STIGQter STIGQter: STIG Summary: Traditional Security Checklist Version: 1 Release: 3 Benchmark Date: 15 Jun 2020:

Counter-Intelligence Program - Training, Procedures and Incident Reporting

DISA Rule

SV-42944r3_rule

Vulnerability Number

V-32607

Group Title

Counter-Intelligence Program - Training, Procedures and Incident Reporting

Rule Version

SM-03.03.01

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Background Information:

It is DoD policy that:
a. Initial and annual CI awareness and reporting (CIAR) training on the foreign intelligence entity (FIE) threat, methods, reportable information, and reporting procedures shall be provided to DoD personnel as outlined in Enclosure 3 of DoDD 5240.06, 17 May 11 .
b. Potential FIE threats to the DoD, its personnel, information, materiel, facilities, and
activities, or to U.S. national security shall be reported by DoD personnel in accordance with
Enclosure 4 of DoDD 5240.06.
c. Failure to report FIE threats as identified in paragraph 3.a and section 5 of Enclosure 4 of
DoDD 5240.06 may result in judicial or administrative action or both pursuant to applicable law or policy.

Fixes:

Ensure all assigned site/organization personnel have received both initial and annual CIAR training in accordance with DoDD 5240.06. Further, ensure there are procedures for reporting possible threat information and that local threat assessments and warnings received are properly shared with the work force.

Check Contents

Background Information:

It is DoD policy that:
a. Initial and annual CI awareness and reporting (CIAR) training on the foreign intelligence entity (FIE) threat, methods, reportable information, and reporting procedures shall be provided to DoD personnel as outlined in Enclosure 3 of DoDD 5240.06, 17 May 11 .
b. Potential FIE threats to the DoD, its personnel, information, materiel, facilities, and
activities, or to U.S. national security shall be reported by DoD personnel in accordance with
Enclosure 4 of DoDD 5240.06.
c. Failure to report FIE threats as identified in paragraph 3.a and section 5 of Enclosure 4 of
DoDD 5240.06 may result in judicial or administrative action or both pursuant to applicable law or policy.

Checks:

Check #1. Check to ensure all assigned site/organization personnel have received both initial and annual CIAR training in accordance with DoDD 5240.06.

Check #2. Check to ensure there are procedures for reporting possible threat information and that local threat assessments and warnings received are properly shared with the work force.

TACTICAL ENVIRONMENT: The check is applicable for fixed (established) tactical processing environments. Not applicable to a field/mobile environment.

Vulnerability Number

V-32607

Documentable

False

Rule Version

SM-03.03.01

Severity Override Guidance

Background Information:

It is DoD policy that:
a. Initial and annual CI awareness and reporting (CIAR) training on the foreign intelligence entity (FIE) threat, methods, reportable information, and reporting procedures shall be provided to DoD personnel as outlined in Enclosure 3 of DoDD 5240.06, 17 May 11 .
b. Potential FIE threats to the DoD, its personnel, information, materiel, facilities, and
activities, or to U.S. national security shall be reported by DoD personnel in accordance with
Enclosure 4 of DoDD 5240.06.
c. Failure to report FIE threats as identified in paragraph 3.a and section 5 of Enclosure 4 of
DoDD 5240.06 may result in judicial or administrative action or both pursuant to applicable law or policy.

Checks:

Check #1. Check to ensure all assigned site/organization personnel have received both initial and annual CIAR training in accordance with DoDD 5240.06.

Check #2. Check to ensure there are procedures for reporting possible threat information and that local threat assessments and warnings received are properly shared with the work force.

TACTICAL ENVIRONMENT: The check is applicable for fixed (established) tactical processing environments. Not applicable to a field/mobile environment.

Check Content Reference

M

Target Key

2506

Comments