Detailed reference · fictional tabletop
Follow the event through the handoffs.
The named operators perform the actions. Blue identifies where Foundations and ADM contributed preparation; gray belongs to another operator; amber marks an open handoff.
Working research model; operational use requires source and program validation. DTM-24-001 Table 1 allocations remain held pending a verified visual reading. Hypotheses shown here are not adopted policy or operational instructions.
Scenario and source boundaries
Working research model of coherent visibility: the security and operational event data flows of a DoD IL5/IL6 cloud General Support System in DISA SCCA shape, landed on AWS, with technical and operational boundaries, ownership, and one worked incident walkthrough. Published as a research download; not a client deliverable and not an operating document. No CUI, no client names. The incidents are fictional.
- status
- Working research model; operational use requires source and program validation.
- source note
- Source access notes record the author’s research, not independent publication verification. Archive readings, secondary reports and reconstructed tables remain provisional.
- dtm hold
- DTM-24-001 Table 1 allocations remain held pending a verified visual reading. Hypotheses shown here are not adopted policy or operational instructions.
- Advisory only. Nothing here is an authorization, an inherited control, a requirement, or a statement that any product is selected.
- Every party except WWT and the JWCC-ordered AWS landing zone is an interchangeable slot; representatives are examples drawn from public sources, never selections.
- Raw events stay in the enclave; curated events and query answers leave it (event-federation rule, GSS decision 5).
- Nothing crosses high to low. IL6 event data never returns to an IL5 or lower surface.
- Four party columns, three parties in policy: Policy recognizes three parties; the landing-zone operator is shown separately because it is where accountability and execution separate in practice — it acts inside the mission owner's accountability. INFERENCE — no public source establishes a fourth party. DoD policy names the CSP, the mission owner and the CSSP; where a commercial or component entity performs cybersecurity activities, the cognizant mission owner retains responsibility for that performance and the authorizing official remains accountable.
IL5 · Fictional scenario
Suspicious credential use and anomalous egress in a mission workload account
Fictional. In Program HARBORLIGHT's production workload account on AWS GovCloud (US), instance-role credentials from an application EC2 instance are used from an address outside the enclave, and the instance starts a large outbound transfer that the inspection VPC alerts on. Nobody's data is real; the flow is what matters.
T+00:00 · Operator responsibility
AWS GuardDuty in the workload account
Raises a credential-exfiltration finding for instance-role credentials used from an address outside the account's expected space.
Preparation: CSP-native detection the landing zone switched on; not an engagement artifact.
Event, handoff, documents and source basis
- event
- GuardDuty finding, high severity
- from
- n-workload
- to
- n-audit
- channel
- kind
- technical
- detail
- Service-native detection; delegated administrator in the Audit account
- boundary crossed
- technical
- boundary ids
- b-account
- sla
- value
- near real time
- grade
- INFERENCE
- deliverables
- exampleParty
- name
- Amazon GuardDuty (AWS GovCloud)
- slot
- slot-csp
- note
- representative — interchangeable
- cites
- S72
- S82
- cites
- S62#security-config
- S72
- grade
- cited; the specific finding type's GovCloud availability is INFERENCE — the GovCloud page lists CredentialAccess:IAMUser/CompromisedCredentials and eight EKS types as unavailable, not the instance-credential types
T+00:01 · Foundations & ADM contribution
Inspection VPC — AWS Network Firewall
Alerts on the outbound session at the east-west/north-south inspection point and writes alert and flow records.
Preparation: The engagement recorded where the boundary sits and what the monitoring profile obliges the GSS to provide; the operator built it.
Event, handoff, documents and source basis
- event
- Network Firewall ALERT and FLOW log records
- from
- n-network-inspect
- to
- n-logarchive
- channel
- kind
- technical
- detail
- CloudWatch Logs → subscription filter → Kinesis → Firehose → S3 prefixes network-firewall/alert and /flow
- boundary crossed
- technical
- boundary ids
- b-account
- sla
- value
- streaming
- grade
- INFERENCE
- deliverables
- GSS exit receipt — decision 1 (boundary) and decision 6 (monitoring profile)
- exampleParty
- name
- AWS Network Firewall in the Network account (LZA Universal Configuration)
- slot
- slot-lz-builder
- note
- representative — interchangeable; an NGFW pair per availability zone is the common alternative
- cites
- S62#network-config
- cites
- S62#network-config logging
- S80
- grade
- cited
T+00:05 · Foundations & ADM contribution
Audit account — Security Hub CSPM
Aggregates the findings and routes a high-severity alert to the subscribed operators.
Preparation: Annex D fixes the severity taxonomy and the notification path so a high finding has a named destination.
Event, handoff, documents and source basis
- event
- Aggregated finding + SNS SecurityHigh notification
- from
- n-audit
- to
- n-mo-ops
- channel
- kind
- technical
- detail
- SNS topic subscription
- boundary crossed
- operational
- boundary ids
- b-lz-mission
- sla
- value
- no published SLA
- grade
- INFERENCE
- deliverables
- CONOPS Annex D (ConMon and POA&M workflow) — the severity taxonomy and who is notified at each level
- exampleParty
- name
- AWS Security Hub CSPM, delegated administrator in the Audit account
- slot
- slot-lz-builder
- note
- representative — interchangeable
- cites
- S62#security-config
- cites
- S62#security-config alert topics
- L05#05-R1
- grade
- cited
T+00:10 · Foundations & ADM contribution
SIEM correlation tier
Correlates CloudTrail API calls, VPC flow records, the firewall alert and the GuardDuty finding into a single case, with the asset identified.
Preparation: Annex C is where the feed's specification lives; without it the SIEM's read path is an undocumented arrangement.
Event, handoff, documents and source basis
- event
- Correlated SIEM alert (asset ID and alert correlation, ZT activity 7.2.4)
- from
- n-logarchive
- to
- n-siem
- channel
- kind
- technical
- detail
- Read-only role on the central log bucket; SIEM correlation rules
- boundary crossed
- technical
- boundary ids
- b-account
- sla
- value
- no published SLA
- grade
- INFERENCE
- deliverables
- CONOPS Annex C — the security-telemetry row for this feed (mode, source, receiver, endpoints, identity, delivery owner, behaviour when unavailable)
- exampleParty
- name
- Splunk Cloud Platform IL5
- slot
- slot-siem
- note
- representative — interchangeable; Amazon OpenSearch Service in the shared-services account is the native alternative the LZA Universal Configuration documents
- cites
- S90
- S62#07-04-Log-Analysis
- cites
- S62#07-04-Log-Analysis
- S24#7.2.4
- grade
- cited
T+00:15 · Foundations & ADM contribution
Enclave monitoring watch floor (24/7/365)
Receives the curated alert — not the raw logs — and opens a case.
Preparation: The anti-tether rule and the feed's specification are engagement decisions; the DoD playbook independently prefers keeping logs in the cloud and sending analysis outward.
Event, handoff, documents and source basis
- event
- Curated alert to the CSSP
- from
- n-siem
- to
- n-cssp-mcd
- channel
- kind
- technical
- detail
- Encrypted alert feed from the IDPS/SIEM tier to the CSSP
- boundary crossed
- technical
- boundary ids
- b-enclave-egress
- sla
- value
- monitoring is 24/7/365 (DTM-24-001); no published alert-delivery SLA
- cites
- S15#3.c.(3)(b)
- grade
- cited
- deliverables
- GSS exit receipt — decision 5, the event-federation tier: curated events leave, raw logs stay
- CONOPS Annex C telemetry row
- CONOPS Annex F — retention reference for the feed
- exampleParty
- name
- US Army DEVCOM C5ISR Center CSSP
- slot
- slot-cssp
- note
- representative — interchangeable, never selected; ARCYBER holds first right of refusal for Army systems, and DISA's CSSP serves IL2–IL6 hosted applications
- cites
- S36
- S49
- cites
- S03#V-259867
- S32#Play 12
- L05#d5
- grade
- cited
T+00:20 · Open handoff
CSSP analyst
Queries the central archive directly for the surrounding hour of CloudTrail and flow records, using the read-only role provisioned at onboarding.
Preparation: Open until the CSSP is aligned and onboarded: the role, the scope and the agreement are the receiving team's to accept.
Event, handoff, documents and source basis
- event
- Analyst query and response
- from
- n-cssp-mcd
- to
- n-logarchive
- channel
- kind
- technical
- detail
- Cross-account read-only role into the LogArchive account
- boundary crossed
- technical
- boundary ids
- b-account
- b-enclave-egress
- sla
- value
- none published
- grade
- INFERENCE
- deliverables
- GSS exit receipt — decision 9, the continuous-monitoring split (whose scope, whose evidence)
- Package readiness — the designated CSSP named in the authority path
- exampleParty
- name
- US Army DEVCOM C5ISR Center CSSP
- slot
- slot-cssp
- note
- representative — interchangeable
- cites
- S36
- cites
- S08#2.1.2.12
- S08#2.1.4.4
- S05#3.3
- grade
- cited-secondary for the FRD requirement text
T+00:25 · Open handoff
CSSP incident handler
Categorizes the event — a user-level intrusion, high impact — and correlates the asset and vulnerability data with threat intelligence (a CSSP-only activity).
Preparation: Only a certified CSSP can categorize and report; until one is aligned, this step has no owner.
DTM-24-001 Table 1 allocations remain held pending a verified visual reading. Hypotheses shown here are not adopted policy or operational instructions.
Event, handoff, documents and source basis
- event
- Category and impact assignment (CJCSM 6510.01B taxonomy)
- from
- n-cssp-mcd
- to
- n-cssp-mcd
- channel
- kind
- operational
- detail
- CSSP case management
- boundary crossed
- none
- boundary ids
- sla
- value
- a reported 72 hours to triage under the 2026 CSSP definition memo — secondary source only, primary text not found
- cites
- S16
- grade
- cited-secondary
- deliverables
- CONOPS Annex A (RACI) — one accountable role per activity
- exampleParty
- name
- US Army DEVCOM C5ISR Center CSSP
- slot
- slot-cssp
- note
- representative — interchangeable
- cites
- S36
- cites
- S15#Table 1
- S17#Table B-A-2
- grade
- held-reconstruction
T+00:30 · Operator responsibility
CSSP watch officer
Notifies the next tier of a high-impact user-level intrusion.
Preparation: Policy-fixed: DoD components report to JFHQ-DODIN, not to CISA.
Event, handoff, documents and source basis
- event
- Initial notification to JFHQ-DODIN
- from
- n-cssp-mcd
- to
- n-jfhq
- channel
- kind
- operational
- detail
- Classified reporting channel; only the CSSP has access to the classified incident reporting system
- boundary crossed
- operational
- boundary ids
- b-classified-reporting
- sla
- value
- within 15 minutes of discovery for a CAT 1 or CAT 2 high-impact incident
- cites
- S17#Table C-A-1
- grade
- cited
- deliverables
- exampleParty
- name
- JFHQ-DODIN / USCYBERCOM
- slot
- slot-dodin
- note
- fixed by policy
- cites
- S18#3.2
- cites
- S15#3.d.(2)
- S17#Table C-A-1
- S18#3.2
- grade
- cited
T+00:35 · Foundations & ADM contribution
CSSP analyst
Notifies the mission owner's ISSM and duty operator, states the category, and directs containment.
Preparation: The RACI, the ticket bridge and the recorded acceptance are what make this call land on a named person instead of an inbox.
Event, handoff, documents and source basis
- event
- Incident notification and acknowledgement
- from
- n-cssp-mcd
- to
- n-mo-ops
- channel
- kind
- operational
- detail
- Ticket raised in the program's enterprise ticketing, plus a voice bridge; notification and acknowledgement procedures are a contract requirement
- boundary crossed
- operational
- boundary ids
- b-cssp-agreement
- sla
- value
- acknowledgement procedures are required by contract; no public clock
- cites
- S15#Attachment 2
- grade
- cited
- deliverables
- CONOPS Annex A (RACI)
- CONOPS Annex F — the ticket bridge standard carrying the reference
- Decision register — the receiving team's acceptance of the handoff
- exampleParty
- name
- US Army DEVCOM C5ISR Center CSSP
- slot
- slot-cssp
- note
- representative — interchangeable
- cites
- S36
- cites
- S15#Attachment 2
- L05#05-R3
- grade
- cited
T+00:45 · Foundations & ADM contribution
Mission operators and ISSO
Contains: revokes the role session and rotates the credential through the privileged-access tier, isolates the instance by security group, and preserves evidence — instance image, volume snapshot, memory where the runbook allows, and the relevant logs.
Preparation: The rehearsal is where this sequence was walked before it was needed; the record keeps the outcome.
Event, handoff, documents and source basis
- event
- Containment actions; evidence preserved
- from
- n-mo-ops
- to
- n-workload
- channel
- kind
- technical
- detail
- IAM Identity Center / IAM role revocation; EC2 and EBS snapshot APIs; all of it recorded in CloudTrail
- boundary crossed
- none
- boundary ids
- sla
- value
- no public clock; in IaaS the mission owner is responsible for capture, working with its MCD and the CSP
- cites
- S01#6.2.4.1
- grade
- cited
- deliverables
- CONOPS Annex G — the rehearsal standard: one finding end to end, detect → ticket → remediate → verify → close
- CONOPS Annex A (RACI)
- exampleParty
- name
- Program HARBORLIGHT operations (fictional)
- slot
- slot-mission-owner
- note
- fictional mission owner
- cites
- cites
- S01#6.2.4.1
- L05#05-R7
- grade
- cited
T+01:00 · Operator responsibility
CSP support and security operations
Supports forensics under the contract: confirms platform-side facts and preserves what only the provider holds. If the offering itself were implicated, the CSP's own report starts here.
Preparation: The provider runs this; the engagement only records the agreement and the owner.
Event, handoff, documents and source basis
- event
- Forensic support; CSP incident report if the offering is implicated
- from
- n-csp-plane
- to
- n-dc3
- channel
- kind
- operational
- detail
- DIB Cyber Incident Collection Format on dibnet.dod.mil, naming the affected mission owners and their CSSPs; at IL6 instead by SIPRNet email or secure phone/fax
- boundary crossed
- operational
- boundary ids
- b-csp-contract
- sla
- value
- initial report within one hour of the CSP's internal triage decision that the incident is reportable
- cites
- S01#6.2.2
- grade
- cited
- deliverables
- CONOPS Annex C — the interconnect/agreement row for the provider relationship
- GSS exit receipt — decision 8, interconnection posture (agreement type and owner)
- exampleParty
- name
- AWS (GovCloud) under its DoD provisional authorization
- slot
- slot-csp
- note
- fixed for this model — the landing zone is ordered from AWS through JWCC
- cites
- S83
- cites
- S01#6.2.2
- S01#6.2.3
- S01#6.2.4
- grade
- cited
T+04:00 · Open handoff
CSSP reporting cell
Files the initial incident report to the next tier.
Preparation: CSSP-only, and the alignment must exist before an incident does.
Event, handoff, documents and source basis
- event
- Initial incident report
- from
- n-cssp-mcd
- to
- n-jfhq
- channel
- kind
- operational
- detail
- Classified reporting channel
- boundary crossed
- operational
- boundary ids
- b-classified-reporting
- sla
- value
- within 4 hours for a CAT 1/2 high-impact incident
- cites
- S17#Table C-A-1
- grade
- cited
- deliverables
- exampleParty
- name
- US Army DEVCOM C5ISR Center CSSP
- slot
- slot-cssp
- note
- representative — interchangeable
- cites
- S36
- cites
- S17#Table C-A-1
- S01#6.2.3
- grade
- cited
T+06:00 · Open handoff
CSSP reporting cell
Enters the incident in JIMS on behalf of the mission owner.
Preparation: Only a CSSP can write to the classified incident system.
Event, handoff, documents and source basis
- event
- JIMS record created
- from
- n-cssp-mcd
- to
- n-jfhq
- channel
- kind
- technical
- detail
- Joint Incident Management System
- boundary crossed
- operational
- boundary ids
- b-classified-reporting
- sla
- value
- first JIMS entry within 6 hours for a CAT 1/2 high-impact incident
- cites
- S17#Table C-A-1
- grade
- cited
- deliverables
- Package readiness — the designated CSSP and the authority path
- exampleParty
- name
- JIMS (DoD)
- slot
- slot-dodin
- note
- fixed by policy
- cites
- S01#6.2.3
- cites
- S01#6.2.3
- S17#Table C-A-1
- grade
- cited
T+1 day · Operator responsibility
JFHQ-DODIN
Issues applicable direction — an order, a TASKORD or a CPCON change — which the CSSP passes to the mission owner and the provider; compliance is reported back.
Preparation: Policy-fixed chain; the engagement only names who receives and acts.
DTM-24-001 Table 1 allocations remain held pending a verified visual reading. Hypotheses shown here are not adopted policy or operational instructions.
Event, handoff, documents and source basis
- event
- Order / CPCON notification and compliance report
- from
- n-jfhq
- to
- n-mo-ops
- channel
- kind
- operational
- detail
- Command channels through the BCD and MCD organizations
- boundary crossed
- operational
- boundary ids
- b-classified-reporting
- b-cssp-agreement
- sla
- value
- set by the order
- grade
- INFERENCE
- deliverables
- CONOPS Annex A (RACI) — who acts on direction
- CONOPS Annex D — the cadence that catches the compliance evidence
- exampleParty
- name
- JFHQ-DODIN / USCYBERCOM
- slot
- slot-dodin
- note
- fixed by policy
- cites
- S01#6.3
- cites
- S01#6.3
- S15#Table 1
- grade
- held-reconstruction
T+2 days · Foundations & ADM contribution
ISSM and system owner
Establishes cause — an over-permissive instance role reachable from an application flaw — records the finding, and opens a plan-of-action item with an owner and milestones.
Preparation: The POA&M shape, the severity clocks and the acceptance authority map are engagement decisions of record.
Event, handoff, documents and source basis
- event
- POA&M item created; risk accepted or scheduled by level
- from
- n-mo-ops
- to
- n-ao-emass
- channel
- kind
- operational
- detail
- eMASS; the CSSP alignment is already documented there
- boundary crossed
- operational
- boundary ids
- b-lz-mission
- sla
- value
- engagement default taxonomy: Critical 15 days, High 30, Moderate 90, Low 180; risk acceptance by level (Critical/High to the AO on ISSM recommendation). Confirmed or tailored per engagement.
- cites
- L05#05-R1
- L05#05-R5
- grade
- cited-internal
- deliverables
- POA&M draft (Readiness package)
- SSP draft — the control statement this finding touches
- CONOPS Annex D — the POA&M workflow and the cadence
- exampleParty
- name
- Program HARBORLIGHT ISSM (fictional)
- slot
- slot-mission-owner
- note
- fictional
- cites
- cites
- L05#05-R1
- S36
- grade
- cited-internal
T+3 days · Operator responsibility
Continuous-ATO partner
Folds the incident, its evidence and the POA&M item into the continuous-monitoring pack and the monthly read-out to the authorizing official.
Preparation: Another party runs the extended ATO work; the engagement drafted the workflow it runs inside.
Event, handoff, documents and source basis
- event
- ConMon evidence and POA&M report
- from
- n-cato
- to
- n-ao-emass
- channel
- kind
- operational
- detail
- Evidence assembly and monthly read-out
- boundary crossed
- operational
- boundary ids
- b-lz-mission
- sla
- value
- monthly POA&M review, weekly ConMon review, quarterly effectiveness review — the engagement's recorded cadence
- cites
- L05#05-R2
- grade
- cited-internal
- deliverables
- CONOPS Annex D (ConMon and POA&M workflow)
- Transformation package — the day-two operating model
- exampleParty
- name
- stackArmor ThreatAlert (a WWT partner solution)
- slot
- slot-cato-partner
- note
- representative — interchangeable, never selected; Second Front's Game Warden is a public alternative at IL5
- cites
- S91
- S92
- cites
- S91
- L05#05-R2
- grade
- cited
T+≤30 days · Foundations & ADM contribution
Engineering and ISSO
Remediates: the role is scoped down, the application flaw patched, a Config rule and a Security Hub control now watch for the pattern. The CSSP verifies and the incident record is closed — never as 'investigating'.
Preparation: Verification and closure criteria are recorded, not improvised.
Event, handoff, documents and source basis
- event
- Remediation verified; incident closed
- from
- n-mo-ops
- to
- n-cssp-mcd
- channel
- kind
- operational
- detail
- Ticket closure with evidence; CSSP confirmation
- boundary crossed
- operational
- boundary ids
- b-cssp-agreement
- sla
- value
- High findings within 30 days on the engagement taxonomy; the published DoD clock of 30/90 days for High-Critical/Moderate applies to the provider's own findings
- cites
- L05#05-R1
- S01#6.4
- grade
- cited
- deliverables
- CONOPS Annex D
- CONOPS Annex G — the rehearsal proves the close-out path before it is needed
- exampleParty
- cites
- S01#6.4
- S17#Table B-A-2
- grade
- cited
T+90 days · Foundations & ADM contribution
ISSM
Holds the finding open through one full effectiveness cycle before closing it, and feeds the lesson back into the telemetry rows and the rehearsal set.
Preparation: The recurrence rule and the turnover note are engagement decisions of record.
Event, handoff, documents and source basis
- event
- Recurrence watch closed; record updated
- from
- n-mo-ops
- to
- n-wwt-record
- channel
- kind
- operational
- detail
- Quarterly effectiveness and recurrence review
- boundary crossed
- none
- boundary ids
- sla
- value
- 90 days after verification before a finding may close — the engagement's recorded rule
- cites
- L05#05-R4
- grade
- cited-internal
- deliverables
- CONOPS Annex D
- Final package — closeout turnover note, open items with owners
- exampleParty
- cites
- L05#05-R4
- grade
- cited-internal
IL6 · Fictional scenario
The same event at IL6 — what changes
Fictional. The same credential misuse in the program's SECRET-domain environment in the AWS Secret Region. Public sources describe the reporting channel and the connection model; almost nothing else about IL6 operations is public, so most steps below are INFERENCE and are marked.
T+00:00 · Operator responsibility
Native detection in the Secret Region
A finding is raised by the native security services authorized at IL6 — GuardDuty, Config and Security Hub are publicly listed there; Detective, Inspector and Security Lake are not.
Preparation: Provider capability; the engagement records what is and is not available.
Event, handoff, documents and source basis
- event
- Finding
- from
- n-il6-lz
- to
- n-il6-lz
- channel
- kind
- technical
- detail
- Service-native; Security Hub in the Secret Region aggregates GuardDuty and Config alerts
- boundary crossed
- none
- boundary ids
- sla
- value
- none published
- grade
- INFERENCE
- deliverables
- The IL6 record's GSS exit receipt — decision 6, monitoring profile
- exampleParty
- name
- AWS Secret Region
- slot
- slot-csp
- note
- fixed for this model
- cites
- S84
- S85
- S82
- cites
- S82
- S85
- grade
- cited
T+00:10 · Foundations & ADM contribution
IL6 landing zone
Aggregates to an IL6 log archive and an in-domain SIEM. No public AWS configuration exists for the Secret partition, so the account shape is assumed from the IL5 pattern.
Preparation: The two-domain instruments exist precisely to record what differs at IL6 rather than assume parity.
Event, handoff, documents and source basis
- event
- Central log aggregation
- from
- n-il6-lz
- to
- n-il6-lz
- channel
- kind
- technical
- detail
- Assumed: the same subscription-filter → stream → archive chain, entirely within the SECRET domain
- boundary crossed
- technical
- boundary ids
- b-account
- sla
- value
- unknown
- grade
- INFERENCE
- deliverables
- The IL6 record's Annex C telemetry rows
- H-1 — what changes at IL6, read in the room
- exampleParty
- cites
- S60#partitions
- S61#aws-iso changelog
- grade
- INFERENCE
T+00:30 · Open handoff
IL6-capable CSSP (special enclave)
Receives the curated alert inside the SECRET domain and opens a case.
Preparation: No public source names the CSSP for any specific IL6 cloud landing zone; the slot stays open until a certified special-enclave CSSP is aligned.
Event, handoff, documents and source basis
- event
- Curated alert
- from
- n-il6-lz
- to
- n-il6-cssp
- channel
- kind
- technical
- detail
- In-domain feed; SIPRNet channels
- boundary crossed
- technical
- boundary ids
- b-enclave-egress
- sla
- value
- unknown
- grade
- INFERENCE
- deliverables
- The IL6 record's decision 9 split and Annex A RACI
- exampleParty
- name
- DISA CSSP (publicly describes a cloud CSSP offering across IL2–IL6)
- slot
- slot-cssp
- note
- representative — interchangeable; the Army C5ISR Center CSSP publicly covers commercial cloud and Secret DREN (secondary source)
- cites
- S49
- S36
- cites
- S49
- grade
- INFERENCE
T+00:45 · Operator responsibility
Provider security operations at IL6
If the offering is implicated, the provider reports to the organization performing mission cyber defense over SIPRNet email or secure phone/fax — not through DIBNet.
Preparation: Provider obligation under the SRG.
Event, handoff, documents and source basis
- event
- CSP incident notification at IL6
- from
- n-csp-plane
- to
- n-il6-cssp
- channel
- kind
- operational
- detail
- SIPRNet email or secure phone/fax
- boundary crossed
- operational
- boundary ids
- b-csp-contract
- sla
- value
- within one hour of the provider's triage decision
- cites
- S01#6.2.2
- S01#6.2.3
- grade
- cited
- deliverables
- The IL6 record's Annex C agreement row
- exampleParty
- name
- AWS Secret Region
- slot
- slot-csp
- note
- fixed for this model
- cites
- S84
- cites
- S01#6.2.3
- grade
- cited
T+00:15 to T+06:00 · Open handoff
CSSP reporting cell
Notification, report and JIMS entry run on the same CJCSM clocks as at IL5.
Preparation: CSSP-only, and the IL6 CSSP is unnamed in public sources.
Event, handoff, documents and source basis
- event
- Notification / report / JIMS entry
- from
- n-il6-cssp
- to
- n-jfhq
- channel
- kind
- operational
- detail
- Classified reporting channel
- boundary crossed
- operational
- boundary ids
- b-classified-reporting
- sla
- value
- 15 minutes / 4 hours / 6 hours for a CAT 1/2 high-impact incident
- cites
- S17#Table C-A-1
- grade
- cited
- deliverables
- exampleParty
- cites
- S17#Table C-A-1
- grade
- cited
T+1 day · Operator responsibility
DoD entity
Insider-threat user activity monitoring is correlated. At IL6 this must be performed by a DoD entity — a commercial party may not, unlike at IL2 and IL4/5.
Preparation: Policy allocates it to a DoD entity; the engagement records the allocation.
DTM-24-001 Table 1 allocations remain held pending a verified visual reading. Hypotheses shown here are not adopted policy or operational instructions.
Event, handoff, documents and source basis
- event
- UAM correlation
- from
- n-il6-lz
- to
- n-jfhq
- channel
- kind
- operational
- detail
- DoD-operated capability
- boundary crossed
- operational
- boundary ids
- b-classified-reporting
- sla
- value
- none published
- grade
- INFERENCE
- deliverables
- H-1 — the IL6 delta read in the room
- The IL6 record's Annex A RACI
- exampleParty
- cites
- S15#Table 1 (IL6 row: UAM is DoD-entity-only)
- grade
- held-reconstruction
always · Foundations & ADM contribution
ISSM
Nothing from the incident — no log, finding, ticket, or report — moves down to the IL5 domain. Only low-to-high transfers happen, by a separately accredited service, and each is a row in the crossing register with its mechanism, accreditation, owner, window and behaviour when unavailable.
Preparation: The two-domain instruments and the high-to-low rail are engagement artifacts.
Event, handoff, documents and source basis
- event
- Domain rule enforced
- from
- n-il6-lz
- to
- n-logarchive
- channel
- kind
- technical
- detail
- Forbidden path; the approved transfer runs low-to-high only
- boundary crossed
- technical
- boundary ids
- b-domain
- sla
- value
- n/a
- grade
- INFERENCE
- deliverables
- H-3 — the crossing register
- H-4 — continues, degrades, stops
- The record refuses other-domain material by construction
- exampleParty
- name
- AWS Diode (cloud cross-domain service, described publicly as controlling data flowing to classified regions; the whitepaper is marked historical)
- slot
- slot-mission-owner
- note
- representative — interchangeable; a cross-domain solution is separately accredited and out of the GSS scope
- cites
- S88
- cites
- S88
- L03#3.3, 3.8
- grade
- INFERENCE
Model context and source register
id
version
generated
schema note
fixed parties
- id
- slot-csp-vehicle
- what
- The AWS landing zone is ordered through a JWCC task order
- why fixed
- Owner direction for this model. JWCC is the DoD vehicle for commercial cloud at every classification level; the Army, for example, must use JWCC for new Secret (IL6) cloud requirements.
- cites
- S42#AFARS 5111.106(S-91)
- S51#JWCC PM quote
- id
- slot-wwt
- what
- WWT Cloud Waypoint — Foundations plus dependency mapping (ADM, Device42)
- why fixed
- Owner direction. WWT records decisions and hands over; it does not build or operate the stack.
- cites
- L03#3.5 'WWT does not build or operate the stack under this SOW'
slots
- id
- slot-csp
- role
- Cloud service provider (the CSO under a DoD provisional authorization)
- fixed
- true
- fixed reason
- Owner direction: the scenario starts from an AWS landing zone ordered through JWCC.
- representative
- Amazon Web Services — AWS GovCloud (US) at IL4/IL5; AWS Secret Region at IL6
- alternatives
- Microsoft Azure Government / Azure Secret
- Google Cloud
- Oracle Cloud (OCI) — publishes its own SCCA landing zone
- note
- All four are JWCC awardees; the alternatives are named only to show the slot is swappable at the vehicle level.
- sources
- S83
- S82
- S84
- S52
- S11
- id
- slot-lz-builder
- role
- Cloud foundation / landing-zone provider (builds and operates the GSS below the mission line)
- fixed
- false
- representative
- A component enterprise cloud program running AWS Landing Zone Accelerator with the LZA Universal Configuration — for example the Army's Enterprise Cloud Management Activity (cARMY)
- alternatives
- Air Force Cloud One
- DON Neptune Cloud Management Office
- DISA Stratus (SECRET IaaS/PaaS on SIPRNet)
- A contractor-operated landing zone under the mission owner's own ATO
- note
- representative — interchangeable. cARMY publicly states it provides common cloud shared services, global connectivity and required CSSP services for Army cloud workloads (indexed text only). Policy recognizes three parties; the landing-zone operator is shown separately because it is where accountability and execution separate in practice — it acts inside the mission owner's accountability.
- sources
- S39
- S40
- S43
- S44
- S48
- S50
- S60
- S62
- S15
- S14
- party split grade
- INFERENCE — no public source establishes a fourth party. DoD policy names the CSP, the mission owner and the CSSP; where a commercial or component entity performs cybersecurity activities, the cognizant mission owner retains responsibility for that performance and the authorizing official remains accountable.
- id
- slot-mission-owner
- role
- Mission owner (system owner, ISSM/ISSO, application operators; the AO is accountable)
- fixed
- false
- representative
- A fictional DoD program office, 'Program HARBORLIGHT', with its own ATO and an AO in its component chain
- alternatives
- note
- Fictional by design. The mission owner is responsible and the authorizing official accountable for the cloud offering's cybersecurity activities.
- sources
- S15#Attachment 2
- S13#Encl 4 2.c
- id
- slot-cssp
- role
- Cybersecurity service provider — mission cyberspace defense (MCD) for this system
- fixed
- false
- representative
- US Army DEVCOM C5ISR Center CSSP (publicly described as executing CSSP services for Army-owned systems in commercial and private cloud environments and on Secret DREN)
- alternatives
- US Army Cyber Command (ARCYBER) — holds first right of refusal for Army CSSP services
- DISA CSSP — publicly describes a cloud CSSP offering for IL2–IL6 hosted applications, 440+ customers
- Navy Cyber Defense Operations Command (NCDOC) — publicly named as the defender of Flank Speed
- note
- representative — interchangeable, and never selected. Only a USCYBERCOM-certified CSSP may perform the CSSP-only activities.
- sources
- S36
- S38
- S49
- S47
- S15#Table 1
- S14#Appendix 4A
- id
- slot-bcd
- role
- Boundary cyberspace defense and the cloud access point
- fixed
- by-policy
- representative
- DISA — operates the NIPRNet BCAP and provides BCD capabilities; SIPRNet ICAP at IL6
- alternatives
- A DoD CIO-approved component CAP, where one exists (the Dec 2025 connection guide removed references to component BCAPs)
- An approved Cloud Native Access Point for internet-facing CUI applications (CNAP is not a BCAP)
- note
- Not commercially interchangeable: the BCAP is ultimately a DISA responsibility.
- sources
- S01#5.9.1.1.1
- S01#Appendix C Table C-1
- S05#v3 revision log
- S01#5.9.1.4
- id
- slot-dodin
- role
- DODIN-wide cyberspace defense and incident system of record
- fixed
- by-policy
- representative
- USCYBERCOM / JFHQ-DODIN, with reporting through the Joint Incident Management System (JIMS); DC3 receives contractor and commercial-CSP reports via DIBNet
- alternatives
- note
- DoD components report to JFHQ-DODIN, not to US-CERT/CISA.
- sources
- S18#3.2
- S01#6.2.3
- S17#Table C-A-1
- id
- slot-siem
- role
- SIEM / security analytics and SOC tooling on the central logs
- fixed
- false
- representative
- Splunk Cloud Platform IL5 (its DoD P-ATO is predicated on all customer traffic traversing the DISA BCAP)
- alternatives
- Amazon OpenSearch Service in the shared-services account (the LZA Universal Configuration documents granting a SIEM role read access to the central log bucket)
- Elastic
- Amazon Security Lake as the OCSF store with a downstream subscriber (IL5 only — Security Lake is not listed at IL6)
- note
- representative — interchangeable. LZA/UC grants SIEM access by appending a role statement to the central log bucket policy (example role names SplunkIngestionRole, OpenSearchAccessRole).
- sources
- S90
- S62#07-04-Log-Analysis
- S82
- id
- slot-endpoint-vuln
- role
- Endpoint security and vulnerability management inside the GSS (VDMS tier)
- fixed
- false
- representative
- DoD enterprise ACAS and Endpoint Security Solutions (ESS, the successor to HBSS), deployed in the shared-services account
- alternatives
- Amazon Inspector plus AWS Systems Manager Patch Manager — native, and not evidence of ACAS or endpoint-defense equivalence without the applicable approval
- GuardDuty Runtime Monitoring for container and EC2 runtime signals
- A commercial EDR the AO accepts
- note
- representative — interchangeable. The SCCA FRD calls for ACAS or an approved equivalent (2.1.3.1) and HBSS or an approved equivalent (2.1.3.2). No public DISA page mandating a specific ESS vendor was reachable.
- sources
- S08#2.1.3.1
- S08#2.1.3.2
- S30
- S31
- L01#A-2
- id
- slot-cato-partner
- role
- Continuous-ATO / extended authorization partner (in-boundary GSS overlay, ConMon and POA&M reporting)
- fixed
- false
- representative
- stackArmor ThreatAlert (a WWT partner solution) — representative, never selected
- alternatives
- Second Front Game Warden (DISA provisional authorization at IL5; applications inherit its validated controls)
- A component software factory such as Platform One
- The mission owner's own team, with no overlay
- note
- representative — interchangeable. Overlay classes are named by boundary ownership, never as vendors, in the record itself.
- sources
- S91
- S92
- L03#3.5 overlay classes
- id
- slot-wwt
- role
- Engagement that records the foundation and the dependencies (fixed)
- fixed
- true
- representative
- WWT — Cloud Waypoint Foundations plus dependency mapping (Device42)
- alternatives
- note
- Runs in parallel with the JWCC award and the landing-zone build-out, not after it. Records decisions, drafts annexes, hands over; builds and operates nothing.
- sources
- L03
- L04
timeline
- id
- t-0
- label
- JWCC task order for the AWS landing zone
- when
- t0
- duration
- ≈45 business days from the mission partner's approach to DISA to award (DISA JWCC program manager, June 2026); packages are prepared in DAPPS and released to the JWCC providers
- fixed
- true
- cites
- S51
- S53
- grade
- cited-secondary
- id
- t-1
- label
- WWT Foundations + dependency mapping start, in parallel with the award
- when
- t0 (parallel)
- duration
- Twenty weeks on an engagement that carries dependency mapping: two advance weeks for the data call, then sixteen to eighteen build weeks — discovery baseline in week 13 (IL5) and 15 (IL6), the concept of operations signed the week after, waves and Device42 handover by week 17·19, both records closed at week 20. A Foundations-only engagement, with no dependency mapping, is eight billed weeks.
- fixed
- true
- note
- Dependency sampling runs at least 30 days across a month-end before the baseline; a shorter window stays provisional.
- cites
- L03#2.4, 3.2, 3.6
- grade
- cited-internal
- id
- t-2
- label
- Landing-zone build-out on AWS GovCloud (LZA + Universal Configuration)
- when
- t0 + weeks
- duration
- No public duration for a generic build. One component program publicly states tenants meeting all criteria can reach a development environment in about four weeks.
- fixed
- false
- cites
- S39
- grade
- cited-secondary
- id
- t-3
- label
- CSSP alignment and onboarding
- when
- before connection approval; overlaps t-2
- duration
- No public SLA. The connection package (SNAP/SGS) must include a CSSP agreement under DoDI 8530.01 and a signed consent to monitor; the mission owner collaborates with the CSSP during architecture development so the required security-relevant data is reachable.
- fixed
- false
- cites
- S05#3.3
- S05#3.6.5
- S02#3.3
- grade
- cited
- id
- t-4
- label
- Continuous-ATO partner overlay and evidence runway
- when
- after the GSS stands up, before the package
- duration
- Roughly a ninety-day operational-evidence runway is what authorization processes expect (practice knowledge, not a published DoD figure)
- fixed
- false
- cites
- L05#GSS_TARGET 14
- grade
- INFERENCE
- id
- t-5
- label
- Connection approval and provisional-authorization prerequisites
- when
- after ATO and PA exist
- duration
- The DISA cloud authorization process requires connection to a DoD-approved BCAP and to DoD-approved DNS and CSSP services; the SCCA PMO activates the BCAP connection only once the mission owner holds its connection approvals.
- fixed
- by-policy
- cites
- S06
- grade
- cited
- id
- t-6
- label
- First application migration
- when
- after t-5
- duration
- Wave order comes from the dependency baseline; no public duration.
- fixed
- false
- cites
- L03#3.4
- grade
- INFERENCE
nodes
- id
- n-mgmt
- name
- Management account
- scca
- governance (not an SCCA component)
- zone
- AWS Organizations management / Control Tower
- owner
- slot-lz-builder
- il5
- true
- il6
- INFERENCE
- services
- AWS Organizations
- Control Tower (organization trail)
- Service control policies
- cites
- S62#accounts-config
- S62#base config: organizationTrail true
- id
- n-tccm
- name
- Credential and privileged-access tier (TCCM)
- scca
- TCCM
- zone
- IAM Identity Center + IAM roles, management/delegated account
- owner
- slot-lz-builder
- il5
- true
- il6
- unknown — IAM Identity Center is listed in scope at IL4/IL5 but not at IL6
- services
- IAM Identity Center
- IAM roles and permission boundaries
- CloudTrail management events
- cites
- S63#TCCM mapping to IAM and IAM Identity Center
- S82
- id
- n-perimeter
- name
- Perimeter account (ingress/egress VPCs)
- scca
- VDSS / CAP-facing
- zone
- Perimeter
- owner
- slot-lz-builder
- il5
- true
- il6
- INFERENCE
- services
- Ingress and egress VPCs
- ALB + WAF
- Internet gateway (IL2/CNAP patterns only at IL5 if approved)
- cites
- S62#us-federal hub-and-spoke
- S63#VDSS = Perimeter and Network accounts
- id
- n-network-inspect
- name
- Network account — Transit Gateway and inspection VPC
- scca
- VDSS
- zone
- Network
- owner
- slot-lz-builder
- il5
- true
- il6
- INFERENCE
- services
- Transit Gateway (hub)
- AWS Network Firewall (north-south and east-west inspection)
- Route 53 Resolver + DNS Firewall
- Direct Connect gateway / VGW toward the DISN
- cites
- S62#network-config
- S64
- S63
- id
- n-shared-vdms
- name
- SharedServices account (VDMS)
- scca
- VDMS
- zone
- SharedServices
- owner
- slot-lz-builder
- il5
- true
- il6
- INFERENCE
- services
- ACAS / ESS control servers (slot-endpoint-vuln)
- Directory, DNS, time, patch repositories
- Systems Manager patching
- Central monitoring components
- cites
- S63#VDMS = SharedServices
- S08#2.1.3.x
- S62#third-party components in SharedServices
- id
- n-audit
- name
- Audit account (security tooling, delegated administrator)
- scca
- VDMS / continuous-monitoring surface
- zone
- Audit (Security OU)
- owner
- slot-lz-builder
- il5
- true
- il6
- partial — Detective, Inspector and Security Lake are not listed at IL6
- services
- GuardDuty (delegated admin, findings export every six hours)
- Security Hub CSPM (FSBP, NIST 800-53 r5, CIS v3.0.0; region aggregation)
- AWS Config
- IAM Access Analyzer
- SNS SecurityHigh/Medium/Low alert topics
- cites
- S62#security-config
- S60#Audit account
- S82
- id
- n-logarchive
- name
- LogArchive account — central log store
- scca
- the 'allocated archiving system' of FRD 2.1.2.12
- zone
- LogArchive (Security OU)
- owner
- slot-lz-builder
- il5
- true
- il6
- INFERENCE
- services
- Kinesis Data Stream (subscription-filter target)
- Data Firehose
- S3 aws-accelerator-central-logs (KMS CMK)
- Control Tower organization trail bucket (365-day logging bucket retention)
- retention
- LZA/UC defaults: CloudWatch Logs 365 days in GovCloud; central S3 objects transition to Glacier IR at 365 days and expire at 1000 days; S3 Object Lock is not set by the default configuration (a Security Hub automation rule suppresses the S3.15 Object Lock finding)
- cites
- S62#logging defaults
- S62#S3 lifecycle
- S62#S3-ObjectLock-Suppress
- S65#Object Lock recommended by the SRA
- grade
- cited
- id
- n-siem
- name
- SIEM / SOC analysis tier
- scca
- MCD analytic tier
- zone
- SharedServices, or an IL5-authorized external service reached across the BCAP
- owner
- slot-siem
- il5
- true
- il6
- INFERENCE — must stay inside the SECRET domain
- services
- Correlation and alerting on the central logs
- Read access granted by a bucket-policy statement for a named ingestion role
- cites
- S62#07-04-Log-Analysis
- S90
- S04#V-259876 SIEM or syslog by both boundary and mission CND providers
- id
- n-workload
- name
- Mission workload account(s)
- scca
- mission enclave (outside the GSS boundary, inside the LZ)
- zone
- Workloads OU (Dev/Test/Prod)
- owner
- slot-mission-owner
- il5
- true
- il6
- INFERENCE
- services
- EC2/EKS/serverless
- VPC flow logs (ALL, 600s aggregation)
- CloudTrail data/management events
- Endpoint agents (ESS/EDR), ACAS scan targets
- Session Manager logs
- cites
- S62#vpc flow logs
- S62#log-filters prefixes
- id
- n-csp-plane
- name
- CSP control plane and CSP security operations
- scca
- CSP responsibility under the PA
- zone
- AWS-operated
- owner
- slot-csp
- il5
- true
- il6
- true
- note
- The CSP owns all logs and monitoring data created within the CSO relating to the mission owner's use, and shares what the contract specifies; it defends the CSO itself.
- cites
- S01#5.2.3
- S01#6.1 CSP cyber defense activities
- id
- n-bcap
- name
- DISA BCAP (NIPRNet) / ICAP (SIPRNet)
- scca
- BCAP
- zone
- DISN boundary, DISA-operated
- owner
- slot-bcd
- il5
- true
- il6
- ICAP instead of BCAP
- services
- DISN perimeter defenses and cyber-defense sensing
- Full packet capture and flow metrics (FRD 2.1.1.11/2.1.1.12)
- PPSM enforcement interface
- cites
- S01#5.9.1.1
- S01#5.9.1.4
- S08#2.1.1.x
- id
- n-cssp-mcd
- name
- CSSP operations centre (MCD)
- scca
- MCD
- zone
- Outside the cloud boundary; the mission owner's aligned CSSP
- owner
- slot-cssp
- il5
- true
- il6
- true
- services
- 24/7 monitoring of the mission environment
- Correlation of asset and vulnerability data with threat data (CSSP-only)
- Incident categorization, reporting and response for law enforcement/CI (CSSP-only)
- Malware notification, CPCON and orders notification (CSSP-only)
- cites
- S15#Table 1
- S01#6.1 MCD
- grade
- held-reconstruction
- publication note
- DTM-24-001 Table 1 allocations remain held pending a verified visual reading. Hypotheses shown here are not adopted policy or operational instructions.
- id
- n-cssp-bcd
- name
- BCD organization at the access point
- scca
- BCD
- zone
- DISN boundary
- owner
- slot-bcd
- il5
- true
- il6
- true
- services
- Protect the DISN via the BCAP
- Provide timely indications and warnings to MCD organizations
- Cross-CSP analysis
- cites
- S01#6.1 BCD
- S01#Appendix C Table C-1
- id
- n-jfhq
- name
- JFHQ-DODIN / USCYBERCOM (JIMS)
- scca
- DCD
- zone
- DODIN-wide, classified reporting system
- owner
- slot-dodin
- il5
- true
- il6
- true
- services
- JIMS incident records
- Orders, TASKORDs, CPCON direction
- Cross-BCAP correlation (DCD)
- cites
- S01#6.1 DCD
- S01#6.2.3
- S01#6.3
- S18#3.2
- id
- n-dc3
- name
- DC3 / DIBNet intake
- scca
- external reporting
- zone
- dibnet.dod.mil
- owner
- slot-dodin
- il5
- true
- il6
- false
- note
- At IL2–IL5 a commercial CSP whose offering is multitenant or shared outside the department reports through the DIB Cyber Incident Collection Format and names the affected mission owners and their CSSPs. At IL6 the CSP reports to the MCD organization over SIPRNet email or secure phone/fax instead.
- cites
- S01#6.2.3
- id
- n-mo-ops
- name
- Mission owner operations (ISSM/ISSO, admins, ticketing)
- scca
- mission owner
- zone
- Mission owner's own tooling
- owner
- slot-mission-owner
- il5
- true
- il6
- true
- services
- Enterprise ticketing (the record prescribes no tool; the ticket bridge carries the reference)
- Containment and remediation actions
- Evidence capture in IaaS
- cites
- L05#05-R3
- S01#6.2.4.1
- id
- n-ao-emass
- name
- Authorizing official and the authorization record (eMASS)
- scca
- authorization
- zone
- Component eMASS instance
- owner
- slot-mission-owner
- il5
- true
- il6
- INFERENCE — a classified instance
- services
- POA&M of record
- CSSP alignment documented in the package and in eMASS
- Risk acceptance by level
- cites
- S36
- L05#05-R5
- id
- n-cato
- name
- Continuous-ATO partner overlay
- scca
- overlay class (in-boundary GSS services)
- zone
- In-boundary, mission owner's accounts
- owner
- slot-cato-partner
- il5
- true
- il6
- INFERENCE
- services
- ConMon evidence assembly and POA&M reporting
- In-boundary SIEM/IDS/HBSS-class services where the mission owner buys them
- Monthly AO read-out support
- cites
- S91
- id
- n-wwt-record
- name
- Cloud Waypoint record (Foundations)
- scca
- design-time, not an event path
- zone
- The engagement's record, sealed and handed over
- owner
- slot-wwt
- il5
- true
- il6
- true
- services
- Nine GSS decisions, incl. d5 event federation and d9 continuous-monitoring split
- CONOPS annexes A, C, D, F, G
- SSP draft, POA&M draft, package readiness
- Crossing register and two-domain instruments on the IL6 record
- cites
- L05#GSS_DECISIONS
- L06#annexes
- L03
- id
- n-d42
- name
- Dependency-mapping appliance (Device42)
- scca
- design-time, not an event path
- zone
- Per-domain appliance, handed to the program's platform owners
- owner
- slot-wwt
- il5
- true
- il6
- true
- services
- Observed east-west and north-south dependencies
- Crossings marked
- Data-quality counts at baseline and handover
- cites
- L03#3.2, 3.6
- id
- n-il6-lz
- name
- IL6 landing zone (AWS Secret Region)
- scca
- GSS at IL6
- zone
- AWS Secret Region, closed SIPRNet enclave
- owner
- slot-lz-builder
- il5
- false
- il6
- true
- note
- LZA claims support for the Secret and Top Secret partitions and the changelog carries aws-iso/aws-iso-b fixes, but no public sample configuration or account layout exists for those partitions. Everything below account-level shape is INFERENCE.
- cites
- S60#partitions
- S61#changelog
- grade
- INFERENCE
- id
- n-il6-icap
- name
- SIPRNet ICAP
- scca
- BCAP equivalent at IL6
- zone
- SIPRNet boundary
- owner
- slot-bcd
- il5
- false
- il6
- true
- note
- IL6 offerings are closed SIPRNet enclaves, assessed like any other SIPRNet enclave connection; ICAPs are required.
- cites
- S01#5.9.1.4
- id
- n-il6-cssp
- name
- CSSP at IL6 (special-enclave capable)
- scca
- MCD at IL6
- zone
- SIPRNet
- owner
- slot-cssp
- il5
- false
- il6
- true
- note
- No public source names the CSSP for any specific IL6 cloud landing zone. Publicly demonstrated IL6-capable CSSP work: DISA's cloud CSSP offering for IL2–IL6 hosted applications; the Army C5ISR Center CSSP covering commercial cloud and Secret DREN (secondary source).
- cites
- S49
- S36
- grade
- INFERENCE
- id
- n-cds
- name
- Approved cross-domain transfer
- scca
- out of scope of the GSS; a separately accredited service
- zone
- Between domains
- owner
- slot-mission-owner
- il5
- true
- il6
- true
- note
- AWS publicly describes a cloud-based cross-domain service (Diode) that controls data flowing to AWS classified regions; the whitepaper is marked historical and says nothing about moving security telemetry, and nothing about high-to-low. In this model no event data moves high to low, ever.
- cites
- S88
- grade
- INFERENCE
boundaries
- id
- b-account
- type
- technical
- name
- Account and organization boundary
- what crosses
- Log records and findings crossing from a workload or infrastructure account into LogArchive and Audit, by subscription filter to a Kinesis stream, by service-native export, or by delegated administration.
- control
- KMS CMKs per purpose; bucket policies; delegated-admin configuration; retain-policy keys.
- cites
- S62#logging
- S60#KMS keys
- id
- b-lz-mission
- type
- operational
- name
- Landing zone ↔ mission owner line
- what crosses
- The inherited GSS services and their evidence; the conditions on the landing zone's decision letter that flow down to tenants; the continuous-monitoring split.
- control
- The nine GSS decisions — boundary (d1), inheritance sourcing (d3), conditions absorption (d4), monitoring profile (d6), the split (d9).
- cites
- L05#GSS_DECISIONS
- id
- b-enclave-egress
- type
- technical
- name
- Enclave egress for telemetry
- what crosses
- Curated events, alerts and query answers leaving the enclave toward a SIEM or a CSSP. Raw logs stay in the cloud by preference: it is best to keep the logs in the cloud and send back analysis and query responses to external sources such as the CSSP, rather than exporting the logs themselves.
- control
- Event-federation tier (GSS decision 5, the anti-tether rule); encrypted path between the IDPS capability and the CSSP; Annex C telemetry rows.
- cites
- S32#Play 12 log handling
- S03#V-259867
- L05#d5
- id
- b-cap
- type
- technical
- name
- BCAP / ICAP — the DISN boundary
- what crosses
- All IL4/IL5 traffic to and from the mission environment, including the management plane for privileged user access and for cybersecurity tool connectivity to DISN-native monitoring systems. At IL6 the equivalent is the SIPRNet ICAP.
- control
- DISA-operated perimeter defenses and sensing; PPSM; connection approval.
- cites
- S01#5.9.1.1.1
- S01#5.9.1.4
- id
- b-cssp-agreement
- type
- operational
- name
- Mission owner ↔ CSSP
- what crosses
- Alignment, service scope, notification and acknowledgement procedures, log access, incident hand-off.
- control
- A CSSP agreement under DoDI 8530.01 in the connection package; the split documented in a support agreement, MOA, contract or component issuance; the consent to monitor.
- cites
- S05#3.3
- S13#Encl 4 2.b
- S05#Appendix H
- id
- b-classified-reporting
- type
- operational
- name
- The classified incident-reporting system
- what crosses
- Categorized incident reports into JIMS, and orders back out.
- control
- Only the CSSP can cross it: the CSSP must perform incident reporting because only CSSPs have access to the classified incident reporting system.
- cites
- S15#3.d.(2)
- S01#6.2.3
- id
- b-csp-contract
- type
- operational
- name
- Mission owner ↔ CSP
- what crosses
- Platform logs and monitoring data the CSP owns; forensic artifacts; incident notifications; continuous-monitoring artifacts DISA shares.
- control
- Contract/SLA language; the CSP must provide the data identified to meet CSSP defensive-cyber requirements and share it with all parties including the designated CSSP.
- cites
- S01#5.2.3
- S15#Attachment 3 1.c
- S01#5.3.1
- id
- b-domain
- type
- technical
- name
- IL5 ↔ IL6 domain boundary
- what crosses
- Low-to-high only, and only by an approved transfer: signatures, patches, threat intelligence. No event data, log, finding or incident record ever moves high to low.
- control
- The crossing register (H-3) records mechanism, accreditation, owner, window and behaviour when unavailable; the record refuses other-domain material.
- cites
- L03#3.3, 3.8
- S88
- grade
- INFERENCE
responsibilities
- id
- r-generate
- function
- Generate the events (platform, network, identity, endpoint)
- csp
- text
- Emits CloudTrail, VPC flow logs, Network Firewall alert/flow logs, Resolver query logs, service findings; owns all logs and monitoring data created within the CSO relating to the mission owner's use.
- cites
- S01#5.2.3
- S62
- grade
- cited
- lz provider
- text
- Turns them on everywhere by configuration, sets retention, and forces new log groups into the same pattern.
- cites
- S60#centralized logging
- S62
- S15#Attachment 2
- S14#3.1.e
- grade
- cited
- accountability
- Performed inside the mission owner's accountability: whatever the landing-zone operator performs, the mission owner remains responsible and its authorizing official accountable.
- mission owner
- text
- Properly configures the cloud services it uses, including enabling encryption and logging; runs endpoint agents and the scanned baseline.
- cites
- S33
- S02#3.3
- grade
- cited
- cssp
- text
- States what security-relevant data it needs, and the mission owner collaborates with it during architecture development so the data will be accessible.
- cites
- S02#3.3
- grade
- cited
- id
- r-aggregate
- function
- Aggregate and retain (the allocated archiving system)
- csp
- text
- Provides the storage services and, at offboarding, makes available all audit logs relevant to the mission owner's use for the period specified by AU-11.
- cites
- S01#5.7
- grade
- cited
- lz provider
- text
- Operates LogArchive: subscription filters to a Kinesis stream, Firehose, the central S3 bucket with a dedicated CMK; lifecycle and retention defaults.
- cites
- S60
- S62
- S15#Attachment 2
- S14#3.1.e
- grade
- cited
- accountability
- Performed inside the mission owner's accountability: whatever the landing-zone operator performs, the mission owner remains responsible and its authorizing official accountable.
- mission owner
- text
- Accepts the retention it inherits and records it; where the inherited retention is shorter than its own obligation, it is the mission owner's gap.
- cites
- L06#Annex F
- grade
- INFERENCE
- cssp
- text
- Needs access to the archive rather than a copy; the SCCA FRD calls for a common collection, storage and access point for event logs by privileged users performing boundary and mission cyber defense.
- cites
- S08#2.1.2.12
- S08#2.1.3.7
- S08#2.1.4.4
- grade
- cited-secondary
- id
- r-analyze
- function
- Analyze — SIEM correlation and alerting
- csp
- text
- Provides native detection services (GuardDuty, Security Hub CSPM, Config, Inspector) with their GovCloud limits.
- cites
- S82
- L01
- grade
- cited
- lz provider
- text
- Runs the delegated-admin security tooling in Audit and, typically, the central monitoring components in SharedServices.
- cites
- S62
- S15#Attachment 2
- S14#3.1.e
- grade
- cited
- accountability
- Performed inside the mission owner's accountability: whatever the landing-zone operator performs, the mission owner remains responsible and its authorizing official accountable.
- mission owner
- text
- Serves as defensive cyberspace operations for its own mission systems and applications; may run its own SIEM tier.
- cites
- S02#3.3
- grade
- cited
- cssp
- text
- Correlating asset and vulnerability data with threat data is a CSSP-only activity at every impact level and service model. Boundary monitoring and intrusion detection is CSSP-only at IL4/5 and IL6. A SIEM or syslog capability must be implemented by both the boundary and the mission CND providers.
- cites
- S15#Table 1
- S04#V-259876
- grade
- held-reconstruction
- publication note
- DTM-24-001 Table 1 allocations remain held pending a verified visual reading. Hypotheses shown here are not adopted policy or operational instructions.
- id
- r-monitor-24x7
- function
- Watch it — 24/7 enclave monitoring
- csp
- text
- Defends its own offering; at IL4–IL6 on dedicated DoD infrastructure its incidents go to USCYBERCOM/JFHQ-DODIN rather than to the CSSP directly.
- cites
- S01#6.1
- S01#6.2.3
- grade
- cited
- lz provider
- text
- Typically operates the platform NOC/SOC for the shared services it owns. Not allocated by public policy — this is a contract and agreement question.
- cites
- S15#Attachment 2
- S14#3.1.e
- grade
- INFERENCE
- accountability
- Performed inside the mission owner's accountability: whatever the landing-zone operator performs, the mission owner remains responsible and its authorizing official accountable.
- mission owner
- text
- Ensures the MCD service provider is identified and funded, and performs endpoint cyberspace defense.
- cites
- S01#Appendix C Table C-1
- grade
- cited
- cssp
- text
- Enclave-level monitoring may be performed by a DoD or a commercial entity, but whoever does it must monitor the mission owner's environment 24/7/365 and provide copies of audit and system logs as requested by the CSSP point of contact. Where the CSSP has the technical capability to use intelligence-derived signatures, the activity must be performed by a CSSP.
- cites
- S15#3.c.(3)(b)
- grade
- cited
- id
- r-vuln
- function
- Vulnerability and endpoint findings
- csp
- text
- CSP vulnerability reports and POA&Ms go to DISA's cloud services support team and on to the MCD and BCD organizations; High and Critical findings in 30 days, Moderate in 90.
- cites
- S01#6.4
- grade
- cited
- lz provider
- text
- Provides ACAS or an approved equivalent and an endpoint security solution in the VDMS tier, with an encrypted path from agents to their control servers.
- cites
- S08#2.1.3.1
- S08#2.1.3.2
- S02#3.3.2
- S15#Attachment 2
- S14#3.1.e
- grade
- cited
- accountability
- Performed inside the mission owner's accountability: whatever the landing-zone operator performs, the mission owner remains responsible and its authorizing official accountable.
- mission owner
- text
- Patching and IAVM compliance are the mission owner's job (except where a SaaS CSP patches the operating system); flaw-remediation data must also be communicated to the CSSP.
- cites
- S01#Section 6 intro
- S03#V-259865
- grade
- cited
- cssp
- text
- Scans and endpoint monitoring may be DoD or commercial; correlating the results with threat data is CSSP-only. Endpoint alerts are reported to the AO or the CSSP.
- cites
- S15#Table 1
- S15#3.b.(2)
- grade
- held-reconstruction
- publication note
- DTM-24-001 Table 1 allocations remain held pending a verified visual reading. Hypotheses shown here are not adopted policy or operational instructions.
- id
- r-incident-report
- function
- Incident categorization and reporting
- csp
- text
- Initial incident report within one hour of the CSP's internal triage decision that the incident is reportable; at IL2–IL5, for offerings shared outside the department, via DIBNet with the affected mission owners and their CSSPs named; at IL6 to the MCD organization by SIPRNet email or secure phone/fax.
- cites
- S01#6.2.2
- S01#6.2.3
- grade
- cited
- lz provider
- text
- No public allocation. In practice the landing-zone operator reports into the same CSSP as a subscriber for the services it owns.
- cites
- S15#Attachment 2
- S14#3.1.e
- grade
- INFERENCE
- accountability
- Performed inside the mission owner's accountability: whatever the landing-zone operator performs, the mission owner remains responsible and its authorizing official accountable.
- mission owner
- text
- Puts incident handling and reporting requirements into the contract or SLA, and reports through its CSSP; NSS incidents are reported to JFHQ-DODIN.
- cites
- S02#3.3
- S02#3.3.2
- grade
- cited
- cssp
- text
- Incident categorization and incident reporting are CSSP-only. DoD CSSPs report all incidents using JIMS, on the clocks in CJCSM 6510.01B — for a high-impact root- or user-level intrusion, notify the next tier within 15 minutes, report within 4 hours, first JIMS entry within 6 hours.
- cites
- S15#Table 1
- S01#6.2.3
- S17#Table C-A-1
- grade
- held-reconstruction
- publication note
- DTM-24-001 Table 1 allocations remain held pending a verified visual reading. Hypotheses shown here are not adopted policy or operational instructions.
- id
- r-forensics
- function
- Evidence capture and forensics
- csp
- text
- Captures logs, memory, images and snapshots — except in IaaS, where the mission owner is responsible; provides automated capture with per-customer segregation, hashing and separate encryption, with keys held so only the government can read its own captured data.
- cites
- S01#6.2.4.1
- grade
- cited
- lz provider
- text
- Provides the snapshot, key and storage mechanisms the mission owner uses.
- cites
- S15#Attachment 2
- S14#3.1.e
- grade
- INFERENCE
- accountability
- Performed inside the mission owner's accountability: whatever the landing-zone operator performs, the mission owner remains responsible and its authorizing official accountable.
- mission owner
- text
- In IaaS, works with its MCD and the CSP to preserve VM images, memory, system logs, network logs and packet-capture data.
- cites
- S01#6.2.4.1
- grade
- cited
- cssp
- text
- Directs and receives the capture; incident response for law enforcement, counterintelligence and analysis is CSSP-only. Incident reports and data are retained 1 year, source and method information 5 years.
- cites
- S15#Table 1
- S14#3.6.b.(2)
- grade
- held-reconstruction
- publication note
- DTM-24-001 Table 1 allocations remain held pending a verified visual reading. Hypotheses shown here are not adopted policy or operational instructions.
- id
- r-orders
- function
- Orders, CPCON and directed action
- csp
- text
- Receives applicable orders through the BCD/MCD organizations and reports compliance.
- cites
- S01#6.3
- grade
- cited
- lz provider
- text
- Implements configuration changes the orders require across the shared tier.
- cites
- S15#Attachment 2
- S14#3.1.e
- grade
- INFERENCE
- accountability
- Performed inside the mission owner's accountability: whatever the landing-zone operator performs, the mission owner remains responsible and its authorizing official accountable.
- mission owner
- text
- Implements and reports compliance; contracts must allow the movement and manoeuvring of DoD cyberspace defensive forces for incident response.
- cites
- S01#6.3
- S14#4.1.d
- grade
- cited
- cssp
- text
- CPCON and orders notification and assistance is CSSP-only; the MCD and BCD report compliance to JFHQ-DODIN and USCYBERCOM.
- cites
- S15#Table 1
- S01#6.3
- grade
- held-reconstruction
- publication note
- DTM-24-001 Table 1 allocations remain held pending a verified visual reading. Hypotheses shown here are not adopted policy or operational instructions.
- id
- r-remediate
- function
- Remediation, POA&M and closure
- csp
- text
- Fixes its own findings on the 30/90-day clocks; a missed deadline can lead to a plan-of-action milestone escalation, then a DFR or corrective action plan.
- cites
- S01#6.4
- grade
- cited
- lz provider
- text
- Remediates the inherited layer and re-issues evidence; its residual conditions flow down to tenants.
- cites
- L05#d4
- S15#Attachment 2
- S14#3.1.e
- grade
- INFERENCE
- accountability
- Performed inside the mission owner's accountability: whatever the landing-zone operator performs, the mission owner remains responsible and its authorizing official accountable.
- mission owner
- text
- Owns the POA&M and the risk acceptance; the engagement's default taxonomy is Critical 15 days, High 30, Moderate 90, Low 180, with risk acceptance by level and a 90-day recurrence watch before closure — confirmed or tailored per engagement.
- cites
- L05#05-R1
- L05#05-R4
- L05#05-R5
- grade
- cited-internal
- cssp
- text
- Verifies and closes the incident record; no report is closed as 'investigating'.
- cites
- S17#Table B-A-2
- grade
- cited
- id
- r-conmon-artifacts
- function
- Continuous-monitoring artifacts and inheritance evidence
- csp
- text
- Produces the CSO's continuous-monitoring artifacts under its provisional authorization.
- cites
- S01#5.3.1
- grade
- cited
- lz provider
- text
- Passes the inherited control evidence and the landing zone's conditions to tenants.
- cites
- L05#d3
- L05#d4
- S15#Attachment 2
- S14#3.1.e
- grade
- INFERENCE
- accountability
- Performed inside the mission owner's accountability: whatever the landing-zone operator performs, the mission owner remains responsible and its authorizing official accountable.
- mission owner
- text
- Consumes them into its own package; the record's continuous-monitoring split says who watches what.
- cites
- L05#d9
- grade
- cited-internal
- cssp
- text
- DISA shares continuous-monitoring information with mission owners, AOs and CSSPs; accredited CSSPs are required to perform information security continuous monitoring.
- cites
- S01#5.3.1
- S05#3.6.5
- grade
- cited
edges
- id
- e-01
- from
- n-workload
- to
- n-logarchive
- event type
- API audit (CloudTrail management and data events)
- transport
- Control Tower organization trail → S3 in LogArchive
- direction
- one-way
- crosses boundary
- true
- boundary
- b-account
- boundary type
- technical
- owner
- slot-lz-builder
- il5
- true
- il6
- INFERENCE
- cites
- S62#organizationTrail true
- S67
- note
- In GovCloud, global service events land in us-gov-west-1, so single-Region trails elsewhere must become multi-Region.
- id
- e-02
- from
- n-workload
- to
- n-logarchive
- event type
- VPC flow records (ALL, 600s aggregation, custom fields)
- transport
- CloudWatch Logs → subscription filter → Kinesis Data Stream (LogArchive) → Firehose → S3 prefix vpc-flow-logs
- direction
- one-way
- crosses boundary
- true
- boundary
- b-account
- boundary type
- technical
- owner
- slot-lz-builder
- il5
- true
- il6
- INFERENCE
- cites
- S62#logging
- S62#log-filters
- note
- Flow logs are metadata, not packet contents.
- id
- e-03
- from
- n-network-inspect
- to
- n-logarchive
- event type
- Network Firewall alert and flow logs (north-south and east-west)
- transport
- CloudWatch Logs → Kinesis → Firehose → S3 prefixes network-firewall/alert and /flow
- direction
- one-way
- crosses boundary
- true
- boundary
- b-account
- boundary type
- technical
- owner
- slot-lz-builder
- il5
- true
- il6
- INFERENCE
- cites
- S62#network-config logging
- S80
- id
- e-04
- from
- n-network-inspect
- to
- n-logarchive
- event type
- Route 53 Resolver DNS query logs
- transport
- CloudWatch Logs → central S3 prefix route53-resolver-query-logs; the configuration is shared by RAM and each VPC associates explicitly
- direction
- one-way
- crosses boundary
- true
- boundary
- b-account
- boundary type
- technical
- owner
- slot-lz-builder
- il5
- true
- il6
- INFERENCE
- cites
- S62#network-config
- S81
- note
- The Resolver logs only unique queries, not those answered from cache. The GovCloud user guide is silent on Resolver query logging specifically.
- id
- e-05
- from
- n-workload
- to
- n-audit
- event type
- Threat findings (GuardDuty)
- transport
- Service-native, delegated administrator in Audit
- direction
- one-way
- crosses boundary
- true
- boundary
- b-account
- boundary type
- technical
- owner
- slot-lz-builder
- il5
- true
- il6
- partial — GuardDuty is listed at IL6; Detective and Inspector are not
- cites
- S62#security-config
- S82
- S72
- id
- e-06
- from
- n-audit
- to
- n-logarchive
- event type
- Findings export (GuardDuty every six hours; Security Hub CSPM findings)
- transport
- S3 export / CloudWatch Logs → central bucket prefix security-hub
- direction
- one-way
- crosses boundary
- true
- boundary
- b-account
- boundary type
- technical
- owner
- slot-lz-builder
- il5
- true
- il6
- INFERENCE
- cites
- S62#security-config
- S62#log-filters
- id
- e-07
- from
- n-audit
- to
- n-mo-ops
- event type
- Severity-routed alert (SecurityHigh / Medium / Low)
- transport
- SNS topic subscription (email by default in the reference configuration)
- direction
- one-way
- crosses boundary
- true
- boundary
- b-lz-mission
- boundary type
- operational
- owner
- slot-lz-builder
- il5
- true
- il6
- INFERENCE
- cites
- S62#security-config alert topics
- id
- e-08
- from
- n-shared-vdms
- to
- n-workload
- event type
- Authenticated vulnerability scan (ACAS or approved equivalent)
- transport
- Scanner to target, inside the enclave
- direction
- one-way
- crosses boundary
- false
- boundary
- boundary type
- none
- owner
- slot-endpoint-vuln
- il5
- true
- il6
- true
- cites
- S08#2.1.3.1
- S03#V-259865
- S19#monthly scans
- id
- e-09
- from
- n-shared-vdms
- to
- n-cssp-mcd
- event type
- Scan results and flaw-remediation data
- transport
- Encrypted path to the CSSP (the STIG check asks the assessor to verify it)
- direction
- one-way
- crosses boundary
- true
- boundary
- b-enclave-egress
- boundary type
- technical
- owner
- slot-mission-owner
- il5
- true
- il6
- true
- cites
- S03#V-259865
- id
- e-10
- from
- n-workload
- to
- n-shared-vdms
- event type
- Endpoint security events (ESS/EDR agents)
- transport
- Encrypted agent-to-control-server path
- direction
- one-way
- crosses boundary
- false
- boundary
- boundary type
- none
- owner
- slot-endpoint-vuln
- il5
- true
- il6
- true
- cites
- S02#3.3.2
- S08#2.1.3.2
- id
- e-11
- from
- n-shared-vdms
- to
- n-cssp-mcd
- event type
- Endpoint alerts and endpoint IDS logs
- transport
- Feed or on-request copies
- direction
- one-way
- crosses boundary
- true
- boundary
- b-enclave-egress
- boundary type
- technical
- owner
- slot-mission-owner
- il5
- true
- il6
- true
- cites
- S15#3.b.(2)
- id
- e-12
- from
- n-logarchive
- to
- n-siem
- event type
- Bulk log read for correlation
- transport
- Read-only role granted by a statement appended to the central log bucket policy (example role names SplunkIngestionRole, OpenSearchAccessRole)
- direction
- one-way
- crosses boundary
- true
- boundary
- b-account
- boundary type
- technical
- owner
- slot-siem
- il5
- true
- il6
- INFERENCE
- cites
- S62#07-04-Log-Analysis
- id
- e-13
- from
- n-network-inspect
- to
- n-cssp-mcd
- event type
- IDPS and VDSS sensor feed
- transport
- Encrypted connection between the virtual IDPS capability and the CSSP
- direction
- one-way
- crosses boundary
- true
- boundary
- b-enclave-egress
- boundary type
- technical
- owner
- slot-mission-owner
- il5
- true
- il6
- true
- cites
- S03#V-259867
- S02#3.3.2 'VDSS feeds must be provided to a DoW CSSP performing boundary defense'
- id
- e-14
- from
- n-siem
- to
- n-cssp-mcd
- event type
- Curated alerts, correlation results, query answers
- transport
- Alert forwarding or federated query
- direction
- two-way
- crosses boundary
- true
- boundary
- b-enclave-egress
- boundary type
- technical
- owner
- slot-cssp
- il5
- true
- il6
- true
- cites
- S32#Play 12
- L05#d5
- note
- The preferred pattern keeps the logs in the cloud and sends analysis and query responses outward — the same rule the record calls the event-federation tier.
- id
- e-15
- from
- n-logarchive
- to
- n-cssp-mcd
- event type
- Direct archive access for cyber-defense analysts
- transport
- Read-only cross-account role into the archive
- direction
- one-way
- crosses boundary
- true
- boundary
- b-account
- boundary type
- technical
- owner
- slot-lz-builder
- il5
- true
- il6
- INFERENCE
- cites
- S08#2.1.2.12
- S08#2.1.4.4
- grade
- cited-secondary
- id
- e-16
- from
- n-tccm
- to
- n-logarchive
- event type
- Privileged-portal activity logs and alerts
- transport
- CloudTrail management events and Identity Center sign-in records into the archive
- direction
- one-way
- crosses boundary
- true
- boundary
- b-account
- boundary type
- technical
- owner
- slot-lz-builder
- il5
- true
- il6
- INFERENCE
- cites
- S08#2.1.4.2
- S63#TCCM 2.1.4.2-2.1.4.4 covered by CloudTrail/CloudWatch/SNS
- id
- e-17
- from
- n-bcap
- to
- n-cssp-bcd
- event type
- Boundary sensing, full packet capture, flow metrics
- transport
- DISA-operated sensor grid at the access point
- direction
- one-way
- crosses boundary
- true
- boundary
- b-cap
- boundary type
- technical
- owner
- slot-bcd
- il5
- true
- il6
- ICAP
- cites
- S08#2.1.1.11
- S08#2.1.1.12
- S01#5.9.1.1
- id
- e-18
- from
- n-cssp-bcd
- to
- n-cssp-mcd
- event type
- Indications and warnings
- transport
- CSSP-to-CSSP sharing, classified channels where needed
- direction
- one-way
- crosses boundary
- true
- boundary
- b-cssp-agreement
- boundary type
- operational
- owner
- slot-bcd
- il5
- true
- il6
- true
- cites
- S01#6.1 BCD
- S15#BCP information sharing on classified networks
- id
- e-19
- from
- n-csp-plane
- to
- n-dc3
- event type
- CSP incident report (offering shared outside the department, IL2–IL5)
- transport
- DIB Cyber Incident Collection Format on dibnet.dod.mil, medium-assurance certificate
- direction
- one-way
- crosses boundary
- true
- boundary
- b-csp-contract
- boundary type
- operational
- owner
- slot-csp
- il5
- true
- il6
- false
- sla
- within one hour of the CSP's internal triage decision
- cites
- S01#6.2.2
- S01#6.2.3
- id
- e-20
- from
- n-csp-plane
- to
- n-cssp-mcd
- event type
- CSP incident notification naming affected mission owners
- transport
- DIBNet report contents; at IL6, SIPRNet email or secure phone/fax
- direction
- one-way
- crosses boundary
- true
- boundary
- b-csp-contract
- boundary type
- operational
- owner
- slot-csp
- il5
- true
- il6
- true
- cites
- S01#6.2.3
- note
- At IL4–IL6 where the CSP provides dedicated DoD infrastructure, its own infrastructure incidents go to USCYBERCOM/JFHQ-DODIN instead, which then coordinates.
- id
- e-21
- from
- n-cssp-mcd
- to
- n-jfhq
- event type
- Categorized incident report
- transport
- JIMS (classified reporting system)
- direction
- two-way
- crosses boundary
- true
- boundary
- b-classified-reporting
- boundary type
- operational
- owner
- slot-cssp
- il5
- true
- il6
- true
- sla
- CJCSM 6510.01B clocks; CAT 1/2 high impact — notify 15 minutes, report 4 hours, JIMS entry 6 hours
- cites
- S01#6.2.3
- S17#Table C-A-1
- S15#3.d.(2)
- id
- e-22
- from
- n-jfhq
- to
- n-cssp-mcd
- event type
- Orders, TASKORDs, CPCON changes, warning intelligence
- transport
- Command channels; the CSSP passes applicable direction to mission owners and CSPs and reports compliance
- direction
- one-way
- crosses boundary
- true
- boundary
- b-classified-reporting
- boundary type
- operational
- owner
- slot-dodin
- il5
- true
- il6
- true
- cites
- S01#6.3
- id
- e-23
- from
- n-cssp-mcd
- to
- n-mo-ops
- event type
- Incident notification, malware notification, direction to contain
- transport
- Ticket and voice bridge; notification and acknowledgement procedures are a contract requirement
- direction
- two-way
- crosses boundary
- true
- boundary
- b-cssp-agreement
- boundary type
- operational
- owner
- slot-cssp
- il5
- true
- il6
- true
- cites
- S15#Attachment 2
- S15#Table 1
- grade
- held-reconstruction
- publication note
- DTM-24-001 Table 1 allocations remain held pending a verified visual reading. Hypotheses shown here are not adopted policy or operational instructions.
- id
- e-24
- from
- n-mo-ops
- to
- n-ao-emass
- event type
- POA&M item, risk acceptance, incident disclosure
- transport
- eMASS; CSSP alignment is documented in the package and in eMASS
- direction
- one-way
- crosses boundary
- true
- boundary
- b-lz-mission
- boundary type
- operational
- owner
- slot-mission-owner
- il5
- true
- il6
- INFERENCE
- cites
- S36
- L05#05-R1
- id
- e-25
- from
- n-cato
- to
- n-ao-emass
- event type
- Continuous-monitoring evidence pack and POA&M reporting
- transport
- Monthly read-out and evidence assembly
- direction
- one-way
- crosses boundary
- true
- boundary
- b-lz-mission
- boundary type
- operational
- owner
- slot-cato-partner
- il5
- true
- il6
- INFERENCE
- cites
- S91
- id
- e-26
- from
- n-csp-plane
- to
- n-mo-ops
- event type
- Continuous-monitoring artifacts for the authorized offering
- transport
- DISA shares them with mission owners, AOs and the CSSP
- direction
- one-way
- crosses boundary
- true
- boundary
- b-csp-contract
- boundary type
- operational
- owner
- slot-csp
- il5
- true
- il6
- true
- cites
- S01#5.3.1
- id
- e-27
- from
- n-d42
- to
- n-wwt-record
- event type
- Observed dependencies and crossings (design-time, not runtime telemetry)
- transport
- Export read into the record as cited claims a named person confirms
- direction
- one-way
- crosses boundary
- false
- boundary
- boundary type
- none
- owner
- slot-wwt
- il5
- true
- il6
- true
- cites
- L03#3.7
- id
- e-28
- from
- n-wwt-record
- to
- n-mo-ops
- event type
- Handover: annexes, decisions, split, telemetry rows (design-time)
- transport
- Readiness, Transformation and Final packages
- direction
- one-way
- crosses boundary
- true
- boundary
- b-lz-mission
- boundary type
- operational
- owner
- slot-wwt
- il5
- true
- il6
- true
- cites
- L03#3.6
- id
- e-29
- from
- n-il6-lz
- to
- n-il6-cssp
- event type
- IL6 curated events and incident coordination
- transport
- Inside the SECRET domain only; SIPRNet channels
- direction
- two-way
- crosses boundary
- true
- boundary
- b-cssp-agreement
- boundary type
- operational
- owner
- slot-cssp
- il5
- false
- il6
- true
- cites
- S01#6.2.3
- S01#5.9.1.4
- grade
- INFERENCE
- id
- e-30
- from
- n-cds
- to
- n-il6-lz
- event type
- Low-to-high transfer only: signatures, patches, threat intelligence
- transport
- Separately accredited cross-domain service
- direction
- one-way
- crosses boundary
- true
- boundary
- b-domain
- boundary type
- technical
- owner
- slot-mission-owner
- il5
- true
- il6
- true
- cites
- S88
- grade
- INFERENCE
- id
- e-31
- from
- n-il6-lz
- to
- n-logarchive
- event type
- FORBIDDEN — no IL6 event data returns to an IL5 or lower surface
- transport
- none
- direction
- forbidden
- crosses boundary
- true
- boundary
- b-domain
- boundary type
- technical
- owner
- slot-mission-owner
- il5
- false
- il6
- true
- cites
- L03#3.3, 3.8
- grade
- INFERENCE
checklist before first migration
- id
- c-01
- condition
- Every log source in the reference set is on and lands in one archive account: organization CloudTrail, VPC flow logs, Network Firewall alert and flow logs, Resolver query logs, Transit Gateway flow logs, Security Hub and Session Manager.
- observable
- The central bucket has an object under each expected prefix in the last 24 hours.
- cites
- S62#log-filters
- id
- c-02
- condition
- New log groups are captured automatically, not by hand.
- observable
- A log group created today has the retention, the KMS key and the subscription filter within minutes.
- cites
- S60#centralized logging
- id
- c-03
- condition
- Retention is decided, written down and longer than the shortest obligation the system carries.
- observable
- The configured retention is recorded in Annex F against each feed; the default LZA/UC setting expires central log objects at 1000 days, and incident data must be kept a year, source and method five.
- cites
- S62#S3 lifecycle
- S14#3.6.b.(2)
- id
- c-04
- condition
- Archive integrity is deliberate, not assumed.
- observable
- Either S3 Object Lock is enabled on the central log bucket, or the decision not to is recorded with the compensating control — the reference configuration does not set it and suppresses the finding.
- cites
- S62#S3-ObjectLock-Suppress
- S65
- id
- c-05
- condition
- A named CSSP is aligned, and the alignment is in the authorization package and in eMASS.
- observable
- The connection package holds the CSSP agreement and the signed consent to monitor.
- cites
- S05#3.3
- S36
- id
- c-06
- condition
- The CSSP can reach what it needs — feed, query role, or both — and has proven it.
- observable
- A demonstrated receipt: the CSSP acknowledges a test event through the production path, recorded as a rehearsal outcome with an evidence item.
- cites
- S02#3.3
- L04#Annex G receipt
- id
- c-07
- condition
- The VDSS sensor feed reaches the boundary-defense provider over an encrypted path, and ACAS flaw-remediation data reaches the CSSP.
- observable
- The STIG checks for V-259867 and V-259865 pass with evidence.
- cites
- S03#V-259867
- S03#V-259865
- id
- c-08
- condition
- The event-federation rule is decided: what leaves the enclave is curated events and query answers, not raw logs.
- observable
- GSS decision 5 is decided, with the Annex C rows that implement it.
- cites
- L05#d5
- S32#Play 12
- id
- c-09
- condition
- The continuous-monitoring split is decided and signed: the landing-zone operator's scope, the enterprise program's, the CSSP's, and the mission owner's residual.
- observable
- GSS decision 9 is decided and prints on the exit receipt with its evidence.
- cites
- L05#d9
- id
- c-10
- condition
- Incident roles and clocks are agreed with the CSSP before an incident, including notification and acknowledgement procedures.
- observable
- Annex A has one accountable role per activity; Annex D carries the severity taxonomy and clocks; the contract carries the CSSP notification requirement.
- cites
- S15#Attachment 2
- L05#05-R1
- id
- c-11
- condition
- The provider's obligations are in the contract: the data the CSSP needs, forensic support, and the incident report within one hour of triage.
- observable
- The interconnect row names the agreement type and owner (decision 8); the contract language exists.
- cites
- S15#Attachment 3 1.c
- S01#6.2.2
- id
- c-12
- condition
- Evidence capture in IaaS is rehearsed, because the provider does not do it for you there.
- observable
- A rehearsal outcome covering image, snapshot and log preservation.
- cites
- S01#6.2.4.1
- L05#05-R7
- id
- c-13
- condition
- The GovCloud service gaps are known and compensated, not discovered later: no Macie, no CloudWatch cross-account observability, CloudTrail Lake limits, Security Hub integration limits, Inspector is not ACAS.
- observable
- Each gap is a named condition or finding with an owner.
- cites
- S68
- S67
- S74
- L01#A-2
- id
- c-14
- condition
- The POA&M and its clocks exist before the first application, not after the first finding.
- observable
- POA&M draft in the Readiness package; severity taxonomy confirmed or tailored in Annex D.
- cites
- L05#05-R1
- id
- c-15
- condition
- On a two-domain program, the IL6 deltas are read and recorded rather than assumed: reporting channel, CSSP, service availability, and the high-to-low rail.
- observable
- H-1 to H-4 delivered on the IL6 record, with the crossing register populated.
- cites
- S01#6.2.3
- L03#3.5
gaps
- id
- g-01
- question
- What audit-log retention does DoD actually require at IL5?
- status
- The SRG defers to the AU-11 parameter and publishes no number; Appendix D does not list AU-11. The value is expected in the DoD RMF Knowledge Service or CNSSI 1253 overlay, neither publicly reachable.
- source needed
- RMF Knowledge Service (CAC-gated) AU-11 parameter for the applicable overlay.
- id
- g-02
- question
- Who is the CSSP for a specific IL6 cloud landing zone?
- status
- No public source names it for cARMY IL6, Cloud One Secret, Neptune IL6 or a JWCC classified task order. DISA publicly describes an IL2–IL6 cloud CSSP offering; the Army C5ISR Center CSSP is described (secondary) as covering commercial cloud and Secret DREN.
- source needed
- The USCYBERCOM list of certified CSSPs, or the component's CSSP alignment memo.
- closing evidence
- Closes on: the USCYBERCOM list of certified and authorized CSSPs (GENSER vs special enclave), or the component's own CSSP alignment memo naming the provider for its Secret cloud. Either would be requested through the program's ISSM rather than found publicly.
- id
- g-03
- question
- What does an IL6 landing zone look like on AWS?
- status
- LZA claims Secret and Top Secret partition support and the changelog shows isolated-partition fixes, but there is no public sample configuration, account layout, or logging design for those partitions, and no public statement on how customers run security monitoring there.
- source needed
- An AWS Secret Region service catalog or an LZA isolated-partition reference configuration, both obtained through an account team.
- closing evidence
- Closes on: the AWS Secret Region service catalog, obtainable only through an AWS account executive, plus an LZA isolated-partition (aws-iso / aws-iso-b) reference configuration. Until one of those is in hand, every IL6 design statement below account level stays INFERENCE.
- id
- g-04
- question
- The SCCA FRD's authoritative text.
- status
- The DISA original of FRD v2.9 is 404 at every DISA path and 403 at every mirror tried. Requirement text used here comes from vendor reproductions (Microsoft, AWS, Oracle) that agree with each other.
- source needed
- The DISA-issued FRD, current revision, through DoD channels.
- id
- g-05
- question
- Is there a newer CSSP definition or certification memo, and what are its clocks?
- status
- A 2026 DoW CIO directive-type memo is reported by trade press (72 hours to triage, 24 hours to report to USCYBERCOM, alignment not waivable). The primary text was not found.
- source needed
- The memo itself from the DoD issuances site.
- id
- g-06
- question
- How does DTM-24-001 Table 1 render its CSSP-only marker?
- status
- The marker is an unrendered glyph in text extraction; the allocation was reconstructed from the narrative, which agrees. Two independent readings matched.
- source needed
- A clean PDF rendering of Table 1.
- closing evidence
- Closes on: a clean rendering of DTM-24-001 Table 1 — the PDF opened in a viewer that draws the marker glyphs, or a component reproduction of the table in text. Two independent readings already agree with the narrative text; a rendered table would move the allocation from reconstructed to quoted. DTM 24-001 stays on hold in the CSP corpus either way; nothing in the corpus is changed by this note.
- id
- g-07
- question
- Does the landing-zone operator report to the same CSSP as its tenants?
- status
- No public policy allocates enclave monitoring or incident reporting to a landing-zone operator as a distinct party; DoD policy knows CSP, mission owner and CSSP. In practice this is a contract and agreement question.
- source needed
- A component enterprise-cloud tenant agreement (cARMY or Cloud One tenant guide, both CAC-gated).
- id
- g-08
- question
- Is Resolver query logging available in AWS GovCloud without limits?
- status
- The GovCloud user guide is silent on Resolver query logging; it states only that public-zone query logging must use a US-West log group. The reference configuration deploys Resolver query logging in GovCloud.
- source needed
- An AWS statement, or a test in a GovCloud account.
sources
- id
- S01
- title
- Department of Defense Cloud Service Provider Security Requirements Guide, V1R7
- publisher
- DISA
- url
- https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Cloud_Computing_Y26M06_SRG.zip
- date
- 2026-06-30
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S02
- title
- Cloud Computing Mission Owner Security Requirements Guide Overview
- publisher
- DISA
- url
- https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Cloud_Computing_Y26M06_SRG.zip
- date
- 2026-06-30
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S03
- title
- Cloud Computing Mission Owner Network Security Requirements Guide, V1R2
- publisher
- DISA
- url
- https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Cloud_Computing_Y26M06_SRG.zip
- date
- 2025-01-30
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S04
- title
- Cloud Computing Mission Owner Operating System Security Requirements Guide, V1R3
- publisher
- DISA
- url
- https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Cloud_Computing_Y26M06_SRG.zip
- date
- 2025-08-13
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S05
- title
- DoD Cloud Connection Process Guide, Version 3
- publisher
- DISA
- url
- https://dl.dod.cyber.mil/wp-content/uploads/cloud/pdf/DoD%20Cloud%20CPG%20Final%2019%20Dec%202025.pdf
- date
- 2025-12-19
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S06
- title
- DoD Cloud Authorization Process briefing and diagram
- publisher
- DISA
- url
- https://dl.dod.cyber.mil/wp-content/uploads/cloud/pdf/unclass-dod_cloud_authorization_process.pdf
- date
- 2024-06
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S07
- title
- DISN Connection Process Guide, Version 6.1
- publisher
- DISA
- url
- https://dl.dod.cyber.mil/wp-content/uploads/connect/pdf/unclass-DISN_CPG.pdf
- date
- 2023-08
- retrieved
- 2026-09-17
- status
- read (cloud and CSSP sections)
- http
- 200
- id
- S08
- title
- Secure Cloud Computing Architecture Functional Requirements Document v2.9
- publisher
- DISA (original); text via vendor reproductions
- url
- https://www.cyber.mil/dccs/dccs-documents/
- date
- 2017-01-31
- retrieved
- 2026-09-17
- status
- current DISA DCCS document collection reachable; the withdrawn v2.9 file remains unavailable; requirement text read from S10, S63 and S11 (secondary, mutually consistent)
- http
- 200
- id
- S09
- title
- Secure Cloud Computing Architecture (SCCA) FRD listing
- publisher
- DON CIO
- url
- https://www.doncio.navy.mil/ContentView.aspx?id=9850
- date
- 2017-01-31 (publish date shown)
- retrieved
- 2026-09-17
- status
- read (metadata only; the linked PDF does not resolve)
- http
- 200
- id
- S10
- title
- Mission Landing Zone — SCCA documentation (scca.md)
- publisher
- Microsoft (GitHub)
- url
- https://github.com/Azure/missionlz
- date
- n/a
- retrieved
- 2026-09-17
- status
- read (secondary reproduction of FRD requirement text)
- http
- 200
- id
- S11
- title
- Oracle Cloud Native SCCA Landing Zone — Customer Responsibility, v2.0
- publisher
- Oracle
- url
- https://www.oracle.com/a/ocom/docs/industries/public-sector/scca-customer-responsibility.pdf
- date
- 2023-07
- retrieved
- 2026-09-17
- status
- read (secondary reproduction of FRD requirement text)
- http
- 200
- id
- S12
- title
- What is the Secure Cloud Computing Architecture?
- publisher
- DISA News via DON CIO CHIPS
- url
- https://www.doncio.navy.mil/CHIPS/ArticleDetails.aspx?ID=10280
- date
- 2018-04-23
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S13
- title
- DoDI 8530.01, Cybersecurity Activities Support to DoD Information Network Operations (Change 1)
- publisher
- DoD CIO
- url
- https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/853001p.pdf
- date
- 2016-03-07, Ch 1 2017-07-25
- retrieved
- 2026-09-17
- status
- 403 direct; read in full from an Internet Archive capture of the official PDF
- http
- 403
- id
- S14
- title
- DoDM 8530.01, Cybersecurity Activities Support Procedures
- publisher
- DoD CIO
- url
- https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodm/853001p.PDF
- date
- 2023-05-31
- retrieved
- 2026-09-17
- status
- 403 direct; read in full from an Internet Archive capture
- http
- 403
- id
- S15
- title
- DTM-24-001, DoW Cybersecurity Activities Performed for Cloud Service Offerings (Change 2)
- publisher
- DoD CIO
- url
- https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dtm/DTM-24-001.pdf
- date
- 2024-02-27, Ch 2 2026-05-07
- retrieved
- 2026-09-17
- status
- 403 direct (confirmed by curl); read in full from an Internet Archive capture
- http
- 403
- publication note
- DTM-24-001 Table 1 allocations remain held pending a verified visual reading. Hypotheses shown here are not adopted policy or operational instructions.
- id
- S16
- title
- DoW CIO issues memo on cybersecurity service provider certification requirements
- publisher
- ExecutiveGov (secondary)
- url
- https://www.executivegov.com/articles/dow-cio-cyber-service-provider-certification-policy-memo
- date
- 2026-07-29
- retrieved
- 2026-09-17
- status
- read (secondary; primary memo not found)
- http
- 200
- id
- S17
- title
- CJCSM 6510.01B, Cyber Incident Handling Program
- publisher
- Joint Staff J-6
- url
- https://www.jcs.mil/Portals/36/Documents/Library/Manuals/m651001.pdf
- date
- 2012-07-10 (current as of 2014-12-18)
- retrieved
- 2026-09-17
- status
- 403 direct; read in full from an Internet Archive capture
- http
- 403
- publication note
- Archived reading reported by the author; confirm the current reporting directive and component instructions before operational use.
- id
- S18
- title
- DoDI 8530.03, Cyber Incident Response
- publisher
- DoD CIO
- url
- https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/853003p.pdf
- date
- 2023-08-09
- retrieved
- 2026-09-17
- status
- 403 direct; read from an Internet Archive capture
- http
- 403
- id
- S19
- title
- DoDI 8531.01, DoD Vulnerability Management
- publisher
- DoD CIO
- url
- https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/853101p.pdf
- date
- 2020-09-15
- retrieved
- 2026-09-17
- status
- 403 direct; read from an Internet Archive capture
- http
- 403
- id
- S20
- title
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
- publisher
- acquisition.gov
- url
- https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting.
- date
- 2024-05
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S21
- title
- Federal Incident Notification Guidelines
- publisher
- CISA
- url
- https://www.cisa.gov/federal-incident-notification-guidelines
- date
- 2017-04-01 (effective)
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S22
- title
- OMB M-21-31, Improving the Federal Government's Investigative and Remediation Capabilities
- publisher
- OMB
- url
- https://www.whitehouse.gov/wp-content/uploads/2021/08/M-21-31-Improving-the-Federal-Governments-Investigative-and-Remediation-Capabilities-Related-to-Cybersecurity-Incidents.pdf
- date
- 2021-08-27
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S23
- title
- DoD Zero Trust Strategy
- publisher
- DoD CIO
- url
- https://dodcio.defense.gov/Portals/0/Documents/Library/DoD-ZTStrategy.pdf
- date
- 2022-10
- retrieved
- 2026-09-17
- status
- 403 on dodcio.defense.gov; read from the dowcio.war.gov copy
- http
- 403
- id
- S24
- title
- DoD Zero Trust Capabilities and Activities / execution roadmap
- publisher
- DoD CIO
- url
- https://dodcio.defense.gov/Portals/0/Documents/Library/ZTCapabilitiesActivities.pdf
- date
- PDF created 2025-08
- retrieved
- 2026-09-17
- status
- 403 on dodcio.defense.gov; read from the dowcio.war.gov copy
- http
- 403
- id
- S25
- title
- NIST SP 800-92, Guide to Computer Security Log Management
- publisher
- NIST
- url
- https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-92.pdf
- date
- 2006-09
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S26
- title
- NIST SP 800-92r1 ipd, Cybersecurity Log Management Planning Guide (initial public draft)
- publisher
- NIST
- url
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-92r1.ipd.pdf
- date
- 2023-10-11
- retrieved
- 2026-09-17
- status
- read (still a draft)
- http
- 200
- id
- S27
- title
- NIST SP 800-137, Information Security Continuous Monitoring for Federal Information Systems and Organizations
- publisher
- NIST
- url
- https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-137.pdf
- date
- 2011-09
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S28
- title
- NIST SP 800-61r3, Incident Response Recommendations and Considerations
- publisher
- NIST
- url
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r3.pdf
- date
- 2025-04
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S29
- title
- NIST SP 800-53 Rev 5 control catalog (OSCAL content 5.2.0)
- publisher
- NIST
- url
- https://github.com/usnistgov/oscal-content
- date
- Rev 5
- retrieved
- 2026-09-17
- status
- read (AU-2, AU-6, AU-9, AU-11, IR-6, SI-4, CA-7 all organization-defined)
- http
- 200
- id
- S30
- title
- DISA Cybersecurity service catalog (help desk directory)
- publisher
- DISA
- url
- https://help.disa.mil/
- date
- n/a
- retrieved
- 2026-09-17
- status
- read (contact entries only; includes ACAS, Endpoint Security Solutions, Cloud & Traditional CSP, Incident Reporting)
- http
- 200
- id
- S31
- title
- DISA: HBSS becomes Endpoint Security Solutions (ESS)
- publisher
- DISA News via DON CIO CHIPS
- url
- https://www.doncio.navy.mil/CHIPS/
- date
- 2016-09-06
- retrieved
- 2026-09-17
- status
- read (article id not captured; cited only for the HBSS→ESS naming)
- http
- 200
- id
- S32
- title
- DoD Cloud Security Playbook, Volume 1
- publisher
- DoD CIO
- url
- https://dodcio.defense.gov/Portals/0/Documents/Library/CloudSecurityPlaybookVol1.pdf
- date
- 2025-02-11, v1.0
- retrieved
- 2026-09-17
- status
- 403 direct; read from an Internet Archive capture
- http
- 403
- id
- S33
- title
- DoD Cloud Security Playbook Overview
- publisher
- DoD CIO
- url
- https://dowcio.war.gov/
- date
- 2024-12-18
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S34
- title
- DoD Cloud Cyberspace Protection Guide
- publisher
- DISA
- url
- https://rmf.org/
- date
- 2017-10-16 (Change 1, 2017-12-19)
- retrieved
- 2026-09-17
- status
- 403 at the mirror; read from an Internet Archive capture; superseded in part by the current SRG
- http
- 403
- id
- S35
- title
- Cybersecurity Test and Evaluation Guidebook, cloud addendum
- publisher
- DoD (ac.cto.mil)
- url
- https://ac.cto.mil/
- date
- 2019-12-04
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S36
- title
- Army CIO issues cybersecurity service provider alignment guidance (memo of 2025-04-14)
- publisher
- ExecutiveGov (secondary)
- url
- https://www.executivegov.com/articles/army-cio-cybersecurity-service-providers-alignment-guidance
- date
- 2025-05-07
- retrieved
- 2026-09-17
- status
- read (secondary). The primary memo, armypubs ARN43551-PPM_CIO-070, was unreachable (DNS failure).
- http
- 200
- id
- S37
- title
- Army CIO policy memo CIO-070 (CSSP alignment)
- publisher
- Army Publishing Directorate
- url
- https://armypubs.army.mil/epubs/DR_pubs/DR_a/ARN43551-PPM_CIO-070-000-WEB-1.pdf
- date
- 2025-04-14
- retrieved
- 2026-09-17
- status
- unreachable (DNS resolution failed)
- http
- id
- S38
- title
- C5ISR Center first to receive certification in quality management in cybersecurity
- publisher
- U.S. Army
- url
- https://www.army.mil/article/253269/c5isr_center_first_to_receive_certification_in_quality_management_in_cybersecurity
- date
- 2021
- retrieved
- 2026-09-17
- status
- 429 Too Many Requests on fetch; indexed text only (C5ISR Center is an authorized DoD CSSP; one of two in the Army)
- http
- 429
- id
- S39
- title
- Enterprise Cloud Management Agency / cARMY
- publisher
- U.S. Army
- url
- https://www.army.mil/ecma
- date
- n/a
- retrieved
- 2026-09-17
- status
- read once, then 403; the CSSP sentence is indexed text only
- http
- 403
- id
- S40
- title
- ECMA officially assigned under ARCYBER
- publisher
- ARCYBER via DVIDS
- url
- https://www.dvidshub.net/news/573181/
- date
- 2026-08-25
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S41
- title
- ARCYBER–ECMA memorandum of agreement coverage
- publisher
- AFCEA SIGNAL (secondary)
- url
- https://www.afcea.org/signal-media/
- date
- 2023-06-13
- retrieved
- 2026-09-17
- status
- read (secondary)
- http
- 200
- id
- S42
- title
- AFARS 5111.106 (S-91) — Army use of JWCC for Secret (IL6) cloud requirements
- publisher
- acquisition.gov
- url
- https://www.acquisition.gov/afars/part-5111-describing-agency-needs
- date
- current
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S43
- title
- Cloud One service offerings
- publisher
- U.S. Air Force
- url
- https://cloudone.af.mil/
- date
- n/a
- retrieved
- 2026-09-17
- status
- read via the site's JavaScript bundle (CSSP Integration, Monitoring & Logging listed as offerings; accreditation inheritance from CSP, USAF, DoD and CSSP)
- http
- 200
- id
- S44
- title
- DoD software factory / Platform One site
- publisher
- U.S. Air Force
- url
- https://software.af.mil/
- date
- n/a
- retrieved
- 2026-09-17
- status
- read (Cloud One uses a CSSP to provide SIEM capabilities)
- http
- 200
- id
- S45
- title
- DoD Enterprise DevSecOps Initiative & Platform One (USAF CSO keynote v2.0)
- publisher
- U.S. Air Force, hosted by NIST
- url
- https://csrc.nist.gov/
- date
- PDF created 2021-02
- retrieved
- 2026-09-17
- status
- read (CNAP centralizes and pushes logs to the CSSP; the deck names C5ISR CSSP VPCs)
- http
- 200
- id
- S46
- title
- Department of the Navy Cloud Policy (ASN RD&A / DON CIO joint memo)
- publisher
- DON CIO
- url
- https://www.doncio.navy.mil/
- date
- 2020-12-07
- retrieved
- 2026-09-17
- status
- read (all DON cloud workloads shall be assigned to a CSSP)
- http
- 200
- id
- S47
- title
- Flank Speed — designed by PEO Digital, operated by NNWC, defended by NCDOC
- publisher
- DON CIO
- url
- https://www.doncio.navy.mil/
- date
- 2024-10-28
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S48
- title
- Neptune Cloud Management Office
- publisher
- DON CIO CHIPS; DVIDS
- url
- https://www.doncio.navy.mil/CHIPS/
- date
- 2023-08-16; 2025-12-02
- retrieved
- 2026-09-17
- status
- read (single point of entry for cloud services; GCP and OCI landing zones accredited through IL6; silent on CSSP and logging)
- http
- 200
- id
- S49
- title
- Beyond boundaries: DISA's cybersecurity solutions for a cloud-connected world
- publisher
- DISA Operations and Infrastructure Center via DON CIO CHIPS
- url
- https://www.doncio.navy.mil/Chips/ArticleDetails.aspx?ID=16566
- date
- 2023-12-20
- retrieved
- 2026-09-17
- status
- read by one reader; a second fetch was rejected by the host (DISA CSSP monitors 440+ customers; a cloud CSSP offering for Azure IL2–IL6)
- http
- 200
- id
- S50
- title
- DISA Stratus / Hybrid Cloud Solutions
- publisher
- DISA
- url
- https://hybridcloud.disa.mil/
- date
- n/a
- retrieved
- 2026-09-17
- status
- read via the site's bundle; the JWCC offering page requires sign-in
- http
- 200
- id
- S51
- title
- Lofty goals for the next version of the military cloud
- publisher
- AFCEA SIGNAL (secondary; quotes DISA's JWCC program manager and HaC director)
- url
- https://www.afcea.org/signal-media/defense-operations/lofty-goals-next-version-military-cloud
- date
- 2026-06-03
- retrieved
- 2026-09-17
- status
- read (45 business days average to award; JWCC Next becomes the JWCC Unified Cloud Marketplace with JWCC Core inside it; majority of workload is IL5 and IL6)
- http
- 200
- id
- S52
- title
- Department names vendors to provide Joint Warfighting Cloud Capability
- publisher
- DoD CIO / Department of Defense
- url
- https://dodcio.defense.gov/In-the-News/News-Display/Article/3267572/
- date
- 2022-12
- retrieved
- 2026-09-17
- status
- 403 (defense.gov release 3239378 also 403); indexed text only — four awardees, $9B ceiling, all classification levels
- http
- 403
- id
- S53
- title
- Where to send requirements packages / DAPPS (services.disa.mil/dapps-atat)
- publisher
- DISA DITCO
- url
- https://services.disa.mil/dapps-atat
- date
- current
- retrieved
- 2026-09-17
- status
- current DAPPS intake reachable; the retired 2024 requirements-package PDF said JWCC task order requests go through DAPPS
- http
- 200
- id
- S60
- title
- Landing Zone Accelerator on AWS — Implementation Guide
- publisher
- AWS
- url
- https://docs.aws.amazon.com/solutions/latest/landing-zone-accelerator-on-aws/
- date
- published 2022-05, last update 2025-12
- retrieved
- 2026-09-17
- status
- read (HTML and full PDF)
- http
- 200
- id
- S61
- title
- Landing Zone Accelerator on AWS — releases and changelog
- publisher
- AWS (GitHub, awslabs)
- url
- https://github.com/awslabs/landing-zone-accelerator-on-aws
- date
- v1.16.3, 2026-09-16
- retrieved
- 2026-09-17
- status
- read (releases API)
- http
- 200
- id
- S62
- title
- LZA Universal Configuration v1.3.1 — US Federal guidance, logging, log analysis, network and security configs
- publisher
- AWS (GitHub, aws)
- url
- https://github.com/aws/lza-universal-configuration
- date
- v1.3.1, 2026-09-02
- retrieved
- 2026-09-17
- status
- read (raw files)
- http
- 200
- id
- S63
- title
- Secure Cloud Computing Architecture on AWS for the US Department of Defense
- publisher
- AWS Prescriptive Guidance
- url
- https://docs.aws.amazon.com/prescriptive-guidance/latest/secure-architecture-dod/introduction.html
- date
- 2024-03-12
- retrieved
- 2026-09-17
- status
- read (PDF)
- http
- 200
- id
- S64
- title
- SCCA on AWS GovCloud (US) reference architecture diagram
- publisher
- AWS
- url
- https://d1.awsstatic.com/architecture-diagrams/ArchitectureDiagrams/dod-scca-multiaccount-ra.pdf
- date
- 2022-06-20
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S65
- title
- AWS Security Reference Architecture — Log Archive account
- publisher
- AWS Prescriptive Guidance
- url
- https://docs.aws.amazon.com/prescriptive-guidance/latest/security-reference-architecture/log-archive.html
- date
- undated
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S66
- title
- AWS Security Reference Architecture — Security Tooling account
- publisher
- AWS Prescriptive Guidance
- url
- https://docs.aws.amazon.com/prescriptive-guidance/latest/security-reference-architecture/security-tooling.html
- date
- undated
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S67
- title
- AWS GovCloud (US) User Guide — AWS CloudTrail
- publisher
- AWS
- url
- https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/govcloud-ct.html
- date
- current
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S68
- title
- AWS GovCloud (US) User Guide — Amazon CloudWatch (cross-account observability unavailable)
- publisher
- AWS
- url
- https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/govcloud-cw.html
- date
- current
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S69
- title
- AWS GovCloud (US) User Guide — CloudWatch Logs
- publisher
- AWS
- url
- https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/govcloud-cwl.html
- date
- current
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S70
- title
- AWS GovCloud (US) User Guide — AWS Config
- publisher
- AWS
- url
- https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/govcloud-config.html
- date
- current
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S71
- title
- AWS GovCloud (US) User Guide — AWS Control Tower
- publisher
- AWS
- url
- https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/govcloud-controltower.html
- date
- current
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S72
- title
- AWS GovCloud (US) User Guide — Amazon GuardDuty
- publisher
- AWS
- url
- https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/govcloud-guardduty.html
- date
- current
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S73
- title
- AWS GovCloud (US) User Guide — Security Hub CSPM
- publisher
- AWS
- url
- https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/govcloud-ash.html
- date
- current
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S74
- title
- AWS GovCloud (US) User Guide — AWS Security Hub
- publisher
- AWS
- url
- https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/govcloud-ashv2.html
- date
- current
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S75
- title
- AWS GovCloud (US) User Guide — Amazon Security Lake
- publisher
- AWS
- url
- https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/govcloud-asl.html
- date
- current
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S76
- title
- AWS GovCloud (US) User Guide — AWS Network Firewall (no differences)
- publisher
- AWS
- url
- https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/govcloud-nf.html
- date
- current
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S77
- title
- AWS GovCloud (US) User Guide — Amazon Route 53 (silent on Resolver query logging)
- publisher
- AWS
- url
- https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/govcloud-r53.html
- date
- current
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S78
- title
- AWS GovCloud (US) User Guide — Amazon S3 (silent on Object Lock; MFA delete unavailable)
- publisher
- AWS
- url
- https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/govcloud-s3.html
- date
- current
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S79
- title
- AWS GovCloud (US) User Guide — Data Firehose and Kinesis Data Streams (no differences)
- publisher
- AWS
- url
- https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/govcloud-kinesisfirehose.html
- date
- current
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S80
- title
- AWS Network Firewall — logging (alert, flow and TLS logs; S3, CloudWatch Logs or Firehose)
- publisher
- AWS
- url
- https://docs.aws.amazon.com/network-firewall/latest/developerguide/firewall-logging.html
- date
- current
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S81
- title
- Route 53 Resolver query logging
- publisher
- AWS
- url
- https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/resolver-query-logs.html
- date
- current
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S82
- title
- AWS services in scope by compliance program — DoD CC SRG
- publisher
- AWS
- url
- https://aws.amazon.com/compliance/services-in-scope/DoD_CC_SRG/
- date
- last updated 2026-09-16
- retrieved
- 2026-09-17
- status
- read (table parsed directly)
- http
- 200
- id
- S83
- title
- AWS DoD compliance page (GovCloud PAs at IL2/4/5; Secret Region PA up to Secret)
- publisher
- AWS
- url
- https://aws.amazon.com/compliance/dod/
- date
- undated
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S84
- title
- AWS Secret Cloud
- publisher
- AWS
- url
- https://aws.amazon.com/federal/secret-cloud/
- date
- undated
- retrieved
- 2026-09-17
- status
- read (IL6 and ICD 503 accreditation; service list deferred to S82)
- http
- 200
- id
- S85
- title
- AWS Security Hub now available in the AWS Secret Region
- publisher
- AWS What's New
- url
- https://aws.amazon.com/about-aws/whats-new/
- date
- 2025-05-12
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S86
- title
- AWS Organizations now available in the AWS Secret Region
- publisher
- AWS What's New
- url
- https://aws.amazon.com/about-aws/whats-new/
- date
- 2024-12-26
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S87
- title
- AWS Secret-West Region is now available
- publisher
- AWS What's New
- url
- https://aws.amazon.com/about-aws/whats-new/2025/10/aws-secret-west-region-is-now-available/
- date
- 2025-10-22
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S88
- title
- Cross-Domain Solutions on AWS (whitepaper; AWS Diode)
- publisher
- AWS
- url
- https://docs.aws.amazon.com/whitepapers/latest/cross-domain-solutions/
- date
- 2020-12 (marked for historical reference only)
- retrieved
- 2026-09-17
- status
- read
- http
- 200
- id
- S89
- title
- How to implement CNAP for federal and defense customers in AWS
- publisher
- AWS Public Sector Blog
- url
- https://aws.amazon.com/blogs/publicsector/how-implement-cnap-federal-dod-customers-aws/
- date
- 2022-07-25
- retrieved
- 2026-09-17
- status
- read (no CSSP or BCAP log-forwarding content)
- http
- 200
- id
- S90
- title
- Splunk Cloud Platform IL5 — validated architecture
- publisher
- Splunk
- url
- https://help.splunk.com/en/data-management/splunk-validated-architectures/splunk-cloud-platform/splunk-cloud-platform-il5
- date
- last updated 2026-02-02
- retrieved
- 2026-09-17
- status
- read (all customer traffic routes across NIPRNet through a DISA BCAP)
- http
- 200
- id
- S91
- title
- ThreatAlert ATO Accelerator
- publisher
- stackArmor (vendor)
- url
- https://stackarmor.com/accelerators/threatalert-ato-accelerator/
- date
- undated
- retrieved
- 2026-09-17
- status
- read (representative partner solution; never selected)
- http
- 200
- id
- S92
- title
- Second Front Systems achieves DISA provisional authorization (IL5)
- publisher
- Second Front Systems (vendor)
- url
- https://www.secondfront.com/resources/news/second-front-systems-achieves-disa-provisional-authorization/
- date
- 2025-09-16
- retrieved
- 2026-09-17
- status
- read (representative alternative; never selected)
- http
- 200
- id
- L01
- title
- AWS GovCloud / DoD landing zones — CSP corpus page (GovCloud security-service limits A-1 to A-7d)
- publisher
- Cloud Waypoint (internal, read-only)
- date
- 2026-09-17
- retrieved
- 2026-09-17
- status
- read
- http
- publication note
- Author-held method reference; not a public source.
- id
- L02
- title
- GSS reference diagram — AWS (LZA GovCloud as the base GSS)
- publisher
- Cloud Waypoint (internal, read-only)
- date
- 2026-09-17
- retrieved
- 2026-09-17
- status
- read
- http
- publication note
- Author-held method reference; not a public source.
- id
- L03
- title
- SOW traceability: what the standard Cloud Waypoint SOW promises and what the product produces
- publisher
- WWT / Cloud Waypoint (internal, read-only)
- date
- 2026-09-17
- retrieved
- 2026-09-17
- status
- read
- http
- publication note
- Author-held method reference; not a public source.
- id
- L04
- title
- Field guide — recording a CSSP handoff (WO-PORTFOLIO-020)
- publisher
- Cloud Waypoint (internal, read-only)
- date
- 2026-09-17
- retrieved
- 2026-09-17
- status
- read
- http
- publication note
- Author-held method reference; not a public source.
- id
- L05
- title
- Engine knowledge — the nine GSS decisions and the Annex D owner calls (05-R1 to R8)
- publisher
- Cloud Waypoint (internal, read-only)
- date
- 2026-09-17
- retrieved
- 2026-09-17
- status
- read
- http
- publication note
- Author-held method reference; not a public source.
- id
- L06
- title
- Engine schema — CONOPS annexes A to G
- publisher
- Cloud Waypoint (internal, read-only)
- date
- 2026-09-17
- retrieved
- 2026-09-17
- status
- read
- http
- publication note
- Author-held method reference; not a public source.