STIGQter STIGQter: STIG Summary: Traditional Security Checklist Version: 2 Release: 9 Benchmark Date: 01 Jul 2026:

Information Assurance - Accreditation Documentation

DISA Rule

SV-245778r1207698_rule

Vulnerability Number

V-245778

Group Title

IA-07.02.01

Rule Version

IA-07.02.01

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. A current accreditation document approved by the AO must be available for all systems and applications connected to the DODIN.

2. Copies of the original accreditation documentation along with any subsequent modifications must be available for review.

3. The Approval to Operate (ATO) or Interim Approval to Operate (IATO) must be up to date and must be signed by the current Approving Authority.

4. Check to ensure the site provided the DISN Connection Approval Office (CAO) current certification documentation IAW CAO guidance.

5. Check to ensure the site also has notified the CAO of any changes/modification to the approved architecture.

6. Check to ensure the Approval to Connect (ATC) or Interim Approval to Connect (IATC) for both SIPRNet/NIPRNet are current.

Check Contents

Check the accreditation package with only a cursory review to ensure the ATO/IATO are current.

1. Check the SIPRNet/NIPRNet connection approval package. Conduct a cursory review for any traditional security issues.

2. Ensure the approvals are current. The approvals must come from the DISN Connection Approval Office (CAO).

TACTICAL ENVIRONMENT: The check is applicable. The ATO and associated documentation should be found in a fixed HQ location where the ISSM/ISSO are located. When possible, documentation should be requested/sought before departing on trips to tactical locations. Copies sent to the reviewer's email (NIPR or SIPR depending on classification of document) can be used to validate compliance.

Note: If any one of the approvals is missing, this is a finding.

Vulnerability Number

V-245778

Documentable

False

Rule Version

IA-07.02.01

Severity Override Guidance

Check the accreditation package with only a cursory review to ensure the ATO/IATO are current.

1. Check the SIPRNet/NIPRNet connection approval package. Conduct a cursory review for any traditional security issues.

2. Ensure the approvals are current. The approvals must come from the DISN Connection Approval Office (CAO).

TACTICAL ENVIRONMENT: The check is applicable. The ATO and associated documentation should be found in a fixed HQ location where the ISSM/ISSO are located. When possible, documentation should be requested/sought before departing on trips to tactical locations. Copies sent to the reviewer's email (NIPR or SIPR depending on classification of document) can be used to validate compliance.

Note: If any one of the approvals is missing, this is a finding.

Check Content Reference

M

Target Key

5410