|
|
Posted 10/23/2007 11:01:56 AM |
|
|
Supreme Being
      
Group: Administrators
Last Login: 7/22/2010 5:24:49 PM
Posts: 289,
Visits: 657
|
|
| Attached are the templates that we use for our DIACAP Services division. We created the templates to fill the void created by the lack of guidance on how to "prove" compliance with the DoDI 8500.2 IA Controls. The Artifact outlines map back to the 8500.2 IA Controls and provide documented traceability to show that the IA Control is met. We are sure that there will be questions about the how and why we did things, so please post comments/suggestions. The attached are sanitized samples from one of our previous engagements and while not the all encompassing end deliverable, they should provide a good starting point. We are offering these up, at no charge, to try and help with what it really means to be DIACAP compliant. Our goal is to move the focus of IA into implementation and execution, not C&A automated tools or documentation circles. Like any template or automated tool, the information is only as good as the person writing it. The templates do not cure cancer, guarantee success or enable you to just paste in your system name--they give you a starting point. Once we are finished posting our internal library, there should be no reason to spend money on automated solutions to produce C&A documentation, thus enabling you to spend your limited IA dollars more wisely by focusing on engineering secure and compliant solutions. And of course, one caveat: -Government Personnel, defined as Civil Service and Military personnel: Use, abuse and change the templates as much as you see fit. You are more than welcome to remove the "Template Developed by I-Assure, http://www.i-assure.com" text on the front page--but of course, it would be nice if you keep it . -Contractors, defined as anyone not in the above category, that plans on using our templates to support their contracts with the Government: Modify the templates as you see fit, but you are required to keep the "Template Developed by I-Assure, http://www.i-assure.com" text on the front page. NOTE: The below IA Controls are not present in the attached Artifacts DCAR-1 ECDC-1 ECML-1 ECND-1, ECND-2 PEDD-1
|
|
|
|
Posted 10/31/2007 6:18:19 AM |
|
|
Forum Newbie
      
Group: Forum Members
Last Login: 5/22/2008 11:36:13 AM
Posts: 1,
Visits: 29
|
|
| Heroes. That's what you are.
|
|
|
|
Posted 11/1/2007 6:45:10 AM |
|
|
Forum Newbie
      
Group: Forum Members
Last Login: 11/1/2007 11:00:23 AM
Posts: 1,
Visits: 8
|
|
| Are these all the controls? For example, there are different controls for Mac III Public vs Mac I Classified. I am wanting to write documentation that will cover us no matter the MAC or Classification.
|
|
|
|
Posted 11/1/2007 7:11:06 AM |
|
|
Forum Newbie
      
Group: Forum Members
Last Login: 12/18/2008 2:59:46 PM
Posts: 5,
Visits: 63
|
|
Just saying thank you doesn't seem like enough!! How about ... YOU ROCK!
Melinda Rentz
|
|
|
|
Posted 11/2/2007 8:32:57 AM |
|
|
Supreme Being
      
Group: Administrators
Last Login: 7/22/2010 5:24:49 PM
Posts: 289,
Visits: 657
|
|
| Yes, the contain mapping to all controls. When you finalize the templates to your specific situation, can remove the IA Control mapping in the content pages.
|
|
|
|