Transcription of DEPARTMENT OF DEFENSE (DoD) Secure Cloud Computing ...
1 I DEPARTMENT OF DEFENSE (DoD) Secure Cloud Computing Architecture (SCCA) Functional Requirements 1/ 31/2017 Developed by the DEFENSE Information Systems Agency (DISA) for the DEPARTMENT of DEFENSE (DoD)i TABLE OF CONTENTS Executive Summary .. 1 1 Introduction .. 2 Scope .. 2 DISN Boundary Security .. 2 DoD Cloud Hosted System Security .. 3 Cloud Governance .. 3 Implementation Guidance .. 3 Secure Cloud Computing Architecture technical Components and Topology .. 3 DoD Cloud Security Guidance .. 6 Networks and Topology .. 6 Cybersecurity Capabilities .. 9 Roles and Responsibilities .. 9 Capability Modularity, Decoupling and Applicability .. 10 Applicable Security Policies .. 11 Reference Documents .. 12 2 Functional Requirements .. 13 Security Requirements .. 15 Cloud Access Point .. 15 Virtual Datacenter Security Stack .. 19 Virtual Datacenter Managed Service.
2 21 Trusted Cloud Credential Manager .. 22 System Connectivity Requirements .. 24 DISN Connectivity .. 26 Mission Application Connectivity .. 27 Management Network Connectivity for Off-Premise CSO .. 27 Management Network Connectivity for On-Premise CSO .. 29 Optional Cyber Security and Interface Translation .. 31 Mission Support System Requirements .. 33 Mission Applications .. 33 Component Management .. 34 Performance Management .. 35 Draft ii 20141015 UNCLASSIFIED FOR OFFICIAL USE ONLY PDCN Requirements PDCN Requirements Version UNCLASSIFIED PDCN Requirements PDCN Requirements SCCA Requirements Security Information & Event Management (SIEM) .. 35 Full Packet Capture (FPC) .. 36 Performance Requirements .. 37 BCAP/ICAP Performance .. 38 VDSS Performance .. 38 VDMS Performance .. 39 Continuity of Operations Requirements .. 39 BCAP/ICAP Continuity of Operations.
3 39 VDSS Continuity of Operations .. 40 VDMS Continuity of Operations .. 40 System Scalability Requirements .. 41 BCAP/ICAP Scalability .. 41 VDSS Scalability .. 41 VDMS Scalability .. 42 Backup and Restoration Requirements .. 42 BCAP/ICAP Backup and Restoration .. 42 VDSS Backup and Restoration .. 43 VDMS Backup and Restoration .. 43 Appendix A: Acronyms and Abbreviations .. 44 Appendix B: Threat Definitions .. 47 Appendix C: Cloud Component Terminology .. 50 TABLE OF TABLES Table 1. Initial SCCA Threat Considerations .. 14 Table 2. BCAP Security Requirements .. 16 Table 3. ICAP Security Requirements .. 17 Table 4. VDSS Security Requirements .. 20 Table 5: VDMS Security Requirements .. 21 Table 6. TCCM Security 23 Table 7. DISN Connectivity Requirements .. 26 Table 8. Mission Application Connectivity .. 27 Table 9. Off-Premise Management Network Connectivity.
4 29 Table 10. On-Premise Management Network Connectivity .. 31 Table 11. Optional Cyber Security and Interface Translation .. 32 Table 12. Integration with Mission Applications .. 33 Draft iii 20141015 UNCLASSIFIED FOR OFFICIAL USE ONLY PDCN Requirements PDCN Requirements Version UNCLASSIFIED PDCN Requirements PDCN Requirements SCCA Requirements Table 13. Component Management Requirements .. 34 Table 14. Performance Management Requirements .. 35 Table 15. Security Information & Event Management Requirements .. 36 Table 16. Full Packet Capture (FPC) Requirements .. 37 Table 17. BCAP/ICAP Performance Requirements .. 38 Table 18. VDSS Performance Requirements .. 38 Table 19. VDMS Performance Requirements .. 39 Table 20. BCAP/ICAP Continuity of Operations 39 Table 21. VDSS Continuity of Operations Requirements .. 40 Table 22. VDMS Continuity of Operations Requirements.
5 40 Table 23. BCAP/ICAP Scalability Requirements .. 41 Table 24. VDSS Scalability Requirements .. 42 Table 25. VDMS Scalability Requirements .. 42 Table 26. BCAP/ICAP Backup and Restoration Requirements .. 42 Table 27. VDSS Backup and Restoration Requirements .. 43 Table 28. VDMS Backup and Restoration Requirements .. 43 TABLE OF FIGURES Figure 1. Cloud Computing Foundations .. 4 Figure 2. Secure Cloud Computing Architecture (SCCA) Components .. 5 Figure 3. Notional Cloud Service Provider Infrastructure & Networks .. 7 Figure 4. Notional DISN Management Networks .. 8 Figure 5. SCCA Component Alignment to Cybersecurity Organizations .. 10 Figure 6. SCCA Component Applicability .. 11 Figure 7. Notional SCCA System & Connectivity .. 25 Figure 8. Management Network Connectivity for Off-Premise CSO .. 28 Figure 9. Management Network Connectivity for On-Premise CSO .. 30 Draft iv 20141015 UNCLASSIFIED FOR OFFICIAL USE ONLY PDCN Requirements PDCN Requirements Version UNCLASSIFIED PDCN Requirements PDCN Requirements SCCA Requirements DOCUMENT INFORMATION CHANGE / REVISION RECORD Date Description of Change 01/16/2015 Initial functional requirements description 02/02/2015 Update on functional requirements document 02/09/2015 Updates to address results of 2/7/15 review with DISA leadership 2/13/2015 Updates to address results of 2/10/15 review with DISA leadership and MITRE Team Review 3/17/2015 Updates to address comments 4/2/2015 Update to address RE comments 4/10/2015 Update to address RE & CTO comments 4/22/2015 Update to address RE comments 6/15/2015 Update to address RE & CC/S/A comments 6/24/2015 Update to add network requirements 6/30/2015 Update to add CAP Extension Appendix 7/15/2015 Update to address
6 Administrative comments from PAO and removed FOUO marking. 10/30/2015 Update to address DoD community and CSP comments 2/23/2016 Renamed CAP FRD to SCCA FRD and updated to include SCCA components 10/31/2016 Update to address industry and DoD Component comments 1/31/2017 SCCA Pilot Team Inputs 1 Version UNCLASSIFIED SCCA Requirements Executive Summary As the DEPARTMENT of DEFENSE (DoD) strives to meet the objectives of the DoD CIO to maximize the use of commercial Cloud Computing , the DEFENSE Information System Network (DISN) perimeter and DoD Information Network (DoDIN) systems must continue to be protected against cyber threats. DISA is responsible for developing the DISN protection requirements and guidance to Secure the connection point to the Cloud Service Provider (CSP). DISA is well positioned to provide enterprise capabilities to Secure DoD Mission Owner systems deployed to the commercial Cloud .
7 The purpose of the Secure Cloud Computing Architecture (SCCA) is to provide a barrier of protection between the DISN and commercial Cloud services used by the DoD while optimizing the cost-performance trade in cyber security. The SCCA will proactively and reactively provide a layer of overall protection against attacks upon the DISN infrastructure and mission applications operating within the commercial Cloud . It specifically addresses attacks originating from mission applications that reside within the Cloud Service Environment (CSE) upon both the DISN infrastructure and neighboring tenants in a multi-tenant environment. It provides a consistent CSP independent level of security that enables the use of commercially available Cloud Service Offerings (CSO) for hosting DoD mission applications operating at all DoD Information System Impact Levels ( 2, 4, 5, & 6).
8 Requirements defined herein cover the array of CSOs to include Infrastructure-as-a-Service (IaaS), Platform-as-a-Service (PaaS), and Software-as-a-Service (SaaS). However, the authors have been careful to word requirements with sufficient specificity to address the DoD Cloud security posture while enabling innovation and allowing flexibility in implementations. The shared responsibility model is assumed to persist so that, where important for cost savings, identified security capabilities can be delivered by either DoD, commercial CSP, or 3rd party organizations. 2 Version UNCLASSIFIED SCCA Requirements 1 Introduction The DoD has made great strides in protecting the DoD Information System Network (DISN) from security threats at its boundary through Non- Secure Internet Protocol Router Network (NIPRNet) hardening initiatives. As the DoD move to maximize the use of commercial Cloud Computing , the DISN perimeter must continue to be protected against cyber threats from external connections.
9 As such, DISA is responsible for developing the requirements to support the DoD in implementing DISN perimeter protection at the connection point to multiple Cloud Service Providers (CSP). DISA is also well positioned to provide enterprise protection capabilities for mission applications and Mission Owner (MO) data hosted within the commercial Cloud Service Environment (CSE). This document provides a summary of the Secure Cloud Computing Architecture (SCCA) and its requirements based upon and analysis of possible attack vectors. The boundary requirements that were developed apply to all Cloud service offerings including: Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS). SCCA requirements have been developed based upon the DoD experiences covering successful implementations of commercial and other non-DoD systems. Such systems have included Internet Access Points (IAPs), NIPRNet Federated Gateway (NFG), and direct connections to approved contractor facilities.
10 SCCA requirements are intended to be consistent with Joint Information Environment (JIE) objectives1. Scope This document addresses functional requirements necessary to enable detection, protection, and response to cyber security threats against the DISN from Non-DoD on- or off-premise CSPs. It also provides functional requirements for the protection, detection, and response to cyber security threats against DoD systems deployed into commercial CSEs for all DoD Information System Impact Levels ( , 2, 4, 5, & 6). The requirements currently specified within this document pertain only to the security and associated interoperability necessary to facilitate Secure deployment and operations of DoD IT systems incorporating commercially owned Cloud based Information Technology (IT) services. The SCCA provides a capability and governance model, which is built upon guidance and requirements provided by the DoD Cloud Computing Security Requirements Guide (SRG)2.