AIR FORCE AF ETL 11-1-2011 Civil Engineer Industrial Control System Information Assurance Compliance.pdf
《AIR FORCE AF ETL 11-1-2011 Civil Engineer Industrial Control System Information Assurance Compliance.pdf》由会员分享,可在线阅读,更多相关《AIR FORCE AF ETL 11-1-2011 Civil Engineer Industrial Control System Information Assurance Compliance.pdf(32页珍藏版)》请在麦多课文档分享上搜索。
1、DEPARTMENT OF THE AIR FORCE HEADQUARTERS AIR FORCE CIVIL ENGINEER SUPPORT AGENCY 30 MAR 2011 APPROVED FOR PUBLIC RELEASE: DISTRIBUTION UNLIMITED FROM: HQ AFCESA/CEO 139 Barnes Drive Suite 1 Tyndall AFB FL 32403-5319 SUBJECT: Engineering Technical Letter (ETL) 11-1: Civil Engineer Industrial Control
2、System Information Assurance Compliance 1. Purpose. This ETL provides technical guidance and criteria for information assurance (IA) of civil engineering (CE) industrial control systems (ICS). This ETL applies to all ICSs that utilize any means of connectivity to monitor and control industrial proce
3、sses, including supervisory control and data acquisition (SCADA) systems, distributed control systems (DCS), and other control system configurations such as programmable logic controllers (PLC), which are often found in industrial equipment and critical infrastructures. Note: The use of the name or
4、mark of any specific manufacturer, commercial product, commodity, or service in this ETL does not imply endorsement by the Air Force. 2. Application. This ETL supersedes ETL 09-11, Civil Engineering Industrial Control System Information Assurance Compliance, dated October 26, 2009. Requirements in t
5、his ETL are mandatory. The interpreting authority for this ETL is the Air Force Civil Engineer Support Agency, Operations and Programs Support Division, Engineer Support Branch (HQ AFCESA/CEOA). 2.1. Authority: Air Force instruction (AFI) 32-1063, Electric Power Systems. 2.2. Effective Date: Immedia
6、tely. 2.3. Intended Users: Major command (MAJCOM) engineers Base civil engineers (BCE) ICS information assurance managers (IAM) 2.4. Coordination: MAJCOM engineers responsible for CE ICSs The Air Force Civil Engineer, Resources Division, Information Technology Branch (HQ AF/A7CRT) Air Force Network
7、Integration Center, Information Assurance Directorate (AFNIC/EV) and Air Force certifying authority (CA) Chief, Cyberspace Surety Division (SAF/A6OI), on behalf of Director, Cyberspace Operations (SAF/A6O) and Air Force senior information assurance officer (SIAO) Provided by IHSNot for ResaleNo repr
8、oduction or networking permitted without license from IHS-,-,-2 3. Referenced Publications. 3.1. Air Force (departmental publications available at http:/www.e-publishing.af.mil/): Air Force policy directive (AFPD) 16-14, Information Protection AFI 31-401, Information Security Program Management AFI
9、31-501, Personnel Security Program Management AFI 32-1063, Electric Power Systems AFI 33-112, Information Technology Hardware Asset Management AFI 33-114, Software Management AFI 33-115V1, Network Operations (NETOPS) AFI 33-115V2, Licensing Network Users and Certifying Network Professionals AFI 33-2
10、00, Information Assurance (IA) Management AFI 33-210, Air Force Certification and Accreditation (C however, PITIs are specifically subject to the AFCAP, per AFI 33-210. 5.2.4. Figure 1 shows the applicability of IA policy for PIT systems and IA policy and the AFCAP for PITIs to the AF-GIG. 6. Design
11、ated Personnel Roles, Responsibilities, and Qualifications. Security Boundary/DMZ Platform IT (PIT) AF-GIG Figure 1. AFCAP Applicability (AFI 33-210) PIT Interconnection (PITI) Subject to IA policy and PIT C validate all access privileges annually; and re-evaluate frequency requirements every three
12、years or at any mission change, system change, or other significant change to operating requirements. Ensure appropriate access privileges for all individuals based on their training, qualification, and functional duties. Manage CE ICS access by ensuring that accounts are deactivated or activated in
13、 a controlled manner. Personnel designated to make configuration decisions and responsible for IA controls for both PIT and PITI shall be certified to IAT Level II or IAM Level I in accordance with DOD 8570.01-M. Have full administrative rights to install software updates/patches. Have access to rev
14、iew, modify, and edit the Enterprise Information Technology Data Repository (EITDR) entries as approved by the ICS FAM. Provided by IHSNot for ResaleNo reproduction or networking permitted without license from IHS-,-,-9 Document and track system configurations for each CE-owned, -operated, and -main
15、tained ICS throughout the system life cycle, including any Air Force CE ICSs operated and maintained by contractors. For each ICS, the ICS IAMs will assemble a PIT determination package in accordance with section 7.1.1 of this ETL and forward the package to the respective ICS FAM. Provide an annual
16、report entitled “Industrial Control System Security Status Report” to the MAJCOM ICS FAM. The report will include a summary of current systems and system changes and will indicate compliance/non-compliance with IA security requirements. This report is due to the ICS FAM in October of each year. 6.1.
17、1.3. The alternate ICS IAM shall: Document and track system configurations for each CE-owned, -operated, and -maintained ICS throughout the system life cycle, including any Air Force CE ICSs operated and maintained by contractors. For each ICS, the ICS IAMs will assemble a PIT determination package
18、in accordance with section 7.1.1 of this ETL and forward the package to the respective ICS FAM. Provide an annual report entitled “Industrial Control System Security Status Report” to the MAJCOM ICS FAM. The report will include a summary of current systems and system changes and will indicate compli
19、ance/non-compliance with IA security requirements. This report is due to the ICS FAM in October of each year. 6.1.2. MAJCOM ICS FAM. The ICS FAM is designated in writing by the MAJCOM A7O (Operations) or equivalent. The ICS FAM is responsible for collecting the base-level PIT determination packages,
20、 reviewing them for completeness, and sending them to the ICS PM. In addition, the ICS FAM will submit an annual report entitled “Industrial Control System Security Status Report” to the ICS PfM. This report will contain a summary of current systems and system changes and will indicate compliance/no
21、n-compliance with IA security requirements. This report is due in November of each year. The ICS FAM may have access to create, modify, or delete EITDR entries as approved by the ICS PM or ICS PfM. 6.1.3. ICS PM. The ICS PM is designated in writing by HQ AFCESA/CEO. The ICS PM is responsible for ens
22、uring appropriate scheduling of all IA aspects of the program to meet the ultimate goals of IA compliance. The ICS PM is also responsible to ensure that the following tasks are accomplished: Review and submit ICS PIT packages to Air Force CA for a PIT determination statement. Complete initial EITDR
23、entries for CE ICS PITs. Provide updates to MAJCOM FAMs on the status of C Phase 2, ICS PIT C and Phase 3, PITI AFCAP. Figure 2 summarizes the CE ICS C Secure Sockets Layer (SSL) v3; Transport Layer Security (TLS); and systems using National Security Agency (NSA) -approved high assurance guards with
24、 link encryption methodology. Exception: Fire alarm reporting systems do not require data encryption for signaling to/from the fire alarm control panel (FACP). See paragraph 8.1.5.3 for requirements for sensitive compartmented information facilities (SCIF). Provided by IHSNot for ResaleNo reproducti
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
5000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- AIRFORCEAFETL1112011CIVILENGINEERINDUSTRIALCONTROLSYSTEMINFORMATIONASSURANCECOMPLIANCEPDF

链接地址:http://www.mydoc123.com/p-427217.html