COMNAVCYBERFORINST 5239.1, INFORMATION ASSURANCE WORKFORCE IMPROVEMENT PROGRAM (IA WIP) Flashcards
Which instruction sets forth the requirements and procedures for Navy commands to professionalize and develop the Navy Information Assurance Workforce (IAWF)
COMNAVCYBERFORINST 5239.1
Which approach is taken by the DoD in relation to Information Assurance (IA)?
Defense in Depth
What is responsible for overseeing and verifying compliance with government IT security regulations and the Department of Defense (DoD) IA policy as it pertains to people?
NAVCYBERFOR
What percent of Echelon II Command Information Officers (CIOs) subordinate commands must be inspected on an annual basis to ensure IA WIP compliance?
5%
How many working days after the inspection outbrief must Echelon II Command Information Officers (CIOs) forward the results of all IA WIP inspections to CYBERFOR?
10
How many guiding principles support the Navy’s IAWF strategy?
5
Where must standardized IAWF Mission Essential Tasks Lists (METLs) and readiness assessments be documented for use by the Fleet and Operating Force?
Defense Readiness Reporting System (DRRS)
Which functions focus on the development, accreditation, operation, management, and enforcement of security capabilities for systems and networks?
IAWF
Who is the official that formally assumes responsibility for operating a system at an acceptable level of risk?
Designated Accrediting Authority (DAA)
Which civilian series is normally held by the DAA at the GS 14/15 level?
2210
Who is the person within a headquarters, acquisition, site, system, etc… who owns the business process and controls funding for the system?
IA Program Manager (IAPM)
Which level must IAPMs be commercially certified up to?
IAM Level III
Which personnel are responsible for the implementation and operation of a DoD Information System (IS) within their environment, enclave, network, or individual computing system level?
IA Manager (IAM)
Which IAM training level are Network Level IAM positions required to train up to?
II
What is the only IAM job that may be carried out on a collateral duty basis?
Level I IAM
The functions of Level I IAMs may be carried out by a higher level authority if the command manpower/personnel structure is less than how many employees?
25
Which personnel are responsible for the maintenance, defense and operation of DoD IS within their environment, enclave, network, or individual computing system level?
Information Assurance Technical (IAT)
Which personnel are responsible to an IAM for ensuring the appropriate operational IA posture is maintained for command, organization, site, or system?
IA Officers (IAOs)
A contractor may not hold the IAO position for which environment level?
III
During what process are tasks required to analyze, assess, and document IA capabilities and services of DoD Information Systems to establish compliance with IA requirements, identify vulnerabilities, and quantify risk?
Certification and Accreditation
Who acts as the accreditation representative on the local level and approves all C&A packages that go to the DAA?
Certification Authority Representative (CAR)
Who is the official responsible for performing the comprehensive evaluation of the technical and non-technical security features and safeguards of an IT system, application, or network?
Certification Authority (CA)
Which individual is responsible for overseeing the site accreditation package or process?
Certification Agent
Which individual is responsible for assisting in preparation of the site accreditation package?
Validator
Which personnel use data collected from a variety of CND tools to analyze events?
CND-A
Which personnel test, implement, deploy, maintain, and administer the infrastructure systems that manage the CND-SP network?
CND Infrastructure Support (CND-IS)
Which personnel investigate and analyze activities related to cyber incidents within the NE or enclave?
CND Incident Responder (CND-IR)
Which personnel assess systems and networks within the NE or enclave and identify deviations from acceptable configurations or policy?
CND Auditor (CND-AU)
Who provides Enterprise policy for civilian personnel?
Assistant Secretary of the Navy for Manpower and Reserve Affairs (ASN M&RA)
Civilian personnel managers and supervisors must ensure that the Commanding Officer’s appointment letter states that a commercial certification is required to meet the requirements of which publication?
DoD 8570.01-M
How many months do IA professionals have to meet commercial certification requirements after they have been hired before being transferred to a job that doesn’t require them?
6
What provides oversight to IAWF with special focus on education and training?
CYBERFOR
What was established to set standards for National Security Systems?
Committee for National Security Standards (CNSS)