DODI 8500.01, Encl. 3 Flashcards
Which program ensures that IT can be used in a way that allows mission owners and operators to have
confidence in the confidentiality, integrity, and availability of IT and DoD information, and to make
choices based on that confidence?
Defense cyber security
What is used by the DoD to address risk management for all DoD ISs and PIT systems?
NIST SP 800-37
From which perspective does tier one risk management address risk?
Organizational
What provides the Tier 1 risk management governance for the DoD?
DOD ISRMC
Which risk management tier addresses risk from a mission and business process perspective?
Tier 2
Which risk management tier addresses risk from an IS and PIT system perspective?
Tier 3
Cybersecurity risk management is planned for and documented in a cybersecurity strategy in accordance with Interim DoD Instruction 5000.02 along with which other reference?
DOD Instruction 8580.1
What provides a disciplined and structured process that combines IS security and risk management
activities into the system development life cycle and authorizes their use within the DoD?
Risk Management Framework (RMF)
How many steps does the Risk Management Framework (RMF) have?
6
The reciprocal acceptance of DoD and other federal agency and department security authorizations will
be implemented in accordance with procedures in which reference?
DoD Instruction 8510.01
- How many conditions must be met for operational resilience?
3
Transmission of DoD information must be protected through the communications security (COMSEC)
measures and procedures established in which reference?
DoDI 8523.01
COMSEC monitoring and cybersecurity readiness testing will be conducted in accordance with which
reference?
DoD Instruction 8560.01
Which type of model provides people, services, and platforms the ability to discover one another and
connect to form new capabilities or teams without being constrained by geographic, organizational, or technical barriers?
Net-centric
What coordinates and facilitates relationships across LE, intelligence, and homeland security
communities?
DoD Cyber Crime Center
What is used to ensure strong identification and authentication as well as eliminates anonymity in DoD
ISs so that entities’ access and access behavior are visible, traceable, and enable continuous monitoring for
LE and cybersecurity?
Identity assurance
Which instruction contains identity assurance policies and procedures regarding identity authentication
for ISs?
DoD Instruction 8520.03
What provide standard cybersecurity, such as boundary defense, incident detection, and response, and
key management as well as delivering common applications such as office automation and e-mail?
Enclaves
Where must all DoD ISs be registered on the low side?
DITPR
Which reference should be consulted for PIT cybersecurity requirements?
DoD Instruction 8510.01
Which DoD level must all PIT systems be registered?
Component
What consists of IT capabilities that are provided according to a formal agreement between DoD
entities or between DoD and an entity external to DoD?
IT Service
Unified capability products will receive unified capability certification for cybersecurity in accordance
with which reference?
DoD Instruction 8100.04
All acquisitions of DoD IS will comply with USD(AT&L) Memorandum along with which other reference?
DoD Instruction 8580.1
Which reference will ports, protocols, and services be managed in accordance with?
DoD Instruction 8551.1
Who is responsible for configuring and reviewing the security for IT below the system level for
acceptance and connection into an authorized computing environment?
ISSM
Who will oversee the development and acquisition of enterprise solutions for use throughout the DoD
that support cybersecurity objectives?
ESSG
Which TPM version or higher if required by DISA STIGs must DoD components ensure that new
computer assets procured to support DoD meet?
1.2
Which standards will be used by STIGs developed by DISA?
SCAP
Who ensures that DoD IT is assigned to and governed by a DoD Component cybersecurity program?
DoD SISO
Who performs the DoD risk executive function?
DoD ISRMC
Who are responsible for overseeing and establishing guidance for the strategic implementation of
cybersecurity and risk management within their MAs?
PAOs
Who render authorization decisions for DoD ISs and PIT systems under their purview in accordance
with DoD Instruction 8510.01?
AOs
Who are responsible for developing and maintaining an organizational or system-level cybersecurity
program?
ISSMs
In accordance with which reference must ISSMs ensure that the handling of possible or actual data spills of classified information are handled with?
DoD Manual 5200.01
Who is responsible for implementing and enforcing all DoD IS and PIT system cybersecurity policies
and procedures as defined by cybersecurity-related documentation?
ISSO
Authorized users must meet the minimum cybersecurity awareness requirements in accordance with
which reference?
DoD 8570.01-M