secure questionnaire 10 1.0

54
UNCLASSIFIED PROFILING QUESTIONNAIRE DISRonline 10-1.0 Be aware not all questions have a standard associated with them. Access Control Does your system interface with the Defense Message System? FORTEZZA ICD, ACP 120 1 Does your system use FORTEZZA Cryptographic algorithms? IETF RFC 2743, FORTEZZA CIPG 1.52, FORTEZZA Application 2 Will your system implement or support DoD PKI? ITU-T X.509:2005 3 Do your individual messages use certificates issued by DoD PKI to protect unclassified sensitive or sensitive information? IETF RFC 2634 4 Does your system require encrypted algorithms and FORTEZZA applications are in use? SKIPJACK/KEA 5 Does your system require signature algorithms? FIPS Pub 186-2, FIPS Pub 186-3 6 Does your system require secure hash algorithms? NIST FIPS Pub 180-3 7 Does your system require PKI Cryptography? FIPS Pub 140-2, FIPS Pub 197 8 Will access to a system be based on a particular role, rather than an individuals credentials? ANSI/INCITS 359-2004 9 Does this application require the use of RFID or smart cards and does it need to be FIPS 201 compliant? ISO/IEC 14443-3:2001 w/ Amd1:2005, Amd1/Cor1:2006, Amd3:2006, ISO/IEC 14443-2:2001 w/ Amd 1:2005 10 Does your system need to transmit event messages? IETF RFC 3195 11 Application-Oriented (GPS) Does your system require GPS standard positioning services? IS-GPS-200D 1 Does your system require GPS precise positioning services? ICD-GPS-227 2 Does your Aviation system use Global Positioning for navigation/landing and will an FAA certification be required? RTCA DO-208 3 Does your Aviation system use Global Positioning for navigation/landing and will interoperability in a NATO environment be required? STANAG 4294 4 Are you creating equipment that will require time stamping? IRIG Standard 200-04 5 Does your system provide emergency position indicating radio services or operate on 406 MHz transmit or receive data via the COSPAS-SARSAT system? COSPAS-SARSAT C/S T.001 Iss.3 Rev.8, COSPAS-SARSAT C/S T.007 Iss.4 Rev.2 6 Application-specific Data Interchange Page 1 of 54 UNCLASSIFIED Valid Date Promulgation Memo Signed

Upload: xyrate

Post on 23-Oct-2014

133 views

Category:

Documents


9 download

TRANSCRIPT

Page 1: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Access Control

Does your system interface with the Defense Message System?

FORTEZZA ICD, ACP 120 1

Does your system use FORTEZZA Cryptographic algorithms? IETF RFC 2743, FORTEZZA CIPG 1.52, FORTEZZA Application

2

Will your system implement or support DoD PKI? ITU-T X.509:20053

Do your individual messages use certificates issued by DoD PKI to protect unclassified sensitive or sensitive information?

IETF RFC 26344

Does your system require encrypted algorithms and FORTEZZA applications are in use?

SKIPJACK/KEA5

Does your system require signature algorithms? FIPS Pub 186-2, FIPS Pub 186-36

Does your system require secure hash algorithms? NIST FIPS Pub 180-37

Does your system require PKI Cryptography? FIPS Pub 140-2, FIPS Pub 1978

Will access to a system be based on a particular role, rather than an individuals credentials?

ANSI/INCITS 359-20049

Does this application require the use of RFID or smart cards and does it need to be FIPS 201 compliant?

ISO/IEC 14443-3:2001 w/ Amd1:2005, Amd1/Cor1:2006, Amd3:2006, ISO/IEC 14443-2:2001 w/ Amd 1:2005

10

Does your system need to transmit event messages? IETF RFC 319511

Application-Oriented (GPS)

Does your system require GPS standard positioning services? IS-GPS-200D1

Does your system require GPS precise positioning services? ICD-GPS-2272

Does your Aviation system use Global Positioning for navigation/landing and will an FAA certification be required?

RTCA DO-2083

Does your Aviation system use Global Positioning for navigation/landing and will interoperability in a NATO environment be required?

STANAG 42944

Are you creating equipment that will require time stamping? IRIG Standard 200-045

Does your system provide emergency position indicating radio services or operate on 406 MHz transmit or receive data via the COSPAS-SARSAT system?

COSPAS-SARSAT C/S T.001 Iss.3 Rev.8, COSPAS-SARSAT C/S T.007 Iss.4 Rev.2

6

Application-specific Data Interchange

Page 1 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 2: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Does your system interchange Atmospheric or Oceanographic data?

1

Does your system exchange weather product messages in Gridded Binary Form?

FM 92-X Ext. GRIB WMO No. 3062

Does your system exchange data in Binary Universal Format for Representation (BUFR)?

FM 94-X Ext. BUFR WMO No. 3063

Does your system exchange large or complex data sets between environmental data processing systems?

HDF v54

Do you need to exchange metadata or bibliographic information?

ISO 2709 5

Does your Combat Support system exchange fingerprint information with other systems?

ANSI/NIST-ITL 16

Will you be implementing a data distribution infrastructure using a publish/subscribe data centric model?

OMG formal/2007-01-017

Will you be implementing a data distribution infrastructure using a distributed object model via CORBA or do you require a deterministic, predictable, real time application that has its operating system priorities mapped at the application thread level?

OMG formal/2005-01-048

Is your organization planning to implement a standards-based all-hazard emergency alerting and warning notification system?

OASIS CAP-V1.19

Is your system responsible for the writing, reading or application of passive RFID tags?

DOD Non-commercial DID, RF-Tag v2.0, Passive RFID Air Interface Class 1, UHF Passive Tag Air Interface Class 0

10

Does your system require data interoperability? DDMS 2.011

Does your system require exchanging the C2 (or C4ISR) information among the US C2 systems, Coalition C2 Systems?

C2IEDM12

Is there a requirement for common, codified identification of the countries of the world?

ISO 3166-113

Do you order items that are measured in commercial contracts?

UNECE Recommendation No. 2014

Will you be transferring stored ISR data or using solid state or disk based removable memory modules or need to share data with NATO allies?

STANAG 4575 Ed. 315

Are you implementing a data distribution service infrastructure in your system that requires applications built with two different vendor DDS products to interoperate?

OMG formal/08-04-0916

Page 2 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 3: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Is your system a sensor used to detect chemical, biological, radiological, or nuclear threats or does the system interact with sensors used for defense against chemical, biological, radiological, or nuclear threats?

JPEO-CBD CCSI v1.017

Does your system need to publish a list of periodically updated summaries or need to provide light-weight event notification?

IETF RFC 502318

Architectures and Applications

Does your system implement a Public Key Infrastructure (PKI)?

1

Does your PKI require Medium Assurance certificate profiles? IETF RFC 2587, IETF RFC 5280, RSA PKCS #11 v2.20, RSA Labs PKCS #15:2000, FIPS Pub 140-2

2

Does your system require firewall devices in Basic Robustness environment?

Traffic Filtering Firewall - Low Risk, Application-level Firewall - Basic

3

Will your system utilize 3D Graphics or virtual reality applications?

ISO/IEC 19775-2:2004 , ISO/IEC 19775-1:2004

4

Does your system require firewall devices in Medium Robustness environment?

Application-level Firewall -Medium:2000, PP_FW_TF_MR_v1.1 (Traffic Filt. Firewall - Med. Robustness), PP_FWPP-MR

5

Does your system require general virtual link security? UML 2.2, IETF RFC 27436

Do you need to specify exact range of performance such as minimum and maximum speed or physical or other environmental (external) or internal constraints?

OMG OCL v2.07

Do you need a tool based on UML that uses the diagrams and vocabulary of Systems Engineering rather than Software Engineering or do you need rigorous parametric constraints expressed in formal language?

OMG SysML v1.18

Do you need a standards-based tool conforming to DoDAF 1.5 or MoDAF 1.2 in defining architecture or designing system/capability?

OMG UPDM v1.09

Does your system architecture design involve the DoDAF products (e.g., AV-1, OV-2, OV-4, OV-5, OV-6c, SV-4, SV-5, SV-6, and TV-1) that are required for such documents as ISP, ICD, CDD, and CPD?

Core Architecture Data Model (CADM) 1.03

10

Does your system need to support metadata for XML-encoded data or does your system need to interact with systems that support metadata for XML-encoded data?

OASIS ebXML RS v3.0, OASIS ebXML RIM v3.0

11

Page 3 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 4: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Are you developing a registry, or are you developing an XML vocabulary that will be published in the DoD Metadata Registry?

ISO/IEC 11179-3:2003(E)12

Audio Data Interchange

Does your system require the interchange of Audio Data?1

Does your system support Audio for Video Imagery Systems? ISO/IEC 13818-3:19982

Does your system process voice data over 2.4 Kbps digital links?

MIL-STD-30053

Does your system require acceptable service quality between voice services within the DSN?

ITU-T P.800, ITU-T P.8624

Do you provide enterprise-wide presence or awareness, or do you provide person-to-person or multi-user text chat?

IETF SIMPLE, IETF XMPP5

Does your network required a keepalive mechanism for SIP sessions or required a SIP session expiration mechanism or has your network experienced any denial-of-service attacks from rogue SIP-based proxies and user agents?

IETF RFC 40286

Does your system deal with sessions that use SIP as a signaling protocol and SDP to describe the parameters of the session?

IETF RFC 33127

Does your system require the use of the SIP REFER method? IETF RFC 35158

Does your system use SIP preconditions in situations that involve session mobility?

IETF RFC 40329

Do your information system and networks comply with all the audiovisual and multimedia systems security control protocols incorporated in the H235 standard?

ITU-T Rec. H.235.110

Are VoIP security protection controls required to be implemented on your audiovisual and multimedia networks?

ITU-T Rec. H.235.8 (09/05)11

Does your system require Internetworking between Session Initiation Protocol (SIP) and Bearer Independent Call Control Protocol or ISDN User Part?

ITU-T Rec. Q.1912.512

Does your system require Session Initiation Protocol (SIP) in the Authenticated Identity Body (AIB) format?

IETF RFC 389313

Does your system require ISDN to pass the signaling messages between the router and the ISDN switch at the local Central Office (CO)?

ITU-T Rec. Q.921, September 199714

Does your system require SDP routing for SAP, SIP, or RTSP use?

IETF RFC 389015

Page 4 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 5: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Does your system require a description to perform the mapping between two signaling protocols: the Session Initiation Protocol (SIP) and the Integrated Services Digital Network (ISDN) User Part (ISUP) of Signaling System No. 7 (SS7)?

IETF RFC 339816

Does your system require ISDN to pass the signaling messages between the router and the ISDN switch at the local CO with Call control and Management?

ITU-T Rec. Q.931, May 199817

Authentication

Does your system use Open Software Foundation DCE Version 1.1?

IETF RFC 28651

Does your system use the One-Time Password System? IETF RFC 22892

Does your PKI require Medium Assurance certificate profiles? RSA Labs PKCS #12 v1.0:1999 with Corrigendum, RSA PKCS #11 v2.20, RSA Labs PKCS #15:2000, IETF RFC 2587, FIPS Pub 140-2, IETF RFC 5280

3

Is verification of the claimed identity of individuals seeking physical access to Federally controlled government facilities and electronic access to government information systems required?

FIPS Pub 201-14

Is this an application of digital signature within DoD using the DoD Public Key Infrastructure (PKI)?

CMS/XML Digital Signature Profiles v1.15

Does your system use a time stamp protocol? IETF RFC 31616

Is this an application of CMS digital signature within DoD using the DoD Public Key Infrastructure (PKI)?

IETF RFC 38527

Is your system based on PKI and is an efficient means of verifying certificates necessary?

IETF RFC 25608

Does this application require the use of secure email? IETF RFC 50359

Does your system require protection of the data portion of the IP packet or require security services?

FIPS Pub 19810

Is PKI being implemented with LDAP? IETF RFC 452311

Do you need to provide HMAC-MD5 authentication algorithm with IS-IS routing ?

IETF RFC 530412

Do you need to provide an authentication algorithm with IS-IS routing?

IETF RFC 531013

Page 5 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 6: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Is your network required to use multiple authentication mechanisms residing in the authentication server instead of the authenticator?

IETF RFC 374814

Aviation: Air Traffic Management

Is your system an Aviation vehicle requiring access to the civil air space with communications capabilities?

1

Will your Aviation system be required to interoperate with civil communications infrastructures?

ICAO Annex 10: Vol. III, ICAO Annex 10 Aeronautical Telecommunications: Volume V, RTCA DO-224B, RTCA DO-210D, RTCA DO-181C, RTCA DO-236B, ICAO Annex 10: Vol. IV, ARINC 750-4, ICAO Annex 10: Vol. II, ICAO Annex 10: Vol. I, RTCA DO-246C, RTCA DO-186B

2

Does your system require GPS precise positioning services? ICD-GPS-2273

Does your Aviation system use Global Positioning for navigation/landing and will an FAA certification be required?

RTCA DO-2084

Does your Aviation system use Global Positioning for navigation/landing and will interoperability in a NATO environment be required?

STANAG 42945

Does your system require military IFF capabilities? DoD AIMS 97-900, DoD AIMS 03-10006

Is your system an Aviation vehicle requiring access to the civil air space with civil IFF capabilities?

7

Will your system require only a military Air Worthiness Certification for IFF versus an FAA certification (A negative response implies an FAA certification or both will be required.)?

8

Does your system require civil FAA IFF capabilities? ICAO Annex 10: Vol. II, ICAO Annex 10 Aeronautical Telecommunications: Volume V, ICAO Annex 10: Vol. IV, ICAO Annex 10: Vol. I, ICAO Annex 10: Vol. III

9

Does your system require traffic alert and collision avoidance? RTCA DO-185A, ARINC 735A-110

Does your system require automatic dependent surveillance (broadcast)?

RTCA DO-242A11

Is your system an Aviation vehicle requiring access to the civil air space with navigation capabilities?

12

Will your system require only a military Air Worthiness Certification for navigation versus an FAA certification (A negative response implies an FAA certification or both will be required.)?

13

Page 6 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 7: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Is your system an Aviation vehicle requiring access to the civil air space with landing aid capabilities?

14

Will your system require only a military Air Worthiness Certification for landing aids versus an FAA certification (A negative response implies an FAA certification or both will be required.)?

15

Will your Aviation system require area navigation? FAA AC 90-96A, RTCA DO-236B16

Will your Aviation system require global navigation? RTCA DO-246C, FAA AC 90-96A, RTCA DO-253A

17

Does your Aviation system require microwave landing aids? ICAO Annex 10 Aeronautical Telecommunications: Volume V, ICAO Annex 10: Vol. I, ICAO Annex 10: Vol. II, ICAO Annex 10: Vol. IV, ICAO Annex 10: Vol. III

18

Does your Aviation system require GPS landing aids? RTCA DO-253A, RTCA DO-246C19

Does your Aviation system require GPS landing aids to be interoperable in NATO environments?

STANAG 439220

Will your Aviation system require global navigation or GPS landing aids?

RTCA DO-229D21

Is system an Unmanned Air Vehicle or UAV Control System or will UAS support Joint / Coalition Operations or does UAS require interoperability with C4I in collecting and disseminating ISR related data or be used as a weapon platform?

STANAG 4586 Ed. 222

Backplanes and Busses

Is your system part of the C4ISR or the Weapon Systems domain?

1

Does your Crypto or Weapon System use VME backplanes and circuit cards?

ANSI/VITA 12

Does your Crypto system use VXI backplanes and circuit cards?

IEEE 11553

Does your system use a CompactPCI bus? CompactPCI4

Does your system require a multiplexing bus? MIL-STD-1553B5

Does your system require a Controller Area Network bus for heavy trucks or off-road vehicles?

SAE J19396

Does your system require a general purpose serial data communications link for heavy-duty vehicle apps?

SAE J1587, SAE J17087

Page 7 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 8: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Does your system require high-speed, reliable, data transfer technology that operates over copper wire and fiber optic cabling?

ANSI/INCITS 297:1997 (R 2002)., ANSI INCITS 373-2003, ANSI/INCITS 357-2002, ANSI INCITS 289-1996 (R2001), ANSI INCITS 387-2004, ANSI/INCITS 352-2002, ANSI/INCITS 332-1999

8

Does your system use Fibre Channel to transfer data? ANSI/INCITS 303-1998 (R 2003)., ANSI/INCITS 355-2001

9

Bindings/Object Code Linking

Does your POSIX system use Ada language bindings? ISO/IEC 145191

Biometric Technology Services

Does your system require biometric technologies for authentication?

ANSI INCITS 358-2002 (R2007) w/ Amd 1:2007

1

Does your organization intend to evaluate the performance of biometric algorithms, components, or systems or does your organization intend to implement a testing program for evaluation of the performance of biometric algorithms, components, or systems?

INCITS 409.3-2005, INCITS 409.1-2005, INCITS 409.2-2005

2

Does your organization require/anticipate implementation of interoperable system components for the collection of biometrics or does your organization collect fingerprint data or is your organization required to process biometric data in the field?

ISO/IEC 19794-2:2005 , ISO/IEC 19794-4:2005

3

Does your organization collect photographs of individuals for identification purposes or is your organization required to process biometric data in the field?

ISO/IEC 19794-5:2005 w/ Amd 1:20074

Does your organization require/anticipate implementation of interoperable system components for the collection of biometrics or does your organization collect iris images or is your organization required to process biometric data in the field?

ISO/IEC 19794-6:2005 5

Does your organization require/anticipate implementation of interoperable system components for the collection of biometrics or does your organization collect face data or is your organization require to process biometric data in the field?

ANSI/INCITS 377-2004, ANSI/INCITS 381-2004, ANSI/INCITS 378-2004

6

Does your organization require/anticipate implementation of interoperable system components for the collection of biometrics or is your organization required to process biometric data in the field or does your organization anticipate the use of modalities for which no record types that exist in ANSI/NIST ITL 1-2000 or 2007?

ISO/IEC 19785-2:2006, ISO/IEC 19785-1:2006

7

Does your organization require developing software to interface with biometric hardware and or devices?

ISO/IEC 19784-2:2007, ISO/IEC 19784-1:2006 w/ Amd 1:2007

8

Page 8 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 9: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Does your organization require/anticipate implementation of interoperable system components for the collection of biometrics or does your organization collect, store, exchange, or match representations of digitized sign or signature data or is your organization required to collect biometric data for logical or physical access control?

ANSI/INCITS 395-20059

Does your organization participate in performance testing of biometric systems or is the primary goal of your testing efforts to determine if the performance of the complete biometric system meets the requirements of a specific application environment for a target population?

ANSI/INCITS 409.4-200610

Does your organization require/anticipate implementation of interoperable system components for the collection of biometrics or is your organization required to comply with HSPD-12 or FIPS 201?

NIST Special Publication 800-76-111

Does your organization require/anticipate implementation of interoperable system components for the collection of biometrics or does your organization collect face data or is your organization required to process biometric data in the field?

ANSI INCITS 385-200412

Does your organization require/anticipate implementation of interoperable system components for the collection of biometrics or plan to exchange biometric data with the FBI IAFIS or does your organization collect fingerprint data or iris data?

IAFIS-DOC-01078-8.00113

Does your organization require/anticipate implementation of interoperable system components for the collection of biometrics or required to process biometric data in the field anticipate implementing or testing a family of biometric systems?

ISO/IEC 24709-2:2007, ANSI INCITS 442-2008, DoD EBTS v2.0, ISO/IEC 24709-1:2007

14

Do you need to define an interface specification for exchange of biometric data?

ANSI INCITS 398-200815

Will your system process or disseminate terrorist information or will your system interface with US-VISIT/IDENT?

IDENT IXM v2.016

C4ISR: Payload Platform

Does your system use fiber channel for high-speed data transfer?

ANSI X3.230:19991

Is Firewire serial bus used in place of the standard parallel bus?

IEEE 1394, IEEE 1394b, IEEE 1394a2

Will your system be using INTELSAT Business Services? IESS-309 Rev. 73

Is your system in the design phase and needs compliance with data rate and TCM/8PSK modulation requirements?

IESS-310 Rev. 24

Page 9 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 10: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Calendaring and Scheduling

Does your system require calendaring and scheduling services?

C3211

Will you be using date/time references in your application? ISO 8601:20042

Cryptographic Key Management

Does your system require Key Management in an IP environment?

IETF RFC 24041

Does your system require DNS authentication and a shared secret key?

IETF RFC 28452

Does your system require dynamic secure updates to the Domain Name Server (DNS)?

IETF RFC 30073

Does your system require datagram authentication or does your system require security services at the IP layer?

IETF RFC 43024

Does your system require authentication and encryption in an IP environment?

IETF RFC 43035

Does your system require protection of the data portion and/or header portion of the IP packet or does your system require security services at the IP layer?

IETF RFC 48356

Do you require defense against attacks on your IP-based network?

IETF RFC 43047

Do you need to be NSA Suite B compliant? IETF RFC 5430, NIST SP 800-56A8

Do you need to be Suite B compliant? NIST SP 800-90, IETF RFC 4754, IETF RFC 5008

9

Do you need to generate a key? NIST SP 800-10810

Does your device transmit key to a fill device or does your device receive key from a fill device or is your device a fill device?

NSA EKMS 308 Rev E11

Does your device transmit key to a fill device or receive key from a fill device or is your device a fill device or does your device require key that contains NATO classifications?

NSA EKMS 308, Rev F12

Do you need to implement the EKMS 308 base document or does your device transmit key to a fill device or does your device receive key from a fill device? Is your device a fill device?

NSA EKMS 308 App C 24Apr09, NSA EKMS 308 Appendix A

13

Page 10 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 11: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Does your device need to receive key from a Data Transfer Device or does your device need to load key to a Data Transfer Device?

NSA EKMS 603 Rev C w/SCN-114

Database Management System

Does your system include a Relational DBMS (RDBMS) or does it use RDBMS resources and does your system need to embed SQL statements within Java based applications or does your system need to embed SQL statements within Java based applications?

ISO/IEC 9075-10:2003 with Cor. 2:20071

Does your system include a Relational DBMS (RDBMS) or does it use RDBMS resources?

ISO/IEC 9075-2:2003 with Cor. 2:2007, ISO/IEC 9075-1:2003 with Cor. 1:2005 and Cor. 2:2007

2

Does your system include a Relational DBMS (RDBMS) or does it use RDBMS resources and does your system have a need to execute statements of the database language SQL from within application programs?

ISO/IEC 9075-3:2003 with Cor. 1:20053

Does your system include a Relational DBMS (RDBMS) or does it use RDBMS resources and does your system need to store data base routines on the RDBMS server itself?

ISO/IEC 9075-4:2003 with Cor. 2:20074

Does your system include a Relational DBMS (RDBMS) or does it use RDBMS resources and will your system implement SQL multimedia spatial capabilities?

ISO/IEC 13249-1:2007, ISO/IEC 13249-3:2006

5

Does your system include a Relational DBMS (RDBMS) or does it use RDBMS resources or does your system need to be able to query your databases to discover their structure?

ISO/IEC 9075-11:2003 with Cor. 2:20076

Will your system implement SQL remote database access (RDA)?

ISO/IEC 9579:20007

Does your client need to define a client/server based service and protocol for Information Retrieval?

ISO 23950/NISO Z39.508

Does the application manage a transactional persistent database or is the application programmed in an object oriented manner in the Java programming language or does the application require an object oriented database management system?

JSR-2439

Devices (Smart Cards)

Does your Combat Support system require contact Smart Cards?

ISO/IEC 7816-7, ISO/IEC 7816-10:1999, ISO/IEC 7816-8:2004 , ISO/IEC 7816-1, ISO/IEC 7816-9:2004, ISO/IEC 7816-11:2004, ISO/IEC 7816-1:1998/Amd 1:2003, ISO/IEC 7816-15:2004/Cor. 1:2004

1

Page 11 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 12: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Is a contact-based access control card required? ISO/IEC 7816-11:20042

Does your Combat Support system require contactless Smart Cards?

ISO/IEC 14443-4:2001, ISO/IEC 14443-1:2000, ISO/IEC 15693-1:2000, ISO/IEC 15693-3:2001

3

Document Interchange

Does your system exchange documents in markup or other format?

1

Is your system part of the Combat Support domain? MIL-PRF-28001C2

Does your system exchange documents in HTML format (including web publication)?

HTML 4.013

Is your HTML expected to evolve into XML applications? XHTML 1.1: 31 May 20014

Does your system exchange documents in XML format? XForms 1.0, XML 1.0 (Third Edition), XML 1.1:2004, WSDL 1.1

5

Will your system be processing WWW metadata? RDF/XML Syntax Specification (Revised), RDF Vocabulary Description Language 1.0: RDF Schema

6

Does your system require exchanging information in a decentralized distributed format?

SOAP MTOM, W3C SOAP 1.2 Part 2, W3C SOAP 1.2 Part 1

7

Will you be using XML Style Sheets? XSL 1.0:20018

Will you be transforming XML through the use of Style Sheets? XPath 2.0:2007, XPATH 1.09

Does your system need read/write random access to XML documents?

DOM Level 3 W3C10

Do you require interoperability in office automation products to include text documents, spreadsheets, charts, and graphical documents like drawings or presentations?

ISO/IEC 29500-2:2008, ISO/IEC 29500-3:2008, ISO/IEC 29500-1:2008, ISO/IEC 29500-4:2008

11

Are industry developed open standards used to model, describe, transfer, store, and provide query/response to ensure interoperability and to comply with DoD directives specifying the use of COTS and open industry developed standards?

MIMOSA OSA-CBM v3.112

Is your organization sharing information on terrorism operations or terrorists?

CISS RM: MES, DDMS 2.0, CISS ISM: XML

13

Will your system automatically process or disseminate terrorism information across security domains?

CISS Tearlines:XML, CISS Tearlines Applications

14

Is your system designed to share terrorism information with the justice and public safety communities?

CISS GJXDM15

Page 12 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 13: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Does your system share terrorist person data? TWPDES16

Do you order items that are measured in commercial contracts?

UNECE Recommendation No. 2017

Do you order supplies or services in non-US dollars? ISO 4217:200118

Are you representing languages in your application? ISO 639-2:199819

Will your applications be using date/time references? ISO 8601:200420

Do you require binary encoding of XML documents? ITU-T X.891:200521

Does your application need to query data that is either stored as XML or appears as XML via a middleware product?

XQuery 1.0:200722

Are you implementing email or DNS? IETF RFC 230823

Electronic Data Interchange (EDI)

Does your system require document interchange of XML documents?

XML Schema Part 1:2004, XML 1.1:2004, XML Schema Part 2:2004, XML 1.0 (Third Edition)

1

Does your XML document require a XML-encoded digital signature rather than as separate data?

XML Signature2

Does your system require profiling documents of PDF-417? ISO/IEC 15418, ISO/IEC 154343

Does your Combat Support system require use of EDI? ANSI ASC X124

Does the system require Healthcare EDI for Administrative or Business Transactions?

ASC X12N 820:2007, ASC X12N 834:2006, ASC X12N 276/277:2008, ASC X12N 278:2008, ASC X12N 270/271:2008, ANSI/HL7 V2.4-2000, ASC X12N 835:2006, ASC X12N 837 (Professional):2006, ASC X12N 837 (Institutional):2007, ASC X12N 837 (Dental):2007

5

Does your Combat Support Medical system require Retail Pharmacy Claim EDI?

NCPDP Batch v1.2, NCPDP v. D.06

Does your system generate, process, transmit, receive, modify, or use Mission Data Files, i.e., mission or target data which is delivered to smart weapons as the Edge User?

MIL-STD-30147

Does your system use ISDN bearer services for the basic rate interface?

ANSI T1.604-1990 (R2004)8

Do you order supplies or services in non-US dollars? ISO 4217:20019

Page 13 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 14: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Does this application require high-speed processing of binary data exchanges?

ITU-T Rec. X.680 (2002), w/ Amd 1-3 and Cor 1

10

Electronic Mail

Does your system require official organizational-messaging traffic between DoD organizations?

ACP 123A:20011

Does your system retrieve or send emails? IETF RFC 35012

Does your system require medium assurance messaging service between DoD organizations?

IETF RFC 2821, IETF RFC 2822, IETF RFCs 2045-2049, IETF RFC 3023, IETF RFC 1870, IETF RFC 2231

3

Does your network require medium-assurance messaging services using SMTP to send e-mails?

IETF RFC 3030, IETF RFC 34624

Does your system require encrypted email capabilities? IETF RFC 38515

Does your system require signature algorithms? FIPS Pub 186-2, FIPS Pub 186-36

Engineering Support-Automatic Testing

Does your Automatic Test System require Digital Test Data Formats (DTF)?

IEEE 14451

Does your Automatic Test System require instrumentation services?

IVI-4.3, IVI-4.1, IVI-4.4, IVI-4.2, IVI-4.7, VPP-3.4 r2.3, VPP-3.3 r4.01, VPP-3.2 r5, VPP-3.1, IVI-4.8, IVI-4.6, IVI-4.10

2

Does your Automatic Test System require interoperable diagnostic tools?

VPP-4.3 r2.2, IEEE 1232:20023

Does your Automatic Test System require a standard representation of BIT data in the test environment?

IEEE 1149.4, IEEE 1149.1:20014

Does your Automatic Test System require product design data (PDD)?

ANSI/EIA 6825

Does your Automatic Test System require system framework standards?

VPP-2 r4.26

Does your Automatic Test System require signal and test modeling for execution of UUT test programs?

IEEE 1641-20047

Does your Automatic Test System require Instrument Drivers? IVI 3.1, r1.68

Does your Automatic Test System require Instrument Drivers to support multiple assets?

IVI-3.10, r1.09

Does your Automatic Test System require the use of LXI instruments and drivers?

IVI 3.15, r 1.010

Page 14 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 15: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Does your Automatic Test System require an instrument with a LAN based capability?

LXI Standard Rev 1.111

Does your Automatic Test System require the use of ATML schemas?

IEEE 1671-200612

Are your ATE instrument drivers based upon the IVI Architecture?

IVI-3.12 Rev 1.013

Does your ATS require the use of a standard to produce an exchange format, using eXtensible Markup Language (XML), for identifying instrumentation that may be integrated in an automatic test system (ATS)?

IEEE STD 1671.2-200814

Does your ATS require the use of a standard to produce an exchange format, using eXtensible Markup Language (XML), for identifying Test Adapters that may be integrated in an automatic test system (ATS)?

IEEE STD 1671.5-200815

Does your ATS require the use of a standard to produce an exchange format, using eXtensible Markup Language (XML), for identifying Test Station information that may be integrated in an automatic test system (ATS)?

IEEE STD 1671.6-200716

Does your ATS require the use of a standard to produce/consume the results of testing a UUT in a standard format?

IEEE 1636.1-200717

Does your Automatic Test Systems require the use of authoring of IVI-C instrument drivers?

IVI-3.9 Rev 1.018

Does your Automatic Test Systems require the use of multiple IVI instrument COM drivers or does you client application need to decouple COM instrument driver instances?

IVI-3.6 Rev 1.019

Does your Automatic Test Systems require the use of multiple IVI instrument drivers for which the driver configuration information needs to have logical ( not physical) mapping of this information?

IVI-3.5 Rev 1.820

GEOINT: Geospatial

Does your system interchange geospatial data (mapping, charting and geodesy services)?

1

Do you require a system-to-system exchange of aeronautical data or do you need a data model for representing aeronautical data or are you working with aeronautical data such as airports, runways, routes, airspace, navigation aids and/or procedures?

AIXM 5.02

Is any of your geospatial data raster-formatted? MIL-STD-2411(2)3

Page 15 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 16: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Is any of your geospatial data raster-formatted or does your system have requirements to either produce or interpret CIB, CADRG, or DPPDB raster products?

MIL-STD-2411-2(1)4

Does your system have requirements to either produce or interpret CIB, CADRG, or DPPDB raster products?

MIL-STD-2411-1(2)5

Is any of your geospatial data in geographic databases intended for direct use?

MIL-STD-2407(1)6

Does your data represent reference frame, reference ellipsoid, fundamental constants, or Earth Gravitational Model with related geoid?

MIL-STD-24017

Does your data interchange require the use of country codes? FIPS Pub 10-4, w/ CNs 1-148

Does your system require an International Standard that provides a clear procedure for the description of digital geographic datasets so that users will be able to determine whether the data in a holding will be of use to them and how to access the data?

ISO 19115:2003 w/ ISO 19115 Cor. 1:20069

Does your system require client access across a network to pre-programmed calculations and/or computation models that operate on spatially referenced data over the world wide web?

WPS 1.010

Does application involve overhead imagery, terrain characteristics?

ISO 19123:200511

Do you have a requirement for use of a coordinate location based application based on usage of geographic information which needs a unique definition of the a reference system?

ISO 19111:200712

Does this application require the interchange, distribution, manipulation, or exploitation of geospatial intelligence data based on place names (e.g., as in a gazetteer) or does this application represent location by reference to a name, or to a position relative to a fixed point or geographic feature, or to a named spatial relationship to a geographic feature?

ISO 19112:200313

Does the application require access to definitions or descriptions of items of geospatial information?

DGIWG FACC, ISO 19135:2005, DFDD 2009-1, ISO 19110:2005

14

Does the application require access to and/or model/manipulate items of geospatial information?

ISO 19109:200515

Does this application require the interchange, distribution, manipulation, or exploitation of geospatial intelligence data in vector form?

ISO 19107:200316

Does your system require geospatial information as a means to reference operational information?

ISO 19119:2005 w/ Amd 1:200817

Page 16 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 17: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Does your development involve publication of or access to an electronically accessible catalogue of geospatial intelligence data?

CAT 2.0.218

Does your system require access to geospatial feature information using an implementation of the OGC Web Feature Service specification or does your system require an ability to select objects from a net accessible data base?

OpenGIS Filter 1.1, ISO 19136:200719

Does your development require exchange of GEOINT data with other systems over a network?

GML 3.1.120

Does your development involve a client that needs to access data that relates position in a spatiotemporal domain to a (possibly multidimensional) range of properties or does your development involve a server that provides access to such data?

WCS 1.021

Does the system that you are developing have requirements to access or distribute geospatial feature data over a network?

WFS 1.122

Does your development involve a client that needs to access and display maps or spatially registered images or does your development involve a server that provides access to geospatial information or spatially registered images?

WMS 1.3, WMC 1.1, SLD 1.0, WMS 1.1.123

Is a registry of data quality measures being established, to include for each measure, a name, possibly alternative names, the referring data quality sub-element, an identifier, a definition and a description, and if required, parameters?

ISO/TS 19138:200624

Does the application acquire, process, analyze, access, present and/or transfer geospatial information in digital/electronic form or does the application participate in the NSG or does the application use, display and/or communicate information about geospatial concepts (e.g. definitions or descriptions of items of geospatial information)?

NFDD v2.0, NAS Pt. 1, v2.0, NEC v2.025

Are you developing an imaging [EO, SAR, LIDAR, FRAME, PUSHBROOM, WHISKBROOM] sensor model or does your software need to interface with a sensor model for derivation of geocoordinates?

CSM, v2.A26

Are you using the ISO 19115 Geographic Information Metadata Standard or does your system require an International Standard that provides a clear procedure for the description of digital geographic datasets so that users will be able to determine whether the data in a holding will be of use to them and how to access the data or do you need a common XML specification for describing, validating and exchanging geospatial metadata?

ISO/TS 19139:200727

Page 17 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 18: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Do you need a common XML specification for describing, validating and exchanging geospatial metadata or are your geospatial metadata requirements driven by Department of Defense Discovery Metadata Specification, and Intelligence Community Metadata requirements and appropriate ISO standards or does your system require standards that provide a clear procedure for the description of digital geographic datasets so that users will be able to determine whether the data in a holding will be of use to them and how to access the data?

NGCMP v1.028

Does your system require a web service interface for requesting, filtering, and retrieving observations and sensor system information?

OGC WCS 1.1.2, SPS 1.0, OpenGIS SOS 1.0

29

Does your application require information about times associated with spatial objects or do you application represent and/or manipulate time coordinates (events and/or intervals)?

ISO 19108:2002 w/ Cor 1:200630

Does your system require precision time? ITU-R TF460-631

Does your system collect, storage and disseminate METOC data between METOC data providers and user applications?

Joint METOC Broker Language (JMBL)32

Does your system require managed rule-based, policy language, access control to geospatial information and services within your service oriented architecture in an interoperable way across jurisdictions?

OpenGIS GeoXACML 1.033

Does your system require the efficient exchange of geographic-point-location data which are universally interpretable and which allow identification of points on, above and below the earth s surface at varying levels of precision?

ISO 6709:200834

Does your system require visualization of geospatial information and data using a web browser?

OGC KML 2.2.035

Does your system interchange scientific data, i.e. environmental science, oceanography, atmospheric modeling and geospatial?

HDF v536

Does your system interchange weather product messages in Gridded Binary Form with geospatial data (mapping, charting and geodesy services)?

FM 92-X Ext. GRIB WMO No. 30637

Does your system interchange data in Binary Universal Format for Representation (BUFR) with geospatial data (mapping, charting and geodesy services)?

FM 94-X Ext. BUFR WMO No. 30638

Does your application need to provide net access to GEOINT data as a map or spatially referenced image or need to access or display GEOINT data?

OGC SLD 1.1.039

Page 18 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 19: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Does your system require the ability to describe, discover, acquire/retrieve and process sensors (parameters and processes) and sensor-based geographic data and information in a web browser?

OGC SensorML v1.0.040

Does application acquire process, analyze, access, present and/or transfer geospatial information in digital/electronic form? Does the application participate in the NSG or does the application collect, use, display and/or communicate geospatial information related to the topographic environment?

NSG TDS Content Spec V2.041

Does your system produce, exchange, process, exploit, or otherwise use high-resolution elevation data?

NGA.IP.0002_1.042

Does your system have a requirement to encode and portray digital Feature and Coverage data using user-defined styling language rules?

SE 1.1.043

Does the application require a standard, flexible and expressive representation for When and Where (time, space, and position) information?

TSPI v1.0.144

GEOINT: Motion Imagery

Does your system exchange Video Imagery?1

Is there a requirement to interactively disseminate large imagery (either still, motion or both) in a bandwidth constrained environment? Note, "large" and "bandwidth-constrained" are relative metrics. What is relevant is how fast does imagery move within?

ISO/IEC 15444-9:20052

Does your system use MPEG-2 Systems for standard and high-definition compression or does your system require support for compressed video?

ISO/IEC 13818-1:2007 w/ Cor 1:2008, ISO/IEC 13818-3:1998

3

Does your system require support for compressed video? ISO/IEC 13818-2:20004

Does your system exchange motion imagery data with external systems or does your system task, collect, produce, process, catalog, store, read, exploit, or disseminate digital motion imagery?

Advanced Authoring Format Version 1.1, SMPTE 377M:2004

5

Do your motion imagery terminals operate on IP-based broadcast-quality video at rates of less than 1 Mbps or do you need the best quality motion imagery at the lowest bandwidth?

ITU-T Rec. H.264 (03/2009)6

Does your system need to make multiple motion imagery sensors on arbitrary platforms interoperable or need accurate timing information on the sensor and platform related metadata associated with my MI streams?

MISB RP 0701.0 Common Metadata System:Structure

7

Page 19 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 20: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Will your system send metadata with a full motion video (FMV) file from a UAV, or will your system need to carry user metadata with the FMV end to end through a system or will you build a fully network-based, metadata-enabled motion imagery system?

MISB Standard 0601.38

Does your system need to compress LVSD, WALF or WAS/WAPS imageries or use JPEG 2000 profiles?

MISB RP 0705.2, v1.19

Does your system exchange motion imagery data with external systems or does your system task, collect, produce, process, catalog, store, read, exploit, or disseminate digital motion imagery?

MISB Standard 0301.4, v1.410

Does your system use motion imagery, full motion video (FMV), or just simply video, or do your imaging sensors/ systems generate sequential or continuous streaming images at rates of 1 frame per second or greater within a common field of regard?

MISP v5.311

Does your system need to convey security information about a Motion Imagery stream or file within the Motion Imagery itself, or will your system need to find security information about Motion Imagery at the point of ingest into the NSG?

MISB Standard 0102.712

Will your system need to time stamp metadata and full motion video (FMV) so they can be correlated, or is the timing accuracy of the metadata in relation to FMV important, or must the position of a certain object in the video frame be accurately identified?

MISB Standard 0604.113

Will your system identify Motion Imagery streams and/or clips, or will your system identify a Motion Imagery clip extracted from a larger file, or will your system discover and retrieve Motion Imagery?

MISB RP 0608.114

Are you building/operating a Tier II or Above UAS or do you provide motion imagery or full motion video for situational awareness or need to send metadata with a full motion video (FMV) file from a UAV?

USIP 1 IP 1.115

Does your system create, store, or search for Motion Imagery clip/stream or exchange MI & metadata in a datalink with other systems or use Motion Imagery metadata to use MI?

MISB Standard 0807.316

Does your system involve the digital conversion, capture or transmission of standard-definition full motion video or does your system use the Motion Imagery Standards Profile (MISP)?

Rec. BT.601-6 (01/07)17

How do I convey metadata in a bit-efficient manner or how do I convey MISB-compliant metadata for Motion Imagery?

SMPTE 336M-200718

GEOINT: Still Imagery

Page 20 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 21: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Does your system exchange Still Imagery data with external systems?

ISO/IEC 15444-1:2004 | ITU-T Rec. T.800, ITU-T T.81, MIL-STD-2500C, ISO/IEC 12087-5:1998 w/Corrigenda 1&2, STDI-0002 v3, MIL-STD-188-199(1), MIL-STD-188-198A(4)

1

Does your system exchange graphically annotated still imagery, raster or gridded data with external systems?

BPCGM01.00, ISO/IEC 8632-3:1999 (Updated citation), ISO/IEC 8632-1:1999 with Corrigenda 1:2006

2

Does your system exchange still imagery, motion imagery, scanned maps, raster or gridded data with external systems?

BPJ2K01.103

Does your system use or exchange Commercial Still Imagery data with external systems?

STDI-0006, 23 July 20084

C4ISR domain: Does your system transmit GMTI from airborne/spaceborne sensor platforms?

STANAG 4607, Ed 25

Does the sys discvr ISR data from a product library or does the ISR library sys support client & server structures, standing queries, info release protection, or web discovery and retrieval of data in STANAG 4545, 4607,4609,4633,7023; NITF, NSIF, JPEG, TIFF?

STANAG 4559, EDITION 26

Does your system exchange, process, exploit, or otherwise use Still Imagery data from national sources?

NGA STDI-0001 v1.3/CN27

Does your system exchange still imagery, scanned maps, raster or gridded data with external systems?

GeoTIFF Revision 1.0, TIFF Revision 6.08

Global Air Traffic Management

Is your system an Aviation vehicle requiring access to the civil air space with navigation capabilities?

1

Will your Aviation system require area navigation? RTCA DO-236B, FAA AC 90-96A2

Will your Aviation system require global navigation? RTCA DO-246C, FAA AC 90-96A, RTCA DO-253A

3

Graphics Services

Does your system require services to support the creation and manipulation of graphics?

OpenGL Graphics System:2001, ANSI/ISO/IEC 9636

1

Does your aircraft require a heads up display to its pilot? MIL-STD-1787C2

Does your system require services to support the creation and manipulation of graphics for the storage and transmission of animated graphics?

MNG 1.03

High Availability Computing Middleware

Page 21 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 22: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Does the system require high availability applications and computing elements that are controlled (started and stopped) based on monitoring system state?

SAF SAI-AIS-AMF-B.04.011

Does the system require high availability computing which includes publishing and subscribing state change notifications among a cluster of processors?

SAF SAI-AIS-CLM-B.04.012

Does the system require high availability computing with standardized APIs for interfacing management applications and internal high availability objects to a cluster of computing processors?

SAF SAI-AIS-IMM-A.03.013

Does the system requires high availability of a service which is provided by a cluster of distributed computing resources?

SAF SAI-AIS-NTF-A.03.014

IA Metadata

Do you need to protect software and firmware changes? IETF RFC 41081

Identification Friend or Foe (IFF)

Does your system require military IFF capabilities? DoD AIMS 97-9001

Does your system require military civil FAA IFF capabilities? ICAO Annex 10: Vol. III, ICAO Annex 10: Vol. I, ICAO Annex 10 Aeronautical Telecommunications: Volume V, ICAO Annex 10: Vol. II, ICAO Annex 10: Vol. IV

2

Does your system require traffic alert and collision avoidance? RTCA DO-185A, ARINC 735A-13

Does your system require automatic dependent surveillance (broadcast)?

RTCA DO-242A4

Does your system implement, for either tactical information exchange, weapons employment decisions, or tactical/strategic situational awareness graphical display, entity identifications?

STANAG 1241, Ed 55

Information System Security Management

Has your system defined a Protection Profile? ISO/IEC 154081

Does your system require the User-based Security Model (USM) for Simple Network Management Protocol (SNMP) version 3 for use in the SNMP architecture which defines the Elements of Procedure for providing SNMP message level security?

IETF RFC 34142

Does your implementation require Type-1 encryption over an IP-based environment?

HAIPE IS v3.0.23

Page 22 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 23: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Does your system implement a Public Key Infrastructure (PKI)? Does your system require Key Management in an IP environment?

IETF RFC 35854

Will your system use IPsec? IETF RFC 3566, IETF RFC 3686, IETF RFC 3602

5

Will your system require the use of Internet Key Exchange (IKE)?

IETF RFC 3526, IETF RFC 36646

Does the system require secure DNS transactions? IETF RFC 36457

Will your system provide secure communications required for real-time applications such as VoIP?

IEEE Std 802.1AE8

Does your system require a secure network management protocol?

IETF RFC 5592, IETF RFC 5591, IETF RFC 5590

9

Internationalization Services

Does your system exchange data internationally? ISO/IEC 10646:2003, ISO/IEC 8859-11

IPv6 Capable Product Class Profiles

Are you building an IPv6 capable system? IETF RFC 4291, IETF RFC 3590, IETF RFC 4861, IETF RFC 4443, IETF RFC 4193, IETF RFC 4007 , IETF RFC 2460, IETF RFC 4862, IETF RFC 2710

1

Please refer to Section 2.1 of the IPv6 Product Profiles v3.0 for an explanation of the autoconfiguration requirements. For a valid IPv6 Capable profile, you MUST answer yes to either or both of the next two questions. Will the system include Stateless Address Autoconfiguration as described in RFC 2462 or RFC 4862?

IETF RFC 48622

Will the system include DHCPv6 Client Side for discovering its own unique IPv6 interface address(es)?

IETF RFC 33153

Do you use DHCPv6 and need to delegate IPv6 prefixes? IETF RFC 36334

Do you plan to expand the Neighbor Discovery Protocol Flag Options?

IETF RFC 51755

Does your system include any Ethernet interfaces? IETF RFC 24646

Will you be sending IPv6 packets over Point-to-Point Protocol (PPP)?

IETF RFC 50727

Will you be sending IPv6 Packets over IEEE 802.15.4 Networks?

IETF RFC 4944, IETF RFC 51728

Page 23 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 24: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Please refer to the Product Class definitions in Section 1.6 of the DoD IPv6 Product Profiles for IPv6 Capable Products Version 3.0. Does the system fit the definition of a Host/Workstation?

IETF RFC 3810, IETF RFC 2711, IETF RFC 3596, IETF RFC 4305, IETF RFC 4306, IETF RFC 3484, IETF RFC 4307, IETF RFC 4303, IETF RFC 4301, IETF RFC 4308, IETF RFC 1981

9

In addition to the mandatory parts of the IPsec Profile, it is recommended that a Host/Workstation support the Authentication Header (AH). Will this system support AH?

IETF RFC 430210

Host/Workstation products SHOULD+ support Privacy Extensions (RFC 4941) and when deployed on some networks, the network policy mandates support for Privacy Extensions when using SLAAC. Will this system support Privacy Extensions?

IETF RFC 494111

Dual Stack operation enables interoperability with IPv4-only systems. Will this system be deployed where IPv4 interoperability is required?

IETF RFC 421312

Will this system be deployed as a MIPv6 Mobile Node? IETF RFC 3775, IETF RFC 3776, IETF RFC 4877

13

MIPv6 Mobile Nodes SHOULD+ support Network Access Identifier (RFC 4282) and the Mobile Node Identifier Option (RFC 4283). Will this system support these options?

IETF RFC 4283, IETF RFC 428214

A system that will be deployed where it will operate with MIPv6 Mobile Nodes SHOULD support Route Optimization as defined in RFC 3775. Will this system support Route Optimization as a correspondent node?

IETF RFC 377515

Please refer to the Product Class definitions in Section 1.6 of the DoD IPv6 Product Profiles for IPv6 Capable Products Version 3.0. Does the system fit the definition of an Advanced Server?

IETF RFC 4306, IETF RFC 3596, IETF RFC 3810, IETF RFC 4301, IETF RFC 4308, IETF RFC 4303, IETF RFC 2711, IETF RFC 4305, IETF RFC 3484, IETF RFC 1981, IETF RFC 4307

16

In addition to the mandatory parts of the IPsec Profile, it is recommended that an Advanced Server support the Authentication Header (AH). Will this system support AH?

IETF RFC 430217

Does the deployment of this system require use of Privacy Extensions (RFC 4941) when using SLAAC?

IETF RFC 494118

Will this system be deployed where IPv4 interoperability is required?

IETF RFC 421319

Will this system be deployed where it will operate with MIPv6 Mobile Nodes?

IETF RFC 377520

Page 24 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 25: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Please refer to the Product Class definitions in Section 1.6 of the DoD IPv6 Product Profiles for IPv6 Capable Products Version 3.0. Does the system fit the definition of a Router?

IETF RFC 3411, IETF RFC 3596, IETF RFC 4302, IETF RFC 4305, IETF RFC 4308, IETF RFC 4301, IETF RFC 4303, IETF RFC 4307, IETF RFC 2711, IETF RFC 2784, IETF RFC 1981, IETF RFC 4306, IETF RFC 2474, IETF RFC 3484, IETF RFC 3810, IETF RFC 4213, IETF RFC 2473

21

Will this system be deployed as a "Home Agent Router" in a MIPv6 configuration?

IETF RFC 3775, IETF RFC 3776, IETF RFC 4877

22

MIPv6 Home Agent Routers SHOULD+ support Network Access Identifier (RFC 4282) and the Mobile Node Identifier Option (RFC 4283). Will this system support these options?

IETF RFC 4283, IETF RFC 428223

Will this system be deployed as a Mobile Router in a NEMO configuration?

IETF RFC 3775, IETF RFC 3776, IETF RFC 3963

24

Will this system be deployed as an Interior Router in the network core?

IETF RFC 2740, IETF RFC 534025

Interior Routers SHOULD+ support Authentication/Confidentiality for OSPFv3. Will this system support this?

IETF RFC 455226

Will this system be deployed as an Interior Router in the network core using IS-IS Protocol?

IETF RFC 530827

Interior Routers using IS-IS Protocol requiring Cryptographic Authentication for IS-IS. Will this system support this?

IETF RFC 5310, IETF RFC 530428

Will this system be deployed as an Exterior Router (BGP Gateway) between routing systems?

IETF RFC 4271, IETF RFC 2545, IETF RFC 1772, IETF RFC 4760

29

Routers to be deployed in an Integrated Services (IntServe) architecture SHOULD+ support RSVP-based QoS. Will this system be providing RSVP-based QoS?

IETF RFC 2205, IETF RFC 2207, IETF RFC 2210, IETF RFC 2750

30

Will this system support Aggregation of RSVP for IPv4 and IPv6 Reservations?

IETF RFC 317531

Will the intended deployment of this Router require Protocol Independent Multicast?

IETF RFC 460132

Please refer to the Product Class definitions in Section 1.6 of the DoD IPv6 Product Profiles for IPv6 Capable Products Version 3.0. Does the system fit the definition of a L3 Switch?

IETF RFC 198133

Will this system be deployed as an exterior system node with routing functions to interface with routers at edge of a switching network?

IETF RFC 1772, IETF RFC 2545, IETF RFC 4271, IETF RFC 4760

34

Will the L3 Switch be used as an Interior Router supporting OSPFv3?

IETF RFC 2740, IETF RFC 534035

Page 25 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 26: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

L3 Switch used as Interior Router using OSPFv3 Must support Authentication/Confidentiality for OSPFv3. Will this system support this?

IETF RFC 455236

Will the L3 Switch be used as an Interior Router in the network core using IS-IS Protocol?

IETF RFC 530837

L3 Switch used as Interior Routers using IS-IS Protocol requiring Cryptographic Authentication for IS-IS. Will this system support this?

IETF RFC 5310, IETF RFC 530438

Is this system a "managed switch", i.e. one that will be managed from a network management system using SNMP?

IETF RFC 341139

Please refer to the Product Class definitions in Section 1.6 of the DoD IPv6 Product Profiles for IPv6 Capable Products Version 3.0. Does the system fit the definition of an IA Device?

IETF RFC 4303, IETF RFC 4301, IETF RFC 1981

40

In addition to the mandatory parts of the IPsec Profile, it is recommended that an IA Device support the Authentication Header (AH). Will this system support AH?

IETF RFC 430241

Will this system be deployed as an Inline Encryptor (INE) or a VPN Server, or will its deployment require IPsec secured connections with other devices?

IETF RFC 4306, IETF RFC 4835, IETF RFC 4308, IETF RFC 4307

42

Will this system be configured to distribute IP Security Policy information to other devices?

IETF RFC 358543

Do you need additional information on how to develop an IP Security Policy (IPSP) configuration and management framework (If the answer is Yes, you should include IETF RFC 3586 as part of your Information Guidance profile)?

44

Will this system be deployed as a Radius server? IETF RFC 316245

Please refer to the Product Class definitions in Section 1.6 of the DoD IPv6 Product Profiles for IPv6 Capable Products Version 3.0. Does the system fit the definition of a Network Appliance?

46

Minimum requirements for Network Appliance include the Base Requirements only, however it is recommended that a Network Appliance support as much of the Host/Workstation Product Class profile as possible, and strongly recommended that a Network Appliance support the IPsec Functional Requirements defined in Section 2.2. Will this system meet the Host/Workstation requirements in entirety?

IETF RFC 4301, IETF RFC 2711, IETF RFC 1981, IETF RFC 3596, IETF RFC 3810, IETF RFC 4306, IETF RFC 3484, IETF RFC 4308, IETF RFC 4303, IETF RFC 4307, IETF RFC 4835

47

Will this Network Appliance support Multicast Listener Discovery, version 2 (RFC 3810)?

IETF RFC 3810, IETF RFC 271148

Will this Network Appliance support Path MTU Discovery (RFC 1981)?

IETF RFC 198149

Page 26 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 27: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Will this Network Appliance support DNS Extensions for IPv6 (RFC 3596)?

IETF RFC 359650

Will this Network Appliance support Default Address Selection for IPv6 (RFC 3484)?

IETF RFC 348451

Will this Network Appliance support IPsec? IETF RFC 4835, IETF RFC 4307, IETF RFC 4303, IETF RFC 4306, IETF RFC 4308, IETF RFC 4301

52

In addition to the mandatory parts of the IPsec Profile, it is recommended that a Network Appliance with IPsec also support the Authentication Header (AH). Will this Network Appliance support AH?

IETF RFC 430253

Will this Network Appliance support Privacy Extensions (RFC 4941)?

IETF RFC 494154

Please refer to the Product Class definitions in Section 1.6 of the DoD IPv6 Product Profiles for IPv6 Capable Products Version 3.0. The only remaining choice for an IPv6 Product Class is Simple Server. If your product does not fit the definition of a Simple Server, review the Product Profiles to identify an appropriate Product Class and restart this questionnaire. Does the system fit the definition of a Simple Sever?

55

Minimum requirements for a Simple Server include the Base Requirements only, however it is recommended that a Simple Server support as much of the Advanced Server Product Class profile as possible, and it is strongly recommended that a Simple Server support the IPsec Functional Requirements defined in Section 2.2. Will this system meet the Advanced Server requirements in entirety?

IETF RFC 3810, IETF RFC 4307, IETF RFC 3596, IETF RFC 2711, IETF RFC 4306, IETF RFC 4835, IETF RFC 4308, IETF RFC 4301, IETF RFC 4303, IETF RFC 3484, IETF RFC 1981

56

Will this Simple Server support Multicast Listener Discovery, version 2 (RFC 3810)?

IETF RFC 2711, IETF RFC 381057

Will this Simple Server support Path MTU Discovery (RFC 1981)?

IETF RFC 198158

Will this Simple Server support DNS Extensions for IPv6 (RFC 3596)?

IETF RFC 359659

Will this Simple Server support Default Address Selection for IPv6 (RFC 3484)?

IETF RFC 348460

Will this Simple Server support IPsec? IETF RFC 4835, IETF RFC 4308, IETF RFC 4301, IETF RFC 4303, IETF RFC 4307, IETF RFC 4306

61

In addition to the mandatory parts of the IPsec Profile, it is recommended that a Simple Server with IPsec also support the Authentication Header (AH). Will this system support AH?

IETF RFC 430262

Page 27 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 28: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Will this Simple Server support Privacy Extensions (RFC 4941)?

IETF RFC 494163

Do you need to operate Mobile IPv6 over both IPv6 and IPv4 networks?

IETF RFC 555564

Do you require the use of Mobile IPv6 and plan to use real time services such as VoIP?

IETF RFC 556865

Landing Aids

Is your system an Aviation vehicle requiring access to the civil air space with landing aid capabilities?

1

Will your system require only a military Air Worthiness Certification for landing aids versus an FAA certification (A negative response implies an FAA certification or both will be required.)?

2

Does your Aviation system require GPS landing aids? RTCA DO-246C, STANAG 4392, RTCA DO-253A

3

Learning Technologies

Will your system provide an integrated environment for education, training, and decision support?

IEEE 1484.11.1-2004, IEEE 1484.1-20031

Will your system be providing online learning or will your system be used for training the warfighter and support personnel?

SCORM2

Medical Services

Does your CS Medical System use EDI for the exchange of messages containing medical data?

ANSI/HL7 V2.4-20001

Does the system use EDI for the exchange of Healthcare Administrative or Business Transactions?

ASC X12N 835:2006, ASC X12N 834:2006, ASC X12N 837 (Professional):2006, ANSI/HL7 V2.5.1, ASC X12N 270/271:2008, ASC X12N 837 (Dental):2007, ASC X12N 837 (Institutional):2007, ASC X12N 278:2008, ASC X12N 276/277:2008, ASC X12N 820:2007

2

Does the system use EDI for retail pharmacy transactions? NCPDP Batch v1.2, NCPDP v. D.03

Does your Medical System need to format, store, and/or exchange medical images and associated information?

DICOM:2008, DICOM:20064

Does the system exchange data that supports patient care and the management, delivery and evaluation of healthcare services?

HL7 V3.05

Page 28 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 29: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Military Messaging

Does your system require the exchange of Tactical Digital Link (TADIL) bit-oriented messages?

1

Does your system exchange TADIL-J (Link 16) messages or communicate with JTIDS/MIDS radio?

MIL-STD-6016D, IBS TIDP, STANAG 4175 Ed.3

2

Is your system required to exchange Link-16 information over long haul media?

MIL-STD-30113

Does your system require Variable Message Format (VMF) data exchange?

MIL-STD-6017A4

Do you exchange tactical data link (TDL) messages in a NATO environment?

STANAG 5522 ed 15

Does your system integrate and provide a TDL forwarding/gateway functionality?

MIL-STD-6020A6

Does your system integrate and provide a TDL gateway/forwarding functionality for Link 22?

STANAG 5616, Volumes II, and III, Edition 3, STANAG 5616, Volumes II, and III, Edition 4.

7

Does your system require Link 11 data exchange? MIL-STD-6011C8

Does your system use the Sensor Link Protocol (SLP) message set to implement a common digital data exchange mechanism?

SLP-MSG-2109

Is your system used for transferring (though not processing) binary floating-point data?

ANSI/IEEE 75410

Does the system interface with the Defense Messaging System (DMS)?

ITU-T Rec. X.41111

Does your system require the exchange of character-based messages?

MIL-STD-6040B12

Modeling and Simulation

Do your developers employ Activity Modeling? IEEE 1320.11

Do your developers employ Data Modeling? IEEE 1320.22

Do your developers use XML DTDs to exchange UML information?

XMI-ax, OMG XMI v2.1.13

Does your system implement the High-level Architecture (HLA)?

IEEE 1516.2, IEEE 1516, IEEE 1516.14

Page 29 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 30: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Are you required to develop a high-level framework for the development and execution of a HLA Federation or are you required to develop a conceptional model?

IEEE 1516.35

Is your system part of the Weapon Systems domain? CIOTE6

Does your system use HLA and/or DIS? NAS Pt. 1, v2.0, SISO-STD-002-20067

Does DIS enable multi-user access and participation and for live interaction between remote sites, does DIS drive (stimulate) other resources from simulations?

IEEE 1278.2-1995, IEEE 1278.3-1996, IEEE 1278.1A-1998, IEEE 1278.4-1997, IEEE 1278.1-1995

8

Multimedia Processing

Does your design capability involve interactive audiovisual presentation technology or streaming media such as audio streaming or video streaming?

SMIL 2.01

Does your system require Internetworking between Session Initiation Protocol (SIP) and Bearer Independent Call Control Protocol or ISDN User Part?

ITU-T Rec. Q.1912.52

Does your system require Session Initiation Protocol (SIP) in the Authenticated Identity Body (AIB) format?

IETF RFC 38933

Does your system require ISDN to pass the signaling messages between the router and the ISDN switch at the local Central Office (CO)?

ITU-T Rec. Q.921, September 19974

Does your system require SDP routing for SAP, SIP, or RTSP use?

IETF RFC 38905

Does your system require a description to perform the mapping between two signaling protocols: the Session Initiation Protocol (SIP) and the Integrated Services Digital Network (ISDN) User Part (ISUP) of Signaling System No. 7 (SS7)?

IETF RFC 33986

Does your system require ISDN to pass the signaling messages between the router and the ISDN switch at the local CO with Call control and Management?

ITU-T Rec. Q.931, May 19987

Network Technologies

Does your network contain host system implementations of the Internet Protocol (IP) suite?

IETF Standard 3/RFC 1122/RFC 11231

Does your network support e-mail?2

Does your network support typical X.400-based messaging? ACP 123A:20013

Page 30 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 31: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Does your network require medium-assurance messaging services using SMTP?

IETF RFC 2231, IETF RFC 2821, IETF RFCs 2045-2049, IETF RFC 3023, IETF RFC 1870, IETF RFC 2822

4

Does your network require directory services for the location of users and resources on the network?

ITU-T X.500:20015

Does your network require a Domain Name Service for host name/IP address resolution for IPv4 & IPv6?

IETF RFC 2136, IETF RFC 1995, IETF Standard 13/RFC 1034/RFC 1035, IETF RFC 1996

6

Does your network require an ftp facility for IPv4 & IPv6? IETF Standard 9/RFC 9597

Does your network require an ftp facility for IPv6? IETF RFC 24288

Does your network require Lightweight Directory Access Protocol Version 3?

IETF RFC 3673, IETF RFC 33779

Will you be requiring Mobile Cellular? ITU-R M.1457-7:2007, IETF RFC 3963 10

Does your network require time synchronization? IETF RFC 130511

Does your network connect to the Internet? IETF RFC 261612

Does your network use the syntax of URLs and URIs for IPv4 and IPv6?

IETF RFC 1738, IETF Standard 66/RFC 3986

13

Does your system support connectionless data transfer? MIL-STD-2045-47001D(1)14

Does your system require use of the Transmission Control Protocol (TCP)?

IETF Standard 7/RFC 793, IETF RFC 2581

15

Does your system require use of the Internet Protocol (IP) for IPv4?

IETF RFC 3344, IETF RFC 2794, IETF Standard 5

16

Does your system require use of the Internet Protocol (IP) for IPv6?

IETF RFC 3544, IETF RFC 4007 , IETF RFC 4213, IETF RFC 2508, IETF RFC 3173, IETF RFC 3595, IETF RFC 3162, IETF RFC 3697, IETF RFC 1981, IETF RFC 2492, IETF RFC 2507, IETF RFC 2473, IETF RFC 2460, IETF RFC 3596

17

Does your system require Open System Interconnection (OSI) applications to operate over IP-based networks using IPv4 and IPv6?

IETF RFC 212618

Can your Internet-based environment be classified as a "stressed" communications environment?

CCSDS 717.0-B-1/ISO 15894:2000, CCSDS 713.0-B-1/ISO 15891:2000, CCSDS 713.5-B-1/ISO 15892:2000

19

Do your subnets require Asynchronous Transfer Mode (ATM) services?

af-phy-0170.00020

Page 31 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 32: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Does your system include an Integrated Services Digital Network (ISDN)?

ANSI T1.603-1990 (R2000)21

Is signaling at the user/network interface required? ANSI T1.619a-1994, ANSI T1.61922

Is signaling at the node-to-node interface required? ATIS 1000111.2005, ATIS 1000112.200523

Is there signaling layer Interface between a PBX-1 and a DSN Switch via T1 or the Signaling Layer Interface between a Customer IST and a DRSN Voice Switch?

ITU-T Q.955.324

Does your system require Synchronous Optical Network Transmission (SONET) Facilities?

ANSI T1.105-2001, ATIS-PP-0900101.2006, ANSI T1.105.06-2002, ANSI T1.107-2002

25

Will your system generate IP Datagrams for transport over SONET or will your system require IP encapsulation for SONET transport?

IETF RFC 261526

Does your SONET/SDH system need automatic, dynamic bandwidth allocation?

ITU-T G.7042/Y.1305 (March 2006)27

Will your system be supporting Voice over IP? IETF RFC 3265, IETF RFC 3264, IETF RFC 3261, IETF RFC 3550

28

Will your system provide an interface to or support the transport services of a wireless local area network?

IEEE 802.11-200729

Do you need wireless access in remote areas where other technologies may not be available?

IEEE 802.16-200430

Does your subnets require LAN technology for joint interoperability using IPv6?

IETF RFC 246431

Does your system require routing and interoperability between subnetworks?

32

Are routers used to interconnect subnetworks and/or end-systems for IPv4?

IETF Standard 7/RFC 793, IETF Standard 6/RFC 768, IETF RFC 3396, IETF Standard 13/RFC 1034/RFC 1035, IETF RFC 1812, IETF RFC 2131, IETF RFC 2132

33

Are IP routers used for interior routing (within the system) for IPv4?

IETF Standard 54/RFC 232834

Does your organization employ IPv4 Private-Use Network addressing [IETF RFC1918]?

IETF RFC 419335

Are IP routers used for exterior routing (external to the system) for IPv4 & IPv6?

IETF RFC 177236

Are IP routers used for exterior routing (external to the system) for IPv6?

IETF RFC 254537

Page 32 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 33: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Do you need to specify the requirements for an IP SCIP endpoint developer or do you need to specify the requirements for an IP device that provides access for a SCIP endpoint located on a different type of network (non-IP)?

SCIP 215 Rev 2.038

Are IP routers used for interior routing (within the system) for IPv6?

IETF RFC 274039

Does your system include a Combat Net Radio subnet? MIL-STD-188-220D(1)40

Do your subnets require LAN technology for joint interoperability using IPv4?

IETF Standard 37/RFC 826, IETF Standard 41/RFC 894

41

Do your subnets require LAN technology for joint interoperability?

IEEE 802.3-200542

Do your subnets require full duplex, synchronous or asynchronous, point-to-point communications?

IETF RFC 1994, IETF RFC 1989, IETF RFC 1990, IETF RFC 1332, IETF RFC 1570, IETF Standard 51/RFC 1661/RFC 1662

43

Do your IPv6 subnets require full duplex, synchronous or asynchronous, point-to-point communications?

IETF RFC 371144

Do your subnets require a serial line interface? TIA/EIA 232-F, TIA/EIA 530-A, IETF RFC 3241

45

Do you have IPv6 networks that need to be connected via an IPv4 MPLS network?

IETF RFC 479846

Is this a mobile node or a router providing Home Agent capabilities or do you require Mobile Ipv6 operation with IKEv2 and the revised IPsec Architecture?

IETF RFC 487747

Does your system use Generic Routing Encapsulation? IETF RFC 278448

Does your network require support for robust header compression for RTP/UDP/IP, UDP/IP and ESP/IP headers?

IETF RFC 3095, IETF RFC 522549

Will your system generate IP Datagrams for transport over ATM or require IP encapsulation for ATM transport?

IETF RFC 268450

Will your system require any electrical interfaces between 1.544Mb/s to 44.736Mb/s.?

ITU-T G.70451

Will your system require T1.5 or 2 Mb/s interfaces multiplexed to a DS-3 rate?

ITU-T G.73252

Does your system use a Management Information Base (MIB) for managed objects, residing in a virtual information store?

IETF Standard 58/IETF RFC-2578, April 1999.

53

Are you managing IP tunnels via SNMP MIBS? Are you currently using IETF RFC 2667?

IETF RFC 408754

Page 33 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 34: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Does your system support the Simple Network Management Protocol (SNMP) version 2?

IETF Standard 62/IETF RFC 341655

Does your network manage TCP transport policy via SNMP? IETF RFC 402256

Does your network manage UDP transport QOS and policy via SNMP?

IETF RFC 411357

Is the network layer interface between a customer VTU and a DVS node via an ISDN connection?

ITU-T Rec Q.93258

Will your network system need to support rapid deployment to new Internet attachment points?

IETF RFC 3963 59

Does your system require terminations for optical signals for single channel, SONET/SDH type formatted signals?

ATIS 0900105.02-200760

Will you be managing SONET/SDH interfaces on the GIG? IETF RFC 359261

Will your system be managing Optical Interfaces associated with Wavelength Division Multiplexing Systems on the GIG?

IETF RFC 359162

Does your system have to interoperate with the DISN Core upgrade?

ITU-T G.703, ITU-T Rec. G.691 (03/2006), ITU-T Rec. G.957 (03/2006)

63

Does your system require ISDN Service? ANSI T1.113:2000, ANSI T1.605-1991 (R2004), ANSI T1.607-2000 (R2004), ANSI T1.602-1996 (R2004), ANSI T1.601-1999 (R2004), ANSI T1.403.01-1999, ANSI T1.610-1998 (R2003), ANSI T1.114:2000

64

Does your networking environment require IPSec functionality across a broad range of network vendors and implementations?

IETF RFC 5244, IETF RFC 4734, IETF RFC 4308, IETF RFC 4733

65

Does your networking environment require advanced services such as AAA authentication or dynamic allocation of network parameters when nodes enter a network?

IETF RFC 4282, IETF RFC 428366

Would your wireless IP network infrastructure benefit from reduction of network overhead resulting from reduced packet header size in network traffic?

IETF RFC 436267

Does your network environment require secure key management and exchange?

IETF RFC 410968

Does your network include a variety of IPv6 address types, mobile or multi-homed nodes, privacy addressing, or global IPv6 prefixes?

IETF RFC 348469

Does your networking environment require integration of your network with other autonomous networks or existing internetworks?

IETF RFC 427170

Page 34 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 35: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Does your network equipment require IPv6 addressing and connectivity or does your network tie together multiple small network domains into a hierarchal internet system or does your network environment include multiple vendors and networking levels?

IETF RFC 429171

Does your network equipment require IPv6 connectivity or does your network environment include multiple vendors and networking levels or does your networking requirements mandate readily-available testing and troubleshooting tools?

IETF RFC 444372

Do your subnets require ATM services for the Physical Layer? af-phy-0133.000, af-phy-0046.000, af-phy-0086.001, af-phy-0015.000, af-phy-0016.000, af-phy-0043.000, af-phy-0064.000, af-phy-0054.000

73

Does your system require a physical layer interface between a PBX-1or PBX-2 and a DSN switch via T1?

ANSI T1.102-1993 (R2005), ITU-T Q.735.374

Is there a physical layer interface between an ISDN-capable device and a DSN switch via a PRI or BRI circuit or is physical layer interface between a customer VTU and a DSV node via an ISDN connection?

ITU-T Rec I.430, ITU-T I.431 (1993)75

Is there physical layer interface between a Customer ATM Switch and a DATMS-C ATM Switch via ATM?

ANSI T1.416.01-1999, ANSI T1.416.04-2005, ANSI T1.416.02-1999

76

Do your subnets require ATM services for the User-to-Network-Interface?

af-sig-0061.000, af-sig-0076.00077

Do your subnets require ATM services for Layer Management Capabilities?

af-ilmi-0065.00078

Do your subnets require ATM services for Traffic Management Functions?

af-tm-0121.00079

Do your subnets require ATM services for Circuit Emulation Functions?

af-vtoa-0078.00080

Do your subnets require ATM services for AAL1 and AAL5 Functions?

ITU-T I.363.1, ITU-T I.363.581

Do your subnets require ATM services for Private Network-to-Network Interfaces?

af-pnni-0066.000, af-ra-0123.000, af-pnni-0055.000

82

Will your subnets require ATM services for trucking using AAL2?

af-vtoa-0113.00083

Will your subnets use the ATM security framework? af-sec-0100.00284

Do you need to interconnect ATM networks with MPLS networks?

af-aic-0178-00185

Page 35 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 36: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Is there data link layer interface between a customer ATM switch and A DATUMS-U ATM switch via ATM or what is the data link layer interface between a customer ATM switch and a DATMS-C ATM switch via ATM?

ITU-T Rec I.36186

Do you require very precise time synchronization using your existing Ethernet network?

IEEE 1588-200287

Do you want to control what access a network device has if it is plugged into any network port on a network switch, or do you want to control which wireless devices get access to the network through a wireless access point?

IEEE 802.1X:200488

Is network addressing scaled beyond the limits of the class B address space?

IETF RFC 151989

Does the system comprise a fully meshed site to site VPN that must scale to the order of 100 or more VPN end points?

IETF RFC 233290

Does your system profile use Border gateway protocol or does your network topology support less than a full mesh topology or does your network topology BGP communities or is it possible that a BGP speaker in the network may send an unrecognized BGP option?

IETF RFC 4360, IETF RFC 2796, IETF RFC 4364, IETF RFC 3392

91

Is the DDDS used to implement lazy bindings of strings to data, in order to support dynamically configured delegation systems?

IETF RFC 376192

Is the multicast inter-domain routing environment in question, subject to NCID or is it necessary to support multicast to or from within the local routing domain?

IETF RFC 395693

Do you plan to use multicast or do you need to discover neighboring nodes?

IETF RFC 271094

Are you planning to implement SNMP based management for IP?

IETF RFC 4293, IETF RFC 429295

Are you planning to implement IPv6 mobility and use SNMP based network management?

IETF RFC 429596

Does the application use Stateless Address Configuration, and would it benefit from reduced latency, as well as enhanced recovery from address collisions?

IETF RFC 442997

Does a backbone network or intranet need to be protected against attacks on routing protocols?

IETF RFC 455298

Would your IP mobility or multihoming deployments benefit from more efficient and automatic maintenance of Security Associations while mobile nodes moved around the network?

IETF RFC 455599

Are multiple network layers (IPv4 and IPv6 for example) operating in the same network ?

IETF RFC 4760100

Page 36 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 37: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Do you have local area internet segments that are remotely monitored from an ops center via a data network or enough network assets on these remote segments that monitoring them individually would adversely load the communications infrastructure?

IETF RFC 4502101

Does the deployment require header compression to conserve bandwidth?

IETF RFC 4996, IETF RFC 4995, IETF RFC 4815

102

Does your system provide resource priority service in which the higher priority calls are permitted to preempt and use resources of other equal or lower precedence call requests in the digital IP based networks? Does your system use Local Session Controllers(LSCs), Assured Real Time Services (ARTS) Softswitches(SS), or Edge Boundary Controllers (EBCs)?

IETF RFC 3590103

Does your system provide resource priority service in which the higher priority calls are permitted to preempt and use resources of other equal or lower precedence call requests in the digital IP based networks or does your system use Local Session Control?

IETF RFC 4412104

Do you plan to build a low rate wireless personal area network or do you require low rate, low power, radio transceiver or sensors?

IEEE STD 802.15.4-2006105

Do you anticipate needing capabilities dependent on Directory Services-based Quality of Service guarantees or acquiring network or transport infrastructure equipment that require use of Directory Services based Quality of Service capabilities?

IETF RFC 4104106

Does your LSC or ARTS SS or EBC support AS-SIP? IETF RFC 4904107

Does your LSC or ARTS SS generate and process the audio and video media feature tags?

IETF RFC 3840108

Does your system require the use of the URI scheme tel", which describes resources identified by telephone numbers or does your system require the use of a telephone number as: (1) the address-of-record or identifier, or (2) a "dial string?

IETF RFC 3966109

Does your system require an IANA registry specification to list and standardize tel URI parameters and values or does your system require interoperability between independent and/or dissimilar tel URI implementations?

IETF RFC 5341110

Does your system use Session Initiation Protocol (SIP) for interactive communications; if so, is additional privacy beyond that which the SIP user Agent can supply required?

IETF RFC 3323, IETF RFC 3311111

Will the Land Mobile Radio (LMR) system use routers to interconnect subnetworks and/or end-systems for IPv4?

IETF RFC 3011112

Page 37 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 38: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Object

Does your system support Distributed Object Computing (CORBA compliance)?

1

Does your system allow internetworking among distributed objects?

OMG document formal/02-06-012

Will an Event Service be implemented? OMG formal/04-10-023

Will a Transaction Service be implemented? OMG formal/03-09-024

Will a Time Service be implemented? OMG formal/02-05-065

Will a Trading Object Service be implemented? OMG document formal/00-06-276

Will a Notification Service be implemented? OMG document formal/00-06-207

Will you be implementing a data distribution infrastructure using a distributed object model via CORBA and do you require a service that provides a basic building block on which higher-level services impose the conventions and semantics which determine how frameworks of application and facilities objects locate other objects?

OMG formal/04-10-038

Operating System Services

Does your system use a POSIX based Operating System? ISO/IEC 14519, ISO/IEC 9945:20091

Does your Operating System run Win32 applications? Win32 APIs-Current2

Will you utilize a real time or embedded POSIX operating system?

IEEE 1003.13-20033

Does your Operating System run (or intend to run) Linux-based applications?

Linux 3.1, Linux 3.1 PPC32, Linux 3.1 IA324

Does your Operating System run UNIX -based applications? UNIX Version 35

Optical Digital Technologies

Will your system require WDM, long haul, optical interfaces? ITU-T G.6921

Will your system require dense WDM (DWDM) optical interfaces?

ITU-T G.694.12

Will your system interface with SDH networks? ITU-T G.707/Y.1322:20073

Does your system require SDH linear or ring protection schemes?

ITU-T G.8414

Page 38 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 39: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Will your system require 10 Gb/s or 40 Gb/s short haul (0.6 Km to 2 Km) optical interfaces?

ITU-T Rec. G.693 (05/2006)5

Will your system interface with multiple vendors or a service provider with OTN G.709 interfaces at rates of 2.5G, 10G, and 40Gb/s?

ITU-T G.709/Y.13316

Does your system provide transport of or interfaces to FICON/ESCON, GigE or ITU-T G.709?

ITU-T G.7041/Y.1303:20087

Does your SONET/SDH system need automatic, dynamic bandwidth allocation?

ITU-T G.7042/Y.1305 (March 2006)8

Do you require UNI signaling to create and delete connections on-demand or do you need to establish SONET/SDH, OTN, and Ethernet connections ?

OIF-UNI-02.0-Common9

Platform Communications Services

Does your system require official organizational-messaging traffic between DoD organizations?

IETF RFC 2822, IETF RFCs 2045-2049, IETF RFC 2231, IETF RFC 2821, IETF RFC 3023, IETF RFC 1870, ACP 123A:2001

1

Does your network require a Domain Name Service for host name/IP address resolution?

IETF RFC 1996, IETF RFC 1995, IETF RFC 2136, IETF Standard 13/RFC 1034/RFC 1035

2

Does your network require directory services for the location of users and resources on the network?

ITU-T X.500:20013

Does your network require Lightweight Directory Access Protocol Version 3?

IETF RFC 2589, IETF RFC 33774

Is your system a router and will it be internal to the GIG-BE network?

IETF RFC 30325

Will your system need to exchange link, and node topology information with other GIG BE Provider routers or will your system forward IP Datagrams internal to the GIG BE network or will your system interface to GIG BE Provider routers?

IETF RFC 11956

Does your system require an intra-system routing protocol? ISO/IEC 105897

Will your system interface to the GIG-BE as an autonomous system and switch MPLS packets or will your system run BGP with the GIG-BE border router and switch MPLS packets?

IETF RFC 31078

Does your system require a User-to-Network (UNI) signaling interface to the GIG-BE network?

OIF-UNI-01.0-R2-Common9

Will your system be used as a label switched router in the GIG-BE or will your system signal over a UNI interface to the GIG-BE a request for precedence services?

IETF RFC 320910

Page 39 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 40: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Does your system require the file format, known as LDIF, for LDAP Data Interchange Format?

IETF RFC 284911

Does your system use Session Initiation Protocol (SIP) for interactive communications?

IETF RFC 332612

Will your system be utilizing messaging over an IP-based network?

IETF RFC 326213

Will your system exchange routing information with GIGBE border routers using BGP?

IETF RFC 238514

Do you use multicast services or do you expect the GIG BE to transport multicast packets to the multicast rendezvous point or does your network create shortest-path trees per source?

IETF RFC 460115

Product Data Interchange

Does your Combat Support system require product data interchange between CAD/CAM systems?

ISO 10303-22:1998, ISO 10303-105:1996, ISO 10303-31, ISO 10303-32, ISO 10303-224:2001, ISO 10303-21:2002, ISO 10303-203:1994, ISO 10303-202, ISO 10303-42:2003 w/Cor 1:2007, ISO 10303-11:2004, ISO 10303-43:2000, ISO 10303-1, ISO 10303-101:1999, ISO/TR 10303-12, ISO/IEC 13584-42, ISO 10303-11:2004, ISO 10303-42:2003 w/Cor 1:2007, ISO 10303-201, ISO 10303-44:2000, ISO 10303-45, ISO 10303-46, ISO 10303-47, ISO 10303-49, ISO/IEC 13584-20, ISO 10303-41:2000

1

Does the system process, store, transmit or receive cryptology or cryptology related data?

CCDM/CCDF Traffic 4.22

Are you providing SIGINT reporting? USSID SG5302, (U) USSID CR1500, (U) USSID DA3611, USSID DA3620, USSID CR1400, (U) USSID CR1501, USSID AP2405, USSID SG5301, USSID CR1551

3

Does the system use facility CAD applications? NCS Version 3.1 4

Does your Combat Support system require the use of bar codes?

ANSI/AIM-BC15

Page 40 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 41: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Does your Combat Support System exchange product model data for ship building?

ISO 10303-210, ISO 10303-203:1994, ISO 10303-204, ISO 10303-207, ISO 10303-32, ISO 10303-201, ISO 10303-11:2004, ISO 10303-31, ISO 10303-224:2001, ISO 10303-225, ISO 10303-202, ISO 10303-214, ISO 10303-21:2002, ISO 10303-101:1999, ISO 10303-44:2000, ISO 10303-46, ISO 10303-47, ISO 10303-22:1998, ISO/TR 10303-12, ISO 10303-209, ISO 10303-42:2003 w/Cor 1:2007, ISO 10303-43:2000, ISO 10303-41:2000, ISO 10303-1, ISO 10303-105:1996, ISO 10303-45, ISO 10303-49

6

Will the system use Building Information Models (BIM) as defined in the Real Property Acceptance policy guidance?

IFC 2x27

Does the Navy require ship or facility product model technical data for my system to do design certification or lifecycle support or does the Navy need technical data on the piping, HVAC, cable trays, or mechanical subsystems in my system to do engineering?

ISO 10303-227:2005, ISO/AP 10303-212:2001

8

Does the Navy require ship product model technical data for my system to do design certification or lifecycle support or does the Navy need compartmentation data on my system to do vulnerability analysis or flooding and casualty control?

ISO 10303 Application Protocol 215:20049

Does the Navy require ship product model technical data for my system to do design certification or lifecycle support or does the Navy need hull form information to do stability, hydrodynamic, hydristatic, wake, efficiency, or other analysis?

ISO 10303 Application Protocol 216:200310

Does the Navy require ship product model technical data for my system to do design certification or lifecycle support or does the Navy need ship product model data on plate/beam/stiffener structure to do repairs, modifications, radar cross section analysis?

ISO 10303 Application Protocol 218:200411

Radio Communications

Does your radio subsystem operate in the Low Frequency (LF)/Very Low Frequency (VLF) frequency bands?

MIL-STD-188-140A1

Does your Automatic Link Establishment (ALE) or radio subsystem operate in the High Frequency (HF) bands?

MIL-STD-188-141B2

Does your system require anti-jamming capabilities for HF radio equipment?

MIL-STD-188-148A3

Does your system require HF data modem interfaces? MIL-STD-188-110B4

Is your system fielded in an aviation vehicle? ARINC 750-4, RTCA DO-186B5

Page 41 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 42: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Does your radio subsystem require operation in the Very High Frequency (VHF) frequency bands?

MIL-STD-188-2426

Does your radio subsystem require operation in the Ultra High Frequency (UHF) frequency bands?

MIL-STD-188-2437

Does your radio subsystem require anti-jamming capabilities for UHF radio equipment?

STANAG 42468

Does your radio subsystem require operation in the Super High Frequency (SHF) frequency bands?

MIL-STD-188-1459

Does your system require communication with the JTIDS/MIDS radios?

STANAG 4175 Ed.310

C4ISR domain: Do you use Unattended Measurement and Signature Intelligence (MASINT) Sensors (UMS)?

SEIWG-00511

Does the application entail over the air communication of high capacity C4ISR data?

Common Data Link Communications Standard

12

Does your system require on-demand or real-time video and audio streaming?

IETF RFC 3605, IETF RFC 384313

Does your system require access to the Land Mobile Radio (LMR) to enable Public Safety officials to communicate, in a secured or encrypted way, with each other to protect their operations in any emergency situation?

TIA-102.AABC-B-4, TIA-102.BAAD-1, ANSI/TIA-102.AABC-B-2-2007, TIA-102.BAAD, TIA TSB-102.BAFA-A, TIA-102.AABC-B-5, ANSI/TIA-102.CAAB-B, TIA TSB-102.BAGA, TIA TSB-102.AABG-1, TIA TSB-102.AABG, ANSI/TIA-102.AABC-B-3-2008, TIA-102.AACE

14

Does your system require access to the Land Mobile Radio (LMR) to enable Public Safety officials to communicate, in a secured or encrypted way, with each other to protect their operations in any emergency situation?

TIA-102.BACA-A, TIA-102.BAAC-A, ANSI/TIA-102.AABA-A-2004, ANSI/TIA-102.AAAB-A-2005, ANSI/TIA/EIA-102.BADA-2000, ANSI/TIA/EIA-102.AACA-2001, ANSI/TIA/EIA-102.AAAD-2002, ANSI/TIA-102.AABB-A-2005, TIA-102.AACD, TIA-102.BACD-A, TIA-102.BAEA-A, TIA-102.BACE, TIA-603-C, ANSI/TIA-102.AABC-B-2005, TIA-102.AABD, TIA-102.AABC-B-1, TIA TSB-102.CAAC, TIA TSB-102.BACC-A, ANSI/TIA-102.BAEE-A, ANSI/TIA-102.BAEC, ANSI/TIA-102.BAEB-A-2005, ANSI/TIA-102.BADA-1-2006, ANSI/TIA-102.BABA-2003, ANSI/TIA-102.AACB-2002, ANSI/TIA-102.AACA-2-2003, ANSI/TIA-102.AACA-1-2002, TIA-102.BAHA

15

Will your system provide an interface to or support handover capabilities.?

IEEE 802.21-200816

Page 42 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 43: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Raster/Image Data Interchange

Does your system exchange large still-raster images where lossy compression is acceptable?

JPEG 1

Does your system require the interchange of lossless raster images such as animation?

GIF v89a2

Does your system support Virtual Reality modeling and capabilities for 3-D data representation?

ISO/IEC 14772-13

Does your system support portable network graphics? ISO/IEC 15948:20044

Representation

Does your system need to mediate environmental data for the physical and/or visual representation of natural and man-made objects among multiple users and producers?

ISO/IEC 18025:2005(E), ISO/IEC 18023-1:2006(E), ISO/IEC 18026:2006(E), ISO/IEC 18042-4:2006(E), ISO/IEC 18024-4:2006(E), ISO/IEC 18041-4:2005(E), ISO/IEC 18023-3:2006(E), ISO/IEC 18023-2:2006(E)

1

Satellite Communications

Does your system transmit data from space? SCPS-TP, SCPS-NP, SCPS-FP1

Does your system require 5-KHz or 25-KHz single-channel access service for the transmission of voice or data?

MIL-STD-188-181C2

Will your satellite communications terminal be required to operate over Intelsat Standard A, B, F and H satellites operating in the 6 and 4GHz Frequency Bands?

IESS-2073

Will your satellite communications terminal be required to operate over Intelsat Standard C, E, and K satellites operating in the 14 and 11/12 GHz Frequency Bands?

IESS-2084

Do your SATCOM systems need to access Intelsat V and VA in higher than nominal orbital inclination?

IESS-411, Rev 45

Do your SATCOM Modems require ensuring the interoperability of QPSK operating in Frequency Division Multiple Access at intermediate data rate (IDR)?

IESS-308 Rev. 116

Do your SATCOM Modems operate on Intelsat carriers (except SCPC carriers) in the 6 GHz Frequency Band?

IESS-401 Rev. 77

Does the system use short-delay, report-broadcast functions and operate over 5- and 25-kHz UHS SATCOM channels?

MIL-STD-188-1868

Does your system require 5-KHz Demand-Assigned Multiple Access (DAMA) service for the transmission of voice or data?

MIL-STD-188-182B9

Page 43 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 44: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Does your system require 25-KHz Time Division Multiple Access (TDMA)/DAMA service for the transmission of voice or data?

MIL-STD-188-183B:200410

Do your data controllers operate over single-access 5-KHz and 25-KHz UHF SATCOM channels?

MIL-STD-188-184A, MIL-STD-188-184(3)11

Does your MILSATCOM equipment control access to DAMA UHF 5-KHz and 25-KHz MILSATCOM channels?

MIL-STD-188-185(2)12

Does your satellite communications terminal need to operate in the SHF spectrum or do you require DSCS or WGS terminal certification?

MIL-STD-188-164A(2)13

Do you need a non-IP based, legacy FDMA modem for your satellite communications terminal that will operate in the SHF spectrum or do you require DSCS or WGS terminal certification?

MIL-STD-188-165A(1)14

Are you required to ensure interoperability of SATCOM baseband equipment?

MIL-STD-188-168(1)15

Does your system have waveform, signal processing, and protocol requirements for Medium Data Rate (MDR) Extremely High Frequency (EHF) satellite data links?

MIL-STD-188-136A(2)16

Does your system have waveform, signal processing, and protocol requirements for acquisition, access control and communications for Low Data Rates (LDR) (75 to 2,400 bps) EHF satellite data links?

MIL-STD-1582D(2)17

Does your system require Digital Storage Media Command and Control (DSM-CC)?

ISO/IEC 13818-618

Does your system require Digital Video Broadcasting (DVB) for data broadcasting?

ETSI EN 301 19219

Does your system require Digital Video Broadcasting (DVB) Framing structure, channel coding and modulation for 11/12 GHz satellite services?

ETSI EN 300 42120

Is your system compatible with the waveform, signal processing and protocols for legacy EHF systems?

MIL-STD-3015A21

Does your system require the use of MPEG-2 Systems, Video and Audio in satellite, cable and terrestrial broadcasting applications?

ETSI TR 101 15422

Secure Operating System

Are evaluation criteria necessary for Basic Robustness of your Operating System?

CAPP1

Page 44 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 45: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Does your system require the Protection Profile for Multilevel Operating Systems in Environments Requiring Medium Robustness which specifies security requirements for commercial-off-the-shelf (COTS) general-purpose multilevel operating systems in networked environments containing sensitive information?

MLOSPP2

Does your system require the Protection Profile for Single-level Operating Systems in Environments Requiring Medium Robustness which specifies security requirements for commercial-off-the-shelf (COTS) general-purpose operating systems in networked environments containing sensitive information?

SLOSPP3

Security Protocols

Does your system require secure organizational messaging? ACP 120 1

Are secure web communications required for client/server applications such as VPN or email?

IETF RFC 4346, IETF RFC 52462

Does your system require secure ftp? IETF RFC 22283

Does your system require components that issue, revolve, and manage public key certificates?

CIMCPP4

Does your system use tokens for sensitive but unclassified (SBU) application (Class 4) in DoD PKI?

PKIKMITKNPP5

Is this an IT implementation that provides DNS capabilities? IETF RFC 4035, IETF RFC 4033, IETF RFC 4034

6

Does your system require IPSec? IETF RFC 24037

Will your system require Layer 3 VPN services from the GIGBE?

IETF RFC 23858

Is this an IT implementation requiring Kerberos (or non-PKI) based authentication?

IETF RFC 41209

Does your system require protection of the data portion and/or header portion of the IP packet or does your system require security services at the IP layer or does your system require a key exchange mechanism to establish IP Security Associations?

IETF RFC 430610

Does your network environment risk attack when using Neighbor Discovery functionality?

IETF RFC 397111

Does your system require secure network services in an IP environment?

IETF RFC 397212

Does your system require a secure network management protocol?

IETF RFC 5592, IETF RFC 5591, IETF RFC 5590

13

Page 45 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 46: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Does your system require network-layer security in an IP environment?

IETF RFC 430114

Does your system require datagram authentication or does your system require security services at the IP layer?

IETF RFC 430215

Does your system require authentication and encryption in an IP environment?

IETF RFC 430316

Does your system require protection of the data portion and/or header portion of the IP packet or does your system require security services at the IP layer?

IETF RFC 4835, IETF RFC 430717

Do you need to implement a secure mail system for information exchange across the GIG?

IETF RFC 385018

Will you be using IPsec and IKE protocols or do you require authentication, confidentiality, or integrity protection?

IETF RFC 486919

Are secure communications required for real-time applications such as VoIP or DDS or are secure communications required over a datagram transport such as UDP/IP?

IETF RFC 434720

Does your system require secure remote access via the Internet?

IETF RFC 425021

Does this application require file transfers for System Administrators, such as in file backups or mass storage?

IETF RFC 421722

Does this application require the use of encryption and authentication at very high data rates (>10 Gb/s)?

IETF RFC 410623

Does your application need to secure XML-based Internet transactions using PKI and digital certificates or benefit from centralizing PKI and digital certificate handling to the server-side instead of client applications?

W3C XKMS 2.024

Does your information systems and networks need to comply with all the audiovisual and multimedia systems security control protocols in the H.235.0 standard?

ITU-T Rec. H.235.025

Does your implementation require Type-1 encryption over an IP-based environment?

HAIPE IS v3.0.226

Does your system achieve the use of SDP Security Preconditions?

IETF RFC 502727

System Management Services

Does your system support the Simple Network Management Protocol (SNMP)?

IETF RFC 3412, IETF RFC 3413, IETF RFC 3411

1

Will your system be utilizing host-to-host communications over an IP-based network?

IETF RFC 32892

Page 46 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 47: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Does your system require management for telecommunications switches?

ANSI T1.208:1997, ITU-T M.3400:2000, ANSI T1.204:1997

3

If your system manages a data communications network, will your system require SNMP MIB modules?

IETF RFC 1473, IETF RFC 2789, IETF RFC 2737, IETF Standard 62/IETF RFC 3418, IETF RFC 1471, IETF RFC 2788, IETF RFC 1472, IETF RFC 2515, IETF RFC 2006, IETF RFC 2605, IETF RFC 1657

4

Does your Windows based System Management Services system use the Distributed Management Task Force (DMTF) Common Information Model (CIM)?

IETF RFC 3060, CIM HTTP, CIM XML, DMI 2.0, CIM Schema v2.10.1

5

Does your network management system utilize SNMPv3 Management Framework?

IETF Standard 62/IETF RFC 34176

Does your system require the GIG-BE to provide guaranteed delivery services?

IETF RFC 32707

Is your system used internal to the GIG-BE packet core? IETF RFC 38108

Will you be managing all Ethernet interfaces on the GIG? IETF RFC 36359

Will your system be required to inter-work with other systems using SDH protection schemes?

ITU-T G.84210

Is your system implementing IGMP Version 3 to support Source Specific Multicast?

IETF RFC 337611

Does your system use any of the IEEE 802 LAN/MAN technologies: IEEE 802.3, IEEE 802.11, IEEE 802.15, or IEEE 802.16, or does your system use VLAN Bridges within a Bridged LAN infrastructure?

IEEE 802.1Q-200512

Does your system require a protocol to support mobile nodes in DoD IPv6 networks?

IETF RFC 377513

Does your system require a set of extensions for supporting generic policy based admission control in RSVP?

IETF RFC 275014

Does your system require mobility support in IPv6 and mechanisms to mitigate the security risks in Mobile IPv6 signaling between Mobile Nodes and Home Agents?

IETF RFC 377615

Does your system require OTN linear protection? ITU-T G.808.1 (March 2006)16

Is your system a router and will it be internal to the GIG-BE network?

IETF RFC 303217

Is your system using MSDP between Protocol Independent Multicast Sparse Mode (PIM-SM) [PIM-SM] domains to convey information about active sources available in other domains?

IETF RFC 361818

Page 47 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 48: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Will your system need to support Resilient Packet Ring or will your system interface with metropolitan or wide area Ethernet networks?

IEEE 802.1719

Does your system require an extension of the Internet Control Message Protocol (ICMP) to enable hosts attached to multicast or broadcast networks to discover the IP addresses of their neighboring routers?

IETF RFC 125620

Does your system require access to the Land Mobile Radio (LMR) to enable Public Safety officials to communicate, in a secured or encrypted way, with each other in order to protect their operations in any emergency situation?

TIA/EIA 102.BAAA-A21

Will your system signal over a UNI interface to the GIG-BE a request for precedence services?

IETF RFC 320922

Do you plan on implementing advanced network monitoring capabilities into your system?

IETF RFC 327323

Do you need to implement a network management system which requires the "control" access rights to network devices?

IETF RFC 341524

Do you plan on implementing a Policy Based Core Informational Model which is consistent with IETF definitions in your Policy-Based Network Management implementations?

IETF RFC 346025

Does your system require secure remote access via the Internet or if web services are used for normal secure access, are there any circumstances when they might not be available when needed and where a secure remote login console would provide the necessary management control capability that the SNMP agent may not provide?

IETF RFC 4255, IETF RFC 4251, IETF RFC 4252, IETF RFC 4256, IETF RFC 4253, IETF RFC 4254

26

Does your system implement any IETF-standardized components that are managed collectively by a single SNMP agent, such as routers, switches, hubs or blade servers?

IETF RFC 413327

Does your network management system manage or monitor IP routers that implement OSPF v2?

IETF RFC 475028

Technical Data Interchange (graphics)

Does the application require the inclusion of graphical information within XML encoded data?

Scaleable Vector Graphics v1.11

Can this standard be used to capture and transmit fault information from a weapon system?

S1000D 2.32

Transaction Processing

Page 48 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 49: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Does your system require guaranteed delivery services from the GIG BE or does your system require preemption services from the GIG-BE or does your system set the DiffServ Code Points or TOS bits in the IP Datagram?

IETF RFC 2918 , IETF RFC 2863 , IETF RFC 2439

1

Will your system implement Electronic Records Management? DoD 5015.02-STD:20072

Transport-Oriented (quality of service)

Will your IP-based networks require Quality of Service (QoS) standards?

IETF RFC 2210, IETF RFC 3168, IETF RFC 3175, IETF RFC 2474, IEEE Std. 802.1D:2004, IETF RFC 2205, IETF RFC 2207, IETF RFC 3031

1

Will your IP-based networks require Quality of Service (QoS) standards for voice services within the DSN?

ITU-T P.800, ITU-T P.8622

Does your system require guaranteed IP transport services from the GIG-BE or does your system class mark IP packets using the DSCP/CSCP bits with the IPv4/v6 Datagram?

IETF RFC 31403

Does your system require IP network transport using multiple IP connections to ensure increased reliability?

IETF RFC 49604

Does your system require guaranteed delivery services from the GIG BE or does your system require preemption services from the GIG-BE or does your system set the DiffServ Code Points or TOS bits in the IP Datagram?

IETF RFC 25975

Will your system be used as a label switched router in the GIG-BE or will your system signal over a UNI interface to the GIG-BE a request for precedence services?

IETF RFC 3032, IETF RFC 32096

In order to define CoS, does your system mark the DSCP/CSCP or TOS bits or does your system require the GIG-BE to provide guaranteed delivery services?

IETF RFC 32707

In order to define CoS, does your system mark the DSCP/CSCP or TOS bits?

IETF RFC 32468

Does your system need to support GMPLS or will your system require automated provisioning services from the GIG-BE or does your system interface to the GIG-BE control plane via the UNI?

IETF RFC 34739

Will your system interface to the GIG-BE as an autonomous system and switch MPLS packets or will your system run BGP with the GIG-BE border router and switch MPLS packets?

IETF RFC 310710

Are you converting analog data to digital for transmission? ITU-T G.73311

Do you use NCIDS or is Quality of Service a required capability?

IETF RFC 3181 , IETF RFC 3182 , IETF RFC 2961 , IETF RFC 3703, IETF RFC 2215

12

Page 49 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 50: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Are you using RSVP and SIP protocols in your application or are you planning to use voice over IP and other on line multimedia applications?

IETF RFC 352413

Will there be planning, organizing and managing the Policy Quality of Service (QoS) Information Model?

IETF RFC 4411, IETF RFC 364414

Will you be in charge of selection and conditioning of traffic in the datapath spans both major QoS architectures: Differentiated Services and Integrated Services?

IETF RFC 367015

Does your system provide multi-party applications, call control, and call services in a distributed peer-to-peer fashion? Does your system require attended call transfer or call-pickup? Does your system use Local Session Controllers(LSCs), Assured Real Time Services (ARTS) Softswitches(SS), or Edge Boundary Controllers (EBCs)?

IETF RFC 389116

User (Physical/Cognitive)

Does your system display Common Warfighting Symbology at the user interface?

MIL-STD-2525C1

User Interface Services

Does your system provide a Common Desktop Environment (CDE) as its POSIX user interface?

C9031

Does your system provide a Microsoft Windows (or Windows compliant) user interface?

Win32 APIs-Current2

Does your weapons system require National Geospatial Intelligence Agency (NGA) generated map data?

WSTAWG MDLS, IETF RFC 1997 3

Are you representing languages in your application? ISO 639-2:19984

Does your system provide both national and international VoIP call services over internet or ISDN circuit switched data network?

ITU-T Rec. Q.850, May19985

Video Teleconferencing

Does your system include video teleconferencing or Multipoint Control Units (MCUs)?

ITU-T G.722.1:2005, ITU-T G.728, ITU-T H.261, ITU-T G.711

1

Does your system require use of motion video or video conferencing?

ITU-T H.263, January 20052

Page 50 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 51: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Does your Video Teleconferencing Units and Multipoint Control Units operate over packet-based tcp/ip networks?

ITU-T T.122:1998, ITU-T H.245 (07/2003), ITU-T H.245 (11/2000), ITU-T H.225.0:2003, ITU-T H.225.0:2000, ITU-T T.81, ITU-T T.127, ITU-T T.124:1998, ITU-T T.123:1999, ITU-T T.125:1998, ITU-T T.120, ITU-T H.323:2000, ITU-T H.248, IETF RFC 3261, ITU-T T.126:1997, ITU-T T.128

3

Will your system be supporting Voice over IP, or will your system be supporting VTC, or does your system require real-time data transport?

IETF RFC 35504

Does your system use require on-demand or real time video and audio streaming or will your system be supporting Voice over IP?

IETF RFC 36055

Do your VTC terminals operate on IP-based broadcast-quality video at rates of less than 1 Mbps?

ITU-T Rec. H.264 (03/2009)6

Will your system be required to handle multimedia sessions or VoIP?

IETF RFC 45667

Does your system include video teleconferencing (VTC) or Multipoint control units or VTC gateways or gatekeepers?

ITU-T H.323 (07/2003)8

Does your system use VoIP or does your voice traffic require low data rates or traverse a satellite link or low bandwidth network circuit?

ITU-T G.7299

Does your system require Internetworking between Session Initiation Protocol (SIP) and Bearer Independent Call Control Protocol or ISDN User Part?

ITU-T Rec. Q.1912.510

Does your system require Session Initiation Protocol (SIP) in the Authenticated Identity Body (AIB) format?

IETF RFC 389311

Does your system require ISDN to pass the signaling messages between the router and the ISDN switch at the local CO with Call control and Management?

ITU-T Rec. Q.931, May 1998, ITU-T Rec. Q.921, September 1997

12

Does your system require SDP routing for SAP, SIP, or RTSP use?

IETF RFC 389013

Does your system require a description to perform the mapping between two signaling protocols: the Session Initiation Protocol (SIP) and the Integrated Services Digital Network (ISDN) User Part (ISUP) of Signaling System No. 7 (SS7)?

IETF RFC 339814

Do you use or interface with payload 64 KB/S or does your ISDN data terminal produce data not compatible with non-linear encoding used in voice or do you need a payload format transparent transport for a 64KB/S data stream?

IETF RFC 404015

Page 51 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 52: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Web Services

Does your network connect to the Internet? IETF RFC 1738, IETF RFC 26161

Does your system use web services? OASIS WS-BusinessActivity 1.12

Do you require a common reference for interoperable text manipulation on the World Wide Web, building on the Universal Character Set, defined jointly by the Unicode Standard and ISO/IEC 10646?

CharModel:20053

Does your system, product, application or service need to interoperate with Content Staging?

IETF RFC 35304

Does your system need to test whether the information content of an XML document or XML document subset has been changed?

W3C Canonical XML 1.05

Do you need to describe the capabilities and preferences of your device for use with content delivery?

W3C CC/PP: Structure and Vocabularies 1.0

6

Do you need to split XML documents into smaller manageable chunks and then be able to merge them back together?

W3C XInclude 1.07

Is your HTML expected to evolve into XML applications? W3C XHTML 1.0, XSLT 1.0, CSS2:1998, XHTML 1.1: 31 May 2001

8

Does your system require document interchange of XML documents?

DOM Level 3 W3C, XML 1.1:2004, XML 1.0 (Third Edition)

9

Will you be transforming XML through the use of Style Sheets? XSLT 1.010

Does your system require encryption algorithms for XML-encoded data?

XML-Encryption W3C11

Does your system require the use of XML tags with the same name but different semantics?

Namespaces in XML 1.112

Does your system require locating and selecting elements and data from XML documents?

XPath 2.0:2007, XPATH 1.013

Is your system required to support formally-specified access control policies or does your system require the application of access control policies for Web services access or XML-based communications?

XACML 2.0 OASIS14

Does your system require the exchange of assertions (information) about user authentication, attributes or authorization, such as between online business partners?

SAML 2.0 OASIS15

Does your system require web-enabled access to the file system?

IETF RFC 325316

Page 52 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 53: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Does the system need to perform identity service discovery and invocation?

ID-WSF 2.017

Does your system require publishing and discovery of web services?

UDDI 3.0.218

Does your system require state management and sessions during http connectivity?

IETF RFC 296519

Does your net-centric application require integration with a Portal?

JSR-16820

Does your net-centric application require peer-to-peer messaging capabilities to communicate with other applications?

JSR-91421

Does your system require support for portlets? WSRP OASIS22

Would remote configuration or monitoring of application software, systems, networks, databases, or hardware be important to your mission?

WSDM V1.023

Do you need a language for specifying, visualizing, constructing, and documenting the artifacts of software systems or what are the best engineering practices with regards to the modeling of large and complex systems?

UML 2.224

Does your application require multiple subscribers to a single SOAP message, where the message producer does not need to know about the message subscribers?

OASIS WS-BaseNotification 1.325

Does your system require the interoperability in the exchange of information using SOAP, WSDL, UDDI, SSL 3.0/TLS 1.0, HTTP, or X.509?

WS-I Basic Profile 1.126

Does this application use Web Services implemented with SOAP or is there a need for end-to-end message content security and not just transport-level security?

WS-Security 1.127

Does your system require exchanging SOAP messages with guaranteed delivery, no duplicates, and guaranteed message ordering ?

WS-Reliability 1.128

Is there a requirement to adhere to interoperable metadata standards, is there a need to describe resources that enable more intelligent information discovery systems?

ISO 15836:200329

Does your system require notification to an existing web service?

WS-Eventing30

Does your system require support for message transmission through networks that include processing nodes such as endpoint managers, firewalls, and gateways in a transport-neutral manner?

W3C WS Addressing 1.0 - Core31

Page 53 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed

Page 54: Secure Questionnaire 10 1.0

UNCLASSIFIED

PROFILING QUESTIONNAIRE

DISRonline 10-1.0

Be aware not all questions have a standard associated with them.

Is there a need to create user accounts and validate users as part of a web-services based infrastructure or does the system require web services such as Single Sign-On?

OASIS SPML v2.032

Does the system interact share data or interoperate with other systems or services in a net-centric environment regardless of the Information Assurance classification of the system or users?

OWL, SPARQL Query Language for RDF:2008

33

Does your system/application require web based security services?

OASIS WS-Trust 1.3, OASIS WS-SecurityPolicy 1.2

34

Do you need to transform or generate XML from another XML source, or do you need more XML transformation operations than those provided by XSLT 1.0, such as content grouping and true datatype recognition during processing?

XSLT 2.0:200735

Do you use several web services together in a combined work process or do you want to pass the output of one (or more) web service(s) automatically into another web service(s) without changing or recoding the web services themselves?

OASIS WS-BPEL v2.036

Does your application use WS-Notification and need an intermediate message broker that sends messages to multiple consumers on behalf of the message producers?

OASIS WS-BrokeredNotification 1.337

Does your application use WS-Notification and require multiple ways to define which topics a user wants to subscribe for messages?

OASIS WS-Topics 1.338

Does your application need to define Qualilty of Service parameters in the WSDL or need a standard way to describe REST Web Services?

W3C WSDL 2.0 Pt. 139

Does your application use WSDL 2.0 and benefit from the normative message exchange patterns like In-Only and In-Out?

W3C WSDL 2.0 Pt. 240

Do your services need to specify certain criteria that must be met before service consumers can connect, e.g. security and reliability or need to specify connection policies that cannot be expressed in a WSDL?

W3C WS-Policy 1.5 - Framework41

Does my application need to access computer and network resources remotely using Web Services?

DMTF WS-Management 1.0.042

Do you need to transport messages over protocols other than HTTP/HTTPS or can a single message be delivered to recipients over multiple transport protocols or do you need a callback mechanism for asynchronous invocation?

W3C WS-Addressing 1.0 Metadata, W3C WS-Addressing 1.0 SOAP Binding

43

Page 54 of 54UNCLASSIFIEDValid Date Promulgation

Memo Signed