<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>elamb &#187; emass</title>
	<atom:link href="http://elamb.org/category/emass/feed/" rel="self" type="application/rss+xml" />
	<link>http://elamb.org</link>
	<description>information system security, risk management, scam research</description>
	<lastBuildDate>Mon, 28 Nov 2011 02:27:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>DIACAP Essentials + IA Control Validation Training (part 4): DIACAP/AFCAP Day 4 &amp; 5</title>
		<link>http://elamb.org/diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day-4-5/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day-4-5</link>
		<comments>http://elamb.org/diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day-4-5/#comments</comments>
		<pubDate>Fri, 03 Jul 2009 05:21:11 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[Assurance/DITSCAP]]></category>
		<category><![CDATA[Assurance/Netcentric]]></category>
		<category><![CDATA[Assurance/SSAA]]></category>
		<category><![CDATA[EITDR]]></category>
		<category><![CDATA[emass]]></category>
		<category><![CDATA[FISMA]]></category>
		<category><![CDATA[information assurance]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sissu]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1744</guid>
		<description><![CDATA[Days 4 &#038; 5 bring the DIACAP/AFCAP Essentials Class to a close. The biggest things I learned were: CNSSI 4009 is the the official glossary of DOD IA, there is a big difference between theory, policy and practice, Agents of &#8230; <a href="http://elamb.org/diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day-4-5/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Days 4 &#038; 5 bring the DIACAP/AFCAP Essentials Class to a close.  The<br />
biggest things I learned were:  CNSSI 4009 is the the official glossary of DOD IA, there is a big difference between theory, policy and practice, Agents of the Certifying Authority (ACA) are official validators and there is a difference between acquisition Mission criticality and IA MAC levels.   </p>
<p><strong>Stuff I learned from people in the class:</strong></p>
<blockquote><p>-AFCA is changing its name (to what?)</p>
<p>DOD is going to put the new IA controls in NCSSI 12-53 (currently in draft)</p>
<p>-a lot of what I need in there is in NIST 800-53</p>
<p>Marines use something called Exacta</p>
<p>Site called securitycritics.org</p>
<p>33-202 is now completely irrelevant and obsolete (not even mentioned ONCE in the class)</p>
<p>800-30</p>
<p>Feds call Certification &#038;Accreditation (C&#038;A) â€œSecurity authorizationâ€ </p>
<p>NIST SP 800-37</p></blockquote>
<p><strong>Day 4:</strong></p>
<blockquote><p>Validator Activities &#038; Issue Accreditation Decision</p>
<p>Prepare POA&#038;M</p>
<p>Validate Results/Scorecard</p>
<p>Scorecard</p>
<p>Make certification determination</p>
<p>CA/DAA Package review </p></blockquote>
<p><strong>Day 5:</strong></p>
<blockquote><p>Validation procedures were discussed.  On day five, we looked at how the validators look at a system.</p>
<p>I thought is was interesting.  It should help me get through the EITDR/DIACAP process easier.</p>
<p>Maintain Situational Awareness</p>
<p>Maintain IA Posture</p>
<p>Conduct Review</p>
<p>R-Accreditation</p>
<p>Retire system </p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day-4-5/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Enterprise Mission Assurance Support Service (eMASS)</title>
		<link>http://elamb.org/enterprise-mission-assurance-support-service-emass/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=enterprise-mission-assurance-support-service-emass</link>
		<comments>http://elamb.org/enterprise-mission-assurance-support-service-emass/#comments</comments>
		<pubDate>Sun, 03 Feb 2008 06:23:36 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[apms]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[ditpr]]></category>
		<category><![CDATA[EITDR]]></category>
		<category><![CDATA[emass]]></category>
		<category><![CDATA[dadms]]></category>
		<category><![CDATA[it portfolio]]></category>

	<!-- AutoMeta Start -->
	<category>dated</category>
	<category>ditpr</category>
	<category>dodd</category>
	<category>portfolio</category>
	<category>emass</category>
	<category>mil</category>
	<category>module</category>
	<category>8570</category>
	<category>dated</category>
	<category>ditpr</category>
	<category>dodd</category>
	<category>portfolio</category>
	<category>emass</category>
	<category>mil</category>
	<category>module</category>
	<category>8570</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/enterprise-mission-assurance-support-service-emass/</guid>
		<description><![CDATA[EMASS **30 Aug 11 Update to eMASS info. Previous information mixed eMass with IT Portfolio Management systems. There was a lot of confusion about eMASS due to is very late release following the official publication of DoDI 8510, DIACAP** eMASS &#8230; <a href="http://elamb.org/enterprise-mission-assurance-support-service-emass/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<h1>EMASS</h1>
<p>**30 Aug 11 Update to eMASS info.  Previous information mixed eMass with IT Portfolio Management systems.  There was a lot of confusion about eMASS due to is very late release following the official publication of DoDI 8510, DIACAP**</p>
<p>eMASS is a database managed by the DoD created to store, track and manage the activities of the Certification &#038; Accreditation process (and/or risk management framework steps).  The database is managed on the NIPR &#038; SIPR.  For more information refer to:<br />
<span class="ms-announcementtitle"><span class="ms-announcementtitle"><span class="ms-announcementtitle"><span class="ms-announcementtitle"><a href="http://iase.disa.mil/">Information Assurance Support Environment (IASE)</a></span></span></span></span></p>
<h2>eMASS vs. IT Portolio Management Systems</h2>
<p>eMASS should not be confused with IT Portfolio management system addressed in <a href="http://www.dtic.mil/whs/directives/corres/html/811501.htm">DoDD 8115.01, &#8220;Information Technology Portfolio Management&#8221;</a>:</p>
<p><strong><a href="http://elamb.org/eitdr-enterprise-information-technology-data-repository/" title="eitdr" target="_blank">USAF Enterprise Information Technology Data Repository (EITDR)</a></strong></p>
<p><strong>Department of NAVY DADMS/DITPR-DON</strong></p>
<p>The DON CIO provides guidance on registration requirements for the DON Application and Database Management System (DADMS) and DoD IT Portfolio Registry (DITPR)-DON, which replaced the DON IT Registry. DITPR-DON is the single, authoritative source for data regarding DON IT systems, including National Security Systems. Registration of mission-critical, mission-essential and mission-support systems in DITPR-DON is central to establishing an accurate and reliable enterprise-wide inventory. Additionally, DITPR-DON is used to satisfy statutory and management reporting requirements, including Federal Information Security Management Act reporting and the Business Management Modernization Program certification process.</p>
<p>&#8211; <a href="http://www.doncio.navy.mil/TagResults.aspx?ID=22">http://www.doncio.navy.mil/TagResults.aspx?ID=22</a></p>
<p><strong>Army Portfolio Management Solution</strong></p>
<p>The The Army Portfolio Management Solution (APMS) is the Army&#8217;s system has four major modules: IT registration module, Domain Certification module, Capital Planning &amp; Investment Mgt IT Prioritization Module and Capital Planning Investment Control IT Budget Reporting Module</p>
<p><del datetime="2011-08-31T02:27:00+00:00">All the databases do essentially the same thing.  For the purpose of DIACAP, the Information Technology registration and IA certification components are the most important.</p>
<p align="center"><strong>References:</strong></p>
<p><span class="ms-announcementtitle"><a href="http://www.dtic.mil/whs/directives/corres/html/520001.htm">DoD Regulation 5200.1-R , â€œDoD Information Security Program,â€ January 1997</a></span><br />
</del><br />
<span class="ms-announcementtitle"><a href="http://www.dtic.mil/whs/directives/corres/html/811501.htm">DoDD 8115.01, &#8220;Information Technology Portfolio Management&#8221;, dated October 10, 2005</a></span></p>
<p><span class="ms-announcementtitle"><a href="http://www.dtic.mil/whs/directives/corres/pdf/850001p.pdf">DoDD 8500.01E, &#8220;Information Assurance (IA),&#8221; dated April 23, 2007</a></span></p>
<p><span class="ms-announcementtitle"><a href="https://ia.gordon.army.mil/docs/85101m.pdf" title="DITSCAP, DOD 8510.1-M">DoD 8510.1-M, â€œDoD Information Technology Security Certification and Accreditation Process (DITSCAP) Application Documentâ€, dated July 31, 2000</a></span></p>
<p><span class="ms-announcementtitle"><span class="ms-announcementtitle"><span class="ms-announcementtitle"><span class="ms-announcementtitle">DoDI 8551.1, &#8220;Ports, Protocols, and Services Management (PPSM) Release 6.9,&#8221; dated September, 2007</span></span></span></span></p>
<p><span class="ms-announcementtitle"><span class="ms-announcementtitle"><a href="http://www.dtic.mil/whs/directives/corres/pdf/857001p.pdf" title="8570 IA Training Certification Workforce Management">DoDD 8570.1, &#8220;Information Assurance Training, Certification, and Workforce Management,&#8221; dated August 15, 2004</a></span></span></p>
<p><span class="ms-announcementtitle"><span class="ms-announcementtitle"><span class="ms-announcementtitle"><a href="http://www.dtic.mil/whs/directives/corres/html/857001m.htm">DoDI 8570.1-M â€œInformation Assurance Workforce Improvement Program,â€ dated December 19, 2005</a></span></span></span></p>
<p><span class="ms-announcementtitle"><span class="ms-announcementtitle"><a href="http://biotech.law.lsu.edu/blaw/dodd/corres/memos/itpm.pdf" title="IT Portfolio Management">Deputy Secretary of Defense Memorandum, â€œInformation Technology Portfolio Management,â€ March 22, 2004</a></span></span></p>
<p><span class="ms-announcementtitle"><span class="ms-announcementtitle"><span class="ms-announcementtitle"><a href="http://csrc.nist.gov/drivers/documents/FISMA-final.pdf">Federal Information Security Management Act (FISMA) (2002)</a></span></span></span></p>
<p><span class="ms-announcementtitle"><span class="ms-announcementtitle"><span class="ms-announcementtitle"><span class="ms-announcementtitle"><a href="http://iase.disa.mil/">Information Assurance Support Environment (IASE)</a></span></span></span></span></p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/enterprise-mission-assurance-support-service-emass/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
	</channel>
</rss>

