DIACAP has been in force for more that 3 years so a system with a DITSCAP authorization has an EXPIRED authorization and the DAA should issue a DATO immediately unless the system owner can provide justifcation for continued operation AND sufficient documentation to allow the CA to evaluate the risk of continued operation and for DAA to accept the risk and issue an IATO until a full re-accreditation can be completed. Note that the DoD will soon be moving to RMF (risk management framework) so DITSCAP will be WAY, WAY out of date then!
Contact the DAA to request an IATO while you hurry up and get your act together and get the DIACAP documentation together before they shut the system down!
Continue DITSCAP for a set period of time
C. Continue DITSCAP This might have been a correct answer to a quiz in the past, but DoDI 5200.40 (DITSCAP) and DoD 8510.1-M (DITSCAP Manual) were cancelled when DoDI 8510.01 (DIACAP) was issued on November 28, 2007. If a system does not have a signed Phase One System Security Authorization Agreement (SSAA) they are required to conduct their certification and accreditation under DIACAP. Anything prepared under DITSCAP is useful only as reference material to aid in preparing the DIACAP documentation.
Since under 8500.2, an ATO cannot be issued for more than 3 years, if a system is operating under a DITSCAP package that is 4 years old, its ATO has expired and the DAA can (and should) issue a DATO (Denial of Authorization To Operate), meaning that the system is immediately denied ATC (Authority To Connect), which means it is then cut off from the GIG. Even if the system is not connected to the GIG, a DATO means that the system must be shut down and not used until it gets at least an IATO from the DAA.
The system's IA controls must be reviewed at least annually and the system must be reaccredited at least every three years
DITSCAP is the outdated version of the DoD process for assessing the security of DoD information systems. It was replaced by DIACAP. DIACAP is, in turn, being replaced by the RMF process where continuous montoring is to be implemented.DIACAP :Platform-centric as opposed to system or network centric.Information belongs to system owner and risks are identified specific to the systemIndividual C/S/A defined IA controlsCertification appointed Certification Authority
Dependant on people
authorization
As an individual, you can't. An information system is what gets accredited for use in the military environment. If you are interested in individual security certification, start with the CompTIA Security+ certification and when you have lots of experience and knowledge, try the Certified Information Systems Security Professional (CISSP) exam. For the information system accreditation, you start by identifying the military Information Assurance (IA) office that will be handling your system, and then work closely with them to identify and then fulfill their requirements to obtain an Authorization to Operate (ATO).
The three types in information system are used to by companies on benefits do they provide
In most cases, the town or city you live in grants a franchise or "rights to service your area" to one cable TV company.
Training Ammunition Management Information System (TAMIS)