Attachment_H_Controlled_Unclassified_Information_Guide_INGOTS.pdf
PDF 291 KB Posted
- Attached to
- Intelligent Generation of Tools for Security (INGOTS) Federal contract opportunity
- Solicitation number
- HR001124S0033
About this file
This document is a Controlled Unclassified Information (CUI) guide for the Intelligent Generation of Tools for Security (INGOTS) program, which is being managed by the Defense Advanced Research Projects Agency (DARPA).
The guide outlines the purpose, applicability, and scope of the INGOTS program, which seeks to semi-autonomously reverse engineer and reconstruct recently fixed software vulnerabilities in a software supply chain. It identifies the CUI categories applicable to the program, including Export Controlled (EXPT), Controlled Technical Information (CTI), Operations Security (OPSEC), and General Proprietary Business Information (PROPIN). The guide provides instructions for protecting and handling CUI associated with INGOTS, as well as guidance on disclosure and notification of unauthorized disclosures. Tables are included to help identify CUI elements and distinguish them from information that is not considered CUI. Overall, the document establishes the security and information protection requirements for the INGOTS program.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment_D_Proposal_Instructions_and_Volume_I_Template__Technical_and_Management_INGOTS__.docx | DOCX document | |
| HR001124S0033-Amendment-03.pdf | ||
| HR001124S0033-Amendment-02.pdf | ||
| HR001124S0033-Amendment-01.pdf | ||
| Attachment_F_DARPAStandardCostProposalSpreadsheetSingleTA11-2021-v2.xlsx | XLSX spreadsheet | |
| Attachment_D_Proposal_Instructions_and_Volume_I_Template__Technical_and_Management_INGOTS.docx | DOCX document | |
| Attachment_A_Abstract_Summary_Side_INGOTS.pptx | PPTX presentation | |
| Attachment_E_Proposal_Instructions_and_Volume_II_Template__Cost_INGOTS.docx | DOCX document | |
| Attachment_C_Proposal_Summary_Slide_INGOTS.pptx | PPTX presentation | |
| HR001124S0033.pdf | ||
| Attachment_B_Abstract_Instructions_and_Template_INGOTS_v2.docx | DOCX document | |
| Attachment_G_Associate_Contractor_Agreements_INGOTS.docx | DOCX document |
Show all 12
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Distribution Statement A. Approved for public release: distribution unlimited.
Controlled Unclassified Information Guide
Program: INtelligent Generation Of Tools for Security (INGOTS) Program Manager: Derek S. Bernsen
Program Security Officer: Justin P. Kokernak
Date: Aug 2024 Version: 3
Derek S. Bernsen Justin P. Kokernak I2O Program Manager I2O Program Security Officer
This document is approved for public release.
Local reproduction of this document is authorized only in its entirety.
ii
FOREWORD
1. DESCRIPTION
2. AUTHORITY
3. DISTRIBUTION
GENERAL
1. PURPOSE
2. APPLICABILITY AND SCOPE
3. OFFICE OF PRIMARY RESPONSIBILITY
4. CONTROLLED UNCLASSIFIED INFORMATION (CUI) CHALLENGES
5. OPERATION SECURITY (OPSEC)
6. CUI CATEGORIES
7. EXPORT CONTROL RESTRICTED INFORMATION
8. FREEDOM OF INFORMATION ACT (FOIA) EXEMPT INFORMATION
9. DISCLOSURE OF CUI
10. CUI PROTECTION REQUIREMENTS
11. NOTIFICATION OF UNAUTHORIZED DISCLOSURE
iii
(U) FOREWORD
1. (U) DESCRIPTION
(U) INtelligent Generation Of Tools for Security (INGOTS) seeks to semi-autonomously reverse engineer and reconstruct recently fixed software vulnerabilities in a software supply chain and will develop tools and techniques to generate exploit chains for cyber-hardened enterprise software. This program enables multiple vulnerabilities to be exploited in a way that is short-lived and disposable.
2. (U) AUTHORITY
(U) CUI elements referenced in this guide are under the authority of DoDI 5200.48, “Controlled Unclassified Information,” March 6, 2020.
3. (U) DISTRIBUTION
(U) Distribution Statement A. Approved for public release: distribution is unlimited.
1. (U) PURPOSE
a. (U) The purpose of this CUI guide is to ensure the protection of INGOTS information IAW DoDI 5200.48. INGOTS information should be controlled and stored consistent with federal requirements and guidance from the National Institute for Standards and Technology (NIST). Sensitive information does not include information in the public domain.
b. (U) This guide is not for classified national security information as defined in Executive
Order 13526 but identifies specific elements of sensitive information that are unclassified in nature requiring protection. This information is not classified national security information, but it is covered by the legislation at large for the Freedom of Information Act (FOIA) and the exemptions therein.
2. (U) APPLICABILITY AND SCOPE
(U) This guide applies to all DARPA personnel, support contractors, mission partners, and industrial performers who support INGOTS. This guide should be cited as the basis for identifying, protecting and marking of information and material designated as a type of controlled unclassified information (CUI) associated with INGOTS. As defined at 32 CFR Section 2002.4(h), CUI is information that the government creates or possesses – or that an entity creates or possesses on behalf of the government that law, regulation or government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls. It is to be used in conjunction with related security classification guides and guidance documents associated with the overall effort of INGOTS, in compliance with Executive Orders and related DoD guidance. The scope of this guide is based on INGOTS as planned at the date of this guide and may expand or change as strategic decisions are made over the course of INGOTS.
3. (U) OFFICE OF PRIMARY RESPONSIBILITY (OPR)
(U) This CUI guide is issued by DARPA. All inquiries concerning content, interpretations, and clarification of this document should be addressed to DARPA at I2Osecurity@darpa.mil with any questions.
4. (U) CONTROLLED UNCLASSIFIED INFORMATION (CUI) CHALLENGES
(U) CUI Challenges: Authorized holders of CUI who, in good faith, believe that a designation of information as CUI within this guide is improper or incorrect, or who believe they have received unmarked CUI, should notify DARPA at I2Osecurity@darpa.mil. Until the challenge is resolved, the challenged CUI, including challenges to unmarked CUI, will continue to be safeguarded and disseminated at the appropriate control level indicated in the markings or presumed category.
5. (U) OPERATIONS SECURITY (OPSEC)
a. (U) OPSEC is a process that identifies and mitigates adversarial risk to our operations by looking at our operations through the eyes of our adversaries. The application of the OPSEC methodology includes identifying critical information, analyzing threats and vulnerabilities, analyzing and assessing adversarial risk, and implementing OPSEC measures that reduce this risk.
b. (U) INGOTS critical information falls under the following index of CUI:
1) Export Control: Export Controlled (EXPT)
2) Defense: Controlled Technical Information (CTI)
3) Intelligence: Operations Security (OPSEC)
4) Proprietary Business Information: General Proprietary Business Information
(PROPIN)
6. (U) CUI Categories
a. (U) Export Control: Export Controlled (EXPT). This category relates to Unclassified information concerning certain items, commodities, technology, software, or other information whose export could reasonably be expected to adversely affect the United States national security and nonproliferation objectives. To include dual use items; items identified in export administration regulations, international traffic in arms regulations (ITAR) and the munitions list;
license applications; and sensitive nuclear technology information.
b. (U) Defense: Controlled Technical Information (CTI). This category relates to technical information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination.
Controlled technical information would meet that criteria, if disseminated, for distribution statements B through F using the criteria set forth in DoD Instruction 5230.24, Distribution Statements on Technical Documents.
c. (U) Intelligence: Operational Security (OPSEC). Critical information determined to give evidence of the planning and execution of sensitive (frequently classified) government activities after going through a formal systematic vetting process in accordance with National Security Decision Directive Number 298. This process identifies unclassified information that must be protected. It almost always results from an agency’s official OPSEC program or is otherwise commonly approved for use by the CUI Senior Agency Official.
d. (U) Proprietary Business Information: General Proprietary Business Information
(PROPIN). Material and information relating to, or associated with, a company's products, business, or activities, including but not limited to financial information; data or statements;
trade secrets; product research and development; existing and future product designs and performance specifications.
7. (U) EXPORT CONTROL RESTRICTED INFORMATION
a. (U) INGOTS tools may be subject to control under Category 5, Part 2 of the Commerce Control List. This CUI guide does not provide relief from any export controls, nor does it provide guidance or instructions on what performer technologies are subject to export control.
Each performer’s empowered official is responsible for determining the export control status of their technology. INGOTS tools that are subject to export control must be handled and protected as CUI per the instructions in this guide.
8. (U) FREEDOM OF INFORMATION ACT (FOIA) EXEMPT INFORMATION
a. (U) The Freedom of Information Act (FOIA), 5 U.S.C. § 552, is a federal law that defines agency records subject to public disclosure, outlines mandatory disclosure procedures, and defines nine exemptions that prohibit certain types of information from being released to the public. In addition to the FOIA, the Code of Federal Regulations (October 2016), 45 CFR § 5.31 specifies the type of information that falls under each of the nine exemptions that preclude release of information to the public under the FOIA. In accordance with 5 U.S.C. § 552(a)(8), DARPA will withhold records or information exempt from disclosure under the FOIA whenever disclosure would harm an interest protected by a FOIA exemption or disclosure is prohibited by law. The most relevant exemptions for INGOTS are listed below; however other exemptions could apply:
1) (U) Exemption 1 – Protects information that is properly classified in the interest of national security pursuant to Executive Order 12958.
2) (U) Exemption 2 – Protects records related solely to the international personnel rules and practices of an agency.
3) (U) Exemption 3 – Protects information exempted from release by statute
4) (U) Exemption 4 – Protects trade secrets and commercial or financial information which could harm the competitive posture or business interests of a company.
5) (U) Exemption 5 – Protects the integrity of the deliberative or policy-making processes within the agency by exempting from mandatory disclosure opinion, conclusions, and recommendations included within inter-agency or intra-agency memoranda or letters.
6) (U) Exemption 6 – Protects information that would constitute a clearly unwarranted invasion of personal privacy of the individuals involved.
9. (U) DISCLOSURE of CUI.
a. (U) Public Disclosure. Information from this CUI guide does not allow automatic public release of this information. DoD information requested by the media or members of the public or proposed for release to the public by DoD civilians or military personnel or their contractors will be processed in accordance with DARPA Instruction 65 and DoD Instructions 5230.09, 5230.29; Volume 3 of DoD Manual 5200.01; and DoD Manual 5400.07, as applicable. Proposed public disclosures of unclassified information shall be submitted using the public release form located at https://www.darpa.mil/work-with-us/contract-management/public-release.
b. (U) Freedom of Information Act (FOIA) Requests. All personnel with knowledge of this Project must coordinate with the DARPA PSO prior to providing a response to requests for information under the provisions of the FOIA.
c. (U) Proprietary Information (PROPIN). Additional safeguards may become necessary if a contract requires the transfer of PROPIN. The holder of the information must clearly identify any and all PROPIN prior to its disclosure and release, the release will be coordinated with the PROPIN owner.
d. (U) Foreign Disclosure. CUI controlled by DARPA, as part of a DARPA funded project, may be shared with a U.S. organization’s (i.e., the U.S. defense industry base (DIB), U.S. academia, or U.S.
research institutions) and non-U.S. citizen employees of those U.S. organizations under specific condition:
i. (U) CUI controlled by DARPA, to include CUI marked NOFORN or EXPORT CONTROLLED, may be disclosed to US Persons if they are a performer on a DARPA S&T proposal team or, if they are a performer who has been awarded a DARPA S&T project. A U.S. Person is a person who is a lawful permanent resident of the United States or who is a protected individual as defined by 8 U.S.C. 1101(a)(20) or 8 U.S.C.1324b(a)(3).
ii. (U) CUI that is NOFORN may be shared with U.S. persons, but will not be provided, in any form, to foreign governments (including coalition partners), international organizations, foreign nationals, or other non-U.S.
persons without the originator’s approval in accordance with E.O.s 13526 and 13556.”
iii. (U) CUI may be disclosed to a foreign person employed by U.S.
organizations if all of the following conditions are met:
1. (U) They are operating under a formally issued solicitation or awarded DARPA S&T project that clearly defines the U.S.
organization’s responsibilities to comply with DoD CUI policies and procedures as detailed in either DoD 5200.48, DFARS 252.204-7012, 7019, and 7020, or similarly acceptable guidance and direction.
2. (U) The CUI is not Export Controlled or NOFORN.
3. (U) Access to such information is within the scope of their assigned duties.
4. (U) Access to such information would help accomplish a lawful and authorized DoD mission or purpose and would not be detrimental to the interests of the DoD or the U.S. Government
10. (U) CUI PROTECTION REQUIREMENTS
a. (U) INGOTS CUI (e.g., confidential business information, CTI, EXPT, OPSEC, ISVI) regardless of media or format, will be protected from disclosure to unauthorized persons or groups, by properly storing in locked offices, cabinets, and drawers in accordance with DoDI 5200.48.
b. (U) CUI may only be processed on DIB systems that are compliant with DFARS 252.204-7012 requirements as detailed in NIST 800-171.
11. (U) NOTIFICATION OF UNAUTHORIZED DISCLOSURE
a. (U) Personnel must immediately report all unauthorized disclosures or suspected and known security incidents, privacy breaches, and suspicious activities involving CUI to the INGOTS PSO and PSR at I2Osecurity@darpa.mil.
b. (U) Data breaches of DIB networks and systems involving INGOTS CUI material must be reported IAW DFARS 252.204-7012 requirements. In addition, all breaches must be reported to the DARPA Project contracting officer and program security officer (PSO) upon discovery.
13. (U) INFORMATION PROTECTION GUIDANCE CHARTS
These charts are provided to assist in identifying what types of information associated with the INGOTS effort may be sensitive, provide guidance on the relevant markings for this information to control dissemination, and provide guidance on when these dissemination controls no longer apply. If at any time there are questions regarding which category of information something falls under, or what dissemination controls apply, individuals should request guidance from DARPA at I2Osecurity@darpa.mil.
Table 1: INGOTS CUI elements Element of Information
Index Category Reason LDC or Distribution Statement
Remarks
Cybersecurity items subject to export controls under Category 5, Part 2 of the Commerce Control List.
Export Control Export Controlled
(EXPT)
10 USC 130e DISTRO C 4D004 controls “Software” “specially designed” or modified for the generation, command and control, or delivery of “intrusion software”.
Performers that assess their tools to be covered by this control must apply CUI protections to their technology.
Development of export controlled items shall not be conducted on fundamental research contracts.
Any INGOTS items considered to be propriety information.
Proprietary Business Information
General Proprietary Business Information
(PROPIN)
18 USC 1905 FEDCON
Defense
Controlled Technical Information
(CTI)
10 USC 130e
DISTRO C FOIA Exemption 3 may be applicable
INGOTS fully integrated system modified for DoD, LE or IC operational use or testing in an operationally relevant environment.
Defense
Controlled Technical Information
(CTI)
10 USC 130e
DISTRO C FOIA Exemption 3 may be
INGOTS software tools that automate exploit generation and are specifically tailored to meet DoD, LE or IC end user requirements.
Defense Controlled Technical Information
(CTI)
10 USC 130e DISTRO C FOIA Exemption 3 may be applicable
TA-3 results of test and evaluation in operationally relevant environments.
Intelligence Operations Security
(OPSEC)
National Security Presidential Memorandum
FEDCON
Defense Controlled Technical Information
(CTI)
10 USC 130e DISTRO C FOIA Exemption 3 may be
TA-3 technical data, source code and documentation related to the integration of mature tools into prototypes for transition.
Defense Controlled Technical Information
(CTI)
10 USC 130e DISTRO C FOIA Exemption 3 may be applicable
Identification of specific potential DoD, LE or IC end users of
INGOTS.
Intelligence
Operations Security
National
Presidential Memorandum
FEDCON
May be classified higher or publicly releasable with transition partner guidance.
All documentation or planning products related to transition to DoD, LE, or IC end users.
Intelligence
Operations
National
Presidential Memorandum
FEDCON
May be classified higher with transition partner guidance.
Table 2: INGOTS NOT CUI elements TA1: Automating Exploit Chain Synthesis
• Identification and characterization of commercial or open-source software vulnerabilities
• Evaluation of upstream patch data
• Triage of exploitable software bugs based on characteristics and available metadata.
• Analysis for the determination of the root cause of potential vulnerabilities.
• Tools created for the automation of exploit primitive production, unless these tools are determined by performer empowered officials to be export controlled and therefore requiring CUI protection.
• Exploit primitives created using automated and non-automated processes.
• The creation of basic building blocks of single exploits.
• Decomposition of exploitation process into discrete steps.
• Identifying the pre-and-post conditions for exploit primitives.
• Functioning exploits built from basic blocks data.
TA2: Automating Exploit Chain Analysis
• Modeling architecture for automated and manual vulnerabilities and exploit chain analysis.
• Metadata and device-specific context related to vulnerabilities and exploit chains.
TA3: Test, Evaluation, and Integration
• Results of test and evaluation of INGOTS technology on surrogate networks that are not representative of an operational environment.
• Automated standardized tools for enabling the quantitative evaluation of exploit chains. Non- operationally relevant environments and tooling for automating the test and evaluation of exploit chains. (Note: An operationally relevant environment would be a test environment that closely resembled an operational use case, or actual operational or target networks).
| Derek S: | |
| 2024-08-05T11:41:35-0400 | |
| BERNSEN.DEREK.S.1387241961 |
| Justin P: | |
| 2024-08-05T19:36:57-0400 | |
| KOKERNAK.JUSTIN.PAUL.1288186037 |
File details come from the government source that posted it. Updated .