This framework, which replaced DIACAP, is used to manage cybersecurity risk for all Department of Defense IT systems.
What is the Risk Management Framework (RMF)?
According to Chapter 7, users are not allowed to connect these types of media or peripherals to DON IT unless specifically authorized.
What are privately-owned media or peripheral devices
This program's purpose is to protect DON cyber-related capabilities, assets, and information from being discovered by adversaries.
What is Operations Security (OPSEC)?
This three-letter acronym stands for the smart card that is the primary hardware token for logical access to NIPRNET.
What is CAC (Common Access Card)?
This type of software, which is past its commercial end-of-life, poses an increased security risk and must not be used without a waiver.
What is unsupported software?
This formal declaration by an Authorizing Official (AO) allows an information system to operate.
What is an Authorization to Operate (ATO)?
This is the preferred software solution for encrypting unclassified Microsoft servers, workstations, and removable media.
What is Microsoft BitLocker?
A list of sensitive command information that must be protected from public disclosure to ensure successful operations.
What is the Critical Information and Indicators List (CIIL)?
This four-letter acronym is an implementation guide, based on DoD policy, geared to a specific product or software version.
What is a STIG (Security Technical Implementation Guide)?
A type of software that includes source code which can be freely accessed, used, and shared, such as Linux or Apache.
What is Open Source Software (OSS)?
This person is responsible for ensuring that all IT assets they oversee are authorized and operated in accordance with their documentation.
Who is the Commanding Officer (CO) or Officer-in-Charge (OIC)?
Media introduced into a classified information system becomes classified unless this type of AO-approved mechanism is used.
What is a write-protection mechanism?
IT Specialists should consult with these individuals when identifying and applying OPSEC countermeasures.
Who are OPSEC Program Managers (PMs) or coordinators?
Data that is stored on a hard drive or other electronic media is referred to by this three-letter acronym.
What is DAR (Data at Rest)?
Commands must migrate to the next major version of an OSS product within this timeframe after its official release date.
What is 12 months?
A user authorized to perform security-relevant functions that ordinary users cannot, such as a system administrator or Information Assurance Officer.
What is a Privileged User?
For a laptop enabled for telework, capabilities like cameras, microphones, and Wi-Fi must be disabled before it is returned to this type of space.
What is a classified space?
A process of identifying critical information and analyzing friendly actions to see what can be observed and exploited by adversary intelligence systems.
What is the OPSEC process?
This acronym refers to a security directive that may order commands to stop using specific software versions due to a critical vulnerability.
What is an IAVM (Information Assurance Vulnerability Management)?
If a command needs to continue using software that has a CAT 1 IAVM directive against it, it must request and receive an approved one of these within 30 days.
What is a waiver or exception?
According to the manual, this is a Federal Information Security Modernization Act (FISMA) management tool used for tracking and mitigating cybersecurity weaknesses.
What is a Plan of Actions and Milestones (POA&M)?
Introducing government or personal mobile devices into areas where classified information is processed is prohibited without approval from the responsible AO, the CSA, and this specific technical authority for emissions security.
What is the Certified TEMPEST Technical Authority (CTTA)?
The Deputy Under Secretary of the Navy (DUSN) is the lead for this across the Department of the Navy.
What is OPSEC oversight, management, readiness, and compliance?
This system, known by its acronym DADMS, is where all DON applications must be registered.
What is the Department of the Navy Applications and Database Management System?
This is the broad term for the combination of policies, processes, and standards that enable the DON to manage digital identities and authorize access to resources.
What is Identity, Credential, and Access Management (ICAM)?