• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer
  • NEWS:
  • SatNews
  • SatMagazine
  • MilSatMagazine
  • SmallSat News
  • |     EVENTS:
  • SmallSat Symposium
  • Satellite Innovation
  • MilSat Symposium
  • SmallSat Europe

SatNews

Satellite Industry Intelligence Since 1983

Subscribe
  • LATEST
  • Missions & Constellations
    • Exploration & Science Missions
    • In-Orbit Servicing & Orbital Operations
    • LEO Constellations
    • Mission Autonomy & Onboard Systems
    • Mission Deployments & Manifests
    • Navigation & PNT
    • SmallSat
    • Spacecraft & Payload Technology
    View All in Missions & Constellations →
    Defense Economics and the European SmallSat MarketDefense Economics and the European SmallSat Market
    The FCC Must Choose: Enforce the Rules or Preserve LEO CompetitionThe FCC Must Choose: Enforce the Rules or Preserve LEO Competition
    Syntiant and Novi Space Successfully Demonstrate Low-Power AI Inference in OrbitSyntiant and Novi Space Successfully Demonstrate Low-Power AI Inference in Orbit
    HTS Market Projected to Reach $76 Billion as NGSO Constellations Reset Industry BenchmarksHTS Market Projected to Reach $76 Billion as NGSO Constellations Reset Industry Benchmarks
  • Business
    • Contracts & Commercial Deals
    • Earnings & Financial Reporting
    • Events & Conferences
    • Funding & Venture Capital
    • Market Forecasts
    • Mergers & Acquisitions
    • Personnel Moves & Appointments
    View All in Business & Finance →
    SES jumps deeper into MEOSES jumps deeper into MEO
    Defense Economics and the European SmallSat MarketDefense Economics and the European SmallSat Market
    SpaceX Accelerates Record-Breaking IPO Following Trillion-Dollar xAI MergerSpaceX Accelerates Record-Breaking IPO Following Trillion-Dollar xAI Merger
    Laser Communications and the Rise of Orbital Data CentersLaser Communications and the Rise of Orbital Data Centers
  • Defense
    • Counterspace & ASAT
    • Defense Budgets & Procurement
    • ISR & Reconnaissance
    • MILSATCOM
    • Missile Warning & Defense
    • National Security Programs
    • Space Domain Awareness
    View All in Military & Defense →
    Defense Economics and the European SmallSat MarketDefense Economics and the European SmallSat Market
    Firefly Aerospace Supports U.S. Space Force VICTUS DIEM ExerciseFirefly Aerospace Supports U.S. Space Force VICTUS DIEM Exercise
    Dual-Use by Design: Telesat Lightspeed and the End of Civilian Telecom in LEODual-Use by Design: Telesat Lightspeed and the End of Civilian Telecom in LEO
    ThinKom Showcases Modular MILSATCOM Architecture for Contested EnvironmentsThinKom Showcases Modular MILSATCOM Architecture for Contested Environments
  • Gov
    • Export Controls & Compliance
    • International Space Agreements
    • National Space Policy
    • Space Law & Treaties
    • Space Sustainability & Debris Policy
    • Space Traffic Management / Debris Removal
    View All in Government & Regulation →
    The FCC Must Choose: Enforce the Rules or Preserve LEO CompetitionThe FCC Must Choose: Enforce the Rules or Preserve LEO Competition
    Space Force Reassigns Final GPS III Mission to SpaceX Following Vulcan AnomalySpace Force Reassigns Final GPS III Mission to SpaceX Following Vulcan Anomaly
    NASA Realignment ‘Ignition’ Accelerates Shift Toward Commercial Lunar EconomyNASA Realignment ‘Ignition’ Accelerates Shift Toward Commercial Lunar Economy
    SpaceX and GSO Giants Clash Over FCC Spectrum Sharing Rules and Power LimitsSpaceX and GSO Giants Clash Over FCC Spectrum Sharing Rules and Power Limits
  • Launch
    • Launch Providers
    • Launch Schedule & Calendars
    • Launch Sites & Infrastructure
    • Rocket Technology & Vehicles
    View All in Launch →
    Defense Economics and the European SmallSat MarketDefense Economics and the European SmallSat Market
    Space Force Reassigns Final GPS III Mission to SpaceX Following Vulcan AnomalySpace Force Reassigns Final GPS III Mission to SpaceX Following Vulcan Anomaly
    China satellite investment soars as SpaceX sparks race for spaceChina satellite investment soars as SpaceX sparks race for space
    L3Harris Honors Goddard Centennial with Advances in Nuclear and Electric PropulsionL3Harris Honors Goddard Centennial with Advances in Nuclear and Electric Propulsion
  • Software
    • Autonomous Ground Operations
    • Data Processing & AI/ML
    • Digital Twins & Modeling
    • Ground Segment & Teleports
    • Mission Planning & Simulation
    • Space Systems Software Engineering
    • Spectrum & Licensing
    View All in Software Automation & Ground Systems →
    NexSat Space Systems Debuts with ACE ‘Invisible’ Aero-Conformal AntennaNexSat Space Systems Debuts with ACE ‘Invisible’ Aero-Conformal Antenna
    Laser Communications and the Rise of Orbital Data CentersLaser Communications and the Rise of Orbital Data Centers
    ThinKom Showcases Modular MILSATCOM Architecture for Contested EnvironmentsThinKom Showcases Modular MILSATCOM Architecture for Contested Environments
    Kymeta Sets Roadmap for KuKa 8 Series Multi-Band TerminalsKymeta Sets Roadmap for KuKa 8 Series Multi-Band Terminals
  • Services & Apps
    • Climate & Environmental Monitoring
    • Disaster Response & Security Mapping
    • Earth Observation & Imaging
    • Maritime & Aviation Satcom
    • Satellite Communications
    View All in Services & Applications →
    The FCC Must Choose: Enforce the Rules or Preserve LEO CompetitionThe FCC Must Choose: Enforce the Rules or Preserve LEO Competition
    CubeSpace Challenges Vertical Integration with Record ADCS Production MilestoneCubeSpace Challenges Vertical Integration with Record ADCS Production Milestone
    OrbitsIQ Global and Wrocław Tech Validate E-SSA Waveform for Space-Based IoTOrbitsIQ Global and Wrocław Tech Validate E-SSA Waveform for Space-Based IoT
    Marlink Reports 50% Surge in GNSS Interference Impacting Global ShippingMarlink Reports 50% Surge in GNSS Interference Impacting Global Shipping
  • SatNews Events
  • Magazines
  • Calendar

DISA Unveils Cyber.mil as the New Home of Cybersecurity Standards

May 27, 2019

The Defense Information Systems Agency (DISA) has migrated its Security Requirements Guides (SRGs) and Security Technology Implementation Guides (STIGs) to a new home.

DISA previously hosted these security configuration standards for Department of Defense (DoD) systems and software on the Information Assurance Support Environment (IASE) portal, https://iase.disa.mil, which the agency is no longer updating.

Sue Kreigline, Chief of DISA’s cyber standards branch, said the new DOD Cyber Exchange portal at cyber.mil, which is restricted to use by individuals with a DoD-issued Common Access Card (CAC), hosts:

  • More than 350 security guides.
  • Security content automation protocols.
  • A STIG viewer capability, which enables offline data entry and provides the ability to view one or more STIGs in a human-readable format.
  • A STIG applicability tool, which assists in determining what SRGs and STIGs apply to specific situations.
  • A Windows 10 Secure Host Baseline download.

 

The cyber standards chief announced the change at AFCEA’s TechNet Cyber 2019 symposium in Baltimore. Maryland, on May 16, where she and other DISA Cyber Standards Branch representatives discussed SRGs and STIGs.

The Cyber Standards Branch — also announced a new STIG collaboration portal — enables technology discussions among subject matter experts. The collaboration portal is also restricted to CAC-holders and can be accessed via software.forge.mil/sf/go/proj2530?uri=/sf/go/proj2530.

According to Jason Mackanick, a DISA information technology (IT) specialist, the collaboration portal allows users to get answers to questions from their peers instead of working through the help desk. He said the collaboration portal grew partly from the questions his team received from mission partners inquiring about which STIGs applied to them and that the agency has the content and the tools that need to get out to the community in an earlier fashion to obtain feedback before the activation of the production side.

SRGs and STIGs play a vital role in helping government and commercial organizations safeguard their information systems, and DISA has played a role in developing them since 1998.

Kreigline added that DOD Directive 8500.01E gives DISA the authority to establish a cybersecurity program to protect and defend the department’s information technology. The directive gives the agency the authority to develop Control Correlation Identifiers (CCI), SRGs, and STIGs.”

Kreigline explained SRGs are a collection of requirements applicable to a given technology family, product category, or organization in general. They are non-product specific requirements used to mitigate common security vulnerabilities encountered across information technology systems and applications.

STIGs, she continued, are an operationally implementable compendium of DoD Information Assurance (IA) controls, security regulations, and best practices for securing IA or IA-enabled device operating systems, networks, applications, and software. Kreigline said STIGs provide security guidance for actions such as mitigating insider threats, containing applications, preventing lateral movements, and securing information system credentials.

SRGs and STIGs are developed from CCIs, which allow security requirements expressed in high-level policy frameworks to be decomposed and explicitly associated with the low-level security settings. The ability to trace a security requirement from its origin to its low-level implementation enables organizations to demonstrate compliance with multiple IA frameworks. CCIs also provide the means to objectively combine and compare related compliance assessment results across disparate technologies.

The agency employs three different methods to write STIGs: in-house, where DISA subject matter experts write the STIG; a consensus effort, during which DISA develops the STIG in partnership with other government organizations — including the National Security Agency (NSA) and Office of the DoD Chief Information Officer; and through a vendor effort.

Kreigline noted that if a vendor is interested in developing a STIG, [DISA guides them] to develop the STIG using the agency’s format — not every vendor gets a STIG. DISA must apply some limiting factors as to what receives a STIG. The biggest factor for determining whether a STIG is written is the [volume of the product’s usage] within DoD. It’s not the only factor, but it’s the biggest factor.

The agency releases STIGs on a quarterly basis, in addition to issuing ad-hoc releases for items requiring immediate fixes.

For more information about SRGs and STIGs, visit https://cyber.mil/. For more information about STIG collaboration, visit project.forge.mil/sf/sfmain/do/home.

A copy of Kreigline’s presentation is located on DISA.mil.

Filed Under: Space Systems Software Engineering

Primary Sidebar

Coverage

  • Missions & Constellations
  • Business & Finance
  • Military & Defense
  • Launch
  • Software Automation & Ground Systems
  • Government & Regulation
  • Services & Applications

Most Read Stories

  • SpaceX Prepares for Record-Breaking $1.75 Trillion Confidential IPO Filing in March
  • The Iran Precedent: Operation Epic Fury and the Law of Armed Conflict in Space
  • AST SpaceMobile Encapsulates BlueBird 7 Satellite for Inaugural New Glenn Mission
  • Rheinmetall Withdraws From Mynaric Bidding Process; Rocket Lab Acquisition Clears Major Competitive Hurdle
  • L3Harris Unveils XL-300P: The First P25 Handheld with 5G and Satellite Direct-to-Device Connectivity

Secondary Sidebar

Footer

 

Satnews is a leading provider of satellite news, events, publications, research and other satellite industry information in both commercial and military enterprises worldwide.

Stories By Category

  • Business & Finance
  • Government & Regulation
  • Launch
  • Military & Defense
  • Missions & Constellations
  • Services & Applications
  • Software Automation & Ground Systems
  • Spectrum & Licensing
  • Startups & NewSpace Business

About Us

  • Leadership & Editorial Team
  • SatNews History
  • Free Satnews Subscription
  • SatNews Events
  • Magazines

Navigation

  • Latest Stories
  • Magazines
  • Events
  • Contact
  • Cookie & Privacy Policy for Satnews

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
x
Sign up Now (For Free)
Access daily or weekly satellite news updates covering all aspects of the commercial and military satellite industry.
Invalid email address
Notify Me Regarding ( At least one ):
We value your privacy and will not sell or share your email or other information with any other company. You may also unsubscribe at anytime.

Click Here to see our full privacy policy.
Thanks for subscribing!