Defense sets requirements for information assurance personnel

The Defense Department has issued a new manual that lays out procedures for training, certifying and managing employees responsible for information assurance within the department.

In the foreword John Grimes, DOD CIO and assistant secretary for networks and information integration, said the manual "is effective immediately and is mandatory for use" by all elements of the Defense Department.

The manual follows up on a directive issued in August 2004 by deputy secretary Paul Wolfowitz that established DOD policy and assigned responsibilities for information assurance training.

This is the first time the Pentagon has formalized and standardized the levels and types of training required for IA professionals throughout the department, said Alan Paller, director of research for the SANS Institute.

Until now, the individual services and Defense agencies were responsible for defining their own professional requirements for IA employees, a process that was less than thorough, he said.

Among the oversight responsibilities given to IA personnel are identifying information assurance requirements as part of the IT acquisition development process; maintaining configuration control of hardware, applications and systems; and installing and administering user identification or authentication mechanisms.

Patience Wait is a senior writer for Washington Technology's sister publication, Government Computer News.

Reader Comments

Please post your comments here. Comments are moderated, so they may not appear immediately after submitting. We will not post comments that we consider abusive or off-topic.

Please type the letters/numbers you see above.

What is your e-mail address?

My e-mail address is:

Do you have a password?

Forgot your password? Click here

Washington Technology Daily

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.


contracts DB