SECNAVINST 5239.3B, DON IA POLICY Flashcards
Measures that protect and defend information and information systems by ensuring their availability, integrity, authentication, confidentiality, and non-repudiation.
INFORMATION ASSURANCE
Who must complete DoD IA approved training as a condition of access?
All authorized users of DON Information Systems
Who must control remote access to DON information systems and networks?
Commanders of DON organizations
What is the primary method for remote client-side authentication?
DoD PKI certificates, protected by a hardware token, such as the CAC
All computers used for remote access must have what approved protection including automated updates?
DoD approved antivirus and firewall protection
Who will centrally manage and monitor DON IDS/IPS systems?
Navy Cyber Defense Operations Command(NCDOC) and Marine Corps Network Operations and Security
Center(MCNOSC)
Unless otherwise superseded by another SSIC, how long shall DON network audit records shall be retained for how long?
1 year (12 mos)
What is the preferred method to ensure confidentiality and integrity of remote connections?
Virtual Private Networks(VPNs)
All remote access to DON classified systems or networks shall utilize what approved COMSEC and keying material?
NSA-approved
What is the primary identity credential support interoperable physical access to DON installations, facilities, buildings, and controlled spaces, and logon access to all unclassified DON networks?
Common access card(CAC)
All e-mail containing an attachment or embedded active content must contain what?
Digital Signature
How often shall a Contingency Plan be exercised?
Annually
What process is designed to provide positive control of the vulnerability notification and corrective action process in the DoD?
Information Assurance Vulnerability Management(IAVM)
How often shall all information systems must undergo information security reviews ?
Annually
What is the ability to maintain the confidentiality and integrity of DON classified information and unclassified information that has not been approved for public release?
Communications Security (COMSEC)