<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: DISA IA Boot Camp (June 2007)</title>
	<atom:link href="http://elamb.org/disa-ia-boot-camp/feed/" rel="self" type="application/rss+xml" />
	<link>http://elamb.org/disa-ia-boot-camp/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=disa-ia-boot-camp</link>
	<description>information system security, risk management, scam research</description>
	<lastBuildDate>Sun, 27 Nov 2011 07:30:02 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Ben Braswell</title>
		<link>http://elamb.org/disa-ia-boot-camp/comment-page-1/#comment-99417</link>
		<dc:creator>Ben Braswell</dc:creator>
		<pubDate>Fri, 16 May 2008 18:05:19 +0000</pubDate>
		<guid isPermaLink="false">http://elamb.org/disa-ia-boot-camp/#comment-99417</guid>
		<description>Having not utilized the previous DITSCAP process the DIACAP process appears to be a good device to bring all the necessary documentation together so it does corelate with all the other processes used for maintaining certifications.  Guess I&#039;m not confussed by all the previous methods.
 
    Not to worry, having a military background lets me know this will all change again in a couple of years and then I be lost like everone else.
Cheers!</description>
		<content:encoded><![CDATA[<p>Having not utilized the previous DITSCAP process the DIACAP process appears to be a good device to bring all the necessary documentation together so it does corelate with all the other processes used for maintaining certifications.  Guess I&#8217;m not confussed by all the previous methods.</p>
<p>    Not to worry, having a military background lets me know this will all change again in a couple of years and then I be lost like everone else.<br />
Cheers!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: swisner</title>
		<link>http://elamb.org/disa-ia-boot-camp/comment-page-1/#comment-11148</link>
		<dc:creator>swisner</dc:creator>
		<pubDate>Thu, 02 Aug 2007 15:43:07 +0000</pubDate>
		<guid isPermaLink="false">http://elamb.org/disa-ia-boot-camp/#comment-11148</guid>
		<description>I have looked on both the DISA and IASE websites and can&#039;t find any information on this course.  Do you have a web link or POC for it?  Thank you.  

The problem with DIACAP is that, while its lofty goals of weaving security through the enterprise, embedding it into the planning and development of our systems, and cutting out much of the fluff from the SSAA were truly overdue, the implementation of the DIACAP has been an absolute mess (at least from the ground level view).  That is if you call putting DIACAP into effect, publishing some token documents and hosting the &quot;figure it out amongst yourselves&quot; forum on the DIACAP portal an implementation plan.  With DITSCAP, I actually had more control over making my C&amp;A package a true representation of my system.  Now, because the Air Force has rolled up its Clinger-Cohen, FISMA, DIACAP IT Lean and countless other requirements into a single database, I have to repeatedly enter the same information about my system in different sections of the same database, despite the fact that most of the items being asked about do not apply to my system.  SPAWAR had an good transition concept that combined the SIP and the new controls/RTM and DIACAP-relevant sections of the old SSAA.  This may not have worked for an enterprise system but for a relatively simple system like the one I have, I could have directed my efforts to improving the documentation and applying more security to the system rather than filling out an endless series of &quot;not applicable&quot;.</description>
		<content:encoded><![CDATA[<p>I have looked on both the DISA and IASE websites and can&#8217;t find any information on this course.  Do you have a web link or POC for it?  Thank you.  </p>
<p>The problem with DIACAP is that, while its lofty goals of weaving security through the enterprise, embedding it into the planning and development of our systems, and cutting out much of the fluff from the SSAA were truly overdue, the implementation of the DIACAP has been an absolute mess (at least from the ground level view).  That is if you call putting DIACAP into effect, publishing some token documents and hosting the &#8220;figure it out amongst yourselves&#8221; forum on the DIACAP portal an implementation plan.  With DITSCAP, I actually had more control over making my C&amp;A package a true representation of my system.  Now, because the Air Force has rolled up its Clinger-Cohen, FISMA, DIACAP IT Lean and countless other requirements into a single database, I have to repeatedly enter the same information about my system in different sections of the same database, despite the fact that most of the items being asked about do not apply to my system.  SPAWAR had an good transition concept that combined the SIP and the new controls/RTM and DIACAP-relevant sections of the old SSAA.  This may not have worked for an enterprise system but for a relatively simple system like the one I have, I could have directed my efforts to improving the documentation and applying more security to the system rather than filling out an endless series of &#8220;not applicable&#8221;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rybolov</title>
		<link>http://elamb.org/disa-ia-boot-camp/comment-page-1/#comment-270</link>
		<dc:creator>rybolov</dc:creator>
		<pubDate>Tue, 19 Jun 2007 13:49:58 +0000</pubDate>
		<guid isPermaLink="false">http://elamb.org/disa-ia-boot-camp/#comment-270</guid>
		<description>Ah, but if you have polyinstantiation of data, then you play the cut-n-paste game.

It also duplicates some effort.  If you change the DIACAP part, then you have to change the various pieces of the SSAA.  Polyinstantiation means that you have started to write spaghetti code in the version of a security controls document.

Trick here is that you *can* use a requirements traceability matrix as your SSAA/SSP/$foo and that&#039;s what the overall trend is going to.  Hopefully the free-form text documents are on their way to an early grave. =)

Knowing IGs, they don&#039;t like it because the presentation layer of the policy stack needs to be in a format that they are used to.  In the long run, it&#039;s easier to give them what they want than it is to educate them.

Knowing IA, all I really want is a brief description of the controls and where I can go for more information if I have a question.</description>
		<content:encoded><![CDATA[<p>Ah, but if you have polyinstantiation of data, then you play the cut-n-paste game.</p>
<p>It also duplicates some effort.  If you change the DIACAP part, then you have to change the various pieces of the SSAA.  Polyinstantiation means that you have started to write spaghetti code in the version of a security controls document.</p>
<p>Trick here is that you *can* use a requirements traceability matrix as your SSAA/SSP/$foo and that&#8217;s what the overall trend is going to.  Hopefully the free-form text documents are on their way to an early grave. =)</p>
<p>Knowing IGs, they don&#8217;t like it because the presentation layer of the policy stack needs to be in a format that they are used to.  In the long run, it&#8217;s easier to give them what they want than it is to educate them.</p>
<p>Knowing IA, all I really want is a brief description of the controls and where I can go for more information if I have a question.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: elamb.security</title>
		<link>http://elamb.org/disa-ia-boot-camp/comment-page-1/#comment-264</link>
		<dc:creator>elamb.security</dc:creator>
		<pubDate>Tue, 19 Jun 2007 13:35:02 +0000</pubDate>
		<guid isPermaLink="false">http://elamb.org/disa-ia-boot-camp/#comment-264</guid>
		<description>Cut &amp; Paste?  

I don&#039;t know how your process works but,  C &amp; A packages are a lot of travel and work for me.  We are currently in limbo on the use of DIACAP and DITSCAP.   Paperwork wise, the only thing the DIACAP adds is a stripped down version of the SSAA.  The cool thing about it is that it is all supposed to be online.  So its the DITSCAP online (digital DITSCAP).</description>
		<content:encoded><![CDATA[<p>Cut &#038; Paste?  </p>
<p>I don&#8217;t know how your process works but,  C &#038; A packages are a lot of travel and work for me.  We are currently in limbo on the use of DIACAP and DITSCAP.   Paperwork wise, the only thing the DIACAP adds is a stripped down version of the SSAA.  The cool thing about it is that it is all supposed to be online.  So its the DITSCAP online (digital DITSCAP).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rybolov</title>
		<link>http://elamb.org/disa-ia-boot-camp/comment-page-1/#comment-148</link>
		<dc:creator>rybolov</dc:creator>
		<pubDate>Mon, 18 Jun 2007 20:19:21 +0000</pubDate>
		<guid isPermaLink="false">http://elamb.org/disa-ia-boot-camp/#comment-148</guid>
		<description>Doing a SSAA as an attachment to the DIACAP package?  How much extra cut-n-paste with no value added and at a large cost to the taxpayers can we produce?</description>
		<content:encoded><![CDATA[<p>Doing a SSAA as an attachment to the DIACAP package?  How much extra cut-n-paste with no value added and at a large cost to the taxpayers can we produce?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

