1
Certification and Standards for Army Blue Teams
Sharmila B. Vaswani-Bowles - Cyber Acquisition Blue Team (CABT) Management Office Lead Rolando Lopez - Lead Computer Engineer
Ensuring Cyber Resiliency In All Phases of Acquisition
Blue Teams Sharmila B. Vaswani-Bowles - Cyber Acquisition Blue Team - - PowerPoint PPT Presentation
Certification and Standards for Army Blue Teams Sharmila B. Vaswani-Bowles - Cyber Acquisition Blue Team (CABT) Management Office Lead Ensuring Cyber Resiliency In All Phases of Acquisition Rolando Lopez - Lead Computer Engineer 1 The
1
Ensuring Cyber Resiliency In All Phases of Acquisition
2
3
4
5
Source: CNSSI 4009, “Committee on National Security Systems (CNSS) Glossary,” APR 2015
6
General Cybersecurity Information to PM’s Cyber Blue Team Events
Vulnerability
assessments
Formal and
informal testing
Present PM with
mitigation options
Provide PM with
solid information to assess risk Central Vulnerability Aggregation & Analysis
Vulnerabilities
centrally collected and analyzed
Identify trends
and lessons learned
Pulled from
programs across the Army in addition to public and Intel sources Assistance Early in Acquisition Lifecycle
Incorporate
cybersecurity in program plans and documents
Assist with
contract language
Cyber Tabletop
facilitation and participation
Advise on supply
chain risks
Cyber SMEs
habitually aligned, always on call
Advise and
assist throughout the entire lifecycle
Can apply
lessons learned from entire Blue Team community Information Sharing & Cyber Trends Reporting
Trends and lessons
learned reporting
Information on Blue
Team capabilities
Readily and easily
available to PMs/ PEOs
Sharing of tools,
TTPs, SOPs, etc.
SME: Subject Matter Expert TTP: Tactics, Techniques and Procedures SOP: Standing Operating Procedures
7
INFOR INFORM ENABLE CE CERTIFY TIFY POL OLICY ICY & & DOC OCTRINE INE
Certification & Standards Manual Evaluator Scoring Metrics Guidebooks, Handbooks, and SOPs Certification Evaluation Teams CABT Certification Events Re-Certifications, Spot Checks & Revocations Facilitate Sharing of Information, Tools, TTPs, SOPs, Best Practices, etc. Quarterly Trends Reporting to ASA(ALT) Gather Data, Synthesize Lessons Learned, Educate and Connect PMs, CABTs CABT Portal, Lessons Learned Repository, C3D, etc.
8
Blue Team Candidate Organization Certified CABTs NSA-Certified Red Teams CABT Management Office
PREPARATION APPLICATION VERIFICATION VALIDATION POST-CERTIFICATION
facilities and admin support
necessary
evaluation
evaluation
access to facilities
interviews and demonstrations
uncorrected deficiencies
needed
signed by the Certifying Official
processes, standards, and systems
examples
clarification
review application package
issues
with team and candidate
In-brief, interviews, analysis, completion of scoring matrix, spot corrections, and out-brief
review POA&M
memorandum to Certifying Authority
memo to candidate, keep copies
adherence to standards
years
lessons learned, ride-alongs, documents, etc.
Certification Evaluation Team as needed
Certification Evaluation Team as needed
regarding open network activities
lessons learned, ride-alongs, documents, etc.
Certification Evaluation Team as needed
Certification Evaluation Team as needed
Learned process
tools w/community
CERTIFIED
9
10
11
12
15
Source: CNSSI 4009, “Committee on National Security Systems (CNSS) Glossary,” APR 2015
16
17
18
19
20