Cyber Operations
Abstract
A number of key IT strategies were identified in the DoD Information Technology Enterprise Strategy and Roadmap issued by the Deputy Secretary of Defense in 2011. The IT Roadmap specifically addresses the need to improve Cybersecurity. It states that DoD networks are under constant attack from cybersecurity threats launched from various sources. MDA must meet the National Command Authority Directives for rapid deployment of the BMDS while complying with the key principles of the Cybersecurity standards to ensure MDA remains a secure member of the DoD Information Network (DODIN). DoD Instruction 8500.01 Cybersecurity issued in March 2014, requires continuous monitoring, data analysis, reporting and incident mitigation of DoD classified and unclassified, mission, test and administrative networks. To comply with the Instruction, MDA must implement a multi-tiered cybersecurity risk management capability to protect critical BMD data and systems from rapidly evolving internal and external threats. The issuance of DoD Instruction 8510.01, Risk Management Framework (RMF) Information Technology in March 2014 requires additional resources to implement, manage, monitor and report as a result of a thirty-five percent increase in controls (237 controls with 817 enhancements). DoD 8510.01 also states that resources for implementing the RMF must be identified and allocated as part of the Defense planning, programming, budgeting, and execution process. The Controls must be tested on all IT supporting research, development, test and evaluation and DoD-controlled IT operated by a contractor or other entity on behalf of DoD and reported. This project provides funds to sustain the Risk Management Framework (RMF) and Controls Validation Testing (CVT) activities, analysis of validation results, risk assessments and reviews of proposed Program Manager/Information Systems Security Officer (PM/ISSO) Plan of Action and Milestones (POA&M) for the MDA mission, test and administrative systems. Maintains the Certification and Accreditation (C&A) data repository, capturing the RMF documentation (artifacts, validation results, and Cybersecurity Risk Assessment results, and Authorizing Official (AO) accreditation decisions) and POA&M on all MDA information systems. Supports the monitoring and tracking of Cybersecurity mitigations detailed in IT security POA&Ms. Activities include preparation of C&A documentation and accreditation recommendations to the MDA PM/ISSO and AO. Independent Verification and Validation (IV&V) team actions ensure the availability, integrity, confidentiality and non-repudiation of the MDA mission, test and administrative systems. Activities in the Project are necessary to comply with Federal Information Security Management Act(FISMA). This project funds the MDA Security Operations Center (SOC), responsible for monitoring, managing, patching, and maintaining MDA network and core IT services; issuing and tracking Technical Compliance Orders; and coordinating overarching Enterprise NetOps. The SOC provides the network security operations centers and supporting processes to protect and defend BMDS and the MDA Enterprise information and information systems. The MDA Computer Emergency Response Team (CERT) monitors the classified and unclassified information technology MDA administrative IT networks and reports vulnerabilities. The MDA CERT coordinates with U.S. Cyber Command to identify and implement network vulnerability updates and patches to comply with U.S. Cyber Command vulnerabilities identified for DoD networks. The project funds Cybersecurity governance management and administrative management support, annual Agency-wide computer-based IA training and metrics reporting, implementation of Public Key Infrastructure and Enabling and COMSEC related activities. New Accomplishment beginning in FY 2019: Outside Federal Service Outreach - Defense Industrial Base - Participate and liaison with the Defense Security Service (DSS), MDA organizations and industry partners to conduct site visits and inspections to improve network monitoring capabilities at classified contractor sites to ensure protection of MDA BMDS data. -Assist with the analysis of network scans of industry partner networks and mitigation of risks to BMDS data.
Document Details
- Document Type
- Project
- Publication Date
- Oct 01, 2020
- Source ID
- MC30_0603890C_4_0400_PB_2020
Related Documents
- Root: BMD Enabling Programs
- Child Accomplishment: Information Assurance/Computer Network Defense (IA/CND)
- Child Accomplishment: Detect, Analyze and Mitigate Intrusions
- Child Accomplishment: Preventing Malicious Cybersecurity Activity
- Child Accomplishment: Continuous Monitoring
- Child Accomplishment: Planning, Policy Development, Workforce Training & Force Management
- Child Accomplishment: Outside Federal Outreach - Defense Industrial Base
- Child Cost Item: 5f3c4b8871b06335565c5bc38e24afea
- Child Cost Item: 4d8cad8882d609607f04f898936fa92f
- Child Cost Item: 161eb777e407b34e5c3b1c799459dc65
- Child Cost Item: 34178d5986489b930cbb827a738c74cf
- Child Cost Item: 77e3edce21c7ca9311a34dc9005dd2fe
- Child Cost Item: c0a49a8aeeec366aad31e56f0cc98167
- Child Cost Item: e6f045a642ffcd443a98983b0216ada9
- Child Cost Item: 765a2dee60376a09e8a3a0fad3383553
- Child Cost Item: 074a2dbc35064049b1c567cea30971d2
- Child Cost Item: c097d23f4bd751df45a39c04906516ea
- Child Cost Item: fd34fa7d10cdfb6c6fe351fc675864ef
- Child Cost Item: 8d4b4c7ce2a37b9f8df9d0545a27f78f
- Child Cost Item: eff2afe812ba9be95bd4452ab6e49ad7
- Child Cost Item: 22bf11365577f3bebeb0345ba713cf19
- Child Cost Item: 7a4061d8d4ccf679382aaaed48d12416
- Child Cost Item: 5f7b0ed8e2e4eb41e3e6b38c0e2eac88
- Child Cost Item: 001fb681a761253558843377f4fc4f94
- Child Cost Item: fd381895fb1a0df318cf67e5e78cb553
- Child Cost Item: 1f25a08a70f8d71601b9f254f69a357a
- Child Cost Item: 5c77b8dd8c806e41a3ff40c2601c674f
- Child Cost Item: d6869db36b99ce9cba06d81d0afd1d68
- Child Cost Item: 6969f03eb7af71b0a395cb4abd365063
- Child Cost Item: 65058508681835ec089ca2889f559d5f
- Child Cost Item: 477a57a22d975c0f8358fb0cd156f799