 |
 |
 |
 |
| This is a 3 day course that will be held June 2-4, 2010. The instructor will be determined at a later date. The CNSS 3 Day In-Depth C&A Course provides an overview of the C&A process and implementing the Risk Management Framework (RFM) for National Security Systems (NSS). This course will provide a complete overview and scenario based hands-on exercises of the RFM to provide a clear knowledge bridge for those currently working with DCID 6/3 or those whom have no C&A experience, per National Security Directive 42 (NSD-42), which outlines the roles and responsibilities for securing NSSs. |
|
 |
 |
|
 |
 |
 |
 |
 |
Features
- Day 1:
- Intro and Ground Rules
- C&A Overview
- C&A Transformation Overview
- Guide for Security Authorization of Federal Information Systems: NIST SP 800-37
- Guide for Security Authorization of Federal Information Systems: The Fundamentals
- Day 2:
- Roles and Responsibilities
- Accreditation Boundary
- System Categorization: CNSSI 1199/FIPS 199
- Risk Management Framework
- Day 3:
- Risk Management Framework Cont’d.
- Security Controls Overview
- Documentation Overview
- Documentation: SAR and POA&M
- Reciprocity
- Hands-On Exercise
- LAWS, DIRECTIVES, INSTRUCTIONS, STANDARDS, AND PUBLICATIONS COVERED:
- Intelligence Community Directive (ICD) 503
- The Risk Management Framework (RMF)
- CNSS 1253 (Overview Until Final Draft is published)
- CNSS 1199 (Overview Until Final Draft is published)
- Federal Information Processing Standard (FIPS) 199
- Federal Information Processing Standard (FIPS) 200
- Federal Information Processing Standard (FIPS) 140-2
- NIST SP 800-53A Guide for Assessing the Security Controls in Federal Information Systems
- NIST SP 800-115 Technical Guide to Information Security Testing and Assessment
- NIST SP 800-53 Recommended Security Controls for Federal Information Systems
- NIST SP 800-39 Managing Risk for Information Systems
- NIST SP 800-34 Contingency Planning Guide for Information Technology Systems
- NIST SP 800-30 Risk Management Guide for Information Technology Systems
- Intelligence Community (IC) Systems Security Plan
- Intelligence Community (IC) Security Assessment Report (SAR)
- Intelligence Community (IC) Plan Of Action and Milestones (POA&M)
|
|
 |
 |
 |
 |
|
 |

|