Category: Assurance

  • DIACAP Guide

    This slide will tell you everything you need to know for now:

    http://www.sdissa.org/downloads/Revised_DIACAP_KS_eMASS_Brief ISSA_10-28-05.ppt

    According to rumors about the DIACAP, the document (8510.bb) is waiting to be signed (or is signed). DoD 8510.bb will be the DIACAP Instruction guide. The DoD 8510.bb, Defense Information Assurance Certification and Accreditation Process will replace the 5200.40, DoD Information Technology Security Certification and Accreditation Process (DITSCAP) and 8510.1-M, Department of Defense Information Technolgoy Security Certification and Accreditation Process (DITSCAP) Application Manual.

     

    Read More on the DIACAP Guide.

  • Marine (naturalized philipine citizen) Spy caught in the White House!

    A Marine (naturalized citizen of the Philipines) stole 100 classified documents from FBI computers.  There is no telling what he took or who sold the information too.  This is bad.

    Top Secret information is information that if compromized could cause grave damage to National Security. 

    This is a wake up call to the entire intelligence community particularly in the area of determining personnel security.  There is perhaps no government employee as trusted as a Marine.  I suspect that this single act will make it more difficult for naturalized citizens of other countries to advance in high ranking government posistions for fear of allegiance to the same. 

    And you know what this means… no President Arnold Schwarznegger :(..     

     As for Mr. Aragoncillo, they will throw the book at him.  Call me crazy but this seems like the wrong administration to mess around with.  The Bush administration might start saying that the Philipines has WMD's. 

    Aragoncillo, a naturalized citizen from the Philippines and US marine, used his top secret clearance to steal classified intelligence documents from White House computers. Both the FBI and CIA are calling it the first case of espionage in the White House in modern history.

    In 2000, Aragoncillo worked on the staff of then-Vice President Al Gore. When interviewed by Philippine television, he remarked how valued Philippine employees were at the White House.

    “I think what they like most is our integrity and loyalty,” Aragoncillo said.

    read more | digg story

  • e-Eye Digital Security Beats Internet System Security

    e-Eye Digital Security hit a homerun in 2004 when they won the $6 Million dollar Defense Information System Agency’s I-ASSURE contract which will allow their robust e-Eye Retina Vulnerability Scanner to be used on DOD systems world wide.

    The Retina Vulnerability Scanner will be used to measure compliance with Department of Defense (DoD) Computer Emergency Response Team (CERT) Information Assurance Vulnerability Management Notices.

    The DOD used to use Internet System Security (ISS) vulnerability assessment tools exclusively for this task. However, on 30 September 2005 the ISS vulnerability tools will no longer be used by the Department of Defense.

    This comes at a time of the “cover up” CiscoGate controversy which involved ISS. On July 2005, Michael Lynn, a former research analyst with Internet Security Systems, resigned from the company just before releasing a major flaw in Cisco routers (many of which are on critical infrastructures).

    According to Lynn, Cisco and ISS allowed him to speak about the flaw at the Black Hat but suddenly changed their minds at the last minute attempting to shut Lynn up with legal action. Cisco and ISS were trying to protect there shareholders at the cost of all the customers, organizations and nations that depend on the Cisco routers. From an ethical perspective, this was not a great way for an Internet System Security company to act.

    It will be interesting to see if e-Eye Digital will be more ethical than ISS as it comes to power.  Something very evil tends to happen when large groups of people get together to gather large sums of money.

    As stated above, after Friday, 30 Sept 05, the ISS scanner will no longer be available. You should be able to download the new e-Eye Retina Network Security Scanner from one of the DISA pages:

    ISS/Retina Vulnerability Scanners (DOD):

    e-Eye Retina Network Security Scanner(SCCVI)

    http://iase.disa.mil/stigs/iss/index.html (gone 17 Oct Update)

    http://iase.disa.mil/stigs/iss/retina.html (gone 17 Oct Update)

     

    eEye Digital Security and DISA press release:

    http://www.eeye.com/html/company/press/PR20040623.html

     

    Official Word from DISA

    Information Assurance Support Environment:

    DISA IA Announcement: DISA will be converting from using Internet Security Scanner to the e-Eye Retina Network Security Scanner(SCCVI) effective 1 Aug 05 for all security reviews, compliance validations, certification efforts, etc. All open findings related to a penetration test conducted with the ISS tool will be archived (closed) as a Retina penetration test is conducted by DISA. The ISS findings are still valid open findings that need to be worked and closed by the site. However, sites are highly encouraged/recommended to perform a self-assessment using the Retina scanner, as soon as they receive the tool.

    Information, online training, and Retina software can be obtained from the http://iase.disa.mil website.

     

    eEye Digital Security

    http://www.eeye.com/html/index.html

    Retina Network Vulnerability Scanner:

    http://www.eeye.com/html/products/retina/index.html

     

    Resources

    ISS is Shady

    e-Eye Press release

    Inside CiscoGate

    Lynn’s Lawyer

    Lynn Presents at the BlackHat

    Cisco & ISS vs. Lynn

  • NR-KPP stands for Net Ready Key Performance Parameters

    NR-KPP stands for Net Ready Key Performance Parameters.
    Net Ready is the ability to have immediate access to mission or business essential information. Like the term Netcentric, Net Readiness is the full exploitation of the Internet and/or Intranet whether the organization's primary mission is business, volunteerism or warfare.

    So Net Ready Key Performance Parameters refers to evaluating the “net readiness” of a given information system or organization.

    Formal Definition:
    NR-KPP was developed to assess net-ready attributes required for both the technical exchange of information and the end-to-end operational effectiveness of that exchange. The NR-KPP replaces the Interoperability KPP, and incorporates net-centric concepts for achieving Information Technology (IT) and National Security System (NSS) interoperability and supportability.

    What are the elements within the Net Ready Key Performance Parameters?

    Net Centric Operations and Warfare Reference Model (NCOW RM) Compliance Statement

    Information Assurance (IA) Accreditation Compliance Statement

    Your guide on creating the NR-KPP will be the CJCSI 6212, Interoperability and Supportability on National Security Systems:

    Net-Ready Key Performance Parameter. All Information Support Plans (ISP) for systems that exchange information with other systems will contain a Net-Ready KPP. For all ISPs with an associated approved JCIDS CDD or CPD capabilities document, the ISP can refer to the associated CDD/CPD. ISPs for CRDs, ORDs, non-ACAT and fielded systems will include the NR-KPP in the ISP.

    The NR-KPP will consist of the following:
    a. AV-1, OV-2, OV-4, OV-5, OV-6C
    b. SV-4, SV-5, SV-6
    c. TV-1 generated from DISR online
    d. Applicable CRD crosswalk (See Table D-3)
    e. Initial LISI Profile (Interface Requirements Profile) See Enclosure K
    f. NR-KPP statement. (Table I-1)
    g. IA Statement of Compliance
    h. Key Interface Profile (KIP) Declaration (list of the KIPS that apply to
    the system)

    Key Interface Profiles (KIPs) Compliance Statement

    Reference:
    CJCSI 6212, Interoperability and Supportability on National Security Systems
    ß http://www.teao.saic.com/cbrtraining/docs/CJCSI_6212_01.pdf

    Net Ready -> http://del.icio.us/tag/%22net%2Bready%22
    More on NR-KPP à http://del.icio.us/tag/%22nr%2Bkpp%22

    http://del.icio.us/rss/tag/netcentric

  • The ISSEP: Information System Security Engineering Professional (ISSEP) certification

     

    I've been thinking of taking the Information System Security Engineering Professional (ISSEP) certification.  Since the CISSP info is still fresh in my mind and much of the ISSEP are things I do or have to deal with daily it seems like a good idea. 

    What is the ISSEP?
    The ISSEP was developed by the International Information System Security Certification Consortium (ISC)2 in conjuction with the National Security Agency/IAD. Where as the CISSP is an all encompassing general look at security, the ISSEP is a concentration on system security engineering process.  System security engineering has to do with ensuring that selected solutions
    meet the mission or business security needs.  It is defined as “the art of and science of discovering users security needs, and designing and making with economy and elegance information
    systems so that they can safely resist the forces they might be subjected to.”

    System Security Engineers tasks:
      Discover Information Protection Needs
      Define system Security Requirements
      Design System Security Architectures
      Develop Detailed Security Design
      Implement System Security
      Assess Information Protection Effectiveness

    Instead of ten Domains the ISSEP has four:
      System Security Engineering
      Certification and Accreditation
      Technical Managment
      U.S. Government Information Assurance Regulations 

    Most of of the ISSEP's material comes from the Information Assurance Technical Framework (IATF). 

    My co-worker recently took the test and he said it was more difficult than the CISSP.  The CISSP is easily THE most difficult test I've every done.  Although, since most of the information comes from the IATF, I'm not sure how it could be more difficult.
    The CISSP is so broad that you could not possibly get all the information from a single source.

    http://www.acsac.org/2003/case/thu-c-1530-Oren.pdf
    www.nsa.gov
    www.isc2.org

     

  • ISP Architectural Views

    One the most important part of an Information Support Plan
    (previously known as a C4ISP) is the Architectural Views.
    The DoD Architectural Framework Document describes each veiw
    in painful, painful detail. Since the C4ISP has been
    changed into the ISP, the DoD Architectural Framework is a
    bit out dated. For example it doesn't mention "ISP" and
    also includes some old views that have been phased out such
    as OV-3 and SV-1. The following gives my view on some of
    the views.

    In my limited experience creating views is very interative
    process. Meaning you create a little then your tweak and
    change them as you go.

    AV-1 Overview and Summary Information is a breeze if you
    have all the appropriate information readily available.

    Operation Views (OV)
    These are fun for me because I feel like I understand
    them. OV-1, High-level Operational Concept Graphic is
    one that I've had the pleasure of not having to do.
    Merely starting it was a bit of a challenge. It is
    intended to look pretty. I've seen it done affectively
    with MS Word and PowerPoint.

    OV-2 is Operation Node Connectivity. As a network guy,
    this is my favorite. I use Visio for this one with
    simple shapes representing the nodes or you can get
    fancy and use computer Icons OV-4, Organizational
    Relationship Chart is another fun easy diagram that can
    be created with Visio or Word using simple shapes.
    Ov-5 is the Activity Model. Since it is so closely
    tied to SV-4, fuctional description and SV-5,
    Operational Activity to System Function Traceability
    Matrix, it is very, very interative and not one of my
    favorites. I complete these three one after another.
    Both SV-4 and OV-5 must be completed before you do SV-5
    since all the info in SV-5 comes from those two.
    OV-6c, Operational Events-Trade Description requires a
    very good understanding of what happens to the data
    upon entering the system. But once you have that
    nailed down it is fairly straight forward. The logical
    data model, OV-7, can get a bit convoluted, I imagine.
    In it you are supposed give a visual representation of
    the various domains.

    System Views (SV)
    The SV's can get a little gray as some of the views can
    touch on things that involve your system but you have
    perhaps only heard of. For example, if your system "A"
    connects with System "B" you may have to show that
    connection even though you don't know much of anything
    about System "B". I haven't seen SV-1 on the Teao Saic
    site so I assume it has been phased out. But it deals
    with Interfaces. SV-2, System Communication Description
    is very much like the example of system "A" in relation
    to "B". SV-2 shows how your system communicates/connects
    with other systems. Its almost like a birds eye veiw of
    OV-2. SV-4, System Functionality Description, like I said
    in the OV section closely related to OV-5 and SV-5. So
    if one changes, they may all have to change.
    SV-5 is a large table that shows the direct relationship
    between Operational Activity to System Function. It is a
    pain in the ass for reason stated above. SV-6 can be a
    very complex table. It is the System Data Exchange
    Matrix.. you'll note that anything with the word "matrix"
    in it sucks. That is because one change on a seperate
    veiw can affect change in other views and almost always
    includes the matrices.

    Technical View (TV)
    TV-1, Technical Standards merely lists all the capabilities
    of the system and references each of the technical standards
    used.

    That is my oppinion of the ISP views. I hope you find them as relatively painless
    as I did and if not this site will help you out --->
    http://www.teao.saic.com/cbrtraining/archpro01.asp
  • Network Vulnerability tool: AutoScan is a utility for network exploration

    AutoScan is a utility for network exploration.

    I used AutoScan on my home network and found out that my Router has Linux on it.  For my customer's enclave I used Autoscan to quickly locate vulnerabilities.

    Although the network is small the scan was usefull since it has given me a good idea what affect AutoScan will have on my customers larger newtork with more valuable assets and a potentially larger number of risks.

    AutoScan did not alter my customers work as it instantly picked up workstations, internetworking devices and printers.  The built in nmap scripts adds a very nice touch. 

    If you're a mobile White Hat on the go like me, autoscan within the WHAX live CD is a great security tool to add to your “batbelt.”

    The objective of the program is to post the list of all equipment connected to the network. A list of ports preset is scanned for each equipment. You can find many more vulnerability tools with tags at Technorati & Del.icio.us:
    http://del.icio.us/tag/vulnerability+assessment

    read more | digg story

  • Net Ready Key Performance Parameters (NR-KPP)

    The Net Ready Key Performance Parameters (NR-KPP) is
    comprised of the following elements: compliance with the Net-Centric
    Operations and Warfare (NCOW) Reference Model (RM), applicable Global
    Information Grid (GIG) Key Interface Profiles (KIP),
    DOD information assurance requirements, and supporting integrated
    architecture products required to assess information exchange and use
    for a given capability.

    Net Centric Operations Warfare Reference Model (NCOW RM) (a) The NCOW
    RM serves as a common, enterprise-level, reference model for the DOD’s
    Enterprise Architecture The NCOW RM will ultimately provide a common
    architectural construct for NCOW with a common language and taxonomy.
    The final version of the RM will include:

    1. All Views (AV): AV-1 and AV-2
    2. Operational Views (OV): OV-1, OV-2, OV-3, and OV-5
    3. System Views (SV): SV-1, SV-2, SV-3, SV-4, and SV-5
    4. Target Technical View

    AV-1 Overview and Summary
    Information Scope, purpose, intended users, environment depicted, analytical findings

    OV-2 Operational Node
    Connectivity Description Operational Nodes, operational activities performed at each node,
    connectivity and information exchange need lines between nodes

    OV-4 Organizational Relationships Chart
    Organizational, role, or other relationships among organizations

    OV-5 Operational Activity Model
    Operational activities, relationships among activities, inputs and outputs.

    OV-6c Operational Event-Trace Description
    One of three products used to describe operational activity sequence and
    timing – traces actions in a scenario or sequence of events and specifiestiming of events.

    SV-4 Systems Functionality Description
    Functions performed by systems and the information flow among system
    functions, including information assurance functions

    SV-5 Operational Activity to Systems Function Traceability Matrix
    Mapping of systems back to operational capabilities or of system functions
    back to operational activities.

    SV-6 Systems Data Exchange Matrix
    Provides details of systems data being exchanged between systems.

    TV-1 Technical Standards Profile Extraction of standards that apply to the given architecture,
    Including information assurance functions.

    Bookmarks
    that are constantly updated by people around the world use delicious
    feed for netcentric (will need an aggregator to view feed):

    http://del.icio.us/rss/tag/netcentric
    More on Netcentrics, Ditscap, DIACAP and Information Assurance at infoassure.blogspot.com

  • SSAA vs. ISP

    I've done a few System Security Authorization Agreements (SSAA's) but I
    admit I'm doing Information Support Plans, ISPs (formerly C4ISPs) for
    the first time.

    I used to think that the SSAA was a little bit
    too much information. Overtime I've learned that it make total sense.
    It forces the Information System designers to answer important questions. Many times the
    questions it answers aren't important until much later (such as life
    cycle issues).

    The ISP's puts the SSAA to shame in its sheer
    volume of information that needs to be gathered. This is because it
    includes the netcentric aspects of the system, the actual schedule and
    money involved, acquisitions issues and a bunch of other things that I,
    as a security guy, don't care about.

    The ISP is a birds eye view
    of the target system where the SSAA is a microscope into all levels of
    security over the life of the system from cradle to the grave.

    More on Information Assurace, DITSCAP, and DIACAP on infoassure.blogharbor.com

  • DIACAP Policy

    This is an overview of the DIACAP’s final draft. 

    The DIACAP includes the same things that the DITSCAP has with two major differerences: netcentric environments and GIG standards. With these two (and MANY other changes) it seems that this evolution of the DITSCAP has to take place. So many major levels of Information Assurance in the DoD and abroad have changed that DITSCAP will have to embrace them to stay relevant.

    The DIACAP policies will come from DoD Directive/Instruction 8500.01E/.2. [fixed 22 Aug 07]

    The DIACAP supports Information Systems transitioning to netcentric environments and GIG Standards by:

    1. Ensuring uniformity of approach
    2. Managing and disseminating Information Assurance Design, implementation, validation, sustainement and approach
    3. Being able to handle differing system
    4. facilitating a dynamic environment

    Information Assurance will be implemented with Information Assurance Controls as defined by DoDI 8500.2 and maintained through a DoD wide configuration management process that considers the GiG architecture and risk assessments conducted at the DoD component level in accordance with FISMA.

    The DIACAP will support the ongoing validation to maintain the Information Assurance posture of an Information System. DoD component IA Programs are the primary method of supporting the DoD Information Assurance Program.

    Status of all systems in the DIACAP program will be available to all who have authorized access.