Bidders Library Security - DISAI 240-110-43.pdf
PDF 96 KB Posted
- Attached to
- TEC II Services RFP Federal contract opportunity
- Solicitation number
- HC102821R0006
- Issued by
- Defense Information Systems Agency
About this file
This document provides policy for the Defense Information Systems Agency's Insider Threat Program. Key details include:
-
The policy prescribes requirements for the Insider Threat Program, including training, foreign travel reporting, and network monitoring. It defines insider threat, outlines executive responsibilities, and assigns duties to the Program Manager.
-
Employees, including contractors, must report any contacts, activities, behaviors or indicators associated with a potential insider threat. These include unexplained foreign travel, attempts to access unauthorized information, suspicious financial activities, and more. Failure to report is subject to administrative or legal action.
-
The Program Manager must report insider threats involving foreign intelligence to the supporting Military Department Counterintelligence Organization or FBI within 72 hours. Comprehensive insider threat training must occur annually.
-
Directors must ensure personnel report insider threat activities and complete annual training. The Risk Management Executive must acquire user activity monitoring on agency networks to detect insider threat behaviors, meeting certain capabilities.
View the file
Other files for this federal contract opportunity
Show all 50
TEC II Services RFP has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DEFENSE INFORMATION SYSTEMS AGENCY
P. O. BOX 549
FORT MEADE, MARYLAND 20755-0549
DISA INSTRUCTION 240-110-43* 26 May 2017
SECURITY
Insider Threat Program
1. Purpose. This Instruction prescribes policy, delineates executive accountabilities, and assigns duties for the Insider Threat Program for DISA. It provides guidance on individual reporting requirements and consequences as a result of failure to report.
2. Applicability. This Instruction applies to all DISA activities worldwide.
3. Authority. This Instruction is published in accordance with the authority contained in DoD Directive 5240.06, Counterintelligence Awareness and Reporting (CIAR), 17 May 2011;
DoD Directive 5240.02, Counterintelligence (CI), 17 March 2015; DoD Instruction 5240.26, Countering Espionage, International Terrorism, and the Counterintelligence (CI) Insider Threat, 4 May 2012; and DoD Directive 5205.16, The DoD Insider Threat Program, 30 September 2014.
4. (U//FOUO) Definitions.
4.1 Insider. Any person with authorized access to any U.S. Government resource to include personnel, facilities, information, equipment, networks, or systems.
4.2 Insider Threat. The threat that an insider will use their authorized access, wittingly or unwittingly, to do harm to the security of the United States. This threat can include damage to the United States through espionage, terrorism, unauthorized disclosure of information, or through the loss or degradation of departmental resources or capabilities.
4.3 Counterintelligence. Information gathered and activities conducted to protect against espionage, other intelligence activities, sabotage, or assassinations conducted for or on behalf of foreign powers, organizations or persons, or international terrorist activities, but not including personnel, physical, document, or communications security programs.
4.4 Counterintelligence Inquiries. Activities undertaken to determine whether a particular U.S. person is acting for, or on behalf of, a foreign power for purposes of conducting espionage and other intelligence activities, sabotage, assassinations, international terrorist activities, and actions to neutralize such acts.
4.5 Counterintelligence Support Plan (CISP). A plan that defines specific counterintelligence (CI) support to be provided to the research, development, and acquisition (RDA) programs to include test and evaluation programs and provides the servicing CI personnel with information about the facility or program being supported.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
DISAI 240-110-43
4.6 Program Protection Plan (PPP). The single source document used by the Program Manager (PM) to coordinate and integrate all protection efforts designed to deny access to Critical Program Information (CPI) to anyone not authorized or not having a need-to-know and prevent inadvertent disclosure of leading edge technology to foreign interests. If there is to be foreign involvement in any aspect of the program, or foreign access to the system or its related information, the PPP will contain provisions to deny inadvertent or unauthorized access.
5. Objective. The Insider Threat Program provides the workforce with an understanding of the threats that malicious insiders present to the Agency's mission and the ability to be able to identify and report contacts, activities, indicators, and behaviors of potential insider activities.
6. Policy. Insider threat considerations shall be included in mission planning in order to ensure all persons involved are aware of indicators, activities, behaviors, and contacts associated with identifying a potential insider threat.
6.1 An Insider Threat Program is a command responsibility and an operational function that will be integrated into all organizational activities. In order for the Insider Threat Program to be successful, it must be coordinated, integrated, and mutually supportive.
6.2 All DISA civilian and military employees, as well as contractors, are required to report contacts, activities, indicators, and behaviors associated with a potential insider threat. Failure to report may subject the individual to judicial or administrative action, or both, pursuant to applicable law and regulation. (Reporting requirements, as prescribed in DoD Directive 5240.06, Counterintelligence Awareness and Reporting (CIAR) (authority document), are provided in enclosures 1, 2, and 3 and, as relayed in the DoD Insider Threat Implementation Plan, in enclosure 4.)
7. (U//FOUO) Executive Accountabilities.
7.1 Workforce Services Executive (WSE). The WSE presides over the Insider Threat Program as the Senior Official and is accountable for:
7.1.1 Notifying the Director and Vice Director of all insider threat activities that result in a counterintelligence (CI) inquiry and that are forwarded to the supporting Military Department CI Organization (MDCO), currently Army Military Intelligence (MI), or the Federal Bureau of Investigation (FBI).
7.1.2 Appointing an Insider Threat Program Manager.
7.1.3 Ensuring members of the Insider Threat Team meet all requirements identified in the Insider Threat Program Minimum Requirements, signed by the President of the United States.
7.2 Workforce Services and Development Directorate (WSD) Chief, Security Division and Counterintelligence (MP6). The Chief, MP6, oversees the Insider Threat Program and is accountable for:
7.2.1 Notifying the WSE of all reported insider threat activities that result in a CI inquiry and that are forwarded to the supporting MDCO, currently Army MI, or the FBI.
7.2.2 Immediately reporting contacts, activities, indicators, and behaviors associated with a potential insider threat to the Insider Threat Team.
7.2.3 Entering all personnel security actions of civilian, military, and contractor employees in the employee's folder contained in the Corporate Management Information System (CMIS).
7.2.4 Notifying the Insider Threat Team of all requests for information from the adjudication facility to include all employee responses.
7.3 Directors, Executives, Commanders, and Chiefs of Major Organizational Elements.
These individuals are accountable for:
7.3.1 Ensuring all of the civilian, military, and contractor personnel in their organization immediately report contacts, activities, indicators, and behaviors associated with a potential insider threat incident to the Insider Threat Team.
7.3.2 Ensuring all employees within their organizations report all foreign travel.
7.3.3 Ensuring all employees within their organization complete Counterintelligence/Insider Threat Training within 30 days of initial assignment to DISA and each year thereafter.
7.3.4 Ensuring all employees within their organization are informed of their reporting requirements and the potential actions for a Failure to Report.
7.3.5 Coordinating with the Insider Threat Program Manager prior to terminating employment of civilian or military or release of a contractor prior to any actions.
7.4 Director for Operations Center (OPC). The Director, OPC, is accountable for:
7.4.1 Reporting, upon discovery, all contacts, activities, indicators, and behaviors associated with a potential insider threat incident which occur on any network monitoring element (CNDSP, IA, DLP, HBSS, et al.) to the Insider Threat Team.
7.4.2 Ensuring activities that may be alerting to a person committing a potential insider threat act do not occur prior to reporting to or consulting with the Insider Threat Team. (These activities include, but are not limited to, confiscating Government Furnished Equipment (GFE);
terminating or suspending accounts; or removing any items, software, or programs from GFE.)
7.5 Risk Management Executive (RME). The RME is accountable for:
7.5.1 Acquiring and employing a User Activity Monitoring (UAM) capability on all DISA networks in order to detect activity indicative of insider threat behavior.
7.5.2 Ensuring UAM capability meets Committee on National Security Systems Directive (CNSSD) 504 minimum capabilities to collect user activity data; i.e,, key stroke monitoring and full application (e.g., mail, chat, data import, data export), obtain screen captures, and perform file shadowing.
7.5.3 Ensuring UAM data is attributable to a specific user.
8. (U//FOUO) Program Manager Duties. The Program Manager maintains the Insider Threat Program for the Agency and will:
8.1 Report insider threat activities with potential foreign intelligence entity (FIE) threats to the supporting MDCO or FBI within 72 hours.
8.2 Ensure comprehensive insider threat annual training is conducted in person every 3 years at each DISA location. (Computer-based training [CbT] will be used for annual refresher training.)
8.3 Implement a foreign travel and foreign contact reporting system for use by civilian and military personnel, including contractors.
8.4 Conduct foreign travel and foreign contact reporting briefs and debriefs and report unusual activity or anomalies, as appropriate.
8.5 Conduct analysis of foreign travel and foreign contact reporting to identify indicators associated with a potential insider threat.
8.6 Coordinate with Army MI or FBI for further evaluations of potential insider threat referrals.
8.7 Collect information in support of insider threat, as authorized per DoD Directives and Instructions, by using the least intrusive means and only information that is publicly available.
8.8 Coordinate with the DISA Office of Inspector General (OIG) in all matters related to law enforcement, including but not limited to, matters related to U.S. persons.
8.9 Coordinate with the DISA Office of General Counsel (OGC) in all matters relating to insider threat activities to ensure adherence to all applicable laws, U.S. codes, and regulations and obtain guidance from OGC for any activity involving the collection of information related to U.S. persons.
8.10 Coordinate with the DISA Security Division (MP6) in all matters related to potential security violations or incidents.
8.11 Conduct insider threat training as part of Counterintelligence Support Plan (CISP) to support Program Protection Plans (PPPs).
8.12 Coordinate with Agency Information Assurance, Network Security, DISA Command Center (DCC), and Network Assurance divisions supporting the DISA Network to develop, maintain, and conduct network monitoring of user activity on United States Government (USG) networks. (This includes audit data collection for insider threat detection and leveraging hard-ware and/or software with triggers deployed on classified and unclassified systems to detect, monitor, and analyze anomalous user behavior for indicators of misuse.)
8.13 Ensure all unauthorized personal electronic devices (PEDs) discovered in DISA facilities are retained by the DISA Security Division (MP6) and that a complete analysis is conducted by the Insider Threat Team in order to ascertain if national security information is contained on the device.
9. Workforce Services and Development Directorate (WSD) Chief, Civilian Personnel Division (MP1), and All Human Resources (HR) Field Advisors. These individuals will ensure all unfavorable personnel actions are immediately reported to the Insider Threat Team.
10. Reporting. An indicator, activity, behavior, or contact associated with identifying a potential insider threat is to be reported by e-mail at disa.meade.wsd.mbx.mp6-insider-threat@mail.mil or by phone at (301) 225-1411 or (301) 225-1532.
4 Enclosures a/s MARK E. ROSENSTEIN Colonel, USA Chief of Staff
SUMMARY OF SIGNIFICANT CHANGES. This revision reflects additional guidance from the Under Secretary of Defense for Intelligence for insider threat programs and multiple changes as a result of Agency reorganization.
*This Instruction replaces DISAI 240-110-43, 20 August 2013.
OPR: WSD - disa.meade.mps.mbx.mps-front-office@mail.mil DISTRIBUTION: Not for public release - FOIA Exemption
Enclosure 1
REPORTABLE FOREIGN INTELLIGENCE
CONTACTS, ACTIVITIES, INDICATORS, AND BEHAVIORS
1. When not related to official duties, contact with anyone known or believed to have information of planned, attempted, actual, or suspected espionage, sabotage, subversion, or other intelligence activities against DoD facilities, organizations, personnel, or informa-tion systems. This includes contact through Social Networking Site (SNS) that is not related to official duties.
2. Contact with an individual who is known or suspected of being associated with a foreign intelligence or security organization.
3. Visits to foreign diplomatic facilities that are unexplained or inconsistent with an individual’s official duties.
4. Acquiring, or permitting others to acquire, unauthorized access to classified or sensitive information systems.
5. Attempts to obtain classified or sensitive information by an individual not authorized to receive such information.
6. Persons attempting to obtain access to sensitive information inconsistent with their duty requirements.
7. Attempting to expand access to classified information by volunteering for assignments or duties beyond the normal scope of responsibilities.
8. Discovery of suspected listening or surveillance devices in classified or secure areas.
9. Unauthorized possession or operation of cameras, recording devices, computers, and communication devices where classified information is handled or stored.
10. Discussions of classified information over a nonsecure communication device.
11. Reading or discussing classified or sensitive information in a location where such activity is not permitted.
12. Transmitting or transporting classified information by unsecured or unauthorized means.
13. Removing or sending classified or sensitive material out of secured areas without proper authorization.
14. Unauthorized storage of classified material, regardless of medium or location, to include unauthorized storage of classified material at home.
15. Unauthorized copying, printing, faxing, e-mailing, or transmitting classified material.
16. Improperly removing classification markings from documents or improperly changing classification markings on documents.
17. Unwarranted work outside of normal duty hours.
18. Attempts to entice co-workers into criminal situations that could lead to blackmail or extortion.
19. Attempts to entice DoD personnel or contractors into situations that could place them in a compromising position.
20. Attempts to place DoD personnel or contractors under obligation through special treatment, favors, gifts, or money.
21. Requests for witness signatures certifying the destruction of classified information when the witness did not observe the destruction.
22. Requests for DoD information that make an individual suspicious, to include suspicious or questionable requests over the Internet or SNS.
23. Trips to foreign countries that are short trips inconsistent with logical vacation travel or not part of official duties or trips inconsistent with an individual’s financial ability and official duties.
24. Unexplained or undue affluence; such as, expensive purchases an individual’s income does not logically support; attempts to explain wealth by reference to an inheritance, luck in gambling, or a successful business venture; or sudden reversal of a bad financial situation or repayment of large debts.
Enclosure 2
REPORTABLE INTERNATIONAL TERRORISM
1. Advocating violence, the threat of violence, or the use of force to achieve goals on behalf of a known or suspected inter-national terrorist organization.
2. Advocating support for known or suspected international terrorist organizations or objectives.
3. Providing financial or other material support to a known or suspected international terrorist organization or to someone suspected of being an international terrorist.
4. Procuring supplies and equipment, to include purchasing bomb making materials or obtaining information about the construction of explosives, on behalf of a known or suspected international terrorist organization.
5. Contact, association, or connections to known or suspected international terrorists, including online, e-mail, and social networking contacts.
6. Expressing an obligation to engage in violence in support of known or suspected international terrorism or inciting others to do the same.
7. Any attempt to recruit personnel on behalf of a known or suspected international terrorist organization or for terrorist activities.
8. Collecting intelligence, including information regarding installation security, on behalf of a known or suspected international terrorist organization.
9. Familial ties, or other close associations, to known or suspected international terrorists or terrorist supporters.
10. Repeated browsing or visiting known or suspected international terrorist Web sites that promote or advocate violence directed against the United States or U.S. forces, or that promote international terrorism or terrorist themes, without official sanction in the performance of duty.
Enclosure 3
REPORTABLE FOREIGN INTELLIGENCE ENTITY (FIE)-ASSOCIATED CYBERSPACE
1. Actual or attempted unauthorized access into U.S. automated information systems and unauthorized transmissions of classified or controlled unclassified information.
2. Password cracking, key logging, encryption, steganography, privilege escalation, and account masquerading.
3. Network spillage incidents or information compromise.
4. Use of DoD account credentials by unauthorized parties.
5. Tampering with or introducing unauthorized elements into information systems.
6. Unauthorized downloads or uploads of sensitive data.
7. Unauthorized use of Universal Serial Bus, removable media, or other transfer devices.
8. Downloading or installing nonapproved computer applications.
9. Unauthorized network access.
10. Unauthorized e-mail traffic to foreign destinations.
11. Denial of service attacks or suspicious network communications failures.
12. Excessive and abnormal intranet browsing, beyond the individual's duties and responsibilities, of internal file servers or other networked system contents.
13. Any credible anomaly, finding, observation, or indicator associated with other activity or behavior that may also be an indicator of terrorism or espionage.
14. Data exfiltrated to unauthorized domains.
15. Unexplained storage of encrypted data.
16. Unexplained user accounts.
17. Hacking or cracking activities.
18. Social engineering, electronic elicitation, e-mail spoofing or spear phishing.
19. Malicious codes or blended threats such as viruses, worms, trojans, logic bombs, malware, spyware, or browser hijackers, especially those used for clandestine data exfiltration.
Enclosure 4
REPORTABLE KEY INDICATORS OF POTENTIALLY VIOLENT BEHAVIOR
1. Direct, indirect, or veiled threats of harm or violence
2. Intimidating, belligerent, harassing, bullying, or aggressive behavior
3. Numerous conflicts with supervisors and other employees
4. Bringing a weapon to the workplace, brandishing a weapon in the workplace, making inappropriate references to guns, or unusual fascination with weapons
5. Statements indicating the individual is involved in criminal activity
6. Statements showing fascination with incidents of workplace violence that is so unusual as to indicate potential criminal activity, statements indicating approval of the use of violence to resolve a problem, or statements indicating identification with perpetrators of workplace homicides
7. Statements indicating desperation (over family, financial, and other personal problems) to the point of contemplating suicide
8. Pending or recent job layoff
9. Drug/alcohol abuse
10. Extreme changes in behavior, personality, or performance
11. Acquisition of multiple weapons
12. Escalation in target practice and weapons training
13. Menacing actions with weapons
14. Interest in explosives
15. Interest in previous shootings or mass attacks
16. Conveying a direct or veiled threat of violence to a third party
17. Physical assault or physical violence
18. Physical restraint or confinement
19. Stalking or surveillance of individual(s)
20. Damages or destroys property
21. Blatant or intentional disregard for the safety of others
22. Disruptive, aggressive, or angry language
23. Poor work performance
24. Disciplinary problems at work site
25. Commission of a violent misdemeanor or felony at work site
26. Delusional statements or paranoid ideas
27. Development of a personal grievance
28. Increased isolation
29. Odd or bizarre behavior
30. Loss of personal relationship (divorce, breakup, family member death)
31. Depressed mood
32. Suicidal ideation expressed
| 2017-05-26T14:08:34-0400 | |
| ROSENSTEIN.MARK.ERIC.1078644431 |
File details come from the government source that posted it. Updated .