MEETING WITH DON LATHAM DUSD (C3I) REGARDING JOINT IC/DDD COMPUTER SECURITY PROJECT

Document Type: 
Collection: 
Document Number (FOIA) /ESDN (CREST): 
CIA-RDP85M00364R000400510033-9
Release Decision: 
RIPPUB
Original Classification: 
S
Document Page Count: 
4
Document Creation Date: 
January 4, 2017
Document Release Date: 
April 14, 2008
Sequence Number: 
33
Case Number: 
Publication Date: 
May 17, 1983
Content Type: 
MEMO
File: 
AttachmentSize
PDF icon CIA-RDP85M00364R000400510033-9.pdf104.72 KB
Body: 
Approved For Release 2008/04/14: CIA-RDP85M00364R000400510033-9 ICS 83-4018 17 May 1983 MEMORANDUM FOR: D/PPS FROM: SUBJECT: IHC Meeting with Don Latham, DUSD (C31), regarding Joint IC/DOD Computer Security Project 1. On 11 April 1983, following DOD representatives Computer Security Project: o Don Latham o Steve Walker ind I met with the to discuss the Intelligence ommunity (IC) o Col. John Lane Deputy Under Secretary of Defense (C31I) Director, Information Systems DUSD (C I) Deputy Director, Information Systems DUSD (Cal) (U) 25X1 2 . Mr. Latham and the other DOD representatives were briefed b f the joint IC/DOD Computer on the scope and nature o Security Project an ered their support of the effort. Mr. Latham agreed that DCID 1/16 is not adequate to address today's processing environment and d to be developed. He also agreed with that new policies and guidelines nee the need to provide guidelines to tell people how and where to go to get their s of materials. There was a t ype systems accredited for processing various general discussion of the difference between the terms certification and accreditation. noted the following: o Certification can be compared to the services that Underwriters Laboratories (UL) performs in industry. UL establishes certain standards for various types of equipment and then conducts tests on a sample set of that equipment to insure that manufacturers are continuing to develop products in accordance with these standards. Electrical equipment is thereby certified for use by , ification process l a, %-e- the American public. In general a,simi o Accreditation can be compared to the process that a city inspector goes through when he inspects the materials in a new home and determines that the home meets or exceeds the minimal standards specified in the city's building codes. Accreditation tem (home) which l e sys is a specific process of reviewing a sing nents " " . compo certified is built using several 3. noted that CSEC's efforts to certify computer systems are ^25X1 just getting un er y. He also noted that the proposed effort b r n r T Approved For Release 2008/04/14: CIA-RDP85M00364R000400510033-9 SECRET Approved For Release 2008/04/14: CIA-RDP85M00364R000400510033-9 would address the issue of expanding the role of the Center to include all intPlliaence components, including CIA, 75X1 25X1 25X1 4. explained that the effort would include threat assessments 25X1 for three different groups: o A highly sensitive threat assessment to be developed for a very limited number of appropriate officials. o A somewhat refined assessment at a high level of classification that can be reviewed by a larger number of people. o A sanitized and summarized threat assessment produced at a lower level of classification that can be reviewed by a larger number of people including industrial participants. 25X1 8. Steve Walker asked if the effort would be limited to the intelligence organizations since it was an Intelligence Community sponsored effort. He ...,+,..a +6,+ nnl;, fnr nrnra inn intPlliaence data is covered under DCID 1/16, 25X1 noted that the effort would be broader 25X1 organizations since military COI networks transmit and store intelligence data derived from IC sources. dentified this as the reason we were 25X1 9 Approved For Release 2008/04/14: CIA-RDP85M00364R000400510033-9 Approved For Release 2008/04/14: CIA-RDP85M00364R000400510033-9 seeking C3I,s support for the effort. Mi. Walker noted the difficulty of the task if we tried to address the entire C I problem. He suggested that we focus on the "I" portion of the problem and that we develop strong and effective policies that could be used to influence the C side of the house. 9. Mr. Latham again supported the effort and dirgcted that either Steve Walker or Col. John Lane be the point of contac 25X1 LJ/\1 3 SECRET Approved For Release 2008/04/14: CIA-RDP85M00364R000400510033-9 Approved For Release 2008/04/14: CIA-RDP85M00364R000400510033-9 Approved For Release 2008/04/14: CIA-RDP85M00364R000400510033-9