The candidate
will be involved in IA activities and must have the capability
to:
• Develop, maintain, implement, and enforce a formal
IA security and training program.
• Implement IAVM dissemination, reporting, compliance,
and verification procedures.
• Report security violations and incidents to the
servicing RCERT in accordance with Section VIII, Incident
and Intrusion Reporting.
• Ensure implementation of periodic security inspections,
assessments, tests, and reviews.
• Manage IASOs, as required, to establish the scope
of responsibilities and the technical and security training
requirements.
• Semi-annually review the status of all ISs and networks
to ensure no relevant security changes have been made to
invalidate the C&A.
• Negotiate C&A issues with the DAA, or his or
her designated representative, for incoming systems and
make recommendations to the commander on acceptance or rejection
of ISs.
• Maintain training and certification records for
IA personnel and user IA awareness training.
• Ensure approved procedures are in place for clearing,
purging, destroying, and releasing system memory, media,
and devices.
• Review all IA C&A support documentation packages
and system fielding, operations, or upgrades requirements
to ensure accuracy and completeness, and that they meet
minimal risk acceptance standards.
• Maintain, as required, a repository for all systems
C&A documentation and modifications, version control,
and management of GOTS, COTS, and non-developmental Items
(NDIs) for his or her organization or site.
• Establish data ownership and responsibilities (including
accountability, access, and special handling requirements)
for each IS as required.
• Ensure that all ISs within the scope of responsibility
are properly certified and accredited in accordance with
DITSCAP and configuration management policies and practices
before operating or authorizing the use of hardware and
software on an IS or network.
• Serve as a member of an applicable CCB, where one
exists.
• Verify that IA personnel are maintaining and auditing
access and log data.
• Assist the IAPM to identify and validate IA resource
requirements.
• Provide input to the IAPM for management controls.
• The Installation IAM will provide policy and guidance
to all IAMs on an installation or cluster of small camps,
posts, or stations.
• Tenant IAMs will assist and support Installation
IAMs.
• Installation IAMs will report to the RCIO IAPM
|