12.07.2015 Views

Download PDF - Department of Navy Chief Information Officer - U.S. ...

Download PDF - Department of Navy Chief Information Officer - U.S. ...

Download PDF - Department of Navy Chief Information Officer - U.S. ...

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

CAST requirements include the ability to collect metrics onall aspects <strong>of</strong> processing and management <strong>of</strong> C&A informationso that a continuous process improvement program can be supportedas the nature and requirements associated with C&Acontinue to evolve.With CAST, automating major DIACAP requirements will bemet for all information systems, including information technologysystems; networks; circuits; sites; infrastructures; enclaves;and environments and assets that require security certificationand accreditation within the DON, regardless <strong>of</strong> current accreditationstatus.Specific goals for CAST include:Ensuring IA is built in from the concept stage through the lifecycle;Accounting for inheritance <strong>of</strong> information assurance controls;Enforcing annual reviews for all systems and sites; andProviding enterprise-wide visibility into security posture andrisk.By facilitating standardization and quality improvement forC&A packages from the initiation <strong>of</strong> the process, significantreductions in review times, rework and learning curves are expectedimmediately.In addition, early collaboration by stakeholders will ensureadequate identification and resolution <strong>of</strong> security risk issuesearly in the process and not later during formal C&A reviews.Once the CAST procurement award is made, the tool will beinitially implemented during a pilot phase with the objective<strong>of</strong> testing processes, procedures and templates. The pilot willbuild the necessary databases, verify process steps and propertool configuration, conduct test and evaluation, and processselected DIACAP C&A packages to verify tool effectiveness in acontrolled environment.TrainingAt the same time, training will be provided to the C&A communityon the tool and detailed DON processes and policies. It isexpected that training will be an ongoing requirement throughoutthe life <strong>of</strong> CAST. Once CAST is fully implemented, DIACAPtraining will target personnel performing activities in the threemain tiers <strong>of</strong> the C&A process: package creation, review andapproval.Training will focus on required tasks and how to performthese using the tool. Each tier <strong>of</strong> training will contain an overview<strong>of</strong> the DON process flow and build upon the activities accomplishedby all members <strong>of</strong> the C&A team.Since transition from DITSCAP to DIACAP will be gradual overthe next three years, there is a phasing out <strong>of</strong> systems’ C&Adocumentation from DITSCAP to DIACAP. The DIACAP transitionteam will provide subject matter experts to support programand system managers, as well as IA managers, in planning eachsystem transition to DIACAP. This will include assistance in developingtransition plans and answering any related questions.Finally, because systems will begin transitioning to DIACAPprior to full implementation <strong>of</strong> the DON automated tool, allsubmissions <strong>of</strong> C&A packages will continue using existing C&Apackage systems in the near term.The transition to DIACAP is great news for DoD and DON systemdevelopers, program managers and security managers!Additional <strong>Information</strong>The C&A process has undergone major changes over the last severalyears. These were driven by increased awareness <strong>of</strong> security vulnerabilities,shrinking resources and the pressing operational need t<strong>of</strong>ield new and improved capabilities to support the warfighter.The movement from DITSCAP to DIACAP has provided an opportunetime to both automate and standardize the entire end-to-end C&Aprocess to conserve resources and ensure security risk is managed atacceptable levels.To stay abreast <strong>of</strong> the information being developedduring this transition time, readers are encouraged to periodically accessthe DON CIO Web site at www.doncio.navy.mil.For now, programs desiring to make use <strong>of</strong> DIACAP templates canaccess them from the Fleet Forces Web site under the View All SiteContents/Documents tab on the left side <strong>of</strong> the page at https://www.fleetforces.navy.mil/netwarcom/navycanda/default.aspx.For the Marine Corps, users can access the Marine Corps Xacta<strong>Information</strong> Assurance Manager tool available at https://hqtelosweb.hqmc.usmc.mil/.The primary contact for DITSCAP to DIACAP transition technicalsupport can be reached by e-mail at SPSC-DON-DIACAP@navy.mil.Secondary contacts for transition technical support are:<strong>Navy</strong> - Operational Designated Approving Authority (ODAA) - e-mail: <strong>Navy</strong>_ODAA@navy.mil or (757) 417-6719 x0.Marine Corps - Programs <strong>of</strong> record (not yet fielded), contact the MarineCorps Systems Command (Systems Engineering, Interoperability,Architectures & Technology (SIAT)) at (703) 437-3824.All other systems (including fielded programs <strong>of</strong> record), contactthe Marine Corps Enterprise Network Designated Approving Authority(MCEN DAA) by e-mail: M_MCEN_DAA@usmc.mil or (703) 693-3490.Resources• DON DITSCAP to DIACAP Transition Guide, version 1.1, June 9,2008 - under the <strong>Information</strong> Assurance topic area at www.doncio.navy.mil.• DON DIACAP Handbook, version 1.0, July 21, 2008 - under the <strong>Information</strong>Assurance topic area at www.doncio.navy.mil.•DoD Instruction 8510.01, DoD <strong>Information</strong> Assurance Certificationand Accreditation Process (DIACAP), Nov. 28, 2007 - www.dtic.mil/whs/directives/corres/pdf/851001p.pdf.• Secretary <strong>of</strong> the <strong>Navy</strong> Manual, SECNAV M-5239.1, <strong>Information</strong> AssuranceManual, November 2005 - http://doni.daps.dla.mil/SECNAV%20Manuals1/5239.1.pdf.• DoD Directive 8500.01E, <strong>Information</strong> Assurance (IA), Oct. 24, 2002 -www.dtic.mil/whs/directives/. Certified as current April 23, 2007.• DoD Instruction 8500.2, <strong>Information</strong> Assurance (IA) Implementation,Feb. 6, 2003 - www.dtic.mil/whs/directives/corres/pdf/850002p.pdf.Ms. Yuh-Ling Su is the DON DIACAP transition assistant program managerunder PMW 160.40 CHIPS www.chips.navy.mil Dedicated to Sharing <strong>Information</strong> - Technology - Experience

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!