• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer
  • NEWS:
  • SatNews
  • SatMagazine
  • MilSatMagazine
  • SmallSat News
  • |     EVENTS:
  • SmallSat Symposium
  • Satellite Innovation
  • MilSat Symposium
  • SmallSat Europe

SatNews

Satellite Industry Intelligence Since 1983

Subscribe
  • LATEST
  • SatNews Events
  • Magazines
  • Calendar
  • Subscribe
  • Missions & Constellations
    • Exploration & Science Missions
    • In-Orbit Servicing & Orbital Operations
    • LEO Constellations
    • Mission Autonomy & Onboard Systems
    • Mission Deployments & Manifests
    • Navigation & PNT
    • SmallSat
    • Spacecraft & Payload Technology
    View All in Missions & Constellations →
    SpaceX’s Secret ‘Starfall’ Capsule Wins FAA Approval for Pacific Reentry TestsSpaceX’s Secret ‘Starfall’ Capsule Wins FAA Approval for Pacific Reentry Tests
    NOAA Activates First Dedicated U.S. Space Weather Satellite One Million Miles from EarthNOAA Activates First Dedicated U.S. Space Weather Satellite One Million Miles from Earth
    Thales Alenia Space to coordinate EROSS SC On-Orbit Servicing projectThales Alenia Space to coordinate EROSS SC On-Orbit Servicing project
    Astroscale Launches Industry Initiative to Study Atmospheric Impact of Spacecraft ReentryAstroscale Launches Industry Initiative to Study Atmospheric Impact of Spacecraft Reentry
  • Business
    • Contracts & Commercial Deals
    • Earnings & Financial Reporting
    • Events & Conferences
    • Funding & Venture Capital
    • Market Forecasts
    • Mergers & Acquisitions
    • Personnel Moves & Appointments
    View All in Business & Finance →
    Isar Aerospace Secures €270 Million Series D to Ramp Up Spectrum Launch Vehicle ProductionIsar Aerospace Secures €270 Million Series D to Ramp Up Spectrum Launch Vehicle Production
    Made in Space: UK funding boosts breakthrough space technologiesMade in Space: UK funding boosts breakthrough space technologies
    Investor Scrutiny Mounts for York Space Systems Following Pentagon Contract TurmoilInvestor Scrutiny Mounts for York Space Systems Following Pentagon Contract Turmoil
    IEC Telecom Establishes Local Indonesian Entity to Address Archipelago’s Expanding Satellite Connectivity DemandsIEC Telecom Establishes Local Indonesian Entity to Address Archipelago’s Expanding Satellite Connectivity Demands
  • Defense
    • Counterspace & ASAT
    • Defense Budgets & Procurement
    • ISR & Reconnaissance
    • MILSATCOM
    • Missile Warning & Defense
    • National Security Programs
    • Space Domain Awareness
    View All in Military & Defense →
    Qorvo Unveils Compact X-Band Radar Module to Enhance Defense System PerformanceQorvo Unveils Compact X-Band Radar Module to Enhance Defense System Performance
    Energration and Atombeam Partner on DARPA Proposal to Revolutionize Tactical Data Movement at the Defense EdgeEnergration and Atombeam Partner on DARPA Proposal to Revolutionize Tactical Data Movement at the Defense Edge
    American military space closed around one company in seven daysAmerican military space closed around one company in seven days
    MDA Space Selected by BAE Systems for U.S. Space Force Missile Warning ConstellationMDA Space Selected by BAE Systems for U.S. Space Force Missile Warning Constellation
  • Gov
    • Export Controls & Compliance
    • International Space Agreements
    • National Space Policy
    • Space Law & Treaties
    • Space Sustainability & Debris Policy
    • Space Traffic Management / Debris Removal
    View All in Government & Regulation →
    Major opportunities for 2 GHz over EuropeMajor opportunities for 2 GHz over Europe
    “Dual-use” is the funding word. It’s also the label operators want off.“Dual-use” is the funding word. It’s also the label operators want off.
    Sovereignty got an answer on Day 3. Two answers, actually, and a commercial veto.Sovereignty got an answer on Day 3. Two answers, actually, and a commercial veto.
    Dependency killed the old debate. Sovereignty is the new one, and Europe hasn’t agreed what it means.Dependency killed the old debate. Sovereignty is the new one, and Europe hasn’t agreed what it means.
  • Launch
    • Launch Providers
    • Launch Schedule & Calendars
    • Launch Sites & Infrastructure
    • Rocket Technology & Vehicles
    View All in Launch →
    Breaking the TRL Bottleneck: Space Phoenix Systems Debuts Cost-Effective Space Test-and-Return ServiceBreaking the TRL Bottleneck: Space Phoenix Systems Debuts Cost-Effective Space Test-and-Return Service
    Twelve Scientific Payloads Experience Microgravity Aboard SubOrbital Express-5Twelve Scientific Payloads Experience Microgravity Aboard SubOrbital Express-5
    Amazon Leo Constellation Surpasses 330 Satellites Following Latest Atlas V LaunchAmazon Leo Constellation Surpasses 330 Satellites Following Latest Atlas V Launch
    If You Thought Space Was Hard Try to Get Your Satellite On a RocketIf You Thought Space Was Hard Try to Get Your Satellite On a Rocket
  • Software
    • Autonomous Ground Operations
    • Data Processing & AI/ML
    • Digital Twins & Modeling
    • Ground Segment & Teleports
    • Mission Planning & Simulation
    • Space Systems Software Engineering
    • Spectrum & Licensing
    View All in Software Automation & Ground Systems →
    Three LEO Operators Bet 2026 on a Supply Chain Built for 2027Three LEO Operators Bet 2026 on a Supply Chain Built for 2027
    NASA Advances Interoperable Space Networks with Successful PExT DemonstrationNASA Advances Interoperable Space Networks with Successful PExT Demonstration
    KSAT and iQPS Expand Strategic Alliance to Accelerate High-Frequency SAR ConstellationKSAT and iQPS Expand Strategic Alliance to Accelerate High-Frequency SAR Constellation
    KSAT and Axelspace Expand Strategic Partnership to Accelerate Earth ObservationKSAT and Axelspace Expand Strategic Partnership to Accelerate Earth Observation
  • Services & Apps
    • Climate & Environmental Monitoring
    • Disaster Response & Security Mapping
    • Earth Observation & Imaging
    • Maritime & Aviation Satcom
    • Satellite Communications
    View All in Services & Applications →
    Eutelsat and Tototheo Global Forge Partnership to Deliver LEO Connectivity Across Maritime and Government SectorsEutelsat and Tototheo Global Forge Partnership to Deliver LEO Connectivity Across Maritime and Government Sectors
    Marlink Equips Groupama-FDJ Cycling Team with Hybrid Starlink and LTE NetworkMarlink Equips Groupama-FDJ Cycling Team with Hybrid Starlink and LTE Network
    Viasat Secures Lockheed Martin Contract for NOAA’s Next-Generation AircraftViasat Secures Lockheed Martin Contract for NOAA’s Next-Generation Aircraft
    SES Partners with Viva to Launch Multi-Orbit In-Flight ConnectivitySES Partners with Viva to Launch Multi-Orbit In-Flight Connectivity

DISA Unveils Cyber.mil as the New Home of Cybersecurity Standards

May 27, 2019

The Defense Information Systems Agency (DISA) has migrated its Security Requirements Guides (SRGs) and Security Technology Implementation Guides (STIGs) to a new home.

DISA previously hosted these security configuration standards for Department of Defense (DoD) systems and software on the Information Assurance Support Environment (IASE) portal, https://iase.disa.mil, which the agency is no longer updating.

Sue Kreigline, Chief of DISA’s cyber standards branch, said the new DOD Cyber Exchange portal at cyber.mil, which is restricted to use by individuals with a DoD-issued Common Access Card (CAC), hosts:

  • More than 350 security guides.
  • Security content automation protocols.
  • A STIG viewer capability, which enables offline data entry and provides the ability to view one or more STIGs in a human-readable format.
  • A STIG applicability tool, which assists in determining what SRGs and STIGs apply to specific situations.
  • A Windows 10 Secure Host Baseline download.

 

The cyber standards chief announced the change at AFCEA’s TechNet Cyber 2019 symposium in Baltimore. Maryland, on May 16, where she and other DISA Cyber Standards Branch representatives discussed SRGs and STIGs.

The Cyber Standards Branch — also announced a new STIG collaboration portal — enables technology discussions among subject matter experts. The collaboration portal is also restricted to CAC-holders and can be accessed via software.forge.mil/sf/go/proj2530?uri=/sf/go/proj2530.

According to Jason Mackanick, a DISA information technology (IT) specialist, the collaboration portal allows users to get answers to questions from their peers instead of working through the help desk. He said the collaboration portal grew partly from the questions his team received from mission partners inquiring about which STIGs applied to them and that the agency has the content and the tools that need to get out to the community in an earlier fashion to obtain feedback before the activation of the production side.

SRGs and STIGs play a vital role in helping government and commercial organizations safeguard their information systems, and DISA has played a role in developing them since 1998.

Kreigline added that DOD Directive 8500.01E gives DISA the authority to establish a cybersecurity program to protect and defend the department’s information technology. The directive gives the agency the authority to develop Control Correlation Identifiers (CCI), SRGs, and STIGs.”

Kreigline explained SRGs are a collection of requirements applicable to a given technology family, product category, or organization in general. They are non-product specific requirements used to mitigate common security vulnerabilities encountered across information technology systems and applications.

STIGs, she continued, are an operationally implementable compendium of DoD Information Assurance (IA) controls, security regulations, and best practices for securing IA or IA-enabled device operating systems, networks, applications, and software. Kreigline said STIGs provide security guidance for actions such as mitigating insider threats, containing applications, preventing lateral movements, and securing information system credentials.

SRGs and STIGs are developed from CCIs, which allow security requirements expressed in high-level policy frameworks to be decomposed and explicitly associated with the low-level security settings. The ability to trace a security requirement from its origin to its low-level implementation enables organizations to demonstrate compliance with multiple IA frameworks. CCIs also provide the means to objectively combine and compare related compliance assessment results across disparate technologies.

The agency employs three different methods to write STIGs: in-house, where DISA subject matter experts write the STIG; a consensus effort, during which DISA develops the STIG in partnership with other government organizations — including the National Security Agency (NSA) and Office of the DoD Chief Information Officer; and through a vendor effort.

Kreigline noted that if a vendor is interested in developing a STIG, [DISA guides them] to develop the STIG using the agency’s format — not every vendor gets a STIG. DISA must apply some limiting factors as to what receives a STIG. The biggest factor for determining whether a STIG is written is the [volume of the product’s usage] within DoD. It’s not the only factor, but it’s the biggest factor.

The agency releases STIGs on a quarterly basis, in addition to issuing ad-hoc releases for items requiring immediate fixes.

For more information about SRGs and STIGs, visit https://cyber.mil/. For more information about STIG collaboration, visit project.forge.mil/sf/sfmain/do/home.

A copy of Kreigline’s presentation is located on DISA.mil.

Filed Under: Space Systems Software Engineering

Primary Sidebar

Coverage

  • Missions & Constellations
  • Business & Finance
  • Military & Defense
  • Launch
  • Software Automation & Ground Systems
  • Government & Regulation
  • Services & Applications

Most Read Stories

  • SpaceX Debuts Starship V3: Redefining Heavy-Lift Launch Capability
  • SpaceX Is Worth $1.75 Trillion. Only 7% of That Is Real.
  • FCC Approves Landmark Spectrum Sharing and Direct-to-Device Frameworks
  • SpaceX: 10,000 Launches Annually
  • The end of GEO?

Secondary Sidebar

Footer

 

Satnews is a leading provider of satellite news, events, publications, research and other satellite industry information in both commercial and military enterprises worldwide.

Stories By Category

  • Business & Finance
  • Government & Regulation
  • Launch
  • Military & Defense
  • Missions & Constellations
  • Services & Applications
  • Software Automation & Ground Systems
  • Spectrum & Licensing
  • Startups & NewSpace Business

About Us

  • Leadership & Editorial Team
  • SatNews History
  • Free Satnews Subscription
  • SatNews Events
  • Magazines

Navigation

  • Latest Stories
  • Magazines
  • Events
  • Contact
  • Cookie & Privacy Policy for Satnews

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
x
Sign up Now (For Free)
Access daily or weekly satellite news updates covering all aspects of the commercial and military satellite industry.
Invalid email address
Notify Me Regarding ( At least one ):
We value your privacy and will not sell or share your email or other information with any other company. You may also unsubscribe at anytime.

Click Here to see our full privacy policy.
Thanks for subscribing!