Bidders Library Interoperability Test and Evaluation - CJCSI 6211 02D.pdf
PDF 295 KB Posted
- Attached to
- TEC II Services RFP Federal contract opportunity
- Solicitation number
- HC102821R0006
- Issued by
- Defense Information Systems Agency
About this file
This is a solicitation for test, evaluation, and certification services issued by the Defense Information Systems Agency. Required services include testing, evaluation, and certification of joint interoperability capabilities for the Joint Interoperability Test Command. The solicitation is unrestricted with no set-asides indicated. Responses are due by November 18, 2021 with an anticipated award date of March 2022. Pricing will be fixed price or time and materials. Incumbent contractors were not specified.
View the file
Other files for this federal contract opportunity
Show all 50
TEC II Services RFP has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
CHAIRMAN OF THE JOINT
CHIEFS OF STAFF
INSTRUCTION
CJCSI 6211.02D J-6
DISTRIBUTION: A, B, C, JS-LAN, S 24 January 2012
DEFENSE INFORMATION SYSTEMS NETWORK (DISN) RESPONSIBILITIES
References: See Enclosure E.
1. Purpose. This instruction establishes policy and responsibilities for the connection of information systems (ISs) (e.g., applications, enclaves, or outsourced processes) and unified capabilities (UC) products to the DISN-provided transport (including data, voice, and video) and access to information services transmitted over the DISN (including data, voice, video, and cross-domain (CD)).
a. The policy and responsibilities in this instruction are in accordance with (IAW) the Unified Command Plan (UCP) (reference a), Department of Defense Directive (DODD) 5100.20, “National Security Agency/Central Security Services (NSA/CSS)” (reference b), DODD 5105.19, “Defense Information Systems Agency (DISA)” (reference c), DODD 8000.01, “Management of the Department of Defense Information Enterprise” (reference d), DODD 8500.01E, “Information Assurance (IA)” (reference e), Department of Defense Instruction (DODI) 8100.04, “DOD Unified Capabilities (UC)” (reference f), DODI 8500.2, “Information Assurance (IA) Implementation” (reference g), DODI 8510.01, “DOD Information Assurance Certification and Accreditation Process (DIACAP)” (reference h), DODI 8410.02, “NETOPS for the Global Information Grid (GIG)” (reference i), DODI 8551.1, “Ports, Protocols and Services Management (PPSM)” (reference j), and Chairman of the Joint Chiefs of Staff Instruction (CJCSI)
6510.01 Series, “Information Assurance (IA) and Support to Computer Network Defense (CND)” (reference k).
b. Additional policies governing satellite communications are covered in the CJCSI 6250.01 Series, “Satellite Communications” (reference l).1
c. Policy on sensitive compartmented information (SCI) is covered in Intelligence Community Directive (ICD) 503, “Intelligence Community
1 https://ca.dtic.mil/cjcs_directives/cdata/limited/6250_01.pdf
Directive Current as of 4 August 2015
CJCSI 6211.02D
24 January 2012
Information Technology Systems Security Risk Management, Certification and Accreditation” (reference m).
2. Cancellation. CJCSI 6211.02C Series, “Defense Information Systems Network (DISN): Policy and Responsibilities” (reference n) and CJCSI 6215.01C Series, “Policy for Department of Defense Voice Networks with Real Time Services (RTS)” (reference o), are canceled.
3. Applicability. This instruction applies to:
a. The Joint Staff, combatant commands, Services, Defense agencies, and Department of Defense (DOD) field and joint activities, including DOD and Service Nonappropriated Fund Instrumentalities (hereafter referred to as CC/S/As).
b. Mission partners and defense contractors connecting to or using DISN-provided transport or information services transmitted over DISN.
c. Instruction Scope:
(1) DISN-provided transport and information services including, but not limited to, the Nonsecure Internet Protocol Router Network (NIPRNET), SECRET Internet Protocol Router Network (SIPRNET), DISN voice services (i.e., Defense Switched Network (DSN), Defense Red Switch Network (DRSN), Voice over Internet Protocol (VoIP), and Voice over Secure Internet Protocol (VoSIP)), DISN Video Services (DVS), Enhanced Mobile Satellite Services (EMSS), and DISN- Leading Edge Services (DISN-LES).
(2) UC products (hardware and software) and end-to-end voice, video, data, and application services funded or operated by the CC/S/As, authorized mission partners, or by defense contractor users IAW DODI 8100.04 (reference f).
(3) ISs and networks connected to DISN-provided transport and/or information services IAW the “DISN Connection Process Guide” (reference p).
(4) Outside Instruction Scope. Information technology (IT), security, connection, and DOD Chief Information Officer (CIO) waiver requirements for non-DISN DOD networks such as the Defense Research Engineering Network (DREN), SECRET Defense Research Engineering Network (SDREN), Combined Enterprise Regional Information Exchange System (CENTRIXS), or other DOD networks (e.g., standalone or training enclaves) not connected to the DISN are outside the scope of this instruction. For guidance on these networks, contact the DOD CIO and/or network owners (e.g., Under Secretary of Defense for Acquisition, Technology, and Logistics (USD(AT&L)) for DREN and SDREN).
For information on multinational networks, see DODI 8110.1, “Multinational
Information Networks Implementation” (reference q), or CJCSI 6285.01, “Multinational Information Sharing (MNIS) Operational Systems Requirements Management Process” (reference r).
4. Policy. See Enclosure B.
5. Definitions. See Glossary. Major source documents for definitions in this instruction are Joint Publication (JP) 1-02, “DOD Dictionary of Military and Associated Terms” (reference s), and Committee on National Security Systems Instruction (CNSSI) 4009, “National Information Assurance Glossary” (reference t).
6. Responsibilities. See enclosures C and D.
7. Summary of Changes
a. Replaces the policy and responsibilities previously published in CJCSI 6211.02C (reference n) and CJCSI 6215.01C (reference o).
b. Updates Joint Staff responsibilities based on disestablishment of the Command, Control, Communications and Computer Systems Directorate (J-6).
c. Removes specific process steps and procedures for connection to and management of DISN-provided transport and information services;
performance measurement standards in terms of management thresholds and performance objectives; and implementation guidance supporting engineering solutions, which will be maintained and updated as required by the Defense Information Systems Agency (DISA) IAW DODD 5105.19 (reference c).
d. Updates Unified Cross Domain Management Office (UCDMO) roles and responsibilities.
e. Adds guidance on prioritization of CD requirements.
f. Adds guidance on Commercial Internet Services Provider (ISP) Connection Waivers.
g. Removes DISN Security Information Assurance Program enclosure.
Updates guidance based on the Cyber Security Inspection Program, which can be found in CJCSI 6510.01 Series (reference k).
h. Provides guidance on use of commercially-provided transport and information services (Telecommunications Act of 1996 (reference u)).
i. Updates guidance on use of CC/S/A-provided connections (e.g., backside connections) to other DOD entities, mission partners, and defense contractors.
j. Updates guidance on Internet Protocol (IP) tunnels.
k. Replaces the term “non-DOD” with the terms “mission partner” as defined in DODD 8000.01 (reference d) and “defense contractor” as defined in title 41, United States Code, chapter 1, “defense contractor” (reference v).
l. The Department of Defense is in the process of updating terminology for a number of terms used in the current certification and accreditation process.
Both old and updated similarly defined terms are used throughout this instruction. Such similar terms include Designated Accrediting Authority (DAA) with Authorizing Official; certification with security control assessment;
and accreditation with authorization to operate. These terms are all defined in CNSSI 4009 (reference t) terminology.
8. Releasability. This instruction is approved for public release; distribution is unlimited. DOD components (to include the combatant commands), other federal agencies, and the public may obtain copies of this instruction through the Internet from the CJCS Directives Home Page--http://www.dtic.mil/cjcs_directives.
9. Effective Date. This instruction is effective upon receipt.
Enclosures:
A -- DEFENSE INFORMATION SYSTEMS NETWORK (DISN) BACKGROUND
B -- POLICY
C -- JOINT STAFF, COMBATANT COMMAND, SERVICE, DEFENSE
AGENCY, DOD FIELD ACTIVITY, AND JOINT ACTIVITY SPECIFIC
RESPONSIBILITIES
D -- JOINT STAFF, COMBATANT COMMAND, SERVICE, DEFENSE
AGENCY, DOD FIELD ACTIVITY, AND JOINT ACTIVITY COLLECTIVE
RESPONSIBILITIES
E -- REFERENCES
CRAIG A. FRANKLIN
Major General, USAF Vice Director, Joint Staff i
DISTRIBUTION
A, B, C, and JS-LAN plus the following:
Copies
Chief Information Officer, Department of Defense Under Secretary of Defense for Intelligence Commandant of the Coast Guard Director, Defense Security Service
OPR for the subject directive has chosen electronic distribution to the above organizations via e-mail. The Joint Staff Information Management Division has responsibility for publishing the subject directive to the SIPR and NIPR Joint Electronic Library Web sites.
ii
(INTENTIONALLY BLANK)
iii
TABLE OF CONTENTS
Page
ENCLOSURE A -- DEFENSE INFORMATION SYSTEMS
NETWORK (DISN) BACKGROUND
DISN ...................................................................................................... A-1 DISN and the Global Information Grid (GIG) ........................................... A-2
ENCLOSURE B -- POLICY
DISN Management.................................................................................. B-1 DISN Connection .................................................................................... B-2 Minimize ................................................................................................ B-5 DISN Voice Precedence ........................................................................... B-5 Computer Network Defense Service Providers (CNDSPs).......................... B-5 Cross Domain (CD) Connections ............................................................. B-6 Cyber Security Inspection Program (CSIP) and Monitoring ...................... B-6 Official and Authorized Use of the DISN .................................................. B-7 Records Management ............................................................................. B-7
ENCLOSURE C -- JOINT STAFF, COMBATANT COMMAND, SERVICE,
DEFENSE AGENCY, DOD FIELD ACTIVITY, AND JOINT ACTIVITY SPECIFIC
RESPONSIBILITIES
Joint Staff .............................................................................................. C-1 Combatant Commanders ........................................................................ C-2 Commander, U.S. Special Operations Command (CDRUSSOCOM) .......... C-3 Commander, U.S. Strategic Command (CDRUSSTRATCOM) ................... C-4 Service Chiefs ......................................................................................... C-5 Director, Defense Information Systems Agency (DISA) ............................. C-7 Director, Defense Intelligence Agency (DIA) ........................................... C-12 Director, National Security Agency (NSA)/Central Security Service (CSS) ..................................................................... C-12 Director, Defense Security Service (DSS) ............................................... C-13 Director, Unified Cross Domain Management Office (UCDMO) .............. C-14 DISN Related Panel, Boards, and Working Groups ................................ C-16
ENCLOSURE D -- JOINT STAFF, COMBATANT COMMAND, SERVICE,
DEFENSE AGENCY, DOD FIELD ACTIVITY, AND JOINT ACTIVITY
COLLECTIVE RESPONSIBILITIES
DISN-Provided Transport and Information Services Responsibilities ................................................................................ D-1 DISN Connection Responsibilities .......................................................... D-2 Owned/Leased Telecommunications Equipment and Services ............................................................................................ D-3 Cyber Security Inspection Program (CSIP) and Monitoring ..................... D-4 Cross-Domain Information Transfer Responsibilities.............................. D-6 Cross-Domain Requirement Prioritization .............................................. D-9 iv
DOD Information Assurance Risk Management Framework (i.e., DIACAP) ...................................................................................D-10 Security Control Assessment (Certification) and Authorization to Operate (Accreditation) Reciprocity ........................D-10 Approval for Mission Partner and Defense Contractor Connections to the DISN .................................................................D-11 Commercial Internet Service Provider (ISP) Connection Waiver ............................................................................................D-13 Commercial ISP Connection Waiver for ISP Connections Not Connected to the DISN ..............................................................D-15 Improper Commercial ISP Connection Implementation .........................D-17 Support to Civil-Military Operations .....................................................D-17 CC/S/A Provided Connections to Other DOD Entities, Mission Partners, and Defense Contractors ..........................................D-19 Use of Tunneling ..................................................................................D-20 DISN Voice Precedence .........................................................................D-22 JWICS Connection Process Requests ....................................................D-24 Official and Authorized Use of the DISN ................................................D-24
ENCLOSURE E -- REFERENCES
References .............................................................................................. E-1
GLOSSARY
Part I -- Abbreviations and Acronyms ................................................... GL-1 Part II -- Definitions .............................................................................. GL-7
TABLES
D-1. Voice Precedence Request Approval..............................................D-23
A-1 Enclosure A
ENCLOSURE A
DEFENSE INFORMATION SYSTEMS NETWORK (DISN) BACKGROUND
1. DISN. The DISN is a composite of DOD-owned and leased subsystems and networks. It is DOD’s worldwide enterprise-level infrastructure providing end-to-end information transfer in support of DOD operations. The DISN facilitates information resource management and supports national security as well as DOD needs. It also furnishes network services to DOD installations and deployed forces. Those services include data, voice, video, CD, messaging, and other unified capabilities along with ancillary enterprise services such as directories. The DISN is comprised of three segments: sustaining base, DISN transport, and deployed infrastructure.
a. The sustaining base infrastructure (i.e., base, post, camp, station, and enclaves) interfaces with the DISN-provided transport infrastructure to support strategic/fixed environment user requirements within the CC/S/A base infrastructures and deployed warfighter. The sustaining base infrastructure is the responsibility of the CC/S/A.
b. DISN-provided transport infrastructure delivers information transfer services between CC/S/A installations and facilities; connections to external mission partners and defense contractors; and connections to the deployed infrastructure (e.g., warfighter) is the responsibility of DISA.
c. The deployed warfighter and associated Combatant Commander’s infrastructure support the Joint Task Force and/or Combined Task Force. The combatant command and subordinate Service components have primary responsibility for the deployed warfighter and associated infrastructure within the theater.
d. The DISN provides the transport infrastructure and makes available a common set of enterprise services necessary to meet operational requirements.
e. DISN information transfer facilities support secure transport requirements and services for sub-networks such as the NIPRNET, SIPRNET, DISN voice transport and information services (e.g., DSN, DRSN, and UC), DVS Network, EMSS, DISN-LES, and other government agency networks.
A-2 Enclosure A
f. The DSN and DRSN are worldwide private-line voice sub-networks of the DISN that provide non-secure and secure services to authorized users between the CC/S/A sustaining base and deployed warfighter infrastructures via the DISN provided transport infrastructure.
g. DISN is designated as a mission critical and mission assurance category (MAC) I (e.g., High) national security system (NSS). The DISN and its sub-networks (including, but not limited to NIPRNET, SIPRNET, DISN Voice, and video services (i.e., DSN, DRSN, VoIP, and VoSIP), DVS, EMSS, and DISN-LES) must be operated to meet criteria established in DISA Circular 310-130-2, “Communications Requirements” (reference w), and protected IAW DODD 8500.01E (reference e) and other 8500 Series issuances.
2. DISN and the Global Information Grid (GIG). The DISN infrastructure is an integral part of the GIG.
a. GIG 2.0 is the DOD effort to evolve the GIG, including the DISN infrastructure, into a seamless, single information environment optimized for the warfighter to achieve and maintain the information advantage as a critical element of national power (GIG 2.0 Concept of Operations (CONOPS) (reference x)).
b. This single information environment will provide an agile and flexible infrastructure that supports military operations while under duress and is capable of rapid configuration change across the terrestrial, space, and aerial layers.
c. Future DISN-provided transport and information services will be developed to support the seamless integration of GIG 2.0 to satisfy tactical service requirements to the warfighter.
B-1 Enclosure B
ENCLOSURE B
POLICY
1. DISN Management
a. The Department of Defense shall use DISN-provided transport to satisfy DOD information transfer requirements between DOD installations and facilities, and for external connections to mission partner and defense contractor ISs and networks IAW DODI 8100.04 (reference f).
b. Current warfighter requirements for DISN-provided transport and information services are documented in the GIG 2.0 Initial Capabilities Document (ICD) (reference y).
c. The DISN shall be managed, operated, and defended as part of a unified DOD information enterprise as an integral component of DOD information networks IAW DODD 8000.01 (reference d), DODI 8500.2 (reference g), and consistent with DODI 8410.02 (reference i).
(1) Direction of DOD information networks operations and defense shall be IAW the UCP (reference a).
(2) DISN-provided transport and information services shall employ:
(a) Certified information assurance (IA) personnel IAW DODD 8570.01, “Information Assurance Training, Certification and Workforce Improvement” (reference z).
(b) Strict change management processes and procedures to implement security requirements contained in applicable Security Technical Implementation Guides (STIGs).
(c) Only those IP protocols, data services, and associated ports that have undergone a vulnerability assessment and authorization process IAW DODI 8551.01 (reference j).
(d) IS configuration approved in the Interoperability Certification letter IAW CJCSI 6212.01, “Interoperability and Supportability of Information Technology and National Security Systems” (reference aa) and the DOD Information Assurance Certification and Accreditation Process (DIACAP) package.
B-2 Enclosure B
(3) UC equipment and software that are leased, procured (whether ISs or services), or operated by the CC/S/As shall be in compliance with Unified Capabilities Requirements (UCR) (reference bb) as specified in DODI 8100.04 (reference f), or have an approved Information Support Plan IAW DODI 4630.8, “Procedures for Interoperability and Supportability of Information Technology (IT) and National Security Systems (NSS)” (reference cc) that includes UC equipment or products.
(4) CC/S/As shall procure or operate UC products listed on the DOD UC Approved Products List (APL),2 as applicable, unless granted an exception to policy IAW DODI 8100.04 (reference f).
(5) Supply Chain Risk Management (SCRM) will be instituted using the process IAW Directive-Type Memorandum (DTM) 09-016, 25 March 2010, “Supply Chain Risk Management (SCRM) to Improve the Integrity of Components Used in DoD Systems” (reference dd).
2. DISN Connection
a. All connections to the DISN shall be IAW the DISN Connection Process Guide (reference p).3
b. DOD ISs
(1) DOD ISs connected to the DISN-provided transport and information services or commercial transport must be authorized to operate IAW applicable guidance and processes including, but not limited to, DODI 8510.01 (reference h), DODI 8100.04 (reference f), or ICD 503 (reference m)). This includes DOD-owned ISs and ISs operated on behalf of the Department of Defense (e.g., contract, memorandum of agreement (MOA), or memorandum of understanding (MOU)) that receive, process, store, display, or transmit DOD information, regardless of classification or sensitivity.
(2) DOD ISs must be registered in the DOD Information Technology Portfolio Repository (DITPR) (i.e., DITPR NIPRNET or SIPRNET IT Registry application) by the responsible CC/S/A prior to connection IAW DOD CIO memorandum, “DOD IT Portfolio Repository (DITPR) and DOD SIPRNET IT Registry Guidance” (reference ee).
2 http://www.disa.mil/ucco/ 3 http://www.disa.mil/connect/
B-3 Enclosure B
(3) DOD ISs connected to the DISN-provided transport capability shall be discoverable, assessable, operated, and managed securely through continuous compliance, monitoring, and risk management IAW DODI 8500.2 (reference g).
c. Mission Partner and Defense Contractor ISs
(1) Mission partner and defense contractor ISs connected to the DISN shall be authorized to operate IAW applicable federal, Intelligence Community (IC), or DOD guidance and processes. For example, defense contractor unclassified ISs operating on behalf of the Department of Defense would comply with DOD 8510.01 (reference h), federal mission partners not identified as an NSS would comply with National Institute of Standards and Technology (NIST) Special Publication (SP) 800-37, “Guide for Applying Risk Management Framework to Federal Information Systems” (reference ff), IC entities would comply with ICD 503 (reference m), and defense contractor ISs that process classified information would comply with DODI 5220.22, “National Industrial Security Program (NISP)” (reference gg) for defense contractor ISs.
(2) Non-U.S. mission partner and defense contractor (when applicable) access to DOD information must be in compliance with DODD 5230.11, “Disclosure of Classified Military Information to Foreign Governments and International Organizations” (reference hh), the International Traffic in Arms Regulations (ITAR) (reference ii), and the Export Administration Regulations (EAR) (reference jj).
(3) Defense contractor and other mission partner ISs operating on behalf of the Department of Defense (e.g., contract or MOA) must be registered in the DITPR (NIPRNET or SIPRNET instance) by the sponsoring CC/S/A prior to connection.
(4) CC/S/A must include documentation and artifacts equivalent in detail and scope to those provided by DOD entities in the request for a direct or indirect connection to the DISN IAW DISN Connection Process Guide (reference p).
(5) All mission partner and defense contractor connections to DISN-provided transport and information services require a sponsoring CC/S/A and a separate connection request. Mission partner and defense contractor system access must be limited only to the information and services required to execute the DOD-approved mission.
B-4 Enclosure B
(6) All connection requests for a mission partner or defense contractor IS to the DISN-provided transport and information services must be endorsed, validated, and submitted by the CC/S/A IAW the DISN Connection Process Guide (reference p) and the Defense IA Security Accreditation Working Group (DSAWG), DISN/GIG Flag Panel processes.
(7) Defense contractor ISs connected to the DISN-provided transport and information services must comply with connection guidelines issued by this instruction and DISA as the operating entity. In addition, if the defense contractor ISs are classified, they must comply with DOD 5220.22-M, “National Industrial Security Program Operating Manual” (reference kk).4
d. CC/S/As will register5 IS connection information as required IAW the DISN Connection Process Guide (reference p).
e. Use of non-DISN commercial transport as an alternative to DISN-provided transport requires a GIG Waiver Panel (GWP) approved Commercial ISP Connection Waiver. See paragraphs 10 and 11 of Enclosure D on Commercial ISP Connection Waivers.
f. Site inspection, remote scanning, acceptable authorized security posture (DODI 8510.01 (reference h)), and providing computer network defense (CND) services IAW DODD O-8530.1, “Computer Network Defense (CND)” (reference ll), are conditions for a DOD IS, mission partner IS, or defense contractor IS to obtain and retain an authority to connect (ATC) or interim authority to connect (IATC) IAW the DISN Connection Process Guide (reference p).
g. Mission partner or defense contractor IS connection to DISN-provided transport and information services must be through an established DISN Demilitarized Zone (DMZ) (e.g., FED DMZ) and will follow DISN DMZ security requirements.
4 DSS is the authorizing official (DAA) for contractor classified ISs under the authority of DODI
5220.22 (reference gg) and the DOD 5220.22-M (reference kk). CC/S/As are the authorizing official (DAA) for contractor unclassified ISs under the authority of DODI 8510.01 (reference h).
5 Network Information Center (www.nic.mil) for all unclassified information; SIPRNET Support Center (www.ssc.smil.mil) for all classified information; Systems/Network Approval Process (SNAP) (https://snap.dod.mil) for unclassified voice, video, data circuit registrations and connections, unclassified voice switches; and DOD CIO GIG Waivers for Internet Service Provider registration; SIPRNET GIG Interconnection Approval Process (GIAP) System (SGS) (https://pnp.cert.smil.mil) for classified voice, video, data circuit registrations and connections;
and cross domain solution (CDS) deployments; and Ports, Protocols, and Services Management (PPSM) (https://pnp.cert.smil.mil) on SIPRNET for all networks/systems ports, protocols, and services for all IP solutions or applications, including VoIP and VoSIP.
B-5 Enclosure B
3. Minimize. The Department of Defense will utilize means available (user or technical) to reduce (i.e., minimize) and/or remove nonessential data, voice, and video communications traffic during times of surge or crisis as required to ensure communications availability to meet DOD mission requirements.6
a. Controls on users or communications can include, but are not limited to, blocking, routing, usage, or availability controls to ensure prompt transmission of communications traffic in support of mission requirements.
b. The directive to implement minimize shall indicate the type of communications traffic to be reduced and/or removed.
4. DISN Voice Precedence7
a. All DISN service requests for voice precedence requirements must be forwarded through the requestor’s chain of command to the appropriate approval authority (see Enclosure D).
b. The use of IMMEDIATE and PRIORITY precedence by DOD personnel assigned to non-U.S. (foreign government adviser, United Nations (UN), North Atlantic Treaty Organization (NATO), etc.) organizations must be approved by the appropriate CC/S/A. Requests for FLASH or FLASH OVERRIDE must be validated by the appropriate CC/S/A and approved by the Joint Staff.
c. Temporary upgrading of voice precedence to support CC/S/As or other equivalent personnel during travel is authorized for all precedence levels for up to 30 days. Temporary upgrading is also authorized for emergencies and exercises. Requests must be coordinated with DISA and approved by the combatant command.
d. Approvals of FLASH and FLASH OVERRIDE access must be provided to DISA and the Joint Staff J-8.
5. Computer Network Defense Service Providers (CNDSPs)
a. DOD ISs connected to the DISN-provided transport and information services must be aligned to an accredited CNDSP IAW DODD O-8530.1 (reference ll) prior to connection.
6 MINIMIZE is a condition wherein normal data, voice, and video communications traffic is drastically reduced in order that communications traffic connected with an actual or simulated emergency shall not be delayed.
7 In communications, a priority of importance designation is assigned by the originator.
B-6 Enclosure B
b. For mission partner and defense contractor ISs, the sponsoring CC/S/A must ensure a signed agreement (e.g., MOA) or contract defines the CNDSP requirements, requirements specified in DODD O-8530.1 (reference ll), are included in the agreement, and these CNDSP requirements are implemented prior to connection.
6. Cross Domain (CD) Connections
a. Enterprise CD services or centralized cross domain solutions (CDSs) will be used for automated DOD CD information transfer requirements.
b. Point-to-point CDSs will only be used when an enterprise service or centralized CDS does not meet CC/S/A operational mission requirements.
c. Enterprise CD services, centralized CDSs, and point-to-point CDSs will employ CDSs from the Cross Domain Baseline, unless an exception letter or a Plan of Action and Milestones (POA&M) is approved through the Cross Domain Resolution Board (CDRB), DSAWG, and DISN/GIG Flag Panel.
d. Life-cycle security management of cross domain security configurations is required. In non-enterprise operating environments, the target Regional or Point-to-Point CDS hosting environment must identify (appoint in writing) individual(s) responsible to oversee the day-to-day security management, configuration, and established information transfer processes. This (or these) individual(s) are responsible for reporting security incidents to the local/site Information Assurance Manager.
e. DISN connections among ISs of different security domains internal to the DOD and external (e.g., mission partner) will be IAW this instruction, DODD 8500.01E (reference e), DODD O-8530.1 (reference ll), and other applicable DOD issuances and instructions. Connections to SCI ISs must be IAW ICD 503 (reference m).
f. Any environment operating under IC governance with connections to a collateral DISN system will be documented in the collateral DOD IS’s security authorization package and require approval from both DOD and IC connection governance processes.
7. Cyber Security Inspection Program (CSIP) and Monitoring
a. ISs connected to DISN-provided transport and information services are subject to the CSIP IAW CJCSI 6510.01 (reference k). This includes a tiered program of vulnerability assessments, Blue Team Vulnerability Evaluations and Intrusion Assessments, cyber security inspections, and Red Team operations to provide a systemic view of enclave and IS technical and traditional security posture. Inspection risk findings may lead to
B-7 Enclosure B organizational or individual sanctions to include potential disconnection of ISs from DISN-provided transport and information services.
b. ISs connected to DISN-provided transport and information services are subject to electronic monitoring for communications management, configuration management, situational awareness, and network security. This includes on-site and remote vulnerability inspections to check configuration for compliance with STIGs and other IA standards and guidelines.
c. Defense contractor systems operating under the NISP will adhere to the policies, procedures, and standards established under the NISP.
8. Official and Authorized Use of the DISN. The DISN and connected DOD ISs will be used for official and authorized purposes IAW DOD Regulation 5500.7-R, “Joint Ethics Regulation (JER)” (reference mm)8 and DTM 09-026, “Responsible and Effective Use of Internet-Based Capabilities” (reference nn).
9. Records Management. Electronic records stored on or pertaining to the DISN will be managed IAW title 44, United States Code, Chapters 31, 33, and 41 (reference oo); DODD 5015.2, “DOD Records Management” (reference pp);
DOD 5015.02-STD, “Electronic Records Management Software Applications Design Criteria Standard” (reference qq), and CJCSI 5760.01 Series, “Records Management Policy for the Joint Staff and Combatant Commands” (reference rr).
8Federal government communication systems and equipment (including government-owned telephones, facsimile machines, electronic mail, Internet systems, and commercial systems when use is paid for by the federal government) shall be for official use and authorized purposes only.
B-8 Enclosure B
C-1 Enclosure C
ENCLOSURE C
JOINT STAFF, COMBATANT COMMAND, SERVICE, DEFENSE AGENCY, DOD
FIELD ACTIVITY, AND JOINT ACTIVITY SPECIFIC RESPONSIBILITIES
1. Joint Staff. The Chairman of the Joint Chiefs of Staff is responsible for developing DISN joint policy IAW DODD 8500.01E (reference e), DODI 8100.04 (reference f), DODI 8510.01 (reference h), and DODD 8115.01, “Information Technology Portfolio Management” (reference ss), and facilitating communications with Combatant Commanders to improve the adequacy and effectiveness of communications, command and control, IA, computing services, interoperability and standardization, DOD enterprise services, engineering, and acquisition functions IAW DODD 5105.19 (reference c).
a. The Director for Operations, J-3 shall:
(1) Advise the Chairman on the responsiveness and readiness of the DISN to support command and control of operating forces in the event of war or threats to national security in coordination with J-8 and United States Strategic Command (USSTRATCOM).
(2) Advise and recommend, when appropriate, implementation of communications traffic controls (MINIMIZE) to ensure National Military Command System (NMCS) communications availability for mission requirements IAW CJCSI 3280.01, “National Military Command System (U)” (reference tt).
b. The Director for Force Structure, Resources, and Assessments, J-8 shall:
(1) Advise the Chairman on command, control, communications, and computer and information systems requirements and priorities in coordination with DOD CIO.
(2) Provide advice and assistance to the Joint Staff directorates and combatant commands on DISN policy and responsibilities to include obtaining approval to connect to DISN (e.g., mission partners or defense contractors), CD transfer requirements, and DOD information networks.
(3) Review DISN planning and programming documents and assess their responsiveness to operational, developmental, and training requirements.
(4) Review and approve or disapprove all requests for FLASH and FLASH OVERRIDE DSN/DRSN service after validation by a Combatant Commander, C-2 Enclosure C
Service Chief, or Director of a Defense Agency.
(5) Serve as the Warfighting Mission Area (WMA) Principal Accrediting Authority (PAA) for the Chairman IAW DODI 8510.01 (reference h).
(6) Appoint a flag-level WMA PAA9 representative to the DISN/GIG Flag Panel.
(7) Appoint a representative in the military grade of O-5/O-6 or U.S.
government (USG) civilian equivalent as primary representative to the GWP and USG alternates with GWP voting authority.
(8) Appoint a representative in the military grade of O-6 (e.g., Colonel) or USG civilian equivalent as primary representative to the DSAWG and USG alternates with Service DSAWG voting authority.
c. The Joint Staff CIO shall implement applicable responsibilities in Enclosure D for Joint Staff networks.
2. Combatant Commanders. In addition to responsibilities outlined in Enclosure D, the Combatant Commanders shall:
a. Approve the connection and subsequent operation of deployed ISs within combatant command information networks and the connection to DISN sites providing DISN transport and information services to local infrastructure. This approval to operate by the Combatant Commander must be included in the DISN connection approval request package submitted to DISA.
b. Endorse and validate combatant command CD, mission partner, and defense contractor DISN connection requests in support of mission
c. Review and submit service restoration priority requests IAW with DISA Circular 310-130-4, “Defense User’s Guide to the Telecommunications Service Priority (TSP) System” (reference uu).
d. Submit DISN-provided transport and information services requirements through designated Service Executive Agent channels to DISA IAW DODD 5100.03, “Support of the Headquarters of Combatant and Subordinate Unified Commands” (reference vv).
9 DOD PAAs are appointed for the four GIG mission areas (MAs) consisting of the WMA, the Enterprise Information Environment MA (EIEMA), the Defense Intelligence MA (DIMA), and the Business Mission Area (BMA).
C-3 Enclosure C
e. Minimize
(1) Plan for the implementation of communications traffic controls (user or technical) for their commands or area of command responsibility during surges or crisis (actual or simulated).
(2) Direct implementation of communications traffic controls during surges or crisis (actual or simulated) for their commands, area of command responsibility, or functional area with notification to National Military Command Center (NMCC), USSTRATCOM, CC/S/As, other USG agencies, and foreign mission partners as deemed appropriate.10
f. Cross Domain Responsibilities. If a combatant command does not designate a Cross Domain Support Element (CDSE) or an existing office to carry out combatant command CD responsibilities outlined in Enclosure D, the combatant command shall:
(1) Request CD support from the combatant command’s Service Executive Agent IAW DODD 5100.03 (reference vv) or another CC/S/A CDSE.
(2) Develop an MOA outlining combatant command and supporting CDSE responsibilities (Enclosure D), including the life-cycle costs, sustainment, and management of any combatant command-directed CDS implementation support.
g. Provide USSTRATCOM and DISA read access to combatant command level vulnerability management ISs (e.g., Vulnerability Management System (VMS)), as requested.
h. Approve or disapprove outside the United States local commander requests for DSN voice service (personal or unofficial use). Notify DISA DSN Program Management Office (PMO) of approvals.
i. Review and revalidate secure voice conference requirements annually.
3. Commander, U.S. Special Operations Command (CDRUSSOCOM). In addition to the responsibilities outlined in paragraph 2 (above) and Enclosure D, the CDRUSSOCOM shall:
a. Coordinate with theater combatant commands and their supporting Service Components for required IS support at theater installation(s).
b. Submit DISN-provided transport and information services requirements directly to DISA, as required. If service requirement is for a CDS, provide a courtesy copy to the UCDMO.
10 Emergency Action Procedures -- CJCS Volume IX (CJCS LERTCON Procedures) (U) (reference ww).
C-4 Enclosure C
4. Commander, U.S. Strategic Command (CDRUSSTRATCOM). In addition to the responsibilities outlined in paragraph 2 (above) and Enclosure D, the CDRUSSTRATCOM shall:
a. Direct DOD information networks operations and defense of DOD information network including the DISN and synchronize cyberspace operations planning in coordination with CC/S/As IAW the UCP (reference a).
b. Delineate U.S. Cyber Command (USCYBERCOM) roles and responsibilities to plan, coordinate, and direct DISN network operations and defense.
c. Issue USSTRATCOM warning and tactical orders and directives11 through USCYBERCOM to provide instructions on the operation and defense of DISN IAW UCP (reference a).
d. Prioritize Service and combatant command CD information transfer requirements based on impact description provided by the combatant command or Service’s ability to execute assigned mission(s) in support of the National Military Strategy (reference xx).
e. Minimize
(1) Plan for the implementation of certain communications traffic controls worldwide during surges or crisis (actual or simulated) in coordination with Joint Staff (NMCC).
(2) Direct worldwide implementation of communications traffic controls during surges or crisis (actual or simulated) as authorized or directed with notification to NMCC, CC/S/As, other USG agencies, and foreign mission partners as deemed appropriate.
f. Direct Command Cyber Readiness Inspections (CCRIs) of DOD DISN-provided transport and information services and connected ISs IAW the
USSTRATCOM/USCYBERCOM CSIP.
g. Monitoring Connections
11 Currently USSTRATCOM-issued warning and tactical orders and directives include alert orders (ALERTORDs), deployment orders (DEPORDs), execute orders (EXORDs), fragmentary orders (FRAGOs), IA Vulnerability Notices, operations orders (OPORDs), planning orders (PLANORDs), tasking orders (TASKORDs), and warning orders (WARNORDs). Previous issued orders and directives include Communications Tasking Orders (CTOs), Coordination Alert Messages (CAMs), GIG Vulnerability Bulletins, Network Defense Tasking Messages (NDTMs), and Operational Directive, Message (ODM).
C-5 Enclosure C
(1) Coordinate with CC/S/As on monitoring of connected enclaves.
(2) Issue procedures for coordination and notification of USSTRATCOM-directed remote compliance monitoring and scanning of CC/S/A ISs.
(3) USSTRATCOM -directed scanning pre-notification may be in the form of notices posted to a designated USSTRATCOM SIPRNET Web site or direct USSTRATCOM communications to the Authorizing Official (DAA).
h. DISN Related Panels, Boards and Working Groups
(1) Appoint a flag-level chair for the DISN/GIG Flag Panel.
(2) Appoint a representative in the military grade of O-5/O-6 or USG civilian equivalent as primary representative to the GWP and USG alternates with GWP voting authority.
(3) Appoint a representative in the military grade of O-6 or USG civilian equivalent as primary representative to the DSAWG and USG alternates with USSTRATCOM DSAWG voting authority.
(4) Appoint a representative in the military grade of O-6 or USG civilian equivalent representative to the CDRB.
5. Service Chiefs. In addition to responsibilities outlined in Enclosure D, the Service Chiefs shall:
a. Provide communications capability to meet combatant command validated connectivity requirements, including combatant command DISN connectivity through DISN collection and distribution sites for both deployed and garrison local infrastructures. ISs must be focused on supporting operational requirements of the combatant command or parent Service and be capable of supporting contingency operations.
b. Approve the connection of tenant ISs to base/post station transport and services and to DISN provided transport and services. This approval to operate by the Service must be included in the DISN connection approval request package submitted to DISA and ensure an MOA is established to provide CND services for these connections.
c. Implement CSIP teams to conduct Service cyber security inspections, Blue Team Vulnerability Evaluations and Intrusion Assessments, and vulnerability assessments of Service ISs connected to DISN-provided transport and information services.
C-6 Enclosure C
d. In addition to the responsibilities outlined in Enclosure D, Services will perform the following tasks in support of Service CD information transfer requirements:
(1) Designate a CDSE to work on Service CD activities and issues with the UCDMO.
(2) Support Security Test and Evaluation (ST&E) of CDSs IAW DOD and IC guidance to implement security controls as required.
(3) As Service Executive Agent IAW DODD 5100.03 (reference vv), when requested by combatant command, provide CD support service per Enclosure D. An MOA or MOU outlining combatant command and supporting Service CDSE responsibilities is required and shall address the life cycle costs, sustainment, and management of any combatant command-directed CDS.
e. Provide requisite site support for DISN equipment located on bases, posts, camps, and stations. This includes providing power, physical security, floor space, and onsite coordination for the DISN network points of presence (POPs) on these bases, posts, camps, and stations. Site support must be specified in procedural documentation and coordinated between the Service Headquarters and DISA Headquarters.
f. Identify, assess, and document the DISN assets and associated dependencies needed to implement required CC/S/A mission-essential tasks and required capabilities in coordination with DISA.
g. Provide Headquarters of Combatant and Subordinate Unified Commands administrative and logistical support (i.e., base operating support including engineering documentation for transport and services, submissions for DISN-provided transport and services, and necessary infrastructure) IAW DODD
5100.03 (reference vv).
h. DISN Related Panels, Boards, and Working Groups
(1) Appoint a representative in the military grade of O-5/O-6 or USG civilian equivalent as primary representative to the GWP and USG alternates with GWP voting authority.
(2) Appoint a representative in the military grade of O-6 or USG civilian
Service DSAWG voting authority.
C-7 Enclosure C
6. Director, Defense Information Systems Agency (DISA). In addition to responsibilities outlined in Enclosure D, the Director, DISA shall:
a. DISN Management and Operation
(1) Provide DISN-provided transport and information services used for data, voice, video, and cross domain through a combination of terrestrial, aerial, satellite assets, and services IAW DODD 5105.19 (reference c).
Transport services include information transfer services between CC/S/A installations, facilities, and enclaves, for connections to external mission partner and defense contractor ISs and networks, and wide area network information transfer.
(2) Manage process for connection to all DISN-provided transport and information services.12
(3) Direct operation and management of DISN-owned and leased DISN subsystems and networks to meet CC/S/A operational requirements.
(4) Maintain configuration management of the DISN-provided transport and information services.
(5) Implement and coordinate the necessary actions to provide end-to-end responsibility, management, and operations of DISN telecommunications and UC.
(6) Prescribe the threshold and objective performance metrics that will be used for the DISN-provided transport and information services in DISA Circular 310-130-2, (reference w) and based on UCR (reference bb).
(7) Provide dialing and numbering plans for DISN-provided transport and information services.
(8) Specify, coordinate, and document Service support required for DISN equipment located at bases, posts, camps, and stations.
(9) Monitor the effectiveness of the DISN-provided transport and information services in satisfying user requirements and respond to combatant command and Service requests for reports on IS performance.
(10) Perform required system engineering and modeling to achieve the optimal network design and implementation approach.
12 DISA connection process can be found at http://www.disa.mil/connect/ on (NIPRNET) and http://www.disa.smil.mil/connect/ on (SIPRNET).
C-8 Enclosure C
(11) Identify and promulgate performance standards, security implementation guidance (i.e., STIG), and supporting engineering solutions for DISN-provided transport and information services (e.g., availability and response time), and mission survivability requirements based on the Joint Staff validated requirements and the UCR (reference bb).
(12) Support the combatant commands in creating a User-Defined Operational Picture for their areas of responsibility (AORs).
(13) Develop process to record the technical and operational characteristics of active connections, in addition to pending and operational CC/S/A CD information transfer requirements.
(14) Assess the technical, programmatic, and operational feasibility of adding new transport and information services capabilities to the DISN as directed by DOD CIO.
(15) Identify technical solutions to close joint capability gaps validated and provided by the Joint Staff with DISN-provided transport and information services.
(16) Establish and operate a contingency response capability to allow for rapid extension of DISN-provided transport and information services into regions around the world to support DOD contingency operations.
(17) Identify existing non DISN-provided transport and information services utilized by CC/S/As and provide recommendations on those services, which could be incorporated into future DISN-provided transport and information services capabilities.
(18) Provide program objective memorandum recommendations with cost data to CC/S/As including UC Master Plan with UC migration strategy, transition engineering solutions, and recommendations for the modernization of DISN-provided transport and information services IAW DODI 8100.4 (reference f).
(19) Publish a catalog of DISN-provided transport and information services and cost-effective and economical rates IAW the Office of the Secretary of Defense cost recovery program based on site subscription fees.13
13 DISA computing services catalogs of service and rates can be found at http://www.disa.mil/computing /index.html and http://www.disa.smil.mil/computing/index.html. The DISN Telecommunications Business Service Catalog can be found at http://disa.mil/ns/customer_service/catalog.html.
C-9 Enclosure C
b. DISN-Provided Transport and Information Services Connection Process
(1) Maintain a DISN Connection Process Guide (reference p) describing steps and requirements for connection to DISN-provided transport and information services IAW DODI 8100.04 (reference f) and DODI 8500.2 (reference g).
(2) Update DISN Connection Process Guide (reference p) IAW DOD CIO issuances and USSTRATCOM warning and tactical orders and directives issued through USCYBERCOM on the operation and defense of the DISN IAW UCP (reference a), as needed.
(3) Process, review, and approve CC/S/A validated DISN connection requests.
(4) Ensure that the connection meets technical and interoperability requirements IAW DODI 4630.8 (reference cc) and CJCSI 6212.01 (reference aa).
(5) Ensure DOD, mission partner, or defense contractor ISs connected to the DISN have authorizations to operate IAW DODI 8510.01 (reference h), for defense contractor classified ISs (DOD 5220.22-M (reference kk)), or other governing policy and process as described in Enclosure B (Paragraph 2).
(6) Track and approve all primary connections/points of presence (POPs) to the…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .