The IA Roadmap Baked-in versus Brushed-on Integrating IA into Major Programs Art King IBM Business Consulting Services Acquisition Team, DIAP 703.604.1480.

Slides:



Advertisements
Similar presentations
Technology Module: Technology Readiness Levels (TRLs) Space Systems Engineering, version 1.0 SOURCE INFORMATION: The material contained in this lecture.
Advertisements

Database Planning, Design, and Administration
METRICS AND CONTROLS FOR DEFENSE IN DEPTH AN INFORMATION TECHNOLOGY SECURITY ASSESSMENT INITIATIVE.
Effectively Integrating Information Technology (IT) Security into the Acquisition Process Section 4: Effective Integration.
BENEFITS OF SUCCESSFUL IT MODERNIZATION
Software Engineering CSE470: Process 15 Software Engineering Phases Definition: What? Development: How? Maintenance: Managing change Umbrella Activities:
Chapter 7: Key Process Areas for Level 2: Repeatable - Arvind Kabir Yateesh.
DoD Integrated Product Support Roadmap Tool
DoD Information Assurance Certification and Accreditation Process (DIACAP) August 2011.
4/29/2009Michael J. Cohen1 Practical DIACAP Implementation CS526 Research Project by Michael J. Cohen 4/29/2009.
SPēD Certification Program Executive Overview. 2April 2012Executive Overview Purpose Outline the SPēD Program Provide SPēD Program update Provide SPēD.
DoD Information Technology Security Certification and Accreditation Process (DITSCAP) Phase III – Validation Thomas Howard Chris Pierce.
Information Assurance (IA) - Measures that protect and defend information and information systems by ensuring their availability, integrity, authentication,
ISS IT Assessment Framework
Christopher P. Cabuzzi CS 591 DEFENSE INFORMATION ASSURANCE CERTIFICATION & ACCREDITATION PROCESS (DIACAP) Chris Cabuzzi, DIACAP, 12/8/10 1.
Secure System Administration & Certification DITSCAP Manual (Chapter 6) Phase 4 Post Accreditation Stephen I. Khan Ted Chapman University of Tulsa Department.
Lecture Nine Database Planning, Design, and Administration
DITSCAP Phase 2 - Verification Pramod Jampala Christopher Swenson.
COMP8130 and 4130Adrian Marshall 8130 and 4130 Test Management Adrian Marshall.
Unclassified. Program Management Empowerment and Accountability Mr. David Ahern Director, Portfolio Systems Acquisition AT&L(A&T) 14 April 2009 The Acquisition.
Justice Information Network Strategic Plan Development Justice Information Network Board March 18, 2008 Mo West, JIN Program Manager.
I n t e g r i t y - S e r v i c e - E x c e l l e n c e Business & Enterprise Systems AF Systems Engineering Assessment Model (AF SEAM) Validation Assessment.
Student Learning Objectives 1 Phase 3 Regional Training April 2013.
Server Virtualization: Navy Network Operations Centers
NDIA SE Division Meeting February 13, Developmental Test and Evaluation Committee Beth Wilson, Raytheon Steve Scukanec, Northrop Grumman Industry.
C &A CS Unit 2: C&A Process Overview using DITSCAP Jocelyne Farah Clinton Campbell.
Managing Intellectual Property for Distance Learning Liz Johnson Project Manager Advanced Learning Technologies Board of Regents of the University System.
4.2 Develop Project Management Plan
Cybersecurity: Engineering a Secure Information Technology Organization, 1st Edition Chapter 7 Software Supporting Processes and Software Reuse.
UNCLASSIFIED Joint and Coalition Warfighting Mr. John Vinett March 2012 Technical Baseline Capability.
Workshop on Programming in support of Anti-Corruption Agencies Bratislava, 30 June - 1 July 2009 A methodology for capacity assessment of AC agencies:
Certification and Accreditation CS Phase-1: Definition Atif Sultanuddin Raja Chawat Raja Chawat.
UNCLASSIFIED DITSCAP Primer. UNCLASSIFIED 1/18/01DITSCAP Primer.PPT 2 DITSCAP* Authority ASD/C3I Memo, 19 Aug 92 –Develop Standardized C&A Process DODI.
Georgia Institute of Technology CS 4320 Fall 2003.
1 © Material United States Department of the Interior Federal Information Security Management Act (FISMA) April 2008 Larry Ruffin & Joe Seger.
ITIL Intermediate Service Design SD eLearning plus Exam Prep 1 We offer a fully accredited, self-managed eLearning
Certification and Accreditation CS Syllabus Ms Jocelyne Farah Mr Clinton Campbell.
EPA Geospatial Segment United States Environmental Protection Agency Office of Environmental Information Enterprise Architecture Program Segment Architecture.
ITIL Intermediate Service Design SD Complete Examination Package 1 Get Everything you need to pass your Service Design Exam
Consultant Advance Research Team. Outline UNDERSTANDING M&E DATA NEEDS PEOPLE, PARTNERSHIP AND PLANNING 1.Organizational structures with HIV M&E functions.
Independent Expert Program Review (IEPR) February 2006.
Evaluate Phase Pertemuan Matakuliah: A0774/Information Technology Capital Budgeting Tahun: 2009.
State of Georgia Release Management Training
Standard III Resources Effective Practices in Accreditation ASCCC Accreditation Institute, Feb , San Diego, CA Cheryl Aschenbach, ASCCC At-large.
Driving Value from IT Services using ITIL and COBIT 5 July 24, 2013 Gary Hardy ITWinners.
LECTURE 5 Nangwonvuma M/ Byansi D. Components, interfaces and integration Infrastructure, Middleware and Platforms Techniques – Data warehouses, extending.
Configuration Control (Aliases: change control, change management )
Info-Tech Research Group1 1 Info-Tech Research Group, Inc. is a global leader in providing IT research and advice. Info-Tech’s products and services combine.
Info-Tech Research Group1 1 Info-Tech Research Group, Inc. is a global leader in providing IT research and advice. Info-Tech’s products and services combine.
PRIIA 305 Technical Subcommittee Systems Engineering Processes for Passenger Equipment Acquisition and Life Cycle Support Presented at: NGEC Executive.
T HE E FFECTIVE P ROJECT M ANAGEMENT O FFICE Strategies For Building, Selling & Setting Up PMOs Mark E. Mullaly, PMP.
Sample Fit-Gap Kick-off
ITIL SERVICE LIFECYCLE
ISA 201 Intermediate Information Systems Acquisition
AF Systems Engineering Assessment Model (AF SEAM) Validation Assessment Out-Brief Program: (INSERT NAME) Current: 14 January 2015.
SAMPLE Develop a Comprehensive Competency Framework
JTAMS MILESTONE A ANALYSIS
ISA 201 Intermediate Information Systems Acquisition
Clinical Engineering Lecture (3).
Enterprise Content Management Owners Representative Contract Approval
Microsoft SAM Managed Service Program
Microsoft SAM Managed Service Program
Standard III Resources
1 Stadium Company Network. The Stadium Company Project Is a sports facility management company that manages a stadium. Stadium Company needs to upgrade.
Microsoft SAM Managed Service Program
Independent Expert Program Review (IEPR)
Enterprise Content Management (ECM) Project
NGEC Executive Board Meeting
Presentation transcript:

The IA Roadmap Baked-in versus Brushed-on Integrating IA into Major Programs Art King IBM Business Consulting Services Acquisition Team, DIAP ext th Annual IA Workshop 3 February 2004 Atlanta, Georgia

2 Purpose The IA Roadmap is conceptual device for organizing IA implementation activities in a manner that is relevant to a typical acquisition program (i.e. an IA “thread” teased out of the overall program effort) It is a generic approach that must be customized for unique situations, such as: –SCI processing –Late program initiation The IA Roadmap is being introduced in the DAU “IA for Program Managers” Learning Module The IA Roadmap has been integrated into the Enterprise Integration (EI) Toolkit for COTS/ERP acquisitions

3 IA Roadmap Steps Establish an IA organization Identify IA requirements Develop an acquisition IA strategy Secure resources for IA Initiate DITSCAP Incorporate IA solutions Test and evaluate IA solutions Accredit the system Maintain the system’s security posture throughout its life-cycle

4 IA Roadmap Correlation to DoD 5000 Lifecycle Establish an IA organization Identify IA requirements Develop an acquisition IA strategy Secure resources for IA Initiate DITSCAP Incorporate IA solutions Test and evaluate IA solutions Accredit the system Maintain the system’s security posture throughout its life-cycle

5 Slide from DAG 28 June

6 IA Roadmap Capsule Step Descriptions 1. Establish an IA organization Trained IA professional as IA Manager IA support – organic/matrixed/contracted 2. Identify IA requirements Specified in Requirements/Capabilities Documents Baseline IA Controls Other requirements (e.g. IPv6, DoD PKI) 3. Develop an acquisition IA strategy Required for Mission Critical/Mission Essential IT systems; recommended for others Approved by Component CIO ACAT 1AC, ACAT 1AM and ACAT 1D reviewed by DoD CIO

7 IA Roadmap Capsule Step Descriptions 4.Secure resources for IA Include IA in program budget Determine funding sources 5.Initiate DITSCAP Begin Phase I SSAA effort Phase I SSAA should be signed at/near MS-B 6.Incorporate IA solutions Systems Security Engineering efforts Procurement of IA/IA enabled products Implementing security policies, plans, procedures IA Training

8 IA Roadmap Capsule Step Descriptions 8.Test and evaluate IA solutions Developmental Test (DT) Security Test & Evaluation, C&A activities Operational Test (OT ) 9.Accredit the system DITSCAP Phase III completed ATO/IATO should be issued prior to MS-C 10. Maintain the system’s security posture throughout its life-cycle Periodic assessments Re-accreditation minimum of 3 years “Fielded System” assessments by Service OTA

9 For your consideration Is this tool helpful? If it is of value, how best to document and disseminate it? How can it be improved?

10 DIAP Acquisition Team Points of Contact Mr. Eustace King ASD(NII)/DIAP-Technologies and Capabilities (703) Mr. Art King (IBM) (703) ext. 104 Mr. Dominic Cussatt (IBM) (703) ext. 119