DEFENSE INFORMATION SYSTEMS AGENCY (DISA) HOSTING OF ALL NAVY WEBSITES:
UNCLASSIFIED// RTTUZYUW RHSSXYZ0001 0672319-UUUU--RHSSSUU. ZNR UUUUU R 072311Z MAR 08 FM CNO WASHINGTON DC//N6// TO AL NAVADMIN NAVADMIN INFO CNO WASHINGTON DC//N6// DON CIO WASHINGTON DC CMC WASHINGTON DC//C4// DISA WASHINGTON DC//UNCLAS //N02000// BT UNCLAS PASS TO OFFICE CODES: FM CNO WASHINGTON DC//N6// TO NAVADMIN INFO CNO WASHINGTON DC//N6/N61/N6N/N6F// DON CIO WASHINGTON DC CMC WASHINGTON DC//C4// DISA WASHINGTON DC// UNCLAS //N02000// NAVADMIN 061/08 MSGID/GENADMIN/CNO WASHINGTON DC/N6/MAR// SUBJ/DEFENSE INFORMATION SYSTEMS AGENCY (DISA) HOSTING OF ALL NAVY WEBSITES// REF/A/NAVADMIN 145-07/CNO/051353ZJUN2007// REF/B/NAVADMIN 275-06/CNO/042205ZOCT2006// REF/C/DOC/PORTAL AND WEBSITE REGISTRATION GUIDE/DCNO N6/JUNE 2007// REF/D/CTO/FILTERING WEB SERVICES TRAFFIC (HTTP AND HTTPS) AT INTERNET ACCESS POINTS (IAPS)/JTF-GNO CTO 06-17// REF/E/DOC/DCNO N6/2005 JUN 14// NARR/REF A REQUESTED INVENTORY OF ECHELON II WEBSITES BE PROVIDED TO OPNAV N6 AND DIRECTED ECHELON II ASSUMPTION OF RESPONSIBILITY FOR ALL SUBORDINATE COMMAND WEBSITE INVENTORY AND INFRASTRUCTURE FOR FUTURE CONSOLIDATION. REF B ANNOUNCED THE NAVYS PORTAL - WEBSITE INVESTMENT MORATORIUM FOR FISCAL YEAR 2007 (FY07). REF C PROMULGATED THE BUSINESS RULES AND PROVIDES GUIDANCE FOR COMMANDS IN THE REGISTRATION OF ALL PORTALS AND WEBSITES. REF E IS OPNAVINST 5239.2, WHICH PROVIDES THE POLICY FOR DOMAIN NAME ESTABLISHMENT AND USE WITHIN THE NAVY AS WELL AS REGISTRATION WITH THE DEPARTMENT OF DEFENSE NETWORK INFORMATION CENTER.// POC/HUGH MCCULLOM/CIV/OPNAV N6NB/TEL: COM: 703-604-6880/ EMAIL: hugh.mccullom@navy.mil// RMKS/1. PURPOSE. A. NAVY WEBSITES ACCESSIBLE DIRECTLY FROM THE PUBLIC INTERNET PRESENT A TARGET FOR ADVERSARIES RANGING FROM ?HACKTIVISTS? TO ORGANIZED NETWORK ATTACK FORCES. IN ORDER TO REDUCE THIS VULNERABILITY IN A COST EFFECTIVE WAY, THE JOINT STAFF HAS DIRECTED THE SERVICES TO CONSOLIDATE PUBLIC FACING WEBSITES TO A SINGLE POINT OF PRESENCE. B. DCNO N6 IN COORDINATION WITH DISA HAS DEVELOPED AN ENTERPRISE WEBSITE HOSTING SOLUTION FOR PUBLICLY ACCESSIBLE WEBSITES, PROVIDING ENHANCED WEBSITE INFORMATION ASSURANCE AND RISK ASSESSMENTS, ACCOUNTABILITY, STANDARDIZATION, AND BRANDING. THIS WILL ALIGN CURRENT NAVY INFRASTRUCTURE WITH NEXT GENERATION ENTERPRISE NETWORK STRATEGY. 2. ACTION. A. ECHELON II COMMANDERS COMPLETE THE FOLLOWING: (1). REGISTER YOUR CURRENT YOUR WEBSITES INTO DADMS IAW REF A AND C AND MAINTAIN AS REQUIRED. (2). REGISTER YOUR CURRENT NIPRNET PUBLICLY-FACING WEB SERVERS IAW JTF-GNO CTO 06-17 AND MAINTAIN AS REQUIRED. (3). ENSURE DOMAIN NAMING REMAINS IN COMPLIANCE WITH REF E. B. IAWS REF A AND B, BY 31 DEC 08 ECHELON II COMMAND INFORMATION OFFICERS (CIOS) ARE TO CONSOLIDATE ALL PUBLICLY ACCESSIBLE WEBSITES (TO INCLUDE LEGACY NETWORK WEB CONTENT PROVIDERS) UNDER THEIR AREA OF RESPONSIBILITY (AOR) TO A SINGLE ECHELON II COMMAND UNIFORM RESOURCE LOCATOR (URL) AND REHOST THE PARENT URL AT A DEFENSE INFORMATION SYSTEM AGENCY (DISA) DEFENSE ENTERPRISE COMPUTING CENTER (DECC). PUBLIC WEB SITES PRESENTLY AT THE NMCI APPLICATION HOSTING FACILITY (AHF) MAY REMAIN THERE FOR INTERIM BUT SHOULD BE MIGRATED NO LATER THAN 30 SEP 2009. EXCEPTIONS INCLUDE WEB APPLICATIONS AND WEB PORTALS AS DEFINED IN REF C POSTED AT HTTPS:(SLASH-SLASH).DADMS.NAVY.MIL. C. AS PART OF THE CYBER ASSET REDUCTION AND SECURITY (CARS) EFFORT, UNITED STATES FLEET FORCES (USFF) IS TASKED WITH OVERSEEING THE EXECUTION OF THIS WEBSITE CONSOLIDATION EFFORT THROUGH NAVAL NETWORK WARFARE COMMAND (NNWC). NNWC WILL PROVIDE ADDITIONAL GUIDANCE TO SUPPORT ENFORCEMENT OF THIS CONSOLIDATION EFFORT AND WILL ESTABLISH METHODS TO SHUTDOWN COMMAND WEBSITES NOT IN COMPLIANCE WITH THIS NAVADMIN. NNWC WILL REPORT MIGRATION STATUS TO DCNO N6 COMMENCING 01 MAY 08. CARS WILL PROVIDE ECHELON II IMPLEMENTATION GUIDANCE VIA SEPCOR. 3. ENFORCEMENT. AFTER 15 JAN 09 THOSE WEBSITES IN VIOLATION OF THIS DIRECTIVE WILL BE BLOCKED FROM THE NAVY.MIL DOMAIN AND WILL NOT BE AUTHORIZED FOR CONTINUED FUNDING IN FY09. ADDITIONALLY, JTF-GNO WILL BLOCK ALL INTERNET INBOUND TRAFFIC TO WEBSITES NOT IDENTIFIED PER REF D AND NOT REGISTERED IN THE DON APPLICATION AND DATABASE MANAGEMENT SYSTEM (DADMS). 4. REPORTING REQUIREMENTS. ECHELON II CIOS ARE DIRECTED TO REPORT STATUS (TO INCLUDE ACTIONS TAKEN, SAVINGS REALIZED BY REDUCED INFRASTRUCTURE AND WEBSITE MANAGEMENT SUPPORT HOURS) BY MESSAGE TO NNWC THE LAST DAY OF EACH MONTH COMMENCING 31 MAR 08 UNTIL ACTION COMPLETED. 5. RELEASED BY VADM M.J. EDWARDS, DCNO N6.// BT #0001 NNNN