Skip to main content
U.S. Department of Energy
Office of Scientific and Technical Information

An Analysis of Department of Defense Instruction 8500.2: ‘Information Assurance (IA) Implementation’

Technical Report ·
DOI:https://doi.org/10.2172/1034875· OSTI ID:1034875
 [1]
  1. Sandia National Laboratories (SNL-NM), Albuquerque, NM (United States)

The Department of Defense (DoD) provides its standard for information assurance in its Instruction 8500.2, dated February 6, 2003. This Instruction lists 157 'IA Controls' for nine 'baseline IA levels.' Aside from distinguishing IA Controls that call for elevated levels of 'robustness' and grouping the IA Controls into eight 'subject areas' 8500.2 does not examine the nature of this set of controls, determining, for example, which controls do not vary in robustness, how this set of controls compares with other such sets, or even which controls are required for all nine baseline IA levels. This report analyzes (1) the IA Controls, (2) the subject areas, and (3) the Baseline IA levels. For example, this report notes that there are only 109 core IA Controls (which this report refers to as 'ICGs'), that 43 of these core IA Controls apply without variation to all nine baseline IA levels and that an additional 31 apply with variations. This report maps the IA Controls of 8500.2 to the controls in NIST 800-53 and ITGI's CoBIT. The result of this analysis and mapping, as shown in this report, serves as a companion to 8500.2. (An electronic spreadsheet accompanies this report.)

Research Organization:
Sandia National Laboratories (SNL-NM), Albuquerque, NM (United States)
Sponsoring Organization:
USDOE National Nuclear Security Administration (NNSA)
DOE Contract Number:
AC04-94AL85000
OSTI ID:
1034875
Report Number(s):
SAND--2012-0110
Country of Publication:
United States
Language:
English

Similar Records

A threat-based definition of IA and IA-enabled products.
Conference · Wed Sep 01 00:00:00 EDT 2010 · OSTI ID:1027081

A threat-based definition of IA- and IA-enabled products.
Conference · Thu Jul 01 00:00:00 EDT 2010 · OSTI ID:1022168

The evolving story of information assurance at the DoD.
Technical Report · Sun Dec 31 23:00:00 EST 2006 · OSTI ID:902561