<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>security blog &#187; Assurance/DIACAP</title>
	<atom:link href="http://elamb.org/category/assurancediacap/feed/" rel="self" type="application/rss+xml" />
	<link>http://elamb.org</link>
	<description>don&#039;t be sheeple</description>
	<lastBuildDate>Mon, 22 Feb 2010 08:45:44 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.3</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>UPDATED IA STUFF + Procrastination</title>
		<link>http://elamb.org/updated-ia-stuff-procrastination/</link>
		<comments>http://elamb.org/updated-ia-stuff-procrastination/#comments</comments>
		<pubDate>Wed, 27 Jan 2010 07:13:40 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[Assurance/SSAA]]></category>
		<category><![CDATA[EITDR]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[blogger]]></category>
		<category><![CDATA[blogging]]></category>
		<category><![CDATA[information assurance]]></category>
		<category><![CDATA[security experts]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=2203</guid>
		<description><![CDATA[My greatest skill is procrastination.  I really am the best, most skilled procrastinator I know. It takes all of my will power to stay consistent with anything, including this blog, which is why (among other things) I am not banking like Darren Rowse or Steve Pav, two of my favorite bloggers.
YOU SEE, I am [...]]]></description>
			<content:encoded><![CDATA[<p><strong>My greatest skill is procrastination.  I really am the best, most skilled procrastinator I know. </strong>It takes all of my will power to stay consistent with anything, including this blog, which is why (among other things) I am not banking like <a href="http://problogger.net">Darren Rowse</a> or <a href="www.stevepavlina.com">Steve Pav</a>, two of my favorite bloggers.</p>
<p><strong>YOU SEE</strong>, I am such a good procrastinator that <strong>JUST</strong> procrastinated on getting to the REAL subject of this article, security, IA updates.</p>
<p>A fellow IA Analyst wrote me with questions that got right to the heart of IA, <em>change</em>.  </p>
<p><strong>She asked about AFI 33-202.</strong><br />
And I said:</p>
<blockquote><p>Right as I felt I had mastered the contents of 33-202, the airforce moved to 33-210 (to replace all its C&#038;A stuff).  I believe 33-202 is now obsolete and replaced with 33-200 &#038; 33-202 and others.. last time I was with the AF, anyway.</p></blockquote>
<p><strong>What about IT LEAN?</strong><br />
I said:</p>
<blockquote><p>As for IT Lean, you can find that on AF Knowledge Now site and I think they have links to it on EITDR.  If you are interested in IT Lean you&#8217;ll be REALLY interested in 33-210:<br />
<a href="http://cryptome.quintessenz.at/mirror/dodi/AFI33-210.pdf">33-210</a>
</p></blockquote>
<p>But if you are working with the Air Force and want more on the IT LEAN process you should be digging into  AFCAP, Air Force Certification &#038; Accreditation Program, an AF version of IT Lean.</p>
<p><strong>CNSS 1253:</strong><br />
A lot of people also ask me to send them a copy of the CNSSI 12-53.  But it is actually OUT.  Its the <a href="http://www.cnss.gov/Assets/pdf/CNSSI-1253.pdf">CNSSI 1253</a>.  I, personally, have not had any clear direction (currently NO direction) on how to start moving some of the CNSSI to the systems I work on.  I suspect that the Govt. will start this within the next couple of years and start phasing out DIACAP.. but who the hell knows what a bureaucracy of their size will do next!</p>
<p>Lastly, my fellow IA Analyst asked me about EITDR<br />
and I said:</p>
<blockquote><p>You&#8217;ll find the EITDR POCs on the Air Force Portal or Knowledge Now.  Log on to the Air Force Portal (if you don&#8217;t have an account get one.. you may have to get sponsor by the Govt to get it).  Once on the AF Portal search for EITDR and they&#8217;ll have tons of stuff on it.  Waaaaay more stuff than you want to read.  You&#8217;ll also find the person you need to start the EITDR process with.</p></blockquote>
<img src="http://elamb.org/?ak_action=api_record_view&id=2203&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://elamb.org/updated-ia-stuff-procrastination/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>SRR Findings to IA Controls</title>
		<link>http://elamb.org/srr-findings-to-ia-controls/</link>
		<comments>http://elamb.org/srr-findings-to-ia-controls/#comments</comments>
		<pubDate>Sat, 08 Aug 2009 06:10:19 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[Assurance/DITSCAP]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[DIACAP]]></category>
		<category><![CDATA[dod]]></category>
		<category><![CDATA[IA]]></category>
		<category><![CDATA[ia controls]]></category>
		<category><![CDATA[poam]]></category>
		<category><![CDATA[srr]]></category>
		<category><![CDATA[STIG]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1814</guid>
		<description><![CDATA[From Reader:
 I stumbled upon your site and am new to security working for a contractor.  I’m attempting to complete a DIACAP POA&#038;M and need to map SRR findings to IA controls – any idea where I might find this information?
The SRR finding reference the DOD Unix STIG and NIPR STIG.  It doesn&#8217;t [...]]]></description>
			<content:encoded><![CDATA[<p>From Reader:</p>
<blockquote><p> I stumbled upon your site and am new to security working for a contractor.  I’m attempting to complete a DIACAP POA&#038;M and need to map SRR findings to IA controls – any idea where I might find this information?</p></blockquote>
<p>The SRR finding reference the DOD Unix STIG <del datetime="2009-11-05T06:51:12+00:00">and NIPR STIG</del>.  It doesn&#8217;t seem to completely match up the the DIACAP IA Controls, but that is where a good system security engineer/ IA analyst comes in.  </p>
<p>Once you&#8217;ve got your SRR results, IA Control compliance and mitigation depends on your situation.  There are a few that map directly (like Screen Saver) but most of the SRR findings will fall under one or two of the IA Controls.</p>
<p>Hope this helps.</p>
<img src="http://elamb.org/?ak_action=api_record_view&id=1814&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://elamb.org/srr-findings-to-ia-controls/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>CNSSI 12-53: New Security Control Catalog for National Security Systems</title>
		<link>http://elamb.org/cnssi-12-53-new-security-control-catalog-for-national-security-systems/</link>
		<comments>http://elamb.org/cnssi-12-53-new-security-control-catalog-for-national-security-systems/#comments</comments>
		<pubDate>Fri, 03 Jul 2009 05:39:49 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[Assurance/DITSCAP]]></category>
		<category><![CDATA[Assurance/Netcentric]]></category>
		<category><![CDATA[Assurance/SSAA]]></category>
		<category><![CDATA[EITDR]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[security]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1746</guid>
		<description><![CDATA[New DIACAP Certification &#038; Accreditation IA Controls
The DoD has had the same IA controls since DoD 8510.1-M, controls since DoD 8510.1-M, Department of Defense Information Technology System Certification &#038; Accreditation Process (DITSCAP), July 31, 2000 – it was developed late last century.
The DoD has a total of 157 IA controls spread across 8 subject areas [...]]]></description>
			<content:encoded><![CDATA[<p><strong>New DIACAP Certification &#038; Accreditation IA Controls</strong></p>
<p>The DoD has had the same IA controls since DoD 8510.1-M, controls since DoD 8510.1-M, Department of Defense Information Technology System Certification &#038; Accreditation Process (DITSCAP), July 31, 2000 <em>– it was developed late last century.</em></p>
<p><strong>The DoD has a total of 157 IA controls spread across 8 subject areas in 4 classes:</strong></p>
<blockquote><p>
DC – Security Design &#038; Configuration</p>
<p>IA – Identification and Authentication</p>
<p>EC – Enclave &#038; Computing</p>
<p>EB – Enclave Boundary Defense</p>
<p>PE – Physical &#038; Environmental</p>
<p>PR – Personnel</p>
<p>CO – Continuity</p>
<p>VI – Vulnerability </p></blockquote>
<p>There is a huge change coming in certification &#038; accreditation for the DoD coming.  The IA controls are being expanded and changed.  The last two DIACAP classes I’ve been to mentioned that there is a big change coming.  Essentially, all the IA Controls (security controls, safeguards, countermeasures.. whatever your organization is calling them) are getting expanded.  All federal organizations will have security controls that look more like what is in the National Institute of Standards and Technology Special Publication 800-53.  This is all being placed in the Committee on National Security Systems Instruction (CNSSI) 1253.  As of 25 June 2009, the CNSSI 1253 is still in draft. </p>
<p>The draft has 17 families &#038; identifiers in three security control classes.  </p>
<p>TABLE 1: SECURITY CONTROL CLASSES, FAMILIES, AND IDENTIFIERS<br />
IDENTIFIER FAMILY CLASS</p>
<blockquote><p>AC Access Control Technical</p>
<p>AT Awareness and Training Operational</p>
<p>AU Audit and Accountability Technical</p>
<p>CA Certification, Accreditation, and Security Assessments Management</p>
<p>CM Configuration Management Operational</p>
<p>CP Contingency Planning Operational</p>
<p>IA Identification and Authentication Technical</p>
<p>IR Incident Response Operational</p>
<p>MA Maintenance Operational</p>
<p>MP Media Protection Operational</p>
<p>PE Physical and Environmental Protection Operational</p>
<p>PL Planning Management</p>
<p>PS Personnel Security Operational</p>
<p>RA Risk Assessment Management</p>
<p>SA System and Services Acquisition Management</p>
<p>SC System and Communications Protection Technical</p></blockquote>
<p>The CNSSI has about 500 controls with pretty good granularity.  </p>
<p>One of the really cool thing about 1253 was the security control mapping.  It’s a table that matches up 800-53, DCID 6/3 and DODI 8500.2.</p>
<img src="http://elamb.org/?ak_action=api_record_view&id=1746&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://elamb.org/cnssi-12-53-new-security-control-catalog-for-national-security-systems/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>DIACAP Essentials + IA Control Validation Training (part 4): DIACAP/AFCAP Day 4 &amp; 5</title>
		<link>http://elamb.org/diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day-4-5/</link>
		<comments>http://elamb.org/diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day-4-5/#comments</comments>
		<pubDate>Fri, 03 Jul 2009 05:21:11 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[Assurance/DITSCAP]]></category>
		<category><![CDATA[Assurance/Netcentric]]></category>
		<category><![CDATA[Assurance/SSAA]]></category>
		<category><![CDATA[EITDR]]></category>
		<category><![CDATA[FISMA]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[emass]]></category>
		<category><![CDATA[information assurance]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sissu]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1744</guid>
		<description><![CDATA[Days 4 &#038; 5 bring the DIACAP/AFCAP Essentials Class to a close.  The
biggest things I learned were:  CNSSI 4009 is the the official glossary of DOD IA, there is a big difference between theory, policy and practice, Agents of the Certifying Authority (ACA) are official validators and there is a difference between acquisition [...]]]></description>
			<content:encoded><![CDATA[<p>Days 4 &#038; 5 bring the DIACAP/AFCAP Essentials Class to a close.  The<br />
biggest things I learned were:  CNSSI 4009 is the the official glossary of DOD IA, there is a big difference between theory, policy and practice, Agents of the Certifying Authority (ACA) are official validators and there is a difference between acquisition Mission criticality and IA MAC levels.   </p>
<p><strong>Stuff I learned from people in the class:</strong></p>
<blockquote><p>-AFCA is changing its name (to what?)</p>
<p>DOD is going to put the new IA controls in NCSSI 12-53 (currently in draft)</p>
<p>-a lot of what I need in there is in NIST 800-53</p>
<p>Marines use something called Exacta</p>
<p>Site called securitycritics.org</p>
<p>33-202 is now completely irrelevant and obsolete (not even mentioned ONCE in the class)</p>
<p>800-30</p>
<p>Feds call Certification &#038;Accreditation (C&#038;A) “Security authorization” </p>
<p>NIST SP 800-37</p></blockquote>
<p><strong>Day 4:</strong></p>
<blockquote><p>Validator Activities &#038; Issue Accreditation Decision</p>
<p>Prepare POA&#038;M</p>
<p>Validate Results/Scorecard</p>
<p>Scorecard</p>
<p>Make certification determination</p>
<p>CA/DAA Package review </p></blockquote>
<p><strong>Day 5:</strong></p>
<blockquote><p>Validation procedures were discussed.  On day five, we looked at how the validators look at a system.</p>
<p>I thought is was interesting.  It should help me get through the EITDR/DIACAP process easier.</p>
<p>Maintain Situational Awareness</p>
<p>Maintain IA Posture</p>
<p>Conduct Review</p>
<p>R-Accreditation</p>
<p>Retire system </p></blockquote>
<img src="http://elamb.org/?ak_action=api_record_view&id=1744&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://elamb.org/diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day-4-5/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DIACAP Essentials + IA Control Validation Training (part 4): DIACAP/AFCAP Day3</title>
		<link>http://elamb.org/diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day3/</link>
		<comments>http://elamb.org/diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day3/#comments</comments>
		<pubDate>Fri, 03 Jul 2009 04:37:14 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[Assurance/DITSCAP]]></category>
		<category><![CDATA[Assurance/Netcentric]]></category>
		<category><![CDATA[Assurance/SSAA]]></category>
		<category><![CDATA[EITDR]]></category>
		<category><![CDATA[FISMA]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[information assurance]]></category>
		<category><![CDATA[sissu]]></category>
		<category><![CDATA[DIACAP]]></category>
		<category><![CDATA[DIACAP Team]]></category>
		<category><![CDATA[ditpr]]></category>
		<category><![CDATA[dod]]></category>
		<category><![CDATA[emass]]></category>
		<category><![CDATA[IA]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1736</guid>
		<description><![CDATA[Day 3 heats up a little.  We start talking about what it take to actually get validated.  The DIACAP Implementers Guide &#038; the DIACAP Validators guide is opened up and reviewed.  I think we all learned a little something during this discussion because there have been some challenges with this.  Unfortunately, [...]]]></description>
			<content:encoded><![CDATA[<p>Day 3 heats up a little.  We start talking about what it take to actually get validated.  The DIACAP Implementers Guide &#038; the DIACAP Validators guide is opened up and reviewed.  I think we all learned a little something during this discussion because there have been some challenges with this.  Unfortunately, we don&#8217;t to far into the validator stuff.</p>
<p><strong>Day 3:</strong>  </p>
<blockquote><p>DIACAP Structure</p>
<p>Terminology Review</p>
<p>Assemble DIACAP Team</p>
<p>Registered System/System Information Profile</p>
<p>Assign IA Controls</p>
<p>Initiate DIACAP Implementation Plan </p></blockquote>
<img src="http://elamb.org/?ak_action=api_record_view&id=1736&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://elamb.org/diacap-essentials-ia-control-validation-training-part-4-diacapafcap-day3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DIACAP Essentials + IA Control Validation Training (part 3): DIACAP/AFCAP Day2</title>
		<link>http://elamb.org/diacap-essentials-ia-control-validation-training-part-3-diacapafcap-day2/</link>
		<comments>http://elamb.org/diacap-essentials-ia-control-validation-training-part-3-diacapafcap-day2/#comments</comments>
		<pubDate>Fri, 03 Jul 2009 04:32:44 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[Assurance/DITSCAP]]></category>
		<category><![CDATA[Assurance/Netcentric]]></category>
		<category><![CDATA[Assurance/SSAA]]></category>
		<category><![CDATA[EITDR]]></category>
		<category><![CDATA[apms]]></category>
		<category><![CDATA[federal]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1733</guid>
		<description><![CDATA[Day 1 &#038; 2 have been all about the very basics of DIACAP.  Were introduced to the terminologies, key players of the C&#038;A process and basically given the big picture.  Like I said, GREAT for beginners, but just lots of theory and refresher if you&#8217;ve been doing C&#038;A since DITSCAP.
Day 1 &#038;2:  [...]]]></description>
			<content:encoded><![CDATA[<p>Day <a href="http://elamb.org/diacap-essentials-ia-control-validation-training-part-2-diacapafcap-day1/">1 </a>&#038; 2 have been all about the very basics of DIACAP.  Were introduced to the terminologies, key players of the C&#038;A process and basically given the big picture.  Like I said, GREAT for beginners, but just lots of theory and refresher if you&#8217;ve been doing C&#038;A since DITSCAP.</p>
<p><strong>Day 1 &#038;2: </strong> </p>
<blockquote><p>Getting the Big Picture</p>
<p>DIACAP/AFCAP Policy &#038; Terminology</p>
<p>Roles and Responsibilities for the C&#038;A process</p>
<p>Accreditation  &#038; Approval to Connect</p>
<p>Homework: review terminology  </p></blockquote>
<p>In between longer breaks, during lunch and just before class we sneak in episode of the The IT Crowd.  Its the first time I&#8217;ve watched it so its a real treat for me.  Hilarious show.  </p>
<img src="http://elamb.org/?ak_action=api_record_view&id=1733&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://elamb.org/diacap-essentials-ia-control-validation-training-part-3-diacapafcap-day2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DIACAP Essentials + IA Control Validation Training (part 2): DIACAP/AFCAP Day1</title>
		<link>http://elamb.org/diacap-essentials-ia-control-validation-training-part-2-diacapafcap-day1/</link>
		<comments>http://elamb.org/diacap-essentials-ia-control-validation-training-part-2-diacapafcap-day1/#comments</comments>
		<pubDate>Tue, 23 Jun 2009 01:29:26 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[Assurance/DITSCAP]]></category>
		<category><![CDATA[Assurance/Netcentric]]></category>
		<category><![CDATA[Assurance/SSAA]]></category>
		<category><![CDATA[Certification/CISSP]]></category>
		<category><![CDATA[EITDR]]></category>
		<category><![CDATA[FISMA]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[federal]]></category>
		<category><![CDATA[information assurance]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[AFCAP]]></category>
		<category><![CDATA[apms]]></category>
		<category><![CDATA[architectural views]]></category>
		<category><![CDATA[DIACAP]]></category>
		<category><![CDATA[DIACAP Team]]></category>
		<category><![CDATA[ditpr]]></category>
		<category><![CDATA[ditprdon]]></category>
		<category><![CDATA[dod]]></category>
		<category><![CDATA[emass]]></category>
		<category><![CDATA[IA]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[sissu]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1731</guid>
		<description><![CDATA[DIACAP/AFCAP Day 1.
This is the second installment of the DIACAP Essentials journal.
In the first day of class we&#8217;ve taken a high level look at the big picture of the Department of Defense Information Assurance Certification &#038; Accreditation Process (DIACAP) and Air Force Certification &#038; Accreditation Program (AFCAP).  It is a very valuable tool for [...]]]></description>
			<content:encoded><![CDATA[<p><strong>DIACAP/AFCAP Day 1.</strong><br />
<a href="http://elamb.org/diacap-essentials-ia-control-validation-training-part-1/">This is the second installment of the DIACAP Essentials journal.</a></p>
<p>In the first day of class we&#8217;ve taken a high level look at the big picture of the Department of Defense Information Assurance Certification &#038; Accreditation Process (DIACAP) and Air Force Certification &#038; Accreditation Program (AFCAP).  It is a very valuable tool for a beginner. </p>
<p>Since I&#8217;ve gone through the entire process (with a legacy system) more than once through all the growing pains of Air Force C&#038;A from DITSCAP to DIACAP, I found that I knew about 90% of everything taught.  I don&#8217;t mind having a refresher, though and quite frankly, I need the CPE&#8217;s for my CISSP <img src='http://elamb.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> .</p>
<p>There were a couple of golden nuggets that I&#8217;ve been able to get out of some of the old timers.  I learned some interesting things about how the Navy, Marines and Army do things.<br />
Navy (as weird as their dumb ass rank system.. yep, I said it.. its dumb) have like three systems: DITPR-DON, DA-DUMB and some other BS, Marines have something called Exacta and the Army has APMS (Army Profile Management System).  Also learned cool off topic stuff like history of eMass.</p>
<p>I must admit I&#8217;m looking forward to day two.<br />
pros of day 1: Good solid start on basics GREAT for beginners.  <a href="http://www.secureinfo.com/">SecureInfo</a> gets mad props for have a great instructor John M.(don&#8217;t know if he wants his full name published.. but he&#8217;s highly, highly knowledgeable and very positive).</p>
<p>cons of day 1: Right off the bat I am noticing a huge hole in the training&#8230; a lack of in depth teaching of <a href="http://elamb.org/eitdr-enterprise-information-technology-data-repository/">EITDR</a>, which is how the Air Force implements, manages and maintains the entire DIACAP/AFCAP process.  I don&#8217;t really see how you can teach one without the other these days.  I guess contractually, SecureInfo can not touch it since some other company has the contract.  But unfortunately, the folks that are new to this are going to suffer.  Because if they goto this class without knowing the EITDR they will know why but now how, and if they go to the EITDR class without knowing the DIACAP they will know how but not Why.</p>
<img src="http://elamb.org/?ak_action=api_record_view&id=1731&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://elamb.org/diacap-essentials-ia-control-validation-training-part-2-diacapafcap-day1/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>DIACAP Essentials + IA Control Validation Training (part 1)</title>
		<link>http://elamb.org/diacap-essentials-ia-control-validation-training-part-1/</link>
		<comments>http://elamb.org/diacap-essentials-ia-control-validation-training-part-1/#comments</comments>
		<pubDate>Wed, 10 Jun 2009 04:49:25 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[Assurance/DITSCAP]]></category>
		<category><![CDATA[Assurance/SSAA]]></category>
		<category><![CDATA[Certification]]></category>
		<category><![CDATA[FISMA]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[Security Awareness]]></category>
		<category><![CDATA[ditpr]]></category>
		<category><![CDATA[information assurance]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1727</guid>
		<description><![CDATA[I&#8217;ve been scheduled to go to DIACAP Essentials + IA Control Validation training.  It is the same training that is given to validators at AFCA, so I guess it is pretty serious stuff.  I was very reluctant to go until I realized that I actually really need the CPE&#8217;s to maintain my CISSP.
Since [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been scheduled to go to DIACAP Essentials + IA Control Validation training.  It is the same training that is given to validators at AFCA, so I guess it is pretty serious stuff.  I was very reluctant to go until I realized that I actually really need the CPE&#8217;s to maintain my CISSP.</p>
<p>Since I&#8217;ve been doing the DIACAP stuff for about 2 years now, I&#8217;m not certain there is any new information for me to learn.</p>
<blockquote><p><strong>DIACAP Essentials </strong><br />
The Department of Defense Information Assurance Certification and<br />
Accreditation Process (DIACAP) Essentials course blends lecture and hands-on<br />
exercises to introduce students to DIACAP policy (to include FISMA<br />
requirements of a comprehensive, repeatable, and auditable Information<br />
Security process). </p></blockquote>
<blockquote><p><strong>IA Control Validation In-Depth </strong>- 3 Days<br />
The IA Control Validation In-Depth course takes the students DIACAP<br />
education and turns the view from an implementor to a Validator perspective<br />
and involves the students in the validation process for the IA Controls<br />
(DoDI 8500.2).</p></blockquote>
<p>What I am hoping to get from the course is a better handle on the FISMA process.<br />
I don&#8217;t feel like I really have a handle on what is supposed to happen with it.</p>
<img src="http://elamb.org/?ak_action=api_record_view&id=1727&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://elamb.org/diacap-essentials-ia-control-validation-training-part-1/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>New Certification &amp; Accreditation Process (Rumor)</title>
		<link>http://elamb.org/new-certification-accreditation-process-rumor/</link>
		<comments>http://elamb.org/new-certification-accreditation-process-rumor/#comments</comments>
		<pubDate>Thu, 26 Mar 2009 03:35:42 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[Assurance/DITSCAP]]></category>
		<category><![CDATA[Assurance/SSAA]]></category>
		<category><![CDATA[EITDR]]></category>
		<category><![CDATA[information assurance]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1662</guid>
		<description><![CDATA[<strong>One C&#038;A package to rule them all? </strong>

The federal government has a bunch of Certification &#038; Accreditation processes.  There is Department of Defense Information Assurance Certification &#038; Accreditation (DIACAP) for the  DOD, there’s Director of Central intelligence Directive (DCID) 6/3 for certain classified systems, there is National Information Assurance Certification &#038; Accreditation (NIACAP) for National Security Systems.  And under each of these their processes  differ according the branch, leadership, organization and/or mission.  Each process, organization, branch and mission has a different set of resources that they pull from.  DIACAP pertains to military branches and pulls from the DoD 8500 series,  many other federal agencies use National Institute of Standards and Technology (NIST) Special Publication (SP) 800-xx series.

Each agency, organization and/or branch uses their own methods and everyone is happy.  The only problem is when a system gets exploited.  When it happens there is mass panic and they realize that there are massive holes in the process.]]></description>
			<content:encoded><![CDATA[<p><strong>One C&#038;A package to rule them all? </strong></p>
<p>The federal government has a bunch of Certification &#038; Accreditation processes.  There is Department of Defense Information Assurance Certification &#038; Accreditation (DIACAP) for the  DOD, there’s Director of Central intelligence Directive (DCID) 6/3 for certain classified systems, there is National Information Assurance Certification &#038; Accreditation (NIACAP) for National Security Systems.  And under each of these their processes  differ according the branch, leadership, organization and/or mission.  Each process, organization, branch and mission has a different set of resources that they pull from.  DIACAP pertains to military branches and pulls from the DoD 8500 series,  many other federal agencies use National Institute of Standards and Technology (NIST) Special Publication (SP) 800-xx series.</p>
<p>Each agency, organization and/or branch uses their own methods and everyone is happy.  The only problem is when a system gets exploited.  When it happens there is mass panic and they realize that there are massive holes in the process.</p>
<p><strong>Rumors and Trends</strong></p>
<p>There  have been rumors floating around about many of these federal C&#038;A processes merging into one.  At their core they are actually pretty similar.  Take NIST SP 800-37, C&#038;A of Federal Information Systems and DOD 8510, DIACAP for example.  Both have an initial phase where data is gathered on the system and all parties involved with a system are pulled together (see table. 1 for more similarities). </p>
<table class=MsoNormalTable border=0 cellspacing=0 cellpadding=0<br />
 style='border-collapse:collapse;mso-padding-alt:0in 0in 0in 0in;border-width:<br />
 initial;border-color:initial'><br />
<tr style='mso-yfti-irow:0;mso-yfti-firstrow:yes'>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt'>
<p><span style='font-family:Arial'>Federal C&amp;A Process<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-left:none;padding:0in 5.4pt 0in 5.4pt;border-left-width:initial;<br />
  border-left-color:initial'>
<p><span style='font-family:Arial'>Phases<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-left:none;padding:0in 5.4pt 0in 5.4pt;border-left-width:initial;<br />
  border-left-color:initial'>
<p><span style='font-family:Arial'>Activities<o:p></o:p></span></p>
</td>
</tr>
<tr style='mso-yfti-irow:1'>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-top:none;padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;<br />
  border-top-color:initial'>
<p><span style='font-family:Arial'>SP 800-37<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>Initiation Phase<o:p></o:p></span></p>
</td>
<td width=213 rowspan=2 valign=top style='width:159.6pt;border-top:none;<br />
  border-left:none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>Gather data, get agreement of all stake<br />
  holders<o:p></o:p></span></p>
</td>
</tr>
<tr style='mso-yfti-irow:2'>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-top:none;padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;<br />
  border-top-color:initial'>
<p><span style='font-family:Arial'>DIACAP<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>Initiate &amp; Plan IA C&amp;A<o:p></o:p></span></p>
</td>
</tr>
<tr style='mso-yfti-irow:3'>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-top:none;padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;<br />
  border-top-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
</tr>
<tr style='mso-yfti-irow:4'>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-top:none;padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;<br />
  border-top-color:initial'>
<p><span style='font-family:Arial'>SP 800-37<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>Security Certification Phase<o:p></o:p></span></p>
</td>
<td width=213 rowspan=2 valign=top style='width:159.6pt;border-top:none;<br />
  border-left:none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>IA Control Assessment and agreement<o:p></o:p></span></p>
</td>
</tr>
<tr style='mso-yfti-irow:5'>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-top:none;padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;<br />
  border-top-color:initial'>
<p><span style='font-family:Arial'>DIACAP<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>Implement &amp; Validate Assigned IA<br />
  Controls<o:p></o:p></span></p>
</td>
</tr>
<tr style='mso-yfti-irow:6'>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-top:none;padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;<br />
  border-top-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
</tr>
<tr style='mso-yfti-irow:7'>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-top:none;padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;<br />
  border-top-color:initial'>
<p><span style='font-family:Arial'>SP 800-37<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>Security Accreditation Phase<o:p></o:p></span></p>
</td>
<td width=213 rowspan=2 valign=top style='width:159.6pt;border-top:none;<br />
  border-left:none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>Security implementation and assessment<o:p></o:p></span></p>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
</tr>
<tr style='mso-yfti-irow:8'>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-top:none;padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;<br />
  border-top-color:initial'>
<p><span style='font-family:Arial'>DIACAP<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>Make Cert. Determination &amp;<br />
  Accreditation Decision<o:p></o:p></span></p>
</td>
</tr>
<tr style='mso-yfti-irow:9'>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-top:none;padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;<br />
  border-top-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
</tr>
<tr style='mso-yfti-irow:10'>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-top:none;padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;<br />
  border-top-color:initial'>
<p><span style='font-family:Arial'>DP 800-37<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>Continuous Monitoring Phase<o:p></o:p></span></p>
</td>
<td width=213 rowspan=2 valign=top style='width:159.6pt;border-top:none;<br />
  border-left:none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>Configuration management; FISMA reporting;<br />
  <span class=SpellE>sustainment</span><o:p></o:p></span></p>
</td>
</tr>
<tr style='mso-yfti-irow:11'>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-top:none;padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;<br />
  border-top-color:initial'>
<p><span style='font-family:Arial'>DIACAP<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>Maintain Authorization to Operate<o:p></o:p></span></p>
</td>
</tr>
<tr style='mso-yfti-irow:12'>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-top:none;padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;<br />
  border-top-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
</tr>
<tr style='mso-yfti-irow:13'>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-top:none;padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;<br />
  border-top-color:initial'>
<p><span style='font-family:Arial'>DIACAP<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>Decommission<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>Retire System<o:p></o:p></span></p>
</td>
</tr>
<tr style='mso-yfti-irow:14'>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-top:none;padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;<br />
  border-top-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
</tr>
<tr style='mso-yfti-irow:15;mso-yfti-lastrow:yes'>
<td width=213 valign=top style='width:159.6pt;border:solid black 1.0pt;<br />
  border-top:none;padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;<br />
  border-top-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
<td width=213 valign=top style='width:159.6pt;border-top:none;border-left:<br />
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;<br />
  padding:0in 5.4pt 0in 5.4pt;border-top-width:initial;border-top-color:initial;<br />
  border-left-width:initial;border-left-color:initial'>
<p><span style='font-family:Arial'>&nbsp;<o:p></o:p></span></p>
</td>
</tr>
</table>
<p>12-37?</p>
<img src="http://elamb.org/?ak_action=api_record_view&id=1662&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://elamb.org/new-certification-accreditation-process-rumor/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Certification &amp; Accreditation Change</title>
		<link>http://elamb.org/certification-accreditation-change/</link>
		<comments>http://elamb.org/certification-accreditation-change/#comments</comments>
		<pubDate>Wed, 27 Aug 2008 00:55:54 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[FDCC]]></category>
		<category><![CDATA[FISMA]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[Security Management]]></category>
		<category><![CDATA[System security engineering]]></category>
		<category><![CDATA[federal]]></category>
		<category><![CDATA[information assurance]]></category>
		<category><![CDATA[CA]]></category>
		<category><![CDATA[Committee on National Security Systems]]></category>
		<category><![CDATA[DIACAP]]></category>
		<category><![CDATA[dod]]></category>
		<category><![CDATA[IA]]></category>
		<category><![CDATA[nist]]></category>
		<category><![CDATA[nist 800]]></category>

	<!-- AutoMeta Start -->
	<category>metafile</category>
	<category>picture</category>
	<category>intelligence</category>
	<category>accreditation</category>
	<category>cnss</category>
	<category>cnss’</category>
	<category>ehlers</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/certification-accreditation-change/</guid>
		<description><![CDATA[Standard-issue security
Certification and accreditation process for national security systems to extend to the rest of government.  A two-year-old effort to standardize processes for certifying and accrediting government IT systems could soon bear fruit, according to officials from several agencies.
The Committee on National Security Systems is preparing instructions for implementing a unified certification and accreditation [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Standard-issue security</strong><br />
Certification and accreditation process for national security systems to extend to the rest of government.  A two-year-old effort to standardize processes for certifying and accrediting government IT systems could soon bear fruit, according to officials from several agencies.</p>
<p>The <strong>Committee on National Security Systems</strong> is preparing instructions for implementing a unified certification and accreditation (C&#038;A) process that could be used on all national security systems, including those in the Defense Department and intelligence community, said Tony Cornish, chairman of the CNSS’ C&#038;A working group.</p>
<p>At the same time, the National Institute of Standards and Technology plans to update its C&#038;A guidance for systems covered by the <strong>Federal Information Security Management Act</strong>, said Ron Ross, a senior computer scientist and FISMA implementation lead at NIST.</p>
<p>“We are very close to producing a unified C&#038;A process for the entire federal government,” Ross said in July at a government security symposium hosted by Symantec. “Within the next six to eight months, you are going to see a plethora of new things coming out” from CNSS and NIST.</p>
<p>CNSS’ instructions will be incorporated into NIST guidelines in its 800 series of special publications. Ross said a major update of SP 800-53 Rev. 2, “Recommended Security Controls for Federal Information Systems,” is expected in December, and a draft of the first revision of SP 800-37, “Guide for the Security Certification and Accreditation of Federal Information Systems,” is expected to be released for comment soon.</p>
<p>A single, governmentwide approach would make it easier for agencies to share data and cooperate with one another and with states, foreign allies and the private sector.</p>
<p>It could enable reciprocity, or the acceptance of other agencies’ C&#038;A processes, without requiring recertification, and also could streamline acquisition processes by making it easier for vendors and developers to meet one set of standards.</p>
<p>C&#038;A is a process for ensuring that IT systems are operating with an appropriate level of security. In the certification phase, the security of the system is documented; for accreditation, a designated authority signs off on the system’s fitness to go into operation. The concept has been around for some time, but there has been little standardization.</p>
<p>“In the past, we each had our own set of policies, and we didn’t look at each other’s,” said Sherrill Nicely, deputy associate director of national intelligence at the Office of the Director of National Intelligence.</p>
<p>FISMA requires C&#038;A of information technology systems, but that does not apply to national security systems. And within the national security community, the military and intelligence sectors each have had their own way of doing things.</p>
<p>“Since about 1993, the Defense Department had its program, the Defense IT Security Certification and Accreditation Process,” said Eustace King, DOD chief of acquisition and technology oversight. “It worked pretty well” in a time before DOD’s emphasis on network- centric systems and information sharing, but it lacked enterprise visibility.</p>
<p>That C&#038;A program was replaced with the Defense Information Assurance Certification and Accreditation Process. DOD was moving to the program in 2006 to harmonize military and intelligence processes when, a year later, it was expanded to include the rest of the national security community by bringing in the CNSS.</p>
<p>Through NIST, C&#038;A procedures eventually will be standardized across all of government. However, policies do not change mind-sets, and old habits still remain one of the primary challenges to a standardized process. At DOD, there is a reluctance to accept reciprocity — that is, to give full credit to another agency’s C&#038;A process without recertification, King said.</p>
<p>The intelligence community faces a similar hurdle, said Sharon Ehlers, an assistant deputy associate director of national intelligence.</p>
<p>“The cultural change has been the biggest challenge,” Ehlers said. “When it is not invented here, people don’t want to look at it.”</p>
<img src="http://elamb.org/?ak_action=api_record_view&id=1242&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://elamb.org/certification-accreditation-change/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
