Skip to content
Cloud WaypointCloud modernization & authorization preparation

Detailed reference · fictional tabletop

Follow the event through the handoffs.

The named operators perform the actions. Blue identifies where Foundations and ADM contributed preparation; gray belongs to another operator; amber marks an open handoff.

← Return to the lifecycle guide

Working research model; operational use requires source and program validation. DTM-24-001 Table 1 allocations remain held pending a verified visual reading. Hypotheses shown here are not adopted policy or operational instructions.

Scenario and source boundaries

Working research model of coherent visibility: the security and operational event data flows of a DoD IL5/IL6 cloud General Support System in DISA SCCA shape, landed on AWS, with technical and operational boundaries, ownership, and one worked incident walkthrough. Published as a research download; not a client deliverable and not an operating document. No CUI, no client names. The incidents are fictional.

status
Working research model; operational use requires source and program validation.
source note
Source access notes record the author’s research, not independent publication verification. Archive readings, secondary reports and reconstructed tables remain provisional.
dtm hold
DTM-24-001 Table 1 allocations remain held pending a verified visual reading. Hypotheses shown here are not adopted policy or operational instructions.
  • Advisory only. Nothing here is an authorization, an inherited control, a requirement, or a statement that any product is selected.
  • Every party except WWT and the JWCC-ordered AWS landing zone is an interchangeable slot; representatives are examples drawn from public sources, never selections.
  • Raw events stay in the enclave; curated events and query answers leave it (event-federation rule, GSS decision 5).
  • Nothing crosses high to low. IL6 event data never returns to an IL5 or lower surface.
  • Four party columns, three parties in policy: Policy recognizes three parties; the landing-zone operator is shown separately because it is where accountability and execution separate in practice — it acts inside the mission owner's accountability. INFERENCE — no public source establishes a fourth party. DoD policy names the CSP, the mission owner and the CSSP; where a commercial or component entity performs cybersecurity activities, the cognizant mission owner retains responsibility for that performance and the authorizing official remains accountable.

IL5 · Fictional scenario

Suspicious credential use and anomalous egress in a mission workload account

Fictional. In Program HARBORLIGHT's production workload account on AWS GovCloud (US), instance-role credentials from an application EC2 instance are used from an address outside the enclave, and the instance starts a large outbound transfer that the inspection VPC alerts on. Nobody's data is real; the flow is what matters.

  1. T+00:00 · Operator responsibility

    AWS GuardDuty in the workload account

    Raises a credential-exfiltration finding for instance-role credentials used from an address outside the account's expected space.

    Preparation: CSP-native detection the landing zone switched on; not an engagement artifact.

    Event, handoff, documents and source basis
    event
    GuardDuty finding, high severity
    from
    n-workload
    to
    n-audit
    channel
    kind
    technical
    detail
    Service-native detection; delegated administrator in the Audit account
    boundary crossed
    technical
    boundary ids
    • b-account
    sla
    value
    near real time
    grade
    INFERENCE
    deliverables
      exampleParty
      name
      Amazon GuardDuty (AWS GovCloud)
      slot
      slot-csp
      note
      representative — interchangeable
      cites
      • S72
      • S82
      cites
      • S62#security-config
      • S72
      grade
      cited; the specific finding type's GovCloud availability is INFERENCE — the GovCloud page lists CredentialAccess:IAMUser/CompromisedCredentials and eight EKS types as unavailable, not the instance-credential types
    • T+00:01 · Foundations & ADM contribution

      Inspection VPC — AWS Network Firewall

      Alerts on the outbound session at the east-west/north-south inspection point and writes alert and flow records.

      Preparation: The engagement recorded where the boundary sits and what the monitoring profile obliges the GSS to provide; the operator built it.

      Event, handoff, documents and source basis
      event
      Network Firewall ALERT and FLOW log records
      from
      n-network-inspect
      to
      n-logarchive
      channel
      kind
      technical
      detail
      CloudWatch Logs → subscription filter → Kinesis → Firehose → S3 prefixes network-firewall/alert and /flow
      boundary crossed
      technical
      boundary ids
      • b-account
      sla
      value
      streaming
      grade
      INFERENCE
      deliverables
      • GSS exit receipt — decision 1 (boundary) and decision 6 (monitoring profile)
      exampleParty
      name
      AWS Network Firewall in the Network account (LZA Universal Configuration)
      slot
      slot-lz-builder
      note
      representative — interchangeable; an NGFW pair per availability zone is the common alternative
      cites
      • S62#network-config
      cites
      • S62#network-config logging
      • S80
      grade
      cited
    • T+00:05 · Foundations & ADM contribution

      Audit account — Security Hub CSPM

      Aggregates the findings and routes a high-severity alert to the subscribed operators.

      Preparation: Annex D fixes the severity taxonomy and the notification path so a high finding has a named destination.

      Event, handoff, documents and source basis
      event
      Aggregated finding + SNS SecurityHigh notification
      from
      n-audit
      to
      n-mo-ops
      channel
      kind
      technical
      detail
      SNS topic subscription
      boundary crossed
      operational
      boundary ids
      • b-lz-mission
      sla
      value
      no published SLA
      grade
      INFERENCE
      deliverables
      • CONOPS Annex D (ConMon and POA&M workflow) — the severity taxonomy and who is notified at each level
      exampleParty
      name
      AWS Security Hub CSPM, delegated administrator in the Audit account
      slot
      slot-lz-builder
      note
      representative — interchangeable
      cites
      • S62#security-config
      cites
      • S62#security-config alert topics
      • L05#05-R1
      grade
      cited
    • T+00:10 · Foundations & ADM contribution

      SIEM correlation tier

      Correlates CloudTrail API calls, VPC flow records, the firewall alert and the GuardDuty finding into a single case, with the asset identified.

      Preparation: Annex C is where the feed's specification lives; without it the SIEM's read path is an undocumented arrangement.

      Event, handoff, documents and source basis
      event
      Correlated SIEM alert (asset ID and alert correlation, ZT activity 7.2.4)
      from
      n-logarchive
      to
      n-siem
      channel
      kind
      technical
      detail
      Read-only role on the central log bucket; SIEM correlation rules
      boundary crossed
      technical
      boundary ids
      • b-account
      sla
      value
      no published SLA
      grade
      INFERENCE
      deliverables
      • CONOPS Annex C — the security-telemetry row for this feed (mode, source, receiver, endpoints, identity, delivery owner, behaviour when unavailable)
      exampleParty
      name
      Splunk Cloud Platform IL5
      slot
      slot-siem
      note
      representative — interchangeable; Amazon OpenSearch Service in the shared-services account is the native alternative the LZA Universal Configuration documents
      cites
      • S90
      • S62#07-04-Log-Analysis
      cites
      • S62#07-04-Log-Analysis
      • S24#7.2.4
      grade
      cited
    • T+00:15 · Foundations & ADM contribution

      Enclave monitoring watch floor (24/7/365)

      Receives the curated alert — not the raw logs — and opens a case.

      Preparation: The anti-tether rule and the feed's specification are engagement decisions; the DoD playbook independently prefers keeping logs in the cloud and sending analysis outward.

      Event, handoff, documents and source basis
      event
      Curated alert to the CSSP
      from
      n-siem
      to
      n-cssp-mcd
      channel
      kind
      technical
      detail
      Encrypted alert feed from the IDPS/SIEM tier to the CSSP
      boundary crossed
      technical
      boundary ids
      • b-enclave-egress
      sla
      value
      monitoring is 24/7/365 (DTM-24-001); no published alert-delivery SLA
      cites
      • S15#3.c.(3)(b)
      grade
      cited
      deliverables
      • GSS exit receipt — decision 5, the event-federation tier: curated events leave, raw logs stay
      • CONOPS Annex C telemetry row
      • CONOPS Annex F — retention reference for the feed
      exampleParty
      name
      US Army DEVCOM C5ISR Center CSSP
      slot
      slot-cssp
      note
      representative — interchangeable, never selected; ARCYBER holds first right of refusal for Army systems, and DISA's CSSP serves IL2–IL6 hosted applications
      cites
      • S36
      • S49
      cites
      • S03#V-259867
      • S32#Play 12
      • L05#d5
      grade
      cited
    • T+00:20 · Open handoff

      CSSP analyst

      Queries the central archive directly for the surrounding hour of CloudTrail and flow records, using the read-only role provisioned at onboarding.

      Preparation: Open until the CSSP is aligned and onboarded: the role, the scope and the agreement are the receiving team's to accept.

      Event, handoff, documents and source basis
      event
      Analyst query and response
      from
      n-cssp-mcd
      to
      n-logarchive
      channel
      kind
      technical
      detail
      Cross-account read-only role into the LogArchive account
      boundary crossed
      technical
      boundary ids
      • b-account
      • b-enclave-egress
      sla
      value
      none published
      grade
      INFERENCE
      deliverables
      • GSS exit receipt — decision 9, the continuous-monitoring split (whose scope, whose evidence)
      • Package readiness — the designated CSSP named in the authority path
      exampleParty
      name
      US Army DEVCOM C5ISR Center CSSP
      slot
      slot-cssp
      note
      representative — interchangeable
      cites
      • S36
      cites
      • S08#2.1.2.12
      • S08#2.1.4.4
      • S05#3.3
      grade
      cited-secondary for the FRD requirement text
    • T+00:25 · Open handoff

      CSSP incident handler

      Categorizes the event — a user-level intrusion, high impact — and correlates the asset and vulnerability data with threat intelligence (a CSSP-only activity).

      Preparation: Only a certified CSSP can categorize and report; until one is aligned, this step has no owner.

      DTM-24-001 Table 1 allocations remain held pending a verified visual reading. Hypotheses shown here are not adopted policy or operational instructions.

      Event, handoff, documents and source basis
      event
      Category and impact assignment (CJCSM 6510.01B taxonomy)
      from
      n-cssp-mcd
      to
      n-cssp-mcd
      channel
      kind
      operational
      detail
      CSSP case management
      boundary crossed
      none
      boundary ids
        sla
        value
        a reported 72 hours to triage under the 2026 CSSP definition memo — secondary source only, primary text not found
        cites
        • S16
        grade
        cited-secondary
        deliverables
        • CONOPS Annex A (RACI) — one accountable role per activity
        exampleParty
        name
        US Army DEVCOM C5ISR Center CSSP
        slot
        slot-cssp
        note
        representative — interchangeable
        cites
        • S36
        cites
        • S15#Table 1
        • S17#Table B-A-2
        grade
        held-reconstruction
      • T+00:30 · Operator responsibility

        CSSP watch officer

        Notifies the next tier of a high-impact user-level intrusion.

        Preparation: Policy-fixed: DoD components report to JFHQ-DODIN, not to CISA.

        Event, handoff, documents and source basis
        event
        Initial notification to JFHQ-DODIN
        from
        n-cssp-mcd
        to
        n-jfhq
        channel
        kind
        operational
        detail
        Classified reporting channel; only the CSSP has access to the classified incident reporting system
        boundary crossed
        operational
        boundary ids
        • b-classified-reporting
        sla
        value
        within 15 minutes of discovery for a CAT 1 or CAT 2 high-impact incident
        cites
        • S17#Table C-A-1
        grade
        cited
        deliverables
          exampleParty
          name
          JFHQ-DODIN / USCYBERCOM
          slot
          slot-dodin
          note
          fixed by policy
          cites
          • S18#3.2
          cites
          • S15#3.d.(2)
          • S17#Table C-A-1
          • S18#3.2
          grade
          cited
        • T+00:35 · Foundations & ADM contribution

          CSSP analyst

          Notifies the mission owner's ISSM and duty operator, states the category, and directs containment.

          Preparation: The RACI, the ticket bridge and the recorded acceptance are what make this call land on a named person instead of an inbox.

          Event, handoff, documents and source basis
          event
          Incident notification and acknowledgement
          from
          n-cssp-mcd
          to
          n-mo-ops
          channel
          kind
          operational
          detail
          Ticket raised in the program's enterprise ticketing, plus a voice bridge; notification and acknowledgement procedures are a contract requirement
          boundary crossed
          operational
          boundary ids
          • b-cssp-agreement
          sla
          value
          acknowledgement procedures are required by contract; no public clock
          cites
          • S15#Attachment 2
          grade
          cited
          deliverables
          • CONOPS Annex A (RACI)
          • CONOPS Annex F — the ticket bridge standard carrying the reference
          • Decision register — the receiving team's acceptance of the handoff
          exampleParty
          name
          US Army DEVCOM C5ISR Center CSSP
          slot
          slot-cssp
          note
          representative — interchangeable
          cites
          • S36
          cites
          • S15#Attachment 2
          • L05#05-R3
          grade
          cited
        • T+00:45 · Foundations & ADM contribution

          Mission operators and ISSO

          Contains: revokes the role session and rotates the credential through the privileged-access tier, isolates the instance by security group, and preserves evidence — instance image, volume snapshot, memory where the runbook allows, and the relevant logs.

          Preparation: The rehearsal is where this sequence was walked before it was needed; the record keeps the outcome.

          Event, handoff, documents and source basis
          event
          Containment actions; evidence preserved
          from
          n-mo-ops
          to
          n-workload
          channel
          kind
          technical
          detail
          IAM Identity Center / IAM role revocation; EC2 and EBS snapshot APIs; all of it recorded in CloudTrail
          boundary crossed
          none
          boundary ids
            sla
            value
            no public clock; in IaaS the mission owner is responsible for capture, working with its MCD and the CSP
            cites
            • S01#6.2.4.1
            grade
            cited
            deliverables
            • CONOPS Annex G — the rehearsal standard: one finding end to end, detect → ticket → remediate → verify → close
            • CONOPS Annex A (RACI)
            exampleParty
            name
            Program HARBORLIGHT operations (fictional)
            slot
            slot-mission-owner
            note
            fictional mission owner
            cites
              cites
              • S01#6.2.4.1
              • L05#05-R7
              grade
              cited
            • T+01:00 · Operator responsibility

              CSP support and security operations

              Supports forensics under the contract: confirms platform-side facts and preserves what only the provider holds. If the offering itself were implicated, the CSP's own report starts here.

              Preparation: The provider runs this; the engagement only records the agreement and the owner.

              Event, handoff, documents and source basis
              event
              Forensic support; CSP incident report if the offering is implicated
              from
              n-csp-plane
              to
              n-dc3
              channel
              kind
              operational
              detail
              DIB Cyber Incident Collection Format on dibnet.dod.mil, naming the affected mission owners and their CSSPs; at IL6 instead by SIPRNet email or secure phone/fax
              boundary crossed
              operational
              boundary ids
              • b-csp-contract
              sla
              value
              initial report within one hour of the CSP's internal triage decision that the incident is reportable
              cites
              • S01#6.2.2
              grade
              cited
              deliverables
              • CONOPS Annex C — the interconnect/agreement row for the provider relationship
              • GSS exit receipt — decision 8, interconnection posture (agreement type and owner)
              exampleParty
              name
              AWS (GovCloud) under its DoD provisional authorization
              slot
              slot-csp
              note
              fixed for this model — the landing zone is ordered from AWS through JWCC
              cites
              • S83
              cites
              • S01#6.2.2
              • S01#6.2.3
              • S01#6.2.4
              grade
              cited
            • T+04:00 · Open handoff

              CSSP reporting cell

              Files the initial incident report to the next tier.

              Preparation: CSSP-only, and the alignment must exist before an incident does.

              Event, handoff, documents and source basis
              event
              Initial incident report
              from
              n-cssp-mcd
              to
              n-jfhq
              channel
              kind
              operational
              detail
              Classified reporting channel
              boundary crossed
              operational
              boundary ids
              • b-classified-reporting
              sla
              value
              within 4 hours for a CAT 1/2 high-impact incident
              cites
              • S17#Table C-A-1
              grade
              cited
              deliverables
                exampleParty
                name
                US Army DEVCOM C5ISR Center CSSP
                slot
                slot-cssp
                note
                representative — interchangeable
                cites
                • S36
                cites
                • S17#Table C-A-1
                • S01#6.2.3
                grade
                cited
              • T+06:00 · Open handoff

                CSSP reporting cell

                Enters the incident in JIMS on behalf of the mission owner.

                Preparation: Only a CSSP can write to the classified incident system.

                Event, handoff, documents and source basis
                event
                JIMS record created
                from
                n-cssp-mcd
                to
                n-jfhq
                channel
                kind
                technical
                detail
                Joint Incident Management System
                boundary crossed
                operational
                boundary ids
                • b-classified-reporting
                sla
                value
                first JIMS entry within 6 hours for a CAT 1/2 high-impact incident
                cites
                • S17#Table C-A-1
                grade
                cited
                deliverables
                • Package readiness — the designated CSSP and the authority path
                exampleParty
                name
                JIMS (DoD)
                slot
                slot-dodin
                note
                fixed by policy
                cites
                • S01#6.2.3
                cites
                • S01#6.2.3
                • S17#Table C-A-1
                grade
                cited
              • T+1 day · Operator responsibility

                JFHQ-DODIN

                Issues applicable direction — an order, a TASKORD or a CPCON change — which the CSSP passes to the mission owner and the provider; compliance is reported back.

                Preparation: Policy-fixed chain; the engagement only names who receives and acts.

                DTM-24-001 Table 1 allocations remain held pending a verified visual reading. Hypotheses shown here are not adopted policy or operational instructions.

                Event, handoff, documents and source basis
                event
                Order / CPCON notification and compliance report
                from
                n-jfhq
                to
                n-mo-ops
                channel
                kind
                operational
                detail
                Command channels through the BCD and MCD organizations
                boundary crossed
                operational
                boundary ids
                • b-classified-reporting
                • b-cssp-agreement
                sla
                value
                set by the order
                grade
                INFERENCE
                deliverables
                • CONOPS Annex A (RACI) — who acts on direction
                • CONOPS Annex D — the cadence that catches the compliance evidence
                exampleParty
                name
                JFHQ-DODIN / USCYBERCOM
                slot
                slot-dodin
                note
                fixed by policy
                cites
                • S01#6.3
                cites
                • S01#6.3
                • S15#Table 1
                grade
                held-reconstruction
              • T+2 days · Foundations & ADM contribution

                ISSM and system owner

                Establishes cause — an over-permissive instance role reachable from an application flaw — records the finding, and opens a plan-of-action item with an owner and milestones.

                Preparation: The POA&M shape, the severity clocks and the acceptance authority map are engagement decisions of record.

                Event, handoff, documents and source basis
                event
                POA&M item created; risk accepted or scheduled by level
                from
                n-mo-ops
                to
                n-ao-emass
                channel
                kind
                operational
                detail
                eMASS; the CSSP alignment is already documented there
                boundary crossed
                operational
                boundary ids
                • b-lz-mission
                sla
                value
                engagement default taxonomy: Critical 15 days, High 30, Moderate 90, Low 180; risk acceptance by level (Critical/High to the AO on ISSM recommendation). Confirmed or tailored per engagement.
                cites
                • L05#05-R1
                • L05#05-R5
                grade
                cited-internal
                deliverables
                • POA&M draft (Readiness package)
                • SSP draft — the control statement this finding touches
                • CONOPS Annex D — the POA&M workflow and the cadence
                exampleParty
                name
                Program HARBORLIGHT ISSM (fictional)
                slot
                slot-mission-owner
                note
                fictional
                cites
                  cites
                  • L05#05-R1
                  • S36
                  grade
                  cited-internal
                • T+3 days · Operator responsibility

                  Continuous-ATO partner

                  Folds the incident, its evidence and the POA&M item into the continuous-monitoring pack and the monthly read-out to the authorizing official.

                  Preparation: Another party runs the extended ATO work; the engagement drafted the workflow it runs inside.

                  Event, handoff, documents and source basis
                  event
                  ConMon evidence and POA&M report
                  from
                  n-cato
                  to
                  n-ao-emass
                  channel
                  kind
                  operational
                  detail
                  Evidence assembly and monthly read-out
                  boundary crossed
                  operational
                  boundary ids
                  • b-lz-mission
                  sla
                  value
                  monthly POA&M review, weekly ConMon review, quarterly effectiveness review — the engagement's recorded cadence
                  cites
                  • L05#05-R2
                  grade
                  cited-internal
                  deliverables
                  • CONOPS Annex D (ConMon and POA&M workflow)
                  • Transformation package — the day-two operating model
                  exampleParty
                  name
                  stackArmor ThreatAlert (a WWT partner solution)
                  slot
                  slot-cato-partner
                  note
                  representative — interchangeable, never selected; Second Front's Game Warden is a public alternative at IL5
                  cites
                  • S91
                  • S92
                  cites
                  • S91
                  • L05#05-R2
                  grade
                  cited
                • T+≤30 days · Foundations & ADM contribution

                  Engineering and ISSO

                  Remediates: the role is scoped down, the application flaw patched, a Config rule and a Security Hub control now watch for the pattern. The CSSP verifies and the incident record is closed — never as 'investigating'.

                  Preparation: Verification and closure criteria are recorded, not improvised.

                  Event, handoff, documents and source basis
                  event
                  Remediation verified; incident closed
                  from
                  n-mo-ops
                  to
                  n-cssp-mcd
                  channel
                  kind
                  operational
                  detail
                  Ticket closure with evidence; CSSP confirmation
                  boundary crossed
                  operational
                  boundary ids
                  • b-cssp-agreement
                  sla
                  value
                  High findings within 30 days on the engagement taxonomy; the published DoD clock of 30/90 days for High-Critical/Moderate applies to the provider's own findings
                  cites
                  • L05#05-R1
                  • S01#6.4
                  grade
                  cited
                  deliverables
                  • CONOPS Annex D
                  • CONOPS Annex G — the rehearsal proves the close-out path before it is needed
                  exampleParty
                  cites
                  • S01#6.4
                  • S17#Table B-A-2
                  grade
                  cited
                • T+90 days · Foundations & ADM contribution

                  ISSM

                  Holds the finding open through one full effectiveness cycle before closing it, and feeds the lesson back into the telemetry rows and the rehearsal set.

                  Preparation: The recurrence rule and the turnover note are engagement decisions of record.

                  Event, handoff, documents and source basis
                  event
                  Recurrence watch closed; record updated
                  from
                  n-mo-ops
                  to
                  n-wwt-record
                  channel
                  kind
                  operational
                  detail
                  Quarterly effectiveness and recurrence review
                  boundary crossed
                  none
                  boundary ids
                    sla
                    value
                    90 days after verification before a finding may close — the engagement's recorded rule
                    cites
                    • L05#05-R4
                    grade
                    cited-internal
                    deliverables
                    • CONOPS Annex D
                    • Final package — closeout turnover note, open items with owners
                    exampleParty
                    cites
                    • L05#05-R4
                    grade
                    cited-internal

                  IL6 · Fictional scenario

                  The same event at IL6 — what changes

                  Fictional. The same credential misuse in the program's SECRET-domain environment in the AWS Secret Region. Public sources describe the reporting channel and the connection model; almost nothing else about IL6 operations is public, so most steps below are INFERENCE and are marked.

                  1. T+00:00 · Operator responsibility

                    Native detection in the Secret Region

                    A finding is raised by the native security services authorized at IL6 — GuardDuty, Config and Security Hub are publicly listed there; Detective, Inspector and Security Lake are not.

                    Preparation: Provider capability; the engagement records what is and is not available.

                    Event, handoff, documents and source basis
                    event
                    Finding
                    from
                    n-il6-lz
                    to
                    n-il6-lz
                    channel
                    kind
                    technical
                    detail
                    Service-native; Security Hub in the Secret Region aggregates GuardDuty and Config alerts
                    boundary crossed
                    none
                    boundary ids
                      sla
                      value
                      none published
                      grade
                      INFERENCE
                      deliverables
                      • The IL6 record's GSS exit receipt — decision 6, monitoring profile
                      exampleParty
                      name
                      AWS Secret Region
                      slot
                      slot-csp
                      note
                      fixed for this model
                      cites
                      • S84
                      • S85
                      • S82
                      cites
                      • S82
                      • S85
                      grade
                      cited
                    • T+00:10 · Foundations & ADM contribution

                      IL6 landing zone

                      Aggregates to an IL6 log archive and an in-domain SIEM. No public AWS configuration exists for the Secret partition, so the account shape is assumed from the IL5 pattern.

                      Preparation: The two-domain instruments exist precisely to record what differs at IL6 rather than assume parity.

                      Event, handoff, documents and source basis
                      event
                      Central log aggregation
                      from
                      n-il6-lz
                      to
                      n-il6-lz
                      channel
                      kind
                      technical
                      detail
                      Assumed: the same subscription-filter → stream → archive chain, entirely within the SECRET domain
                      boundary crossed
                      technical
                      boundary ids
                      • b-account
                      sla
                      value
                      unknown
                      grade
                      INFERENCE
                      deliverables
                      • The IL6 record's Annex C telemetry rows
                      • H-1 — what changes at IL6, read in the room
                      exampleParty
                      cites
                      • S60#partitions
                      • S61#aws-iso changelog
                      grade
                      INFERENCE
                    • T+00:30 · Open handoff

                      IL6-capable CSSP (special enclave)

                      Receives the curated alert inside the SECRET domain and opens a case.

                      Preparation: No public source names the CSSP for any specific IL6 cloud landing zone; the slot stays open until a certified special-enclave CSSP is aligned.

                      Event, handoff, documents and source basis
                      event
                      Curated alert
                      from
                      n-il6-lz
                      to
                      n-il6-cssp
                      channel
                      kind
                      technical
                      detail
                      In-domain feed; SIPRNet channels
                      boundary crossed
                      technical
                      boundary ids
                      • b-enclave-egress
                      sla
                      value
                      unknown
                      grade
                      INFERENCE
                      deliverables
                      • The IL6 record's decision 9 split and Annex A RACI
                      exampleParty
                      name
                      DISA CSSP (publicly describes a cloud CSSP offering across IL2–IL6)
                      slot
                      slot-cssp
                      note
                      representative — interchangeable; the Army C5ISR Center CSSP publicly covers commercial cloud and Secret DREN (secondary source)
                      cites
                      • S49
                      • S36
                      cites
                      • S49
                      grade
                      INFERENCE
                    • T+00:45 · Operator responsibility

                      Provider security operations at IL6

                      If the offering is implicated, the provider reports to the organization performing mission cyber defense over SIPRNet email or secure phone/fax — not through DIBNet.

                      Preparation: Provider obligation under the SRG.

                      Event, handoff, documents and source basis
                      event
                      CSP incident notification at IL6
                      from
                      n-csp-plane
                      to
                      n-il6-cssp
                      channel
                      kind
                      operational
                      detail
                      SIPRNet email or secure phone/fax
                      boundary crossed
                      operational
                      boundary ids
                      • b-csp-contract
                      sla
                      value
                      within one hour of the provider's triage decision
                      cites
                      • S01#6.2.2
                      • S01#6.2.3
                      grade
                      cited
                      deliverables
                      • The IL6 record's Annex C agreement row
                      exampleParty
                      name
                      AWS Secret Region
                      slot
                      slot-csp
                      note
                      fixed for this model
                      cites
                      • S84
                      cites
                      • S01#6.2.3
                      grade
                      cited
                    • T+00:15 to T+06:00 · Open handoff

                      CSSP reporting cell

                      Notification, report and JIMS entry run on the same CJCSM clocks as at IL5.

                      Preparation: CSSP-only, and the IL6 CSSP is unnamed in public sources.

                      Event, handoff, documents and source basis
                      event
                      Notification / report / JIMS entry
                      from
                      n-il6-cssp
                      to
                      n-jfhq
                      channel
                      kind
                      operational
                      detail
                      Classified reporting channel
                      boundary crossed
                      operational
                      boundary ids
                      • b-classified-reporting
                      sla
                      value
                      15 minutes / 4 hours / 6 hours for a CAT 1/2 high-impact incident
                      cites
                      • S17#Table C-A-1
                      grade
                      cited
                      deliverables
                        exampleParty
                        cites
                        • S17#Table C-A-1
                        grade
                        cited
                      • T+1 day · Operator responsibility

                        DoD entity

                        Insider-threat user activity monitoring is correlated. At IL6 this must be performed by a DoD entity — a commercial party may not, unlike at IL2 and IL4/5.

                        Preparation: Policy allocates it to a DoD entity; the engagement records the allocation.

                        DTM-24-001 Table 1 allocations remain held pending a verified visual reading. Hypotheses shown here are not adopted policy or operational instructions.

                        Event, handoff, documents and source basis
                        event
                        UAM correlation
                        from
                        n-il6-lz
                        to
                        n-jfhq
                        channel
                        kind
                        operational
                        detail
                        DoD-operated capability
                        boundary crossed
                        operational
                        boundary ids
                        • b-classified-reporting
                        sla
                        value
                        none published
                        grade
                        INFERENCE
                        deliverables
                        • H-1 — the IL6 delta read in the room
                        • The IL6 record's Annex A RACI
                        exampleParty
                        cites
                        • S15#Table 1 (IL6 row: UAM is DoD-entity-only)
                        grade
                        held-reconstruction
                      • always · Foundations & ADM contribution

                        ISSM

                        Nothing from the incident — no log, finding, ticket, or report — moves down to the IL5 domain. Only low-to-high transfers happen, by a separately accredited service, and each is a row in the crossing register with its mechanism, accreditation, owner, window and behaviour when unavailable.

                        Preparation: The two-domain instruments and the high-to-low rail are engagement artifacts.

                        Event, handoff, documents and source basis
                        event
                        Domain rule enforced
                        from
                        n-il6-lz
                        to
                        n-logarchive
                        channel
                        kind
                        technical
                        detail
                        Forbidden path; the approved transfer runs low-to-high only
                        boundary crossed
                        technical
                        boundary ids
                        • b-domain
                        sla
                        value
                        n/a
                        grade
                        INFERENCE
                        deliverables
                        • H-3 — the crossing register
                        • H-4 — continues, degrades, stops
                        • The record refuses other-domain material by construction
                        exampleParty
                        name
                        AWS Diode (cloud cross-domain service, described publicly as controlling data flowing to classified regions; the whitepaper is marked historical)
                        slot
                        slot-mission-owner
                        note
                        representative — interchangeable; a cross-domain solution is separately accredited and out of the GSS scope
                        cites
                        • S88
                        cites
                        • S88
                        • L03#3.3, 3.8
                        grade
                        INFERENCE

                      Model context and source register

                      id
                      gss-event-flow-north-star
                      version
                      1.0.0
                      generated
                      2026-09-17
                      schema note
                      See BRIEF.md section 1 for the documented schema. Ids are stable: nodes n-*, edges e-*, boundaries b-*, slots slot-*, timeline t-*, steps s5-* (IL5) and s6-* (IL6), sources S##. Every factual field carries either cites[] (source ids, with a section pointer after #) or grade:"INFERENCE".
                      fixed parties
                      • id
                        slot-csp-vehicle
                        what
                        The AWS landing zone is ordered through a JWCC task order
                        why fixed
                        Owner direction for this model. JWCC is the DoD vehicle for commercial cloud at every classification level; the Army, for example, must use JWCC for new Secret (IL6) cloud requirements.
                        cites
                        • S42#AFARS 5111.106(S-91)
                        • S51#JWCC PM quote
                      • id
                        slot-wwt
                        what
                        WWT Cloud Waypoint — Foundations plus dependency mapping (ADM, Device42)
                        why fixed
                        Owner direction. WWT records decisions and hands over; it does not build or operate the stack.
                        cites
                        • L03#3.5 'WWT does not build or operate the stack under this SOW'
                      slots
                      • id
                        slot-csp
                        role
                        Cloud service provider (the CSO under a DoD provisional authorization)
                        fixed
                        true
                        fixed reason
                        Owner direction: the scenario starts from an AWS landing zone ordered through JWCC.
                        representative
                        Amazon Web Services — AWS GovCloud (US) at IL4/IL5; AWS Secret Region at IL6
                        alternatives
                        • Microsoft Azure Government / Azure Secret
                        • Google Cloud
                        • Oracle Cloud (OCI) — publishes its own SCCA landing zone
                        note
                        All four are JWCC awardees; the alternatives are named only to show the slot is swappable at the vehicle level.
                        sources
                        • S83
                        • S82
                        • S84
                        • S52
                        • S11
                      • id
                        slot-lz-builder
                        role
                        Cloud foundation / landing-zone provider (builds and operates the GSS below the mission line)
                        fixed
                        false
                        representative
                        A component enterprise cloud program running AWS Landing Zone Accelerator with the LZA Universal Configuration — for example the Army's Enterprise Cloud Management Activity (cARMY)
                        alternatives
                        • Air Force Cloud One
                        • DON Neptune Cloud Management Office
                        • DISA Stratus (SECRET IaaS/PaaS on SIPRNet)
                        • A contractor-operated landing zone under the mission owner's own ATO
                        note
                        representative — interchangeable. cARMY publicly states it provides common cloud shared services, global connectivity and required CSSP services for Army cloud workloads (indexed text only). Policy recognizes three parties; the landing-zone operator is shown separately because it is where accountability and execution separate in practice — it acts inside the mission owner's accountability.
                        sources
                        • S39
                        • S40
                        • S43
                        • S44
                        • S48
                        • S50
                        • S60
                        • S62
                        • S15
                        • S14
                        party split grade
                        INFERENCE — no public source establishes a fourth party. DoD policy names the CSP, the mission owner and the CSSP; where a commercial or component entity performs cybersecurity activities, the cognizant mission owner retains responsibility for that performance and the authorizing official remains accountable.
                      • id
                        slot-mission-owner
                        role
                        Mission owner (system owner, ISSM/ISSO, application operators; the AO is accountable)
                        fixed
                        false
                        representative
                        A fictional DoD program office, 'Program HARBORLIGHT', with its own ATO and an AO in its component chain
                        alternatives
                          note
                          Fictional by design. The mission owner is responsible and the authorizing official accountable for the cloud offering's cybersecurity activities.
                          sources
                          • S15#Attachment 2
                          • S13#Encl 4 2.c
                        • id
                          slot-cssp
                          role
                          Cybersecurity service provider — mission cyberspace defense (MCD) for this system
                          fixed
                          false
                          representative
                          US Army DEVCOM C5ISR Center CSSP (publicly described as executing CSSP services for Army-owned systems in commercial and private cloud environments and on Secret DREN)
                          alternatives
                          • US Army Cyber Command (ARCYBER) — holds first right of refusal for Army CSSP services
                          • DISA CSSP — publicly describes a cloud CSSP offering for IL2–IL6 hosted applications, 440+ customers
                          • Navy Cyber Defense Operations Command (NCDOC) — publicly named as the defender of Flank Speed
                          note
                          representative — interchangeable, and never selected. Only a USCYBERCOM-certified CSSP may perform the CSSP-only activities.
                          sources
                          • S36
                          • S38
                          • S49
                          • S47
                          • S15#Table 1
                          • S14#Appendix 4A
                        • id
                          slot-bcd
                          role
                          Boundary cyberspace defense and the cloud access point
                          fixed
                          by-policy
                          representative
                          DISA — operates the NIPRNet BCAP and provides BCD capabilities; SIPRNet ICAP at IL6
                          alternatives
                          • A DoD CIO-approved component CAP, where one exists (the Dec 2025 connection guide removed references to component BCAPs)
                          • An approved Cloud Native Access Point for internet-facing CUI applications (CNAP is not a BCAP)
                          note
                          Not commercially interchangeable: the BCAP is ultimately a DISA responsibility.
                          sources
                          • S01#5.9.1.1.1
                          • S01#Appendix C Table C-1
                          • S05#v3 revision log
                          • S01#5.9.1.4
                        • id
                          slot-dodin
                          role
                          DODIN-wide cyberspace defense and incident system of record
                          fixed
                          by-policy
                          representative
                          USCYBERCOM / JFHQ-DODIN, with reporting through the Joint Incident Management System (JIMS); DC3 receives contractor and commercial-CSP reports via DIBNet
                          alternatives
                            note
                            DoD components report to JFHQ-DODIN, not to US-CERT/CISA.
                            sources
                            • S18#3.2
                            • S01#6.2.3
                            • S17#Table C-A-1
                          • id
                            slot-siem
                            role
                            SIEM / security analytics and SOC tooling on the central logs
                            fixed
                            false
                            representative
                            Splunk Cloud Platform IL5 (its DoD P-ATO is predicated on all customer traffic traversing the DISA BCAP)
                            alternatives
                            • Amazon OpenSearch Service in the shared-services account (the LZA Universal Configuration documents granting a SIEM role read access to the central log bucket)
                            • Elastic
                            • Amazon Security Lake as the OCSF store with a downstream subscriber (IL5 only — Security Lake is not listed at IL6)
                            note
                            representative — interchangeable. LZA/UC grants SIEM access by appending a role statement to the central log bucket policy (example role names SplunkIngestionRole, OpenSearchAccessRole).
                            sources
                            • S90
                            • S62#07-04-Log-Analysis
                            • S82
                          • id
                            slot-endpoint-vuln
                            role
                            Endpoint security and vulnerability management inside the GSS (VDMS tier)
                            fixed
                            false
                            representative
                            DoD enterprise ACAS and Endpoint Security Solutions (ESS, the successor to HBSS), deployed in the shared-services account
                            alternatives
                            • Amazon Inspector plus AWS Systems Manager Patch Manager — native, and not evidence of ACAS or endpoint-defense equivalence without the applicable approval
                            • GuardDuty Runtime Monitoring for container and EC2 runtime signals
                            • A commercial EDR the AO accepts
                            note
                            representative — interchangeable. The SCCA FRD calls for ACAS or an approved equivalent (2.1.3.1) and HBSS or an approved equivalent (2.1.3.2). No public DISA page mandating a specific ESS vendor was reachable.
                            sources
                            • S08#2.1.3.1
                            • S08#2.1.3.2
                            • S30
                            • S31
                            • L01#A-2
                          • id
                            slot-cato-partner
                            role
                            Continuous-ATO / extended authorization partner (in-boundary GSS overlay, ConMon and POA&M reporting)
                            fixed
                            false
                            representative
                            stackArmor ThreatAlert (a WWT partner solution) — representative, never selected
                            alternatives
                            • Second Front Game Warden (DISA provisional authorization at IL5; applications inherit its validated controls)
                            • A component software factory such as Platform One
                            • The mission owner's own team, with no overlay
                            note
                            representative — interchangeable. Overlay classes are named by boundary ownership, never as vendors, in the record itself.
                            sources
                            • S91
                            • S92
                            • L03#3.5 overlay classes
                          • id
                            slot-wwt
                            role
                            Engagement that records the foundation and the dependencies (fixed)
                            fixed
                            true
                            representative
                            WWT — Cloud Waypoint Foundations plus dependency mapping (Device42)
                            alternatives
                              note
                              Runs in parallel with the JWCC award and the landing-zone build-out, not after it. Records decisions, drafts annexes, hands over; builds and operates nothing.
                              sources
                              • L03
                              • L04
                            timeline
                            • id
                              t-0
                              label
                              JWCC task order for the AWS landing zone
                              when
                              t0
                              duration
                              ≈45 business days from the mission partner's approach to DISA to award (DISA JWCC program manager, June 2026); packages are prepared in DAPPS and released to the JWCC providers
                              fixed
                              true
                              cites
                              • S51
                              • S53
                              grade
                              cited-secondary
                            • id
                              t-1
                              label
                              WWT Foundations + dependency mapping start, in parallel with the award
                              when
                              t0 (parallel)
                              duration
                              Twenty weeks on an engagement that carries dependency mapping: two advance weeks for the data call, then sixteen to eighteen build weeks — discovery baseline in week 13 (IL5) and 15 (IL6), the concept of operations signed the week after, waves and Device42 handover by week 17·19, both records closed at week 20. A Foundations-only engagement, with no dependency mapping, is eight billed weeks.
                              fixed
                              true
                              note
                              Dependency sampling runs at least 30 days across a month-end before the baseline; a shorter window stays provisional.
                              cites
                              • L03#2.4, 3.2, 3.6
                              grade
                              cited-internal
                            • id
                              t-2
                              label
                              Landing-zone build-out on AWS GovCloud (LZA + Universal Configuration)
                              when
                              t0 + weeks
                              duration
                              No public duration for a generic build. One component program publicly states tenants meeting all criteria can reach a development environment in about four weeks.
                              fixed
                              false
                              cites
                              • S39
                              grade
                              cited-secondary
                            • id
                              t-3
                              label
                              CSSP alignment and onboarding
                              when
                              before connection approval; overlaps t-2
                              duration
                              No public SLA. The connection package (SNAP/SGS) must include a CSSP agreement under DoDI 8530.01 and a signed consent to monitor; the mission owner collaborates with the CSSP during architecture development so the required security-relevant data is reachable.
                              fixed
                              false
                              cites
                              • S05#3.3
                              • S05#3.6.5
                              • S02#3.3
                              grade
                              cited
                            • id
                              t-4
                              label
                              Continuous-ATO partner overlay and evidence runway
                              when
                              after the GSS stands up, before the package
                              duration
                              Roughly a ninety-day operational-evidence runway is what authorization processes expect (practice knowledge, not a published DoD figure)
                              fixed
                              false
                              cites
                              • L05#GSS_TARGET 14
                              grade
                              INFERENCE
                            • id
                              t-5
                              label
                              Connection approval and provisional-authorization prerequisites
                              when
                              after ATO and PA exist
                              duration
                              The DISA cloud authorization process requires connection to a DoD-approved BCAP and to DoD-approved DNS and CSSP services; the SCCA PMO activates the BCAP connection only once the mission owner holds its connection approvals.
                              fixed
                              by-policy
                              cites
                              • S06
                              grade
                              cited
                            • id
                              t-6
                              label
                              First application migration
                              when
                              after t-5
                              duration
                              Wave order comes from the dependency baseline; no public duration.
                              fixed
                              false
                              cites
                              • L03#3.4
                              grade
                              INFERENCE
                            nodes
                            • id
                              n-mgmt
                              name
                              Management account
                              scca
                              governance (not an SCCA component)
                              zone
                              AWS Organizations management / Control Tower
                              owner
                              slot-lz-builder
                              il5
                              true
                              il6
                              INFERENCE
                              services
                              • AWS Organizations
                              • Control Tower (organization trail)
                              • Service control policies
                              cites
                              • S62#accounts-config
                              • S62#base config: organizationTrail true
                            • id
                              n-tccm
                              name
                              Credential and privileged-access tier (TCCM)
                              scca
                              TCCM
                              zone
                              IAM Identity Center + IAM roles, management/delegated account
                              owner
                              slot-lz-builder
                              il5
                              true
                              il6
                              unknown — IAM Identity Center is listed in scope at IL4/IL5 but not at IL6
                              services
                              • IAM Identity Center
                              • IAM roles and permission boundaries
                              • CloudTrail management events
                              cites
                              • S63#TCCM mapping to IAM and IAM Identity Center
                              • S82
                            • id
                              n-perimeter
                              name
                              Perimeter account (ingress/egress VPCs)
                              scca
                              VDSS / CAP-facing
                              zone
                              Perimeter
                              owner
                              slot-lz-builder
                              il5
                              true
                              il6
                              INFERENCE
                              services
                              • Ingress and egress VPCs
                              • ALB + WAF
                              • Internet gateway (IL2/CNAP patterns only at IL5 if approved)
                              cites
                              • S62#us-federal hub-and-spoke
                              • S63#VDSS = Perimeter and Network accounts
                            • id
                              n-network-inspect
                              name
                              Network account — Transit Gateway and inspection VPC
                              scca
                              VDSS
                              zone
                              Network
                              owner
                              slot-lz-builder
                              il5
                              true
                              il6
                              INFERENCE
                              services
                              • Transit Gateway (hub)
                              • AWS Network Firewall (north-south and east-west inspection)
                              • Route 53 Resolver + DNS Firewall
                              • Direct Connect gateway / VGW toward the DISN
                              cites
                              • S62#network-config
                              • S64
                              • S63
                            • id
                              n-shared-vdms
                              name
                              SharedServices account (VDMS)
                              scca
                              VDMS
                              zone
                              SharedServices
                              owner
                              slot-lz-builder
                              il5
                              true
                              il6
                              INFERENCE
                              services
                              • ACAS / ESS control servers (slot-endpoint-vuln)
                              • Directory, DNS, time, patch repositories
                              • Systems Manager patching
                              • Central monitoring components
                              cites
                              • S63#VDMS = SharedServices
                              • S08#2.1.3.x
                              • S62#third-party components in SharedServices
                            • id
                              n-audit
                              name
                              Audit account (security tooling, delegated administrator)
                              scca
                              VDMS / continuous-monitoring surface
                              zone
                              Audit (Security OU)
                              owner
                              slot-lz-builder
                              il5
                              true
                              il6
                              partial — Detective, Inspector and Security Lake are not listed at IL6
                              services
                              • GuardDuty (delegated admin, findings export every six hours)
                              • Security Hub CSPM (FSBP, NIST 800-53 r5, CIS v3.0.0; region aggregation)
                              • AWS Config
                              • IAM Access Analyzer
                              • SNS SecurityHigh/Medium/Low alert topics
                              cites
                              • S62#security-config
                              • S60#Audit account
                              • S82
                            • id
                              n-logarchive
                              name
                              LogArchive account — central log store
                              scca
                              the 'allocated archiving system' of FRD 2.1.2.12
                              zone
                              LogArchive (Security OU)
                              owner
                              slot-lz-builder
                              il5
                              true
                              il6
                              INFERENCE
                              services
                              • Kinesis Data Stream (subscription-filter target)
                              • Data Firehose
                              • S3 aws-accelerator-central-logs (KMS CMK)
                              • Control Tower organization trail bucket (365-day logging bucket retention)
                              retention
                              LZA/UC defaults: CloudWatch Logs 365 days in GovCloud; central S3 objects transition to Glacier IR at 365 days and expire at 1000 days; S3 Object Lock is not set by the default configuration (a Security Hub automation rule suppresses the S3.15 Object Lock finding)
                              cites
                              • S62#logging defaults
                              • S62#S3 lifecycle
                              • S62#S3-ObjectLock-Suppress
                              • S65#Object Lock recommended by the SRA
                              grade
                              cited
                            • id
                              n-siem
                              name
                              SIEM / SOC analysis tier
                              scca
                              MCD analytic tier
                              zone
                              SharedServices, or an IL5-authorized external service reached across the BCAP
                              owner
                              slot-siem
                              il5
                              true
                              il6
                              INFERENCE — must stay inside the SECRET domain
                              services
                              • Correlation and alerting on the central logs
                              • Read access granted by a bucket-policy statement for a named ingestion role
                              cites
                              • S62#07-04-Log-Analysis
                              • S90
                              • S04#V-259876 SIEM or syslog by both boundary and mission CND providers
                            • id
                              n-workload
                              name
                              Mission workload account(s)
                              scca
                              mission enclave (outside the GSS boundary, inside the LZ)
                              zone
                              Workloads OU (Dev/Test/Prod)
                              owner
                              slot-mission-owner
                              il5
                              true
                              il6
                              INFERENCE
                              services
                              • EC2/EKS/serverless
                              • VPC flow logs (ALL, 600s aggregation)
                              • CloudTrail data/management events
                              • Endpoint agents (ESS/EDR), ACAS scan targets
                              • Session Manager logs
                              cites
                              • S62#vpc flow logs
                              • S62#log-filters prefixes
                            • id
                              n-csp-plane
                              name
                              CSP control plane and CSP security operations
                              scca
                              CSP responsibility under the PA
                              zone
                              AWS-operated
                              owner
                              slot-csp
                              il5
                              true
                              il6
                              true
                              note
                              The CSP owns all logs and monitoring data created within the CSO relating to the mission owner's use, and shares what the contract specifies; it defends the CSO itself.
                              cites
                              • S01#5.2.3
                              • S01#6.1 CSP cyber defense activities
                            • id
                              n-bcap
                              name
                              DISA BCAP (NIPRNet) / ICAP (SIPRNet)
                              scca
                              BCAP
                              zone
                              DISN boundary, DISA-operated
                              owner
                              slot-bcd
                              il5
                              true
                              il6
                              ICAP instead of BCAP
                              services
                              • DISN perimeter defenses and cyber-defense sensing
                              • Full packet capture and flow metrics (FRD 2.1.1.11/2.1.1.12)
                              • PPSM enforcement interface
                              cites
                              • S01#5.9.1.1
                              • S01#5.9.1.4
                              • S08#2.1.1.x
                            • id
                              n-cssp-mcd
                              name
                              CSSP operations centre (MCD)
                              scca
                              MCD
                              zone
                              Outside the cloud boundary; the mission owner's aligned CSSP
                              owner
                              slot-cssp
                              il5
                              true
                              il6
                              true
                              services
                              • 24/7 monitoring of the mission environment
                              • Correlation of asset and vulnerability data with threat data (CSSP-only)
                              • Incident categorization, reporting and response for law enforcement/CI (CSSP-only)
                              • Malware notification, CPCON and orders notification (CSSP-only)
                              cites
                              • S15#Table 1
                              • S01#6.1 MCD
                              grade
                              held-reconstruction
                              publication note
                              DTM-24-001 Table 1 allocations remain held pending a verified visual reading. Hypotheses shown here are not adopted policy or operational instructions.
                            • id
                              n-cssp-bcd
                              name
                              BCD organization at the access point
                              scca
                              BCD
                              zone
                              DISN boundary
                              owner
                              slot-bcd
                              il5
                              true
                              il6
                              true
                              services
                              • Protect the DISN via the BCAP
                              • Provide timely indications and warnings to MCD organizations
                              • Cross-CSP analysis
                              cites
                              • S01#6.1 BCD
                              • S01#Appendix C Table C-1
                            • id
                              n-jfhq
                              name
                              JFHQ-DODIN / USCYBERCOM (JIMS)
                              scca
                              DCD
                              zone
                              DODIN-wide, classified reporting system
                              owner
                              slot-dodin
                              il5
                              true
                              il6
                              true
                              services
                              • JIMS incident records
                              • Orders, TASKORDs, CPCON direction
                              • Cross-BCAP correlation (DCD)
                              cites
                              • S01#6.1 DCD
                              • S01#6.2.3
                              • S01#6.3
                              • S18#3.2
                            • id
                              n-dc3
                              name
                              DC3 / DIBNet intake
                              scca
                              external reporting
                              zone
                              dibnet.dod.mil
                              owner
                              slot-dodin
                              il5
                              true
                              il6
                              false
                              note
                              At IL2–IL5 a commercial CSP whose offering is multitenant or shared outside the department reports through the DIB Cyber Incident Collection Format and names the affected mission owners and their CSSPs. At IL6 the CSP reports to the MCD organization over SIPRNet email or secure phone/fax instead.
                              cites
                              • S01#6.2.3
                            • id
                              n-mo-ops
                              name
                              Mission owner operations (ISSM/ISSO, admins, ticketing)
                              scca
                              mission owner
                              zone
                              Mission owner's own tooling
                              owner
                              slot-mission-owner
                              il5
                              true
                              il6
                              true
                              services
                              • Enterprise ticketing (the record prescribes no tool; the ticket bridge carries the reference)
                              • Containment and remediation actions
                              • Evidence capture in IaaS
                              cites
                              • L05#05-R3
                              • S01#6.2.4.1
                            • id
                              n-ao-emass
                              name
                              Authorizing official and the authorization record (eMASS)
                              scca
                              authorization
                              zone
                              Component eMASS instance
                              owner
                              slot-mission-owner
                              il5
                              true
                              il6
                              INFERENCE — a classified instance
                              services
                              • POA&M of record
                              • CSSP alignment documented in the package and in eMASS
                              • Risk acceptance by level
                              cites
                              • S36
                              • L05#05-R5
                            • id
                              n-cato
                              name
                              Continuous-ATO partner overlay
                              scca
                              overlay class (in-boundary GSS services)
                              zone
                              In-boundary, mission owner's accounts
                              owner
                              slot-cato-partner
                              il5
                              true
                              il6
                              INFERENCE
                              services
                              • ConMon evidence assembly and POA&M reporting
                              • In-boundary SIEM/IDS/HBSS-class services where the mission owner buys them
                              • Monthly AO read-out support
                              cites
                              • S91
                            • id
                              n-wwt-record
                              name
                              Cloud Waypoint record (Foundations)
                              scca
                              design-time, not an event path
                              zone
                              The engagement's record, sealed and handed over
                              owner
                              slot-wwt
                              il5
                              true
                              il6
                              true
                              services
                              • Nine GSS decisions, incl. d5 event federation and d9 continuous-monitoring split
                              • CONOPS annexes A, C, D, F, G
                              • SSP draft, POA&M draft, package readiness
                              • Crossing register and two-domain instruments on the IL6 record
                              cites
                              • L05#GSS_DECISIONS
                              • L06#annexes
                              • L03
                            • id
                              n-d42
                              name
                              Dependency-mapping appliance (Device42)
                              scca
                              design-time, not an event path
                              zone
                              Per-domain appliance, handed to the program's platform owners
                              owner
                              slot-wwt
                              il5
                              true
                              il6
                              true
                              services
                              • Observed east-west and north-south dependencies
                              • Crossings marked
                              • Data-quality counts at baseline and handover
                              cites
                              • L03#3.2, 3.6
                            • id
                              n-il6-lz
                              name
                              IL6 landing zone (AWS Secret Region)
                              scca
                              GSS at IL6
                              zone
                              AWS Secret Region, closed SIPRNet enclave
                              owner
                              slot-lz-builder
                              il5
                              false
                              il6
                              true
                              note
                              LZA claims support for the Secret and Top Secret partitions and the changelog carries aws-iso/aws-iso-b fixes, but no public sample configuration or account layout exists for those partitions. Everything below account-level shape is INFERENCE.
                              cites
                              • S60#partitions
                              • S61#changelog
                              grade
                              INFERENCE
                            • id
                              n-il6-icap
                              name
                              SIPRNet ICAP
                              scca
                              BCAP equivalent at IL6
                              zone
                              SIPRNet boundary
                              owner
                              slot-bcd
                              il5
                              false
                              il6
                              true
                              note
                              IL6 offerings are closed SIPRNet enclaves, assessed like any other SIPRNet enclave connection; ICAPs are required.
                              cites
                              • S01#5.9.1.4
                            • id
                              n-il6-cssp
                              name
                              CSSP at IL6 (special-enclave capable)
                              scca
                              MCD at IL6
                              zone
                              SIPRNet
                              owner
                              slot-cssp
                              il5
                              false
                              il6
                              true
                              note
                              No public source names the CSSP for any specific IL6 cloud landing zone. Publicly demonstrated IL6-capable CSSP work: DISA's cloud CSSP offering for IL2–IL6 hosted applications; the Army C5ISR Center CSSP covering commercial cloud and Secret DREN (secondary source).
                              cites
                              • S49
                              • S36
                              grade
                              INFERENCE
                            • id
                              n-cds
                              name
                              Approved cross-domain transfer
                              scca
                              out of scope of the GSS; a separately accredited service
                              zone
                              Between domains
                              owner
                              slot-mission-owner
                              il5
                              true
                              il6
                              true
                              note
                              AWS publicly describes a cloud-based cross-domain service (Diode) that controls data flowing to AWS classified regions; the whitepaper is marked historical and says nothing about moving security telemetry, and nothing about high-to-low. In this model no event data moves high to low, ever.
                              cites
                              • S88
                              grade
                              INFERENCE
                            boundaries
                            • id
                              b-account
                              type
                              technical
                              name
                              Account and organization boundary
                              what crosses
                              Log records and findings crossing from a workload or infrastructure account into LogArchive and Audit, by subscription filter to a Kinesis stream, by service-native export, or by delegated administration.
                              control
                              KMS CMKs per purpose; bucket policies; delegated-admin configuration; retain-policy keys.
                              cites
                              • S62#logging
                              • S60#KMS keys
                            • id
                              b-lz-mission
                              type
                              operational
                              name
                              Landing zone ↔ mission owner line
                              what crosses
                              The inherited GSS services and their evidence; the conditions on the landing zone's decision letter that flow down to tenants; the continuous-monitoring split.
                              control
                              The nine GSS decisions — boundary (d1), inheritance sourcing (d3), conditions absorption (d4), monitoring profile (d6), the split (d9).
                              cites
                              • L05#GSS_DECISIONS
                            • id
                              b-enclave-egress
                              type
                              technical
                              name
                              Enclave egress for telemetry
                              what crosses
                              Curated events, alerts and query answers leaving the enclave toward a SIEM or a CSSP. Raw logs stay in the cloud by preference: it is best to keep the logs in the cloud and send back analysis and query responses to external sources such as the CSSP, rather than exporting the logs themselves.
                              control
                              Event-federation tier (GSS decision 5, the anti-tether rule); encrypted path between the IDPS capability and the CSSP; Annex C telemetry rows.
                              cites
                              • S32#Play 12 log handling
                              • S03#V-259867
                              • L05#d5
                            • id
                              b-cap
                              type
                              technical
                              name
                              BCAP / ICAP — the DISN boundary
                              what crosses
                              All IL4/IL5 traffic to and from the mission environment, including the management plane for privileged user access and for cybersecurity tool connectivity to DISN-native monitoring systems. At IL6 the equivalent is the SIPRNet ICAP.
                              control
                              DISA-operated perimeter defenses and sensing; PPSM; connection approval.
                              cites
                              • S01#5.9.1.1.1
                              • S01#5.9.1.4
                            • id
                              b-cssp-agreement
                              type
                              operational
                              name
                              Mission owner ↔ CSSP
                              what crosses
                              Alignment, service scope, notification and acknowledgement procedures, log access, incident hand-off.
                              control
                              A CSSP agreement under DoDI 8530.01 in the connection package; the split documented in a support agreement, MOA, contract or component issuance; the consent to monitor.
                              cites
                              • S05#3.3
                              • S13#Encl 4 2.b
                              • S05#Appendix H
                            • id
                              b-classified-reporting
                              type
                              operational
                              name
                              The classified incident-reporting system
                              what crosses
                              Categorized incident reports into JIMS, and orders back out.
                              control
                              Only the CSSP can cross it: the CSSP must perform incident reporting because only CSSPs have access to the classified incident reporting system.
                              cites
                              • S15#3.d.(2)
                              • S01#6.2.3
                            • id
                              b-csp-contract
                              type
                              operational
                              name
                              Mission owner ↔ CSP
                              what crosses
                              Platform logs and monitoring data the CSP owns; forensic artifacts; incident notifications; continuous-monitoring artifacts DISA shares.
                              control
                              Contract/SLA language; the CSP must provide the data identified to meet CSSP defensive-cyber requirements and share it with all parties including the designated CSSP.
                              cites
                              • S01#5.2.3
                              • S15#Attachment 3 1.c
                              • S01#5.3.1
                            • id
                              b-domain
                              type
                              technical
                              name
                              IL5 ↔ IL6 domain boundary
                              what crosses
                              Low-to-high only, and only by an approved transfer: signatures, patches, threat intelligence. No event data, log, finding or incident record ever moves high to low.
                              control
                              The crossing register (H-3) records mechanism, accreditation, owner, window and behaviour when unavailable; the record refuses other-domain material.
                              cites
                              • L03#3.3, 3.8
                              • S88
                              grade
                              INFERENCE
                            responsibilities
                            • id
                              r-generate
                              function
                              Generate the events (platform, network, identity, endpoint)
                              csp
                              text
                              Emits CloudTrail, VPC flow logs, Network Firewall alert/flow logs, Resolver query logs, service findings; owns all logs and monitoring data created within the CSO relating to the mission owner's use.
                              cites
                              • S01#5.2.3
                              • S62
                              grade
                              cited
                              lz provider
                              text
                              Turns them on everywhere by configuration, sets retention, and forces new log groups into the same pattern.
                              cites
                              • S60#centralized logging
                              • S62
                              • S15#Attachment 2
                              • S14#3.1.e
                              grade
                              cited
                              accountability
                              Performed inside the mission owner's accountability: whatever the landing-zone operator performs, the mission owner remains responsible and its authorizing official accountable.
                              mission owner
                              text
                              Properly configures the cloud services it uses, including enabling encryption and logging; runs endpoint agents and the scanned baseline.
                              cites
                              • S33
                              • S02#3.3
                              grade
                              cited
                              cssp
                              text
                              States what security-relevant data it needs, and the mission owner collaborates with it during architecture development so the data will be accessible.
                              cites
                              • S02#3.3
                              grade
                              cited
                            • id
                              r-aggregate
                              function
                              Aggregate and retain (the allocated archiving system)
                              csp
                              text
                              Provides the storage services and, at offboarding, makes available all audit logs relevant to the mission owner's use for the period specified by AU-11.
                              cites
                              • S01#5.7
                              grade
                              cited
                              lz provider
                              text
                              Operates LogArchive: subscription filters to a Kinesis stream, Firehose, the central S3 bucket with a dedicated CMK; lifecycle and retention defaults.
                              cites
                              • S60
                              • S62
                              • S15#Attachment 2
                              • S14#3.1.e
                              grade
                              cited
                              accountability
                              Performed inside the mission owner's accountability: whatever the landing-zone operator performs, the mission owner remains responsible and its authorizing official accountable.
                              mission owner
                              text
                              Accepts the retention it inherits and records it; where the inherited retention is shorter than its own obligation, it is the mission owner's gap.
                              cites
                              • L06#Annex F
                              grade
                              INFERENCE
                              cssp
                              text
                              Needs access to the archive rather than a copy; the SCCA FRD calls for a common collection, storage and access point for event logs by privileged users performing boundary and mission cyber defense.
                              cites
                              • S08#2.1.2.12
                              • S08#2.1.3.7
                              • S08#2.1.4.4
                              grade
                              cited-secondary
                            • id
                              r-analyze
                              function
                              Analyze — SIEM correlation and alerting
                              csp
                              text
                              Provides native detection services (GuardDuty, Security Hub CSPM, Config, Inspector) with their GovCloud limits.
                              cites
                              • S82
                              • L01
                              grade
                              cited
                              lz provider
                              text
                              Runs the delegated-admin security tooling in Audit and, typically, the central monitoring components in SharedServices.
                              cites
                              • S62
                              • S15#Attachment 2
                              • S14#3.1.e
                              grade
                              cited
                              accountability
                              Performed inside the mission owner's accountability: whatever the landing-zone operator performs, the mission owner remains responsible and its authorizing official accountable.
                              mission owner
                              text
                              Serves as defensive cyberspace operations for its own mission systems and applications; may run its own SIEM tier.
                              cites
                              • S02#3.3
                              grade
                              cited
                              cssp
                              text
                              Correlating asset and vulnerability data with threat data is a CSSP-only activity at every impact level and service model. Boundary monitoring and intrusion detection is CSSP-only at IL4/5 and IL6. A SIEM or syslog capability must be implemented by both the boundary and the mission CND providers.
                              cites
                              • S15#Table 1
                              • S04#V-259876
                              grade
                              held-reconstruction
                              publication note
                              DTM-24-001 Table 1 allocations remain held pending a verified visual reading. Hypotheses shown here are not adopted policy or operational instructions.
                            • id
                              r-monitor-24x7
                              function
                              Watch it — 24/7 enclave monitoring
                              csp
                              text
                              Defends its own offering; at IL4–IL6 on dedicated DoD infrastructure its incidents go to USCYBERCOM/JFHQ-DODIN rather than to the CSSP directly.
                              cites
                              • S01#6.1
                              • S01#6.2.3
                              grade
                              cited
                              lz provider
                              text
                              Typically operates the platform NOC/SOC for the shared services it owns. Not allocated by public policy — this is a contract and agreement question.
                              cites
                              • S15#Attachment 2
                              • S14#3.1.e
                              grade
                              INFERENCE
                              accountability
                              Performed inside the mission owner's accountability: whatever the landing-zone operator performs, the mission owner remains responsible and its authorizing official accountable.
                              mission owner
                              text
                              Ensures the MCD service provider is identified and funded, and performs endpoint cyberspace defense.
                              cites
                              • S01#Appendix C Table C-1
                              grade
                              cited
                              cssp
                              text
                              Enclave-level monitoring may be performed by a DoD or a commercial entity, but whoever does it must monitor the mission owner's environment 24/7/365 and provide copies of audit and system logs as requested by the CSSP point of contact. Where the CSSP has the technical capability to use intelligence-derived signatures, the activity must be performed by a CSSP.
                              cites
                              • S15#3.c.(3)(b)
                              grade
                              cited
                            • id
                              r-vuln
                              function
                              Vulnerability and endpoint findings
                              csp
                              text
                              CSP vulnerability reports and POA&Ms go to DISA's cloud services support team and on to the MCD and BCD organizations; High and Critical findings in 30 days, Moderate in 90.
                              cites
                              • S01#6.4
                              grade
                              cited
                              lz provider
                              text
                              Provides ACAS or an approved equivalent and an endpoint security solution in the VDMS tier, with an encrypted path from agents to their control servers.
                              cites
                              • S08#2.1.3.1
                              • S08#2.1.3.2
                              • S02#3.3.2
                              • S15#Attachment 2
                              • S14#3.1.e
                              grade
                              cited
                              accountability
                              Performed inside the mission owner's accountability: whatever the landing-zone operator performs, the mission owner remains responsible and its authorizing official accountable.
                              mission owner
                              text
                              Patching and IAVM compliance are the mission owner's job (except where a SaaS CSP patches the operating system); flaw-remediation data must also be communicated to the CSSP.
                              cites
                              • S01#Section 6 intro
                              • S03#V-259865
                              grade
                              cited
                              cssp
                              text
                              Scans and endpoint monitoring may be DoD or commercial; correlating the results with threat data is CSSP-only. Endpoint alerts are reported to the AO or the CSSP.
                              cites
                              • S15#Table 1
                              • S15#3.b.(2)
                              grade
                              held-reconstruction
                              publication note
                              DTM-24-001 Table 1 allocations remain held pending a verified visual reading. Hypotheses shown here are not adopted policy or operational instructions.
                            • id
                              r-incident-report
                              function
                              Incident categorization and reporting
                              csp
                              text
                              Initial incident report within one hour of the CSP's internal triage decision that the incident is reportable; at IL2–IL5, for offerings shared outside the department, via DIBNet with the affected mission owners and their CSSPs named; at IL6 to the MCD organization by SIPRNet email or secure phone/fax.
                              cites
                              • S01#6.2.2
                              • S01#6.2.3
                              grade
                              cited
                              lz provider
                              text
                              No public allocation. In practice the landing-zone operator reports into the same CSSP as a subscriber for the services it owns.
                              cites
                              • S15#Attachment 2
                              • S14#3.1.e
                              grade
                              INFERENCE
                              accountability
                              Performed inside the mission owner's accountability: whatever the landing-zone operator performs, the mission owner remains responsible and its authorizing official accountable.
                              mission owner
                              text
                              Puts incident handling and reporting requirements into the contract or SLA, and reports through its CSSP; NSS incidents are reported to JFHQ-DODIN.
                              cites
                              • S02#3.3
                              • S02#3.3.2
                              grade
                              cited
                              cssp
                              text
                              Incident categorization and incident reporting are CSSP-only. DoD CSSPs report all incidents using JIMS, on the clocks in CJCSM 6510.01B — for a high-impact root- or user-level intrusion, notify the next tier within 15 minutes, report within 4 hours, first JIMS entry within 6 hours.
                              cites
                              • S15#Table 1
                              • S01#6.2.3
                              • S17#Table C-A-1
                              grade
                              held-reconstruction
                              publication note
                              DTM-24-001 Table 1 allocations remain held pending a verified visual reading. Hypotheses shown here are not adopted policy or operational instructions.
                            • id
                              r-forensics
                              function
                              Evidence capture and forensics
                              csp
                              text
                              Captures logs, memory, images and snapshots — except in IaaS, where the mission owner is responsible; provides automated capture with per-customer segregation, hashing and separate encryption, with keys held so only the government can read its own captured data.
                              cites
                              • S01#6.2.4.1
                              grade
                              cited
                              lz provider
                              text
                              Provides the snapshot, key and storage mechanisms the mission owner uses.
                              cites
                              • S15#Attachment 2
                              • S14#3.1.e
                              grade
                              INFERENCE
                              accountability
                              Performed inside the mission owner's accountability: whatever the landing-zone operator performs, the mission owner remains responsible and its authorizing official accountable.
                              mission owner
                              text
                              In IaaS, works with its MCD and the CSP to preserve VM images, memory, system logs, network logs and packet-capture data.
                              cites
                              • S01#6.2.4.1
                              grade
                              cited
                              cssp
                              text
                              Directs and receives the capture; incident response for law enforcement, counterintelligence and analysis is CSSP-only. Incident reports and data are retained 1 year, source and method information 5 years.
                              cites
                              • S15#Table 1
                              • S14#3.6.b.(2)
                              grade
                              held-reconstruction
                              publication note
                              DTM-24-001 Table 1 allocations remain held pending a verified visual reading. Hypotheses shown here are not adopted policy or operational instructions.
                            • id
                              r-orders
                              function
                              Orders, CPCON and directed action
                              csp
                              text
                              Receives applicable orders through the BCD/MCD organizations and reports compliance.
                              cites
                              • S01#6.3
                              grade
                              cited
                              lz provider
                              text
                              Implements configuration changes the orders require across the shared tier.
                              cites
                              • S15#Attachment 2
                              • S14#3.1.e
                              grade
                              INFERENCE
                              accountability
                              Performed inside the mission owner's accountability: whatever the landing-zone operator performs, the mission owner remains responsible and its authorizing official accountable.
                              mission owner
                              text
                              Implements and reports compliance; contracts must allow the movement and manoeuvring of DoD cyberspace defensive forces for incident response.
                              cites
                              • S01#6.3
                              • S14#4.1.d
                              grade
                              cited
                              cssp
                              text
                              CPCON and orders notification and assistance is CSSP-only; the MCD and BCD report compliance to JFHQ-DODIN and USCYBERCOM.
                              cites
                              • S15#Table 1
                              • S01#6.3
                              grade
                              held-reconstruction
                              publication note
                              DTM-24-001 Table 1 allocations remain held pending a verified visual reading. Hypotheses shown here are not adopted policy or operational instructions.
                            • id
                              r-remediate
                              function
                              Remediation, POA&M and closure
                              csp
                              text
                              Fixes its own findings on the 30/90-day clocks; a missed deadline can lead to a plan-of-action milestone escalation, then a DFR or corrective action plan.
                              cites
                              • S01#6.4
                              grade
                              cited
                              lz provider
                              text
                              Remediates the inherited layer and re-issues evidence; its residual conditions flow down to tenants.
                              cites
                              • L05#d4
                              • S15#Attachment 2
                              • S14#3.1.e
                              grade
                              INFERENCE
                              accountability
                              Performed inside the mission owner's accountability: whatever the landing-zone operator performs, the mission owner remains responsible and its authorizing official accountable.
                              mission owner
                              text
                              Owns the POA&M and the risk acceptance; the engagement's default taxonomy is Critical 15 days, High 30, Moderate 90, Low 180, with risk acceptance by level and a 90-day recurrence watch before closure — confirmed or tailored per engagement.
                              cites
                              • L05#05-R1
                              • L05#05-R4
                              • L05#05-R5
                              grade
                              cited-internal
                              cssp
                              text
                              Verifies and closes the incident record; no report is closed as 'investigating'.
                              cites
                              • S17#Table B-A-2
                              grade
                              cited
                            • id
                              r-conmon-artifacts
                              function
                              Continuous-monitoring artifacts and inheritance evidence
                              csp
                              text
                              Produces the CSO's continuous-monitoring artifacts under its provisional authorization.
                              cites
                              • S01#5.3.1
                              grade
                              cited
                              lz provider
                              text
                              Passes the inherited control evidence and the landing zone's conditions to tenants.
                              cites
                              • L05#d3
                              • L05#d4
                              • S15#Attachment 2
                              • S14#3.1.e
                              grade
                              INFERENCE
                              accountability
                              Performed inside the mission owner's accountability: whatever the landing-zone operator performs, the mission owner remains responsible and its authorizing official accountable.
                              mission owner
                              text
                              Consumes them into its own package; the record's continuous-monitoring split says who watches what.
                              cites
                              • L05#d9
                              grade
                              cited-internal
                              cssp
                              text
                              DISA shares continuous-monitoring information with mission owners, AOs and CSSPs; accredited CSSPs are required to perform information security continuous monitoring.
                              cites
                              • S01#5.3.1
                              • S05#3.6.5
                              grade
                              cited
                            edges
                            • id
                              e-01
                              from
                              n-workload
                              to
                              n-logarchive
                              event type
                              API audit (CloudTrail management and data events)
                              transport
                              Control Tower organization trail → S3 in LogArchive
                              direction
                              one-way
                              crosses boundary
                              true
                              boundary
                              b-account
                              boundary type
                              technical
                              owner
                              slot-lz-builder
                              il5
                              true
                              il6
                              INFERENCE
                              cites
                              • S62#organizationTrail true
                              • S67
                              note
                              In GovCloud, global service events land in us-gov-west-1, so single-Region trails elsewhere must become multi-Region.
                            • id
                              e-02
                              from
                              n-workload
                              to
                              n-logarchive
                              event type
                              VPC flow records (ALL, 600s aggregation, custom fields)
                              transport
                              CloudWatch Logs → subscription filter → Kinesis Data Stream (LogArchive) → Firehose → S3 prefix vpc-flow-logs
                              direction
                              one-way
                              crosses boundary
                              true
                              boundary
                              b-account
                              boundary type
                              technical
                              owner
                              slot-lz-builder
                              il5
                              true
                              il6
                              INFERENCE
                              cites
                              • S62#logging
                              • S62#log-filters
                              note
                              Flow logs are metadata, not packet contents.
                            • id
                              e-03
                              from
                              n-network-inspect
                              to
                              n-logarchive
                              event type
                              Network Firewall alert and flow logs (north-south and east-west)
                              transport
                              CloudWatch Logs → Kinesis → Firehose → S3 prefixes network-firewall/alert and /flow
                              direction
                              one-way
                              crosses boundary
                              true
                              boundary
                              b-account
                              boundary type
                              technical
                              owner
                              slot-lz-builder
                              il5
                              true
                              il6
                              INFERENCE
                              cites
                              • S62#network-config logging
                              • S80
                            • id
                              e-04
                              from
                              n-network-inspect
                              to
                              n-logarchive
                              event type
                              Route 53 Resolver DNS query logs
                              transport
                              CloudWatch Logs → central S3 prefix route53-resolver-query-logs; the configuration is shared by RAM and each VPC associates explicitly
                              direction
                              one-way
                              crosses boundary
                              true
                              boundary
                              b-account
                              boundary type
                              technical
                              owner
                              slot-lz-builder
                              il5
                              true
                              il6
                              INFERENCE
                              cites
                              • S62#network-config
                              • S81
                              note
                              The Resolver logs only unique queries, not those answered from cache. The GovCloud user guide is silent on Resolver query logging specifically.
                            • id
                              e-05
                              from
                              n-workload
                              to
                              n-audit
                              event type
                              Threat findings (GuardDuty)
                              transport
                              Service-native, delegated administrator in Audit
                              direction
                              one-way
                              crosses boundary
                              true
                              boundary
                              b-account
                              boundary type
                              technical
                              owner
                              slot-lz-builder
                              il5
                              true
                              il6
                              partial — GuardDuty is listed at IL6; Detective and Inspector are not
                              cites
                              • S62#security-config
                              • S82
                              • S72
                            • id
                              e-06
                              from
                              n-audit
                              to
                              n-logarchive
                              event type
                              Findings export (GuardDuty every six hours; Security Hub CSPM findings)
                              transport
                              S3 export / CloudWatch Logs → central bucket prefix security-hub
                              direction
                              one-way
                              crosses boundary
                              true
                              boundary
                              b-account
                              boundary type
                              technical
                              owner
                              slot-lz-builder
                              il5
                              true
                              il6
                              INFERENCE
                              cites
                              • S62#security-config
                              • S62#log-filters
                            • id
                              e-07
                              from
                              n-audit
                              to
                              n-mo-ops
                              event type
                              Severity-routed alert (SecurityHigh / Medium / Low)
                              transport
                              SNS topic subscription (email by default in the reference configuration)
                              direction
                              one-way
                              crosses boundary
                              true
                              boundary
                              b-lz-mission
                              boundary type
                              operational
                              owner
                              slot-lz-builder
                              il5
                              true
                              il6
                              INFERENCE
                              cites
                              • S62#security-config alert topics
                            • id
                              e-08
                              from
                              n-shared-vdms
                              to
                              n-workload
                              event type
                              Authenticated vulnerability scan (ACAS or approved equivalent)
                              transport
                              Scanner to target, inside the enclave
                              direction
                              one-way
                              crosses boundary
                              false
                              boundary
                              boundary type
                              none
                              owner
                              slot-endpoint-vuln
                              il5
                              true
                              il6
                              true
                              cites
                              • S08#2.1.3.1
                              • S03#V-259865
                              • S19#monthly scans
                            • id
                              e-09
                              from
                              n-shared-vdms
                              to
                              n-cssp-mcd
                              event type
                              Scan results and flaw-remediation data
                              transport
                              Encrypted path to the CSSP (the STIG check asks the assessor to verify it)
                              direction
                              one-way
                              crosses boundary
                              true
                              boundary
                              b-enclave-egress
                              boundary type
                              technical
                              owner
                              slot-mission-owner
                              il5
                              true
                              il6
                              true
                              cites
                              • S03#V-259865
                            • id
                              e-10
                              from
                              n-workload
                              to
                              n-shared-vdms
                              event type
                              Endpoint security events (ESS/EDR agents)
                              transport
                              Encrypted agent-to-control-server path
                              direction
                              one-way
                              crosses boundary
                              false
                              boundary
                              boundary type
                              none
                              owner
                              slot-endpoint-vuln
                              il5
                              true
                              il6
                              true
                              cites
                              • S02#3.3.2
                              • S08#2.1.3.2
                            • id
                              e-11
                              from
                              n-shared-vdms
                              to
                              n-cssp-mcd
                              event type
                              Endpoint alerts and endpoint IDS logs
                              transport
                              Feed or on-request copies
                              direction
                              one-way
                              crosses boundary
                              true
                              boundary
                              b-enclave-egress
                              boundary type
                              technical
                              owner
                              slot-mission-owner
                              il5
                              true
                              il6
                              true
                              cites
                              • S15#3.b.(2)
                            • id
                              e-12
                              from
                              n-logarchive
                              to
                              n-siem
                              event type
                              Bulk log read for correlation
                              transport
                              Read-only role granted by a statement appended to the central log bucket policy (example role names SplunkIngestionRole, OpenSearchAccessRole)
                              direction
                              one-way
                              crosses boundary
                              true
                              boundary
                              b-account
                              boundary type
                              technical
                              owner
                              slot-siem
                              il5
                              true
                              il6
                              INFERENCE
                              cites
                              • S62#07-04-Log-Analysis
                            • id
                              e-13
                              from
                              n-network-inspect
                              to
                              n-cssp-mcd
                              event type
                              IDPS and VDSS sensor feed
                              transport
                              Encrypted connection between the virtual IDPS capability and the CSSP
                              direction
                              one-way
                              crosses boundary
                              true
                              boundary
                              b-enclave-egress
                              boundary type
                              technical
                              owner
                              slot-mission-owner
                              il5
                              true
                              il6
                              true
                              cites
                              • S03#V-259867
                              • S02#3.3.2 'VDSS feeds must be provided to a DoW CSSP performing boundary defense'
                            • id
                              e-14
                              from
                              n-siem
                              to
                              n-cssp-mcd
                              event type
                              Curated alerts, correlation results, query answers
                              transport
                              Alert forwarding or federated query
                              direction
                              two-way
                              crosses boundary
                              true
                              boundary
                              b-enclave-egress
                              boundary type
                              technical
                              owner
                              slot-cssp
                              il5
                              true
                              il6
                              true
                              cites
                              • S32#Play 12
                              • L05#d5
                              note
                              The preferred pattern keeps the logs in the cloud and sends analysis and query responses outward — the same rule the record calls the event-federation tier.
                            • id
                              e-15
                              from
                              n-logarchive
                              to
                              n-cssp-mcd
                              event type
                              Direct archive access for cyber-defense analysts
                              transport
                              Read-only cross-account role into the archive
                              direction
                              one-way
                              crosses boundary
                              true
                              boundary
                              b-account
                              boundary type
                              technical
                              owner
                              slot-lz-builder
                              il5
                              true
                              il6
                              INFERENCE
                              cites
                              • S08#2.1.2.12
                              • S08#2.1.4.4
                              grade
                              cited-secondary
                            • id
                              e-16
                              from
                              n-tccm
                              to
                              n-logarchive
                              event type
                              Privileged-portal activity logs and alerts
                              transport
                              CloudTrail management events and Identity Center sign-in records into the archive
                              direction
                              one-way
                              crosses boundary
                              true
                              boundary
                              b-account
                              boundary type
                              technical
                              owner
                              slot-lz-builder
                              il5
                              true
                              il6
                              INFERENCE
                              cites
                              • S08#2.1.4.2
                              • S63#TCCM 2.1.4.2-2.1.4.4 covered by CloudTrail/CloudWatch/SNS
                            • id
                              e-17
                              from
                              n-bcap
                              to
                              n-cssp-bcd
                              event type
                              Boundary sensing, full packet capture, flow metrics
                              transport
                              DISA-operated sensor grid at the access point
                              direction
                              one-way
                              crosses boundary
                              true
                              boundary
                              b-cap
                              boundary type
                              technical
                              owner
                              slot-bcd
                              il5
                              true
                              il6
                              ICAP
                              cites
                              • S08#2.1.1.11
                              • S08#2.1.1.12
                              • S01#5.9.1.1
                            • id
                              e-18
                              from
                              n-cssp-bcd
                              to
                              n-cssp-mcd
                              event type
                              Indications and warnings
                              transport
                              CSSP-to-CSSP sharing, classified channels where needed
                              direction
                              one-way
                              crosses boundary
                              true
                              boundary
                              b-cssp-agreement
                              boundary type
                              operational
                              owner
                              slot-bcd
                              il5
                              true
                              il6
                              true
                              cites
                              • S01#6.1 BCD
                              • S15#BCP information sharing on classified networks
                            • id
                              e-19
                              from
                              n-csp-plane
                              to
                              n-dc3
                              event type
                              CSP incident report (offering shared outside the department, IL2–IL5)
                              transport
                              DIB Cyber Incident Collection Format on dibnet.dod.mil, medium-assurance certificate
                              direction
                              one-way
                              crosses boundary
                              true
                              boundary
                              b-csp-contract
                              boundary type
                              operational
                              owner
                              slot-csp
                              il5
                              true
                              il6
                              false
                              sla
                              within one hour of the CSP's internal triage decision
                              cites
                              • S01#6.2.2
                              • S01#6.2.3
                            • id
                              e-20
                              from
                              n-csp-plane
                              to
                              n-cssp-mcd
                              event type
                              CSP incident notification naming affected mission owners
                              transport
                              DIBNet report contents; at IL6, SIPRNet email or secure phone/fax
                              direction
                              one-way
                              crosses boundary
                              true
                              boundary
                              b-csp-contract
                              boundary type
                              operational
                              owner
                              slot-csp
                              il5
                              true
                              il6
                              true
                              cites
                              • S01#6.2.3
                              note
                              At IL4–IL6 where the CSP provides dedicated DoD infrastructure, its own infrastructure incidents go to USCYBERCOM/JFHQ-DODIN instead, which then coordinates.
                            • id
                              e-21
                              from
                              n-cssp-mcd
                              to
                              n-jfhq
                              event type
                              Categorized incident report
                              transport
                              JIMS (classified reporting system)
                              direction
                              two-way
                              crosses boundary
                              true
                              boundary
                              b-classified-reporting
                              boundary type
                              operational
                              owner
                              slot-cssp
                              il5
                              true
                              il6
                              true
                              sla
                              CJCSM 6510.01B clocks; CAT 1/2 high impact — notify 15 minutes, report 4 hours, JIMS entry 6 hours
                              cites
                              • S01#6.2.3
                              • S17#Table C-A-1
                              • S15#3.d.(2)
                            • id
                              e-22
                              from
                              n-jfhq
                              to
                              n-cssp-mcd
                              event type
                              Orders, TASKORDs, CPCON changes, warning intelligence
                              transport
                              Command channels; the CSSP passes applicable direction to mission owners and CSPs and reports compliance
                              direction
                              one-way
                              crosses boundary
                              true
                              boundary
                              b-classified-reporting
                              boundary type
                              operational
                              owner
                              slot-dodin
                              il5
                              true
                              il6
                              true
                              cites
                              • S01#6.3
                            • id
                              e-23
                              from
                              n-cssp-mcd
                              to
                              n-mo-ops
                              event type
                              Incident notification, malware notification, direction to contain
                              transport
                              Ticket and voice bridge; notification and acknowledgement procedures are a contract requirement
                              direction
                              two-way
                              crosses boundary
                              true
                              boundary
                              b-cssp-agreement
                              boundary type
                              operational
                              owner
                              slot-cssp
                              il5
                              true
                              il6
                              true
                              cites
                              • S15#Attachment 2
                              • S15#Table 1
                              grade
                              held-reconstruction
                              publication note
                              DTM-24-001 Table 1 allocations remain held pending a verified visual reading. Hypotheses shown here are not adopted policy or operational instructions.
                            • id
                              e-24
                              from
                              n-mo-ops
                              to
                              n-ao-emass
                              event type
                              POA&M item, risk acceptance, incident disclosure
                              transport
                              eMASS; CSSP alignment is documented in the package and in eMASS
                              direction
                              one-way
                              crosses boundary
                              true
                              boundary
                              b-lz-mission
                              boundary type
                              operational
                              owner
                              slot-mission-owner
                              il5
                              true
                              il6
                              INFERENCE
                              cites
                              • S36
                              • L05#05-R1
                            • id
                              e-25
                              from
                              n-cato
                              to
                              n-ao-emass
                              event type
                              Continuous-monitoring evidence pack and POA&M reporting
                              transport
                              Monthly read-out and evidence assembly
                              direction
                              one-way
                              crosses boundary
                              true
                              boundary
                              b-lz-mission
                              boundary type
                              operational
                              owner
                              slot-cato-partner
                              il5
                              true
                              il6
                              INFERENCE
                              cites
                              • S91
                            • id
                              e-26
                              from
                              n-csp-plane
                              to
                              n-mo-ops
                              event type
                              Continuous-monitoring artifacts for the authorized offering
                              transport
                              DISA shares them with mission owners, AOs and the CSSP
                              direction
                              one-way
                              crosses boundary
                              true
                              boundary
                              b-csp-contract
                              boundary type
                              operational
                              owner
                              slot-csp
                              il5
                              true
                              il6
                              true
                              cites
                              • S01#5.3.1
                            • id
                              e-27
                              from
                              n-d42
                              to
                              n-wwt-record
                              event type
                              Observed dependencies and crossings (design-time, not runtime telemetry)
                              transport
                              Export read into the record as cited claims a named person confirms
                              direction
                              one-way
                              crosses boundary
                              false
                              boundary
                              boundary type
                              none
                              owner
                              slot-wwt
                              il5
                              true
                              il6
                              true
                              cites
                              • L03#3.7
                            • id
                              e-28
                              from
                              n-wwt-record
                              to
                              n-mo-ops
                              event type
                              Handover: annexes, decisions, split, telemetry rows (design-time)
                              transport
                              Readiness, Transformation and Final packages
                              direction
                              one-way
                              crosses boundary
                              true
                              boundary
                              b-lz-mission
                              boundary type
                              operational
                              owner
                              slot-wwt
                              il5
                              true
                              il6
                              true
                              cites
                              • L03#3.6
                            • id
                              e-29
                              from
                              n-il6-lz
                              to
                              n-il6-cssp
                              event type
                              IL6 curated events and incident coordination
                              transport
                              Inside the SECRET domain only; SIPRNet channels
                              direction
                              two-way
                              crosses boundary
                              true
                              boundary
                              b-cssp-agreement
                              boundary type
                              operational
                              owner
                              slot-cssp
                              il5
                              false
                              il6
                              true
                              cites
                              • S01#6.2.3
                              • S01#5.9.1.4
                              grade
                              INFERENCE
                            • id
                              e-30
                              from
                              n-cds
                              to
                              n-il6-lz
                              event type
                              Low-to-high transfer only: signatures, patches, threat intelligence
                              transport
                              Separately accredited cross-domain service
                              direction
                              one-way
                              crosses boundary
                              true
                              boundary
                              b-domain
                              boundary type
                              technical
                              owner
                              slot-mission-owner
                              il5
                              true
                              il6
                              true
                              cites
                              • S88
                              grade
                              INFERENCE
                            • id
                              e-31
                              from
                              n-il6-lz
                              to
                              n-logarchive
                              event type
                              FORBIDDEN — no IL6 event data returns to an IL5 or lower surface
                              transport
                              none
                              direction
                              forbidden
                              crosses boundary
                              true
                              boundary
                              b-domain
                              boundary type
                              technical
                              owner
                              slot-mission-owner
                              il5
                              false
                              il6
                              true
                              cites
                              • L03#3.3, 3.8
                              grade
                              INFERENCE
                            checklist before first migration
                            • id
                              c-01
                              condition
                              Every log source in the reference set is on and lands in one archive account: organization CloudTrail, VPC flow logs, Network Firewall alert and flow logs, Resolver query logs, Transit Gateway flow logs, Security Hub and Session Manager.
                              observable
                              The central bucket has an object under each expected prefix in the last 24 hours.
                              cites
                              • S62#log-filters
                            • id
                              c-02
                              condition
                              New log groups are captured automatically, not by hand.
                              observable
                              A log group created today has the retention, the KMS key and the subscription filter within minutes.
                              cites
                              • S60#centralized logging
                            • id
                              c-03
                              condition
                              Retention is decided, written down and longer than the shortest obligation the system carries.
                              observable
                              The configured retention is recorded in Annex F against each feed; the default LZA/UC setting expires central log objects at 1000 days, and incident data must be kept a year, source and method five.
                              cites
                              • S62#S3 lifecycle
                              • S14#3.6.b.(2)
                            • id
                              c-04
                              condition
                              Archive integrity is deliberate, not assumed.
                              observable
                              Either S3 Object Lock is enabled on the central log bucket, or the decision not to is recorded with the compensating control — the reference configuration does not set it and suppresses the finding.
                              cites
                              • S62#S3-ObjectLock-Suppress
                              • S65
                            • id
                              c-05
                              condition
                              A named CSSP is aligned, and the alignment is in the authorization package and in eMASS.
                              observable
                              The connection package holds the CSSP agreement and the signed consent to monitor.
                              cites
                              • S05#3.3
                              • S36
                            • id
                              c-06
                              condition
                              The CSSP can reach what it needs — feed, query role, or both — and has proven it.
                              observable
                              A demonstrated receipt: the CSSP acknowledges a test event through the production path, recorded as a rehearsal outcome with an evidence item.
                              cites
                              • S02#3.3
                              • L04#Annex G receipt
                            • id
                              c-07
                              condition
                              The VDSS sensor feed reaches the boundary-defense provider over an encrypted path, and ACAS flaw-remediation data reaches the CSSP.
                              observable
                              The STIG checks for V-259867 and V-259865 pass with evidence.
                              cites
                              • S03#V-259867
                              • S03#V-259865
                            • id
                              c-08
                              condition
                              The event-federation rule is decided: what leaves the enclave is curated events and query answers, not raw logs.
                              observable
                              GSS decision 5 is decided, with the Annex C rows that implement it.
                              cites
                              • L05#d5
                              • S32#Play 12
                            • id
                              c-09
                              condition
                              The continuous-monitoring split is decided and signed: the landing-zone operator's scope, the enterprise program's, the CSSP's, and the mission owner's residual.
                              observable
                              GSS decision 9 is decided and prints on the exit receipt with its evidence.
                              cites
                              • L05#d9
                            • id
                              c-10
                              condition
                              Incident roles and clocks are agreed with the CSSP before an incident, including notification and acknowledgement procedures.
                              observable
                              Annex A has one accountable role per activity; Annex D carries the severity taxonomy and clocks; the contract carries the CSSP notification requirement.
                              cites
                              • S15#Attachment 2
                              • L05#05-R1
                            • id
                              c-11
                              condition
                              The provider's obligations are in the contract: the data the CSSP needs, forensic support, and the incident report within one hour of triage.
                              observable
                              The interconnect row names the agreement type and owner (decision 8); the contract language exists.
                              cites
                              • S15#Attachment 3 1.c
                              • S01#6.2.2
                            • id
                              c-12
                              condition
                              Evidence capture in IaaS is rehearsed, because the provider does not do it for you there.
                              observable
                              A rehearsal outcome covering image, snapshot and log preservation.
                              cites
                              • S01#6.2.4.1
                              • L05#05-R7
                            • id
                              c-13
                              condition
                              The GovCloud service gaps are known and compensated, not discovered later: no Macie, no CloudWatch cross-account observability, CloudTrail Lake limits, Security Hub integration limits, Inspector is not ACAS.
                              observable
                              Each gap is a named condition or finding with an owner.
                              cites
                              • S68
                              • S67
                              • S74
                              • L01#A-2
                            • id
                              c-14
                              condition
                              The POA&M and its clocks exist before the first application, not after the first finding.
                              observable
                              POA&M draft in the Readiness package; severity taxonomy confirmed or tailored in Annex D.
                              cites
                              • L05#05-R1
                            • id
                              c-15
                              condition
                              On a two-domain program, the IL6 deltas are read and recorded rather than assumed: reporting channel, CSSP, service availability, and the high-to-low rail.
                              observable
                              H-1 to H-4 delivered on the IL6 record, with the crossing register populated.
                              cites
                              • S01#6.2.3
                              • L03#3.5
                            gaps
                            • id
                              g-01
                              question
                              What audit-log retention does DoD actually require at IL5?
                              status
                              The SRG defers to the AU-11 parameter and publishes no number; Appendix D does not list AU-11. The value is expected in the DoD RMF Knowledge Service or CNSSI 1253 overlay, neither publicly reachable.
                              source needed
                              RMF Knowledge Service (CAC-gated) AU-11 parameter for the applicable overlay.
                            • id
                              g-02
                              question
                              Who is the CSSP for a specific IL6 cloud landing zone?
                              status
                              No public source names it for cARMY IL6, Cloud One Secret, Neptune IL6 or a JWCC classified task order. DISA publicly describes an IL2–IL6 cloud CSSP offering; the Army C5ISR Center CSSP is described (secondary) as covering commercial cloud and Secret DREN.
                              source needed
                              The USCYBERCOM list of certified CSSPs, or the component's CSSP alignment memo.
                              closing evidence
                              Closes on: the USCYBERCOM list of certified and authorized CSSPs (GENSER vs special enclave), or the component's own CSSP alignment memo naming the provider for its Secret cloud. Either would be requested through the program's ISSM rather than found publicly.
                            • id
                              g-03
                              question
                              What does an IL6 landing zone look like on AWS?
                              status
                              LZA claims Secret and Top Secret partition support and the changelog shows isolated-partition fixes, but there is no public sample configuration, account layout, or logging design for those partitions, and no public statement on how customers run security monitoring there.
                              source needed
                              An AWS Secret Region service catalog or an LZA isolated-partition reference configuration, both obtained through an account team.
                              closing evidence
                              Closes on: the AWS Secret Region service catalog, obtainable only through an AWS account executive, plus an LZA isolated-partition (aws-iso / aws-iso-b) reference configuration. Until one of those is in hand, every IL6 design statement below account level stays INFERENCE.
                            • id
                              g-04
                              question
                              The SCCA FRD's authoritative text.
                              status
                              The DISA original of FRD v2.9 is 404 at every DISA path and 403 at every mirror tried. Requirement text used here comes from vendor reproductions (Microsoft, AWS, Oracle) that agree with each other.
                              source needed
                              The DISA-issued FRD, current revision, through DoD channels.
                            • id
                              g-05
                              question
                              Is there a newer CSSP definition or certification memo, and what are its clocks?
                              status
                              A 2026 DoW CIO directive-type memo is reported by trade press (72 hours to triage, 24 hours to report to USCYBERCOM, alignment not waivable). The primary text was not found.
                              source needed
                              The memo itself from the DoD issuances site.
                            • id
                              g-06
                              question
                              How does DTM-24-001 Table 1 render its CSSP-only marker?
                              status
                              The marker is an unrendered glyph in text extraction; the allocation was reconstructed from the narrative, which agrees. Two independent readings matched.
                              source needed
                              A clean PDF rendering of Table 1.
                              closing evidence
                              Closes on: a clean rendering of DTM-24-001 Table 1 — the PDF opened in a viewer that draws the marker glyphs, or a component reproduction of the table in text. Two independent readings already agree with the narrative text; a rendered table would move the allocation from reconstructed to quoted. DTM 24-001 stays on hold in the CSP corpus either way; nothing in the corpus is changed by this note.
                            • id
                              g-07
                              question
                              Does the landing-zone operator report to the same CSSP as its tenants?
                              status
                              No public policy allocates enclave monitoring or incident reporting to a landing-zone operator as a distinct party; DoD policy knows CSP, mission owner and CSSP. In practice this is a contract and agreement question.
                              source needed
                              A component enterprise-cloud tenant agreement (cARMY or Cloud One tenant guide, both CAC-gated).
                            • id
                              g-08
                              question
                              Is Resolver query logging available in AWS GovCloud without limits?
                              status
                              The GovCloud user guide is silent on Resolver query logging; it states only that public-zone query logging must use a US-West log group. The reference configuration deploys Resolver query logging in GovCloud.
                              source needed
                              An AWS statement, or a test in a GovCloud account.
                            sources