About two weeks ago I attended the DISA IA Boot Camp. The training was run by two guys who had removed all of their childhood memories and replaced them with DODD 8500.01E and DODI 8500.2. They knew information assurance like nobodies business.
I would recommend this class to ALL Information Assurance Officers (IAO) and Information Assurance Managers (IAM). The level of the material stays right in the middle – its not really technical and backs off of some of the intricate details of a specific organization’s implementation of something like the DIACAP. Which brings me to the most controversial and frustrating part of the training.
These guys were saying that the DIACAP was rejected (as of mid-2006/beginning 2007 time frame) by a few key organizations (namely the Inspectors Generals office) because the method in which it was approved did not comply with regs. The irony is like a knife stabbing itself.
Anyway, they emphasized the importance of maintaining with the IA Controls indicated in both the DIACAP and DITSCAP. Beyond the mountain of documentation and mind numbing bureaucracy, it is MOST important to secure the systems.
What guys out in the field are doing is implementing the DITSCAP’s SSAA package as a supplement (artifact.. whatever you want to call it) in the DIACAP package in order to cover all tracks.