Defense Security Service Contractor SIPRNet Process June 2013

Slides:



Advertisements
Similar presentations
Industrial Security 2010 Worldwide Security Conference.
Advertisements

Defense Security Service Facility Clearance Branch (FCB)
ODAA Workshop December 2012 Charles Duchesne, DSS Tiffany Snyder, DSS
What’s the path to a SSP? Information System Profile Contractor: Lockheed Martin, Missiles and Fire Control Address: 1701 W. Marshall Dr. Grand Prairie,
NIH Security, FISMA and EPLC Lots of Updates! Where do we start? Kay Coupe NIH FISMA Program Coordinator Office of the Chief Information Officer Project.
1 Office of the Designated Approving Authority (ODAA) April 2008.
ISFO – ODAA Defense Security Service Industrial Security Field Operations (ISFO) Office of the Designated Approving Authority (ODAA) Nov Nov 2013.
DoD Information Assurance Certification and Accreditation Process (DIACAP) August 2011.
4/29/2009Michael J. Cohen1 Practical DIACAP Implementation CS526 Research Project by Michael J. Cohen 4/29/2009.
Summer IAVA1 NATIONAL INFORMATION ASSURANCE TRAINING STANDARD FOR SYSTEM ADMINISTRATORS (SA) Minimum.
DISN Video Services September 21, 2009 An Overview of the VTF DIACAP Process A Combat Support Agency Defense Information Systems Agency.
Industrial Security Field Operations (ISFO) Office of the Designated Approving Authority (ODAA) August 2010.
DoD Information Technology Security Certification and Accreditation Process (DITSCAP) Phase III – Validation Thomas Howard Chris Pierce.
OVERSIGHT & COMPLIANCE BRANCH (OCB) INVOICE PAYMENTS February 16,
Cybersecurity Summit 2004 Andrea Norris Deputy Chief Information Officer/ Director of Division of Information Systems.
Christopher P. Cabuzzi CS 591 DEFENSE INFORMATION ASSURANCE CERTIFICATION & ACCREDITATION PROCESS (DIACAP) Chris Cabuzzi, DIACAP, 12/8/10 1.
Secure System Administration & Certification DITSCAP Manual (Chapter 6) Phase 4 Post Accreditation Stephen I. Khan Ted Chapman University of Tulsa Department.
ODAA Update Agenda ODAA Business Management System (OBMS) Deployment
DITSCAP Phase 2 - Verification Pramod Jampala Christopher Swenson.
Stephen S. Yau CSE , Fall Security Strategies.
SAS 112: The New Auditing Standard Jim Corkill Controller Accounting Services & Controls.
Network Centric Enterprise Public Trust Information and Navy Enterprise Resource Planning Presented to the Small Business and Industry Outreach Initiative.
A Combat Support Agency Defense Information Systems Agency Unified Capabilities Requirements (UCR) Overview Joint Interoperability Test Command.
Contractor SIPRNet Process
1 Preparing a System Security Plan. 2 Overview Define a Security Plan Pitfalls to avoid Required Documents Contents of the SSP The profile Certification.
CDS CERTIFICATION AND ACCREDITATION PROCESS
Section Seven: Information Systems Security Note: All classified markings contained within this presentation are for training purposes only.
OFFICE OF THE UNDER SECRETARY OF DEFENSE FOR INTELLIGENCE CI & SECURITY DIRECTORATE, DDI(I&S) Valerie Heil March 20, 2015 UNCLASSIFIED Industrial Security.
Federal Cyber Policy and Assurance Issues Dwayne Ramsey Computer Protection Program Manager Berkeley Lab Cyber Security Summit September 27, 2004.
OFFICE OF THE UNDER SECRETARY OF DEFENSE FOR INTELLIGENCE CI & SECURITY DIRECTORATE, DDI(I&S) Valerie Heil August 12, 2014 UNCLASSIFIED NISPOM Update.
Section Five: Security Inspections and Reviews Note: All classified markings contained within this presentation are for training purposes only.
TrAMS User Access and User Roles
Important acronyms AO = authorizing official ISO = information system owner CA = certification agent.
1 Defense Health Agency Privacy and Civil Liberties Office Data Sharing Program Overview Ms. Rita DeShields DHA Data Sharing Compliance Manager August.
1 Personnel Security 2007 Data Protection Seminar TMA Privacy Office HEALTH AFFAIRS TRICARE Management Activity.
Certification and Accreditation CS Phase-1: Definition Atif Sultanuddin Raja Chawat Raja Chawat.
UNCLASSIFIED DITSCAP Primer. UNCLASSIFIED 1/18/01DITSCAP Primer.PPT 2 DITSCAP* Authority ASD/C3I Memo, 19 Aug 92 –Develop Standardized C&A Process DODI.
Steven Burke Industrial Security Supervisor Lockheed Martin
Ali Pabrai, CISSP, CSCS ecfirst, chairman & ceo Preparing for a HIPAA Security Audit.
Jewuan Davis DSN Voice Connection Approval Office 18 May 2006 DSN Connection Approval Process (CAP)
NOAA Aviation Safety Board Meeting May 16, 2006 Lieutenant Commander Debora Barr NOAA Aviation Safety Program.
SECRET Internet Protocol Router Network (SIPRNET)
Important acronyms AO = authorizing official ISO = information system owner CA = certification agent.
You are accessing a U.S. Government (USG) Information System (IS) that is provided for USG-authorized use only. By using this IS (which includes any device.
ISSM 101 Break-Out Session
The Risk Management Framework (RMF)
Defense Security Service
Defense Security Service Risk Management Framework (RMF)
“SPEAR” Workshop May 18, 2017 Julie Wammack
Safeguarding Covered Defense Information
Executive Summary Chart 1: Multiple Submissions
Unified Capabilities APL Testing Process
Team 1 – Incident Response
Investigator of Record – Definition
Sponsored Programs (SP)
Derivative Classification Overview
Josh Thompson Classified Information Systems – Western Region
IS4550 Security Policies and Implementation
Defense Security Service Risk Management Framework (RMF)
Electronic Fingerprints
Investigator of Record – Definition
Investigator of Record – Definition
Compliance Toolbox.
SECRET Internet Protocol Router Network (SIPRNET)
1 Stadium Company Network. The Stadium Company Project Is a sports facility management company that manages a stadium. Stadium Company needs to upgrade.
Registration, Role Request, and Appointment for CPMs
Registration, Role Request, and Appointment for OA/OPCs and A/OPCs
Defense Security Service Top 10 Vulnerabilities
Capabilities Briefing
Nomination, Registration, and Appointment of CHs
Presentation transcript:

Defense Security Service Contractor SIPRNet Process June 2013

Objectives Roles & Responsibilities Circuit Validation & Registration Required Equipment & Devices Certification & Accreditation Connection Approval Package SIPRNet Process Flow Chart

Roles and Responsibilities Organizations Responsibilities DoD CIO - Final approval authority for all connection requests in support of sponsor’s mission Defense Information Systems Agency (DISA) Responsible for management of Defense Information Systems Networks (DISN) circuits and oversight. Government Sponsor Sponsor/owner of contractor connection Provide funding for circuit and any other required services for contractor connection to SIPRNet (i.e. Computer Network Defense Service Provider (CNDSP), Host Based Security System (HBSS), email, Domain Name Service (DNS), SIPRNet Hardware Token and SIPRNet GIAP System Accounts). DISA SIPRNet Service Management Office (SSMO) - Review SIPRNet requests and initial topologies to determine whether the proposed DISN solution is appropriate. Forwards the approved solution to DoD CIO for approval. Defense Security Service (DSS) DAA for accrediting contractor information systems used to process classified information in industry – issues IATO, ATO and DATO. DISA Certification and Accreditation Office/Classified Connection Approval Office (CAO) - Process Connection Approval Packages (CAP) – issues Authority to Test/Connect IATT, IATC and ATC.

Circuit Validation Government Contracting Authority (GCA) All Non-DoD Connections require a contract, MOU/A, and DoD Sponsor to validate mission need for partner access to DISN. Sponsors must adhere to responsibilities as stated in DoD CIO Sponsor Memorandum, dated 11 Jan 2012 Click here for Sponsor Memo

Circuit Validation Sponsorship Letter (Validation request) Request must document all SIPRNet resources contractor will require (e.g. ports, protocols, services, websites) Topology (complete & accurate) Non-DoD Validation request: disa.meade.ns.mbx.siprnet-management- office@mail.mil Approvals needed from: DISA SIPRNet Service Manager Office (SSMO), Sponsor’s Service/Agency official, and DoD CIO Full Validation is valid for three years or expiration of contract Revalidation is required every three years or if change in sponsor, mission, requirements, contract or physical location (CAGE) DoD CIO approval may be required. Example: Contractor relocating circuit to new facility or additional sponsor organization to existing circuit

CNDSP CJCSI 6211.02D For mission partner and defense contractor ISs, the sponsoring CC/S/A must ensure: A signed agreement (e.g., MOA) or contract defines the Computer Network Defense Service Provider (CNDSP) requirements, as specified in DODD O-8530.1, are included in the agreement CNDSP requirements are implemented prior to connection.

Circuit Order Initiate SIPRNet Connection DISA Direct Online Entry (DDOE) Sponsor creates account and submits Telecommunication Service Request (TSR) Accurate POC information is critical to ordering process Key personnel: Sponsor, Contractor FSO, ISSM and/or ISSO and COMSEC manager

Required Equipment & Devices All SIPRNet circuits require NSA Type 1 encryption (e.g. KIV 7M) Sponsor must provide at both ends of SIPRNet circuit National Information Assurance Program (NIAP) approved Firewall (EAL-4) and Intrusion Detection System (IDS/IPS) (EAL-2) or Approved Products List (APL)

Circuit Registration Circuit Sponsor must register connection information in the following systems/databases Network Information Center (SIPRNet Support Center) Ports, Protocols, & Services (PPSM) SIPRNet IT Registry **Check DISA’s Non-DoD Connection Process site for the above URLs/POCs for registration. ** Website: http://iase.disa.mil/connect/index.html

Certification & Accreditation In accordance with DSS DISA MOA DSS is accrediting authority for NISP cleared contractor systems Grants Authority to Operate (I/ATO) based on contract expiration date or three years whichever occurs first. DISA has management and oversight responsibilities of DISN Grants Authority to Connect (I/ATC) Cleared contractor’s systems must have both current ATO & ATC prior to processing on SIPRNet

Certification & Accreditation System Security Plan and supporting documentation System Security Plan (SSP) and IS Profile Utilize and configure systems to applicable DoD Secure Technical Implementation Guide (STIG) Topology must include compliant Firewall/IDS and Routers Consent To Monitor (CTM) with sponsor signature Statement of Residual Risk (SRR) with contractor management signature (contractor personnel not GCA) Sponsor Validation/Re-Validation Letter DoD CIO Approval Letter

SIPRNet Requirements Command Cyber Readiness Inspections (CCRI) Contractors subject to annual CCRI Utilization of DoD STIGs Compliance with USCYBERCOM directives Including Host Based Security System (HBSS) SIPRNet Hardware Token Vulnerability Management System See DSS NISP SIPRNet Circuit Acquisition Process (NSCAP) for additional guidance Formerly called DSS SIPRNet Contractor Approval Process (SCAP)

Connection Approval Package Request for IATT, IATC/ATC Sponsor must register contractor system with SIPRNet GIG Interconnection Approval Process (GIAP) Sponsor and/or Contractor must upload the following documentation: SSP, Network Topology, POA&M (if applicable), CTM, SRR, DSS ATO, Validation Memo, DoD CIO Approval Letter DISA CAO analyst will review for completeness New circuits will have 72 burn in implemented by DISA (IATT) DISA CAO will scan enclave prior to issuing IATC/ATC

Disclosure Authorization Contractors are NOT permitted unfiltered access to the SIPRNet (see CJCSI 6211.02D). The government sponsor determines requirements (validation letter/contract) Sponsor completes Disclosure Authorization Form with required ports/protocols and submits to DISA. DISA will update contractor access list

SIPRNet Flow Chart

Questions? David Scott, CISSP Sr, ISSP, Defense Security Service David.scott@dss.mil