Jewuan Davis DSN Voice Connection Approval Office 18 May 2006 DSN Connection Approval Process (CAP)

Slides:



Advertisements
Similar presentations
METRICS AND CONTROLS FOR DEFENSE IN DEPTH AN INFORMATION TECHNOLOGY SECURITY ASSESSMENT INITIATIVE.
Advertisements

PROJECT MANAGER DEFENSE COMMUNICATIONS AND ARMY SWITCHED SYSTEMS COL David W. Ludwig IPTP Brief 13 July 2001.
CIP Cyber Security – Security Management Controls
Nick Vennaro, NHIN Team (Contractor), Office of the National Coordinator for Health IT Michael Torppey, CONNECT Health IT Security Specialist (Contractor)
ODAA Workshop December 2012 Charles Duchesne, DSS Tiffany Snyder, DSS
What’s the path to a SSP? Information System Profile Contractor: Lockheed Martin, Missiles and Fire Control Address: 1701 W. Marshall Dr. Grand Prairie,
1 Office of the Designated Approving Authority (ODAA) April 2008.
ISFO – ODAA Defense Security Service Industrial Security Field Operations (ISFO) Office of the Designated Approving Authority (ODAA) Nov Nov 2013.
DoD Information Assurance Certification and Accreditation Process (DIACAP) August 2011.
4/29/2009Michael J. Cohen1 Practical DIACAP Implementation CS526 Research Project by Michael J. Cohen 4/29/2009.
Springfield Public Schools 1 Project Management Methodologies in Support of Student Achievement.
SPēD Certification Program Executive Overview. 2April 2012Executive Overview Purpose Outline the SPēD Program Provide SPēD Program update Provide SPēD.
Summer IAVA1 NATIONAL INFORMATION ASSURANCE TRAINING STANDARD FOR SYSTEM ADMINISTRATORS (SA) Minimum.
DISN Video Services September 21, 2009 An Overview of the VTF DIACAP Process A Combat Support Agency Defense Information Systems Agency.
Industrial Security Field Operations (ISFO) Office of the Designated Approving Authority (ODAA) August 2010.
DoD Information Technology Security Certification and Accreditation Process (DITSCAP) Phase III – Validation Thomas Howard Chris Pierce.
Information Assurance (IA) - Measures that protect and defend information and information systems by ensuring their availability, integrity, authentication,
National Institute of Standards and Technology 1 NIST Guidance and Standards on System Level Information Security Management Dr. Alicia Clay Deputy Chief.
Connecting People With Information DoD Net-Centric Services Strategy Frank Petroski October 31, 2006.
1 For System Administrators INFORMATION INFORMATION SYSTEM SECURITY INFORMATION INFORMATION SYSTEM SECURITY.
Increase Information Assurance Awareness through Secure Operations/Management Training and Certification Percent Trained & Certified Goal = 100% Percentage.
Stephen S. Yau 1CSE , Fall 2006 IA Management.
University of California, Davis1 Draft Wireless Network Policy Administrative Computing Coordinating Council September 10, 2001.
Christopher P. Cabuzzi CS 591 DEFENSE INFORMATION ASSURANCE CERTIFICATION & ACCREDITATION PROCESS (DIACAP) Chris Cabuzzi, DIACAP, 12/8/10 1.
Information Systems Security Officer
Secure System Administration & Certification DITSCAP Manual (Chapter 6) Phase 4 Post Accreditation Stephen I. Khan Ted Chapman University of Tulsa Department.
DITSCAP Phase 2 - Verification Pramod Jampala Christopher Swenson.
Roles and Responsibilities
DISN Video Services October 2, 2009 VTF DIACAP Scorecard Matrix Instructions A Combat Support Agency Defense Information Systems Agency.
A Combat Support Agency Defense Information Systems Agency Unified Capabilities Requirements (UCR) Overview Joint Interoperability Test Command.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco PublicITE I Chapter 6 1 Characterizing the Existing Network Designing and Supporting Computer Networks.
1 Preparing a System Security Plan. 2 Overview Define a Security Plan Pitfalls to avoid Required Documents Contents of the SSP The profile Certification.
CDS CERTIFICATION AND ACCREDITATION PROCESS
OFFICE OF THE UNDER SECRETARY OF DEFENSE FOR INTELLIGENCE CI & SECURITY DIRECTORATE, DDI(I&S) Valerie Heil March 20, 2015 UNCLASSIFIED Industrial Security.
C &A CS Unit 2: C&A Process Overview using DITSCAP Jocelyne Farah Clinton Campbell.
United States Department of Agriculture Office of Procurement & Property Management Charge Card Service Center USDA Purchase Card Coordinators Procedures.
N-Wave Shareholders Meeting May 23, 2012 N-Wave Security Update Lisa
A Combat Support Agency Defense Information Systems Agency DISN NetOps Service Assurance 2011 Customer Conference August 2011.
Just In Time Training (JITT): How Not to Jump from the Frying Pan into the Fire.
NIST Special Publication Revision 1
OFFICE OF THE UNDER SECRETARY OF DEFENSE FOR INTELLIGENCE CI & SECURITY DIRECTORATE, DDI(I&S) Valerie Heil August 12, 2014 UNCLASSIFIED NISPOM Update.
Move over DITSCAP… The DIACAP is here!
Federal Aviation Administration Federal Aviation Administration 1 Presentation to: Name: Date: Federal Aviation Administration AMHS Security Security Sub-Group.
Certification and Accreditation CS Unit 1: Background LTC Tim O’Hara Ms Jocelyne Farah Mr Clinton Campbell.
Important acronyms AO = authorizing official ISO = information system owner CA = certification agent.
Information Assurance Program Manager U.S. Army Europe and Seventh Army Information Assurance in Large-Scale Practice International Scientific NATO PfP/PWP.
Certification and Accreditation CS Phase-1: Definition Atif Sultanuddin Raja Chawat Raja Chawat.
Sample Security Model. Security Model Secure: Identity management & Authentication Filtering and Stateful Inspection Encryption and VPN’s Monitor: Intrusion.
UNCLASSIFIED DITSCAP Primer. UNCLASSIFIED 1/18/01DITSCAP Primer.PPT 2 DITSCAP* Authority ASD/C3I Memo, 19 Aug 92 –Develop Standardized C&A Process DODI.
Shift Left Feb 2013 Page-1 DISTRIBUTION STATEMENT A – Cleared for Open Publication by OSR on January 17 th, 2013 – SR case number 13-S-0851 Dr. Steven.
Certification and Accreditation CS Syllabus Ms Jocelyne Farah Mr Clinton Campbell.
Federal Information Security Management Act (FISMA) By K. Brenner OCIO Internship Summer 2013.
Defense Information Systems Agency A Combat Support Agency E3 Engineering Division 13 December 2011 Defense Information Systems Agency A Combat Support.
NOAA Aviation Safety Board Meeting May 16, 2006 Lieutenant Commander Debora Barr NOAA Aviation Safety Program.
Defense Security Service Contractor SIPRNet Process June 2013
Networked Systems Survivability CERT ® Coordination Center Software Engineering Institute Carnegie Mellon University Pittsburgh, PA © 2002 Carnegie.
SECRET Internet Protocol Router Network (SIPRNET)
~ pertemuan 4 ~ Oleh: Ir. Abdul Hayat, MTI 20-Mar-2009 [Abdul Hayat, [4]Project Integration Management, Semester Genap 2008/2009] 1 PROJECT INTEGRATION.
 Local commanders understand impact of IA on mission accomplishment  Standard allies and coalition partners can emulate  IA for other workforces (acquisition,
Important acronyms AO = authorizing official ISO = information system owner CA = certification agent.
Kevin Watson and Ammar Ammar IT Asset Visibility.
EECS David C. Chan1 Computer Security Management Session 1 How IT Affects Risks and Assurance.
Unified Capabilities APL Testing Process
Defense Information Systems Agency A Combat Support Agency
Description of Revision
Certification and Accreditation
Matthew Christian Dave Maddox Tim Toennies
SECRET Internet Protocol Router Network (SIPRNET)
1 Stadium Company Network. The Stadium Company Project Is a sports facility management company that manages a stadium. Stadium Company needs to upgrade.
{Project Name} Organizational Chart, Roles and Responsibilities
Presentation transcript:

Jewuan Davis DSN Voice Connection Approval Office 18 May 2006 DSN Connection Approval Process (CAP)

DSN VCAO DoD Policy Guidance Mandating DSN CAP Process CJCSI B “D efense Information System Network and Connected Systems,” 31 July 2003, requires that all connections to the DISN undergo a “Network Circuit Approval Process” DoDI “DoD Voice Networks” Jan 2004 “All connections to the Defense Switched Network must have an Authority to Connect issued by the DSN Single System Manager.” Memorandum For Principal Director For Global Information Grid Combat Support (ATO for the Defense Switched Network), Jun 2005 “Ensure implementation of DSN System Network Approval Process as approved.”

DSN CAP Scope: Tactical and Strategic BACKBONE IST’s DISA O&M RESPONSIBILITY SIGNALING NETWORK (CCS7) DC SMEO End Office Switch Switch DC DVX/SMU RSU Switch End Office/ Small End Office PBX-2 ADIMSS DISA SSM Connection Approval Boundary Local DAA Boundary MILDEP O&M BOUNDARY MILDEPO&M BOUNDARY DISA End-to-End Management Responsibility Multi- Function (MFS) DC PBX-1 DCDCDC Local DAA Boundary

DSN CAP ATC Requirements DITSCAP APL Authority to Connect (ATC) Requirements APL: DoDI and CJCSI B require any currently supported voice switch planned for acquisition, installation, or connection to the DSN must either be on the Approved Products List, or be a component of an ISP certification. Local DITSCAP: IAW DoDD and DoDI , local DITSCAP must be completed for the local switch environment, with signed Authority to Operate (ATO) issued by the local Designated Approval Authority (DAA) certifying and accrediting the switch configuration and environment. Command & Control: Supports Military Unique Features (MUF)/Multiple Level Precedence and Pre-emption. Command & Control

DSN CAP Interim ATC Requirements Interim Authority to Connect (IATC) Requirements APL 1) Legacy Equipment: Solution no longer being supported, manufactured, or sold by vendor. Legacy Status verified by JITC and solution vendor. 2) APL Process Underway: -APL Status (IO): Site has Interim Certificate to Operate (ICTO) issued by ITP Panel based upon critical mission requirement for solution. -APL Status (IA): Dependent upon Local DITSCAP Status. Local DITSCAP: IAW DoDD and DoDI , local DITSCAP underway for switch, with signed Interim Authority to Operate (IATO) issued by the local Designated Approval Authority (DAA) accepting responsibility for switch while DITSCAP is being completed. Command & Control (C2): IAW CJCSI B, if switch does not support Military Unique Features (MUF)/Multiple Level Precedence & Pre- emption, site requires MUF Waiver by Joint Staff verifying that C2 capabilities are not necessary by users on this switch, at this site. DITSCAP APL Command & Control

DSN CAP Local DITSCAP Site Assist (IATO) Interim Letter of Accreditation Requirements The IATO grants temporary authorization to process information under Defined conditions. The letter will contain: The organization’s letterhead and date of signature The security mode of operations and data sensitivity or classification level Safeguards (ie: administrative, physical, personnel, COMSEC, emission, and computer security controls) The defined threat and stated vulnerabilities Interconnections to other systems The level of risk The specific period of time for approval Specific system/suite hardware and software The description of the operations environment The signature and signature block of the Designated Approving Authority (DAA)

DSN CAP Local DITSCAP Site Assist (IATO) Sample Interim Authority to Operate COCOMs/Services/Agency’s Letterhead Address SUBJECT: Interim Approval to Operate (IATO) the Defense Switched Network Switch for UID:____ Ref: (a) Accreditation Support Documentation 1.In accordance with the provisions of (COCOMs/Services/Agency’s) Instruction xxxx, an Interim Approval to Operate (IATO) is hereby granted to the (COCOMs/Services/Agency’s) Network, located in Building xxxx, room xxxx, to include (list major applications), address. This IATO is based upon a review of the information provided in reference (a). This IATO is valid for as long as the Baseline Security safeguards defined in the (COCOMs/Services/Agency’s specific directives and guidelines) are implemented. This system is authorized to operate in the thread environment defined in reference (a) and with stated vulnerabilities as identified in the (COCOMs/Services/Agency’s Baseline Security Documents). This system is authorized to process (place maximum level of information being processed) in the (mode of operation). The (COCOMs/Services/Agency’s) network is connected to the DSN and (place any other network that may be connected). 2.This IATO is valid for up to one year from the date of this letter. Final accreditation action is required before the expiration date of this IATO. This IATO will terminate sooner if there are any changes that affects the security posture of the system. It is the responsibility of the senior official in charge of the system to ensure that any change in threat, vulnerability, configuration, hardware, software, connectivity, or any other modification is analyzed to determine its impact on system security. Appropriate safeguards will be implemented to maintain a level of security consistent with the requirements of this IATO. 3.The undersigned accepts the risk for the operation of the (COCOMs/Services/Agency’s) system defined above. Signature Designated Approving Authority (COCOMs/Services/Agency’s)

June 2005May 2006July Nov 2006 DSN Interim CAP Form to SNAP Transition IAW DSN ATO Interim DSN CAP Form Established DSN SNAP Final Version Put into Production Mar 2006 DSN CCB decision to move to SNAP Initiate DSN SNAP reporting to to DSAWG, GIG Flag Panel, Deadline for DoD Components to input switch data into SNAP/ Interim CAP Form removed from web Annual DSN Inventory updated through SNAP

DSN CAP (Interim Tool)

DSN CAP (SNAP)