Process Deviations and/or Additional Requirements
Documentation Requirements
Develop a PowerPoint briefing based on provided guidance and the waiver criteria. The briefing will cover the points below and be conducted at the Secret level or below. New and renewal waiver briefing templates are located in SNAP at https://snap.dod.mil/gcap/reference-docs.cfm. A Soft copy of the briefing must be uploaded electronically in SNAP for review at least six weeks prior to the OSD GIG Waiver Panel meeting. All CC/S/A partners are required to coordinate the presentation with their SRO.
NOTE: Prior to submission of this brief the SRO's must validate the brief, including the mission in SNAP, and ensure the DAA has provided the applicable IATO/ATO.
Accreditation - All DoD ISs require certification and accreditation through DIACAP (DoDI 8510.01 (ref g)). Waivers will not be processed further if the accreditation is not current. DAA approved Scorecard with expiration date should assert the DAA's acknowledgement of mission and connection requirements, and acceptance of the risk associated with deviation from standard architecture.
NOTE: The scorecard must be signed and dated by the DAA
Independent verification (Certification and Accreditation (CA) letter) of physical and logical separation from the DoD network may be required.
PowerPoint Briefs should include the following slides:
1. Cover slide
-
Type of Waiver Request, Name of Component/Agency, Waiver Request Identification #, Submission Date, CIO, and POC.
2. Request Summary Slide
-
Specify what you are requesting and for how long. Also specify if the connection will be procured through DITCO or another DISN service in the future.
3. Organization and Mission Requirement Slide
4. Requirements Overview Slide
-
What is the operational requirement?
-
What has DISA provided as a DISN solution and why does it not fulfill your requirement?
-
Data Transfer Movement Policy (what policy is currently in place for the command/headquarters?)
-
Data Information (what data and information is crossing the connection. How is traffic being introduced to the DISN?)
- Other questions the panel/board will consider:
-
Is the requirement National Security System (NSS), command and control, mission essential?
-
What operational considerations merit deviation from the DoD DISN/GIG architecture?
-
Is this a requirement or a solution?
-
Is the time requirement valid?
5. Security Evaluation Status Slide
6. Topology Diagram Slide
-
Provide a communications diagram of current architecture and proposed architectures. At a minimum, the drawing must identify any Intrusion Detection Systems (IDSs), premise router, firewalls, any other security-related systems that are installed, and any connections to other systems/networks. If NIPRNet-to-Internet connection, identify the command communications service designators (CCSDs) of all connections to the DISN. Identifications to other connected systems should include the name of the organization that owns the system/enclave, the connection type (e.g., wireless, dedicated point-to-point), and the organization type (e.g., federal, DoD, contractor, etc.).
7. Waiver Architecture Slide (see topology guidance at the end of this section)
-
Architectural Congruence - Coordination with the DISA NIPRNet Manager is required to ensure DoD Global Information Grid (GIG) architecture compliance.
-
Other questions the panel/board will consider:
-
Is this a defined technical requirement?
-
Is the request duplicative of other reaccreditation service?
-
Does this deviate from DoD architecture and preserve interoperability?
-
Does this deviate from DoD architecture and preserve positive control?
-
Does this deviate from DoD architecture and enable network control?
-
Does this deviate from DoD architecture and enable configuration management?
-
How much time will it take DISA to migrate the network to DISN?
-
Using current offerings, can DISA provide the services requested?
-
Will DISA expand current offerings to include the services requested?
8. Identified Vulnerabilities & Risk Mitigation Slide
9. Residual Risk Slide
-
Discuss all of the residual security risks that cannot be mitigated (or will not be mitigated until a future date).
10. Business Case/Best Practices Slide
-
How much will it cost? Include all costs. This must be coordinated with DISA.
-
Questions the panel/board will consider:
-
-
Is there a supporting business case?
-
If a service network solution is not possible, what is the business case for transport only solution?
-
Time requirement – Commercial Contract expires/Waiver expires.
-
Monthly Reoccurring or Annual Cost for the ISP connection.
-
What is the total cost to DoD?
11. Alternative Solutions Slide
-
Specify why the CC/S/A cannot use a Defense Information System Network (DISN) solution to perform the requirement being requested.
12. Cost Alternatives Slide
13. Alternative Comparisons Slide
14. Business Plan Alternatives Slide
-
Plan for obtaining the commercial ISP connection through the appropriate DITCO contracting office.
15. Recommendation & Actions Slide
-
Provide recommendation and actions of chosen alternative required to make it happen.