1. Home
  2. Frameworks and Standards
  3. DoD 8500
  4. DoD 8500 – DCIT-1 – IA for IT Services

DoD 8500 – DCIT-1 – IA for IT Services

Overview

Acquisition or outsourcing of IT services explicitly addresses Government, service provider, and end user IA roles and responsibilities.

Threat

IA roles that are not clearly defined and expressed during the acquisition or outsourcing of IT services create a confusing environment where IA responsibility can be easily passed and accountability is nonexistent.  By clearly defining and expressing IA roles, organizations ensure IA ownership, accountability, and IA consideration throughout the entire systems lifecycle.

Guidance

During acquisition or outsourcing of IT services, contracts and other documentation identifying roles shall include  Government, service provider, and end user IA roles and responsibilities for example: PM, IAM, User Representative, CA, DAA, SIAO, and CIO.

DoD classifies this control in the subject area of “Security Design and Configuration” with a impact of “High”.

Reference(s)

Updated on July 16, 2022
Was this article helpful?

Related Articles