<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: DIACAP Team</title>
	<atom:link href="http://elamb.org/diacap-team/feed/" rel="self" type="application/rss+xml" />
	<link>http://elamb.org/diacap-team/</link>
	<description>don&#039;t be sheeple</description>
	<lastBuildDate>Fri, 30 Jul 2010 09:41:50 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.3</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: AL Hough</title>
		<link>http://elamb.org/diacap-team/comment-page-1/#comment-195650</link>
		<dc:creator>AL Hough</dc:creator>
		<pubDate>Tue, 12 Jan 2010 01:44:09 +0000</pubDate>
		<guid isPermaLink="false">http://elamb.org/diacap-team/#comment-195650</guid>
		<description>I would like to know the answer to Cedric&#039;s question also. 
 </description>
		<content:encoded><![CDATA[<p>I would like to know the answer to Cedric&#039;s question also.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: AL Hough</title>
		<link>http://elamb.org/diacap-team/comment-page-1/#comment-195649</link>
		<dc:creator>AL Hough</dc:creator>
		<pubDate>Tue, 12 Jan 2010 01:42:31 +0000</pubDate>
		<guid isPermaLink="false">http://elamb.org/diacap-team/#comment-195649</guid>
		<description>What requirements apply when considering a DIACAP on a server that will host applications that are on the approved software listing?  Does the system require a full DIACAP or can it have an executive package created?  The system itself is not going to be an application server in the sense that it will be dedicated to hosting one application.  Also, what requirements apply when the server will host user shares and organizational data?  For file servers already within and enclave (our servers on on a domain we do not own) does the host hold an responsibility for providing our organization with info regarding Inherited IA Controls? </description>
		<content:encoded><![CDATA[<p>What requirements apply when considering a DIACAP on a server that will host applications that are on the approved software listing?  Does the system require a full DIACAP or can it have an executive package created?  The system itself is not going to be an application server in the sense that it will be dedicated to hosting one application.  Also, what requirements apply when the server will host user shares and organizational data?  For file servers already within and enclave (our servers on on a domain we do not own) does the host hold an responsibility for providing our organization with info regarding Inherited IA Controls?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel</title>
		<link>http://elamb.org/diacap-team/comment-page-1/#comment-151881</link>
		<dc:creator>Daniel</dc:creator>
		<pubDate>Tue, 16 Dec 2008 23:50:37 +0000</pubDate>
		<guid isPermaLink="false">http://elamb.org/diacap-team/#comment-151881</guid>
		<description>I&#039;d like to second Cedric&#039;s question.</description>
		<content:encoded><![CDATA[<p>I&#8217;d like to second Cedric&#8217;s question.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cedric</title>
		<link>http://elamb.org/diacap-team/comment-page-1/#comment-130622</link>
		<dc:creator>Cedric</dc:creator>
		<pubDate>Mon, 15 Sep 2008 20:22:15 +0000</pubDate>
		<guid isPermaLink="false">http://elamb.org/diacap-team/#comment-130622</guid>
		<description>Who is responsible for certifying and accreditating Platform IT (systems-hardware/software)?</description>
		<content:encoded><![CDATA[<p>Who is responsible for certifying and accreditating Platform IT (systems-hardware/software)?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: elamb.security</title>
		<link>http://elamb.org/diacap-team/comment-page-1/#comment-93779</link>
		<dc:creator>elamb.security</dc:creator>
		<pubDate>Wed, 30 Apr 2008 01:44:59 +0000</pubDate>
		<guid isPermaLink="false">http://elamb.org/diacap-team/#comment-93779</guid>
		<description>fred,

I don&#039;t have a lot of experience with plain applications.  

I would contact the AF Infostructure Technology Reference Model (i-TRM)  to determine the appropriate action to take https://infostructure.hq.af.mil -- I think that is the link.  They are who you want to talk to for applications.  

There is a STIG for applications, but I believe its only applies to servers.
http://iase.disa.mil/stigs/draft-stigs/index.html</description>
		<content:encoded><![CDATA[<p>fred,</p>
<p>I don&#8217;t have a lot of experience with plain applications.  </p>
<p>I would contact the AF Infostructure Technology Reference Model (i-TRM)  to determine the appropriate action to take <a href="https://infostructure.hq.af.mil" rel="nofollow">https://infostructure.hq.af.mil</a> &#8212; I think that is the link.  They are who you want to talk to for applications.  </p>
<p>There is a STIG for applications, but I believe its only applies to servers.<br />
<a href="http://iase.disa.mil/stigs/draft-stigs/index.html" rel="nofollow">http://iase.disa.mil/stigs/draft-stigs/index.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fred Juarez</title>
		<link>http://elamb.org/diacap-team/comment-page-1/#comment-93697</link>
		<dc:creator>Fred Juarez</dc:creator>
		<pubDate>Tue, 29 Apr 2008 18:31:39 +0000</pubDate>
		<guid isPermaLink="false">http://elamb.org/diacap-team/#comment-93697</guid>
		<description>I am a program manager for a manpower tool that does not receive or transmit data.  It reads a file and the output is written to a file (much like Excel, Access operrates.  Would that be categorized as a system?  The tool is an application installed on an individual&#039;s PC,,,</description>
		<content:encoded><![CDATA[<p>I am a program manager for a manpower tool that does not receive or transmit data.  It reads a file and the output is written to a file (much like Excel, Access operrates.  Would that be categorized as a system?  The tool is an application installed on an individual&#8217;s PC,,,</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Register the System with DoD IA Component : security blog</title>
		<link>http://elamb.org/diacap-team/comment-page-1/#comment-66081</link>
		<dc:creator>Register the System with DoD IA Component : security blog</dc:creator>
		<pubDate>Sun, 10 Feb 2008 06:43:15 +0000</pubDate>
		<guid isPermaLink="false">http://elamb.org/diacap-team/#comment-66081</guid>
		<description>[...] the DIACAP Team, the IA Component&#8217;s role will likely be the &#8220;Certifying Authority&#8221; which is [...]</description>
		<content:encoded><![CDATA[<p>[...] the DIACAP Team, the IA Component&#8217;s role will likely be the &#8220;Certifying Authority&#8221; which is [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: elamb</title>
		<link>http://elamb.org/diacap-team/comment-page-1/#comment-65597</link>
		<dc:creator>elamb</dc:creator>
		<pubDate>Fri, 08 Feb 2008 07:04:11 +0000</pubDate>
		<guid isPermaLink="false">http://elamb.org/diacap-team/#comment-65597</guid>
		<description>Here is a good question from someone who stumble upon the site:

 I have the following questions about certain DIACAP team positions:
 
DAA - My DAA is a one star, Your telling me he&#039;s supposed to sit in on the meetings?  

PM/SM - This would be the system owner or system POC?

CA - ??? ... how would this differ from the DAA?

CAR - ??? is this similar to the role of the ACA?

&lt;strong&gt;Answer:&lt;/strong&gt;
The DAA usually delegates to a lower more tech savvy person.  Or at least, that has been my experience.  When I was in the AF, our commander (full bird) was the DAA which was pushed down from the Wing Commander.  All packages were read and evaluated by an Ops officer (a Capt).  If the Ops officer approved then the commander would usually sign off.  These days the DAA has been pushed to an even higher level (in the Air Force anyway).  This Capt could be seen as the Certifying Authority, because it should be someone who is knowledgeable enough to realize what risks to take and which ones are unacceptable.  They will typically have a lot of say in whether the system is acceptable.

I don&#039;t know about the other branches, but the USAF depends completely on the IA Component as the CA which is AFCA.  

In the Air Force, the DAA is the AFNETOPS/CC.  Stick with DoD 8510.10 and 8500.02.  

more on the IA Components can be found here http://elamb.org/diacap-activity-1-initiate-and-plan-certification-accreditation/

The IA Component is a great guide for the entire process for the Army its Army NETCOM Information Assurance Office; Navy info can be found here: http://www.doncio.navy.mil 

The PM or Program Management Office is critical because they manage the money and sustainment issues on a system.  They will have to answer important sustainment questions as well as help coordinate how certain IA Controls will (or won&#039;t - lol)  be implemented.  The PM works closely with the system owner (and I suppose it can sometime be the system owner).  8510 points out which roles can be one and the same and which ones can not.</description>
		<content:encoded><![CDATA[<p>Here is a good question from someone who stumble upon the site:</p>
<p> I have the following questions about certain DIACAP team positions:</p>
<p>DAA &#8211; My DAA is a one star, Your telling me he&#8217;s supposed to sit in on the meetings?  </p>
<p>PM/SM &#8211; This would be the system owner or system POC?</p>
<p>CA &#8211; ??? &#8230; how would this differ from the DAA?</p>
<p>CAR &#8211; ??? is this similar to the role of the ACA?</p>
<p><strong>Answer:</strong><br />
The DAA usually delegates to a lower more tech savvy person.  Or at least, that has been my experience.  When I was in the AF, our commander (full bird) was the DAA which was pushed down from the Wing Commander.  All packages were read and evaluated by an Ops officer (a Capt).  If the Ops officer approved then the commander would usually sign off.  These days the DAA has been pushed to an even higher level (in the Air Force anyway).  This Capt could be seen as the Certifying Authority, because it should be someone who is knowledgeable enough to realize what risks to take and which ones are unacceptable.  They will typically have a lot of say in whether the system is acceptable.</p>
<p>I don&#8217;t know about the other branches, but the USAF depends completely on the IA Component as the CA which is AFCA.  </p>
<p>In the Air Force, the DAA is the AFNETOPS/CC.  Stick with DoD 8510.10 and 8500.02.  </p>
<p>more on the IA Components can be found here <a href="http://elamb.org/diacap-activity-1-initiate-and-plan-certification-accreditation/" rel="nofollow">http://elamb.org/diacap-activity-1-initiate-and-plan-certification-accreditation/</a></p>
<p>The IA Component is a great guide for the entire process for the Army its Army NETCOM Information Assurance Office; Navy info can be found here: <a href="http://www.doncio.navy.mil" rel="nofollow">http://www.doncio.navy.mil</a> </p>
<p>The PM or Program Management Office is critical because they manage the money and sustainment issues on a system.  They will have to answer important sustainment questions as well as help coordinate how certain IA Controls will (or won&#8217;t &#8211; lol)  be implemented.  The PM works closely with the system owner (and I suppose it can sometime be the system owner).  8510 points out which roles can be one and the same and which ones can not.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DIACAP Activity #1 Initiate and Plan Certification &#38; Accreditation : security blog</title>
		<link>http://elamb.org/diacap-team/comment-page-1/#comment-62947</link>
		<dc:creator>DIACAP Activity #1 Initiate and Plan Certification &#38; Accreditation : security blog</dc:creator>
		<pubDate>Sun, 03 Feb 2008 06:35:40 +0000</pubDate>
		<guid isPermaLink="false">http://elamb.org/diacap-team/#comment-62947</guid>
		<description>[...] DIACAP Team [...]</description>
		<content:encoded><![CDATA[<p>[...] DIACAP Team [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
