|
Welcome
To The Definitive
DIACAP / DITSCAP / FISMA / NIST
Information Resource
Published by
Regulatory Compliance
Associates &
McGuinnessPublishing
Published as a free service to aid
in locating and accessing official information about DIACAP, DITSCAP,
FISAM and
NIST Certification & Accreditation security certification processes.
In addition, Regulatory Compliance
Associates and its
team provide expert level DIACAP/ DITSCAP / FISMA / C&A services to industry and government
customers. This includes State, Local, and Federal Governments.
DITSCAP / FISMA / C&A
Regulatory
Security
Services by
Regulatory Compliance Associates
DITSCAP, as well as
NIST 800-37 C&A are processes
for the identification of security risks and vulnerabilities, the
agreement of corrective action plans, and their achievement for
obtaining authorization to operate.
This is typically required
for connection to Department of Defense, and other Federal systems,
networks, and applications. DITSCAP is a process, not a
technology, so it includes numerous supporting technologies within its
framework. NIST800-37 is now being required by most Federal
Agencies for themselves and their subcontractors.
However, regardless of the use of specific solutions,
with the DITSCAP process, security is not automatically verifiable or
validated to meet requirements, unless the full process is utilized.
As an experienced DITSCAP service provider,
we
can manage your DITSCAP or C&A process or provide specific solution
requirements, including documentation (policies and procedures),
audits, and general oversight.
For more information about the DITSCAP
or C&A services provided, please contact us via email at:
ditscap @
regulatorypro . us
Regulatory Compliance Associates also specialists in
Regulatory Privacy & Security
HIPAA GLBA COPPA •
GCP 21cfr11
NIST800 •
ISO17799 Privacy Act 74
For
more information about
our Services please visit www.RegulatoryPro.us
|
|
DIACAP
RESOURCES
|
|
DIACAP Documents |
 |
Interim DoD IA Certification &
Accreditation Process:
Signed Directive - Type Memo for DIACAP
New!
(posted 7/20/2006) Jul 6, 2006 |
 |
Interim DoD IA Certification &
Accreditation Process Guidance
New!
(posted 7/20/2006) Jul 6, 2006
|
 |
DIACAP Workflow Map
- New! (posted 7/28/2006) Jul
6, 2006 |
 |
DIACAP FAQ's
New!
(posted 7/20/2006)
Provides answers on how to
access the
Knowledge Service, find out
about eMASS, and includes contact information Jul 6, 2006
|
 |
Certification and Accreditation
Requirements for DoD-wide Managed Enterprise Services
Procurements, DoD Chief Information Officer memorandum
New!
(posted 9/11/2006)
(DoD PKI cert req'd) Jun 22, 2006 |
|
DITSCAP
To DIACAP
TRANSITION
RESOURCES
|
|
DIACAP Documents |
 |
Enclosure 6 - DIACAP Transition
Guidelines
- New! (posted 7/28/2006)
Enclosure 6 of the Interim DoD IA
C&A Process Guidance (DIACAP) provides a timeline and general
instructions for the transition from DITSCAP to DIACAP. More
detailed information and associated DIACAP templates are
available on the |
 |
DIACAP Knowledge Service. |
|
DITSCAP
RESOURCES
|
|
DITSCAP Documents |
|
|
According to the instructions in the
above Enclosure 6, under certain conditions organizations will
continue to maintain a DITSCAP status for specific systems as
they execute the transition to the DIACAP. Consequently, some
DITSCAP related documents will be retained on this site. |
 |
DITSCAP Application Manual
Signed PDF July 31, 2000 |
 |
DITSCAP Application Manual
Text Format
July
31, 2000 |
 |
Policy and Guidance |
 |
NIACAP April 2000 |
 |
What is DITSCAP? Click Here First!
FREE DITSCAP Training |
 |
DITSCAP
On-Line - Online Version |
 |
DITSCAP (Signed PDF)
The official signed
version of DoD Instruction 5200.40,DITSCAP is dated 30 Dec. 97.
An
Adobe Acrobat reader is required to view PDF file. |
 |
DoD Information Technology Security
Certification and Accreditation Process Signed PDF
Dec 30, 1997 |
 |
DITSCAP (Text Format)
The text version of DoDI
5200.40 DITSCAP. |
|
DITSCAP Support |
 |
DITSCAP Application
Manual
Signed PDF (678
KB)
ASCII Text (306
KB) |
 |
DITSCAP
Article
Life Cycle Security and
DITSCAP article from the IAnewsletter |
 |
DITSCAP
Presentation
Power point presentation of
the DITSCAP. |
 |
DAA
Information Operations and
the DAA presentation |
 |
DoD Generic
Training Plan
This training plan
describes and defines the security awareness, training, and
educational program goals, objectives, and standards for
supporting the Department of Defense mission. |
 |
Guidance
Memorandums
The DITSCAP Policy (DoD
Instruction 5200.4), directs DISA to provide assistance such as
information systems security engineering, security solutions, and
security guidance to the DoD components in the use of the
DITSCAP. DISA was also directed to operate and maintain an
on-line information assurance support environment (IASE) website.
In response to this tasking, a series of DITSCAP Guidance
Memorandums (DGM's) are being developed by DISA (in coordination
with the DITSCAP Working Group), to provide interim guidance and
assistance for parts of the DITSCAP policy and processes that
require further clarification. (These DGM's are not intended to
supercede any existing Service and Agency policy guidance related
to the DITSCAP). An updated version of the DITSCAP policy is
under development by the DITSCAP Working Group, and these DGM's be
superceded when the new policy instruction is signed. |
 |
RTM
Database
Contains all technical
security requirements of DoD Information Systems (ISs). |
 |
NIACAP
National Information
Assurance Certification and Accreditation Process (NIACAP)
provides guidance for federal departments and agencies on how to
implement a C&A process for national security systems under their
operational control. |
 |
DITSCAP
Documents - List of DITSCAP related
documents. |
 |
DoDD 8500.1 Information Assurance (IA)
Directive |
|
FISMA
RESOURCES
|
|
FISMA Support |
 |
Wiki FISMA Introduction Document |
 |
Full text of FISMA |
 |
Report on 2004 FISMA scores |
 |
NIST FISMA Implementation Project Home
Page |
|
NIST
RESOURCES
|
|
NIST Support |
 |
Security Certification and Accreditation
101 |
 |
NIST Computer Security Resource Center |
 |
NIST SP 800 Series Special Publications
Library |

NATURAL DISASTER WARNING:
All sites within the Emergency Zones
following a major disaster may be required
to re-certify as a result of storm related activities!
Most entities, be they Federal Agencies or
Subcontractors located in this area, either evacuated, were damaged,
or engaged in other impacting activities. Thus a full analysis
of restart and continuity status must be performed, possibly resulting
in repeating (although possibly on a limited basis) the C&A process.
We, and our partners, stand ready to
assist you rapidly recertify to obtain your renewed authorization.
Please contact us at once. Please email us at
contact @
regulatorypro . us
Also visit our C&A
Site. |