180 likes | 764 Views
Navy C&A Process. Overview of Key Concepts. Paul Hilton Navy Certifying Authority SPAWAR 5.0.9 January 20, 2011. Agenda. Introduction DoD Information Assurance Certification and Accreditation Process ( DIACAP ) The Importance of Testing/Following the Process
E N D
Navy C&A Process Overview of Key Concepts Paul Hilton Navy Certifying AuthoritySPAWAR 5.0.9January 20, 2011
Agenda • Introduction • DoD Information Assurance Certification and Accreditation Process (DIACAP) • The Importance of Testing/Following the Process • Security Architecture and Engineering • Policy, Guidance, and Information Assurance (IA) Controls • Information System (IS) Documentation • Inheritance, Aggregation, Reciprocity, and Mitigation • Roles and Responsibilities • IS Security Engineer (ISSE) • Validator • Liaison • Certifying Authority (CA) • ODAA (Operational Designated Approving Authority)
Introduction • The Navy Certifying Authority • RADM Bachmann designation of GENSER Certifying Authority and Alternates Paul Hilton, Navy CA Keven Nelson, Alternate CA Amrik Khatra, Alternate CA
Policy, Guidance, and IA Controls NIST Guidance NSA Guidance
Questions? NAVY_CA@navy.mil Toll-free phone number: (866) 966-2748
Backups Stopping the wily hacker That one magic security setting Starting the DIACAP process too late