|
|
Chapter Twenty: Risk Management Security Policy
20. CHAPTER TWENTY: RISK MANAGEMENT SECURITY POLICY
a. General Policy Statement
Protection of information assets and maintaining the confidentiality, integrity, and availability of
USDA Office of the Chief Information Officer (OCIO), Information Technology Services (ITS)
information technology assets and telecommunications resources are vital in meeting the USDA’s
overall program delivery requirements. Implementation of security measures such as a risk
management program, effective security controls, certification and accreditation of information
systems, and updated security plans are vital components.
b. Policy Detail
The OCIO-ITS will perform formal Risk Assessments (RA) of all IT systems. RAs will be
conducted using the same processes and procedures as defined in the DM3540-000 Risk
Management Program, dated August 19, 2004, inclusive of Table 1: USDA Risk Assessment
Methodology dated, dated February 11, 2003, or their replacements. Risk assessments typically
identify risks that a system could be affected by. Risk mitigation plans are required as a follow-
up document to an RA.
A formal system risk analysis is required every three years or when a major change is made in a
General Support System (GSS) or Major Application (MA). Major changes are defined as
modifications to the system that affect the security controls and which render the system
vulnerable to compromise or intrusion. Waiver requests will be considered for extensions in
compliance time only; all IT systems will undergo regular risk assessments. The OCIO-ITS will
include the cost for IT system mitigations in budgetary planning and prepare a business case to
ensure that funding is available to implement protection against identified vulnerabilities.
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 70
Number 3602-001
FOR OFFICIAL USE ONLY
Chapter Twenty-One: Router and Switch Management Security Policy
21. CHAPTER TWENTY-ONE: ROUTER AND SWITCH MANAGEMENT
SECURITY POLICY
a.
General Policy Statement
This policy establishes requirements for access to USDA Office of the Chief Information Officer
(OCIO), Information Technology Services (ITS) router and switch resources. These
environments shall require authorization and access control through the use of individual
credentials as outlined in Chapter 3: Authorization and Access Control Security Policy or its
replacement. Where possible, the Terminal Access Controller Access System (TACAS+) is to be
used for authentication. Additionally, the use of local system accounts shall be limited and used
on an exception basis.
b.
Policy Detail
(1).
Router and Switch Configuration
(a).
Configuration standards and management procedures shall be used to control usability,
efficiency, and security of the overall router and switch environment, and shall be kept
in a Trusted Facility Manual (TFM) in accordance with Chapter 5: Certification and
Accreditation Security Policy or its replacement. These standards and other procedures
shall be followed when designing, implementing, or managing router and switch
configurations. Written approval from the Change Control Board (CCB) is required to
deviate from these standards.
(b).
The following shall be disallowed on all routers and switches:
1. IP direct Broadcasts
2. Incoming packets with invalid source address.
3. TCP and UDP small servers
4. Router web services
(c).
All routers and switches shall use Access Control Lists (ACL) to only permit traffic that
has a recognizable business need.
(d).
Traffic shall be denied unless permitted.
(e).
All security related service packs, patches, and hot-fixes shall be tested and applied to
all routers and switches in a timely manner.
(f).
All routers and switches must present and display a warning banner in accordance with
Chapter 14: Network Access Security Policy or its replacement.
(g).
All back-up media shall be kept in a secured manner consistent with Chapter 17:
Physical Access Security Policy, or its replacement, and be protected by a password.
(h).
A selected portion of backup media shall be kept in an alternate physical location and
shall be secured in a manner consistent with Chapter 17: Physical Access Security
Policy or its replacement.
(i).
The Administrator/Root Account is the original administrative account of the router and
switch. This account shall be renamed and used only on a limited or emergency basis.
Only select administrative personnel shall have knowledge of these account credentials,
which must be stored in a locked environment.
(2).
Router and Switch Management
(a). All routers and switches shall be physically secured in accordance with Chapter 17:
Physical Access Security Policy or its replacement.
(b). All routers and switches shall be backed up in a manner that permits a complete
recovery of routers and switches on a weekly basis. Archives of router and switch
backups shall be maintained until no longer required by management.
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 71
Number 3602-001
FOR OFFICIAL USE ONLY
Chapter Twenty-One: Router and Switch Management Security Policy
(c). Any prolonged or delayed application of a security-related service pack, patch, or hot-
fix shall be documented and an application for a wavier to this policy must be applied
for.
(3).
Router and Switch Management Access
(a). Access to router and switch consoles and operating systems shall be limited to network
administrator personnel only. All router and switch user accounts shall comply with
password requirements in accordance with Chapter 3: Authorization and Access
Control Security Policy or its replacement.
(b). Permitted access shall be limited to only essential users and service accounts.
(c). Only one person shall have access to one user account - that is, more than one person
shall not have access to the same account.
(d). All network administrators shall receive the appropriate level of training to perform
their duties in a competent manner.
(4).
Router and Switch Information Access
Access to router and switch information shall be restricted to the network administrator,
CCB, OCIO-ITS Information Systems Security Program Manager (ISSPM) or designated
representative, and/or persons with written permission from the CCB or ISSPM. Restricted
information shall minimally include documents, details, drawings, diagrams, or screen prints
containing any information regarding router and switch configurations, installed
applications, data storage, scripts, pass codes, or log files. Any account with administrative
privileges shall be issued to network administrators only.
(5).
Router and Switch Logs
(a). All routers and switches shall maintain and record security auditing events to logs.
(b). All routers and switches shall log security auditing events that display both successful
and unsuccessful incidents.
(c). All log files and events shall be managed in a manner that maintains their integrity and
authenticity. These logs are to be stored or archived for a minimum of six (6) months.
(d). Requests for access to router and switch logs shall be made to the appropriate network
administrator and Agency ISSPM.
(e). Event logs shall be reviewed by the network administrator and ISSPM or designated
representative on a regular basis.
(6).
Change Request
Change requests for any modifications to a router and switch system, configuration, or
design shall be submitted in writing to as a Request for Change (RFC) following Change
Management (CM) procedures. All change requests shall include the reason and timeframe
for the request as well as all risks, threats, and known issues associated with this change.
Only after CCB approval shall network administrator personnel proceed with the router and
switch changes. Any changes from the original design once approved, and not yet
implemented or in the process of implementation, will require a formal change request form.
(7).
Router and Switch Implementation
A request for implementation of new routers and switches shall be submitted to the CM.
This request shall include all configuration settings together with other pertinent system
information. Only after obtaining approval from the CCB shall authorized personnel
proceed with the router and switch implementation.
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 72
Number 3602-001
FOR OFFICIAL USE ONLY
Chapter Twenty-One: Router and Switch Management Security Policy
(8). Implied Authority
(a). All network administration personnel have the implied authority and responsibility to
take action(s) to protect OCIO-ITS assets from loss without approval from the CCB in
an emergency only to include modifying router and switch operating systems,
hardware, or configurations. This authority is only justified if a direct threat or attack
has been discovered and prompt action is required to reduce the risk and/or loss.
(b). The OCIO-ITS ISSPM has the implied authority and responsibility to direct and
authorize action(s) to protect OCIO-ITS information assets from loss without CCB
approval in an emergency only.
(c). If this authority is exercised, the administrator shall report it as an incident and follow
Chapter 10: Incident Identification, Declaration, Reporting, and Handling Security
Policy or it replacement.
(9). Incident Reporting and Response
In the event that a security vulnerability or breach, malicious activity, successful attack, or
violation of this policy has been discovered or suspected, an incident shall be reported in
accordance with Chapter 10: Incident Identification, Declaration, Reporting, and Handling
Security Policy or its replacement.
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 73
Number 3602-001
FOR OFFICIAL USE ONLY
Chapter Twenty-Two: Security Architecture Framework Management Security Policy
22. CHAPTER TWENTY-TWO: SECURITY ARCHITECTURE
FRAMEWORK MANAGEMENT SECURITY POLICY
a.
General Policy Statement
This policy establishes requirements for the USDA Office of the Chief Information Officer
(OCIO), Information Technology Services (ITS) to evaluate their Information System Security
(ISS) architecture framework to ensure adequate protection of all OCIO-ITS information
resources. The OCIO-ITS will conduct an initial review to develop a security model of their
information systems assets. The review will include a systematic approach of identifying and
allocating all information systems assets to a security architecture baseline. The baseline will
include assigning assets with their functional responsibilities (end user systems, relay systems,
etc), identifying how these assets are used to meet OCIO-ITS business needs and requirements, in
the form of security domains (Internal, External, Public Access, Remote Access), and finally
identifying the general security control requirements for each asset.
b.
Policy Detail
(a).
The OCIO-ITS will develop a Security Architecture Framework (SAF) baseline and security
model within their respective IT structure in alignment with Cyber Security’s Guidance
Regarding Developing a Security Architecture Framework, CS-035, or its replacement, for
additional information and guidelines. The steps in this process include:
1. Identifying/storing information pertaining to local IT assets: The SAF process shall be
used by the OCIO-ITS to identify how each IT asset contributes to the security
architecture framework.
2. Identifying how assets link to a generic security model: The Service Center Agencies
supported by the OCIO-ITS shall determine how their assets link to a Basic Element
category and assign it to a generic security model.
3. Identifying security domains: After identifying the assets and assigning them to their
basic elements within the security model, the OCIO-ITS must develop security domains.
A security domain consists of a set of users, the data for a system, and a security policy
that governs the use of the domain.
4. Identifying security control requirements: Once OCIO-ITS assets have been categorized
into basic elements in the security model and security domains have been created,
security controls will be assigned based upon the level of security required for each
domain level and element.
5. Identifying security products to support security controls and security domains:
Only those products approved by the USDA OCIO in the Security Product Database will
be used for meeting security requirements unless otherwise agreed upon with the OCIO-
ITS.
6. Periodic Review of Security Architecture Framework: The OCIO-ITS will periodically
evaluate their ISS architecture to ensure that changes are made accordingly to the SAF
baseline to reflect changes in business and systems requirements.
7. Process Scope: This process can be used by the OCIO-ITS for small and large IT
architectures. The key is capturing all IT assets within the OCIO-ITS architecture.
(2).
Submission and review of the SAF shall follow the guidance in Cyber Security’s Guidance
Regarding Developing a Security Architecture Framework, CS-035, or its replacement.
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 74
Number 3602-001
FOR OFFICIAL USE ONLY
Chapter Twenty-Three: Security Awareness, Training, and Education Security Policy
23. CHAPTER TWENTY-THREE: SECURITY AWARENESS, TRAINING,
and EDUCATION SECURITY POLICY
a.
General Policy Statement
(1). This policy establishes requirements for the Security Awareness, Training, and Education
program for information resources supporting the USDA Office of the Chief Information
Officer (OCIO), Information Technology Services (ITS).
(2). Federal requirements justifying the OCIO-ITS Security Awareness, Training, and Education
program are as follows:
(a). OPM Regulation 5 CFR 930, Employees Responsible for the Management of Use of
Federal Computer Systems.
(b). National Institute of Standards and Technology (NIST) Special Publication 800-16,
OCIO-ITS Security Training Requirements: A Role-and Performance-Based Model,
dated April 1998.
(c). Executive Order 13103, Computer Software Piracy, dated September 30, 1998.
(d). NIST Special Publication 800-18, Guide for Developing Security Plans for Information
Technology Systems, December 1998.
(e). Office of Management and Budget (OMB) Circular No. A-130, Appendix III, dated
February 8, 1996, Security of Federal Automated Information Resources.
(f). Computer Security Act of 1987.
(g). Presidential Decision Directive 63 (PDD63), May 22, 1998.
(h). OPM Regulation Title 5, Volume2, Parts 930.301-305
b.
Policy Detail
(1).
The OCIO-ITS will develop, organize, implement, and maintain an IT systems security
awareness training program to ensure the security of OCIO-ITS information resources and to
establish requirements for formal training to be conducted at least annually.
(2).
NIST Special Publication 800-16 is the source for guidance and direction in the design of the
computer security awareness training program in the OCIO-ITS.
(3).
All OCIO-ITS employees, contractors, subcontractors, grantees and co-operators involved in
the management, use, design, development, maintenance or operation of an application or
automated information system shall be made aware of their security responsibilities based on
their need-to-know and trained to fulfill them.
(4).
Training content shall assure that all groups specified above are versed in the rules and
requirements pertaining to security of the respective Federal IT systems, which they access,
operate, or manage.
(5).
Computer security awareness refresher training is required at least annually or whenever
there is a significant change in IT direction, major system modifications, changes/upgrades
in software utilized, or change of duties for continued access to OCIO-ITS information
systems.
(6).
The OCIO-ITS will retain records documenting initial or annual computer security
awareness training.
(7).
Training must include software piracy prevention and appropriate software use training in
compliance with Executive Order 13103, “Computer Software Piracy.”
(8).
The OCIO-ITS will distribute security alerts and advisories, as needed, through appropriate
media to remind all groups of security practices or to inform them of new security issues.
(9).
New OCIO-ITS and Service Center Agency (SCA) employees and Government contractors
shall receive Security Awareness Training within 30 days of being hired.
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 75
Number 3602-001
FOR OFFICIAL USE ONLY
Chapter Twenty-Four: Security Plan Management Security Policy
24. CHAPTER TWENTY-FOUR: SECURITY PLAN MANAGEMENT
SECURITY POLICY
a.
General Policy Statement
(1).
Federal Requirements
The Computer Security Act of 1987 and OMB A-130, Appendix III, requires security plans
for all USDA Office of the Chief Information Officer (OCIO), Information Technology
Services (ITS) information technology systems. Each plan shall reflect accurate and
comprehensive details required by NIST 800-18, Guide for Developing Security Plans for IT
Systems. The generic term “systems” covers all General Support Systems (GSS) and Major
Applications (MA).
(2).
Security Plans
(a).
The OCIO-ITS shall develop and maintain individual security plans for all general
support systems and major applications, and an Overall Program Security Plan. These
three types of plans shall be prepared using the instructions and templates as defined in
the following:
1. Security Plan Development, section b., (1).
2. General Support System (GSS) Security Plan Templates for Hardcopy Submission
(refer to CS-021, 2003 Annual Security Plans for Information Technology Systems
or its replacement for template)
3. Major Application (MA) Security Plan Templates for Hardcopy Submission (refer
to CS-021, 2003 Annual Security Plans for Information Technology Systems or its
replacement for template)
4. General Support System (GSS) Security Plan Templates for Electronic Submission
(refer to CS-021, 2003 Annual Security Plans for Information Technology Systems
or its replacement for template)
5. Major Application (MA) Security Plan Templates for Electronic Submission (refer
to CS-021, 2003 Annual Security Plans for Information Technology Systems or its
replacement for template)
6. Modification of these templates closely parallels NIST 800-18 but also contains
information required by Federal Information Security Management Act (FISMA),
and the Office of Inspector General audits.
(b).
The OCIO-ITS and Agency Information Systems Security Program Managers
(ISSPMs) shall work with their respective system owners and developers to prepare and
update security plans for all general support systems and/or major applications on a
periodic basis or when a GSS or MA is implemented or significantly changed.
(c).
The OCIO-ITS ISSPM shall prepare a security plan for the Overall Security Program as
outlined in Security Plan Development (Section b), and the Overall Program Security
Plan Template.
(d).
The OCIO-ITS ISSPMs will submit all completed annual security plans to the OCIO-
ITS CIO’s office and shall submit a cover letter with all plans attesting to the
completeness and accuracy of these security plans.
(e).
All OCIO-ITS shall submit security plans will be updated every three years or upon a
major change.
b.
Policy Detail
(1). Security Plan Development
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 76
Number 3602-001
FOR OFFICIAL USE ONLY
Chapter Twenty-Four: Security Plan Management Security Policy
(a). Security plans shall reflect input from individuals with responsibilities concerning the
system and/or application including functional end users, system owners, the system
administrator, and the system security manager.
(b). For those contractors and/or partners operating an OCIO-ITS sponsored information
system, the respective ISSPM will ensure that the necessary contract language is
included in procurement requests to specify compliance with the security plan in the
development, maintenance, and operation of all information systems and/or
applications.
(c). Any security plan developed by a contractor or outside entity shall always be reviewed
by the sponsoring ISSPM and the application or system owners.
(2).
Determining General Support Systems and Major Applications
(a). All applications and systems shall be covered by system security plans if they are
categorized as a major application or general support system. All other applications
shall be accounted for in the Service Center Agencies’ Overall Security Plan.
(b). Applications that are categorized as non-major will require a statement regarding
security and require software certification before inclusion in the enterprise system.
(c). A system is identified by constructing logical boundaries around a set of processes,
communications, storage, and related resources. The elements within these boundaries
constitute a single system requiring a security plan. Each element of the system shall:
1. Be under the same direct management control
2. Have the same function or mission objective
3. Have essentially the same operating characteristics and security needs
4. Reside in the same general operating environment
5. A group of portable PCs provided to employees who require mobile computing
capability for their jobs
6. A system with multiple identical configurations that are installed in locations with
the same IT environmental and physical safeguards.
(d). All components of a system need not be physically connected, for example:
1. A group of stand alone personal computers (PCs) in an office
2. A group of PCs placed in an employees’ homes under defined telecommunications
program rules
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 77
Number 3602-001
FOR OFFICIAL USE ONLY
Chapter Twenty-Five: Server Management Security Policy
25. CHAPTER TWENTY-FIVE: SERVER MANAGEMENT SECURITY
POLICY
a.
General Policy Statement
This policy establishes requirements for authorization and access to USDA Office of the Chief
Information Officer (OCIO), Information Technology Services (ITS) server resources through the
use of individual credentials. Group credentials are not permitted for access to any server. For
the purpose of this policy, system level resources such as Domain Name Server (DNS) or
Dynamic Host Configuration Protocol (DHCP) do not apply. The intent is to eliminate
anonymous access to resources and establish a foundation for auditing. Additionally, OCIO-ITS
servers containing sensitive information shall meet USDA C2-like Level of Trust.
b.
Policy Detail
(1).
Server Configuration
(a).
Configuration standards and management procedures shall be used to control usability,
efficiency, and security of the overall server environment and shall be kept in a Trusted
Facility Manual (TFM). These standards and other procedures shall be strictly followed
when designing, implementing or managing server configurations. Written approval
from the Change Control Board (CCB) is required prior to any deviation from these
standards.
(b).
All security-related service packs, patches, and hot-fixes shall be tested and applied to
all servers in a timely manner in accordance with Chapter 16: Patch Management
Security Policy or its replacement.
(c).
All servers shall comply with the encryption of sensitive data in accordance with
Chapter 11: Information Classification Security Policy or its replacement.
(d).
All servers shall be physically secured in accordance with Chapter 17: Physical Access
Security Policy or its replacement.
(e).
All servers shall be protected by antivirus software in accordance with Chapter 27:
Virus Protection Security Policy or its replacement.
(f).
All servers will display a warning banner in accordance with Chapter 14: Network
Access Security Policy or its replacement.
(g).
All servers shall be backed up in a manner that allows for a complete server recovery,
including operating system, applications, data and system state, on a daily basis.
Archives of server backups shall be kept for a period of at least six weeks.
(h).
All back-up media shall be kept in a secured manner consistent with Chapter 17:
Physical Access Security Policy, or its replacement, and be protected by controlled
access.
(i).
A selected portion of backup media shall be kept in an alternate physical location
secured in a manner consistent with Chapter 17: Physical Access Security Policy, or its
replacement, and be protected by controlled access.
(j).
System owners shall be responsible for the documentation, validity, and availability of
information regarding their full operations outside of the backup archive.
(2).
Server Specification Settings
(a). Maximum password age shall be no more than 90 days.
(b). Maximum password length shall be set to 14 and the minimum length shall be set to 9.
(c). Lock out duration is set to 0 (zero) to enable lockout forever, or until unlocked by an
authorized administrator.
(d). Lock out procedures shall be initiated after three failed attempts to login.
(e). Password complexity shall be implemented on all servers.
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 78
Number 3602-001
FOR OFFICIAL USE ONLY
Chapter Twenty-Five: Server Management Security Policy
(f). Null login credentials shall be disabled on all servers.
(g). All server configurations shall be set to prevent administrators from performing the
following actions:
1. Debugging programs
2. Using logon as a service
(3).
Server Management Access
(a). Access to server consoles and operating systems shall be limited to system
administrator personnel only. For security purposes, no exceptions to this rule shall be
allowed. All server administrator accounts shall comply with the password
requirements set by Chapter 3: Authorization and Access Control Security Policy or its
replacement.
(b). All non-essential user, group, and service accounts must be removed immediately.
(c). All non-essential services must be removed immediately.
(d). The administrator account is the original administrative account of the server and/or
domain. This account shall be renamed and used on a limited basis. Only select system
administrator personnel are to have knowledge of this account’s credentials.
(e). Administrators are not permitted to have access to more than one administrator account.
(f). Administrators are not permitted to share their account information with anyone,
including the help desk and management.
(g). Any service account used by a service to access system resources is not to be used for
any other purpose. Only system administrator personnel are permitted to have
knowledge of service account credentials.
(h). All system administrators shall receive the appropriate level of training to perform their
duties in a competent manner.
(4).
Server Classification
(a). Each server hosting a mission critical application or service in a production
environment shall be identified as a production server. All production servers must be
logically separated and isolated from test and development environments.
(b). Each server shall be clearly identified as to the classification of information stored or
used by the server. These classifications shall follow information classification
processes in accordance with Chapter 11: Information Classification Security Policy or
its replacement.
(c). Servers shall be managed and administered in accordance to their identified type and
classification.
(5).
Server Information Access
Access to server information is restricted to a system administrator and Information Systems
Security Program Managers (ISSPM) or persons with written permission from the ISSPM.
In the event that server access is created for security audit purposes, it shall be with read-
only privileges.
(6).
Server Logs
(a). All servers shall maintain security audit logs that include (at a minimum) the UserID,
date, time, and action performed.
(b). All servers shall log security auditing events showing successful and unsuccessful
events, including inappropriate access events.
(c). All log files and events shall be managed in a manner that maintains their integrity and
authenticity, and will be stored or archived for a minimum of six (6) months.
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 79
Number 3602-001
FOR OFFICIAL USE ONLY
Chapter Twenty-Five: Server Management Security Policy
(d). Request for access to server logs shall comply with the server information statement in
this document.
(e). Access to security auditing logs shall be limited to system administrators and ISSPM
personnel.
(f). Event logs should be reviewed by system administrators on a daily basis and reviewed
randomly or on an as-needed basis by ISSPM personnel.
(7).
Server Implementation
All new servers shall meet defined standards and configuration requirements as outlined in
the appropriate configuration management document. A request for implementation of new
or revised configuration servers shall be submitted to the CCB. Only after obtaining CCB
approval shall system administrators proceed with the server implementation. Any changes
from the original design plan approved by CCB shall need to be resubmitted via a Request
for Change (RFC). Servers being added to the environment shall require additional approval
by the CCB.
(8).
Server Change Requests
Change requests for any changes to the enterprise server system components, configuration
or active directory design shall be submitted in writing via an RFC to the CCB for review.
All change requests shall include the reason and timeframe for the request as well as all
risks, threats, and known issues associated with this change. Only after CCB approval shall
system administrators proceed with the server changes.
(9).
Server Services
Servers shall only host services for which they were designed and approved to host. Any
additional services must be approved by the CCB. For the purpose of this policy, the term
‘services’ refers to specific services that a server was designed to host such as a web site, file
and print, DNS, DHCP, Telnet, or FTP. All services not required for system functionality
are to be disabled.
(10). Implied Authority
(a). All system administrators have the implied authority and responsibility to take action(s)
to protect OCIO-ITS information assets from loss without CCB approval in an
emergency to include modifying or changing server operating systems, hardware,
configurations, or accounts. This authority is only justified if a direct threat or attack
has been discovered and prompt action is required to reduce the risk and/or loss.
(b). The OCIO-ITS ISSPM has the implied authority and responsibility to direct and
authorize action(s) to protect OCIO-ITS information assets from loss without CCB
approval in an emergency only. This authority is only justified if a direct threat or
attack has been discovered and prompt action is required to reduce the risk and/or loss.
(c). If this authority is exercised, the administrator shall report it as an incident and follow
Chapter 10: Incident Identification, Declaration, Reporting, and Handling Security
Policy or it replacement.
(11). Incident Reporting and Response
In the event of a security vulnerability or breach, malicious activity, successful attack, or
violation of this policy has been discovered or suspected, an incident shall be reported in
accordance with Chapter 10: Incident Identification, Declaration, Reporting, and Handling
Security Policy or its replacement.
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 80
Number 3602-001
FOR OFFICIAL USE ONLY
Chapter Twenty-Six: Systems Development Life Cycle Security Policy
26. CHAPTER TWENTY-SIX: SYSTEMS DEVELOPMENT LIFE CYCLE
SECURITY POLICY
a.
General Policy Statement
(a).
This policy establishes requirements for the USDA Office of the Chief Information Officer
(OCIO), Information Technology Services (ITS) to successfully implement security
protocols and procedures into the Systems Development Life Cycle (SDLC) to ensure that a
system is developed in accordance with the stated requirements, works effectively, is cost
effective, is secure, and is maintainable. The inclusion of security controls and measures
early in the SDLC will result in less expensive and more effective security than adding it
after a system is operational.
(b).
The OCIO-ITS will implement baseline security controls during the developmental life cycle
of all IT systems. The security controls selected for each baseline must be implemented at
the recommended level of robustness in order to achieve the estimated threat coverage. In
cases where security baselines do not provide sufficient coverage against certain types of
threats, additional security controls must be provided upon discovery. National Institute of
Standards and Technology (NIST) Special Publication (SP) 800-53, Recommended Security
Controls for Federal Information Systems, provides additional information on appropriate
security controls for each type of baseline.
(c).
OCIO-ITS information systems security controls shall be integrated into the SDLC from
system inception. System owners will identify and contact the Information Systems Security
Program Manager (ISSPM) when the system is in the Initiation Phase of the SDLC.
(d).
Legacy systems which do not have an existing SDLC plan, or equivalent, shall develop an
SDLC Plan relative to the current phase of the system if it is not fully operational or
identified for additional security controls. Corresponding documentation shall clearly
reference its equivalence to SDLC information.
(e).
OCIO-ITS system security requirements documentation as identified in the SDLC shall be
placed under configuration management control from the inception of the system and will be
included as part of the total set of system documentation that evolves over the lifecycle.
(f).
All SDLC plans and SDLC related documents shall be kept current.
b.
Policy Detail
The SDLC is separated into five phases during which information system products are developed.
These phases include the Initiation Phase, the Development/Acquisition Phase, the
Implementation Phase, the Operations/Maintenance Phase, and the Disposition Phase.
(1). Initiation Phase
This is the first phase in the SDLC. The following shall be included in this phase:
(a). Preparation of the Interconnectivity Security Agreement (ISA)
The OCIO-ITS shall initiate an ISA during this phase of the SDLC. An ISA is part of
the overall Certification and Accreditation process and must be completed for each new
system that will be connected to an existing legacy system, unless those systems are
under the same management.
(b). Preliminary Risk Assessment
The OCIO-ITS shall conduct an assessment in examination of the basic security needs
of the proposed system. A preliminary risk assessment shall define the threat
environment in which the system will operate. This assessment should (1) result in a
brief initial description of the basic security needs of the system, (2) define the threat
environment in which the product or system will operate, and (3) define a potential set
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 81
Number 3602-001
FOR OFFICIAL USE ONLY
Chapter Twenty-Six: Systems Development Life Cycle Security Policy
of countermeasures. This risk-based approach to information security is defined in
NIST SP 800-30, Risk Management Guide for Information Technology Systems.
(c). Security Categorization
The OCIO-ITS shall define and establish a level (i.e., low, moderate, or high) of
potential impact(s) to prevent a potential breach of security. FIPS Publication 199,
Standards for Security Categorization of Federal Information and Information Systems,
shall be used in conjunction with available vulnerability and threat information in
assessing all potential risk to an organization through operation of the proposed
information system.
(d). Privacy Impact Assessment
The OCIO-ITS is required to initiate a Privacy Impact Assessment (PIA) in this phase
as part of the ongoing security effort. Refer to Chapter 19: Privacy Impact Assessment
Security Policy, or its replacement, for additional information on this subject.
(2).
Development Phase
This is the second phase in the SDLC. The following shall be included in this phase:
(a).
Risk Assessment
The OCIO-ITS is required to perform a Security Risk Assessment during this phase to
identify protection requirements for the system through a formal risk assessment
process. The selection of appropriate types of safeguards or countermeasures must take
into consideration the results of the security assurance requirements analysis as defined
in the previous phase.
(b).
Security Functional Requirements Analysis
The OCIO-ITS is required to perform an analysis of requirements that include the
following components: (1) system security environment, and (2) security functional
requirements. This process shall include an analysis of laws and regulations such as the
Privacy Act, FISMA, OMB circulars, Agency enabling acts, NIST Special Publications
and FIPS, and other legislation and federal regulations, which define baseline security
requirements.
(c).
Security Assurance Requirements Analysis
The OCIO-ITS is required to conduct an analysis of requirements that address the
developmental activities required and assurance evidence needed to produce the desired
level of confidence that the information security will work correctly and effectively. A
balance must exist between the benefits to mission performance from system security
and the risks associated with operation of the system without security.
(d).
Cost Considerations and Reporting
The OCIO-ITS is required to determine what percentage of the development cost can be
attributed to information security over the life cycle of the system. Security controls
should be included at the beginning of the SDLC as it is the most cost effective
approach for two reasons: (1) it is usually more difficult to add functionality into a
system after it has been built; and (2) it is frequently less expensive to include the
preventive measures to deal with the cost of a security incident.
(e).
Security Planning
The OCIO-ITS is required to ensure that agreed upon security controls, planned or in
place, are fully documented in a system security plan. Refer to Chapter 24: Security
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 82
Number 3602-001
FOR OFFICIAL USE ONLY
Chapter Twenty-Six: Systems Development Life Cycle Security Policy
Plan Management Security Policy, or its replacement, for additional information on this
subject.
(f). Security Control Development
Security controls described in the respective security plans shall be designed,
developed, and implemented in this phase. Refer to Chapter 24: Security Plan
Management Security Policy, or its replacement, for additional information on this
subject.
(g). Developmental Security Test and Evaluation
The OCIO-ITS is required to ensure that security controls developed for a new
information system are working properly and are effective as evidence by the
developer’s test materials and test results.
(3).
Implementation Phase
This is the third phase of the SDLC. The following shall be included in this phase:
(a). Security Control Integration
The OCIO-ITS is required to make certain that security controls are integrated at the
operational site where the information system is to be deployed into production.
Security control settings and switches will be enabled in accordance with manufacturer
instructions and available security implementation guidance such as the Trusted Facility
Manual (TFM) for the system.
(b). Security Certification
The OCIO-ITS is required to ensure that security controls are effectively implemented
through established verification techniques and procedures within the system
certification process. Refer to Chapter 5: Certification and Accreditation Security
Policy, or its replacement, and in accordance with NIST SP 800-37: Guide for the
Security Certification and Accreditation of Federal Information Systems, May 2004.
(c). Security Accreditation
The OCIO-ITS is required to ensure that the necessary security authorization of an
information system to process, store, or transmit information is obtained. OMB
Circular A-130 requires the security authorization of an information system to process,
store, or transmit information. Refer to Chapter 5: Certification and Accreditation
Security Policy, or its replacement, and in accordance with NIST SP 800-37: Guide for
the Security Certification and Accreditation of Federal Information Systems, May 2004.
(4).
Operations and Maintenance Phase
This phase is the fourth phase of the SDLC. The following shall be included in this phase:
(a). Configuration Management and Control
The OCIO-ITS is required to ensure adequate consideration of potential security
impacts due to specific changes to an information system or its surrounding
environment. Depending upon the extent of change to an operational system, additional
Certification and Accreditation (C&A) measures may be required. Significant changes
include operating system version and major applications that could impact the current
operation.
(b). Continuous Monitoring
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 83
Number 3602-001
FOR OFFICIAL USE ONLY
Chapter Twenty-Six: Systems Development Life Cycle Security Policy
The OCIO-ITS is required to make certain that controls continue to be effective in their
application through periodic testing and evaluation.
(5). Disposition Phase
Disposition is the final phase in the SDLC. The following shall be included in this phase:
(a). Media Sanitization
The OCIO-ITS is required to make certain that all data is deleted, erased, and/or written
over as necessary to protect information system hardware. Refer to Chapter 13: Media
Sanitation and Disposal Security Policy, or its replacement, for additional information
on this subject.
(b). Hardware and Software Disposition
The OCIO-ITS is required to ensure that all hardware and software is disposed of in
accordance with Chapter 13: Media Sanitation and Disposal Security Policy or its
replacement.
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 84
Number 3602-001
FOR OFFICIAL USE ONLY
Chapter Twenty-Seven: Virus Protection Security Policy
27. CHAPTER TWENTY-SEVEN: VIRUS PROTECTION SECURITY
POLICY
a.
General Policy Statement
(1). This policy establishes the guidelines for the management and protection of software used
within the USDA Office of the Chief Information Officer (OCIO), Information Technology
Services (ITS). Instructions for installing and configuring the virus protection software on
workstations and laptops shall be made available online at
http://www.sci.usda.gov/cce/guides.html.
(2). Virus definitions and updates shall be tested and certified prior to deployment.
(3). All users are responsible for reporting suspected viruses to designated IT support staff
immediately.
b.
Policy Detail
(1).
Virus Protected Systems
(a). Virus-checking software must be installed and maintained to include the latest virus
signature file applied on all servers, workstations, laptops, and personal electronic
devices regardless of operating system, whether connected to the OCIO-ITS networks
or not. This includes contractor-owned and/or contractor-operated systems, standalone
computers and personal electronic devices, and computers of the OCIO-ITS and
business partners connected to networks. Virus-checking software must meet the
requirements outlined in this policy and in CCE Trusted Facilities Manuals (TFM) or
standards.
(b). E-mail servers must have an antivirus package installed and running with the latest
virus signatures applied. E-mail servers shall have a content filtering package or
additional device capable of blocking specified attachments, installed, and be running.
(2).
Virus Software Configurations and Scanning Policy
(a). All non-Government machine-readable produced computer media (for example, floppy
diskettes, zip cartridges, CD-ROMs, tapes, etc.) and downloaded files must be scanned
for viruses and other malicious software before initial use. This pertains to all OCIO-
ITS equipment operated by employees, contractors, and partners.
(b). Remote access users are required to bring in their Government-issued computer laptops
and Portable Electronic Devices (PED) to their designated Service Center Agency work
facility (minimum of once each month) so that OCIO-ITS approved virus scans can be
run and/or antivirus software updates be installed on this equipment. However, this
frequency may change in the event of a virus outbreak.
(c). When feasible, standardized virus software configurations shall be used on non-
enterprise systems.
(d). Antivirus software shall be configured to scan all files and macros (not just program
executables) for viruses. This does not apply to swap files.
(e). Antivirus software shall be configured for both on-access and scheduled scanning.
(f). Antivirus software shall be configured so that all inbound and outbound files are
scanned along with the boot sector and floppy drive (during shutdown).
(g). Antivirus software shall be configured to scan e-mail attachments prior to sending or
opening.
(h). Antivirus software shall be configured so that ActiveX and Java components in Web
pages and HTML-based e-mail messages are scanned.
(i). End users shall not have the ability to disable the antivirus software on their computer.
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 85
Number 3602-001
FOR OFFICIAL USE ONLY
Chapter Twenty-Seven: Virus Protection Security Policy
(j). All e-mail stored, inbound or outbound, with or without attachments, must be scanned
for viruses regardless of the destination address.
(k). E-mail scanning must include all attachments and macros. Attachments and macros
that cannot be scanned must be deleted and replaced with a message detailing the action
taken. Outgoing e-mail must be scanned at the network server to which the client is
connected. If a virus is detected on outgoing e-mail, the server must run a virus scan
immediately on the originating client.
(l). Antivirus software shall be configured so that all activity of the antivirus software is
logged. Ensure the logs are included in the daily backups. Logs must be maintained
until no longer needed.
(m). The date of the virus definitions shall be monitored to ensure the automatic update is
functioning properly.
(n). The directory that contains the “setup.exe” for the antivirus software shall be secured so
that end users cannot delete, rename, or write files to this directory, and/or inhibit any
file tampering.
(o). Antivirus software shall be configured to block e-mail that it is unable to scan.
(p). Antivirus updates shall be loaded at the time system instruction is received.
(q). Antivirus software shall be configured to automatically pull and apply the latest virus
definition updates from a central repository site daily.
(r). All non-Government-owned laptops shall have an OCIO-ITS approved/current version
of antivirus software installed prior to connecting to any OCIO-ITS network or
computer source.
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 86
Number 3602-001
FOR OFFICIAL USE ONLY
Chapter Twenty-Eight: Vulnerability Scan Security Policy
28. CHAPTER TWENTY-EIGHT: VULNERABILITY SCAN SECURITY
POLICY
a.
General Policy Statement
(1). This policy establishes the guidelines for the protection of USDA Office of the Chief
Information Officer (OCIO), Information Technology Services (ITS) information systems.
Vulnerability scans are required to be conducted on a monthly basis for all operational
networks, systems, and servers, inclusive of routers and switches, that the OCIO-ITS are
responsible for managing.
(2). OCIO-ITS is the configuration authority for all vulnerability scans performed and requires
that all scanning configurations established by the Service Center Agencies are required to
be uniform in approach.
(3). Each Information Systems Security Program Manager (ISSPM) is responsible for scanning
all regional-based hardware, regardless of who owns the equipment.
(a). East Region: Natural Resources Conservation Service, ISSPM
(b). Central Region: Farm Service Agency, ISSPM
(c). West Region: Rural Development, ISSPM
b.
Policy Detail
(1).
New Equipment/Equipment Upgrade
(a). Informational scans may be requested by the ISSPM and Change Control Board (CCB)
prior to implementation of new or modified/upgraded equipment into the production
environment. Scan results shall be provided to the ISSPM and CCB.
(b). Scans will be conducted prior to new system installations and when any major
modifications/upgrades are implemented on current operational systems regarding their
connectivity, application functionality, and general security configurations. Service
Center Agencies and staff shall only scan networks or servers for which they are
responsible.
(c). A series of scans shall be performed during the developmental cycle such as baseline
server (if new hardware) with full applications loaded, then pre-pilot and pre-
production. The systems administrator should contact the closest regional Field Office
to coordinate the scanning request. Only pre-pilot and pre-production scans are
required for configuration management approval prior to further action.
(d). New systems and equipment or major modifications to existing systems/equipment
must be scanned in their development and/or test environment prior to deployment into
a production environment. System representatives must contact the ISSPM and CCB to
initiate a scan 10 working days prior to scheduling a special or pre-production scan.
The system/equipment will not be deployed until vulnerabilities identified have been
adequately addressed or a waiver has been approved. Equipment not scanned prior to
production will be removed immediately from the network.
(2).
Routine Scans
(a). The ISSPM shall coordinate all scans performed at the Agency level and provide the
OCIO Office of Cyber Security with the names and contact information for a primary
and secondary contact person relative to performing scans.
(b). Scan results from production sources shall be forwarded to the responsible ISSPM and
CCB for corrective action depending upon hardware ownership. It is the responsibility
of the applicable ISSPM and/or the CCB to ensure that all vulnerabilities are addressed
within the appropriate timeframes or when waivers are requested.
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 87
Number 3602-001
FOR OFFICIAL USE ONLY
Chapter Twenty-Eight: Vulnerability Scan Security Policy
(c).
All scans should be completed no later than the 15th calendar day of each month, unless
they are considered a special scan, i.e., following major modifications/upgrades.
ISSPMs must notify the Department and all relative Service Center Agencies prior to
performing a scan.
(d).
Scan results will be provided to the responsible system owners/administrators so that
identified vulnerabilities can be addressed. High and medium risk vulnerabilities
require a formal response from the appropriate system representatives.
(e).
Responsible parties will reply back to the respective Agency ISSPM within seven
calendar days after receiving the scan results for a medium risk vulnerability, and
within one workday for a high-risk vulnerability. An action plan must be included for
vulnerabilities not mitigated within the required timeframes. The originating ISSPM
must receive the results no later than the 23rd calendar day of each month.
(f).
Computer network staff shall address vulnerabilities in the order of their associated risk
as a means to mitigate the most serious vulnerabilities immediately (High
→Medium→Low). All vulnerabilities on OCIO-ITS networks, systems, and servers
identified as ‘high’ and ‘medium’ must be formally addressed in a timely fashion. A
reasonable effort shall be made to address and correct vulnerabilities rated “low.”
(g).
Scan responses provided to the Agency ISSPM and CCB for all high and medium
vulnerabilities should fall into one of five categories:
1.
Vulnerability has been corrected.
The response shall indicate what corrective action has been taken and the date of
correction. The system owner/administrator must sign the response to certify that
these actions have been taken. The ISSPM and CCB must initiate a rescan to
ensure that corrective actions mitigated the vulnerability.
2.
Vulnerability is a false-positive.
System owners/administrators must explain why they believe an identified
vulnerability is a false-positive. Once the system owner/administrator has provided
the ISSPM and CCB an explanation and the ISSPM and CCB have concurred, the
system representatives will no longer have to address the vulnerability on
subsequent monthly reports.
3.
Corrective action is planned, but has not been completed.
The response must include an explanation outlining steps planned and the
timeframe for expected completion.
4.
Vulnerability cannot be mitigated for business reasons.
The responsible system owner/administrator shall provide strong justification for
vulnerabilities for which there is not a plan to correct. The ISSPM will request a
waiver from the OCIO for vulnerabilities that cannot be mitigated for business
reasons.
5.
Vulnerability cannot be mitigated for vendor reasons.
The system owner/administrator shall provide information on what is needed from
the vendor to correct the vulnerability and the timeframe. If no fix is available or
will not be available for one month or longer, then the owner/administrator should
work with the ISSPM to find a workable alternative to mitigate the vulnerability.
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 88
Number 3602-001
FOR OFFICIAL USE ONLY
Appendices
APPENDICES
Appendix A: Acronyms
ACRONYM
DEFINITION
ACL
Access Control List
AD
Active Directory
ADPO
Application Development Program Office
AIM
AOL Instant Messenger
C&A
Certification and Accreditation
C2
Command and Control
CCB
Change Control Board
CCE
Common Computing Environment (enterprise system)
CCTV
Closed Circuit Television
CHAP
Challenge-Handshake Authentication Protocol
CIO
Chief Information Officer
CIRT
Computer Incident Response Team
CM
Configuration Management
CO
Certifying Officer
COTR
Contracting Officers Technical Representative
COTS
Commercial-Off-The-Shelf (Software)
CPIC
Capital Planning and Investment Control
CS
Cyber Security (USDA)
CT
Certification Team
DAA
Designated Accrediting Authority
DAM
Deputy Administrators for Management
DES
Data Encryption Standard
DHCP
Dynamic Host Configuration Protocol
DIG
Director of Infrastructure Governance
DIO
Director of Infrastructure Operations
DMZ
De-Militarized Zone
DNS
Domain Name Server
DoS
Denial of Service
DRAM
Dynamic Random Access Memory
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 89
Number 3602-001
FOR OFFICIAL USE ONLY
ACRONYM
DEFINITION
EPROM
Erasable Programmable ROM
FIPS
Federal Information Processing Standards
FISMA
Federal Information Security Management Act
FMFIA
Federal Managers Financial Integrity Act
FOIA
Freedom of Information Act
FOUO
For Official Use Only
FPS
Federal Protective Service
FSA
Farm Service Agency
FSC
Field Service Center
FTP
File Transfer Protocol
FTPS
Secure File Transfer Protocol
GISRA
Government Information Security Reform Act
GMSP
Group Manager of Security Policy
GOTS
Government-Off-The-Shelf (Software)
GPEA
Government Paperwork Elimination Act
GPRA
Government Performance and Results Act
GSA
General Services Agency
GSS
General Support System
HTTP
HyperText Transmission Protocol
HTTPS
HyperText Transmission Protocol, Secure
I-TIPS
Information Technology Investment Portfolio System
IA
IDS Administrator
IAP
Internet Access Provider
IDS
Intrusion Detection System
IHP
Incident Handling Program
IHT
Incident Handling Team
IMAP
Internet Message Access Protocol
IMAPS
Internet Message Access Protocol, Secure
IO Lab
Interoperability Lab
IRC
Internet Relay Chat
ISA
Interconnectivity Security Agreement
ISP
Internet Service Provider
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 90
Number 3602-001
FOR OFFICIAL USE ONLY
ACRONYM
DEFINITION
ISS
Information System Security
ISSPM
Information Systems Security Program Manager
IT
Information Technology
ITS
Information Technology Services
ITWG
Information Technology Working Group
LAN
Local Area Network
MA
Major Application
MAC
Media Access Control
Malware
Malicious Software
MP3
MPEG Audio Layer 3
NetBIOS
Network Basic Input/Output System
NFS
Network File System
NIACAP
National Information Assurance Certification & Accreditation Process
NIST
National Institute of Standards and Technology
National information Technology Center - Systems Network Control
NITC- SNCC
Center
NRCS
Natural Resources Conservation Services
NSA
National Security Agency
NTP
Network Time Protocol
OCIO
Office of the Chief Information Officer
OEP
Occupant Emergency Plan
OIG
Office of Inspector General
OMB
Office of Management and Budget
OPM
Office of Personnel Management
PC
Personal Computer
PDA
Personal Digital Assistant
PDD
Presidential Decision Directive
PDSD
Personnel and Document Security Division
PED
Portable Electronic Device
PGP
Pretty Good Privacy
PIA
Privacy Impact Assessment
PKI
Public Key Infrastructure
PL
Public Law
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 91
Number 3602-001
FOR OFFICIAL USE ONLY
ACRONYM
DEFINITION
PM
Program Manager
POP3
Post Office Protocol, version 3
POP3S
Post Office Protocol, version 3, Secure
PROM
Programmable ROM
RA
Risk Assessment
RCF
Remote Call Forwarding
RD
Rural Development
RIP
Routing Information Protocol
RFC
Request for Change
RLOGIN
Remote Login
ROM
Read Only Memory
RPC
Remote Procedure Call
RS
Relay System
S/MIME
Secure/Multipurpose Internet Mail Extension
SAF
Security Architecture Framework
SBU
Sensitive But Unclassified
SCA
Service Center Agency
SCIF
Secure Compartmented Information Facility
SCMI
Service Center Modernization Initiative
SDLC
Systems Development Life Cycle
SF
Standard Form
SIDO
Security Incident Duty Officer
SM
Strategic Manager
SMTP
Simple Mail Transfer Protocol
SNMP
Simple Network Management Protocol
SOW
Statement of Work
SP
Security Plan
SSP
System Security Plan
SRAM
Static Random Access Memory
SSH
Secure Shell
SSI
Sensitive Security Information
SSID
Service Set ID
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 92
Number 3602-001
FOR OFFICIAL USE ONLY
ACRONYM
DEFINITION
SSL
Secure Socket Layer
TACAS
Terminal Access Controller Access System
TCP
Transmission Control Protocol
TFM
Trusted Facilities Manual
TFTP
Trivial File Transfer Protocol
TS
Transfer System
UDP
User Datagram Protocol
UPS
Uninterrupted Power Supply
US-CERT
United States - Computer Emergency Response Team
USDA
United States Department of Agriculture
UUCP
Unix-to-Unix Copy Program
WAN
Wide Area Network
WEP
Wired Equivalent Privacy
VPN
Virtual Private Network
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 93
Number 3602-001
FOR OFFICIAL USE ONLY
Appendix B: Definitions
TERM
DEFINITION
The ability to log on to an information resource through the use of an
identifier, such as a UserID, to associate a person/user with a set of
Access
access authorizations and privileges on a particular information system
(i.e., an account). Generally, an individual must have an account and/or
a password in order to use a system.
The security service that ensures LAN resources are being utilized in an
Access Control
authorized manner.
The formal declaration by the Designated Accrediting Authority (DAA)
that the system is approved to operate using a prescribed set of
Accreditation
safeguards and should be strongly based on the risks identified during
certification.
Active Directory
The directory service for Microsoft Windows 2000 Domain Controllers.
Security commensurate with the risk and magnitude of the harm
resulting from the loss, misuse, or unauthorized access to, or
modification of, information. This includes assuring that systems and
Adequate Security
applications used by the Agency operate effectively and provides
appropriate confidentiality, integrity, and availability, using cost-
effective management, personnel, operational, and technical controls.
A contraction of the words alphabetic and numeric, which indicates a
Alphanumeric
combination of any letters, numbers, and special characters.
A place away from the traditional worksite that has been approved for
Alternative Worksite
the performance of officially assigned duties. It may be an employee’s
home, a Telework Center, or other approved worksite.
Application
A program or system that permits a user to process certain types of data.
Centralized office within the Application Development division of
OCIO-ITS which is established for each IT project and it’s associated
SDLC processing. The mission of the Program Office is to ensure that
Application Development
the appropriate administrative, physical, and technical safeguards are
Program Office (ADPO)
incorporated into all applications, whether new or modified existing
programs. Additionally, it is responsible for generating a strategic plan
for each application or system.
Information system resources that support an OCIO-ITS organizational
Asset
mission. This includes, but is not limited to, property, software, data,
public image, and intellectual property.
An audit trail is a series of records of computer events, about an
operating system, application or user activities. An information
Audit Trail
resource may have several audit trails, each devoted to a particular type
of activity.
Verifying the identity of a user, process, or device, often as a
Authentication
prerequisite to allowing access to resources in an information system.
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 94
Number 3602-001
FOR OFFICIAL USE ONLY
TERM
DEFINITION
The property of being genuine and able to be verified and be trusted;
Authenticity
assurance of the validity of a transmission, message, or originator
within an information system.
The act of empowering and individual with the ability to perform a
specific action with regards to an information system. This action or
Authorization
actions may include the ability to access and/or modify system
software, hardware, networks, etc.
An AIS is any assembly of electronic equipment, hardware, software,
Automated Information
and firmware configured to collect, create, communicate, disseminate,
System
process, store, and control data or information.
That aspect of security that deals with the timely delivery of
Availability
information and services to the user.
Basic Input/Output System
A set of instructions stored in Erasable Programmable Read-Only
(BIOS)
Memory (EPROM) chip on the computer system.
This method of authentication using fingerprint scan, voice recognition,
retina scan, or signature recognition. This may be used as an alternative
Biometric Authentication
to dynamic passwords or smart cards only if it can be proved to provide
a level of reliability.
To start the computer by loading the computer’s operating system into
Boot
the computer's main memory.
Any illegal penetration or unauthorized access to an information
Breach
resource.
Capital Planning and
A systematic approach to selecting, managing, and evaluating
Investment Control
information technology investments.
(CPIC)
The comprehensive assessment of technical and non-technical security
features and other safeguards associated with the use and environment
Certification
of a system to establish whether the system meets a set of specified
security requirements.
A formal evaluation and approval process with regard to technical and
non-technical security controls of an Information Technology (IT)
Certification and
system that establishes the extent to which a particular design and
Accreditation (C&A)
implementation meets a set of specified security requirements based on
an assessment of management, operational, and technical controls
within the IT system.
The Certifying Officer assumes the role of an independent technical
liaison for all stakeholders involved in the Certification and
Accreditation process and is an objective third party, independent of the
Certifying Officer (CO)
system developers. The Certifying Officer provides a comprehensive
evaluation of the system, including technical and non-technical controls,
to determine if the system is configured with the proper security
controls in place.
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 95
Number 3602-001
FOR OFFICIAL USE ONLY
TERM
DEFINITION
Clear Text
Unencrypted information or data.
Software acquired by Government contract through a commercial
Commercial-Off-The-Shelf
vendor. This software is a standard product, not developed by a vendor
(COTS)
for a particular Government project.
The Common Computing Environment was established as an enterprise
Common Computing
system to provide a single, common computing environment for the
Environment (CCE)
Farm Service Agency (FSA), Natural Resources Conservation Service
(NRCS), and Rural Development (RD) agencies of USDA.
The unauthorized disclosure, modification, substitution, or use of
Compromise
sensitive information (includes plaintext cryptographic keys and other
critical security components).
The physical space that houses any equipment or interconnected system
or subsystems of equipment that is used in the automatic acquisition,
Computer Room
storage, manipulation, management, movement, control, display,
switching, interchange, transmission or reception of data or information.
A violation or imminent threat of violation of computer security
Computer Security
policies, acceptable use policies, standard security practices, or an
Incident
exploited system weakness or vulnerability.
Files provided by manufacturers of computer virus detection software to
Computer Virus Definition
identify all known current viruses. As new computer viruses are
Files
identified, virus definition files are updated and released by vendors to
eliminate, prevent, or destroy computer viruses.
Preserving authorized restrictions on information access and disclosure,
Confidentiality
including means for protecting personal privacy and proprietary
information.
A family of security controls on the management class dealing with the
Configuration
control of changes made to hardware, software, firmware,
Management
documentation, test, test fixtures, and test documentation throughout the
lifecycle of an information system.
A plan that describes the management controls involved in all changes
and updates made to a system that affects security. The plan includes
Configuration
all documentation supporting these changes and updates. This plan is
Management Plan
maintained throughout the Certification and Accreditation process and
updated according to system development lifecycle (SDLC) activities.
An action plan for ensuring Information Technology processing
continuity despite catastrophic events. Contingency Plans cover three
types of actions: 1) Emergency procedures for initially responding to
Contingency Plan
disruptions at primary locations; 2) Backup procedures for conducting
operations at alternate locations, when necessary; 3) Recovery
procedures for restoring normal operations back at the primary IT
facility.
Non-Government employee under contract and who use OCIO-ITS
Contractors
information systems or computer resources.
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 96
Number 3602-001
FOR OFFICIAL USE ONLY
TERM
DEFINITION
Any action, device, procedure, technique or measure that reduces a
Countermeasure
system’s vulnerability to a threat.
An intruder who breaks into an information resource or network using a
Cracker
variety of unauthorized access methods, exploiting resources either
maliciously or for personal gain.
Credentials
Identification consists of a unique UserID and password for each user.
Critical information is that information which is used to support
Critical Information
customer service functions and other ongoing business requirements.
The science and practice that embodies principles, means and methods
Cryptography
for the transformation of information to hide its content, prevent its
undetected modification, and prevent its unauthorized use.
The unauthorized accidental or deliberate modification, destruction or
Damage
removal of information or data from an information resource.
Data Encryption Standard
A DES key consist of 64 binary digits of which 567 are randomly
(DES)
generated and used directly by the algorithm per FIPS Publication 46-3
The state that exists when computerized data or information is the same
Data Integrity
as that in the source documents or code and has not been exposed to
accidental or malicious alteration or destruction.
A cryptographic key, which is used to transform data (i.e., encrypt,
Data Key
decrypt, authenticate).
The process of transforming encrypted data into plain or readable
Decryption
information.
Decryption takes encrypted information and makes it comprehensible
Decryption Software
again.
A De-Militarized Zone is logically and physically restricted space that
De-Militarized Zone
may contain sensitive equipment such as firewalls, Intrusion Detection
(DMZ)
Systems (IDS), or network nodes.
The intentional degradation or blocking of computer or network
Denial of Service (DoS)
resources. Action(s) which prevent any part of a computer system or
network from functioning in accordance with its intended purpose.
Designated Accrediting
The DAA determines accreditation based on security risks of the
Authority (DAA)
system, business case, and budget.
A peripheral device that connects computers to each other for sending
Dial-in Modem
communications via the telephone lines.
A plan that identifies recovery procedures in the event of natural or
man-made disasters or catastrophes affecting the availability of the
Disaster Recovery Plan
system. This plan is tested annually to ensure the continued
effectiveness and adequacy of the plan.
The process of transforming readable information into cipher text
Encryption
through a sophisticated mathematical conversion process.
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 97
Number 3602-001
FOR OFFICIAL USE ONLY
TERM
DEFINITION
A computer program that allows data to be encrypted during
transmission (useful for transmitting data across unsecured
Encryption Software
communications links) or in storage of the data (i.e., saving to a PDA,
computer hard disk, floppy disk, or CD).
There are a wide variety of different encryption products available. The
National Institute of Standards and Technology maintains a list of
Encryption Standards
cryptographic modules that have been validated against Federal
Information Processing Standard (FIPS) 140-2.
The process of transforming encrypted data into plain or readable
Exposure
information.
This term includes, but is not limited to, personal and mainframe
computers (networked or stand-alone), software; systems, networks,
Facility
network ports for access, email servers, intranet web servers, and
gateways used to access external networks such as the Internet and
World Wide Web.
A combination of hardware and software that controls network traffic
using stateful inspection of all traffic and monitors and controls sessions
Firewall
between internal and external users and internal networks, computers,
and resources.
A method of communication that incrementally can go from the speed
Frame Relay
of an ISDN to the speed of a T1 line.
The Freedom of Information Act, enacted in 1966, provides that any
person has a right, enforceable in court, of access to Federal Agency
Freedom of Information
records, except to the extent that such records are protected from
Act (FOIA)
disclosure by one of nine exemptions or by one of three special law
enforcement record exclusions.
Interconnected information resources under the same direct
management control that shares common functionality. It normally
includes hardware, software, information, data, applications,
General Support Systems
communications, facilities, and people, and provides support for a
(GSS)
variety of users and/or applications. Individual applications support
different mission-related functions. Users may be from the same or
different organizations.
An individual who attempts to unauthorized access information systems
Hacker
and network resources primarily to create havoc, produce disruptions,
and/or bring the system down altogether.
To damage, injure, or impair information systems using electronic
Harm
methods.
Potential for exceptionally serious impact on an Agency or program
High-risk
mission or the overall efficiency of the service.
The use of an identifier, such as a UserID, to allow an information
Identification
system to associate a person/user with a set of access authorizations and
privileges on a particular information system.
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 98
Number 3602-001
FOR OFFICIAL USE ONLY
TERM
DEFINITION
Requires individual users to be held accountable for their actions after
Individual Accountability
being notified of the rules of behavior in the use of the system and the
penalties associated with the violation of those rules.
Analysis is performed during the initial life cycle phases to determine
Impact Analysis
the overall effect of proposed changes on existing security controls.
Any adverse event, real or suspected, involving the security of OCIO-
ITS information resources is to be considered a security incident. Any
Incident
violation of law, regulation or security policy, real or suspected, is to be
considered a security incident.
Policies, procedures and practices used to report, contain, investigate
Incident Handling and
and preserve evidence and respond to security incidents. Used
Response
synonymously with incident response.
Any OCIO-ITS Information Technology Resource consisting of
Information Resources
personnel, equipment, funds, and information technology.
The protection of data and information systems from unauthorized
Information Security
access, use, disclosure, disruption, modification, or destruction in order
to provide confidentiality, integrity, and availability.
The formal process of identifying each system in terms of its
Information Sensitivity
confidentiality, integrity, and availability.
A discrete set of information resources organized for the collection,
Information System
processing, maintenance, use, sharing, dissemination, or disposition of
information.
The primary role of the ISSPM is to provide security engineering and
Information Systems
security architecture support to the OCIO-ITS. This is performed in
Security Program
formal establishment of realizable security solutions that is consistently
Manager (ISSPM)
applied within OCIO-ITS in compliance with the application
development community.
Any equipment or interconnected system or subsystem of equipment
that is used in the automatic acquisition, storage, manipulation,
management, movement, control, display, switching, interchange,
Information Technology
transmission, or reception of data or information. The term information
(IT)
technology includes computers, ancillary equipment, software,
firmware and similar procedures, services (including support services),
and related resources.
An area of special-use space in OCIO-ITS locations that houses web
Information Technology
farms, computer or telecommunications equipment/devices and the
Restricted Space
general space surrounding those areas.
Office of the Chief
USDA IT component that specializes in providing information
Information Officer
technology support to the Service Center Agencies including Large
(OCIO), Information
Offices, Field Offices, and their partners.
Technology Services (ITS)
Integrity
Guarding against improper information modification or destruction, and
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 99
Number 3602-001
FOR OFFICIAL USE ONLY
TERM
DEFINITION
includes ensuring information non-repudiation and authenticity.
A set of networks and machines that use the TCP/IP protocol suite
Internet
connected through gateways, and share a common name and address
spaces.
The Lab’s primary focus is the testing and approval/disapproval of
legacy and COTS software and hardware products on the CCE
Interoperability Lab (IO
platform. Other functions are system and security configuration
LAB)
management of PC and server rollouts, software repackaging, SNA
gateway configuration, and virus protection administration throughout
the CCE Enterprise Domain.
Intruder
An intruder is a person who is the perpetrator of a security incident.
Intrusion is an unauthorized, inappropriate or illegal activity by insiders
Intrusion
or outsiders that can be considered a penetration or breach of an IT
resource.
Intrusion Detection Systems can include the following four types: 1)
Anomaly Detection - this type picks out traffic, protocols, or packets
Intrusion Detection System
that appear out of the ordinary, 2) Misuse Detection - these identify
(IDS)
threats based on signatures and are similar to antivirus programs, 3)
Passive Systems - these identify and log security compromises, and 4)
Reactive Systems - these block apparent malicious activity.
Represents a broad scope of activities designed to sustain and recover
critical IT services following an emergency. IT contingency planning
fits into a much broader emergency preparedness environment that
includes organizational and business process continuity and recovery
IT Contingency Planning
planning. Ultimately an organization would use a suite of plans to
properly prepare response, recovery, and continuity activities for
disruptions affecting the organization’s IT systems, business processes,
and the facility.
An expenditure of money and/or resources for IT and IT-related
products or services involving managerial, technical, or organizational
IT Investment
risks for which there are expected benefits to the organization’s
performance.
The net mission impact considering 1) the probability that a particular
threat-source will exercise (accidentally trigger or intentionally exploit)
IT Related Risk
a particular information system vulnerability and 2) the resulting impact
if this should occur.
Computer rooms used for housing Web Farms, DMZ equipment,
IT Restricted Space
mission critical systems, systems containing sensitive information and
critical infrastructure resources.
Defining boundaries around a set of processes, communications,
IT System
storage, and related resources (an architecture) identifies a system.
A room that contains equipment used to support Local Area Networks
LAN Room
(LAN). Most LANs connect workstations and personal computers that
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 100
Number 3602-001
FOR OFFICIAL USE ONLY
TERM
DEFINITION
span a relatively small area such as a single building or complex.
The impact an incident has on an organization. Impact includes: loss of
data; the cost to a OCIO-ITS Agency or mission area, negative
Level of Consequence
consequences to the organization (i.e., damage to reputation); and the
magnitude of damage that must be corrected.
An expression of the criticality/sensitivity of an information system in
Levels of Concern
the areas of confidentiality, integrity, availability, and exposure as
expressed qualitatively as high, moderate, or low.
Local Area Network
A LAN connects workstations and personal computers that span a
(LAN)
relatively small area, such as a single building or complex.
A command procedure stored on the laptop with a set of commands for
Login Script
logging into another computer or computer network.
Potential for limited impact on an Agency or program mission or
Low Risk
efficiency of the service.
An application that requires special attention to security due to the risk
and magnitude of the harm resulting from the loss, misuse, or
unauthorized access to or modification of the information in the
application. A breach in a major application might comprise many
Major Application (MA)
individual application programs and hardware, software, and
telecommunications components. Major applications can be either a
major software application or a combination of hardware/software
where the only purpose of the system is to support a specific mission-
related function.
Medium Access Control
At the lowest level, computers communicate with each other using this
(MAC) Address
hardware address.
An operation system and its resource components that are required for
Mission Critical
an OCIO-ITS site to successfully function
Misuse
Unauthorized use of any OCIO-ITS Asset by any individual.
Potential for moderate to serious impact on an OCIO-ITS or program
Moderate-Risk
mission or efficiency of the service.
A part of the U.S. Department of Commerce, formerly called the
National Institute of
National Bureau of Standards, NIST promotes and maintains
Standards and Technology
measurement standards. It also has active programs for encouraging
(NIST)
and assisting industry and science to develop and use these standards.
Information that has been determined pursuant to Executive Order
National Security
12958 or any predecessor order, or by the Atomic Energy Act of 1954,
Information
as amended, to require protection against unauthorized disclosure and is
marked to indicate its classified status.
Those positions involving activities of the Government that are
concerned with the protection of the nation from foreign aggression or
National Security Position
espionage, including development of defense plans or policies,
intelligence or counterintelligence activities, and related activities
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 101
Number 3602-001
FOR OFFICIAL USE ONLY
TERM
DEFINITION
concerned with the preservation of the military strength of the United
States; positions that require regular use of, or access to, classified
information.
Any information system (including any telecommunications system)
used or operated by the OCIO-ITS or by a contractor of the OCIO-ITS,
or other organization on behalf of the OCIO-ITS - 1) the function,
operation, or use of which: involves intelligence activities; involves
cryptologic activities related to national security; involves command
and control of military forces; involves equipment that is an integral
part of a weapon or weapons system; or is critical to the direct
National Security System
fulfillment of military or intelligence missions, excluding a system that
is to be used for routine administrative and business applications, for
format, payroll, finance, logistics, and personnel management
applications; or, 2) is protected at all times by procedures established
for information that have been specifically authorized under criteria
established by an Executive Order or an Act of Congress to be kept
classified in the interest of national defense or foreign policy.
The necessity for access to, knowledge of, or possession of classified or
other sensitive information in order to carry out officially sanctioned
duties. Responsibility for determining whether a person’s duties require
possession or access to this information rests upon the individual having
Need-to-Know
current possession (or ownership) of the information involved, and not
on the prospective recipient. This principle is applicable whether the
prospective recipient is an individual, a contractor, another Federal
Agency or a foreign Government. (Source: USDA DM 3440-1).
A group of computers and associated peripheral devices connected by a
Network
communications channel capable of sharing files and other resources
among several users.
Network-based systems examine the individual packets flowing through
a network. Unlike firewalls, which typically look primarily at IP
Network-Based IDS
addresses and ports, network-based intrusion detection systems are able
to understand all the different flags and options that can exist with a
network packet.
Assurance that the sender of information is provided with proof of
delivery and the recipient is provided with proof of the sender’s
Non-Repudiation
identity, so neither can later legitimately deny having processed, stored,
or transmitted the information.
Potential for limited damage to the national security (Damage to
Non-Sensitive
national security defines National Defense Confidential information).
The OEP provides the response procedures for occupants of a facility in
the event of a situation posing a potential threat to the health and safety
Occupant Emergency Plan
of personnel, the environment, or property. Such events would include
(OEP)
a fire, hurricane, criminal attack or medical emergency. General
Services Administration (GSA) owned facilities maintain plans based
on the GSA OEP template.
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 102
Number 3602-001
FOR OFFICIAL USE ONLY
TERM
DEFINITION
Office of Chief
The USDA's OCIO supervises and coordinates the design, acquisition,
Information Officer
maintenance, use, and disposition of information and information
(OCIO)
technology (IT) by the OCIO-ITS.
The mission of the Office of Inspector General is to investigate
Office of Inspector
allegations of crime against the department’s programs, and to promote
General (OIG)
the economy and efficiency of it operations, with the object of helping
to protect its programs and to ensure integrity.
Security methods that focus on mechanisms that primarily are
Operational Controls
implemented and executed by people as opposed to systems.
A unique, secret, string of alphanumeric characters selected by each
user that is associated with a particular UserID. The password’s
Password
primary function is to protect the UserID from unauthorized use. A
non-display mode is used when the password is entered to prevent
disclosure to others.
A small mobile hand-held device that provides computing and
Personal Digital Assistant
information storage and retrieval capabilities. PDA devices offer
(PDA)
applications such as office productivity, database applications, address
books, schedulers, and to-do lists.
Physical security refers to the protection of building sites and equipment
(and all information and software contained therein) from theft,
Physical Security
vandalism, natural disaster, manmade catastrophes and accidental
damage.
Any electronic device that is capable of receiving, storing, or
Portable Electronic Device
transmitting information using any format (i.e., radio, infrared, network
(PED)
or similar connections) without permanent connections to Federal
networks.
The location where an employee would work absent a Telework
Primary Worksite
arrangement. Also known as a traditional worksite or official duty
station.
Any item, collection, or grouping of information about an individual
that is maintained by an Agency, including, but not limited to, his
education, financial transactions, medical history, and criminal or
Privacy Information
employment history and that contains his name, or the identifying
number, symbol, or other identifying particular assigned to the
individual, such as a finger or voice print or a photograph.
Data which is accessible to all identified and authenticated public users
Public Data
of OCIO-ITS information resources, i.e., customers that use or store
information on OCIO-ITS data resources.
The ability to access OCIO-ITS information and systems from a remote
Remote Access
location, across an external telecommunications service.
A combination of: 1) the likelihood that a particular vulnerability in an
Risk
information system will be either intentionally or unintentionally
exploited by a particular threat resulting in a loss of confidentiality,
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 103
Number 3602-001
FOR OFFICIAL USE ONLY
TERM
DEFINITION
integrity, or availability; and 2) the potential impact or magnitude of
harm that a loss of confidentiality, integrity, or availability will have on
operations (including mission, functions, image, or reputation), assets,
or individuals (including privacy) should the exploitation occur.
A process that includes defining and valuing the assets, defining the
threats to those assets, determining the system’s vulnerabilities, and
Risk Assessment
recommending reasonable safeguards to reduce risks to acceptable
levels.
The ongoing process of identifying, controlling, and mitigating risks to
OCIO-ITS operations (including mission, functions, image, or
reputation), assets, or individuals resulting from the operation of an
Risk Management
information system or multiple information systems. It includes: risk
assessment, cost benefit analysis, and the selection, implementation,
testing and evaluation of security controls.
Rules that have been established and implemented concerning the use
of, security in, and acceptable level of risk for the system. Rules will
clearly delineate responsibilities and expected behavior of all
individuals with access to the system. Rules should cover such matters
Rules of Behavior
as work at home, dial-in access, connection to the internet, use of
copyrighted works, unofficial use of Federal Government equipment,
the assignment and limitation of system privileges, and individual
accountability.
Safeguards
Synonymous with security controls and countermeasures.
A screen engaged by an operating system to prevent screen burns or
Screen Saver
discoloring. Screen savers can be configured to start after a specific
period of time and to also be password protected.
Secure Compartmented
A facility where Sensitive Compartmented Information (SCI) may be
Information Facility
stored, used, discussed, and/or processed is called a Sensitive
(SCIF)
Compartmented Information Facility or SCIF.
The official management decision to authorize operation of an
information system. This authorization, given by a senior OCIO-ITS
official, is applicable to a particular environment of operation, and
Security Accreditation
explicitly accepts the level of risk to operations (including mission,
functions, image, or reputation), assets, or individuals, remaining after
the implementation of an agreed upon set of security controls.
A formal analysis conducted by the Agency Information Systems
Security Program Manager in conjunction with the business owner or
Security Analysis
developer, for the purpose of determining the importance of
information, assessing risks, formulating mitigation strategies, and other
measures needed to safeguard the IT investment.
The automatic logging of successful and unsuccessful access events
Security Audit Logs
including login/logoff, resource access, execution of security
commands, and changes to security tables.
Security Certification
A comprehensive evaluation of the management, operational, and
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 104
Number 3602-001
FOR OFFICIAL USE ONLY
TERM
DEFINITION
technical security controls in an information system. This evaluation,
made in support of the security accreditation process, determines the
effectiveness of these security controls in a particular environment of
operation and the remaining vulnerabilities in the information system
after the implementation of such controls.
The management, operational, and technical controls (safeguards or
countermeasures) prescribed for an information system which, taken
Security Controls
together, satisfy the specified security requirements and adequately
protect the confidentiality, integrity, and availability of the system and
its information.
The Security Plan documents all security-related activities. In the pre-
operation phases of the SDLC, the Security Plan needs to list actions to
ensure that the system is developed in a reasonably secure environment
and that it contains sufficient and appropriate security features. It
defines the security requirements and provides the systematic
Security Plan
management plans to meet those requirements. During the system’s
operation phase, the Security Plan becomes the document for
responding to new vulnerabilities and threats as well as serving as the
primary basis for management reports. It must be updated as least
annually, but may be updated more often prior to the system’s
operational phase.
A document outlining acceptable and unacceptable requirement and
Security Policy
practices directed and with the intent to provide IT security.
Information that is not as critical as Classified Information, the need to
Sensitive But Unclassified
protect this data has been recognized by the administration, law and the
(SBU)
Institute of Standards and Technology .
Information for which unauthorized access to, or the loss or misuse of,
which would adversely affect the national interest or the conduct of
Federal programs, or the privacy to which individuals are entitled under
5 U.S.C. Section 552a (the Privacy Act), but that has not been
specifically authorized under criteria established by an Executive Order
or an Act of Congress to be kept classified in the interest of national
Sensitive Security
defense or foreign policy. Systems that are not national security
Information (SSI)
systems, but contain sensitive information, are to be protected in
accordance with the requirements of the Computer Security Act of 1987
(P.L.
100-235). Some specific categories of sensitive information are
protected by statute, regulation or contract, (i.e., privacy information,
proprietary information, export control information, pre-publication
academic information).
A class of modules that provide automated detection and response to
threats. These modules are installed at strategic locations throughout
Sensors/Taps
the enterprise network and include network sensors, server sensors and
operating system sensors.
A computer or device on a network that manages and hosts network
Server
resources.
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 105
Number 3602-001
FOR OFFICIAL USE ONLY
TERM
DEFINITION
These Agencies, which include FSA, NRCS, and RD, are currently
Service Center Agency
operating in partnership to accomplish a USDA modernization initiative
(SCA)
that establishes a common information technology infrastructure.
Handheld smart cards with embedded microprocessor chips containing
authentication data and verified by a corresponding card reader (i.e.,
PCMCIA slot in a notebook computer) may be used for remote user
authentication, only if used with a secondary (two factor) authentication
Smart Cards
mechanism. Acceptable secondary authentication mechanisms include:
remembered PIN code or Biometric (i.e., signature verification,
fingerprint reader) authentication. PIN codes must not be stored in
close proximity to the smart card and must not be marked on the token.
Simultaneous direct access to a non-USDA network (such as the
Split Tunneling
Internet or a home network) from a remote device while connected into
the OCIO-ITS network via a VPN tunnel.
The OCIO-ITS organization that requested that the third party have
Sponsoring Organization
access into the OCIO-ITS network.
A major subdivision or component of an information system consisting
Subsystem
of hardware, software, or firmware that performs a specific function.
A collection of hardware, software, major application, operating system,
System
and firmware integrated together to perform one or more functions.
The process for creating and implementing information technology-
based system software and hardware inclusive of application code,
System Development
middleware, operating systems, networks, firewalls, routers, switches,
personal computers, servers, mainframe computers, etc., within the
OCIO-ITS.
A contingency planning guide for Information Technology systems. It
is the scope of activities associated with a system, encompassing the
system’s initiation, development and acquisition, implementation,
operation and maintenance, and ultimately its disposal that instigates
System Development Life
another system initiation. The phases through which software evolves
Cycle (SDLC)
from an idea to implementation include the Initiation Phase,
Development Phase, Certification and Accreditation Phase,
Implementation Phase, Operation and Maintenance Phase, and the
Disposal Phase. These phases may vary depending on the complexity
of the system being developed.
The primary liaison for a designated information system within the IT
community. This person is responsible for all information technology-
System Owner
related activities including security. Additionally, this official
represents the interests of the user community throughout the life cycle
of the information system.
A set of requirements that are used to delegate how system security will
be managed. This plan includes system identification, management
Security Plan (SP)
controls, operational controls, and technical controls. The Security Plan
outlines responsibilities for all system users and describes the rules of
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 106
Number 3602-001
FOR OFFICIAL USE ONLY
TERM
DEFINITION
behavior for those users.
Hardware and software controls used to provide automated protection to
Technical Controls
the system or applications. Technical controls operate within the
technical system and applications.
A customized arrangement that allows an employee to work away from
the traditional worksite or official duty station in either 1) his/her home,
2) a Telework center, such as those established by the General Services
Administration (GSA) or, 3) a virtual or mobile office setting. The
Telework
work site is not to be considered a barrier to an employee’s ability to
perform such obligations as official travel, attending face-to-face
meetings and communication with colleagues and customers. Telework
addresses the location of the work site as opposed to the work schedule.
A written agreement completed and signed by an employee and
Telework Agreement
appropriate official(s), that outlines the terms and conditions of the
Telework arrangement.
An employee who, with the approval of his/her supervisor, works full,
part-time at locations, or work sites other than the primary worksite.
Telework Participant
This does not include employees who only work remotely while in
official travel status.
Any circumstance or event with the potential to intentionally or
Threat
unintentionally exploit a specific vulnerability in an information system
resulting in a loss of confidentiality, integrity, or availability.
Triple DES
A key that consist of three DES keys, also referred to as a key bundle.
A Trojan horse is a command procedure containing hidden code that,
Trojan Horse
when invoked, performs some unwanted function. A virus can infect a
legitimate program and transform it into a Trojan horse.
A document listing required security standards and settings, including
implemented setting and standards. The TFM cautions about the
Trusted Facilities Manual
functions and privileges that should be controlled when running a
(TFM)
secure facility and procedures for examining and maintaining audit
trails including the audit trail record structure.
In networking, a gateway is a combination of hardware and software
that links two different types of networks. A secure gateway or firewall
Trusted Network Gateway
blocks or filters access between two networks, often between an internal
trusted network and an external un-trusted (public) network such as the
Internet.
All Federal Employees, Contractors, and volunteers, Permanent or
User
Temporary, which access OCIO-ITS information resources and network
resources.
The authorization code used to identify OCIO-ITS users who are
UserID
entitled to access OCIO-ITS computer resources.
The process of evaluating software at the end of the software
Validation
development process to ensure compliance with software requirements.
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 107
Number 3602-001
FOR OFFICIAL USE ONLY
TERM
DEFINITION
The process used by an independent certification agent to confirm or
Verification
establish by testing, evaluation, examination, investigation or competent
evidence.
A technology by which authorized individuals (such as remote
employees) can gain secure access to an organization’s intranet via the
Internet. VPN technology provides secure data transmission across
Virtual Private Network
public network infrastructures. VPNs employ cryptographic techniques
(VPN)
to protect information as it passes from one network to the next or from
one location to the next. Data that is inside the VPN tunnel, the
encapsulation of one protocol packet inside another, is encrypted and
isolated from other network traffic.
A program that searches out other programs and infects them by
embedding a copy of itself within the other programs. When the other
Virus
programs are executed, the embedded virus is executed, thus spreading
the infection.
A condition or weakness in security procedures, technical, management
Vulnerability
or physical controls that could be exploited by a threat.
A test of the network’s or system’s vulnerability to known exploits and
Vulnerability Scan
attack methods, by either passive (non-intrusive) or active (intrusive)
scanning of network points of access.
A formal approval to not comply with a security policy or exemption
Waiver
from a security policy.
A web farm is an integrated collection of firewalls, switches, servers,
back-up libraries and other components that are precisely focused to
Web Farm
develop and maintain a secure, scalable and redundant web delivery
infrastructure.
Any digital communication protocol or process that does not require a
Wireless Access
physical connection media. This includes but not limited to all 802.11
a/b/g or infer-red access devices or point-to-point devices.
A transport mechanism that supports communication between mobile,
Wireless Technology
portable, or fixed facilities using the electromagnetic spectrum without
a physical connection.
A self-replicating program that is self-contained and does not require a
host program. It is designed to propagate through a network rather than
Worm
just a single computer. A worm exploits flaws in operating systems or
inadequate system configurations. Release of a worm usually results in
brief, but spectacular, outbreaks that can shut down entire networks.
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 108
Number 3602-001
FOR OFFICIAL USE ONLY
Appendix C: OCIO-ITS Security Waiver Form
OCIO-ITS Security Waiver Form
Requests for exceptions to these waiver requirements will include a persuasive and cogent justification.
The waiver package will include the following:
1.
An explanation of exception requested.
• Identify which policy and item(s) the exception covers and provide information detailing the
exemption requested. Explain why the policy cannot be implemented.
2.
Business case necessitating the service.
• How will the lack of this exemption impact program delivery?
3.
Is sensitive (SBU) information involved?
• Details explaining how the confidentiality, integrity and availability of the sensitive information
will be preserved.
• Since this exemption may increase the vulnerabilities to the system/application, how will the
information be safeguarded?
4.
Technical details of the proposed alternative approach.
• Explain the technical solution. Include diagrams that show the current condition and what the
proposed alternative approach will look like (before and after). If this is provided electronically,
use Visio or a similar type of software.
5.
Associated security costs for the Agency requested solution funded by the proposing Agency (Include
a copy of any IT Moratorium Waiver Request and associated hardware and software costs not
covered in waiver)
• How much is this going to cost? How does this compare to the cost of implementing the policy?
6.
Risk analysis of the proposed alternative approach.
• Since this exemption may increase the vulnerabilities to the system/application, a risk assessment
needs to accompany this request. What are some of the current exploits of these vulnerabilities
identified in risk analysis and how are these addressed by the proposed solution?
7.
Assurances that any alternatives implemented will not adversely affect the costs, security,
maintenance or operations of existing solutions implemented by other Departmental entities.
• Who else is potentially at risk and are they aware of the risk?
8.
A schedule and tasks to be undertaken to become compliant.
• When do you plan to become compliant with OCIO-ITS policy? Provide an action plan and
appropriate milestones. Typically the plan should run no more than a year. Waivers for longer
than 12 months will be re-evaluated periodically.
NOTE: Any alternatives implemented will be subject to periodic reviews and must be adjusted, as
necessary, to conform to the USDA Enterprise Architecture and Security standards. Waiver packages
will be forwarded to the ITS Information Systems Security Program Manager (ISSPM) in accordance
with normal procedures. These packages will be forwarded to OCIO Cyber Security for review and
further action. Additionally, all waiver packages are subject to review by the OIG and other audit bodies.
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 109
Number 3602-001
FOR OFFICIAL USE ONLY
OCIO-ITS Security Policy Manual - FINAL - Version 1.0
Page 110
Number 3602-001
FOR OFFICIAL USE ONLY
DEPARTMENT OF THE NAVY
Headquarters United States Marine Corps
Washington, D.C. 20380-1775
13 October 2010
FOREWORD
Marine Corps Warfighting Publication (MCWP) 4-11.9, Ammunition Logistics, provides
guidance for commanders, staffs, logisticians, ammunition and aviation ordnance
officers, supply officers, and ammunition and aviation ordnance Marines. This
publication discusses the Marine Corps ammunition and aviation ordnance communities’
organization and support structure, the general responsibilities of ammunition and
aviation ordnance personnel, the systems used in support of ammunition logistics,
planning considerations, safety issues, training, and the regulatory environment in which
Marine Corps ammunition logistic operations are planned and executed. Various
elements of Navy supporting establishments with ammunition responsibilities that have
not been addressed in other USMC Service doctrine are introduced in the MCWP 4-11.9.
This publication’s purpose is to extend the concepts established by Marine Corps
Doctrinal Publication 4, Logistics; MCWP 4-1, Logistics Operations; MCWP 4-11, Tac-
tical Level Logistics; MCWP 4-11.7, MAGTF Supply Operations; MCWP 3-21.2,
Aviation Logistics; and Field Manual 4-30.1, Munitions Support in the Theater of
Operations, as they apply to ammunition operations for the operating forces. This
publication describes Marine Corps ammunition and aviation ordnance logistic operations
in both garrison and expeditionary environments. Applicable tactics, techniques and
procedures from other Service manuals have been incorporated. The overall intent is to
provide a single-source, informative reference for Marine Corps ammunition logistics.
In order to reach the widest possible audience, this publication will address ammunition
as a general use commodity, only distinguishing between subclass V(W) ground
ammunition and subclass V(A) aviation ordnance where it is absolutely necessary. In
general, wherever the terms ammunition, munitions, or ordnance appears in this
document it should be construed as both ground ammunition and aviation ordnance,
unless one term or the other is specifically applicable to the subject.
FOR OFFICIAL USE ONLY
Reviewed and approved this date.
BY DIRECTION OF THE COMMANDANT OF THE MARINE CORPS
GEORGE J. FLYNN
Lieutenant General, U.S. Marine Corps
Deputy Commandant for Combat Development and Integration
Publication Control Number: 143 000160 00
DISTRIBUTION STATEMENT C: Distribution authorized to U.S. Government agencies
and their contractors. Other requests for this document will be referred to Marine Corps
Combat Development Command, Capabilities Development Directorate, Logistics Inte-
gration Division.
FOR OFFICIAL USE ONLY
AMMUNITION LOGISTICS
TABLE OF CONTENTS
Chapter 1: Overview
Strategic, Operational, and Tactical Logistics
1-1
Strategic Logistics
1-1
Operational Logistics
1-2
Tactical Logistics
1-2
DOD Munitions Requirements Process
1-2
Implementation of the Munitions Requirements Process
1-3
Roles and Responsibilities
1-3
Chief of Naval Operations Responsibilities
1-3
Navy Organizational Responsibilities
1-3
Deputy Commandant for Installations and Logistics
1-3
Deputy Commandant for Aviation
1-4
Commanding General, Marine Corps
Combat Development Command
1-4
Commanding General, Training and Education Command
1-4
Commander, Marine Corps Systems Command
1-4
Deputy Chief of Naval Operations for
Fleet Readiness and Logistics
1-4
The Naval Operational Logistics Support Center
1-4
Service Requirements Determination
1-4
War Reserve Munitions Requirement
1-6
Training and Testing Requirement
1-6
Universal Need Statement
1-6
Class V(A) Requirements Determination
1-6
Resourcing
1-7
Class V Acquisition
1-7
Acquisition of Marine Corps Ground Ammunition
1-7
Acquisition of Navy Munitions
1-7
Quality Evaluation
1-7
Care of Supplies in Storage
1-8
Class V(W) Maintenance
1-8
Disposal
1-9
The Marine Corps Combat Logistics Organization
1-9
Marine Logistics Group
1-9
Marine Aviation Logistics Squadron
1-10
Chapter 2: General Class V Management
Logistic Operational Architecture
2-1
Request Management
2-1
Order Management
2-1
FOR OFFICIAL USE ONLY
_____________________________________________________________________________________________________
iv
MCWP 4-11.9
Capacity Management
2-1
Production Management
2-1
Execution
2-2
Ordnance Information System
2-2
The Marine Corps and Ordnance Information System
2-2
Marine Corps Class V Inventory Management Systems
2-2
Navy Class V Inventory Management Systems
2-2
Future Capabilities
2-2
Munition Inventory and Transaction Reporting
2-3
Asset Visibility and Accountability
2-3
Malfunction Reporting
2-3
Supply Discrepancy Report
2-3
Missing, Lost, Stolen, or Recovered
2-3
Automatic Identification Technologies
2-4
Chapter 3: Operational Ammunition Requirements Determination
Ground Ammunition
3-1
Aviation Ordnance
3-1
Modeling/Deliberate Planning for Major
Operations and Campaigns
3-1
Execution of a Deliberate Plan
3-2
Crisis Action/Contingency Planning
and Immediate Requirements Determination
3-2
Transition of Class V(W) Combat Planning Factors
3-2
Operational Requirements in a Joint Environment
3-2
Expressing Capabilities and Requirements for Class V(W)
3-3
Combat Load
3-3
Day of Ammunition
3-3
Combat Load Versus Day(s) of Ammunition
3-4
Chapter 4: Class V Movement Planning
Planning for Class V Combat Logistic Support
4-1
Special Consideration During Movement Planning
4-2
The Global Command and Control System
4-2
Joint Operation Planning and Execution System
4-2
The Global Combat Support System-Joint
4-2
Joint Force Requirements Generator II
4-2
Logistics Automated Information
Systems and Aviation Logistics
4-3
Class V Sourcing
4-3
War Reserve Positioning
4-3
Class V(W) Sourcing
4-3
Class V(A) Sourcing
4-4
Transportation Planning
4-4
FOR OFFICIAL USE ONLY
Ammunition Logistics____________________________________________________________________________________________ v
Time-Phased Force and Deployment Data
4-4
Validation
4-6
Reports
4-6
Flow Initiation Class V(W)
4-6
Planned Class V Sustainment Flow Notification
4-7
Chapter 5: Movement, Mobility, and Deployment of Class V Materiel
Transportation Funding
5-1
Transportation and Asset Tracking
5-1
Organizations Supporting Movement of Class V
5-2
United States Transportation Command
5-2
Air Mobility Command
5-2
Military Sealift Command
5-2
Prepositioning Ships
5-2
Sealift Ships
5-2
Military Surface Deployment and Distribution Command
5-2
Joint Munitions Command
5-3
Joint Munitions Transportation Coordinating Activity
5-3
Naval Operational Logistics Support Center
5-3
Modes of Shipment
5-3
Airlift
5-4
Strategic Airlift
5-4
Channel Lift
5-4
Ship Movement
5-4
Surface Movement
5-4
Strategic Ammunition Ports
5-4
Military Ocean Terminal, Sunny Point
5-4
Military Ocean Terminal, Concord
5-4
Navy Munitions Command, Detachment Indian Island
5-4
Additional Ammunitions Ports (Nonstrategic)
5-5
Navy Munitions Command, Detachment Charleston
5-5
Navy Munitions Command, Detachment Earle
5-5
Blount Island Terminal, Jacksonville
5-5
Chapter 6: Ammunition/Aviation Ordnance Operations
Reception and Staging
6-1
Naval Expeditionary Logistics Support Force
6-1
Navy Cargo Handling Battalion
6-1
Naval Ordnance Reporting and Handling Battalion
6-1
Port and Terminal Operations
6-1
Operational Safety Concerns
6-2
Onward Movement and Integration
6-2
Movement
6-2
Combat Logistic Support During Amphibious Operations
6-3
FOR OFFICIAL USE ONLY
_____________________________________________________________________________________________________
vi
MCWP 4-11.9
Storage
6-3
Aviation Ground Support
6-5
Aviation Logistic Support
6-6
Forward Arming and Refueling Points
6-6
Security
6-6
Distribution
6-7
Distribution Methods
6-8
Distribution Method Considerations
6-8
The Munitions Report
6-8
Sustainment and Resupply
6-8
Class V Resupply
6-8
Theater-Level Class V General Support
6-9
Class V(A) Sustainment
6-9
Sustainment Planning
6-9
Supply Rates
6-9
Class V External Support
6-9
Common Item Support
6-9
Cross-Service Support
6-11
Common Item Support Versus Cross-Leveling
6-11
Class V(A) and Common Item Support
6-11
Chapter 7: Retrograde Operations
General Retrograde Planning
7-1
Operational Safety
7-2
Condition of Munitions
7-2
Functional Considerations
7-2
Retrograde Operations
7-3
Visibility and Accountability
7-3
Segregation and Inspection
7-3
Packaging and Packing Materials
7-4
Unserviceable Munitions
7-4
Other Considerations
7-4
Safety
7-4
Destruction of Ammunition
7-4
Routine Destruction
7-4
Emergency Destruction
7-5
Ammunition Maintenance
7-5
Physical Security
7-6
Transportation and Storage
7-6
Ammunition Supply Points
7-7
Retrograde Turn In
7-7
Chapter 8: Class V for the Marine Expeditionary Unit
The MEU as Part of an Expeditionary Strike Group
8-1
Landing Force Supplies
8-1
Combat Load
8-1
FOR OFFICIAL USE ONLY
Ammunition Logistics__________________________________________________________________________________________ vii
Prepositioned Emergency Supplies
8-1
Remaining Supplies
8-1
Landing Force Operational Reserve Material
8-1
Mission Load Allowance
8-2
Ground Ammunition Personnel Afloat
8-2
Aviation Ordnance Personnel Afloat
8-3
Appendices
A. Class V Support Under Unified Action
A-1
B. Safety, Training, and Environmental/Regulatory Requirements
B-1
Glossary
References and Related Publications
FOR OFFICIAL USE ONLY
CHAPTER 1
OVERVIEW
Class V ammunition is a complex commodity in
end item, it is funded and procured through a
terms of research and development, acquisition,
complex cycle of processes managed at the Ser-
life cycle management, and, eventually, disposal.
vice headquarters level.
The Department of Defense (DOD) spends bil-
lions of dollars annually to develop and acquire
new munitions and to replenish stocks expended
STRATEGIC, OPERATIONAL,
in training and operational use. Therefore, the
AND TACTICAL LOGISTICS
business of ammunition, supply Class V, is a com-
plex and highly interrelated venture composed of
Strategic, operational, and tactical logistics are
planning, requirements determination, resourcing,
the supporting triad that enables commanders to
acquisition, storage, maintenance, quality eval-
execute modern expeditionary warfare. Opera-
uation, multimodal transportation, movement and
tional logistics is the bridge between organic
retrograde planning and execution, explosives
capabilities that serve tactical requirements and
safety, disposal, and, most importantly, sustain-
strategic or national capabilities. Tactical logis-
ment of the operating forces whether in garrison
tics includes organic unit capabilities and the
or deployed.
combat service support that is necessary to sup-
port military operations. Combat service support
Ground ammunition and aviation ordnance are
is executed in the form of general and direct sup-
two of the most complex commodities used by
port obligations.
the operating forces to sustain combat, contin-
gency, and training operations. Although funda-
Strategic Logistics
mentally a supply commodity, Class V materiel
Strategic logistic capabilities are generated based
has a number of management attributes that do
on guidance from the President and/or Secretary
not apply to general supplies and requires
of Defense, the Joint Chiefs of Staff, and logistic
specialized storage, handling, transportation, and
requirements that are identified by the operating
inventory control methods.
forces. Upon receipt of an execution, the Service
Like fuel or food, ammunition is a consumable
components will execute Class V sourcing to
item; however, ammunition is often character-
meet the combatant commanders (CCDRs)/joint
ized by variable rates of consumption. Thus, it
force commanders (JFCs) requirements and move
the materiel into theater and areas of operations.
must be replenished from time to time, to ensure
sufficient stocks are available on short notice in
Therefore, the Service component commander
the event of a contingency. In addition, unlike
must rely on force-held stocks for initial accom-
most consumables, Class V materiels cannot be
panying supplies. The commander is then
procured on the open market. Like principal end
dependent on the respective Navy or Marine
items such as tanks or the expeditionary fighting
Corps inventory control point (ICP) to provide
vehicle, Class V materiel is characterized by
the balance of identified requirements. The
long lead times for production; in most cases,
Defense Logistics Agency is a significant agent
upwards of several years. Also like a principal
in supplying deployed forces with many of the
FOR OFFICIAL USE ONLY
1-2 ____________________________________________________________________________________________________ MCWP 4-11.9
commodities and parts that are required. However,
Tactical Logistics
Defense Logistics Agency has no Class V
responsibilities or capabilities.
Class V is delivered to tactical level combat sup-
port agencies during the integration phase of the
Operational Logistics
RSOI process. Tactical logistics includes organic
capabilities and the combat support activities that
Operational logistics connects the logistic efforts
are necessary to support military operations.
of the strategic level with those of the tactical
level. The reception, staging, onward movement,
and integration (RSOI) process is the operational
DOD MUNITIONS
level activity that brings strategically delivered
REQUIREMENTS PROCESS
ammunition through the ports and to the tactical
level combat logistic agencies. The RSOI
process involves identification of containers, the
Each Military Service is required to identify a
major subordinate command, and the cargo’s
total munitions requirement (TMR) to arm their
intended destination.
weapon systems and forces to perform their
assigned military mission. The steps and
Class V material will often be delivered to
procedures for doing so are depicted in figure 1-1
multiple locations, which is determined by
and are described in DOD Instruction (DODI)
Service component and the type of activity being
3000.4, DOD Munitions Requirements Process
supported. Great care must be taken when
(DOD MRP).
storing ammunition before the local storage sites
are prepared.
1.
Combat Requirement
6.
4.
Total Munitions
War Reserve Munitions
Phased Threat
Requirement
Requirement
Distribution
5.
2.
Training and Testing
8.
Strategic Readiness
Requirement
Program
Requirement
Development
3.
Current Operation/
7.
Forward Presence
Projected
Requirement
Inventory
Figure 1-1. Munitions Requirements Process.
FOR OFFICIAL USE ONLY
Ammunition Logistics__________________________________________________________________________________________ 1-3
Chief of Naval Operations Responsibilities
IMPLEMENTATION OF THE
MUNITIONS REQUIREMENTS PROCESS
The CNO provides Service headquarters-level
munitions management support to the operating
Marine Corps Order (MCO) 8000.7, Marine
forces. In concert with the Marine Corps’ Deputy
Corps Capabilities-Based Munitions
Commandant (DC) for Aviation, they collectively:
Requirements (MCCBMR) Process for Ground
z
Coordinate with MARFOR, CINCs
[Navy
Ammunition (Class V[W]),provides a full
Commander in Chiefs] , and other major
explanation of the munitions requirements pro-
cess
(MRP) and the Marine Corps’
claimants to obtain accurate input to the
implementation of this process for Class V(W).
NNOR and to ensure training and testing
The Navy implements MRP through the
requirements (TTRs) are submitted.
nonnuclear ordnance requirement (NNOR) pro-
z
Provide ordnance logistic guidance and policy
cess described in the current editions of Office of
during the deliberate planning process.
the Chief of Naval Operations Instruction
z
Pass TTR inputs to the Naval Operational
(OPNAVINST) 8011.9A, Non-Nuclear
Logistics Support Center (NOLSC) and
Ordnance Requirements (NNOR) Process, and
resource sponsors for development of the CNO-
OPNAVINST 8010.12F, Naval Conventional
and CMC-approved noncombat expenditure
Ordnance Operational Logistics Policy.
allocation.
z
Approve and promulgate annual noncombat
expenditure allocation to the numbered fleet
ROLES AND RESPONSIBILITIES
commanders, MARFOR, and other major
claimants for further distribution to the naval
Responsibilities and capabilities for munitions
forces.
management overlap because no organization or
z
Resolve Class V(A) materiel shortfalls identified
level of support can function effectively without
during the deliberate planning process.
extensive coordination between supported and
supporting organizations. Responsibility for
Class V(W) ammunition within the Marine Corps
Navy Organizational Responsibilities
rests with multiple departments within Headquar-
ters, Marine Corps (HQMC), Marine Corps Com-
Since Class V(A) aviation ordnance material used
bat Development Command (MCCDC), Training
by the Marine Corps is procured and managed by
and Education Command (TECOM), Marine
the Navy, the CNO and CMC headquarters staffs
Corps Systems Command (MARCORSYSCOM),
jointly have specific responsibilities for overall
and the Marine Corps forces (MARFOR).
naval ordnance management.
Class V(A) aviation ordnance material used by
Deputy Commandant for
the Marine Corps is procured and managed by the
Installations and Logistics
Navy, Chief of Naval Operations (CNO) and
Commandant of the Marine Corps (CMC) head-
The DC for Installations and Logistics establishes
quarters staffs. Each staff has specific responsi-
logistic and materiel management policies for all
bilities that collectively manage naval ordnance.
Marine Corps-owned equipment and supplies.
Operational requirements are principally the
With few exceptions, these policies are applicable
domain of the operating forces and are discussed
to all classes of supply managed by the Marine
in detail in chapter 4. Details on Class V support
Corps, including Class V(W) ground ammunition.
under unified action can be found in appendix A.
FOR OFFICIAL USE ONLY
1-4 ____________________________________________________________________________________________________ MCWP 4-11.9
Deputy Commandant for Aviation
testing, and ammunition assets undergoing
maintenance or renovation.
The DC for Aviation assists the Deputy CNO for
Fleet Readiness and Logistics (N4) in esta-
Deputy Chief of Naval
blishing acquisition and fielding policies for
Operations for Fleet Readiness and Logistics
aviation ordnance materiel used by Marine avia-
Class V(A) logistic and materiel management
tion organizations.
policies for munitions used by Marine aviation
are separately prescribed by the Deputy Chief of
Commanding General, Marine
Naval Operations for Fleet Readiness and
Corps Combat Development Command
Logistics (N4) and implemented through the
The Commanding General (CG), MCCDC is
Commander, Naval Supply Systems Command
(NAVSUPSYSCOM).
responsible for establishing the Class V(W) TMR
and publishing planning factors for combat and
The Naval Operational
contingencies. The CG, MCCDC is also the DC
Logistics Support Center
for Combat Development and Integration.
The NOLSC will provide ICP-level management
Commanding General,
for naval ammunition, serving as the
Training and Education Command
NAVSUPSYSCOM operational and joint force to
the Navy component commanders and to the
The CG, TECOM determines training require-
unified commanders.
ments and provides Class V(W) materiel allow-
ances for all Marine Corps training requirements.
SERVICE
Commander, Marine
REQUIREMENTS DETERMINATION
Corps Systems Command
The Commander, MARCORSYSCOM is
Determination of Service-wide ammunition
responsible for research, development, and
requirements is a complex task, and it is the
acquisition of Marine Corps systems, equipment,
responsibility of a multitude of agencies identi-
and materiel. The Program Manager for Ammu-
fied in figure 1-2.
nition (PM Ammo) performs these functions for
the commander with respect to Class V(W). The
In the 1990s, following Operations Desert
PM Ammo is a unique organization within the
Shield/Desert Storm, it became apparent that a
Marine Corps and within DOD. The organization
more sophisticated process was required for
performs or manages all life cycle tasks
determining the Services’ ammunition require-
associated with Marine Corps ground ammu-
ments. This complex analysis provides a greater
nition. Among these responsibilities is providing
role for the CCDRs/JFCs and the Service com-
worldwide ICP services for the Marine Corps.
ponents of the operating forces, and one that
This includes ammunition stocks held as war
begins much earlier in the process. This process
reserve, stocks procured or held for training and
is the MRP. The product of the MRP is a TMR.
FOR OFFICIAL USE ONLY
Ammunition Logistics__________________________________________________________________________________________ 1-5
OSD (AT&L)
OSD (P)
DIA
COCOMs
J8
POM MRP
Kickoff
Implementation
Threat Reports
Near-Year PTDs
Out-Year PTDs
Conference
Guidance
OCT
NOV
FEB
JUN
JUL
MARFORs
MCSC
TFSD
Testing
TPFDDs
TFSMS Data
Requirements
MARFORs
MCSC
TECOM
QUANTICS
MCCDC
MCCDC
30 Sep
OPLAN
Inventory/
Training
Run USMC
Analyze/ Review
Submit Signed
Validation
Requirements
WRMR Model
Output Results
TMR
Deliveries
PP&O
FMID/PP&O
JTCG/ME
OCT - DEC
Warfighting-
SME Input
JMEMS Data
Capabilities
Validation
Requirements
JUN - SEP
MCCDC
MCCDC
CJCS/Services
Run USMC
Analyze/ Review
Submit Signed
WRMR Model
Output Results
TMR
FEB
SEP
SEP
CJCS
Chairman of the Joint Chiefs of Staff
DIA
Defense Intelligence Agency
FMID
Fires and Maneuvers Integration Division
JMEMS
Joint Munitions Effectiveness Manuals
JTCG/ME
Joint Technical Coordination Group for Munitions
MCCDC
Marine Corps Combat Development Command
MCSC
Marine Corps Systems Command
OPLAN
Operational Plan
OSD(AT&L)
Operational Services Division (Acquisition Technology and Operational)
OSD(P)
Office of Secretary of Defense Policy
POM
Program Objective Memorandum
PP&O
Plans, Policy, and Operations
PTD
Phased Threat Distribution
SME
Subject Matter Expert
TFSD
Total Force Structure Division
TFSMS
Total Force Structure Management System
WRMR
War Reserve Munitions Requirement
Figure 1-2. Munitions Requirements for Program Objectice Memorandum Cycle.
FOR OFFICIAL USE ONLY
1-6 ____________________________________________________________________________________________________ MCWP 4-11.9
The TMR for each Service is the sum of the war
Defense Program requirement, and/or projected
reserve materiel requirement (WRMR) and the
life cycle of each munition. Surveillance, accep-
TTR. The following paragraphs discuss the further
tance testing, and production losses of munitions
subdivision of these two main requirements.
items are accounted for in this category.
War Reserve Munitions Requirement
Universal Need Statement
The three components of the WRMR are the
During operational execution, requirements are
combat requirement, the strategic readiness
updated as needed or conditions change through
requirement, and the current operations/forward
the UNP [universal need process] .
presence requirement.
The component commander may initiate the
universal need statement (UNS) process at any
Combat Requirement
time. Through the chain of command, the UNS is
The combat requirement represents the quantity
ultimately presented to the CG MCCDC. If the
of munitions that are required in order to equip a
CG MCCDC validates the requirement, it is
specified force structure to perform its assigned
forwarded to the Marine Requirements Oversight
military mission and to meet CCDR/JFC objec-
Council (MROC). The MROC is a panel of
tives, including munitions needed for overlapped
senior officers headed by the Assistant Comman-
threat allocations.
dant of the Marine Corps; its members consist of
the DCs of all departments.
Strategic Readiness Requirement
If approved by the MROC, the DC for Program
The strategic readiness consists of the quantity of
and Resources provides fiscal resources, or may
munitions needed to arm forces that are not com-
direct the realignment of existing funds origi-
mitted to support combat operations in the
nally allocated for another program. The develop-
assigned major operations and campaigns, as
ment or procurement of the requested item is the
well as those in the strategic reserve. This also
responsibility of MARCORSYSCOM, along with
includes any additional munitions requirements
the total life cycle management of the material
generated from treaties or statutory obligations
solution to the operational requirement.
to allies.
For example, during Operations Iraqi Freedom
and Enduring Freedom there were a number of
Current Operations/Forward
instances where validated requirements (via the
Presence Requirement
appropriate chain of command) were provided to
The current operations/forward presence require-
PM Ammo, MARCORSYSCOM for immediate
ment represents the sum of munitions that are
sourcing, procurement, and delivery. These UNS
required to arm forces, conduct current opera-
included shoulder-launched multipurpose assault
tions, and meet forward presence obligations in
weapon rocket (with novel explosive [thermo
accordance with DODI 3000.4.
baric]), 5.56mm nonmolybdenum coated 77 grain
projectile, the surface demining flare, and the
Training and Testing Requirement
light assault weapon (rocket).
The TTR is the munitions required in order to
Class V(A) Requirements Determination
train the Marine Corps and support its Service
programs ensuring that weapons and platforms
The Navy and Marine Corps aviation component
deliver the intended effectiveness. This can be
of the MRP is the NNOR process. The NNOR
stated as an annual requirement, a Future Years
identifies ordnance ship fill, combat expenditures,
FOR OFFICIAL USE ONLY
Ammunition Logistics__________________________________________________________________________________________ 1-7
maintenance pipeline and training, testing,
ammunition items that are used by the Marine
current operations, and forward presence require-
Corps are common to the Army and/or other
ments to accomplish Navy and Marine Corps’
Services. For common items, Marine Corps funds
missions and to execute the scenarios outlined in
are transferred to PEO Ammo located at Picatinny
DODI 3000.4. The output of the NNOR provides
Arsenal, NJ, because one Service is responsible
the Department of the Navy’s (DON’s) baseline
for providing the acquisition support infrastructure
input into the DOD Planning, Programming, and
for two or more user Services. All Service-unique
Budgeting System.
munitions are procured through Navy Program
Managers or directly by PM Ammo.
Acquisition of Navy Munitions
RESOURCING
The Navy has a complex munitions acquisition
The DC for Programs and Resources develops
infrastructure that is built around the PEOs for
and manages the Marine Corps’ budget process,
various weapons platforms and combatants that
makes high-level investment decisions, and allo-
are currently in the operating forces. For the pur-
cates the funds appropriated by the Congress to
poses of this publication, the primary interest is
meet the Marine Corps’ mission needs. The DC
on the Class V(A) aviation ordnance procured by
for Programs and Resources also works closely
the Naval Air Systems Command affiliated PEOs
with the Navy counterpart to ensure that the Navy
for use by naval aviation.
and Marine Corps programs and priorities are
aligned to serve a common naval logistic inte-
Quality Evaluation
gration strategy for the operating forces and the
supporting establishment.
Quality evaluation (QE) is a broad, general term
applied to a set of inspections, functional testing,
and laboratory analysis of representative munition
lot samples taken from the inventory for the sole
CLASS V ACQUISITION
purpose of assessing the proper state of the
inventory. Quantity, exposure to environmental
Acquisition (or procurement) of munitions is a
elements during storage, age, malfunction history,
complex process, and it is collaboratively
and manufacturing variables are considered when
executed by acquisition professionals, graduates
selecting samples. Random sampling of available
of the Defense Acquisition University, and com-
lots provides a statistically sound method and
modity subject matter experts. These acquisition
repeatable results in determining reliability and
professionals and subject matter experts are
probabilities of future performance at a given
located with the various Navy/Marine Corps pro-
confidence level. From these determinations,
gram executive offices (PEOs) and program
inventory management decisions such as global
managers, such as Naval Sea Systems Com-
positioning, reclassification, and maintenance
mand, Naval Air Systems Command,
options can be implemented.
MARCORSYSCOM, and the Army’s Program
Executive Office, Ammunition (PEO Ammo).
In addition, quality audits of vendors/suppliers
are conducted that include the following:
Acquisition of Marine
z
Reviewing vendor/supplier’s quality system
Corps Ground Ammunition
procedures.
Acquisition of Marine Corps ground ammunition
z
Conducting on-site auditing of vendors and/or
is managed and executed by the PM Ammo,
suppliers.
MARCORSYSCOM. Most Class V(W) ground
z
Auditing and reviewing of maintenance lines.
FOR OFFICIAL USE ONLY
1-8 ____________________________________________________________________________________________________ MCWP 4-11.9
z
Participating in pre- and post-contract award
the care and maintenance of those stocks rests
and facility reviews.
with the owning Service. There is a large
z
Reviewing contracts and solicitations.
quantity of ammunition that is held by the
z
Monitoring first article acceptance tests and lot
Services in order to meet wartime requirements,
and the special storage requirements associated
acceptance tests.
with ammunition for safety and security belongs
to the owning Service. A significant portion of
The Navy and Marine Corps both conduct exten-
Marine Corps-owned ammunition is stored in
sive stockpile QE and in-Service engineering
other-Service facilities, primarily Army, and to a
support activities on their respectively-owned
lesser extent, Navy tidewater activities, amphi-
stocks. The Marine Corps and the Navy conduct
bious shipping, and maritime prepositioning
functional testing and laboratory analysis of rep-
ships (MPS). A small percentage of Marine
resentative lot samples from the inventory.
Corps-owned ammunition is also held in host
The Services conduct an extensive quality assu-
nation (HN) facilities as geoprepositioned
rance and stockpile monitoring effort for most
stocks, with the HN providing care of supplies
Class V assets. Quality is ensured through
in storage.
assessments and audits of manufacturers, as well
The Navy is responsible for the care and main-
as surveillance and maintenance programs. The
tenance of those stocks held in Navy storage
Marine Corps generally contracts for the requisite
facilities, including Class V(A) aviation ord-
engineering and technical support from a variety
nance. Like the Marine Corps, a portion of the
of Army and Navy technical and engineering
Navy’s large inventory is stored in other-Service
support agencies to accomplish this task. For the
facilities, primarily the Army. However, unlike
Navy, much of this support is organic.
the Marine Corps, a substantial portion of the
Oversight for QE and in-Service engineering
Navy’s preferred weapons inventory is embarked
activities on Navy ammunition is the respon-
in the Navy’s combatant vessels as ship’s allow-
sibility of the Deputy CNO (Fleet Readiness and
ance; on combat logistics force (CLF) shipping as
Logistics) (N4). The CNO is responsible for
replenishment stocks; or is stored at tidewater
assessing the maintenance and QE programs to
weapons stations, on amphibious shipping, and
ensure optimization of resources and compliance
on MPS. A small percentage of Navy-owned
with OPNAVINST 4850.1, Conventional
ammunition is also held in HN facilities as
Ordnance Assessment and Maintenance Re-
geoprepositioned stocks (principally, Class V(A)
quirements Policy.
aviation ordnance), with the HN providing care
of supplies in storage.
CARE OF SUPPLIES IN STORAGE
Class V(W) Maintenance
The care of supplies in a storage program, as part
The assistant program managers at PM Ammo,
of the DOD Stock Readiness Program, is
with in-Service engineering and technical sup-
intended to maintain stored Navy and Marine
port personnel, determine if a maintenance effort
Corps material in ready-for-issue condition and to
is more cost effective than new procurement.
prevent deterioration and additional damage of
Once a maintenance project is planned and
unserviceable material.
scheduled, a complex process is begun to obtain
replacement components, select a maintenance
As is the case with all Service-owned stocks held
site, position assets, and conduct a quality audit
within Service-owned facilities, responsibility for
FOR OFFICIAL USE ONLY
Ammunition Logistics__________________________________________________________________________________________ 1-9
of the maintenance line. The maintenance
regarding the disposition of Class V(A), to
program gives PM Ammo an option to meet
include item specific DDAs for naval ammu-
stockpile inventory objectives at a lower cost than
nition can be found in OPNAVINST 8026.2,
new procurement.
Navy Munitions Disposition Policy.
Disposal
THE MARINE CORPS
From time to time, munitions must also be
COMBAT LOGISTICS ORGANIZATION
removed from the inventory for a variety of rea-
sons. In some cases, it has become obsolete or the
Operational experience, coupled with lessons
weapon system that it served is no longer in the
learned and technological advancements prompted
active inventory. In other cases, the ammunition
the reorganization and realignment of the combat
item may have become unserviceable due to age
support infrastructure to more efficiently and
or other environmental factors and may not be
effectively support the operating forces and
economically repairable. Most frequently, the
ammunition has been rendered unusable due to
supporting establishment.
rough handling in the field, loss of lot identity, or
Combat service support centers around the
damage that occurred in transit to or from train-
Marine logistics group (MLG). The MLG is the
ing exercises or operational events.
MARFOR, Marine expeditionary force (MEF),
and Marine air-ground task force (MAGTF) com-
Class V(W) Disposal Authority
bat support/logistic support agent.
The PM Ammo manages the disposal of muni-
tions that are no longer useful and has esta-
Marine Logistics Group
blished a designated disposition authority (DDA)
for making determinations on such munitions.
The MLG, shown in figure 1-3, on page 1-11, is a
The functions of the DDA and the rules under
combat and logistic support organization that
which PM Ammo operates are discussed in
includes units, oriented to both the garrison and
appendix B.
deployed environments, executing specified gen-
eral and direct support missions.
Class V(A) Disposal Authority
The MLG provides logistic support for the MEF.
Commander, NAVSUPSYSCOM is assigned
The MLG performs those functions that exceed
authority for the worldwide management of
the organic capabilities of the supported units.
demilitarization, recycling, declassification, and
The MLG commander, normally a brigadier
disposal of excess, obsolete, unserviceable, and
general, serves as the principal logistic advisor to
waste military and foreign Class V(A) generated
the MEF commander.
at Navy and Marine Corps activities. The only
exception is with large strategic rocket motors.
The MLG consists of the MLG headquarters, a
Commander, NAVSUPSYSCOM designated the
general support combat logistics regiment, a
NOLSC to perform these functions for Navy-
direct support combat logistics regiment, and
owned Class V materiel. Accordingly, the DDA
several separate reporting battalions. In general,
for Navy-owned assets (including Class V(A)
these battalions include a headquarters and
assets of interest to the Marine Corps) is located
service battalion, three general support combat
within the NOLSC. Further detailed information
logistics battalions, a deployable MLG Forward
FOR OFFICIAL USE ONLY
1-10 ___________________________________________________________________________________________________ MCWP 4-11.9
with a headquarters element and limited core
Class V support and structured to facilitate task
support capabilities to facilitate the arrival of the
organization in support of the entire MEF or any
main body of the MLG, and a separate combat
combination of smaller MAGTFs.
logistics company.
Marine Aviation Logistics Squadron
Based on the mission, the commander task orga-
nizes the MLG’s general support regiment into
The Marine aviation logistics squadron (MALS) is
combat service support organizations of varying
the Marine Corps’ tactical aviation logistic organi-
sizes. The general support regiment also provides
zation. The MALS provides direct Class V(A)
core maintenance, transportation support, deliber-
support to aircraft squadrons and is responsible
ate engineering, and health services support.
for providing intermediate ordnance/armament
support and is organized under the Marine air-
The direct support regiment is organized into
craft group of the Marine aircraft wing. In a
separate combat logistics battalions in direct
deployed environment, MALS ordnance is typi-
support of assigned infantry or artillery battalions.
cally referred to as aviation combat element (ACE)
ordnance and it may deploy as a unit or a small
The ammunition company of the MLG provides
detachment as a part of the MAGTF. This MALS
Class V supply support to the MEF-sized
ordnance detachment maintains and operates the
MAGTF. The company possesses organic capa-
ammunition supply point (ASP), or theater stor-
bilities to transport its administrative and com-
age area (TSA), normally a function of the sup-
mand and control functions. The company is
porting station.
organized to plan, coordinate, and supervise
FOR OFFICIAL USE ONLY
Ammunition Logistics_________________________________________________________________________________________ 1-11
FOR OFFICIAL USE ONLY
CHAPTER 2
GENERAL CLASS V MANAGEMENT
The term wholesale is usually applied to an
z
Capacity management.
activity that controls and manages both material
z
Production management.
assets and storage facilities, and is usually not a
z
Execution.
direct supplier to the end user. In the ammunition
context, wholesale is applied to management
Request Management
activities undertaken by the Navy or Marine Corps
Class V ICPs.
Request management is the process performed by
the supported unit, and includes the planning and
Ammunition storage facilities are managed and
preparation for future training or contingency
operated by local commanders. The Service ICP
events. When the supported unit’s ammunition
does not own or control the storage facilities
requirements have been determined, it leads to
where a majority of the conventional ammunition
the creation of a demand that initiates a requisition
that they manage is stored. The ICP must rely on
that the logistic and supply systems must satisfy.
other Services, organizations, and activities to
execute the retail inventory management actions,
Order Management
including processing issues, receipt documents,
and preparation for shipment.
Order management is generally the same for
Class V(W) and V(A). The ASP, which is the
Retail level ammunition management functions
supporting unit, will receive the demand and
include responsibilities for both the supported
begin the process of obligating assets, planning
and the supporting units. These responsibilities
human and equipment resources, and performing
include maintaining asset visibility and account-
all the administrative work that is required in
ability, providing physical security, and reporting
order to issue the ammunition assets to the
of expenditures and other transactional activity.
supported unit.
These functions are performed in the context of
the logistic operational architecture.
Capacity Management
Capacity management for Class V is the responsi-
bility of the supporting establishment such as the
LOGISTIC OPERATIONAL ARCHITECTURE
ASP, the field ammunition supply point (FASP),
or the forward arming and refueling point (FARP).
The logistic operational architecture is a transfor-
Capacity management involves ensuring that the
mational approach to organizational change for
quantities of Class V that are on hand at any
meeting the logistic support demands of the
given storage area not exceed the physical capac-
operating forces and supporting establishment. The
ity or violate the explosives safety regulations for
logistic operational architecture breaks the
the materiel being stored.
functional actions down into five broad cate-
gories that are directly applicable to all Class V
Production Management
management activities:
Production management is an event-driven
z
Request management.
activity of the supporting unit and ensures that all
z
Order management.
required personnel, equipment, tools, and
FOR OFFICIAL USE ONLY
2-2 ____________________________________________________________________________________________________ MCWP 4-11.9
materials are available to satisfy the supported
throughout the DON. Users are able to perform a
unit’s demand on their required delivery date in a
wide variety of local management functions using
timely manner.
only the local Web browser on a desktop computer
and a set of specialized ordnance information
Execution
management applications. Transactional and stock
status information is uploaded as batch processes.
Execution is a joint responsibility of the sup-
porting storage activity and the supported unit, it
The Marine Corps and
involves both the administrative actions and the
Ordnance Information System
physical transfer of Class V assets. Execution
also includes observance of the requirements for
The Marine Corps uses an unclassified version of
physical security of arms, ammunition, and
the Navy’s OIS; a commodity-based system sup-
explosives and the assignment of qualified per-
porting naval logistic integration. This transition
sonnel to perform those duties.
merges the wholesale ammunition management
functions of the Navy and Marine Corps, as well
Supporting unit responsibilities for execution
as the Coast Guard, into a single, coherent, inte-
include the processing of issues; transaction
grated system and set of processes.
reporting; processing and implementation of
notices of ammunition reclassification to retail
Marine Corps Class V
stocks; ammunition information notices; and
Inventory Management Systems
other activities that facilitate ammunition support
and administration, operations, and accounting at
The Marine Corps version of OIS supports both
wholesale management functions executed by the
the retail level.
PM Ammo and the retail-level ammunition man-
agement functions executed by supporting ASPs,
ORDNANCE INFORMATION SYSTEM
both in garrison and when deployed.
Navy Class V Inventory
Near real time data entry and update is provided
Management Systems
by the Web-enabled Ordnance Information
System (OIS). The OIS provides the capabilities
The Navy version of OIS supports both wholesale
to exercise wholesale—and retail—level ammu-
management functions executed by the NOLSC
nition inventory management functions. At
and the retail-level ammunition management
appropriate management levels, several OIS-
functions executed by supporting shore activi-
based applications are available to authorized and
ties, air stations, and ships afloat.
accredited users on secured networks:
Future Capabilities
z
Ordnance visibility.
z
Naval forces operational readiness assessment
Future releases of the OIS should enable the
z
Ordnance assessment portfolio.
ground ammunition and aviation ordnance
z
Global Naval Ordnance Positioning Plan.
communities to become full participants in the
Global Combat Support System-Joint (GCSS-J)
The OIS provides ordnance information support to
family of systems and the future integrated
naval leadership and the user community
digital environment.
FOR OFFICIAL USE ONLY
Ammunition Logistics__________________________________________________________________________________________ 2-3
with Class V notify the appropriate agencies in
MUNITION INVENTORY AND
order to implement “cause and effect” analysis.
TRANSACTION REPORTING
Class V(W) malfunction/deficiency reports are
required when supported units experience a mal-
The OIS will be utilized to account for and
function. These reports are submitted in accor-
manage Class V stocks. Standard accounting
dance with the current edition of MCO 8025.1D,
practices/forms will apply. In addition to the in-
Class V(W) Malfunction and Defect Reporting.
theater munitions reporting procedures, Class V
transactions will be reported to the appropriate
Class V(A) malfunction/deficiency reports are
ICP as follows:
required when supported units experience a mal-
function. These reports are submitted as conven-
z
Class V(A) transactions are reported to
tional ordnance deficiency reports or explosives
NOLSC via an ammunition transaction report
event reports in accordance with the current edi-
generated from the Retail Ordnance Logistics
tion of OPNAVINST 5102.1D, Navy & Marine
Management System. When the OIS is fully
Corps Mishap and Safety Investigation, Report-
deployed, the requirement for ammunition
ing, and Record Keeping Manual.
transaction report will be eliminated.
z
Class V(W) transactions are reported to PM
Supply Discrepancy Report
Ammo via a transaction item report generated
from the Retail Ordnance Logistics Manage-
Supply discrepancies result when the quantity
ment System. When the OIS is fully deployed,
identified on shipping and transportation docu-
the requirement for an internal transaction item
ments, or on ammunition packaging, differs from
report will be eliminated, but it will still be
what is actually received. When this occurs, a
required for transactions external to the Marine
supply discrepancy report is required per the
Corps.
current edition of Naval Supply Systems Com-
mand (NAVSUP) Publication P-724, Conven-
Asset Visibility and Accountability
tional Ordnance Stockpile Management Policies
and Procedures.
Once ammunition is issued to supported units, a
process must be in place to establish and maintain
Missing, Lost, Stolen, or Recovered
asset visibility and accountability. Reporting
requirements exist to account for assets held by
The loss of ammunition items due to inadequate
supported units; expenditures of serialized
accountability, negligence, or theft may result in
ammunition; and to report missing, lost, stolen, or
significant monetary loss, safety, and security
recovered ammunition items. Personnel assigned
problems. Such losses may potentially impact
ammunition duties are responsible for following
unit readiness and adversely affect homeland
procedures established in local standing operating
security efforts. The missing, lost, stolen, or
procedures (SOPs). These principles also apply
recovered reporting system was designed to
when conducting munitions reports (MUREPs)
enable the Marine Corps to centrally track mate-
for the CCDR/JFC, as discussed in chapter 6.
rial losses and to identify trends and areas where
security enhancements may be required. The cur-
Malfunction Reporting
rent MCO 4340.1A, Reporting of Missing, Lost,
Knowledge of Class V performance is critical in
Stolen, or Recovered (MLSR) Government Prop-
maintaining a robust, flexible, and safe stockpile.
erty, contains details for reporting missing, lost,
It is imperative that units experiencing problems
stolen, or recovered ammunition.
FOR OFFICIAL USE ONLY
2-4 ____________________________________________________________________________________________________ MCWP 4-11.9
Automatic Identification Technologies
multiple formats in use in commercial
applications, but the format used for military
Automatic identification technologies are combi-
shipments is PDF-417. The two-dimensional
nations of reader equipment, software, tools, and
format label contains a significantly larger amount
procedures that are inserted into logistic manage-
of information than linear barcode labels.
ment processes. These technologies may be
Additionally, since the data is stored redundantly,
applied in a variety of end uses, including receipt
the label can sustain a substantial amount of
and inventory, point-of-issue transaction tracking,
damage and still be read by a barcode reader.
transportation tracking, and asset management.
Radio Frequency Identification
The two most common methods in use for Class V
management functions are barcoded labels and
The use of RFID as a technology to automate the
radio frequency identification (RFID) tags.
collection of data that is used for tracking ship-
ments and materiel until delivered to a storage
Barcoding
point or the supported unit is just beginning to
mature. The RFID technology requires a tag
Barcoding is a mature technology used extensively
where the transported items are stored, a tag
by DOD and commercial industry for tracking
reader device for interrogating or creating the
material in transit and in storage. Barcodes used
tags, and a communications method to move the
by DOD are either linear or data matrix.
collected data to a system where the information
The linear barcode is considered to be a legacy
can be used or evaluated. Unlike the one-
barcode. This barcode format is known as 3-of-9,
dimensional and two-dimensional labels, RFID
and it is sometimes shortened to Code 39. The
tags can be reformatted and reused several times.
linear, one-dimensional barcode is a series of
Receiving and transportation processes must
vertical lines of varying thickness with spaces of
ensure that all tags are “captured” and read, or the
variable duration that can be read by a scanning
benefits of the tag are lost.
device. The barcode may also display a human-
readable string beneath the coding to make ready
Other Technologies
identification possible without a scanner. Used
Other technologies/techniques that will be
for two decades, the one-dimensional label has
incorporated in ammunition logistic processes in
significant limitations in that it contains only
the near future include the electronic product
limited information and may be unreadable if
code tag (class 2) (as a successor to the current
damaged or faded.
RFID tag media) and the use of unique
The data matrix barcode is a modern barcode
identification numbers for costly ammunition
format, also known as data matrix, two-
items, as well as ammunition items that may meet
dimensional barcode symbology. There are
other defined criteria.
FOR OFFICIAL USE ONLY
CHAPTER 3
OPERATIONAL AMMUNITION
REQUIREMENTS DETERMINATION
Class V operational requirements can be described
AVIATION ORDNANCE
as the quantity of munitions required to equip a
specified force structure to accomplish its
assigned missions. This quantity of munitions is
The NNOR is the methodology used to calculate
conventional ordnance requirements for the
intended to support the CCDR/JFC commander’s
DON. The NNOR process is outlined in detail in
requirements to execute combat operations, as
OPNAVINST 8011.9A and uses a sophisticated
well as materiel required for the conduct of sub-
model to calculate DON threat-oriented and level
sequent security operations (during the transition
of effort ordnance requirements for Navy forces
from combat operations).
and Marine Corps aviation units. Model inputs
While the CG, MCCDC also has a role in the
regarding support and sustainment of the
operating forces are provided by the warfighters.
requirements determination process, the com-
Model outputs that support operational
mander is ultimately responsible for determining
requirements are reviewed and approved by the
that operational Class V requirements are suffi-
Nonnuclear Ordnance Planning Board, which
cient to execute the mission. Ammunition require-
provides top-level direction in the NNOR
ments are determined based on the mission,
process. Class V(A) sustainment methodologies
commander’s intent, assigned force levels, and
are predicated on theater and type, model, and/or
established planning factors.
series (T/M/S) of assigned aircraft for a given
operational plan. The NNOR provides the factors
for determining initial requirements and follow-
GROUND AMMUNITION
on sustainment. Sortie generation rates are a
primary determining factor in expressing the
The operating forces use combat planning fac-
remaining endurance of MAGTF aviation and its
tors (CPFs) that are generated by MCCDC and
ordnance support capability.
used to assist in Class V(W) combat/contin-
gency requirements planning. In general, ammu-
MODELING/DELIBERATE PLANNING FOR
nition requirements are determined by applying
MAJOR OPERATIONS AND CAMPAIGNS
force structure (table of organization and table of
equipment data), weapons mix, combat inten-
sity, and phase duration to the appropriate com-
In deliberate planning, operational requirements
bat planning factors.
will be developed by MCCDC, in active consul-
tation with the MARFOR, using an automated
Supportability of those requirements may be con-
computer modeling method. Aggregate require-
strained by available inventories. The process for
ments and individual combat planning factors are
programming and budgeting for ammunition
generated from this model. In order to attain
requirements is described in MCO 8000.7.
precise outputs, a high degree of accuracy and
FOR OFFICIAL USE ONLY
3-2 ____________________________________________________________________________________________________ MCWP 4-11.9
granularity is required in the model data inputs
For operations where predetermined combat plan-
time-phased force and deployment data (TPFDD);
ning requirements have not been established by
phases; posture statements; and theater specific
the WRMR model, refer to CPFs published on
logistical constraints such as, terrain-related,
the MCCDC Web page www.mccdc.usmc.mil/
open mountainous, or urban terrain that is
CDD/Ammo/mysite/default.htm. The Web page,
provided by the MARFOR.
in conjunction with the ammunition require-
ments generator, will act as the sole source docu-
ment for Class V(W) requirements determination.
EXECUTION OF A DELIBERATE PLAN
TRANSITION OF CLASS V(W)
In determining operational requirements for
COMBAT PLANNING FACTORS
Class V, a number of considerations must be
taken into account, bearing in mind the inherently
fluid environment in which combat operations
As a regional theater matures, the combat plan-
ning factors used for initial planning may no
take place. Requirements must be reviewed, mod-
longer support the operational requirements due
ified, and updated when conditions such as
to changes in tactics, techniques, and procedures
forces, force closure timeline, threat report, or
or the overall scope of the mission. As condi-
target apportionment change or branching plans
tions mature, planners must base their future sus-
are considered or executed. Given that the input-
tainment requirements on current combat
ted model data remains the same and only a force
expenditure data as long as a correlation exists
structure increase has occurred, additional opera-
with planned future operations. This evolving pro-
tional requirements should not be determined by
cess provides commanders with the maximum
applying CPFs to the increased force structure;
operational flexibility to prosecute near term cur-
rather the additional units should be armed with
rent and planned future operations. Although the
combat loads that support Marine Corps doc-
quantities for combat loads (CLs) (which provide
trine of arming the force. Additionally, the
the initial combat capability) may remain static,
increase of combat units/personnel may increase
emergent tactics, techniques, and procedures and
the Class V(W) logistical requirements, since
local tactical conditions will require adjustment
additional personnel normally increase physical
of planning rates to complement operational con-
dispersion. Similar considerations must be taken
siderations. Designation of expenditure-based
into account when analyzing any of the above ele-
planning factors for determining future ammuni-
ments. Planning requirements always require
tion requirements is a component function in a
revalidation prior to execution.
mature theater.
CRISIS ACTION/CONTINGENCY
OPERATIONAL REQUIREMENTS
PLANNING AND IMMEDIATE
IN A JOINT ENVIRONMENT
REQUIREMENTS DETERMINATION
In an era of increasingly joint operations and the
planned potential for implementation of common
Class V(A) crisis action/contingency planning
item support (CIS), new concepts and approaches
will be initially guided by the planned consump-
for sustainment of the forces are required. Plans
tion rates established in the NNOR for the T/M/S
must consider the efficiencies that are gained by
aircraft assigned and adjusted to reflect locally
having integrated ammunition support. Plans
available or readily accessible assets.
FOR OFFICIAL USE ONLY
Ammunition Logistics___________________________________________________________________________________________ 3-3
must be coordinated with the various Services
Combat Load
that are involved to ensure the adequacy of per-
In accordance with the MCO 8000.7, the CL is
sonnel, assets, storage requirements, materials
defined as the standard quantity and type of
handling equipment, accountability procedures,
munitions carried by weapons platforms/troops
and safety.
and/or its dedicated support vehicle. Using the
phrase CL implies that a weapons platform or an
individual has its full doctrinal load of ammuni-
EXPRESSING CAPABILITIES AND
tion, in terms of quantity and type. It is important
REQUIREMENTS FOR CLASS V(W)
to note that the CL provides various durations of
support depending on the weapon system when
In expressing logistical capabilities and require-
the CPFs are used as the divisor.
ments, it is important to understand that ammuni-
Day of Ammunition
tion requirements and capabilities are generally
expressed in terms of CL and day(s) of ammuni-
By design, the DOA corresponds to a composite
tion (DOA). These terms are exclusive to ground
daily quantity that represents an average daily
ammunition and are not interchangeable. Each
expenditure for total forces and weapons plat-
term of reference comes with its own set of
forms over the entire battlespace during a specific
advantages and liabilities.
period of time, typically measured in days. In
Pre-battle
Battle
Post-battle
Combat Logistic Support
Combat Arms
Duration of Activity
Figure 3-1. Logistic Demands Versus Duration and Intensity of Activity.
FOR OFFICIAL USE ONLY
3-4 ____________________________________________________________________________________________________ MCWP 4-11.9
terms of the MCCDC modeled CPF, a DOA is
capability, while the DOA is more definitive for a
the projected average quantity required to replen-
commander to assess his logistic endurance,
ish the previous days expenditure from the CL.
depending on current and future consumption.
This approach requires that the commander
The DOA provides a point in time measure of
understands the interrelation and fluidness of the
endurance and can fluctuate during different
terms, especially the DOA. In expressing endur-
phases of an operation based on intensity and
ance, the term DOA should be placed in a context
duration as depicted in figure 3-1. Assault phase
where the planned requirements may be arrayed
combat operations will consume assets at a higher
rate than stability operations.
against estimated future operational needs. The
MUREP and historical expenditures are valuable
Combat Load Versus Day(s) of Ammunition
tools for the continual validation and comparison
of the projected and actual expenditures as related
Under combat conditions, the CL should be
to the available inventory.
regarded as a tool for identifying initial combat
FOR OFFICIAL USE ONLY
CHAPTER 4
CLASS V MOVEMENT PLANNING
Movement planning is the art and science of
unit’s mission. If the mission is not correctly
selecting the forces and equipment that are to be
determined, follow-on planning in support of that
moved and marshaled to arrive at their respective
mission will also be flawed.
planned ports of embarkation (POE). Depending
The purpose of mission analysis is to review and
on the origin of the deploying force, it may be
analyze orders, guidance, and other information
either a strategic deployment from the continental
provided by higher headquarters and produce a
United States (CONUS) or an operational deploy-
mission statement. The inputs to the mission
ment from elsewhere within the theater. Move-
analysis step come from the higher headquarters
ment planning is done in conjunction with
deliberate or crisis action planning.
and the commander. During the mission analysis
process, intelligence preparation of the bat-
Any plan involving insertion of military forces
tlespace is a critical input for both the commander
into a conflict or contingency generally requires
and the logistician.
ammunition to initially arm and sustain that
force. Therefore, Class V planning requires a
The commander’s initial guidance will broadly
careful analysis of what ammunition would be
outline what is expected of the operational
required, timing of the required ammunition
planning team and the products that are produced
deliveries, and sourcing of the required
in the planning process. The most critical inputs
incremental shipments.
to the planning process are those contained within
the commander’s orientation, which is comprised
To facilitate ammunition requirements into
of his initial guidance and his commander’s
planning, logisticians participate in all steps of
battlespace area evaluation. The Class V planner
the Marine Corps Planning Process (MCPP)
must look at the infrastructure within the battle-
with representatives of the other warfighting
space and ask the following:
functions, staff sections, and subject matter
experts by participating in the operational
z
Where are the ports, airfields, and roads?
planning team. The operating forces provide input
z
What are the choke points in the amphibious
to the joint planning process using the process
objective area?
described in Marine Corps Warfighting Publi-
z
What are the limiting factors for RSOI of Class
cation (MCWP) 5-1, Marine Corps Planning
V materiel?
Process. The MCPP is designed for use at any
echelon of command to plan force organization
During this process, the Class V planner can
and employment, and it complements the joint
derive the major POE(s) and begin to determine
deliberate and crisis action planning procedures.
the anticipated throughput rates for these
locations. The commander will also provide the
first look at the friendly and enemy centers of
PLANNING FOR CLASS V
gravity. The logistician will look at these from a
COMBAT LOGISTIC SUPPORT
logistic perspective to analyze where the center of
gravity is for the operation. The commander will
Mission analysis is the first and, arguably, the
describe their intent and will outline what is
most important step in the MCPP for logisti-
viewed to be critical information requirements,
cians, and it is the step in the process where the
both in planning and in execution. Logistic-related
commander and planners will determine the
commander’s critical information requirements
FOR OFFICIAL USE ONLY
4-2 ____________________________________________________________________________________________________ MCWP 4-11.9
may be the capabilities of the port/airfield/bridges
family of systems that are necessary to plan,
within the area of operations or the depth of
deploy, sustain, and employ forces. The GCCS
sustainment available or desired. Necessarily, this
provides joint operation planning and execution
includes Class V materiel.
capabilities and facilitates the deployment and
redeployment of MARFOR and associated
The Class V planner should plan for main and
supplies and equipment, to include ammunition.
intermediate storage locations and the sequences
of actions that are best suited to supporting the
Joint Operation
maneuver forces. In addition, he should under-
Planning and Execution System
stand the probable timing of each action. These
are initial projections, which should be derived
The Joint Operation Planning and Execution Sys-
from the various courses of action as they evolve.
tem (JOPES) enables supported commanders,
Class V planners should be aware of critical
supporting commanders, and other members of
events and decision points to enable the logistic
the joint planning and execution community to
support to be in place prior to the critical event.
manage the deployment of forces and follow-on
Logistic critical events and decision points are
sustainment. See Chairman of the Joint Chiefs of
likely to occur 24 to 48 hours ahead of MAGTF
Staff Manual (CJCSM) 3122.02C, Joint Opera-
events and decision points that depend on the
tion Planning and Execution System (JOPES),
action and reaction continuum.
Volume III (Crisis Action Time-Phased Force
and Deployment Data Development and Deploy-
Special Consideration
ment Execution), for detailed information .
During Movement Planning
The Global Combat Support System-Joint
In planning Class V, special considerations have
to be given to proper timelines. Services must be
The GCSS-J provides universal access to infor-
careful to consider all aspects of planning
mation and interoperability of logistic information
timelines such as, at a minimum, official release
and other support functions through vertical and
of assets by Service headquarters, requisitioning,
horizontal fusion. The GCSS-J will share infor-
containerization, depot out loading, and shipping
mation with other command and control systems
in order to ensure that the assets do not arrive too
to contribute to the CCDR’s/JFC’s common
late to support the CCDR’s concept of operations.
operational picture. Ultimately, the GCSS-J will
Untimely or inaccurate planning can reduce depot
provide near real time command and control of the
responsiveness, tax commercial transportation
ammunition logistic pipeline from battlefield to
mechanisms, congest ports, and ultimately
sustaining base as a fused picture of combat
jeopardize mission accomplishment. Additionally,
support to the warfighter.
costs for ammunition movements can reach
exorbitant levels if it is not planned properly or if
Joint Force Requirements Generator II
execution does not closely follow planning. For
many reasons, planning must be carefully crafted
Planners use the Joint Force Requirements
and maintained in order to ensure that the
Generator II (JFRG II) (an automated tool) to
available resources are used and to ensure a
develop force structure, tailor force lists, compute
timely execution.
sustainment, estimate and plan lift requirements,
and generate the TPFDD. The JFRG II also acts
The Global Command and Control System
as a deployable JOPES enabling the planner to
communicate with JOPES in order to transmit or
The United States’ national command and control
receive TPFDD information. The forces and
system—the Global Command and Control
equipment entered in JFRG II are used to develop
System (GCCS)—consists of an interoperable
time-phased Class V(W) requirements. Plans may
FOR OFFICIAL USE ONLY
Ammunition Logistics__________________________________________________________________________________________ 4-3
be downloaded from JOPES to the JFRG II,
War Reserve Positioning
modified, and transmitted to other logistics
automated information systems (LOGAISs).
A significant portion of Marine Corps-owned
ammunition is held in Joint Munitions Com-
Logistics Automated Information
mand (JMC)-managed depot(s) and, to a lesser
Systems and Aviation Logistics
extent, Navy activities. The Navy also stores a
portion of its inventory in JMC-managed facilities.
The LOGAISs are utilized by Marine aircraft
The bulk of Class V(W) sustainment/WRMSI
wing/MALS aviation logistic planners and
will be sourced from these wholesale level depots.
embarkation representatives while developing
TPFDD in support of deliberate and crisis action
Unlike Marine Corps ground ammunition, a
planning. While designing force deployment,
substantial portion of Class V(A) used by Marine
planning, and execution plans, Marine aviation
aviation is embarked in amphibious and strike
logistic planners utilize data derived from the
force vessels as mission load allowance (MLA),
Support Equipment Resources Management
on CLF shipping as replenishment stocks, at
Information System and the Shipboard Uniform
naval weapons stations, and on MPS. A small
Automated Data Processing System databases in
percentage of Class V(A) aviation ordnance is
order to develop TPFDD in support of deliberate
also held in HN facilities as geoprepositioned
and crisis action planning.
stocks. The Army JMC is subordinate to the
Army Material Command and performs logistic
functions, as agreed upon with the single manager
CLASS V SOURCING
for conventional ammunition (SMCA). The JMC
is a field operating activity that supports the
Sourcing of Class V materiel (the function of
SMCA executor and the Military Services. As
identifying assets by Department of Defense
such, the JMC is responsible for providing
identification code [DODIC], location, quantity,
storage, physical security, basic housekeeping,
and mode of shipment for movement) to support
and depot offloading for the Military Services.
warfighting requirements differs between ground
The PEO Ammo is designated as the executor for
ammunition and aviation ordnance. While the
the SMCA.
mechanisms are generally the same, the sources
of supply are not.
Class V(W) Sourcing
The Marine Corps war reserve support is desig-
During crisis, conflict, or wartime, a crisis
nated as either war reserve material stocks force-
response cell (CRC) is activated at PM Ammo,
held (WRMSF) or war reserve materiel stocks in-
MARCORSYSCOM. Once requirements are
stores (WRMSI). The WRMSF assets are
determined and consolidated, the MARFOR/MEF
prepositioned or regionally controlled by ope-
will source the allocated WRMSF. Initial sourcing
rating forces such as landing force operational
shortfalls are based on validated requirements,
reserve material (LFORM), maritime preposi-
minus available WRMSF and other theater stocks,
tioning forces (MPFs), and HN/NATO [North
and forwarded to PM Ammo for sourcing from
Atlantic Treaty Organization] storage activities
WRMSI. Figure 4-1, on page 4-5, illustrates this
and other available Marine Corps theater stocks to
concept. Additional information on management
increase accessibility. The WRMSI stocks are held
and withdrawal of WRMSF and WRMSI stocks
at wholesale depots, which are managed by the
can be found in MCO P4400.39H, War Reserve
Service ICP.
Materiel Policy Manual.
FOR OFFICIAL USE ONLY
|
||
|
|
|