Bidders Library JITC Instructions - JITCI 630-230-01.pdf

PDF 925 KB Posted

Attached to
TEC II Services RFP Federal contract opportunity
Solicitation number
HC102821R0006
Issued by
Defense Information Systems Agency

About this file

This is a request for proposal for test, evaluation, and certification services issued by the Defense Information Systems Agency. The solicitation seeks proposals to provide services in support of the Joint Interoperability Test Command including testing, evaluating, and certifying systems to validate interoperability and compliance with standards. Offerors are required to have expertise in various domains including cybersecurity, spectrum management and electromagnetic environment effects, and test and evaluation of communications, computer, and intelligence systems. Proposals are due by August 15, 2022 and the period of performance is a five year base period with five one-year option periods. The total contract value is not to exceed $995M. The solicitation encourages proposals from small businesses including woman-owned small businesses, historically underutilized business zone small businesses, service-disabled veteran-owned small businesses, and small disadvantaged businesses.

View the file

Other files for this federal contract opportunity

Other files attached to TEC II Services RFP, newest first.
File Type Posted
HC102821R0006 Conformed Through amendment 0008.pdf PDF
HC102821R0006 Conformed Through amendment 0007.pdf PDF
HC102821R0006 Conformed Through amendment 0006.pdf PDF
HC102821R0006 Conformed through amendment 0002.pdf PDF
HC102821R00060002.pdf PDF
Bidders Library DODI 5000 02.pdf PDF
Bidders Library Security - ISOO Handbook.pdf PDF
Bidders Library Security - DoDM 5200 01 Vol 1.pdf PDF
Bidders Library Security - DISAI 240-115-04.pdf PDF
Bidders Library Security - DISAI 240-110-35.pdf PDF
Bidders Library Operational Test and Evaluation - JITC OTE Guidebook v2 0.docx DOCX document
Bidders Library Operational Test and Evaluation - DoTE MEMO 10-19-2010.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 10-18-2010.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 6-16-2003.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 04-03-2018.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 1-21-2015.pdf PDF
Bidders Library JITC Instructions - JITCI 100-50-01.pdf PDF
Bidders Library JITC Instructions - JITCI 210-20-02.pdf PDF
Bidders Library JITC Instructions - JITCI 210-15-01.pdf PDF
Bidders Library JITC Instructions - JITCI 200-05-07.pdf PDF
Bidders Library Interoperability Test and Evaluation - JITC Notional Guide for Action Officers.pdf PDF
Bidders Library Interoperability Test and Evaluation - JITC Fact Sheet.pdf PDF
Bidders Library Interoperability Test and Evaluation - DODI 8551 01.pdf PDF
Bidders Library Interoperability Test and Evaluation - DoD 8570 01-M.pdf PDF
Bidders Library DoD Policy Instruction and Guidance - DoDI 4000 19.pdf PDF
Bidders Library DoD Policy Instruction and Guidance - DoDD 510035.pdf PDF
Bidders Library DoD Policy Instruction and Guidance - DoD Net Centric Service Strategy.pdf PDF
Bidders Library DISA - DISA Mandatory Contractor Training as of 20201110.xlsx XLSX spreadsheet
Bidders Library Cybersecurity - DoDI 8510 01.pdf PDF
Bidders Library Security - DISAI 240-110-8.pdf PDF
Bidders Library Cybersecurity - DOD Cybersecurity TE Guidebook.pdf PDF
Bidders Library Security - ICD 701.pdf PDF
Bidders Library Security - ICD 503.pdf PDF
Bidders Library Security - DoD 5220 22-M.pdf PDF
Bidders Library Security - DoDI 5200 01.pdf PDF
Bidders Library Security - DISAI 630-230-19.pdf PDF
Bidders Library Security - DISAI 240-110-33.pdf PDF
Bidders Library Security - DISAI 240-110-38.pdf PDF
Bidders Library Security - DISAI 240-110-43.pdf PDF
Bidders Library Security - DISAI 240-110-37.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 09-14-2010.pdf PDF
Bidders Library Operational Test and Evaluation - DISA Test Evaluation Process Guidebook.docx DOCX document
Bidders Library Operational Test and Evaluation - DoTE MEMO 6-3-2011.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 06-24-2011.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 4-23-2010.pdf PDF
Bidders Library Operational Test and Evaluation - DoDD 5141 02.pdf PDF
Bidders Library JITC Instructions - JITCI 270-95-02.pdf PDF
Bidders Library JITC Instructions - JITCI 280-50-01.pdf PDF
Bidders Library JITC Instructions - JITCI 640-50-06.pdf PDF
Bidders Library JITC Instructions - JITCI 630-225-07.pdf PDF
Show all 50

TEC II Services RFP has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

JOINT INTEROPERABILITY TEST COMMAND

2001 BRAINARD ROAD

FORT HUACHUCA, ARIZONA 85613-5070

IN REPLY

REFER TO: JITC INSTRUCTION 630-230-01* 29 March 2019

CYBERSECURITY

Cybersecurity User Instruction

1. Purpose. This instruction establishes general user responsibilities and procedures for the secure and efficient operation of the Joint Interoperability Test Command (JITC) Information Systems (IS) in accordance with Department of Defense (DoD) security policies, Defense Information Systems Agency (DISA), and JITC instructions. This document covers procedures and provides references to additional information sources.

2. Applicability. This instruction applies to the use of IT at JITC’s Headquarters Fort Huachuca (FHU) and JITC Labs at Fort George G. Meade (FGGM) locations. Provisions applicable to specific accredited systems are found in system/laboratory Cybersecurity Architecture Description (CAD) and Standard Operating Procedures (SOP).

3. Authority. DoD Instruction (DoDI) 8510.01, Risk Management Framework (RMF) for DoD Information Technology (IT), Change 1, effective 24 May 2016.

4. References.

4.1 Chairman of the Joint Chiefs of Staff Instruction 6510.01F, Information Assurance and Support to Computer Network Defense (CND), 9 February 2011, current as of 9 February 2015.

4.2 DoDI 8500.01, Cybersecurity, March 2014. (Incorporates and cancels DoDI 8500.02, DoDD C-5200.19, DoDI 8552.01, Assistant Secretary of Defense for Networks and Information Integration (ASD(NII))/DoD Chief Information Officer DoD CIO) Memorandums, and Directive-type Memorandum (DTM) 08-060).

ii

4.3 DoDI 8510.01, Risk Management Framework (RMF) for DoD

Information Technology (IT), Change 1, effective 24 May 2016.

Reissues and Renames DoDI 8510.01 (reference (4.2) in accordance with the authority in DoDD 5144.02)

4.4 DoDI 5200.02R, Personnel Security Program, March 2014, changes: 9 September 2014.

4.5 DoD 8570.01-M, “Information Assurance Workforce Improvement Program,” December 19, 2005, as amended.

4.6 DoD Manual (DoDM) 5200.01-V1, “DoD Information Security

Program: Overview, Classification, and Declassification,” February 24, 2012

4.7 DoDM 5200.01-V2, “DoD Information Security Program: Marking of Classified Information,” February 24, 2012 incorporating Change 2, March 19, 2013.

4.8 DoDM 5200.01-V3, “DoD Information Security Program:

Protection of Classified Information,” February 24, 2012 incorporating Change 2, March 19, 2013

4.9 DISA Instruction 630-230-19*, “Cybersecurity (Information Assurance)”, 8 August 2017

4.10 DISA Policy Letter 2016-2, Wireless Devices, 13 January

4.11 Joint Interoperability Test Command (JITC) Policy on

Analysis and Incident Handling

4.12 JITC Data Transfer Process

4.13 “DRAFT_DISA Vulnerability Management Policy,”June 3, 2015

5. Responsibilities. Areas of responsibility are listed in Chapter C2.

iii

6. Delegation of Authority. The JITC Commander has delegated to the Information System Security Manager the responsibility of DISA Instruction implementation / compliance and the establishment of the JITC Cybersecurity program.

SHAWN ROBERTS

CAPT, USN

Commanding

SUMMARY OF SIGNIFICANT CHANGES. This revision incorporates DISAI 630-230-19, 8 August 2017. This revision supercedes JITCI 240-110-03 IT Security User Instruction. This instruction also contains extensive changes to the contents of this instruction, administrative changes to formatting, grammar, punctuation, spacing, and other critical administrative updates needed to conform to current guidelines. Updated instruction should be read in its entirety.

*This Instruction supersedes JITCI 240-110-03, dated 21 Jun 2007

OPR: JT3B

DIST: All JITC Civilian, Military, and Contractor Personnel iv

(This page intentionally left blank) v

RECORD OF REVISIONS

Revision Summary Originator Date 2010 Annual review & update RB Rice May 2010

2011 Annual review & update RB Rice Oct 2011

2012 Annual review & update RB Rice Apr 2012

2016 Review & update Melissa LaSure Aug 2016

2017 Review & update Cecil Simi Nov 2017

2018 Review & update Melissa LaSure July 2018

2019 Review & update Melissa LaSure Feb 2019 vi vii

TABLE OF CONTENTS

Page

BASIC INSTRUCTION

1. Purpose.....................................................i

2. Applicability and Scope.....................................i

3. Authority...................................................i

4. References..................................................i

5. Responsibilities...........................................ii

6. Delegation of Authority...................................iii

DEFINITIONS

ACRONYMS

CHAPTERS

C1 CHAPTER 1. JOINT INTEROPERABILITY TEST COMMAND (JITC) FORT

HUACHUCA FACILITY INFRASTRUCTURE.............................C1-1

C2 CHAPTER 2. SECURITY ORGANIZATION........................C2-1

C2.1 JITC Security Office ..................................C2-1 C2.2 Cybersecurity/IA Workforce Management .................C2-2 C2.3 IA Technical (IAT) and IA Management (IAM) Level Position Designations..........................................C2-3 C2.4 JITC Information System Security Manager (ISSM) .......C2-4 C2.5 JITC Information System Security Officer (ISSO) .......C2-5 C2.6 Privileged Users With IA Responsibilities ............C2-6 C2.7 Authorized Users ......................................C2-6

C3 CHAPTER 3. VISITORS TO JITC.............................C3-1

C3.1 Visitor Control .......................................C3-1 C3.2 JITC Host .............................................C3-2 C3.3 IT Equipment ..........................................C3-2 C3.4 Visitor’s Access To JITC IT Equipment .................C3-2 C3.5 Visitor’s Out-Processing ..............................C3-3 C3.6 JITC FGGM Visit Request ...............................C3-3

C4 CHAPTER 4. JITC PERSONNEL VISITING OTHER LOCATIONS......C4-1

C4.1 Hand Receipt ..........................................C4-1 C4.2 Classified Material ...................................C4-1 viii

C4.3 Protection Of IT Equipment ............................C4-1 ix

TABLE OF CONTENTS (continued)

C5 CHAPTER 5. PHYSICAL SECURITY............................C5-1

C6 CHAPTER 6. JITC ACCESS..................................C6-1

C6.1 JITC Access Control Strategy ..........................C6-1 C6.2 Personnel Controls ....................................C6-1 C6.3 Onboarding ............................................C6-3 C6.4 Offboarding ...........................................C6-6 C6.5 Temporary Administrative Suspension of Access .........C6-7

C7 CHAPTER 7. MAINTENANCE PERSONNEL ACCESS.................C7-1

C7.1 Responsibilities ......................................C7-1 C7.2 IT/IS Maintenance Support .............................C7-1 C7.3 Maintenance Equipment .................................C7-3 C7.4 External Maintenance Personnel (Facility Maintenance) .C7-3

C8 CHAPTER 8. JITC GENERAL IS PROVISIONS...................C8-1

C8.1 Session Timeout/Lockout ...............................C8-1 C8.2 Computer Viruses ......................................C8-1 C8.3 Security Technical Implementation Guidance (STIG) Compliance.............................C8-2 C8.4 Identification And Authentication .....................C8-2 C8.5 Access Control ........................................C8-3 C8.6 Auditing ..............................................C8-6 C8.7 Data Backup Responsibilities ..........................C8-8 C8.8 Software ..............................................C8-8 C8.9 Wireless Devices ......................................C8-8 C8.10 Use Of Universal Serial Bus (USB) .....................C8-9 C8.11 Derivative Classification Reviews .....................C8-9 C8.12 Data Transfers ........................................C8-9 C8.13 Malicious Logic Procedures ............................C8-9 C8.14 Library Control ......................................C8-10 C8.15 Boot Media ...........................................C8-10 C8.16 Marking And Labeling .................................C8-10 C8.17 Declassification/Downgrading/Destruction Procedures ..C8-11 C8.18 Remote Access ........................................C8-11 C8.19 Use of Social Media/Networking Sites .................C8-11 C8.20 Media Protection .....................................C8-12 C8.21 Mobile Code Policy ...................................C8-12 x

TABLE OF CONTENTS (continued)

C9 CHAPTER 9 HOST BASED SECURITY SYSTEM (HBSS)DOCUMENTABLES.C9-1

C9.1 Vulnerability Training ................................C9-3 C9.2 Flaw Remediation ......................................C9-3 C9.3 Malicious Code ........................................C9-4

C10 CHAPTER 10. JITC TRAINING REQUIREMENTS ...............C10-1

C11 CHAPTER 11. IT COOP/CONTINGENCY PLAN..................C11-1

ENCLOSURES

1 FORT MEADE ACCESS CONTROL PROCEDURES.............Enclosure 1-1

LIST OF FIGURES

1 Data Flow ................................................C1-3 2 Vulnerability Scanning/Remediation Process ...............C9-3 xi

DEFINITIONS

Authorizing Official – Formerly known as Designated Approving Official (DAA).

Continuity of Operations Plan - Plan maintained for emergency response, backup operations, and post-disaster recovery for an IS, as a part of its security program, which maintains the availability of critical resources and facilitate the continuity of operation in an emergency situation.

Contracting Officer’s Representative - An individual who is designated and authorized in writing by the Contracting Officer (KO) to perform specific contract administration or technical functions on contracts or task/delivery orders.

Directorate ISSM – The Directorate Information System Security Manager (ISSM) appointed responsibility for JITC cybersecurity compliance and accreditation. The JITC ISSM oversees FHU and FGGM Site ISSM duties and responsibilities and interacts with cybersecurity personnel, analysts and assessors, the Authorizing Official (AO) and representative/office and Program Management Offices (PMO). Site ISSMs at FHU and FGGM work with the Directorate ISSM.

DISANet – An enterprise level accredited system of systems that resides on the NIPRNet. The accreditation is managed and operated by DISA, not JITC. DISANet is used for administrative daily work by providing Office products, Enterprise E-mail, and access to the Internet gateway via the NIPRNet. JITC users have a DISANet laptop/workstation accessible at their desk. JITC’s Information Management Branch provides DISANet support via a DISANet Global JITC Fort Huachuca for JITC FHU; JITC FGGM is supported by DISA Operations.

Facility – A site under the operational control and authority of a single organization with the responsibility to define and implement security controls.

Government Action Officer – The government point of contact for a task or project. This may or may not be the COR for the task or project.

Information System Security Manager – Formerly known as Information Assurance Manager.

Information System Security Officer – Formerly known as Information Assurance Officer.

Information Systems - The entire infrastructure, organization, personnel, and components that collect, process, store, transmit, display, disseminate, and act on information (Joint Pub 6-0).

Malicious Code - Code designed with a malicious intent to deny, destroy, modify, or impede system configuration, programs, data files, or routines. Causes unwanted modification or destruction of data. It can also steal data, allow unauthorized access, and exploit/damage an Information System or entire network. This includes Trojan horses, bombs, worms, and viruses.

Malicious Logic - Hardware, software, or firmware intentionally included in an Information System for an unauthorized purpose.

Mission Partner - Any identity or IS supported by DISA that is not assigned with DISA (e.g. any CC/S/A, United States (US) DoD identity, US National/State\Local Government identity, Foreign National Government.

NIPRNet – Unclassified Internet Protocol Router Network. DoD’s network used to exchange sensitive but unclassified information to “internal” users as well as provide access to the Internet.

Military and government networks run on this network as separate services, protected by a secure layer of IP routers that support the Sensitive But Unclassified (SBU) IP Data telecommunication services.

SBU IP Data – Formerly known as NIPRNet, SBU IP Data provides point-to-point connectivity to DISA mission partners. The IP data service for Internet connectivity and information transfer supports DoD applications such as e-mail, web services, and file transfer.

Secret IP Data – Formerly known as SIPRNet, this service provides point-to-point connectivity to mission partners. The IP-based secret information transfer across DoD for official business applications such as e-mail, web services, and file transfer. The data service gateway function provides DoD customers with centralized and protected connectivity to federal, Intelligence Community (IC) and allied information at the secret level.

SIPRNet – Secret Internet Protocol Router Network. DoD’s network used to exchange sensitive but unclassified information to “internal” users as well as provide access to the Internet.

Military and government networks run on this network as separate services, protected by a secure layer of IP routers and customer-provided encryption devices

Top Secret/Sensitive Compartmented Information Data (TS/SCI IP Data) – Formerly known as JWICS, this service provides a secure high-speed multimedia communication service between SCI users designed to support the DoD Intelligence Information System (DoDIIS) community through the Defense Intelligence Agency (DIA) Regional Support Centers (RSC).

User - In IS, a person or process accessing an IS by direct connection (e.g., via terminals), or indirect connections (e.g., prepare input data or receive output that is not reviewed for content or classification by a responsible individual).

Virus - A computer program usually hidden within another seemingly innocuous program that produces copies of itself, often by inserting itself into other programs, and that usually performs a malicious action (such as destroying data). The word is often used when discussing worms and Trojans, however there are differences.

ACRONYMS

ACAS Assured Compliance Assessment Solution AO Authorizing Official ATO Authority to Operate

CAC Common Access Card CAD Cybersecurity Architecture Description CCB Configuration Control Board COMSEC Communications Security COOP Continuity of Operations Plan COSA Classified Open Storage Area CP Contingency Plan

DAC Discretionary Access Control DCRA Derivative Classification Review Agent DISA Defense Information Systems Agency DISAI DISA Instruction DISANet DISA Network DoD Department of Defense DREN Defense Research and Engineering Network ePO Enterprise Policy Originator

FHU Fort Huachuca FSO Field Security Office

GAO Government Action Officer

HBSS Host Based Security System

IA Information Assurance IAT Information Assurance Technical (Level categories) IAM Information Assurance Management (Level categories)

IO

IAW In Accordance With IRP Incident Response Plan IS Information Systems ISSM Information Systems Security Manager ISSO Information Systems Security Officer IT Information Technology ITSM Information Technology Service Management

JITC Joint Interoperability Test Command JPAS JITC Project and Accounting System JWICS Joint Worldwide Intelligence Communications System

MAC Mandatory Access Control

NATO North Atlantic Treaty Organization

PED Portable Electronic Device PIT Platform Information Technology PKI Public Key Infrastructure PM Program Manager PMO Program Management Office POA&M Plan of Action and Milestones

RHR Reliable Human Reviewer

SA System Administrator SBU Sensitive But Unclassified SF Standard Form SME Subject Matter Expert SOP Standard Operating Procedure SRG Security Requirements Guide STIG Security Technical Implementation Guide

T&D Test and Development T&E Test and Evaluation

US United States

WIIP Workforce Improvement Implementation Program

C1-1

C1. CHAPTER 1. Joint Interoperability Test Command (JITC) Fort

Huachuca (FHU) Facility Infrastructure

JITC is in the Center/Directorate of Defense Information Systems Agency (DISA) Development and Business Center. JITC’s overall mission is to support the Warfighter in their efforts to manage information both on and off the battlefield. Computer operations are performed in widely varying conditions at JITC facilities from controlled environments of the Classified Open Storage Areas (COSA) to equipment shelters on test nodes and local area network users in office areas.

JITC’s environments rely heavily on the Enclave Test and Development (T&D) Security Technical Implementation Guide (STIG) Zoning References utilizing Zones A, B, C, and D. Refer to the specific system/laboratory Standard Operating Procedure (SOP) and Cybersecurity Architecture Description (CAD) for detailed information about each system/laboratory.

JITC’s Authority to Operate (ATO) boundary granted by the

Authorizing Official (AO) is as follows:

“JITC Core Systems and Zone A/B systems/labs utilize connectivity to CJCSI 6211.02D, "DISN provided Transport", with Command Circuit Service Designators (CCSD). Zone A systems are predominantly pre-production under Program Control for management by JITC, such as the Public Key Infrastructure, Global Directory Service, and Electronic Business Systems – Test Facility.

Systems/labs utilizing CJCSI 6510.01 networks utilize Zones

B, C, and D to service communities of interest for T&D, Standards Conformance, and Interoperability testing. The 6510 networks may be standalone or have connections to the DREN, S- DREN, or CFBLNet. The CFBLNet connection is for CFBLNet Initiative Information Pack (CIIP) only, which is NSA Type 1 encrypted and keyed for the Initiative. Systems in Zones B/C/D are non-DISN assets and "do not process, store, share, and/or transmit real-world operational data and are isolated from operational." The ISSM has discretion for STIG compliancy in Zones B, C, and D, which includes standalone systems. This is so that T&D (T&E) can remain both agile and secure. ISSM discretion allows for vulnerability assessment and risk mitigation for the test environment, event, or exercise. Risk and Mitigation factors are weighed against the Communities of Interest.

C1-2

As an example, the figure below details data flow and separation of core/operational systems and T&D within the zones.

This diagram depicts the accreditation boundary of JITC FHU.

Note: DISA Network (DISANet), NSANet, and Top Secret/Sensitive Compartmented Information Data (formerly known as Joint Worldwide Intelligence Communications System (JWICS)) are outside of the accreditation boundary as their ATO is managed and controlled by other organizations whereas JITC FHU is a tenant to their service.

C1-3

LEGEND:

C2 Command and Control CFBL Combined Federated Battle Laboratory CDL Common Data Link CFBLNet CFBL Network

COCOM

CTB Coalition Testbed DDTE Distributed Developmental and Test

Enterprise

DISA

DISANet DISA Network DISN Defense Information System Network DREN Defense Research and Engineering

Network DRSN Defense Red Switching Network DSN Defense Switched Network EBEC Electronic Business/Electronic Commerce EKMS Electronic Key JANETT Joint Analysis Net-Centric Evaluation

Testing Toolkit JIT Joint Interoperability Tool JITC Joint Interoperability Test Command JPAS Joint Personnel Adjudication System

JSAP

JTDL Joint Tactical Data Link JWICS Joint Worldwide Intelligence

Communications System KMI Key Management Infrastructure MFL Multifunction Laboratory MSS Mission Supports System MTED Mobility Test, Evaluation & Development NATO North Atlantic Treaty Organization NIPRNet Unclassified-But-Sensitive Internet

Protocol Router Network

NIT Network Integration Testbed NITFS National Imagery Transmission

Format Standard NSA National Security Agency NSANet NSA Network PKE Public Key Enabled PKI Public Key Infrastructure RF Radio Frequency RFTF Radio Frequency Test Facility SADL Situational Awareness Data Link SAT Situational Awareness Table SCIF Sensitive Compartmented Information

Facility SDREN Secure DREN SIL Systems Integrated Laboratory SIPRNet SECRET Internet Protocol Router

Network SMC SIPRNet Management Center SOAIT Service Oriented Architecture

Interoperability Testbed STEP Standardized Tactical Entry Point T-1 Transmission Carrier 1 TDL Tactical Data Links TDLDSA TDL Development Support Analysis TE Tactical Edge TETB Tactical Edge Testbed UC Unified Capabilities UHF Ultra High Frequency VTCTF Video Teleconferencing Test

Facility

C1-4

Figure 1. Data Flow

C2-1

C2. CHAPTER 2. SECURITY ORGANIZATION

C2.1 JITC Security Office The JITC Security Office is the controlling organization for security matters concerning Federal Government civilian employees and military members supporting JITC. If there are general security questions or concerns, contact the JITC Security Manager at 520.538.5573 (DSN 879), or the Security Office at 520.538.5200 (DSN 879), or the Special Security Representatives at 520.538.4242 (DSN 879).

In addition to Federal Government requirements, JITC contractor personnel are also governed by their respective company security policies. A key contractor responsibility is guarding company proprietary data. In addition, JITC in-house projects may have numerous subcontractors, each of which may require Non-Disclosure Agreements (NDA). It is vital that NDAs be respected and followed as they are contractual obligations.

If any questions arise about Conflict of Interest, or if there are general security questions or concerns, contact the respective company management or JITC management.

The JITC Security Office is the focal point for managing physical access to all JITC FHU and FGGM facilities. The primary physical control enforcing the authorized access is the Common Access Card. The CAC is used to grant access to laboratory spaces using access readers programmed by the FHU Security Office. Additional physical controls include CDX-09s and CDX-10 security locks, combination locks, and traditional locks. JITC Security manages all aspects of physical keys.

C2.1.1 Security Office Responsibilities

JITC Security Manager. The JITC Security Manager’s responsibilities are:

• Manage the Command Security Program.

• Inform personnel of any security deficiencies that require individual corrective action.

• On a recurring basis, reminding personnel of their continuing responsibility to safeguard sensitive information and that unauthorized disclosure of sensitive information violates Department of Defense (DoD) regulations and contractual obligations, and is punishable under provisions of Federal criminal statutes.

• Ensure users who have possession or knowledge of

C2-2 an element or item of sensitive information are informed that they are responsible for determining whether a prospective recipient of the information is an authorized person and that they are required to advise the recipient of the information classification.

• Manage the issuance and monitor use of JITC Security/Proximity and common access card (CAC) badges.

• Manage unescorted physical access via proximity badge/CAC.

• Validate security clearances for JITC personnel and visitors.

• Oversees management of classified information and the usage of the Automated Classification Document Repository (ACDR) tool.

JITC Security Specialists are responsible for JITC physical, personnel, and information security, and for ensuring government regulations and sound security practices are followed.

C2.2 Cybersecurity/Information Assurance (IA) Workforce Management. JITC tasks sometimes require privileged access and performance of IA and Cybersecurity functions, duties, and responsibilities. In accordance with (IAW) DoD 8570.01M, "Information Assurance Workforce Improvement Program," individuals who require privileged access and who perform these tasks, must hold the appropriate IA Technical (IAT) Level certification and be designated, in writing, by their JITC ISSM as a member of the IA Work Force. Working with the Government Action Officer (GAO)/Supervisor and their Information System Security Officer (ISSO), the responsible JITC ISSM will determine the IA level requirements and number of IA positions required for this task.

For contractors, the government requests a proposal that designates, by name, the contractors that will have privileged access and perform these functions under tasks. After initial designation, the contract Program Manager (PM) must submit a signed Form 9 to the JITC ISSM that includes a request for ISSM approval, when making any position changes that affect contractors designated as part of the IA Work Force. The Form 9 justification must include the names of the incoming person, effective date of replacement and the JPN/Task # and routed by the contractor PM through the GAO, ISSO, and then to the ISSM.

C2-3

The Government will track the certification completion and expiration information for the contractor.

In addition to meeting the baseline DoD 8570.01M certification requirement, individuals with privileged access and/or performing IA functions must also meet the DISA specific requirements listed in Appendix C of the DISA IA Workforce Improvement Implementation Plan (WIIP), IA Training and Certification Program. DISA WIIP requirements include Computer- Based and Online Training, a Core Skill Checklist, and a competency exam. The DISA specific training, checklist, and exam are not available to the public so the Government will sponsor time, not to exceed 40 hours, for designated contractors to complete the DISA WIIP requirements.

Upon completion, the individuals will be issued an appointment letter specific to the level of IAT and privileged level access to the system(s). Personnel must sign the appointment letter. The individual’s name is entered into the IA/Cybersecurity Tracking Database and documented with the professional certification and appointment letter before unsupervised privileged access will be granted. Individuals are not allowed privileged access unless they have an appointment letter.

C2.3 IAT and Information Assurance Management (IAM) Level Position Designations. The three levels of the Cybersecurity/IA workforce structure utilized most at JITC are: Computing Environment or Level I, Network Environment or Level II, and Enclave Environment or Level III. These levels apply to both the IAT and the IAM Level positions.

C2.3.1 The IAT Level position designations are explained in Chapter 3 of the DoD 8570.01-M. IAT Level positions require privileged level access for system, network, or test administration, and must qualify under DoD 8570.01-M guidelines.

These privileged-access positions require a professional IA certification in addition to DISA Workforce Improvement Implementation IA training for qualification. Personnel without a minimum of IAT-I will not be allowed privileged access until issued an appointment letter by the JITC ISSM for the system.

C2.3.2 The IAM Level position designations are explained in Chapter 4 of DoD 8570.01-M, and require a professional IA certification. IAM Level positions are commonly appointed and referred to as ISSOs or Cybersecurity Analysts.

C2-4

C.2.4 JITC ISSM. The Directorate JITC ISSM is responsible for the JITC Headquarters facility located at Fort Huachuca, Arizona and the JITC Labs at Fort George G. Meade, Maryland. This ISSM is the Commander’s principal advisor in the area of cybersecurity and is responsible for compliance and accreditation of various boundaries to the AO. The JITC ISSM is appointed by the Center/Director with a written statement of cybersecurity responsibilities.

An ISSM and an alternate are appointed at both JITC FHU and JITC FGGM. JITC FHU and FGGM ISSMs are appointed by the Directorate ISSM with a written statement of cybersecurity responsibilities. ISSMs monitor the environment and operation of these accredited systems, managing and controlling changes, and assessing the security impact of those changes. JITC has accreditation packages that allow connectivity and functionality within the accreditation boundary/environment. There are other accreditation packages under the purview of other organizational ISSMs such as DISANet, JWICS, Enterprise Email, Distributed Common Ground/Surface Systems, etc. Those systems when brought to JITC are under Authority to Operate (ATO) accepted by the JITC ISSMs under certification reciprocity.

The ISSMs, are responsible for the organizational cybersecurity program that includes cybersecurity architecture, requirements, objectives and policies, cybersecurity personnel, and cybersecurity processes and procedures. These responsibilities include:

• Ensure AOs and stewards associated with DoD information received, processed, stored, displayed, or transmitted on each DoD Information Systems (IS) and Platform Information Technology (PIT) system are identified in order to establish accountability, access approvals, and special handling requirements.

• Maintain a repository for all organizational or system-level cybersecurity-related documentation.

• Ensure cybersecurity inspections, tests, and reviews are synchronized and coordinated with affected parties and organizations.

• Act as the primary cybersecurity technical advisor to the AO for DoD IS and PIT systems under their purview.

• Ensure cybersecurity-related events or

C2-5 configuration changes that may impact DoD IS and PIT systems authorization or security posture are formally reported to the AO and other affected parties, such as IOs and stewards and AOs of interconnected DoD ISs.

• Ensure the secure configuration and approval of IT below the system level (e.g, products and IT services) IAW applicable guidance prior to acceptance into or connection to a DoD IS or PIT system.

• Appoint personnel to the IAT (System, Network, and Test/Technical Administrators) and IAM (ISSO for Networks and Systems/Laboratories) level positions, dependent on the civilian, military, or contracted task requirement. The appointment is in writing and specific to the IAT/IAM level and system name. ISSMs provide oversight to ensure that they are following established cybersecurity policies and procedures. The appointee signs for repudiation and the appointment letter is uploaded to the individual’s Personnel Locator System record where it is recognized by the IA/Cybersecurity Tracking Database.

• Manages the Cybersecurity/IA workforce according to Chapter C2.2. The ISSM also monitors certification and training to ensure all individuals remain eligible IAW DoD 8570.01-M.

• Provide guidance to ISSO’s and SA’s on procedures to facilitate the implementation of the System and Communications Protection Policy. This guidance is contained within these instructions and within the individual system Cybersecurity Architecture Descriptions (CAD) and system Standard operating Procedures (SOP).

C2.5 ISSO. The ISSOs support accreditation and compliance efforts by managing the configuration, access control, and day-to-day operation of the accredited system. The ISSOs shall assist the ISSMs in meeting the duties and responsibilities outlined above. These responsibilities include:

• Implement and enforce all DoD IS and PIT system cybersecurity policies and procedures, as defined by cybersecurity-related documentation.

• Ensure all users have the requisite security clearances and access authorization, and are aware of their cybersecurity responsibilities for DoD IS and PIT systems under their purview before being granted access to those systems.

C2-6

• In coordination with the ISSM, initiate protective or corrective measures when a cybersecurity incident or vulnerability is discovered. Ensure that a process is in place for authorized users to report all cybersecurity-related events and potential threats and vulnerabilities to the ISSO.

• Ensure all DoD IS cybersecurity-related documentation is current and accessible to properly authorized individuals.

• Provide guidance to SA’s on procedures to facilitate the implementation of the System and Communications Protection Policy. This guidance is contained within these instructions and within the individual system CAD and system SOP.

C2-7

C2.6 Privileged Users with IA Responsibilities (e.g. System, Network, Test/Technical Administrators). In addition to satisfying all responsibilities of an Authorized User, their responsibility is to:

• Configure and operate IT according to DoD Cybersecurity policies and procedures.

• Notify the responsible ISSO or, in the absence of an ISSO, the responsible ISSM, of any changes that might affect security posture.

• Implement technical controls IAW DoD, DISA, and FHU guidance.

• Implement individual access as directed in approved requests.

• Restore approved access through unlocking accounts or resetting passwords IAW the Incident Management process.

• Follow the Incident Management process to notify the ISSO and ISSM when there has been a confirmed, or suspected, violation of Access Management Controls.

• Enforce the implementation of the System and

Communications Protection Policy within their respective systems. This guidance is contained within these instructions and within the individual system Cybersecurity Architecture Descriptions (CAD) and system Standard operating Procedures

(SOP).

C2.7 Authorized Users. Any individual who uses IT should be aware of the information control procedures for that IT and should obtain additional information or procedure clarification from the system ISSO/ISSM, if necessary. Authorized users must:

• Immediately report all cybersecurity-related events (e.g., data spill) and potential threats and vulnerabilities (e.g., insider threat) to the appropriate ISSO or, in the absence of an ISSO, the ISSM.

• Protect authenticators commensurate with the classification or sensitivity of the information accessed and report any compromise or suspected compromise of an authenticator to the appropriate ISSO.

• Protect terminals, workstations, other input or

C2-8 output devices and resident data from unauthorized access.

• Inform the responsible ISSO when access to a particular DoD IS or PIT system is no longer required (e.g., completion of project, transfer, retirement, resignation).

• Observe policies and procedures governing the secure operation and authorized use of DoD IT, including operations security (OPSEC).

• Use DoD IT only for official or authorized purposes.

• Annually read and review the Lab SOP and the Lab Read Book, these instructions, and DISA Forms 786 or 787, Access Agreements. Acknowledgement of review is contained in Appendix F of the lab SOP and maintained by the Lab SA.

• Not unilaterally bypass, strain, or test cybersecurity mechanisms. If cybersecurity mechanisms must be bypassed, users will coordinate the procedure with the ISSO and receive written approval from the ISSM.

• Not introduce or use software, firmware, or hardware that has not been approved by the AO or a designated representative on the accredited DoD IT.

• Not relocate or change DoD IT equipment or the network connectivity of equipment without proper authorization.

• Meet minimum cybersecurity awareness requirements.

C3-1

C3. CHAPTER 3. VISITORS TO JITC

C3.1 Visitor Control. JITC Security is the focal point for visitor access. Contact JITC Security to identify the required steps for visitors to obtain access to JITC FHU and FGGM.

C3.1.1 JITC Security reviews visit requests to determine the level of physical or system access that will be granted.

Depending on the security clearance of the visitor and the area being visited, the visitor might require an escort while physically accessing JITC facilities.

C3.1.2 Visitors must complete the Visit Authorization Requests (VARs) IAW direction from JITC Security. See the JITC Web Site for more details or contact JITC Security.

C3.1.3 Government Test Lead or Contractor Lead submits an email request to the GAO responsible for the laboratory space providing the following access request details:

• Name of individual

• Individual’s Organization

• Individual’s contact information

• Individual’s JITC Visitor Badge Number(if already issued)

• Requested date for access to begin

• Requested termination date, if known

• Brief justification for access

C3.1.4 GAO forwards the email to assigned ISSO requesting access be granted or provides the requestor the reason for disapproval.

C3.1.5 The ISSO forwards a new access roster as a request to JITC Security or provides the GAO the reason for ISSO disapproval.

C3.1.6 JITC Security validates the security clearance of the individual and grants access to the laboratory via the badge system, or provides the ISSO the reason for disapproval.

C3.1.8 Upon completion of the visit, the escort notifies the GAO that the visit was completed and if there was anything significant to report.

C3-2

C3.2 JITC Host. It is the responsibility of all personnel hosting visitors at JITC to ensure compliance with the following IT equipment procedures. The IT equipment includes (but is not limited to) laptop computers and Portable Electronic Devices

(PED).

C3.3 IT Equipment. All IT equipment brought into or removed from JITC for any use is the responsibility of the visitor’s

JITC POC.

C3.4 Visitor’s Access to JITC IT Equipment. No visitor will have access to IT equipment on any JITC system or data network without prior authorization from the applicable ISSO. The System Authorization Access Request (SAAR) DD2875 form is used to request access. Some items for ISSO consideration/action:

C3.4.1 Devices to be connected to any JITC systems / networks must be approved by the ISSM.

C3.4.2 Data obtained from or through a classified JITC system will be considered to be at the host classification. Any portable media needed must follow the Manual Data Transfer Process. IAW Communications Tasking Order 10-133 all data transfers from a classified system require two person control, and further requires the personnel performing the transfer be authorized by the AO. The procedure for performing a data transfer includes completing a data transfer request form, submitting a request in Information Technology Service Management (ITSM), and receiving approval from the ISSM.

C3.4.3 Prior to connection, hard drive(s) of the visitor IT equipment will be scanned for malicious logic, using the latest prescribed virus scan software available from DISA. After the hard drive has been scanned, all CD/DVDs associated with the visitor IT equipment will also be scanned prior to use.

C3.4.4 Personally-owned IT equipment is not permitted within JITC workspaces without government review and approval by Security Manager, ISSO, or ISSM. JITC does not allow personally owned IT equipment because of classified processing areas located throughout the compounds. Personally-owned IT equipment is not allowed inside a Classified Open Storage Area (COSA). As well, personally-owned IT equipment will NOT be connected to any JITC networks or systems.

C3-3

C3.4.5 The ISSO must advise the Task ISSO or ISSM of any actions needed in regard to visitor accesses requiring Testbed System/Laboratory interaction.

C3.5 Visitor’s Out-Processing. At the completion of the visit, if the visitor was processing classified, the following requirements must be strictly adhered to:

C3.5.1 The person hosting a visitor with classified IT equipment will escort the visitor to the Security Office.

C3.5.2 Classified equipment and storage media will be turned over to the Security Office for screening and disposition determination.

C3.5.3 In order to transport classified equipment or storage media, the visitor must have courier documentation from the home organization.

C3.5.4 If the visitor is not personally transporting the classified IT material, the GAO and/or the Automated Classified Document Register custodian through the Security Office will arrange for its transport (e.g, official USPS mailing, SIPRNet e-mail, etc.) to the visitor’s home organization IAW applicable regulations.

C3.6 JITC FGGM Visit Request. Enclosure 1 contains the instructions and procedures JITC FGGM follows to accommodate visitors to FMLTC-U/C Labs. JITC FGGM ISSM/ISSO coordinate with DISA security, and requesting sponsor to facilitate visits.

***** Note: Attachment 3 of Enclosure 1 is not the current version, it is presented just for illustration.*****

C4-1

C4. CHAPTER 4. JITC PERSONNEL VISITING OTHER LOCATIONS

C4.1 Hand Receipt. When removing IT equipment from JITC, take a copy of the hand receipt to provide proof that the equipment is lawfully in the user’s possession and is a JITC asset. A Letter of Accreditation (LOA) is required for any IT that will need to connect at that location.

C4.2 Classified Material. If a need exists to transport classified material to or from a temporary duty location, whenever possible it should be shipped by authorized means and not carried. On a case-by-case basis, authorization to hand carry may be obtained. Contact the Security Office as early as possible for authorization and assistance in making proper arrangements. Refer to DISA Instruction (DISAI) 240-110-8, Information Security Program, Section C, for transporting classified information.

C4.3 Protection of IT Equipment. When traveling with a laptop or notebook computer and other PEDs, always keep in mind that these are easily stolen items. They can be targeted for their value as a high-dollar item as well as the value of the data they may contain. Some considerations:

C4.3.1 Classified laptops will NEVER be left unsecured. They must be stored in an authorized General Services Administration-approved container. DO NOT TAKE THEM TO THE HOTEL! Have them properly stored overnight at an approved facility.

C4.3.2 During travel, laptops and other PEDs must be hand carried and never checked as baggage.

C4.3.3 Be aware of them while in such public places as airport terminals.

C4.3.4 If possible, carry diskettes or removable hard drives separate from the laptop.

C4.3.5 Laptops and PEDs may be stored in a government facility. If it must be stored in a vehicle, it should be in the locked trunk out of plain view. This may not apply to overseas travel, depending on local travel warnings. Contact the Security Office for additional information. Cable locks are provided for all laptops to secure property while traveling.

C4.3.6 Laptops and PEDs will be allowed through airport screening devices. However, care must be taken to avoid theft

C4-2 during this process. Allow all persons in front to proceed through metal detection before placing the laptop and PEDs on the belt of the x-ray equipment. This prevents being held up by a decoy setting off the metal detector, while an accomplice removes them from the end of the x-ray belt.

C4.3.7 Prior to travel, have the latest virus definition files loaded.

C5-1

C5. CHAPTER 5. Physical Security

JITC FHU Facility. Compliance with JITC FHU physical and personnel access policies are enforced through the deployment of multiple physical barriers layered to provide a solid defense in depth. Parameter fencing and proximity badge controlled entry points funnel visitors and new JITC FHU personnel to the main JITC FHU entrance where security personnel are able to authenticate their identity and grant access as appropriate.

JITC Labs at FGGM. Compliance with DISA physical and personnel access policies are enforced by DISA.

Refer to JITC Security Office SOP Physical Security for additional information.

C6-1

C6. CHAPTER 6. JITC SYSTEM ACCESS

C6.1 JITC Access Control Strategy. JITC FHU/FGGM Access Control strategy is focused on ensuring JITC controlled information does not experience a loss of confidentiality, integrity or availability. Confidentiality will be maintained through implementation of controls that limit access to only properly authenticated individuals who have been granted access by a proper authority. Integrity will be maintained by ensuring individuals with access are assigned only the permissions appropriate for their role. Availability will be supported by detailing procedures necessary to obtain approved access.

C6.1.1. Limited Access. The execution of the JITC access policies and procedures will be governed by the principle of “least privilege.” This means that individuals will only be granted the minimal permissions or rights required to accomplish their assigned role. Furthermore, those permissions/rights will only be granted for the minimum time required. Access will be removed when that access is no longer required due to departure or change in duties.

C6.1.2. Contract Control. The JITC business model has resulted in most contractor work being segregated through a task order contract vehicle. This business model automatically limits the number of JITC contractor personnel needing access to the associated IS to those who have been authorized to work on that task order. Furthermore, the Form 1 requires contractor personnel being assigned to, or removed from, the Cybersecurity/IA workforce as governed by DoD 8570.01-M to be identified by name on a Form 9 that is staffed to the JITC ISSM through the contractor Program Manager and the Contracting Officer Representative.

C6.2. Personnel Controls

C6.2.1. Security Clearance Requirements. JITC FHU/FGGM Security policy requires personnel with unescorted access to classified work spaces to have at least a FINAL United States (US) Secret security clearance. This requirement was developed because multiple programs supported by the JITC Test and Evaluation (T&E) mission require a FINAL Secret security clearance. These requirements, combined with the dynamic nature of the T&E enclaves and the multi-use configurable laboratory spaces, necessitated that JITC policy requires ALL JITC personnel to have a FINAL Secret clearance before being granted access to classified JITC T&E IS or workspaces). JITC personnel

C6-2

(Government Civilian/Military/Contractor) security clearance rescreening will be accomplished per established security clearance investigative requirements. Additionally, if Security related activities are identified, JITC Security follows all required procedures to have an individual's clearance status properly reviewed.

Interim US Secret clearances are not sufficient for access to special categories of classified information, such as Communications Security (COMSEC), North Atlantic Treaty Organization (NATO), and Restricted Data. Interim Top Secret clearances are sufficient for access to COMSEC, NATO, and Restricted Data at the Secret and Confidential levels only.

These special categories must be considered when reviewing access requests to classified information/workspaces/information systems. At JITC sites, there is continuous change in the level of classified being worked within our workspaces and information systems as customers cycle their systems through the test/certification process.

JITC employees (Government, Military, or Contractor) with an Interim US Secret clearance are permitted to access COSAs when another employee with a FINAL US Secret clearance is present in the workspace. Interim US Secret clearances are granted to employees to alleviate impact to mission and/or to allow for contractual requirements to be fulfilled where there is impact to mission. Employees with an Interim US Security clearance may be provided access to a COSA and some classified systems. In some instances the access must be supervised, especially where large classified information repositories are involved. Some IS process classified information in addition to US Secret, such as Restricted Data, FRD, CNWDI, etc., which require a Final Secret clearance. Some laboratories may also have COMSEC encryption devices present and personnel require a FINAL US Secret clearance based upon National Security Agency (NSA) policy. The government owner of the IS or the employee’s government sponsor determines need-to-know/clearance requirements for access to an IS and security certifies the clearance (highlighting Interim) within the DD Form 2875.

C6.2.2 Need-to-know requirements. JITC limits access to JITC personnel who have a valid need-to-know. The GAO, in combination with contractor task leaders for contractor personnel, is responsible for validating the need-to-know for JITC FHU/FGGM personnel. GAOs validate the need-to-know for JITC personnel prior to signing as Supervisor in block 18 of DD Form 2875, or prior to submitting any request for access.

C6-3

C6.2.3 Special Access Requirements. JITC limits access to JITC personnel who have satisfied special access requirements, JITC Security ensures all personnel who require access to NATO data have completed their indoctrination and annual refresher briefings. The GAO validates the need to know and requests the individual is read on to NATO by emailing a request to JITC Security.

C6.2.4 Failure to comply with established JITC information security policies and procedures, physical security policies and procedures, these instructions, and other DISA and DoD policies and procedures can result in formal sanctions. The JITC Commander, GAO, ISSM, and contractor supervisor will be immediately notified of any deviations or violations.

C6.2.5 In the event either general users or privileged users supporting JITC-FHU/FGGM systems are identified as high risk, the following additional monitoring will be implemented:

• High risk personnel will require an escort to access JITC- FHU systems

• Audit Trail Review – After high risk personnel access JITC- FHU systems the audit trail will be immediately reviewed to ensure unauthorized actions have not occurred

The following sources will be used to identify individuals who pose an increased level of risk to JITC-FHU/FGGM systems:

• Personnel Sanctions

• Supervisor concern

• Other credible sources (i.e., law enforcement, intelligence information)

C6.3 Onboarding. Onboarding processes will be followed to grant access to all new JITC FHU personnel.

C6.3.1 DISA IS and Main JITC Facilities. Initial Onboarding of new JITC FHU personnel is initiated by the JITC Human Resources Branch or applicable contractor Field Security Officer (FSO).

Key outputs of this onboarding are:

• Validation of Security Clearance

• Issuance of…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .