Category: Assurance

  • SUBJECT: DoD Information Assurance Certification and Accreditation Process (DIACAP)

    The Department of Defense Information Assurance Certification and Accreditation Process (DIACAP) is replacing with the DoD Information Technology Security Certification and Accreditation Process (DITSCAP). More on DITCAP can be found at the DOD's IASE website.

    What is DIACAP?
    The DIACAP is the DoD process for identifying, implementing, and validating information assurance controls, for authorizing the operation of DoD information systems, and for managing information assurance posture across DoD information systems consistent with the Federal Information Security Management Act (FISMA).

    What is so special about the DIACAP?
    It will replace DoDI 5200.40 and DoD 8510.1-M
    Guide for compliance with the Global Information Grid
    Supports Netcentricity.

    Follow this link to my interpretation of the DIACAP Policy.

    What will we have to do differently with the DIACAP. (soon)

  • DITSCAP, DIACAP, NICAP, ISP

    If you are looking for the acronyms above go to –> http://infoassure.blogspot.com  

    Most human beings have the luxury of not having to know what the acronyms DITSCAP, DIACAP, NIACAP and ISP mean.  I am not one of those human beings. 

    You know all those times you were at work and the Big Wigs decide to come up with some new ridiculous security rule that is just more hassle; have you ever cursed the stupid, stupid bastards that came up with a web blocker that won't let you visit fark.com, ebaum's world or stileproject… I'm the that stupid, stupid bastard

    But hey, man, don't blame me.  Any policy I (or any other System Security Engineer) comes up with usually is and interpretation of a company policy.  And usually (at least in my experience) we aren't the ones making the final decisions.

    (Sigh) Anyway, bitches…  

    I try to include some actual Security Engineering in this blog but it just seems a little over the top because most of my readers (who are either techies or N00bies) can not relate and/or don't have a use for. 

    System Security Engineering has to do with Certification and Accreditation, developing security and business plans, and creating organizational information security policies far Information Systems (boring, boring, booooring stuff… that pays pretty good).  It includes all levels of computer security but also deals with things like… operational security.

    http://infoassure.blogspot.com  will focus on system security engineering.

    I'll continue to put the SSE post in this blog but I'll hide most of them in the DITCAP category so my regular elamb.org visitors don't get nauseated.

  • Common Criteria, the Rainbow Series and Windows 2K

    Windows 2000 was awarded the Common Criteria Certificate.  This
    is the first Microsoft Operating System to receive such a prestigious
    certification putting it on the same level as SecureOS Solaris Unix,
    both built on an operating system that has been around for over thirty
    years.  This document will explain what the Common Criteria Certificate is, how a vendor achieves it and why a vendor would want it.

    Common Criteria is based on the idea of a sound way of evaluating the security of an operating system.  Common Criteria has evolved over the years.  Security evaluation criteria goes back to the ‘70’s.  The
    first standard for this criteria was published in the United States
    Trusted Computer Systems Evaluation Criteria (TCSEC), the “Orange Book.”  It was published in 1985 by the National Security Agency.  Europe
    came up with similar standards in an effort to create an international
    standard called Information Technology Security Evaluation and
    Certification (ITSEC) in 1991.  This led to the CC Editorial Board (CCEB) which was formed establishing globally recognized standards for security evaluation (dinopolis).  Each country has its own organization that enforces and advertises these international standards.  In the United States,
    both the NSA and the National Institute of Standards and Technology
    meet the security and testing needs of Information Technology producers
    and consumers.  They do this through a joint program called the National Information Assurance Partnership (NIAP).  The responsibilities of these organization are outlined in the Computer Security Act of 1987 (epic).

    In order for a vendor to be awarded the Common Criteria Certification it must pass all required tests for a security certification accepted in 15 countries.  There
    are three parts to the CC: 1) Introduction and general model, is the
    introduction to the CC. It defines general concepts and principles of
    IT security evaluation and presents a general model of evaluation.  2)
    Security functional requirements, establishes a set of security
    functional components as a standard way of requirements for Targets of
    Evaluation (TOEs).  3) Security assurance
    requirements, establishes a set of assurance components as a standard
    way of expressing the assurance requirements for TOEs (CRYPTIC).

    Common Criteria is essential particularly in these times of heightened Information security awareness.  The CC Certification is verification that the operating system has met a specific level of security.  Consumers
    are more likely to purchase an operating system that is internationally
    accredited than one with just a good reputation.

    This certification took Microsoft three years and millions of dollars to attain.  Very few companies have the time, money and resources to reach this level security.  According to Microsoft they obtained the Common Criteria “because its evaluation and certification process helps consumers make informed security decisions (Microsoft).”

     

    Works Cited

     

    Dinopolis. Common Criteria History. 11 May 2001. http://www.dinopolis.org/documentation/misc/theses/hhaub/node78.html

     NIAP. Common Criteria Evaluation Verification Scheme.

    http://niap.nist.gov/

     Electronic Privacy Center. Computer Security Act of 1987. http://www.epic.org/crypto/csa/

     Microsoft. Windows 2000 achieves the Common Criteria Certificate. 29 Oct 2002.

    http://www.microsoft.com/windows2000/server/evaluation/news/bulletins/cccert.asp#top

    Radium. The Rainbow Series Library. 28 June 2000.

    http://www.radium.ncsc.mil/tpep/library/rainbow/

    Digg This