Implications of Aggregated DoD Information Systems for Information Assurance Certification and Accreditation

Eric Landree, Daniel Gonzales, Chad J. R. Ohlandt, Carolyn Wong

ResearchPublished Mar 3, 2010

The challenges associated with securing U.S. Department of Defense (DoD) information systems have grown as the department's information infrastructure has become more complex and interconnected. At the same time, the potential negative consequences associated with cyber intrusions have become more severe. Are current information assurance (IA) policies and procedures sufficient to address this growing threat, and are they able to address vulnerability issues associated with highly networked information systems? The current IA certification and accreditation (C&A) process focuses on individual, discrete systems or components of larger, aggregated information systems and networks that are colocated or operate on the same platform (such as a Navy ship). An examination of current policy shows that a new approach is needed to effectively extend the IA C&A process to aggregations of information systems and improve the security of DoD information systems. A number of recommendations are put forth to improve current IA policy and to enable the IA C&A of aggregations of DoD information systems that reside on a common platform.

Topics

Document Details

Citation

Chicago Manual of Style

Landree, Eric, Daniel Gonzales, Chad J. R. Ohlandt, and Carolyn Wong, Implications of Aggregated DoD Information Systems for Information Assurance Certification and Accreditation. Santa Monica, CA: RAND Corporation, 2010. https://www.rand.org/pubs/monographs/MG951.html.
BibTeX RIS

This publication is part of the RAND monograph series. RAND monographs were products of RAND from 2003 to 2011 that presented major research findings that addressed the challenges facing the public and private sectors. All RAND monographs were subjected to rigorous peer review to ensure high standards for research quality and objectivity.

This document and trademark(s) contained herein are protected by law. This representation of RAND intellectual property is provided for noncommercial use only. Unauthorized posting of this publication online is prohibited; linking directly to this product page is encouraged. Permission is required from RAND to reproduce, or reuse in another form, any of its research documents for commercial purposes. For information on reprint and reuse permissions, please visit www.rand.org/pubs/permissions.

RAND is a nonprofit institution that helps improve policy and decisionmaking through research and analysis. RAND's publications do not necessarily reflect the opinions of its research clients and sponsors.