STIGQter STIGQter: STIG Summary: Traditional Security Checklist Version: 1 Release: 3 Benchmark Date: 15 Jun 2020:

Foreign National (FN) Systems Access - Local Nationals (LN) Overseas System Access - Vetting for Privileged Access

DISA Rule

SV-41430r3_rule

Vulnerability Number

V-31221

Group Title

FN System Access - Local Nationals (LN) Overseas Systems Access - (Privileged Access)

Rule Version

FN-02.01.02

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

When local foreign nationals are hired by DOD organizations overseas IAW the applicable SOFA and are assigned to Cyber Security (AKA: Information Assurance (IA)) positions of trust:

1. They must have successfully completed and comply with background investigation requirements (SSBI or equivalent)

2. They must not be assigned to any IAM Level III positions or IAT Level III positions of trust IAW DoD 8570.01-M, IA Workforce Improvement Program.

3. A Local National (LN) or Foreign National (FN) employed in an information system position of trust must always be supervised by a higher level IA position occupied by a US Government employee who is also a US citizen.

4. An Information Assurance Manager must never be a LN or FN.

Check Contents

When local foreign nationals are hired by DOD organizations overseas IAW the applicable Status of Forces Agreement (SOFA) and are assigned to Cyber Security (AKA: Information Assurance (IA)) positions of trust:

1. Check to ensure they comply with background investigation requirements (SSBI or equivalent) AND that they are not assigned to any IAM Level III positions or IAT Level III positions of trust IAW DoD 8570.01-M, IA Workforce Improvement Program.

2. Check to ensure that Local Nationals (LN) and Foreign Nationals (FN) are always supervised by a higher level Information Assurance (IA) position that is occupied by a US Government employee who is a US citizen.

3. Check to ensure that the Information Assurance Manager is never a LN/FN.

TACTICAL ENVIRONMENT: This check is applicable where LN/FN are employed in a tactical environment with access to US or Coalition Forces Systems.

Vulnerability Number

V-31221

Documentable

False

Rule Version

FN-02.01.02

Severity Override Guidance

When local foreign nationals are hired by DOD organizations overseas IAW the applicable Status of Forces Agreement (SOFA) and are assigned to Cyber Security (AKA: Information Assurance (IA)) positions of trust:

1. Check to ensure they comply with background investigation requirements (SSBI or equivalent) AND that they are not assigned to any IAM Level III positions or IAT Level III positions of trust IAW DoD 8570.01-M, IA Workforce Improvement Program.

2. Check to ensure that Local Nationals (LN) and Foreign Nationals (FN) are always supervised by a higher level Information Assurance (IA) position that is occupied by a US Government employee who is a US citizen.

3. Check to ensure that the Information Assurance Manager is never a LN/FN.

TACTICAL ENVIRONMENT: This check is applicable where LN/FN are employed in a tactical environment with access to US or Coalition Forces Systems.

Check Content Reference

M

Target Key

2506

Comments