DI-ADMN-81969
Joint Special Access Program Implementation Guide (JSIG) System Authorization Package (SAP)
The JSIG SAP is used to identify, control, and authorize a contractor's proposed stand-alone computer systems and/or networks created and used during the performance of the contract.
Approval DateAugust 7, 2014
AMSC NumberF9488
Preparing Activity—
Project Number—
OPR20 (AFRL/RYS)
DTIC ApplicableNo
GIDEP ApplicableNo
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatfree_text
963C CompliantYes
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
The JSIG SAP is used to identify, control, and authorize a contractor's proposed stand-alone computer systems and/or networks created and used during the performance of this contract. The contract Information System Security Officer (ISSO) or Information System Security Manager (ISSM) must submit the SAP documentation for a proposed system or network to the Authorizing Official (AO), Delegated Authorizing Official (DAO), or the Program Security Officer (PSO). The AO, DAO, or the PSO must provide written approval of any new information system or network before processing can begin.
a. The SAP describes the methods to: (1) identify systems, security responsibilities and requirements; (2) define overall security standard practice guidance and procedures; (3) identify potential problem areas and determine solutions; and (4) develop security awareness inputs into the overall system security process.
b. This Data Item Description (DID) defines the data required to obtain information systems authorization in accordance with the JSIG. A copy of the JSIG can be obtained from the government program office.
c. This DID contains the format and content preparation instructions for the data product generated by the specific and discrete task requirements delineated in the contract.
Preparation Instructions
1Reference documents.The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as cited in the ASSIST at the time of the solicitation or contract. (Copies of these documents are available from the Government Agency awarding the contract.)
1.1Department of Defense (DoD) JSIG
1.2DoD JSIG Template Handbook.
1.3Government Program Office Guidance.
2Format.The JSIG SAP Documentation shall be presented in Microsoft Word formats outlined by the DoD JSIG, DoD JSIG Template Handbook and the Government Information Assurance Officer (IAO). The initially used format arrangement shall be used for all subsequent submissions.
3Content.A JSIG system/network authorization package typically consists of:
3.1Authorization Package Cover Letter.
3.2Authorization to Operate (ATO) Letter.
3.3Security Assessment Report (SAR).
3.4Risk Assessment Report (RAR).
3.5System Security Plan (SSP).
3.6Security Control Traceability Matrix (SCTM).
3.7Plan of Action and Milestones (POA&M).
3.8ISSO/ISSM Appointment Letter.
3.9ISSO/ISSM 8570 Certification (per DoD 8570.01-M, Information Assurance Workforce Improvement Program).(Copies of this document are available online at http://www.dtic.mil/whs/directives/index.html.)
3.10General User's Guide (GUG).
3.11Privileged User's Guide (PUG).
3.13Software Approval Forms for High-Risk.
3.15Any other supporting documentation required via above documentation (facility accreditation, etc.)
3.16An SSP will be developed and maintained for each proposed stand-alone system or network.
3.17If an approved Interagency Standing Operating ProcedureIf an approved Interagency Standing Operating Procedure (IASOP) exists for previously authorized systems/networks, and will apply to the proposed system/network, submit a copy of the IASOP in addition to the items a through o, above.
3.18The SAP documentation will be revisedThe SAP documentation will be revised when any modifications are made to any portion of the system, network, personnel, or documentation.
3.19Classification of documentation will be appliedClassification of documentation will be applied in accordance with security classification guides or classification tables. 'Distribution Statement F. Further dissemination only as directed by (inserting controlling DoD office) (date of determination) or higher DoD authority.' applies to this package.
Schema v3.0Community-maintained · Verify against ASSIST