www.giac.org




Is it Really Working?


The Department of Defense 8570 provides guidance and procedures for the training, certification, and management of the DoD workforce conducting Information Assurance functions in assigned duty positions. It also provides guidance on reporting metrics.

Agencies covered by 8570 include:
Who is affected by 8570?

Any full- or part-time military service member, contractor, or local nationals with privileged access to a DoD information system performing information assurance (security)functions -- regardless of job or occupational series.

The manual, 8570.01M, specifies that the Department of Defense requires approximately 110,000 identified Information Assurance professionals to be certified within a five year time period. The Defense Information Assurance Program office has divided its Information Assurance workforce into six defined categories (see chart below). The manual also specifies the types of commercial information assurance credentials that qualify for each of the defined categories.1

Are Agencies on track to get their people certified?

Obviously we do not have access to the official number, but we believe Agencies are running a bit behind. From the manual, year one was fiscal year 2006 and Agencies were to identify Information Assurance workforce positions and fill 10 percent of the IA positions with certified personnel.2 Most people agree that did not happen. Thereafter:

Is 8570 achieving its goals?

If we put the number of people that have completed the requirement aside, yes the program really is working well. Let's examine the goals and see.

The bottom line!

Agencies appear to be a bit behind in sending people to be trained and certifieddds and there is a bit of a lowest common denominator problem where some of the courses and certifications are not technical enough to meet the needs of the warfighter. However those are minor nits, overall, the program is clearly meeting its objectives. This was a very forward thinking program and it will benefit the Department of Defense for years to come.

  1. DoD 8570 — Overview
  2. DoD 8570 — Official Manual
  3. SANS® +S™ Training Program for the CISSP® Certification Exam
  4. CISSP Certification All-in-One Exam Guide, 4th Ed.
  5. SANS Security Leadership Essentials For Managers with Knowledge Compression™
  6. NIST SP 800
  7. www.giac.org
  8. GIAC Security Leadership Certification (GSLC)
  9. Why Certification Matters
  10. Global Information Assurance Certification (GIAC) Announces ANSI/ISO/IEC 17024 Accreditation
Number of certified professionals: 22,087
Network Security 2008 :: Las Vegas, NV :: Sep 28 - Oct 6, 2008