Common questions

What is considered critical program information?

What is considered critical program information?

According to DoDI 5200.39, Critical Program Information, or CPI, is defined as U.S. capability elements that contribute to U.S. warfighters’ technical advantage, and that, if compromised, could undermine U.S. military preeminence.

What is a key component of a program protection plan PPP?

The PPP document includes five appendices: Security Classification Guide (SCG), Counterintelligence Support Plan (CISP), Criticality Analysis, Anti-Tamper (AT) Plan, and the Cybersecurity Strategy.

What is the objective of the program protection plan PPP?

The goal of program protection is to help programs identify and implement the most appropriate mix of measures to protect the program and system information, components, and technologies from the known security threats and attacks across the acquisition life cycle.

What is a program protection implementation plan?

The PPIP is the principle communications means for validation and approval by the DoD or Component Program Manager of the specific methods used by the contractor to (1) identify the means chosen to the PPP at contractor, sub-contractor, vendor controlled locations and (2) provide protection inputs to the system …

What is horizontal protection?

The Horizontal Protection Program ensures that DoD acquisition programs developing new or revised Program Protection Plans (PPP) have access through a standard DoD-wide automated system. Access to the database allows the programs to compare levels of classification and sensitivity.

Which step in the seven step process to establish a program protection plan?

Why is this seven-step process needed?

  • Identify.
  • Protect.
  • Detect.
  • Respond.
  • Recover.

Who creates the program protection plan?

Program Management Office
Developing the Program Protection Plan (PPP) Coordination between the Program Management Office (PMO) and supporting Counterintelligence (CI) and security activities is critical to ensure that any changes in the system CPI, threat, or environmental conditions are communicated to the proper organizations.

What is CIL OPSEC?

The Critical Information List (CIL) includes specific facts about friendly intentions, capabilities, and activities needed by adversaries to plan and act effectively against friendly mission accomplishment.

Which authority ensures horizontal identification and protection?

DoD Component heads ensure horizontal identification and protection of CPI, utilizing the Acquisition Security Database (ASDB) when conducting horizontal identification and protection analysis.

Which of the following is one of the five pillars of cybersecurity?

The U.S. Department of Defense has promulgated the Five Pillars of Information Assurance model that includes the protection of confidentiality, integrity, availability, authenticity, and non-repudiation of user data.

What is critical program information analysis?

Critical Program Information (CPI) Analysis CPI analysis is the means by which programs identify, protect, and monitor CPI. This analysis should be conducted early and throughout the life cycle of the program. Additionally, because CPI is critical to U.S. technological superiority, its value extends beyond any one program.

What is a program Protection Plan (PPP)?

The Program Protection Plan (PPP) is the single source document used to coordinate and integrate all protection efforts. It’s designed to deny access to Critical Program Information (CPI) to anyone not authorized, not having a need to know and prevent inadvertent disclosure of leading-edge technology to foreign interests.

Who should publish a Program Improvement Plan (PPP)?

Any program, product, technology demonstrator, or other item developed as part of a separate acquisition process and used as a component, subsystem, or modification of another program should publish a PPP. The effectiveness of the PPP is highly dependent upon the quality and currency of the information available to the program office.

What does PPP stand for?

Program Protection Plan (PPP) The Program Protection Plan (PPP) is the single source document used to coordinate and integrate all protection efforts.