Bidders Library JITC Instructions - JITCI 240-110-05.pdf

PDF 53 KB Posted

Attached to
TEC II Services RFP Federal contract opportunity
Solicitation number
HC102821R0006
Issued by
Defense Information Systems Agency

About this file

This document provides security classification guidance for cybersecurity assessments conducted in support of operational test and evaluation activities. Test procedures, plans, data collected, attack vectors, tools, and reports are required to be classified depending on whether they depict systems residing on SIPRNet or NIPRNet, operational sites providing high system resources, or vulnerabilities. The classification level must be at least Secret unless the system under test is unclassified only, in which case the information can be marked For Official Use Only. Communications must be handled accordingly depending on the classification of the system, data collection, and reporting methods utilized. The related solicitation seeks Test, Evaluation, and Certification services for the Joint Interoperability Test Command under the Defense Information Systems Agency.

View the file

Other files for this federal contract opportunity

Other files attached to TEC II Services RFP, newest first.
File Type Posted
HC102821R0006 Conformed Through amendment 0005.pdf PDF
HC102821R0006 Conformed Through amendment 0004.pdf PDF
HC102821R0006 AMD 0003.pdf PDF
TEC II Bidders Library List.xlsx XLSX spreadsheet
Bidders Library DODI 5000 02t.pdf PDF
Bidders Library DISA I 240 110 36.pdf PDF
Bidders Library Test and Evaluation Scorecard Guidebook Version 3 0 3 Dec 2020.pdf PDF
Bidders Library DISA Form 786.pdf PDF
Bidders Library Security - ICD 701.pdf PDF
Bidders Library Security - ICD 503.pdf PDF
Bidders Library Security - DoD 5220 22-M.pdf PDF
Bidders Library Security - DoDI 5200 01.pdf PDF
Bidders Library Security - DISAI 630-230-19.pdf PDF
Bidders Library Security - DISAI 240-110-33.pdf PDF
Bidders Library Security - DISAI 240-110-38.pdf PDF
Bidders Library Security - DISAI 240-110-43.pdf PDF
Bidders Library Security - DISAI 240-110-37.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 09-14-2010.pdf PDF
Bidders Library Operational Test and Evaluation - DISA Test Evaluation Process Guidebook.docx DOCX document
Bidders Library Operational Test and Evaluation - DoTE MEMO 6-3-2011.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 06-24-2011.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 4-23-2010.pdf PDF
Bidders Library Operational Test and Evaluation - DoDD 5141 02.pdf PDF
Bidders Library JITC Instructions - JITCI 270-95-02.pdf PDF
Bidders Library JITC Instructions - JITCI 630-230-01.pdf PDF
Bidders Library JITC Instructions - JITCI 280-50-01.pdf PDF
Bidders Library JITC Instructions - JITCI 640-50-06.pdf PDF
Bidders Library JITC Instructions - JITCI 630-225-07.pdf PDF
Bidders Library Interoperability Test and Evaluation - JCIDS Manual.pdf PDF
Bidders Library Interoperability Test and Evaluation - JITC IOP Service Area SOP v1 0.pdf PDF
Bidders Library Interoperability Test and Evaluation - DoDI 8320 07.pdf PDF
Bidders Library Interoperability Test and Evaluation - CJCSI 8010 01C.pdf PDF
Bidders Library DoD Policy Instruction and Guidance - DoDI 5134 01.pdf PDF
Bidders Library DoD Policy Instruction and Guidance - DoDD 5105 53.pdf PDF
Bidders Library Cybersecurity - NIST SP 800-53r4.pdf PDF
Bidders Library Cybersecurity - JITC Cyber TE Guidebook.pdf PDF
Bidders Library Security - ICD 703.pdf PDF
Bidders Library Interoperability Test and Evaluation - DOD Dictionary.pdf PDF
Bidders Library Interoperability Test and Evaluation - DoDI 8100 04.pdf PDF
Bidders Library Interoperability Test and Evaluation - NR KPP Evaluation Guidebook.docx DOCX document
Bidders Library Security - ISOO Handbook.pdf PDF
Bidders Library Security - DoDM 5200 01 Vol 1.pdf PDF
Bidders Library Security - DISAI 240-115-04.pdf PDF
Bidders Library Security - DISAI 240-110-35.pdf PDF
Bidders Library Operational Test and Evaluation - JITC OTE Guidebook v2 0.docx DOCX document
Bidders Library Operational Test and Evaluation - DoTE MEMO 10-19-2010.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 10-18-2010.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 6-16-2003.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 04-03-2018.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 1-21-2015.pdf PDF
Show all 50

TEC II Services RFP has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DEFENSE INFORMATION SYSTEMS AGENCY

P. O. BOX 549

FORT MEADE, MARYLAND 20755-0549

UNCLASSIFIED//FOR OFFICIAL USE ONLY ENCLOSURE

DISA CIRCULAR 240-110-5

SECURITY

Cybersecurity Assessments (CSAs) in Support of Operational Test and Evaluation (OT&E)

Security Classification Guide

1. Purpose. This Circular provides security classification guidance for cybersecurity assessments (CSAs) in support of operational test and evaluation (OT&E).

2. Applicability. The Circular applies to all military, civilian, and contractor personnel assigned to or employed by the Joint Interoperability Test Command (JITC) who conduct OT&E activities.

3. Authority.

3.1 This Circular is published in accordance with (IAW) the authority contained in Executive Order (E.O.) 13526, Classified National Security Information Memorandum, 29 December 2009;

DoD Manual (DoDM) 5200.01, Volume 1, DoD Information Security Program: Overview, Classification, and Declassification, 24 February 2012; and DoD Instruction (DoDI) O-3600.02, Information Operations (IO) Security Classification Guidance, 28 November 2005. In case of conflict between E.O. 13526 and DoDM 5200.01, the E.O. takes precedence. In case of conflict between DoDM 5200.01 and DoDI O-3600.02, the DoDM takes precedence.

3.2 This Circular is also published in accordance with the authority contained in DISA Circular (DISAC) 300-110-3, Defense Information Systems Network (DISN) Security Classification Guide, 27 September 2012, and DISAC 300-115-3, Defense Information Systems Network (DISN) Secret Internet Protocol Routing Network (SIPRNet), 1 June 2013. In case of conflict between DoDI O-3600.02 and DISACs 300-110-3 and 300-115-3, the DoDI takes precedence.

3.3 DoDI O-3600.02 takes precedence if there is no classification guide for the system(s) under test.

4. Original Classification Authority (OCA). The Chief of Staff, DISA, has been formally designated, in writing, by the Deputy Secretary of Defense as an OCA and is the OCA for this Circular.

5. Point of Contact. All inquiries concerning this guide and recommended changes to this Circular with supporting rationale should be addressed to the following:

Joint Interoperability Test Command (JITC) Attn: JITC Security Manager P.O. Box 12798 Fort Huachuca, AZ 85670-2798

DISAC 240-110-5

6. Objective of this Circular. The objective of this Circular is to clarify the handling of cybersecurity test procedures, test plans, data collected, and test reports for CSAs conducted during operational test activities. This Circular includes tools used for the collection and reduction of data produced from these activities. This Circular does not supersede current guidance; rather, it amplifies JITC procedures for handling this information and is to be used by JITC if there is no security classification guide for a particular program or system under test.

This Circular supplements DoDM 5200.01 and DoDI O-3600.02 and is to be used in conjunc-tion to obtain complete guidance on a particular subject.

7. Security Classification Guidance. Security classification guidance for CSAs in support of OT&E is provided at the enclosure.

8. Classification and Handling Markings and Downgrading and Declassification.

Classification and/or handling markings and downgrading and declassification will be applied IAW the authority documents. Information identified as classified by provisions of this Circular should be marked as would be appropriate for its classification.

9. Dissemination. Classified and for official use only (FOUO) information must be protected against unauthorized disclosure IAW Presidential guidance and DoD Regulations and Instructions. Dissemination of associated classified and/or sensitive information is addressed in the authority documents.

Enclosure a/s JOEL S. LINDEMAN Colonel, USA Chief of Staff

OPR: JITC JTA - disa.huachuca.jt.list.security-office@mail.mil DISTRIBUTION: For Official Use Only (FOUO)

DISAC 240-110-5

UNCLASSIFIED//FOR OFFICIAL USE ONLY

Enclosure

SECURITY CLASSIFICATION GUIDANCE FOR

CYBERSECURITY ASSESSMENTS (CSAs) IN SUPPORT OF

OPERATIONAL TEST AND EVALUATION (OT&E)

1. Test Procedures.

1.1 (U//FOUO) Test procedures for CSAs that include attack vectors (AVs) or test cases that depict a system that resides on the Secret Internet Router Protocol Network (SIPRNet) will be classified at a minimum of secret.

1.2 (U//FOUO) Test procedures for CSAs that include AVs or test cases that depict a system that resides on the Nonclassified Internet Router Protocol Network (NIPRNet) where the system in a similar but classified form resides on any network with a higher classification level will be classified at a minimum of secret.

1.3 (U//FOUO) Test procedures for CSAs that include AVs or test cases that depict an opera-tional site that provides for system high resources will be classified at a minimum of secret.

2. (U//FOUO) Test Plans. Test plans that depict any of the test procedures specified in paragraph 1 are based on derivative classification. Test plans can be separated to provide an unclassified portion that does not depict any classified information. In this event, a classified annex should be produced to cover the classified material. If the plans are separated, the unclassified portion should be properly marked for classification no lower than unclassified// for official use only.

3. (U//FOUO) Data Collected, Analyzed, and Reported. Data collected, analyzed, and reported during the CSA will be classified no lower than secret. In the event that the system under test is unclassified or if the system is tested on the NIPRNet with no system in similar form residing on a network that provides system high resources, the data can be handled as unclassified//for official use only during collection. In this event, the data must be moved to the secret environment for analysis and reporting in order to provide for cases where an entity would send JITC data on a system or site vulnerability via unclassified or NIPRNet e-mail for analysis on a system.

4. Attack Vectors or Test Cases.

4.1 (U//FOUO) In the event that JITC personnel conduct information gathering in an unclassified environment for AV or test case development, the AV or test case must not depict any system or site. Once the data is compiled, the data will be handled as unclassified// for official use only and then transferred to the secret environment for incorporation into any test artifact.

DISAC 240-110-X

UNCLASSIFIED//FOR OFFICIAL USE ONLY

4.2 (U//FOUO) Any AV or test case used in any CSA activity will be classified at the minimum level of secret.

4.3 (U//FOUO) Any tool containing AVs or test cases that depict a site or system or have been used in any CSA activity will be classified at the minimum level of secret.

4.4 (U//FOUO) Any DoD computer network attack (CNA) capability in which particular technologies, techniques, targets, or concepts are identified will be classified at the minimum level of secret.

5. Reports.

5.1 (U//FOUO) A CSA report containing information on AV or test case results is classified at the minimum level of secret.

5.2 (U//FOUO) A CSA report containing information on vulnerabilities or risk items associated with DoD systems or networks is classified at the minimum level of secret unless the system is unclassified only, in which case the information will be marked unclassified//for official use only.

5.3 (U//FOUO) A CSA report containing information on corrective recommendations for vulnerabilities or risk items associated with DoD systems or networks is classified at the minimum level of secret unless the system is unclassified only, in which case the information will be marked unclassified//for official use only.

5.4 (U//FOUO) A CSA report containing information on exploited vulnerabilities or findings is classified at the minimum level of secret.

5.5 (U//FOUO) The total number of findings discovered and associated with any vulnerability, site, or network is unclassified//for official use only, unless the site, facility, or location is classified at a higher level.

5.6 (U//FOUO) The terms "secure," "secure with limitations," "not secure, and "undetermined" referring to the JITC security determination are unclassified//for official use only.

6. Lines of Communication. Lines of communications will be handled accordingly depending on the classification of the system, data collection, and reporting methods utilized in order to prevent spillage and over classification of information. Direction as to how communications will be handled is provided by the JITC Action Officer.

2018-05-22T11:27:38-0400
LINDEMAN.JOEL.STEVEN.1040296189

File details come from the government source that posted it. Updated .