Book 2 Flashcards
NCDOC Platform Specific
State the function of JTF-GNO and discuss their relationship with NNWC
Plans, coordinates, integrates, synchronizes, and conducts activities to direct the operations and defense of specified DoD information networks. USCYBERCOM issues Orders & Directives to DoD and NNWC pushes them out to the Navy
Who is currently designated as the Navy’s Level 2 accredited CNDSP?
NCDOC
State who JTF-GNO reports to directly:
USSTRATCOM
Explain what a CNDS Certification Authority (CNDS/CA) is.
Responsible for CNDSP Accreditation
Explain who the central manager for all DoD Enterprise incident sets is.
DISA
State who the Area Coordinators are for NCDOC and NNWC.
SWO, BWC, and DCOWO
State who has TACON of NCDOC watch floor personnel and is responsible directly to the Commanding Officer, Operations Officer, and the Commander USSTRATCOM, via the JTF-GNO Network Defense Watch Officer.
Commanding Officer of 10th Fleet
Name the DoD agency that is tasked with handling Electronic Spillage issues and incidents.
NCDOC/NNWC
In the event of Electronic Spillage originating at NCDOC, list the personnel or agencies that should be contacted in order.
NCDOC watch standers create ticket. ISSM and SSO is informed.
State who has tactical control over NCDOC and NNWC:
10th Fleet
JTF-GNO is dual-hatted IRT CND operations at NCDOC and NNWC. Explain what these two positions are.
CO is commander of NCDOC and CTF 1020 (NIOCS, NCTAMS, etc.)
State who, by direction of the Operations Officer, is responsible to the Commanding Officer for the assignment and general supervision of all NCDOC watch standers.
SWO (Senior Watch Officer)
List the duties and responsibilities of the Senior Watch Officer (SWO)
Manning of the watch, delegate tasks to DCOWO, as well as liaise with BWC from NNWC.
Define Computer Network Attack (CNA).
Operations to disrupt, deny, degrade, or destroy information resident on computers and computer networks or the computers and networks themselves
Explain the standard reporting procedures for reporting a computer network incident
Depends on the type of incident as to overall mitigation, however, CER is created, analysis is conducted of activity, PCAP is pulled as necessary, and upon QC, an NCD is created and passed to Incident Handling to be communicated to site for remediation
Define deconfliction as it applies to CND operations
Deconfliction is the communication that occurs between NCDOC and satellite locations (other NIOCs, EDU sites, etc.) to ensure that duplicate efforts are eliminated.
Define Incident Handling as it applies to Computer Network Operations (CNO).
Provides CND with the following:
1. Protect
2. Monitor, analyze, and detect
3. Respond
List the four phases of CNDS Certification and Accreditation:
Phase 1
Registration: initiates the CNDS C&A process
List the four phases of CNDS Certification and Accreditation:
Phase 2
Verification: includes activities related to the on-site C&A evaluation.
List the four phases of CNDS Certification and Accreditation:
Phase 3
Validation: the evaluation team prepares a Deficiency Report and a Certification Report for CNDSICA review.
List the four phases of CNDS Certification and Accreditation:
Phase 4
Post Accreditation: includes activities by the Provider to maintain C&A status, monitor changes to the CNDS mission, and prepare and apply for recertification.
State what the Commander’s Critical Information Requirements (CCIR) identify
Identify events that require immediate or time-sensitive reporting or notification
State what a NAR is, and name what department creates and maintains them.
Network Analysis Report, Threat Analysis is typically tasked with their creation and maintenance.
List the four steps in creating a Network Analysts Report
- Assessment
- Research
- Analysis
- Reporting
Explain what a Cyber Alert is (CA).
Provides initial analysis of unusual activity, threats, or mass malware outbreaks on the Navy Network. This type of report serves as a time sensitive notification for mitigation of potential threats, and may include preliminary, unfinished assessments.