<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>elamb &#187; EITDR</title>
	<atom:link href="http://elamb.org/category/assurance/eitdr/feed/" rel="self" type="application/rss+xml" />
	<link>http://elamb.org</link>
	<description>information system security, risk management, scam research</description>
	<lastBuildDate>Mon, 28 Nov 2011 02:27:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>UPDATED IA STUFF + Procrastination</title>
		<link>http://elamb.org/updated-ia-stuff-procrastination/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=updated-ia-stuff-procrastination</link>
		<comments>http://elamb.org/updated-ia-stuff-procrastination/#comments</comments>
		<pubDate>Wed, 27 Jan 2010 07:13:40 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[Assurance/SSAA]]></category>
		<category><![CDATA[blogger]]></category>
		<category><![CDATA[blogging]]></category>
		<category><![CDATA[EITDR]]></category>
		<category><![CDATA[information assurance]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[security experts]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=2203</guid>
		<description><![CDATA[My greatest skill is procrastination. I really am the best, most skilled procrastinator I know. It takes all of my will power to stay consistent with anything, including this blog, which is why (among other things) I am not banking &#8230; <a href="http://elamb.org/updated-ia-stuff-procrastination/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><strong>My greatest skill is procrastination.  I really am the best, most skilled procrastinator I know. </strong>It takes all of my will power to stay consistent with anything, including this blog, which is why (among other things) I am not banking like <a href="http://problogger.net">Darren Rowse</a> or <a href="www.stevepavlina.com">Steve Pav</a>, two of my favorite bloggers.</p>
<p><strong>YOU SEE</strong>, I am such a good procrastinator that I <strong>JUST</strong> procrastinated on getting to the REAL subject of this article, security, IA updates.</p>
<p>A fellow IA Analyst wrote me with questions that got right to the heart of IA&#8230; <em>change</em>.  </p>
<p><strong>She asked about AFI 33-202.</strong><br />
And I said:</p>
<blockquote><p>Right as I felt I had mastered the contents of 33-202, the airforce moved to 33-210 (to replace all its C&#038;A stuff).  I believe 33-202 is now obsolete and replaced with 33-200 &#038; 33-202 and others.. last time I was with the AF, anyway.</p></blockquote>
<p><strong>What about IT LEAN?</strong><br />
I said:</p>
<blockquote><p>As for IT Lean, you can find that on AF Knowledge Now site and I think they have links to it on EITDR.  If you are interested in IT Lean you&#8217;ll be REALLY interested in 33-210:<br />
<a href="http://cryptome.quintessenz.at/mirror/dodi/AFI33-210.pdf">33-210</a>
</p></blockquote>
<p>But if you are working with the Air Force and want more on the IT LEAN process you should be digging into  AFCAP, Air Force Certification &#038; Accreditation Program, an AF version of IT Lean.</p>
<p><strong>CNSS 1253:</strong><br />
A lot of people also ask me to send them a copy of the CNSSI 12-53.  But it is actually OUT.  Its the <a href="http://www.cnss.gov/Assets/pdf/CNSSI-1253.pdf">CNSSI 1253</a>.  I, personally, have not had any clear direction (currently NO direction) on how to start moving some of the CNSSI to the systems I work on.  I suspect that the Govt. will start this within the next couple of years and start phasing out DIACAP.. but who the hell knows what a bureaucracy of their size will do next!</p>
<p>Lastly, my fellow IA Analyst asked me about EITDR<br />
and I said:</p>
<blockquote><p>You&#8217;ll find the EITDR POCs on the Air Force Portal or Knowledge Now.  Log on to the Air Force Portal (if you don&#8217;t have an account get one.. you may have to get sponsor by the Govt to get it).  Once on the AF Portal search for EITDR and they&#8217;ll have tons of stuff on it.  Waaaaay more stuff than you want to read.  You&#8217;ll also find the person you need to start the EITDR process with.</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/updated-ia-stuff-procrastination/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CNSSI 12-53: New Security Control Catalog for National Security Systems</title>
		<link>http://elamb.org/cnssi-12-53-new-security-control-catalog-for-national-security-systems/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cnssi-12-53-new-security-control-catalog-for-national-security-systems</link>
		<comments>http://elamb.org/cnssi-12-53-new-security-control-catalog-for-national-security-systems/#comments</comments>
		<pubDate>Fri, 03 Jul 2009 05:39:49 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[Assurance/DITSCAP]]></category>
		<category><![CDATA[Assurance/Netcentric]]></category>
		<category><![CDATA[Assurance/SSAA]]></category>
		<category><![CDATA[EITDR]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[security]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1746</guid>
		<description><![CDATA[New DIACAP Certification &#038; Accreditation IA Controls The DoD has had the same IA controls since DoD 8510.1-M, controls since DoD 8510.1-M, Department of Defense Information Technology System Certification &#038; Accreditation Process (DITSCAP), July 31, 2000 â€“ it was developed &#8230; <a href="http://elamb.org/cnssi-12-53-new-security-control-catalog-for-national-security-systems/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><strong>New DIACAP Certification &#038; Accreditation IA Controls</strong></p>
<p>The DoD has had the same IA controls since DoD 8510.1-M, controls since DoD 8510.1-M, Department of Defense Information Technology System Certification &#038; Accreditation Process (DITSCAP), July 31, 2000 <em>â€“ it was developed late last century.</em></p>
<p><strong>The DoD has a total of 157 IA controls spread across 8 subject areas in 4 classes:</strong></p>
<blockquote><p>
DC â€“ Security Design &#038; Configuration</p>
<p>IA â€“ Identification and Authentication</p>
<p>EC â€“ Enclave &#038; Computing</p>
<p>EB â€“ Enclave Boundary Defense</p>
<p>PE â€“ Physical &#038; Environmental</p>
<p>PR â€“ Personnel</p>
<p>CO â€“ Continuity</p>
<p>VI â€“ Vulnerability </p></blockquote>
<p>There is a huge change coming in certification &#038; accreditation for the DoD coming.  The IA controls are being expanded and changed.  The last two DIACAP classes Iâ€™ve been to mentioned that there is a big change coming.  Essentially, all the IA Controls (security controls, safeguards, countermeasures.. whatever your organization is calling them) are getting expanded.  All federal organizations will have security controls that look more like what is in the National Institute of Standards and Technology Special Publication 800-53.  This is all being placed in the Committee on National Security Systems Instruction (CNSSI) 1253.  As of 25 June 2009, the CNSSI 1253 is still in draft. </p>
<p>The draft has 17 families &#038; identifiers in three security control classes.  </p>
<p>TABLE 1: SECURITY CONTROL CLASSES, FAMILIES, AND IDENTIFIERS<br />
IDENTIFIER FAMILY CLASS</p>
<blockquote><p>AC Access Control Technical</p>
<p>AT Awareness and Training Operational</p>
<p>AU Audit and Accountability Technical</p>
<p>CA Certification, Accreditation, and Security Assessments Management</p>
<p>CM Configuration Management Operational</p>
<p>CP Contingency Planning Operational</p>
<p>IA Identification and Authentication Technical</p>
<p>IR Incident Response Operational</p>
<p>MA Maintenance Operational</p>
<p>MP Media Protection Operational</p>
<p>PE Physical and Environmental Protection Operational</p>
<p>PL Planning Management</p>
<p>PS Personnel Security Operational</p>
<p>RA Risk Assessment Management</p>
<p>SA System and Services Acquisition Management</p>
<p>SC System and Communications Protection Technical</p></blockquote>
<p>The CNSSI has about 500 controls with pretty good granularity.  </p>
<p>One of the really cool thing about 1253 was the security control mapping.  Itâ€™s a table that matches up 800-53, DCID 6/3 and DODI 8500.2.</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/cnssi-12-53-new-security-control-catalog-for-national-security-systems/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>DIACAP Essentials + IA Control Validation Training (part 4): DIACAP/AFCAP Day 4 &amp; 5</title>
		<link>http://elamb.org/diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day-4-5/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day-4-5</link>
		<comments>http://elamb.org/diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day-4-5/#comments</comments>
		<pubDate>Fri, 03 Jul 2009 05:21:11 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[Assurance/DITSCAP]]></category>
		<category><![CDATA[Assurance/Netcentric]]></category>
		<category><![CDATA[Assurance/SSAA]]></category>
		<category><![CDATA[EITDR]]></category>
		<category><![CDATA[emass]]></category>
		<category><![CDATA[FISMA]]></category>
		<category><![CDATA[information assurance]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sissu]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1744</guid>
		<description><![CDATA[Days 4 &#038; 5 bring the DIACAP/AFCAP Essentials Class to a close. The biggest things I learned were: CNSSI 4009 is the the official glossary of DOD IA, there is a big difference between theory, policy and practice, Agents of &#8230; <a href="http://elamb.org/diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day-4-5/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Days 4 &#038; 5 bring the DIACAP/AFCAP Essentials Class to a close.  The<br />
biggest things I learned were:  CNSSI 4009 is the the official glossary of DOD IA, there is a big difference between theory, policy and practice, Agents of the Certifying Authority (ACA) are official validators and there is a difference between acquisition Mission criticality and IA MAC levels.   </p>
<p><strong>Stuff I learned from people in the class:</strong></p>
<blockquote><p>-AFCA is changing its name (to what?)</p>
<p>DOD is going to put the new IA controls in NCSSI 12-53 (currently in draft)</p>
<p>-a lot of what I need in there is in NIST 800-53</p>
<p>Marines use something called Exacta</p>
<p>Site called securitycritics.org</p>
<p>33-202 is now completely irrelevant and obsolete (not even mentioned ONCE in the class)</p>
<p>800-30</p>
<p>Feds call Certification &#038;Accreditation (C&#038;A) â€œSecurity authorizationâ€ </p>
<p>NIST SP 800-37</p></blockquote>
<p><strong>Day 4:</strong></p>
<blockquote><p>Validator Activities &#038; Issue Accreditation Decision</p>
<p>Prepare POA&#038;M</p>
<p>Validate Results/Scorecard</p>
<p>Scorecard</p>
<p>Make certification determination</p>
<p>CA/DAA Package review </p></blockquote>
<p><strong>Day 5:</strong></p>
<blockquote><p>Validation procedures were discussed.  On day five, we looked at how the validators look at a system.</p>
<p>I thought is was interesting.  It should help me get through the EITDR/DIACAP process easier.</p>
<p>Maintain Situational Awareness</p>
<p>Maintain IA Posture</p>
<p>Conduct Review</p>
<p>R-Accreditation</p>
<p>Retire system </p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day-4-5/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DIACAP Essentials + IA Control Validation Training (part 4): DIACAP/AFCAP Day3</title>
		<link>http://elamb.org/diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day3/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day3</link>
		<comments>http://elamb.org/diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day3/#comments</comments>
		<pubDate>Fri, 03 Jul 2009 04:37:14 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[Assurance/DITSCAP]]></category>
		<category><![CDATA[Assurance/Netcentric]]></category>
		<category><![CDATA[Assurance/SSAA]]></category>
		<category><![CDATA[EITDR]]></category>
		<category><![CDATA[FISMA]]></category>
		<category><![CDATA[information assurance]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[sissu]]></category>
		<category><![CDATA[DIACAP]]></category>
		<category><![CDATA[DIACAP Team]]></category>
		<category><![CDATA[ditpr]]></category>
		<category><![CDATA[dod]]></category>
		<category><![CDATA[emass]]></category>
		<category><![CDATA[IA]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1736</guid>
		<description><![CDATA[Day 3 heats up a little. We start talking about what it take to actually get validated. The DIACAP Implementers Guide &#038; the DIACAP Validators guide is opened up and reviewed. I think we all learned a little something during &#8230; <a href="http://elamb.org/diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day3/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Day 3 heats up a little.  We start talking about what it take to actually get validated.  The DIACAP Implementers Guide &#038; the DIACAP Validators guide is opened up and reviewed.  I think we all learned a little something during this discussion because there have been some challenges with this.  Unfortunately, we don&#8217;t to far into the validator stuff.</p>
<p><strong>Day 3:</strong>  </p>
<blockquote><p>DIACAP Structure</p>
<p>Terminology Review</p>
<p>Assemble DIACAP Team</p>
<p>Registered System/System Information Profile</p>
<p>Assign IA Controls</p>
<p>Initiate DIACAP Implementation Plan </p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DIACAP Essentials + IA Control Validation Training (part 3): DIACAP/AFCAP Day2</title>
		<link>http://elamb.org/diacap-essentials-ia-control-validation-training-part-3-diacapafcap-day2/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=diacap-essentials-ia-control-validation-training-part-3-diacapafcap-day2</link>
		<comments>http://elamb.org/diacap-essentials-ia-control-validation-training-part-3-diacapafcap-day2/#comments</comments>
		<pubDate>Fri, 03 Jul 2009 04:32:44 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[apms]]></category>
		<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[Assurance/DITSCAP]]></category>
		<category><![CDATA[Assurance/Netcentric]]></category>
		<category><![CDATA[Assurance/SSAA]]></category>
		<category><![CDATA[EITDR]]></category>
		<category><![CDATA[federal]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1733</guid>
		<description><![CDATA[Day 1 &#038; 2 have been all about the very basics of DIACAP. Were introduced to the terminologies, key players of the C&#038;A process and basically given the big picture. Like I said, GREAT for beginners, but just lots of &#8230; <a href="http://elamb.org/diacap-essentials-ia-control-validation-training-part-3-diacapafcap-day2/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Day <a href="http://elamb.org/diacap-essentials-ia-control-validation-training-part-2-diacapafcap-day1/">1 </a>&#038; 2 have been all about the very basics of DIACAP.  Were introduced to the terminologies, key players of the C&#038;A process and basically given the big picture.  Like I said, GREAT for beginners, but just lots of theory and refresher if you&#8217;ve been doing C&#038;A since DITSCAP.</p>
<p><strong>Day 1 &#038;2: </strong> </p>
<blockquote><p>Getting the Big Picture</p>
<p>DIACAP/AFCAP Policy &#038; Terminology</p>
<p>Roles and Responsibilities for the C&#038;A process</p>
<p>Accreditation  &#038; Approval to Connect</p>
<p>Homework: review terminology  </p></blockquote>
<p>In between longer breaks, during lunch and just before class we sneak in episode of the The IT Crowd.  Its the first time I&#8217;ve watched it so its a real treat for me.  Hilarious show.  </p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/diacap-essentials-ia-control-validation-training-part-3-diacapafcap-day2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DIACAP Essentials + IA Control Validation Training (part 2): DIACAP/AFCAP Day1</title>
		<link>http://elamb.org/diacap-essentials-ia-control-validation-training-part-2-diacapafcap-day1/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=diacap-essentials-ia-control-validation-training-part-2-diacapafcap-day1</link>
		<comments>http://elamb.org/diacap-essentials-ia-control-validation-training-part-2-diacapafcap-day1/#comments</comments>
		<pubDate>Tue, 23 Jun 2009 01:29:26 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[Assurance/DITSCAP]]></category>
		<category><![CDATA[Assurance/Netcentric]]></category>
		<category><![CDATA[Assurance/SSAA]]></category>
		<category><![CDATA[Certification/CISSP]]></category>
		<category><![CDATA[EITDR]]></category>
		<category><![CDATA[federal]]></category>
		<category><![CDATA[FISMA]]></category>
		<category><![CDATA[information assurance]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[AFCAP]]></category>
		<category><![CDATA[apms]]></category>
		<category><![CDATA[architectural views]]></category>
		<category><![CDATA[DIACAP]]></category>
		<category><![CDATA[DIACAP Team]]></category>
		<category><![CDATA[ditpr]]></category>
		<category><![CDATA[ditprdon]]></category>
		<category><![CDATA[dod]]></category>
		<category><![CDATA[emass]]></category>
		<category><![CDATA[IA]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[sissu]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1731</guid>
		<description><![CDATA[DIACAP/AFCAP Day 1. This is the second installment of the DIACAP Essentials journal. In the first day of class we&#8217;ve taken a high level look at the big picture of the Department of Defense Information Assurance Certification &#038; Accreditation Process &#8230; <a href="http://elamb.org/diacap-essentials-ia-control-validation-training-part-2-diacapafcap-day1/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><strong>DIACAP/AFCAP Day 1.</strong><br />
<a href="http://elamb.org/diacap-essentials-ia-control-validation-training-part-1/">This is the second installment of the DIACAP Essentials journal.</a></p>
<p>In the first day of class we&#8217;ve taken a high level look at the big picture of the Department of Defense Information Assurance Certification &#038; Accreditation Process (DIACAP) and Air Force Certification &#038; Accreditation Program (AFCAP).  It is a very valuable tool for a beginner. </p>
<p>Since I&#8217;ve gone through the entire process (with a legacy system) more than once through all the growing pains of Air Force C&#038;A from DITSCAP to DIACAP, I found that I knew about 90% of everything taught.  I don&#8217;t mind having a refresher, though and quite frankly, I need the CPE&#8217;s for my CISSP <img src='http://elamb.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> .</p>
<p>There were a couple of golden nuggets that I&#8217;ve been able to get out of some of the old timers.  I learned some interesting things about how the Navy, Marines and Army do things.<br />
Navy (as weird as their dumb ass rank system.. yep, I said it.. its dumb) have like three systems: DITPR-DON, DA-DUMB and some other BS, Marines have something called Exacta and the Army has APMS (Army Profile Management System).  Also learned cool off topic stuff like history of eMass.</p>
<p>I must admit I&#8217;m looking forward to day two.<br />
pros of day 1: Good solid start on basics GREAT for beginners.  <a href="http://www.secureinfo.com/">SecureInfo</a> gets mad props for have a great instructor John M.(don&#8217;t know if he wants his full name published.. but he&#8217;s highly, highly knowledgeable and very positive).</p>
<p>cons of day 1: Right off the bat I am noticing a huge hole in the training&#8230; a lack of in depth teaching of <a href="http://elamb.org/eitdr-enterprise-information-technology-data-repository/">EITDR</a>, which is how the Air Force implements, manages and maintains the entire DIACAP/AFCAP process.  I don&#8217;t really see how you can teach one without the other these days.  I guess contractually, SecureInfo can not touch it since some other company has the contract.  But unfortunately, the folks that are new to this are going to suffer.  Because if they goto this class without knowing the EITDR they will know why but now how, and if they go to the EITDR class without knowing the DIACAP they will know how but not Why.</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/diacap-essentials-ia-control-validation-training-part-2-diacapafcap-day1/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Validation: Track the Results</title>
		<link>http://elamb.org/validation-track-the-results/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=validation-track-the-results</link>
		<comments>http://elamb.org/validation-track-the-results/#comments</comments>
		<pubDate>Tue, 26 May 2009 22:29:26 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Assurance]]></category>
		<category><![CDATA[EITDR]]></category>
		<category><![CDATA[information assurance]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Awareness]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1712</guid>
		<description><![CDATA[If you are doing Certification &#038; Accreditation then you know it&#8217;s all about the documentation. But its not just about reviewing the documentation that a system is supposed to have. If you&#8217;re in the business of getting systems validated sometimes &#8230; <a href="http://elamb.org/validation-track-the-results/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>If you are doing Certification &#038; Accreditation then you know it&#8217;s all about the documentation.  </p>
<p>But its not just about <em>reviewing</em> the documentation that a system is supposed to have.  If you&#8217;re in the business of getting systems validated sometimes you&#8217;ll have to produce the documentation.</p>
<p>An IA Analyst, system security engineer or Information Assurance Officer (IAO) usually documents the results of their security tests.  For example, if they run a Retina Scan they will want to generate a report that has the results of that network or system scan.  </p>
<p>DoD Information Assurance Certification &#038; Accreditation (DIACAP) Knowledge Service, the Enterprise Information Technology Data Repository (EITDR) and other IT profile databases have very detailed information on what the final Validators are looking for.</p>
<p>If you&#8217;re in line with the final validators you will not have much of a problem, because they will approve the system and move it on to the Designated Approval Authority (DAA).</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/validation-track-the-results/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Certification &amp; Accreditation Process (Rumor)</title>
		<link>http://elamb.org/new-certification-accreditation-process-rumor/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=new-certification-accreditation-process-rumor</link>
		<comments>http://elamb.org/new-certification-accreditation-process-rumor/#comments</comments>
		<pubDate>Thu, 26 Mar 2009 03:35:42 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[Assurance/DITSCAP]]></category>
		<category><![CDATA[Assurance/SSAA]]></category>
		<category><![CDATA[EITDR]]></category>
		<category><![CDATA[information assurance]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1662</guid>
		<description><![CDATA[<strong>One C&#038;A package to rule them all? </strong>

The federal government has a bunch of Certification &#038; Accreditation processes.  There is Department of Defense Information Assurance Certification &#038; Accreditation (DIACAP) for the  DOD, thereâ€™s Director of Central intelligence Directive (DCID) 6/3 for certain classified systems, there is National Information Assurance Certification &#038; Accreditation (NIACAP) for National Security Systems.  And under each of these their processes  differ according the branch, leadership, organization and/or mission.  Each process, organization, branch and mission has a different set of resources that they pull from.  DIACAP pertains to military branches and pulls from the DoD 8500 series,  many other federal agencies use National Institute of Standards and Technology (NIST) Special Publication (SP) 800-xx series.

Each agency, organization and/or branch uses their own methods and everyone is happy.  The only problem is when a system gets exploited.  When it happens there is mass panic and they realize that there are massive holes in the process. <a href="http://elamb.org/new-certification-accreditation-process-rumor/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><strong>One C&#038;A package to rule them all? </strong></p>
<p>The federal government has a bunch of Certification &#038; Accreditation processes.  There is Department of Defense Information Assurance Certification &#038; Accreditation (DIACAP) for the  DOD, thereâ€™s Director of Central intelligence Directive (DCID) 6/3 for certain classified systems, there is National Information Assurance Certification &#038; Accreditation (NIACAP) for National Security Systems.  And under each of these their processes  differ according the branch, leadership, organization and/or mission.  Each process, organization, branch and mission has a different set of resources that they pull from.  DIACAP pertains to military branches and pulls from the DoD 8500 series,  many other federal agencies use National Institute of Standards and Technology (NIST) Special Publication (SP) 800-xx series.</p>
<p>Each agency, organization and/or branch uses their own methods and everyone is happy.  The only problem is when a system gets exploited.  When it happens there is mass panic and they realize that there are massive holes in the process.</p>
<p><strong>Rumors and Trends</strong></p>
<p>There  have been rumors floating around about many of these federal C&#038;A processes merging into one.  At their core they are actually pretty similar.  Take NIST SP 800-37, C&#038;A of Federal Information Systems and DOD 8510, DIACAP for example.  Both have an initial phase where data is gathered on the system and all parties involved with a system are pulled together (see table. 1 for more similarities). </p>
<table class=MsoNormalTable border=0 cellspacing=0 cellpadding=0<br />
 style='border-collapse:collapse;mso-padding-alt:0in 0in 0in 0in;border-width:<br />
 initial;border-color:initial'><br />
<tr style='mso-yfti-irow:0;mso-yfti-firstrow:yes'>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt'>
<p><span style='font-family:Arial'>Federal C&amp;A Process<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-left:none;padding:0in 5.4pt 0in 5.4pt;border-left-width:initial;<br />
  border-left-color:initial'>
<p><span style='font-family:Arial'>Phases<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-left:none;padding:0in 5.4pt 0in 5.4pt;border-left-width:initial;<br />
  border-left-color:initial'>
<p><span style='font-family:Arial'>Activities<o:p></o:p></span></p>
</td>
</tr>
<tr style='mso-yfti-irow:1'>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-top:none;padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;<br />
  border-top-color:initial'>
<p><span style='font-family:Arial'>SP 800-37<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>Initiation Phase<o:p></o:p></span></p>
</td>
<td width=213 rowspan=2 valign=top style='width:159.6pt;border-top:none;<br />
  border-left:none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>Gather data, get agreement of all stake<br />
  holders<o:p></o:p></span></p>
</td>
</tr>
<tr style='mso-yfti-irow:2'>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-top:none;padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;<br />
  border-top-color:initial'>
<p><span style='font-family:Arial'>DIACAP<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>Initiate &amp; Plan IA C&amp;A<o:p></o:p></span></p>
</td>
</tr>
<tr style='mso-yfti-irow:3'>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-top:none;padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;<br />
  border-top-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
</tr>
<tr style='mso-yfti-irow:4'>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-top:none;padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;<br />
  border-top-color:initial'>
<p><span style='font-family:Arial'>SP 800-37<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>Security Certification Phase<o:p></o:p></span></p>
</td>
<td width=213 rowspan=2 valign=top style='width:159.6pt;border-top:none;<br />
  border-left:none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>IA Control Assessment and agreement<o:p></o:p></span></p>
</td>
</tr>
<tr style='mso-yfti-irow:5'>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-top:none;padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;<br />
  border-top-color:initial'>
<p><span style='font-family:Arial'>DIACAP<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>Implement &amp; Validate Assigned IA<br />
  Controls<o:p></o:p></span></p>
</td>
</tr>
<tr style='mso-yfti-irow:6'>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-top:none;padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;<br />
  border-top-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
</tr>
<tr style='mso-yfti-irow:7'>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-top:none;padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;<br />
  border-top-color:initial'>
<p><span style='font-family:Arial'>SP 800-37<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>Security Accreditation Phase<o:p></o:p></span></p>
</td>
<td width=213 rowspan=2 valign=top style='width:159.6pt;border-top:none;<br />
  border-left:none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>Security implementation and assessment<o:p></o:p></span></p>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
</tr>
<tr style='mso-yfti-irow:8'>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-top:none;padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;<br />
  border-top-color:initial'>
<p><span style='font-family:Arial'>DIACAP<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>Make Cert. Determination &amp;<br />
  Accreditation Decision<o:p></o:p></span></p>
</td>
</tr>
<tr style='mso-yfti-irow:9'>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-top:none;padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;<br />
  border-top-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
</tr>
<tr style='mso-yfti-irow:10'>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-top:none;padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;<br />
  border-top-color:initial'>
<p><span style='font-family:Arial'>DP 800-37<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>Continuous Monitoring Phase<o:p></o:p></span></p>
</td>
<td width=213 rowspan=2 valign=top style='width:159.6pt;border-top:none;<br />
  border-left:none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>Configuration management; FISMA reporting;<br />
  <span class=SpellE>sustainment</span><o:p></o:p></span></p>
</td>
</tr>
<tr style='mso-yfti-irow:11'>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-top:none;padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;<br />
  border-top-color:initial'>
<p><span style='font-family:Arial'>DIACAP<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>Maintain Authorization to Operate<o:p></o:p></span></p>
</td>
</tr>
<tr style='mso-yfti-irow:12'>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-top:none;padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;<br />
  border-top-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
</tr>
<tr style='mso-yfti-irow:13'>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-top:none;padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;<br />
  border-top-color:initial'>
<p><span style='font-family:Arial'>DIACAP<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>Decommission<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>Retire System<o:p></o:p></span></p>
</td>
</tr>
<tr style='mso-yfti-irow:14'>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-top:none;padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;<br />
  border-top-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
</tr>
<tr style='mso-yfti-irow:15;mso-yfti-lastrow:yes'>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-top:none;padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;<br />
  border-top-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
</tr>
</table>
<p>12-37?</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/new-certification-accreditation-process-rumor/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DIACAP Activity #4 Maintain Authorization to Operate and Conduct Review</title>
		<link>http://elamb.org/diacap-activity-4-maintain-authorization-to-operate-and-conduct-review/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=diacap-activity-4-maintain-authorization-to-operate-and-conduct-review</link>
		<comments>http://elamb.org/diacap-activity-4-maintain-authorization-to-operate-and-conduct-review/#comments</comments>
		<pubDate>Thu, 21 Feb 2008 22:57:02 +0000</pubDate>
		<dc:creator>elamb</dc:creator>
				<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[Assurance/DITSCAP]]></category>
		<category><![CDATA[Assurance/SSAA]]></category>
		<category><![CDATA[EITDR]]></category>
		<category><![CDATA[DIACAP]]></category>
		<category><![CDATA[emass]]></category>
		<category><![CDATA[Maintain Authorization to Operate and Conduct Review]]></category>

	<!-- AutoMeta Start -->
	<category>iam</category>
	<category>subparagraph</category>
	<category>posture</category>
	<category>controls</category>
	<category>newly</category>
	<category>daa</category>
	<category>reaccreditation</category>
	<category>revalidation</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/diacap-activity-4-maintain-authorization-to-operate-and-conduct-review/</guid>
		<description><![CDATA[Maintain Situational AwarenessIncluded in the IA controls assigned to all DoD ISs are IA controls related to configuration and vulnerability management, performance monitoring, and periodic independent evaluations (e.g., penetration testing). The IAM continuously monitors the system or information environment for &#8230; <a href="http://elamb.org/diacap-activity-4-maintain-authorization-to-operate-and-conduct-review/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><font size="3"><strong>Maintain Situational Awareness</strong></font><font size="3"><em>Included in the IA controls assigned to all DoD ISs are IA controls related to configuration and vulnerability management, performance monitoring, and periodic independent evaluations (e.g., penetration testing). The IAM continuously monitors the system or information environment for security-relevant events and configuration changes that negatively impact IA posture and periodically assesses the quality of IA controls implementation against performance indicators such as security incidents, feedback from external inspection agencies (e.g., IG DoD, Government Accountability Office (GAO)), exercises, and operational evaluations. In addition the IAM may, independently or at the direction of the CA or DAA, schedule a revalidation of any or all IA controls at any time. Reference (a) requires revalidation of a select number of IA controls at least annually. (DoD 8510.01, 6.3.4.1)</p>
<p></em>Knowing what is going on with the system is the job of the Information Assurance Manager (IAM). This can be delegated to the Information Assurance Officer (IAO) or the IAM and IAO may be the same person, but keep in mind that these permission require training, a technical and security certification (IAW DoD 8570).</p>
<p><strong>Maintain IA Posture</strong></p>
<p>Ensuring that there are no changes to the IA posture falls on the shoulders of the IAM.Â  This includes making sure that the establish baseline of the system has no signifigant changes.Â  Most patches (even involving security) will have a minimal impact on the system.Â  Applicable patches should always be tested before being put on a system.Â  Major patches are usually service packs that may actually change the IA posture.Â  The DIACAP Team should be involved with any major changes to the IA posture.Â  They will also decide whichÂ modifications, upgrades and additionsÂ should be considered changes to the IA posture of the system.Â  As a minimum, the Program Manager, IAM, subject matter experts (software/system security engineers) andÂ information system owner/user representative should be appart of that decision.Â </p>
<p><strong>What will likely be considered a change to the IA Posture:</strong></p>
<blockquote><p>Adding IA products (firewalls, intrusion detection systems, ect)</p>
<p>Some internetworking devices such as Routers and Switches</p>
<p>New operating systems</p>
<p>Major upgrades to software or operating systems (not including support applications)</p>
<p>Newly discover major vulnerabilities</p>
<p>*Basically any major changes thatÂ willÂ affect theÂ security, supportability, usability, and interoperability of the system.Â  It is important to have who, what when and where of sustainability, new risks, and usability requirements in writing.Â  Information Assurance includes all these things, not just security.</p></blockquote>
<p><strong>What are usually not changes to the IA Posture:</strong>Â </p>
<blockquote><p>Most NOTAM/IAVAS/TCNOs (such as Office patches, browser upgrades, ect)</p>
<p>Re-positioning equipment within the office (as long as the IAM has readable documentation on the data connections)</p>
<p>Adding passive periferal devices such as stand-alone printers, scanners and new monitors (devices with connectivityÂ to external sourcesÂ such as faxes, share external networkÂ printers shouldÂ go before theÂ DIACAPÂ Team)</p>
<p>Devices such as DVD, CD and hard drives with more capacity may notÂ affect the IA Posture but it is best toÂ have some formalized method of tracking upgrades to hardwareÂ Â especially on mission systems as some changes could have some unpredictable affects</p></blockquote>
<p><strong>Annual FISMA Reviews</strong></p>
<p>DIACAP includes the task of performing reviews annually on the system.Â  This is one ofÂ theÂ key features ofÂ the <a href="http://csrc.nist.gov/groups/SMA/fisma/index.html" title="FISMA">Federal Information System Management Act of 2002</a>.Â  What ever command or branch of the DoD you reside, your system has the potential of being audited annually to make sure it is in compliance with federal regulations.Â  The <a href="http://elamb.org/enterprise-mission-assurance-support-service-emass/" title="emass eitdr ditpr apms">eMASS</a> IT Portfolio management systems (EITDR, DITPR-DON, APMS) also has this feature intergrated into its key functions.Â Â All data on each systems IA postureÂ is collect annually.Â Â  This is done by the IAMs and/or the DIACAP Team.</p>
<p>Additionally, each system must be re-accredited every three years:</p>
<p><font size="3"></p>
<blockquote><p><em>6.3.4.4. Initiate Reaccreditation. In accordance with OMB Circular A-130 (Reference (s)), an IS must be recertified and reaccredited once every 3 years. The results of an annual review or a major change in the IA posture at any time may also indicate the need for recertification and reaccreditation of the IS.</em>Â  <strong>DoD 8510.01, 6.3.4.4</strong></p></blockquote>
<p></font><strong>From DoD 8510.01, DIACAP:</strong>Â </p>
<p>6.3.4.1.1. DoD ISs with a current ATO that are found to be operating in an unacceptable IA posture through GAO audits, IG DoD audits, or other reviews or events such as an annual security review or compliance validation shall have the newly identified weakness added to an existing or newly created IT Security POA&amp;M.</p>
<p>6.3.4.1.2. If a newly discovered CAT I weakness on a DoD IS operating with an ATO cannot be corrected within 30 days, the system can only continue operation under the terms prescribed in subparagraph 6.3.3.2.6.1.2.</p>
<p>6.3.4.1.3. If a newly discovered CAT II weakness on a DoD IS operating with a current ATO cannot be corrected or satisfactorily mitigated within 90 days, the system can only continue operation under the terms prescribed in subparagraph 6.3.3.2.6.2.5.</p>
<p>6.3.4.2. Maintain IA Posture. The IAM may recommend changes or improvement to the implementation of assigned IA controls, the assignment of additional IA controls, or changes or improvements to the design of the IS itself.</p>
<p>6.3.4.3. Perform Reviews. The IAM shall annually provide a written or DoD PKI-certified digitally signed statement to the DAA and the CA that indicates the results of the security review of all IA controls and the testing of selected IA controls as required by Reference (a). The review will either confirm the effectiveness of assigned IA controls and their implementation, or it will recommend: changes such as those described in subparagraph 6.3.4.2.; a change in accreditation status (e.g., accreditation status is downgraded to IATO or DATO); or development of an IT Security POA&amp;M. The CA and DAA shall review the IAM statement in light of mission and information environment indicators and determine a course of action that will be provided to the concerned CIO or SIAO for reporting requirements described in Reference (a). The date of the annual security review will be recorded in the SIP. A DAA may downgrade or revoke an accreditation decision at any time if risk conditions or concerns so warrant.</p>
<p>6.3.4.4. Initiate Reaccreditation. In accordance with OMB Circular A-130 (Reference (s)), an IS must be recertified and reaccredited once every 3 years. The results of an annual review or a major change in the IA posture at any time may also indicate the need for recertification and reaccreditation of the IS.</p>
<p></font><font size="2" face="Arial"></font></p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/diacap-activity-4-maintain-authorization-to-operate-and-conduct-review/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Register the System with DoD IA Component</title>
		<link>http://elamb.org/register-the-system-with-dod-ia-component/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=register-the-system-with-dod-ia-component</link>
		<comments>http://elamb.org/register-the-system-with-dod-ia-component/#comments</comments>
		<pubDate>Sun, 10 Feb 2008 06:42:55 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[EITDR]]></category>
		<category><![CDATA[DIACAP]]></category>
		<category><![CDATA[IT Lean]]></category>
		<category><![CDATA[sissu]]></category>

	<!-- AutoMeta Start -->
	<category></category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/register-the-system-with-dod-ia-component/</guid>
		<description><![CDATA[Register the System with DoD IA Component Each branch of the military has an IA component. Each of the US Armed Services have a division under their respective chief information officerâ€™s responsible for all computers, communications and networks in a &#8230; <a href="http://elamb.org/register-the-system-with-dod-ia-component/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><strong>Register the System with DoD IA Component </strong></p>
<p>Each branch of the military has an IA component.  Each of the US Armed Services have a division under their respective chief information officerâ€™s responsible for all computers, communications and networks in a given military branch. These communications divisions will house the Information Assurance component responsible for the DIACAP tasks.</p>
<p><strong><em>Table 1.  DoD IA Components</em></strong></p>
<table style="border: medium none ; border-collapse: collapse" class="MsoTableGrid" border="1" cellpadding="0" cellspacing="0">
<tr>
<td style="border: 1pt solid windowtext; padding: 0in 5.4pt; background: #e6e6e6 none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; width: 63.9pt" width="85"><strong><font size="3"><font face="Times New Roman">DoD Branch<o:p></o:p></font></font></strong></td>
<td style="border-style: solid solid solid none; border-color: windowtext windowtext windowtext #ece9d8; border-width: 1pt 1pt 1pt medium; padding: 0in 5.4pt; background: #e6e6e6 none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; width: 144.85pt" width="193"><strong><font size="3"><font face="Times New Roman">Branch Communication &amp; Information Service<o:p></o:p></font></font></strong></td>
<td style="border-style: solid solid solid none; border-color: windowtext windowtext windowtext #ece9d8; border-width: 1pt 1pt 1pt medium; padding: 0in 5.4pt; background: #e6e6e6 none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; width: 188.25pt" width="251"><font size="3"><font face="Times New Roman"><st1:place w:st="on"><st1:city w:st="on"><strong>Branch</strong></st1:city><strong> <st1:state w:st="on">IA</st1:state></strong></st1:place><strong> Component<o:p></o:p></strong></font></font></td>
</tr>
<tr>
<td style="border-style: none solid solid; border-color: #ece9d8 windowtext windowtext; border-width: medium 1pt 1pt; padding: 0in 5.4pt; width: 63.9pt; background-color: transparent" valign="top" width="85"><font size="3"><font face="Times New Roman">US Air Force<o:p></o:p></font></font></td>
<td style="border-style: none solid solid none; border-color: rgb(236, 233, 216) windowtext windowtext rgb(236, 233, 216); border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 144.85pt; background-color: transparent" valign="top" width="193"><font size="3"><font face="Times New Roman">Air Force Communication Agency (AFCA)<o:p></o:p></font></font><font size="3"><font face="Times New Roman">http://public.afca.af.mil/<o:p></o:p></font></font></td>
<td style="border-style: none solid solid none; border-color: rgb(236, 233, 216) windowtext windowtext rgb(236, 233, 216); border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 188.25pt; background-color: transparent" valign="top" width="251"><font size="3"><font face="Times New Roman">AFCA/EV<o:p></o:p></font></font><font size="3"><font face="Times New Roman">Assessment and Validators<o:p></o:p></font></font><font size="3"><font face="Times New Roman">http://public.afca.af.mil/library/<o:p></o:p></font></font></td>
</tr>
<tr>
<td style="border-style: none solid solid; border-color: #ece9d8 windowtext windowtext; border-width: medium 1pt 1pt; padding: 0in 5.4pt; width: 63.9pt; background-color: transparent" valign="top" width="85"><font size="3"><font face="Times New Roman">US Army <o:p></o:p></font></font></td>
<td style="border-style: none solid solid none; border-color: rgb(236, 233, 216) windowtext windowtext rgb(236, 233, 216); border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 144.85pt; background-color: transparent" valign="top" width="193"><font size="3"><font face="Times New Roman">*Army NETCOM 9<sup>th</sup> Signal Corps <o:p></o:p></font></font><font size="3"><font face="Times New Roman">http://www.netcom.army.mil/<o:p></o:p></font></font></td>
<td style="border-style: none solid solid none; border-color: rgb(236, 233, 216) windowtext windowtext rgb(236, 233, 216); border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 188.25pt; background-color: transparent" valign="top" width="251"><font size="3"><font face="Times New Roman">Army NETCOM Information Assurance Office<o:p></o:p></font></font></td>
</tr>
<tr>
<td style="border-style: none solid solid; border-color: #ece9d8 windowtext windowtext; border-width: medium 1pt 1pt; padding: 0in 5.4pt; width: 63.9pt; background-color: transparent" valign="top" width="85"><font size="3"><font face="Times New Roman">Department of the Navy<o:p></o:p></font></font></td>
<td style="border-style: none solid solid none; border-color: rgb(236, 233, 216) windowtext windowtext rgb(236, 233, 216); border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 144.85pt; background-color: transparent" valign="top" width="193"><font size="3"><font face="Times New Roman">DON CIO<o:p></o:p></font></font><font size="3"><font face="Times New Roman">DON Information Management and Information Technology (IM/IT)<o:p></o:p></font></font><font size="3"><font face="Times New Roman">http://www.doncio.navy.mil<o:p></o:p></font></font></td>
<td style="border-style: none solid solid none; border-color: rgb(236, 233, 216) windowtext windowtext rgb(236, 233, 216); border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 188.25pt; background-color: transparent" valign="top" width="251"><font size="3"><font face="Times New Roman">DON SIAO<o:p></o:p></font></font><font size="3"><font face="Times New Roman"><a href="http://www.doncio.navy.mil/Main.aspx">http://www.doncio.navy.mil/Main.aspx</a><o:p></o:p></font></font></td>
</tr>
</table>
<p><font face="Times New Roman">*more on <a href="http://findarticles.com/p/articles/mi_m0OBA/is_4_22/ai_n8704549/pg_2" title="Army Netcom">Army NETCOM</a></font></p>
<p>Its important to get registered as soon as possible, because the DIACAP process (as with any certification &amp; accreditation process) can take well over from six months to accomplish.</p>
<p><strong>Role of the IA Component </strong></p>
<p>Within the <a href="http://elamb.org/diacap-team/" title="DIACAP TEAM" target="_blank">DIACAP Team</a>, the IA Component&#8217;s role will likely be the &#8220;Certifying Authority&#8221; which is responsible for the final validation of security controls.  This role is powerful in that it will determine whether or not the system is certified.  The designated accreditation authority (DAA) listens the the recommendation of the CA.  If the CA validates, the DAA will accredit.  Also, the DAA can actually be within the IA Component, depending on the Mission Assurance Category (MAC) level (<em>ref: USAF IT Lean/SISSU guidelines, this may differ within Army &amp; DON</em>).</p>
<p><strong>IA Component&#8217;s IT Portfolio</strong></p>
<p>DoD IT portfolio management (DoDD 8115.01) requires that each of the branches report to the DoD the status of IT systems.Â  Each branches IA Component has a Enterprise Mission Assurance Support Service (eMASS).Â  You will likely be tasked with entering your system into that database.Â  This is what is essentially meant by register the system with the DoD IA Component.</p>
<p>More on <a href="http://elamb.org/enterprise-mission-assurance-support-service-emass/" title="eMASS &amp; IT Portfolio" target="_blank">DoD IT portfolio management &amp; eMASS</a></p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/register-the-system-with-dod-ia-component/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

