|
|
Contents
Table A-7. Abbreviations for Table A-4
A-20
Table B-1. A-GNOSC and TNOSC NETOPS tools list
B-1
Table B-1. A-GNOSC and TNOSC NETOPS tools list (continued)
B-2
Table B-1. A-GNOSC and TNOSC NETOPS tools list (continued)
B-3
Table B-1. A-GNOSC and TNOSC NETOPS tools list (continued)
B-4
Table B-1. A-GNOSC and TNOSC NETOPS tools list (continued)
B-5
Table F-1. IA management responsibilities of LIAA CND protection levels
F-14
Table F-2. IAM training requirements
F-17
Table F-3. IANM/IANO training requirements
F-17
Table F-4. IASO training requirements
F-18
Table F-5. System administrator/Network manager training requirements
F-19
Table F-6. Scanning guidelines/actions
F-20
Table F-7. Remediation actions
F-21
Table I-1. Operation and maintenance responsibilities for JNN-N hub node services
I-12
Table I-2. Configuration and management responsibilities for JNN-N hub node
equipment
I-12
Table I-3. Centrally hosted user services
I-14
19 November 2008
FMI 6-02.71
v
FOR OFFICIAL USE ONLY
Preface
FM 6-02.71 provides doctrine for the overall guidance and direction pertaining to the command and control of
Army communications networks (voice, video, and data) and information services (collaboration, messaging,
storage, mediation, etc.) throughout strategic, operational, and tactical levels. It describes the Army’s portion of
the Global Information Grid ( hereafter referred to as LandWarNet), network operations goals and objectives,
and the associated roles and responsibilities of applicable organizations, materiel, leadership, personnel, and
facilities that must integrate LandWarNet standards, telecommunications, services, and applications for the
purpose of enabling warfighters to conduct the information management and knowledge management tasks
necessary to meet achieve information superiority and decision dominance.
The network operations construct is an integrated operational framework consisting of network
management/enterprise systems management, information assurance/computer network defense, and information
dissemination management/content staging. This manual provides a general functional understanding of each
network operations component, along with an understanding of why the components must be integrated in order
to meet overall objectives.
As stated, network operations are critical to the command and control of organizational communications
networks and information services that enable commanders to use the network in order to shape and influence
operations. Its principles allow for assured network and information system availability, assured information
protection, and assured information delivery. The result is a horizontal fusion of information that flows to the
right place, at the right time, and in the right format in order to attain information superiority and decision
dominance over any adversary.
This publication has been prepared under the direction of the Commander, TRADOC. It sets forth doctrine to
govern the activities and performance of the Army in reference to network operations and provides the doctrinal
basis for establishing interoperability in a joint, interagency, multinational environment. It provides military
guidance for the exercise of authority by commanders. With that stated, it is not the intent of this publication to
restrict the authority of commanders from organizing the force and executing the mission in a manner they deem
most appropriate to ensure unity of effort in the accomplishment of the overall objective.
The guidance in this publication is authoritative; as such, this doctrine will be followed except when, in the
judgment of the commander, exceptional circumstances dictate otherwise. If conflicts arise between the
contents of this publication and the contents of other publications, this publication will take precedence unless
the Commander, TRADOC.
The proponent of this publication is the United States Army Signal Center. Send comments and
recommendations on DA Form
2028
via
e-mail to signal.doctrine@conus.army.mil or
signal.doctrine@us.army.mil. Key your comments and recommendations to pages and lines of text to which they
apply. Provide reasons for your comments to ensure understanding and proper evaluation.
Mailing address is Commander, United States Army Signal Center and Fort Gordon, ATTN: ATZH-IDC-CB
(Doctrine Section), Building 29808, 506 Chamberlain Ave, Fort Gordon, GA 30905-5075.
Unless this publication states otherwise, masculine nouns and pronouns do not refer exclusively to men.
19 November 2008
FMI 6-02.71
vi
FOR OFFICIAL USE ONLY
Chapter 1
Network Operations Overview
This chapter discusses the Global Information Grid (GIG), the Army’s portion of the
GIG - LandWarNet (LWN), and the integrated components of network operations
(NETOPS) used to command and control LWN across strategic, operational, and
tactical levels in support of commanders’ information requirements. This chapter
additionally discusses the functional services, critical capabilities, and effects
enabled by each component. The chapter concludes by mentioning the principles
associated with NETOPS, as well as the Army enterprise network infrastructure
concept utilized to integrate network processes across full spectrum operations.
SECTION I - GLOBAL INFORMATION GRID
1-1. Joint Publication
(JP)
6.0 defines the GIG as
―the globally interconnected, end-to-end set of
information capabilities, associated processes and personnel for acquiring, processing, storing, transporting,
controlling, and presenting information on demand to joint forces and support personnel.‖ The GIG—
z
Spans all services and components and includes all owned and leased computing systems,
communications, software and applications, data, security services, and other information
services necessary to achieve information superiority.
z
Supports all Department of Defense
(DOD), national security, and related intelligence
community missions and functions (strategic, operational, tactical, and business).
z
Extends capabilities from all operating locations (bases, posts, camps, stations, facilities, mobile
platforms, and deployed sites).
z
Provides interfaces to multinational, coalition, non-DOD users, and systems as required.
z
Integrates computing platforms, weapons systems, and sensors that exchange information
through a globally interconnected network.
1-2. In concept, the GIG is very much like the Worldwide Web. It exists as a baseline capability and is
comprised of information and information services residing on transporting infrastructures and segments. It
is important to note that the GIG is a portion of cyberspace. The DOD definition of cyberspace is ―the
global domain consisting of interdependent networks of information technology infrastructures, and
includes the internet, telecommunications networks, computer systems, and embedded processors and
controllers.‖ The GIG, as the DOD’s portion of cyberspace, interacts with and provides connections to
national and global cyberspace, the national information infrastructure and global information infrastructure
respectively. DOD's strategy is to create the cyberspace domain by integrating the seven components of the
GIG (warrior, global applications, computing, communications, NETOPS, information management, and
foundation as described in Figure 1-1) in order to enable joint forces to achieve information superiority, as
well as in the future, allow them to conduct offensive cyberspace operations when necessary. Authorized
users access the GIG and its services either through military or commercial communications or through a
series of entry points, e.g., standardized tactical entry point (STEP) and teleport facilities. These points
provide information transfer gateways as a means of forming a junction of space-based, aerial, and
terrestrial networks and a connection for strategic or fixed assets and tactical or deployed users. It provides
multiple connection paths between information users and information producers and enables effective and
efficient information flow.
19 November 2008
FMI 6-02.71
1-1
FOR OFFICIAL USE ONLY
Chapter 1
GLOBAL INFORMATION GRID COMPONENTS
Warrior Components Connects
warfighters and their combat platforms to the
network.
Warrior Components
Global Applications The set of
information applications used by the Warfighter.
MEDICAL
Global Combat
Business
Computing DOD hardware, software,
Support System
Applications
and processes, including search services,
Global Applications
shared data ware-housing, software
distribution, e-mail delivery, web services,
Software Distribution
collaboration services, common directories,
Electronic Mail
Web Services
Mega Member
and data services.
Delivery
Service
Computing
Communications
Provide common-user
information transport and processing services
SATCOM
Wireless
to all DOD users—extends from base, post,
Commercial Fiber
Com
camp, and station, through the strategic
DISN
networks to the last tactical mile.
MSS
RF NETS
Communications
Foundation Anchors the enterprise
DOCTRINE
POLICY
STANDARDS
through standards, doctrine, policy,
compliance, architecture, testing, spectrum,
SPECTRUM
ENGINEERING
and host nation approval.
ARCHITECTURE
GOVERNANCE
Foundation
Network Operations Provides the integrated, secure end-to-end
Information Management Controlling and
management of networks and applications across the GIG. It also
prioritizing of information through its life cycle -
includes information assurance and content staging/information
creation or collection, processing, dissemination,
dissemination management (awareness, access, and delivery of the right
use storage and disposition.
information, in the right place, at the right time).
Figure 1-1. Global Information Grid
1-3. At the joint level, NETOPS is the operational construct implemented by the Commander, United
States Strategic Command (CDRUSSTRATCOM) that provides the command and control and situation
awareness
(SA) required to operate and defend the GIG. NETOPS consists of GIG Enterprise
Management, GIG Network Defense, and GIG Content Management. The purpose of NETOPS is to
provide assured network and information system availability, assured information protection, and assured
information delivery across strategic, operational, and tactical boundaries. The end result is a horizontal
fusion across the GIG that ensures the right information flows to the right place, at the right time, and in the
right format in order to achieve information superiority, and ultimately decision dominance. This supports
the DOD’s full spectrum of warfighting functions. NETOPS provides commanders the ability to harness the
power of GIG and bring this power to the battlefield in order to shape and influence operations.
GLOBAL INFORMATION GRID GOVERNING BODIES
1-4. The governing bodies of the GIG are the Theater Joint Tactical Network Configuration Control
Board (TJTNCCB), The Army Enterprise Infostructure Technical Configuration Control Board (CCB) and
AENIA. These governing bodies have been empowered to approve, oversee, and enforce standards to
ensure a shared view of the network through compatibility of equipment and software. The new
registry/management tool for Information Technology Standard is the DOD Information System Registry.
1-2
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Overview
JOINT TECHNICAL ARCHITECTURE-ARMY
1-5. The joint technical architecture-Army (JTA-A) requires all Army networks to use proven engineering
criteria and modern communications equipment and technologies that are standard across the GIG. The use
of standards ensures compatibility between US forces.
THEATER JOINT TACTICAL NETWORK CONFIGURATION CONTROL BOARD
1-6. The TJTNCCB governs tactical network and system equipment standards and capabilities. These
standards lead to a common baseline of equipment and software throughout the tactical portion of the GIG.
The Joint Tactical Switched Systems Network Management Configuration Control Board (JTSSNMCCB)
grants exceptions and extensions under the following conditions:
z
Nonstandard prototype capability fielding is an addition to the standard baseline fielding.
z
Nonstandard capability is unique to a particular location and will be submitted to the TJTNCCB
as an annex, but is not intended to become part of the standard configuration.
z
Nonstandard capability is critical to a specific mission and not intended for use beyond the scope
and time of the particular mission. If the nonstandard capability evolves into a recurring required
capability, it must be submitted to the JTSSNMCCB for inclusion either as an annex or as a part
of the standard configuration.
ARMY ENTERPRISE INFOSTRUCTURE TECHNICAL CONFIGURATION CONTROL BOARD
1-7. The Army Enterprise Infostructure Technical CCB was established by the CIO/G-6 to oversee the
Army LWN Enterprise using standard change management to process the request for change submitted by
Army organizations wanting to change their LWN infrastructure. NETCOM has the responsibility for
configuration/change management.
1-8. NETCOM/9th SC(A) manages and maintains the Networthiness Regulatory Authority’s network
responsibilities and technical oversight over all organizations that operate and maintain portions of the
LWN per Field Manual (FM) 3-0; AR 25-1, Para 2-2a(10); and AR 10-87.
LANDWARNET NETWORK OPERATIONS
Note. Global information grid enterprise management (GEM), global information grid network
defense (GND), and global information grid content management (GCM) are joint and global
network terms. These components at the LWN level are referred to as network
management/enterprise systems management
(NM/ESM), information assurance/computer
network defense (IA/CND), and information dissemination management and content staging
(IDM/CS) respectively. For the purpose of this field manual (FM), the terms refer to the same
NETOPS processes at the GIG or LWN levels of the network. This construct aligns LWN
NETOPS processes with the GIG NETOPS processes.
1-9. Inherent to the Joint mission, the Army’s NETOPS mission is to provide command and control and
situational awareness in order to operate and defend its portion of the GIG- the LWN. LWN encompasses
the required standards, transport, services, and applications that enable warfighters to collect, process, store,
transmit, and disseminate required information via the network from and to anywhere in the world. It
enables the effective and efficient execution of all Army warfighting functions and facilitates the
achievement of information superiority, which is necessary to make and execute accurate and timely
decisions. It allows commanders to exercise command and control from anywhere in their area of
operations. Unlike many missions that are deemed successful at a defined completion date, operating and
defending LWN is perpetual and requires continual support to be successful.
1-10. LWN NETOPS is an integrated construct of three critical components (NM/ESM, IA/CND, and
IDM/CS) that guide Signal entities in the installation, management, and protection of communications
19 November 2008
FM 6-02.71
1-3
FOR OFFICIAL USE ONLY
Chapter 1
networks and information services necessary to directly support operational forces. NETOPS provides
users/systems, at all levels, with end-to-end network and information system availability, information
protection, and timely information delivery.
1-11. An objective of the network-enabled management of information is to quickly get information to
decision-makers, with adequate context, enabling them to make better decisions affecting the mission and to
project their decisions forward to their forces for execution. If the decision maker is not getting the needed
network-enabled services, the LWN NETOPS community must collaboratively determine who will take
action and how information flow will be optimized. NETOPS personnel require a shared situational
awareness/common operating picture; as well as the technologies, procedures, and collaborative
organizational structures; to rapidly assess and respond to network and information system degradations,
outages, or changes in operational priorities. All functions required to effectively support LWN operations
will be holistically managed.
1-12. Information systems throughout areas of operations compete for the limited LWN access and
capacity. NETOPS provides the means to operate and defend LWN transport, services, and applications in
order to meet the commander’s intent and priorities. This allows for better user/system support by—
z
Identifying the information requirements (who, what, when, and where) of the user/system.
z
Identifying the communications network and information service resources
(hardware and
software) required to fulfill user/system information requirements.
z
Ensuring user/system access to the required communications networks and information services.
z
Protecting the confidentiality, integrity, and availability of information and information systems
with IA/CND measures coupled with the use of intelligence to enable threat-based risk
management.
z
Ensuring the establishment of information flows and information processing so that the right
information is disseminated to the right place, at the right time, and in the right format.
z
Identifying the resource requirements necessary to enable the wired, fiber, and wireless portion
of the network.
z
Ensuring that the allotment of resources is effectively utilized to efficiently maximize the
bandwidth available to the user/system.
1-13. The effectiveness of NETOPS is measured in terms of availability and reliability of network enabled
services, across all areas of interest, in adherence to required service levels. The method for service
assurance in a network-enabled collaborative environment is to establish operational thresholds, compliance
monitoring, and a clear understanding of the capabilities between providers and consumers through service
level agreements (SLAs). Proper instrumentation of the LWN enables monitoring of adherence to these
SLAs, as well as enables timely decision making/execution, service prioritization, resource allocation, root
cause, and mission impact assessment.
1-14. The purpose of NETOPS is to provide assured network and information system availability,
assured information protection, and assured information delivery. These objectives are all required to
achieve and sustain operational goals. Adhering to the NETOPS mission and performing the essential tasks
associated with the three NETOPS components provides warfighters with the desired information effects.
Integration of the NETOPS components must be performed at the strategic, operational, and tactical levels
and across all warfighting functions. Thus, Signal entities must command and control the entire network
within the operational area and be cognizant of the performance of those portions of the LWN outside of the
operational area that affect the information requirements of the commander.
NETWORK OPERATIONS COMPONENTS AND EFFECTS
1-15. Assured network availability provides visibility and control over the network and information system
resources. These resources are effectively managed and problems are anticipated and mitigated. Proactive
measures are taken to ensure the uninterrupted availability and protection of the network and information
system resources. This includes providing for graceful degradation, self-healing, fail over, diversity, and
elimination of critical failure points.
1-4
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Overview
1-16. Assured information protection provides protection for the information traversing networks and
residing on information systems - from the time it is collected, stored, and processed until it is discovered,
distributed, and utilized by the users, systems, and decision makers. Information protection is active or
passive measures to protect and defend friendly information and information systems to ensure friendly
access to timely, accurate, and relevant information while denying adversaries the opportunity to exploit
friendly information and information systems for their own purposes. Information protection comprises
information assurance (IA), computer network defense (CND), and electronic protect capabilities (FM 3-0).
1-17. Assured information delivery provides information to users, systems, and decision makers in a timely
manner. The networks are continuously monitored to ensure the information is transferred with the correct
response time, throughput, availability, and performance that meet user/system needs.
1-18. NETOPS is the methodical integration of NM/ESM, IA/CND, and IDM/CS components’ individual
capabilities and the resultant synergy. In addition, NM/ESM, IA/CND, and IDM/CS are the Signal
Regiment’s core competencies. Figure 1-2 depicts and establishes a common understanding of the technical
composition that must be considered to provide and sustain the effects of NETOPS. The center of the
diagram illustrates the three NETOPS components, their relationships, and the desired effects once they are
transformed into a tightly integrated NETOPS capability.
1-19. The three NETOPS critical components are discussed in the following sections.
Information Superiority for the Warfighter
Right Information - Right User Right
Time - Right Protection Horizontal
Fusion Across The GIG
Connect Route
Process
Flow
Account
Allocate
Maintain
Configure
ESM/NM
Assured Information
Assured System &
Delivery
Network Availability
Resist
Retrieve
NETOPS
Cache
Recognize
IA/CND IDM/CS
Compile
Respond
Recover
Catalog
Reconstitute
Distribute
Assured Information
Protection
Figure 1-2. NETOPS components, effects, and objectives
NETWORK MANAGEMENT/ENTERPRISE SYSTEMS MANAGEMENT
1-20. NM/ESM is defined as the technologies, processes, and policies necessary to effectively and
efficiently engineer, install, operate, manage, administer, optimize, and restore communications networks,
information systems, and/or applicable applications that comprise the LWN. This essential component
merges information technology (IT) services with the NETOPS critical capabilities.
19 November 2008
FM 6-02.71
1-5
FOR OFFICIAL USE ONLY
Chapter 1
1-21. Network management refers to the activities, methods, procedures, and tools that pertain to the
operation, administration, maintenance, and provisioning of networked systems in order to provide the
desired level of quality and guaranteed availability
1-22. Enterprise systems management refers to network-wide administration of distributed information
systems through performance monitoring, configuration management
(CM) and problem
detection/resolution, ESM is strongly influenced by network management initiatives in telecommunications.
Functional Services
1-23. There are five major functional services within NM/ESM. These services foster the engineering,
installation, operation, management, administration, optimization, and restoration of communications
networks and information services technologies to ensure the effective and efficient operation, performance,
availability, and security of information and information systems. These services must be employed at the
strategic, operational, and tactical levels across all Army warfighting functions. The five services are—
z
Enterprise services availability for end-user/systems applications and focuses on the
accessibility, reachability, availability, performance, and responsiveness of enterprise service
capabilities. An ―enterprise‖ is described as a set of diverse, physically separated, but related,
components that work together in order to achieve a functional objective. Enterprise services are
those that offer collaborative, software distribution, messaging, discovery, storage, user/system
assistance, and security functionality.
z
Systems availability provides the day-to-day management of computer-based systems, elements
of systems, and services to include software applications, operating systems, databases, and hosts
of the end-users. System management comprises of all the measures necessary to ensure the
effective and efficient operations of the LWN systems and elements of systems and services.
z
Network availability provides the functionality of a network infrastructure with the desired level
of quality and guaranteed service. Networks included within NM/ESM are located on all three
tiers of communication (terrestrial, aerial, or satellite communications [SATCOM]), and they
include: circuit-switched, packet-switched, and cell-switched networks utilizing wired, fiber, or
wireless transport media. .
z
SATCOM availability is the day-to-day operational management of all apportioned and non-
apportioned SATCOM resources, to include appropriate support when disruption of service
occurs; provides SATCOM system status; maintains situational awareness to include the
organization’s current and planned operations as well as space, control, and terminal segment
asset and operational configuration management, satellite anomaly resolution and management,
and SATCOM interference to the network.
z
Electromagnetic spectrum availability involves the effective and efficient utilization of the
electromagnetic spectrum including: international planning; frequency allotment; coordination
with civilian and other government departments, agencies, military Services and components,
and allies; frequency assignment, allotment, and approval; protection; frequency deconfliction;
interference resolution; and coordination with electronic warfare activities. Spectrum
management ensures that the combatant commanders (CCDRs) and subordinate commanders
have cognizance of all spectrum management decisions that impact accomplishment of their
missions (refer to FMI 6-02.70).
Critical Capabilities
1-24. NM/ESM involves several NETOPS critical capabilities associated with the IT services previously
discussed. The critical capabilities for NM/ESM must be achieved at the strategic, operational, and tactical
levels across all warfighting functions. The critical capabilities of NM/ESM are:
z
Fault management is associated with failure of the network or information systems, which
impacts connectivity and functionality. Fault management involves a five-step process of
detecting faults, locating faults, restoring service, identifying the root cause of the fault, and
establishing solutions so that similar faults do not occur in the future.
1-6
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Overview
z
Configuration management is used to discover the specifics of network and information system
architectures and then developing configuration parameters. The parameters then guide the
provisioning, deployment, and management of hardware and software resources.
z
Accounting management assists in the effective and efficient allocation of internal and external
resources to the warfighter. The goal is to identify true requirements based on monitoring
network and system utilization. The end result is that the configuration of the network and
information systems provides for the most effective and efficient use of current resources; as well
as the data gathered during monitoring assists in the planning of future resources.
z
Performance management is the monitoring and management of performance parameters related
to networks and information systems. The purpose of networks and information systems is to
transmit and process information; thus performance management is actually data traffic
management. It involves data monitoring, problem isolation, performance tuning, analysis of
statistical data for recognizing trends, and resource planning.
z
Security management is both the technical and administrative considerations involved in securing
access to the information being transmitted over the network or being processed/stored on
information systems. Security management is the capability that integrates NM/ESM with
IA/CND.
Enabled Effects
1-25. NM/ESM enables the effects of assured network and information system availability and assured
information delivery. This is achieved by —
z
Maintaining robust LWN capabilities in the face of component or system failure and adversarial
attack.
z
Configuring and allocating the LWN network and information system resources.
z
Accounting for resource usage.
z
Rapidly and flexibly deploying networked resources.
z
Ensuring effective, efficient, and timely processing. As well as connectivity, routing, and
information flow.
z
Planning for increased network utilization.
INFORMATION ASSURANCE AND COMPUTER NETWORK DEFENSE
1-26. IA/CND provides true end-to-end, defense-in-depth protection that ensures data confidentiality,
integrity, and availability, as well as protection against unauthorized access.
1-27. IA is defined as measures that protect and defend information and information systems by ensuring
their confidentiality, integrity, availability, authentication, and nonrepudiation. It considers both the
technical and non-technical measures
(such as risk management, personnel training, audits, business
continuity/disaster recovery planning, etc.). Additionally IA holistically factors all incidents that occur
through malicious or accidental activity by enemy or friendly entities. IA includes providing for restoration
of information systems and information by incorporating protection, detection, and reaction capabilities.
1-28. CND is a sub-set of IA that provides defensive measures to protect and defend information,
information systems, and networks from disruption, denial, degradation, or destruction. CND incorporates
technical actions taken specifically to protect, monitor, analyze, detect, and respond to unauthorized,
malicious activity.
Functional Services
1-29. The 10 functional services within IA/CND help to protect friendly information, networks, and
information systems, while denying adversaries access to the same information, networks, and information
systems. The 10 functional services of IA/CND are:
19 November 2008
FM 6-02.71
1-7
FOR OFFICIAL USE ONLY
Chapter 1
z
Access control to information and information systems, which is influenced by the mechanisms
that work together to create a secure environment that protects assets on the network. Access
control provides the capability to specify what resources users can access and what actions users
can perform.
z
Application security provides security to software applications and software solution
development, which is the environment where software is internally designed and developed. Some
examples of application security solutions are software update service and patch management.
z
Business continuity and disaster recovery provides preservation and recovery of information
and network/information systems resources in the event of incidents that have the potential to
interrupt normal operations.
z
Communications security provides the principles, means, and methods of disguising voice, video,
data, and imagery information to ensure confidentiality, integrity, authentication, and non-
repudiation.
z
Risk analysis identifies organization information assets, the threats and vulnerabilities against
those assets, and the development of documentation and the implementation of policies, standards,
procedures, and guidelines that relate to countermeasures.
z
Legal and regulatory compliance enables the organization to meet the requirement for applicable
individuals to be aware of and understand the IA/CND standards that must be met based on U.S.,
DOD, and Army laws and regulations. It additionally assists investigative efforts used to
determine if defenses have been breached.
z
Development of IA/CND policies and procedures specifically related to organizational
personnel, hardware, software, and media. The capability identifies security guidelines for
data/media, telecommunications equipment, and information systems. The capability additionally
provides for the security activities required by users and Signal Regimental Soldiers. Examples of
the required activities are log monitoring or analyzing audit trails.
z
Physical (environmental) security encompasses protection techniques for the entire network
facility, from the outside perimeter to the inside operational space, including all information
system resources. Physical security provides measures to safeguard and protect network and
information systems against damage, loss, and theft. Physical (environment) security provides for
the determination and integration of site selection criteria related to network facilities and
implements effective perimeter and interior security for those facilities. It additionally provides for
the implementation of measures that enable adequate temperature, humidity, and fire controls.
z
Security in development and acquisition provides the implementation of concepts, principles,
structures, and standards used to acquire hardware and software resources in order to enforce
various levels of confidentiality, integrity, and availability. The key is the integration of the
common set of security criteria found in Army, DOD, and international standards - to include the
trusted computing base and reference monitor concepts.
z
Telecommunications and network security provide for the implementation of network
architectures; transmission methods; transport formats; security measures to provide
confidentiality, integrity, and availability; and authentication for transmission over private and
public communications and media. Common solutions include intrusion detection/prevention
systems, anti-virus solutions, web caches, and firewalls. Network security is achieved by
engineering, installing, operating, and maintaining secure networks that incorporate cross domain
solutions, remote access protocols, internet protocol security (IPSEC), virtual private networking
(VPN) technologies, and access control lists.
1-8
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Overview
Critical Capabilities
1-30. IA/CND involves several critical capabilities associated with the functional services previously
addressed. The capabilities for IA/CND must be achieved at the strategic, operational, and tactical levels
across all warfighting functions. IA/CND NETOPS critical capabilities include—
z
Protection involves prior actions taken to counter vulnerabilities associated with information
transport, processing, storage, and operational uses. Protection activities include emission
security, communications security (COMSEC), computer security, information security, and
critical infrastructure protection. In addition, protection addresses vulnerabilities presented by
the physical (environmental) environment.
z
Monitoring involves the examination of network and information systems to sense and assess
abnormalities and the use of anomaly and intrusion detection systems (IDSs).
z
Detection is instrumental to initiating system response and restoration actions. Timely detection,
identification, and location of abnormalities include: attack, damage, unauthorized access
attempts or modifications.
z
Analyzing involves assessing pertinent information to determine indications and warnings,
providing situational awareness, evaluating system status, identifying root cause, defining
courses of action, and prioritizing response and recovery actions. These steps are taken in order
to conduct the necessary reconfiguration of LWN assets and supporting elements.
z
Responding requires that direct action is taken to mitigate the operational impact of an attack,
damage, or other incapacitation of a network resource or information system. Response also
includes restoration. This is the prioritized return of essential systems, elements of systems, or
services to pre-event capability. CND response actions include defensive and restoration actions.
Response actions are deliberate, authorized defensive measures or activities. These actions
protect and defend systems and networks under attack or targeted for attack or exploitation by
adversary systems and networks. Response actions extend defense in depth (DID) capabilities
and increase the ability to withstand adversary attacks or exploitations. Objectives for using CND
response actions include—
Strengthening the defensive posture and operational readiness.
Halting or minimizing attack and exploitation effects or damage.
Supporting rapid, complete attack, or exploitation characterization.
Enabled Effects
1-31. IA/CND enables the effects of assured information protection, and assured network and system
availability. This is achieved by—
z
Instituting agile capabilities
(firewalls, password protect, intrusion detection, etc) to resist
adversarial attacks, through recognition of such attacks as they are initiated or progressing.
z
Detecting and performing analysis of an anomaly or intrusion, providing all Network Operations
and Security Centers and the joint task force-global network operations (JTF-GNO) with incident
reports.
z
Directing response actions in their portion of the LWN.
z
Alerting others on the LWN of incident local status to correct the intrusion.
z
Certifying, accrediting and reporting on all networks, peripherals, and edge devices in their
portion of the LWN in addition to enforcing information security.
z
Conducting security readiness reviews and vulnerability analysis assessments of subordinate
units for compliance with communications tasking orders, Information Assurance Vulnerability
Managers (IAVMs), and reporting compliance to higher.
z
Ensuring compliance of LWN management and defense training, awareness, and certification
programs per established policies and directives.
z
Developing and deconflicting local contingency plans to defend against malicious activity and
providing copies to higher.
19 November 2008
FM 6-02.71
1-9
FOR OFFICIAL USE ONLY
Chapter 1
z
Conducting risk assessments of networks.
z
Sharing IA/CND information in accordance with
(IAW) formal agreements and national
disclosure policies except where limited by law, policy, or security classification.
z
Providing reports as tasked.
z
Developing and maintaining remediation, mitigation, and reconstitution plans for critical
infrastructure protection criteria.
INFORMATION DISSEMINATION AND CONTENT STAGING
1-32. IDM/CS is defined as the technologies, techniques, processes, policies, and procedures necessary to
technically provide warfighters awareness of relevant, accurate information; automated access to newly
revealed or recurring information; and timely, efficient and assured technical delivery of information in a
usable format. As IDM/CS becomes more mature, the complete complement of its services will be available
for use by all authorized users/systems as a network-enabled service.
1-33. IDM enables warfighters to perform network-enabled information management tasks and seeks to
achieve the dissemination of the right information, to the right place, at the right time, and in a usable
format.
1-34. CS is a technique by which information is compiled, cataloged, and cached.
Functional Services
1-35. The functional services provided by IDM/CS are messaging, discovery, mediation, collaboration,
storage, and user assistance in relation to voice, video, data, and imagery content. These core services are
envisioned to be enterprise wide services used by the entire Army to ensure information is available to all
authorized users. The LWN enterprise service effort and the network-enabled enterprise services program
will deliver these core services. The core services are further described as:
z
Messaging enables warfighters to exchange information among users and systems utilizing the
network. Messaging examples include email, DOD unique message formats, message-oriented
middleware, instant messaging, and alerts. Information that is received in the area of
responsibility (AOR) by the information manager is delivered using the CS delivery service.
z
Discovery enables warfighters to discover information content or services that exploit unique
descriptions stored in directories, registries, and catalogs. An example of a discovery service is a
search engine.
z
Mediation enables system interoperability by processing data so that it is translated, aggregated,
fused, or integrated with other data.
z
Collaboration provides the ability for warfighters to work together and jointly use selected
capabilities. Examples of collaboration services are chat, on-line meetings, and work group
applications.
z
Storage provides the physical and virtual hosting of data on the network with varying degrees of
persistence, such as archiving, continuity of operations, and content staging. Information
regarding storage locations may be listed in unit standing operating procedures (SOPs) or
operations orders (OPORDs).
z
User Assistance provides centralized, automated access to lessons learned information that
reduces the effort required to perform manpower intensive tasks.
Critical Capabilities
1-36. IDM/CS involves several critical capabilities associated with the functional services previously
addressed. The capabilities for IDM/CS must be achieved at the strategic, operational, and tactical levels
across all warfighting functions. The IDM/CS NETOPS critical capabilities are:
1-10
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Overview
z
Collection of information describes acquiring data based on information requirements.
z
Processing of information describes the act of translating data via an established and usually
routine set of procedures to convert it from one form to another.
z
Storage of information describes the recording of information to any medium residing on the
network.
z
Transmission of information describes the conveyance of information from one place to
another based on a prescribed information flow.
z
Display of information describes the visual presentation of information, data, or knowledge
collected.
z
Dissemination of information involves automated mechanisms that ensure collected and
processed information is transmitted to the right person in a timely manner.
Enabled Effects
1-37. IDM/CS enables the effects of assured information delivery and assured information protection. This
is achieved by—
z
Retrieving critical information from information systems within the information environment that
directly contribute to situational awareness, collaboration, and decision-making by the
warfighter.
z
Compiling the information retrieved in order for it to be processed and stored until needed.
z
Caching the compiled information in a secure system IAW applicable regulations and policies.
z
Cataloging the cached information in order to facilitate warfighter future search and discovery of
required information.
z
Distributing critical information to the warfighter or information system in order to gain
situational awareness, conduct collaboration, or execute decisions.
SECTION II - NETWORK OPERATIONS PRINCIPLES
1-38. NETOPS principles allow for active involvement, coordination, status sharing, and cooperation of
service providers for an open view of networks and information systems throughout the LWN. The
following principles govern developing and implementing NETOPS.
SHARED NETWORK MANAGEMENT CONTROL
1-39. The components of the LWN are controlled by multiple organizations that provide network services
to the functional user. These different organizations accomplish end-to-end management of a network by
sharing information related to their assets and collaborating on problem resolution and service provisioning
issues. Network service providers must know the status of major components of networks and information
systems as well as their overall performance. Network operations and security centers (NOSCs) provide
near- and real-time statuses. Information sharing should not imply sharing of control responsibilities beyond
what is necessary to manage the network.
ASSURANCE AND PROTECTION OF INFORMATION
1-40. A greater reliance on information to plan operations, deploy forces, and execute missions has placed
increased emphasis on assuring and protecting information. Mission accomplishment depends on protecting
and defending information and information systems from destruction, disruption, corruption, intrusion, and
exploitation. Protection and defense of data and voice networks and information systems is accomplished
through aggressive application of IA measures, CND, CND response action, critical infrastructure
protection, and NETOPS force protection in defense of the LWN.
19 November 2008
FM 6-02.71
1-11
FOR OFFICIAL USE ONLY
Chapter 1
DISSEMINATION OF INFORMATION
1-41. Managing and protecting networks and information systems does not alone ensure that relevant
information is being disseminated to the intended user. A major component of NETOPS is the management
of the delivery of relevant and accurate information, to the appropriate user, in an efficient manner, and in
the proper format.
INTEGRATED ARCHITECTURE
1-42. As our Army strives to achieve the objectives of joint net-centric warfare, Army transformation, and a
modularized force, we must have an integrated enterprise-wide NETOPS architecture to effectively manage
both battlefield and business network environments across the joint operating spectrum. The Army
Enterprise Network Operations Integrated Architecture (AENIA) is a top-to-bottom enterprise vision, vice a
specific program of record architecture that will evolve as the Army’s transformation and modularity
concepts, doctrine, architecture and organizations mature.
ARMY ENTERPRISE NETOPS INTEGRATED ARCHITECTURE
1-43. The AENIA is the baseline LWN enterprise NETOPS architecture for the Army’s Chief Information
Officer (CIO)/G-6 Policy Memorandum, 24 Apr 06. It was developed by NETCOM and is under the
oversight of the CIO/G-6 as one of five architectures which collectively comprise the Army Knowledge
Enterprise Architecture established per Army Regulation (AR) 25-1. The AENIA is based on DOD, joint,
Army, installation, and industry
―Best Business Practices‖
(Information Technology Infrastructure
Library®) and supports the Army’s IT Portfolio Management mandate.
1-44. The AENIA describes a standardized set of NETOPS capabilities for the LWN. It defines the
organizations, roles, activities, and systems necessary to operate, manage, and defend the flow of
information in the enterprise information environment. The NETOPS capabilities addressed within the
AENIA v5.0 includes:
z
Internet Protocol (IP)-based transport management focusing on securely operating, managing,
and maintaining firewalls, IP network management systems/applications, layer-2 switches, layer-
4 switches, network intrusion detection devices, network intrusion prevention devices, routers,
Voice over Internet Protocol (VOIP) systems/applications, Virtual Private Networks (VPNs),
and wireless IP network systems. Note: these generic network devices/systems may actually be
combined as modules/components within a single system, cabinet, or device, as is the case with
current Top Layer Architecture-Redesign 2 stacks.
z
Computing platform management focusing on securely operating, managing, and maintaining
anti-malware (anti-virus/spyware/adware) systems, backup and recovery systems, host IDSs, host
intrusion prevention systems (IPSs), network attached storage devices, secure configuration
remediation/patch management systems, storage area network systems, computer/server
management systems/applications, data security at rest, and host-based security systems. The
managed devices and management applications may also be combined as modules/components
within a larger single system, cabinet, or application, as is the case with host-based security
system; the AENIA requirements still apply.
z
Security management focusing on securely operating, managing, and maintaining; IAVM
compliance managers, IP network vulnerability scanners, security information management
systems/applications, cryptographic systems, identity management systems/applications, public
key infrastructure (PKI) systems, remote access systems, high assurance IP encryption systems,
IP network policy-based servers/systems/applications, secure socket layer accelerator systems,
network access control, and trusted platform module.
z
Enterprise support focusing on providing the Army enterprise infostructure-repository, IP
capacity and availability monitoring, help desk/customer relationship management/CM,
NETOPS situation awareness, frequency assignment, and service level management.
1-12
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Overview
z
Enterprise services and applications management—focusing on securely operating, managing,
and maintaining collaboration services, electronic-mail (e-mail) services, Lightweight Directory
Access Protocol//X.500 services, Active Directory (AD) services (Refer to Appendix A for a
detailed discussion of AD management), databases, meta-directory systems/applications/services,
and organizational messaging services (the Defense Message System-Army).
19 November 2008
FM 6-02.71
1-13
FOR OFFICIAL USE ONLY
Chapter 2
Network Operations Components
This chapter more thoroughly addresses the NM/ESM, IA/CND, and IDM/CS
components of NETOPS. It describes the activities, responsibilities, associated
functions, and tasks that must be accomplished to effectively and efficiently use the
networks, systems, and resources that contribute to the Army’s communications
systems operation support mission.
SECTION I - ENTERPRISE SYSTEMS MANAGEMENT/NETWORK
MANAGEMENT
2-1. The specific management requirements vary depending on the echelon of the systems and networks.
This section will guide network managers during the activities, functions, and tasks performed at the
strategic, theater, and tactical levels of NM/ESM.
2-2. The role of NM/ESM is to coordinate, manage, and control the installation and the operations and
maintenance of networks and systems to meet user requirements. This objective requires performing a set of
activities, functions, and tasks necessary to control the network’s topology, maintain its operational
capability, optimize its performance, and account for its usage.
OBJECTIVE
2-3. The NM/ESM mission provides network control for all Army communications systems operation and
interaction with other services for various NM/ESM operations in joint networks. NM/ESM directs the
allocation of responsibilities among Army and joint organizations. The Army’s NETOPS managers perform
NM/ESM at the strategic, theater, and tactical military operations levels. Specific functions and tasks may
vary depending on the mission and capabilities of the organization. There is, however, a common set of
activities that NETOPS managers perform for effective and efficient NM/ESM.
ACTIVITIES
2-4. The activities for the operation, management, and control of information networks and systems are
performed consistently at NOSCs from the sustaining base to the theater tactical signal units (numbered
Army, corps, and division) as well as to the brigade combat team (BCT) and battalion. These activities
occur during the predeployment, deployment, and redeployment stages of an operation. NM/ESM is broken
down into seven activities. Each activity represents a different step in the NM/ESM cycle. Network and
information systems management resources are identified for each activity to create a manageable
NM/ESM. Many of the activities required for NM/ESM are also necessary for the execution of general
NETOPS. The seven activities are—
z
Operational control and management.
z
Service delivery.
z
Service support.
z
Mission planning.
z
Capability design and engineering.
19 November 2008
FM 6-02.71
2-1
FOR OFFICIAL USE ONLY
Chapter 2
z
Logistics.
z
Administration.
2-5. Specific functions and associated tasks are accomplished within each activity of NM/ESM, whether it
applies to user-owned,
-operated, and
-managed information systems or to voice and data networks
provided by communications networks and information services support elements. A distinct separation
exists between networks and their management and user information equipment operation and its
management.
2-6. The user drives the NM/ESM activities and directly interfaces in three areas: operational control and
management, service delivery, and service support. A user request for information support services initiates
the cycle and is supported through the operational control and management activity. The NM/ESM cycle
ends when network managers perform the service support activities that provide customer service and
performance analysis of the user’s needs. The various control centers perform the remaining activities to
provide continuous network and information system support to the user.
2-7. Mission planning and capability design and engineering are centralized activities that design the
networks to meet the user's service requirements. Logistics support is required for maintenance on existing
services and procurement of equipment to meet new service requirements. The following paragraphs define
NM/ESM activities and the associated functions and tasks.
Note. Refer to Chapter 5 for a detailed description of the activities required for NM/ESM and the
execution of general NETOPS.
OPERATIONAL CONTROL AND MANAGEMENT
2-8. Network managers perform service provisioning to add, delete, or change network and information
system services available to the user. Operational control and management covers the non-engineering tasks
associated with providing users access to the requested services. Services may be of a global nature, such as
the GIG long-haul capability controlled and managed by the Global Network Operations Support Center
(GNSC). Services may also be the direct user services provided by a network manager at a NOSC and at the
theater (numbered Army, corps, and division) or BCT tactical level of operations. Operational control and
management involves—
z
Configuration change implementation.
z
Sub-element installation.
z
Service modification verification.
z
Configuration of end-user equipment.
SERVICE DELIVERY
2-9. Service delivery is the activity that directly interfaces with the user to monitor satisfaction with the
service provided by the network or information systems components. Service delivery looks at what
services the user requires of the provider in order to provide adequate support to the Army mission area.
The service delivery management activities involve—
z
Service level management.
z
Financial management for IT services.
z
Capacity management.
z
IT service continuity management.
z
Availability management.
2-2
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Components
SERVICE SUPPORT
2-10. Service support is the core NM/ESM activity that provides the monitoring and control to keep the
network and systems operating and providing quality service. The service support targets network and
systems operations and management. NETOPS managers perform this activity during the operational stages
of the network. Service support involves—
z
Service desk.
z
Incident management.
z
Problem management.
z
CM.
z
Change management.
z
Release management.
MISSION PLANNING
2-11. The mission planning activity assesses user requirements and develops the schedule and resources to
meet the requirements. It consists of functions that deal with the current, short-term (less than 2 years), and
long-term
(2-20 years) planning requirements. The mission planning activity ensures changes in
requirements for services are collected, analyzed, prioritized, cost assessed, and scheduled for
implementation. The ultimate goal of mission planning is to ensure that resources are available to meet
current and emerging short-term and long-term requirements, and that proposed implementations conform
to follow-on short- and long-term objectives. The mission planning activity involves—
z
Analysis of user requirements.
z
Technology assessment.
z
Architecture definition.
z
Services planning and programming.
z
Sub-system definition and funding.
z
Cost benefits analysis.
z
Performance objectives establishment.
z
Contingency and restoration planning.
z
Capacity planning.
z
System planning.
z
Integration planning.
z
Security planning.
z
Frequency assignment.
z
SATCOM management.
CAPABILITY DESIGN AND ENGINEERING
2-12. The capability design and engineering activity tailors network and information system resources to
meet user service requirements. Capability design and engineering bases network and systems design
requirements on planning direction that relates to capacity allocation and new services for implementation.
Capability design and engineering is required from the strategic LWN level of NM/ESM, down to the
theater (numbered Army, corps, and division) tactical NM/ESM performed by a theater network operations
and security center (TNOSC). The capability design and engineering activity involves—
z
Planning assistance to users.
z
Network and systems design.
z
Security design.
z
Facility and equipment design.
z
Integration of operations, facilities, and equipment.
19 November 2008
FM 6-02.71
2-3
FOR OFFICIAL USE ONLY
Chapter 2
z
Technical documentation.
z
Equipment and services specification.
z
Implementation design and procedures development.
z
Hardware and software development.
z
Information systems support and development.
z
Frequency assignment.
LOGISTICS
2-13. The logistics activity provides for the logistical support of the network and systems. Logistics
includes procurement, handling, storage, packaging, distribution, maintenance, and replacement of materiel
such as spare or repair parts and consumable items. Logistics activities involve—
z
Corrective maintenance.
z
Requisition processing.
z
Equipment inventory management.
z
Stockage.
z
Property accountability.
ADMINISTRATION
2-14. The administration activity is associated with budgeting, training, procurement, staffing, and other
business-related functions. Network managers perform these functions primarily at the strategic sustaining-
base level and at theater bases, posts, camps, and stations. They also perform some of these functions to a
lesser degree at all levels of NM/ESM. The administration activities involve—
z
Training management.
z
Program and budget management.
z
Procurement.
z
Staffing management.
z
Chargeback.
z
Special services.
SECTION II - INFORMATION ASSURANCE AND COMPUTER NETWORK
DEFENSE
OVERVIEW
2-15. Army commanders rely on information support to plan operations, deploy forces, and execute
missions. By protecting the flow of information from attacks, intrusions, and interruptions, the commander
can be assured of gaining and maintaining information superiority.
2-16. IA is the defensive component of information operations (IO) that with concurrent use of validated
intelligence defining the threat enables the availability, integrity, authentication, confidentiality, and non-
repudiation of friendly information and information systems in the information environment that is now a
component of the operational environment. IA provides a DID that protects the LWN against exploitation,
degradation, and denial of service. The DID incorporates vigorous protection, detection, reaction, and
restoration capabilities. This incorporation allows for effective defensive measures and timely restoration of
debilitated networks and information systems.
2-17. IA capabilities reside in depth throughout the LWN. Network and information system managers must
actively monitor and evaluate the effectiveness of the IA systems used in their AOR. They must maintain an
awareness of the overall network status, incident reporting, and network management processes to integrate
IA into the NETOPS activities, functions, and tasks. IA-trained personnel must be integrated into the Army
2-4
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Components
NOSCs at all echelons. This placement ensures the expertise to quickly determine the cause of and take
appropriate action in response to IA issues as they affect the LWN.
2-18. IA encompasses a diverse field of network and information systems security disciplines. The Army
Information Assurance Program (AIAP) focuses the Army’s efforts to secure information and its associated
systems and resources. It provides a unified approach to protecting classified and sensitive information by
using the risk management approach for implementing security safeguards. The AIAP is not limited to
information security; it covers other aspects of security such as COMSEC, emission security, operations
security (OPSEC), physical security, personnel security, and industrial security.
2-19. Commanders at all levels use the DID strategy to secure Army information and information systems
against the full spectrum of capabilities of adversaries operating in the information environment and
identified in paragraph
2-27, below. The interactive nature of the Army’s technical networks and
information systems using the publicly available Internet in light of these threats makes them vulnerable to
intrusions and disruptions.
2-20. The DID strategy protects networks and information systems through a layered series of protective
perimeters; enhanced protect, detect, and react capabilities; and a supporting IA infrastructure. It is a long-
term, dynamic strategy that incorporates IA/CND tools and policy enforcement, and it uses current and
evolving technology, policies, procedures, and trained, knowledgeable people. The strategy is flexible and
adjusts to changes in technology that may pose new attack threats or offer new protection capabilities.
2-21. Commanders must develop comprehensive protection measures in anticipation of how an adversary
may use elements of attack and intrusions to disrupt systems and networks. These measures keep in mind
the guiding principles of the DID strategy, including risk management, vulnerability assessment, levels of
concern and protection, and the capability to detect and react to attacks and intrusions.
INFORMATION ASSURANCE AND COMPUTER NETWORK
DEFENSE FUNDAMENTAL ATTRIBUTES
2-22. The IA/CND mission essential task ensures the fundamental attributes of availability, authentication,
confidentiality, integrity and non-repudiation of friendly information and information systems while denying
adversaries access to the same information and information systems. The fundamental attributes are—
z
Availability. Actions taken to allow the timely, reliable access to data and information services
for authorized users.
z
Authentication. A security measure designed to establish the validity of a transmission,
message, originator, or as a means of verifying an individual’s authorization to access specific
categories of information.
z
Confidentiality. Actions taken that assure information is not disclosed to unauthorized
individuals, processes, or devices.
z
Integrity. Assuring the quality of an information system reflecting the logical correctness and
reliability of the operating system; the logical completeness of the hardware and software
implementing the protection mechanisms; and the consistency of the data structures and
occurrence of the stored data. In a formal security mode, integrity is interpreted more narrowly to
protect against unauthorized modification or the destruction of information.
z
Non-repudiation. Assurance that the sender of data is provided with proof of delivery and the
recipient is provided with proof of the sender's identity in order to create a record of the parties
that processed the data.
2-23. IA/CND incorporates those actions taken to protect, monitor, analyze, detect, and respond to
unauthorized activity within DOD information systems and computer networks. IA incorporates protection,
detection, and response capabilities while providing for restoration of information systems. It provides end-
to-end protection to ensure data quality and protection against unauthorized access and inadvertent damage
or modification. CND activity employs IA protection activity and includes deliberate actions taken to
modify an assurance configuration or condition in response to a CND alert or threat information.
19 November 2008
FM 6-02.71
2-5
FOR OFFICIAL USE ONLY
Chapter 2
2-24. CND response actions include defensive and restoration actions. CND response actions are
deliberate, authorized defensive measures or activities that protect and defend DOD computer systems and
networks under attack or targeted for attack by adversary computer systems and networks. CND response
actions extend DOD’s layered DID capabilities and increase DOD’s ability to withstand adversary attacks.
Objectives for using CND response actions include:
z
Strengthening DOD’s defensive posture and operational readiness.
z
Halting or minimizing attack effects or damage.
z
Supporting rapid, complete attack characterization.
2-25. IA and CND are focused on assured information protection and assured network and information
system availability. The objectives of this focus are achieved by—
z
Instituting agile capabilities
(firewalls, password protect, intrusion detection, etc) to resist
adversarial attacks through recognition of the attacks as they are initiated or are progressing.
z
Efficient and effective response actions to counter the attack, and safely and securely recover
from such attacks.
z
Reconstituting capabilities from reserve or reallocated assets when original capabilities are
destroyed.
z
Maintaining correlation activities between user elements to ascertain hostile IA/CND events from
other system outages or degradations.
RISK MANAGEMENT
2-26. A comprehensive risk management program is the most effective way to protect a network or
information system. Risk management consists of identifying, measuring, controlling, and eliminating or
minimizing uncertain events that may adversely affect system resources. The objective of risk management
is to achieve the most effective safeguards against threats of both intentional and unintentional intrusions
into a network or system. Intentional intrusions are planned attacks against information resources and must
be protected by an effective DID. Risk management also includes identifying network and information
system vulnerabilities created by weaknesses in design, ineffective security procedures, or faulty internal
controls that are susceptible to exploitation by authorized or unauthorized users. The following paragraphs
discuss the aspects of risk management. (Refer to FM 5-19 for additional information on risk management.)
THREAT
2-27. Threats to the GIG and LWN are genuine, world-wide in origin, technically multifaceted and
growing. They come from individuals and groups motivated my military, political, cultural, ethnic,
religious, personal, or industrial gain. These types of threats are categorized by the Committee on National
Security Systems Instruction No. 4009 as incidents (assessed occurrence having actual or potential adverse
effects on an information system, or events occurrences, not yet assessed, that may affect the performance
of an information system). According to FM
3-13, the capabilities of adversaries operating in the
information environment are:
z
First level: lone or small groups of amateurs using common hacker tools and techniques in an
unsophisticated manner without significant support.
z
Second level: individuals or small groups supported by commercial business entities, criminal
syndicates, or other transnational groups using common hacker tools in a sophisticated manner.
This level of adversary includes terrorists and non-governmental terrorist organizations. Their
activities include espionage, data collection, network mapping or reconnaissance, and data theft.
z
Third level: individuals or small groups supported by state-sponsored institutions (military or
civilian) and significant resources, using sophisticated tools. Their activities include espionage,
data collection, network mapping or reconnaissance, and data theft.
z
Fourth level: state-sponsored offensive IO, especially computer network attacks, using state-of-
the-art tools and covert techniques conducted in coordination with (ICW) military operations.
2-6
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Components
2-28. These events and incidents (both initiated by potential or actual adversaries or by Army users or
administrators as a result of carelessness or non-compliance) are identified by the IA and CND communities
into categories that include:
z
Category 1: root level intrusion (incident) unauthorized privileged access (administrative or root
access to a DOD system).
z
Category
2: user-level intrusion
(incident) unauthorized non-privileged access
(user-level
permissions) to a DOD system.
z
Category 3: unsuccessful activity attempt (event) attempt to gain unauthorized access to the
system that is defeated by normal defensive mechanisms. Attempt fails to gain access to the
system (e.g., attacker attempt valid or potentially valid username and password combinations)
and the activity cannot be characterized by as exploratory scanning.
z
Category
4: denial of service
(incident) activity that impairs, impedes, or halts normal
functionality of a system or network.
z
Category 5: non-compliance activity (event) activity that due to DOD actions (or non-actions)
makes an IT system potentially vulnerable (e.g., missing security patches, connections across
security domains, installation of vulnerable applications, etc.).
z
Category 6: reconnaissance (event) an activity (scan or probe) that seeks to identify a computer,
an open port, an open service, or any combination thereof for later exploit.
z
Category 7: malicious logic (incident) installation of malicious software (e.g., Trojan, backdoor,
virus, or worm).
2-29. The globalization of network communications and the IT marketplace creates vulnerabilities due to
increased access to the information infrastructure from points around the world and the uncertainties of the
security of the IT supply chain. The global commercial supply chain provides adversaries with greater
opportunities to manipulate information and communications technology products over the products life
cycle…adversaries have greater access to our networks when (their) products or services are delivered.
Threats against computers, network, and information systems vary by the level of hostility (peacetime,
conflict, or war), technical capabilities and motivation of the perpetrator. Threats to the information systems
and networks relied upon by strategic and tactical forces exist from various sources, and they exist on a
continual basis.
2-30. Attacks and intrusions compromise missions, corrupt data, degrade networks and systems, and can
destroy hardware and software applications. These results hamper the effectiveness of support forces and
the supported Soldier.
Intentional Intrusion
2-31. Intentional intrusion into a network or system is a deliberate act. This act has proven to be one of the
most challenging to protect against, detect, and react to. Examples of intentional intrusion include—
z
Unauthorized users, such as attackers. Attackers are the source of most attacks against
information systems in peacetime. They mostly target personal computers, but recently have
targeted network communications, mainframes, and local area network (LAN) based computers.
z
Trusted insiders with legitimate access to a system. They pose one of the most difficult threats to
defend. Whether recruited or self-motivated, insiders can access systems normally protected
against attack. While insiders can attack at almost any time, a system is most vulnerable during
the design, production, transport, and maintenance stage.
z
Terrorist groups who have access to commercial information systems (including the Internet).
They may obtain unauthorized access to an information network or direct attacks against the
infrastructure (bombing). Terrorists use computer bulletin boards and Internet systems to pass
intelligence and technical data across international borders. These organized groups pose a
serious threat to the information infrastructure and national security of the US.
19 November 2008
FM 6-02.71
2-7
FOR OFFICIAL USE ONLY
Chapter 2
z
Non-state groups, such as drug cartels and social activists. Taking advantage of the information
age, they can acquire (at low cost) the capabilities to strike at their foes' commercial, security,
and communications infrastructures. Moreover, they can strike from a distance with impunity.
z
Foreign intelligence services that are active during peace and conflict and take advantage of the
anonymity offered by the computer, bulletin boards, and the Internet. They hide organized
collection or disruption activities behind the facade of unorganized attackers. Their primary
targets are often commercial, scientific, and university networks. They may also directly attack
military and government networks and systems.
z
Opposing militaries or political opponents. While the adversary's activities are more traditionally
associated with open conflict or war, opposing militaries or political opponents may invade US
computer and telecommunications networks during peacetime. Such strikes help frame the
situation to their advantage preceding the onset of hostilities. Adversaries may also try to
manipulate the news media and public opinion to their advantage.
ATTACKS
2-32. An intentional intrusion is an attack against computers or information systems. Some attacks have a
delayed effect and others are immediate. Both the delayed and immediate attacks corrupt databases and
controlling programs, and may degrade or physically destroy the system attacked. Timely attack detection is
essential to initiating network restoration and network intrusion response capabilities. The following
paragraphs discuss types of attacks.
2-33. Computer attacks generally aim at software or data contained in either end-user or network
infrastructure computers. Adversaries aim at unobtrusively accessing information, modifying software and
data, or totally destroying software and data. These activities can target individual computers or a number
of computers connected to a LAN or wide area network (WAN). Computer attacks may take place during
routine tactical operations and may be multifaceted to disrupt major military missions. These attacks can
also take place during wartime and peacetime. Attacks can be part of a major nation-state effort to cripple
the US national information infrastructure. They can also come from mischievous or vengeful insiders,
criminals, political dissidents, terrorists, and foreign espionage agents.
2-34. Malicious computer attacks can be intentionally designed to unleash computer viruses, trigger future
attacks, or install software programs that compromise or damage information and systems. They may also
involve unauthorized copying of files, directly deleting files, or introducing malicious software or data.
Malicious software generally consists of executable software codes secretly introduced into a computer and
includes viruses, Trojan horses, trap-doors, and worms. Malicious data insertion, sometimes termed
―spoofing,‖ misleads a user or disrupts systems operation. For example, an attack disrupts a packet data
network by introducing false routing table data into one or more routers. An attacker who denies service or
corrupt data on a wide scale may weaken user confidence in the information they receive by corrupting or
sending false data.
2-35. Physical attacks generally deny service and involve destruction, damage, overrun, or capture of the
systems components. This may include end-user computers, communications devices, and network
infrastructure components. A physical attack involves the overrun and capture of computer equipment that
allows the adversary to employ a computer attack. Another form of physical attack is theft of items, such as
cryptographic keys or passwords. This is a major concern since these items can support subsequent
electronic or computer attacks.
2-36. Electronic attacks focus on specific or multiple targets within a wide area. Attacks against
communications links include the following two types of signal intelligence operations: signal intercept and
analysis to compromised data and emitter direction findings, and geo-location to support signal analysis and
physical attacks. ―Jamming‖ is another attack against communications links. Jamming corrupts data and
may cause denial of service to users. For example, the jamming of communications links supporting global
positioning system users is a specific concern.
2-8
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Components
VULNERABILITIES
2-37. The information age has enabled the Army to use information as an element of combat power.
Supporting crises and contingency operations require the rapid expansion of IO capabilities beyond their
normal peacetime limits. Deploying forces require secure video, database connectivity, and broadcast and
receive capabilities for reach operations access to intelligence, logistics, and other essential support data.
Successful conduct of operations requires access to information available outside the operational area.
Information infrastructures no longer parallel traditional command lines. Soldiers need frequent, instant,
and reliable access to information in the continental United States (CONUS) and outside the continental
United States (OCONUS). The Soldiers’ mobility capabilities and force sustainment requirements depend
on commercial reach operations infrastructures that include international telecommunications and the public
switched networks.
2-38. This increased reliance on reach operations information capabilities by the Soldier has created
vulnerabilities to attack from various sources. Networks and information systems are vulnerable to attack
from adversaries who can quickly take advantage of weaknesses in design, ineffective or lax security
procedures, or insufficient internal controls. An adversary who may not be a technological equivalent could
initiate a covert or overt attack by using inexpensive, commercial off-the-shelf products and attacker tools
obtained from the Internet. The attack can be from any location that has access to the Internet. Recent trends
that have increased vulnerability include use of commercial services, commercial off-the-shelf hardware and
software, the integration and consolidation of stovepipe systems, moving toward an open systems
environment, and extensive interfacing with government, industry, and public networks. (Refer to AR 25-2
for specific examples of vulnerabilities.)
2-39. A vulnerability analysis should be conducted to assess the security status of networks and information
systems. A vulnerability analysis should be conducted or requested at every organizational level. The
analysis can ensure that the network or information systems security features are properly configured for
optimum IA capabilities. Another critical component of an effective vulnerability analysis program is the
periodic review of the IA tools in use to ensure that the latest version is installed. An effective program will
identify unauthorized users and unauthorized use of the network or information system. Once unauthorized
activity is identified and verified, established incident and vulnerability reporting procedures must be
followed. The reporting procedures are outlined in the Chairman of the Joint Chiefs of Staff Manual
(CJCSM) 6510.01 and AR 25-2.
INFORMATION SYSTEMS SECURITY
2-40. IA programs within the Army must include the full range of security measures. Information systems
security occurs only when a common set of technical procedures apply to all assets connected to the
common-user LAN and throughout the WAN. Protection from intrusions into or via a WAN must begin
with a cooperative information systems security effort between all of the services and the Defense
Information Systems Agency (DISA). All security measures taken to detect, respond to, react to, and report
attacks and intrusions will adhere to public laws, DOD directives, and ARs. System administrators and
network managers are required to complete IA security and awareness certification training. Specific
information regarding measures to reduce the threat, vulnerabilities, and risks will be covered for the
information systems under their purview.
LEVEL OF CONCERN
2-41. All information systems will be assigned a level of concern rating based on the confidentiality,
integrity, and availability of the information processed, stored, or transmitted. The level of concern rating
for each of these areas can be basic, medium, or high. The decision regarding the level of concern will be
explicit for all systems. (Refer to AR 25-2 for more information on the level of concern rating process.)
19 November 2008
FM 6-02.71
2-9
FOR OFFICIAL USE ONLY
Chapter 2
PROTECTION LEVELS
2-42. Protection levels only apply to confidentiality requirements. Protection levels are based on the
required clearance, formal access approval, and need-to-know of all direct and indirect users who receive
information from the information systems without manual intervention and reliable human review.
Protection levels indicate the implicit level of trust that is placed in the system’s technical capabilities. The
service providers and the users must cooperate to implement the required level of protection. The Soldier
must have assurance that his information systems have the level of protection or trust required for a
successful mission.
PROTECTION, DETECTION, AND REACTION CAPABILITIES
2-43. Information and network systems are critical to the military’s ability to conduct operations. The
Soldier’s assurance that networks and information systems are defended adequately against attack requires
the ability to—
z
Protect the information that computer systems and data networks pass and store.
z
Detect when an intrusion into the network or information system happens.
z
React to contain the damage and repair the network or information system.
PROTECTION
2-44. Information protection is active or passive measures that protect and defend friendly information and
information systems to ensure timely, accurate, and relevant friendly information. It denies enemies,
adversaries, and others the opportunity to exploit friendly information and information systems for their
own purposes (FM 3-0).
2-45. Information protection includes information assurance, computer network defense, and electronic
protection. All three are interrelated.
z
Information assurance consists of measures that protect and defend information and information
systems by ensuring their availability, integrity, authentication, confidentiality, and
nonrepudiation. This includes providing for restoration of information systems by incorporating
protection, detection, and reaction capabilities (JP 3-13).
z
Computer network defense consists of actions taken to protect, monitor, analyze, detect, and
respond to unauthorized activity within the Department of Defense information systems and
computer networks (JP 6-0). Effective network defense assures Army computer networks’
functionality. It detects and defeats intruders attempting to exploit Army information and
information systems. Commanders and staffs remain aware of and account for information on
regulated (Department of Defense) and nonregulated (Internet) networks. They analyze how
information from these mediums affects their operation; they take action to mitigate the
associated risks.
z
Electronic protection is that division of electronic warfare involving actions taken to protect
personnel, facilities, and equipment from any effects of friendly or enemy use of the
electromagnetic spectrum that degrade, neutralize, or destroy friendly combat capability (JP 3-
13.1).
2-46. Information protection applies to any medium and form including hard copy, electronic, magnetic,
video, imagery, voice, telegraph, computer, and human. Information protection involves determining the
appropriate security measures based on the value of information protected. The protection measures should
reflect the changing value of the information that pertains to each operational phase of any given mission.
Ensuring the protection of information is the responsibility of leaders, information producers, processors,
and users.
2-47. Continuity of operations (COOP), operations plans, and OPORDs specify the priorities of protection
measures for network and information systems. The protection measures should consist of firewalls, IDSs,
and software that harden these systems against intruders. Figure 2-1 is an example of the basic network and
2-10
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Components
information systems protection measures. Every effort must be made to improve the protection of
information stored on US computers and that flows through the networks.
2-48. Army network and system managers must devise and implement comprehensive plans for using a full
range of security means. The plans will include external and internal perimeter protection. External
perimeter protection consists of COMSEC, router filtering, access control lists (ACL), security guards, and
physical isolation serving as a barrier to outside networks such as the Non-Secure Internet Protocol Router
Network (NIPRNET). Internal perimeter protection consists of firewalls and router filtering. These serve as
barriers between echelons of interconnected networks and information systems. Internal COMSEC barriers
are also required. Local workstation protection consists of individual access controls, configuration audit
capability, protection and intrusion detection tools, and security procedures.
2-49. Other considerations that must be addressed when protecting vital networks and information systems
include—
z
Developing comprehensive training programs. Programs should instill IA intrusion and detection
doctrine, and operational procedures in all members of the command.
z
Developing vigorous programs for sharing results of red team and vulnerability assessments.
z
Programs that have a standard practice at the appropriate levels of information flow and—
Ensure intrusion protection and detection systems are employed at all levels
of network management.
Train to protect against, detect, react to, and restore from intrusions should
become a common task.
2-50. Other initiatives to enhance the architecture and limit intrusions into the NIPRNET are underway.
These initiatives include routing communications through a limited number of gateways and closing access
to networks through other connection points around the globe
(thus easing monitoring tasks and
responsibilities), and upgrading firewalls and IDS devices to help prevent unauthorized entries.
ASR
Cisco 6509
Routers
ASR
Cisco 6509
Routers
Protocol
Protocol
Analyzer
Analyzer
NetScreen
5400
Terminate
Firewall
Cisco ASA 5400
NetScreen
Installation
5400
VPN Concentrator
Cisco
Firewall
VPNs
Cisco
7206
Remote
7206
User Access
Remote
VPN
User Access
VPN
Concentrator
Concentrator
Syslog/Radius
Syslog/Radius
Intrushield
Server
Server
Intrushield
4000 NPS
4000 NPS
SPA Crypto
SPA Crypto
Module
Module
Cisco 6509
Cisco 6509
Router
Router
Figure 2-1. Basic network and information systems protection measures
19 November 2008
FM 6-02.71
2-11
FOR OFFICIAL USE ONLY
Chapter 2
2-51. Protection against intrusions into friendly computer networks by denying unauthorized entry and
access into these systems is essential for network and system protection. OPSEC procedures allow the
commander to identify actions that adversary intelligence systems and intruders observe. It provides an
awareness of the indicators that adversary intelligence systems might obtain. OPSEC identifies and selects
information that is subject to exploitation by adversaries and identifies countermeasures that reduces risk to
an acceptable level. Since most intrusions result from human error, training in OPSEC is one measure that
protects against intentional and unintentional intrusions. Many different measures affect OPSEC, including
information security, transmission security, COMSEC, and signal security.
2-52. New global commercial capabilities (including imaging, positioning, and cellular systems) offer
potential adversaries access to an unprecedented level of information about our forces. Army and other
service personnel can send information directly from the battlefield via e-mail to points around the world
from most areas of operation. These e-mails may contain sensitive or classified information, and if
disclosed, could endanger US personnel and compromise missions.
2-53. Information provided on Army Web pages is also a security concern. For Web pages, the OPSEC
guidelines are the same as any other information available within the Army. Sensitive and classified
information needs protection against disclosure to unauthorized personnel. Refer to
procedures, and network security tools.
2-54. As more of the Army’s information flow transitions to network enabled communications, information
security takes on an ever-growing importance for protecting information management. Units rely on
computer systems and networks for logistics, personnel, administration, maintenance, and financial data
processing and transfer in both war and peace. These critical networks and systems are vulnerable to
intrusions and attack at every echelon in the Army. The Internet is the preferred communications platform
for intruders to launch an attack or intrusion. Normally, the intruder's IP address is difficult to track, making
it impossible to apprehend the perpetrator.
2-55. Security measures and procedures must actively and passively preserve the confidentiality, integrity,
and functionality of information systems throughout the LWN. Protection includes real and near-real-time
measures that detect intrusions and then restore the affected device or system. Security measures that assist
in protection include—
z
Adopting vigorous IA protection programs.
z
Denying unauthorized access.
z
Hardening programs and gateways with specific software and hardware means.
z
Developing procedures for quality assurance in all program and hardware acquisition.
z
Strict access control for use of networked computers and other devices.
2-56. US forces must be assured that the expanded communications system infrastructure can attain the
level of protection required for mission success. Service providers, the DOD, and other government
agencies must cooperate to implement this or any other level of protection for the GIG.
2-57. The technical complexity of information infrastructures may inhibit a commander’s ability to manage
the information available. Additionally, the availability of information dissemination devices (such as e-
mail) may prove to be a menace to the security of information that originates from the battlefield. Currently,
the DOD has taken steps to restrict the entrance into sensitive information areas, critical network nodes, and
the elements of the GIG. Several initiatives are underway to protect the US information infrastructure from
intrusions and attacks.
2-58. Close coordination with the supporting judge advocate is critical in confronting information security
challenges at each network management level. Network managers must be aware of regulations, statutes,
and public laws that govern privacy and monitor activities. Due to recent disclosures of sensitive or
classified information using networked computers, legislation may change regulations and laws that govern
monitoring activities of the various government agencies. If approved, these changes will allow law
enforcement agencies greater access and authorization to search computers and files used by government
2-12
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Components
workers (military, civilian, or contractors) when suspected of unauthorized transfer of information. Only
authorized investigation agencies (e.g., the Federal Bureau of Investigation and Criminal Investigation
Division) will perform these investigations. Under present federal and state laws and statutes, most counter-
attack actions are illegal.
2-59. Transmission security secures information across the various networks. Trunk encryption devices, in-
line encryption devices, COMSEC, frequency hopping, and time division techniques usually secure
transmissions. Transmission security ensures information security when using one or more of these
techniques or devices. All systems must operate in SECRET systems high mode to prevent the intrusion into
information systems. Any non-secure system or device connected to, or entering, any secure network must
have an inline encryption device in use between the network entry point and the entering equipment. This
ensures complete network security. In some cases there may be a requirement to send information across
domains. In these cases a cross domain solution is required. A cross domain solution is ―An information
assurance solution that provides the ability to manually and/or automatically access and/or transfer
information between two or more differing security domains.‖ (Chairman of the Joint Chiefs of Staff
Instruction [CJCSI] 6211.02B) A security domain is a system or network operating at a particular sensitivity
level.
2-60. COMSEC in networks and system devices is essential in order to protect the networks information.
Specific keys enable secure encryption of the voice and data passed through transmission devices and
computers. The National Security Agency controls most encryption keys and governs local key generation,
distribution, and storage of these materials.
2-61. Information security policies deny unauthorized persons access to classified or sensitive information
during electrical transmission from the sender to the receiver. They establish requirements designed to
prevent the disclosure of valuable information from other aspects of communications (for example, traffic
flow and message analysis) and to enhance the authentication of communications. (See AR 380-5, AR 380-
40, and Technical Bulletin 380-41 for additional information on COMSEC.)
2-62. Demonstrations in the banking industry have shown how vulnerable encoded systems are to any
individual or adversary with the help of ordinary computer technology. The demonstration validated that the
civilian sector and government agencies are subject to intrusions and attacks from ordinary sources using
current, state-of-the-art technology. Though the demonstration focused on encryption keys of less
complexity than used in the Army, it reiterated that good COMSEC procedures and password control must
be followed at all times.
2-63. The information operations condition (INFOCON) system provides a framework for commanders to
increase the measurable readiness of the networks to match operational priorities. The Army maintains the
general status of its networks and information systems by using INFOCON reporting procedures. The
INFOCON provides a coordinated, structured approach of defense against, and reaction to, attacks on DOD
computers, networks, and information systems. IT, increased system connectivity, and standoff capability
make computer network attacks attractive to adversaries of the US. INFOCON outlines countermeasures to
scanning, probing, unauthorized access, and data browsing. See the Army Global Network Operations and
Security Center (A-GNOSC) and Army Computer Emergency Response Team Tactical Operations Center
statuses are—
z
INFOCON 5—NETOPS procedures IAW Strategic Command Directive 527-1.
z
INFOCON 4—increased military vigilance procedures.
z
INFOCON 3—enhanced readiness procedures.
z
INFOCON 2—greater readiness procedures.
z
INFOCON 1—maximum readiness procedures.
DETECTION
2-64. Real-time security management and intrusion detection should be included in routine operations for
NOSCs. To detect occurrences that constitute violations of security policies, selected events or occurrences
19 November 2008
FM 6-02.71
2-13
FOR OFFICIAL USE ONLY
Chapter 2
(such as numerous log on attempts within a specified period) are monitored using conventional protection
and detection tools and devices. When violations are detected, the network manager must prevent further
violations and report the event to the commander, information assurance security officer (IASO), TNOSC,
and regional computer emergency response team (RCERT).
2-65. NOSCs (such as the A-GNOSC and TNOSC) provide near real-time surveillance for networks and
systems to detect suspicious security events and initiate preliminary defensive actions to block or contain
the attack in order to minimize the operational impact. Robust and resilient infrastructure architecture
isolates and controls the damage from attacks, and makes these systems readily repairable in case of attack.
The fundamental criteria are that no single attack leads to failure of a critical function, and no single
protection mechanism protects critical functions or systems.
2-66. Network managers and users must train in all aspects of information systems security on the systems
they operate and maintain. They must maintain the audit functions and review audit information for
detection of possible system abuse. They must also coordinate with the information assurance manager
(IAM), information assurance network manager (IANM), IASO, and other appropriate agencies when
violations occur.
2-67. Appropriate safeguards detect and minimize unauthorized access and inadvertent, malicious, or non-
malicious modification or destruction of data. Appropriate detection safeguards ensure security
classification labels remain with data transmitted via a network to another information system.
2-68. Security management devices and IAVMs warn NOSC personnel of intrusion attempts, attacks, and
other anomalies for networks and systems. The response to these alerts depends on the severity of the
attack, intrusion, or breach. Appropriate reactive measures must be taken when problems occur. Network
managers need to consider operational status or mission status before responding to alerts. The information
systems protection concept envisions real-time security management as a component of NETOPS as well as
being incorporated into the operations. When detection occurs, network managers may need to take the
following actions—
z
Change boundaries and perimeters.
z
Reconfigure firewalls, guards, and routers.
z
Reroute traffic.
z
Change encryption levels or re-keys.
z
Zeroize suspected compromised communications.
z
Re-establish a net without selected members.
z
Change passwords and authentication.
PASSWORD CONTROL AND AUTHENTICATION
2-69. Since 31 JUL 06, access to all Army networks is mandated to be via the Common Access Card only.
This was mandated by the Army Password Standards Version 2.5. Passwords are an important aspect of
computer security and are used to achieve authenticated access control at the workstation or host level for
authenticating user’s access to Army resources until Common Access Card is implemented or for personal
use. A poorly chosen password may result in the undetected compromise of an Army network or unlawful
usage of Army systems. As such, all users, employees, including contractors and vendors, with access to
Army information systems, are responsible for taking the appropriate steps to select and secure their
credentials. The commander’s designated representative oversees generation, issuance, and control of all
passwords. Password issuance is performed IAW AR 25-2. Basic password guidelines are—
z
After generation, password handling and storage are at levels of the most sensitive data contained
in the system. Password issuance is only available to users authorized to access the system.
z
At the time of password issuance, all users will be briefed on—
Exclusiveness, classification, and uniqueness of each password.
Safeguard measures required for classified and unclassified passwords.
2-14
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Components
Prohibitions against disclosure to anyone, to include personnel assigned to
the same project and holding identical clearances.
Immediately informing the IASO of password disclosure, misuse, or other
potentially dangerous practices.
One time issuance of password.
Retirement of passwords when the time limit has expired or the user has
transferred to other duties, been reassigned, retired, or been discharged or
otherwise separated from the duties or the function for which the password
was required.
Passwords, as unique identifiers of individual authority and privileges, are
strictly for use by one user.
Changing all passwords IAW AR 25-2.
Protection of passwords against unauthorized observation on terminals and
video displays.
z
In addition to a password, a user can be authenticated by something the user possesses (token), or
a physical characteristic (biometric).
REACTION
2-70. Reaction to a network or information system intrusion incorporates the capability to restore essential
information services and initiate IO attack response processes. Establishing a disaster recovery capability
requires devising restoration procedures in a detailed COOP plan. The plan should address various levels of
restoration depending on the number of possible disasters. Immediate restoration capabilities may rely on
backup or redundant network links or system components, backup databases, or even alternative means of
information transfer services.
2-71. Network managers do not require permission to react to attacks or intrusions if their activities are
IAW appropriate regulations, statutes, and public law. Upon verification that an intrusion has occurred,
network managers or the system administrators must take the following emergency steps:
z
Stop the breach, if possible, and restore any destroyed or compromised data from backups and
other identified COOP capabilities.
z
Follow network security incident policy, as outlined in the standing operating procedure and
other applicable regulations.
z
Report the incident to the commander, IAM, or IASO and the supporting RCERT immediately.
z
Report the incident to other control facilities, as required.
2-72. The response processes begin when the emergency is under control and information services are
restored. Responses can be offensive or defensive. Offensive measures are restricted to law enforcement
agencies during peacetime operations. During hostilities, the commander may use military force to eliminate
or disrupt the means or systems an adversary uses to conduct an information attack. Defensive responses
include all measures and countermeasures available to a commander to limit an adversary’s attack,
exploitation, or deception, or an electronic warfare capability to protect against further attacks.
Note. A network manager, systems administrator, or user performs only defensive actions. They
do not perform offensive actions, such as hacking into adversaries’ computers or launching
computer attacks.
ROLES AND RESPONSIBILITIES
2-73. All network and information system users are responsible for the security of the terminal devices and
transmission media they use. AR 25-2 describes the information systems security program and the authority
for protecting these systems. It requires structured physical and network security programs that include
19 November 2008
FM 6-02.71
2-15
FOR OFFICIAL USE ONLY
Chapter 2
security personnel and procedures to combat intrusions into networks and information systems. Specific
organizations and personnel within DOD protect against, detect, and react to intrusion and attacks to the US
information infrastructure. The following paragraphs discuss the roles and responsibilities of the
organizations and personnel that play an integral part in IA at the numbered Army, corps, division, and
BCT.
2-74. The Unified Command Plan 2004, dated March 2005, assigns CDRUSSTRATCOM as the CCDR for
IO and global communications system intelligence, surveillance, and reconnaissance. CDRUSSTRATCOM
has determined that this mission includes directing global network operations (GNO), advocating the
NETOPS requirements for all combatant command (command authority) (COCOM), and planning and
developing national requirements.
2-75. JTF-GNO directs the operation and defense of the GIG to assure timely and secure network enabled
capabilities across strategic, operational, and tactical boundaries in support of DOD's full spectrum of
warfighting, intelligence, and business domains.
2-76. The commander, JTF-GNO, will exercise operation control (OPCON) of the GIG for GNO issues.
Under the authority of CDRUSSTRATCOM, JTF-GNO issues the orders and directives necessary to
maintain the assured service of the GIG, ensuring that the President, Secretary of Defense (SECDEF),
combatant commands, services, and agencies
(CC/S/A) can accomplish their missions. The CC/S/A
executes the JTF-GNO’s directives within their respective areas and report compliance.
DEFENSE INFORMATION SYSTEMS AGENCY
2-77. DISA performs significant NETOPS support functions. DISA manages OPCON over information
services, IT environments, and computing processing centers for all DOD components. For additional
information regarding the roles and responsibilities of DISA, refer to Chapter 3.
2-78. DISA also provides the Department of Defense-Computer Emergency Response Team (DOD-
CERT), which is the information security incident response support to the GIG community for IA. The
DOD-CERT identifies, analyzes, assesses, and resolves all information security vulnerabilities and
exploitations in the GIG to support the DISA’s IA mission. The DOD-CERT works closely with service
response teams and organizations to combat the threat of attacks and intrusions into the GIG.
DEPARTMENT OF DEFENSE-COMPUTER EMERGENCY RESPONSE TEAM
2-79. The DOD-CERT is under OPCON of the JTF-GNO and serves as the primary network or information
system intrusion response capability within the DOD. It helps identify, assess, contain, and counters attacks
that threaten IO across the spectrum of military operations. In addition to the DOD-CERT, the services
establish computer emergency response teams (CERTs) to provide an effective CND for their portion of the
GIG. The Army infrastructure consists of an A2TOC, RCERTs, and local CERTs. They work with other
security agencies to minimize or eliminate identified vulnerabilities to networks and information systems.
Their major capabilities include—
z
Identifying and resolving computer security anomalies that affect the GIG’s ability to support the
Soldier.
z
Identifying threats to networks and information systems; developing, disseminating, and
implementing countermeasures to these threats.
z
Assessing the incidents reported and determining the impact on the Soldier’s ability to carry out
his mission.
z
Coordinating the response actions taken by the organizations experiencing intrusions.
z
Serving as the technical advisor on all protection measures.
2-16
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Components
JOINT TASK FORCE-GLOBAL NETWORK OPERATIONS
2-80. The commander, joint task force-global network operations (CJTF-GNO) will exercise OPCON of
the GIG for GNO issues. To achieve this mission, CDRUSSTRATCOM assigned these tasks to the CJTF-
GNO:
z
Maintain direct operations and defense of the GIG.
z
Maintain GIG availability and integrity; ensure efficient traffic management.
z
Establish and oversee SA of the GIG readiness and defensive posture.
z
Assist CDRUSSTRATCOM in developing tools, monitoring threats, verifying policy
compliance, and controlling network access for consistent IAVM.
z
Direct and oversee network defense and information services.
z
Assist in establishing and maintaining standards for network, component, and defensive
requirements.
z
Conduct network defense planning, preparation, and operations employment for normal
operations and for crisis and deliberate planning. When directed, support deliberate and crisis
action planning requested by other CCDRs.
z
Develop, coordinate, integrate, direct, and oversee specific network defense courses of action in
support of GIG NETOPS and defense. Coordinate with CDRUSSTRATCOM for approval
authority on Tier 2.1 CND response actions.
z
Support United States Strategic Command (USSTRATCOM) participation in exercises and
experiments involving GIG network management and defense.
z
Provide intelligence requirements in support of network defense.
z
Provide assessments and recommendations to USSTRATCOM for watch condition
(WATCHCON) changes dictated in network threat warning.
z
Provide recommendations to USSTRATCOM for INFOCON changes.
z
Direct and oversee the establishment and maintenance of standards for technical testing,
evaluation, and measures of effectiveness of NETOPS and defense capabilities.
z
Direct and oversee establishing procedures to provide department measures of effectiveness and
battle damage assessment during and following network defense operations.
z
Assist in formulating guidance for training NETOPS and defense forces.
z
Assist in developing and promulgating joint tactics, techniques, and procedures for NETOPS and
defense activities.
z
Identify desired characteristics and capabilities for NETOPS and defense.
2-81. USSTRATCOM has assigned the GNO mission to the JTF-GNO, which was formed by the merger of
the DISA Global Network Operations and Security Center (GNOSC) and JTF-GNO. The JTF-GNO is
staffed 24 hours a day, seven days a week. Due to the merger, the JTF-GNO can take advantage of the
existing intrusion detection capabilities of the unified commands, its components, and DOD and non-DOD
agencies. The joint task force (JTF) receives intrusion data from these sources and then fuses this critical
information with ongoing operational missions and intelligence and technical data into a synopsis of the
incident.
2-82. United States Army Space and Missile Defense Command (USASMDC)/United States Army Forces
Strategic Command (ARSTRAT) is the Army Service component command (ASCC) to USSTRATCOM
and directly supports the JTF-GNO. USASMDC/ARSTRAT is also USSTRATCOM’s primary point of
contact for all Army NETOPS and CND missions. USASMDC/ARSTRAT plans, integrates, and sustains
Army CND and is the communications system advocate. The commander, USASMDC/ARSTRAT has
designated the Commanding General (CG), NETCOM/9th SC(A) as the USASMDC/ARSTRAT deputy for
NETOPS to represent USASMDC/ARSTRAT in communicating and coordinating directly with DOD and
USSTRATCOM regarding NETOPS. (Refer to Figure 2-2.)
19 November 2008
FM 6-02.71
2-17
FOR OFFICIAL USE ONLY
Chapter 2
CHIEF INFORMATION OFFICER G-6
2-83. The CIO G-6 establishes policy and procedures to manage a cohesive AIAP. The CIO G-6 is the
focal point for managing and implementing the AIAP. The CIO G-6 reviews and evaluates proposed
policies, procedures, directives, doctrinal publications, plans, materiel requirement documents, life-cycle
management documents, basis of issue plans (BOIPs), and similar documents with IA implications.
Additional responsibilities include—
z
Evaluating technological trends in IA and establishing a methodology to integrate advancements
into networks and information systems.
z
Providing IA policy to Army elements to include assisting PEOs and program managers in
identifying and incorporating IA requirements in the development of new information systems.
z
Acting as the Army proponent for the IA training and awareness program.
z
Providing direction, procedures, and guidance on IA protection measures to all Army support
organizations.
z
Developing certification requirements for system administrators, network managers, and IA
personnel (information assurance program manager [IAPM], IANM, IAM, and IASO).
Note. AR 25-6 uses IAPM, IANM, IAM, and IASO as replacements for the information systems
security program manager, information systems security manager, and information systems
security officer used in AR 25-2.
OPCON
DIRLAUTH
SMDC/
ARSTRAT
USA NETCOM
OPCON
SGNOSC
ADCON
Ft Belvoir
Supports
STNOSC
STNOSC
STNOSC
STNOSC
STNOSC
USARPAC /
USAREUR
USARSO
USARCENT
CONUS
EUSA
RNOSC
RNOSC
RNOSC
RNOSC
RNOSC
RNOSC
RNOSC
RNOSC
RNOSC
RNOSC
RNOSC
RNOSC
USPACOM
USEUCOM
USSOUTHCOM
USCENTCOM
USNORTHCOM
Figure 2-2. US Army Space and Missile Defense Command/US Army Forces Strategic
Command
2-18
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Components
NETWORK ENTERPRISE TECHNOLOGY COMMAND/9TH SIGNAL COMMAND (ARMY)
2-84. The NETCOM/9th SC(A) is responsible for the operations, management and defense of the LWN to
include centralized intrusion detection and monitoring worldwide. Collocating and integrating the
operations of TNOSCs with the 1st Information Operations Commands (IO CMDs) RCERTs providing a
common view of all detected network and host intrusion events to the strategic and tactical units worldwide.
2-85. This collocation provides theater and below support by monitoring, detecting, and responding to
incidents within their AOR. The RCERTs provide training within their AOR and conduct local coordination
with Army criminal and counterintelligence assets. They also disseminate information and reports
throughout their AOR and to the A2TOC for further analysis and dissemination.
2-86. NETCOM integrates and coordinates the execution of NETOPS to include CND support to
USSTRATCOM/JTF-GNO. Through the A-GNOSC, NETCOM/9th SC(A) is responsible for global
NETOPS and CND actions across the entire Army LWN. The A2TOC, maintains/provides daily NETOPS
and CND SA to Army and Joint leadership. The A2TOC will provide recurring reports (e.g. commander’s
critical information requirement, operational, situational) and, if applicable, day-to-day actions and
preplanned NETOPS and CND operations directly to JTF-GNO and USASMDC/ARSTRAT.
ARMY GLOBAL NETWORK OPERATIONS AND SECURITY CENTER AND ARMY COMPUTER
EMERGENCY RESPONSE TEAM TACTICAL OPERATIONS CENTER
2-87. The A-GNOSC and Army computer response team (ACERT) operate the A2TOC. The A2TOC is the
single focal point for Army NETOPS. As part of NETOPS, 1st IO CMD and the 2nd Battalion, 1st IO
CMD are in direct support of the Army for all CND and CND response action.
2-88. All IA security incidents and vulnerabilities for the Army are reported to the A2TOC as the Army’s
single focal point. The A-GNOSC is responsible for IAVM. All IAVM messages are posted to Army
Knowledge Online (AKO) NIPRNET and SECRET Internet Protocol Router Network (SIPRNET), and all
IA personnel are required to subscribe to the AKO Knowledge Management Center to receive IAVM
notifications. The IAVM message are used to notify directorates of information management (DOIMs),
regional chief information officer
(RCIOs), IAPMs, network managers, IAMs, IASOs, system
administrators, and eventually users of incidents, vulnerabilities, and other potential network security
events.
2-89. The A2TOC monitors, detects, and prevents network and information system attacks. It also conducts
vulnerability assessments and responds to Army IA security incidents. The A2TOC leverages and integrates
intelligence support from counterintelligence, OPSEC staff, and law enforcement agencies. ICW the
A2TOC, theater teams and other Army NOSCs unify the CND effort across Army networks.
INFORMATION OPERATIONS TRIAD
2-90. The CIO G-6, the Deputy Chief of Staff for Operations and Plans, and the Deputy Chief of Staff for
Intelligence form the Information Assurance Triad. In a coordinated effort, these agencies implement
procedural and material protective measures, develop plans and policies, and validate requirements to
protect command, control, communications, computers, and intelligence systems. The CIO G-6 has overall
responsibility and oversight for the ACERT program.
2-91. The Deputy Chief of Staff for Operations and Plans IA responsibilities, as they relate to the ACERT
program, consist of providing staff support and OPCON of the 1st IO CMD.
2-92. The Deputy Chief of Staff for Intelligence IA responsibilities, as they relate to the ACERT program,
include—
z
Identifying the threat and establishing policy for integrating intelligence support.
z
Identifying computer network attack capabilities targeted against friendly information systems.
z
Promulgating the information systems security monitoring policy.
19 November 2008
FM 6-02.71
2-19
FOR OFFICIAL USE ONLY
Chapter 2
Note. See AR 25-2 and pertinent security and intelligence regulations for additional AOR
specific details of these agencies.
1ST INFORMATION OPERATIONS COMMAND
2-93. 1st IO CMD, through the ACERT and in conjunction with the A-GNOSC, provides CND for the
LWN. The ACERT analyzes operational information relating to threats to the LWN; supports the Army
with attack sensing and warning, indications and warnings; and synchronizes and executes global CND
operations in support of Army and joint forces worldwide.
NOSC AND CERT RELATIONSHIP
2-94. The NOSCs and CERTs assist in the war against attackers, intrusions, viruses, and other technical
complications when needed. They are collocated, enabling the organizations to work closely together to
protect network and information systems.
2-95. The ACERT and RCERT use specific security and vulnerability assessment tools (e.g., scanning
tools) for network and systems evaluation. These CERTs will enter equipment, networks, and systems only
at the request of the commanders or the equivalent responsible person. (Refer to AR 25-2 and AR 380-53
for specific authorizations and details of these missions.)
2-96. The A-GNOSC, TNOSCs, and other NOSCs perform their GND duties IAW AR 25-2. The NOSCs
and CERTs may also perform duties IAW other pertinent SOPs, regulations, and public laws.
2-97. Reporting procedures for incidents of intrusions and attacks flow vertically and horizontally to all
levels of the chain of command, system administrator, IASO, IAM, DOIM, RCIO, theater team, A2TOC,
and JTF-GNO. This flow of information allows for notification and an area view, by authorized
organizations, to combat an all-out attack against networks, systems, computers, and the GIG.
2-98. The commander, network manager, or user notifies the local IASO and IAM when he detects an
actual or potential security incident or intrusion. The IASO or IAM then reports the incident or intrusion to
the supporting CERT and NOSC. The CERT works with the network manager and customer to identify the
problem, remove the threat, and recover from the incident. These teams respond to incident reports and
coordinate actions IAW CJCSI 6510.01E, Chapter 1, appropriate service regulations, and public laws.
INFORMATION ASSURANCE PROGRAM MANAGERS
2-99. An IAPM is appointed at each Army command (ACOM) and PEO. The IAPM establishes, manages,
and assesses the effectiveness of the IA program at that command or activity. The IAPM manages the
personnel who perform the computer security and COMSEC sub-disciplines of IA. AR 25-2 contains a
complete list of responsibilities for all IA personnel. Other responsibilities of the IAPM include—
z
Establishing and managing a command IA program and developing an IA policy based on
command-unique guidance.
z
Establishing and overseeing an IA training and accreditation program that integrates IA into
operational training programs for managers, system administrators, and users.
z
Coordinating and reviewing operational concepts, SOPs, and security accreditation for command
and control systems.
z
Chairing the ACOM IO Triad, ensuring IA standards and programs are enforced.
z
Ensuring an ACOM IANM is appointed.
z
Ensuring IAMs are appointed at designated echelons below the ACOM.
z
Serving as the ACOM point of contact for IAVM advisories and managing the command IA
incident reporting program.
2-20
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Components
ARMY COMMAND INFORMATION ASSURANCE NETWORK MANAGER
2-100. An ACOM IANM is appointed to support the IAPM with network security and the command IA
program. Specific responsibilities include—
z
Developing and staffing IA technical policy and procedures for all ACOM-unique networks and
information systems.
z
Ensuring that all networks and information systems are planned, installed, managed, maintained,
and properly accredited IAW AR 25-2.
z
Ensuring that all IA command policies are implemented.
z
Assisting the IAPM in monitoring and enforcing the IAVM process.
INFORMATION ASSURANCE MANAGER
2-101. An IAM is appointed at the appropriate levels of command below ACOMs, which include major
subordinate command, post, camp, and stations. Where there are multiple IAMs, the installation IAM will
be designated as the senior IAM. The responsibilities of the IAM include—
z
Developing, staffing, and managing IA plans for his AOR.
z
Conducting individual network and information systems risk assessment to determine potential
threats and vulnerabilities, and determining appropriate measures to effectively manage the risks.
z
Conducting IA training and awareness programs.
z
Implementing IA and IAVM reporting and compliance procedures, to include IA incidents and
technical vulnerabilities.
z
Ensuring that an IASO is appointed for each network and information system, and an IANM for
each installation or NOSC.
z
Establishing the scope of responsibility for each IASO.
INFORMATION ASSURANCE NETWORK MANAGER
2-102. The IAM appoints an IANM for each installation or group of networks to provide direct support to
the IAM. The responsibilities of the IANM include—
z
Implementing the IA program for networks IAW policy received from the appropriate network
security manager, the IAPM, and the IAM.
z
Ensuring procedures are in place to support security integrity of the network, providing
protection for the network, and supporting secure access controls and connectivity.
z
Developing and implementing security procedures and protocols.
z
Conducting reviews of network threats and vulnerabilities, and reporting any attempts to gain
unauthorized access to the network.
z
Implementing IA and IAVM reporting and compliance procedures to include the use of only
Army-approved IA products.
S-2 AND G-2
2-103. The intelligence staff officer (S-2) and assistant chief of staff, intelligence (G-2) identify and assess
foreign intelligence threats directed toward command assets and functions. Within the context of NETOPS,
this staff officer will consider the threats to the command’s information systems and networks as part of his
overall intelligence support program by—
z
Being engaged in the reporting of IA-related security violations and incidents to the servicing
RCERT IAW Section VIII, Incident and Intrusion Reporting of AR 25-2.
z
Including IO and IA requirements in submissions of commander’s critical information
requirements or priority intelligence requirements.
z
Providing technical and non-technical information to support a commander’s INFOCON
program.
19 November 2008
FM 6-02.71
2-21
FOR OFFICIAL USE ONLY
Chapter 2
z
Providing a means for commanders, risk managers, IAMs, and IANMs to request intelligence to
fill knowledge gaps about threats to information systems and networks during any phase of the
IA program process.
G-6
2-104. The G-6 has overall responsibility for the secure operation of network and information systems at
all levels. The G-6 assumes the responsibilities of the IAM, supervises the IANM, and oversees the actions
of the IASOs in the subordinate units.
INFORMATION ASSURANCE SECURITY OFFICER
2-105. The IASO is an additional duty appointed by the commander for each information system or group
of systems. The IASO—
z
Prepares, distributes, and maintains plans, instructions, guidance, and SOPs for command and
control systems security.
z
Prepares or oversees the certification and accreditation documentation of systems IAW AR 25-2.
z
Coordinates with the brigade S-2 to ensure users have the required security investigations,
clearances, authorizations, and need-to-know.
z
Establishes and implements a system for issuing, protecting, and changing systems passwords.
z
Establishes the training and awareness programs.
z
Monitors and ensures the proper security of systems connected to the network.
z
Assesses direct threat and vulnerability, enabling the commander to analyze the risks to
interconnected systems.
z
Determines appropriate measures to manage network risks effectively.
z
Oversees the review of network and information systems audit trails, resolves discrepancies, and
reports incidents to the brigade or battalion S-2 for evaluation and reporting.
z
Performs assigned password control duties.
S-6
2-106. The command, control, communications, and computer operations (S-6) have overall responsibility
for the secure operation of the network and information systems at BCT and subordinate units. At the BCT,
the S-6 normally assumes the role and responsibilities of the IASO unless otherwise appointed by the
commander. The responsibilities of the S-6 include—
z
Advising the commander on recommended IA policy updates.
z
Determining the network plan for IA to distribute the IA tools to the network and information
system managers.
z
Downloading the appropriate tools as they are updated or as new tools are introduced.
z
Downloading and distributing the current network IDS, attack and virus files, and the relevant
software security patches.
z
Monitoring the network IDS and network IPS for possible attacks and reconfiguring the network,
if necessary.
z
Ensuring that password integrity is maintained.
S-3
2-107. The operations staff officer (S-3), as the operations officer for signal units at the numbered Army,
corps, division, BCT, and battalion, supervises the IANM and the operation of the Information Analysis
Center. The Information Analysis Center resides within the NOSC and consists of several workstations that
monitor a variety of IA software applications and tools.
2-22
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Components
USER
2-108. Each information systems user is responsible for security. The user—
z
Secures operations of his information systems.
z
Operates his terminal IAW equipment operation procedures and SOPs.
z
Performs other duties as assigned by the IASO and network manager to ensure security and
protection of network and information systems.
z
Follows regulatory and policy restrictions for authorized use of government equipment.
z
Reviews and complies with user responsibilities outlined in AR 25-2.
z
Reviews and acknowledges the Acceptable Use Policies as provided by the IASO.
INFORMATION ASSURANCE TOOLS
2-109. A variety of software and hardware tools enable network managers and IANMs to prevent, detect,
monitor, and evaluate intrusions into their networks. These tools change continuously as technology
evolves, and they must be CIO G-6 approved. The CIO G-6 approves the current list of protection tools and
distributes them to subordinate activities, as necessary. The A2TOC and RCERTs maintain these tools and
software on their Web sites for downloading by network managers and system administrators. (Refer to
Appendix B for a detailed discussion of the different systems and tools available to perform the required
NETOPS functions). Protection and detection tools include—
z
Audit monitoring and IDSs and IPSs.
z
Isolate systems under attack by automated infrastructure management.
z
Detect malicious codes and eradicate systems.
z
Analyze and assess vulnerability.
2-110. To protect against external and internal attackers and virus attacks the RCERT and A2TOC
recommend, and the IANM enforces, the following hardware and software tools:
z
Antivirus software.
z
Hard-disk purge capability.
z
Network mapping software.
z
Audit profile software.
z
IDSs and IPSs.
z
Secure password generation systems.
z
Inline network encryption devices.
z
Firewalls, high-assurance guards, and tactical security guards.
z
Encryption key management systems.
z
Security posture of networks and systems.
z
Host Base Security System.
z
Patch Management System.
z
Vulnerability Scanning Systems.
INCIDENT AND VULNERABILITY REPORTING
2-111. Any user noticing abnormal or suspicious activity must report it to his chain of command, IAM,
IANM, IASO, and CERT. The internal staff reporting will be designated by local SOP. Refer to the A2TOC
Web site at https://www.acert.1stiocmd.army.mil, the DOD-CERT Web site at https://www.cert.mil/ , or
CJCSI 6510.01E, Chapter 1 for details on incident and vulnerability reporting. Detection of security
incidents may cause users or network managers to conduct—
z
Logging. Recording security-relevant information to facilitate detection and investigation of
security breaches IAW applicable regulations, statutes, and public laws. All devices require
reporting the event to an audit manager.
19 November 2008
FM 6-02.71
2-23
FOR OFFICIAL USE ONLY
Chapter 2
z
Local reporting. Specific security-relevant events and violations will follow reporting
procedures to the IAM, IASO, S-3, G-6, and S-6 depending on the incident and reporting
process.
z
Remote reporting. The IAM, IASO, S-3, G-6, and S-6 evaluate security-relevant events and
report the specific occurrences through the chain of command and operational structure to the
CERTs.
z
Recovery actions. After a security breach, implementation of recovery actions occurs
throughout the affected networks and equipment.
INFORMATION ASSURANCE VULNERABILITY MANAGEMENT
2-112. The IAVM message is another method used throughout to report vulnerabilities. The A-GNOSC is
the Army’s focal point for the implementation of the IAVM process. The AKO Knowledge Management
Center mail service, on behalf of the A-GNOSC, issues alerts, bulletins, technical tips, and system
administrator reports. These messages are based on both mandatory JTF-GNO information assurance
vulnerability alert (IAVA) messages and Army generated IAVM requirements. The A-GNOSC messages
direct specific actions (protect, detect, and react) and establishes mandatory suspense dates for compliance.
concerning IAVM policies.
2-113. IAVM is the DOD program to identify and resolve discovered vulnerabilities in Army systems and
platforms. It requires the completion of four distinct phases to ensure compliance. These phases are: (1)
vulnerability identification, dissemination, and acknowledgement; (2) application of measures to affected
systems to make them compliant; (3) compliance reporting; and (4) compliance verification. This program
includes IAVAs, information assurance vulnerability bulletins (IAVBs), and technical advisories.
2-114. A patch is an immediate solution provided to users once a bug is discovered and can often be
downloaded from the software maker's Web site. Previously, patches required a manual touch at each
device on the network coupled with the length of time an automated tool was required. An enterprise
solution has been selected by the DOD which is Eye Retina for scanning and Citadel Hercules for
remediation.
2-115. Complete asset inventories (100 percent) will be conducted and reported to the Army Asset and
Vulnerability Tracking Resource (A&VTR) Database semi-annually as a minimum and after every IAVM.
Training
is
to
be recorded
in
the
Army Training Command database at
https://atc.us.army.mil/iastar/index.php. Dissemination of IA technical advisories, IAVBs, and IAVAs will
automatically be forwarded upon registration completion. Interoperability testing will be performed prior to
the application of system patches and fixes for interoperability compliance.
2-116. All IAVMs will be applied immediately. If the IAVM cannot be implemented, a mitigation plan
must be submitted in A&VTR for approval/disapproval.
SCANNING AND REMEDIATION
2-117. Scanning is the gathering of information on information systems and device configurations, which
may be used for system identification, maintenance, security assessment and investigation, vulnerability
compliance, or compromise. This includes network port scanning and vulnerability scanning, whether wired
or wireless, classified or unclassified. Scanning is conducted throughout all phases of operation (phases
0-4).
2-118. An operational scanning capability will be retained at the unit level as well as layered throughout
the enterprise operational management structure for all classifications of networks. Regular, scheduled, and
no-notice scans are integral to Security Policy and Compliance Enforcement and shall be done at all levels
and all operational networks. Scanning tools may be obtained through Communications Security Logistics
Activity.
2-24
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Components
2-119. Assessors must use a five step methodology for assessment scanning as follows: identify assets,
determine vulnerabilities, review vulnerabilities, remediate vulnerabilities, and validate remediation
measures. All new information systems and device vulnerabilities must be proactively managed.
2-120. System administrators/Network managers must identify and prioritize which systems are most
critical and develop a protection strategy. System administrator/Network managers and IA personnel will
perform routine and scheduled unit vulnerability assessments and management in addition to IAVM
procedures to manage system and network vulnerabilities proactively and to maintain the necessary skill
sets to remediate vulnerabilities proficiently, whether these networks reside with generating or deployed
forces. The system administrator/network manager needs the consent of the IASO and G-6/S-6, who will
consider operational or mission status and tactical bandwidth constraints before scanning. Table 2-1 details
the actions that must be conducted when scanning.
19 November 2008
FM 6-02.71
2-25
FOR OFFICIAL USE ONLY
Chapter 2
Table 2-1. Scanning guidelines/actions
Step
Scanning guidelines/actions
1
System administrator will obtain and maintain training and certification on Army approved
IA scanning tools from Communications Security Logistics Activity located at
2
System administrator will review Army Best Business Practices at
3
System administrator will scan network-attached devices with Army-approved products
monthly or after receipt of an IAVA.
4
System administrator will review scan reports and determine devices to be patched.
Update locally created database/spreadsheet for future reference on false positives.
5
IASO and system administrator will manually or electronically remediate devices requiring
patch.
6
IASO and system administrator will rescan network for patch verification.
IASO and system administrator will maintain scan results locally and report scan results to
the organization commander and IA personnel, DOIM and servicing NETCOM and
7
information management area component, RCIO, functional CIO, RCERT/TNOSC, or
ACERT/A-GNOSC.
8
IASO and system administrator will update A&VTR with compliancy information.
2-121. Remediation is defined as the process of correcting a fault or deficiency, or, in this case,
vulnerability. The system administrator/network manager will ensure the confidentiality of information by
preventing unauthorized individuals access to computer equipment. The system administrator/network
manager/operator will patch system security vulnerabilities on all Army platforms. DOIM and tactical unit
administrators are required to validate patches whether on the installation network or placed in storage.
These requirements should be stated in unit OPORDs and other directives with command.
2-122. System administrators are responsible for reducing the vulnerability of their system through the
application of software patches, both hot fixes and service packs. Table 2-2 details the actions taken during
the remediation process.
Table 2-2. Remediation actions
Step
Remediation actions
1
Implement unit policy, on a weekly basis, directing users to log off their workstations but
leave workstations on for application of patches during non-duty hours. Specific day to be
determined by the unit IAM.
2
Receive IAVM identifying required patch.
3
Select required patches from the applicable Web site.
4
Ensure individual responsible for IAVM has administrative rights to the assets to be
scanned and patched.
5
Scan assets (servers, routers, switches, and workstations) to identify assets that require
patch application.
6
Identify ―test‖ machine, apply patch, and scan the machine to confirm patch application.
7
Apply patch to the remainder of assets.
8
Issue Conformance Report (via patch application software).
9
Rescan to validate patch application.
2-26
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Components
Disaster Recovery/Continuity of Operations
2-123. A contingency plan or COOP is a plan for emergency response, backup operations, transfer of
operations, and post-disaster recovery procedures maintained by an activity as a part of its IA security
program. A disaster recovery plan/COOP ensures that organizations are able to continue functioning after
some catastrophic event and ensures that procedures are defined and in-place to protect and restore the
organization’s vital data and resume operations. Contingency plans/disaster recovery procedures will be
tested at a minimum annually. (For more detailed information on COOP, refer to AR 500-3 and Department
of the Army Pamphlet 25-1-2.) A list of objectives for a disaster recovery/COOP include:
z
Define the essential systems of the organization.
z
Describe the personnel necessary to maintain systems.
z
Define the objectives tasked with recovery.
z
Provide guidance for appropriate locations, timing, and actions required to restore operations in
an emergency.
Note. Appendix C provides scenarios that serve as examples of how many activities might occur
and their relationships between each other.
EMERGENCY PROCEDURES
2-124. Some cases require emergency procedures to protect US networks. Local SOPs generally explain
these emergencies. The following procedures are carried out only under extreme emergencies or otherwise
directed by the commander:
z
Notify activities, as required, to enable a proper response.
z
Purge systems.
z
Zeroize COMSEC devices.
z
Destruct classified systems only when capture is imminent.
SECTION III - INFORMATION DISSEMINATION MANAGEMENT AND CONTENT
STAGING
OVERVIEW
2-125. Managing and protecting networks and information systems for the users does not alone ensure that
relevant information is being provided to the Soldier to gain and maintain information superiority. The
management of access and delivery of relevant, accurate information to the appropriate user in a timely,
efficient manner and in the proper format is a major component of NETOPS.
2-126. IDM/CS provides the LWN warfighting intelligence and business domains at all levels (strategic,
operational, and tactical) with awareness of relevant, accurate information; automated access to newly
discovered or recurring information; and timely, efficient, and assured delivery of information in a usable
format. These services permit commanders to adjust information delivery methods and priorities for
enhanced SA. They also allow information producers to advertise, publish, and distribute information to the
Soldier. IDM/CS is accomplished by enabling LWN users to safeguard, compile, catalog, discover, cache,
distribute, retrieve, and share data in a collaborative environment. IDM/CS enhances all aspects of the
LWN transport capabilities and improves bandwidth utilization.
2-127. IDM/CS will allow NETOPS centers to optimize the flow and location of information over the GIG
by positioning and repositioning data and services to optimum locations on the GIG in relation to the
information producers, information consumers, and the mission requirements. Some of the objectives of
IDM/CS are:
z
Enabling commanders to adjust information delivery methods and priorities for enhanced SA.
19 November 2008
FM 6-02.71
2-27
FOR OFFICIAL USE ONLY
Chapter 2
z
Enabling information producers to advertise, publish, and distribute information to the Soldier.
z
Enabling users to define and set information needs to facilitate timely and efficient information
delivery and/or search information databases to retrieve desired products as required.
z
Improving bandwidth utilization.
z
Enhancing all aspects of the GIG transport capabilities.
2-128. IDM provides awareness of relevant, accurate information; automated access to newly discovered
or recurring information; and timely, efficient delivery of information based on the commander’s priorities.
It seeks to achieve the right information, arriving at the right place, at the right time, and in a usable format.
IDM uses specific processes, services, and applications to provide this information to Soldiers at the
strategic, operational, and tactical military operations.
2-129. IDM is the means for efficiently communicating information products (such as video, voice, and
data) to commanders and their staffs, and ensuring that they know its availability. It uses a distribution
system to integrate the delivery and notification functions of the information producers, consumers, and
managers. IDM will enable the Soldiers to do the following:
z
Define the types of information needed and have it delivered.
z
Define particular information products needed, and deliver them as requested.
z
Access data from a variety of information systems and retrieve relevant, accurate information for
situational understanding.
2-130. The core IDM/CS services are envisioned to be enterprise wide services used by the entire DOD to
ensure information is available to all authorized users. The core IDM/CS services are—
z
Content discovery.
z
Content delivery.
z
Content storage.
JOINT TASK FORCE-GLOBAL NETWORK OPERATIONS AND
NETWORK OPERATIONS COMMUNITY GRID CONTENT
MANAGEMENT RESPONSIBILITIES
2-131. GCM enables JTF-GNO and the NETOPS community to provide GIG users with an awareness of
relevant, accurate information, and automated access to newly discovered information for timely, efficient
delivery in a usable format. Again, this is accomplished in large part through SA and the associated
instrumentation of the GIG. Capitalizing on the content management framework found within the Net-
Centric Enterprise Services and Net-Centric Data Strategy, JTF-GNO will facilitate the placement, posting,
and transport of information required by GIG users.
2-132. NETOPS centers at all levels will be responsible for ensuring the content discovery, storage, and
delivery services, as well as mitigation, are operating correctly and that information is ―maneuvered‖ to the
optimum location on the GIG.
2-133. The IDM/CS services are used by NETOPS centers to ensure that the GIG is optimally delivering
the information required by GIG users IAW information delivery priorities. The IDM/CS services will
provide NETOPS centers at all levels with:
z
Visibility of the information flowing across the GIG and of those systems used to store, catalog,
discover, and transport information.
z
Tools to view information flows and access, to determine impact to network capacity, and to
ensure that user profiles are being satisfied with a reasonable quality of service.
z
The capability to prioritize information requirements, determine the sources responsible for
providing that information, and stage information content throughout the GIG in support of a
given operation.
2-28
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Components
z
The ability to track and maintain knowledge of the various requests and user profiles for
information; coordinate changes in the operating parameters of GIG assets; identify new
products; review and validate the user-profile database; and develop joint policies and
procedures governing information flow across the GIG.
2-134. IDM will also enable commanders to control, secure, and manage the use of networks and
information systems by establishing priorities for gaining access to the information products. Commanders
can also deny access to critical information and information products to maintain the integrity and non-
repudiation of the data. Additionally, IDM will assure timely delivery of critical information elements
across the battlefield.
PROVISIONING OF INFORMATION DISSEMINATION
MANAGEMENT/CONTENT STAGING
2-135. The following sections outline the IT organizations and their responsibilities concerning the
provision of IDM/CS. The following sections detail what is generally required by the information manager
across all echelons and phases of deployment. These responsibilities speak to the individual activities and
tasks that ultimately provide IDM/CS services to a user.
DIRECTORATE OF INFORMATION MANAGEMENT
2-136. The DOIM mission is to provide information systems and services support to the tenants and
business partners on installations, thus facilitating the provision of IDM/CS services. The goal of the DOIM
is to provide a focus of leadership for IT and to coordinate IT activities with the installation business
partners and customers. The DOIM will:
z
Build, test, and provide software distribution packages to the tactical units within its AOR.
z
Plan forest synchronization for the tactical units.
z
Perform PKI certification for the tactical units.
z
Provide technical support for tactical units’ organizational unit managers.
z
Carry out performance management (monitoring and analyzing) of the tactical units’ systems.
z
Provide anti-virus signatures to the tactical units’ e-mail servers.
z
Provide technical support on e-mail servers for the tactical units.
z
Schedule and facilitate video teleconferencing for the tactical units.
z
Provide multipoint video teleconferencing capability for the tactical units.
z
Provide mission specific sensitive and SECRET video teleconferencing service to the tactical
units, as required (e.g., classroom, transportable, command and control, and desktop).
z
Build the patch package.
z
Conduct necessary patch testing.
z
Provide Tier 3 support to the tactical units to ensure proper installation of the patch and to ensure
that operational integrity of the system(s) is maintained.
z
Push the patch package to the tactical units.
z
Notify tactical units when patch is successfully installed.
z
Maintain procedures to prepare for recovery of information from disasters and execute
preparatory procedures in support of the tactical units.
z
Operate, maintain, and manage the local control center in support of the tactical units.
z
Provide technical support on problems escalated from the tactical units.
BCT, DIVISION, AND CORPS INFORMATION MANAGEMENT
2-137. The unit information management mission insures that IDM/CS services are provided, assessable,
and utilized. The unit information manager will—
19 November 2008
FM 6-02.71
2-29
FOR OFFICIAL USE ONLY
Chapter 2
z
Restore to tactical units’ critical data in event of disaster.
z
Begin the process X.509 certificates and create FORTEZZA cards for tactical units.
z
Perform capacity measurement and performance analysis on tactical units’ e-mail servers.
z
Pull anti-virus signatures to the tactical units’ e-mail servers.
z
Perform forest synchronization for the tactical units.
z
Perform storage services (backup, recovery, archiving) on e-mail servers for the tactical units.
z
Apply system and desktop management services (monitoring, account management, CM, and
remote control) to the AD systems.
z
Apply patch management service to the AD systems.
z
Perform capacity and availability monitoring (collect, process, analyze, store, and report) of AD
systems.
z
Operate and maintain domain name service (DNS) servers.
z
Maintain Defense Message System servers, software, and other hardware within the AOR.
z
Escalate Defense Message System problems to DISA, if necessary.
z
Provide the capability to compose, format, transmit, and receive formal organizational e-mail
messages at individual workstations.
z
Provide unclassified, sensitive and classified organizational messaging capabilities.
z
Perform backup and recovery of the tactical units’ AD systems.
z
Obtain software distribution packages from the DOIM, regional service center, and regional
network operations and security center (RNOSC).
z
Maintain a separate and distinct AD forest.
z
Receive video teleconferencing services from DOIM, regional service center, and RNOSC.
z
Perform systems and desktop management organizational activities.
z
Provide technical support to the tactical units on all service management issues.
z
Pull, test, and provide software distribution packages to the tactical units.
z
Push software distribution packages to the subordinate units.
z
Provide additional event management capabilities, such as analysis and correlation of event data,
to the subordinate units, as required.
z
Operate and configure e-mail servers and clients.
z
Perform accounts management.
z
Perform resource availability measurements on e-mail servers.
z
Monitor e-mail components.
END-USER
2-138. An end-user is an individual who uses the GIG. Within this process, the end-user is the final
recipient of all services and processes discussed in this manual. End-users have the following general
responsibilities for IDM/CS:
z
Access and use authorized IT systems IAW Army policy.
z
Forward requests for configuration changes.
z
Maintain their desktop at approved configuration.
INFORMATION DISSEMINATION MANAGEMENT PRINCIPLES
2-139. IDM principles support the tenet that disseminating information is one of the primary activities
involved in information management. IDM is the communication of relevant information of any kind from
one person or place to another, in a usable form, by any means to improve understanding or to initiate or
govern action. Information dissemination takes the following two basic forms: broadcast or point-to-point
2-30
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Components
dissemination. IDM activities should exhibit a judicious combination of broadcast and point-to-point forms
of dissemination.
BROADCAST DISSEMINATION
2-140. Broadcast dissemination allows senders to distribute information simultaneously to a large number
of users. Anyone with access to the network can receive the information. The greatest advantage of this
method is that information managers can disseminate information to the widest audience in the shortest
amount of time. Since the information is sent to a variety of users with varying relevant information
requirements, the information cannot be tailored to a specific commander's needs. Another major drawback
of broadcast dissemination is that undisciplined use of this method can quickly lead to information
overload.
POINT-TO-POINT DISSEMINATION
2-141. Point-to-point dissemination directs information to a specific user or users. Information can be
easily passed from one commander to the next. The network can be tailored to meet specific relevant
information needs of each recipient with built-in control mechanisms that are not present in broadcast
dissemination. Each level of command can filter and integrate information as appropriate and modify it to
meet the needs of the next level of command before passing it on. The major disadvantages of point-to-
point dissemination are that information reaches a broad audience slowly, and the chances of distortion
increase through each level of command.
IDM SCALABILITY
2-142. IDM offers the commander a tremendous amount of flexibility with the capability to configure
networks and information systems to meet relevant information needs. Networks can be expanded or
contracted to meet the commander’s critical information requirements. Network links can be modified so
that throughput is increased or decreased for a particular user. Commanders and staff elements can be
designated to receive only certain information and information products. Separate networks can be
established to pass only that information which is critical to a particular set of users. Ultimately, IDM
allows the commander to determine what information is passed to whom, where, and when.
19 November 2008
FM 6-02.71
2-31
FOR OFFICIAL USE ONLY
Chapter 3
Network Operations Roles and Responsibilities
This chapter identifies the organizations and agencies with NETOPS responsibilities
that ensure connectivity of network and information systems users throughout the
GIG and LWN. It also explains the NETOPS roles and responsibilities of the
agencies and network managers at the various levels of the numbered Army, corps,
division, BCT, and battalion.
COMMANDER, UNITED STATES STRATEGIC COMMAND
3-1. NETOPS is the operational construct that the CDRUSSTRATCOM will use to operate and defend
the GIG. The goal of NETOPS is to provide assured and timely network enabled services across strategic,
operational, and tactical boundaries in support of DOD’s full spectrum of warfighting, intelligence, and
business missions. NETOPS ―service assurance‖ goals include: assured system and network availability,
assured information protection, and assured information delivery.
3-2. IAW Unified Command Plan 02, Change 2 and the supporting terms of reference, USSTRATCOM
will enable and enhance the effectiveness of network defenses by acknowledging and strengthening the
close interrelationship between NETOPS and network defense. CDRUSSTRATCOM will act through the
CJTF-GNO to—
z
Direct operations and defense of the GIG.
z
Maintain GIG availability and integrity; ensure efficient traffic management.
z
Establish and oversee SA of the GIG readiness and defensive posture.
z
Assist the CDRUSSTRATCOM in developing tools, monitoring threats, verifying policy
compliance, and controlling network access for consistent IAVM.
z
Direct and oversee network defense and information services.
z
Assist in establishing and maintaining standards for network, component, and defensive
requirements.
z
Conduct network defense planning, preparation, and operations employment for normal
operations and for crisis and deliberate planning. When directed, support deliberate and crisis
action planning requested by other CCDRs.
z
Develop, coordinate, integrate, direct, and oversee specific network defense courses of action in
support of GIG NETOPS and defense. Coordinate with the CDRUSSTRATCOM for approval
authority on Tier 2.1 CND response actions.
z
Support USSTRATCOM participation in exercises and experiments involving GIG network
management and defense.
z
Provide intelligence requirements in support of network defense.
z
Provide assessments and recommendations to USSTRATCOM for WATCHCON changes
dictated in network threat warning.
z
Provide recommendations to USSTRATCOM for INFOCON changes.
z
Direct and oversee the establishment and maintenance of standards for technical testing,
evaluation, and measures of effectiveness of NETOPS and defense capabilities.
z
Direct and oversee establishing procedures to provide department measures of effectiveness and
battle damage assessment during and following network defense operations.
19 November 2008
FM 6-02.71
3-1
FOR OFFICIAL USE ONLY
Chapter 3
z
Assist in formulating guidance for training NETOPS and defense forces.
z
Assist in developing and promulgating joint tactics, techniques, and procedures for NETOPS and
defense activities.
z
Identify desired characteristics and capabilities for NETOPS and defense.
z
Execute NETOPS through the integration of network and enterprise systems management
operations, IA and CND, and IDM/CS into a core GIG operational capability.
z
Coordinate with the Chairman of the Joint Chiefs of Staff (CJCS), Services, agencies, combatant
commands, and Assistant Secretary of Defense for Networks and Information Integration to
develop the policy and CONOPS for collaboratively operating the GIG.
z
Establish a global network operations center (GNC) and theater network operations center
(TNC) to execute designated responsibilities; provide NETOPS support to theater and functional
CCDRs, and coordinate with Services and agencies.
z
Establish policies and collaborative procedures that facilitate coordination and information
exchange with the other CCDRs, Services and agencies.
Note. Refer to Chapter
4 for additional information on the organizational structure of
USSTRATCOM.
COMBATANT COMMANDER
3-3. The CCDR has command and control of the component commands in the assigned theater of
operations. This responsibility includes the organizations and systems provided by DOD services and
agencies to extend the GIG into the theater. The CCDR’s J-6 assumes NETOPS responsibility to manage
and control the communications system resources in the joint area.
3-4. The CCDRs, through the supporting role of the NETOPS command and control organizations,
exercise OPCON over their portions of the GIG SA information resources (data stores, databases, graphical
views, etc.). The combatant command establishes priorities for information collection, filtering, display,
dissemination, etc. Consistent with these priorities, the CCDR controls the release of GIG SA information
to supporting and multinational forces. Subordinate and supporting commands
(service component,
functional component, sub-unified commands, and JTF) will provide fault and GND event and performance
data on all systems and networks within their commands. On behalf of the CCDR, the NETOPS command
and control organizations will consolidate and correlate this data to generate a single integrated GIG SA
view that will be available to all organizations via the SIPRNET.
3-5. The theater network operations control center (TNCC) leads the CCDR response to NETOPS events
and responds to JTF-GNO direction when required to correct or mitigate a global NETOPS issue. The
primary mission of the TNCC is to lead, prioritize, and direct theater GIG assets and resources to ensure
they are optimized to support the geographic combatant commander’s (GCC’s) assigned missions and
operations, and to advise the CCDR of the GIG’s ability to support current and future operations. The
specific roles of the TNCC include monitoring of the GIG assets in their theater, determining operational
impact of major degradations and outages, leading and directing responses to degradations and outages that
affect joint operations, and directing GIG actions in support of changing operational priorities.
JOINT COMMAND J-6
3-6. The J-6 serves on the CCDRs staff as the communications system director. The J-6 assumes the role
of the CCDRs network manager with the establishment of a joint network operations control center (JNCC)
that manages and controls all communications systems and networks deployed during joint operations and
exercises. The JNCC is the single control agency for the management and operational direction of all joint
communications system elements in the theater of operations. The NETOPS responsibilities of the J-6
include:
3-2
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Roles and Responsibilities
z
Formulating policy and guidance for all communications assets supporting the joint force
commander.
z
Developing communications system architectures and plans to support the mission of the CCDR.
z
Developing policy and guidance for the integration and installation of the operational networks.
z
Providing command and control of the joint information systems infrastructure.
z
Exercising staff supervision and OPCON of the theater assets provided by DISA, other Services,
and other DOD agencies.
z
Performing network management activities, functions, and tasks required to effectively and
efficiently manage the joint information systems infrastructure and multinational networks
supporting the CCDR mission.
z
Oversight of the TNCC in the management and control of the CCDRs communications system
assets in theater.
z
Ensuring adherence to COMSEC principles with the establishment of effective IA program
initiatives.
TEMPORARY OPERATIONAL COMMANDS
3-7. At the tactical level, NETOPS functions may be performed by a standing joint force headquarters,
standing joint force headquarters CCDR staff combination, combined JTF, or single Service task force.
CCDRs may organize a combined JTF or single Service task force and assign tailored forces among the
four Service components and special operations forces to the task force commander. The CCDR assigns the
task force commander OPCON of designated forces.
JOINT TASK FORCE
3-8. The CJTF will exercise OPCON of the joint force systems and networks through a JNCC as detailed
in CJCSM 6231.01C and CJCSM 6231.07D.
ARMY FORCES
3-9. The Army forces (ARFOR) commands and controls the Army Service portion of the JTF. The
ARFOR is directly subordinate to the JTF, but is also under the administrative control of the numbered
Army to which it is assigned or attached. The ARFOR has a dual NETOPS reporting relationship to the JTF
and the geographical combatant command ASCC. The JTF exercises overall authority and responsibility for
NETOPS within the ARFOR. The geographical combatant command ASCC also has a responsibility to
provide Army-based guidance through technical channels to the ARFOR to ensure compliance with Army
modularity and security standards.
3-10. The ARFOR G-6 is the senior signal officer in charge of the Army portion of the JTF information
network. The G-6 has the overall responsibility for the information network’s responsiveness to supporting
the commander’s tactical plan.
3-11. The ARFOR role may be filled by a numbered Army, a portion of a numbered Army, a corps or
division, or a BCT. Therefore, the exact composition of the ARFOR is highly dependant on the operational
scenario. Additional signal assets, such as integrated theater signal battalions/expeditionary signal battalions
(ITSB/ESBs), may be attached or assigned to the ARFOR as required.
3-12. The ARFOR G-6 exercises overall authority and responsibility for all NETOPS within the ARFOR
AOR. The ARFOR G-6 works closely with the higher headquarters J-6 and subordinate S-6 officers to
achieve integrated network management and support services while executing the ARFOR commander’s
intent. The ARFOR G-6 and staff plan and direct the NETOPS capabilities and support for the ARFOR
command posts and provide training and readiness of attached ARFOR assets to ensure efficient and
effective mission execution. ARFOR G-6 responsibilities are—
19 November 2008
FM 6-02.71
3-3
FOR OFFICIAL USE ONLY
Chapter 3
z
Recommends communications systems operation network priorities for battle command (e.g.,
changing bandwidth allocation to support the ARFOR main effort).
z
Conducts communications infrastructure management ICW the SC(T) in order to comply with
GIG requirements.
z
Advises the commander, staff, and subordinate commanders on communications networks and
information services.
z
Establishes and staffs the G-6’s theater communications system information management center.
z
Monitors and makes recommendations on all technical communications networks and
information services.
z
Prepares, maintains, and updates communications systems operation estimates, plans, and orders.
Such orders often will cause for CM changes across multiple subordinate elements.
z
Provides signal unit operations sections with direction and guidance during preparation of
network plans and diagrams establishing the information network.
z
Provides signal unit operations sections with unit locations, organizational status, and circuit or
data requirements.
z
Plans integration of battle command and other information systems.
z
Develops, modifies, updates, and distributes signal operating instructions.
z
Coordinates with signal offices of higher, adjacent, allied, and coalition units.
z
Prepares and publishes SOPs for ARFOR command posts.
z
Coordinates, plans, and manages the ARFOR electromagnetic spectrum operational environment,
both internal and external, to the Army network within its AOR.
z
Plans and coordinates with higher and lower headquarters regarding information systems
upgrade, replacement, elimination, and integration.
z
ICW the G-2 and the IO officer, performs communications systems operation vulnerability and
risk assessments.
z
Monitors information dissemination that changes warfighting functions priorities and control
measures.
z
Coordinates, plans, and directs all IA activities.
z
Ensures automation systems and administration procedures for all automation hardware and
software employed by the ARFOR are compliant with the GIG procedures and standards or
Army LWN specifications.
z
Monitors force integration of the force information systems resources.
z
Confirms and validates user information requirements in direct response to the tactical mission.
z
In concert with the chief of staff or executive officer, establishes and disseminates the electronic
battle rhythm.
z
Establishes communications system policies and procedures for the use and management of
information tools and resources.
z
ICW the staff, actively coordinates with a variety of external agencies to develop the information
and communications plans, manage the information network, obtain required services, and
support mission requirements.
CHIEF INFORMATION OFFICER G-6
3-13. The CIO G-6 provides Army functional policy and guidance regarding NETOPS. The responsibilities
of the CIO G-6 are to—
z
Develop and resource Army NETOPS policies.
z
Approve NETOPS standards ICW the NETCOM/9th SC(A), US Army Signal Center and Fort
Gordon, Army Communications-Electronics Life Cycle Management Command, and DISA.
z
Develop, maintain, and facilitate sound and integrated IT architecture.
3-4
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Roles and Responsibilities
z
Integrate the budget, program management, and acquisition decisions affecting information
technologies to promote NETOPS inclusion in new information systems.
z
Provide policy and guidance on the Army’s use of and interface with the Internet, to include
Army Web site management.
z
Decide overall policy and direction for information systems within the Army.
z
Network Security Improvement Program.
US ARMY SPACE AND MISSILE DEFENSE COMMAND/US ARMY
FORCES STRATEGIC COMMAND
3-14. USASMDC/ARSTRAT is the ASCC to USSTRATCOM and directly supports the JTF-GNO.
USASMDC/ARSTRAT is also USSTRATCOM’s primary point of contact for all Army NETOPS and
CND missions. USASMDC/ARSTRAT plans, integrates, and sustains Army CND and is the
communications system advocate. The CG, USASMDC/ARSTRAT has designated the CG, NETCOM/9th
SC(A) as the USASMDC/ARSTRAT deputy for NETOPS to represent USASMDC/ARSTRAT in
communicating and coordinating directly with DOD and USSTRATCOM regarding NETOPS.
UNITED STATES ARMY SIGNAL CENTER & FORT GORDON
3-15. The Commanding General, United States Army Signal Center of Excellence and Chief of the Signal
Regiment and Fort Gordon (USASC&FG), directs and supervises all officer and enlisted service school
training for the Military Occupational Specialties associated with NETOPS. The United States Army Signal
Center of Excellence provides world class Soldiers and Leaders; trains, educates, and develops adaptive IT
professionals; and plans, synchronizes, experiments, and implements Future Network capabilities.
3-16. Fort Gordon’s 442d Signal Battalion trains Signal Regiment officers (first lieutenant through captain)
in order to develop officers with the necessary leadership, technical and tactical skills to support the Army
and Joint forces. The courses trained by the 442d Signal Battalion are:
z
Signal Basic Officer Leader Course Phase III—teaches communications planning and
management; communications interface; leadership; information technology; electronics;
microwave; tropospheric scattering; property accounting; telecommunications; COMSEC
accounting; training management; military justice; signal systems tactics and doctrine. The
course also includes communications requirements, planning and execution unique to a maneuver
battalion or brigade.
z
Signal Captains Career Course—provides US Army signal officers the academic instruction,
which supports the leader, tactical, and technical skills needed to lead company-size units and to
serve at battalion and brigade staff levels.
z
Signal Captains Career Course-Reserve Component—provides Reserve Component signal
officers with technical updates related to:
Communications interfaces.
Electronic warfare.
Chemical, biological, radiological and nuclear operations.
Leadership.
Human resources support.
Property accounting.
Training management.
Force integration.
Military justice.
Signal system tactics and doctrine.
19 November 2008
FM 6-02.71
3-5
FOR OFFICIAL USE ONLY
Chapter 3
z
Battalion Command, Control, Communications, and Computer Operations Staff Officer (S-6)
Course—utilizes the Signal Captains Career Course knowledge as a foundation. The S-6 course
provides small group instruction heavily reliant upon hands-on learning and practical exercise.
The goal of the course is to produce signal staff officers with the skills required to plan a signal
communications network, produce an Annex H (signal annex), and manage the implementation
and troubleshooting of combat net radio, Army Battle Command System, and command post
node networks. There are no prerequisites for this course. However, the course requires either
pre-existing knowledge of combat net radio or completion of distance learning products to allow
the content of the instruction to reach the higher levels of knowledge. The course content
includes:
Administration (Skills Assessment Exam, assigned homework and computer
based tutorials).
Military decision making process and planning tools (Systems Planning,
Engineering, and Evaluation Device/Terrain Analysis).
Spectrum management and electronic warfare.
Antenna theory.
S-6 management
(unit standing operating procedures, SMART books,
battery management plans).
Very high frequency-frequency modulation, Defense Advanced Global
Positioning System Receiver, Simple Key Loader.
High frequency and automatic link establishment planning (AN/PRC-150).
Multi-band radio planning (AN/PSC-5C, AN/PRC-117).
Handheld radios
(AN/PRC-148
[Multiband Inter/Intra Team Radio],
AN/PRC-152).
Force XXI Battle Command, Brigade-and-Below.
Command post node networks.
Tactical Information Management System, Lower Tactical Internet,
Enhanced Position Location and Reporting System.
Army Battle Command System integration exercise.
CAPSTONE exercise.
Advanced technology briefings.
3-17. The 442d Signal Battalion’s purpose is to prepare signal corps company grade officers for company
level command and for assignments to staff positions at battalions and brigades, both signal and non-signal,
with primary emphasis on signal operations.
3-18. The 442d Signal Battalion is part of the Leader College of Information Technology at USASC&FG
and information on signal officer education and training can be obtained by contacting the Chief, Officer
Education and Training Division at (Commercial) (706) 791-2150 or (DSN) 780-2150.
3-19. Personnel interested in attending a 442d Signal Battalion or noncommissioned officer Academy
Course should contact their branch/functional area representative, local post/installation training
coordinator for Army Training Resources and Requirements System enrollment or the
442d Signal
Battalion, Training Support Division at (Commercial) (706) 791-0192 or (DSN) 780-0192.
CAPABILITIES DEVELOPMENT INTEGRATION DIRECTORATE
3-20. The Capabilities Development Integration Directorate/TRADOC Integration Office (CDID/TIO)-
Networks is responsible for managing and integrating the user activities associated with the development,
synchronization, and integration of Communications Networks and associated aspects of the Army. The
CDID/TIO-Networks will manage the commonality and interoperability aspects within the current and
future force to ensure Army, Joint, Interagency, and Multinational interoperability. CDID/TIO serves as
user representative for all aspects of the communications network system of systems. Intensively manage
3-6
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Roles and Responsibilities
and synchronize all organization, training, materiel, leadership and education, personnel, and facilities
(DOTMLPF) actions in order to deliver network capabilities over time. CDID/TIO is responsible for
capabilities development and support of system testing and fielding. Oversee efforts that implement and
update the LandWarNet transition strategy for current force network transport and operations. In addition,
CDID/TIO is responsible for the three TRADOC Capabilities Managers (TCM), the Experimentation
Division, and the Signal Concepts, Requirements, and Doctrine Division.
TRADOC PROJECT OFFICE DIRECTOR FOR NETWORK OPERATIONS
3-21. TRADOC Project Office (TPO) NETOPS, reporting to the SIGCEN Commanding General as an
integral part of the CDID, will perform as the Army's primary focal point as a user advocate for the
integration and synchronization activities associated with functional capability area Network Operations and
Electro-Magnetic Spectrum Operations (EMSO). TPO NETOPS is responsible for the integration and
synchronization of all systems or components of systems designated as performing NETOPS functions,
EMSO, and Communications Security (COMSEC). The TPO Director acts for the proponent in discharging
responsibilities in developing and integrating total system requirements in the area of Network Operations
and EMSO. In this capacity, TPO NETOPS, as part of the CDID, is the counterpart to TRADOC
Capabilities Manager (TCM) Networks & Services (N&S), TCM - SATCOM & Network Extension (SNE),
and TCM Tactical Radio (TR). TPO NETOPS is a user advocate responsible for coordinating integration
efforts across key programs of record such as the Warfighter Information Network -Tactical (WIN-T), Joint
Tactical Radio System (JTRS), Battle Command systems, and Future Combat System (FCS).
3-22. TPO NETOPS is responsible for duties as outlined in TRADOC Regulation 71-12, TRADOC System
Management. The TPO will coordinate with the appropriate TCMs and other organizations to ensure that
all doctrine, organization, training, materiel, leadership and education, personnel, and facilities
(DOTMLPF) imperatives are developed and synchronized with respect to the fielding of NETOPS
capabilities and associated systems. The TPO will coordinate to ensure that existing programs of record are
appropriately modified in providing materiel solutions.
NETWORK ENTERPRISE TECHNOLOGY COMMAND/9TH SIGNAL
COMMAND (ARMY)
3-23. NETCOM/9th SC(A) is the Army’s CONUS-based, worldwide network and systems provider. It
supports the Army’s force projection mission through its integrated, worldwide-deployable theater tactical
units, strategic and sustaining-base units, and global network operations role. As the executive agent for the
Army’s portion of the GIG, NETCOM/9th SC(A) exercises network and information systems control at the
strategic and operational military operations. It also executes the strategic and sustaining-base and theater
tactical communications systems integration with all Service components, defense agencies, and
nongovernmental organizations. Refer to FMI 6.02-45 for additional information on NETCOM/9th SC(A)
theater tactical units. The NETOPS responsibilities include:
z
Establishing and enforcing theater and Army NETOPS policies and procedures for the LWN.
z
Providing input for the JTA-A, JTSSNMCCB, and Installation Information Infrastructure
Architecture Configuration Control Board.
z
Providing a centralized configuration control capability to monitor and manage configuration
changes of Army tactical and strategic voice and data switches.
z
Serving as the Army’s primary interface with the DISA on issues related to the performance of
DISA-managed long-haul networks.
z
Providing NETOPS for the LWN and NETOPS support to ACOMs and DOIMs.
z
Providing command and control for the primary Army organizations performing NETOPS at the
enterprise level in CONUS and at all other levels.
z
Performing Army ESM/NM activities, functions, and tasks during exercises and operations of
peacetime and war.
19 November 2008
FM 6-02.71
3-7
FOR OFFICIAL USE ONLY
Chapter 3
z
Managing the Army Internet domain (.mil or .smil) as the Army’s Internet Service Provider and
manager.
z
Operating provisions and equipping the A-GNOSC and the TNOSCs.
z
Providing operation and maintenance and Army ESM/NM for networks and information systems
under its direct responsibility.
z
Providing an IA program to unify the Army’s ESM/NM and information security functions.
z
Exercising CM of the integrated hardware and software solutions for the Army’s WAN and
systems security infrastructure.
z
Providing an IDM capability for network and information system users.
ARMY GLOBAL NETWORK OPERATIONS AND SECURITY CENTER
3-24. The A-GNOSC mission is to provide Army and DOD NETOPS reporting and situational
understanding for the LWN. The A-GNOSC provides worldwide operational and technical support to the
LWN across the strategic, operational, and tactical levels. The A-GNOSC interfaces with all Army
TNOSCs, functional NOSCs, the DISA GNOSC, as well as other Service’s NOSC. The A-GNOSC will—
z
Carry out performance management (monitoring and analyzing) of tactical Army networks.
z
Provide network and systems administration of lower echelon Army NOSCs.
z
Receive and coordinate requests for services that cross regional boundaries.
z
Design, operate, and manage the Army's protected DNS—the Army's world-wide "electronic
address book."
z
Operate and manage data storage and retrieval for enterprise-level applications hosted on AKO
or consolidated servers.
z
Manage the enterprise-level architecture for the Army's directory services
(e.g., Microsoft
Windows 2000) and AD enterprise-level architecture. The AD enterprise-level architecture
includes domain management of all consolidated Windows
2000 domains and domain
controllers.
z
Provide technical guidance to installations and sites for migration to Windows 2000 and AD.
THEATER NETWORK OPERATIONS AND SECURITY CENTER AND REGIONAL NETWORK
OPERATIONS AND SECURITY CENTER
3-25. The TNOSC mission is to act as the single point of contact for Army network services, operational
status, and anomalies in the theater. The TNOSC provides visibility and status information to the A-NOSC
and TNC. In some theaters, the TNOSC may provide visibility to other Service component NOSCs. There
are TNOSCs established in all theaters of operations: CONUS, Europe, Pacific, Korea, and Southwest Asia.
3-26. These TNOSC functions are interchangeable across all theaters. Theater common functions can be
performed at multiple geographical locations and should be performed the same way at each location.
3-27. The TNOSC will perform or coordinate any task that spans the theater or multiple regions. This will
provide consistent service among regions. It will also place the operational function at the only location in
the enterprise that would have visibility or awareness of what was happening in both regions. The TNOSC
will—
z
Provide additional event management capabilities such as analysis and correlation of event data,
to the tactical units, as required.
z
Build, test, and provide software distribution packages to the tactical units.
z
Perform performance management (monitoring and analyzing) of the tactical units’ systems.
z
Prepare and implement COOP in support of the tactical units.
z
Exercise, monitor, and evaluate COOP in support of the tactical units.
z
Determine system patch implementation.
z
Determine if the patch requires testing.
3-8
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Roles and Responsibilities
z
Notify the A-GNOSC of the impending patch.
z
Coordinate and direct patch implementation.
z
Notify the DOIM, regional service center, RNOSC, and the tactical units of the impending patch.
z
Build the patch package.
z
Conduct necessary patch testing.
z
Perform global address list synchronization for the tactical units.
z
Manage e-mail hubs in support of the tactical units.
z
Provide technical support on problems escalated from the DOIM for tactical units.
3-28. The RNOSC performs NETOPS functions that provide strategic, reach operations, and operational
environment information and network service to support CCDRs, organizations, and agencies within the
assigned AOR. The RNOSC supports operations and maintenance of RNOSC-level LWN related
information systems and services and network management, IA, and IDM functions within its area of
operation. The RNOSC is the single point of coordination for end-to-end connectivity to the GIG and LWN
infrastructure for the CCDR it supports.
SIGNAL COMMAND (THEATER)
3-29. The SC(T) provides NETOPS capabilities and support to theater, joint, and coalition forces. These
forces leverage the LWN to enable extension and reach operations capabilities in support of the CCDR. It
operates the LWN in the numbered Army AOR and provides assured delivery of common user services in
support of the CCDR and the numbered Army. With additional joint manning document-based
augmentation, the SC(T) may also assume joint and coalition NETOPS functions for a CJTF or combined
joint force land component command.
3-30. The SC(T) consists of all strategic- and operational-level signal organizations within the theater of
operations. It plans, installs, operates, manages, controls, and maintains data, voice, and video networks and
information systems throughout the theater. The SC(T) performs centralized NETOPS activities for the
networks that provide communications capabilities to the ASCC, ARFOR, and joint forces in the JTF AOR.
The SC(T) is a major subordinate command of the NETCOM/9th SC(A). Under the OPCON of the ASCC,
the SC(T) commander is dual hatted as the ASCC G-6.
3-31. The SC(T) performs various tasks depending on the military operation or situation. The CCDR may
task the SC(T) to provide overall signal command and control, direction, and guidance to a JTF or assign
portions of the signal mission to the SC(T). All or a portion of the SC(T) may be tasked to establish or
augment the JNCC when the numbered Army and ASCC is tasked as the JTF, or provide land forces
network control when tasked to act as a JFLCC or ARFOR. In these scenarios the JNCC and JFLCC NOSC
report directly to the CCDR J-6.
3-32. The SC(T) is comprised of one or more signal brigades (tactical), a signal brigade (strategic), and a
TNOSC, and it may have a combat camera company and/or a tactical installation and network company
assigned as depicted in Figure 3-1. The SC(T) NETOPS responsibilities include:
z
Providing centralized management control and engineering for the Army Theater’s data, voice,
and video networks. This includes network interfaces with joint, combined, and coalition
systems.
z
Operating a fixed TNOSC during normal strategic operations of the LWN, and a deployed
NOSC during tactical operations.
z
Formulating and implementing plans, policies, and procedures for the engineering, installation,
operation, management, and control of assigned portions of the LWN.
z
Providing network planning and management of special purpose communications and
information systems.
z
Providing IA planning and management for the theater networks and information systems.
z
Providing an IDM capability for network and information systems users in the theater.
19 November 2008
FM 6-02.71
3-9
FOR OFFICIAL USE ONLY
Chapter 3
z
Establishing or augmenting the JNCC as required and staffing the Army’s portion with
augmentation from other Services.
z
Providing frequency assignments for Army, joint, and coalition elements throughout the theater.
z
Providing planning and staff management of the ground mobile forces tactical satellite in the
theater of operations.
++
Signal
Command
X
I
I
X
Combat
Tactical
TACTICAL
STRATEGIC
TNOSC
Camera
Install Net
Figure 3-1. SC(T) structure
3-33. The SC(T) TNOSC NETOPS responsibilities include:
z
Operating TNOSCs and providing guidance through technical channels to Army NOSCs within
the theater at all echelons.
z
Supervising the operation of NETOPS tools such as the AENIA standard tool capabilities,
Integrated Systems Control (ISYSCON), and IA management assemblage. (Refer to Appendix B
for more information on these and other NETOPS tools.)
z
Exercising OPCON of other communications assets provided by external organizations and
agencies.
z
Managing all signal support interfaces with joint and multinational forces, including host nation
support interfaces.
z
Managing and controlling the LWN and network services from the strategic force projection
sustaining base to the tactical units.
z
Performing ESM/NM activities, functions, and tasks required to effectively and efficiently
manage the information systems infrastructure and multi-organizational networks supporting the
operational mission.
z
Ensuring the IA tools are in place to provide security integrity of the network, protection for the
network and support secure access controls and connectivity.
SIGNAL BRIGADE (STRATEGIC)
3-34. The signal brigade (strategic) provides fixed, strategic communications support to the Soldier. Each
strategic signal brigade is unique and tailored to support specific theater requirements. The TNOSC
supports the strategic signal brigade in performing NETOPS functions for the networks and information
systems that support an ongoing presence in the theater. These functions include backbone networks,
e-mail, frequency assignment, circuitry, gateway routing to multinational networks, and commercial and
Defense Switched Network (DSN) access out of the theater of operations. During peace, each CONUS
strategic signal brigade is doctrinally under the command and control of the NETCOM/9th SC(A). During
major theater war or peacetime operations, the SC(T) assumes OPCON of the brigades deploy from
CONUS or other theaters of operations.
3-10
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Roles and Responsibilities
SIGNAL BRIGADE (TACTICAL)
3-35. The OCONUS signal brigade (tactical) (SB[T]) provides tactical communications support capability
to the numbered Army and ASCC. The signal brigade tactical is doctrinally under the command and control
of the SC(T). The SB(T) deploys to provide tactical communications systems operation support to the
ASCC. The brigade will also assume command and control of any assigned or attached signal unit and
install, operate, and maintain assigned portions of the theater communications network as directed. The
brigade S-3 will establish a tactical NOSC to perform the NETOPS functions required to manage and
control the networks and information systems it provides in the theater.
3-36. In an operational scenario, elements of the tactical signal brigade may be placed under the OPCON of
various operational commands such as a JTF, JFLCC, and JTF ARFOR, corps, division, or brigade. SB(T)
assets are also commonly placed under the OPCON of operational elements in a remote theater when
required. (Refer to FMI 6-02.45 for additional information on SC(T), and the supporting units.)
INTEGRATED THEATER SIGNAL BATTALION
3-37. The centerpiece of the current force transformation of theater tactical signal units is the ITSB/ESB.
The ITSB/ESB is organized into multifunctional elements, each containing all of the switching equipment,
the transmission systems, the data network management systems, and the command and control and data
network management resources that comprise a complete signal node.
3-38. The multifunctional nodal structure of the ITSB/ESB reflects a train-as you-fight and organize-as-
you-fight philosophy. This alleviates one of the greatest difficulties of the current structures, which is to task
organize from multiple organizations to form a single communications node in order to support a single
customer enclave.
3-39. The ITSB/ESB will typically be assigned to a SB(T), although it may be assigned or attached to other
organizations as well.
3-40. The ITSB/ESB and its subordinate companies are multifunctional organizations that are designed in a
modular fashion. Modules are designed around communications nodes so that support to the customer can
be easily tailored in a scalable fashion by deploying the required number of nodes.
3-41. Each node module includes voice switching and data networking capabilities, along with a mixture of
transmission systems such as SATCOM, tropospheric scatter, and line of sight.
EXPEDITIONARY SIGNAL BATTALION
3-42. The ESB is being created to addresses shortcomings in ITSB capabilities. At the same time, the
highly modularized ESB structure will serve as an organizational platform into which Warfighter
Information Network-Tactical capabilities can be introduced with minimal adjustment.
3-43. Outdated mobile subscriber equipment switching and line of sight systems employed by the ITSB do
not meet the data throughput requirements of supported units at any echelon. The ESB incorporates the next
generation of switch/data systems. Joint Network Transport Capability-Spiral capabilities, such as the joint
network node (JNN) and command post node (CPN), can provide the needed data capacity at all levels and
network services consistent with those provided to Soldiers at corps and division levels. The ESB will also
serve as an organizational platform for the introduction of Warfighter Information Network-Tactical
capabilities as they become available. The ESB is dependent on the fielding of the Joint Network Transport
Capability-Spiral or Warfighter Information Network-Tactical systems to completely equip the unit.
3-44. Replacement of mobile subscriber equipment systems will greatly enhance the maneuverability of
supported units and improve compatibility with corps- and division-level units. The ability to relocate a
command post quickly with minimal network installation and tear-down times will be especially important
to functional battalions supporting division-level organizations in a fast-moving operation.
3-45. Introduction of the next generation switch/data systems and a reduction in the number of large
switches will allow the battalion to be structured in a way that better enables employment of network assets
19 November 2008
FM 6-02.71
3-11
FOR OFFICIAL USE ONLY
Chapter 3
to support the increased number of medium and small command posts. This flexible structure will improve
the battalion’s ability to respond quickly to support missions with precisely-sized capabilities, down to team
level, that minimize the deployed signal footprint. The total support capability of the ESB grows from 27 to
30 command posts.
DIRECTOR OF INFORMATION MANAGEMENT
3-46. The DOIM provides overall NETOPS for the data and voice networks and Army information systems
on their base, post, camp, and station or within an assigned geographical area. Under ACOM guidelines and
procedures, DOIMs plan and budget for appropriate network and information systems hardware and
software technology upgrades or replacements to ensure that customer demands are met. They work with
external organizations to ensure the proper operation of installation-level components of DOD or Army-
level networks and information systems. The DOIM NETOPS responsibilities include:
z
Managing all support functions associated with providing customer access to the installation
common-user networks and information systems infrastructure.
z
Ensuring support and problem resolution for physical networks and information systems
equipment that provide access to DOD or Army-level networks and information systems.
z
Sharing information with other network managers concerning lessons learned and innovative
ideas to support users.
z
Implementing NETOPS practices IAW DOD, Army, information management activity, and
RCIO policy and guidance.
z
Establishing policies and procedures for the performance of the operation and maintenance of
networks and information systems within its AOR.
z
Establishing Service level support agreements with the NETCOM/9th SC(A).
z
Coordinating with RCIO and NETCOM/9th SC(A) for management of inter-installation networks
and information systems that affect their supported organizations.
z
Establishing and managing the command IA program for base, post, camp, and station.
OCONUS, this function is provided by the signal battalions.
z
Using NETOPS activities, functions, and capabilities to effectively and efficiently manage the
use of the network and information system resources within its AOR.
z
Providing mission impact of outages, CND incidents, and other network issues to the TNOSC.
z
Responding to TNOSC direction in support of problem resolution, change requests, and IAVMs.
3-47. DOIMs are organic elements of the United States (US) Army Garrison. While DOIMs report directly
to their Garrison Commander, NETCOM/9th SC(A) manages the CONUS DOIMs’ technical functions
through their RCIO, who is co-located with the Installation Management Command regional headquarters.
3-48. NETCOM RCIOs are OPCON to Installation Management Command region directors and serve as
the G-6 for the region. They focus on day-to-day network related issues and develop and enforce network
architectures, programs, IT budgets, policies, and standards. There are three CONUS RCIOs located at Fort
McPherson, Georgia; Fort Sam Houston, Texas; and Fort Monroe, Virginia. There are three OCONUS
RCIOs located in Heidelberg, Germany; Yongsan, Korea; and Fort Shafter, Hawaii, designated from theater
signal commands.
G-6, S-6, AND SIGNAL UNIT S-3
3-49. The S-3 serves as the strategic or tactical signal unit’s operations officer, and the G-6 or S-6 serves as
a non-signal unit’s communications systems operation officer depending on the unit’s structure and level of
responsibility. In all cases, the S-3, G-6, and S-6 work in concert to conduct NETOPS in their AOR. The S-
3, G-6, and S-6 ensure that data and voice networks and information systems are available and secure for
commanders to receive the information they need to command and control their forces throughout an area
of operations. (Refer to FM 5-0.1 for additional information on the operations process of the S-3, G-6, and
S-6.)
3-12
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Roles and Responsibilities
3-50. The numbered Army is the ASCC for the theater. Numbered Army organic signal support consists of
the numbered Army G-6 staff and the SC(T). The numbered Army G-6 has duel responsibilities as the
commander of the SC(T). The NETOPS responsibilities of the G-6 at numbered Army or ASCC include:
z
In conformance with Army global and theater NETOPS policies, establish NETOPS policies and
procedures for the integration, installation, and operation and maintenance of the operational
networks under their direct responsibility.
z
Following higher headquarters’ NETOPS policies and procedures for network interfaces.
z
Coordinating all communications systems operation support interfaces with joint and
multinational forces, including host nation support interfaces.
z
Coordinating the availability of commercial information systems and services for military use.
z
Exercising staff supervision of other communications assets provided by external organizations
and agencies.
z
Managing communications protocols through the coordination of DISN and tactical network user
interfaces down to the battalion Tactical Internet.
z
Planning redundant signal means to pass time-sensitive battle command information from
collectors to processors.
z
Managing the employment automation (hardware and software) supporting the force, including
the operations of the automation management office.
z
Establishing automation systems administration procedures for all automation software and
hardware employed by the force.
z
Establishing information systems security policy for all automation software and hardware
employed by the force.
z
Establishing IA policies and procedures for the command and enforcing command global
policies.
z
Providing supporting assets and services to deployed and deployable units.
z
Responding to TNOSC direction in support of problem resolution, change requests, and IAVMs.
z
Ensuring and reporting IAVM compliance for all IT networks, systems and devices.
z
Performing organizational level maintenance on unit communications and electronic systems,
remote control systems, intercoms, information systems and other battlefield functional area
systems.
z
Troubleshooting to a defective line replaceable unit (LRU)/line replaceable module (LRM) unit
communications and electronic systems, remote control systems, intercoms, information systems
and other battlefield functional area systems.
z
Replacing and evacuating to the forward support company for repair of faulty LRUs/LRMs on
communications and electronic systems, and information systems.
z
Repairing and installing unit communications and electronics systems wiring and cabling.
z
Performing the installation and removal of all unit vehicular and base station communications,
electronics, and information systems.
z
Performing communications and electronic systems test using appropriate test, measuring and
diagnostic equipment (TMDE). Maintains TMDE calibration records.
z
Managing and maintaining battery inventory and charging systems.
z
Ordering and maintaining bench stock.
TACTICAL NETWORK OPERATIONS
3-51. The G-6 has the overall responsibility for the corps and division information network’s
responsiveness to supporting the commander’s tactical plan. Figure 3-2 outlines network responsibilities for
the division staff operations cell. The same responsibilities are applicable at the corps.
3-52. The corps and division consist of an organic headquarters element which commands maneuver and
support elements that have been assigned to meet mission requirements. Corps and division signal support
19 November 2008
FM 6-02.71
3-13
FOR OFFICIAL USE ONLY
Chapter 3
consists of the signal corps or division G-6 cell and a corps or division signal company. Additional signal
assets, such as ITSB/ESB, may be attached or operationally controlled to the corps and division as required.
3-53. The corps and division G-6 exercises overall authority and responsibility for all NETOPS within the
AOR IAW Army and theater policies and procedures. The G-6 may also be required to serve as the Army
component signal commander or joint command signal commander. The corps and division G-6 works
closely with the higher headquarters G-6, J-6, subordinate S-6 officers, and the corps and division signal
company to achieve integrated network management and support services while executing the commander’s
intent. The corps and division G-6 and staff plan and design the NETOPS capabilities and support for the
command posts and subordinate units, as well as providing training and readiness responsibility to ensure
efficient and effective mission execution for assigned and attached units.
PRIVATE
NETWORK
Division NETOPS
ASCC Application Network Managers
Div
TROJAN
LOGNET
NET
ll
G1
G2
G3
G4
G6
STB
Log
Internal TOC
DIMHRS
ASAS
ABCS
Configuration
and other
and all
NetworkNetwork
l
Network SA
Networks
Other
SIG
supporting
Networked
Systems
CO
Personnel
TSO
l
BCT NET
Communications Transport NETOPS (Extending the GIG)
Common SVCS (Voice & Data), IA, Connectivity for Battle
CO
CO
Command and Proponent Application Networks
CO
Figure 3-2. Division network responsibilities
3-54. The corps and division habitually provide AOR services from the forward-deployed corps or division
tactical operations center (TOC). Due to recent enhancements to tactical reach operations capability, the
corps and division G-6 may elect to stage select services from remote sanctuary locations. These locations
include the corps and division tactical unit hub node (UHN) or a corps and division-controlled cell within
the network service center regional. Staging corps and division services at sanctuary locations is generally
most effective during deployment and decisive operations. During these phases, the corps and division
TOCs are highly mobile and are unable to provide a stable, high-speed environment to host AOR services.
The corps and division G-6 has the following responsibilities:
z
Recommends communications systems operation network priorities for battle command (e.g.,
changing bandwidth allocation to support the corps and division main effort: a BCT reinforced
with additional intelligence, surveillance, and reconnaissance assets).
z
Conducts IT infrastructure management ICW the numbered Army SC(T) in order to comply with
GIG requirements.
z
Acts as the Army component G-6 when needed (equipment and personnel augmentation will be
required to support this mission).
3-14
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Roles and Responsibilities
z
Acts as the JTF J-6, if required. Equipment and personnel augmentation will be required to
support this mission and will be provided by the numbered Army or ASCC as necessary.
z
Advises the commander, staff, and subordinate commanders on communications networks and
information services.
z
Supervises the activities of the NETOPS officers and units NETOPS activities.
z
Monitors and makes recommendations on all technical communications networks and
information services.
z
Prepares, maintains, and updates communication systems operation estimates, plans, and orders.
Such orders often will cause for CM changes across multiple divisions.
z
Provides signal unit operations sections with direction and guidance during preparation of
network plans and diagrams establishing the information network.
z
Provides signal unit operations sections with unit locations, organizational status, and circuit or
data requirements.
z
Works issues on information systems equipment and personnel requirements analysis due to the
modified table of organization and equipment changes.
z
Plans integration of battle command and other information systems.
z
Develops, modifies, updates, and distributes signal operating instructions.
z
Coordinates with signal offices of higher, adjacent, allied, and coalition units.
z
Prepares and publishes communications systems operation SOPs for corps and division
command posts.
z
Coordinates, plans, and manages the electro magnetic spectrum operational environment, both
internal and external, to the corps and divisions within its AOR.
z
Plans and coordinates with higher and lower headquarters regarding information systems
upgrade, replacement, elimination, and integration.
z
ICW the G-2 and the IO officer, performs communications systems operation vulnerability and
risk assessments.
z
Monitors information dissemination that changes warfighting function priorities and control
measures.
z
Coordinates, plans, and directs all IA activities.
z
Ensures that automation systems and administration procedures for all hardware and software
employed by the corps and division are compliant with the GIG procedures and standards or
Army specifications policies.
z
Monitors force integration of the force information systems resources.
z
Confirms and validates user information requirements in direct response to the tactical mission.
z
ICW with the chief of staff or executive officer, establishes and disseminates the electronic battle
rhythm.
z
Establishes communications system policies and procedures for the use and management of
information tools and resources.
z
ICW the staff, actively coordinates with a variety of external agencies to develop the information
and communication plans, manages the information network, obtains required services, and
supports mission requirements.
z
Plans, manages, and directs all IA activities ICW the TNOSC and RCERT.
z
ICW the G-6 staff, plans and designs the NETOPS capabilities and support for the corps and
division command posts and subordinate units. They also provide training and readiness
responsibility to ensure efficient and effective mission execution.
z
Performing organizational level maintenance on unit communications and electronic systems,
remote control systems, intercoms, information systems and other battlefield functional area
systems.
19 November 2008
FM 6-02.71
3-15
FOR OFFICIAL USE ONLY
Chapter 3
z
Troubleshooting to a defective line replaceable unit (LRU)/line replaceable module (LRM) unit
communications and electronic systems, remote control systems, intercoms, information systems
and other battlefield functional area systems.
z
Replacing and evacuating to the forward support company for repair of faulty LRUs/LRMs on
communications and electronic systems, and information systems.
z
Repairing and installing unit communications and electronics systems wiring and cabling.
z
Performing the installation and removal of all unit vehicular and base station communications,
electronics, and information systems.
z
Performing communications and electronic systems test using appropriate test, measuring and
diagnostic equipment (TMDE). Maintains TMDE calibration records.
z
Managing and maintaining battery inventory and charging systems.
z
Ordering and maintaining bench stock.
Note. Appendix D provides division commanders and staff members an understanding of
systems and personnel that comprise the communications network at division.
BRIGADE COMBAT TEAM AND SUPPORT BRIGADE
3-55. The modular design of Army tactical forces employs six basic types of brigade-sized formations: the
BCT and five support brigades. The BCT is a standing combined arms formation intended to conduct close
combat in offensive, defensive, and stability operations. The other five types of tactical brigades will
perform supporting functions and include a battlefield surveillance brigade, a combat support brigade, a
fires brigade, a combat aviation brigade, and a sustainment brigade. Organic signal support includes a signal
company. In addition, the brigade S-6 possesses a small team of embedded signal Soldiers.
3-56. Any tactical brigades, tactical companies, and other tactical units which do not possess an organic
signal company will be supported via pooled numbered Army or ASCC tactical signal assets. The NETOPS
functions of these units are addressed under the category of ITSB/ESB supported echelons.
Brigade and Brigade Combat Team S-6 Responsibilities
3-57. On behalf of the commander, the brigade S-6 maintains overall authority and responsibility for all
NETOPS within the brigade AOR in compliance with joint, Army, and theater policies. The brigade S-6
may also be required to serve as the Army component signal commander. The brigade S-6 works closely
with its higher headquarters G-6, J-6, and the brigade signal company to achieve integrated NETOPS while
executing the brigade commander’s intent.
3-58. The brigade S-6 and staff plan the NETOPS capabilities and support (e.g., voice, video, networks,
messaging) for the brigade command posts and subordinate units. The S-6 section personnel are located
within brigade command posts to support the commander’s identified NETOPS requirements. The brigade
and BCT S-6—
z
Recommend communications system network priorities for battle command (e.g., changing
bandwidth allocation to support the BCT main effort: a maneuver battalion reinforced with
additional intelligence, surveillance, and reconnaissance assets).
z
Conduct communications infrastructure management in conjunction with the numbered Army
SC(T) to comply with GIG requirements.
z
Act as the Army component G-6 when needed. Equipment and personnel will be required to
support this mission. Equipment will be provided by the corps, division, and numbered Army.
z
Advise the commander, staff, and subordinate commanders on communications networks and
information services.
z
Plan, configure, manage, and monitor the TOC LAN and Tactical Internet for all brigade
command posts.
3-16
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Roles and Responsibilities
z
Supervise the activities of the NETOPS cell.
z
Monitor and makes recommendations on all technical communications networks and information
services.
z
Prepare, maintains, and updates communications systems operation estimates, plans, and orders.
They also coordinate such efforts with the higher headquarters’ G-6, J-6, and signal company.
z
Provide the brigade NOSC with direction and guidance during preparation of network plans and
diagrams, establishing the information network.
z
Provide signal unit operations sections with unit locations, organizational status, and circuit or
data requirements.
z
Work issues on information systems equipment and personnel requirements analysis due to
modified table of organization and equipment changes.
z
Plan integration of battle command and other information systems.
z
Develop modify, update, and distribute signal operating instructions.
z
Coordinate with signal offices of higher, adjacent, allied, and coalition units. Prepares and
publishes communications systems operation SOPs for brigade command posts. Plans and
coordinates with higher and lower headquarters regarding information systems upgrade,
replacement, elimination, and integration. The brigade and BCT S-6 are responsible for all
network assets IAW joint, Army, and theater policy.
z
Perform communications systems operation vulnerability and risk assessments ICW the BCT S-2
and the IO officer.
z
Monitor information dissemination that changes warfighting function priorities and control
measures.
z
Coordinate, plans, and directs all IA activities (AR 25-2 and unit SOP provide details on IA
activities).
z
Ensure that automation systems and administration procedures for all automation hardware and
software employed by the brigade are compliant with the GIG procedures and standards or Army
specifications.
z
Confirm and validates user information requirements in direct response to the tactical mission.
z
Perform all of the duties and responsibilities of the corps and division G-6 when the brigade is
operating independently.
z
Coordinate, plan, and manage the electro magnetic spectrum operational environment, both
internal and external, to the brigade within its AOR.
z
Plan and manage the brigade information network ICW the operational chain of command.
z
Plan and manage brigade IA systems (firewalls, IDSs, and ACLs) ICW the TNOSC.
z
Plan and manage brigade IDM/CS procedures (user profiles, file and user priorities, and
dissemination policies).
z
Deploy range extension assets to maintain connectivity and reliability of the brigade
communications network.
z
Evaluate network requirements to determine needs for unmanned aerial vehicles and
communications relay requirements.
z
Execute command and control of all NETOPS responsibilities in support of the unit mission.
z
Performing organizational level maintenance on unit communications and electronic systems,
remote control systems, intercoms, information systems and other battlefield functional area
systems.
z
Troubleshooting to a defective line replaceable unit (LRU)/line replaceable module (LRM) unit
communications and electronic systems, remote control systems, intercoms, information systems
and other battlefield functional area systems.
z
Replacing and evacuating to the forward support company for repair of faulty LRUs/LRMs on
communications and electronic systems, and information systems.
19 November 2008
FM 6-02.71
3-17
FOR OFFICIAL USE ONLY
Chapter 3
z
Repairing and installing unit communications and electronics systems wiring and cabling.
z
Performing the installation and removal of all unit vehicular and base station communications,
electronics, and information systems.
z
Performing communications and electronic systems test using appropriate test, measuring and
diagnostic equipment (TMDE). Maintains TMDE calibration records.
z
Managing and maintaining battery inventory and charging systems.
z
Ordering and maintaining bench stock.
Note. Appendix E provides BCT commanders and staff members a brief overview of the related
mission responsibilities of the S-6. Similar to the division, the BCT is required to operate its own
network without augmentation from higher headquarters.
BRIGADE SIGNAL COMPANY
3-59. The brigade has an organic signal company to provide NETOPS capabilities and support. The
brigade signal company is comprised of a NETOPS cell and two network extension platoons, as depicted in
Figure 3-3. The brigade signal company contains many of these same components while it is tailored to the
requirements of a specific support brigade. In general, the NETOPS capabilities in the signal company are
resourced to support connectivity to the enterprise LWN services; operate, manage and defend NETOPS
assets in its AOR; and extend strategic NETOPS policies into the tactical formation. The signal company
maintains organic network systems and devices. Signal soldiers are designated operator/maintainer for
major network assemblages.
Brigade Network Service Support Locations
3-60. The brigade habitually provides network services from the forward-deployed brigade command post.
Due to recent enhancements to tactical reach operations capability, the brigade S-6 may elect to stage select
brigade services from numbered Army-hosted strategic sanctuary locations, such as a network service center
regional. Staging brigade services at sanctuary locations is generally most effective during deployment and
decisive operations. During these phases, the brigade command post is highly mobile and is unable to
provide a stable high-speed environment to host network services.
MANEUVER AND SUPPORT BATTALIONS
3-61. Battalions possess an organic signal capability consisting of a signal officer (S-6) and staff; additional
signal assets may be attached or assigned as required. As part of Army transformation, battalions are fielded
with new technologies (e.g., satellite access provided by the Joint Network Transport Capability) to extend
the LWN into the tactical formation.
Note. A force design update has been submitted to move the NETOPS cell from within the signal
company to the G-6/S-6 section.
3-18
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Roles and Responsibilities
NETWORK SPT
NET EXT PLT
HQ & NET SPT
NET EXT PLT
LEGEND
NET--------------Network
EXT--------------Extention
PLT---------------Platoon
SPT---------------Support
Figure 3-3. Typical BCT signal company structure
3-62. There is one CPN located at the battalion level to provide voice and data capabilities. It uses time
division multiple access (TDMA) satellite transmission to gain access through the JNN or UHN to the GIG.
The CPN consists of a Ku band trailer and associated transit cases to provide a wide array of services.
Figure 3-4 shows battalion connectivity to the brigade using the TDMA mesh.
3-63. The CPN is located at the battalion command post (CP), and the battalion S-6 typically exercises
control from this location. The equipment that is used to interface with the CPN in the CP is organic to the
unit; therefore the unit sets up and operates the equipment with technical oversight from the S-6. The
battalion may have an AN-TRC-190(V1) assigned, to provide a 2 Mbps traffic capability to the brigade
when the mission dictates. There is one 2.4M dish Ku band satellite transportable terminal (STT) fielded to
provide direct reach capabilities to higher command and or strategic enclaves using frequency division
multiple access (FDMA) and TDMA
3-64. The personnel to operate the CPN are assigned to the S-6 section.
3-65. The battalion S-6 exercises control for the NETOPS assets and related operations within the battalion
AOR and works closely with higher and adjacent headquarters to ensure efficient NETOPS employment
and management. The S-6 section personnel are task organized and located within battalion command posts
to support the commander’s NETOPS requirements. See Appendix E for a diagram of a battalion to brigade
and division layout.
19 November 2008
FM 6-02.71
3-19
FOR OFFICIAL USE ONLY
Chapter 3
Figure 3-4. Battalion Command Post Connectivity
3-66. The S-6 in a Stryker Brigade Combat Team (SBCT) battalion is the primary planner for battalion
communications operations. The S6 advises the battalion commander, staff, and the maneuver companies
on all signal and communication matters. The section provides trained communications personnel to each
maneuver company, and they coordinate closely with the S3 section to ensure and maintain clear lines of
communication during tactical operations. The communications section is responsible for the transfer of
information, the networking of automated systems, and the development of communications policies,
procedures, and training for the battalion commander. For additional information on the S-6 section of a
SBCT battalion see FM 3-21.21.
3-67. The battalion S6 manages the operations of communications systems received from the SBCT
communications systems to support their organization as well as the battalion's own communications
systems. The battalion S-6 maintains the battalion’s C2 and communications systems. As a principal staff
officer, the battalion S-6 interacts closely with the commander, XO, S3, and other staff officers to determine
specific or unique signal requirements and develop situational understanding of the area of operation.
He/she has OPCON of attached signal personnel. The battalion S6—
z
Participates in the planning and operations process of the battalion.
z
Coordinates closely with the brigade S6 on planning and operating the TI as it relates to the
battalion.
z
Understands the capabilities and operation of all communication and automation equipment in
the battalion.
z
Advises the battalion staff on communications matters.
z
Receives and validates Enhanced Position Location Reporting System
(EPLRS) VHSIC
requirements and provides these to the SBCT signal officer.
3-20
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Roles and Responsibilities
z
Maintains the status of communications systems operating in the battalion.
z
Coordinates employment and operation of the SIV assigned for network management.
z
Keeps the systems integration vehicle team apprised of battalion mission operations.
z
Exercises supervisory responsibility for training and assigning the signal support system
specialists in the battalion.
z
Develops a concise signal annex to the battalion OPLAN or OPORD.
z
Tracks COMSEC distribution within the battalion.
3-68. The infantry battalions signal officer
(S-6) is the primary planner for battalion communication
operations. He/she advises the battalion commander, staff, and the maneuver companies on all signal and
communication matters. The duties of the battalion signal officer include—
z
Plans, manages, and directs all aspects of the unit communications systems.
z
Plans, supervises integration of communications with headquarters up, down, and adjacent.
z
Supervises the communications activities of subordinate and attached units.
z
Supervises unit maintenance of signal equipment for the unit and for subordinate units.
z
Monitors status of support maintenance on unit and subordinate unit signal equipment.
z
Prepares and writes the signal annex of unit orders and plans.
z
Advises commander and staff on electronic counter-counter measures (ECCM) and develops
reporting procedures.
z
Helps the S-3 determine the location of the main, combat trains and field trains CPs.
z
Ensures selected areas offer the best communications and the least interference.
3-69. The infantry battalion S-6 section is responsible for performing limited unit level repair and
maintenance. It also conducts evacuation of the battalion’s digital and wire communications equipment as
well as maintenance of the digital system architecture that connects platoon, company and battalion to the
BCT and higher networks; and on both secure and non-secure local area networks. The communications
section also has the capability to provide two retrans stations for the battalion, and normally provides one
Soldier to each company during operations as a communications equipment expert. For additional
information on the S-6 section of an infantry battalion see FM 3-21.20.
3-70. The Field Artillery (FA) Battalion S6 is responsible for communications and automation operations,
management, and security. The S6 is a coordinating staff officer and is directly accountable to the XO. For
additional information on the S-6 section of a field artillery battalion see FM 3-09.21.In addition to those
listed in FM 101-5, S6 duties include the following:
z
Advise the commander and staff on:
Selection of unit position areas (PAs), from a communications standpoint.
Communications and automation planning, operations, priorities, security,
training, and rehearsals.
ECCM.
Communications and automation requirements associated with essential fire
support tasks and essential field artillery tasks, e.g., unique communications
and/or automation equipment, nets, database exchange, or procedures for
sensor-to shooter links or other critical communications.
z
Plan, manage, and direct communications operations to include establishment of communications
networks and systems and installation and maintenance of equipment.
Coordinate integration of battalion communications systems into those of a
supported maneuver/FA unit and a FA HQ.
Coordinate with signal units for communications support.
Supervise operator and organizational maintenance of communication
equipment.
Manage all frequency allocations and assignments.
19 November 2008
FM 6-02.71
3-21
FOR OFFICIAL USE ONLY
Chapter 3
z
Manage and direct COMSEC. Direct and supervise the battalion COMSEC custodian who issues
and accounts for COMSEC equipment, key lists, codes, ciphers, signal operating instructions
(SOI), and authentication systems.
z
Plan, manage, and direct automation systems administration, maintenance, and security.
Establish automation systems administration and security procedures for
automation hardware and software.
Supervise and direct battalion local area networks configuration and usage
of battalion network capabilities.
z
Prepare communications estimates and write the signal paragraph (paragraph 4a) of the field
artillery support plan.
z
Perform communications reconnaissance and survey to assist the S3 in positioning key elements
of the battalion, to include retransmission (retrans) stations.
NETOPS OPERATORS OR MANAGERS
3-71. Network managers have similar responsibilities for ESM/NM, IA/CND, and IDM/CS in many
different organizations and echelons. Network managers are in units and agencies at the strategic and
theater tactical military operations. At the strategic and theater tactical level, the JTF-GNO is the highest
echelon of NETOPS control. A LAN manager or system administrator at a department or agency within the
sustaining base is the lowest echelon. Network management positions at the operational level are at
brigades, battalions, and companies supporting a theater.
3-72. Each network manager is responsible for operating, managing, and defending his portion of the
network while sharing additional responsibilities with other network managers in a network. They have
similar core responsibilities and perform many of the same activities, functions, and tasks. They plan,
engineer, and manage networks that consist of transmission systems, circuit switches, data switches, routers,
other devices, and information systems. Network management is hierarchical; therefore, network managers
take direction from higher-level network managers and provide direction to lower-level network managers.
3-73. The network manager and operators uses NETOPS tools to identify potential problems and prioritize
actions to be taken within the network or information system. If the network manager/operator suspects a
problem is developing (when notified by alarm or person), he consults with his staff to determine root cause
and correct the problem or escalates it to the responsible NOSC for resolution. Network managers must
have knowledge of every aspect and the makeup of the network as well as the connectivity of the various
information systems in the network. The network manager—
z
Provides users with quality service of voice, data, and video networks.
z
Provides a single point of control within a domain for critical NETOPS issues.
z
Identifies and requests hardware and software requirements of nodes and site configuration for
the network.
z
Reports and escalates network and circuit outages to the appropriate service provider.
z
Conforms to hardware, software, and communications architecture standards for proper
NETOPS.
z
Monitors overall network performance.
z
Applies information systems security standards for network information, access, transmission,
storage, and processing.
z
Establishes network priorities.
z
Focuses on network level issues.
z
Records and processes information gathered from NETOPS systems that monitor the operation
and security of the network, and collects and reports NETOPS statistics, e.g., bandwidth usage,
error rates, and equipment failure rates for trend analysis and higher echelons.
z
Identifies and diagnoses installations used in correcting network problems.
3-22
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
|
||
|
|
|