DI-MGMT-82510
Cybersecurity System Administrator Guide (CSAG)
The CSAG provides system administrators and cybersecurity personnel with system-specific administrative, operational, and technical procedures to securely operate and maintain a delivered system.
Approval DateJanuary 8, 2026
AMSC NumberN10612
Preparing ActivityAS
Project NumberMGMT-2026-001
OPR—
DTIC Applicable—
GIDEP Applicable—
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatfree_text
963C CompliantYes
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
The Cybersecurity System Administrator Guide (CSAG) provides system and subsystem specific administrative, operational, and technical procedures necessary to ensure the secure, reliable, and compliant operation of the delivered system in accordance with the terms and conditions of the contract. It serves as a critical resource for system administrators, cybersecurity personnel, and support staff responsible for maintaining system integrity, availability, and confidentiality throughout the lifecycle of the system.
The CSAG identifies key areas and outlines detailed procedures for system configuration, account management, patch management, system hardening, auditing, logging, incident response support, backup and recovery. This guide provides experienced individuals in cybersecurity roles with authoritative information and procedures to securely operate and maintain the system within its intended environment, reducing risk and ensuring mission continuity.
This DID contains the format, content, and intended use information for the data product resulting from the work task described in the contract SOW.
Preparation Instructions
1Referenced documents.Not applicable.
2Format.The CSAG shall be in contractor format.
3.1The CSAG shall contain the following:
3.1.1Title page.The CSAG shall have a title page providing the following information, as applicable:
3.1.1.1Document identification numbering
3.1.1.3Version or revision indicator
3.1.1.4Security classification
3.1.1.7Name of the system to which this CSAG applies
3.1.1.9Contract Data Requirements List (CDRL) item Number
3.1.1.10Organization for which the document has been prepared
3.1.1.11Distribution statement
3.1.1.12Controlled Unclassified Information (CUI)
3.1.1.13Export-Control warning
3.1.1.14Destruction notice
3.1.2Record of changesThe CSAG shall have a record of change from the previous document submission. Each submission shall append the changes to the record of changes section. The submissions shall have track changes turned on to record edits made in the document.
3.1.3Table of contentsThe CSAG shall have a table of contents providing the number, title, and page number for each titled paragraph, figure, table, and appendix.
3.1.4Page numberingEach page shall have a unique page number and include the document number, document version, volume, and date, as applicable.
3.1.5StylesDiagrams, tables, and other presentation styles are acceptable substitutes for text when the data required by this DID can be made more readable using these styles.
3.1.6Multiple paragraphs and subparagraphsAny section, paragraph, or subparagraph may be written as multiple paragraphs or subparagraphs to enhance readability.
3.1.7Duplicated contentAny section, paragraph, or subparagraph shall include dissimilar information to avoid the duplication of information.
3.1.8Substitution of existing documentsExisting documents may be substituted for portions of the CSAG if they contain the required information as defined by this DID and do not impose additional distribution restrictions. Such substitutions shall be included in the CSAG either as an appendix or as a separate document.
Additionally, if specified actions or relevant content are already present in previously delivered or to be delivered documents (e.g., Software Product Package (SPP), Training Device Inventory Checklist / Record (TD ICL/R)) those documents may be referenced to satisfy the content requirements of this DID, provided they meet the specified criteria. Each reference must clearly identify the document title, section number, and section title where the applicable procedures are located.
3.1.9Specified actionsRequired specified actions shall be broken down into discrete, manageable actions to effectively address complex tasks. Each specified action shall clearly outline the specific action to be performed, the expected result following that action. To enhance clarity and readability, visual aids such as images, screenshots, or other presentation formats maybe incorporated either alongside the text or in place of it.
3.1.10TraceabilityWhen applicable, delivered content shall include an associated Cybersecurity Control Requirements Identifier (e.g., RMF Control ID or CCI) adjacent to the content element to ensure traceability, accountability, and alignment with applicable cybersecurity compliance frameworks.
3.1.11Document topics and numberingThe following paragraph titles and content shall be included in the CSAG.
3.2ScopeThis section shall be divided into the following paragraphs.
3.2.1IdentificationThis paragraph shall fully identify the system to which this CSAG applies, including as applicable, identifying number(s), title(s), abbreviation(s), acronym(s), version number(s), release number(s), and other identifying information.
3.2.2System overviewThis paragraph shall summarize the purpose of the system to which this CSAG applies. It shall describe the general nature of the system; summarize the system development history; identify the project sponsor, acquirer, user(s), developer(s), and support agencies; identify current and planned operating sites; and list relevant documents.
3.2.3Document overviewThis paragraph shall summarize the purpose of this CSAG and describe the security or privacy considerations associated with its use.
3.2.4Referenced MaterialThis section shall list the title, number, revision, and date of the documents referenced within the CSAG. This section shall identify the source(s) for the documents not available through normal Government procuring activities.
3.3CSAG System(s) Content RequirementsThis section shall include the following content, as applicable:
3.3.1.1System DescriptionDefine the authorization boundary, network architecture, networks and sub-networks, and the internal and external interfaces.
3.3.1.2System ComponentsList and describe the hardware, software, and firmware per subsystem.
3.3.1.3Network DiagramInclude detailed diagrams in accordance with the DISA Connection Process Guide (CPG) with Internet Protocol (IP) addresses and network topology.
3.3.1.4Network Devices EquipmentIdentify the networking equipment (e.g., firewalls, routers, switches, IDS, and KVM) and explain their configuration settings and functionalities.
3.3.1.4.1Include specified actions to recover and restore the networking equipment, along with specified actions to reconfigure the port lockdown settings.
3.3.1.4.2Include a table detailing the function of each equipment port (e.g., VLAN access, Trunk, etc.).
3.3.1.5Ports, Protocols, and Services Management (PPSM)Identify the purpose of the PPS and the functionality.
3.3.1.5.1Identify open ports on each subsystem.
3.3.2System Configuration and Inventory
3.3.2.1IP Address InventoryInclude a table that lists the internal and external Ips with subsystem names.
3.3.2.2Asset Function SummaryDescribe the function of each Cybersecurity Management System (CMS) asset.
3.3.2.3Software LicensesIdentify the software license agreements, expiration dates, and support contact.
3.3.2.4Backup and Restore Capabilities
3.3.2.4.1Identify subsystems included in backups.
3.3.2.4.2Include specified actions to perform backup and restoration.
3.3.2.4.3Include specified actions to update passwords on backup jobs.
3.3.3Access Control and Account Management
3.3.3.1Identify and describe the access control method(s)(e.g., Role-Based Access Control (RBAC), Attribute-Based Access Control (ABAC), etc.).
3.3.3.2List and describe the administrators, users, groups, and permissions implemented.
3.3.3.3Authentication, Authorization, Accounting (AAA) Server Administration(e.g., RADIUS/TACAS+/ISE).
3.3.3.3.1Identify the AAA components and detail administrative actions.
3.3.3.4Remote Access Administration
3.3.3.4.1Identify any remote access to the system and administrative actions to maintain secure functionality.
3.3.3.5Account Creation and Management
3.3.3.5.1Identify the local, domain and service accounts with detailed information on the purpose of the accounts.
3.3.3.5.2Include specified actions to create, unlock, and change passwords for the account types.
3.3.3.5.3Identify privileged user setup: Operating System (OS), applications, databases, and network devices.
3.3.3.5.4Identify Application accounts: requirements and management.
3.3.3.5.5Identify SSH key setup, permissions, and group membership.
3.3.3.6Troubleshooting and Maintenance
3.3.3.6.1Identify group permissions per subsystem.
3.3.3.6.2Identify account maintenance process for OS, applications, databases, and network devices.
3.3.4Directory Services (Domain Controller / Active Directory)
3.3.4.1Describe the overview of the domain setup, including domain name, forest trust, organizational units (OUs), and relationships.
3.3.4.2Include specified actions for rejoining devices post Recovery and Restoration (R&R).
3.3.4.3Include specified actions for implementing baseline GPOs.
3.3.4.4Identify GPOs impacting authentication and access, including Original Equipment Manufacturer (OEM) created GPOs.
3.3.5Audit Log Management
3.3.5.1Centralized Auditing Implementation
3.3.5.1.1Identify the logging configuration across systems (e.g., PCs, servers, network devices).
3.3.5.1.2Identify Security Information and Event Management (SIEM) system details (e.g., location, access).
3.3.5.1.3Include specified actions required for log collection, aggregation, viewing, and reporting.Include specified actions to view and generate reports for subsystems without central auditing capabilities.
3.3.6Continuous Monitoring
3.3.6.1Include specified actions for the monitoring activities for the system, including the frequency (e.g., continuous, weekly, monthly, quarterly, semiannual, or annual) as provided by the government and applicable to the local site cybersecurity policies.
3.3.7System Updates and Vulnerability Management
3.3.7.1System Updates and Package Management
3.3.7.1.1Identify the configuration of the package manager to include external IPs to the centralized servers.
3.3.7.1.2Identify the Secure boot compatibility per subsystem.
3.3.7.1.3Include specified actions to implement system updates per subsystem.
3.3.7.2Updating Outside Networked Source
3.3.7.2.1Include specified actions for updating subsystems outside of the networked update source.
3.3.7.3Rebuilding Drivers Post Update
3.3.7.3.1Include specified action for rebuilding drivers in cases where the system or subsystem becomes nonfunctional during the update process.
3.3.7.4Vulnerability Scanning
3.3.7.4.1Identify the Scanner portal Uniform Resource Locator (URL), plugin and feed set, system coverage.
3.3.7.4.2Identify IPs and configuration for the scan servers.
3.3.7.4.3Describe the specifying credentials, targets and other configurations required for scans.
3.3.7.5.1Describe the patch management system and implementation of the patch management system for the vulnerabilities of a system.
3.3.8Encryption and Credential Binding
3.3.8.1Identify the key locations for the disk encryption solutions (e.g., BitLocker and Linux Unified Key Setup (LUKS)).
3.3.8.2Include specified action for configuring the encryption solution to include decryption.
3.3.8.3Include specified action for the credential binding and password change.
3.3.8.4Include specified actions to recover the encrypted subsystem.
3.3.9Endpoint Security Solution (ESS) and Endpoint Protection
3.3.9.1ESS/Centralized Security Management Agent Components
3.3.9.1.1Identify and describe each module implemented.
3.3.9.1.1.1Include specified action for Workstations and Servers.
3.3.9.1.2Anti-phishing and Anti-Malware software and ESS Policy Management
3.3.9.1.2.1Include specified action for temporarily disabling the software during maintenance.
3.3.9.1.3Antivirus Software Management
3.3.9.1.3.1Include specified actions to update the definitions and scanning per operating system.
3.3.9.1.3.2Provide procedures for configuring the security policy server, to include agent deployment, virus definition updates, and other necessary configuration settings.
3.3.10Firewall Configuration
3.3.10.1Describe the configurations for host-based firewalls, network firewalls and web application firewalls.
3.3.11.1Describe system tools that support incident response recognition, reporting, evidence preservation, and corrective actions.
3.3.12Public Key Infrastructure (PKI) and Certificate Management
3.3.12.1Describe the PKI implementation and management of certificates.
3.3.12.2Include specified actions to maintain PKI and certificates.
3.3.13Domain Name System (DNS) Administration
3.3.13.1Identify maintenance and review actions to maintain the DNS server role.
3.3.13.2Identify troubleshooting techniques for the replication of issues or general issues.If no issues have been discovered or identified, indicate "N/A."
3.3.14Dynamic Host Configuration Protocol (DHCP) Administration
3.3.14.1Identify maintenance and review actions to maintain the DHCP server role.
3.3.14.2Identify troubleshooting techniques for general issues.
3.3.15Hypervisor Administration
3.3.15.1Include specified actions for hypervisor administration to include virtual machine importing, exporting, networking and configuration as relevant.
3.3.16Network Attached Storage (NAS) AdministrationInclude specified actions for NAS administration (e.g., managing storage volumes, performance monitoring, updates, maintaining applications, file access controls, troubleshooting).
3.3.17Storage Area Network (SAN) AdministrationInclude specified actions for SAN administration (e.g., managing storage volumes, performance monitoring, updates, maintaining applications, file access controls, troubleshooting).
3.3.18Security Technical Implementation Guides (STIGs)
3.3.18.1Identify the applicable STIGs for the subsystems.
3.3.18.2Include actions for viewing all STIGs and steps required for manually completing those not automatically evaluated by available tools.
3.3.19Additional Security Controls
3.3.19.1Include specified actions for hardware swap-out if blocked by a control.
3.3.19.2Include specified actions for resetting and reauthorizing USB device control software (e.g., USBGuard).
3.3.19.3Include specified actions for whitelisting to bypass applications for updates.
3.3.19.4Include specified actions for temporary security exceptions.
3.3.19.5Include specified actions for the utilization of devices required to perform security functions (e.g., USB hard drive, connected shares, etc.)
3.3.20Maintenance and Cybersecurity Sustainment
3.3.20.1Identify compliance scanning and reporting.
3.3.20.2Include troubleshooting procedures for cybersecurity related subsystems, addressing commonly known issues and resolutions.
3.4NotesThis section shall provide an alphabetic listing of acronyms, abbreviations, and their meaning as used in this CSAG list of terms and definitions needed to understand the CSAG or the Appendices.
3.5AppendixesAppendixes may be used to provide information published separately for convenience in document maintenance (e.g., charts, classified data). As applicable, each appendix shall be referenced in the main body of the document where the data would normally have been provided. Appendixes may be bound as separate documents for ease in handling. Appendixes shall be lettered alphabetically (A, B, etc.)
Schema v3.0Community-maintained · Verify against ASSIST