Course

Credit Type:
Course
ACE ID:
DAU-0381
Version:
1
Organization's ID:
ACQ 1600/ENG 260
Location:
Online
Length:
21 hours
Minimum Passing Score:
80
ACE Credit Recommendation Period:
Credit Recommendation & Competencies
Level Credits (SH) Subject
Lower-Division Baccalaureate 3 Cybersecurity Risk Management
Description

Objective:

The objective of the Program Protection Planning Awareness (ACQ 1600) course is to emphasize the principles and policies of system security engineering. Program protection planning requires each acquisition’s integrated product team to prevent, detect, and respond to program protection challenges. This course provides training on threats, vulnerabilities, risks, cost-benefit risk trade-offs, and required mitigations for Department of War (DoW) systems. It also addresses supply chain management and the need for acquisition program protection documents such as the Program Protection Plan, Cybersecurity Strategy, and security plans.

The objective of the Program Protection for Practitioners (ENG 260) course is to provide program protection (PP) and System Security Engineering (SSE) training, with an emphasis on exercises. The online exercises help focus students on acquisition program scenarios to accomplish PP planning and SSE actions to support Information and Critical Program Information (CPI). and Trusted Systems and Networks (TSN) Analyses. Students have to identify, prevent, and respond to PP and SSE challenges during the acquisition process during this course work. Students learn how to identify information, CPI, mission critical functions, and mission critical components to protect. They encounter system threats, vulnerabilities, risks, and test and evaluation challenges. Students also gain focus on how system engineering technical reviews (SETRs) can be used to assess information, CPI, and TSN countermeasures and security risks. Topics such as security specialties, cybersecurity, hardware assurance, software assurance, anti-tamper, and others are presented.

Learning Outcomes:

  • Recognize that the system security solution approach includes risk-based prevention, detection and response to system security threats and vulnerabilities.
  • Recognize system security threats and consequences to acquisition programs and that the system security solution approach includes risk-based prevention, detection, and response to system security threats.
  • Define critical program information (CPI), CPI policy, CPI threat definition, and associated attacks.
  • Identify trusted system and network threat definitions, associated attacks, and policy.
  • Given DoDI 5000.02, recognize the requirement of the Program Protection Plan (PPP) within the Acquisition Life Cycle and how program protection is incorporated into the Request for Proposal (RFP).
  • In accordance with DoDI 5000.02, recognize how program protection integrates system security engineering specialties and security specialties through a high-level overview of each specialty's activities and outputs.
  • Recognize the elements of Critical Protection Information (CPI) analysis for security implementation.
  • Define how the National Industrial Security Program Operating Manual (NISPOM) activities are incorporated into the Request for Proposal (RFP).
  • Given DoDI 5200.39 and 5200.44, recognize the impact of System Security Engineering (SSE) analyses on the technical baselines and systems engineering technical reviews.
  • Describe program protection test and evaluation (T&E) activities and capabilities.
  • Recognize the elements of Information Analysis for acquisition programs in accordance with DoD Instruction (DoDI) 5000.83, DoDI 5200.48, and Defense Federal Acquisition Regulation Supplement (DFARS) Clauses 252.204-7008, 252.204-7009, 252.204-7012, 252.204-7019, and 252.204-7020.
  • Apply Trusted Systems and Networks (TSN) Analyses to protect mission-critical functions for given Major Capability Acquisition life cycle scenarios and applicable DoDI 5000.02 acquisition pathways in accordance with DoD Instructions (DoDI) 5000.02, 5000.83, and 5200.44.
  • Given DoD Instructions (DoDI) 5000.83, 5200.39, and 5200.44, apply systems security engineering (SSE), to include program protection planning and analysis across the Major Capability Acquisition life cycle as well as each of the systems engineering baselines and technical reviews.
  • Recognize that program protection is most effective when begun early in, and addressed throughout, the program lifecycle by integrating protections from system security engineering and the security specialties to provide a defense-in-depth security solution.

General Topics:

  • System Security Threats
  • Risk-based Prevention
  • Critical Program Information (CPI)
  • Program Protection Measures & Analyses
  • Malicious Insertion Threats
  • Program Protection Plan (PPP)
  • Request for Proposal (RFP)
  • Acquisition Lifecycle
  • System Security Engineering (SSE)
  • Protection, Test & Evaluation
  • Requirements Analysis
Instruction & Assessment

Instructional Strategies:

  • Audio Visual Materials
  • Case Studies
  • Practical Exercises
  • Work-based Learning

Methods of Assessment:

  • Case Studies
  • Examinations
  • Quizzes
Supplemental Materials
Equivalencies

Other offerings from Defense Acquisition University - now Warfighting Acquisition University (WarU)