DEFENSE INFORMATION SYSTEMS AGENCY (DISA) HOSTING OF ALL NAVY WEBSITES:
UNCLASSIFIED//
RTTUZYUW RHSSXYZ0001 0672319-UUUU--RHSSSUU.
ZNR UUUUU
R 072311Z MAR 08
FM CNO WASHINGTON DC//N6//
TO AL NAVADMIN
NAVADMIN
INFO CNO WASHINGTON DC//N6//
DON CIO WASHINGTON DC
CMC WASHINGTON DC//C4//
DISA WASHINGTON DC//UNCLAS //N02000//
BT
UNCLAS
PASS TO OFFICE CODES:
FM CNO WASHINGTON DC//N6//
TO NAVADMIN
INFO CNO WASHINGTON DC//N6/N61/N6N/N6F// DON CIO WASHINGTON DC CMC
WASHINGTON DC//C4// DISA WASHINGTON DC// UNCLAS //N02000//
NAVADMIN 061/08
MSGID/GENADMIN/CNO WASHINGTON DC/N6/MAR//
SUBJ/DEFENSE INFORMATION SYSTEMS AGENCY (DISA) HOSTING OF ALL NAVY
WEBSITES//
REF/A/NAVADMIN 145-07/CNO/051353ZJUN2007//
REF/B/NAVADMIN 275-06/CNO/042205ZOCT2006//
REF/C/DOC/PORTAL AND WEBSITE REGISTRATION GUIDE/DCNO N6/JUNE 2007//
REF/D/CTO/FILTERING WEB SERVICES TRAFFIC (HTTP AND HTTPS) AT INTERNET
ACCESS POINTS (IAPS)/JTF-GNO CTO 06-17//
REF/E/DOC/DCNO N6/2005 JUN 14//
NARR/REF A REQUESTED INVENTORY OF ECHELON II WEBSITES BE PROVIDED TO
OPNAV N6 AND DIRECTED ECHELON II ASSUMPTION OF RESPONSIBILITY FOR ALL
SUBORDINATE COMMAND WEBSITE INVENTORY AND INFRASTRUCTURE FOR FUTURE
CONSOLIDATION. REF B ANNOUNCED THE NAVYS PORTAL - WEBSITE INVESTMENT
MORATORIUM FOR FISCAL YEAR 2007 (FY07). REF C PROMULGATED THE BUSINESS
RULES AND PROVIDES GUIDANCE FOR COMMANDS IN THE REGISTRATION OF ALL
PORTALS AND WEBSITES. REF E IS OPNAVINST 5239.2, WHICH PROVIDES THE
POLICY FOR DOMAIN NAME ESTABLISHMENT AND USE WITHIN THE NAVY AS WELL AS
REGISTRATION WITH THE DEPARTMENT OF DEFENSE NETWORK INFORMATION
CENTER.// POC/HUGH MCCULLOM/CIV/OPNAV N6NB/TEL: COM: 703-604-6880/
EMAIL: hugh.mccullom@navy.mil//
RMKS/1. PURPOSE.
A. NAVY WEBSITES ACCESSIBLE DIRECTLY FROM THE PUBLIC INTERNET PRESENT A
TARGET FOR ADVERSARIES RANGING FROM ?HACKTIVISTS? TO ORGANIZED NETWORK
ATTACK FORCES. IN ORDER TO REDUCE THIS VULNERABILITY IN A COST
EFFECTIVE WAY, THE JOINT STAFF HAS DIRECTED THE SERVICES TO CONSOLIDATE
PUBLIC FACING WEBSITES TO A SINGLE POINT OF PRESENCE.
B. DCNO N6 IN COORDINATION WITH DISA HAS DEVELOPED AN ENTERPRISE
WEBSITE HOSTING SOLUTION FOR PUBLICLY ACCESSIBLE WEBSITES, PROVIDING
ENHANCED WEBSITE INFORMATION ASSURANCE AND RISK ASSESSMENTS,
ACCOUNTABILITY, STANDARDIZATION, AND BRANDING.
THIS WILL ALIGN CURRENT NAVY INFRASTRUCTURE WITH NEXT GENERATION
ENTERPRISE NETWORK STRATEGY.
2. ACTION.
A. ECHELON II COMMANDERS COMPLETE THE FOLLOWING:
(1). REGISTER YOUR CURRENT YOUR WEBSITES INTO DADMS IAW REF A AND C
AND MAINTAIN AS REQUIRED.
(2). REGISTER YOUR CURRENT NIPRNET PUBLICLY-FACING WEB SERVERS IAW
JTF-GNO CTO 06-17 AND MAINTAIN AS REQUIRED.
(3). ENSURE DOMAIN NAMING REMAINS IN COMPLIANCE WITH REF E.
B. IAWS REF A AND B, BY 31 DEC 08 ECHELON II COMMAND INFORMATION
OFFICERS (CIOS) ARE TO CONSOLIDATE ALL PUBLICLY ACCESSIBLE WEBSITES (TO
INCLUDE LEGACY NETWORK WEB CONTENT PROVIDERS) UNDER THEIR AREA OF
RESPONSIBILITY (AOR) TO A SINGLE ECHELON II COMMAND UNIFORM RESOURCE
LOCATOR (URL) AND REHOST THE PARENT URL AT A DEFENSE INFORMATION SYSTEM
AGENCY (DISA) DEFENSE ENTERPRISE COMPUTING CENTER (DECC). PUBLIC WEB
SITES PRESENTLY AT THE NMCI APPLICATION HOSTING FACILITY (AHF) MAY
REMAIN THERE FOR INTERIM BUT SHOULD BE MIGRATED NO LATER THAN 30 SEP
2009.
EXCEPTIONS INCLUDE WEB APPLICATIONS AND WEB PORTALS AS DEFINED IN REF C
POSTED AT HTTPS:(SLASH-SLASH).DADMS.NAVY.MIL.
C. AS PART OF THE CYBER ASSET REDUCTION AND SECURITY (CARS) EFFORT,
UNITED STATES FLEET FORCES (USFF) IS TASKED WITH OVERSEEING THE
EXECUTION OF THIS WEBSITE CONSOLIDATION EFFORT THROUGH NAVAL NETWORK
WARFARE COMMAND (NNWC). NNWC WILL PROVIDE ADDITIONAL GUIDANCE TO
SUPPORT ENFORCEMENT OF THIS CONSOLIDATION EFFORT AND WILL ESTABLISH
METHODS TO SHUTDOWN COMMAND WEBSITES NOT IN COMPLIANCE WITH THIS
NAVADMIN. NNWC WILL REPORT MIGRATION STATUS TO DCNO N6 COMMENCING 01
MAY 08.
CARS WILL PROVIDE ECHELON II IMPLEMENTATION GUIDANCE VIA SEPCOR.
3. ENFORCEMENT. AFTER 15 JAN 09 THOSE WEBSITES IN VIOLATION OF THIS
DIRECTIVE WILL BE BLOCKED FROM THE NAVY.MIL DOMAIN AND WILL NOT BE
AUTHORIZED FOR CONTINUED FUNDING IN FY09. ADDITIONALLY, JTF-GNO WILL
BLOCK ALL INTERNET INBOUND TRAFFIC TO WEBSITES NOT IDENTIFIED PER REF D
AND NOT REGISTERED IN THE DON APPLICATION AND DATABASE MANAGEMENT
SYSTEM (DADMS).
4. REPORTING REQUIREMENTS. ECHELON II CIOS ARE DIRECTED TO REPORT
STATUS (TO INCLUDE ACTIONS TAKEN, SAVINGS REALIZED BY REDUCED
INFRASTRUCTURE AND WEBSITE MANAGEMENT SUPPORT HOURS) BY MESSAGE TO NNWC
THE LAST DAY OF EACH MONTH COMMENCING
31 MAR 08 UNTIL ACTION COMPLETED.
5. RELEASED BY VADM M.J. EDWARDS, DCNO N6.// BT
#0001
NNNN