Military reference books and manuals (2009-2023, Volume 7) - page 32

 

  Index      Manuals     Military reference books and manuals (2009-2023, Volume 7)

 

Search            copyright infringement  

 

   

 

   

 

Content      ..     30      31      32      33     ..

 

 

 

Military reference books and manuals (2009-2023, Volume 7) - page 32

 

 

Network Operations Roles and Responsibilities
z
Recommends general policy on the operation of a network based on detailed historical
information.
z
Establishes and monitors security by applying security standards IAW applicable regulations,
standards, and TNOSC.
z
Executes service desk capabilities for network operational problems and provides remote site
operations support.
z
Uses managed elements to enable a remote management capability.
z
Depending on the unit of assignment, performs activities, functions, and tasks in the areas of
network engineering, transmission management, frequency assignment, systems control, etc.
USER
3-74. The user is responsible for proper and acceptable use of his terminal devices. The user shall not
change the configuration or security of his terminal device except under the written conditions established
by the responsible NETOPS manager. Commanders and their staffs are the primary users of the networks
provided by the signal units located throughout all military operations. Along with staff duties and
responsibilities, the staff officer integrates and uses the warfighting function or other information systems to
support the mission. The staff officer coordinates with the S-6 or G-6 (depending on the operational level of
the unit) in all aspects of planning, implementing, integrating, operating, managing, and maintaining these
information systems. The user operates—
z
Warfighting function, information systems, and equipment under his/her control.
z
Command and control systems and associated peripherals.
z
The Standard Army Management Information System.
z
Office automation.
z
Radios.
z
Hardware and software applications.
z
Other user-owned devices.
3-75. The user is also responsible for the functional operation, troubleshooting, and maintenance IAW the
user’s limitations. If a system or device malfunctions, the situation should be reported to the support NOSC.
The NETOPS manager or system administrator will provide connectivity and configuration advice, where
needed. (For information outlining the responsibilities of the system administrator, refer to AR 25-2.)
19 November 2008
FM 6-02.71
3-23
FOR OFFICIAL USE ONLY
Chapter 4
Network Operations Control Centers
This chapter identifies and describes the organizations that perform NETOPS
functions to manage, control, and secure the GIG at the strategic to the theater
tactical level of operations. This chapter also identifies and describes the control
centers that perform NETOPS functions to manage, control, and secure tactical
networks and their interfaces into the GIG. With a thorough understanding of the
hierarchy of communications systems and network control, signal commanders and
staff can better manage and control communications systems operation support.
GLOBAL INFORMATION GRID NETWORK OPERATIONS
CONTROL CENTERS
4-1. Within the GIG, many organizations perform network and information systems management, security,
and operational direction and control functions. These organizations ensure the GIG is managed through an
established hierarchy of NETOPS control centers. These control centers are located at the global, theater,
and tactical levels. Each center performs integrated GEM, GND, and GCM functions supporting
communications system and information systems. USSTRATCOM, joint and unified commands, and
Service components operate, manage, and staff these centers to control their portion of the GIG.
4-2. The GIG NETOPS control centers, at all echelons, ensure that the Soldier and all DOD components
can obtain and sustain responsive, reliable, secure, and effective GIG services.
4-3. NETOPS architecture is focused on central management from higher-level echelons with overall
responsibility for joint NETOPS in each theater residing under the CCDR. The CCDR relies on support
from USSTRATCOM, JTF-GNO, and the numbered Army SC(T). The USSTRATCOM provides each
CCDR a TNC as an additional asset, and each TNC falls under the tactical control of the CCDR. Each
CCDR is required to establish a TNCC which assists them in maintaining SA and provides them with
operational and tactical control of their respective system and network environment.
4-4. Each TNC provides direct support to its TNCC, ensuring the effective operation and defense of the
GIG within the theater. The TNC is OPCON to JTF-GNO and offers onsite, theater support. Each TNC can
issue technical directives to the A-GNOSC. The TNC develops monitors and maintains a GIG SA view for
the theater. The theater GIG SA view is aggregated and segmented based on requirements provided by the
TNCC as derived from the GIG common SA standards. The GIG SA view will include pertinent theater,
operational, and tactical-level system and network, GND, and GCM status. Coordination with the TNCC is
paramount especially with regards to reporting requirements and SA.
4-5. Successful operations of NETOPS control centers rely on compatibility, interoperability, and the
integration of policies, procedures, standards, and tools. Shared USSTRATCOM, CCDR, and Service
component requirements and responsibilities for successful end-to-end management of the GIG include:
z
Identification of infrastructure dependencies and vulnerabilities.
z
Coordination of operational response and reporting.
z
End-to-end CM and review.
z
Identification of network and systems purpose, criticality, interdependencies, and information
flow.
z
Integration of policies, operations, and tools.
19 November 2008
FM 6-02.71
4-1
FOR OFFICIAL USE ONLY
Chapter 4
GLOBAL LEVEL
4-6. Organizations with NETOPS responsibilities at the global level include: Chairman of the Joint Staff,
National Military Command Center, USSTRATCOM, JTF-GNO, GNC, National Security Incident
Response Center, functional combatant commands, and Service and agency headquarters.
4-7. Figure
4-1 graphically portrays the command and control relationships for GNO.
CDRUSSTRATCOM is the supported commander for GNO. The other CCDRs are supporting commanders
to USSTRATCOM for GNO. This relationship gives CDRUSSTRATCOM the authority to direct the
CC/S/A to take action to ensure the availability and integrity of the GIG. While this relationship gives the
CDRUSSTRATCOM global authority, it does not take away the CCDRs’ authority over their assigned
NETOPS forces. For GNO issues, USSTRATCOM will issue orders and alerts through JTF-GNO to the
CCDR, Services, and agencies.
4-8. The CCDR, Services, and agencies will direct compliance with these directives within their AOR
using their inherent authority over assigned forces. This construct will allow USSTRATCOM to exercise its
global authority while strengthening the responsibilities of the other CCDRs. The TNCs will fall under the
OPCON of JTF-GNO for GNO issues. This allows the JTF-GNO to immediately direct action by the TNCs
when necessary to protect the GIG. JTF-GNO will ensure that the CCDRs are informed about all GNO
issues. This OPCON relationship gives JTF-GNO the authority to issue immediate directives when
necessary. The TNCs will provide direct support to the TNCCs and general support to the GNCCs in
executing JTF-GNO directives.
SECDEF
Supported
GCC
USSTRATCOM
FCC
Services
Agency
Title 10/32
NetOps Org
NetOps Org
Net Org
(TNCC)
(GNCC)
JTF-GNO
Non-DoD
TNC
GNC
OPCON
OPCON
Mission
Partner
GNSC
GSSC
GISMC
IC-IRC
Direct
Direct
Support
Support
Service NetOps
SCC,FCC,JTF
SCC,FCC,JTF
NetOps Forces
NetOps Forces
Components
NOSC/CE(I)RT
ADCON
Command Relationship Legend
Supported
OPCON
DirectSupport
ADCON
ORG-----------------Organization
Figure 4-1. Global NETOPS command and control
4-9.
JTF-GNO exercises OPCON of Service GNO units through the ASCC. For the Army, The A-
GNOSC is OPCON to JTF-GNO through USARSTRAT. Defense agencies will follow the NETOPS orders
4-2
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Control Centers
and directives issued by USSTRATCOM and JTF-GNO. Service and Agency Systems Management
Centers and Central Design Authorities are in general support of JTF-GNO, ensuring that the systems they
operate and provide as parts of the GIG are compliant with JTF-GNO guidance.
COMMANDER, JOINT TASK FORCE-GLOBAL NETWORK OPERATIONS
4-10. The CJTF-GNO will lead and direct continuous GEM, GND, and GCM throughout the GIG. To
ensure global decision superiority, they will maintain near real-time SA, end-to-end management, and
dynamic GIG defense.
4-11. The CJTF-GNO will also exercise OPCON of the GIG for global network operations issues. global
network operations issues are those where action or inaction potentially affects multiple CCDR, Services,
and agencies. Under the authority of CDRUSSTRATCOM, JTF-GNO will issue the orders and directives
necessary to maintain the assured service of the GIG. This ensures that the President, SECDEF, CCDRs,
and Services and agencies can accomplish their missions. The CCDR, Services, and agencies will execute
JTF-GNO’s directives within their respective areas and report compliance. To achieve this mission, the
CDRUSSTRATCOM has assigned these tasks to the commander of JTF-GNO. The commander of JTF-
GNO has the following tasks:
z
Direct GIG NETOPS to ensure confidentiality, integrity, availability and efficiency of the GIG
infrastructure and information services.
z
Establish and maintain SA of the GIG and report readiness and defensive posture to HQ
USSTRATCOM, as required.
z
Coordinate with HQ USSTRATCOM staff and subordinate organizations, as required, during the
development, acquisition, implementation, promulgation and operation of NETOPS joint tactics
techniques procedures and tools intended for monitoring performance, threats, policy compliance
and controlling network access.
z
Assist in identifying, establishing and maintaining GIG NETOPS characteristics, capabilities,
standards and requisite measures of effectiveness for infrastructure and information services.
z
Direct and oversee NETOPS and defense capabilities. Synchronize network defense capabilities
with the Joint Functional Component Command Network Warfare (JFCC-NW), the joint IO
warfare command and other USSTRATCOM components, as necessary. Assume OPCON or
tactical control (TACON), where applicable, of NETOPS/CND forces and capabilities for day-
to-day and crisis response actions.
z
In collaboration with the joint IO warfare command and ICW JFCC-NW ensure that computer
NETOPS (computer network attack, CND and CND response action) are synchronized for crisis
and deliberate planning. These activities support USSTRATCOM JFCCs and other CCDRs'
mission objectives and courses of action; including integration with supporting operational and
tactical level plans, as directed by CDRUSSTRATCOM.
z
Develop course of action (COA) recommendations for NETOPS, including CND and CND
response action, in support of USSTRATCOM and national strategic objectives. Support the
JFCCs for the integration of NETOPS into USSTRATCOM mission areas. Provide an embedded
capability in the Global Operations Center to support JFCC global strike and integration mission
of operational level integration of USSTRATCOM missions and maintaining SA for the
commander.
z
Establish procedures to conduct CND response action IAW DOD policy and coordinate with
JFCC-NW for Tier 1 CND RAs. CDRUSSTRATCOM retains the execution authority and
responsibility for those procedures.
z
Oversee procedures to establish and provide measures of effectiveness and damage assessment as
a part of network defense operations.
z
Provide support for USSTRATCOM and other geographic and functional CCDRs’ exercises,
wargames and experimentation requirements involving NETOPS. Integrate and synchronize
efforts with USSTRATCOM Training and Exercise Division.
19 November 2008
FM 6-02.71
4-3
FOR OFFICIAL USE ONLY
Chapter 4
z
Provide network defense priority intelligence requirements, requests for intelligence, intelligence
production requirements and intelligence collection requirements with USSTRATCOM J-2 for
tasking, deconfliction and accomplishment.
z
Perform all-source analysis of threats to the GIG, including threat analysis of foreign malicious
activity, ICW USSTRATCOM J-2, JFCC ISR, and JFCC-NW. Provide assessments and
recommendations to CDRUSSTRATCOM and other CCDRs for changes dictated in network
threat warning and INFOCON procedures.
z
Establish a relationship with mission area experts in the applicable GCC Standing Joint Force
Headquarters to provide operational support for NETOPS with emphasis on CND capabilities.
This relationship will include the training and periodic qualification of NETOPS support in
Standing Joint Force Headquarters, as required.
z
Support USSTRATCOM development and execution of NETOPS assessments, research and
development efforts and advocacy of capability needs for the Joint Capabilities Integration
Development System process.
z
Support USSTRATCOM and JFCC's led efforts to create and maintain strategic-level operations
plans. Support development and coordination of NETOPS and command, control,
communications and computers portions of operations plans, concept plans, functional plans, and
supplemental plans as directed by headquarters. Support other combatant commands with
NETOPS and command, control, communications and computers operational planning and
execution, as directed by headquarters.
z
Develop and coordinate NETOPS CONOPS.
COMMANDER OF THE GLOBAL NETWORK OPERATIONS CENTER
4-12. The CJTF-GNO has established the GNC as a subordinate command responsible for executing the
daily operation and defense of the GIG. The GNC directs, manages, controls, monitors, and reports on
essential elements and applications of the GIG in order to ensure its availability to support the needs of the
President, SECDEF, CCDRs, Services, agencies, and business and intelligence domains. The GNC
coordinates through technical channels the overall management, control, and guidance for GIG NETOPS
and oversees a collaborative coordination process involving all CC/S/A. The GNC has the following
responsibilities:
z
Direct the operation and defense of the GIG.
z
Collaborate with the NETOPS community to ensure effective operation and defense of the GIG.
z
Advise CDR, JTF-GNO and CDRUSSTRATCOM on matters regarding the allocation and
adjudication of GIG resources.
z
Advise CDR, JTF-GNO and CDRUSSTRATCOM of any matters impacting the GIG’s integrity
and/or NETOPS issues affecting DOD missions.
z
ICW CC/S/A, establish and maintain the technical and operational standards by which the GIG
SA will be generated across the GIG.
z
Provide a consolidated global SA view to the GCCs/TNCCs and other NETOPs components.
z
Ensure close coordination between the global satellite communications support center (GSSC)
and the Joint Space Operations Center to ensure anomaly/incident management can support SA.
z
Perform global incident/intrusion monitoring and detection, strategic vulnerability
z
Analysis, media analysis, and responses to GND-related activity.
z
Direct COA and coordinate the CND incident RAs across DOD to defend networks under attack.
z
Determine COA and direct restoral of GIG capabilities and services when required.
z
Maintain GIG SA in support of each CCDRs current and near term operations as well as
deliberate plans.
z
Maintain visibility, to include security monitoring of the GIG, through an integrated GIG SA
view. This is achieved through the integration of the TNC and Service/agency collected and
4-4
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Control Centers
shared GIG SA data. This shared SA view includes wireless, terrestrial, SATCOM systems,
enterprise services, and limited logical and physical infrastructure views of the networks.
z
Identify, localize, and resolve GIG security anomalies that affect the GIG’s ability to support
senior military leadership at the national level, Joint Staff, and supported CCDR.
z
Coordinate GND support to the CCDR.
z
Coordinate with and receive support from the DOD law enforcement and counterintelligence
center.
4-13. The GNC establishes procedures facilitating the ability of geographic commanders who share
common GIG assets to:
z
Consider the impact of one’s own actions or inactions on adjacent commanders and related
business and intelligence communities.
z
Provide access to timely information among adjacent commanders regarding others’ intentions
and actions, as well as those of non-military agencies or the enemy, which may influence
adjacent activity.
z
Support adjacent commanders, as required, by establishing a common aim and monitoring the
unfolding situation.
z
Coordinate the support provided and received.
COMMANDER OF THE GLOBAL NETWORK OPERATIONS SUPPORT CENTER
4-14. The CJTF-GNO will create a subordinate command to provide the day-to-day technical operation,
control, and management of the portions of the GIG that support global operations but are not assigned to a
CCDR. The GNSC will conduct GIG backbone NETOPS, STEP mission support, provisioning of provided
services, network engineering, circuit implementation and inter-theater connectivity among the US Army
Northern Command; US Army, Pacific Command; US Army, European Command; USARSO; and US
Central Command AORs. The GNSC will provide general support to the GCCs and TNCs. The GNSC will
provide direct support to the functional CCDRs.
4-15. The GNSC will provide full-time (24 hours a day, seven days a week), near real-time, correlated
visibility, monitoring, coordination, control, and management support of the global backbone portions of
the GIG. The commander of the GNSC will develop, monitor, and maintain a GIG SA view for the global
backbone. To carry out its mission, the GNSC—
z
Operates and maintains GIG backbone services within the CONUS boundaries to include
services originating within CONUS to OCONUS locations.
z
Collaborates with the CC/S/As NETOPS centers to ensure effective operation and defense of the
GIG.
z
Advises the GNC on issues relative to the allocation and performance of GIG backbone
resources.
z
Advises the GNC of issues impacting the integrity of the GIG and/or NETOPS issues affecting
DOD missions.
z
Works collaboratively with the GNC and the CC/S/As to establish and maintain the technical and
operational standards by which information sharing and status reporting will be implemented to
fully enable NETOPS.
z
Ensures compliance with JTF-GNO issued directives and guidance within their respective areas
of responsibility.
z
Provides SA information for backbone services within their boundaries of the GIG.
z
Monitors and collects performance and trending data for those GIG resources deemed important
by JTF-GNO.
z
Provides system and network status (fault and performance) information for their portion of the
global SA view.
19 November 2008
FM 6-02.71
4-5
FOR OFFICIAL USE ONLY
Chapter 4
z
Assists in the correlation and analysis to determine the technical and operational mission impacts
caused by degradations, outages, and GND events.
z
Performs global, theater, and non-global incident/intrusion monitoring and detection, strategic
vulnerability analysis, media analysis, and coordinates responses to GND-related activities.
Directs the execution of CND incident RAs within their respective areas of responsibility to
defend networks under attack.
z
Determines COAs and directs the restoral of capabilities and services as required.
z
Maintains SA in support of each functional component commander's current, near term, and
deliberate planning operations, as required.
z
Maintains security monitoring through an integrated GIG sensor grid.
z
Coordinates with and receive support from the law enforcement/counter-intelligence community.
FUNCTIONAL COMBATANT COMMANDS (UNITED STATES STRATEGIC COMMAND, UNITED
STATES SPECIAL OPERATIONS COMMAND, UNITED STATES JOINT FORCES COMMAND, AND
UNITED STATES TRANSPORTATION COMMAND)
4-16. Functional CCDRs have a global mission, often providing support to the GCCs, and have a global
requirement for NETOPS support. Some functional CCDRs operate their own function-specific global
network, Joint National Training Capability, Global Transportation Network, and Ballistic Missile Defense.
The functional CCDRs will receive direct support from the GNSC and general support from
USSTRATCOM, JTF-GNO, and all TNCs. Functional CCDRs will exercise OPCON over their portions of
the GIG through their GNCC. The GNCC will coordinate the functional CCDR’s NETOPS requirements
with the GNSC and the TNCCs.
GLOBAL NETOPS CONTROL CENTER
4-17. The primary mission of a GNCC is to advise the functional CCDR and ensure the portion of the GIG
resources supporting the commander’s assigned missions and operations are optimized. To be effective,
each GNCC must remain cognizant of all current, future, or contemplated operations in which their portion
of the GIG will play a role.
4-18. The GNCCs monitor the CCDR’s GIG assets, determine operational impact of major degradations
and outages, and coordinate responses to degradations and outages that affect joint operations. Each GNCC
will coordinate with the GNC and support any TNC mission or operational impacts that are associated with
system and network anomalies or resource limitations. Additionally, the GNCC has direct liaison
authorization with the TNCCs. This authorization gives the GNCCs and TNCCs the ability to directly
coordinate scheduled changes in the GIG or troubleshoot outages.
SERVICES AND AGENCIES
4-19. The Services and defense agencies provide, operate, and maintain the vast majority of the equipment,
personnel, and other resources that make up the GIG. Execution of these functions requires the Services and
agencies to be actively engaged in NETOPS of the GIG. To execute these functions, the Services and most
agencies have established NOSCs, which maintain SA of their portions of the GIG. In this manual, these
organizations are called Service and agency global NOSCs.
4-20. These Service GNOSCs and agency GNOSCs serve as a central point of contact for matters
concerning the resources they provide to the GIG. JTF-GNO will exercise OPCON of the Service
GNOSCs. DOD agencies will align their agency GNOSCs to provide USSTRATCOM visibility and insight
of their GIG status and will follow the orders and directives issued by JTF-GNO. Services and agencies will
maintain a global perspective of their GIG assets and provide service specific support to the global network
operations mission. This global SA is necessary for the Service and agency to properly provide the
equipment, personnel, and other resources they contribute to the GIG. The Army executes its Service
GNOSC responsibilities via the A-GNOSC and the ACERT (also known as the A2TOC).
4-6
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Control Centers
ARMY GLOBAL NETWORK OPERATIONS AND SECURITY CENTER
4-21. The A-GNOSC is the Army's execution arm for Operations, Management and Defense of the LWN.
The A-GNOSC executes this responsibility using the NETOPS construct. The A-GNOSC uses the
NETOPS essential tasks of ESM/NM, IA/CND and IDM/CS to execute its responsibilities in order to
achieve LWN availability, LWN information protection and delivery. The A-GNOSC synchronizes,
coordinates and directs all Army LWN IT/information management service management, through the
TNOSC in each ASCC; the ACOMSs, the direct reporting units, and the PEOs. The A-GNOSC is
responsible for acquiring and providing NETOPS SA to the Army decision makers at all echelons.
Service Responsibilities
4-22. As the first step in achieving GNO, the SECDEF has approved the transfer of OPCON of the A-
GNOSC to CDRUSSTRATCOM through the designated Service component (ARSTRAT) headquarters for
CND per Headquarters Department of the Army Computer Network Operations Standing Execute Order.
CDRUSSTRATCOM will further delegate OPCON of the A-GNOSC to JTF-GNO. The A-GNOSC serves
as a part of the Service component to JTF-GNO. The A-GNOSC mission is to provide the Army-specific
NETOPS reporting and SA for the Army’s portion of the GIG. The A-GNOSC provides worldwide
operational and technical support to the Army’s portion of the GIG across the strategic, operational, and
tactical levels, leveraging collaboration of the established TNOSC. The Army NOSC is integrated with the
1st IO CMD ACERT to create a consolidated NETOPS center called A2TOC. This alignment of
organizations provides a critical synergism of effectiveness and efficiency to receive, distribute, and analyze
information in order to integrate, synchronize, and coordinate Army NETOPS.
Note. To enhance the A-GNOSC support to the CDRUSSTRATCOM in CND, Appendix F will
provide the CND view of the LandWarNet information assurance architecture (LIAA).
THEATER LEVEL
4-23. The theater portion of the GIG, from the operational perspective, is comprised of that portion of the
GIG operated by a Geographic Unified Command, its sub-unified and component commands, its joint and
single-service task forces, and installations and activities within the AOR. From a technical perspective, it is
a subset of GIG assets, resources, and services.
4-24. Figure 4-2 depicts the command and control relationships for theater NETOPS. The theater CCDR
exercises OPCON of all assigned NETOPS forces and their portion of the GIG. The USSTRATCOM TNC
is under the tactical control of the theater CCDR for theater NETOPS issues. The CCDR’s TNCC is
responsible for the operation of their portion of the GIG and issues directives to the TNC and component
NETOPS organizations to ensure that the GIG supports the theater mission. USSTRATCOM and JTF-GNO
are in support of the theater CCDR and ensure that the GIG is capable of supporting the theater CCDR’s
requirements.
4-25. When there are conflicts or resource contention between CCDRs’ requirements, JTF-GNO will
deconflict resource requirements. Competing resource requirements that cannot be resolved will be
forwarded through CDRUSSTRATCOM to the CJCS for adjudication. The Service and agencies may
establish theater-level NOSCs or provide 24 hours a day, seven days a week theater level SA to support the
requirements of the CCDRs and their Service components. Either the global or theater NOSC will provide
theater GIG visibility to the TNC and other DOD component NOSCs as required. This Service or agency
NOSC will also serve as a central point of contact for operational matters and emergency provisioning for a
supported CCDR. This will enable improved GIG SA at all levels of the command structure and facilitate
end-to-end GIG management.
19 November 2008
FM 6-02.71
4-7
FOR OFFICIAL USE ONLY
Chapter 4
SECDEF
Supported
GCC
FCC
USSTRATCOM
Services
Agency
Title
10/32
NETOPS Org
GNCC
TNCC
COCOM
JTF-GNO
Non-DoD
TNC
GNSC
GISMC
GNC
Mission
GSSC
Partner
IC-IRC
SUC,SCC,FCC,JTF
Service NETOPS
SCC,FCC,JTF
NETOPS Forces
Components
NETOPS Forces
NOSC/CE(I)RT
ADCON
Command Relationship Legend
Supported
OPCON
DirectSupport
ADCON
General Support
TACON
Coordination
Figure 4-2. Theater NETOPS command and control
GEOGRAPHIC COMBATANT COMMANDS (UNITED STATES CENTRAL COMMAND, UNITED
STATES EUROPEAN COMMAND, UNITED STATES PACIFIC COMMAND, UNITED STATES
NORTHERN COMMAND, UNITED STATES SOUTHERN COMMAND)
4-26. The GCC exercises OPCON over the GIG and component NETOPS forces, and exercises tactical
control over the TNC for theater NETOPS matters. To accomplish this, all GCCs will establish a TNCC,
through which they will maintain SA and exercise OPCON and tactical control of their apportioned,
allocated, or assigned system and network environment. The CCDR’s main operations responsibility at the
theater level is to direct, establish, and control the systems and networks used to conduct command and
control of the CCDR’s mission.
THEATER NETWORK OPERATIONS CONTROL CENTER
4-27. The primary mission of the TNCC is to lead, prioritize, and direct GIG resources to ensure they are
optimized to support the GCC’s assigned missions and operations. The TNCC is also required to advise the
4-8
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Control Centers
CCDR of the ability of the GIG to support current and future operations. In performing its mission, the
TNCC exercises OPCON over all theater systems and networks operated by forces assigned to the CCDR.
The TNCC also exercises tactical control over the TNC for theater NETOPS issues. The specific roles of
the TNCC include monitoring of the GIG, determining operational impact of major degradations and
outages, coordinating responses to degradations and outages that affect joint operations, and coordinating
GIG actions in support of changing operational priorities. The TNCC also responds to JTF-GNO direction
when required to correct or mitigate a GNO issue.
4-28. The TNCC, in advising the CCDR of the GIG’s ability to support assigned missions and operations,
must remain cognizant of all current, future, or contemplated operations involving the GIG. This requires
continual contact and coordination with the CCDR’s Joint Operations Center. Serving as an operational
extension to the CCDR’s command center, the TNCC provides GIG SA and operational impact assessments
to the commander and the Joint Operations Center.
4-29. The TNCC will use the GIG SA view provided by their TNC, component NETOPS organizations,
and theater JNCCs to maintain SA over the portion of the GIG necessary for the success of their CCDR’s
assigned missions. Although the NETOPS SA software application will be a part of an enterprise-wide
software toolset, the input data requirements and output products (picture or view reports, etc.) will be user
customizable, based on built-in options, to meet the needs of each CCDR.
4-30. The TNCC is responsible for coordinating the definition and development of the content and scope of
the GIG SA information view for the theater based on DOD parameters to assure complete integration. This
will be based on the commander’s guidance and requirements submitted by subordinate commands. The
specifications will be submitted to the TNC, which is responsible for producing and disseminating the GIG
SA view. Some level of minimum SA view shall be defined to ensure that all NETOPS facilities provide a
consistent set of information and to make it easier to integrate and roll-up SA views generated by different
theaters or organizations.
4-31. The TNCCs will direct and prioritize required operational actions through their supporting TNC and
assigned NETOPS forces. System and network management activities, in response to NETOPS decisions
made by the TNCC, are accomplished through the CCDR’s tactical control authority over the TNC and
through OPCON over forces assigned to the CCDR. In order to carry out it’s mission, the TNCC will:
z
Establish uniform 24 hours a day, seven days a week visibility into the status of the GIG SA view
to/from the TNC and assigned NETOPS organizations.
z
Collaborate with the NETOPS community of interest to ensure effective operation and defense of
the GIG.
z
Establish and retain visibility of system and network outages and customer service shortfalls.
Receive, consolidate, and analyze all available reports from the components, agencies, JTFs, and
deployed units.
z
Direct reporting of NETOPS events, conduct analysis of the impact of such events on the
operational mission, develop alternate COAs, and advise the commander and other senior
decision makers on the status of GIG degradations, outages, GND events, and areas requiring
improvement.
z
Prioritize the installation and restoration of system and network services for the TNC and
subordinate organizations in the form of a critical customer (i.e., decision-maker) listing.
z
Direct, coordinate, and integrate response actions to computer network attacks and significant
intrusions affecting the CCDR’s portion of the GIG.
z
Direct the theater’s response to JTF-GNO directives for correcting or mitigating GNO issues.
z
Coordinate with JTF-GNO to deconflict the CCDR’s theater NETOPS priorities with the global
network operations priorities of JTF-GNO and USSTRATCOM.
z
Deconflict issues between the TNC and TNOSC/A-GNOSC.
19 November 2008
FM 6-02.71
4-9
FOR OFFICIAL USE ONLY
Chapter 4
THEATER NETWORK OPERATIONS CENTER
4-32. The TNCs OPCON to the JTF-GNO provide full-time (24 hours a day, seven days a week), near real-
time, correlated visibility, monitoring, coordination, control, and management support of the CCDR,
Service, and agency portions of the GIG. For example, the TNC provides the view of the GIG within a
CCDR’s AOR. This type of capability will include reciprocal, shareable "look-up" and "look-down" near
real-time correlated views of component, sub-unified, and JTF elements of the GIG.
4-33. The commander of each TNC will develop, monitor, and maintain a GIG SA view for the theater.
The theater GIG SA view will be aggregated and segmented based on requirements provided by the TNCC
or GNCC. It will include pertinent theater, operational, and tactical-level system and network GND and
GCM status. To carry out its mission, the TNC will—
z
Operate and maintain the backbone services of the GIG assets located in their theater.
z
Collaborate with the NETOPS community of interest to ensure effective operation and defense of
the GIG.
z
Issue technical directives to STNOSCs and agency TNOSCs to ensure compliance with TNCC
and JTF-GNO direction.
z
Receive SA information in order to monitor all theater service or Service component and agency
systems and networks designated as mission critical.
z
Support the CCDR, Services, and agencies by creating and disseminating the NETOPS SA views
for the theater Service or Service component and agency. This is accomplished by integrating
NETOPS event and status information received from those elements within the TNC AOR that
have NETOPS reporting requirements. This shared SA view includes wireless, terrestrial, space
based systems, and enterprise services.
z
Coordinate with the TNCC regarding reporting requirements (input data) and view specifications
for NETOPS SA.
z
Continuously monitor and collect performance data for those information resources deemed
important by the CCDR’s TNCC or GNCC.
z
Provide system and network status (fault and performance) information as part of the SA view.
z
Provide the TNCC or GNCC with information security products and services to include: the
monitoring and reporting of intrusions, physical threats and analysis, correlation of intrusion
incidents with components, sub-unified commands, and JTFs.
z
Assist in determining the technical and operational mission impacts caused by degradations,
outages, and GND events.
z
Perform incident and intrusion monitoring and detection, strategic vulnerability analysis,
computer forensics, and responses to GND-related activity. Direct COAs and coordinate the
GND incident response actions across DOD to defend networks under attack.
z
Determine COAs and direct restoration of capabilities and services when required.
z
Maintain SA in support of each CCDR's current and near term operations as well as deliberate
plans.
z
Maintain security monitoring through an integrated GIG SA view. This is achieved through
integration of TNC and Service or agency collected and shared GIG SA data. This shared SA
view includes wireless, terrestrial, and space-based systems and enterprise services.
z
Identify and resolve computer security anomalies that affect the GIG assets located in their
theater.
z
Coordinate theater GND support as directed by the TNCC.
z
Coordinate with and receive support from law enforcement and counterintelligence center.
z
Manage theater radio frequency interference resolution, satellite anomaly resolution, and
SATCOM systems.
4-10
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Control Centers
SERVICE AND AGENCY THEATER NETWORK OPERATIONS AND
SECURITY CENTERS
4-34. Service components supporting a geographical combatant command may establish TNOSCs based on
the size and topology of their NETOPS responsibilities in order to provide and manage systems and
network services. The TNOSC will serve as a single point of contact for their theater elements for systems
and network services; ESM/NM, IA/CND, and IDM/CS capabilities; and operational reporting. The
TNOSC provides GIG SA information to the TNC and the TNCC. In the absence of a TNOSC, the A-
GNOSC will perform the function of the TNOSC. To facilitate end-to-end management and maintain the
accuracy of the GIG SA view, each TNOSC will—
z
Sub-exercise routine, day-to-day management, control, and defense of system and network
services provided as part of the GIG.
z
Collaborate with the NETOPS community of interest to ensure effective operation and defense of
the GIG.
z
Comply with GIG SA (visibility and status) reporting requirements for their portion of the GIG
as determined by the CCDR.
z
Provide GIG SA information specifically from the TNC points of presence to the component’s
deployed forces.
z
Provide the TNCC or GNCC and TNC current (near real-time) SA of systems and networks
under their control and within their portion of the GIG for retrieval and use by other NETOPS
centers.
z
Assist the TNC and the TNCC or GNCC in tracking the status of NETOPS events and
determining the technical and operational mission impacts caused by NETOPS events.
z
Respond to a variety of threats using a range of response measures to preclude, detect, and
counter any threat.
z
Exercise tactical control over the system and network resources of their assigned NOSCs,
divisions, and brigades and systems administrators.
ARMY FORCES NETWORK OPERATIONS AND SECURITY CENTER
4-35. The ARFOR NOSC is provided by the SC(T)’s TNOSC. The ARFOR G-6, as a staff officer, should
establish an Army NETOPS Control Center.
4-36. The Army NETOPS Control Center provides the commander’s intent and direction to the TNOSC
that is responsible to operate, manage, and defend the theater’s portion of the LWN and GIG. The TNOSC
executes the command’s intent and direction for the LWN. The SC(T) or its deployed element is OPCON to
the ARFOR. Thus the TNOSC or its deployed element is OPCON to the ARFOR.
THEATER NETWORK OPERATIONS AND SECURITY CENTER
4-37. The TNOSC operates, manages, and defends LWN in order to deliver seamless communications
system information management capabilities in support of all in-theater Army entities in its AOR. The
TNOSC executes its NETOPS responsibilities ICW the numbered Army G-6. The responsibilities of the
TNOSC include the oversight of both fixed theater infrastructure as well as tactical Army units within the
theater AOR. Figure 4-3 represents the TNOSC structure.
UNIFIED COMMANDS
4-38. CCDRs may organize a sub-unified command and assign tailored forces from among the four Service
components and special operations forces to the sub-unified commander. The CCDR assigns the sub-unified
commander OPCON of designated forces.
19 November 2008
FM 6-02.71
4-11
FOR OFFICIAL USE ONLY
Chapter 4
4-39. Sub-unified commands may establish sub-unified NETOPS control centers with responsibilities and
relationships similar to a Service TNOSC. The sub-unified command’s NOSC will serve as a single point of
contact for their subordinate elements for systems, network services, and reporting.
SUB-UNIFIED NETOPS CONTROL CENTER
4-40. Sub-unified NETOPS control centers will provide GIG visibility and status information to the
geographical combatant command’s TNCC and TNC to facilitate end-to-end management and maintain
accuracy of the NETOPS.
JOINT NETOPS CONTROL CENTER
4-41. The JNCC manages the tactical communications of the joint force, serving as the NOSC for the
deployed portion of the GIG supporting a JTF. It exercises staff supervision over the communications
system signal company belonging to deployed components and subordinate commands. The JNCC provides
the appropriate TNCC with:
z
GIG SA information (directly to TNCC and TNC).
z
Mission impact assessments of system and network events.
z
GIG requirements beyond the JTF’s current assets or authority.
THEATER NETWORK OPERATIONS AND SECURITY CENTER DEPLOYMENT SUPPORT
DIVISION
4-42. In conjunction with the modular restructuring of the Army, the SC(T) is undergoing revision in order
to support emerging requirements of the new modular force. One revision is the addition of a new
deployment support division within the TNOSC. The deployment support division has primary
responsibility for all NETOPS support to deployed forces. It is comprised of two branches: the tactical
network team (TNT) and the tactical integration cell (TIC). Refer to Figure 4-3 for an illustration.
Office of the
Directorate
TNOSC
Ops Div
Info
Deplymt
IDM/CS
Enterpr
Network
Enterpr System
Assur
Support
DIV
Serv Div
Mgt Div
Mgt Div
Div
Div
Mission
Support Br
Data
Sys Spt
Tactical
Config
Infostruct
NW & SYS
Network
& Integr
Integrat’n
Mgt Br
Serv Br
Monitor BR
Br
Br
Cell
Action
Request
Center
Service
Voice
Database
Info
Tactical
IDM
Level Mgt
Systems
Mgt&
Assur
Network
BR
Br
Br
Applic Br
Br
Tm(TNT)
Transmsn
Systems
Br
Figure 4-3. TNOSC structure
4-12
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Control Centers
Tactical Network Team
4-43. The TNT is an authoritative NETOPS cell for a joint or Army component command. It is a fully
deployable (but based on mission, enemy, terrain and weather, troops and support available-time available,
it is not necessarily fully or always deployed) NETOPS entity that can provide a complement of NETOPS
capabilities to a deployed headquarters. For example, the TNT could deploy to implement or augment the
ARFOR NOSC supporting the JFLCC.
Tactical Integration Cell
4-44. The TIC is a body of tactical network personnel within the deployment support division of the
TNOSC that is dedicated to the integration and support of tactical units. This would include oversight and
management of tactical numbered Army NETOPS support services, such as the network service center
regional and tactical NETOPS systems. It also includes the formation of temporary tactical liaison team
(TLT), which is dedicated to support a specific tactical unit.
4-45. Other divisions under the TNOSC structure include a TNOSC Operations Division, IDM/CS
Division, Enterprise Services Division, Network Management Division, Enterprise Systems Division, and
the Information Assurance Division. Each division is structured with several branches reporting to the
division which reports to the directorate.
TNOSC OPERATIONS DIVISION
4-46. The TNOSC Operations Division is the analog of the S-3 in a regular battalion. It has oversight of the
day-to-day operations of all divisions, focusing on larger systemic problems that require directed focus or
resolution. The division consist of the following branches:
z
Mission Support Branch. This branch provides all the administrative and logistic support for
the TNOSC. Included here are the budget, personnel, and training activities. Contracting
Officer’s Representative duties and oversight of other contracts (for which the TNOSC is not the
Contracting Officer’s Representative) that affect the TNOSC. Responsible for procurements,
Unfunded Requirements, Program Objective Memorandum submissions, IMPAC card, military
interdepartmental purchase request tracking and coordination with resource managers. This
branch operates 8 hours a day, 5 days a week.
z
Action Request Center. This branch operates 24 hours a day, seven days a week to provide SA
of all NETOPS activities that the TNOSC controls or interacts with. The staffing for the watch
officers is in the action request center. This branch does all reporting to higher and lateral
agencies. It provides overall direction of troubleshooting and reporting of subordinate units. This
branch operates 24 hours a day, seven days a week.
INFORMATION DISSEMINATION MANAGEMENT DIVISION
4-47. The IDM Division provides the CM for the theater operations. It also determines customer info
source/sink and provides immediate feedback of the accuracy of the CM documents and products providing
the best feedback loop. The division consist of the following branches:
z
Configuration Management Branch. This branch runs the theater level NETOPS CM program.
It chairs the theater NETOPS CCB. It maintains the CM database and network level drawings.
This branch manages the program for the theater and monitors and measures the effectiveness of
subordinate CM programs. Coordinates with the theater Army G-6 and signal command theater
program managers to insure projects are included in the CM process. This branch works 8 hours
a day, 5 days a week.
z
IDM Branch. This branch manages the theater IDM program, establishing the architecture and
overseeing the IDM efforts of subordinate NOSCs. Coordinates IDM with other divisions and
teams. Provides expertise to incorporate IDM into communications planning, optimizes IDM
infrastructure resources, analyzes and documents IDM requirements and implements IDM
enabling technology to include CS. This branch works 8 hours a day, 5 days a week.
19 November 2008
FM 6-02.71
4-13
FOR OFFICIAL USE ONLY
Chapter 4
ENTERPRISE SERVICES DIVISION
4-48. The Enterprise Services Division operates the applications (as opposed to the networks) that provide
the enterprise network services and enable the management of the enterprise ―down to the desktop‖. This
division also tracks and monitors operation of the area processing centers (APC) in theater. The division
consist of the following branches:
z
Infostructure Services Branch. This branch manages the services that the networks provide to
enable the customers to utilize the enterprise. These services would include DNS, Remote
Authentication Dial-In User Server (RADIUS), and remote access services (VPN program). It
includes management of the AD theater root and domain controllers/catalogs. It includes
messaging services and management of Defense Message Service and Exchange.
z
Service Management Branch. This branch implements the Service Management program for
the TNOSC and the theater. It manages the Service Level and Operational Level Agreements that
the TNOSC enters into. It monitors the theater Service level delivery program for the
TNOSC/SC(T) and the subordinate units providing the SC(T) and commanders with SA of the
service delivery across all disciplines of NETOPS. It provides performance management
monitoring and reporting on the Information Technology Infrastructure Library
capacity/availability areas and trending. The plans and engineering sections of the theater army
G-6 and the signal command theater assistant chief of staff, operations (G-3) are customers of the
performance analysis. This branch works 8 hours a day, 5 days a week.
NETWORK MANAGEMENT DIVISION
4-49. The Network Management Division operates and/or manages the underlying ―transport‖ networks
that other applications and services use. It is the focus on the underlying network that distinguishes it from
the Enterprise Services Division. In some cases, the TNOSC operates a theater backbone and directs the
operation of subordinate agencies in their operation of lower portions of the network. In other cases, it
entirely directs the operations of subordinate units. A good example of this dichotomy is (the current day)
DISA RNOSC/SC(T). It operates an IP backbone, but the Service/agencies operate the DSN backbone
(OCONUS). The division consist of the following branches:
z
Data Networks Branch. This branch provides oversight of the IP router networks (classified
and unclassified). Operates the theater IP backbone. Provides oversight to operation of the IP
networks by subordinate organizations. Provides theater level analyst functions, theater designs
and access list architecture. Implements theater level IP reach back, to include routing plans,
when the reach back is not to a STEP site. Reporting and SA of theater IP network capabilities.
This branch operates 24 hours a day, seven days a week.
z
Switched Systems Branch. This branch manages/operates the voice networks in theater, to
include DSN and Defense Red Switch Network (DRSN). Actions performed by this branch
include oversight of subordinate operating activities, validation of DISA implementation
directives, CM of switches, integrating voice reach back and trunking, reporting and SA for
voice capabilities within the theater. This branch operates 24 hours a day, seven days a week.
z
Transmission Systems Branch. This branch operates/manages the transmission systems
backbone, and oversees the operations of transmission systems by subordinate units. Examples of
backbone systems operated include Fiber infrastructure, synchronous optical network, dense
wavelength division multiplexing, asynchronous transfer mode (ATM), and integrated digital
network exchange. Coordinates theater wide COMSEC re-keys. Oversees/tracks operation of
satellite facilities by subordinate units. SA reporting for all transmission systems, to include
deployed units. Depending on theater may also monitor circuits on STEP facilities (via ―copy‖
feed of native management system). Implements routing plans. This branch operates 24 hours a
day, seven days a week.
4-14
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Control Centers
ENTERPRISE SYSTEMS MANAGEMENT DIVISION
4-50. This division manages the internal systems of the TNOSC (LAN, power, servers and operating
systems) and devices distributed throughout the theater controlled by the TNOSC (such as DNS/RADIUS).
The division consist of the following branches:
z
Systems Support and Integration Branch. This branch provides support for the infrastructure
and servers, with their accompanying operating systems. Notionally, this branch has a UNIX
team, and Windows team, and a team that supports the infrastructure (switches, routers, virtual
LAN configurations) as well as environmental concerns (power, A/C, server room management).
The system administrators perform backups and coordinate this part (server restoral) of the
COOP. Support for various operating system related tools, such as Citrix. They centrally manage
patches and upgrades for the TNOSC controlled servers. This branch operates 8 hours a day, 5
days a week with on-call support.
z
Database and Applications Branch. This branch operates and maintains the applications used
by the TNOSC and distributed throughout the theater. A notional list would include: Remedy,
Spectrum (or other network management systems), Formula, Tivoli, Oracle, Cricket/MRTG,
ATM manager (supporting Remedy, as well as other applications such as CiscoWorks,
CiscoSecure, et al). This team also integrates programs and provides interfaces to other agencies’
systems (e.g. feeding status from Spectrum to DISA’s integrated network management system).
This branch also establishes the technical architecture for distributing these products and views
throughout the theater. This branch operates 8 hours a day, 5 days a week with on-call support.
INFORMATION ASSURANCE DIVISION
4-51. The IA Division provides operational oversight of the IA aspects of the network. The division consist
of the following branches:
z
Network and Systems Monitoring Branch. This branch monitors the theater network sensor
grid, including the IDS, other Top Level Architecture sensors, DID IDS sensors, host based IDS,
(theater level) firewalls, etc. It provides detection, first level analysis (triage) and initial response,
to include coordinating for blocking actions, trouble ticket initiation and dispatch. This branch is
staffed 24 hours a day, seven days a week.
z
Information Assurance Branch. This branch does the follow up, tracking, and reporting of
incident tickets. Performs internal and directed external scans and reports. Designs and verifies
ACL/firewall rule set. IAVA reporting for the TNOSC. Manages the theater software update
services program
(or other update service). Manages theater Anti-Virus update programs.
Manages theater CAP registration. Oversees accreditation and security actions of subordinate
units’ IA personnel. Crosschecks patch levels and IAVA compliance for all TNOSC systems.
This branch is staffed for 8 hours a day, 5 days a week with on-call support.
4-52. The TLT performs a liaison function to a corps, division, or brigade NETOPS cell that already exists.
The TLT provides essential integration services between the tactical unit and the respective TNOSC. It also
provides valuable technical NETOPS augmentation to the unit’s organic NETOPS capability. When
supporting a corps or division and a corps or division-based command, a TLT would typically collocate
with appropriate personnel at the assigned sanctuary. TLT personnel in support of an expeditionary BCT
may perform these functions from the TNOSC, or they may relocate to other locations as the mission
dictates. A typical scenario for these elements is depicted in Figure 4-4.
19 November 2008
FM 6-02.71
4-15
FOR OFFICIAL USE ONLY
Chapter 4
TNT
REAR
TIC
STEP
TNOSC
TLT
Division Signal
Company
DIV
JTF/JFLCC
TNT
FWD
SBDE
BCT
SBDE
BCT
BCT
BDE Control
DIV Control
ASCC Control
Joint Control
Robust Transmission
Tactical Transmission
Figure 4-4. TNOSC deployment support division elements: TNT, TIC, and TLT
TACTICAL SIGNAL BRIGADE NETOPS
4-53. The SB(T) S-3 performs NETOPS functions for all subordinate ITSB/ESBs and other supported
units. It also serves as the NETOPS interface to higher headquarters (e.g., it acts as a tactical NOSC). This
includes operational planning in conjunction with the theater G-6 as well as detailed engineering of
ITSB/ESB provisioned NETOPS capabilities.
INTEGRATED THEATER SIGNAL BATTALION NETOPS
4-54. The battalion S-3 element of the ITSB/ESB headquarters provides a NETOPS span of control
function for the ITSB/ESB. The S-3 performs all NOSC functions necessary to manage and secure the
ITSB/ESB network assets, and provide NETOPS capabilities and SA to the supported commander.
DIVISION NETOPS AND SECURITY CENTER
4-55. The division G-6 employs a fully integrated NOSC that provides NETOPS functions for the division
G-6. The division signal elements must coordinate with the NOSC during the engineering, installation,
operation, maintenance, and defense of the division information network.
4-56. Habitually, the division NOSC is co-located with one or more division TOCs. Due to recent
enhancements to tactical reach operations capability, the division G-6 may elect to perform some or all
NOSC functions from remote sanctuary locations such as the division tactical UHN or a division-controlled
cell within the network service center regional. Performing NOSC functions at unit-controlled sanctuary
locations is generally most effective during deployment and decisive operations. During these phases, the
division TOC is highly mobile and cannot provide a stable high-speed environment to host AOR services.
4-16
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Control Centers
4-57. The division NOSC, under the direction of the division G-6, has overall responsibility for establishing
the division information network and provides the operational and technical support to all of the division
signal elements in its AOR. The division NOSC performs the NETOPS activities, functions, and tasks
required to quickly shift priorities in order to support the division commander’s intent. Division NOSC
responsibilities include:
z
ICW the TNOSC, monitors, manages, and ensures implementation of ESM/NM, IA/CND, and
IDM/CS activities (performed by the division G-6 and subordinate organizations).
z
Provides near real-time awareness of division networks and systems to the division G-6 and
higher headquarters’ NOSC.
z
Coordinates actions to resolve attacks or incidents on the division network with the TNOSC and
subordinate organizations.
z
Coordinates operational procedures and requirements for IA/CND and information systems
security with the supporting TNOSC.
z
ICW the TNOSC, monitors, manages, and controls intra-division information network
components (performed by the division G-6).
z
Monitors the operation of the networks in the division’s subordinate brigades.
z
Provides support and assistance to the subordinate NOSCs as required.
z
Manages the organizational messaging system of record (Defense Message System, Tactical
Message System) in the division, including managing network addresses and sub-domains.
z
Coordinates operation and maintenance support of communications systems attached to support
deployed division forces with the split-base and reach operations capability to the home base.
z
Shares ESM/NM information with other management or monitoring centers.
z
Provides the supporting TNOSC with near real-time information on the status and performance
of inter-division networks.
z
Orders and accounts for all forms of COMSEC material. This includes storing keys in encrypted
form and performing key generation and automatic key distribution.
z
Performs COMSEC material accounting functions and communicates with other COMSEC
elements.
z
Performs IDM/CS functions to support all aspects of relevant information dissemination.
z
Provides near real-time awareness of all networks and systems within the division AOR.
BRIGADE NOSC
4-58. The brigade NOSC is the control center for the brigade network that manages all current operations
and network configuration. The brigade NOSC reports directly to the brigade G-6. The brigade NOSC
operates closely with the TOC nodal platoon, utilizing the JNN’s organic network management capability to
configure, monitor, and manage the WAN. The brigade NOSC supports the G-6 section in the planning,
configuration, management, and monitoring of the TOC LANs as well as prioritizes the dissemination of
information across the WAN. ICW the brigade G-6, the brigade NOSC—
z
Coordinates, plans, and manages brigade frequency assignments.
z
Plans and manages the brigade information network.
z
Plans and manages all IA/CND operations to include, but not limited to, IA systems (firewalls,
IDSs, and ACLs), key management distribution, IAVA compliance, and IDM and operations,
and compliance with all directives outlined in AR 25-2.
z
Plans and manages brigade IDM/CS procedures (user profiles, file and user priorities, and
dissemination policies) (at higher headquarters’ NOSC and supporting TNOSC).
z
Evaluates network requirements to determine needs for brigades and communications relay
requirements.
z
Aides in the execution of all NETOPS responsibilities in support of the unit mission.
19 November 2008
FM 6-02.71
4-17
FOR OFFICIAL USE ONLY
Chapter 4
Note. To support the information in this chapter, Appendix G and H provides deployment
scenarios for the division, BCT, and ASCC.
NETWORK OPERATIONS COMMAND AND CONTROL
RELATIONSHIPS
4-59. The senior ARFOR mission commander commands and controls the tactical Army network in
compliance with joint, Army, and theater NETOPS policy and direction. To ensure that a seamless and
autonomous network is achieved, the mission commander delegates the authority to control and configure
the network to the G-6 through the telecommunications service order (TSO) process.
4-60. For current operations, the G-6 coordinates network reconfigurations through technical channels
based on the TSO process mentioned above and as specified by the commander in the operations order.
These changes include frequency modification, router configurations, or equipment settings. When
reconfiguration involves the movement of personnel and equipment within the current operation, the G-6
coordinates that adjustment with the G-3 and the G-3 issues the appropriate fragmentary order (FRAGO) in
support of that reconfiguration.
4-61. For future operations, the G-6 participates in the military decision making process. He identifies the
correct placement of network equipment and personnel on the battlefield in support of the mission. This
information is then vetted through COA development and published in the unit OPORD and requisite signal
annex.
4-62. The TSO process and technical channels are used for coordinating the configuration of the network.
This process flows from the GCC J-6 through the JTF, combined joint force land component command,
ARFOR, corps, division, BCT, and the battalion J-6, G-6, and S-6 structure to facilitate the establishment
and health of the enterprise network and theater network.
4-63. NETOPS control is the authority granted to a senior signal officer and his staff from their immediate
operational commander in compliance with joint, Army, and theater NETOPS policy and direction. This
ensures the day-to-day compliance of their network with their associated LWN and GIG requirements. In
addition, the fast moving nature of NETOPS, which is inherently a 24-hour/7-day operation, requires quick
decisions and adjustments that exceed the responsiveness of the traditional orders process.
4-64. Through technical channels coordination and the TSO process, the signal officer and staff execute the
commander’s directives to maintain and secure their network. This process involves policy, guidance, and
directives issued to subordinate signal organizations along the NETOPS channels. The TSO does not allow
the commander’s signal staff to move equipment or personnel but it does allow them to coordinate CM of
network devices within their area of operations. If there is a need to move equipment or personnel in order
to meet network requirements, the signal staff needs to coordinate with their respective G-3 or S-3 and issue
a FRAGO to the existing signal annex of the operations order for movement.
4-65. It is important to remember the TSO is a current operations process. The TSO is designed to give the
commander, through his signal staff, a means to adjust and modify the existing network plan to meet
unexpected circumstances that can range from outright network attacks to system failures and service
interruptions. Any future NETOPS control issues must be planned and executed through the orders process
(military decision making process) performed by the chain of command.
4-66. Lastly, any time the signal staff receives a TSO from a higher signal entity, they conduct a review to
determine if that TSO is potentially detrimental to their commander’s mission priorities. If it is determined
that the impact is not relevant to the mission, the signal staff then executes that TSO and informs the
commander. If the potential exists, the implementation of that TSO will affect the mission; the signal staff
coordinates with the command chain and requests guidance. If the decision is made by the commander not
to execute the TSO, then the necessary coordination to deconflict any issues is performed between the
command chain and the higher headquarters that issued the TSO.
4-18
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Chapter 5
Network Operations Activities
This chapter provides the conceptual framework for the execution of NETOPS. It
links organizations described in Chapter 3 and the phases and relationships described
in Chapter 4. It also addresses methods to reduce forward-deployed NETOPS and
global NETOPS policies and standards.
OVERVIEW
5-1. NETOPS activities were derived from the AENIA. They address the activities associated with the
provisioning and management of NETOPS capabilities. The activities are organized into four major areas:
z
NETOPS policies, standards, planning, and design. NETOPS policies and standards provide a
common foundation and general guidance for the provisioning and management of NETOPS
capabilities in support of the Soldier. NETOPS capabilities require planning and design to be
effective regardless of the affected organization, system, or technology. Planning and design of
NETOPS capabilities is especially important in the tactical environment with its potential for
limited connectivity and the ―fog of war‖ that can be experienced in the tactical environment.
z
Tactical operation of the network. The activities in this area directly support the Soldier with
NETOPS capabilities. This support spans all phases of operations. The NETOPS operational
activity area comprises the majority of this chapter. These activity categories represent the best
practices of NETOPS capability providers (both Army and industry) and provide a means of
categorizing NETOPS capabilities that is not specific to any technology or organizational
structure.
z
NETOPS evaluation. The evaluation of NETOPS capabilities extends the infrastructure
monitoring found in the operations activity area. It supports the monitoring and reporting of
capacity, availability, and IA compliance. It is focused on the health and protection of the
network and its services. It also provides the capability to support proactive management of
NETOPS capabilities.
z
NETOPS training. Effective use of NETOPS capabilities requires continuous training. As new
or updated NETOPS capabilities enter the tactical environment, the skills of the Soldiers require
enhancement or refreshment.
5-2. The descriptions of the activities in this chapter follow a common template. First, the NETOPS
functional activity itself is defined and described. Next, the echelon(s) and organization(s) that support the
specific activity are identified and details are provided on how organizations support the specific NETOPS
activity. This support information includes the inter-organizational relationships associated with the specific
NETOPS activity. Lastly, any joint implications related to the execution and support of the activities is
identified.
NETWORK OPERATIONS POLICIES, STANDARDS, PLANNING,
AND DESIGN
5-3. NETOPS policies and standards provide a common foundation and guidance for the provisioning of
NETOPS capabilities to the Soldier. The NETOPS planning and design process encompasses the
preparation required for the fielding and the continued support for NETOPS capabilities. Both global and
temporary mission-specific policies and standards are addressed in this section.
19 November 2008
FM 6-02.71
5-1
FOR OFFICIAL USE ONLY
Chapter 5
GLOBAL NETOPS POLICIES AND STANDARDS
5-4. Global tactical NETOPS policies and standards, while approved and issued from the global Army and
joint levels, apply to the provisioning of NETOPS capabilities at all tactical echelons. These policies and
standards define general NETOPS-related system configurations, procedures, protocols, and information
exchange requirements.
Note. Temporary changes to network policies can be more stringent or strict than the global
policies but cannot be less stringent or strict.
5-5. Global NETOPS policies and standards enable compatibility between tactical elements and minimize
the disruption caused by task organization. Global policies and standards are also critical in order to provide
tactical units with strategic support services and to help ensure compatibility between units that come
together from different geographical areas and different commands. Tactical units are partially dependent
on support from non-tactical echelons due to physical and manpower limitations. To effectively provide
strategic NETOPS support, the provisioning of tactical NETOPS capabilities must be performed in a
uniform and well-defined manner. While global tactical NETOPS policies and standards define and support
standardized NETOPS capabilities within tactical echelons, they do not impair the tactical commander’s
ability to dynamically manage and allocate NETOPS capabilities.
5-6. Some examples of global NETOPS policies and standards include:
z
Protocols and port configuration guidelines.
z
Inter-organization information exchange requirements.
z
Change approval and change implementation responsibilities.
z
Reportable CM information.
Note. Appendix C outlines a scenario of how policy management may occur.
Global NETOPS Policies and Standards in Echelons and Organizations
5-7. The primary responsibility of establishing global Army NETOPS policies and standards resides with
the CIO G-6. Both NETCOM/9th SC(A) and the US Army Signal Center support the CIO G-6. Refinement
of global policies with respect to tactical echelons is performed via direct interaction between theater
policy-makers and the tactical echelons. Global policies and standards are continually reviewed and
periodically updated based on policy and standards recommendations from tactical organizations, Army
enterprise modularity and efficiency requirements, and relevant technological advancements.
Global Policies and Standards Joint Implications
5-8. A working relationship must be in place between Army NETOPS policymakers and the joint
NETOPS community. Global tactical NETOPS policies initiated from the joint level require incorporation
into global Army policy. Policies arising within the Army tactical community must also be considered by
Army NETOPS policymakers through joint channels. This prevents policy conflicts when Army tactical
elements are operating in a joint environment.
TEMPORARY EXCEPTIONS TO NETOPS POLICIES AND STANDARDS
5-9. Isolated changes or additions to NETOPS policies and standards threaten Army enterprise modularity
and efficiency and should be minimized. NETOPS policies and standards in the tactical environment, due to
the time-sensitive and volatile nature of tactical operations, cannot always adhere to the lengthy policy
change process that is normally required in the fixed-station environment. Mission-specific factors may
necessitate temporary additions or changes to policy.
5-2
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Activities
5-10. Additions, changes, or exceptions to tactical NETOPS policy are approved via the chain of command
as previously described in Chapter 4. Prior approval must be granted from the next higher headquarters if
any particular echelon wishes to add, change, or circumvent tactical NETOPS policy. For example, if a
BCT commander wishes to issue a policy stating that all subordinate units must block a particular network
protocol, prior approval must be obtained from its higher headquarters, which will typically be a division.
This approval process decreases the likelihood that a unit will issue guidance that will impair the
functionality of the assets under its control or impact the broader NETOPS state of affairs. If the policy
addition or change is likely to cause a decrease in overall network health or modularity, the approving
headquarters will carefully consider whether the requirement for the policy change outweighs the potential
impacts.
5-11. In some cases, a policy change or addition requires approval by an echelon higher than the requesting
organization’s parent headquarters. This is expected to occur when the policy change may cause immediate
network-wide security or functionality ramifications. In the general case, echelons above the organization’s
parent headquarters only require notification when there is policy modification.
5-12. Exceptions to policy are forwarded through, and accumulated by, the chain of command. This data
should be reviewed and used to provide recommendations for global Army NETOPS policy and standard
changes and additions.
5-13. In any tactical scenario, there may be urgent situations where there is no time for an approval process
before policy guidance must be issued. The unit commander (advised by the S-6, G-6, and J-6) will make
this decision and take responsibility for any potential impact to the Army enterprise, both fixed and tactical.
Temporary Exceptions to NETOPS Policies and Standards in Echelons and Organizations
5-14. For the BCT and below, temporary exceptions to policies and standards are defined and maintained
by the BCT S-6 personnel. These short-term exceptions to policies and standards are based on BCT mission
requirements and refined from Army global policies and standards, as well as any other temporary mission-
specific policies and standards implemented by echelons within the BCTs chain of command. The BCT
provides policies and standards guidance to its AOR.
5-15. The corps and division G-6 personnel define and maintain temporary exceptions to policies and
standards in support of the corps and division. These exceptions to policies and standards are based on the
corps or division mission requirements and further refined from Army global policies and standards, as well
as any other temporary mission-specific policies and standards implemented by echelons within the corps or
division’s chain of command. The corps and division provide exceptions to policies and standard guidance
to its assigned AOR, including BCTs, ITSBs, ESBs and support brigades. The corps and division should
also consider how changes might affect lateral or supporting organizations and the modularity of
subordinate organizations.
5-16. The numbered Army NETOPS temporary exceptions to policies and standards are defined and
maintained by the numbered Army G-6 personnel. These exceptions to policies and standards are based on
the numbered Army’s mission requirements from Army global, and potentially joint, policies and standards
applicable within their theater. The numbered Army provides policies and standards guidance to its
assigned corps and division, directly reporting BCTs and other theater assets. The ASCC must consider how
any changes could affect NETOPS with other ASCC organizations and should be guided by policies and
direction from the A2TOC.
Temporary Exceptions to NETOPS Policies and Standards Joint Implications
5-17. The ARFOR NETOPS mission specific policies and standards are defined and maintained by
ARFOR G-6 personnel. These mission-specific policies and standards are based on ARFOR mission
requirements and further refined from Army global standards as well as any other temporary mission-
specific policies and standards implemented by echelons within the ARFORs chain of command. The
ARFOR provides mission-specific policies and standards guidance to its assigned corps and division,
BCTs, and other signal elements within its AOR. The ARFOR must carefully consider how policy changes
19 November 2008
FM 6-02.71
5-3
FOR OFFICIAL USE ONLY
Chapter 5
might affect lateral or supporting signal organizations and the modularity of subordinate corps, division, and
BCTs.
5-18. Joint organizations within an Army organization’s chain of command are expected to define and
maintain organizational and mission-specific NETOPS policies and standards. Joint organizational and
mission-specific policies and standards are created and approved through the joint operational environment
chain of command.
5-19. Army tactical organizations will incorporate joint and global Army tactical NETOPS policies and
standards just as they would if their parent headquarters was an Army organization. If Army and joint
NETOPS policies or standards conflict, the organizational S-6, G-6, and J-6 will notify their joint and Army
parent headquarters. The clarification of conflicting policies and standards is the responsibility of their
chain of command.
NETOPS MISSION PLANNING
5-20. NETOPS mission planning is the collection of current and future user requirements, requirements
validation and prioritization, mission alignment to the commander’s intent, the allocation of technical and
organizational resources, and the publication of operation orders. Major NETOPS mission planning is
normally performed during the first phase of the operation. Because of some system transmission delays
that are inherent in some SATCOM equipment, one example of mission planning is to allocate tropospheric
scatter capability to a user instead of a SATCOM. Smaller scale mission planning is performed in all phases
of operations as dictated by mission requirements.
Mission Planning Echelons and Organizations
5-21. All organizations in the tactical chain of command are involved in the NETOPS mission planning
process. As each echelon of the tactical chain of command performs mission planning, guidance is given to
subordinate echelons. This guidance is then used to create or refine NETOPS mission planning at the lower
echelon. Mission planning is a continual process that is performed by the organization’s S-6, G-6, and J-6
staff.
5-22. For the BCT and below, NETOPS mission planning is performed by the BCT S-6. The BCT provides
mission planning support to subordinate maneuver battalions.
5-23. The corps and division G-6 performs NETOPS mission planning in support of the corps and division.
The corps and division provide mission planning guidance to assigned BCTs and support brigades as well
as coordinating mission planning efforts between its subordinate BCTs and support brigades.
5-24. For the numbered Army, NETOPS mission planning is performed by the numbered Army G-6. The
numbered Army provides mission planning guidance to assigned corps and divisions, directly reporting
BCTs, and support brigades. The numbered Army also coordinates mission planning efforts between its
subordinate organizations. The numbered Army G-6 also coordinates with the signal command (theater)
(SC[T]) during this planning process.
5-25. During mission planning and especially during Phase One, coordination may be required between
theaters. The numbered Army will perform inter-theater coordination in support of deploying or re-
deploying organizations.
Mission Planning Joint Implications
5-26. Mission planning is performed by the joint and Army operational environment chain of command.
The joint chain of command will participate in the activities as described. Army tactical organizations will
incorporate joint mission planning guidance as they would should their parent headquarters be an Army
organization. If the Army and joint NETOPS mission planning guidance conflict, the organizational S-6, G-
6, and J-6 will notify their joint and Army parent headquarters. The clarification of conflicting guidance is
the responsibility of their chain of command.
5-4
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Activities
NETOPS CAPABILITY DESIGN
5-27. NETOPS capability employment configuration is usually performed in response to the receipt of
planning information in the form of OPORDs and annexes related to the accomplishment of a specific
mission. NETOPS capability employment configuration supports and provides feedback to the mission
planning activity described in this chapter. NETOPS employment configuration is defined to include—
z
Development of operational configurations to provide the required IT mission support capability.
Tactical NETOPS capability employment configuration includes development of configurations
for communications, networks, systems, and security capabilities in support of Soldier NETOPS.
z
Development of operational configurations required to facilitate the internetworking of
NETOPS-related applications, systems, networks, and communications infrastructure.
Capability Employment Configuration Echelons and Organizations
5-28. The tactical environment where NETOPS capability employment configuration is performed depends
on the echelon providing the NETOPS capability, the means by which the capability is provided, the
echelon to which the capability is being provided, and the NETOPS capability being employed. For
example, in electromagnetic spectrum operations, most echelons are required to identify what frequency
resources will be required and where they will be used within frequency management (sometimes referred
to as spectrum management), most echelons are required to identify what frequencies will be used and
where they will be used within their AOR. In other scenarios, electronic messaging may not require
capability employment configuration below the corps or division level.
5-29. All organizations in the tactical chain of command are involved in the NETOPS capability
employment configuration, either directly or in a coordinating or supporting role. As each echelon of the
tactical chain of command performs NETOPS capability employment configuration, information is
provided to subordinate echelons. The echelon that begins the employment configuration process for a
particular system is the highest echelon that must integrate the system across multiple subordinate units. The
employment configuration process then extends down to the echelon that maintains operational management
of the system in question (refer to operational control and management process for further details). This
information is then used to create or refine NETOPS capability employment configuration at the lower
echelon. NETOPS capability employment configuration is performed by the organization’s S-6, G-6, and J-
6 staff.
5-30. For the BCT and below, NETOPS capability employment configuration is performed by the BCT
S-6. The BCT provides capability employment configuration support to subordinate maneuver battalions.
5-31. For the corps and division, NETOPS capability employment configuration is performed by the corps
and division G-6. The corps and division provide capability employment configuration guidance to its
AOR, including assigned ITSBs/ESBs, BCTs, and support brigades. The corps and division coordinate
capability employment configuration efforts between their subordinate BCTs and support brigades. Corps
and division capability employment configuration is focused on facilitating the interoperability of the
NETOPS capabilities between echelons.
5-32. For the numbered Army, NETOPS capability employment configuration is performed by the
numbered Army G-6. The numbered Army provides capability design guidance to assigned corps, divisions,
and directly reporting BCTs. The numbered Army coordinates capability employment configuration efforts
between its subordinate organizations. The numbered Army G-6 also coordinates with the SC(T) in this
capability employment configuration process. The numbered Army’s capability employment configuration
is focused on facilitating the interoperability of the NETOPS capabilities between echelons.
5-33. During capability employment configuration, and especially during Phase One, coordination may be
required between theaters. The numbered Army will perform inter-theater coordination in support of
deploying or redeploying organizations.
19 November 2008
FM 6-02.71
5-5
FOR OFFICIAL USE ONLY
Chapter 5
Capability Employment Configuration Joint Implications
5-34. The ARFOR NETOPS capability employment configuration is performed by the ARFOR G-6. The
ARFOR provides capability employment configuration guidance to its AOR. This includes assigned corps,
division, ITSB/ESB, BCTs, and support brigades. The ARFOR also coordinates capability employment
configuration efforts between subordinate assets within its AOR. ARFOR capability employment
configuration is focused on facilitating the interoperability of the NETOPS capabilities between echelons
and provisioning services to meet mission requirements.
5-35. Tactical NETOPS capability employment configuration is performed by the joint and Army
operational environment chain of command. The joint chain of command will participate in the NETOPS
capability employment configuration in support of assigned Army organizations. Army tactical
organizations will incorporate joint capability employment configuration guidance as they would should
their parent headquarters be an Army organization. If the Army and joint NETOPS capability employment
configuration guidance conflict, the organizational S-6, G-6, and J-6 will notify their joint and Army parent
headquarters. The clarification of conflicting guidance is the responsibility of their chain of command.
TACTICAL OPERATIONS
5-36. Tactical operations are the NETOPS activities that frame the management, support, execution, and
evaluation processes required to provide a stable NETOPS infrastructure to support the tactical LWN.
These activity categories represent the best practices of NETOPS capability providers (both Army and
industry). They also provide a general means of categorizing NETOPS capabilities that are not specific to
any technology or organizational structure. The following paragraphs discuss these NETOPS activities.
NETOPS REPORTING
5-37. The corps, division, and numbered Army level organizations are required to provide day-to-day SA
of Army network and system reports in their AOR to the senior tactical commander and the TNOSC.
NETOPS reporting identifies critical network outages, availability, integrity, and confidentiality of the
LWN.
5-38. The A-GNOSC will publish Army NETOPS reporting requirement in an OPORD. Army NETOPS
OPORD 05-01, dated 20 April 2005, delineates NETOPS reporting threshold guidelines for post, camp, and
station service providers (tactical and strategic); TNOSCs; and the A-GNOSC. The thresholds identified are
considered baseline criteria only; service providers or unit commanders may modify the baseline to allow
for more stringent reporting criteria as deemed necessary.
Reporting Joint Implications
5-39. When the numbered Army is not acting as the joint operational area ARFOR, the ARFOR has a dual
NETOPS reporting requirement to its joint command and to its local numbered Army. NETOPS reporting
responsibilities to a joint command are determined by the joint community (reference JP 6-0). NETOPS
reporting responsibilities between the ARFOR and the numbered Army should be performed according to
the guidelines listed above.
NETOPS SHARED SA PICTURE
5-40. The requirement for NETOPS shared SA was established in the August 2000 Deputy Secretary of
Defense-DOD CIO Guidance and Policy Memorandum No. 10-8460 Network Operations, which mandated
a network common operating picture (NETOPS shared SA). Detailed descriptions of the execution of this
requirement are found in the current joint NETOPS concept of operations (CONOPS), which directs a
shared, single integrated network SA view for the GIG and, specifically, for the Army. The Army NETOPS
CONOPS further directs a NETOPS shared SA that will display relevant NETOPS information to Army
commanders to assist in identifying
―...outages and degradations, network attacks, mission impacts,
communications system shortfalls, operational requirements, and problem resolutions at the strategic,
5-6
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Activities
operational, and tactical levels.‖ This integrated, near-real-time picture tracks critical systems and
designated high priority applications via views that are relevant to the specific information consumer (e.g.,
A-GNOSC, CCDR, numbered Army, TNOSC, corps, and division).
5-41. The NETOPS shared SA activity involves the collection of data from various LWN sources. These
sources provide OPORD 05-01 defined reportable situations (outages, hazardous conditions information
records, aggregated near real-time network event data from multiple network management toolsets, and data
from other NETOPS shared SA systems). The collected data is then transformed into relevant information
for a specific consumer or set of consumers and published as a view. Each consumer requesting a NETOPS
shared SA view has the ability to customize the presented information to make it relevant to their situational
requirements. In this manner it is envisioned that this common source of theater NETOPS shared SA
information will allow any user on the network to pull only what is needed at the time. Figure 5-1 provides a
high-level overview of the current NETOPS shared SA architecture developed and shared by the
AGNOSC/TNOSC.
TNC
A-GNOSC
Army
NETOPS Shared
SA
Theater
NETOPS Shared
JTF-GNO
SA
Infostructure
Regional
Infostructure
NETOPS Shared
Monitoring
Performance Data
SA
TNOSC
RCIO
Installation
Oerational Environment
NETOPS Shared
NETOPS Shared
SA
SA
Installation
Operational Environment
Figure 5-1. NETOPS shared SA system overview
Shared SA Echelons and Organizations
5-42. The BCT is responsible for ensuring the relevant systems within its AOR are equipped and
configured to report OPORD 05-01 required NETOPS shared SA data to the TNOSC. A BCT may be a
consumer of NETOPS shared SA information, but the NETOPS shared SA view would be provided by the
TNOSC.
5-43. The corps and division is responsible for ensuring the relevant systems within its AOR are equipped
and configured to report OPORD 05-01 required NETOPS shared SA data to the TNOSC. A corps and
division may be a consumer of NETOPS shared SA information, but the NETOPS shared SA view would
be provided by the TNOSC. The larger a corps or division’s AOR, the more likely it would be a NETOPS
shared SA consumer.
19 November 2008
FM 6-02.71
5-7
FOR OFFICIAL USE ONLY
Chapter 5
5-44. The numbered Army is responsible for ensuring the relevant systems within its AOR are equipped
and configured to report OPORD 05-01 required NETOPS shared SA data to the TNOSC. The TNOSC
will aggregate the data for the entire theater AOR and transform the data into presentable NETOPS shared
SA information. The TNOSC then publishes a NETOPS shared SA view for consumer organizations. The
TNOSC also reports aggregated NETOPS shared SA data for the theater to the A-GNOSC.
5-45. It is within the TNOSC’s purview to provide a NETOPS shared SA to any eligible consumer that
makes the request. In this respect, the TNOSC is the sole provider of the theater NETOPS shared SA.
NETOPS shared SA support for the theater will come from the TNOSC due to the centralization of
NETOPS shared SA activities at the TNOSC.
Shared SA Joint Implications
5-46. Upon request, the TNOSC will provide a NETOPS shared SA picture to ARFOR NOSCs, joint force
land component commanders (JFLCCs), JTFs, JNCCs, theater NETOPS centers, and TNCCs. It is
important to note that the deployed joint and Army communities will have different focuses and be
interested in tracking different information. For example, while the Army is interested in the overall health
of its NETOPS capabilities, the joint community will be focused on the warfighting situation. NETOPS
shared SA will be essential to the JTF’s ability to quickly assess and react to capability degradations that
potentially impact its warfighting ability.
NETOPS CHANGE MANAGEMENT
5-47. The goal of change management is to ensure that standardized methods and procedures are used for
efficient and prompt handling of all modifications. This will help facilitate necessary changes and minimize
the negative impacts of change-related events. The process encompasses the identification, documentation,
approval, and implementation of variances from configuration baselines requirements.
5-48. Change management activities concerning user systems and NETOPS capabilities are generally
performed by the unit’s S-6, G-6, and J-6. Some of the activities concerning the network and basic network
capabilities are provided by the supporting signal unit such as the division, brigade, and BCT signal
company, the TLTs (BCT, corps, and division), or the ITSB ESB and TNT (numbered Army, ARFOR, and
above).
5-49. The change management process is initiated by a request for change. A request for change may
originate from any organization within the tactical chain of command, as well as the A-GNOSC or
numbered Army. Requests for changes may be initiated as a resolution to an incident or problem, to request
temporary exceptions to policies, or to support other emerging mission requirements.
5-50. Once a request for change is submitted, it enters the change processing state and is sent up through
the tactical chain of command until it reaches the appropriate echelon to approve the change. As the change
request is forwarded, it must pass through each intermediate echelon of tactical command. This ensures that
the chain of command is aware of all requests and that approved changes are implemented in an orderly
manner. At each echelon, the change must be examined by plans and engineering personnel. The reviewing
stage is necessary to ensure that the change is feasible, justified, and does not violate network, system, or
security policy guidance.
5-51. Change approval authority is based upon operational management responsibilities as defined in the
NETOPS Operational Control and Management section later in this chapter. If an echelon has operational
management of a particular system, it also has the authority to approve changes to that system, as long as
these changes do not violate policy or guidance. If the request for change violates current policies or
guidance, the change request must be processed as a temporary exception to policy (refer to the Temporary
Exceptions to NETOPS Policies and Standards Section earlier in this chapter).
5-52. The unit commander will generally delegate the authority to approve or deny network change
requests to the S-6, G-6, and J-6 command staff. This authority may be institutionalized or delegated to
5-8
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Activities
technical network personnel within the unit. Qualified personnel include members of a signal company,
ITSB/ESB, or supporting TLT.
5-53. After the echelon with the necessary authority has approved the change, the validated change request
will pass to the echelon(s) with change implementation responsibility for the system(s) affected. This
echelon will then coordinate the change with all necessary organizations before execution. An organization
requires prior change coordination if the change may result in failure or the compromise of services within
the organization’s AOR.
5-54. Changes may also be initiated by high level echelons such as the CCDR or A2TOC. For example, a
system may urgently require a patch based upon a newly identified vulnerability. Change requests
originating at the CCDR are not required to go through the change approval process, but coordination with
the ARFOR and affected tactical units is necessary to determine when and how the change should be
implemented. Change requests originating from the A2TOC must be passed via the numbered Army to the
ARFOR for approval. If the ARFOR determines that a change originating from the CCDR or A2TOC will
have an unacceptable risk of disrupting user services, it can request to delay or defer the change through its
chain of command.
5-55. Change implementation should always be performed by the echelon with operational management of
the system in question. The NETOPS Operational Change and Management section in this chapter contains
a general definition and delineation of operational management. In the tactical networking environment,
situations will commonly arise that require immediate action to be taken. In these emergency situations,
personnel may need to perform change implementation activities that are outside of their normal scope of
responsibility.
5-56. Changes made to user systems, NETOPS capabilities, and network capabilities often involve
configuration changes. These changes include updates to software, modifications to configuration
parameters, and the replacement of hardware. Changes that are made within the network are recorded as
they occur in an automated CM system. This system will provide notification to the appropriate
organizations regarding any configuration modifications resulting from change requests. All units, BCT and
above within the tactical network chain of command will have access to this system. Army organizations
such as the numbered Army and A-GNOSC will also receive notification of configuration changes in order
to maintain Army-based awareness across the enterprise.
Note. Change and CM are integrated activities. Specifically, changes to a configuration must be
recorded through the CM activity. Appendix C contains scenarios that serve as examples of how
change and CM occur.
Change Management Echelons and Organizations
5-57. NETOPS change management operations for assets within the BCT AOR are performed by the BCT
S-6, supported by the BCT signal company, and assigned or attached signal personnel. At the BCT and
below, each change request is approved, denied, or escalated to the next higher headquarters for further
processing. The BCT performs change implementation on all systems for which it has operational
management responsibility as defined in the Operational Control and Management Section of this chapter.
5-58. NETOPS change management operations for assets within the corps and division AOR are performed
by the corps and division G-6, supported by the corps and division signal company, supporting TLT, and
assigned or attached signal personnel. Each change request is approved, denied, or escalated to the next
higher headquarters for further processing. The corps and division perform change implementation on all
systems for which it has operational management responsibility as defined in the Operational Control and
Management section of this chapter.
5-59. The ITSB/ESB performs designated change management functions in support of the echelon to which
it is currently assigned. It will process and initiate change requests regarding the active NETOPS
19 November 2008
FM 6-02.71
5-9
FOR OFFICIAL USE ONLY
Chapter 5
capabilities it provides. The ITSB/ESB may also be delegated the authority to approve certain change
requests from the supported S-6, G-6, or J-6.
5-60. The numbered Army and A-GNOSC perform all change management functions listed above for the
support Services which are provided to the tactical forces via the TNOSC and A-GNOSC. The numbered
Army or A-GNOSC receives and approves change requests regarding Army supporting services through the
chain of command. The implementation of this change must be coordinated through all affected
organizations as defined in the change implementation process. For example, a BCT under the OPCON of a
corps or division may directly request a change to TNOSC support services through its corps or division.
Change Management Joint Implications
5-61. Joint guidance governs change management operations within joint organizations or between Army
and joint organizations. Army personnel supporting these functions will operate within joint guidance while
also utilizing Army change management procedures.
5-62. NETOPS change management operations for assets within the ARFOR AOR are performed by the
ARFOR G-6, supporting ITSB/ESBs, and assigned or attached signal personnel. At the ARFOR, each
change request is approved, denied, or escalated to the next higher headquarters J-6 for further processing.
The JFLCC and commander, joint task force (CJTF) perform change approval activities for all joint-
managed systems that require approval above the corps and division level. The ARFOR performs change
implementation on all systems for which it has operational management responsibility as defined in the
Operational Control and Management section of this chapter. The ARFOR, JFLCC, and CJTF will also be
fully involved in the change notification process for all assets within their respective AORs.
NETOPS CONFIGURATION MANAGEMENT
5-63. NETOPS CM supports the identification, control, maintenance, and verification of systems and
devices associated with the provisioning of NETOPS capabilities. Configuration item (CI) information
includes hardware, software, device configurations, and version information. Activities associated with CM
include:
z
Identification of all CIs.
z
Control of CIs.
z
Maintenance of current and past CI status.
z
Verification of CI status.
5-64. Policy dictates what qualifies as a CI and what information regarding each CI must be collected and
stored. Policy also dictates how often CI information must be updated based upon mission factors including
operational tempo and bandwidth constraints.
5-65. CM concerning user systems and capabilities are primarily performed by the unit’s S-6, G-6, and J-6
staff. CM activities concerning the network and basic network capabilities are delegated to a supporting
signal unit such as the signal company or the ITSB/ESB.
Configuration Management Echelons and Organizations
5-66. It is the responsibility of each echelon to ensure that all subordinate assets within its AOR perform
the necessary CM activities. Each echelon in the tactical chain of command will ensure that CIs within
subordinate echelons are accurately reflected within the CI database. To facilitate this process, read-only
access of all network resources will be shared between designated network management personnel within
each echelon.
5-67. An authoritative theater Army CI database (in support of the global Army CI database) will be
maintained in a distributed fashion by the numbered Army TNOSCs.
5-68. For the BCT and below, CM operations are performed by the S-6 personnel, the signal company,
supporting ITSB/ESBs, and supporting signal organizations. During the operational phases, all personnel
5-10
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Activities
supporting NETOPS functions are required to ensure that CIs under their operational management are
accurately identified and maintained within the CI database. When the BCT is task organized under a
particular corps, division, or ARFOR, the BCT CI information is made available to the joint operational
area chain of command and the gaining numbered Army. The BCT and below is also responsible for
ensuring that all changes to systems under the operational control and management of the BCT are
accurately reflected within the CI database.
5-69. Within the corps and division, CM operations will be performed by G-6 personnel, the signal
company, supporting ITSB/ESBs, the TIC, and supporting signal organizations. During the operational
phases, all personnel supporting NETOPS functions are required to ensure that CIs under their operational
management are accurately identified and maintained within the CI database. This information can then be
made available to the joint operations area ARFOR and the numbered Army as the corps or division
deploys. The corps, division, and subordinate units are also responsible for ensuring that all changes to
systems under their operational control and management are accurately reflected within the CI database.
5-70. Tactical CM operations are also performed by the ITSB/ESB on behalf of the supported tactical
organizations. ITSB/ESBs will ensure that CIs under their operational management and those of their
supported organization are identified and maintained accurately within the CI database throughout all
operational phases. This information can then be passed from the owning numbered Army to various
tactical echelons as the ITSB/ESB is task reorganized.
5-71. For the numbered Army’s tactical support services, CM operations will be performed by the SC(T)
and TNOSC. All personnel supporting NETOPS functions are required to ensure that CIs under their
control are identified and maintained accurately within the CI database throughout all operational phases.
The numbered Army is also responsible for ensuring that all changes to systems under the operational
control and management of the numbered Army are accurately reflected within the CI database.
5-72. It is important to remember that one echelon may be responsible for a physical CI but not the CI’s
device configuration. For example, the BCT is responsible for ensuring that all its routers are entered or
removed from the CI database. The BCT’s higher headquarters, as the echelon with operational
management of the BCT routers, is responsible for maintaining the status of router configurations within the
CI database.
Configuration Management Joint Implications
5-73. The ARFOR, JFLCC, and CJTF CM operations are governed by joint guidance. Army personnel
supporting these organizations will operate within this guidance while also utilizing Army CM procedures
to the fullest possible extent. Army assets within these organizations will utilize the Army-provided CI
database unless otherwise directed. Joint organizations will have the ability to view information from this
database as required.
5-74. CM functions within the ARFOR, JFLCC, and CJTF are anticipated to be performed by the G-6, J-6,
TNT, the supporting ITSB/ESB, and supporting signal organization. During the operational phases, all
personnel supporting Army-based NETOPS functions should ensure that CIs under their operational
management are accurately identified and maintained within the CI database. The ARFOR is also
responsible for ensuring that all NETOPS changes to systems under the operational management of the
ARFOR or subordinate Army elements are accurately reflected within the CI database.
NETOPS INCIDENT AND PROBLEM MANAGEMENT
5-75. The incident and problem management process involves the processing and resolution of any event
that is not part of the standard operation of a NETOPS capability, and that causes or may cause an
interruption to or a reduction in the quality of that capability.
5-76. The goal of the incident and problem management process is to restore normal operation of the
capability as quickly as possible, and minimize the adverse impact on tactical operations, therefore ensuring
that the best possible levels of capability quality, availability, and security are maintained.
19 November 2008
FM 6-02.71
5-11
FOR OFFICIAL USE ONLY
Chapter 5
5-77. Management of network related incidents and problems concerning user systems and capabilities are
the responsibility of the unit S-6, G-6, and J-6 staff. Incidents and problems concerning the network and
basic network capabilities may be delegated to a supporting signal unit such as the signal company, TLT
(BCT, corps, and division), or the ITSB/ESB and TNT (numbered Army or ARFOR).
Note. Appendix C outlines a scenario that serves as an example of how the incident and problem
management activity might occur.
Incident and Problem Management Echelons and Organizations
5-78. For the BCT and below, incident and problem management operations are performed by the S-6,
signal company, supporting ITSB/ESBs, and supporting signal organization. When an incident is identified
within the BCT, it is first analyzed within the BCT to identify if an immediate resolution can be found. In
the echelons BCT and below, the ability to locally analyze incidents is very limited. If a solution cannot be
locally identified, the problem escalates to the next higher headquarters.
5-79. Within the corps and division, incident and problem management operations are performed by the G-
6, signal company, supporting ITSB/ESB, TLT, and supporting signal organization. When an incident is
identified within or escalates to the corps or division from a subordinate organization, it is first analyzed
within the corps or division to identify if an immediate resolution can be found. If a solution cannot be
locally identified, the problem escalates to the next higher headquarters within the tactical chain of
command.
5-80. The ITSB/ESB personnel perform incident and problem functions for network capabilities and
infrastructure provided by the ITSB/ESB. When an incident or problem is identified, it is first analyzed by
ITSB/ESB NETOPS personnel to identify if an immediate resolution can be found. If a solution cannot be
locally identified, the problem escalates to the supporting tactical echelon.
5-81. The numbered Army performs incident and problem management activities for all NETOPS
capabilities provided by the numbered Army. If a tactical incident or problem cannot be resolved through
local numbered Army resources, the numbered Army may escalate the problem to the A-GNOSC, material
developer, or vendor subject matter experts.
5-82. The ultimate responsibility for tactical incident and problem management resides within the
operational chain of command. Army organizations such as the TNOSC and the A-GNOSC play an
important supporting role in this process. The deployment support division, within the TNOSC, supports
tactical troubleshooting functions by leveraging a database of problems, incidents, and fixed-station subject
matter experts. Tactical Army organizations may request support from the TNOSC or A-GNOSC through
the chain of command.
Incident and Problem Management Joint Implications
5-83. Within the ARFOR, incident and problem management operations will be performed by the G-6,
supporting ITSB/ESB, TNT, and supporting signal organization. When an incident is identified within or
escalates to the ARFOR via a subordinate organization, it is first analyzed to identify if an immediate
resolution can be found. The ARFOR will normally be supplemented by a numbered Army TNT in order to
augment its ability to analyze incidents and problems. If a solution cannot be locally identified, the problem
then escalates to the numbered Army TNOSC or the joint NETOPS cell within the JFLCC or CJTF.
5-84. The ARFOR will generally request assistance from the numbered Army’s TNOSC to resolve
problems related to Army-specific systems and procedures. Problems related to systems and procedures
directly managed by the operational environment joint command will generally escalate to the joint NOSC.
These problems can also be referred to the TNOSC at the discretion of the ARFOR. Regardless of
escalation sequence, both the TNOSC and the combat chain of command will be notified of all incidents
and problems as they occur.
5-12
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Activities
5-85. The ARFOR, JFLCC, and CJTF incident and problem management operations are governed by joint
guidance. Army personnel supporting these organizations will operate within this guidance while also
participating in Army incident and problem management procedures to the fullest extent.
NETOPS RELEASE MANAGEMENT
5-86. Release management deals with the planning, design, construction, configuration, and testing of
hardware and software to create a set of release components for a live environment. Release management
activities also cover the planning, preparation, and scheduling of a release to various subscribers and
locations.
5-87. The initiation, planning, and testing of releases are primarily performed in the fixed-station, non-
tactical environment. It is critical that release building and testing are performed with the tactical
environment in mind. This section provides details regarding those activities which are specific to the
tactical echelons: release rollout planning, installation, and training.
5-88. The activities associated with release rollout planning are executed according to the change
management and planning processes. When a release is issued, it is initiated as a change request. This
request is then coordinated and planned through the tactical chain of command and all affected
organizations.
5-89. The activities associated with release installation are executed according to change management
guidelines. The echelon responsible for change management of the effected system(s) will execute the
release.
NETOPS SERVICE DESK MANAGEMENT
5-90. Tactical service desk management encompasses all activities involved with tracking NETOPS
activities, gathering NETOPS status or performance information, and interfacing with the tactical
subscriber. This includes incident and problem processing, change request processing, availability
management, user interaction, and collection of user satisfaction data. These activities are often associated
with a user help desk.
5-91. Service desk management functions concerning user systems and NETOPS capabilities are the
responsibility of the unit’s S-6, G-6, and J-6 staff and functional areas. Service desk management functions
are assigned, as necessary, by the S-6, G-6, and J-6 to a supporting signal unit such as the signal company
or the ITSB/ESB.
Service Desk Management Echelons and Organizations
5-92. At the BCT and below, service desk management functions are performed in support of local
subscribers. The service desk management information is collected, analyzed, and made available to the
G-6 or J-6 within the next higher echelon.
5-93. Within the corps and division, service desk management functions are performed in support of local
subscribers. The service desk management information is collected, analyzed, and made available to the
G-6 or J-6 of the next higher commanding echelon.
5-94. Personnel performing service desk management functions within the corps, division, and below are
likely to be network design, engineering, or incident management personnel with additional service desk
management duties. In the upper echelons such as the ARFOR, numbered Army, and joint commands,
service desk management functions will often be performed by dedicated personnel from a service
management desk or help desk.
5-95. The ITSB/ESB will perform service desk management functions for the NETOPS infrastructure and
all related capabilities provided by the ITSB/ESB. This information will be made available to the supported
echelon and the local numbered Army.
19 November 2008
FM 6-02.71
5-13
FOR OFFICIAL USE ONLY
Chapter 5
5-96. The numbered Army will perform service desk management functions for all tactical support services
provided by the SC(T) or TNOSC. This information will be made available to tactical Army units and the
JTF.
Service Desk Management Joint Implications
5-97. Within the ARFOR, service desk management operations will be performed by the G-6, supporting
ITSB/ESB, TNOSC TNT, and supporting signal organizations.
5-98. The JFLCC and CJTF service desk management operations are governed by joint guidance. Army
personnel supporting these organizations will operate within this guidance while also performing Army
service desk management procedures.
NETOPS INFRASTRUCTURE MONITORING/MANAGEMENT
5-99. NETOPS infrastructure monitoring is the monitoring of all IT components that are providing
NETOPS-related capabilities to the Soldier. Monitoring is focused on the health of NETOPS capabilities.
Some of these components include radios, multiplexers, cryptographic devices, routers, switches, firewalls,
IDSs, enabling protocols, capability providing hosts, and critical applications.
5-100. NETOPS infrastructure monitoring is performed continuously throughout all phases of operations.
It supports and enables other NETOPS operational activities such as NETOPS shared SA, service desk
management, and incident and problem management.
5-101. Due to the complex nature of the Army’s modular infrastructure, which consists of multiple Army
NETOPS provisioning organizations, the monitoring of Army infrastructure components will be distributed
among those organizations. Critical information collected by distributed NETOPS monitoring systems will
be forwarded to a higher level NETOPS monitoring system. The concept of distributed monitoring is
facilitated through the establishment of distinct monitoring domains, which are purposely aligned with the
Army theaters’ NETOPS provisioning organizations. The ARFOR, numbered Army, corps, division, BCT,
and battalion organizations monitor their own domain as established in the NETOPS mission plan.
5-102. Each organization’s monitoring domain consists of both the IT components within their AOR and
the distant end of the WAN links to directly higher and directly subordinate organizations. For example, a
corps or division monitoring domain would consist of all the IT components within its AOR as well as the
distant ends of WAN links to the ARFOR (higher organization), adjacent units, ITSB/ESBs, and its BCTs
(subordinate organization). In most situations, there will be line of sight and other WAN connections within
an organization’s monitoring domain that provide connectivity to distant entities of that organization. In this
situation, all the IT components on the distant end of a particular WAN link are still under the monitoring
responsibility of that organization.
5-103. In a dynamic combat scenario, there may be ad hoc Army, joint, coalition, or civilian assets
attached to a BCT, corps, division, or ARFOR AOR. When this occurs, monitoring functions for these
attached assets are the responsibility of the supported command. If the attached asset has the capability to
perform independent monitoring activities, such as an ITSB/ESB or Marine expeditionary force, this asset
would simply forward the monitoring data to the supported command. If not, the supported command would
assume active, real-time monitoring of the attached asset.
5-104. Tactical units also require limited visibility of adjacent and higher networks for SA and
troubleshooting purposes. A high-level view of the network as a whole can be obtained via remote network
views provided by higher headquarters. For example, if a BCT needs to identify why communications to a
remote ITSB/ESB are not functioning, it could access the Web view of the theater AOR which is available
as a service via the TIC of the numbered Army’s supporting TNOSC. Figure 5-2 illustrates the concept of
distributed monitoring and the flow of the monitoring information.
5-14
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Activities
Infrastructure Monitoring/Management Echelons and Organizations
5-105. For the BCT and battalion, infrastructure monitoring activities are performed by the S-6, signal
company, supporting ITSB/ESBs, and other supporting signal organizations. These organizations will use
their NETOPS monitoring system to monitor, manage, and troubleshoot the network infrastructure within
their AOR. The battalion will provide all monitoring information from its AOR to the BCT. This
information will consist of network topology, as well as event and alarm data. This provides the BCT with a
read-only view of the battalion’s infrastructure that will facilitate troubleshooting and analysis activities.
Figure 5-2. Distributed infrastructure monitoring example
5-106. The BCT will provide all monitoring information from its AOR and its subordinate battalion's
AORs to the corps and division’s NETOPS monitoring system. This information will consist of network
topology and event and alarm data. This will provide the corps and division with a read-only view of the
BCT’s and battalion’s infrastructure. The information received will facilitate troubleshooting and analysis
activities.
19 November 2008
FM 6-02.71
5-15
FOR OFFICIAL USE ONLY
Chapter 5
5-107. Within the corps and division, infrastructure monitoring is performed by the G-6, signal company,
supporting ITSB/ESB, TLT, and supporting signal organizations. The corps and division will use their
NETOPS monitoring system to monitor, manage, and troubleshoot the network infrastructure within their
AOR. The corps and division will provide all monitoring information from their AOR and subordinate
BCT’s, and battalion’s AORs to the ARFOR NETOPS monitoring system. This information will consist of
network topology and event and alarm data that will provide the ARFOR with a read-only view of the
corps’, division’s, BCT’s, and battalion’s infrastructure, thereby facilitating troubleshooting and analysis
activities. The corps and division is also responsible for making consolidated AOR monitoring information
accessible to subordinate assets for SA and troubleshooting purposes.
5-108. The numbered Army will use its NETOPS monitoring system to monitor, manage, and troubleshoot
the network infrastructure within its AOR. In addition to supporting these activities, the numbered Army’s
NETOPS monitoring system will be used to assist in the troubleshooting activities within the combat AOR,
as required (see below for incident and problem management). The numbered Army is also responsible for
making consolidated Army theater monitoring information accessible to the CCDR, A-GNOSC, and tactical
Army assets within the theater for SA and troubleshooting purposes.
Infrastructure Monitoring/Management Joint Implications
5-109. The ARFOR is responsible for the management of the NETOPS capabilities and infrastructure
within its AOR. Within the ARFOR, infrastructure monitoring and management activities will be performed
by the G-6, supporting ITSB/ESB, TNT, and supporting signal organizations. The ARFOR conducts this
mission through the monitoring and management activities conducted by subordinate ITSB/ESBs, corps,
divisions, BCTs, and any other monitoring domains within the Army combat AOR. The ARFOR will
provide all monitoring and management information from the Army combat AOR to the numbered Army’s
NETOPS monitoring system, which will consist of network topology and event and alarm data from its
subordinate organizations. The ARFOR is also responsible for making consolidated AOR monitoring and
management information accessible to subordinate assets for SA and troubleshooting purposes. For more
information regarding troubleshooting and trouble ticketing, see Appendix C.
5-110. According to joint guidance, the CJTF and JFLCC will direct NETOPS monitoring and
management within their respective AORs. Army assets supporting joint commands will perform
monitoring and management functions according to the processes listed above, unless these processes
conflict with joint guidance. Any conflict between joint guidance and army requirements will be adjudicated
by the Army G-6.
NETOPS OPERATIONAL CONTROL AND MANAGEMENT
5-111. There are two distinct and complementary NETOPS activities discussed in this section: operational
control and operational management. Operational control of a NETOPS system, capability, or component
involves the day-to-day activities involved in keeping the system, capability, or component running. Some
of these activities include providing power, environmental controls, cleaning, preventative maintenance,
installation, deinstallation, physical inventory, and touch labor. Operational management activities include
configuration, reconfiguration, monitoring, patching, and upgrading. Some of the devices include
computing platforms, routers, switches, multiplexers, uninterruptible power sources, encryption devices,
and IDSs.
5-112. Operational control and management responsibilities are determined by global policy and the
network topology. Even though the transmission system is relatively flat, the interconnection of IP networks
is organized in a hierarchy. The demarcation points between the tiers (refer to Appendix I for tier detailed
information) of the hierarchy in conjunction with tactical unit boundaries are natural borders for OPCON
and management. Operational control of NETOPS capabilities, systems, and components is the
responsibility of the unit that has physical control of the item. Operational management of NETOPS
capabilities, systems, and components falls into the following three categories:
z
Unit managed component systems. The operational management of a component or system, not
capable of being remotely managed, falls to the echelon that physically controls the component
5-16
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Activities
or system. One example of such a system is the squad level radio. Although all components and
systems require a certain amount of touch labor, many components or systems may be under the
operational management of a remote echelon. A limited set of touch labor functions such as
installation, disaster recovery, troubleshooting, and deinstallation may be performed by local
personnel under the direction of an echelon with remote operational management responsibility.
z
Echelons above corps and division capabilities. Some systems are managed and operated as a
capability by echelons above the corps or division. These systems may be more efficiently
provisioned from a higher echelon, or may require centralized management. These systems are
designed and implemented to provide flexible capabilities and do not require frequent
reconfiguration in response to tactical mission requirements. Some examples of echelons above
corps capabilities include the Army DNS system and the joint router network. Operational
management of these systems resides at the echelon which provides the supporting capability.
z
Echelon above brigade managed systems. The remaining NETOPS capabilities, systems, or
components are both remotely manageable and require a distributed management structure to
ensure that configurations are dynamically aligned with command requirements. Operational
management of these systems within the corps or division and below falls to the tactical echelon
directly above the brigade. In most cases, this will be a division. In some scenarios, the echelon
above brigade may be a corps, numbered Army, ARFOR, or a joint command. The corps and
division are augmented by the TIC to perform these functions. The ARFOR or joint command is
augmented by a TNT to perform the same functions. Operational management of these types of
systems within the echelons above corps generally falls to the supported echelons above corps
command. For example, all remotely manageable systems within an ITSB/ESB-supported
ARFOR TOC, as well as the ITSB/ESB itself, fall under the operational management of the
ARFOR command. The only exception to this rule is when the SB(T) itself is operationally
controlled to echelons above corps command in order to provide an additional span of control for
echelons above corps networks. When this occurs, the signal brigade
(theater) assumes
operational management of the supported command’s ITSB/ESB systems. Some examples of
echelon above brigade managed systems could be called managers, VOIP gateways, private
branch exchanges, routers, firewalls, collaboration tools, and unit directory services.
Note. Any echelon with operational management may delegate this responsibility to subordinate
echelons or organizations as needed.
Operational Control and Management Echelons and Organizations
5-113. Operational control and management are executed at all echelons. The component types in the
NETOPS infrastructure are the same regardless of whether they are located in a numbered Army, corps,
division, BCT, or battalion. These include, but are not limited to, routers, data switches, voice switches,
private branch exchanges, multiplexers, satellite terminals, line of sight transmission equipment, and
computing platforms. Location and ownership of a NETOPS capability, system, or component will often
affect which echelon or organization has operational control. For example, a unit-managed radio within the
corps or division signal company is operated and managed by the corps or division, whereas the same type
of radio within a brigade signal company is managed by the brigade.
5-114. The numbered Army is responsible for the operation and management of capabilities, systems, and
components for its entire AOR. The TNOSC OPCON to the numbered Army executes OPCON and
management in support of the G-6 and SC(T). In addition to managing and operating capabilities, systems,
and components to conduct business on its portion of the NETOPS infrastructure, it has the responsibility to
operate and manage support services for the tactical AOR. Some of these capabilities include Army DNS,
IDSs, and Tier-1 routing domains. See Appendix I paragraph I-41 for an explanation of Tier 0, Tier 1, and
Tier 2.
5-115. The deployment of an IDS to an organization is a good example to illustrate the operation and
management responsibilities of several devices within multiple organizations. For this example, assume that
19 November 2008
FM 6-02.71
5-17
FOR OFFICIAL USE ONLY
Chapter 5
a pre-configured IDS is shipped to an organization. The receiving organization installs the IDS and
connects it to the IP network (operational activity). A precoordinated IP address was configured on the IDS,
which is immediately active on the LAN. Some of the activities that the local organization may have to
perform to provide end-to-end connectivity is to create a reservation in their Dynamic Host Configuration
Protocol (DHCP) server (manage DHCP activity) and reconfigure the local firewall(s) to permit the
protocols and IP address of the IDS (manage firewall activity). The TNOSC will have to reconfigure their
firewall(s) and reconfigure their IDS management station to complete the deployment. There are a number
of operational and management activities on several devices in the respective organizations to successfully
deploy the IDS capability. The receiving organization could be a corps, division, brigade, BCT, or a
battalion.
Operational Control and Management Joint Implications
5-116. The ARFOR delegates responsibility for the operation and management of capabilities, systems, or
components within its AOR to the corps, division, and directly reporting BCTs as appropriate.
5-117. The numbered Army will perform OPCON and management of Army Service components
operationally controlled to the JTF in support of the joint mission. The TNOSC OPCON to the numbered
Army executes OPCON and management in support of the G-6 and SC(T). The CJTF and JFLCC will
orchestrate and coordinate the operation and management of NETOPS capabilities, systems, and
components.
NETOPS NETWORK DEFENSE MANAGEMENT
5-118. The management of security is integral to and included in each of the NETOPS activities described
in this chapter. This section is focused on security-specific activities that support the other NETOPS
activities described throughout the chapter.
5-119. NETOPS security management includes the defensive components of IO that serve to protect and
defend information and information systems by ensuring their availability, integrity, authentication,
confidentiality, and non-repudiation. The provisioning of many IA capabilities is implemented as Army
enterprise capabilities. For example, Microsoft Windows AD is expected to provide enterprise-wide
identification and authentication for Windows platforms.
5-120. Fundamental to the provisioning of the defensive components of NETOPS is the concept of DID.
DID identifies three network-accessible areas that require defensive measures:
z
Perimeter defense includes protections for both public and extranet access. Extranet access
includes those ports and protocols that are external to and specifically identified by the tactical
unit. Extranet A private network that uses IPs and the public telecommunications system to
securely share information among selected external users. An Extranet requires the use of
firewalls, authentication, encryption, and VPNs that tunnel through the public network (see AR
25-2).
z
Enclaves are usually contiguous networks that support a specific geographical location,
organization, or unit.
z
Hosts are the final layer of defense. Protection at this layer consists of host-based configuration
parameters and host-based intrusion detection and prevention software.
5-121. To support these defensive components, security information management tools are employed to
support security event collection, data reduction, and correlation.
Security Management Echelons and Organizations
5-122. NETOPS security management is centralized to the greatest extent possible. Centralization ensures
consistency and minimizes the number of personnel with the highly specialized skills needed to perform
NETOPS security analysis. For NETOPS security management to be effective, it must be performed in near
real time. This includes the ability for near real-time 24 hours a day, seven days a week operational control
5-18
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Activities
and management of NETOPS security components and sensors. Security information management tools
may be employed by the TNOSC in support of tactical organizations to efficiently aggregate and analyze
NETOPS security event information.
5-123. Centralized management of NETOPS security perimeter protection components and sensors is
performed by the TNOSCs within each theater. The operational tempo may require support from the
TNOSC deployment support division to ensure that the commander’s needs are met with respect to
NETOPS security for deployed forces.
5-124. The TNOSC also manages NETOPS security enclave protection components and sensors. At the
discretion of the chain of command, this responsibility may be delegated to the corps, division, or BCT
level organizations. Enclave protection will also be performed at the corps, division, or BCT level if
connectivity to the TNOSC is interrupted.
5-125. Local commanders at all levels have responsibility for host protection. ITSB/ESB and signal
company personnel will provide assistance to local commanders as requested or directed.
Security Management Joint Implications
5-126. ARFOR, JFLCC, and CJTF NETOPS security management operations are governed by joint
guidance. Army personnel supporting these organizations will operate within this guidance while also
participating in Army security management procedures to the fullest possible extent.
5-127. Within the ARFOR, JFLCC, and CJTF, NETOPS security management operations are performed
by the G-6, supporting ITSB/ESB, TNT, and the supporting signal organization. When a potential security
incident is identified within or escalates to the ARFOR via a subordinate organization, its potential local
impact is determined and it is escalated to both the appropriate NETOPS cell within the JFLCC or CJTF
and the TNOSC. Appropriate responses or defensive measures are then directed via the chain of command.
INTERRELATIONSHIP OF NETOPS ACTIVITIES
5-128. It is important to note that the successful execution of the identified NETOPS activities requires a
high degree of coordination and cooperation within and between responsible organizations at all echelons.
The NETOPS activities described in this chapter are interrelated and dependent upon one another. For
example, the incident and problem management activity relies upon the change management activity in
order to implement corrective actions. This activity also relies on the infrastructure monitoring activity in
order to detect anomalies. Appendix C provides more examples of the interrelationships between NETOPS
activities and the organizations that carry them out. Figure 5-3 depicts the most common interrelationships
that exist between the NETOPS activities.
NETWORK OPERATIONS EVALUATION CAPABILITIES
5-129. Within the operational environment, NETOPS capabilities must be evaluated to ensure that they
are adequately supporting the Soldier. The evaluation activity is focused on the proactive maintenance of
the health and protection of the NETOPS capabilities. Evaluation activities are grouped into two areas: IA
compliance and NETOPS capacity and availability.
5-130. A NETOPS capability itself has requirements that must be met in order for the capability to operate
normally. These requirements are characterized by key parameters that, when evaluated against a threshold,
provide useful information about the health of the capability. For example, a key parameter of a T-1 circuit
is the instantaneous transmission rate. When the instantaneous transmission rate exceeds 1.536 megabits per
second (Mbps), the maximum transmission rate threshold has been exceeded and users of the transmission
system can expect dropped packets and slow application performance (e.g., degraded availability).
19 November 2008
FM 6-02.71
5-19
FOR OFFICIAL USE ONLY
Chapter 5
Network
Infrastructure
Data
Service
Infrastructure
Network
Event
Monitoring
Events
Security
Events
Service Desk
Security
Incident/Problem
Management
Management
Management
Request
Request
for
Request
for
Change
for
Hardware/
Change
Change
Software
Releases
Infrastructure
Change
Status
Management
Status of
Change Plan
Service
Configuration
Incident
Management
Reports
Incident
Reports
Release Planning
Information
Release
Management
NETOPS Shared
SA
Figure 5-3. NETOPS operational activities process flowchart
5-131. NETOPS capability evaluation provides the information needed to identify degraded availability,
capacity shortfalls, and IA compliance deficiencies. The result of the evaluation activities is information
required for NETOPS capability planners, IA analysts, and engineers to apply remediation or isolation
actions, reallocate resources, and identify upgrades to NETOPS capabilities supporting the Soldier.
5-20
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Activities
5-132. The evaluation activities presented so far have focused on the health, maintenance, and protection
of the NETOPS capabilities. The evaluation of trends over a long period of time provides information on
the overall health of the NETOPS systems. The evaluation of trends illuminates training deficiencies and
weaknesses in individual components or systems. It also provides valuable information to evaluate the
effectiveness of doctrine, organization, training, materiel, leader education, personnel, and facilities.
IA COMPLIANCE
5-133. IA compliance relates to security management, which specifies the performance of vulnerability
assessments. The evaluation of IA compliance, through CM, is the verification that the activities described
in the Systems Maintenance Section of this chapter have been performed and any deficiencies have been
identified. These assessments will be evaluated to ensure timely and adequate vulnerability remediation.
The evaluation should be scheduled as part of the overall IA security plan.
5-134. A few of the NETOPS capabilities requiring IA compliance are represented by computing
platforms, client applications, server applications, routers, and data switches that provide capabilities to the
Soldier.
IA Compliance Echelons and Organizations
5-135. The A2TOC will provide IAVM messages for distribution to the theater teams, RCIOs, and
DOIMs, and via AKO Knowledge Management bulk mail distribution. The RCIOs and DOIMs will ensure
that corps, division(s), and BCTs comply with the IA updates. Compliance with IAVMSs and IA
vulnerability bulletins must be reported in the Asset and Vulnerability Tracking Resource database. The
updates are pushed to the organization with operational management for action. The corps and division G-6
has SA of echelons in the AOR and determines the appropriate time to apply the IA updates. In some
instances, there are many baselines for a given NETOPS capability or there are too many to be supported by
the numbered Army. In this situation, the tactical operations staff will have to modify, recreate, and test IA
updates for distribution.
5-136. The corps/division G-6 has the responsibility to execute IA compliance IAW the commander’s
intent. The corps and division G-6 will use the appropriate resources (e.g., ITSB/ESB, signal company,
corps and division sanctuary, TIC, and TNT) to accomplish this mission. The organization that executes IA
compliance will be the organization with operational management of the system. The variety and
complexity of the NETOPS capabilities requires specialized groups to operate and maintain the systems.
For instance, the application of an IA package to a telecommunications component is best suited to the
signal company or the ITSB/ESB. The organization that is chosen to perform the activity depends on the
location of the component and which organization has OPCON. In another instance, the corps and division
sanctuary would be the appropriate location to modify and apply a patch for a computing platform. Lastly,
the organization with OPCON or management has the responsibility to provide compliance reports to the
corps and division G-6 via the signal company or the corps and division sanctuary. The numbered Army
will compile the compliance reports from the corps and division G-6.
IA Compliance Joint Implications
5-137. The ARFOR G-6 has the responsibility to execute IA compliance within its AOR IAW the ARFOR
commander’s intent. The ARFOR G-6 will use the appropriate resources (e.g., ITSB/ESBs, TIC, TNT, and
subordinate G-6 or S-6) to accomplish this mission.
5-138. Upon request of the ARFOR, the numbered Army will evaluate IA compliance of Army Service
components operationally controlled to the JTF in support of the CJTF. The CJTF and JFLCC will
orchestrate and coordinate the evaluation of IA compliance of NETOPS capabilities, systems, and
components.
19 November 2008
FM 6-02.71
5-21
FOR OFFICIAL USE ONLY
Chapter 5
NETOPS CAPACITY AND AVAILABILITY
5-139. There is a close correlation between NETOPS infrastructure capacity and availability of NETOPS
capabilities. While the functions are different, the organizational responsibilities are identical. It should be
noted that there is synchronization between the NETOPS capacity and availability and NETOPS
infrastructure monitoring. Infrastructure monitoring is a short-term activity that will feed the long-term
planning activity for such things as reallocation of resources with regards to IT capacity and availability.
5-140. The objectives of NETOPS infrastructure capacity evaluation are effective support to the Soldier
and efficient use of NETOPS capabilities. The NETOPS capacity evaluation results in information to aid
planners in forecasting capability degradation and making recommendations on capability reallocation and
upgrades, and a host of other items to maintain the health and protection of the NETOPS infrastructure.
Capacity evaluation encompasses all networking equipment, computing platforms, peripherals, and
software. It involves monitoring the performance or operating level(s) of key parameters and comparing
them against thresholds to forecast problems. The capacity evaluation activity provides critical, proactive
information for infrastructure planners to better allocate resources and identify potential bottlenecks.
5-141. As previously mentioned, capability availability is closely tied to infrastructure capacity. The
objective of availability evaluation seeks to ensure a sustained level of availability, reliability, and
maintainability of NETOPS capabilities. The availability evaluation measures key parameters against
thresholds to forecast service degradations. Availability evaluation encompasses all networking equipment,
computing platforms, peripherals, and software. The results are used by NETOPS capability planners to
improve the overall availability of the capabilities; ultimately resulting in a reduction of the frequency and
duration of adverse incidents.
Capacity and Availability Echelons and Organizations
5-142. It is the primary responsibility of the corps, division, and ARFOR, with technical assistance from
the numbered Army, to evaluate the capacity and availability of NETOPS capabilities. In addition, the
mission, enemy, terrain and weather, troops and support available-time available may dictate that lower
echelons, such as the BCT, perform this activity. The combined capacity and availability metrics and
evaluations will then be reported to the corps or division.
5-143. The corps and division will monitor data under their control to evaluate capacity and availability
metrics associated with NETOPS capabilities and enabling devices. The corps and division will also
evaluate capacity and availability metrics from the BCT in order to form an assessment scoped to its AOR.
The combined capacity and availability metrics and evaluations will then be reported to the numbered
Army.
5-144. The numbered Army is responsible for evaluating the capacity and availability metrics associated
with the NETOPS capabilities and enabling devices under their control as well as those provided by other
service providers (e.g., DISA). The results of the evaluations are used to make capacity and availability
improvements locally as well as to other NETOPS capability providers in support of the Soldier. The
numbered Army will also evaluate its entire AOR based on capacity and availability metrics and evaluations
collected from lower echelons. This investigation will help formulate an appropriate scoped assessment.
This allows for the identification of issues that might not be seen when taking a narrower view from a lower
echelon.
5-145. All capacity and availability improvement changes made to the NETOPS infrastructure at any
echelon will be done through the established change management process. This ensures the proper level of
coordination in keeping with the overarching goal of improved efficiency.
Capacity and Availability Joint Implications
5-146. The ARFOR will evaluate capacity and availability metrics associated with the NETOPS
capabilities and enabling devices under its control. The ARFOR will also direct capacity and availability
functions within the corps, division, BCTs, ITSB/ESBs, and any other subordinate signal organizations to
5-22
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Network Operations Activities
form an assessment scoped to its AOR. These metrics are then reported to the local numbered Army.
Capacity and availability metrics are also evaluated and reported to its joint command as directed by joint
policy.
NETWORK OPERATIONS TRAINING AND EXERCISE
5-147. As the capabilities and dependencies of the network evolve, the complexities of NETOPS and the
management of the LWN and the GIG increase. NETOPS spans the entire enterprise and is no longer
limited to just a local network, a small enclave, or a tactical battlefield, or the strategic environment. The
Soldier is reliant on NETOPS capabilities continually being available. NETOPS capabilities are not just
dependent upon the proper mix of equipment and processes. They demand a finely tuned, technically
competent force that is continually being trained. Training and readiness responsibility is the driver for
ensuring properly trained NETOPS forces. The Army provides a trained and ready force. It manages
training from Army learning centers through the integrated command post exercise to support the CCDRs in
exercising their Title 10 responsibilities.
5-148. Exercising these NETOPS activities has multiple impacts. First, it exposes many of the challenges
that will be addressed by tools, technologies, and processes if the enterprise is to be fully leveraged as a war
fighting platform. Second, it opens communications and exposes expertise and capabilities so that they may
be leveraged across the enterprise. Only through exercising NETOPS activities will organizations learn the
capabilities, challenges, and expertise that are required at each echelon to effectively provision NETOPS
capabilities.
5-149. The activities Soldiers must perform in training are the same as when performed in an actual
operational environment. The training environment should replicate as closely as possible the conditions,
circumstances, and influences of an actual operational environment, except potentially in a physical location
and that they may be augmented by simulation or stimulation. Detailed examples of NETOPS activities and
their inter-dependant nature are provided in Appendix C.
TRAINING AND EXERCISE JOINT IMPLICATIONS
5-150. The Army must be ready to execute its mission as part of a joint force conducting joint operations.
To accomplish this goal the Army must perform joint, interagency, intergovernmental, and multinational
training. Some training must also be performed in the area of coalition network support.
5-151. To achieve joint operational interoperability, that being the joint tactics, techniques, and
procedures as well as the processes associated with installation, operation, maintenance, and defense and
NETOPS of LWN communications systems, joint operational interoperability must become an integral part
of training requirements from Army learning centers to the integrated command post exercise. The joint
operational interoperability training requirement should become a part of the training and readiness
responsibility cycle for the CCDR. This will enhance the training of Army units on the interdependent
activities and organizational relationships needed to perform joint NETOPS. It will also make it easier for
Army units to integrate into the joint enterprise and to adhere to joint NETOPS standards and doctrine.
METHODS TO REDUCE FORWARD-DEPLOYED NETWORK
OPERATIONS
5-152. The effort to migrate tactical NETOPS functions from the operational environment to a fixed-
station location decreases the forward-deployed operational environment footprint, greatly facilitates
coordination and data exchange between tactical units, and drastically increases the supportability of
NETOPS functions. This can be approached via two distinct but complimentary methods: the migration of
selected support services to the TNOSC and A-GNOSC, and the migration of tactical command functions to
a unit-owned fixed station NETOPS cell.
19 November 2008
FM 6-02.71
5-23
FOR OFFICIAL USE ONLY
Chapter 5
METHOD 1: THE MIGRATION OF SELECTED SUPPORT SERVICES TO THE TNOSC AND THE
A-GNOSC
5-153. As the physical network connectivity between the Soldier and sustaining base improves, it becomes
advantageous to identify target opportunities for the extension of garrison and theater-based NETOPS
capabilities to the Soldier. Consistent with Title 10 functions and responsibilities, these capabilities will be
available to the Soldier wherever they deploy.
5-154. The evolution of tactical support services must be designed with the purpose of not impairing the
flexibility or responsiveness of the ARFOR, corps, division, or BCT. Operational management
responsibilities of the combat echelons are discussed in further detail within the NETOPS Operational
Control and Management section.
5-155. For example, consider the AKO e-mail account and portal. The AKO e-mail address and portal are
available wherever a Soldier or organization deploys. The organization does not have to worry about the
operation and maintenance of this capability, and total cost of ownership is reduced. Additional examples of
tactical support services are IAVA guidance, anti-virus updates, capacity and availability data collection
and reports, and router configuration backups. The Soldier can access and manipulate these services by
logging into an AKO or a TNOSC site.
5-156. It is essential that the numbered Army and theater Army stand up to this service paradigm so that
opportunities to capitalize on economy of scale, standardization, and overall NETOPS value added are fully
realized. This will help to meet the vision of a single integrated Army enterprise that is capable of
projecting NETOPS capabilities in full support of the Soldier.
METHOD 2: THE MIGRATION OF TACTICAL COMMAND FUNCTIONS TO A UNIT-OWNED
FIXED STATION NETOPS CELL
5-157. Many NETOPS functions require a distributed management structure which parallels the combat
chain of command to ensure that activities are dynamically and quickly aligned with command guidance and
user requirements. These functions are not candidates for migration to the TNOSC or A-GNOSC. Some
examples of these functions are policy development, change management processing and approval, tactical
engineering functions, tactical planning functions, and operational management of specific devices.
5-158. In order for these functions to take place at a fixed station location, it is necessary to stage a unit-
controlled NETOPS cell within the fixed station. Robust lines of communication between the fixed station
and the operational environment TOCs can then be utilized for intra-unit coordination and data exchange.
The corps or division sanctuary serves this purpose for the corps and division. The TNT (rear) serves this
purpose for the ARFOR, JFLCC, or the JTF.
5-159. Some NETOPS functions require direct physical interaction with equipment or personnel within
the operational environment. Examples of these operational environment-linked NETOPS functions are
touch labor troubleshooting, device installation, manual recovery and teardown, site reconnaissance, and
physical interaction with unit subscribers or command personnel. These functions cannot be migrated to the
corps or division sanctuary, the ARFOR, JFLCC, or the JTF TNT (rear). All other unit-based NETOPS
functions for the corps, division, and above will be migrated to these locations.
5-160. There are few NETOPS tasks in the BCT and below that are not operational environment linked.
For this reason, the BCT and below will not generally operate a unit controlled NETOPS cell within the
fixed station. The BCT and below has the option of staging unit NETOPS services at the numbered Army-
hosted fixed UHN. They can also place unit personnel at a corps or division sanctuary or a TNT (rear) in
order to facilitate unit integration and provide remote NETOPS services from the fixed-station.
5-24
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Appendix A
Active Directory
This appendix describes the AD concept for command and staff elements that
deployable Army units will use to implement and operate AD in CONUS, OCONUS,
and across all theaters of operations. This information is not meant to provide the
technical procedures required to install, operate, and maintain networks in an AD
environment. This document establishes that tactical unit guidance is provided by the
US Army Signal Center and the US Army NETCOM/9th SC(A). They will provide
the overall guidance for the standards, responsibilities, and processes necessary to
migrate from the current IT environment to an AD based environment.
OVERVIEW
A-1. To meet the operational philosophy of training and working-as-you-fight, the deployable units should
operate the same way in garrison as they would when they are deployed. This ―deployed-in-garrison‖
concept helps to support modularity and achieve a ―plug-&-play‖ functionality for the deployable units.
Deployable force users will be able to leverage local DOIM or TNOSC expertise, as available. The users
will increase and maintain automation proficiency by practicing the skills learned while providing service in
garrison.
A-2. Introduction of AD into the Army will provide both a new capability plus satisfy the Army mandate
for a technology replacement of the old NT 4.0 LAN operating system.
ACTIVE DIRECTORY OPERATIONAL FEATURES
A-3. The AD architecture and associated features introduce a more granular management capability with
the introduction of structures such as forests, and organizational units. The enabling technology for all of
these new structures is AD, which is the directory service for Windows 2003 server capabilities. AD
implementation is both necessary and beneficial in that current disparate architectures and personnel
responsibilities at each installation can be combined to form an Army Windows IT enterprise. Approved
deployed forest information is in the approved Technical Authority 2006-006, 14 May 2007.
ENTERPRISE MANAGEMENT FEATURES
A-4. The enterprise management features include:
z
Extensible schema—AD lets developers and administrators extend the directory schema and
create new properties and objects. Using the directory as a data store, developers can create their
own data structures for applications. Users on the network can publish important information in
the directory so other users can easily locate the material.
z
Centralized management—allows enterprise level management of Windows users, clients, and
servers through a single consistent interface, reducing redundancy and maintenance costs.
z
Group policy—allows administrators to define and control the policies governing groups of
computers and users within their organization. Administrators can set group policy for any of the
sites, domains, or organization unit in AD. Once the policy is set, the system maintains group
policy without further intervention.
z
Global catalog—provides a way to centrally maintain information about users and universal
groups for access control. The information is managed by using one or more domain controllers
19 November 2008
FM 6-02.71
A-1
FOR OFFICIAL USE ONLY
Appendix A
that contain subset attribute information for most entries in a Windows 2000 domain forest.
These controllers also replicate domain schema, configuration, and partial user or other resource
entries.
z
Automated software distribution—provides the capabilities for administrators to automatically
distribute applications to users based on their functional requirements.
z
AD service interfaces—simplifies the development of directory enabled applications and the
administration of distributed systems. Developers and administrators use this single set of
interfaces to manage the resources in a direct support, regardless of the network environment that
contains the resource.
z
Delegated administration—provides administrators the ability to delegate a selected set of
administrative privileges to appropriate individuals within the organization and specify the
specific rights they have over different containers and objects in the directory.
z
Multi-master replication—ensures changes made to any one domain controller will replicate to
all the other direct currents in the same domain, and assures that the directory is available for
changes 100 percent of the time.
Security
A-5. AD security features include:
z
Kerberos authentication—provides fast, single sign-on to Windows-based resources and to
other environments that support this protocol.
z
Transitive Domain Trust—reduces the number of trust relationships to manage between the
Windows domains.
z
PKI x.50—ensures interoperability with and deployment of extranet and e-commerce
applications.
z
Attribute-level security—enforces object and attribute-level security for detailed control of
access to information stored in the directory.
z
Spanning security groups—permits central management of groups.
z
Lightweight Directory Access Protocol ACL support—ensures interoperability for secure
extranets and e-commerce applications.
z
Smart Card support—allows logon via smart cards for strong authentication to sensitive
resources.
z
Group policy—allows administrators to define and control the security policies governing
groups of computers and users within their organization and filter the effects by using
membership in security groups.
ACTIVE DIRECTORY MULTI-FOREST AND OPERATIONAL
CONSIDERATIONS
A-6. The current approved AD architecture represents a multi-forest approach that divides the Army
enterprise into element permanent AD forests and allows for tactical forests.
A-7. Since the security boundary is at the forest level, a single forest approach produces a security
vulnerability that is not acceptable. Single forest architecture would allow someone with access to the
forest’s domain controller or administrative rights in a domain to exceed their authority and obtain
enterprise administrative rights. Objects stored in the AD represent all of the users, systems, and services
within that forest. A person with these rights could destroy the validity of the data causing enterprise wide
consequences. The global catalog contains a partial copy of every object in the AD forest. If the system that
hosts AD for a forest is compromised, there is a risk of exposing a portion of the Army’s infrastructure
information. A larger forest makes more infrastructure information vulnerable at a central location. The
multi-forest operational concept limits the consequences of an attack. The smaller the forest, the more
readily problems associated with the global catalog can be discovered. The single forest has a limited ability
A-2
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Active Directory
to compartmentalize. This circumstance presents an unacceptably high risk for secure information
distributed into potentially hostile areas.
A-8. In addition to security considerations, scalability is an operational risk associated with a single forest
deployment. The larger the forest size in terms of number of supported users and desktops, the larger the
directory must be that supports the forest. Since the Army has in excess of 1,000,000 users, a single
directory and the associated global catalog would be extremely large and would impose potentially
excessive replication loads on available network bandwidth. The architecture of each forest will have a top
level AD domain that forms a contiguous name space from the top level Army enterprise forest root
domain; and a contiguously named management domain that is a placeholder domain to manage the
enterprise administrator accounts and processes.
A-9. Organizations’ geographic ―regions‖ are included in a designated regional forest. Examples of
regional forests are CONUS, Pacific, Korea, and Europe. In addition to the standard regional forests, some
organizations require autonomy due to sensitive or specialized business practice or geographic region that
does not adequately represent its mission support needs. For these cases, a
―virtual region‖ and
corresponding forest exists. Examples of organizations with their own ―virtual region‖ include Army
Medical Command, Corps of Engineers, and National Guard. Given the multiple forest configurations of
AD, the A-GNOSC uses the CONUS-TNOSC operation and maintenance resources and capabilities to
fulfill its Windows server or AD enterprise management role. The current list of forests are:
z
North America forest: five child domains representing information management area regions.
z
Europe forest: three child domains.
z
Global catalog forest: three child domains.
z
National Guard forest: four child domains.
z
Pacific forest: three child domains.
z
Southwest Asia forest: one child domain.
z
Korea forest: one child domain.
z
Corps of Engineers forest: three child domains.
z
Education forest: to be determined.
z
Enterprise Application forest: one child domain.
z
Deployed forest information can be found in Technical Authority 2006-006, dated 14 May 2007.
ACTIVE DIRECTORY IMPLEMENTATION CONSIDERATIONS
A-10. When implementing AD the commander and staff must consider:
z
Implementing, managing, and maintaining IP addressing as related to the DHCP.
z
Name resolution as related to the DNS.
z
Network security as related to overall security templates to include parameter security and CND
oversight.
z
Routing and remote access as related to remote access authentication protocols.
z
Managing network architecture as related to connectivity to the Internet and troubleshooting
network services.
A-11. A global catalog server is required to communicate between domains. There must also be a sufficient
amount of automation materiel (hardware or software) for the deployable force. AD implementation needs
an information system platform that meets or exceeds the performance requirements to run Microsoft
Advanced Server 2000/2003 software domain controller, a DNS, DHCP server, and a global catalog server.
The DNS may be co-hosted on the domain controller provided it does not adversely impact system
performance.
19 November 2008
FM 6-02.71
A-3
FOR OFFICIAL USE ONLY
Appendix A
FLEXIBLE SINGLE MASTER OPERATION
A-12. The enterprise flexible single master operation roles for each forest will be physically located on the
domain controllers. Flexible single master operation roles will include the schema and domain naming
masters. The root or management domain specific roles are—
z
Primary domain controller emulator.
z
Relative identifier master.
z
Infrastructure master.
A-13. All domains in an AD forest share a single schema, configuration naming context, and a global
catalog containing selected information about each object in the forest. The Army will maintain consistent
schemas across all forest implementations. This is accomplished through strict adherence to published Army
Enterprise Infrastructure (AEI) standards and tightly controlled change management through the CCB
process. NETCOM chairs the AEI Tech CCB, which adjudicates modifications to the currently
implemented AD schema in an operational environment.
Note. CCDR participation in and input to the AEI Tech CCB will aid future CCDR AD
migration.
MANAGEMENT ROLES AND RESPONSIBILITIES
A-14. This section addresses the roles and responsibilities of Army organizations within the Windows
server or AD enterprise. AD is a key component of any future enterprise-wide directory service. Therefore,
the management and configuration control of AD implementations and maintenance requires strict central
control and well-defined roles and responsibilities across the enterprise. The role of schema or enterprise
administration is the responsibility of the local enterprise administrator, which delegates operation and
maintenance responsibility to selected support and helpdesk personnel. NETCOM has been tasked by the
CIO G-6 to establish technical guidance, procedures, and standards for AD implementation and operations.
The current version of the AEI Directory Services Naming Conventions and Standards (NETC-EST-G-
0306-009-STD), published by NETCOM Enterprise Systems Technology Activity is the authoritative
document governing AD. This and other documents can be found at the following URL
https://www.us.army.mil/suite/folder/626256. Figure A-1 shows the interface relationships by
organizational level. Table A-1 shows the organizations by level with their associated operational roles.
A-4
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Active Directory
Area of Responsibility (AOR)
AGNOSC
Theater Management
Theater Management
COCOM
Garrison Operations
Tactical Operations
TNOSC/ x Army
DOIM
Tenant
Organizations
DIV
DIV
Corps
Garrison Functional
Staff
BDE
BDE
BDE BDE
BDE BDE BDE
UNITS*
UNITS*
UNITS*
UNITS* UNITS* UNITS*
*BDE UNITS include: BCT, Fires, BFSB,
AVN, Maneuver Enhancement, and
Garrison
Deployed
Sustainment Brigades.
Same standard Operational Interfaces and Services while in
Garrison (DOIM/CTNOSC) and while deployed in Theater (TNOSC)
Figure A-1. AD operational interfaces by NETOPS organizational level
19 November 2008
FM 6-02.71
A-5
FOR OFFICIAL USE ONLY
Appendix A
Table A-1. AD operational concepts by NETOPS organizational level
NETOPS Level
GARRISON
DEPLOYED
AD Operational Roles
Has specific responsibilities for:
Exchange e-mail.
Unit Level
Web hosting and collaboration (information dissemination
management-tactical [IDM-T]).
Corp, Division, and
Brigade Unit
AD and user account management.
Patch management to defend the tactical network.
File, print, and store.
Installation and numbered
The site or installation will be a top-level organizational unit.
Army level
Has specific responsibilities for:
Collaboration services (Defense Collaboration Tool Suite and
information warfare support).
Record messaging services (Defense Message System and
Automated Message Handling System).
Major
Perimeter security; CND oversight.
DOIM
Subordinate
Command
Trouble ticketing services.
Global address list synchronization.
Level 2 and 3 technical support and operational CM.
Provides NETOPS shared SA data to respective TNOSC.
Manages and administers AD forest and domains for the respective
Theater Level
theaters; delegates top-level organizational units’ administrative roles to
ensure efficient, effective distributed operations for lower level
organizations.
Provides expertise to support the expanded enterprise operation and
maintenance of critical domain and theater level AD equipment
DOIM
TNOSCs
Monitors network common relevant operational picture (NETOPS shared
SA) for installations in region.
Provides all Army users enterprise-wide visibility and access to ―yellow
and white‖ pages.
Establishes technical guidance, procedures, and standards for AD
support.
Global Level
Has specific responsibilities for:
NETCOM (A-GNOSC)
SA.
Domain naming service master.
Circuit management.
Provides top level configuration control through AEI Tech CCB.
KEY AD MANAGEMENT ROLES IN THE MULTI-FOREST ARCHITECTURE
A-15. The multi-forest architecture provides the foundation for the operation and maintenance support of
the Army AD community. AD provides the capability, at the enterprise level, to support the mission to
manage, operate, maintain, monitor, and defend the AEI. The master forest (ds.army.mil for NIPRNET and
A-6
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Active Directory
ds.army.smil.mil for SIPRNET) provides the framework for Army enterprise management using Microsoft’s
Windows 2003 AD services across all approved forests. The key aspects of the AD environment requiring
central control are—
z
Schema and naming standards throughout the multiple forests.
z
Administration of the domain controllers precludes the delegation of specific privileges below
the central management organization.
z
AD and Windows 2000/2003 server administration capabilities do not preclude the delegation of
specific privileges required by local support staff. This delegation of responsibilities may be
handled via third-party software tools.
z
Execution of administrative roles.
z
Forest level administration of the AD forest includes responsibilities related to managing the AD
schema and those tasks requiring enterprise administrator privileges.
z
Domain level administration of the AD domain includes responsibilities of domain management
and maintenance of the domains within the forest, to include all tasks requiring domain
administrator privileges.
z
Administration of the top-level organization unit includes responsibilities of organization unit
management and maintenance to include user, group, resource, and data administration.
UNIT LEVEL
A-16. Units may operate and maintain specialized IT resources such as specialized software or hardware
devices required to perform the unit’s mission. These resources remain the operation and maintenance
responsibility of the unit. These organizations use standard Army support to the greatest extent possible,
thus minimizing differences.
Corps, Division, and Brigade Mission-Critical Services
A-17. Corps, division, and brigade mission-critical services include:
z
Organizational messaging (Defense Message System).
z
Exchange e-mail.
z
Web hosting or collaboration (IDM-T).
z
Managing user accounts within their unit based on the AD policies and administrative
capabilities.
z
Patch management to defend their network.
z
Hosting and maintaining local print servers, local file servers, and local storage.
z
DNS management.
z
AD replication; DHCP authorization.
z
Trust management.
z
Local exchange message tracking and troubleshooting.
z
Perimeter security and CND oversight.
z
Managing and creating domain local groups.
z
Managing NETOPS.
z
Trouble ticketing and helpdesk services.
Additional Corps, Division, and Brigade Required Services
A-18. Additional corps, division, and brigade required services include:
z
Providing group policy object policy administration to include domain and domain controller
polices.
z
Providing level 2/3 technical support and operational CM.
19 November 2008
FM 6-02.71
A-7
FOR OFFICIAL USE ONLY
Appendix A
z
Maintaining the approved configuration of core AD equipment on the installation or region as
directed by its TNOSC related to the initialization or termination of operations and to the
establishment or maintenance of configuration.
z
Populating and managing organization units provided, and delegating authority for subordinate
level organization units.
z
Applying security necessary to prevent unauthorized individuals any physical access to enterprise
resources geographically located at the installation.
z
Notifying appropriate higher command of physical security compromised of any system.
z
Executing global catalog server roles.
z
Executing schema master role for the unit forest.
z
Executing domain naming master role for the forest.
INSTALLATION AND NUMBERED ARMY LEVEL
A-19. Organizations at the installation or numbered Army level may operate and maintain specialized IT
resources such as specialized software or hardware devices required to perform their mission as well as their
subordinate unit’s missions. These organizations include TNOSC, DOIM, and major subordinate
commands (e.g., CCDRs). These resources remain the operation and maintenance responsibility of the unit,
and the organization’s commander will act as the designated approval authority (DAA). These organizations
use standard Army support to the greatest extent possible to minimize differences. Critical tasks include all
the tasks required at the unit level as well as the tasks requiring AD enterprise, domain administration, and
exchange rights. These tasks include:
z
DNS CM.
z
Collaboration services (Defense Collaboration Tool Suite and information warfare support).
z
AD replication; DHCP authorization.
z
Group policy object policy administration to include domain and domain controller polices.
z
Trust management.
z
Exchange installation and message tracking and troubleshooting to include:
„ Trouble ticketing services.
„ Record messaging services
(Defense Message System and Automated
Message Handling System).
z
Enabling global address list synchronization.
z
Perimeter security; CND oversight.
z
Level 2/3 technical support/operational CM.
DOIM AND MAJOR SUPPORT COMMANDS
A-20. The DOIM and the major subordinate commands in the US Army theaters have two basic functions:
one of operational support and one of administration and management. These organizations provide
infrastructure IT services to all Army users on the installation, consistent with the concept established by the
NETOPS CONOPS. In addition, they provide access to IT services based on support agreements with other
non-Army organizations and activities. From a Windows server or AD perspective, DOIM and major
subordinate command activities include:
z
Conducting Windows server and AD implementation, and coordinating the necessary
implementation planning actions with NETCOM and its TNOSC.
z
Hosting and maintaining local print servers, local file servers, and local Windows servers for
legacy systems interaction.
z
Ensuring that noncritical member servers provided by the installation meet the minimum server
requirements to join the enterprise.
z
Providing troubleshooting support for core AD servers in support of the TNOSC operation and
maintenance responsibilities.
A-8
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Active Directory
z
Performing necessary hands-on maintenance of AD assets ICW its TNOSC.
z
Managing user accounts within their installation or region based on the AD policies and
administrative capabilities.
z
Maintaining the approved configuration of core AD equipment on the installation or region as
directed by its TNOSC related to the initialization or termination of operations and to the
establishment or maintenance of configuration.
z
Managing and creating domain local groups.
z
Populating and managing top-level organization units provided as part of the installation
resources and delegation authority for subordinate level organization units.
z
Validating and forwarding, through the RCIO, all configuration change requests from local
organizations.
z
Maintaining installation member servers and applications.
z
Applying security necessary to prevent unauthorized individuals any physical access to enterprise
resources geographically located at the installation.
z
Notifying the TNOSC of physical security compromised of any system.
THEATER LEVEL
A-21. At each theater level, the TNOSC has the key management role for the Windows server and AD
operations within that theater. In general, these roles are the forest and domain administrative related roles
as delegated by the A-GNOSC.
TNOSC
A-22. The TNOSC is the highest-level organization with IT operations responsibilities. They interact with
the RCIOs and with the A-GNOSC. Within a given theater of operation, the TNOSC has the responsibility
for IT assets that span its theater. It is responsible for ensuring that IT assets operate correctly, and for
creating policy on a theater-by-theater basis. The TNOSC currently manages the public side of the
demilitarized zone. Note that the demilitarized zone currently starts at the installation Army DISN router
program. The TNOSC supplies technical support (e.g., tool sets to ensure the local health of AD) to the
installations. The TNOSC proactively monitors all systems within the child domains. Each TNOSC is
responsible for the performance management to support AD operations in theater. TNOSC performs the
appropriate monitoring for those systems within their child domains. They use the information to affect root
level configuration change request through the A-GNOSC to the AEI technical CCB.
A-23. The TNOSC is responsible for ensuring standard configuration, CONOPS, and centralized
management of domain controllers within the Windows server or AD enterprise. It ensures the systems
located in these domains are capable of providing those services detailed in the Army enterprise, AD
architecture, and any subsequent AEI technical CCB additions. The TNOSC maintains the necessary system
configuration, conducts theater level Configuration Control Review Board, and implements system changes
authorized by the AEI technical CCB. The TNOSC ensures proper configuration of external devices and
provides the backup and recovery processes relative to child domains. Under the AD enterprise concept, the
TNOSC’s responsibilities will expand and include the administrative management of the domain for the
theater’s respective AD. These responsibilities include:
z
Operating and maintaining the domain controllers for all domains and the critical member servers
in the theater.
z
Maintaining and disseminating enterprise management and directory management tools.
z
Hosting and maintaining:
„ DNS server for the theater’s domains (DNS server is a secondary for the
root zone).
„ Infrastructure master role for theater respective domains.
„ Primary domain controller emulator role for theater domains.
19 November 2008
FM 6-02.71
A-9
FOR OFFICIAL USE ONLY
Appendix A
A-24. TNOSC executes security related guidance from the A-GNOSC by implementing security programs,
procedures, policies, and IAVA patches as directed. It is imperative that the TNOSC take all actions to
protect its domain level systems from compromise. TNOSC provides a level of physical security ensuring
that only authorized individuals have access to their child level domains. TNOSC will notify the appropriate
organizations if systems are compromised within their domains and will provide the organizations with all
the information relative to the compromise. TNOSC will implement best security practices by controlling
accounts relative to administrative functions within respective domains.
A-25. The respective TNOSC also has regional level responsibilities for the domain hub domain controllers
that are established in a region. Each TNOSC will have the administrative rights for the child domains
affected by these domain controllers for that region. The NETCOM domain design document provides the
technical guidelines for the functions of these domain controllers. The respective TNOSC has site level
responsibilities for the domain replicas on each site. The TNOSC has the administrative rights for the top
level organization units for the site. The NETCOM domain design document provides the technical
guidelines for the functions of these domain controllers.
REGIONAL CHIEF INFORMATION OFFICER
A-26. The RCIO acts as the CIO for an assigned region. The RCIO ensures all personnel operating on an
Army installation are provided the IT resources they require in a manner that is consistent with policies,
regulations, and other guidelines developed in or by the RCIOs management chain. The RCIO provides
administrative and managerial IT support to any DOIM located within its regional director geographic
region.
GLOBAL MANAGEMENT ROLES
A-27. This section addresses the role of those global level organizations that affect Windows server and AD
operations. Refer to the Army Knowledge Management NETOPS CONOPS for a complete description
from a NETOPS perspective of all organizations for the global level.
ARMY GLOBAL NETWORK OPERATIONS AND SECURITY CENTER
A-28. The A-GNOSC’s prime responsibility for Windows server and AD operations is to establish and
exercise strict control over the AD forests at all levels within the enterprise. The proactive centralized
monitoring of enterprise systems within the Army AD environment provides organizations responsible for
those assets the valuable information necessary to achieve a stable and productive enterprise environment.
The A-GNOSC provides operational and management policy input to NETCOM. The A-GNOSC delegates
AD administrative roles by:
z
Assigning the responsibilities for schema and enterprise administration at the forest level to the
appropriate TNOSC.
z
Assigning operating responsibilities for cross-forest meta-directory services to the appropriate
TNOSC.
z
Assigning responsibilities for administration at the top-level organization unit and delegation of
administrative authority to the installation DOIM or major subordinate command organization
unit administrators.
z
Assigning responsibility for administration at the second-level organization unit or below by the
major subordinate command or DOIM to other lower-level organizations.
A-29. At present, the A-GNOSC uses the CONUS-TNOSC capabilities and resources to conduct its AD
enterprise management functions. The A-GNOSC has the following roles and responsibilities relative to the
Army AD enterprise:
z
Delegates, to the TNOSC, the responsibility to perform the appropriate monitoring for all
systems within TNSOCs respective domains. The scope of this responsibility includes hardware,
operating systems, services (to include the Army AD), networking services, third party tools,
Windows 2003 policies, sites, organizational units, and enterprise accounts.
A-10
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Active Directory
z
Delegates to the TNOSC operation and maintenance support actions, to include:
„ Management of the enterprise management and directory tools in the
management and services domains of the master forest.
„ Global catalog server at the root level.
„ Schema master role for the forest.
„ Domain naming master role for the forest.
„ CM support responsibilities.
z
Ensures maintenance of a standard system baseline, and overall administration of systems located
within all approved forests supporting the actions of the AEI technical CCB. The AEI technical
CCB has overall responsibility for CM of the Army IT enterprise.
z
Establishes processes with the respective TNOSCs for a theater level CCB to implement
processes for the following call manager actions:
„ Implement CCB approved system changes for the root domains.
„ Ensure that approved configuration changes are propagated to child domains
within the Army AD domain structure.
„ Maintain the system configuration for the hardware, software, and
applications necessary for the CONOPS of systems in the root level domains
based on standard server configuration document.
„ Ensure proper configuration of external peripheral devices and provide the
management of the backup and recovery systems within the root domain.
„ Ensure consistency across the enterprise for AD supporting tools sets via
requirements developed ICW NETCOM product engineers.
z
Participate in an advisory role to the AEI technical CCB to provide operational expertise.
A-30. A-GNOSC identifies, tracks, and manages all security areas relative to enterprise servers for all
forests. A-GNOSC directs the respective TNOSC implementation of security programs, procedures,
policies, and IAVA patches. A-GNOSC administers control over accounts relative to administrative
functions within the root domains, and uses whatever means necessary and reasonable to ensure security of
the root systems. A-GNOSC is responsible for notifying the appropriate organizations if systems within the
root level are compromised. They also provide that organization with all the information relative to that
compromise.
A-31. The greatest level of protection must be exercised in guarding the Army AD data. Given the existence
of host-based IDS, the A-GNOSC directs the respective TNOSC to configure the software in such a way as
to maximize the efficiency of the software while balancing system performance. Security management
duties include:
z
Managing the settings for encryption level between root and child-level domains.
z
Coordinating with the TNOSC in order to implement encryption levels.
z
Establishing the accounts and access permissions to the file systems located within the root
domains.
z
Ensuring that user and administrative accounts within the root domain have proper password
security.
z
Ensuring user and administrative accounts have not been compromised.
NETWORK ENTERPRISE TECHNOLOGY COMMAND
A-32. NETCOM was designated as the Army's authority to operate (ATO) and manage the enterprise level
infrastructure. NETCOM is also in charge of implementing Army IT operational and management policies.
Through operational review and coordination, NETCOM agencies establish standards and evaluate devices
that impact upon the Army enterprise level infrastructure.
19 November 2008
FM 6-02.71
A-11
FOR OFFICIAL USE ONLY
Appendix A
A-33. NETCOM delegates the management of Windows server and AD operational services by assigning
administrative roles to the Army organizations. From the Windows server or AD perspective, NETCOM
responsibilities are:
z
Integrating, operating, and maintaining the Army’s protected (public) and AD (private) DNS.
z
Providing processing platform management and administration of all AD enterprise level servers.
z
Managing the Windows server and AD top-level architecture (this includes domain management
of all consolidated Windows 2003/2000 domains and domain controllers).
z
Managing the root and services domain (ds.army.mil) for the enterprise.
z
Providing support for organizational unit managers.
z
Providing policy and technical guidance to installations or sites for migration to the Windows
server and AD.
z
Integrating directory services.
z
Integrating AD with TNOSC COOP.
z
Integrating Windows server and AD developed backup and restore technology.
z
Operating, managing, and maintaining Windows server and AD root and regional footprints.
z
Managing COOP and backup and restore technology for Windows server and AD systems.
z
Expanding security monitoring to support enterprise Windows server or AD servers.
z
Testing and applying all security patches and validating IAVA compliance for all AD and
consolidated servers.
z
Assisting with the installation DOIM as necessary during the execution of the approved plan.
z
Validating compliance IAW AEI technical CCB.
z
Accommodating issues that prevented routine migration of installation users or organizations.
ARMY CHIEF INFORMATION OFFICER G-6
A-34. The CIO G-6 is responsible to the secretary of the Army and responsive to the chief of staff of the
Army for all information management area activities of the Department of the Army. The information
management area includes automation, communications, records management, publications and printing,
visual information disciplines, and library activities throughout the Army theater and strategic (tactical and
sustaining base) environments. From a Windows server or AD perspective, the CIO G-6 activities include:
z
Providing high level (global) Windows server or AD policies.
z
Establishing high level (global) Windows server or AD operating rules and guidelines.
TACTICAL INTERNET NAMING CONVENTIONS
A-35. The naming standards described in this document apply to all Army networks of all classifications,
strategic and tactical. This appendix covers the specifics that apply to all tactical and deployable Army units
(active and reserve) and is intended to be used in conjunction with the entire Naming Convention document,
making it interoperable with the naming convention of the DISN and the tactical naming conventions of
other tactical forces. It is not intended to be used as a stand alone document. This appendix incorporates
data networks at theater, corps, division, BCT, combat aviation brigades, fires brigades, combat support
brigades, sustainment brigades, battlefield surveillance brigades, and battalion/small command posts. This
naming convention applies to both tactical SIPRNET and tactical NIPRNET addressing with the difference
in domains of ―.army.smil.mil‖ for SIPRNET and ―.army.mil‖ for NIPRNET.
Note. This guidance document is based on current policies and procedures at the time it was
written. Any changes in policy or guidance could impact this guidance and will be reviewed as
needed.
A-12
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Active Directory
A-36. NETCOM and the US Army Signal Center agree to support the following SECRET Internet Protocol
Router
(SIPR)/Non-Secure Internet Protocol Router
(NIPR) DNS structure for autonomous units.
Autonomous units are defined as any unit that satisfies the Joint Expeditionary Mindset (Task Force
Modularity) and can be deployed without regard to any habitual relationship or task organization, CONUS
or otherwise. Notable examples include the reorganized BCT or other brigade unit, division, and corps
and/or theater.
A-37. The autonomous unit maintains its SIPRNET/NIPRNET AD forest and only one AD domain. If the
autonomous unit desires additional domains, they must be approved by NETCOM ICW the US Army
Signal Center.
ACTIVE COMPONENT TACTICAL/DEPLOYABLE AD FORESTS NAMES
A-38. Tables A-2 through A-4 are the standardized names to be used upon approval of AD
tactical/deployable forests. Inclusion in this list does not constitute an approval for implementation. All
forests must be approved by the CIO/G-6 prior to implementation based on current policies and procedures.
No deviations are authorized. Any additions to this list must be requested from the proponent for this
publication. Current information (Army guidance) is in Appendix M of the AEI directory services naming
conventions and standards document. For the most current Appendix M please click the URL listed below.
DOMAIN NAME
A-39. Each tactical/deployable forest will initially have only one AD domain. Its name has been assigned
according to Tables A-2, A-3, and A-4 below. In the event that additional domains are required, requests
must be coordinated, through the unit’s parent G-6/S-6, with the Global Database Manager at the US Army
Signal Center (Concepts, Requirements and Doctrine Division, Material Requirements Branch), DSN: 780-
6920) for concurrence; and then must receive approval from NETCOM.
Note. The ―.DS‖ appears only in the root domain name; the nameserver record pointing to the
tactical DNS servers IP will be for public presence namespace and is the same as the existing
namespace but without the DS. The unit does not include the ―.DS‖ in its request for a
nameserver record (with its DNS IP) to be added. Example: A server is installed using the DNS
namespace 3BCT82AB.ds.army.mil or 3BCT82AB.ds.army.smil.mil. The nameserver IP is
registered with 3BCT82AB.army.mil or 3BCT82AB.army.smil.mil for external resolution. If a
system on the internal network needs to be publicly accessible then an alias record would be
created in the 3BCT82AB nameserver pointing to the internal machine. This ensures that only
authorized systems are resolved from outside of the unit’s network.
Table A-2. Forest names, domain names, and exchange organization names
of active component tactical deployable units
Exchange
NIPR Domain name (one per
SIPR Domain name (one per
Forest Name
Organization name
forest only)
forest only)
SIPR and NIPR
Corps
ICorps
ICORPS.DS.ARMY.MIL
ICORPS.DS.ARMY.SMIL.MIL
ICORPS
IIICorps
IIICORPS.DS.ARMY.MIL
IIICORPS.DS.ARMY.SMIL.MIL
IIICORPS
VCorps
VCORPS.DS.ARMY.MIL
VCORPS.DS.ARMY.SMIL.MIL
VCORPS
XVIIICorps
XVIIICORPS.DS.ARMY.MIL
XVIIICORPS.DS.ARMY.SMIL.MIL
XVIIICORPS
Divisions
1AD
1AD.DS.ARMY.MIL
1AD.DS.ARMY.SMIL.MIL
1AD
1BCT1AD
1BCT1AD.DS.ARMY.MIL
1BCT1AD.DS.ARMY.SMIL.MIL
1BCT1AD
19 November 2008
FM 6-02.71
A-13
FOR OFFICIAL USE ONLY
Appendix A
2BCT1AD
2BCT1AD.DS.ARMY.MIL
2BCT1AD.DS.ARMY.SMIL.MIL
2BCT1AD
Table A-2. Forest names, domain names, and exchange organization names
of active component tactical deployable units (continued)
Exchange
NIPR Domain name (one per
SIPR Domain name (one per
Forest Name
Organization name
forest only)
forest only)
SIPR and NIPR
Divisions
3BCT1AD
3BCT1AD.DS.ARMY.MIL
3BCT1AD.DS.ARMY.SMIL.MIL
3BCT1AD
4BCT1AD
4BCT1AD.DS.ARMY.MIL
4BCT1AD.DS.ARMY.SMIL.MIL
4BCT1AD
1CAB1AD
1CAB1AD.DS.ARMY.MIL
1CAB1AD.DS.ARMY.SMIL.MIL
1CAB1AD
1CD
1CD.DS.ARMY.MIL
1CD.DS.ARMY.SMIL.MIL
1CD
1BCT1CD
1BCT1CD.DS.ARMY.MIL
1BCT1CD.DS.ARMY.SMIL.MIL
1BCT1CD
2BCT1CD
2BCT1CD.DS.ARMY.MIL
2BCT1CD.DS.ARMY.SMIL.MIL
2BCT1CD
3BCT1CD
3BCT1CD.DS.ARMY.MIL
3BCT1CD.DS.ARMY.SMIL.MIL
3BCT1CD
4BCT1CD
4BCT1CD.DS.ARMY.MIL
4BCT1CD.DS.ARMY.SMIL.MIL
4BCT1CD
1CAB1CD
1CAB1CD.DS.ARMY.MIL
1CAB1CD.DS.ARMY.SMIL.MIL
1CAB1CD
1ID
1ID.DS.ARMY.MIL
1ID.DS.ARMY.SMIL.MIL
1ID
1BCT1ID
1BCT1ID.DS.ARMY.MIL
1BCT1ID.DS.ARMY.SMIL.MIL
1BCT1ID
2BCT1ID
2BCT1ID.DS.ARMY.MIL
2BCT1ID.DS.ARMY.SMIL.MIL
2BCT1ID
3BCT1ID
3BCT1ID.DS.ARMY.MIL
3BCT1ID.DS.ARMY.SMIL.MIL
3BCT1ID
4BCT1ID
4BCT1ID.DS.ARMY.MIL
4BCT1ID.DS.ARMY.SMIL.MIL
4BCT1ID
1CAB1ID
1CAB1ID.DS.ARMY.MIL
1CAB1ID.DS.ARMY.SMIL.MIL
1CAB1ID
2ID
2ID.DS.ARMY.MIL
2ID.DS.ARMY.SMIL.MIL
2ID
1BCT2ID
1BCT2ID.DS.ARMY.MIL
1BCT2ID.DS.ARMY.SMIL.MIL
1BCT2ID
2BCT2ID
2BCT2ID.DS.ARMY.MIL
2BCT2ID.DS.ARMY.SMIL.MIL
2BCT2ID
3BCT2ID
3BCT2ID.DS.ARMY.MIL
3BCT2ID.DS.ARMY.SMIL.MIL
3BCT2ID
4BCT2ID
4BCT2ID.DS.ARMY.MIL
4BCT2ID.DS.ARMY.SMIL.MIL
4BCT2ID
2CAB2ID
2CAB2ID.DS.ARMY.MIL
2CAB2ID.DS.ARMY.SMIL.MIL
2CAB2ID
3ID
3ID.DS.ARMY.MIL
3ID.DS.ARMY.SMIL.MIL
3ID
1BCT3ID
1BCT3ID.DS.ARMY.MIL
1BCT3ID.DS.ARMY.SMIL.MIL
1BCT3ID
2BCT3ID
2BCT3ID.DS.ARMY.MIL
2BCT3ID.DS.ARMY.SMIL.MIL
2BCT3ID
3BCT3ID
3BCT3ID.DS.ARMY.MIL
3BCT3ID.DS.ARMY.SMIL.MIL
3BCT3ID
4BCT3ID
4BCT3ID.DS.ARMY.MIL
4BCT3ID.DS.ARMY.SMIL.MIL
4BCT3ID
3CAB3ID
3CAB3ID.DS.ARMY.MIL
3CAB3ID.DS.ARMY.SMIL.MIL
3CAB3ID
4ID
4ID.DS.ARMY.MIL
4ID.DS.ARMY.SMIL.MIL
4ID
1BCT4ID
1BCT4ID.DS.ARMY.MIL
1BCT4ID.DS.ARMY.SMIL.MIL
1BCT4ID
2BCT4ID
2BCT4ID.DS.ARMY.MIL
2BCT4ID.DS.ARMY.SMIL.MIL
2BCT4ID
3BCT4ID
3BCT4ID.DS.ARMY.MIL
3BCT4ID.DS.ARMY.SMIL.MIL
3BCT4ID
4BCT4ID
4BCT4ID.DS.ARMY.MIL
4BCT4ID.DS.ARMY.SMIL.MIL
4BCT4ID
4CAB4ID
4CAB4ID.DS.ARMY.MIL
4CAB4ID.DS.ARMY.SMIL.MIL
4CAB4ID
7ID
7ID.DS.ARMY.MIL
7ID.DS.ARMY.SMIL.MIL
7ID
10ID
10ID.DS.ARMY.MIL
10ID.DS.ARMY.SMIL.MIL
10ID
1BCT10ID
1BCT10ID.DS.ARMY.MIL
1BCT10ID.DS.ARMY.SMIL.MIL
1BCT10ID
2BCT10ID
2BCT10ID.DS.ARMY.MIL
2BCT10ID.DS.ARMY.SMIL.MIL
2BCT10ID
3BCT10ID
3BCT10ID.DS.ARMY.MIL
3BCT10ID.DS.ARMY.SMIL.MIL
3BCT10ID
A-14
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Active Directory
4BCT10ID
4BCT10ID.DS.ARMY.MIL
4BCT10ID.DS.ARMY.SMIL.MIL
4BCT10ID
Table A-2. Forest names, domain names, and exchange organization names
of active component tactical deployable units (continued)
Exchange
NIPR Domain name (one per
SIPR Domain name (one per
Forest Name
Organization name
forest only)
forest only)
SIPR and NIPR
Divisions
10CAB10ID
10CAB10ID.DS.ARMY.MIL
10CAB10ID.DS.ARMY.SMIL.MIL
10CAB10ID
24ID
24ID.DS.ARMY.MIL
24ID.DS.ARMY.SMIL.MIL
24ID
25ID
25ID.DS.ARMY.MIL
25ID.DS.ARMY.SMIL.MIL
25ID
1BCT25ID
1BCT25ID.DS.ARMY.MIL
1BCT25ID.DS.ARMY.SMIL.MIL
1BCT25ID
2BCT25ID
2BCT25ID.DS.ARMY.MIL
2BCT25ID.DS.ARMY.SMIL.MIL
2BCT25ID
3BCT25ID
3BCT25ID.DS.ARMY.MIL
3BCT25ID.DS.ARMY.SMIL.MIL
3BCT25ID
4BCT25ID
4BCT25ID.DS.ARMY.MIL
4BCT25ID.DS.ARMY.SMIL.MIL
4BCT25ID
25CAB25ID
25CAB25ID.DS.ARMY.MIL
25CAB25ID.DS.ARMY.SMIL.MIL
25CAB25ID
82AB
82AB.DS.ARMY.MIL
82AB.DS.ARMY.SMIL.MIL
82AB
1BCT82AB
1BCT82AB.DS.ARMY.MIL
1BCT82AB.DS.ARMY.SMIL.MIL
1BCT82AB
2BCT82AB
2BCT82AB.DS.ARMY.MIL
2BCT82AB.DS.ARMY.SMIL.MIL
2BCT82AB
3BCT82AB
3BCT82AB.DS.ARMY.MIL
3BCT82AB.DS.ARMY.SMIL.MIL
3BCT82AB
4BCT82AB
4BCT82AB.DS.ARMY.MIL
4BCT82AB.DS.ARMY.SMIL.MIL
4BCT82AB
82CAB82AB
82CAB82AB.DS.ARMY.MIL
82CAB82AB.DS.ARMY.SMIL.MIL
82CAB82AB
101AA
101AA.DS.ARMY.MIL
101AA.DS.ARMY.SMIL.MIL
101AA
1BCT101AA
1BCT101AA.DS.ARMY.MIL
1BCT101AA.DS.ARMY.SMIL.MIL
1BCT101AA
2BCT101AA
2BCT101AA.DS.ARMY.MIL
2BCT101AA.DS.ARMY.SMIL.MIL
2BCT101AA
3BCT101AA
3BCT101AA.DS.ARMY.MIL
3BCT101AA.DS.ARMY.SMIL.MIL
3BCT101AA
4BCT101AA
4BCT101AA.DS.ARMY.MIL
4BCT101AA.DS.ARMY.SMIL.MIL
4BCT101AA
101CAB101AA
101CAB101AA.DS.ARMY.MIL
101CAB101AA.DS.ARMY.SMIL.MIL
101CAB101AA
159CAB101AA
159CAB101AA.DS.ARMY.MIL
159CAB101AA.DS.ARMY.SMIL.MIL
159CAB101AA
Separate Brigades
173ABBCT
173ABBCT.DS.ARMY.MIL
173ABBCT.DS.ARMY.SMIL.MIL
173ABBCT
2ACRCT
2ACRCT.DS.ARMY.MIL
2ACRCT.DS.ARMY.SMIL.MIL
2ACRCT
3ACRCT
3ACRCT.DS.ARMY.MIL
3ACRCT.DS.ARMY.SMIL.MIL
3ACRCT
11ACRCT
11ACRCT.DS.ARMY.MIL
11ACRCT.DS.ARMY.SMIL.MIL
11ACRCT
12CAB
12CAB.DS.ARMY.MIL
12CAB.DS.ARMY.SMIL.MIL
12CAB
Fires Brigades
4FSBDE
4FSBDE.DS.ARMY.MIL
4FSBDE.DS.ARMY.SMIL.MIL
4FSBDE
17FSBDE
17FSBDE.DS.ARMY.MIL
17FSBDE.DS.ARMY.SMIL.MIL
17FSBDE
18FSBDE
18FSBDE.DS.ARMY.MIL
18FSBDE.DS.ARMY.SMIL.MIL
18FSBDE
75FSBDE
75FSBDE.DS.ARMY.MIL
75FSBDE.DS.ARMY.SMIL.MIL
75FSBDE
212FSBDE
212FSBDE.DS.ARMY.MIL
212FSBDE.DS.ARMY.SMIL.MIL
212FSBDE
214FSBDE
214FSBDE.DS.ARMY.MIL
214FSBDE.DS.ARMY.SMIL.MIL
214FSBDE
CS Brigades (ME) (On 07 Nov 07, HQDA approved the re-designation of the Combat
Support Brigade (Maneuver Enhancement) to the "Maneuver Enhancement Brigade
(MEB)).
1CSBDEME
1CSBDEME.DS.ARMY.MIL
1CSBDEME.DS.ARMY.SMIL.MIL
1CSBDEME
2CSBDEME
2CSBDEME.DS.ARMY.MIL
2CSBDEME.DS.ARMY.SMIL.MIL
2CSBDEME
19 November 2008
FM 6-02.71
A-15
FOR OFFICIAL USE ONLY
Appendix A
3CSBDEME
3CSBDEME.DS.ARMY.MIL
3CSBDEME.DS.ARMY.SMIL.MIL
3CSBDEME
Table A-2. Forest names, domain names, and exchange organization names
of active component tactical deployable units (continued)
Exchange
NIPR Domain name (one per
SIPR Domain name (one per
Forest Name
Organization name
forest only)
forest only)
SIPR and NIPR
Sustainment Brigades
1CSBDE
1CSBDE.DS.ARMY.MIL
1CSBDE.DS.ARMY.SMIL.MIL
1CSBDE
3CSBDE
3CSBDE.DS.ARMY.MIL
3CSBDE.DS.ARMY.SMIL.MIL
3CSBDE
4CSBDE
4CSBDE.DS.ARMY.MIL
4CSBDE.DS.ARMY.SMIL.MIL
4CSBDE
7CSBDE
7CSBDE.DS.ARMY.MIL
7CSBDE.DS.ARMY.SMIL.MIL
7CSBDE
10CSBDE
10CSBDE.DS.ARMY.MIL
10CSBDE.DS.ARMY.SMIL.MIL
10CSBDE
15CSBDE
15CSBDE.DS.ARMY.MIL
15CSBDE.DS.ARMY.SMIL.MIL
15CSBDE
16CSBDE
16CSBDE.DS.ARMY.MIL
16CSBDE.DS.ARMY.SMIL.MIL
16CSBDE
29CSBDE
29CSBDE.DS.ARMY.MIL
29CSBDE.DS.ARMY.SMIL.MIL
29CSBDE
43CSBDE
43CSBDE.DS.ARMY.MIL
43CSBDE.DS.ARMY.SMIL.MIL
43CSBDE
45CSBDE
45CSBDE.DS.ARMY.MIL
45CSBDE.DS.ARMY.SMIL.MIL
45CSBDE
64CSBDE
64CSBDE.DS.ARMY.MIL
64CSBDE.DS.ARMY.SMIL.MIL
64CSBDE
82CSBDE
82CSBDE.DS.ARMY.MIL
82CSBDE.DS.ARMY.SMIL.MIL
82CSBDE
101CSBDE
101CSBDE.DS.ARMY.MIL
101CSBDE.DS.ARMY.SMIL.MIL
101CSBDE
501CSBDE
501CSBDE.DS.ARMY.MIL
501CSBDE.DS.ARMY.SMIL.MIL
501CSBDE
507CSBDE
507CSBDE.DS.ARMY.MIL
507CSBDE.DS.ARMY.SMIL.MIL
507CSBDE
593CSBDE
593CSBDE.DS.ARMY.MIL
593CSBDE.DS.ARMY.SMIL.MIL
593CSBDE
Table A-3. Forest names, domain names, and exchange organization names
of National Guard tactical deployable units
Exchange
NIPR Domain name (one
SIPR Domain name (one per
Forest Name
Organization name
per forest only)
forest only)
SIPR and NIPR
Divisions
28ID
28ID.DS.ARMY.MIL
28ID.DS.ARMY.SMIL.MIL
28ID
2BCT28ID
2BCT28ID.DS.ARMY.MIL
2BCT28ID.DS.ARMY.SMIL.MIL
2BCT28ID
55BCT28ID
55BCT28ID.DS.ARMY.MIL
55BCT28ID.DS.ARMY.SMIL.MIL
55BCT28ID
56BCT28ID
56BCT28ID.DS.ARMY.MIL
56BCT28ID.DS.ARMY.SMIL.MIL
56BCT28ID
28CAB28ID
28CAB28ID.DS.ARMY.MIL
28CAB28ID.DS.ARMY.SMIL.MIL
28CAB28ID
29ID
29ID.DS.ARMY.MIL
29ID.DS.ARMY.SMIL.MIL
29ID
116BCT29ID
116BCT29ID.DS.ARMY.MIL
116BCT29ID.DS.ARMY.SMIL.MIL
116BCT29ID
29CAB29ID
29CAB29ID.DS.ARMY.MIL
29CAB29ID.DS.ARMY.SMIL.MIL
29CAB29ID
34ID
34ID.DS.ARMY.MIL
34ID.DS.ARMY.SMIL.MIL
34ID
1BCT34ID
1BCT34ID.DS.ARMY.MIL
1BCT34ID.DS.ARMY.SMIL.MIL
1BCT34ID
2BCT34ID
2BCT34ID.DS.ARMY.MIL
2BCT34ID.DS.ARMY.SMIL.MIL
2BCT34ID
34CAB34ID
34CAB34ID.DS.ARMY.MIL
34CAB34ID.DS.ARMY.SMIL.MIL
34CAB34ID
35ID
35ID.DS.ARMY.MIL
35ID.DS.ARMY.SMIL.MIL
35ID
35CAB35ID
35CAB35ID.DS.ARMY.MIL
35CAB35ID.DS.ARMY.SMIL.MIL
35CAB35ID
36ID
36ID.DS.ARMY.MIL
36ID.DS.ARMY.SMIL.MIL
36ID
A-16
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Active Directory
56BCT36ID
56BCT36ID.DS.ARMY.MIL
56BCT36ID.DS.ARMY.SMIL.MIL
56BCT36ID
Table A-3. Forest names, domain names, and exchange organization names
of National Guard tactical deployable units (continued)
Exchange
NIPR Domain name (one
SIPR Domain name (one per
Forest Name
Organization name
per forest only)
forest only)
SIPR and NIPR
72BCT36ID
72BCT36ID.DS.ARMY.MIL
72BCT36ID.DS.ARMY.SMIL.MIL
72BCT36ID
36CAB36ID
36CAB36ID.DS.ARMY.MIL
36CAB36ID.DS.ARMY.SMIL.MIL
36CAB36ID
38ID
38ID.DS.ARMY.MIL
38ID.DS.ARMY.SMIL.MIL
38ID
38CAB38ID
38CAB38ID.DS.ARMY.MIL
38CAB38ID.DS.ARMY.SMIL.MIL
38CAB38ID
40ID
40ID.DS.ARMY.MIL
40ID.DS.ARMY.SMIL.MIL
40ID
2BCT40ID
2BCT40ID.DS.ARMY.MIL
2BCT40ID.DS.ARMY.SMIL.MIL
2BCT40ID
40CAB40ID
40CAB40ID.DS.ARMY.MIL
40CAB40ID.DS.ARMY.SMIL.MIL
40CAB40ID
42ID
42ID.DS.ARMY.MIL
42ID.DS.ARMY.SMIL.MIL
42ID
27BCT42ID
27BCT42ID.DS.ARMY.MIL
27BCT42ID.DS.ARMY.SMIL.MIL
27BCT42ID
42CAB42ID
42CAB42ID.DS.ARMY.MIL
42CAB42ID.DS.ARMY.SMIL.MIL
42CAB42ID
Separate Brigades
116ACRCT
116ACRCT.DS.ARMY.MIL
116ACRCT.DS.ARMY.SMIL.MIL
116ACRCT
149BCT
149BCT.DS.ARMY.MIL
149BCT.DS.ARMY.SMIL.MIL
149BCT
155BCT
155BCT.DS.ARMY.MIL
155BCT.DS.ARMY.SMIL.MIL
155BCT
207BCT
207BCT.DS.ARMY.MIL
207BCT.DS.ARMY.SMIL.MIL
207BCT
218BCT
218BCT.DS.ARMY.MIL
218BCT.DS.ARMY.SMIL.MIL
218BCT
256BCT
256BCT.DS.ARMY.MIL
256BCT.DS.ARMY.SMIL.MIL
256BCT
26BCT
26BCT.DS.ARMY.MIL
26BCT.DS.ARMY.SMIL.MIL
26BCT
278ACRCT
278ACRCT.DS.ARMY.MIL
278ACRCT.DS.ARMY.SMIL.MIL
278ACRCT
29BCT
29BCT.DS.ARMY.MIL
29BCT.DS.ARMY.SMIL.MIL
29BCT
30BCT
30BCT.DS.ARMY.MIL
30BCT.DS.ARMY.SMIL.MIL
30BCT
32BCT
32BCT.DS.ARMY.MIL
32BCT.DS.ARMY.SMIL.MIL
32BCT
33BCT
33BCT.DS.ARMY.MIL
33BCT.DS.ARMY.SMIL.MIL
33BCT
37BCT
37BCT.DS.ARMY.MIL
37BCT.DS.ARMY.SMIL.MIL
37BCT
39BCT
39BCT.DS.ARMY.MIL
39BCT.DS.ARMY.SMIL.MIL
39BCT
41BCT
41BCT.DS.ARMY.MIL
41BCT.DS.ARMY.SMIL.MIL
41BCT
45BCT
45BCT.DS.ARMY.MIL
45BCT.DS.ARMY.SMIL.MIL
45BCT
48BCT
48BCT.DS.ARMY.MIL
48BCT.DS.ARMY.SMIL.MIL
48BCT
50BCT
50BCT.DS.ARMY.MIL
50BCT.DS.ARMY.SMIL.MIL
50BCT
53BCT
53BCT.DS.ARMY.MIL
53BCT.DS.ARMY.SMIL.MIL
53BCT
58BCT
58BCT.DS.ARMY.MIL
58BCT.DS.ARMY.SMIL.MIL
58BCT
76BCT
76BCT.DS.ARMY.MIL
76BCT.DS.ARMY.SMIL.MIL
76BCT
81BCT
81BCT.DS.ARMY.MIL
81BCT.DS.ARMY.SMIL.MIL
81BCT
86BCT
86BCT.DS.ARMY.MIL
86BCT.DS.ARMY.SMIL.MIL
86BCT
92BCT
92BCT.DS.ARMY.MIL
92BCT.DS.ARMY.SMIL.MIL
92BCT
19 November 2008
FM 6-02.71
A-17
FOR OFFICIAL USE ONLY
Appendix A
Table A-3. Forest names, domain names, and exchange organization names
of National Guard tactical deployable units (continued)
Exchange
NIPR Domain name (one
SIPR Domain name (one per
Forest Name
Organization name
per forest only)
forest only)
SIPR and NIPR
Fires Brigades
45FSBDE
45FSBDE.DS.ARMY.MIL
45FSBDE.DS.ARMY.SMIL.MIL
45FSBDE
65FSBDE
65FSBDE.DS.ARMY.MIL
65FSBDE.DS.ARMY.SMIL.MIL
65FSBDE
138FSBDE
138FSBDE.DS.ARMY.MIL
138FSBDE.DS.ARMY.SMIL.MIL
138FSBDE
142FSBDE
142FSBDE.DS.ARMY.MIL
142FSBDE.DS.ARMY.SMIL.MIL
142FSBDE
169FSBDE
169FSBDE.DS.ARMY.MIL
169FSBDE.DS.ARMY.SMIL.MIL
169FSBDE
197FSBDE
197FSBDE.DS.ARMY.MIL
197FSBDE.DS.ARMY.SMIL.MIL
197FSBDE
CS Brigades (ME)
110CSBDEME
110CSBDEME.DS.ARMY.MIL
110CSBDEME.DS.ARMY.SMIL.MIL
110CSBDEME
111CSBDEME
111CSBDEME.DS.ARMY.MIL
111CSBDEME.DS.ARMY.SMIL.MIL
111CSBDEME
130CSBDEME
130CSBDEME.DS.ARMY.MIL
130CSBDEME.DS.ARMY.SMIL.MIL
130CSBDEME
136CSBDEME
136CSBDEME.DS.ARMY.MIL
136CSBDEME.DS.ARMY.SMIL.MIL
136CSBDEME
142CSBDEME
142CSBDEME.DS.ARMY.MIL
142CSBDEME.DS.ARMY.SMIL.MIL
142CSBDEME
157CSBDEME
157CSBDEME.DS.ARMY.MIL
157CSBDEME.DS.ARMY.SMIL.MIL
157CSBDEME
225CSBDEME
225CSBDEME.DS.ARMY.MIL
225CSBDEME.DS.ARMY.SMIL.MIL
225CSBDEME
Sustainment Brigades
34CSBDE
34CSBDE.DS.ARMY.MIL
34CSBDE.DS.ARMY.SMIL.MIL
34CSBDE
36CSBDE
36CSBDE.DS.ARMY.MIL
36CSBDE.DS.ARMY.SMIL.MIL
36CSBDE
38CSBDE
38CSBDE.DS.ARMY.MIL
38CSBDE.DS.ARMY.SMIL.MIL
38CSBDE
40CSBDE
40CSBDE.DS.ARMY.MIL
40CSBDE.DS.ARMY.SMIL.MIL
40CSBDE
67CSBDE
67CSBDE.DS.ARMY.MIL
67CSBDE.DS.ARMY.SMIL.MIL
67CSBDE
108CSBDE
108CSBDE.DS.ARMY.MIL
108CSBDE.DS.ARMY.SMIL.MIL
108CSBDE
230CSBDE
230CSBDE.DS.ARMY.MIL
230CSBDE.DS.ARMY.SMIL.MIL
230CSBDE
287CSBDE
287CSBDE.DS.ARMY.MIL
287CSBDE.DS.ARMY.SMIL.MIL
287CSBDE
369CSBDE
369CSBDE.DS.ARMY.MIL
369CSBDE.DS.ARMY.SMIL.MIL
369CSBDE
371CSBDE
371CSBDE.DS.ARMY.MIL
371CSBDE.DS.ARMY.SMIL.MIL
371CSBDE
Table A-4 Forest names, domain names, and exchange organization names
of US Army Reserve tactical deployable units
Exchange
NIPR Domain name (one
SIPR Domain name (one per
Forest Name
Organization name
per forest only)
forest only)
SIPR and NIPR
CS Brigades (ME)
301CSBDEME
301CSBDEME.DS.ARMY.MIL
301CSBDEME.DS.ARMY.SMIL.MIL
301CSBDEME
302CSBDEME
302CSBDEME.DS.ARMY.MIL
302CSBDEME.DS.ARMY.SMIL.MIL
302CSBDEME
303CSBDEME
303CSBDEME.DS.ARMY.MIL
303CSBDEME.DS.ARMY.SMIL.MIL
303CSBDEME
Sustainment Brigades
55CSBDE
55CSBDE.DS.ARMY.MIL
55CSBDE.DS.ARMY.SMIL.MIL
55CSBDE
158CSBDE
158CSBDE.DS.ARMY.MIL
158CSBDE.DS.ARMY.SMIL.MIL
158CSBDE
A-18
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Active Directory
Table A-4 Forest names, domain names, and exchange organization names
of US Army Reserve tactical deployable units (continued)
Exchange
NIPR Domain name (one
SIPR Domain name (one per
Forest Name
Organization name
per forest only)
forest only)
SIPR and NIPR
162CSBDE
162CSBDE.DS.ARMY.MIL
162CSBDE.DS.ARMY.SMIL.MIL
162CSBDE
164CSBDE
164CSBDE.DS.ARMY.MIL
164CSBDE.DS.ARMY.SMIL.MIL
164CSBDE
300CSBDE
300CSBDE.DS.ARMY.MIL
300CSBDE.DS.ARMY.SMIL.MIL
300CSBDE
304CSBDE
304CSBDE.DS.ARMY.MIL
304CSBDE.DS.ARMY.SMIL.MIL
304CSBDE
321CSBDE
321CSBDE.DS.ARMY.MIL
321CSBDE.DS.ARMY.SMIL.MIL
321CSBDE
474CSBDE
474CSBDE.DS.ARMY.MIL
474CSBDE.DS.ARMY.SMIL.MIL
474CSBDE
A-40. Tables A-5 through A-7 are the abbreviations used in Tables A-2 through A-4, respectively.
Table A-5. Abbreviations for Table A-2
Active Component
Abbreviation
1st Armored Division
1AD
1st Cavalry Division
1CD
1st Infantry Division
1ID
2d Infantry Division
2ID
3d Infantry Division
3ID
4th Infantry Division
4ID
7th Infantry Division
7ID
10th Infantry Division
10ID
24th Infantry Division
24ID
25th Infantry Division
25ID
82d Airborne Division
82AB
101st Air Assault Division
101AA
Table A-6. Abbreviations for Table A-3
Army National Guard/Reserve
Abbreviation
28th Infantry Division
28ID
29th Infantry Division
29ID
34th Infantry Division
34ID
35th Infantry Division
35ID
36th Infantry Division (old 49AD)
36ID
38th Infantry Division
38ID
40th Infantry Division
40ID
42d Infantry Division
42ID
19 November 2008
FM 6-02.71
A-19
FOR OFFICIAL USE ONLY
Appendix A
Table A-7. Abbreviations for Table A-4
Term
Abbreviation
Air Assault
AA
Airborne
AB
Airborne Brigade Combat Team
ABCT
Armored Cavalry Regiment Combat Team
ACRCT
Air Defense
AD
Brigade Combat Team
BCT
Brigade
BDE
Combat Aviation Brigade
CAB
Cavalry Division
CD
Combat Support
CS
Fire Support
FS
Infantry Division
ID
Maneuver Enhancement
ME
Multi-Function Aviation Brigade
MFAB
A-20
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
Appendix B
NETWORK OPERATIONS SYSTEMS AND TOOLS
This appendix addresses the different systems and tools available to perform the
required NETOPS functions. It is separated by the tools used in the A-GNOSC and
TNOSC and into three other distinct areas: ESM/NM, IA/CND, and IDM/CS.
APPROVED NETWORK OPERATIONS TOOLS FOR NETWORK
OPERATIONS AND SECURITY CENTERS.
B-1. The list in Table B-1 defines the minimum approved NETOPS tools for use in the AGNOSCs and
TNOSCs with respect to capabilities outlined in the AENIA. This list will be reviewed on a quarterly basis
or sooner, if required.
B-2. The NETCOM Chief, NETOPS Planning Division will establish an action officer level NOSC
working group under the AEI Technical Configuration Control Board. The NOSC working group will
include representation from the requirements, material development and user communities. The NOSC
working group will establish specific CIs; manage specific changes and updates to the listed set of tools via
a CM process.
B-3. NOSCs not operating on these standard tools will develop migration plans ICW the NOSC working
group to comply with the stated standard.
B-4. Functional Proponent for the AENIA and NOSC NETOPS tools is the chief, NETOPS planning
division NETCOM at commercial: (520) 533-1 852, DSN: 821-1852.
Table B-1. A-GNOSC and TNOSC NETOPS tools list
AENIA Capability
Capability Description
NOSC Standard
Comments
Anti-Virus (Anti-
This system provides an
Three DOD Anti-Virus
McAfee ePolicy
Malware)
enterprise view and
standards: Symantec,
Orchestrator
management capability
McAfee, and TrendMicro.
Entercept is
for anti-virus and anti-
undergoing
malware.
DISA/Army pilot.
DOD CND enterprise-wide
solutions steering group has
selected McAfee ePolicy
Orchestrator Entercept as
standard for Host-Based
Security System which
includes anti-virus
management and Computer
Associates Pest Patrol to
provide a standard
Adware/Spyware capability.
19 November 2008
FM 6-02.71
B-1
FOR OFFICIAL USE ONLY
Appendix B
Table B-1. A-GNOSC and TNOSC NETOPS tools list (continued)
AENIA Capability
Capability Description
NOSC Standard
Comments
Capacity,
This system provides the
eHealth (Computer
Additional
Availability and
capability to monitor and
Associates)
capacity,
Performance
analyze capacity and
availability and
Monitoring
availability information
performance
System
collected by other
monitoring tool
systems and stored in
standards are
this system.
anticipated to
support this
capability.
CM
This system provides a
Remedy Information
Database/Support
great deal of
Technology Service
System
functionality. The
Management
functionality can be
broken down into 4
broad areas:
incident/problem/service
request management,
operational asset
management, change
management and other
supporting features.
Host IDS
This system provides the
Symantec Intruder
The current
capability for an agent to
Alert/Enterprise Security
standard for Host
monitor host activities
Manager DOD CND
IDS/ Host
and identify those
enterprise-wide solutions
Intrusion
activities that have been
steering group has selected
Prevention
identified as being
McAfee ePolicy
System is
potentially hostile. The
Orchestrator/Entercept as
Symantec Intruder
potentially hostile
standard under the Host-
Alert/Enterprise
activities are reported to
Based Security System
Security Manager.
a management console
initiative to provide a standard
for analysis.
host intrusion detection and
NETCOM will
host-based firewall capability.
migrate to the
DISA/Army Host-
Based Security
System standard
upon successful
completion of the
DISN/Army pilot.
B-2
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
NETWORK OPERATIONS SYSTEMS AND TOOLS
Table B-1. A-GNOSC and TNOSC NETOPS tools list (continued)
AENIA Capability
Capability Description
NOSC Standard
Comments
Host Intrusion
This system provides the
Symantec Intruder
The current
Prevention
capability for an agent to
Alert/Enterprise Security
standard for Host
System
monitor host activities
Manager DOD CND
IDS/Host Intrusion
and identify potentially
enterprise-wide solutions
Prevention
hostile activities.
steering group has selected
System is
Predefined remedial
McAfee ePolicy
Symantec Intruder
actions are then taken to
Orchestrator/Entercept as
Alert/Enterprise
mitigate the impact of
standard under the Host-
Security Manager.
these activities on the
Based Security System
operational system. The
initiative to provide a standard
NETCOM will
identification and
host intrusion prevention and
migrate to the
mitigation of potentially
host-based firewall capability.
DISA/Army Host-
hostile activities are
Based Security
reported to a
System standard
management console for
upon successful
analysis.
completion of the
DISA/Army pilot.
IP Network
This system provides a
Spectrum Network
Management
network monitoring and
Management System
System
graphical display
(Computer Associates)
capability. It is the only
system that collects
Simple Network
Management Protocol
data from devices
connected to the
network.
SA
This system provides the
Formula (Managed Objects)
capability for non-IT staff
to understand the impact
of IT services on the
theater's operational
mission. It receives
status information from
sources external to the
Army from the Army
level situation
awareness System. The
situation awareness at
the Army level receives
status information from
sources external to the
Army and passes this
external status
information to the
theater situation
awareness.
19 November 2008
FM 6-02.71
B-3
FOR OFFICIAL USE ONLY
Appendix B
Table B-1. A-GNOSC and TNOSC NETOPS tools list (continued)
AENIA Capability
Capability Description
NOSC Standard
Comments
Network IDS
This system provides the
Internet Security Systems
NETCOM has
capability for an agent or
SiteProtector; Snort
initiated a plan to
device to monitor
replace existing
network traffic and to
Network IDS with
identify traffic that has
Network Intrusion
been identified as being
Prevention
potentially hostile. The
Systems.
potentially hostile traffic
is reported to a
management console for
analysis.
Network Intrusion
This system provides the
To Be Determined
NETCOM has
Prevention
capability for an agent or
initiated a plan to
System
device to monitor
replace existing
network traffic and to
Network IDSs with
identify and mitigate
Network Intrusion
traffic that has been
Prevention
identified as being
Systems.
potentially hostile. The
potentially hostile traffic
is reported to a
management console for
analysis
Secure
This system provides the
Citadel Hercules
Citadel Hercules
Configuration
capability to define
selected by DOD
Remediation
configuration conditions
CND enterprise-
Windows Environment-
(Patch)
and responses. It may
wide solutions
Microsoft Systems
Management
change system
steering group.
Management Server
configuration or install
DOD acquisition
patches to existing
includes
software.
Enterprise
License for
software, and on-
line training.
Systems
Management
Server 3rd Party
Bolt-on being
considered for
Non-Windows
Environment
Enterprise
solution.
B-4
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY
NETWORK OPERATIONS SYSTEMS AND TOOLS
Table B-1. A-GNOSC and TNOSC NETOPS tools list (continued)
AENIA Capability
Capability Description
NOSC Standard
Comments
Security
This system provides the
Arcsight (Arcsight)
DOD CND
Information
capability to receive
enterprise-wide
Management
events from a large
solutions steering
System
number of other
group is currently
commercial operations
researching a Tier
and security related
3 Systems
products. These events
Management
are then correlated to all
Server solution to
of the other events it has
support
received from all of its
post/camp/station
other sources.
and enclaves.
Systems
This system provides the
Windows Desktop
Systems
Management
capability to monitor and
Environment-Microsoft
Management
manage various aspects
Systems Management Server
Server/Microsoft
of computing platforms
Operations
(both servers and
Management 3rd
Windows Server
desktops). It provides an
Party Bolt-on
Environment-Microsoft
inventory and
being considered
Systems Management Server
configuration capability,
for Non-Windows
and Microsoft Operations
a software distribution
Environment
Management
capability, and a
Enterprise
condition monitoring
solution.
capability.
IP Network
This system provides the
eEye Retina
eEye Retina
Vulnerability
capability to define a
selected by DOD
Scanner
number of different
CND enterprise-
scanning profiles. These
wide solutions
scanning profiles should
steering group.
be related to the
DOD acquisition
compliance baselines
includes
established in the
Enterprise
compliance manager.
License for
The system then
software, and on-
interrogates systems
line training.
using a number of
different means to
determine how
vulnerable the system is
to the scanning criteria.
GLOBAL INFORMATION GRID ENTERPRISE MANAGEMENT AND
LANDWARNET SYSTEMS AND TOOLS
B-5. The ESM/NM and LWN systems and tools will be available to the management personnel. Many of
the systems and tools may be listed more than once due to the tool being a subsystem to other management
systems as well as a stand alone tool used for other functions in the networks. The NM/ESM and LWN
systems and tools are:
z
CISCO Call Manager is a software-based call processing component providing signaling and call
control services to Cisco integrated telephony applications (e.g., VG-248 subscribers, Cisco IP
Phones, or Cisco IP softphones). The Call Manager also registers with the Vantage as a gateway.
19 November 2008
FM 6-02.71
B-5
FOR OFFICIAL USE ONLY
Appendix B
The JNN Call Manager is physically associated to a particular security domain by keyboard
video monitor and Ethernet connectivity to that domain. The JNN Call Manager software
function is hosted on a rack mounted computer and has a single Ethernet connection to the Tier 2
router Ethernet switch module. There are two Call Managers in the shelter: one dedicated for
NIPR and another for SIPR.
z
Cisco Call Manager Version 3.3(2) software provides the call management function. The Cisco
Call Manager’s primary functions are: call processing, signaling and device control, dial plan
administration, and phone feature administration. The Cisco Call Manager is a main component
in the shelter voice architecture.
B-6. Network Management-Element and Node Planning and Management platform is present within each
security domain
(NIPR and SIPR). The node manager provides monitoring and control capabilities
reporting on the condition of the router and network components. In addition, the node manager platform
provides the capability to build and save Cisco device configurations (router's and firewall) based upon
mission specific criteria. A Denika Multi-Router Traffic Grapher application shall be provided for the
purpose of monitoring bandwidth utilization. The JNN manager platform is designed to operate on a laptop
computer with the following software installed:
z
Ciscoworks for Small Network Management Systems includes:
„ Resource Manager Essentials 3.3.
„ CiscoView 5.3.
z
WhatsUp Gold.
z
Multi-Router Traffic Grapher v3.0.1.210.
z
Warfighter Machine Interface.
B-7. CiscoWorks for Small Network Management Systems is an end-to-end network management
solution. It is ideal for small networks that may include two or three branches. It also provides management
capabilities that simplify network administration. CiscoWorks for Small Network Management Systems
enables network operators to efficiently and effectively manage the network through a simplified browser-
based interface that can be accessed anytime and anywhere within the network. CiscoWorks for Small
Network Management Systems provides tools that make the job of configuring, monitoring, and
troubleshooting routers and switches quicker in order to reduce the likelihood of human errors.
B-8. The functionality of CiscoWorks for Small Network Management Systems can be categorized under
three functional areas: network discovery and policy management, device configuration, and device
management. Network discovery and policy management is performed using the WhatsUp Gold software
package. Device configuration tasks are performed using the CiscoView software package, and device
management is performed using the Resource Manager Essentials software package.
B-9. Resource Manager Essentials 3.3 is a suite of Web-based applications offering network management
solutions for Cisco switches, access servers, and routers. Resource Manager Essentials is comprised of
several applications which are discussed below.
B-10. The inventory manager, is responsible for—
z
Up-to-date inventory of all Cisco devices in the network.
z
Hardware and software summary information as well as detailed reports for groups of devices,
including device name, chassis type, memory, flash, and software version or characteristics.
z
Capacity planning information by identifying the total number of free and used slots in many
Cisco devices.
z
Multi-service port report on the number and location of Catalyst® switches that are multi-service
port-enabled.
B-11. The device configuration manager maintains an active archive and simplifies deployment of
configuration changes to multiple devices. It consists of the following subcomponents:
z
Configuration Archive—
B-6
FM 6-02.71
19 November 2008
FOR OFFICIAL USE ONLY

 

 

 

 

 

 

 

Content      ..     30      31      32      33     ..