DIACAP Essentials + IA Control Validation Training (part 2): DIACAP/AFCAP Day1

by Bruce Brown | 2 Comments

DIACAP/AFCAP Day 1.
This is the second installment of the DIACAP Essentials journal.

In the first day of class we’ve taken a high level look at the big picture of the Department of Defense Information Assurance Certification & Accreditation Process (DIACAP) and Air Force Certification & Accreditation Program (AFCAP). It is a very valuable tool for a beginner.

Since I’ve gone through the entire process (with a legacy system) more than once through all the growing pains of Air Force C&A from DITSCAP to DIACAP, I found that I knew about 90% of everything taught. I don’t mind having a refresher, though and quite frankly, I need the CPE’s for my CISSP :).

There were a couple of golden nuggets that I’ve been able to get out of some of the old timers. I learned some interesting things about how the Navy, Marines and Army do things.
Navy (as weird as their dumb ass rank system.. yep, I said it.. its dumb) have like three systems: DITPR-DON, DA-DUMB and some other BS, Marines have something called Exacta and the Army has APMS (Army Profile Management System). Also learned cool off topic stuff like history of eMass.

I must admit I’m looking forward to day two.
pros of day 1: Good solid start on basics GREAT for beginners. SecureInfo gets mad props for have a great instructor John M.(don’t know if he wants his full name published.. but he’s highly, highly knowledgeable and very positive).

cons of day 1: Right off the bat I am noticing a huge hole in the training… a lack of in depth teaching of EITDR, which is how the Air Force implements, manages and maintains the entire DIACAP/AFCAP process. I don’t really see how you can teach one without the other these days. I guess contractually, SecureInfo can not touch it since some other company has the contract. But unfortunately, the folks that are new to this are going to suffer. Because if they goto this class without knowing the EITDR they will know why but now how, and if they go to the EITDR class without knowing the DIACAP they will know how but not Why.

2 Comments on DIACAP Essentials + IA Control Validation Training (part 2): DIACAP/AFCAP Day1

  1. Jeff Beason
    June 23, 2009 at 9:54 am (8 years ago)

    The Marine Corp is using Xacta, as well as a few Air Force MAJCOMs such as the ANG. They are then using EITDR as the submission tool.

    Reply

1Pingbacks & Trackbacks on DIACAP Essentials + IA Control Validation Training (part 2): DIACAP/AFCAP Day1

  1. […] 1 & 2 have been all about the very basics of DIACAP. Were introduced to the terminologies, key […]

Leave a Reply

Your email address will not be published. Required fields are marked *

Comment *