DSS Overview and UpdatesPresentationDecember2013
DSS Overview and UpdatesPresentationDecember2013
DSS Overview and UpdatesPresentationDecember2013
DSS Update
• Web-based ISFD going to CAC/PKI enabling --- ready for 2014 deployment
Risk =
f { Threat,
Suspicious Contact Reports
IIRs
Referrals for Action
Cyber\Threat Notifications
Vulnerability,
Vulnerability Assessments
IT Accreditations
CCRIs
Security Clearance Process
Consequence
Value
Risk Based Prioritization
Company Assessments
Program Assessments
FOCI Analysis
{
CFIUS Reviews
Security Education
Security Training
Security Professionalization
Vulnerability Assessments
THREAT
• Closed Areas • SIPRNet
• Personnel Security • Accredited WAN/LAN
• Secure Storage • Trusted Download
• Security Violations • Electronic Control Plans
• Classified Visits
• Acquisitions & Mergers
Traditional / Information
Physical Systems
Security FOCI
Education International
0.2% 0.2%
0.2%
8.4% 0.2%
7.5%
16.8%
16.0%
FY12 FY13
74.4%
76.1%
Vulnerability Assessments
Top Ten Acute/Critical Vulnerabilities (59% of total):
• 08-602 Audit Capability (incl. 08-602A 3 Audit Trail Analysis)
• 02-200 - PERSONNEL SECURITY CLEARANCES - General (incl. 02-200B Deny Access for Deny Revoke
or Suspension PCLs)
• 08-202 Accreditation
• 01-302 Reports to be Submitted to the CSA (incl. 01-302G Change Conditions Affecting the FCL)
• 02-104 PCLs Required in Connection with the FCL
• 02-201 Investigative Requirements
• 08-305 Malicious Code
• 01-303 Reports of Loss, Compromise, or Suspected Compromise
• 08-311 Configuration Management
• 05-309 Changing Combinations (incl. 05-309B Employee with Knowledge Combination Change)
IT Vulnerabilities
Top five deficiencies we’re seeing in System Security Plans:
• SSP was incomplete or missing attachments
• Inaccurate or incomplete configuration diagram
• Sections in general procedures contradict protection profile
• Integrity & availability not properly addressed
• SSP was not tailored to the system
NISS enables DoD enterprise decision making and analysis (Acquisition, IC, etc.)
Systems
Users Access Interface DSS Systems
• DSS • Computer or • One Web or App • ISFD Replacement
Mobile Device Interface • ODAA BMS
• Industry • NCCS (DD254)
• Single Point of • Role Based Privileges • STEPP
Entry and Access • e-FCL
• Government
• Cross-Domain Solution
• Analytics,
• NCAISS (PKI/CAC) Automated
External Data
Login • JPAS / DISS
Business • e-QIP / SWFT
Management, • FPDS / SAM
Workflows • SEC Filings
• Commercial Data
Social Media
@DSSPublicAffair
@TheCDSE
Like Us on facebook at
DSS.stakeholders
16
Questions?
17