Cyber Security Fundamentals
Handling Media & Devices
OPSEC Awareness
Cyber Acronyms
Software & Compliance
100

This framework, which replaced DIACAP, is used to manage cybersecurity risk for all Department of Defense IT systems.

What is the Risk Management Framework (RMF)?

100

 According to Chapter 7, users are not allowed to connect these types of media or peripherals to DON IT unless specifically authorized.

What are privately-owned media or peripheral devices

100

This program's purpose is to protect DON cyber-related capabilities, assets, and information from being discovered by adversaries.

What is Operations Security (OPSEC)?

100

This three-letter acronym stands for the smart card that is the primary hardware token for logical access to NIPRNET.

What is CAC (Common Access Card)?

100

 This type of software, which is past its commercial end-of-life, poses an increased security risk and must not be used without a waiver.

What is unsupported software?

200

This formal declaration by an Authorizing Official (AO) allows an information system to operate.

What is an Authorization to Operate (ATO)?

200

 This is the preferred software solution for encrypting unclassified Microsoft servers, workstations, and removable media.

What is Microsoft BitLocker?

200

 A list of sensitive command information that must be protected from public disclosure to ensure successful operations.

What is the Critical Information and Indicators List (CIIL)?

200

This four-letter acronym is an implementation guide, based on DoD policy, geared to a specific product or software version.

What is a STIG (Security Technical Implementation Guide)?

200

 A type of software that includes source code which can be freely accessed, used, and shared, such as Linux or Apache.

What is Open Source Software (OSS)?

300

This person is responsible for ensuring that all IT assets they oversee are authorized and operated in accordance with their documentation.

Who is the Commanding Officer (CO) or Officer-in-Charge (OIC)?

300

Media introduced into a classified information system becomes classified unless this type of AO-approved mechanism is used.

What is a write-protection mechanism?

300

IT Specialists should consult with these individuals when identifying and applying OPSEC countermeasures.

Who are OPSEC Program Managers (PMs) or coordinators?

300

 Data that is stored on a hard drive or other electronic media is referred to by this three-letter acronym.

 What is DAR (Data at Rest)?

300

Commands must migrate to the next major version of an OSS product within this timeframe after its official release date.

What is 12 months?

400

A user authorized to perform security-relevant functions that ordinary users cannot, such as a system administrator or Information Assurance Officer.

What is a Privileged User?

400

 For a laptop enabled for telework, capabilities like cameras, microphones, and Wi-Fi must be disabled before it is returned to this type of space.

What is a classified space?

400

A process of identifying critical information and analyzing friendly actions to see what can be observed and exploited by adversary intelligence systems.

 What is the OPSEC process?

400

This acronym refers to a security directive that may order commands to stop using specific software versions due to a critical vulnerability.

What is an IAVM (Information Assurance Vulnerability Management)?

400

If a command needs to continue using software that has a CAT 1 IAVM directive against it, it must request and receive an approved one of these within 30 days.

What is a waiver or exception?

500

According to the manual, this is a Federal Information Security Modernization Act (FISMA) management tool used for tracking and mitigating cybersecurity weaknesses.

What is a Plan of Actions and Milestones (POA&M)?

500

Introducing government or personal mobile devices into areas where classified information is processed is prohibited without approval from the responsible AO, the CSA, and this specific technical authority for emissions security.

What is the Certified TEMPEST Technical Authority (CTTA)?

500

The Deputy Under Secretary of the Navy (DUSN) is the lead for this across the Department of the Navy.

What is OPSEC oversight, management, readiness, and compliance?

500

This system, known by its acronym DADMS, is where all DON applications must be registered.

What is the Department of the Navy Applications and Database Management System?

500

This is the broad term for the combination of policies, processes, and standards that enable the DON to manage digital identities and authorize access to resources.

What is Identity, Credential, and Access Management (ICAM)?