Bidders Library Security - DISAI 630-230-19.pdf
PDF 282 KB Posted
- Attached to
- TEC II Services RFP Federal contract opportunity
- Solicitation number
- HC102821R0006
- Issued by
- Defense Information Systems Agency
About this file
This is a solicitation for test, evaluation, and certification services. The Defense Information Systems Agency seeks a contractor to provide Test, Evaluation, and Certification services for the Joint Interoperability Test Command. Services will include testing and certification of systems to verify interoperability, cybersecurity, and compliance with standards. The solicitation number is HC102821R0006. Interested offerors should review the full requirements and instructions and submit proposals in accordance with the response date listed on FedBizOpps.
View the file
Other files for this federal contract opportunity
Show all 50
TEC II Services RFP has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DEFENSE INFORMATION SYSTEMS AGENCY
P. O. BOX 549
FORT MEADE, MARYLAND 20755-0549
UNCLASSIFIED//FOR OFFICIAL USE ONLY
DISA INSTRUCTION 630-230-19* 8 August 2017
CYBERSECURITY
Cybersecurity
1. Purpose. This Instruction prescribes policy and assigns responsibilities and duties for cybersecurity.
2. (U//FOUO) Applicability. This Instruction applies to all DISA military and civilian employees and Agency contractors at DISA activities. It also applies to all personnel authorized to use DISA information systems (ISs), platform information technology (PIT) systems, communications, and networks.
3. (U//FOUO) Scope. This Instruction pertains to DISA ISs that receive, process, store, display, or transmit DoD information residing on the nonclassified Department of Defense information networks (DoDIN), classified DoDIN, Combined Enterprise Regional Information Exchange (CENTRIX), Griffin, and All Partners Access Network (APAN) to include ISs supporting production, research, development, test and evaluation (T&E) laboratory, and DISA controlled ISs operated by a contractor or other entity on behalf of DISA.
4. Authority. This Instruction is published in accordance with (IAW) the authority contained in DoD Instruction (DoDI) 8500.01, Cybersecurity, 14 March 2014; DoDI 8510.01, Risk Management Framework (RMF) for DoD Information Technology (IT), 12 March 2014; and DoD Directive (DoDD) 5105.19, Defense Information Systems Agency (DISA), 25 July 2006.
(The guidance provided in this Instruction is intended to be consistent with Federal, DoD, and DISA policies and guidance that address cybersecurity. Where conflicts arise, Federal and DoD policy and guidance take precedence. Nothing in this Instruction alters or supersedes the existing authorities and policies of the Director of National Intelligence (DNI) regarding the protection of sensitive compartmented information (SCI), as directed by Executive Order 12333, United States Intelligence Activities, 4 December 1981. Conflicts identified should be documented and presented to the DISA Authorizing Official (AO) for reconciliation.)
5. References.
5.1 DoD 8570.01-M, Information Assurance Workforce Improvement Program, 19 December 2005, incorporating change 4, 10 November 2015.
5.2 CJCSI 6510.01F, Information Assurance (IA) and Support to Computer Network Defense (CND), 9 February 2011.
DISAI 630-230-19
UNCLASSIFIED//FOR OFFICIAL USE ONLY
6. Definitions. Definitions are provided at enclosure 1.
7. (U//FOUO) Policy. DISA information shall be properly managed and appropriately protected commensurate with its level of sensitivity and magnitude of potential harm resulting from loss, misuse, authorized access, or modification that could adversely affect the national interest or assured delivery for DISA systems.
7.1 (U//FOUO) The appropriate level of access shall be granted to users authorized to access DISA-owned or -controlled ISs that receive, process, store, display, or transmit DoD information.
7.2 (U//FOUO) Authorized users of DISA ISs, including the cybersecurity workforce, shall receive initial DoD Cyber Awareness Challenge training as a condition of authorized access to the DISA network and complete annual refresher awareness training, as directed.
7.3 (U//FOUO) Authorized users of DISA ISs, including the cybersecurity workforce, shall review, agree to compliance requirements by signature, and upload a signed DISA Form 786:
DISA Statement of Information System Use and Acknowledgement of User Responsibilities (Basic User), into the DISA Corporate Management Information System (CMIS). Designated individuals required to perform any full-time, part-time, or embedded cybersecurity duties that require privileged access (i.e., Privileged Access Positions) shall complete a separate DISA Form 787: DISA Statement of Information System Use and Acknowledgement of User Responsibilities (Privileged User), which acknowledges consent to the terms in the subject agreement.
7.4 (U//FOUO) DISA civilians, military, and contractors required to perform any full-time, part-time, or embedded cybersecurity duties, to include System Administrator (SA) or Network Administrator (NA) with privileged access, regardless of the job series being held, shall be fully qualified, trained, and certified to DoD baseline requirements to perform their cybersecurity duties.
7.5 (U//FOUO) Cybersecurity personnel billets for civilians and military shall be appropriately identified (prior to onboarding or change in work duties [role(s)]), tracked, and managed in CMIS by information assurance (IA) category and level.
7.6 (U//FOUO) Cybersecurity training and certification will be completed by all designated cybersecurity workforce employees, as required by DoD Manual 8570.01-M, Information Assurance Workforce Improvement Program (reference 5.1); Chairman of the Joint Chiefs of Staff Instruction (CJCSI) 6510.01F, Information Assurance (IA) and Support to Computer Network Defense (CND) (reference 5.2); and DoD Instruction (DoDI) 8500.01, Cybersecurity (authority document).
7.6.1 (U//FOUO) DISA personnel possessing a cybersecurity certification shall enter their certification information in the DoD Workforce Certification Application (DWCA) at https://www.dmdc.osd.mil/appj/dwc/.
7.6.2 (U//FOUO) DISA personnel possessing a cybersecurity certification shall provide evidence of such qualifications to their designated directorate-level Information System Security Manager (ISSM). (Qualifications are outlined in the DISA Information Assurance Implementation Manual. [Refer to paragraph 11 for information regarding the manual.])
7.7 (U//FOUO) A DISA System Security Plan (SSP) shall include a documented privileged access management plan and responsibility matrix and will outline quarterly tracking procedures.
Privileged access will be reported quarterly through organizational ISSMs and tracked by system and role to the AO for tracking and management purposes. The plan is to describe specific privileged user roles, designated information technology (IT) positions, and DoD IA workforce categories, operation and maintenance functions, specialties, and levels. In addition, the plan is to include primary authentication mechanisms for roles and other two-factor mechanisms for roles that cannot use public key infrastructure (PKI) authentication. (A privileged access management plan is reviewed and approved collectively by the risk management framework [RMF] team.)
7.8 (U//FOUO) Authorized unsupervised privileged access accounts will only be issued to DISA personnel who maintain a requisite security clearance for the IT position that is held.
The personnel must successfully meet and maintain mandatory training and baseline certification requirements IAW DoD IA workforce categories, specialties, and levels including DISA-specific certifications for operating systems and/or security-related tools and devices that are employed and supported by DISA (i.e., Computing Environment [CE], CISCO router, etc.). The personnel must also maintain a signed Privileged Access Agreement (DISA Form 787).
7.9 (U//FOUO) Designated privileged access users who are required to perform multiple roles IAW DoD IA workforce categories and levels must be certified to the highest-level role(s) performed, as required by DoD 8570.01-M (reference 5.1). (The function of the role for a particular level establishes the basis for the individual's certification requirements. Information Assurance Technical (IAT) category functions are cumulative, and an IAT level II or III role requires mastery of the functions of the preceding levels.)
7.10 (U//FOUO) A privileged access user's system account(s) will be deactivated and privileged access rights revoked when personnel in positions are not meeting qualification requirements or are not maintaining proper DoD IA workforce continuing education requirements.
7.11 (U//FOUO) A privileged access user will use nonprivileged accounts for routine and/or day-to-day activity. Privileged accounts shall not be used for e-mail, Web browsing, office functions, etc. Changes to a privileged access user's status shall be immediately reported to the AO through the organizational-level ISSM. (Status changes include, but are not limited to, employment, contract, security clearance, conduct investigations, violations of DISA policy, and security incidents.)
7.12 (U//FOUO) The ISs, PIT systems, communications, and networks shall be assessed and authorized IAW the RMF.
7.13 (U//FOUO) All DISA ISs, both unclassified and classified, that operate under the DISA AO authorization will report Cybersecurity Scorecard surveys monthly via the DoD Cyberscope on the Secret Internet Protocol Router Network (SIPRNet) Defense Collaboration Services (DCS-S) at https://emass-ers.csd.disa.smil.mil/.
7.14 (U//FOUO) All DISA ISs and computer networks will register with Systems/Network Approval Process (SNAP), Enterprise Mission Assurance Support Service (eMASS), and a Cyber Security Service Provider (CSSP), and all circuits will be equipped with the appro-priate sensors for monitoring, detecting, and isolating unauthorized activity to protect network operations.
7.15 (U//FOUO) All ISs shall comply with the U.S. Cyber Command (USCYBERCOM) cybersecurity directions, orders, and taskings.
7.16 (U//FOUO) Investment portfolios shall integrate cybersecurity requirements into all phases of portfolio execution, including system development and life-cycle management.
7.17 (U//FOUO) A plan of action and milestones (POA&M) must be developed to address known vulnerabilities to include those inherited in all ISs on PIT systems. A POA&M will be maintained throughout the IS life cycle. Vulnerabilities listed in the POA&M are never removed, but may be marked "closed" after correction or mitigation actions have been completed. (Procedures for maintaining a POA&M are documented in the DISA Information Assurance Implementation Manual. [Refer to paragraph 11 for information regarding the manual.])
7.18 (U//FOUO) To ensure compliance with DoD, USCYBERCOM, and DISA policies pertaining to POA&M management, DISA organizations supporting mission partners will coordinate with the mission partner ISs program manager. (Procedures for coordinating with the mission partner ISs program manager are outlined in the DISA Information Assurance Implementation Manual. [Refer to paragraph 11 for information regarding the manual.])
7.19 (U//FOUO) Continuous monitoring capabilities will be implemented IAW RMF procedures, as documented in DoDI 8510.01, Risk Management Framework (RMF) for DoD Information Technology (IT) (authority document).
7.20 (U//FOUO) All ISs will utilize the latest versions of antivirus or antimalware while maintaining updated signatures and definitions files and will utilize data encryption and safeguard removable media.
7.21 (U//FOUO) All personnel will be familiar with protection of personally identifiable information (PII) and protected health information (PHI) and will review incident manage-ment procedures on the handling of spillages and breaches.
UNCLASSIFIED//FOR OFFICIAL USE ONLY
8. (U//FOUO) Responsibilities. Responsibilities for senior-level cybersecurity officials are assigned in enclosure 2.
9. (U//FOUO) Delegated Authorities. Authorities delegated to the Directors, Executives, Commanders, and Chiefs of major organizational elements in general and to specific Directors and Executives are delineated in enclosure 3.
10. (U//FOUO) Duties. Duties for cybersecurity defense personnel are assigned in enclosure 4.
11. DISA Information Assurance Implementation Manual. The DISA Information Assurance Implementation Manual, June 2008, version 1.0, approved by the DISA Chief Information Officer (CIO), serves as a companion document to this Instruction and addresses IA issues within the Agency. It provides direction for implementing, managing, and maintain-ing IA for the Agency, its concepts, and its application within DISA. The manual is located on the Risk Management Executive (RME) Cybersecurity and Policy Division Web site on the DoD Enterprise Portal Service (DEPS). (Scroll on "Centers," "Fifth Estate," "RME – Risk Management Executive," and "RE2 – Cybersecurity Policy and Strategy Division." Click on "RE2 Shared Documents" on left side of screen. Click on "IA Documentation" on left side of screen. Click on "IA Implementation Manual Version 1 2008" to view the manual.)
12. Related Authority and Reference Documents. Authority and reference documents pertaining to cybersecurity that are not cited in the Instruction but are cited in enclosures 2, 3, and 4 are detailed in enclosure 5.
5 Enclosures a/s ANDRES A. LOPEZ Chief of Staff (Acting)
SUMMARY OF SIGNIFICANT CHANGES. This revision assigns roles and responsibilities specific to the current DISA organization and DISA cybersecurity environment. The title was changed from "Information Assurance" to "Cybersecurity" to reflect updated DoD guidance.
*This Instruction replaces DISAI 230-630-19, 2 March 2007.
OPR: RME RE2 - disa.meade.re.mbx.re2-policy@mail.mil DISTRIBUTION: Restricted
Enclosure 1
DEFINITIONS
Authorizing Official (AO). Official with the authority to formally assume responsibility for operating a system at an acceptable level of risk. This term is synonymous with Designated Approving Authority and Delegated Accrediting Authority.
Communications Security (COMSEC). The protection resulting from all measures designed to deny unauthorized persons information of value that might be derived from the possession and study of telecom-munications or to mislead unauthorized persons in their interpretation of the results of such possession and study.
Cybersecurity. The prevention of damage to, protection of, and restoration of computers, electronic communication systems, electronic communication services, wire communication, and electronic communication, including information contained therein, to ensure its availability, integrity, authen-tication, confidentiality, and nonrepudiation.
Cybersecurity Professional. An individual assigned the responsibility of ensuring the availability, integrity, authentication, confidentiality, and nonrepudiation of DoD information systems (ISs) (e.g., information system security managers, program managers, network security officers, etc.).
Cybersecurity Service Provider (CSSP). Organization responsible for delivering protection, detection, and response services to its users.
Defense Information Assurance Security and Accreditation Working Group (DSAWG).
The first accreditation or accreditation review level for the transport, network management, and network segments of the Defense Information Systems Network (DISN) for the Department of Defense information networks (DODIN). In addition, as the community jury for evaluating risk to the DISN and/or DODIN, the DSAWG reviews specific topic areas assigned by the DISN and/or DODIN Principal Accrediting Authorities (PAAs) in their capacity as the DoD Information Security Risk Management Committee
(ISRMC).
Enclave. Collection of information systems connected by one or more internal networks under the control of a single authority and security policy.
Incident. An assessed event of attempted entry, unauthorized entry, or an information attack on an automated information system. It includes unauthorized probing and browsing; disruption or denial of service; altered or destroyed input, processing, storage, or output of information; or changes to information system hardware, firmware, or software characteristics with or without the users' knowledge, instruction, or intent.
Information System Owner (ISO). An organizational official responsible for the procurement, development, integration, modification, operation, maintenance, and disposal of an information system (IS). The IS owner is responsible for addressing the operational interests of the user community (i.e., users who require access to the IS to satisfy mission, business, or operational requirements) and for ensuring compliance with information security requirements.
Information System Security Manager (ISSM). The individual responsible for the cybersecurity program of a DoD information system (IS), network, or organization. Also known as the Information Assurance Manager (IAM).
Information System Security Officer (ISSO). An individual responsible to the Information System Security Manager (ISSM) for ensuring that the appropriate operational information assurance (IA) posture is maintained for a DoD information system (IS), network, or organization. Also known as the Information Assurance Officer (IAO).
Information Life Cycle. The stages through which information passes, typically characterized as creation or collection, processing, dissemination, use, storage, and disposition.
Information System (IS). A discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.
Information Technology (IT). Any equipment or interconnected system or subsystem of equipment that is used in the automatic acquisition, storage, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the DoD component. The term "information technology" includes computers, ancillary equipment, software, and firmware and similar procedures, services (including support services), and related sources. It also includes the National Security System (NSS). Notwithstanding the above, the term "information technology" does not include any equipment that is acquired by a federal contractor incidental to a federal contract.
Mission Area. A defined area of responsibility with functions and processes that contribute to mission accomplishment.
Privileged Access. An authorized user who has access to system control, monitoring, administration, criminal investigation, or compliance functions.
Security Control Assessor (SCA). The official responsible for performing the comprehensive evaluation of the technical and nontechnical security features of an information technology (IT) system and other safeguards made in support of the authorization process to establish the extent that particular design and implementation meet a set of specified security requirements.
Telecommunication. Any transmission, emission, or reception of signs, signals, writings, images, sounds, or information of any nature by wire, radio, visual, or other electromagnetic systems.
Vulnerability Assessment. Systematic examination of an information system (IS) or product to determine the adequacy of security measures, identify security deficiencies, provide data from which to predict the effectiveness of proposed security measures, and confirm the adequacy of such measures after implementation.
Enclosure 2
RESPONSIBILITIES FOR SENIOR-LEVEL CYBERSECURITY OFFICIALS
1. Chief Information Officer (CIO). The CIO will:
1.1 (U//FOUO) Ensure DISA personnel are trained on how to conduct timely reporting of all detected threats to their respective Cyber Security Service Provider (CSSP).
1.2 (U//FOUO) Provide situational awareness to the DISA organizations of any internal element or command analysis; information or warnings pertaining to intrusions, attacks, suspicious activities, known vulnerabilities, mitigation strategies; or changes that cause major impacts to the network or systems.
1.3 (U//FOUO) Appoint the DISA Senior Information Security Officer (SISO) to direct and coordinate the cybersecurity for the Agency.
2. Authorizing Official (AO). The AO will:
2.1 (U//FOUO) Maintain oversight and management for DISA risk management and cybersecurity.
2.2 (U//FOUO) Ensure DoD information systems (ISs) and platform information technology (PIT) systems are categorized according to the guidelines provided in the risk management framework framework (RMF).
2.3 (U//FOUO) Verify that a Program Manager (PM) or Information System Owner (ISO) has been appointed, in writing, for all ISs and PIT systems.
2.4 (U//FOUO) Ensure personnel engaged in or supporting the RMF are trained and possess professional certifications, as appropriate.
2.5 (U//FOUO) Participate in the DoD Information Security Risk Management Committee (ISRMC), as directed by the Director, DISA.
2.6 (U//FOUO) Develop and implement DISA's cybersecurity policy and serve as the AO for all systems under DISA control that are not otherwise assigned by higher authority.
2.7 (U//FOUO) Develop and maintain an effective cybersecurity policy that identifies cybersecurity architecture, requirements, objectives, policies, processes, and procedures.
2.8 (U//FOUO) Oversee DISA's information assurance vulnerability management (IAVM) and continuous monitoring.
2.9 (U//FOUO) Ensure Control Correlation Identifiers (CCIs), Security Requirements Guides (SRGs), and Security Technical Implementation Guides (STIGs) developed by DISA are consis-tent with security controls and assessment procedures used by DoD.
2.10 (U//FOUO) Ensure compliance with the Federal Information Security Management Act (FISMA) of 2014.
2.11 (U//FOUO) Ensure compliance of DISA systems and enclaves with authorization and connection approval processes mandated for all DoD ISs to include, but not be limited to, being supported by a CSSP.
2.12 (U//FOUO) Ensure appropriate cybersecurity requirements are incorporated as a key element of IS life-cycle management processes.
2.13 (U//FOUO) Oversee cybersecurity training and certification.
2.14 (U//FOUO) Ensure cybersecurity processes are integrated with DISA strategic budgeting and operational planning processes.
2.15 (U//FOUO) Ensure DISA ISs are assessed for risk and render authorization decisions for ISs and platform information technology (PIT) systems, in accordance (IAW) with DoD Manual 8570.01-M, Information Assurance Workforce Improvement Program.
2.16 (U//FOUO) Ensure compliance with all authorization decisions, including Denial of Authorization to Operate (DATO) and enforce Authorization Termination Dates (ATDs).
2.17 (U//FOUO) Advise the Director and senior leadership on cybersecurity issues.
3. Senior Information Security Officer (SISO). The SISO will:
3.1 (U//FOUO) Provide policy and procedural oversight and direction to DISA cybersecurity programs which include, but are not limited to, the Agency's RMF; assessment and authorization (A&A) process; continuous monitoring; IAVM; cross domain; ports, protocols, and services management (PPSM); connection process; whitelist process; cybersecurity compliance; and information assurance (IA) workforce certification.
3.2 (U//FOUO) Ensure the A&A function posts DISA's RMF guidance to an approved DISA Knowledge Service (KS) and that it is consistent with DoD and DISA policy and guidance.
3.3 (U//FOUO) Perform as the DISA Security Control Assessor (SCA) for governed information technology (IT) or formally delegate that function.
3.4 (U//FOUO) Facilitate the alignment and consistent application of IT and cybersecurity policies, guidelines, processes, responsibilities, and procedures across DISA.
3.5 (U//FOUO) Provide oversight and ensure maintenance of network security throughout DISA networks.
3.6 (U//FOUO) Serve as the single cybersecurity coordination point for joint or DoD-wide programs that are deploying IT to DISA's enclaves.
3.7 (U//FOUO) Serve as an advising member for all DISA cybersecurity policy forums, which include the Risk Management Framework (RMF) Technical Advisory Group (TAG), Defense Information Assurance Security and the Accreditation Working Group (DSAWG), and Enterprise Mission Assurance Support Service (eMASS) Configuration Control Board, or delegate the function.
3.8 (U//FOUO) Manage knowledge capital of policies and procedures for conducting vulnerability scans, notification processes, and tools implementation to be distributed to DISA organizations.
3.9 (U//FOUO) Ensure proper and timely acknowledgement and reporting of IAVM notices from U.S. Cyber Command (USCYBERCOM) and monitor the implementation of all IAVMs.
3.10 (U//FOUO) Oversee the DISA Cyber Scorecard and ensure it includes, but is not limited to, guidance regarding network scan management, remediation, and monitoring compliance to include operation guidance of approved security compliance systems and services.
3.11 (U//FOUO) Oversee DISA's overall IA awareness training for all users, as well as IA certi-fication and training for personnel performing CSSP functions, as identified in DoD 8570.01-M, Information Assurance Workforce Improvement Program.
3.12 (U//FOUO) Coordinate with the Workforce Services and Development Directorate (WSD) to monitor and report currency of awareness training and professional certifications as an element of cybersecurity mission readiness and as a management review item.
3.13 (U//FOUO) Coordinate with the Procurement and Logistics Directorate (PLD) to ensure contracts that include the acquisition of DoD IS cybersecurity services specify the certification requirements of DoDI 8510.01, Risk Management Framework (RMF) for DoD Information Technology (IT).
3.14 (U//FOUO) Comply with DISA written orders, directives, and instructions.
3.15 (U//FOUO) Direct and manage cybersecurity for DISA ISs and PIT systems.
3.16 (U//FOUO) Ensure implementation of continuous monitoring capabilities to the greatest extent possible.
3.17 (U//FOUO) Identify and recommend changes and improvements to the security assessment process; security, test, and evaluation; and risk assessment methodology including procedures, risk factors, assessment approach, and analysis approach to the RMF TAG for inclusion in the KS.
3.18 (U//FOUO) Ensure the A&A function manages DISA's Plan of Action and Milestones (POA&M) and ensure Information System Security Managers (ISSMs) monitor and track the execution of system-level POA&Ms for DISA-owned and -managed ISs and PIT systems, in coordination with the AO, until the vulnerabilities have been remediated and documentation appropriately adjusted.
3.19 (U//FOUO) Ensure the A&A function tracks the status of DISA ISs and PIT systems.
3.20 (U//FOUO) Ensure DISA organizations are compliant with change management (CM) plans through the A&A processes.
3.21 (U//FOUO) Ensure the A&A function enforces AO authorization decisions for hosted or interconnected ISs and PIT systems and implement the corresponding set of security controls published in the National Institute of Standards and Technology Special Publication (NIST SP) 800-53, Revision 4, Security and Privacy Controls for Federal Information Systems and Organizations, for all DISA ISs and PIT systems.
4. Security Control Assessor (SCA). The SCA will:
4.1 (U//FOUO) Establish and manage security control assessment for the Agency.
4.2 (U//FOUO) Assess DISA ISs and PIT systems regarding security risks, IAW Federal Information Processing Standard (FIPS) Publication 199, Standards for Security Categorization of Federal Information and Information Systems.
4.3 (U//FOUO) Provide verification on the configurations on ISs and PIT systems, IAW applicable DoD and DISA policies, USCYBERCOM orders, and STIGs, and ensure the configurations are aligned with the RMF.
4.4 (U//FOUO) Assess all ISs and PIT systems documentation, develop a security assessment plan for each DISA IS and PIT systems, and submit for approval.
4.5 (U//FOUO) Ensure the A&A function submits the authorization documentation to the DISA AO for approval and that it is complete and meets all the requirements of the RMF guidance prior to it being sent to the AO for approval.
4.6 (U//FOUO) Conduct a complete assessment of the ISs or PIT systems infrastructure and documentation, which includes review of POA&M for proper mitigation strategy and assessment, if applicable, to ensure security controls have been properly implemented.
4.7 (U//FOUO) Develop a security assessment report (SAR), per AO direction, to include a risk level for every noncompliant security control and an overall system level of risk.
4.8 (U//FOUO) Ensure personnel conducting security assessments are qualified IAW RMF for DoD IT, per reference DoDI 8510.01, Risk Management Framework (RMF) for DoD Information Technology (IT).
4.9 (U//FOUO) Consider all threats, vulnerabilities, and potential impacts, as well as existing and planned risk mitigations, to create a risk assessment. (A risk assessment will be used to determine the overall system cybersecurity risk posture and to make a recommendation for risk acceptance or denial to the AO.)
4.10 (U//FOUO) Report all DISA ISs and PIT systems assessment activities directly to the SISO.
4.11 (U//FOUO) Use all automated cybersecurity tools and/or capabilities to the highest extent possible to conduct an assessment and in the implementation of continuous authorizations.
4.12 (U//FOUO) Promote reciprocity to the maximum extent possible.
4.13 (U//FOUO) Comply with DISA written orders, directives, and instructions.
5. Authorizing Official Designated Representative (AODR). An AODR will:
5.1 (U//FOUO) Advise the AO on the cybersecurity adequacy of DISA ISs and PIT systems.
5.2 (U//FOUO) Ensure DISA ISs and PIT systems are operated at an acceptable level of risk reducing the threat vector of our adversaries (internal and external).
5.3 (U//FOUO) Implement continuous monitoring capabilities to the greatest extent possible.
5.4 (U//FOUO) Review security assessment plans and security plans.
5.5 (U//FOUO) Ensure security plans include a documented privileged access management plan that describes specific privileged user roles; designated IT positions; DoD IA workforce categories, specialties, and levels; primary authentication mechanisms for roles; and two-factor mechanisms for roles that cannot use public key infrastructure (PKI) authentication.
5.6 (U//FOUO) Ensure privileged access management plans identify all positions performing privileged access IA functions, document a role and responsibility matrix for operation and maintenance, and outline quarterly tracking procedures.
5.7 (U//FOUO) Maintain visibility of A&A status of ISs and PIT systems.
5.8 (U//FOUO) Monitor and track overall execution of DISA IS and PIT system POA&Ms.
5.9 (U//FOUO) Promote reciprocity to the maximum extent possible.
5.10 (U//FOUO) Review and submit the security authorization package to the AO.
5.11 (U//FOUO) Enforce the AO authorization decisions for hosted or interconnected ISs and PIT systems.
5.12 (U//FOUO) Enforce all aspects of cybersecurity for ISs and PIT systems, IAW DoDI 8510.01, Risk Management Framework (RMF) for DoD Information Technology (IT).
Enclosure 3
DELEGATED AUTHORITIES FOR CYBERSECURITY TO SENIOR LEADERS
1. Directors, Executives, Commanders, and Chiefs of Major Organizational Elements.
These individuals will:
1.1 (U//FOUO) Ensure all information technology (IT) systems and programs under their supervision are planned, funded, tested, implemented, monitored, and executed in a manner consistent with DoD and DISA cybersecurity plans, policies, and requirements.
1.2 (U//FOUO) Ensure cybersecurity incident and vulnerability reporting and mitigation efforts are executed as directed in enclosure 3 to DoD Instruction (DoDI) 8530.01, Cybersecurity Activities Support to DoD Information Network Operations. (All suspected or confirmed computer security incidents are to be reported to the appropriate organizations and commands (to the established supervisor, Information System Security Manager (ISSM), Information System Security Officer (ISSO), Commander, etc.) in addition to their respective Cybersecurity Service Provider (CSSP), as outlined in Chairman of the Joint Chiefs of Staff Manual (CJCSM) 6510.01B, Cyber Incident Handling Program.)
1.3 (U//FOUO) Comply with all U.S. Cyber Command (USCYBERCOM) cybersecurity directions and tasks.
1.4 (U//FOUO) Identify and include cybersecurity requirements in all phases of DISA information system (IS) life-cycle planning and execution.
1.5 (U//FOUO) Comply with DISA written orders, directives, and instructions.
1.6 (U//FOUO) Ensure organizational IS policies and procedures meet all standards, as outlined in National Institute of Standards and Technology Special Publication (NIST SP) 800-53, Revision 4, Security and Privacy Controls for Federal Information Systems and Organizations, as they pertain to the assessment and authorization (A&A) of DISA systems and networks.
1.7 (U//FOUO) Ensure any contract document written by DISA ISs management properly reflects the training and clearance requirements, as described in DoDI 5200.02, DoD Personnel Security Program (PSP), and DISA cybersecurity requirements. (A contract will not be initiated without the direct involvement of the Resource Management Center [RMC] and the Procurement Service Directorate [PSD]. A contract must contain the information found in Defense Federal Acquisition Regulation Supplement [DFARS].)
1.8 (U//FOUO) Designate appropriate government and contractor personnel to be part of the DISA cybersecurity workforce and ensure all personnel, including contractors, successfully complete DoD Cyber Awareness Challenge training and are certified commensurate with their respective responsibilities.
1.9 (U//FOUO) Ensure DISA IS assets are authorized in accordance with the DoD risk management framework (RMF).
1.10 (U//FOUO) Ensure any DISA circuits associated with a system have been approved by the Authorizing Official (AO) prior to connecting to the Department of Defense information networks (DODIN). (The procedures are detailed in the Defense Information Systems Network (DISN) Connection Process Guide (CPG) located on the DISA Enterprise Connections Web site at "www.disa.mil." Click on "Network Services," "Enterprise Connections" [lower left side of screen], and "DISN CPG 5.1 (PDF)" [right side of screen].)
1.11 (U//FOUO) Support the annual assessment of cybersecurity, as required by Federal Information Security Management Act (FISMA) of 2014, the RMF, and other cybersecurity guidance.
1.12 (U//FOUO) Appoint, in writing, resource ISSMs and other supporting cybersecurity structure, as necessary, within the organizational unit.
1.13 (U//FOUO) Ensure an internal incident handling reporting process, to include a reporting chain, is established and followed. (The reporting chain shall include notification to the CSSP and the AO when incidents occur.)
1.14 (U//FOUO) Ensure all appropriate personnel (ISSMs, System Administrators [SAs], etc.)
maintain active cybersecurity management accounts.
1.15 (U//FOUO) Ensure an Information System Owner (ISO) or Project Manager (PM) is appointed for all ISs and platform information technology (PIT) systems.
1.16 (U//FOUO) Ensure DoD information technologies under their authority comply with the RMF.
1.17 (U//FOUO) Operate only authorized ISs and PIT systems (i.e., those with a current Authorization to Operate (ATO) or Interim Authorization to Test (IATT)).
1.18 (U//FOUO) Comply with all authorization decisions, including Denial of Authorization to Operate (DATO), and enforce Authorization Termination Dates (ATD).
1.19 (U//FOUO) Ensure personnel engaged in or supporting the RMF are appropriately trained and possess professional certifications, consistent with DoD Manual 8570.01-M, Information Assurance Workforce Improvement Program, and supporting issuances.
1.20 (U//FOUO) Ensure ISOs appoint User Representatives (URs) for ISs and PIT systems.
1.21 (U//FOUO) Ensure all devices are listed within Assured Compliance Assessment Solution (ACAS) if a component manages assets to include DISA-sponsored networks.
1.22 (U//FOUO) Provide all necessary support to their Tier II CSSP.
1.23 (U//FOUO) Ensure their respective systems and networks enter into a service relationship with their respective CSSP and establish a memorandum of agreement (MOA) for any service arrangements with non-DISA cross domain (CD) providers. (A copy of the MOA will be provided to the AO for review and approval, and an additional copy will be provided to the DISA Tier II CSSP Team.)
2. Director for Resource Management/Comptroller (RMC). The Director, RMC, will:
2.1 (U//FOUO) Ensure funding for training is available to support required network monitoring systems and services.
2.2 (U//FOUO) Ensure all the requirements found in DFARS Clause 252.239-7001 are included in all contracting vehicles written for ISs management within DISA.
2.3 (U//FOUO) Comply with DISA written orders, directives, and instructions.
3. Director for Procurement Service Directorate (PSD). The Director, PSD, will:
3.1 (U//FOUO) Ensure contracts include the acquisition of DoD IS cybersecurity services.
3.2 (U//FOUO) Ensure any contract document written for DISA ISs management properly reflects the training and clearance requirements, as described in DFARS 252.239-7001;
DoDI 5200.02, DoD Personnel Security Program (PSP); and DISA cybersecurity requirements.
(A contract will not be initiated without the direct involvement of PSD.)
4. Workforce Services Executive (WSE). The WSE will:
4.1 (U//FOUO) Manage communications security (COMSEC) for the Agency, as prescribed in DoDI 8560.01, Communications Security (COMSEC) Monitoring and Information Assurance (IA) Readiness Testing.
4.2 (U//FOUO) Manage sensitive compartmented information (SCI) for the Agency and the Special Security Office (SSO).
4.3 (U//FOUO) Investigate and report security violations and incidents and ensure proper protection and corrective measures have been taken when an information security incident or vulnerability has been discovered.
4.4 (U//FOUO) Ensure DISA cybersecurity requirements and responsibilities are incorporated into DISA personnel processes.
4.5 (U//FOUO) Support DISA cybersecurity certification and training of the cybersecurity workforce.
4.6 (U//FOUO) Provide centralized tracking of DISA cybersecurity training and certification of the DISA cybersecurity workforce.
4.7 (U//FOUO) Develop and execute DISA's classified information spillage handling procedures, in conjunction with Risk Management Executive (RME).
4.8 (U//FOUO) Implement a process to ensure counterintelligence (CI) reportable incidents are forwarded to the Lead CI Agent, located in the Workforce Services and Development Directorate (WSD) Security Division (MP6), for review and action, where appropriate.
4.9 (U//FOUO) Comply with DISA written orders, directives, and instructions.
5. Risk Management Executive (RME). The RME will:
5.1 (U//FOUO) Develop, acquire, engineer, and implement enterprise cybersecurity and network operations (NetOps) capabilities to include identity management, NetOps situational awareness, sensor grid management, computer and network protection, and enterprise CD service capabilities and work with DISA organizations to assist in adopting the enterprise solutions.
5.2 (U//FOUO) Ensure effective and efficient application, planning, programming, budgeting, and execution of DISA cybersecurity resources for all of DISA, in concert with DoD goals and objectives.
5.3 (U//FOUO) Monitor DISA's configuration management (CfM) and architecture to include, but not be limited to, policies and procedures for asset management; network diagrams; ports, protocols, and services (PPS) listings; configuration baseline; baseline assessment; and security standards.
5.4 (U//FOUO) Ensure CfM and architecture updates (i.e., policies and procedures for asset management; network diagrams; PPS listings; configuration baseline and assessment and security standards) are provided to the DISA Tier II CSSP Team on an annual basis, or as required, for implementation.
5.5 (U//FOUO) Provide DISA ISs security training to Cybersecurity Professionals (SPs) and SAs and develop and distribute relevant training products.
5.6 (U//FOUO) Oversee implementation of the DISA cyber defense strategy that includes situational awareness, incident management, and machine-to-machine information exchanges.
5.7 (U//FOUO) Oversee DISA Cybersecurity Scorecard reporting to include the management of DISA Defense Collaboration Services - Secret (DCS-S) accounts and ensure final submissions to the DoD Chief Information Officer (CIO) by the 1st of each month.
5.8 (U//FOUO) Provides monthly access to the Cybersecurity Scorecard survey via the DoD Cyberscope to directorate- and program-level ISSMs two business days after the DoD CIO makes it available.
5.9 (U//FOUO) Coordinate with the AO and DISA Tier II Team to ensure the net defense information supporting cyber situational awareness and Global NetOps is timely and accurate.
5.10 (U//FOUO) Oversee the DISA strategic plan and technical solution regarding hardening of the information enterprise infrastructure to include machine-to-machine information exchanges.
5.11 (U//FOUO) Coordinate with RMC to ensure funding is available to support deployment and sustainment of network monitoring devices.
5.12 (U//FOUO) Collaborate with the Operations Center (OP) in the development of all current and future DISA contingency and disaster recovery plans.
5.13 (U//FOUO) Comply with DISA written orders, directives, and instructions.
5.14 (U//FOUO) Develop and maintain the DISA sensor grid strategy.
5.15 (U//FOUO) Coordinate with OP to ensure CD requirements are incorporated into education, training, and awareness (ETA) curricula and courseware and provide course development technical support in the areas of network protections, malicious code, information operations condition (INFOCON), and information assurance vulnerability management (IAVM).
5.16 (U//FOUO) Alert the AO to vulnerabilities and provide timely technical solutions based on network configurations and implementations and provide general and specific guidance at least annually to the AO and RME on the hardening of DISA network organizations.
5.17 (U//FOUO) Distribute documented guidance to DISA organizations annually of best practices that support an overall DoD policy for configurations or rule sets.
5.18 (U//FOUO) Review the impact to DISA of emerging cybersecurity and cybersecurity-related policies and develop draft cybersecurity policy for the Office of the Secretary of Defense.
5.19 (U//FOUO) Develop, implement, and maintain the DoD Security Technical Implemen-tation Guides (STIGs).
5.20 (U//FOUO) Establish and maintain processes and procedures to manage DISA's Plan of Action & Milestones (POA&M).
5.21 (U//FOUO) Approve DISA-initiated COMSEC monitoring and information assurance (IA) readiness testing of DISA-owned or -leased systems, as delegated by the Director, DISA.
5.22 (U//FOUO) Approve the registration of all DoD public Internet services and Internet-based capabilities (IbC), as described in DoDI 8550.01, DoD Internet Services and Internet-Based Capabilities.
6. Director for Operations Center (OC). The Director, OC, will:
6.1 (U//FOUO) Manage the DISA Tier III CSSP Team to direct and provide oversight of DISA CD services at the Tier III level.
6.2 (U//FOUO) Validate identified incidents across DISA's enterprise and establish operational impact with Tier III level components to provide feedback to the DISA Tier II CSSP Team.
6.3 (U//FOUO) Self-report all DISA incidents and questionable events for covered enclaves, networks, systems, the cloud, or the DODIN, upon discovery, to the DISA Tier II CSSP Team, in a timely manner.
6.4 (U//FOUO) Provide updates to DISA leadership, in coordination with the DISA Tier II CSSP Team, on all DISA CD compliance status to include any emerging threats and vulnerabilities.
6.5 (U//FOUO) Notify the DISA Tier II CSSP Team of all external vulnerability assessment (VA) scans of the DISA enterprise and assist the DISA Tier II CSSP Team in coordination and execution of external scans.
6.6 (U//FOUO) Oversee DISA's CfM and architecture to include, but not be limited to, policies and procedures for asset management, configuration baseline, baseline assessment, and security standards. (Updates are to be provided to the DISA Tier II CSSP Team on an annual basis, or as required, for implementation.)
6.7 (U//FOUO) Ensure DISA organizations maintain up-to-date configuration documentation for DISA networks and provide the information to the DISA Tier II CSSP Team to include network diagrams, software and hardware inventories, and network points of contact (POCs) and related information.
6.8 (U//FOUO) Assist the DISA Tier II CSSP Team to collect unclassified and classified network topology diagrams, Internet protocol (IP) space, contact information, and other information, as required, to ensure CD coverage.
6.9 (U//FOUO) Maintain a data repository of DISA's Security Category High and Very High systems, IP space for DISA organizations, and critical assets (Domain Name System [DNS] servers, Web servers, File Transfer Protocol [FTP] servers, Primary Domain Controller [PDC], and Backup Domain Controller [BDC], etc.) and provide the updated information to the DISA Tier II CSSP Team annually or sooner as changes occur.
6.10 (U//FOUO) Assist RME in the implementation of the DISA cyber defense strategy and standards-based machine-to-machine information exchanges for improved cyber situational awareness and Global NetOps.
6.11 (U//FOUO) Maintain DISA's guidelines for the hardening of networks and inform the DISA CIO of any significant changes to the security or architecture of the networks.
6.12 (U//FOUO) Self-report all DISA incidents and questionable events for covered enclaves, networks, systems, the cloud, or the DODIN, upon discovery, to the DISA Tier II CSSP Team, in a timely manner.
6.13 (U//FOUO) Provide updates to DISA leadership, in coordination with the DISA Tier II CSSP Team, on all DISA CD compliance status to include any emerging threats and vulnerabilities.
6.14 (U//FOUO) Notify the DISA Tier II CSSP Team of all external VA scans of the DISA enterprise and assist the DISA Tier II CSSP Team in coordination and execution of external scans.
6.15 (U//FOUO) Ensure DISA organizations maintain up-to-date configuration documentation for DISA networks and provide this information to the DISA Tier II CSSP Team to include network diagrams, software and hardware inventories, and network POCs and related information.
6.16 (U//FOUO) Assist the DISA Tier II CSSP Team in collecting unclassified and classified network topology diagrams, IP space, contact information, and other information, as required, to ensure CD coverage.
7. Commander, Joint Interoperability Test Command (JITC). The Commander, JITC, located in the Development and Business Center (DBC), will:
7.1 (U//FOUO) Verify or validate incidents identified within the DISA enterprise with the DISA Tier III component, along with any operational impact, and provide feedback to the DISA Tier II CSSP Team.
7.2 (U//FOUO) Self-report all DISA incidents and questionable events for covered enclaves, networks, systems, the cloud, or the DODIN, upon discovery, to the DISA Tier II CSSP Team, in a timely manner.
7.3 (U//FOUO) Provide updates to DISA leadership, in coordination with the DISA Tier II CSSP Team, on all DISA CD compliance status to include any emerging threats and vulnerabilities.
7.4 (U//FOUO) Notify the DISA Tier II CSSP Team of all external VA scans of the DISA enterprise and assist the DISA Tier II CSSP Team in coordination and execution of external scans.
7.5 (U//FOUO) Maintain DISA Tier II CSSP Team vulnerability mitigation recommendations, provisioning of technical assistance, and any implementation of recommendations and, as needed, monitor and track corrective actions or mitigation strategies for implemented VAs.
7.6 (U//FOUO) Oversee DISA's CfM and architecture to include, but not be limited to, policies and procedures for asset management, configuration baseline, baseline assessment, and security standards. (Updates are to be provided to the DISA Tier II CSSP Team on an annual basis, or as required, for implementation).
7.7 (U//FOUO) Ensure DISA organizations maintain up-to-date configuration documentation for DISA networks and provide this information to the DISA Tier II CSSP Team to include network diagrams, software and hardware inventories, and network POCs and related information.
7.8 (U//FOUO) Assist the DISA Tier II CSSP Team to collect unclassified and classified network topology diagrams, IP space, contact information, and other information, as required, to ensure CD coverage.
7.9 (U//FOUO) Maintain a data repository of DISA's Security Category High and Very High systems, IP space for DISA organizations, and critical assets (Domain Name System [DNS] servers, Web servers, File Transfer Protocol [FTP] servers, Primary Domain Controller [PDC], and Backup Domain Controller [BDC], etc.) and provide the updated information to the DISA Tier II CSSP Team annually or sooner as changes occur.
7.10 (U//FOUO) Oversee the circuit provisioning process and ensure all DISA or DISA-sponsored circuits owners coordinate with a DISA CSSP and provide a receipt of CD services allowing for visibility of all DISA IP address space via machine-to-machine information exchanges.
7.11 (U//FOUO) Notify the DISA Tier II CSSP Team and AO, upon provisioning of new circuits, to ensure CSSP coverage for connecting ISs has been arranged prior to a system becoming operational.
7.12 (U//FOUO) Coordinate with RMC to ensure funding is available to support deployment of network monitoring devices.
7.13 (U//FOUO) Assist RME with implementation of the DISA cyber defense strategy and standards-based machine-to-machine information exchanges for improved cyber situational awareness and Global NetOps.
8. Director for Cyberspace-Operations Directorate (CE). The Director, CE, located in the Operations Center (OC), will:
8.1 (U//FOUO) Assist the directorates in adopting enterprise cyber security solutions in conjunction with the Business Development Center (BDC) and Chief Technical Officer (CTO).
8.2 (U//FOUO) Develop and execute DISA's classified information spillage handling procedures in conjunction with Workforce Services and Development Directorate (WSD).
8.3 (U//FOUO) Oversee the Agency's Tier II CSSP, as outlined in DoDI 8530.01, Cybersecurity Activities Support to DoD Information Network Operations.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .