DoD cybersecurity policy compliance for Air Force technology services delivery
Delivery of Technology Services to the U.S. Air Force Cyber Security Center
The U.S. Air Force has a major responsibility in protecting the lives and property of American citizens and their allies abroad. Today, this armed force must use the most sophisticated and state-of the-art information technology available to protect the nation’s interests at home and abroad. Currently, the U.S. Air Force depends on a wide array of sophisticated computer and software systems and it is essential to maintain these networks. The mission of the professionals at the U.S. Air Force’s Cyber Systems Operations is to design, install and support these state-of-the-art networks to ensure they operate properly and remain secure from intrusion by nefarious perpetrators. To gain some fresh insights into this critical mission, this paper provides a review of the relevant literature to develop policies that are compliant with the U.S. Department of Defense’s guidelines together with a list of controlling legislation and a list of required standards for all devices, categorized by IT domain. Finally, a summary of the research and important findings concerning these issues are provided in the paper’s conclusion.
Review and Analysis
Overview of the U.S. Department of Defense
According to the information provided by its official Web site, the U.S. Department of Defense (DoD), this agency is the oldest and largest government agency in the country today. The overarching mission of the DoD is to “provide the military forces needed to deter war and to protect the security of our country” (About the Department of Defense, 2017, para. 3). Established during the pre-Revolutionary era, the DoD has transformed into a major public and private sector employer with more than 1.3 million active duty service members and nearly three-quarters of a million civilian employees. The size and complexity of the DoD can be discerned from its current organizational chart as depicted in Figure 1 below.
Create policies that are DoD compliant for the organization’s IT infrastructure.
The mission of the U.S. Air Force Cyber Security Center (AFCSC) is critically important to the nation’s safety, especially in the post-September 11, 2001 climate. Therefore, private sector companies working with the AFCSC must develop the proper Department of Defense (DoD) security policies that are needed to satisfy DoD standards for delivery of technology services to the AFCSC. Pursuant to the Department of Defense Instruction (DoDI) 8510.01 (March 12, 2014), the policy of the DoD states in part that:
· The DoD will establish and use an integrated enterprise-wide decision structure for cybersecurity risk management (the RMF) that includes and integrates DoD mission areas (MAs) pursuant to DoDD 8115.01 (Reference (m)) and the governance process prescribed in this instruction.
· The cybersecurity requirements for DoD information technologies will be managed through the RMF consistent with the principals established in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-37 (Reference (c)).
· The RMF must satisfy the requirements of subchapter III of chapter 35 of Title 44, United States Code (U.S.C.), also known and referred to in this instruction as the “Federal Information Security Management Act (FISMA) of 2002” (Reference (d)).
· DoD must meet or exceed the standards required by the Office of Management and Budget (OMB) and the Secretary of Commerce, pursuant to FISMA and section 11331 of Title 40, U.S.C. (Reference (n)).
· All DoD IS and PIT systems must be categorized in accordance with Committee on National Security Systems Instruction (CNSSI) 1253 (Reference (e)), implement a corresponding set of security controls from NIST SP 800-53 (Reference (f)), and use assessment procedures from NIST SP 800-53A (Reference (g)) and DoD-specific assignment values, overlays, implementation guidance, and assessment procedures found on the Knowledge Service (KS) at https://rmfks.osd.mil.
· As supporting reference security control documents are updated, DoD’s implementation of these updates will be coordinated through the RMF TAG.
· Pursuant to DoDI 8510.01 (March 12, 2014), each DoD IS, DoD partnered system, and PIT system must have an authorizing official (AO) responsible for authorizing the system’s operation based on achieving and maintaining an acceptable risk posture.
· Reciprocal acceptance of DoD and other federal agency and department IS and PIT system authorizations will be implemented to the maximum extent possible. Refusals must be timely, documented, and reported to the responsible DoD Component senior information security officer (SISO) (formerly known as the senior information assurance (IA) officer).
· IT products (including applications), as defined in Reference (h), will be configured in accordance with applicable STIGs under a cognizant ISSM and security control assessor (SCA). STIGs are product-specific and document applicable DoD policies and security requirements, as well as best practices and configuration guidelines. STIGs are associated with security controls through CCIs, which are decompositions of NIST SP 800-53 security controls into single, actionable, measurable items. SRGs are developed by DISA to provide general security compliance guidelines and serve as source guidance documents for STIGs. When a STIG is not available for a product, an SRG may be used. STIGs, SRGs and CCIs are available.
Based on the foregoing DoD requirements and guidelines, the following policies for our company should be implemented:
Email: All emailed corresponding shall conform to the requirements of the DoD’s procedures for enterprise and security gateways updated on April 22, 2016. According to the DoD’s latest guidance concerning email security:
The DoD Enterprise Email (DEE) service provides secure cloud-based email to the DoD enterprise that is designed to increase operational efficiency and facilitate collaboration across organizational boundaries. As an enterprise service, DEE reduces the cost of operations and maintenance by consolidating hardware into the Defense Information Systems Agency’s (DISA's) secure, global data center locations. Consequently, DEE meets both the DoD's strategic consolidation initiatives and mission partner messaging requirements. (Dod enterprise email, 2017, p. 2).
The security policies required by the DoD for email communications will therefore be strictly followed by the company and its personnel in all cases. Violations of these security policies may result in disciplinary actions up to and including termination and/or criminal prosecution.
Confidentiality. The DoD has implemented instructions that prohibit contracting with private sector organizations that require internal confidentiality agreements that could interfere with whistleblowing by concerned employees. For instance, according to Stamp (2017), “Under a class deviation issued by DoD on November 14, 2016, no funds may be used to contract with a business that prohibits or restricts its employees or sub-contractors from reporting waste, fraud, or abuse to a designated investigative or law enforcement representative of a federal department or agency” (para. 2).
The DoD requires that private sector organizations seeking to conduct business with the federal government must provide assurances that they do not have internal confidentiality policies in place that would prevent employees or subcontractors to report instances of fraud, abuse or waste of government funds (Stamp, 2017). Therefore, our company must ensure that the confidentiality of all DoD-related information will be strictly protected but that employees and/or subcontractors are allowed to report cases of intentional or unintentional waste, fraud or the abuse of federal government funds. Violations of this policy can result in disciplinary actions up to and included termination and/or criminal prosecution,
Deliverables. The DoD’s contract with our company stipulates that all deliverables must comply with the relevant laws required for DoD contracts as discussed further below.
Develop a list of compliance laws required for DoD contracts.
Given the importance and complexity of the DoD’s overarching mission to protect the United States and its interests at home and abroad, it is not surprising that the DoD has implemented a wide range of compliance laws that are required for contracts with private sector organizations. Some of the more salient laws in this context include the following:
· DoD DFARS (Defense Federal Acquisition Regulation Supplement) subpart 204.73 --Safeguarding Covered Defense Information and Cyber Incident Reporting (Revised October 21, 2016). The scope of this law extends to the following: (a) this subpart applies to contracts and subcontracts requiring contractors and subcontractors to safeguard covered defense information that resides in or transits through covered contractor information systems by applying specified network security requirements. It also requires reporting of cyber incidents. This subpart does not abrogate any other requirements regarding contractor physical, personnel, information, technical, or general administrative security operations governing the protection of unclassified information, nor does it affect requirements of the National Industrial Security Program (Subpart 204.73, 2016, p. 1). According to Stanton and Cassidy (2017), “The protections required to protect Government information are dependent upon the type of information being protected and the type of system on which the information is processed or stored. Thus, different information is subject to different protections depending upon whether it is housed on contractor or DOD systems” (para. 2). These guidelines are depicted graphically in Figure 2 below.
Figure 2. Protecting unclassified DoD information requirements
Source: https://insidegovernmentcontracts.covingtonburlingblogs.com/wp-content/uploads/sites/11/2017/02/Image.png
· FIPS Publication 200, Minimum Security Requirements for Federal Information and Information Systems, is a mandatory federal standard developed by NIST in response to FISMA. To comply with the federal standard, organizations first determine the security category of their information system in accordance with FIPS Publication 199, Standards for Security Categorization of Federal Information and Information Systems, derive the information system impact level from the security category in accordance with FIPS 200, and then apply the appropriately tailored set of baseline security controls in NIST Special Publication 800-53, Security and Privacy Controls for Federal Information Systems and Organizations. Organizations have flexibility in applying the baseline security controls in accordance with the guidance provided in Special Publication 800-53. This allows organizations to tailor the relevant security control baseline so that it more closely aligns with their mission and business requirements and environments of operation (FIPS pub 200, 2006).
· In October 2016, the DoD published revised guidelines for the Defense Federal Acquisition Regulations Supplement (DFARS) concerning unclassified controlled technical information (UCTI). These more rigorous guidelines are intended to improve cyber security practices between the DoD and private sector organizations. The most significant changes in the most recent guidelines provided by DFARS Clause 252.204-7012 include the following: (a) All contractors must be in full compliance with the requirements outlined in NIST 800-171; (b) Contractors must report cyber incidents within 72 hours or less to the DoD, (c) All non-compliant aspects must be reported to the DoD within 30 days after contract award; and, (d) Compliance must extend to all operation aspects - all suppliers and subcontracts storing, processing and/or creating CDI that is part of contract performance (Solutions for DFARs, 2017).
· National Institute of Standards and Technology (NIST) Special document 800-53, Revision 4 on Security and Privacy Controls for Federal Information Systems and Organizations. According to Langenberg (2016), “The Defense Federal Acquisition Regulation 204.73 consists of a limited selection of the controls from this document (SP 800-53). The best way to determine what steps you need to take to comply is to take both documents to your IT department, or contact a company that can perform a gap assessment to see where you are vulnerable. BUT, the biggest thing your company needs to do is have an assessment done as soon as possible. Then decide how you will comply with the DFARS clause 204.73 and get those procedures in place” (para. 2).
· Network Penetration Reporting and Contracting for Cloud Services. (Defense Federal Acquisition Regulation Supplement Parts 202, 204, 212, 239, and 252. On August 26, 2016, the DoD implemented updated cyber security regulations following the high-profile breach in security at the Office of Personnel Management that compromised secure data concerning more than 21.5 million government employees and contractors. In response, the DoD implemented stricter guidelines concerning private sector organizations and their use of cloud computing resources (Wagner, 2016).
Even the above list is not exhaustive, though, and it is vitally important to keep in mind, though, that the DoD regularly updates its guidelines concerning IT security and private sector organizations, including the controls placed on domains in the IT infrastructure as discussed further below.
List controls placed on domains in the IT infrastructure.
On March 12, 2014, the DoD issued DoDI 8510.01 which is commonly referred to as the Risk Management Framework (RMF) for DoD Information Technology (IT) or RMF for DoD IT (RMF for DoD IT, 2017). According to the DoD’s most recent guidance concerning DoDI 8510.01, these controls apply to all public and private sector organizations performing work for the federal government. In this regard, DoDI 8510.01 stipulates in part that these policies apply to, “All DoD IT that receive, process, store, display, or transmit DoD information. These technologies are broadly grouped as DoD IS, platform IT (PIT), IT services, and IT products. This includes IT supporting research, development, test and evaluation (T&E), and DoD-controlled IT operated by a contractor or other entity on behalf of the DoD” (DoDI 8510.01, 2014).
The DoD has adopted standards outlined in the National Institute of Standards and Technology (NIST) concerning the types of controls that should be used with IT systems, including the following:
· The environment in which the information system will be used (e.g., inside a guarded building within the continental United States, in an unmanned space vehicle, while traveling for business to a foreign country that is known for attempting to gain access to sensitive or classified information, or in a mobile vehicle that is in close proximity to hostile entities);
· The type of information that will be processed, stored, or transmitted (e.g., personal identity and authentication information, financial management information, facilities, fleet, and equipment management information, defense and national security information, system development information);
· The functionality within the information system or the type of system (e.g., standalone system, industrial/process control system, or cross-domain system); and,
· Other characteristics related to the overlay that help protect organizational missions/business functions, information systems, information, or individuals from a specific set of threats that may not be addressed by the assumptions otherwise described in NIST Special Publication 800-53 (NIST Special Publication (SP) 800-53 Revision 4, 2013).
In addition, the DoD has developed an Active Directory (AD) of controls that are required for its IT infrastructure based on the goals outlined in Table 1 below.
Table 1
Principles and rules for DoD IT networks
Source: Adapted from Active Directory optimization reference architecture, 2010
List required standards for all devices, categorized by IT domain
The general considerations that apply to DoD IT standards are set forth in DoDI 8500.01 (March 14, 2014) that will be relevant for the company’s DoD contract include, but may not be limited to, the following depending on what types of IT products and services are involved at the time:
· System managers (SMs) and program managers (PMs) must use trusted system and network (TSN) tools, techniques, and practices, including the use of all source threat assessments to inform acquisition and engineering mitigation decisions, for all IT when required in accordance with required standards.
· Cybersecurity will be implemented in all system and service acquisitions at levels appropriate to the system characteristics and requirements throughout the entire life cycle of the acquisition in accordance with Reference (q).
· All acquisitions of qualifying IT must have an adequate and appropriate cybersecurity strategy that will be reviewed prior to acquisition milestone decisions and acquisition contract awards and operational test oversight
· Each mobile code technology used in DoD information systems must undergo a risk assessment, be assigned to a mobile code risk category, and have its use regulated based on its potential to cause damage to DoD operations and interests if used maliciously.
· Disposal and destruction of classified hard drives, electronic media, processing equipment components, and the like will be accomplished in accordance prescribed standards and applicable security controls.
· Disposal of unclassified electronic media will be accomplished in accordance with the guidelines provided in NIST SP 800-88 (Reference (dm)) and applicable security controls.
· Cryptographic products used to protect IT and the information that resides in the IT will be acquired and implemented in accordance with Reference (bi).
· All IT will be assigned to and governed by a DoD Component cybersecurity program. IT below the system level (i.e., IT services and products) will be security configured and reviewed by the cognizant information system security managers (ISSMs) under the direction of the authorizing official (AO) for acceptance and connection into an authorized computing environment.
· Cybersecurity must be consistent with enterprise architecture principles and guidelines within the DoD Architecture Framework (Reference (dn)) and DoD cybersecurity architectures developed or approved by the DoD chief information officer (CIO).
· Connections to the DISN must comply with connection approval procedures and processes as established in Reference (am).
· All persons entrusted with the management of DoD IT will be responsible for proper use, care, physical protection, and disposal or disposition in accordance with DoDI 5000.64 (Reference (do)), DoDI 2030.02 (Reference (dp)) and, when appropriate, Reference (bo).
· In addition to complying with the provisions of DoDI 1035.01 (Reference (dq)):
(a) Telework solutions involving the use of DoD-owned, government-furnished equipment for remote access to unclassified DoD networks will comply with the requirements of applicable security controls defined in Reference (cj).
(b) Telework solutions involving the use of non-government furnished equipment (i.e., any computer or other telework device not furnished by DoD) for remote access to unclassified DoD networks will be developed by the DoD Components desiring the capability based on the guidance provided in NIST SP 800-114 (Reference (dr)) and evaluated and approved by the DoD CIO on a case-by-case basis.
· DoD will ensure new computer assets (e.g., server, desktop, laptop, thin client, tablet, smartphone, personal digital assistant, mobile phone) procured to support DoD will include a TPM version 1.2 or higher where required by the Defense Information Systems Agency’s (DISA), security technical implementation guides (STIGs) where such technology is available.
· Vendor trust platform models (TPMs) must be in conformance with Trusted Computing Group standards (www.trustedcomputinggroup.org/groups/tpm) and must be approved by the procuring DoD Component. The TPM must be turned on and ready for provisioning when the computer asset is received from the vendor. Written justification must be provided to the responsible AO if assets are procured without TPM technology in cases where it is available.
· DoD IT must comply with Security Content Automation Protocol (SCAP) standards (Solution for DFARs, 2017, para. 1-4).
Develop a deployment plan for implementation of these polices, standards, and controls.
The compliance checklist provided by DoDI 8550.01 (September 11, 201) recommends reviewing each DoD Internet service or Internet-based capabilities (IbC) used for compliance with the policies and directives listed within each area of the procedures section of this Instruction. This compliance checklist will facilitate the deployment and implementation of the policies, standards and control required by the DoD for private sector contractors as illustrated in the example provided in Table 2 below.
Table 2
Compliance checklist example: Public and private DoD internet services
No.
Checklist item
Y
N
1.a
The DoD Internet service or DoD information on IbC meets Electronic and Information Technology Accessibility Standards as defined in Reference (r).
1.b
Information collection complies with DoD manuals, instructions, or PLs where appropriate, as listed in References (o) and (p) and in DoDI 8910.01, DoDI 7750.07, DoD 7750.07-M, DoDI 1100.13, chapter 91 of title 15, United States Code (U.S.C.), OMB Memorandum “Information Collection under the Paperwork Reduction Act,” DoD 5200.1-R, and DA&M Memorandum, “SSN Exposed on Public Facing and Open Government Websites” (References (u) through (ab))
1.c
The DoD Internet service or IbC includes a notice of copyright, if applicable, and the specific copyrighted work(s) and owner of the copyright(s) are identified.
1.d
The DoD Internet service or IbC does not contain official DoD imagery altered in any way, except as allowed by DoDI 5040.02 (Reference (ac)).
1.e
The DoD Internet service or IbC only contains unclassified information that is of value to the intended audience.
1.f
The DoD Internet service or IbC only contains unclassified information and information has been removed that could put missions or personnel at risk, or constitute in aggregate classified or sensitive information.
Source: DoDI 8550.01, September 11, 2012, p. 17
References
About the Department of Defense. (2017). U.S. Department of Defense. Retrieved from https://www.defense.gov/About/.
Active Directory optimization reference architecture. (2010, December 15). U.S. Department of Defense. Retrieved from http://dodcio.defense.gov/Portals/0/Documents/DIEA/ADORA_ Final_v1_20101215.pdf.
Dod enterprise email. (2017). U.S. Department of Defense. Retrieved from http://www.disa.mil/enterprise-services/applications/dod-enterprise-email.
DoDI 8510.01. (2014, March 12). U.S. Department of Defense. Retrieved from https://rmf.org/images/stories/rmf_documents/851001_2014.pdf.
FIPS pub 200. (2006, March). U.S. Department of Defense. Retrieved from http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.200.pdf.
Langenberg, K. (2016). Cyber security requirements for DoD contractors. Association of Procurement Technical Assistance Centers. Retrieved from http://www.aptac-us.org/cyber-security-requirements-dod-contractors/.
NIST Special Publication (SP) 800-53 Revision 4. (2013, April 30). National Institute of Standards and Technology. Retrieved from https://csrc.nist.gov/csrc/media/publications/ sp/800-53/rev-4/archive/2013-04-30/documents/sp800-53-rev4-ipd.pdf.
RMF for DoD IT. (2017). Lunar Line. Retrieved from https://lunarline.com/RMF-for-DoD-IT?gclid=CjwKCAjwmefOBRBJEiwAf7DstCU2BvdDG0M504mDu0ZbWC-TrO-yaW5_NcX8JMdggGCxJS0NQ1EwKxoCkowQAvD_BwE.
Solutions for DFARs. (2017). RegDox. Retrieved from https://www.regdox.com/regulatory-compliance-solutions/dfars/.
Stamp, M. E. (2017, January 25). New confidentiality agreement restrictions for DoD contractors. Protorae Law LLC. Retrieved from http://www.protoraelaw.com/new-confidentiality-agreement-restrictions-dod-contractors/.
Stanton, P. & Cassidy, S. (2017, February 8). DoD further clarifies its DFAR cybersecurity requirements. Covington. Retrieved from https://www.insidegovernmentcontracts. com/2017/02/dod-clarifies-dfars-cybersecurity-requirements/.
Subpart 204.73. (2016). U.S. Department of Defense. Retrieved from http://www.acq.osd.mil/ dpap/dars/dfars/html/current/204_73.htm.
Wagner, W. C. (2016, September 22). Introduction to the new DoD cyber security regulations. Privacy & Data Security Insight. Retrieved from http://www.privacyanddatasecurity insight.com/2015/09/introduction-to-the-new-dod-cyber-security-regulations/.
Create your account
Always verify citation format against your institution’s current style guide requirements.