Bidders Library Security - DISAI 240-115-04.pdf
PDF 86 KB Posted
- Attached to
- TEC II Services RFP Federal contract opportunity
- Solicitation number
- HC102821R0006
- Issued by
- Defense Information Systems Agency
About this file
This Defense Information Systems Agency instruction outlines responsibilities for responding to classified data spillages on the DISA network. Key stakeholders must promptly report, document, and address any potential or confirmed spillages at the secret level or below. The Global Service Desk will notify relevant parties and ensure appropriate response actions. The IT Services Division will disable accounts, archive information, and sanitize impacted assets. The Security Division must meet policy requirements, coordinate with IT, and report additional details as needed. All network users and employees must immediately report any spillages and follow guidance.
View the file
Other files for this federal contract opportunity
Show all 50
TEC II Services RFP has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DEFENSE INFORMATION SYSTEMS AGENCY
P. O. BOX 549
FORT MEADE, MARYLAND 20755-0549
UNCLASSIFIED//FOR OFFICIAL USE ONLY
DISA INSTRUCTION 240-115-4* 4 December 2017
COMMUNICATIONS SECURITY
Spillages on the DISA Network (DISANet)
1. Purpose. This Instruction assigns responsibilities and duties for spillages on the DISA network (DISANet).
2. Applicability. This Instruction applies to all Defense Information Systems Agency (DISA) activities and the Joint Force Headquarters – Department of Defense Information Network (JFHQ-DoDIN).
3. Scope. This Instruction applies to spillages on the DISANet at the classification level of secret or below.
4. Authority. This Instruction is published in accordance with the authority contained in DoD Manual 5200.01-M, Volume 3, DoD Information Security Program: Protection of Classified Information, 24 February 2012, and DoD Instruction (DoDI) 5200.01, DoD Information Security Program and Protection of Sensitive Compartmented Information (SCI), 21 April 2016.
5. General.
5.1 In accordance with Volume 3 of DoD 5200.01-M (authority document), classified data spills occur when classified data is introduced either onto an unclassified information system (IS) or to an IS with a lower level of classification or to a system not accredited to process data of that restrictive category. Although it is possible that an unauthorized disclosure did not occur, classi-fied data spills are considered and handled as a possible compromise of classified information involving ISs, networks, and computer equipment until the inquiry determines whether an unauthorized disclosure did or did not occur.
5.2 In accordance with DoDI 5200.01 (authority document), overall security responsibility for protection of classified information and controlled unclassified information (CUI) remains with the information security program and staff, even though the data and/or information resides on information technology (IT) and ISs and networks managed and controlled by the DoD Chief Information Officer (CIO). Accordingly, proactive and continuous engagement and collabora-tion between security, IT, information assurance (IA), and security professionals, at all organiza-tional levels, are essential in order to ensure the protection of DoD information, as well as the Department's electronic enterprise.
DISAI 240-115-4
6. Responsibilities.
6.1 Director for Operations Center (OC). The Director, OC, designated as the DISA Chief Information Officer (CIO), will oversee the Agency's policy and guidance for spillages on the DISANet through the Services Directorate (SE) IT Services Division (SE6).
6.2 (U/FOUO) Directors, Executives, Commanders, and Chiefs of Major Organizational Elements. These individuals will ensure all personnel are aware of their individual responsi-bility for properly protecting classified information and CUI under their custody and control to include the prompt reporting of any potential or confirmed compromises of said information.
(Financial reimbursement for asset cleanup activities and DoD Enterprise E-mail (DEE) spillages is to be provided to the SE IT Services Division (SE6) by the organization responsible for a potential or confirmed spill.)
7. Duties.
7.1 Chief, Global Service Desk (GSD). The Chief, GSD, located in the Operations Center (OC) Resource Management Directorate (OC) Mission Support Division (OCM), will:
7.1.1 Document and bring attention to any and all incidents involving potential or confirmed compromises of classified information.
7.1.2 Ensure appropriate spillage reporting and response actions are taken by completing a standardized spillage checklist and ensure incident management processes are followed.
7.1.3 Provide guidance on spillage cleanup to the customer.
7.1.4 (U/FOUO) Provide notification to the appropriate stakeholders of a potential or confirmed spill. (Notification is made to (1) the DISA Spillage E-mail Distribution List,
(2) DISA Ft Meade SE List Spillage Notification Distribution mailbox at disa.meade.se.list.
spillage-notification-distro@ mail.mil, (3) Workforce Services and Development Directorate (WSD) Security Division (MP6), (4) DISANet Information System Security Managers (ISSMs), and (5) incident response personnel.)
7.1.5 Notify the SE IT Services Division (SE6) of any spillages that may have affected DISANet assets, including servers, shared drives, and printers, and ensure the appropriate Program Manager(s) of any additional affected systems, such as DEE, Defense Enterprise Portal Service (DEPS), mobility, etc., are also notified for action.
7.2 Operations Center (OC) Services Directorate (SE) Chief, DISANet IT Services Division (SE6). The OC SE Chief, SE6, will:
7.2.1 Validate the spillage checklist documented by the GSD and create a Tier 3 checklist to be forwarded to the WSD Security Division (MP6) and appropriate stakeholders.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
7.2.2 Archive spill information as official evidence and provide spill information to the WSD Security Division (MP6) if contained within the desktop or laptop hard drive, server infrastruc-ture, or share drive.
7.2.3 Disable DISANet local area network (LAN) accounts and DEE mailboxes immediately, upon notification of a spillage, until advised by the WSD Security Division (MP6) that the investigation has been accomplished and that clearing and sanitization has been completed by appropriate stakeholders.
7.2.4 Take actions required for clearing or sanitizing classified information from all impacted DISANet assets.
7.2.5 Report the completion of clearing or sanitizing of a spillage to the DISA Spillage E-mail Distribution List.
7.3 Workforce Service and Development Directorate (WSD) Chief, Security Division (MP6). The WSD Chief, MP6, will:
7.3.1 Ensure policy requirements for addressing an unauthorized disclosure are met when a classified data spill occurs (e.g., notification, inquiry, damage assessment), as specified in Volume 3 of DoD 5200.01-M (authority document). (These requirements must be carried out in close coordination with the IT and/or IA staff, which have overall responsibility for the operation of the networks and systems, as well as the technical knowledge required to address the spill. Information security personnel have the overall lead for addressing such events.)
7.3.2 Report additional incident details that are identified and would increase the scope of the originally reported incident; such as, the existence of other prints, copies, e-mails, etc., and/or if the computer(s) involved were connected to other networks; such as, a home network.
7.3.3 Report the classification of suspected or identified spillage information, as determined by the appropriate information owner or subject matter expert (SME) who shall utilize the appropriate classification guide governing the information.
7.3.4 Report confirmed classification of spillage information to the DISA Spillage E-mail Distribution List.
7.4 DISANet Users and DISA Employees. These individuals will:
7.4.1 Immediately report any identified or suspected spillages to the Global Service Desk (GSD). (The GSD may be contacted at (301) 225-0000 (option 2).)
7.4.2 Safeguard the device at the classification level of the information involved in the spillage.
7.4.3 Follow guidance provided by the WSD Security Division (MP6), IT Services Division (SE6) response team, and GSD.
JOEL S. LINDEMAN
Colonel, USA Chief of Staff
*This Instruction replaces DISAI 240-115-4, 20 May 2015.
OPR: OC SE6 - disa.meade.eis.mbx.eis-front-office@mail.mil DISTRIBUTION: Not For Public Release - FOIA Exemption mailto:disa.meade.eis.mbx.eis-front-office@mail.mil
| 2017-12-05T17:36:34-0500 | |
| LINDEMAN.JOEL.STEVEN.1040296189 |
File details come from the government source that posted it. Updated .