Bidders Library Security - DISAI 240-110-37.pdf
PDF 230 KB Posted
- Attached to
- TEC II Services RFP Federal contract opportunity
- Solicitation number
- HC102821R0006
- Issued by
- Defense Information Systems Agency
About this file
This instruction prescribes the Defense Information Systems Agency's policy for operations security and assigns responsibilities to protect critical information. It details the five-step OPSEC process of identifying critical information, analyzing threats, analyzing vulnerabilities, assessing risks, and applying countermeasures. Responsibilities include appointing OPSEC managers and coordinators, conducting training and reviews, integrating OPSEC into all activities, and coordinating with security programs. The enclosure provides the agency's critical information list covering administration, personnel, intelligence, operations, and logistics details whose disclosure could harm military missions or advantages.
View the file
Other files for this federal contract opportunity
Show all 50
TEC II Services RFP has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DEFENSE INFORMATION SYSTEMS AGENCY
P. O. BOX 549
FORT MEADE, MARYLAND 20755-0549
UNCLASSIFIED//FOR OFFICIAL USE ONLY ENCLOSURE
DISA INSTRUCTION 240-110-37* 6 February 2018
SECURITY
Operations Security (OPSEC)
1. Purpose. This Instruction prescribes policy and assigns responsibilities for operations security (OPSEC). It also provides the Agency Critical Information List (CIL).
2. Applicability. This Instruction applies to Defense Information Systems Agency (DISA) activities and the Joint Force Headquarters – Department of Defense Information Networks
(JFHQ-DODIN).
3. Authority. This Instruction is published in accordance with the authority contained in DoD Directive 5205.02E, DoD Operations Security (OPSEC) Program, 20 June 2012.
4. Definitions.
4.1 Operations Security (OPSEC). An analytic process used to deny an adversary information--generally unclassified--concerning agency intentions and capabilities by identifying, controlling, and protecting indicators associated with agency planning processes or operations. OPSEC does not replace other security disciplines--it supplements them.
4.2 Critical Information. Information important to the successful achievement of
U.S. objectives and missions or which may be of use to an adversary of the United States.
Critical information consists of specific facts about friendly capabilities, activities, limitations
(includes vulnerabilities), and intentions needed by adversaries for them to plan and act effec-tively so as to degrade friendly mission accomplishment. Critical information is information that is vital to a mission that if an adversary obtains it, correctly analyzes it, and acts upon it will prevent or seriously degrade mission success. Critical information can either be classified or unclassified. Critical information can also be an action that provides an indicator of value to an adversary and places a friendly activity or operation at risk.
4.3 Open Source Information. Information that involves the collection and analysis of freely available information; such as, that presented in the media or available in libraries or the Internet.
Open source information includes photographs, newspapers, magazine advertisements, govern-ment and trade publications, contract specifications, congressional hearings, computers, and other public media.
DISAI 240-110-37
4.4 Special Access Program (SAP). A sensitive program, approved in writing by a head of an agency with original top secret classification authority, that imposes need-to-know and access controls beyond those normally provided for access to confidential, secret, or top secret information.
5. Policy. A formal OPSEC program will be used to promote a greater understanding of
OPSEC to Agency personnel while avoiding unnecessary operational or administrative burden.
Critical information, capabilities, technologies, plans, and activities will be maintained through the use of OPSEC measures prior to, during, and after operations and other potentially vulner-able activities. OPSEC measures will be applied to special access programs (SAPs), research programs, and system development, testing, and evaluation with the process beginning early in the program life and continuing to final termination of the system in an effort to maintain essential secrecy.
6. Objective. The objective of the OPSEC program is to ensure mission effectiveness and to comply with DoD Directive 5205.02E (authority document). OPSEC is one of the means that must be used to manage the physical and collection risk to Agency operations and activities.
7. Overview.
7.1 The OPSEC program supports the Agency in attaining mission accomplishment by protecting critical information and by denying that information to any potential adversary.
When involved in joint operations, OPSEC will be implemented, in accordance with
CJCSI 3213.01D, Joint Operations Security, in the development of support to those programs and activities.
7.2 All leaders and managers are actively involved in OPSEC. This is particularly true in defining OPSEC goals, providing planning guidance, and making decisions regarding the balancing of operational needs versus security needs.
8. Application of the Process. In determining the need for and implementing OPSEC, all organizational elements will use the following five-step OPSEC process: (1) identification of critical information, (2) analysis of threats, (3) analysis of vulnerabilities, (4) assessment of risks, and (5) application of OPSEC countermeasures.
9. Critical Information List (CIL). A basic principle for an effective OPSEC program is determining what information if made available to one or more adversaries would harm the ability of the Agency, Services, and DoD to effectively carry out the operation or activity.
This critical information constitutes the "core secrets" of the organization; i.e., the few pieces of information that are central to the organization's mission or the specific activity. Critical information usually is, or should be, protected as controlled unclassified information (CUI).
(The Agency CIL is provided in the enclosure.)
10. Responsibilities.
10.1 Chief, Security Division (MP6). The Chief, MP6, will:
10.1.1 Appoint, in writing, the primary and alternate Agency OPSEC Program Manager.
10.1.2 Ensure appropriate agreements are established when OPSEC areas of responsibility, training, and operational needs either support, overlap, or are shared with internal or external organizations.
10.1.3 Coordinate and approve any changes or modifications to the OPSEC mission.
10.2 Directors, Executives, Commanders, and Chiefs of Major Organizational Elements.
These individuals will:
10.2.1 Coordinate with the Security Division (MP6) and the OPSEC Program Manager on all OPSEC-related matters.
10.2.2 Appoint, in writing, an OPSEC coordinator for their activity.
10.2.3 Ensure the OPSEC Program Manager is included in all SAPs, research programs, and system development, testing, and evaluation from the beginning early in the program life and continuing to final termination to verify the established OPSEC plan and CIL in an effort to maintain essential secrecy.
11. Duties.
11.1 OPSEC Program Manager. The OPSEC Program Manager oversees OPSEC for the Agency and will:
11.1.1 Ensure OPSEC measures are implemented Agencywide.
11.1.2 Ensure a comprehensive command OPSEC training program is implemented
Agencywide that includes orientation, awareness, and specialized OPSEC instruction.
11.1.3 Ensure command OPSEC programs are examined annually, in accordance with DoD 5205.02E (authority document), by means of OPSEC staff assistance visits or self-inspections.
11.1.4 Ensure coordination is conducted with the security managers for the acquisition and dissemination of threat assessments in support of security program and command elements.
11.1.5 Ensure organizations develop, coordinate, publish, maintain, and implement a critical information list (CIL).
11.1.6 Ensure threat briefings are provided to organizational personnel and elements in support of antiterrorism and force protection.
11.1.7 Ensure security reviews are conducted for all briefings, proposed publishing of newspaper or magazine articles, or any open source information to be made available to the public.
11.1.8 Ensure reviews of all unclassified information intended for posting on a public
Web site are coordinated with the Web content team for OPSEC issues.
11.1.9 Maintain a roster of all OPSEC points of contact for the Agency.
11.2 Activity OPSEC Coordinator. An activity OPSEC coordinator will:
11.2.1 Ensure all employees within their respective activities receive initial and annual
OPSEC training.
11.2.2 Publish an OPSEC plan in support of their activity operations.
11.2.3 Develop and publish, as necessary, specific element CILs and implement measures to protect them, ensuring all employees are knowledgeable of organizational CILs.
11.2.4 Establish OPSEC review procedures, as directed by their organization and/or chain of command.
11.2.5 Establish OPSEC measures, as directed by their organization and/or chain of command.
11.2.6 Report OPSEC vulnerabilities to the OPSEC Program Manager.
11.2.7 Maintain knowledge of the threats and vulnerabilities directed against their facility.
11.2.8 Coordinate all training and briefings with the OPSEC Program Manager.
11.2.9 Conduct OPSEC reviews, as directed by the OPSEC Program Manager.
12. Relationship to Other Programs. OPSEC is a command responsibility and an operational function that will be integrated into all organizational activities. In order for OPSEC and the traditional security disciplines to be effective, they must be coordinated, integrated, and mutually supportive. OPSEC has a functional relationship with the following disciplines: information security, physical security, personnel security, industrial security, information assurance, foreign disclosure and technology transfer, public affairs, freedom of information, antiterrorism and force protection, and information operations.
13. Controlled Unclassified Information (CUI), For Official Use Only (FOUO), Privacy
Act (PA), and Personally Identifiable Information (PII). All CUI, FOUO, PA, and PII media, to include, but not be limited to, paper, CD-ROMs, and floppy diskettes, must be destroyed by
National Security Agency approved shredders.
14. Review of Material for Public Release. A security review of all manuscripts, briefings, presentations, Web-based publications, interviews, newspaper and magazine articles, and other informational materials developed by Agency personnel and containing Agency information for public release is to be conducted in accordance with guidance published by the OPSEC
Program Manager.
Enclosure a/s JOEL S. LINDEMAN
Colonel, USA
Chief of Staff
*This Instruction replaces DISAI 240-110-37, 24 March 2017.
OPR: MP6 – disa.meade.mps.mbx.mps-front-office@mail.mil
DISTRIBUTION: Not For Public Release - FOIA Exemption 2
Enclosure
CRITICAL INFORMATION LIST (CIL)
(U/FOUO) Administration/Personnel
- personnel manning strengths, availability, and replacements
- special duty assignments (military/government)
- locations, duties, and arrival and return dates of deployed personnel or units
- critical personnel shortages
- key personnel when associated with special assignments or functions
- future personnel assignments (by name) that require special access prior to arrival at new duty station
- personnel data regarding operational intelligence personnel
- specific details regarding personnel sensitive compartmented information (SCI) roles and responsibilities
- compiled information detailing all SCI positions and specific degree of access
- organizational personnel or access rosters
- complete telephone directories
- detailed itineraries of general and flag officers, officer (O)-6 level commanders, general service (GS)-14s and above, or specified individuals
- itineraries involving outside the continental United States (OCONUS) travel by
U.S. general and flag officers or civilian equivalents
- personally identifiable information (PII) (name, address, social security number, etc.)
- identification of classified documents by classified titles
- Top Secret Control Officer (TSCO) or document control personnel
- information labeled controlled unclassified information (CUI) or classified by regulatory guidance to include, but not be limited to, security classification guides (SCGs)
(U/FOUO) Intelligence
- Agency status of readiness or efficiency
- intelligence spot reports, situation reports, and summaries
- tactical locations
- intelligence plans
- passwords, countersigns, call words, call signs, and suffixes
- any nickname or code word which could be associated with classified operations, projects, or activities
(U/FOUO) Operations
- information regarding Agency movement, deployment, or redeployment of personnel
- sensitive requirements, design, creation, implementation, and management of technology systems, products, tools, etc.
- disclosure of special activities to include mission, organization function, capability, or special areas of interest being conducted
- detailed disclosure of network availability, area of responsibility (AOR) customers, and outages/impacts
UNCLASSIFIED//FOR OFFICIAL USE ONLY
- exercise or maneuver plans, dates, locations, and results
- information regarding changes in organizational results
- information regarding the reorganization of the Agency to include
Base Realignment and Closure (BRAC)
- counterterrorist missions, functions, or relationships
- planned wartime augmentation
- mission priorities
- specific support to units identified in the sensitive unit installation listing or special operations or tactical units
- detailed contingency or emergency plans
- alert notification plan
- specific vulnerabilities, weaknesses, or findings, recommendations, or results of
OPSEC surveys or other evaluations (i.e., command cyber readiness inspection
(CCRI), Defense Threat Reduction Agency (DTRA), etc.)
- specific critical operational commitments to support commands/campaigns
- security requirements and other guidance referenced on a Department of Defense (DD) Form 254:
Contract Security Classification Specification
(U/FOUO) Logistics
- supply or logistical status and shortages which impact on Agency readiness
- design, procurement, and deployment of equipment systems
- information regarding logistical reserves
- alert or contingency plans
- alert, recall, or personnel notification procedures
- readiness/contingency test locations
- planning weaknesses
- differences and relationship between practice and actual alerts
- specific mission and reaction time of all elements under contingency planning
- advance knowledge of unannounced alerts and readiness tests
(U/FOUO) Security
- physical security inspection reports
- physical security risk analysis reports
- specific information regarding physical security measures
- changes to the alert status or security posture to include justification
- evacuation plans or routes
- barrier systems and deployment methods
- force protection control level(s) and detailed measures/plans
- military deception methods
- electronic security systems specifications
UNCLASSIFIED//FOR OFFICIAL USE ONLY
| 2018-02-06T16:52:01-0500 | |
| LINDEMAN.JOEL.STEVEN.1040296189 |
File details come from the government source that posted it. Updated .