12.07.2015 Views

SOW Annex D - Ministerio de Defensa

SOW Annex D - Ministerio de Defensa

SOW Annex D - Ministerio de Defensa

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

NATO UNCLASSIFIEDIFB-CO-12546-GAG - <strong>SOW</strong> <strong>Annex</strong> DAppendix 1NATO 7. Target of AccreditationThe primary objective of security approval or accreditation is to ensure thatthe implemented CIS conforms with NATO Security Policy and supportingdirectives (and, where appropriate, National equivalent(s)), and the CISspecificsecurity-related documentation (e.g. CSRS). Security approval andaccreditation is the authorisation granted to a CIS to store, process or transmitinformation up to the <strong>de</strong>termined security classification in its operationalenvironment.8. Accreditation DocumentationIn or<strong>de</strong>r to grant security approval or accreditation for a CIS, the SecurityApproval or Accreditation Authority should be satisfied that the applicablesecurity requirements will be met by proper enforcement of the SRS(s), withparticular emphasis on the SSRS, and the SecOPs. The SRS(s) form thebasis for an un<strong>de</strong>rstanding and agreement between the security approval oraccreditation authority and the CIS Operating Authority that the CIS will beoperated in a secure manner.9. Approved SoftwareSoftware used on the system shall be approved by the appropriate SAA. Thisapproval is automatically applied if the software is listed in the ApprovedFiel<strong>de</strong>d Product List (AFPL) maintained by NCSA.10. Process of Accreditationa. A security risk assessment of the shall be conductedby the Host Nation (HN) e.g. NATO C3 Agency (NC3A) inconjunction with the SAA and project staffs.b. HN shall produce SRS(s) for the as required. TheSRS(s) shall:(1) Inclu<strong>de</strong> (generic) Security Operating Procedures(SecOPs).(2) Describe the minimum levels of security <strong>de</strong>emednecessary to counter risk i<strong>de</strong>ntified in a risk assessmentof the .(3) Define the security testing requirements and inclu<strong>de</strong> asecurity test and evaluation (ST&E) plan.(4) Inclu<strong>de</strong> a Statement of Compliance, including aninterconnection statement, as <strong>Annex</strong> to the SRS(s)c. The SRS(s) shall be presented to the SAA for approval in duetime to permit timely reviews and resolution of outstandingissues prior to being required operationally.NATO NATO UNCLASSIFIEDPage 12 of 14

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!