENGINEERING

(ASD(R&E)). Under the authority, direction, and control of the USD(AT&L), the ASD(R&E) oversees all DoD-wide research and technology investments and activities to:

a. Protect the DODIN.

b. Provide developments and results to the Assistant Secretary of Defense for Acquisition in support of their acquisition oversight responsibilities.

5. USD(P). Consistent with the responsibilities assigned in DoDD 5111.1 (Reference (ad)) on the formulation of national security and defense policy, the USD(P):

a. Supervises cyber activities related to offensive missions, defense of the United States, and defense of the DODIN, including oversight of policy and operational considerations, resources, Change 1, 07/25/2017 ENCLOSURE 2 16 personnel, acquisition (in consultation with the USD(AT&L)), technology (in consultation with the USD(AT&L) and DoD CIO), and on military cyber forces and activities in accordance with section 932 of Public Law 113-66 (Reference (ae)) and Deputy Secretary of Defense Memorandum (Reference (af)).

b. Coordinates with the USD(AT&L), USD(I), and DoD CIO on the development of DoD cyberspace operations policy, including DODIN operations and DCO internal defensive measures policy to protect the DODIN.

6. ASSISTANT SECRETARY OF DEFENSE FOR HOMELAND DEFENSE AND GLOBAL

SECURITY. Under the authority, direction, and control of USD(P), and as the PCA designated by Secretary of Defense Memorandum (Reference (ag)), will in coordination with relevant Principal Staff Advisors, serve as the principle advisor to the Secretary of Defense on cyberspace operations and missions and advise the Secretary with respect to matters pertaining to those identified in Reference (af).

7. USD(I). Consistent with the responsibilities assigned in DoDD 5143.01 (Reference (ah)), the

USD(I):

a. Ensures that Defense intelligence, counterintelligence, and security programs support DoD’s requirements to protect the DODIN;

b. Oversees the use of National Intelligence Program and Military Intelligence Program resources to support DoD’s efforts to protect the DODIN. Ensures the equitable and appropriate use of those resources across the Defense Intelligence Enterprise;

c. Oversees DoD intelligence activities, including warning intelligence and AS&W support to DODIN operations and DCO internal defensive measures;

d. Coordinates with DoD CIO to develop UAM guidelines and procedures to implement the requirements specified in References (x), (y), and (z);

e. Provides security advice and support to the DoD CIO and separately to the USD(AT&L) when acquisition programs utilizing cleared defense contractors are involved; and

f. Oversees policy and management of the NISP and develops and approves Reference (l).

8. DIRNSA/CHCSS. Under the authority, direction, and control of the USD(I), consistent with section 142 of Title 10, United States Code (Reference (ai) in addition to the cybersecurity-related responsibilities in DoDD 5100.20 (Reference (aj)) and the responsibilities in section 14 of this enclosure, the DIRNSA/CHCSS:

Change 1, 07/25/2017 ENCLOSURE 2 17

a. Conducts DoD-wide capability research and technology development to protect the DODIN.

(1) Provides support for capability research to the CDRUSSTRATCOM, the DoD CIO cybersecurity architect, and the USD(AT&L).

(2) Conducts and manages basic research, applied research, advanced technology development, and technology component development and prototyping in order to advance the state-of-the-art for capabilities used to protect the DODIN and conduct DODIN operations and DCO internal defensive measures.

(3) Develops proofs-of-concept, prototype systems, and system pilots to enable more effective capabilities to protect the DODIN.

(4) Advises and assists in the design of standards and interfaces to integrate existing capabilities.

(5) Maintains a comprehensive view of all capabilities gaps, shortfalls, and research, development, and technology transfer requirements across the DoD.

b. Provides and coordinates technical and analytical support to DoD Components, as requested by the CDRUSSTRATCOM.

c. Provides the CDRUSSTRATCOM, joint, and the DoD Component NOSCs and their supporting cybersecurity service providers with warning intelligence and AS&W information in accordance with Reference (aj) and DoDI O-3115.07 (Reference (ak)). In support of DoD organizations, provides:

(1) Detection, alerting, and response capabilities to mitigate threats to the DODIN.

(2) Warning intelligence information through reporting or posting on secure websites.

(3) Overall DoD-wide long-term effectiveness trend and pattern analysis to support the protection of the DODIN as informed by situational awareness of DODIN operations and DCO internal defensive measures and the results of DoD assessments, evaluations, inspections, and exercises.

(4) Monitoring and analysis of vulnerabilities and adversary threat to the DODIN.

(5) Multi-source reporting on threats to the DODIN.

(6) Technology, information, expertise, and other support to the DoD NOSCs and their supporting cybersecurity service providers, as required.

Change 1, 07/25/2017 ENCLOSURE 2 18

d. Supports the DoD CIO cybersecurity architect and the DoD Components in the development of capabilities to protect the DODIN, within the DoD Enterprise and the JIE architectures.

e. Evaluates DoD Cyber Red Teams in accordance with Chairman of the Joint Chiefs of Staff Manual (CJCSM) 6510.03 (Reference (al)) and CDRUSSTRATCOM direction.

f. Provides evaluation documents with authorization recommendations to the CDRUSSTRATCOM for these teams to conduct operations across DODIN outside of their DoD Component’s authorization boundaries (e.g., DoD-owned or -operated systems).

g. Serves as the technical advisor to the DoD CIO on DoD-wide capability requirements to protect the DODIN in coordination with the Director, DISA.

9. DIRECTOR, DIA. Under the authority, direction, and control of the USD(I), in addition to the responsibilities in section 14 of this enclosure and consistent with the responsibilities in DoDD 5105.21 (Reference (am)), the Director, DIA:

a. Develops, maintains, and implements the DoD special enclave (SE) cybersecurity service provider processes in accordance with Reference (p) and in coordination with the DoD CIO; the CDRUSSTRATCOM and the Director, DISA.

(1) Maintains the SE maturity evaluation criteria found in Reference (p) in coordination with the DoD Components with SE cybersecurity providers, CDRUSSTRATCOM, and the DoD CIO.

(2) Functions as the evaluator of SE DoD cybersecurity services in accordance with Reference (p).

(3) Conducts evaluation of DoD Component cybersecurity service providers’ services as directed by the CDRUSSTRATCOM. Evaluation documents with a recommendation are provided to the Director, DIA designated office to authorize the cybersecurity service provider to offer SE cybersecurity services.

(4) Provides cybersecurity services on a subscription basis to any DoD Component organization that does not establish or otherwise subscribe to a DoD SE cybersecurity service provider.

(5) Verifies DoD SE cybersecurity service providers’ qualifications in accordance with Reference (ac) during evaluations or inspections.

(6) Establishes advisory and alert procedures for SE DoD Components and their supporting cybersecurity service providers.

Change 1, 07/25/2017 ENCLOSURE 2 19

b. Coordinates with the Intelligence Community Chief Information Officer and DIRNSA/CHCSS on the design, development, and maintenance of capabilities to protect DoD and intelligence community (IC) SEs operated by DoD Components (e.g., Joint Worldwide Intelligence Communications System (JWICS)).

c. Coordinates the incorporation of IC information network situational awareness information into the DODIN situational awareness capabilities and processes in coordination with DIRNSA/CHCSS; and provides DoD SE network situational awareness information to the intelligence community.

d. Provides DoD-wide threat analysis focused on the DODIN in support of the United States Strategic Command (USSTRATCOM) and the other DoD Components in coordination with

DIRNSA/CHCSS.

e. Provides for the collection, processing, and dissemination of all-source, finished intelligence to identify potential threats, provide indications of threat activity, and disseminate warnings of threat activities against the DODIN and IC networks.

f. Provides all source analysis of adversary threats and finished intelligence in support of DODIN situational awareness for the CDRUSSTRATCOM, joint and DoD Component NOSCs, and their supporting cybersecurity service providers.

10. DIRECTOR, DSS. Under the authority, direction, and control of the USD(I), in addition to the responsibilities in section 14 of this enclosure, and consistent with the responsibilities assigned in DoDD 5105.42 (Reference (an)), the Director, DSS:

a. Oversees the NISP, including cleared defense contractor systems processing classified information.

b. Requires companies operating under a foreign ownership, control, or influence mitigation agreement to develop and maintain an Electronic Communications Plan as described in Volume 3 of DoD Manual (DoDM) 5220.22 (Reference (ao)).

c. Provides DODIN situational awareness and threat alerts to cleared defense contractors on threats to their systems.

d. Disseminates information to identify potential threats, provide indications of threat activity, and disseminate warnings of threat activities against cleared defense contractor systems.

11. DIRECTOR, OPERATIONAL TEST AND EVALUATION (DOT&E). The DOT&E:

a. Oversees the conduct of operational test and evaluation of DODIN operations and DCO internal defensive measures to assess joint interoperability and evaluate joint technical and

Change 1, 07/25/2017 ENCLOSURE 2 20 operational concepts to protect the DODIN and future JIE consistent with the responsibilities assigned in DoDD 5141.02 (Reference (ap)) and DoDI 5010.41 (Reference (aq)).

b. Oversees the conduct of cybersecurity assessments during major exercises consistent with Reference (ap).

12. GENERAL COUNSEL OF THE DEPARTMENT OF DEFENSE (GC DoD). The GC DoD provides legal advice regarding legal issues related to DODIN operations and DCO internal defensive measures, with the exception of those undertaken by the IG DoD in accordance with DoDD 5145.01 (Reference (ar)).

13. IG DoD. The IG DoD:

a. Develops policy guidance, as appropriate, for law enforcement and criminal investigations that relate to cyberspace in accordance with DoDI 5025.01 (Reference (as)) and DoDD 5106.01 (Reference (at)).

b. Through the Director, Defense Criminal Investigation Service, and in accordance with Reference (at), provides data to cyber incident DODIN situational awareness databases, as the IG DoD deems appropriate.

14. DoD COMPONENT HEADS. The DoD Components heads:

a. Conduct DODIN operations and DCO defensive internal measures in accordance with CDRUSSTRATCOM and DoD Component orders and directives to protect their respective portion of the DODIN.

b. Implement actions to ensure DODIN readiness, respond to potential adversary operations, or disrupt potential adversary presence in the DODIN. Examples of actions include: verifying accounts having administrative privileges, reestablishing known good software baselines on servers, ensuring use of common access cards and resetting passwords.

c. Practice and evaluate DODIN operations and DCO internal defensive measures during exercises (e.g., joint or continuity of operations exercises) to ensure that processes and procedures can be evaluated and the effectiveness of pre-planned actions or potential directed DCO internal measures in a denied or contested cyber environment can be measured against opposing forces (OPFOR) operations and other CMF team requirements as described in CJCS Notice 3500.01 (Reference (au)). This includes testing and evaluating DoD Component ICSs to ensure survivability and to preclude a mission disabling event occurring in a cyber contested environment as described in Deputy USD(AT&L) memorandum (Reference (av)).

d. Use organic or external cybersecurity activities and capabilities to protect DoD Component owned or operated portion of the DODIN in accordance with References (f) and (h);

Change 1, 07/25/2017 ENCLOSURE 2 21 subchapter III of chapter 35 of Title 44, U. S. Code, also known as the “Federal Information Security Modernization Act (FISMA) of 2014” (Reference (aw)); Appendix III to Office of Management and Budget Circular A-130 (Reference (ax)); and federal and DoD issuances applicable to these activities.

e. Ensure DoD Component systems are aligned to a joint or DoD Component NOSC to receive and comply with orders or directives from USSTRATCOM and their DoD Component.

f. Oversee the implementation of all directed actions required by USSTRATCOM or its Component for their respective owned or operated portion of the DODIN.

(1) Implement directed actions in accordance with CDRUSSTRATCOM orders or other directives issued through the CDRUSCYBERCOM or subordinate Commander, JFHQ-DODIN in accordance with Reference (ab). Examples of an order or directive include an operation order (OPORD), fragmentary order, tasking order (TASKORD), EXORD, vulnerability management alert, and vulnerability management bulletin. The collection of information must be approved and licensed in accordance with the procedures in Volume 1 of DoDM 8910.01 (Reference (ay)).

(2) Coordinate with USSTRATCOM or other affected DoD Components actions or measures that could affect the DODIN outside their Component.

g. Plan for, coordinate, request, and support deployment of USSTRATCOM CMF.

(1) Force deployments in support of joint operations will be in accordance with CJCSM 3122.01A (Reference (az)), CJCSM 3122.02D (Reference (ba)), Joint Publication (JP) 3-35 (Reference (bb)), and DoDD 3000.06 (Reference (bc)).

(2) Provide CMF teams support in accordance with the deployment order.

(3) Notify DoD counterintelligence and law enforcement agencies responsible for the affected portion of the DODIN of CMF deployment, and any counterintelligence or law enforcement support requested.

(4) Provide cyber mission forces required access to DoD Component owned or operated portions of the DODIN to support of DoD cyberspace operations in accordance with Secretary of Defense and CDRUSSTRATCOM orders and other directives.

h. Establish a DoD Component-wide sensor grid and DODIN situational awareness capability to share data on cybersecurity activities and to collaborate with other organizations in coordination with the CDRUSSTRATCOM; the Director, DISA; DIRNSA/CHCSS; and with review of the Cyber Investment Management Board (CIMB) to support DODIN operations and DCO internal defensive measures.

i. Designate DoD Component-owned or -operated portions of the DODIN as either SE or

GENSER.

Change 1, 07/25/2017 ENCLOSURE 2 22

j. Validate that cybersecurity services provided to DoD Component organizations or offered by a DoD Component cybersecurity provider to external organizations have been evaluated in accordance with Reference (p) and that CDRUSSTRATCOM has authorized the service provider to provide those cybersecurity services.

k. Provide information to the DoD CIO, as requested, to support the DODIN architectures, the cybersecurity service provider process, and capability development activities to protect the

DODIN.

l. Develop intelligence requirements (IRs) to facilitate timely decision making for the protection of the DoD Component-owned or -operated portion of the DODIN. Submit those IRs to supporting intelligence organizations.

m. Validate requests by DoD Component organizations to be designated as a DoD cyber red team authorized to conduct operations across the DODIN in accordance with Reference (al), and prioritize requests, if required.

n. Inform the IG DoD when cybersecurity deficiencies in the DODIN contribute to a security breach or failure and are the result of noncompliance with DoD standards or contractual provisions.

o. Ensure that all users understand and follow the policy and guidance to protect classified and controlled unclassified information and prevent unauthorized disclosures on DoD IT.

(1) Classified Information

(a) Unauthorized disclosure or data spillage involving classified information will be identified as a negligent discharge of classified information incident to be reported and investigated in accordance with Volume 3 of DoDM 5200.01 (Reference (bd)). The investigation must determine whether the incident was willful, negligent, or inadvertent.

(b) Classified information may be processed only on systems approved for such use, at the required level of classification and access control, in accordance with Reference (bd).

(2) Controlled Unclassified Information (CUI)

(a) Unauthorized disclosures of CUI will be handled and reported in accordance with Volume 4 of DoDM 5200.01(Reference (be)) or guidance for specific types of CUI provided by the DoD Component Head or information owner (e.g., DoD 5400.11-R (Reference (bf)) for privacy information).

(b) If possible, electronic transmission CUI and privacy information (e.g., data, website, or e-mail) will be approved by secure communications systems or systems utilizing other protective measures such as encryption to protect confidentiality and integrity of CUI and privacy information to avoid unauthorized disclosure.

Change 1, 07/25/2017 ENCLOSURE 2 23

p. Ensure personnel creating and compiling vulnerability and technical details on the configuration of systems are aware of the need to refer to applicable security classification guides, such as DISA Circular 300-110-3 (Reference (bg)), JWICS Security Classification Guide (Reference (bh)), and DoDI O-3600.02 (Reference (bi)), for guidance on classifying and marking information.

(1) Vulnerability information specific to DoD IT systems, and technical details on the configuration of DoD IT systems, will be handled, at a minimum, as controlled unclassified information or at classification level of the systems in accordance with applicable classification guidance such as References (bg), (bh), and (bi).

(2) CDRUSSTRATCOM will provide amplifying classification guidance in directives and orders for specific threat, vulnerability, or configuration information, and directed DODIN operations or DCO internal measures.

q. Ensure all personnel understand cybersecurity best practices and compliance requirements and procedures, as appropriate.

(1) Establish criteria for inclusion of cybersecurity compliance with individual and unit readiness, assessments, and evaluations.

(2) Employ sanctions against individuals or units in accordance with the severity of non-compliance with…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .