Annex H22 IA Vulnerability Management Flashcards

0
Q

Three (3) functions of the IAVM Program

A

IA Vulnerability alert (vulnerability is severe, compulsory)

IA Vulnerability bulletin (vulnerability does not pose immediate risk)

Technical Advisory (vulnerability generally categorized as low risk)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
1
Q

IA Vulnerability Management Program (IAVM)

A

Provide management over mitigating vulnerabilities that are found in DoD info systems
Identifying and correcting vulnerabilities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Eight (8) steps associated with the Marine Corps IAVM

A

1: DISA identifies vulnerabilities of significance to the DoD and reports them to the JTF-GNO
2: The MCNOSC acknowledges receipt of IAVA and IAVB within 5 working days to JTF-GNO
3: The MCNOSC will issue IAVM messages, which will be tailored to the specific info tech environment of the USMC
4: Configuration Control Authorities (Program Offices) issue approval to apply IAVM corrective actions to Centrally Managed Systems
5: Implementation of IAVM message corrective actions
6: Reporting of IAVM compliance is a third echelon reporting responsibility for USMC assets in NMCI AOR, non NMCI managed assets and deployed networks
7: Compliance verification: The MCNOSC will validate MCEN compliance via vulnerability analysis tools and report these results to the USMC DAA
8: The MCNOSC will compile and submit an aggregated service component report of IAVM compliance and extensions to JTF GNO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly