DI-MGMT-81857
System Security Administrator Operators Documentation (SSAOD)
The SSAOD provides format and content instructions for contractor-developed documentation covering audit, archive, and anti-cyber warfare operating procedures to be integrated into a government OPSEC training manual.
Approval DateDecember 21, 2011
AMSC NumberN9239
Preparing Activity—
Project Number—
OPRSH/PEO IWS1.0
DTIC Applicable—
GIDEP Applicable—
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatdd_form_1664
963C CompliantNo
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
The SSAOD developed by the contractor will be integrated into a baseline OPSEC training manual by the government to train the audit and archive procedures and the operation of the anti-cyber warfare capabilities provided in the delivered system.
This Data Item Description (DID) contains the format and content preparation instructions for the data product generated by the specific and discrete task requirement as delineated in the contract.
Preparation Instructions
1Format.The System Security Administrator Operators Documentation shall be presented in a format similar to that of Figures 1 and 2.
2Content.The System Security Administrator Operators Documentation shall contain Appendixes "A" through "E".
2.1Appendix A shall identify:
2.1.2Appendix A.2 shall identify Diagnosing IA Alarms
2.1.3Appendix A.3 shall identify Generating an Incident Report Summary
2.2Appendix "B" shall include Changing Passwords:
2.2.1Appendix B.1 shall identify changing passwords on workstation consoles
2.2.2Appendix B.2 shall identify changing password procedures for rack mounted cpus
2.2.3Appendix B.3 shall identify changing password procedures for the automated status board
2.2.4Appendix B.6 shall identify changing password procedures for network devices
2.2.5Appendix B.7 shall identify changing file integrity checker passphrases
2.2.6Appendix B.8 shall identify changing file integrity checker passphrase
2.2.7Appendix B.9 shall identify changing audit tool password
2.2.8Appendix B.9.1 shall identify changing audit tool password for security administrator
2.2.9Appendix B.9.1 shall identify changing audit tool password for system administrator
2.3Appendix "C" shall be entitled Conduct System Audit.This appendix shall specify procedures to identify system misuse and hacker threat attacks. It shall detail what action should be taken if a security violation is found. This appendix shall also include the procedures to identify the following auditable items from the contractor's delivered system:
2.3.1List of Hostnames Included in the audit report
2.3.2List of Hostnames not Included in the audit report
2.3.3Alphabetical list of authorized usernames
2.3.4Chronological list of successful login attempts organized by Information System (IS)
2.3.5Chronological list of failed login attempts organized by IS
2.3.6Chronological list of successful sulog attempts organized by IS
2.3.7Chronological list of failed sulog attempts organized by IS
2.3.8Chronological list of alerts from the Intrusion Detection System (IDS)/Intrusion Prevention System (IPS) organized by IS
2.3.9Chronological list of file monitor alerts organized by IS
2.3.10Chronological list of system status
2.3.11Chronological list of successful root login attempts organized by IS
2.3.12Chronological list of root login attempts organized by IS
2.3.13Chronological list of user additions or deletions organized by IS
2.3.14Chronological list of password change attempts, both successful and unsuccessful organized by IS
2.3.15Chronological list of router/switch login attempts, both successful and unsuccessful organized by IS
2.3.16Chronological list of enable router/switch login, both successful and unsuccessful organized by IS
2.4Appendix "D" shall be entitled "Archive Security Logs".This appendix shall provide procedures to archive audit logs to removable backup media that will be stowed in a GSA-approved security container. This appendix shall include warnings to users that security audit logs and reports shall be kept for one year. This appendix shall also include warnings to users that record destruction shall be specified.
2.5Appendix "E" shall include procedures generating the Formal Incident Report.This appendix shall provide the procedures for reporting and documenting a computer security incident on DoD computer equipment to the Navy Cyber Defense Operations Command (NCDOC), the In-Service Engineering Agent, Program office and its support activities. This appendix shall include the procedures for crew submittal of an OPREP3. This appendix shall also specify the procedures to be used for reporting incident details after the OPREP-3 is sent.
3Media Requirements:The SSAOA electronic media shall be Microsoft Word Version 2003-2007.
Figures

Figure 1. How to Use This Appendix

Figure 2. Appendix B.1 Change Passwords on Workstation Consoles
Schema v3.0Community-maintained · Verify against ASSIST