<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>elamb &#187; sissu</title>
	<atom:link href="http://elamb.org/category/sissu/feed/" rel="self" type="application/rss+xml" />
	<link>http://elamb.org</link>
	<description>information system security, risk management, scam research</description>
	<lastBuildDate>Mon, 28 Nov 2011 02:27:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>DIACAP Essentials + IA Control Validation Training (part 4): DIACAP/AFCAP Day 4 &amp; 5</title>
		<link>http://elamb.org/diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day-4-5/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day-4-5</link>
		<comments>http://elamb.org/diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day-4-5/#comments</comments>
		<pubDate>Fri, 03 Jul 2009 05:21:11 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[Assurance/DITSCAP]]></category>
		<category><![CDATA[Assurance/Netcentric]]></category>
		<category><![CDATA[Assurance/SSAA]]></category>
		<category><![CDATA[EITDR]]></category>
		<category><![CDATA[emass]]></category>
		<category><![CDATA[FISMA]]></category>
		<category><![CDATA[information assurance]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sissu]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1744</guid>
		<description><![CDATA[Days 4 &#038; 5 bring the DIACAP/AFCAP Essentials Class to a close. The biggest things I learned were: CNSSI 4009 is the the official glossary of DOD IA, there is a big difference between theory, policy and practice, Agents of &#8230; <a href="http://elamb.org/diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day-4-5/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Days 4 &#038; 5 bring the DIACAP/AFCAP Essentials Class to a close.  The<br />
biggest things I learned were:  CNSSI 4009 is the the official glossary of DOD IA, there is a big difference between theory, policy and practice, Agents of the Certifying Authority (ACA) are official validators and there is a difference between acquisition Mission criticality and IA MAC levels.   </p>
<p><strong>Stuff I learned from people in the class:</strong></p>
<blockquote><p>-AFCA is changing its name (to what?)</p>
<p>DOD is going to put the new IA controls in NCSSI 12-53 (currently in draft)</p>
<p>-a lot of what I need in there is in NIST 800-53</p>
<p>Marines use something called Exacta</p>
<p>Site called securitycritics.org</p>
<p>33-202 is now completely irrelevant and obsolete (not even mentioned ONCE in the class)</p>
<p>800-30</p>
<p>Feds call Certification &#038;Accreditation (C&#038;A) â€œSecurity authorizationâ€ </p>
<p>NIST SP 800-37</p></blockquote>
<p><strong>Day 4:</strong></p>
<blockquote><p>Validator Activities &#038; Issue Accreditation Decision</p>
<p>Prepare POA&#038;M</p>
<p>Validate Results/Scorecard</p>
<p>Scorecard</p>
<p>Make certification determination</p>
<p>CA/DAA Package review </p></blockquote>
<p><strong>Day 5:</strong></p>
<blockquote><p>Validation procedures were discussed.  On day five, we looked at how the validators look at a system.</p>
<p>I thought is was interesting.  It should help me get through the EITDR/DIACAP process easier.</p>
<p>Maintain Situational Awareness</p>
<p>Maintain IA Posture</p>
<p>Conduct Review</p>
<p>R-Accreditation</p>
<p>Retire system </p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day-4-5/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DIACAP Essentials + IA Control Validation Training (part 4): DIACAP/AFCAP Day3</title>
		<link>http://elamb.org/diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day3/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day3</link>
		<comments>http://elamb.org/diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day3/#comments</comments>
		<pubDate>Fri, 03 Jul 2009 04:37:14 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[Assurance/DITSCAP]]></category>
		<category><![CDATA[Assurance/Netcentric]]></category>
		<category><![CDATA[Assurance/SSAA]]></category>
		<category><![CDATA[EITDR]]></category>
		<category><![CDATA[FISMA]]></category>
		<category><![CDATA[information assurance]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[sissu]]></category>
		<category><![CDATA[DIACAP]]></category>
		<category><![CDATA[DIACAP Team]]></category>
		<category><![CDATA[ditpr]]></category>
		<category><![CDATA[dod]]></category>
		<category><![CDATA[emass]]></category>
		<category><![CDATA[IA]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1736</guid>
		<description><![CDATA[Day 3 heats up a little. We start talking about what it take to actually get validated. The DIACAP Implementers Guide &#038; the DIACAP Validators guide is opened up and reviewed. I think we all learned a little something during &#8230; <a href="http://elamb.org/diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day3/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Day 3 heats up a little.  We start talking about what it take to actually get validated.  The DIACAP Implementers Guide &#038; the DIACAP Validators guide is opened up and reviewed.  I think we all learned a little something during this discussion because there have been some challenges with this.  Unfortunately, we don&#8217;t to far into the validator stuff.</p>
<p><strong>Day 3:</strong>  </p>
<blockquote><p>DIACAP Structure</p>
<p>Terminology Review</p>
<p>Assemble DIACAP Team</p>
<p>Registered System/System Information Profile</p>
<p>Assign IA Controls</p>
<p>Initiate DIACAP Implementation Plan </p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security, Interoperability, Supportability, Sustainability and Usability (SISSU)</title>
		<link>http://elamb.org/security-interoperability-supportability-sustainability-and-usability-sissu/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=security-interoperability-supportability-sustainability-and-usability-sissu</link>
		<comments>http://elamb.org/security-interoperability-supportability-sustainability-and-usability-sissu/#comments</comments>
		<pubDate>Tue, 05 Feb 2008 20:14:15 +0000</pubDate>
		<dc:creator>elamb</dc:creator>
				<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[EITDR]]></category>
		<category><![CDATA[sissu]]></category>
		<category><![CDATA[AFCA]]></category>
		<category><![CDATA[Air Force]]></category>
		<category><![CDATA[IA]]></category>

	<!-- AutoMeta Start -->
	<category>sissu</category>
	<category>sustainability</category>
	<category>interoperability</category>
	<category>supportability</category>
	<category>usability</category>
	<category>considered</category>
	<category>controls</category>
	<category>â œstakeholders</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/security-interoperability-supportability-sustainability-and-usability-sissu/</guid>
		<description><![CDATA[Â  The Security, Interoperability, Supportability, Sustainability and Usability (SISSU) is considered a part of the USAF IT LEAN process.Â  SISSU is a comprehensive database of security controls (IA Controls) addressed in DoDI 8500.02 needed to complete the DIACAP process.Â  Â  &#8230; <a href="http://elamb.org/security-interoperability-supportability-sustainability-and-usability-sissu/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><o:p><font face="Times New Roman">Â </font></o:p></p>
<p style="margin: 0in 0in 0pt" class="MsoNormal"><font face="Times New Roman">The Security, Interoperability, Supportability, Sustainability and Usability (SISSU) is considered a part of the USAF IT LEAN process.<span>Â  </span>SISSU is a comprehensive database of security controls (IA Controls) addressed in DoDI 8500.02 needed to complete the DIACAP process.<span>Â  </span></font></p>
<p><o:p><font face="Times New Roman">Â </font></o:p></p>
<p style="margin: 0in 0in 0pt" class="MsoNormal"><font face="Times New Roman">The SISSU questions includes everything from documentation of the system to physical security, to network security.<span>Â  </span>To access the SISSU process in the EITDR one need an account and â€œstakeholders listâ€ approval via AFCA/EV.</font></p>
<p style="margin: 0in 0in 0pt" class="MsoNormal">&nbsp;</p>
<p style="margin: 0in 0in 0pt" class="MsoNormal"><font face="Times New Roman">Security, Interoperability, Supportability, Sustainability and Usability are each considered disciplines.Â  Each discipline is assigned a set of roles: producer, reviewer, validator, and approver.Â  Once all of these roles have done their part on each of their applicable questions inÂ a given discipline they can move on to the next phase.Â  The phases are Define Need, Design, Build &amp; Test, and Release.</font></p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/security-interoperability-supportability-sustainability-and-usability-sissu/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

