DOD 8570.01-M (WITH CHANGE-3), INFORMATION ASSURANCE WORKFORCE IMPROVEMENT PROGRAM Flashcards

1
Q

Who is responsible for developing, coordinating, and publishing baseline certification requirements for personnel who perform specialized IA functions?

A

ASD (NII)/DoD CIO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How often at a minimum must the IA WIPAC meet?

A

Annually

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which office provides oversight to the IA WIPAC and IA baseline certification approval process?

A

Defense-wide Information Assurance Program (DIAP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Who is required to serve as the DoD Shared Service Center (SSC) for the Office of Management and Budget (OMB)-directed Information System Security Line of Business (ISS LoB) for Tier I Awareness training?

A

Director of the Defense Information Systems Agency (DISA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What manages the certification testing process requirement for the Department?

A

DANTES

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

The heads of the DoD Components must provide for the initial IA orientation and annual awareness training to all authorized users to ensure they know, understand, and can apply the IA requirements of their system(s) in accordance with which reference?

A

DoD Directive 8570.1

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

The heads of the DoD Components must obtain the appropriate background investigation per which reference prior to granting unsupervised privileged access or management responsibilities to any DoD system?

A

DoD Instruction 8500.2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which training requirements must the heads of the DoD components ensure are met for personnel who perform IA functions on national security systems?

A

Committee on National Security Systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which functions focus on the development, operation, management, and enforcement of security capabilities for systems and networks?

A

Information Assurance (IA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

IA measures protect and defend information and information systems by ensuring their availability, integrity, authentication, confidentiality, along with what else?

A

Non-repudiation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What must be completed by personnel who hold privileged access?

A

Privileged Access Agreement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Personnel performing IA duties assess and implement identified corrections associated with technical vulnerabilities as part of which program?

A

Information Assurance Vulnerability Management (IAVM)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are intended to produce IA personnel with a baseline understanding of the fundamental IA principles and practices related to the functions of their assigned position?

A

IA certification programs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

DoD Components must use certifications approved by which office to meet the minimum IA baseline certification requirement?

A

ASD(NII)/DoD CIO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What provides DoD IA policy, training requirements, and DoD sponsored training to support IA professionals?

A

DoD IA Portal

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Personnel IA certification status and renewal rates are management review items according to which reference?

A

DoD Instruction 8500.2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Within how many months of IA duty assignments must all military and Government civilian IAT personnel achieve the appropriate IA certification unless a waiver is granted?

A

6

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

How many years from the effective date of DoD 8570.01-M to DoD employees and contractors who perform IA functions have to comply with certification requirements?

A

4 (page 22)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What is the minimum certification level that is required prior to IA Managers authorizing unsupervised privileged access for personnel performing IAT Levels I through III functions?

A

IAT Level I

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What is the maximum time that Designated Accrediting Authorities (DAAs) can issue certification requirement waivers for severe operational or personnel constraints?

A

6 months

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Personnel who are not appropriately qualified within how many months of assignment to a position or who fail to maintain their certification status shall not be permitted privileged access?

A

6

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Which positions are not authorized to be held by LNs or Foreign Nationals (FNs)?

A

IAT Level III

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Which personnel provide Network Environment (NE) and advancement level CE support?

A

IAT Level II

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

How many years of experience do IAT Level II personnel typically have in IA technology or a related area?

A

3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Which personnel focus on the enclave environment and support, monitor, test, and troubleshoot hardware and software IA problems pertaining to the CE, NE, and enclave environments?

A

IAT Level III

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

How many years of experience do IAT Level III personnel typically have in IA technology or a related area?

A

7

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

Within how many months of assignment of IA duties must management category military and Government civilian personnel achieve the appropriate IA baseline certification for their level?

A

6

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

DAAs may waive certification requirements under severe operational or personnel constraints for a maximum of how many months?

A

6

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

Personnel in management category positions will retain an appointing letter assigning them IA responsibilities for their systems per which reference?

A

DoD Instruction 8500.2

30
Q

Which IAM positions may not be assigned to LNs or FNs?

A

IAM Level III

31
Q

Which personnel are responsible for the implementation and operation of a DoD IS or system DoD Component within their CE?

A

IAM Level I

32
Q

Which personnel are responsible for the IA program of an IS within the NE?

A

IAM Level II

33
Q

How many years of management experience do IAM Level II’s usually have?

A

5

34
Q

Which personnel are responsible for ensuring all enclave IS are functional and secure?

A

IAM Level III

35
Q

How many years of management experience do IAM Level III’s usually have?

A

10

36
Q

Which reference directs that a DAA be appointed for each DoD information system operating within, or on behalf of, the Department of Defense?

A

DoD Directive 8500.1 (page 41)

37
Q

Who is the official that has the authority to formally assume responsibility for operating a system at an acceptable level of risk?

A

DAA (page 41)

38
Q

Each assigned DAA must complete the DoD DAA CBT or WBT product within how many days assignment to the position?

A

60

39
Q

How often must each assigned DAA recertify in the DISA DAA Certification course?

A

Every 3 years (page 43)

40
Q

Who is the first and most vital line of defense for securing DoD information and systems?

A

User

41
Q

Which CBT presented by DISA meets all DoD level requirements for end user awareness training?

A

DoD IA Awareness

42
Q

What are the DoD Components required to use as their IA Awareness Provider?

A

DoD SSC

43
Q

How often must personnel take IA awareness refresher training to retain access?

A

Annually

44
Q

IA workforce data elements must comply with requirements established in which reference?

A

DoD Instruction 8500.2

45
Q

All positions in the 2210 or other civilian IA job series must comply with what guidance on standardized titling?

A

Office of Personnel Management (OPM)

46
Q

What must be used as the Position Specialty Code (PSC) in the Defense Civilian Personnel Data System for all DoD civilian positions and personnel with IA functions regardless of OPM series or job title?

A

INFOSEC

47
Q

What allows identification of a DoD civilian position with IA functions regardless of OPM series or job title?

A

Position Specialty Code (PSC)

48
Q

What is used to consolidate IA qualification and workforce management reporting requirements?

A

IA WIP Annual Report

49
Q

Who coordinates IA Training and Certification Program requirements?

A

ASD(NII)/DoD CIO

50
Q

What includes all individuals working for the Department of Defense in a foreign country who are nationals or non U.S. residents of that country?

A

LN

51
Q

Within how many months of assignment of IA duties must IASAE specialty military and Government civilian personnel achieve the appropriate IA baseline certification for their level?

A

6

52
Q

How many years after the effective date of DoD 8570.01-M do DoD employees and contractors performing IA fucntions have to comply with the certification requirements?

A

4

53
Q

Waivers issued by DAAs to waive certification requirements when there are severe operational personnel constraints cannot be extended beyond how many months?

A

6

54
Q

Personnel in IASAE specialty positions will retain an appointing letter assigning them IA responsibilities for their system(s) in accordance with which reference?

A

DoD Instruction 8500.2

55
Q

Which positions may not be held by LNs or FNs?

A

IASAE Level III

56
Q

How many years of experience do IASAE Level II personnel usually have?

A

5

57
Q

Which positions are responsible for the design, development, implementation, and/or integration of a DoD IA architecture, system, or system component for use within the CE, NE, and enclave environments?

A

IASE Level III

58
Q

Which personnel are responsible for the design, development, implementation, and/or integration of a DoD IA architecture, system, or system component for use within their CE?

A

IASAE Level I

59
Q

Which personnel are responsible for the design, development, implementation, and/or integration of a DoD IA architecture, system, or system component for use within the NE?

A

IASAE Level II

60
Q

How many years of experience do IASAE Level III personnel usually have?

A

10

61
Q

What is the normal sustainment training/continuing education required over 3 years to maintain certification status for planning purposes?

A

120 hours

62
Q

Within how many months of assignment to an accredited CND-SP position must all CND-SP specialty military and government civilian personnel achieve the appropriate CND certification?

A

6

63
Q

What has the authority to waive certification requirements under severe operational or personnel constraints?

A

USSTRATCOM

64
Q

Which personnel use collected data from a variety of CND tools to analyze events that occur within their environment?

A

CND-A

65
Q

How many years of minimum experience in CND technology or a related field is recommended for CND-A personnel?

A

2

66
Q

Which personnel test, implement, deploy, maintain, and administer infrastructure systems?

A

CND-IS

67
Q

How many years of minimum experience in supporting CND and/or network systems and technology is recommended for CND-IS personnel?

A

4

68
Q

Who do CND-IS personnel work under and typically report to?

A

CND-SPM

69
Q

Which personnel investigate and analyze all response activities related to cyber incidents within the NE or Enclave?

A

CND-IR

70
Q

How many years of minimum experience in the CND technology or a related field is recommended for CND-IR personnel?

A

5

71
Q

Which personnel perform assessments of systems and networks within NE or enclave and identify where those systems/networks deviate from acceptable configurations, enclave policy, or local policy?

A

CND-AU

72
Q

Which personnel are responsible for producing guidance for their NE or enclave, assisting with risk assessments and risk management for organizations within their NE or enclave, and are responsible for managing the technical classifications within their organization?

A

CND-SPM