Introduction to Network Implementation and Maintenance 113-SCCCD01
Learning objective and standard
Learning objectiveIdentify the Network Implementation and Maintenance module requirements, schedule, and reading
StandardPurpose: The purpose of this module is to equip U.S. Army Signal Officers with a foundational understanding of core networking principles - encompassing architectures, protocols, hardware, security standards and strategies, troubleshooting, and best practices - so they can effectively deploy, install, maintain, and secure mission-critical communication systems. By blending theoretical instruction with hands-on exercises and scenario-based discussions, these lectures aim to enhance technical competency, critical thinking, and adaptability, ultimately fostering confident leaders capable of ensuring robust, resilient networks that support operational readiness and mission success.
Module D's front door, and the only place the whole 95-hour module is laid out at once. Unlike most lessons in the course, D01 carries a module purpose statement rather than a formal action-condition-standard, so what is quoted above is the purpose verbatim. The lesson matters for two practical reasons. First, it sets the reading: nine of the twelve days have an assigned read-ahead, and six of them point at the same document - the Network Operations and Planning Student Handout, which is the single richest source in Module D. Second, it names the two graded events the whole module builds toward: the Network Operations Practicum and the Network Essentials Exam. Every learning standard in D02 through D08 ends with the same clause about passing both.
Doctrinal sets to know cold
The twelve-day Module D schedule
- Day 1 - Network architecture: components, devices and servers; the OSI model
- Day 2 - Base 2, 10 and 16 conversion; IP schemes, IPv4 overview and mitigation, IPv6, subnetting; topology; network technologies
- Day 3 - Transmission mediums and transport concepts; CAT 5E practical exercise; midpoint review
- Day 4 - Introduction to virtualization
- Day 5 - Network management and network operations
- Day 6 - Data literacy and data governance
- Day 7 - Data governance and database fundamentals
- Day 8 - Power of data and telling a story with data
- Day 9 - Power BI basics
- Day 10 - Zero trust fundamentals and implementation
- Day 11 - Cloud fundamentals and the cloud practical exercise
- Day 12 - Network Operations and Planning Exam
Module D read-ahead by day
- Prior to day 1 - Student Handout pages 7 to 17
- Day 1 - Student Handout: review pages 25 to 28, read pages 30 to 40, and conduct the group assigned task
- Day 2 - Student Handout: review Attachment 4 How to Subnet a Network, read pages 18 to 25, and conduct the group assigned task
- Day 3 - Student Handout: review pages 41 to 51
- Day 4 - Student Handout: read pages 52 to 63
- Day 5 - none
- Prior to day 6 - Army Digital Transformation Strategy (October 2021)
- Days 6 and 7 - Army Data Stewardship Roles and Responsibilities
- Days 8 and 9 - none
- Days 10 and 11 - Army Cloud Plan of 2022 and the JADC2 Implementation Plan
Network scale, from smallest to largest (FM 6-02)
- Local area network (LAN) - a limited spatial area, specific user group, specific topology, not a public switched network
- Campus area network (CAN) - interconnected LANs within a limited geographical area such as a military base
- Metropolitan area network (MAN) - interconnected LANs over a city-wide area
- Wide area network (WAN) - interconnected LANs over large geographical areas such as nationwide
Why networking literacy matters to a leader
- Ensure operational readiness - anticipate, diagnose and mitigate communication disruptions before they hit mission effectiveness
- Enhance cybersecurity posture - enforce security protocols, manage vulnerabilities, and support defensive cyber operations
- Optimize tactical and strategic communications - facilitate joint and allied interoperability for seamless command and control
- Drive effective decision-making - talk to technical experts, assess infrastructure needs, and make informed investments
- Support future force modernization - integrate AI, cloud computing and software-defined networks into the battlespace
Module D references
- FM 6-02, Signal Support to Operations, September 2019
- ATP 6-02.12, Department of Defense Information Network-Army Planning Techniques, 17 November 2021
- ATP 6-02.71, Techniques for Department of Defense Information Network Operations, April 2019
- Network Operations and Planning Student Handout
- DoD Instruction 8510.01, Risk Management Framework for DoD Systems, 19 July 2022
- The Army Unified Network Plan, 2021
The two graded events every Module D standard depends on
- The Network Operations Practicum
- The Network Essentials Exam
- Every learning standard from D02 through D08 is written as met only when the listed requirements are complete AND a passing grade is received on both
Key terms
- Network
- Two or more computing devices connected for the purpose of communicating with one another to share information and/or resources. The simplest definition in the module, and the one everything else builds on.
- Network architecture
- The physical and logical layout of the network, consisting of the network devices, software, connective dependencies, communication protocols, and transmission mediums such as wired or wireless. Note that it is both physical and logical - a diagram of the cabling is only half of it.
- Local area network (LAN)
- A data communications system that lies within a limited spatial area, has a specific user group, has a specific topology, and is not a public switched telecommunications network but may be connected to one. (FM 6-02) LANs are not subject to public telecommunications regulations.
- Campus area network (CAN)
- An interconnection of local area networks within a limited geographical area, such as a military base. (FM 6-02)
- Metropolitan area network (MAN)
- An interconnection of local area networks over a city-wide geographical area. (FM 6-02)
- Wide area network (WAN)
- An interconnection of local area networks over large geographical areas, such as nationwide. (FM 6-02)
- The network as part of the command and control system
- ADP 6-0 treats the network as a component of the command and control system. Signal formations provide the network and conduct information management tasks that support the knowledge management process, enabling secure communications and situational awareness across the area of operations.
- Network Operations Practicum
- One of the two graded events Module D builds toward. Every learning standard from D02 through D08 is written as met only when the student completes the listed requirements and receives a passing grade on the Practicum and the Network Essentials Exam.
- Network Essentials Exam
- The written examination at the end of Module D, scheduled on the final day alongside the Network Operations and Planning exam block. The second half of the pass condition attached to every Module D standard.
- Network Operations and Planning Student Handout
- The module's core reference, roughly 70 pages. Assigned as the read-ahead for six of the module's twelve days and covering network components, information assurance devices, server roles, the OSI model layer by layer, switching, topologies, IPv4 and subnetting, ports and routing protocols, cloud concepts, DoDIN operations, and network planning TTPs.
- Multidomain operations context
- The reason the module gives for teaching networking to leaders rather than only to operators: as the Army moves toward multidomain operations and network-centric warfare, leaders must be prepared to integrate artificial intelligence, cloud computing, and software-defined networks into the battlespace.
Testable points
- Module D is Network Implementation and Maintenance, and it is 95 academic hours - the second largest module in the course after Common Core.
- The module purpose names six things Signal officers must understand: architectures, protocols, hardware, security standards and strategies, troubleshooting, and best practices.
- The purpose statement names four verbs the officer must be able to perform on communication systems: deploy, install, maintain, and secure.
- Module D's risk assessment level is Low, with no major safety considerations and no environmental considerations. Its foreign disclosure marking is FD1.
- The module runs twelve scheduled days, with the Network Operations and Planning Exam on the final day.
- The module content overview names thirteen subject areas, running from key terms and network devices through the OSI model, topologies, server infrastructure, switching, transmission mediums, network segmentation, routing protocols, the Risk Management Framework, NETOPS management and troubleshooting, data literacy, cloud fundamentals, and zero trust implementation.
- Nine of the twelve days carry an assigned read-ahead. Six of those point at the Network Operations and Planning Student Handout.
- The handout reading is sequenced deliberately: pages 7 to 17 before day 1, pages 30 to 40 for day 1, pages 18 to 25 for day 2, pages 41 to 51 for day 3, and pages 52 to 63 for day 4.
- Day 2's read-ahead adds Attachment 4, How to Subnet a Network - the only attachment called out by name in the pre-reading.
- Days 6 and 7 assign Army Data Stewardship Roles and Responsibilities. Day 6's preparation assigns the Army Digital Transformation Strategy (October 2021).
- Days 10 and 11 assign the Army Cloud Plan of 2022 and the JADC2 Implementation Plan - the same two readings for zero trust and for cloud.
- Days 5, 8 and 9 have no assigned reading: network management and NETOPS, power of data and storytelling, and Power BI basics.
- Days 1 through 3 each end with a group exercise preparation block for the following day, so the practical work is continuous rather than a single capstone.
- The module reference list is short and specific: FM 6-02 (September 2019), ATP 6-02.12 DODIN-Army Planning Techniques (17 November 2021), ATP 6-02.71 Techniques for DODIN Operations (April 2019), the Network Operations and Planning Student Handout, DoDI 8510.01 Risk Management Framework (19 July 2022), and The Army Unified Network Plan (2021).
- A network is defined as two or more computing devices connected to communicate and share information or resources. Everything else in the module is an elaboration of that sentence.
- FM 6-02's LAN definition has four parts - limited spatial area, specific user group, specific topology, and not a public switched telecommunications network though it may connect to one. The distinction between LAN, campus area network, metropolitan area network and wide area network in FM 6-02 is purely one of geographic scale.
- Network architecture is both physical and logical. A cable diagram alone does not describe an architecture; the protocols and connective dependencies are part of it.
- The Army's network extends as low as the individual Soldier, because modern tactical radio systems pass digital information.
- The five reasons the module gives for teaching networking to leaders are operational readiness, cybersecurity posture, optimized tactical and strategic communications, effective decision-making, and future force modernization.
- The decision-making argument is the one most relevant to a career-course student: networking literacy lets a leader communicate effectively with technical experts, assess infrastructure needs, and make informed investments in emerging technologies.
References
FM 6-02ADP 6-0ATP 6-02.12ATP 6-02.71DoDI 8510.01Army Unified Network Plan (2021)
Network Architecture: Components, IA Devices and Servers 113-SCCCD02
Learning objective and standard
Learning objectiveDefine network components and roles
StandardDefine network components and roles. The student must correctly define and identify the following without error: 1. Define a network. 2. Define network components and roles. 3. Define OSI model layers. 4. Define circuit based networks. 5. Define packet based networks. 6. Identify network diagrams. 7. Complete network architecture concepts exercise.
Day 1 of Module D, and the lesson with the highest ratio of memorizable facts to concepts in the whole module. It is a device catalogue in three parts: the components that move traffic, the information assurance devices that police it, and the servers that provide services on it. The exam-relevant discriminations are narrow and specific - repeater versus media converter, layer 2 switch versus multilayer switch versus router, IDS versus IPS, host-based versus network-based IDS, KIV-19M versus KIV-7M, symmetric versus asymmetric encryption. Learn the boundaries rather than the paragraphs; nearly every question that can be asked here is a question about which side of a line something falls on.
Doctrinal sets to know cold
Network components and devices, in order of increasing intelligence
- Network interface card - provides the physical connection to the media and a MAC address
- Repeater - eliminates attenuation, forwards every frame, no filtering
- Media converter - joins segments running on different media
- Modem - modulates digital to analog and back for transmission to the ISP
- Wireless access point - lets wireless clients reach the wired network
- Layer 2 switch - forwards by MAC address, dedicated bandwidth per port
- Multilayer switch - decides dynamically whether to switch at layer 2 or route at layer 3
- Router - connects multiple networks and chooses the most efficient path by IP address
The six functions of a layer 2 switch
- MAC address learning - build the table from source addresses of incoming frames
- Forwarding - send frames between devices on the same network by destination MAC
- Filtering - control which devices may communicate
- VLAN support - segment into virtual networks with their own policies
- Spanning Tree Protocol - prevent loops by disabling redundant links
- Link aggregation - combine physical links into one logical link for bandwidth and redundancy
The six functions of a router
- Network addressing - identify devices and networks by IP address
- Routing - determine the most efficient path by destination IP
- Network segmentation - split a network into subnets for performance and security
- Access list - block or allow traffic by source, destination or characteristic
- Quality of service - prioritize critical traffic such as voice and video
- VPN support - enable secure remote access from outside the organization
The five key components of information assurance
- Confidentiality - only authorized individuals have access
- Integrity - information is accurate, complete, and not altered without authorization
- Availability - information and systems are accessible to authorized users when needed
- Non-repudiation - origin and authenticity can be verified and actions cannot be denied
- Resilience - information and systems can recover from disruptions such as cyber attacks or natural disasters
Firewall benefits and limitations
- Benefits: prevents exposure of sensitive hosts, resources and applications to untrusted users; blocks malicious data from servers and clients; reduces security management complexity; controls user access through authentication, authorization and accounting
- Limitations: misconfiguration or hardware failure can be disastrous; introduces performance bottlenecks; cannot control data paths that circumvent it; users who view the policy as oppressive may find ways around it; only protects between security zones, not within them
Host-based versus network-based IDS
- HIDS advantages: verifies the success or failure of an attack; monitors system activities; detects attacks a NIDS misses; near real-time detection and response; lower entry cost
- HIDS disadvantages: harder to manage; its information sources reside on the host being attacked; poorly suited to detecting network scans across an entire network; can be disabled by certain denial-of-service attacks
- NIDS advantages: fewer systems needed for coverage; lower deployment, maintenance and upgrade costs; visibility into all network traffic and able to correlate attacks across multiple systems
- NIDS disadvantages: ineffective when traffic is encrypted; cannot see traffic that does not cross it; must handle high traffic volumes; knows nothing about activity on the hosts themselves
Encryption devices
- KIV-19M - dual-channel, independently keyed link encryption supporting multiple traffic algorithms; part of the Link Encryptor Family; a bulk encryption device
- KIV-7M - NSA-certified type-1 dual-channel device for router-to-router serial connections; both a bulk and a line encryption device; two independently configurable channels at different security levels; four modes or personalities chosen by the distant-end equipment
- In-line network encryptor (INE), also HAIPE - Type I, NSA-certified for classified information, NSA-approved algorithms; may support routing and layer 2 VLANs; placed in each network and tunnelled to its peers; cleared by zeroization if physical compromise threatens
The five functions of a domain controller
- User authentication - verify credentials against the account database
- User authorization - grant or deny access by role or group membership
- Group policy management - enforce rules and settings governing computer behavior and configuration
- Directory services - store and manage resource information centrally in Active Directory
- Replication - provide redundancy so resources stay available if a server fails
Server infrastructure roles
- Domain controller - central authentication and authorization for a Windows domain
- DNS server - translates hostnames to IP addresses for zones it is authoritative for
- DHCP server - supplies IP address, subnet mask, gateway and DNS servers to a new host
- Web server - serves web page files over HTTP in response to browser requests
- Database server - provides database services to other programs on a client-server model
- Email server - accepts and delivers mail; handles IMAP, POP3 and SMTP
- Collaboration server - information sharing, content management, enterprise search and portals for licensed internal users
- Configuration and patch management server - manages a large number of networked computers
- Performance and health monitoring server - watches everything from servers to individual applications
- Update management server - downloads and distributes vendor updates and patches
- Antivirus server - protects against viruses, worms, Trojan horses, spyware and adware
The four things a DHCP server provides a new host
- IP address
- Subnet mask
- Gateway
- DNS servers to use
Common hardware components
- Central Processing Unit (CPU) - executes instructions, directs everything else
- Memory (RAM) - the volatile workspace, on top of registers and cache
- Storage (HDD or SSD) - persistent secondary memory
- Motherboard - connects every component, distributes power, holds the firmware
- Power supply - converts AC from the outlet to DC for the internals
- Graphics Processing Unit (GPU) - parallel processing, originally for rendering
- Cooling systems - fans and heat sinks
- Expansion slots (PCI / PCIe) - where added capability goes
The memory hierarchy, fastest and smallest first
- CPU registers - built into the processor, hold immediate instructions and results
- Cache - L1 closest and fastest, L2 larger, L3 largest and shared between cores
- RAM - the main workspace, volatile
- Virtual memory - secondary storage standing in for RAM, at a performance cost
- Secondary storage - HDD or SSD, persistent
Key terms
- Network interface card (NIC)
- Allows computers to communicate over the network using media access control (MAC) with a low-level addressing system. It provides the physical connection to network media. A NIC may be an expansion card, built in, or virtualized in a virtual environment.
- Attenuation
- Any reduction in the strength of a signal over long distances. It is the problem a repeater exists to solve.
- Repeater
- A device that increases the length of a network by eliminating attenuation of the signal, connecting two segments of the same network and overcoming the distance limitations of the transmission media. It forwards every frame and has no filtering capability - that last clause is the discriminator.
- Media converter
- Hardware that enables networks or segments running on different media to interconnect and exchange signals. A repeater extends the same medium; a media converter joins two different ones.
- Modem
- Converts a digital signal to an analog signal for transmission to the internet service provider, with the conversion inverted at the distant end. The process is modulation and demodulation, which is where the name comes from.
- Wireless access point (WAP)
- A network device connected to the wired network that allows a wireless client to pass through and access the wired network and its resources.
- Layer 2 switch
- Allows multiple devices to access a network, allocating dedicated bandwidth to each access port. It operates at the data link layer and forwards traffic between devices on the same network using MAC addresses.
- MAC address learning
- How a layer 2 switch builds its table: it examines the source MAC address of incoming frames, records which port each address was seen on, and then uses that table to decide where to forward traffic based on destination MAC address.
- Spanning Tree Protocol (STP)
- A layer 2 switch feature that prevents loops in the network topology by disabling redundant links.
- Link aggregation
- Combining multiple physical connections between switches into a single logical connection, increasing bandwidth and improving redundancy.
- Multilayer switch
- Makes switching and filtering decisions based on both data link and network layer addresses, and dynamically decides whether to switch at layer 2 or route at layer 3. It relies on route processors that build routing tables and distribute them to the switches - so several switches can share one route processor to reduce cost.
- Route processor
- The device within a multilayer switch architecture that processes routing protocols, determines optimum paths, and produces the routing table that is then distributed periodically to the switches. It may sit in the same chassis as the switch or in another one.
- Router
- A highly intelligent hardware device used to connect multiple networks together and route traffic between them. Its primary function is determining the most efficient path for data packets between different networks, using the destination IP address.
- Access list
- Firewall-style rules configured on a router that block or allow specific types of traffic based on source, destination, or other characteristics.
- Quality of service (QoS)
- A router capability that prioritizes network traffic by importance, ensuring critical data such as voice or video is transmitted with minimal delay or loss.
- Information assurance (IA)
- The practice of protecting and securing information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction. It combines technical, operational and management controls.
- Firewall
- A security device that monitors and controls incoming and outgoing network traffic, blocking unauthorized access while allowing legitimate traffic through. It applies rules based on source or destination IP address, traffic type, or protocol.
- Intrusion detection system (IDS)
- A security device that monitors network traffic and detects potential breaches or attacks, comparing traffic to known patterns of attack and generating an alert, blocking the traffic, or writing a log entry when it finds a match.
- Intrusion prevention system (IPS)
- Monitors network traffic for malicious or unwanted behavior and blocks, rejects, or redirects that traffic in real time. The handout is explicit about the boundary: a device that only monitors is not a true IPS - it must be able to stop or prevent malicious traffic from having an impact.
- Host-based IDS (HIDS)
- Examines activity on an individual system - a mail server, web server, or individual PC. It is concerned only with that system and usually has no visibility into the network or the systems around it.
- Network-based IDS (NIDS)
- Examines activity on the residing network. It sees only the traffic crossing the link it monitors and typically has no idea what is happening on individual systems.
- Encryption
- Converting plaintext or clear text into an encoded format called ciphertext, which can only be deciphered with a secret key or password. An algorithm transforms the plaintext using the key; the same key or password reverses it.
- Symmetric encryption
- The same key is used for both encryption and decryption, so the key must be kept secret - anyone with it can decrypt. Often used for bulk data encryption such as files or hard drives.
- Asymmetric encryption
- Two different keys: the public key encrypts and the private key decrypts. Often used for secure communication such as email encryption or secure web browsing.
- KIV-19M
- Provides dual-channel, independently keyed link encryption and decryption supporting multiple traffic algorithms in a single unit, as part of the Link Encryptor Family. It is considered a bulk encryption device.
- KIV-7M
- An NSA-certified type-1 dual-channel encryption device used to encrypt router-to-router serial connections. It is considered both a bulk and a line encryption device - the discriminator against the KIV-19M, which is bulk only. It has two independently configurable channels at possibly different security levels, and operates in one of four modes or personalities depending on the distant-end COMSEC equipment.
- In-line network encryptor (INE)
- Also called a high-assurance Internet Protocol encryptor (HAIPE). A Type I encryption device - meaning NSA-certified for securing US government classified information, using NSA-approved algorithms. INEs are placed in each network needing their services and communicate with one another through a secure tunnel. They may also support routing and layer 2 VLANs.
- Zeroization
- The technique by which an INE is easily disabled and cleared of keys when in danger of physical compromise.
- Server
- A powerful computer that is at the service of the network, running a network operating system to maintain and control the network and provide resources to many individual users at once.
- Domain controller
- A server responsible for managing access to network resources - user accounts, groups, computers, printers - in a Windows domain environment. It is the central authentication and authorization service, letting users log in and reach resources with a single set of credentials.
- Active Directory
- The central directory service in which a domain controller stores and manages information about network resources, letting administrators manage them from one location.
- Domain Name System (DNS) server
- Translates a hostname into an IP address. A DNS server maintains a local directory of names and addresses for which it is authoritative, and answers queries for those names.
- Dynamic Host Configuration Protocol (DHCP) server
- Answers a new host's request for IP information with everything it needs to communicate: its IP address, subnet mask, gateway, and which DNS servers to use. Those four items are the memorizable part.
- Collaboration server
- A server platform for information sharing, collaboration and content management, accessible only to appropriately licensed internal users. Its four major capabilities are collaboration, enterprise content management, enterprise search, and portals.
- Central Processing Unit (CPU)
- The "brain" of any computing device - executes instructions and directs every other component. Its performance bears directly on routers, switches, servers and clients that must handle thousands of packets per second.
- CPU registers
- The top of the memory hierarchy: the fastest and smallest storage, built into the processor itself, holding instructions, memory addresses and the results of immediate operations.
- Cache memory
- Bridges the speed gap between the CPU and system memory by holding frequently accessed instructions and data. L1 is fastest and closest to the core, L2 larger and slower, L3 largest and shared among cores.
- RAM (Random Access Memory)
- Main memory - the primary workspace, holding active programs and data while the machine runs. Volatile: contents are lost at power-down. DRAM needs constant refreshing; SRAM is faster and more reliable but expensive enough that it is used mainly for cache.
- ROM (Read-Only Memory)
- Non-volatile memory holding firmware - the permanent instructions needed to boot and initialise hardware, such as the BIOS or UEFI. PROM, EPROM and EEPROM are variants that can be programmed and sometimes reprogrammed.
- Virtual memory
- Uses part of secondary storage to simulate additional RAM, letting larger applications run at a performance cost, because disk access is far slower than real RAM.
- Thrashing
- What happens when virtual memory is overused: the system spends more time swapping data between RAM and disk than doing actual work.
- Hard disk drive (HDD)
- Mechanical storage - data held on spinning magnetic platters, read and written by heads on an actuator arm. Performance is tied to rotational speed: 5,400 and 7,200 RPM for consumer drives, 10,000 or 15,000 for enterprise. Advantages are high capacity and low cost.
- Solid-state drive (SSD)
- Storage with no moving parts, holding data in NAND flash cells addressed by an electronic controller. Far faster than an HDD, lower power, less heat, more shock-resistant. SATA SSDs use the same connectors as HDDs; NVMe SSDs connect straight to the PCIe bus. The downsides are cost per gigabyte and a finite number of write cycles.
- Motherboard
- The central circuit board connecting every major component - the nervous system to the CPU's brain. It distributes power from the supply through voltage regulators, holds the BIOS/UEFI firmware, and integrates audio, Ethernet and often Wi-Fi that once needed separate cards.
- BIOS / UEFI
- The firmware on the motherboard and the first software to run at power-on. It verifies the hardware, initialises devices and hands control to the operating system. Its interface is where boot order and security settings are set.
- Motherboard form factor
- The size and layout standard. ATX gives the most expansion; Micro-ATX and Mini-ITX are smaller with fewer slots and ports; Extended ATX adds space and is used in servers and advanced workstations.
- Power supply
- Converts AC from the outlet to the DC the internal components require.
- Graphics Processing Unit (GPU)
- A specialised circuit for rendering images, animation and video, built around thousands of small cores. That highly parallel architecture also makes it valuable for scientific work, artificial intelligence and high-performance data processing.
- Heat sink
- Passive cooling - a thermally conductive block, usually aluminium or copper, sitting on the component with thermal paste between to remove microscopic air gaps. Heat spreads from its base into thin fins whose large surface area releases it into the air.
- Expansion slots (PCI / PCIe)
- Connectors on the motherboard that take expansion cards - graphics, network adapters, sound, storage controllers. PCI arrived in the 1990s; PCIe is the modern standard, with lanes that scale x1, x4, x8 and x16, x16 being most common for graphics.
Testable points
- A repeater forwards every frame and has no filtering capability. That single clause separates it from a switch, which filters by MAC address.
- A repeater extends the same medium; a media converter joins two different media. Both sit between segments, but they solve different problems.
- A layer 2 switch allocates dedicated bandwidth to each access port. A hub or repeater does not.
- The six key functions of a layer 2 switch are MAC address learning, forwarding, filtering, VLAN support, Spanning Tree Protocol, and link aggregation.
- A multilayer switch dynamically decides whether to switch at layer 2 or route at layer 3 for incoming traffic - it does not do one or the other permanently.
- Multiple multilayer switches can share one route processor, which is the stated reason the architecture exists: it reduces cost.
- The six key functions of a router are network addressing, routing, network segmentation, access lists, quality of service, and VPN support.
- A router segments a network into multiple subnets each with its own address range, to improve both performance and security.
- Information assurance has five key components in the handout: confidentiality, integrity, availability, non-repudiation, and resilience. Note that this is a five-item list and that resilience is the one most often forgotten.
- Resilience means information and information systems can recover from disruptions such as cyber attacks or natural disasters. It is the IA component that has no equivalent in the classic CIA triad.
- A firewall's five functions are access control, traffic filtering, intrusion prevention, content filtering, and VPN support.
- A firewall only provides protection between network security zones, not within a security zone. This is the limitation most likely to be tested.
- Firewalls cannot control data paths that circumvent them, and if users see the policy as oppressive some will find ways around it. Both are listed limitations, not incidental commentary.
- Firewall benefits include controlling user access by leveraging authentication, authorization and accounting services - the AAA acronym.
- Misconfiguration of a firewall can have disastrous consequences, and a firewall introduces performance bottlenecks. Both are listed limitations.
- The difference between an IDS and an IPS is action, not detection. An IPS must be able to block, reject, or redirect traffic in real time; a device that only monitors and alerts is an IDS no matter what it is called.
- An IDS performs four functions: threat detection, incident response support, security policy enforcement, and compliance monitoring.
- A host-based IDS can verify the success or failure of an attack. A network-based IDS cannot, because it cannot see what happened on the host.
- A network-based IDS is ineffective when traffic is encrypted, cannot see traffic that does not cross it, and must be able to handle high volumes of traffic.
- A host-based IDS can be disabled by certain denial-of-service attacks, and its information sources reside on the very host under attack - the two disadvantages that matter most operationally.
- A host-based IDS has a lower entry cost; a network-based IDS has lower deployment, maintenance and upgrade costs because it needs fewer systems for the same coverage. Both are true and they are not contradictory - one is per-unit, the other is per-coverage.
- A network-based IDS can correlate attacks among multiple systems. A host-based IDS cannot, because it has no visibility outside its own host.
- Symmetric encryption uses one key for both directions and is used for bulk data such as files and hard drives. Asymmetric uses a public key to encrypt and a private key to decrypt, and is used for secure communication such as email and web browsing.
- The KIV-19M is a bulk encryption device. The KIV-7M is both a bulk and a line encryption device and is used to encrypt router-to-router serial connections. Both are dual-channel and independently keyed.
- The KIV-7M can operate in one of four modes, called personalities, and the mode used depends on the type of COMSEC equipment at the distant end.
- The KIV-7M supports different security levels on each of its two channels.
- An in-line network encryptor is also called a HAIPE - high-assurance Internet Protocol encryptor. Type I designation means NSA-certified for classified US government information using NSA-approved algorithms.
- INEs are placed in each network that needs them and communicate with one another through a secure tunnel. They can also support routing and layer 2 VLANs.
- INEs are built for zeroization - being cleared of keys quickly if physical compromise is a risk.
- A domain controller performs five functions: user authentication, user authorization, group policy management, directory services, and replication.
- Domain controller replication exists for redundancy, so network resources stay available if a server fails.
- A DHCP server hands a new host four things: IP address, subnet mask, gateway, and DNS servers to use.
- An email server handles more protocols than a web or FTP server does - IMAP, POP3 and SMTP, against HTTP and HTTPS for web.
- A collaboration server's capabilities are collaboration, enterprise content management, enterprise search, and portals. Its services are accessible only to appropriately licensed internal users.
- Enterprise content management covers the whole content life cycle - creation, editing, collaboration, approval, long-term retention, and final expiration - and can automate compliance with information management and data security policy.
- A configuration and patch management server manages a large number of computers on a corporate network; an update management server specifically downloads updates from a vendor and distributes them. Their five features are automatic updates, centralized management, reporting, customization, and integration with other tools such as antivirus and intrusion detection.
- The memory hierarchy runs registers, cache, RAM, then secondary storage. No single type is ideal for everything: registers and cache are lightning fast but tiny, RAM balances capacity against speed but loses everything at power-down.
- DRAM requires constant refreshing to hold its data; SRAM does not, and is faster and more reliable, which is why it is used for cache and not for main memory - it is far more expensive.
- ROM is non-volatile and holds the firmware. RAM is volatile and holds the work. That is the distinction to keep straight.
- An SSD's speed advantage shows most in booting, launching applications and moving large files. Its two real costs are price per gigabyte and a finite number of NAND write cycles.
- A modern processor throttles its own speed, or shuts down, if it gets too hot - cooling is what keeps it out of that state under load.
- Fans and heat sinks are complementary, not alternatives. A heat sink without airflow eventually saturates; a fan without a heat sink has too little surface area to cool the chip in time.
- Case airflow is a system: intake fans pull cool air in, exhaust fans push warm air out, and the fans on the CPU cooler and GPU move air across their own heat sinks.
- PCIe differs from earlier slot designs in using multiple serial lanes, which is where its bandwidth advantage comes from.
- This hardware material comes from `Network Operations and Planning v5.pdf` rather than from the Student Handout the rest of this lesson is built on. v5 is a superset of the handout; the handout has no hardware section at all.
References
Network Operations and Planning Student HandoutFM 6-02ADP 6-0ATP 6-02.71
The OSI Model and Switching Technologies 113-SCCCD02
Learning objective and standard
Learning objectiveDefine OSI model layers, circuit based networks, and packet based networks
StandardDefine OSI model layers. Define circuit based networks. Define packet based networks. Identify network diagrams. The student must correctly define and identify the following without error, and receive a passing grade on the Network Operations Practicum and Network Essentials Exam.
The OSI model is the spine of Module D. Almost everything later in the module - transports, routing protocols, tunneling, zero trust, even troubleshooting - is described by which layer it operates at, so the layers have to be automatic rather than looked up. Three things carry most of the exam weight: the protocol data unit at each layer, which layer a given device or protocol lives at, and the two sub-layers of layer 2. The lesson closes with switching technologies, where the discriminator worth memorizing is that circuit switching guarantees the full bandwidth of the channel and wastes it when idle, while packet switching is connectionless best-effort with no delivery guarantee and no setup delay.
Doctrinal sets to know cold
The seven OSI layers and their protocol data units
- Layer 1 physical - raw bitstream over the medium - PDU: bits
- Layer 2 data link - node-to-node, two sub-layers LLC and MAC - PDU: frames
- Layer 3 network - logical addressing and routing between networks - PDU: packets (datagrams)
- Layer 4 transport - segmenting and reassembling, TCP and UDP - PDU: segments
- Layer 5 session - establish, maintain and terminate connections; simplex, half-duplex, full-duplex
- Layer 6 presentation - formatting, translation, compression, encryption, character encoding
- Layer 7 application - the interface end-user applications use to reach network services
The five functions of layer 1
- Encoding and decoding of data into and out of a transmittable format
- Transmission of data using electrical, optical or wireless signals
- Synchronization of transmission and reception between devices
- Signal generation representing the data being transmitted
- Media access control - preventing collisions and ensuring each device gets access when it needs it
The two sub-layers of layer 2
- Logical link control (LLC, 802.2) - the top sub-layer; identifies and converges different network layer protocols and encapsulates them; interfaces with the network layer; works with the transport layer for flow control and error detection via the frame check sequence
- Media access control (MAC) - the lower sub-layer; specifies how data is placed and transported over the physical wire and controls access to the medium; physical addressing, network topologies, error notification and frame delivery are defined here
The five key functions of layer 3
- Logical addressing - each device has a unique IP address identifying it on the network
- Routing - moving packets between networks using protocols such as BGP or OSPF
- Fragmentation and reassembly - so large packets cross networks with smaller MTUs
- Quality of service - prioritizing traffic by type or source for critical applications
- Security - encryption and authentication protecting data as it traverses the network
Connection-oriented versus connectionless
- Connection-oriented: reliable and guaranteed; three-way handshake before transfer; connection held open until complete; packets carry unique identifiers and sequence numbers; receiver acknowledges each; sender resends losses. Advantages: reliability, orderliness, flow control, error detection and correction
- Connectionless: packets individually addressed and routed, sent independently, no guarantee of arrival or ordering. Advantages: efficiency, flexibility, scalability. Used for video streaming, online gaming and VoIP
The three session layer communication modes
- Simplex - one direction only; example, a public address system
- Half-duplex - sender and receiver alternate, one side at a time; example, a push-to-talk radio
- Full-duplex - both sides send and receive simultaneously
OSI versus the TCP/IP (DoD) model
- TCP/IP has four layers: network access, internet, transport, application
- The OSI model includes a dedicated session layer; the TCP/IP model does not
- The TCP/IP model combines presentation and application into one layer; OSI keeps them separate
- OSI was authored as a theoretical model; TCP/IP was constructed as a practical model from the architecture of the internet, and is more widely used
Circuit switching versus packet switching
- Circuit switching: a dedicated physical path established, maintained and terminated per session; guarantees the full bandwidth of the channel; fixed data rate both subscribers must match; defining example is the early analog telephone network
- Circuit switching's two inefficiencies: channel capacity is dedicated for the whole connection so idle time is wasted, and connection setup takes time
- Packet switching: transmission broken into packets that may each take a different route, may arrive out of order, and are reassembled at the destination; connectionless, best-effort; no connection setup and no delivery-guarantee overhead
- MPLS: forwards on labels applied at the network ingress rather than on routing tables; faster and more predictable; lets providers offer QoS guarantees by prioritizing on the label
Layer 1 media standards
- Wired: 802.1, 802.3 - CAT 5/5e/6, fiber optics, coax, USB, DSL, FireWire
- Wireless: 802.11a/b/d/e/g/h/i/n, 802.12 demand priority, 802.15 wireless personal area network including 802.15.1 Bluetooth, 802.16 wireless metropolitan area network
- 802.2 - logical link control
- 802.3 - Ethernet LAN, 10 Mbps to 10 Gbps, CSMA/CD over coax, UTP/STP copper and fiber
UTP categories
- Category 1 - telephone communications; not suitable for data
- Category 2 - up to 4 Mbps
- Category 3 - 10BASE-T networks, up to 10 Mbps
- Category 4 - Token Ring networks, up to 16 Mbps
- Category 5 - up to 100 Mbps
- Category 5e - up to 1000 Mbps (1 Gbps)
- Category 6 - four pairs of 24-gauge copper at higher speeds still
Key terms
- OSI model
- The Open Systems Interconnection model, a seven-layer framework describing how data moves between devices on a network. Authored as a theoretical model, which is why it separates functions the TCP/IP model merges.
- Protocol data unit (PDU)
- The name for the encapsulated unit of data at a given OSI layer. Bits at layer 1, frames at layer 2, packets at layer 3, segments at layer 4. Knowing these four is the single highest-yield fact set in the lesson.
- Layer 1 - physical
- The lowest layer, responsible for the physical transmission and reception of raw bitstreams over a medium such as copper, fiber, or wireless. Its PDU is bits.
- Layer 2 - data link
- Concerns node-to-node communications. It receives data from layer 3 and encapsulates it into frames sent across the physical network. It has two sub-layers: logical link control and media access control.
- Logical link control (LLC) sub-layer
- 802.2. The top sub-layer of the data link layer. It identifies and converges different network layer protocols and encapsulates them for transfer, interfaces with the network layer, and works with the transport layer to administer flow control and error detection through the frame check sequence.
- Media access control (MAC) sub-layer
- The lower data link sub-layer. It specifies how data is placed and transported over the physical wire and controls access to the physical medium. Physical addressing, network topologies, error notification, and delivery of frames are all defined here.
- Frame check sequence (FCS)
- The error-detection mechanism the LLC sub-layer uses, working with the transport layer to administer flow control and error detection.
- Layer 3 - network
- Provides logical addressing and routing services for data packets between hosts on different networks. It receives data from layer 4 and encapsulates it into packets called datagrams carrying source and destination IP addresses. Its PDU is packets.
- Datagram
- The name for a layer 3 packet, containing the source and destination IP addresses.
- Maximum transmission unit (MTU)
- The largest packet a network segment will carry. The network layer fragments and reassembles large packets so they can cross networks with smaller MTUs.
- Layer 4 - transport
- Segments and reassembles data from upper-layer applications into data streams, and provides reliable data transmission to the upper layers. It supports both connection-oriented service through TCP and connectionless service through UDP. Its PDU is segments.
- Layer 5 - session
- Establishes, maintains and terminates connections, synchronizes data exchange, and manages the flow of data throughout the communication. Session layer protocols support three communication modes.
- Simplex mode
- Communication in only one direction. The handout's example is a public address system - the sender speaks into a microphone and the audience only listens.
- Half-duplex mode
- The sender and receiver alternate speaking, one side at a time. The handout's example is a push-to-talk radio, which is why this mode matters more to a Signal officer than to most network engineers.
- Full-duplex mode
- Both sides send and receive simultaneously.
- Layer 6 - presentation
- Ensures data is properly formatted and translated so the receiving system can understand it, providing a common representation of data across different systems. It handles compression and decompression, translation, encryption and decryption, and character encoding and decoding.
- Layer 7 - application
- The topmost layer, providing communication services directly to end-user applications. It gives applications a standardized interface to network services such as email, file transfer and remote login. It is the layer that interacts directly with the user and the user's application.
- Connection-oriented service
- Provides reliable, guaranteed delivery between two endpoints. It establishes a dedicated connection - the three-way handshake - before data transfer begins, and the connection remains open until the transfer completes. Data is divided into packets each with a unique identifier and sequence number, the receiver acknowledges each one, and the sender resends anything lost or corrupted.
- Three-way handshake
- The connection establishment procedure in a connection-oriented service, performed before any data transfer begins.
- Connectionless service
- Data is sent in individually addressed and routed packets. Each packet is sent independently, and there is no guarantee packets will arrive at all or in the order sent.
- User Datagram Protocol (UDP)
- An unreliable service providing no delivery guarantee and no protection from duplication. Its simplicity reduces protocol overhead, and it provides a minimal, unreliable, best-effort, message-passing transport to applications and upper-layer protocols.
- Circuit switching
- A switching method in which a dedicated physical communication path between two stations is established, maintained and terminated for each communication session. The circuit guarantees the full bandwidth of the channel and stays connected for the duration of the session, functioning as if the nodes were physically wired together.
- Packet switching
- Breaking a transmission into multiple packets, each potentially taking a different route, received possibly out of order and reassembled at the destination. Characterized as connectionless, best-effort switching - no connection is established before sending and no overhead is spent guaranteeing delivery.
- Multiprotocol Label Switching (MPLS)
- A routing technique common in telecommunications networks that forwards data based on labels instead of traditional routing tables. Labels are added at the ingress point and guide the packet through the network to its destination, which is faster and more predictable than conventional routing.
- TCP/IP model
- Also called the Department of Defense model. A four-layer conceptual framework - network access, internet, transport, application - constructed as a practical model based on the architecture of the internet, in contrast to the OSI model's theoretical origin.
- 802.3
- The Ethernet LAN standard, covering all forms of Ethernet media and interfaces at data speeds from 10 Mbps to 10 Gbps, using asynchronous networking with carrier sense multiple access with collision detect over coax, UTP or STP copper, and fiber.
- CSMA/CD
- Carrier sense multiple access with collision detect, the access method 802.3 Ethernet uses for asynchronous networking.
- Twisted pair
- A pairing of copper wires used for telecommunications and networking, consisting of two insulated copper wires twisted in a helix pattern to reduce electromagnetic interference and crosstalk between adjacent wires.
- Unshielded twisted pair (UTP)
- The most common twisted pair cable and the standard in Ethernet networks. It consists of four pairs of color-coded wires, typically terminated with an RJ-45 connector.
Testable points
- The protocol data units, bottom to top: bits at layer 1, frames at layer 2, packets at layer 3, segments at layer 4. If you learn nothing else from this lesson, learn those four.
- Layer 1's five functions are encoding and decoding of data, transmission of data, synchronization, signal generation, and media access control.
- Industry standards at layer 1 address three functional areas: physical components, media types, and signaling methods.
- Layer 2 has exactly two sub-layers. Logical link control (802.2) is the top one and interfaces with the network layer; media access control is the lower one and controls access to the physical medium.
- Physical addressing, network topologies, error notification, and delivery of frames are all defined at the MAC sub-layer - not at the LLC sub-layer and not at layer 1.
- The LLC sub-layer works with the transport layer to administer flow control and error detection through the frame check sequence.
- Layer 3's five key functions are logical addressing, routing, fragmentation and reassembly, quality of service, and security.
- The network layer names BGP and OSPF as its routing protocol examples.
- Fragmentation and reassembly at layer 3 exists so large packets can cross networks with smaller maximum transmission units.
- Layer 4's typical functions are end-to-end communications, flow control, multiplexing, error detection and correction, and virtual circuit management.
- Layer 4 supports both connection-oriented service through TCP and connectionless service through UDP. Both live at the same layer.
- A connection-oriented service establishes its connection through a three-way handshake before any data transfer begins, and holds it open until the transfer is complete.
- Connection-oriented services offer four advantages: reliability, orderliness, flow control, and error detection and correction.
- Connectionless services offer three advantages: efficiency, flexibility, and scalability.
- Connectionless services are used where reliability and ordering are not required - the handout names video streaming, online gaming, and voice over IP.
- UDP provides no guarantee of delivery and no protection from duplication. Its value is the reduced overhead that comes from its simplicity.
- Layer 5 supports three communication modes: simplex, half-duplex and full-duplex. Half-duplex is push-to-talk radio, which makes it the mode a Signal officer meets most often.
- Layer 6 handles compression, decompression, translation, encryption, decryption, and character encoding and decoding. Its example formats are ASCII, EBCDIC, GIF, JPEG and TIFF.
- Encryption appears at two layers in this lesson: as a network layer security service at layer 3, and as a presentation layer function at layer 6. That is not a contradiction - they are different kinds of encryption at different points in the stack.
- Layer 7 is the layer that interacts directly with the user and the user's application. It provides the standardized interface applications use to reach network services such as email, file transfer and remote login.
- The TCP/IP model has four layers: network access, internet, transport, application.
- The two structural differences between the models: the OSI model has a dedicated session layer and the TCP/IP model does not, and the TCP/IP model combines presentation and application into a single layer while OSI keeps them separate.
- The OSI model was authored as a theoretical model; the TCP/IP model was constructed as a practical model based on the architecture of the internet. The handout states the TCP/IP model is more widely used and better suited for modern network environments.
- Circuit switching guarantees the full bandwidth of the channel for the duration of the session. Its defining example is the early analog telephone network, where switches created a continuous wire circuit between two telephones for the length of the call.
- Circuit switching is inefficient compared to packet switching for two specific reasons: channel capacity is completely dedicated for the duration of the connection so idle time is wasted capacity, and setting up the connection takes time.
- Circuit switching provides a fixed data rate channel, and both subscribers must operate at that rate.
- Packet switching is connectionless, best-effort switching. No connection is established before sending, and no overhead is spent guaranteeing delivery.
- In packet switching, each packet may take a different route, packets can be received out of order, and they are assembled at the destination.
- MPLS forwards on labels rather than routing tables. Labels are applied at the ingress point of the network and guide the packet to its destination.
- Service providers use MPLS to offer quality of service guarantees, because traffic can be prioritized by its label.
- 802.2 is logical link control, 802.3 is Ethernet LAN, and 802.11 is wireless networking. The 802.3 speed range given is 10 Mbps to 10 Gbps.
- UTP consists of four pairs of color-coded wires, typically terminated with an RJ-45 connector. Twisting the pairs is what reduces electromagnetic interference and crosstalk.
- The UTP categories run Cat 1 telephone only, Cat 2 up to 4 Mbps, Cat 3 up to 10 Mbps in 10BASE-T, Cat 4 up to 16 Mbps in Token Ring, Cat 5 up to 100 Mbps, Cat 5e up to 1 Gbps, and Cat 6 four pairs of 24-gauge copper at higher speeds again.
References
Network Operations and Planning Student HandoutFM 6-02ATP 6-02.71
IP Addressing Schemes and Subnetting 113-SCCCD02
Learning objective and standard
Learning objectiveApply IP addressing and subnetting concepts to network planning
StandardIdentify network architecture concepts. The student must correctly define, identify and complete the following without error, and receive a passing grade on the Network Operations Practicum and Network Essentials Exam: base 2, base 10 and base 16 conversion; IPv4 overview and classes; IPv4 mitigation through DHCP, private addressing, NAT and PAT; IPv6; and subnetting.
Day 2, and the most arithmetic-heavy day in the module. The pre-reading sends you to Attachment 4, How to Subnet a Network, before you arrive - the only attachment called out by name anywhere in the module schedule, which tells you how much the course expects you to already have in hand. Two things carry the exam weight. First, the class boundaries: the first-octet ranges for classes A, B and C, and the fact that 127 is missing from all of them. Second, the four IPv4 lifespan-extension techniques, because they are frequently confused with each other - subnetting divides, CIDR reallocates, private addressing reuses, and NAT translates. They solve the same shortage in four different ways.
Doctrinal sets to know cold
The five IPv4 classes
- Class A - first octet 1 to 126; three octets for devices; large organizations
- Class B - first octet 128 to 191; two octets for devices; medium-sized organizations
- Class C - first octet 192 to 223; one octet for devices; small organizations
- Class D - multicast communication, such as streaming video or audio
- Class E - reserved for experimental or research purposes, not used in production
The four techniques for extending the lifespan of IPv4
- Subnetting - divide one network into smaller subnetworks, each with its own network address
- Classless Inter-Domain Routing (CIDR) - allocate address space with variable-length subnet masks instead of fixed class boundaries, permitting subnets of any size
- Network Address Translation (NAT) - let many devices on a private network share one public IP address
- Private addressing - use non-globally-routable ranges reserved for internal use, so the same addresses can be reused in many separate networks
The three RFC 1918 private address ranges
- 10.0.0.0/8 - 10.0.0.0 through 10.255.255.255
- 172.16.0.0/12 - 172.16.0.0 through 172.31.255.255
- 192.168.0.0/16 - 192.168.0.0 through 192.168.255.255
NAT benefits and challenges
- Benefits: improved security by hiding the private addresses of devices; reduced cost by sharing a single public address; increased flexibility through non-routable ranges that need not be globally unique
- Challenges: limits hosting servers or services on the private network, because incoming traffic is hard to map to the correct device; adds complexity to network design; makes troubleshooting more difficult
IPv6 advantages over IPv4
- Larger address space - 128-bit against 32-bit, supporting a virtually unlimited number of devices
- Improved security - built-in support for IPsec, where IPv4 requires additional configuration
- Better performance - simplified header formats, improved routing protocols, and support for multicast traffic
- Simplified network configuration - autoconfiguration lets devices obtain addresses and DNS servers without manual setup
IPv6 adoption limitations
- Upgrading existing network infrastructure is costly and time-consuming, particularly for large networks or legacy equipment
- Every device on the network - routers, switches and other equipment - must support IPv6, which is hard where older or less common devices are in use
Physical versus logical network diagrams
- Physical - devices, cables and other hardware; the physical layout and interconnections; symbols joined by lines representing actual cables
- Logical - how the network operates and how information flows; adds IP addresses, subnet masks and configuration details for each device, plus the protocols used between them
- Both - used to design, plan, manage and document networks; the logical diagram is additionally named as a troubleshooting tool
Benefits of a physical network diagram
- Provides a visual representation that helps identify potential problems or bottlenecks
- Makes it easier to plan and implement changes to the topology
- Enables easier communication of network information to non-technical stakeholders
- Helps ensure the network is properly documented and understood by the whole IT team
Topologies covered on day 2
- Mesh - high redundancy and fault tolerance; expensive to build and maintain; used where reliability is critical, including the internet and military and aerospace applications
- Hybrid - combines two or more topologies to take the strengths of each while minimizing their weaknesses
- Wireless - nodes joined by radio or infrared through an access point; flexible, mobile and quick to set up; vulnerable to interference and unauthorized access
- Point-to-point - two nodes connected directly, typically between two buildings
- Point-to-multipoint - one node serving many, typically a wireless access point
Key terms
- IPv4
- Internet Protocol version 4, first specified in 1981 in RFC 791, which defined the format of IPv4 packets and the rules for routing data between networks. It uses a 32-bit addressing scheme developed in the 1970s.
- Octet
- One of the four 8-bit groups in an IPv4 address. The value in the first octet is what identifies an address's class.
- Class A
- First octet in the range 1 to 126. The remaining three octets identify specific devices, so a Class A network is very large. Typically used by large organizations requiring a large number of IP addresses.
- Class B
- First octet in the range 128 to 191. The remaining two octets identify devices. Typically used by medium-sized organizations.
- Class C
- First octet in the range 192 to 223. Only the last octet identifies devices, so a Class C network is small. Typically used by small organizations.
- Class D
- Used for multicast communication - sending a single message to multiple recipients, such as streaming video or audio. It is not divided into network and host portions the way A, B and C are.
- Class E
- Reserved for experimental or research purposes and not typically used in production networks.
- Internet Assigned Numbers Authority (IANA)
- The body that defines the specific address ranges for each class of IP address. The handout notes those ranges are subject to change over time.
- Subnetting
- Dividing a single network into smaller subnetworks, each with its own unique network address. It allows more efficient use of IP addresses and can improve network performance. One of the four techniques for extending the lifespan of IPv4.
- Classless Inter-Domain Routing (CIDR)
- A method of allocating IP addresses for more efficient use of available address space. CIDR replaces the traditional Class A, B and C scheme with a variable-length subnet mask, allowing subnets of any size.
- Variable-length subnet mask (VLSM)
- The mechanism CIDR uses in place of fixed class boundaries, allowing the creation of subnets of any size rather than only the three sizes the classes permit.
- Network Address Translation (NAT)
- A technique allowing multiple devices on a private network to share a single public IP address for communication with the internet. The NAT device replaces the source IP address of an outbound request with its own public address, then uses the source port number to work out which internal device an inbound response belongs to.
- Private addressing
- The use of IP addresses that are not globally routable on the internet but are reserved for use within private networks, defined in RFC 1918. Devices can be assigned addresses from these ranges with no coordination with an ISP and no registration with an internet registry.
- RFC 1918 ranges
- The three reserved private address ranges: 10.0.0.0/8 (10.0.0.0 to 10.255.255.255), 172.16.0.0/12 (172.16.0.0 to 172.31.255.255), and 192.168.0.0/16 (192.168.0.0 to 192.168.255.255). Note the middle range stops at 172.31, not 172.255.
- IPv6
- The latest version of the Internet Protocol, designed to eventually replace IPv4. It uses a 128-bit address format against IPv4's 32-bit, giving a vastly expanded address space.
- IPsec
- A suite of protocols providing secure communication over the internet. IPv6 includes built-in support for it; IPv4 requires additional configuration to implement it.
- Autoconfiguration
- An IPv6 feature allowing devices to obtain network configuration information such as IP addresses and DNS servers automatically, without manual configuration.
- Physical network diagram
- A graphical representation of the physical components of a network - devices, cables and other hardware - showing the physical layout and the interconnections between devices. Each device is a symbol; the lines are the actual cables.
- Logical network diagram
- A graphical representation of the logical components of a network, focusing on how the network operates and how information flows through it. It typically includes IP addresses, subnet masks and other configuration details for each device, plus the protocols used to move packets between them.
- Mesh topology
- A topology in which nodes have many interconnections. It provides high redundancy and fault tolerance - if a node or link fails, data reroutes through other nodes - at the cost of expense to build and maintain and possible congestion from the sheer number of connections.
- Hybrid topology
- Combines two or more different topologies, such as star and mesh, to take advantage of the strengths of each while minimizing their weaknesses.
- Wireless topology
- Nodes connected by wireless communication technology rather than physical cables, communicating through radio waves or infrared. A wireless access point or router usually provides connectivity to multiple wireless nodes.
- Point-to-point topology
- Two nodes directly connected to each other. Commonly used to connect two remote locations, such as between two buildings.
- Point-to-multipoint topology
- One node connected to multiple other nodes. Commonly used in wireless networks, where a single access point serves many devices.
Testable points
- IPv4 addresses divide into five classes, identified by the value in the first octet.
- Class A is first octet 1 to 126. Class B is 128 to 191. Class C is 192 to 223. Class D is multicast. Class E is experimental and research.
- 127 is absent from all the class ranges. Class A stops at 126 and Class B begins at 128 - the gap is real and is a favorite exam trap.
- The number of octets available for identifying devices shrinks as the class letter advances: three octets in Class A, two in Class B, one in Class C. That is exactly why A suits large organizations and C suits small ones.
- Class D is for multicast - a single message to multiple recipients, such as streaming video or audio.
- Class E is reserved for experimental or research purposes and is not typically used in production networks.
- IANA defines the specific address ranges for each class, and the handout notes those ranges are subject to change over time.
- There are four techniques for extending the lifespan of IPv4: subnetting, CIDR, NAT, and private addressing. Learn them as a set of four, because the questions that separate them are the ones most often missed.
- Subnetting divides one network into smaller subnetworks each with its own network address. CIDR reallocates address space using variable-length subnet masks instead of fixed classes. Private addressing reuses non-routable ranges inside many separate networks. NAT translates many private addresses onto one public address.
- CIDR replaces the traditional Class A, B and C scheme entirely, which is what makes it classless.
- NAT works by replacing the source IP address of an outbound request with the NAT device's own public address, then using the source port number to route the response back to the right internal device.
- NAT's three benefits are improved security by hiding private addresses, reduced cost by sharing one public address, and increased flexibility by letting private networks use non-routable ranges that need not be globally unique.
- NAT's three challenges are limiting the ability to host servers or services on a private network, added design complexity, and harder troubleshooting.
- The reason NAT makes hosting hard is specific: incoming traffic is difficult to map to the correct internal device, because the mapping normally depends on an outbound request having been made first.
- Private addressing is defined in RFC 1918 and reserves three ranges: 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16.
- The 172 range runs 172.16.0.0 to 172.31.255.255 - it stops at 172.31, not 172.255. The /12 prefix is what makes that true and it is the most commonly misremembered of the three.
- Private addresses require no coordination with an ISP and no registration with an internet registry, which is the whole point of them.
- Private addressing and NAT are normally used together: private addresses inside, one NAT device translating to a single public address for internet connectivity.
- IPv6 uses a 128-bit address format. IPv4 uses 32-bit. That single comparison is the most likely IPv6 exam item.
- IPv6's four key advantages are a larger address space, improved security through built-in IPsec support, better performance through simplified headers and improved routing and multicast support, and simplified configuration through autoconfiguration.
- The security advantage is a matter of defaults rather than capability: IPv6 includes built-in support for IPsec, while IPv4 requires additional configuration to implement it.
- IPv6 adoption has two named limitations: the cost and time of upgrading existing infrastructure, especially large networks and legacy equipment, and the need for every device on the network - routers, switches and other equipment - to support it.
- A physical network diagram shows devices, cables and hardware layout. A logical network diagram shows IP addresses, subnet masks, configuration details and protocols. Both use the same symbology for devices; what differs is the information attached to them.
- Both diagram types are used to design, plan and manage networks and to document existing ones. The logical diagram is additionally named as a troubleshooting tool.
- A mesh topology's advantage is high redundancy and fault tolerance; its disadvantages are expense and the congestion that can come from the sheer number of connections. It is used where reliability is critical - the internet itself, and military and aerospace applications.
- A wireless topology's advantages are flexibility and mobility plus quick setup; its disadvantages are susceptibility to interference from other wireless networks and greater vulnerability to unauthorized access than wired networks.
- Point-to-point connects two nodes directly and is typical between two buildings. Point-to-multipoint connects one node to many and is typical of a wireless access point serving many devices.
References
Network Operations and Planning Student HandoutRFC 791RFC 1918FM 6-02
Transport Concepts 113-SCCCD03
Learning objective and standard
Learning objectiveApply network transport concepts and principles to network planning
StandardApplication will include, and the student will have met the standards when they accurately complete the listed requirements while also receiving a passing grade on the Network Operations Practicum and Network Essentials Exam: 1. Define transport concepts. 2. Identify wired technologies. 3. Identify wireless technologies. 4. Identify UNICAST, MULTICAST, BROADCAST and ANYCAST. 5. Identify advantages and disadvantages of transport systems. 6. Estimate the priority of links. 7. Perform the transport concepts exercise. 8. Review the transport concepts exercise.
Day 3, and the lesson that most directly answers a question a battalion S6 gets asked in the field: which transport, and why. The lesson plan opens with a story from Operation Iraqi Freedom in 2003 in which senior leadership insisted on running fiber to forward forces and the signal officer had to build a case for line of sight or satellite instead - and won it with data rather than opinion. That is the skill the lesson is teaching. Two things carry the exam weight. The Ethernet naming convention is fully decodable once you know the rule, so it is free points. And the four communication types - unicast, broadcast, multicast, anycast - are a small closed set with a clean discriminator each, so they are worth learning cold.
Doctrinal sets to know cold
The four communication types
- Unicast - one to one; a frame from one source host to one destination host
- Broadcast - one to many meaning all; a frame from one source host to every other host in the network
- Multicast - one to a defined group rather than to everyone; carried by IPv4 Class D addresses
- Anycast - the sender delivers to the destination nearest to it; a group may share one destination address and the network picks the closest
Decoding an Ethernet standard name
- The leading number is the data rate in Mbps - 10, 100 or 1000
- Base means baseband, one signal at a given instant, as opposed to broadband which carries several
- T means twisted pair
- 2 means thin coaxial and 5 means thick coaxial
- F or X usually means fiber-optic cable
Common Ethernet standards
- 10Base-2 - 10 Mbps, coaxial RG-58
- 10Base-5 - 10 Mbps, coaxial RG-8
- 10Base-T - 10 Mbps, twisted pair, two pairs of Cat-3 or higher
- 100Base-T - 100 Mbps, twisted pair, two pairs of Cat-5; the 100Base-T4 variant uses four pairs
- 100Base-TX - 100 Mbps, twisted pair, two pairs of Cat-5
- 100Base-FX - 100 Mbps, fiber-optic
- 1000Base-T - 1 Gbps, twisted pair, four pairs of Cat-5
- 10GBase-X - 10 Gbps, fiber-optic
Wired transmission mediums and where each ended up
- Coaxial - two concentric conductors and two insulators, 10 to 100 Mbps; once the long-range analog backbone between telephone exchanges; displaced by fiber in telephone networks and by twisted pair in LANs; kept alive by cable television and video distribution
- Twisted pair - dominant in houses and offices because the telephony plant was already installed; better isolators, copper and shielding made it a high-speed data medium
- Multimode optical fiber - increasingly installed to homes, several Gbps
- Single mode optical fiber - the most used medium in transport networks
Why demand for optical fiber is rising across LAN, MAN and WAN
- Immunity to electromagnetic interference
- Extremely high bandwidth
The structure of a transport network
- Backbone or core network - transfers large amounts of data among main nodes
- Main nodes - connect onward to secondary nodes
- Secondary nodes - connect to customer nodes
- Customer nodes - the end of the chain
What the 2003 transport vignette teaches
- Senior leadership directed fiber to forward forces to move HUMINT and SIGINT quickly
- The signal officer assessed that emplacement time made fiber the wrong choice and recommended line of sight or satellite
- He compiled the supporting data with two NCOs and a warrant officer rather than arguing from authority
- After an hour of offline discussion the recommendation was accepted
- The lesson: the medium with the best specifications is not automatically right for the timeline, and the argument has to be made with data
Key terms
- Transmission medium
- The path a signal travels between transmitter and receiver. Mediums classify as wired or wireless, and that first split organizes the entire lesson.
- Wired transmission medium
- Examples include twisted pair cables, coaxial cables, and multimode or single mode optical fiber cables.
- Wireless transmission medium
- A transmitter and a receiver using antennas to convert electric signals into electromagnetic waves and back, with the waves propagating over air. Wireless mediums can be either guided or unguided.
- Guided wireless
- Directional antennas at both the transmitter and receiver, so electromagnetic waves propagate directly from the transmit antenna into the receive antenna. Unguided radiates broadly instead.
- Baseband
- A connection carrying only one signal at a given instant. The word Base in an Ethernet standard name means the network is baseband.
- Broadband
- A connection carrying multiple signals at any time - the contrast to baseband.
- Ethernet standard naming
- Standards such as 10Base-2 or 100Base-TX encode everything in the name. The leading number is the data rate in Mbps, Base means baseband, and the terminating letter or number gives the cable: T for twisted pair, 2 for thin coaxial, 5 for thick coaxial, F or X for fiber-optic.
- Coaxial cable
- Consists of two concentric conductors and two insulators, supporting 10 to 100 Mbps. It was the main medium for long-range analog transmission between local telephone exchanges and supported high capacity communications, before being replaced by optical fiber in telephone networks and by twisted pair in LANs.
- Twisted pair
- The transmission medium that still dominates houses and offices, originally installed for analog telephony. Improvements in isolators, copper quality and shielding made it capable of high-speed data as well.
- Multimode optical fiber
- Increasingly installed at homes, reaching throughputs on the order of several gigabits per second.
- Single mode optical fiber
- The most used transmission medium in transport networks - the long-haul, high-capacity choice.
- Transport network
- The backbone or core network used for transferring large amounts of data among different main nodes. Those main nodes connect to secondary nodes, which finally connect to customer nodes.
- Unicast
- One-to-one communication. A frame is sent from one source host to one destination host.
- Broadcast
- One-to-many, meaning all. A frame is sent from one source host to every other destination host in the network.
- Multicast
- One-to-many, but only to a defined group rather than to everyone. It is the middle case between unicast and broadcast, and IPv4 Class D addresses exist to carry it.
- Anycast
- The sender delivers packets to whichever destination is nearest to it. It may allow messages to be sent to a group of hosts that all share the same destination address, with the network choosing the closest.
- Convergence of voice and data
- Most companies now run IP telephony over the same physical infrastructure as their data. The handout treats this as the reason the twisted pair plant installed for telephony ended up carrying the network.
Testable points
- Transmission mediums classify first as wired or wireless. Everything else in the lesson hangs off that split.
- Wireless mediums can be guided or unguided. Guided means directional antennas at both ends so the wave travels directly from transmit to receive antenna.
- The number of destination stations determines the form of broadcasting - which is the reason unicast, multicast, broadcast and anycast are taught in a transport lesson rather than an addressing one.
- Unicast is one to one. Broadcast is one to all. Multicast is one to a defined group. Anycast is one to the nearest member of a group sharing a destination address.
- Anycast is the only one of the four where the network, not the sender, decides which host receives the packet.
- In an Ethernet standard name, the leading number is the data rate in Mbps: 10, 100 or 1000.
- Base in an Ethernet standard name means baseband - one signal at a given instant - as opposed to broadband, which carries multiple signals at any time.
- The terminating character in an Ethernet standard name gives the cable type: T for twisted pair, 2 for thin coaxial, 5 for thick coaxial, F or X for fiber-optic.
- 10Base-2 is 10 Mbps over RG-58 coaxial. 10Base-5 is 10 Mbps over RG-8 coaxial. The 2 and 5 refer to the cable, not the speed.
- 10Base-T is 10 Mbps over two pairs of Cat-3 or higher twisted pair. 100Base-T is 100 Mbps over two pairs of Cat-5, and 100Base-T4 designates four pairs.
- 100Base-FX is 100 Mbps over fiber. 1000Base-T is 1 Gbps over four pairs of Cat-5. 10GBase-X is 10 Gbps over fiber.
- Coaxial cable consists of two concentric conductors and two insulators and supports 10 to 100 Mbps.
- Coaxial was the main medium for long-range analog transmission between local telephone exchanges, supporting high capacity as defined by ITU-T G.333 - 10,800 telephone channels at a maximum frequency of 60 MHz.
- Coaxial was displaced twice: by optical fiber in telephone networks, and by twisted pair in LANs. Cable television is what kept it in service, and it is still used for video distribution between devices.
- Twisted pair dominates houses and offices because the telephone plant was already there. Improved isolators, copper quality and shielding are what turned it into a high-speed data medium.
- Single mode optical fiber is the most used transmission medium in transport networks. Multimode fiber is what has increasingly been installed to homes, at several gigabits per second.
- A transport network is the backbone or core, moving large amounts of data among main nodes, which connect to secondary nodes, which connect to customer nodes.
- Demand for optical fiber is increasing across LAN, MAN and WAN segments for two stated reasons: immunity to electromagnetic interference and extremely high bandwidth.
- Immunity to electromagnetic interference is the property that makes fiber attractive in a contested electromagnetic environment - the point where this lesson connects to Module C.
- The lesson's concrete experience is a 2003 Operation Iraqi Freedom vignette: senior leadership insisted on running fiber forward, the signal officer argued for line of sight or satellite because of the time fiber would take to emplace, and won by compiling the supporting data with his NCOs and warrant officer.
- The takeaway from that vignette is not that fiber is wrong. It is that a transport recommendation has to be made with data, and that the medium with the best raw specifications is not automatically the right one for the timeline.
- The lesson's major topic is 2.0 DODIN Access Operations, with minor topics 2.2 Unified Network, 2.4 Network Operations, and 2.6 Network Management.
- The supported task is 113-25A-2001, Plan DODIN Enterprise Services in support of a Mission - the task this whole module ultimately serves.
References
Network Operations and Planning Student HandoutFM 6-02ATP 6-02.12ATP 6-02.71ITU-T G.333
Network Technologies: Routing, VLANs and Tunneling 113-SCCCD05
Learning objective and standard
Learning objectiveDefine network technologies and apply them in Signal planning
StandardDefine network technologies. The student must correctly define and identify the following without error: 1. Define autonomous system concepts. 2. Define the functions of routing protocols. 3. Identify network tunneling concepts.
Three related ideas that together explain how traffic gets from one network to another and how it stays private on the way. Autonomous systems are the administrative boundary; routing protocols are how routers inside and between those boundaries agree on paths; tunneling is how one protocol rides inside another. The exam value is concentrated in two closed sets. The interior-versus-exterior gateway protocol split is small and absolute - RIP, OSPF and IS-IS are interior, BGP is exterior. And the three routing algorithm families each have a clear discriminator: distance vector counts hops, link state builds a map, hybrid does both. Tunneling adds a fourth set worth learning, because each protocol is tied to a specific OSI layer.
Doctrinal sets to know cold
The two types of routing protocol
- Interior Gateway Protocols (IGPs) - exchange routing information within an autonomous system. Examples: RIP, OSPF, IS-IS
- Exterior Gateway Protocols (EGPs) - exchange routing information between different autonomous systems. Example: BGP
The three routing algorithm families
- Distance vector - best path by hop count; exchanges tables with neighbors; simple, light on resources, slower to converge, less accurate. Example: RIP
- Link state - best path from the topology and the status of each link; floods link state updates and builds a detailed map; faster convergence, more accurate, more resource-hungry and complex. Examples: OSPF, IS-IS
- Hybrid - combines both and keeps a partial topology map, aiming for fast convergence with efficient resource use. Example: EIGRP
RIP versus EIGRP
- Maximum hop count - RIP 15, EIGRP 224
- Metric - RIP counts hops only; EIGRP uses a composite metric of bandwidth, delay, reliability, load and the minimum bandwidth of the whole path
- Algorithm - RIP is distance vector with periodic updates every 30 seconds; EIGRP uses the Diffusing Update Algorithm
- Addressing - RIPv1 has no classless support; RIPv2 and EIGRP both support classless routing and variable-length subnet masks
- Portability - RIP is open; EIGRP is Cisco proprietary and may not work with other vendors' equipment
The four VLAN benefits
- Improved network performance by reducing broadcast traffic
- Enhanced security by segregating sensitive data or devices
- Simplified network management through control of traffic flow
- Flexible network design - virtual networks without physical changes to the infrastructure
Tunneling protocols by OSI layer
- PPTP - layer 2, data link; encapsulates in GRE; widely supported and easy to configure; least secure of the four
- L2TP - layer 2, data link; encapsulates in UDP; commonly paired with IPsec for security
- IPsec - layer 3, network; encrypts and authenticates packets; strong security, more complex to configure
- SSTP - layer 4, transport; encapsulates in SSL/TLS; Microsoft proprietary, designed for Windows
DMVPN characteristics
- Hub-and-spoke architecture with a central hub and multiple remote spokes
- Spokes joined to the hub through a dynamic routing protocol such as OSPF or EIGRP
- Establishes VPN connections between sites dynamically as needed
- New spoke sites can be added without additional configuration on the hub
- Supports multiple tunneling protocols including GRE and IPsec
- Used in large-scale enterprise networks and to connect cloud resources to on-premises infrastructure
The three mechanisms of trust-based security
- Authentication - verifying that network entities are who they claim to be
- Authorization - determining whether an authenticated entity has permission for a specific resource or action
- Encryption - scrambling data to prevent unauthorized access or modification
Key terms
- Autonomous system (AS)
- A network under a single administrative domain with a common routing policy, typically managed by a single organization such as an internet service provider. Autonomous systems let different organizations connect their networks and exchange traffic while keeping control of their own routing policies and infrastructure.
- Autonomous System Number (ASN)
- The unique identifier assigned to an autonomous system by the Internet Assigned Numbers Authority.
- Routing protocol
- A set of policies and procedures used by routers to exchange information with each other and determine the best path for forwarding traffic to its destination. Protocols choose paths based on factors such as network topology, bandwidth and delay.
- Interior Gateway Protocol (IGP)
- Exchanges routing information within an autonomous system. Examples are RIP, OSPF and IS-IS.
- Exterior Gateway Protocol (EGP)
- Exchanges routing information between different autonomous systems. BGP is the example.
- Distance vector routing
- Determines the best path based on the number of hops - intermediate devices - between source and destination. Routers exchange routing information with their neighbors and update their tables accordingly. Simple to configure and light on network resources, but slower to converge and less accurate than the alternatives.
- Link state routing
- Determines the best path from the network topology, including the status of each link or interface. Routers flood the network with link state updates and each builds a detailed map. Faster to converge and more accurate than distance vector, at the cost of more network resources and more configuration complexity.
- Hybrid routing
- Combines features of distance vector and link state, maintaining a partial map of the network topology. It aims to give the benefits of both - faster convergence and more efficient use of network resources.
- Convergence
- How quickly all routers in a network agree on a consistent view of the topology after a change. It is the property that most separates the three routing algorithm families.
- Routing Information Protocol (RIP)
- One of the oldest and simplest routing protocols, an IGP using a distance-vector algorithm based on hop count. Its maximum hop count is 15, which confines it to small networks with simple topologies. Updates are sent every 30 seconds by default.
- RIPv1 versus RIPv2
- RIPv1 does not support subnet masks, classless routing, or authentication. RIPv2 addresses all three, adding support for variable-length subnet masks and authentication.
- Open Shortest Path First (OSPF)
- A link-state interior gateway protocol for routing within a single autonomous system, designed to be faster and more efficient than distance-vector protocols such as RIP while supporting more complex topologies.
- Intermediate System to Intermediate System (IS-IS)
- A link state interior gateway protocol, listed alongside OSPF as the other link-state example.
- Border Gateway Protocol (BGP)
- The example of an exterior gateway protocol - the protocol that exchanges routing information between different autonomous systems.
- Enhanced Interior Gateway Routing Protocol (EIGRP)
- A Cisco proprietary hybrid routing protocol combining distance-vector and link-state features, designed for large enterprise networks. It offers fast convergence, efficient bandwidth use, and support for a wide range of topologies - but only on Cisco equipment.
- Composite metric
- The multi-factor path calculation EIGRP uses, considering bandwidth, delay, reliability, load, and the minimum bandwidth of the entire path. EIGRP also supports using multiple metrics so administrators can prioritize some over others.
- Diffusing Update Algorithm (DUAL)
- The algorithm EIGRP uses to compute the shortest path to a destination. It converges quickly after a topology change while minimizing the update traffic generated.
- Unequal-cost load balancing
- An EIGRP feature distributing traffic over multiple paths with different metrics, as long as the difference in metrics falls within a threshold. EIGRP also supports load balancing based on bandwidth so traffic spreads more evenly over high-speed links.
- Virtual local area network (VLAN)
- A way to segment a physical network into multiple logical networks, grouping devices by criteria such as location, function or security requirement even when they are physically scattered. VLANs are created by configuring switches to assign specific ports to a VLAN.
- Inter-VLAN routing
- Traffic between VLANs is routed by a router or by a layer 3 switch through sub-interfaces. Devices in different VLANs cannot reach each other at layer 2 alone, which is the point.
- Tunneling
- Encapsulating one network protocol within another. Data is taken from one protocol, wrapped in another, transmitted across the network, and unwrapped at the far end. The outer protocol transports; the inner protocol carries the actual data.
- Point-to-Point Tunneling Protocol (PPTP)
- Operates at the data link layer, layer 2. It encapsulates data packets within Generic Routing Encapsulation packets and adds a control header. Widely supported and relatively easy to configure, but considered less secure than L2TP or IPsec.
- Layer 2 Tunneling Protocol (L2TP)
- Operates at the data link layer, layer 2. It encapsulates data packets within UDP packets and adds a control header, and is commonly used together with IPsec for secure VPN connections.
- IPsec as a tunneling protocol
- Operates at the network layer, layer 3. It encrypts and authenticates data packets for secure transmission over the internet, and can be combined with other tunneling protocols such as L2TP. Strong encryption and authentication, but more complex to configure.
- Secure Socket Tunneling Protocol (SSTP)
- Operates at the transport layer, layer 4. It encapsulates data packets within SSL/TLS packets and adds a control header. A Microsoft proprietary protocol designed to work with Windows-based systems.
- Generic Routing Encapsulation (GRE)
- The encapsulation PPTP uses to wrap data packets, and one of the tunneling protocols DMVPN supports alongside IPsec.
- Dynamic Multipoint VPN (DMVPN)
- A technology providing secure and scalable connectivity between multiple sites over a public or private network, designed to simplify deploying and managing VPNs in large-scale networks. It uses a hub-and-spoke architecture with a dynamic routing protocol such as OSPF or EIGRP joining spokes to the hub.
- Trust-based security
- A security approach emphasizing the establishment and maintenance of trust relationships between network entities. Trusted entities are granted access to resources and data; untrusted entities are denied. Trust is established through authentication, authorization and encryption.
Testable points
- An autonomous system is a network under a single administrative domain with a common routing policy, and it receives a unique Autonomous System Number from IANA.
- Autonomous systems matter because they let different organizations connect their networks and exchange traffic while each keeps control of its own routing policies and infrastructure.
- Routing protocols split into exactly two types: interior gateway protocols within an autonomous system, and exterior gateway protocols between autonomous systems.
- RIP, OSPF and IS-IS are interior gateway protocols. BGP is the exterior gateway protocol example. That split is small, absolute, and frequently tested.
- There are three standard routing algorithm families: distance vector, link state, and hybrid.
- Distance vector counts hops. Link state builds a map of the topology including the status of each link. Hybrid keeps a partial map and combines both.
- Distance vector protocols are simple to configure and use fewer network resources, but converge more slowly and less accurately.
- Link state protocols converge faster and more accurately, but require more network resources and are more complex to configure. The trade runs in exactly the opposite direction from distance vector.
- RIP's maximum hop count is 15. That single number is what confines it to small networks with simple topologies.
- RIP sends updates every 30 seconds by default, containing the hop count to all known destinations. The interval is adjustable.
- RIP can suffer slow convergence and routing loops in larger networks, causing packet loss and network instability.
- RIPv1 does not support subnet masks, classless routing, or authentication. RIPv2 adds variable-length subnet masks and authentication.
- OSPF is a link-state IGP designed to be faster and more efficient than distance-vector protocols such as RIP, while supporting more complex topologies.
- EIGRP is Cisco proprietary. That is its defining limitation - it can only be used with Cisco routers and may not be compatible with other vendors' equipment.
- EIGRP's maximum hop count is 224, against RIP's 15, which is why it suits far larger networks.
- EIGRP's composite metric considers bandwidth, delay, reliability, load, and the minimum bandwidth of the entire path - five factors, against RIP's single hop count.
- EIGRP uses the Diffusing Update Algorithm to compute shortest paths, converging quickly after a topology change while minimizing update traffic.
- EIGRP supports unequal-cost load balancing, distributing traffic across paths with different metrics when the difference falls within a threshold.
- EIGRP supports classless routing, which gives more efficient use of address space and better scalability than classful routing.
- VLANs group devices by location, function or security requirement even when they are physically scattered across the network, and are created by assigning switch ports to a VLAN.
- Devices in the same VLAN communicate as though they were on the same physical network, even across different switches or network segments.
- Traffic between VLANs is routed by a router or by a layer 3 switch through sub-interfaces. A layer 2 switch alone cannot move traffic between VLANs.
- VLANs provide four benefits: improved performance by reducing broadcast traffic, enhanced security by segregating sensitive data or devices, simpler management through control of traffic flow, and flexible design without physical infrastructure changes.
- Tunneling has two stated aims: enabling communication between networks using different protocols, and providing a secure communication channel between networks.
- In a tunnel, the outer protocol transports the encapsulated data across the network and the inner protocol carries the actual data.
- The four tunneling protocols map to specific OSI layers: PPTP at layer 2, L2TP at layer 2, IPsec at layer 3, and SSTP at layer 4.
- PPTP encapsulates within GRE packets; L2TP encapsulates within UDP packets; SSTP encapsulates within SSL/TLS packets. IPsec encrypts and authenticates rather than wrapping in a carrier protocol.
- PPTP is easy to set up but considered less secure than L2TP or IPsec. IPsec gives strong encryption and authentication but is more complex to configure. SSTP is Microsoft proprietary and designed for Windows.
- L2TP is commonly used in conjunction with IPsec, because L2TP provides the tunnel and IPsec provides the security.
- DMVPN uses a hub-and-spoke architecture with a central hub connecting to multiple remote spokes, joined by a dynamic routing protocol such as OSPF or EIGRP.
- DMVPN's key benefit is that new spoke sites can be added without additional configuration on the hub - it establishes VPN connections between sites dynamically as needed.
- DMVPN supports multiple tunneling protocols including GRE and IPsec.
- Trust-based security establishes trust through three mechanisms - authentication, authorization and encryption - and can be implemented at the application, transport or network layers.
References
Network Operations and Planning Student HandoutFM 6-02ATP 6-02.71ATP 6-02.12
Network Signal Flow 113-SCCCD04
Learning objective and standard
Learning objectiveApply network signal flow concepts in an operational environment
StandardApply network signal flow in an operational environment by completing the following: 1. Define traffic flow within different network architectures in a clear and concise manner, without error. 2. Apply network signal flow concepts in a clear and concise manner, without error.
The lesson that turns the OSI model from a list into a process. It traces a packet from source to destination four times over, at increasing difficulty: inside one LAN, between LANs, across a WAN, and finally through a tunnel and a TACLANE into a colorless core. The organizing device is a postal analogy that maps every OSI layer onto a step in sending a letter, and it is worth learning because it makes encapsulation order intuitive rather than memorized. Three things carry the exam weight: which device maintains which of the three tables, the fact that signal flow is always destination-based, and the encapsulation order when GRE and IPsec are stacked - because the order is counterintuitive and the lesson states it explicitly.
Doctrinal sets to know cold
The three essential tables and who maintains each
- MAC address table - maintained by switches only; maps MAC addresses to switch ports; built dynamically, ages out; avoids unnecessary flooding within the LAN
- ARP table or cache - maintained by hosts and routers; maps IP addresses to MAC addresses; populated by ARP requests and replies; performs layer 3 to layer 2 resolution within a subnet
- Routing table - maintained by routers and layer 3 switches; determines the next hop by destination IP; entries hold destination networks, subnet masks, next-hop IPs and interfaces; routes may be connected, static or dynamic
The postal system analogy, layer by layer
- Layer 7 application - writing the letter; drafting the message for the recipient
- Layer 6 presentation - formatting the letter; legibility, common language, encrypting, compressing, translating
- Layer 5 session - the postal counter processing it; initiating and managing the communication
- Layer 4 transport - the envelope and delivery confirmation; segmenting, error checking, acknowledgements
- Layer 3 network - the postal code for post office processing; choosing the best route to the destination regional hub, that is IP addressing
- Layer 2 data link - the local address for delivery; handoff to the local delivery truck for pinpoint delivery, that is MAC addressing
- Layer 1 physical - trucks, roads and planes; the physical medium, wired copper or fiber, or wireless
Four networking concepts the postal model makes concrete
- Encapsulation - a letter goes inside an envelope, just as data is wrapped in protocol headers at each layer
- Addressing - a letter needs a mailing address, just as packets need IP and MAC addresses
- Reliability and tracking - registered mail gives confirmation and tracking, just as TCP ensures delivery with acknowledgements
- Routing - postal hubs choose the optimal path, just as routers choose the best network path using routing tables
The intra-LAN forwarding decision
- Is the destination device in the same network? If yes, this is intra-LAN
- Is the ARP entry already in the ARP cache table? If yes, the MAC address is known
- Forward the frame to the directly connected device
- One broadcast domain throughout - each switch port is its own collision domain, but the network is a single broadcast domain
Encapsulation order when GRE and IPsec are stacked
- GRE: new IP header 1, GRE header, payload - where the GRE payload is the original IP header plus the original payload
- IPsec: new IP header 2, ESP header, payload - where the ESP payload is new IP header 1, the GRE header, and the GRE payload
- The frame then encapsulates all of that layer 3 information into its own payload
- Neither the GRE header nor the ESP header can route anything - neither carries source or destination IP addresses, which is why each needs a new IP header
Where routing decisions use which header
- Outside the tunnel - routing uses the original IP header
- Inside the tunnel - routing uses the new IP header
- That substitution is the entire mechanism of tunneling
Interchangeable names for network encryption devices
- HAIPE - High Assurance Internet Protocol Encryptor
- TACLANE - Tactical Local Area Network Encryption
- INE - Inline Network Encryptor
- KG-series designations
Red and black in signal flow symbology
- Red - plain text (PT), unencrypted; the protected side of an encryption device
- Black - cipher text (CT), encrypted; the side facing the untrusted transport
- Colorless core - all data encrypted end to end regardless of classification, so the core carries no red-black distinction at all
- Colorless communication - SIPR and NIPR tunneled over a single signal flow path
Key terms
- Network signal flow
- The path a data packet takes as it travels from its source to its destination across a network - the sequence of decisions and handoffs rather than the diagram of the wiring.
- MAC address table
- Maintained by switches. Maps MAC addresses to specific switch ports and enables frame forwarding based on destination MAC address. Built dynamically as frames arrive, with entries that age out over time. It exists only on switches or other layer 2 devices.
- ARP table (ARP cache)
- Maintained by hosts and routers. Maps IP addresses to MAC addresses and is used when a device wants to send data to another device on the same subnet. Populated through ARP requests and replies. It is the layer 3 to layer 2 resolution step.
- Routing table
- Maintained by routers and layer 3 switches. Determines the next hop for forwarding packets based on destination IP address. Entries include destination networks, subnet masks, next-hop IP addresses, and interfaces, and may be directly connected, static, or dynamic routes learned from OSPF or EIGRP.
- Collision domain
- A network segment where simultaneous transmissions collide. On a modern switch, each switch port is its own collision domain.
- Broadcast domain
- The set of devices that receive a broadcast frame. A single network or subnet is a single broadcast domain, which is why a LAN is usually thought of as one network or one subnet.
- Intra-LAN communication
- Communication within a single broadcast domain - source and destination on the same network. The switch forwards the frame directly to the connected device once the ARP entry is in cache.
- Inter-LAN communication
- Communication between different networks, requiring a router or layer 3 switch to move the packet from one broadcast domain to another.
- Destination-based forwarding
- The governing rule of signal flow: basic IP communication is always destination based, and the destination always determines the first step. Every decision in the chain starts by asking whether the destination is local or remote.
- Vertical layer communication
- Interaction between OSI layers inside a single device. Layers communicate with adjacent layers, and upper and lower layer interaction occurs at the session and transport layers.
- Generic Routing Encapsulation (GRE) header
- A tunneling header that carries no routing information of its own - it has no source or destination IP addresses. A GRE header must therefore be given a new IP header in order to be routed. Its payload consists of the original IP header and the original payload.
- Encapsulating Security Payload (ESP) header
- The IPsec header providing confidentiality through encryption. Like the GRE header, it contains no source or destination IP addresses and cannot route anything, so it too requires a new IP header.
- TACLANE
- Tactical Local Area Network Encryption. One of several interchangeable names for the same class of network encryption device.
- HAIPE
- High Assurance Internet Protocol Encryptor. Used interchangeably with TACLANE, INE, and the KG-series designations for network encryption devices securing data in transit.
- Plain text (PT) side
- The red side of an encryption device - unencrypted traffic. In the lesson's symbology, red is plain text.
- Cipher text (CT) side
- The black side of an encryption device - encrypted traffic. In the lesson's symbology, black is cipher text.
- Colorless core architecture
- An architecture that encrypts all data end to end regardless of classification, so classified and unclassified traffic both undergo encryption and the core carries no distinction between them.
- Colorless communication
- Tunneling SIPR and NIPR over a single signal flow communication path. The core does not know or care which is which, which is the point of the name.
- Physical network diagram (signal flow context)
- Shows the physical arrangement of components - hardware, physical ports, cables.
- Logical network diagram (signal flow context)
- Shows the signal flow of information - hardware plus configuration such as IP addresses and subnets. The lesson notes that in practice a combination of both is usually drawn on the same diagram.
- Socket
- An IP address paired with a port number, written as address:port. The lesson's device tables track network, IP and socket, and MAC together, because signal flow needs all three.
Testable points
- Network signal flow is the path a packet takes from source to destination - the process, not the wiring diagram.
- There are three essential tables, and each is maintained by a different kind of device. Knowing which device holds which table is the highest-yield fact in the lesson.
- The MAC address table is maintained by switches, maps MAC addresses to switch ports, and exists only on switches or other layer 2 devices.
- MAC address table entries are built dynamically as frames arrive and age out over time. The table speeds delivery within the local LAN by avoiding unnecessary flooding.
- The ARP table is maintained by both hosts and routers - not by switches. It maps IP addresses to MAC addresses and is populated through ARP requests and replies.
- The ARP table is what performs layer 3 to layer 2 resolution, and it is used when a device wants to reach another device on the same subnet.
- The routing table is maintained by routers and layer 3 switches, and determines the next hop based on destination IP address.
- Routing table entries include destination networks, subnet masks, next-hop IP addresses, and interfaces, and can be directly connected, static, or dynamic routes learned from protocols such as OSPF or EIGRP.
- Each switch port is its own collision domain. A single network or subnet is a single broadcast domain.
- Intra-LAN communication means one broadcast domain. That is the definition the lesson uses, and it is why a LAN is usually thought of as one network or one subnet.
- Basic IP communication is always destination based. The destination always determines the first step in signal flow.
- The intra-LAN decision sequence is: the destination device is in the same network, the ARP entry is in the ARP cache table, so forward the frame to the directly connected device.
- Layers communicate with adjacent layers within a single device. Upper and lower layer interaction occurs at the session and transport layers.
- In the postal analogy, layer 7 is writing the letter, layer 6 is formatting it, layer 5 is the postal counter processing it, layer 4 is the envelope and delivery confirmation, layer 3 is the postal code and route selection, layer 2 is the local address and delivery truck, and layer 1 is the trucks, roads and planes themselves.
- The analogy maps four networking concepts precisely: encapsulation is the letter going inside an envelope, addressing is the mailing address, reliability and tracking is registered mail against TCP acknowledgements, and routing is postal hubs choosing the optimal path against routers using routing tables.
- A GRE header carries no source or destination IP addresses and therefore cannot route anything. It must be given a new IP header to be routed.
- A GRE payload consists of the original IP header plus the original payload - the whole original packet, not just its data.
- An ESP header, like a GRE header, has no source or destination IP addresses and cannot route. It too requires a new IP header.
- When GRE and IPsec are stacked, the order is: new IP header 1, GRE header, payload - and then the ESP payload consists of new IP header 1, the GRE header, and the GRE payload, wrapped by new IP header 2 and the ESP header.
- Outside a tunnel, routing uses the original IP header. Inside the tunnel, routing uses the new IP header. That is the whole mechanism of tunneling stated in one sentence.
- The frame encapsulates all layer 3 information into its payload - the layer 2 wrapper goes on last and comes off first.
- HAIPE, TACLANE, INE and the KG-series designations are used interchangeably for network encryption devices securing data in transit.
- In the lesson's symbology, red means plain text and unencrypted; black means cipher text and encrypted. A TACLANE has a plain text side and a cipher text side.
- The colorless core architecture encrypts all data end to end regardless of classification, so classified and unclassified data both undergo encryption.
- Colorless communication means tunneling SIPR and NIPR over one signal flow communication path. Adding a SIPR side to an existing NIPR path is what creates it.
- A physical network diagram shows hardware, physical ports and cables. A logical network diagram shows signal flow with configuration such as IP addresses and subnets. In practice a combination of both is drawn on one diagram.
- The lesson tracks four attributes per device: network, IP and socket, MAC address, and the device name. Signal flow analysis needs all of them at once.
References
Network Operations and Planning Student HandoutFM 6-02ATP 6-02.71ATP 6-02.12
Network Management 113-SCCCD07
Learning objective and standard
Learning objectiveIdentify network management tools and manage network monitoring tools
StandardIdentify network management tools. The student must correctly define, perform and review the following without error: 1. Define network monitoring tools. 2. Define internet control message protocol (ICMP) concepts. 3. Define simple network message protocol (SNMP) concepts. 4. Define network management system (NMS). 5. Define Installation as a Docking Station (IaaDS). 6. Define Risk Management Framework (RMF). 7. Perform network management tools practical exercise. 8. Review network management tools practical exercise.
Day 5, and the most immediately usable lesson in the module for anyone who will run a help desk. It is built around two protocols and one framework. ICMP is the agentless option - ping, traceroute and pathping all run on it, and the whole advantage-and-disadvantage list follows from the fact that it needs nothing installed on the device being watched. SNMP is the agent-based option, with three components and three versions whose differences are entirely about security. The FCAPS model organizes what network management even means. Then two Army-specific items sit on top: IaaDS, a FORSCOM directive rather than a technology, and RMF, which replaced the legacy certification and accreditation process.
Doctrinal sets to know cold
The five characteristics of monitoring tools
- Identify problems and send an alert message to the administrator
- Log real-time and historical information
- Find optimal settings
- Monitor the number of users on a network
- Monitor network traffic, in real time or over a period for later analysis
The two ICMP message classes
- Error messages - report problem conditions and give feedback to a source device about an error that occurred
- Informational or query messages - let devices exchange information, for diagnostics, testing and other purposes
The three ICMP-based tools
- Ping - confirms reachability of a remote host at layer 3 using Echo Request and Echo Reply
- Traceroute - displays the path a packet takes, using the same Echo Request and Echo Reply messages but changing the time-to-live value
- Pathping - a route tracing tool combining ping and traceroute plus latency and loss at intermediate hops; default 30 hops and a 3-second time-out
ICMP monitoring advantages
- Agentless - requires no installation or configuration on the monitored devices
- Monitors any network device regardless of operating system, vendor or device type
- Provides a quick bird's-eye view of the entire network
- Is simple to implement
ICMP monitoring disadvantages
- Limited to monitoring device status at the network layer only
- Cannot monitor services such as HTTP, FTP and SMTP
- Can fail because many networks block ICMP traffic
- Can choke links on slower WANs by consuming excessive bandwidth
- Can produce false results in redundant networks by reporting standby interfaces as down
- Caution: ICMP is often assigned lower priority, so a busy router may not answer even though it is healthy
The three SNMP components
- SNMP manager - runs the network management application and periodically polls agents by querying the device
- SNMP agent - software running on a managed device such as a server, router or switch
- Management Information Base (MIB) - defines a managed device's resources and activity as a series of objects; the NMS must have access to it for SNMP to work
The three SNMP versions
- SNMPv1 - RFC 1157; a full internet standard; legacy; minimal security
- SNMPv2c - RFCs 1901 to 1908; community-string based; adds bulk retrieval and more detailed error reporting; still minimal security
- SNMPv3 - RFCs 2273 to 2275; provides secure access by authenticating and encrypting packets; the only secure version
The FCAPS model
- F - Fault: detect, isolate, correct and log faults occurring in the network
- C - Configuration: telling the network what it is supposed to do in the first place
- A - Accounting or Administration: also billing management; gather usage data and base charges on it, mostly for service providers
- P - Performance: efficiency of the network - throughput, percentage utilization and related measures
- S - Security: ensuring the network is protected from unauthorized users
What an NMS assists with
- Network device discovery - identifying what devices are present on the network
- Network device monitoring - determining the health of network components at the device level
- Network performance analysis - tracking bandwidth utilization, packet loss, latency and availability
- Intelligent notifications - configurable alerts that page, email, call or text in response to specific network scenarios
Installation as a Docking Station (IaaDS)
- What it is: a FORSCOM directive mandating FORSCOM units to connect Mission Command Systems to home station networks
- Why: to maintain acceptable training and readiness proficiencies
- Three aims: near-real-time updating of tactical servers and applications; training and enhanced technical proficiency of Soldiers on tactical servers; the capability to collaborate and maintain situational awareness
- When employed: on-post training exercises, Mission Training Complexes, day-to-day training, pre-deployment
- Benefits: an environment similar to expeditionary conditions, a seamless training environment, operational readiness, system readiness, and continuously patched and maintained systems
Risk Management Framework in the network management context
- The unified information security framework for the entire federal government
- Replaces the legacy Certification and Accreditation process
- An integral part of implementing FISMA, and based on NIST publications
- Promotes near real-time risk management and ongoing authorization through robust continuous monitoring
- Encourages automation so senior leaders can make cost-effective, risk-based decisions
Key terms
- Monitoring tool
- A tool used to constantly track the status of a system in use, in order to have the earliest possible warning of failures, defects or problems. Monitoring tools exist for servers, networks, databases, security, performance, website and internet usage, and applications.
- Internet Control Message Protocol (ICMP)
- Part of the Internet Protocol suite. Its main purpose is to provide a way to communicate that an error occurred during the routing of IP packets, and it provides a connectivity verification function for IP. It supports both IPv4 and IPv6 as ICMPv4 and ICMPv6.
- ICMP error messages
- One of the two ICMP message classes. Used to report problem conditions and provide feedback to a source device about an error that has occurred.
- ICMP informational messages
- Also called query messages. The second ICMP class, used for diagnostics, testing, and letting devices exchange information.
- ICMP Type field
- An 8-bit field that can define a maximum of 256 message types. A separate set of Type values is maintained for ICMPv4 and ICMPv6.
- ICMP Code field
- Identifies the subtype of message within each ICMP message Type value. Up to 256 subtypes can be defined for each type.
- Ping (Packet Internet Groper)
- Uses ICMP to confirm the reachability of a remote host at layer 3. It uses ICMP Echo Request and Echo Reply messages during the exchange - the originator transmits an echo request and the receiver replies with an echo reply.
- Traceroute
- Displays the path a packet takes to reach a remote device, using IP packet time-to-live time-outs together with ICMP. It uses the same Echo Request and Echo Reply messages as ping but modifies the time-to-live value on each set.
- Pathping
- A TCP/IP based command-line utility that provides information about network latency and network loss at intermediate hops between a source and destination. It combines features of ping and traceroute plus information neither provides on its own.
- Simple Network Management Protocol (SNMP)
- Developed to allow administrators to manage devices on an IP network. It uses the UDP transport mechanism and consists of three elements: the SNMP manager, the SNMP agent, and the Management Information Base.
- SNMP manager
- Runs a network management application and periodically polls the SNMP agents on managed devices by querying the device for data.
- SNMP agent
- A piece of software that runs on a managed device such as a server, router or switch.
- Management Information Base (MIB)
- The structure that defines information about a managed device's resources and activity as a series of objects. The network management system must have access to the MIB for SNMP to operate.
- Community string
- A plaintext password used by SNMPv1 and SNMPv2c to authenticate access to MIB objects. Because it is plaintext, it is the reason those versions offer minimal security.
- Read-only community string
- Provides access to the MIB variables but does not allow them to be changed - read only. Because security is minimal in version 2c, many organizations run SNMPv2c in read-only mode.
- Read-write community string
- Provides read and write access to all objects in the MIB.
- SNMPv1
- The original Simple Network Management Protocol, a full internet standard defined in RFC 1157. A legacy solution with minimal security.
- SNMPv2c
- Defined in RFCs 1901 to 1908. Uses a community-string based administrative framework, and adds a bulk retrieval mechanism and more detailed error message reporting over SNMPv1.
- SNMPv3
- Originally defined in RFCs 2273 to 2275. Provides secure access to devices by authenticating and encrypting packets over the network - the only one of the three versions that does.
- Network management system (NMS)
- A set of hardware and/or software tools that allow an IT professional to supervise the individual components of a network within a larger network management framework.
- FCAPS
- The model that categorizes network management functions: Fault, Configuration, Accounting or Administration, Performance, and Security.
- Fault management
- The F in FCAPS. A fault is an event that shows a problem in the network. Fault management detects, isolates, corrects and logs faults that occur.
- Accounting management
- The A in FCAPS, also known as billing management and mostly relevant to network service providers. The goal is to gather usage data and base charges on it.
- Installation as a Docking Station (IaaDS)
- A FORSCOM directive - not a technology - mandating FORSCOM units to connect Mission Command Systems to home station networks in order to maintain acceptable training and readiness proficiencies. FORSCOM has directed that all units equipped with these capabilities will connect to the installation campus network.
- Risk Management Framework (RMF)
- The unified information security framework for the entire federal government, replacing the legacy Certification and Accreditation process. It is an integral part of implementing FISMA and is based on publications of the National Institute of Standards and Technology.
- FISMA
- The Federal Information Security Management Act. RMF is an integral part of its implementation.
- Continuous monitoring
- The practice that lets RMF promote near real-time risk management and ongoing information system authorization, rather than a point-in-time accreditation that expires.
Testable points
- The primary function of a network is to provide reliable and secured transmittal of data to end users, and network management is what makes that achievable.
- Monitoring tools have five listed characteristics: identify problems and alert the administrator, log real-time and historical information, find optimal settings, monitor the number of users on a network, and monitor network traffic.
- ICMP's main purpose is to communicate that an error occurred during the routing of IP packets. Connectivity verification is its second function, not its first.
- ICMP messages divide into exactly two classes: error messages that report problem conditions, and informational or query messages used for diagnostics and testing.
- The ICMP Type field is 8 bits wide, defining a maximum of 256 message types, with separate value sets maintained for ICMPv4 and ICMPv6.
- In ICMPv4, Type values were assigned sequentially to both error and informational messages. In ICMPv6 they are split by range: 0 to 127 for error messages and 128 to 255 for informational messages.
- The ICMP Code field identifies the subtype within a Type, and up to 256 subtypes can be defined per type.
- Ping uses ICMP Echo Request and Echo Reply messages. That pairing is the deck's own check-on-learning answer.
- By default an ICMP packet is between 74 and 78 bytes.
- An ICMP Time Exceeded message is generated when a router receives an IP packet with an expired time-to-live value.
- Traceroute uses the same Echo Request and Echo Reply messages as ping, but modifies them by changing the time-to-live value - that is the entire trick behind it.
- Pathping's default number of hops is 30 and the default wait before a time-out is three seconds, or 3000 milliseconds.
- An asterisk in pathping output does not necessarily mean a failure - a firewall may be blocking ICMP even though the host is reachable.
- ICMP monitoring is agentless: it requires no installation or configuration on the monitored devices. Every one of its four advantages follows from that.
- ICMP's four advantages are agentless monitoring, the ability to monitor any device regardless of operating system, vendor or type, a quick bird's-eye view of the entire network, and simplicity to implement.
- ICMP's five disadvantages are that it monitors device status only at the network layer, cannot monitor services such as HTTP, FTP and SMTP, can fail because many networks block ICMP, can choke slower WAN links by consuming excessive bandwidth, and can produce false results in redundant networks by reporting standby interfaces as down.
- ICMP traffic is often assigned a lower priority, so a router with high CPU utilization might not respond to ICMP even though it is working - a false negative worth knowing before you report a device down.
- SNMP uses UDP, not TCP. Agents listen on UDP port 161 and managers listen on UDP port 162.
- SNMP has exactly three components: the SNMP manager running the network management application, the SNMP agent running on the managed device, and the Management Information Base defining the device's resources and activity as objects.
- All three SNMP versions use managers, agents and MIBs. What differs between them is security and features, not architecture.
- SNMPv1 is defined in RFC 1157, SNMPv2c in RFCs 1901 to 1908, and SNMPv3 in RFCs 2273 to 2275.
- SNMPv2c adds a bulk retrieval mechanism and more detailed error message reporting over SNMPv1.
- SNMPv3 is the only version that provides secure access by authenticating and encrypting packets over the network. SNMPv1 and SNMPv2c can neither authenticate the source of a management message nor encrypt it.
- Community strings are plaintext passwords. That single fact explains why SNMPv1 and SNMPv2c offer minimal security.
- There are two types of community string: read-only, which allows MIB variables to be read but not changed, and read-write, which allows read and write access to all MIB objects.
- Because security is minimal in SNMPv2c, many organizations deliberately run it in read-only mode.
- Network management addresses three broad aims: security, ensuring the network is protected from unauthorized users; performance, eliminating bottlenecks; and reliability, keeping the network available and responding to hardware and software malfunctions.
- The FCAPS model has five categories: Fault, Configuration, Accounting or Administration, Performance, and Security.
- A fault is an event that shows a problem in the network. Fault management detects, isolates, corrects and logs it - four verbs, in that order.
- Accounting management is also called billing management and is mostly relevant to network service providers, whose goal is to gather usage data and base charges on it.
- An NMS assists with four things: network device discovery, network device monitoring, network performance analysis, and intelligent notifications.
- Intelligent notifications are configurable alerts that respond to specific network scenarios by paging, emailing, calling or texting.
- Network performance analysis tracks bandwidth utilization, packet loss, latency and availability.
- IaaDS is a FORSCOM directive, not a piece of equipment. It mandates FORSCOM units to connect Mission Command Systems to home station networks to maintain training and readiness proficiencies.
- IaaDS has three stated aims: near-real-time updating of tactical servers and applications, training and enhanced technical proficiency of Soldiers on those tactical servers, and the capability to collaborate and maintain situational awareness.
- IaaDS is employed during on-post training exercises, training at Mission Training Complexes, day-to-day training, and pre-deployment.
- The benefits of IaaDS named in the check on learning are an environment similar to expeditionary conditions, a seamless training environment, operational readiness, system readiness, and systems continuously patched and maintained.
- RMF is the unified information security framework for the entire federal government and replaces the legacy Certification and Accreditation process.
- RMF is an integral part of implementing FISMA and is based on NIST publications.
- RMF promotes near real-time risk management and ongoing information system authorization through robust continuous monitoring - the shift away from a point-in-time accreditation is the whole idea.
- RMF encourages automation so senior leaders get the information they need to make cost-effective, risk-based decisions.
References
Network Operations and Planning Student HandoutDoDI 8510.01FM 6-02ATP 6-02.71RFC 1157RFC 1901-1908RFC 2273-2275
DODIN Operations and NETOPS Fundamentals 113-SCCCD08
Learning objective and standard
Learning objectiveApply Network Operations (NETOPS) fundamentals
StandardManage Network Operations (NETOPS) fundamentals by completing the following: 1. Define NETOPS basics in a clear and concise manner; without error. 2. Define NETOPS management procedures in a clear and concise manner; without error. 3. Define Installation as a Docking Station (IAADS) in a clear and concise manner; without error. 4. Apply NETOPS fundamentals for a practical exercise in a clear and concise manner; without error.
Day 5's second half, and the lesson that ties the whole module back to doctrine. Everything before it was how networks work; this is what the Army calls the job of running one. The structure is three nested lists worth learning as a unit: DODIN operations has three essential tasks, each essential task has its own set of critical functions, and the whole thing is defined by six verbs in ATP 6-02.71. Learn the six verbs of the definition and the three essential tasks, and most of what this lesson can ask is covered. Note that the current version of this deck is titled DODIN OPS while its learning objective still says NETOPS - the terminology moved and the objective did not follow it.
Doctrinal currencyThe terminology moved from NETOPS to DODIN operations and this lesson is caught mid-move. The current version of the deck is titled DODIN OPS, but the learning objective and standard it carries still say NETOPS. Both terms describe the same job.
What this course teaches — answer this on the exam
- The terminal learning objective reads "Apply Network Operations (NETOPS) fundamentals" and every learning step is written as "Define NETOPS basics", "Define NETOPS management procedures"
- The lesson's own concrete experience asks students what they think of when they see the term NETOPS
- A figure in the lesson is cited as showing NETOPS components, effects and objectives, and refers to the Global Information Grid
What the current publication and the current deck use
- The current version of the deck is titled 113-SCCCD08 DODIN OPS (v5.3) - the file name still says NETOPS but the title slide does not
- ATP 6-02.71 (30 April 2019) is cited for the definition and defines DODIN operations, not NETOPS
- Global Information Grid is itself superseded terminology; the DODIN is the current construct
- If a question asks for the doctrinal definition, give the DODIN operations one - secure, configure, operate, extend, maintain and sustain DoD cyberspace
Doctrinal sets to know cold
DODIN operations defined - the six verbs
- Secure
- Configure
- Operate
- Extend
- Maintain
- Sustain
- ...Department of Defense cyberspace (ATP 6-02.71, 30 April 2019)
The three critical components of NETOPS
- Network management - how we establish and maintain the network; sub-areas planning, engineering, reconfiguration, operations
- Information assurance - how we protect the information on our network; sub-areas computer network defense, information assurance, information protection
- Information dissemination management - how we provide the information over the network; the right information at the right priority
The five services network management keeps available
- Systems - mission command systems such as CPOF, AFATDS and JCR
- Enterprise services - collaborative, software distribution, messaging, discovery, storage, user and system assistance, and security functions
- Electromagnetic spectrum - effective and efficient use of available frequencies for operations
- Network - the infrastructure meeting the desired level of quality and guaranteed services
- SATCOM - availability of all required satellite transmissions
The five critical functions of network management
- Fault management - detect, isolate and resolve problems; keep the network at an optimum level and provide fault tolerance
- Configuration management - establish and maintain consistency of performance by developing configuration parameters based on the network architecture
- Accounting management - effective and efficient allocation of internal and external resources; identify true requirements based on monitoring
- Performance management - monitor data flow, isolate problems, tune performance, analyze trends, plan resources
- Security management - the technical and administrative aspects of securing access to information transmitted over or processed by the network
The five information assurance security services
- Availability - ready when needed at an acceptable performance level
- Integrity - information is changed only by those authorized to do so
- Authentication - a person's identity is determined before access is granted
- Confidentiality - information is available only to the people intended to use or see it
- Non-repudiation - prevents a user from performing an action and later denying it
The three information states
- Transmission - how data is protected as it travels the network, over fiber, SATCOM, CAT-5 and so on
- Storage - how data is protected in share drives, servers, portals and cloud computing
- Processing - how data is protected when actively used or accessed by the user
The three countermeasure categories
- Technology - firewalls, intrusion detection systems, intrusion prevention systems
- Policy and practice - standard operating procedures, acceptable use policies
- People - user training, employee actions
The six critical functions of information assurance
- Protection - actions taken to counter vulnerabilities within the network, including COMSEC and infrastructure
- Monitoring - examination of networks and systems to identify abnormalities
- Detection - identifying the location and type of abnormality found during monitoring
- Analyzing - determining indicators and warnings, root causes, courses of action, and priorities
- Responding - direct action to mitigate the operational impact of an attack or loss of a network resource
- Management - technical and administrative involvement in securing access to information within the network
The six information dissemination services
- Messaging - systems that let users exchange information
- Discovery - lets users search data based on file descriptions
- Mediation - translates and integrates required information so it is usable
- Collaboration - lets users work together and jointly use capabilities such as chat, online meetings and work group applications
- Storage - the physical and virtual hosting of information
- User assistance - automated tasks that reduce manpower requirements
The six critical functions of information dissemination
- Collection of information - how we acquire data based on information requirements
- Processing of information - procedures that translate data into a usable form
- Storage of information - how information is stored on various mediums within the network
- Transmission of information - how information is conveyed from one place to another; this is signal flow
- Display of information - the visual presentation of information, data or knowledge collected
- Dissemination of information - automated mechanisms ensuring collected and processed information reaches the right person in a timely manner
The twelve components of tactical network operations
- Shared situational understanding
- Change management
- Configuration management
- Incident and problem management
- Release management
- Service desk management
- Infrastructure monitoring and management
- Physical and operational management
- Security management
- Cybersecurity compliance
- Capacity and availability
- Training and exercise
Key terms
- DODIN operations
- Operations to secure, configure, operate, extend, maintain, and sustain Department of Defense cyberspace. (ATP 6-02.71, 30 April 2019) Six verbs, and they are the most quotable line in the lesson.
- Network management (as a NETOPS component)
- How we establish and maintain the network. Activities pertaining to the operation, administration, maintenance and provisioning of networked systems in order to provide the desired quality of service. Its sub-areas are planning, engineering, reconfiguration and operations.
- Information assurance (as a NETOPS component)
- How we protect the information on our network. Measures that protect and defend information and information systems by ensuring their confidentiality, integrity, availability, authentication and non-repudiation. Its sub-areas are computer network defense, information assurance and information protection.
- Information dissemination management (as a NETOPS component)
- How we provide the information over the network. The technologies, techniques, processes, policies and procedures needed to give warfighters awareness of relevant, accurate information - the right information at the right priority.
- Fault management (network management function)
- Focuses on detecting, isolating and resolving problems. The end goal is keeping the network running at an optimum level and providing a measure of fault tolerance.
- Configuration management (network management function)
- A process for establishing and maintaining consistency of a product's performance by developing configuration parameters based on the network architecture.
- Accounting management (network management function)
- The effective and efficient allocation of internal and external resources. The goal is to identify true requirements based on monitoring - which is a different emphasis from the billing sense the term carries in commercial FCAPS.
- Performance management (network management function)
- Manages network performance parameters by monitoring data flow, isolating problems, performance tuning, trend analysis, and resource planning.
- Security management (network management function)
- Focuses on the technical and administrative aspects involved in securing access to information being transmitted over or processed by the network.
- Protection (IA function)
- Actions taken to counter vulnerabilities within the network, including COMSEC and infrastructure measures.
- Monitoring (IA function)
- Examination of networks and systems to identify abnormalities - an intrusion detection system is the example given.
- Detection (IA function)
- Identifying the location and type of abnormality found during monitoring, such as attacks, unauthorized access attempts, or modifications.
- Analyzing (IA function)
- Assessing the information gathered to determine indicators and warnings, establish root causes, define courses of action, and prioritize actions.
- Responding (IA function)
- Direct action taken to mitigate the operational impact of an attack or the loss of a network resource.
- Information states
- The three conditions in which information must be protected: transmission, storage, and processing. Security services must be provided across all three, not just one.
- Transmission state
- How data is protected as it travels the network - over fiber, SATCOM, CAT-5 and so on.
- Storage state
- How data is protected in various storage types - share drives, servers, portals, cloud computing.
- Processing state
- How data is protected when it is actively used or accessed by the user. The state most often forgotten of the three.
- Countermeasures (the three)
- Technology - firewalls, IDS, IPS and similar systems; policy and practice - SOPs, acceptable use policies; and people - user training and employee actions. Two of the three are not technical.
- Mediation
- An information dissemination service that translates and integrates required information so it becomes usable.
- Discovery
- An information dissemination service enabling users to search data based on file descriptions.
- Collaboration (IDM service)
- Allows users to work together and jointly use selected capabilities - chat, online meetings, work group applications.
- User assistance
- Automated tasks that reduce manpower requirements, listed as one of the six information dissemination services.
- Enterprise services
- Collaborative, software distribution, messaging, discovery, storage, user and system assistance, and security functions - one of the five service areas network management must keep available.
- Installation as a Docking Station (IaaDS)
- A FORSCOM directive requiring units to connect Mission Command Systems to home station networks to maintain training and readiness proficiency. It appears as its own learning step in this lesson as well as in Network Management.
Testable points
- ATP 6-02.71 (30 April 2019) defines DODIN operations as operations to secure, configure, operate, extend, maintain, and sustain Department of Defense cyberspace. Six verbs, in that order.
- NETOPS enables the commander through three critical components: network management, information assurance, and information dissemination management.
- The one-line summary of the three: network management is how we establish and maintain the network, information assurance is how we protect the information on it, and information dissemination is how we provide that information.
- Network management's four sub-areas are planning, engineering, reconfiguration, and operations.
- Information assurance's three sub-areas are computer network defense, information assurance, and information protection.
- Information dissemination management's stated aim is the right information at the right priority.
- Network management must keep five service areas available: systems, enterprise services, electromagnetic spectrum, network, and SATCOM.
- The systems service area means mission command systems - CPOF, AFATDS and JCR are the examples given.
- The electromagnetic spectrum service area is about effective and efficient use of available frequencies for operations, which is where this module meets Module C.
- Network management performs five critical functions: fault, configuration, accounting, performance, and security management - the FCAPS set again, now in a doctrinal frame.
- In the doctrinal framing, accounting management is about the effective and efficient allocation of internal and external resources and identifying true requirements based on monitoring. That is a different emphasis from the commercial billing sense of the same word.
- Information assurance provides five security services: availability, integrity, authentication, confidentiality, and non-repudiation.
- Availability means ready when needed at an acceptable performance level - the performance qualifier is part of the definition, not an add-on.
- Integrity means information is changed only by those authorized to do so. Authentication means a person's identity is determined before access is granted. Non-repudiation prevents a user from performing an action and later denying it.
- Security services must be provided during every information state: transmission, storage, and processing.
- There are three countermeasure categories: technology, policy and practice, and people. Only one of the three is technical.
- Information assurance performs six critical functions: protection, monitoring, detection, analyzing, responding, and management.
- Monitoring finds that something is abnormal; detection identifies where it is and what kind it is. They are two separate functions in this model and are easy to conflate.
- Information dissemination offers six services: mediation, messaging, storage, user assistance, collaboration, and discovery.
- Information dissemination performs six critical functions: collection, processing, storage, transmission, display, and dissemination of information.
- Storage appears twice in the information dissemination model - once as a service, the physical and virtual hosting of information, and once as a critical function, how information is stored within various mediums.
- Transmission of information is explicitly equated with signal flow, which is the direct link back to lesson 113-SCCCD04.
- Dissemination of information means the automated mechanisms that ensure collected and processed information reaches the right person in a timely manner - automation is part of the definition.
- Tactical network operations has twelve named components, ranging from shared situational understanding and change management through service desk management to training and exercise.
- Incident and problem management, release management and service desk management are all named as tactical network operations components - the lesson deliberately borrows service-management vocabulary.
- The lesson's own concrete experience is a single question - what do you think of when you see the term NETOPS - which is a signal that the term itself is the thing being unpacked.
References
ATP 6-02.71FM 6-02ATP 6-02.12Network Operations and Planning Student HandoutDoDI 8510.01
Network Planning TTPs: Transport, Satellite Access and Hardening ATP 6-02.12
Learning objective and standard
Learning objectiveApply network planning techniques for transport, satellite communications access, and network hardening
StandardIdentify network transport means, satellite communications planning considerations, and the requests through which access is obtained; and identify the network hardening measures a commander and staff apply to secure the DODIN-A.
The handout's final substantive section, drawn from ATP 6-02.12 DODIN-Army Planning Techniques, and the closest Module D comes to describing what a signal staff actually produces. It is not taught as its own slide deck - it is read-ahead for days 3 and 4 and it underwrites the Network Operations Practicum. Two things carry the weight. The satellite access request and the gateway access request are different requests to different approving authorities over different networks, and confusing them is the most likely error. And the hardening section is where zero trust, defense in depth and the Risk Management Framework all reappear as planning tasks rather than as concepts.
Doctrinal sets to know cold
The four key network transport means for planning
- Satellite communications
- Line of sight
- Tropospheric scatter
- Single-channel radio systems
What Army satellite communications planners must be familiar with
- The Satellite Communications Database
- Requirements submission
- Operation in degraded and denied environments
- Satellite access requests
- Gateway access requests
- Satellite communications access priorities
- Satellite communications apportionment
- Access planning
- Redundant communications procedures
- Allocation process
- After action reporting
- Planner checklist
The nine items the network engineer determines for a satellite access request
- Mission starting and ending date-time group
- Mission priority
- Type of satellite - commercial or military
- Terminals used, listed by satellite database number
- Modulation type - FDMA, TDMA, or network centric waveform
- Type of services required - voice, data, or both
- Data throughput required
- Point of contact information for each terminal, to establish positive control
- Geographic location of each terminal - latitude and longitude
Satellite access request versus gateway access request
- SAR - for satellite communications access; submitted through ACAS or the Joint Integrated SATCOM Tool; engineer identifies requirements and terminals, spectrum manager completes it
- GAR - for access to Defense Information Systems Network services; DISA is the controlling organization for approvals
- GAR submission - spectrum manager submits over SIPRNET using the Joint Integrated SATCOM Tool, after the network engineer defines service requirements
- GAR routing - through the chain of command to theater Army for validation, then to the regional satellite communications support center and DISA
- GAR result - DISA generates a gateway access authorization returned to the requesting unit and the servicing DOD gateway facility
- Commercial SATCOM request - through ACAS over NIPRNET, when military resources are inadequate
Global Agile Integrated Transport (GAIT)
- Lets commanders maintain situational awareness from garrison to deployed elements through the regional hub node
- Enables access to the tactical DODIN-A enclave
- Access is requested using the satellite access request
- Elements connect through the installation's network enterprise center
Network hardening measures
- Zero trust architecture - planners should consider implementing it; NIST SP 800-207 gives detailed guidance
- Strong authentication - reduce anonymity, enforce authenticity and accountability, protect high-value assets such as servers, routers and privileged administrator access
- Device hardening - proper configuration, vulnerability patching, and disabling active content in emails; patch before entering an area of operations
- Defense in depth - layers of defensive measures to slow or stop adversary entry, privilege escalation and free maneuver
- Reduced attack surface
Network centric waveform - the trade
- Many terminals share one frequency and bandwidth block in timeslots
- Allocates limited satellite bandwidth more efficiently than frequency division multiple access
- Costs relatively lower throughput per terminal
- Planners submit NCW satellite access requests for tactical hub nodes, tactical communications nodes and satellite transportable terminals at division, brigade and battalion, command post nodes at battalion headquarters, points of presence, and Soldier Network Extension
Key terms
- Network transport
- The processes, equipment, and transmission media that provide connectivity and move data between networking devices and facilities. (FM 6-02) It connects elements across all echelons so the DODIN-A operates as an integrated network.
- Information services
- Services allowing access, storage, and sharing of information among mission partners, and dynamically tailoring and prioritizing information to support the mission. Deployed forces reach Defense Information Systems Network services through satellite communications reachback to the regional hub node or DOD gateway.
- Regional hub node (RHN)
- The reachback point through which deployed forces access Defense Information Systems Network services, and one of the two destinations for satellite communications reachback alongside the DOD gateway.
- Satellite Communications Database
- A consolidated repository of all validated military satellite communications requirements. Planners must ensure a validated satellite database entry exists before access can be obtained.
- Frequency division multiple access (FDMA)
- One of the modulation types a satellite access request must specify. Contrasted with time division multiple access using the network centric waveform.
- Time division multiple access / network centric waveform
- Many terminals share a given frequency and bandwidth block in timeslots. It allocates limited satellite bandwidth more efficiently than frequency division multiple access, at the cost of relatively lower throughput. That trade - efficiency against throughput - is the exam-relevant point.
- Satellite access request (SAR)
- The request through which planners obtain satellite communications access. Submitted through either the Army Centralized Army Service Request System or the Joint Integrated Satellite Communications Tool. The network engineer identifies mission requirements and terminals; the spectrum manager completes the request.
- Gateway access request (GAR)
- The request for access to Defense Information Systems Network services. The Defense Information Systems Agency is the controlling organization for approvals. The network engineer defines service requirements and the spectrum manager submits it using the Joint Integrated Satellite Communications Tool over SIPRNET.
- Gateway access authorization
- What DISA generates upon approving a gateway access request, returned to both the requesting unit and the servicing DOD gateway facility.
- Army Centralized Army Service Request System (ACAS)
- A web-based platform and database consolidating Army satellite communications service request processes worldwide. It is the standard application for requesting and generating commercial satellite access requests and all Army satellite communications service requests for bandwidth authorization and connections to network service center training and regional hub nodes.
- Joint Integrated Satellite Communications Tool
- The other route for submitting a satellite access request, and the tool used to submit gateway access requests over SIPRNET.
- Global Agile Integrated Transport (GAIT)
- A system allowing commanders to maintain situational awareness from garrison to deployed elements through the regional hub node. It enables access to the tactical DODIN-A enclave. Access is requested using the satellite access request, and elements connect through the installation's network enterprise center.
- Network hardening
- Measures ensuring the confidentiality, integrity, and availability of network services. A hardened network mitigates enemy entry into the DODIN-A.
- Zero trust architecture (planning definition)
- An enterprise's cybersecurity plan that uses zero trust concepts and encompasses component relationships, workflow planning, and access policies. NIST SP 800-207 provides detailed implementation guidance.
- Strong authentication
- Reducing anonymity and enforcing authenticity and accountability for actions on the DODIN-A. It prevents unauthorized access including wide-scale compromise through impersonating privileged administrators.
- Device hardening
- Proper configuration, vulnerability patching, and disabling active content in email. Its purpose is stated as increasing the cost and complexity of adversary exploitation - not eliminating it.
- Device vulnerability
- An exploitable weakness in software or hardware that gives an adversary an opportunity to compromise the confidentiality, integrity, and availability of an information system.
- Defense in depth (planning application)
- Placing layers of defensive measures to slow down or stop an adversary from entering the network. It is described as critical to thwarting attempts to escalate privileges and maneuver freely within DOD networks.
- Commercial satellite communications
- Used when available military satellite resources are not adequate. The Army employs a disciplined process of mission analysis, solution analysis, and resource analysis to obtain them, and the request goes through ACAS over NIPRNET.
Testable points
- Network transport connects elements across all echelons so the DODIN-A can operate as an integrated network.
- Signal staffs plan redundant means of network transport for reliability and survivability in contested operational environments. Redundancy is the planning default, not a contingency.
- The four key network transport means for planning are satellite communications, line of sight, tropospheric scatter, and single-channel radio systems.
- Deployed forces access Defense Information Systems Network services through satellite communications reachback to the regional hub node or a DOD gateway.
- Satellite communications provide full access to Defense Information Systems Network services as soon as the first nodes establish the network, even in remote environments - which is why they are the expeditionary force's advantage.
- Army satellite communications planners must be familiar with twelve things, from the Satellite Communications Database and requirements submission through operation in degraded and denied environments to the planner checklist.
- Operation in degraded and denied environments is on the satellite planner's required-knowledge list, which places Module C's contested-spectrum material directly inside Module D's planning task.
- The Satellite Communications Database is a consolidated repository of all validated military satellite communications requirements.
- Network centric waveform lets many terminals share a frequency and bandwidth block in timeslots. It allocates limited bandwidth more efficiently than frequency division multiple access, at the cost of relatively lower throughput.
- A satellite access request goes through either the Army Centralized Army Service Request System or the Joint Integrated Satellite Communications Tool.
- On a satellite access request, the network engineer identifies the mission requirements and terminals, and the spectrum manager completes the request. Two different people with two different roles on the same form.
- The engineer determines nine things for a satellite access request: mission start and end date-time group, mission priority, satellite type commercial or military, terminals by satellite database number, modulation type, services required, data throughput required, point of contact for each terminal, and geographic location of each terminal by latitude and longitude.
- Some WIN-T node types support frequency division multiple access and time division multiple access simultaneously - and that requires a full separate satellite access request for each modulation type.
- A gateway access request is for access to Defense Information Systems Network services, and the Defense Information Systems Agency is the controlling organization for approvals.
- The gateway access request is submitted over SIPRNET using the Joint Integrated Satellite Communications Tool. The commercial satellite request through ACAS goes over NIPRNET. The networks are different and so is the tool.
- A gateway access request routes through the chain of command to the theater Army headquarters for validation, then to the regional satellite communications support center and DISA.
- On approval, DISA generates a gateway access authorization and returns it to both the requesting unit and the servicing DOD gateway facility.
- GAIT lets commanders maintain situational awareness from garrison to deployed elements through the regional hub node, and enables access to the tactical DODIN-A enclave.
- GAIT access is requested using the satellite access request, and elements connect through the installation's network enterprise center.
- ACAS is a web-based platform and database that consolidates Army satellite communications service request processes worldwide.
- ACAS is the standard application for commercial satellite access requests and for all Army satellite communications service requests for bandwidth authorization and connections to network service center training and regional hub nodes.
- Planners should register for ACAS in advance and adhere to the submission timelines published on the ACAS website - the timeline is a planning constraint, not an administrative detail.
- Commercial satellite communications are used when available military satellite resources are not adequate. The Army applies mission analysis, solution analysis, and resource analysis to obtain them.
- Network hardening ensures the confidentiality, integrity, and availability of network services, and a hardened network mitigates enemy entry into the DODIN-A.
- Network planners should consider implementation of a zero trust architecture - it appears in the planning technique publication, not only in the zero trust lesson.
- The connection between weak authentication and account seizure is described as well known and established. Strong authentication prevents wide-scale network compromise through impersonating privileged administrators.
- Commanders and supervisors focus authentication protection on high-value assets - servers, routers, and privileged system administrator access.
- Device hardening increases the cost and complexity of adversary exploitation. The wording is deliberate: it raises the price of an attack rather than preventing it outright.
- The three named device hardening techniques are proper configuration, vulnerability patching, and disabling active content in emails.
- Planners should ensure updated device patching before entering an area of operations. Patching is a pre-deployment task, not an in-theater one.
- Defense in depth places layers of defensive measures to slow or stop an adversary entering the network, and is critical to thwarting privilege escalation and free maneuver within DOD networks.
- A device vulnerability is an exploitable weakness in software or hardware giving an adversary the opportunity to compromise confidentiality, integrity and availability.
References
ATP 6-02.12FM 6-02ATP 6-02.54ATP 6-02.71NIST SP 800-207Network Operations and Planning Student Handout
Unified Network Operations 113-SCCCB15
Learning objective and standard
Learning objectiveApply Unified Network concepts in support of Multi-Domain Operations
StandardApply Unified Network concepts in support of Multi-Domain Operations by completing the following requirements without error: Define Unified Network Operations in relation to Multi-Domain Operations. Define the phases of the Unified Network Plan. Define Unified Network Capabilities. Identify the Lines of Effort of the Unified Network Plan. Define the Role of a Signal Officer to enable at echelons of the UNO.
The lesson that puts everything else in Module D on a timeline. Zero trust, hybrid cloud, the Mission Partner Environment and the Integrated Tactical Network are each taught elsewhere as a subject; here they appear as phased deliverables of a single Army plan running from 2021 into the 2030s. The structure is three closed lists worth learning together - three phases, five capabilities, four lines of effort - and a fourth thing that matters more than any of them: what a Signal officer is expected to do in each phase. Note that this deck carries a Module B lesson code while being filed and taught in Module D; the content is the Army Unified Network Plan either way.
Doctrinal sets to know cold
The three phases of the Unified Network Plan
- Phase I - Near term, present to 2024: Set the Unified Network
- Phase II - Mid term, 2025 to 2027: Operationalize the Unified Network
- Phase III - Far term, 2028 and beyond: Continuously Modernize the Unified Network - a phase with no end
Phase I primary efforts
- Standard security architecture, zero trust principles
- Emerging technologies: software defined networking and 5G
- Utilize wireless cellular networks
- Movement to cloud infrastructure
- Common data standards for AI and machine learning
- Ongoing development of the Mission Partner Environment
- Updates to force structure
- Eliminate redundant systems
Phase II primary efforts
- Completion of updates to force structure
- Fully developed hybrid cloud capabilities set up for AI and machine learning assistance
- Mission Partner Environment fully developed to integrate joint and multinational partners
- Continued convergence of ITN and IEN capabilities, beginning FY25
- Doctrine matures to support multi-domain operations
Phase III primary efforts
- Continuous modernization, with no end state
- Dynamic and diverse transport, robust computing, and edge sensors
- Data to decisive action
- Robotics and autonomous operations
- Corresponding cybersecurity and resiliency capabilities
The five Unified Network capabilities
- Common Operating Environment
- Common Services Infrastructure
- Common Transport Layer
- Unified Network Operations
- Cyber Defensive Capabilities
The four Unified Network Plan lines of effort
- Establish the Unified Network
- Posture the Force
- Security and Survivability
- Reform Processes and Policies
The technologies and tools the plan rests on
- Zero trust architecture - security focused on users, assets and resources rather than perimeters and devices; eliminates implicit trust at the cost of greater requirements
- Hybrid cloud and cloud computing - shifts computing from local resources to larger data centers, reducing cost and letting Soldiers test new technology in compartmentalized environments
- Mission Partner Environment - a framework for joint and multinational partners to share information and collaborate
- Integrated Tactical Network - next generation mobile network reaching the dismounted squad; replaces WIN-T while absorbing some of its components
- AI and machine learning - computer-assisted statistical analysis and decision making tools
The Signal officer's role by phase
- Phase I - be prepared for a wider variety of equipment and constant change; begin developing best practices for training on and using new equipment; learn to operate in the ESB-Enhanced structure
- Phase II - understand how systems integrate to provide data to AI and machine learning platforms; refine TTPs and SOPs for ITN equipment within formations; support maturing doctrine
- Phase III - understand the continuous modernization approach and the data-to-action flow; balance current systems against emerging ones
- Throughout - act as the key proponent developing and advancing doctrine, TTPs and SOPs, and advise commanders on how AI and machine learning bear on operational planning
Key terms
- Integrated Tactical Network (ITN)
- The next generation mobile network, available to users down to the dismounted squad level. It is the replacement for WIN-T, though some WIN-T components remain as part of it.
Testable points
- This lesson carries a Module B code (113-SCCCB15) but is filed in the course drop under Module D, alongside the Army Unified Network Plan key-note documents. It is on both module pages for that reason - the same lesson, not two.
- The Army Unified Network is defined as inclusive of all hardware, software, and infrastructure from the very forward edge of the battlefield back to the continental United States.
- The Unified Network Plan aligns to and underpins the Army's modernization priorities and supports the intent to build an MDO-capable force.
- The plan is dated October 2021, and the lesson cites specific pages of it throughout.
- The lesson's background is Russia's invasion of Ukraine in 2022 and the heavy use of cell phones in that conflict, raising the balance between the speed commanders expect and the security operations require.
- Three drivers motivate the plan: diverse equipment sets, rapidly changing technologies, and the need for streamlined policies and procedures.
- There are three phases. Phase I near term, present to 2024, set the Unified Network. Phase II mid term, 2025 to 2027, operationalize the Unified Network. Phase III far term, 2028 and beyond, continuously modernize the Unified Network.
- The three phase verbs are set, operationalize, and continuously modernize. Learning the verbs is faster than learning the date ranges and answers most questions about them.
- Phase III has no end. It is described as a program of continuous development and improvement rather than a state to be reached.
- Phase I begins with synchronizing the modernization of the Integrated Tactical Network and the Integrated Enterprise Networks.
- Phase I's eight primary efforts are a standard security architecture with zero trust principles; emerging technologies including software defined networking and 5G; wireless cellular networks; movement to cloud infrastructure; common data standards for AI and machine learning; ongoing development of the Mission Partner Environment; updates to force structure; and eliminating redundant systems.
- The ITN replaces the legacy WIN-T, but some WIN-T components remain as part of the ITN. It is a replacement that absorbs rather than discards.
- Phase I's force structure update requires Signal officers to learn to operate in the ESB-Enhanced structure, which represents more modularity than what it replaces.
- Phase II begins in FY25 with the continued convergence of ITN and IEN capabilities.
- Phase II's three primary efforts are completing the force structure updates, fully developed hybrid cloud capabilities set up for AI and machine learning assistance, and a fully developed Mission Partner Environment integrating joint and multinational partners.
- Doctrine matures during Phase II to support multi-domain operations, and officers are expected to familiarize themselves with and support those doctrinal changes.
- Phase III's emerging technologies are dynamic and diverse transport, robust computing, edge sensors, data to decisive action, robotics and autonomous operations, and corresponding cybersecurity and resiliency capabilities.
- Note the phrase corresponding cybersecurity and resiliency capabilities in Phase III - security is expected to scale with the new capability rather than trail it.
- There are five Unified Network capabilities: common operating environment, common services infrastructure, common transport layer, unified network operations, and cyber defensive capabilities.
- Four of the five capabilities begin with the word common or unified. Standardization is the organizing idea of the entire capability set.
- There are four lines of effort: establish the unified network, posture the force, security and survivability, and reform processes and policies.
- Two of the four lines of effort are not about technology at all - posturing the force is about structure and people, and reforming processes and policies is about how the Army governs itself.
- Zero trust architecture is described as eliminating implicit trust and providing significantly greater protection for Army networks at the cost of greater requirements - the cost is stated, not hidden.
- Hybrid cloud is valued in this lesson for a specific reason: it lets Signal Soldiers test and implement new technologies in more compartmentalized environments.
- The Mission Partner Environment is presented here as a framework for joint and multinational partners to share information and collaborate more easily than before - the same MPE taught in Module C's multinational lesson.
- The ITN is available to users even at the dismounted squad level, which is what makes it a genuine change rather than an upgrade at the top.
- The Signal officer's role changes by phase. In Phase I, be prepared for a wider variety of equipment and constant change, and begin developing best practices for training and use. In Phase II, understand how systems integrate to feed AI and machine learning platforms and refine TTPs and SOPs for ITN equipment. In Phase III, understand the continuous modernization approach and the data-to-action flow.
- Signal officers are named as the key proponents to develop and advance doctrine, TTPs and SOPs for the Unified Network and its sub-components - the plan makes doctrine development part of the job.
- Signal officers are expected to understand how AI and machine learning work with regard to operational planning and future systems, in order to advise commanders.
References
The Army Unified Network Plan (October 2021)FM 6-02ATP 6-02.12NIST SP 800-207DoDI 8110.01
Zero Trust Fundamentals 113-SCCCD11
Learning objective and standard
Learning objectiveDefine Zero Trust fundamentals
StandardAt the end of this lesson, the students will be able to identify the concepts, principles, and components of zero trust.
Day 10, and the lesson that answers a question the network architecture lessons left open. A firewall protects between security zones and not within them - so what happens once an attacker is inside? Zero trust is the doctrinal answer: stop treating network location as evidence of trustworthiness. The lesson is built on four nested structures, and they are worth learning as a set because they are what questions are drawn from: the DoD definition, the five tenets the deck teaches, the ten core concepts, and the seven DoD pillars with their four strategic goals. Watch the tenet count - the deck teaches five and the NIST publication it rests on lists seven, and both numbers are defensible depending on which document a question is drawn from.
Doctrinal currencySettled: answer SEVEN, the NIST SP 800-207 tenets. The deck's slide reads "5 Tenants for Zero Trust" and that five-item list is the DoD strategy's operational framing - worth knowing, and the two lists are not in conflict, because the DoD Zero Trust Strategy cites the seven NIST tenets directly in its own footnotes. The slide also misspells tenets as "tenants".
What this course teaches — answer this on the exam
- 1) All data sources and computing services are considered resources; 2) All communication is secured regardless of network location; 3) Access to individual enterprise resources is granted on a per-session basis; 4) Access to resources is determined by dynamic policy
- 5) The enterprise monitors and measures the integrity and security posture of all owned and associated assets; 6) All resource authentication and authorization are dynamic and strictly enforced before access is allowed; 7) The enterprise collects as much information as possible about the current state of assets, network infrastructure and communications, and uses it to improve its security posture
- The DoD Zero Trust Strategy cites these seven NIST tenets directly in its own footnotes, so the two lists are not in conflict - the five are the DoD's operational framing and the seven are the underlying standard
The deck's five-item DoD framing - background, not the answer
- The deck's slide reads "5 Tenants for Zero Trust" and lists: assume a hostile environment; presume breach; never trust, always verify; scrutinize explicitly; apply unified analytics
- These five are the DoD strategy's own framing and are what the course assesses
- The slide's spelling is "tenants"; the word is tenets
Doctrinal sets to know cold
The deck's five - the DoD operational framing, not the seven-tenet answer
- Assume a hostile environment
- Presume breach
- Never trust, always verify
- Scrutinize explicitly
- Apply unified analytics
The ten core concepts and principles
- Least privilege access
- Continuous authentication, authorization and auditing
- Assumption of a breach mentality
- Identity as the new perimeter
- Always verify equals never trust
- Risk-based access control
- Data security
- Continuous monitoring
- Automation and orchestration
- Micro-segmentation
The seven DoD Zero Trust Pillars
- User
- Device
- Application and Workload
- Data - central to the model; the other six exist to secure it
- Network and Environment
- Automation and Orchestration
- Visibility and Analytics
The four zero trust strategic goals
- Zero trust cultural adoption - a framework and mindset guiding design, development, integration and deployment of IT across the DoD zero trust ecosystem
- DoD information systems secured and defended - cybersecurity practices incorporating and operationalizing zero trust for enterprise resilience
- Technology acceleration
- Zero trust enablement
The nine User pillar capabilities
- 1.1 User inventory
- 1.2 Conditional user access
- 1.3 Multi-factor authentication (MFA)
- 1.4 Privileged access management (PAM)
- 1.5 Identity federation and user credentialing
- 1.6 Behavioral, contextual ID, and biometrics
- 1.7 Least privileged access
- 1.8 Continuous authentication
- 1.9 Integrated ICAM platform
The four maturity steps of identity lifecycle management
- 1.5.1 Organizational - a standardized identity lifecycle process
- 1.5.2 Enterprise part 1 - automated processes integrated with enterprise ICAM tools
- 1.5.3 Enterprise part 2 - integrated with critical identity management and identity provider functions; primary functions cloud based
- 1.5.4 Enterprise part 3 - all functions moved to cloud as appropriate, integrated with all identity management and identity provider functions
Execution enablers - the non-technical half of the strategy
- Zero trust awareness and culture
- Adaptive implementation governance
- Zero trust policy framework
- Zero trust training
- All are cross-cutting and address culture, governance and elements of DOTmLPF-P
How zero trust answers the firewall's limitation
- A firewall only provides protection between network security zones, not within a security zone (from the network architecture lesson)
- Zero trust removes implicit trust based on physical location, so being inside a zone grants nothing
- Micro-segmentation divides the network so a compromise in one zone does not permit movement into others
- Continuous authentication and per-request access decisions mean a session does not stay trusted because it was trusted once
- Least privilege access limits what a compromised account can reach even when it is legitimately authenticated
The seven tenets of zero trust (NIST SP 800-207) - the answer
- All data sources and computing services are considered resources
- All communication is secured regardless of network location
- Access to individual enterprise resources is granted on a per-session basis
- Access to resources is determined by dynamic policy
- The enterprise monitors and measures the integrity and security posture of all owned and associated assets
- All resource authentication and authorization are dynamic and strictly enforced before access is allowed
- The enterprise collects as much information as possible about the current state of assets, network infrastructure and communications, and uses it to improve its security posture
Key terms
- Zero trust (DoD definition)
- An evolving set of cybersecurity paradigms that move defenses from static, network-based perimeters to focus on users, assets, and resources. Zero trust assumes there is no implicit trust granted to assets or user accounts based solely on their physical location.
- Zero trust (NIST framing)
- A collection of concepts and ideas designed to minimize uncertainty in enforcing accurate, least privilege per-request access decisions in information systems and services in the face of a network viewed as compromised.
- Never trust, always verify
- The maxim that summarizes zero trust. It is one of the five tenets the lesson teaches and also appears among the ten core concepts as "always verify equals never trust".
- Assume a hostile environment
- The first of the five tenets. The network is treated as contested by default rather than as safe until proven otherwise.
- Presume breach
- The second tenet. Design and operate as though an adversary is already inside, which is what makes internal segmentation and continuous verification necessary.
- Scrutinize explicitly
- The fourth tenet. Access decisions rest on explicit evaluation of available signals rather than on implicit assumptions about where a request came from.
- Apply unified analytics
- The fifth tenet. Data from across the enterprise is analyzed together rather than in isolated tool-by-tool views.
- Least privilege access
- Limiting user permissions to only what is necessary for their role. One of the ten core concepts, and also capability 1.7 in the User pillar.
- Identity as the new perimeter
- One of the ten core concepts, and the clearest statement of what zero trust replaces. The boundary that matters is who is asking, not where they are.
- Micro-segmentation
- One of the ten core concepts. Dividing the network into small zones so that a compromise in one does not grant movement into others - the direct answer to a firewall protecting only between zones.
- Risk-based access control
- One of the ten core concepts. Access decisions adapt to assessed risk rather than following a fixed allow list.
- Continuous authentication, authorization and auditing
- One of the ten core concepts. Verification is ongoing rather than a single event at login.
- DoD Zero Trust Pillars
- The seven foundational areas that organize zero trust capability development, deployment and operation: User, Device, Application and Workload, Data, Network and Environment, Automation and Orchestration, and Visibility and Analytics.
- Data pillar
- The pillar at the center of the model. All capabilities within the other pillars must work together in an integrated fashion to effectively secure the Data pillar.
- Execution enablers
- Cross-cutting, non-technical capabilities and activities addressing culture, governance and elements of DOTmLPF-P. Identified enablers include zero trust awareness and culture, adaptive implementation governance, a zero trust policy framework, and zero trust training.
- DOTmLPF-P
- Doctrine, organization, training, materiel, leadership and education, personnel, facilities and policy. The DoD Zero Trust Strategy's execution process is built on this framework, which is why the strategy is not purely technical.
- Target level and advanced zero trust
- The two maturity levels each DoD zero trust capability breaks down into. Most capabilities have activities at both levels; some are achieved at target level only and a few are strictly advanced.
- User inventory
- Capability 1.1 of the User pillar - knowing who your users actually are. It is listed first because nothing else in the pillar is possible without it.
- Conditional user access
- Capability 1.2 of the User pillar, running from application-based permissions per enterprise through rule-based dynamic access to enterprise-wide roles and permissions.
- Privileged Access Management (PAM)
- Capability 1.4 of the User pillar, covering the migration of privileged users onto a managed system and progressing to real-time approvals with just-in-time and just-enough-access analytics.
- JIT/JEA
- Just-in-time and just-enough-access. Privilege is granted for the moment it is needed and no more of it than is needed, rather than held standing.
- Identity lifecycle management (ILM)
- The process of managing user credentialing so that updated permissions are applied as a user's status changes. It matures from a standardized manual process to fully cloud-based functions integrated with all identity management and identity provider functions.
- User and Entity Behavior Analytics (UEBA)
- Tooling implemented under capability 1.6, monitoring user behavior for anomalies. It matures from enterprise identity provider implementation to integration with JIT/JEA for all services.
- Integrated ICAM platform
- Capability 1.9 of the User pillar - identity, credential and access management brought onto a single platform. It is the same ICAM framework taught in Module C's cybersecurity lesson, arriving here as a zero trust capability.
Testable points
- The DoD defines zero trust as an evolving set of cybersecurity paradigms that move defenses from static, network-based perimeters to focus on users, assets and resources.
- The defining assumption is that no implicit trust is granted to assets or user accounts based solely on their physical location. Being inside the perimeter proves nothing.
- The NIST framing adds that zero trust minimizes uncertainty in enforcing accurate, least privilege, per-request access decisions in the face of a network viewed as compromised.
- Per-request is the operative phrase in the NIST framing. Access is decided each time it is asked for, not once at login.
- Zero trust has SEVEN tenets, per NIST SP 800-207 - the standard the DoD Zero Trust Strategy rests on and cites in its own footnotes. The deck's five - assume a hostile environment, presume breach, never trust always verify, scrutinize explicitly, apply unified analytics - are the DoD's operational framing of the same standard.
- The lesson teaches ten core concepts and principles, split across two slides - five on each.
- The first five core concepts are least privilege access; continuous authentication, authorization and auditing; assumption of a breach mentality; identity as the new perimeter; and always verify equals never trust.
- The second five core concepts are risk-based access control, data security, continuous monitoring, automation and orchestration, and micro-segmentation.
- There are seven DoD Zero Trust Pillars: User, Device, Application and Workload, Data, Network and Environment, Automation and Orchestration, and Visibility and Analytics.
- The Data pillar is central to the model. All capabilities within the other pillars must work together in an integrated fashion to secure it effectively.
- The pillars exist to ensure standardization of execution, and provide the foundational areas for both the DoD Zero Trust Security Model and the DoD Zero Trust Architecture.
- There are four strategic goals: zero trust cultural adoption, DoD information systems secured and defended, technology acceleration, and zero trust enablement. This is the deck's own discussion question.
- Goal 1, cultural adoption, is about a security framework and mindset guiding the design, development, integration and deployment of IT across the DoD zero trust ecosystem - it is deliberately not a technical goal.
- Goal 2, DoD information systems secured and defended, is about cybersecurity practices incorporating and operationalizing zero trust to achieve enterprise resilience.
- The four goals are described as synergistic and as addressing cultural, technological and environmental requirements together.
- Execution enablers are cross-cutting and non-technical, addressing culture, governance and DOTmLPF-P elements. Named enablers include zero trust awareness and culture, adaptive implementation governance, a zero trust policy framework, and zero trust training.
- The reference for the strategy is the DoD Zero Trust Strategy dated 21 October 2022, signed by the DoD Chief Information Officer.
- Each DoD zero trust capability aligns to one of the seven pillars and breaks down into activities achieved at either target level or advanced level.
- The User pillar has nine capabilities, numbered 1.1 through 1.9.
- The User pillar capabilities are user inventory; conditional user access; multi-factor authentication; privileged access management; identity federation and user credentialing; behavioral, contextual ID and biometrics; least privileged access; continuous authentication; and integrated ICAM platform.
- User inventory is capability 1.1 - the first thing on the list, because nothing else in the pillar works without knowing who the users are.
- Privileged access management matures from migrating privileged users onto a managed system to real-time approvals with just-in-time and just-enough-access analytics.
- Identity lifecycle management matures in four steps: a standardized process, then automated and integrated with enterprise ICAM, then primary functions moved to cloud, then all functions in cloud and integrated with all identity management and identity provider functions.
- Capability 1.7, least privileged access, is implemented by updating applications to deny by default unless a specific role or attribute grants access.
- The User pillar mitigation strategies named are least privilege access, multi-factor authentication, and behavioral analytics monitoring users for anomalies.
- ICAM appears in this lesson as capability 1.9 and in Module C's cybersecurity lesson as a framework in its own right. It is the same thing seen from two directions.
References
DoD Zero Trust Strategy (21 October 2022)NIST SP 800-207DoD Zero Trust Overlays (February 2024)DoD ZT Capabilities and ActivitiesCNSSP 21The Army Cloud Plan 2022
Cloud Fundamentals 113-SCCCD12
Learning objective and standard
Learning objectiveApply Cloud Fundamentals as a Signal Officer
StandardApply Cloud Fundamentals as a Signal Officer by completing the following: Define Cloud Principles in a clear and concise manner, without error. Identify Network Requirements for Data Operations in a clear and concise manner, without error. Interpret the requirements for data-centric networks. Apply cloud planning fundamentals for Signal Planning.
Day 11, and a lesson built almost entirely on one framework. The NIST cloud model has three parts - five essential characteristics, three service models, four deployment models - and nearly every question that can be asked here is a question about which item belongs to which of those three lists. Learn the counts first (five, three, four) and then the members, because the most common error is putting a deployment model in the service model list. The Army-specific layer sits on top: the Enterprise Cloud Management Agency, the Army Cloud Plan of 2022, and JADC2 are what turn a commercial framework into a signal planning problem.
Doctrinal sets to know cold
The five essential characteristics
- On-demand self-service - no human administrator required; users provision, monitor and manage resources themselves
- Broad network access - services provided over standard networks and heterogeneous devices
- Resource pooling - networks, servers, storage, applications and services shared across multiple applications and tenants
- Rapid elasticity - quickly scale resources up and down in response to demand, optimizing usage and cost
- Measured service - a metering system continuously monitors consumption, enabling comprehensive assessment and pay-as-you-go pricing
The three service models
- Infrastructure as a Service (IaaS) - providers rent compute and storage; users are cloud architects and IT administrators. AWS, Microsoft Azure, Google Cloud Platform, IBM Cloud, Oracle Cloud
- Platform as a Service (PaaS) - hardware and software tools provided over the internet. AWS Elastic Beanstalk, Google App Engine, Salesforce, Apache Stratos
- Software as a Service (SaaS) - applications delivered as a service over the internet on subscription. Microsoft Office 365, Slack, Google Workspace, Zoom
The four deployment models
- Public - owned and operated by a third-party provider, available to the general public, resources shared among customers, pay-per-use or subscription
- Private - dedicated to a single organization, hosted on-premises or in a third-party data center, isolated and customized
- Hybrid - a combination of public and private
- Community - shared by several organizations with common concerns
Public cloud advantages and limits
- Advantage: scalability - handles large traffic volumes and scales quickly with demand
- Advantage: high availability and redundancy - applications and data stay available through hardware failures
- Limit: shared among multiple users, so it may not suit applications or data requiring high security or regulatory compliance
- In those cases, a private or hybrid cloud is the better option
Cloud security considerations
- Data privacy and compliance
- Identity and access management
- Encryption and data protection
- Threat detection and response
Cloud governance
- Policies and regulations for cloud adoption
- Risk management
- Cost management
- Compliance with industry standards
The Army cloud governance layer
- Enterprise Cloud Management Agency (ECMA)
- Army Cloud Plan of 2022
- JADC2 - Joint All-Domain Command and Control
- Cloud authorization
Benefits and concerns of cloud computing
- Benefits: increased scalability, flexibility and cost-effectiveness
- Benefits: remote collaboration and access to resources from anywhere with an internet connection
- Concern: data security and privacy, because sensitive information may be stored on remote servers
Key terms
- Cloud computing (NIST definition)
- A model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources that can be rapidly provisioned and released with minimal management effort or service provider interaction.
- Cloud computing (working definition)
- The delivery of computing services - servers, storage, databases, networking, software, analytics and intelligence - over the internet. The core idea is that organizations rent computing power instead of purchasing and maintaining physical infrastructure.
- On-demand self-service
- The first essential characteristic. Cloud services require no human administrator - users themselves provision, monitor and manage computing resources.
- Broad network access
- The second essential characteristic. Computing services are provided over standard networks and heterogeneous devices.
- Resource pooling
- The third essential characteristic. IT resources - networks, servers, storage, applications and services - are shared across multiple applications and tenants.
- Rapid elasticity
- The fourth essential characteristic. The ability to quickly scale resources up and down in response to demand, which optimizes resource usage and improves cost efficiency.
- Measured service
- The fifth essential characteristic. A metering system continuously monitors resource consumption, allowing comprehensive assessment of resource use - and it is what makes pay-as-you-go pricing possible.
- Infrastructure as a Service (IaaS)
- Cloud providers rent compute and storage resources to customers. Common users are cloud architects and IT administrators. Examples: Amazon Web Services, Microsoft Azure, Google Cloud Platform, IBM Cloud, Oracle Cloud.
- Platform as a Service (PaaS)
- Hardware and software tools provided over the internet, so a customer builds and runs applications without managing the underlying infrastructure. Examples: AWS Elastic Beanstalk, Google App Engine, Salesforce, Apache Stratos.
- Software as a Service (SaaS)
- Applications delivered as a service over the internet, with customers charged on a subscription basis. It gives instant access to powerful applications without worrying about the underlying infrastructure, upgrades or maintenance. Examples: Microsoft Office 365, Slack, Google Workspace, Zoom.
- Public cloud
- A deployment model where cloud resources are owned and operated by a third-party provider and made available to the general public over the internet. Resources are shared among multiple customers, charged on a pay-per-use or subscription basis.
- Private cloud
- A deployment model where cloud resources are dedicated to a single organization, hosted either on-premises or in a third-party data center. Resources are isolated from other customers and customized to that organization's requirements.
- Hybrid cloud
- A deployment model combining public and private cloud implementations, so an organization can place each workload where its security, compliance and cost profile fits best.
- Community cloud
- The fourth deployment model. Infrastructure shared by several organizations with common concerns - the model most often left off the list when students recall only public, private and hybrid.
- On premise
- The contrast to cloud - hosting software and data on local servers or personal computers rather than accessing them remotely through a third-party vendor.
- Pay-as-you-go pricing
- A pricing model where users are charged based on resource utilization. It is made possible by the measured service characteristic.
- Enterprise Cloud Management Agency (ECMA)
- The Army organization named in the lesson's cloud governance basics, alongside the Army Cloud Plan of 2022 and JADC2.
- Army Cloud Plan of 2022
- One of the two assigned read-aheads for both the zero trust day and the cloud day. It is the Army's governing document for cloud adoption.
- JADC2
- Joint All-Domain Command and Control. Its implementation plan is the second assigned read-ahead for both the zero trust and cloud days, which is why the course treats cloud, zero trust and joint C2 as one problem set.
- Cloud authorization
- One of the four governance topics in the cloud basics slide, alongside ECMA, the Army Cloud Plan and JADC2 - the process by which a cloud service is approved for DoD use.
- Virtualized resources
- The underlying mechanism of cloud computing - multiple users share the same physical hardware, which is what allows flexibility, scalability and rapid provisioning.
- J.C.R. Licklider
- Dr. Joseph Carl Robnett Licklider, whose Intergalactic Computer Network memos from 1960 onward are cited in the lesson as the origin of cloud computing concepts.
Testable points
- The NIST definition of cloud computing has five parts worth noticing: ubiquitous, convenient, on-demand network access, to a shared pool of configurable computing resources, rapidly provisioned and released with minimal management effort or service provider interaction.
- The core idea of cloud computing is renting computing power instead of purchasing and maintaining physical infrastructure.
- There are five essential characteristics, three service models, and four deployment models. Learn the counts before the members - putting a deployment model into the service model list is the most common error.
- The five essential characteristics are on-demand self-service, broad network access, resource pooling, rapid elasticity, and measured service.
- On-demand self-service specifically means no human administrator is required - the user provisions, monitors and manages resources themselves.
- Broad network access means services are delivered over standard networks to heterogeneous devices - it is about device and network diversity, not about bandwidth.
- Resource pooling means IT resources are shared across multiple applications and tenants. It is the characteristic that makes public cloud economics work and also the reason public cloud may not suit high-security data.
- Rapid elasticity is the ability to scale up and down in response to demand. Down matters as much as up, because that is where the cost efficiency comes from.
- Measured service provides a metering system that continuously monitors resource consumption. It is what makes pay-as-you-go pricing possible.
- The three service models are Infrastructure as a Service, Platform as a Service, and Software as a Service.
- IaaS is renting compute and storage. Its common users are cloud architects and IT administrators - the model closest to running your own infrastructure.
- PaaS is hardware and software tools provided over the internet - a platform to build on without managing what is underneath.
- SaaS is applications delivered as a service over the internet on a subscription basis, giving instant access without worrying about infrastructure, upgrades or maintenance.
- The four deployment models are public, private, hybrid, and community. Community is the one most often forgotten.
- A public cloud is owned and operated by a third-party provider and made available to the general public, with resources shared among multiple customers.
- Public cloud advantages are scalability - it handles large volumes of traffic and scales quickly with demand - and high availability and redundancy, so applications and data stay available through hardware failures.
- A public cloud may not suit applications or data requiring high levels of security or regulatory compliance, precisely because it is shared among multiple users. In those cases a private or hybrid cloud is the better option.
- A private cloud is dedicated to a single organization and hosted either on-premises or in a third-party data center - being off-premises does not make a cloud public.
- Private clouds are typically built using virtualization technology that lets multiple virtual machines run on a single physical machine, maximizing hardware use while keeping the resources isolated.
- Cloud computing typically involves virtualized resources where multiple users share the same physical hardware - that sharing is what enables flexibility and scalability.
- The stated benefits of cloud computing are increased scalability, flexibility, and cost-effectiveness, plus remote collaboration and access from anywhere with an internet connection.
- The stated concern is data security and privacy, because sensitive information may be stored on remote servers.
- Cloud security considerations named in the lesson are data privacy and compliance, identity and access management, encryption and data protection, and threat detection and response.
- Cloud governance topics named are policies and regulations for cloud adoption, risk management, cost management, and compliance with industry standards.
- The Army-specific governance layer is the Enterprise Cloud Management Agency, the Army Cloud Plan of 2022, JADC2, and cloud authorization.
- Both the zero trust day and the cloud day assign the same two read-aheads: the Army Cloud Plan of 2022 and the JADC2 Implementation Plan. The course treats cloud, zero trust and joint command and control as one connected problem.
- The lesson traces cloud computing's origins to Dr. J.C.R. Licklider's Intergalactic Computer Network memos, from 1960 onward.
- The four major cloud service providers are quoted defining cloud computing in their own words, and all four definitions reduce to the same idea: on-demand delivery of IT resources over the internet, rented rather than bought.
References
The Army Cloud Plan 2022JADC2 Implementation PlanDOD Cloud StrategyDUSA Cloud Requirements Memo (15 January 2021)Network Operations and Planning Student HandoutNIST SP 800-145
Data Literacy 113-SCCCD10
Learning objective and standard
Learning objectiveIdentify concepts of data literacy for a Signal Officer
StandardIdentify concepts of data literacy by completing the following requirement in a clear and concise manner, without error. Define data literacy. Identify the principles of working with data. Identify the importance of being data literate. Interpret strategies for ensuring data access. Define the 5 pillars of data-driven questions. Identify the concepts of how to tell a story with data. Determine the difference between Knowledge Management and Data Management.
Day 6, and the start of the data block. The lesson's premise is stated as Army policy rather than as an aspiration: every individual is part of the Army's data workforce, so data literacy is not the data expert's job alone. Three definitions carry most of the exam weight. Data literacy has four verbs and four purposes, and both sets are worth memorizing. The distinction between data and information is a one-way relationship that is easy to state backward. And the four types of analytics form a natural progression - what is happening, why, what will happen, what should we do - which the lesson illustrates with a dentist visit and which is the clearest thing in the block.
Doctrinal sets to know cold
Data literacy - the four verbs and the four purposes
- Read data - accessing information from storage; understanding what data you have and whether it is structured or unstructured, categorical or numerical
- Work with data - asking the data a question and getting an answer
- Analyze data - breaking an entity into parts for scrutiny; turning answers into something useful for decisions
- Communicate about data - using what analysis produced to tell a data-driven story
- ...in order to describe, diagnose, predict, and prescribe
The four types of analytics
- Descriptive - what is going on now; the most basic form
- Diagnostic - why is this phenomenon occurring; sometimes called causal analysis
- Predictive - what is going to happen in the future
- Prescriptive - what should be done about it; the so-what that supports better and more informed decisions
The dentist analogy for the four analytics types
- Descriptive - the dentist confirms the gum is swollen, which you already knew
- Diagnostic - the dentist identifies a probable cavity or gum infection
- Predictive - the swelling and discomfort may persist a few days, then improve
- Prescriptive - take this medication and apply ice to reduce the swelling
The three principles of tidy data
- Each variable is a column
- Each observation is a row
- Each type of observational unit is a data table
- Consequence: all variables in the dataset share the same unit of observation
Types of data
- Numerical (quantitative, interval) - expressible as numbers and measurable. Discrete has specific fixed values; continuous falls within a range
- Categorical - two or more categories. Nominal has no intrinsic ordering; ordinal has a clear ordering
- Special: unstructured - no set structure, cannot be stored in a traditional relational database
- Special: spatial - carries attributes about a location such as a map, photographs or historical information
The five foundations of working with data
- Statistical concepts and analysis - mean, median, mode, variance, probability and related terms
- Data collection, cleaning and management - eliminating redundant and extraneous data points
- Data visualization - transforming data into a more digestible format that emphasizes patterns
- Critical thinking - not accepting information blindly; inquiring and looking for supporting evidence
- Programming language - instructions written to make a computer perform a task
The five steps of data cleaning
- Remove duplicate or irrelevant observations
- Fix structural errors
- Filter unwanted outliers
- Handle missing data
- Validate and QA
Why data literacy is mission-critical for the Army
- Improves efficiency in operations
- Provides information to empower data-driven decisions
- Enables faster decisions that help neutralize critical targets, penetrate, disintegrate and exploit adversaries in order to win
- Promotes data as a strategic asset
- Supports multi-domain operations
- Decreases fielding time
- Aids in protecting data
- Ensures transparency and accountability in assets and costs
- Supports digitization, modernization and innovation
Three questions for whether you can trust your data
- Is your data accurate?
- Does your data measure what it says it is measuring?
- Is your data complete?
Key terms
- Data literacy
- The ability to read, work with, analyze, and communicate with data in order to describe, diagnose, predict, and prescribe. Four verbs and four purposes - the four purposes map exactly onto the four types of analytics.
- DoD data literacy
- The ability to read, work with, analyze, and communicate data, per the Decision-Driven Data Concept of Operations. The DoD version keeps the four verbs and drops the four purposes.
- Data
- Raw facts and figures that have not been processed or analyzed. Data on its own is meaningless.
- Information
- Data that has been processed, analyzed, and organized in a meaningful way to provide context and relevance. Information provides valuable insights and helps in decision-making.
- Read data
- Accessing information from a storage device or memory. At the concept level it is the basic understanding of what data you have in front of you - structured or unstructured, categorical or numerical.
- Work with data
- The ability to ask the data a question and, because you know what data you have, to get an answer.
- Understand data
- What reading and working with data combine to produce - the capacity to comprehend and interpret what the data holds.
- Analyze data
- Breaking down a complete entity into its distinct parts for individual scrutiny, and turning the answers obtained from working with the data into something useful for making decisions.
- Communicate about data
- Taking the information obtained from analysis and using it to tell a data-driven story.
- Descriptive analytics
- The most basic form of analytics - what is going on now.
- Diagnostic analytics
- Why is this phenomenon occurring. Sometimes thought of as causal analysis.
- Predictive analytics
- What is going to happen in the future, and can we predict it.
- Prescriptive analytics
- The so-what layer - what should be done about it. It helps organizations make better and more informed decisions.
- Tidy data
- A way of organizing tabular data so it is easy to manipulate, visualize and model, based on three principles: each variable is a column, each observation is a row, and each type of observational unit is a data table. In tidy data all variables share the same unit of observation.
- Numerical data
- Also called quantitative or interval data - data expressible as numbers and measurable. Examples include counts, costs, revenue, sales, percentages, scores, profits, height, weight and age.
- Discrete data
- Numerical data with specific or fixed values.
- Continuous data
- Numerical data that falls within a given range rather than taking fixed values.
- Categorical data
- A variable with two or more categories where there is no intrinsic ordering to the categories. Sometimes called a nominal variable.
- Nominal data
- Categorical data with no ordering - the unordered case.
- Ordinal data
- Similar to a categorical variable, but with a clear ordering of the categories.
- Unstructured data
- Information with no set structure or organization, which therefore cannot be stored in a traditional relational database.
- Spatial data
- Data that can carry any number of attributes about a location - a map, photographs, historical information and so on.
- Data cleaning
- Part of data cleansing. The detection and rectification of errors and inconsistencies in datasets.
- Data cleansing
- The broader process. Besides cleaning, it includes standardization, validation, de-duplication and more. The process of identifying and correcting or removing inaccurate, incomplete or irrelevant data from a dataset.
- Extract, Transform, Load (ETL)
- A process that combines data from multiple sources into a single repository such as a data warehouse, data lake, or data store. Data cleansing within ETL guarantees that only superior-quality data is processed and loaded.
- Data access
- The on-demand, authorized ability to retrieve, modify, copy or move data from IT systems.
- Data life cycle management
- Managing data through its life, described in the lesson as just as vital as ammunition management to meeting the Army's operational needs.
- Army Chief Data and Analytics Officer (CDAO)
- The role held by Dr. David Markowitz in the lesson's citations, and the source of the statement that every individual is part of the Army's data workforce.
- Army Chief Information Officer (CIO)
- The principal advisor to the Secretary of the Army responsible for exercising overall supervision of Army data management. Army CIO Leonel Garciga issued the April 2 memorandum on Army Data Stewardship Roles and Responsibilities.
Testable points
- Data literacy is the ability to read, work with, analyze, and communicate with data to describe, diagnose, predict, and prescribe. Both the four verbs and the four purposes are quotable.
- The four purposes - describe, diagnose, predict, prescribe - map exactly onto the four types of analytics. That correspondence is the most useful structural fact in the lesson.
- Data literacy is explicitly not solely the role or responsibility of the data expert. If experts build tools that decision makers cannot use, the tools do not help.
- Dr. David Markowitz, Army CDAO, is quoted: every individual is part of the Army's data workforce.
- The Army is increasing data literacy across Soldiers and civilians, with some becoming specialists such as data scientists or data engineers and the rest becoming literate consumers.
- The Army's approach is framed as a culture change requiring investment across DOTMLPF-P components, not as a training task alone.
- All information is data, but not all data is information. The relationship runs one way, and stating it backward is the most likely error.
- Data is raw facts and figures not yet processed or analyzed. Information is data processed, analyzed and organized meaningfully to provide context and relevance.
- Data on its own is meaningless; information provides valuable insights and helps in decision-making.
- Cleaning and manipulating data is how raw data is translated into usable information.
- Many analytics professionals estimate that cleaning and manipulation consume 80 percent of the time spent on most analytics work.
- Tidy data has three principles: each variable is a column, each observation is a row, and each type of observational unit is a data table.
- In tidy data all variables in the dataset share the same unit of observation, which is what makes it easy to manipulate.
- Descriptive analytics says what is going on now. Diagnostic asks why. Predictive asks what will happen. Prescriptive asks what should be done - it is the so-what.
- The dentist analogy: descriptive is the dentist confirming the gum is swollen; diagnostic is identifying a cavity or infection; predictive is saying the swelling will persist a few days then improve; prescriptive is recommending medication and ice.
- Numerical data divides into discrete, which has specific or fixed values, and continuous, which falls within a given range.
- Categorical data divides into nominal, which is unordered, and ordinal, which has a clear ordering of categories.
- The two special data types are unstructured data, which has no set structure and cannot go in a traditional relational database, and spatial data, which carries attributes about a location.
- The foundation of data literacy includes five things: statistical concepts and analysis; data collection, cleaning and management; data visualization; critical thinking; and programming language.
- Critical thinking is defined in this lesson as not accepting information blindly - inquiring and looking for supporting evidence.
- Statistical understanding is required for three stated reasons: to work with data effectively, to derive insights and use them for decisions, and to communicate findings.
- Data cleaning has five steps: remove duplicate or irrelevant observations, fix structural errors, filter unwanted outliers, handle missing data, and validate and QA.
- Data cleaning is a part of data cleansing. Cleansing is broader, adding standardization, validation, de-duplication and more.
- The lesson's summary of why this matters: complexity, incomplete data and inaccurate data impede decision dominance.
- Data cleansing produces faster response rates, generates quality insights, and improves user experience - and enables better integration of data from multiple sources.
- The Army CIO is the principal advisor to the Secretary of the Army responsible for overall supervision of data management.
- Data stewards, data custodians and functional data managers are all responsible and obligated to make their data visible to authorized users.
- Army CIO Leonel Garciga laid out data stewardship policy in an April 2 memorandum on Army Data Stewardship Roles and Responsibilities - the same document assigned as read-ahead for days 6 and 7.
- Data life cycle management is described as just as vital as ammunition management to meeting the Army's operational needs.
- Data access is defined narrowly as the on-demand, authorized ability to retrieve, modify, copy or move data from IT systems. Both on-demand and authorized are part of the definition.
- Data literacy is called mission-critical for the Army for eight reasons, running from improving operational efficiency through supporting multi-domain operations to supporting digitization, modernization and innovation.
- One of those eight reasons is stated in operational terms: enabling faster decisions that help neutralize critical targets, penetrate, disintegrate and exploit adversaries in order to win.
- The four elaborated benefits are enhanced decision making, operational efficiency, intelligence analysis, and critical thinking and problem solving.
- Three questions the lesson poses for testing whether data can be trusted: is it accurate, does it measure what it says it measures, and is it complete.
References
Decision-Driven Data CONOPSArmy Data Plan (2022)Army Digital Transformation Strategy (October 2021)Army Data Stewardship Roles and ResponsibilitiesDOD Data StrategyThe Army Unified Network Plan
Data Governance 113-SCCCD10
Learning objective and standard
Learning objectiveIdentify the concepts, principles, and components of data governance
StandardIdentify the concepts, principles, and components of data governance. Define processes, policies, roles, metrics, and standards of data governance. Ensure minimization of risk to data while maximizing the use of data. Communicate the organizational benefits of data governance. Employ principles, standards, and practices that render data consistent and reliable.
Days 6 and 7, and the most policy-dense lesson in Module D. Where data literacy was about individual skill, governance is about the rules an organization sets so that data can be trusted at all. Two things dominate. VAULTIS is the DoD Data Strategy's seven goals for data and it is an acronym, which makes it close to certain exam material - learn the seven words and what each means. And the seven governing documents form a stack from the DoD Data Strategy of September 2020 up to the Army Stewardship Roles and Responsibilities Memorandum of April 2024, which is one of the two assigned read-aheads for this block.
Doctrinal sets to know cold
VAULTIS - the seven DoD data goals
- Visible - the ability to locate the needed data
- Accessible - the ability to retrieve the data
- Understandable - the ability to recognize context, content and applicability
- Linked - the ability to exploit data elements through their innate relationships
- Trusted - the ability to be confident in all aspects of the data for decision making
- Interoperable - the ability to have a common representation and comprehension of data
- Secure - the ability to know the data is protected from unauthorized use and manipulation
The five principles of data governance
- Data ownership - possession and accountability for information; owners may access and grant access
- Data quality - how effectively a dataset meets standards for precision, completeness, legitimacy, coherence and distinctiveness
- Data security - upholding confidentiality, reliability and accessibility in alignment with the risk management plan
- Data privacy - an individual's control over the sharing of personal information
- Compliance - managing personal and sensitive data while adhering to regulatory requirements
The seven documents governing Army data, oldest first
- DoD Data Strategy - September 2020
- Army Digital Transformation Strategy - October 2021
- Army Unified Network Plan - October 2021
- Army Data Plan - February 2022
- Decision-Driven Data CONOPS - July 2023
- DoD Data, Analytics, and Artificial Intelligence Adoption Strategy - June 2023
- Army Data Stewardship Roles and Responsibilities Memorandum - April 2024
The eight things the Army must do to data for it to be effective and useful
- Design
- Generate
- Quality check
- Inventory
- Distribute
- Store
- Use
- Dispose of
The three roles obligated to make data visible to authorized users
- Data stewards
- Data custodians
- Functional data managers
What data governance delivers
- Consistent, confident decisions based on trustworthy data aligned with the purposes the data assets are used for
- Regulatory compliance, by documenting the lineage of data assets and the access controls on them
- Minimized risk to data while maximizing the use of data
- Data that is consistent and reliable through applied principles, standards and practices
Two roles easily confused in the data block
- DoD Chief Digital and AI Officer (CDAO) - Craig Martell in the lesson's citation
- Army Chief Data and Analytics Officer (CDAO) - Dr. David Markowitz
- Army Chief Information Officer (CIO) - Leonel Garciga, who issued the April 2024 stewardship memorandum
Key terms
- Data governance
- How an organization manages the availability, usability, integrity, and security of data. In the Army specifically, it includes the processes, policies, standards, and responsibilities that ensure data is managed properly.
- Data governance as a life cycle method
- A systematic method for overseeing data throughout its entire life cycle, from the point of acquisition onward - not a one-time approval.
- VAULTIS
- The DoD Data Strategy's seven goals for data: Visible, Accessible, Understandable, Linked, Trusted, Interoperable, Secure. It is described as a tool for organizing and monitoring data management plans, and must be achieved to become a data-centric DoD.
- Visible
- The V in VAULTIS - the ability to locate the needed data. Consumers can find it.
- Accessible
- The A in VAULTIS - the ability to retrieve the data once it has been located.
- Understandable
- The U in VAULTIS - the ability to recognize the context, content, and applicability of the data.
- Linked
- The L in VAULTIS - the ability to exploit data elements through their innate relationships.
- Trusted
- The T in VAULTIS - the ability to be confident in all aspects of the data for decision making.
- Interoperable
- The I in VAULTIS - the ability to have a common representation and comprehension of data.
- Secure
- The S in VAULTIS - the ability to know that the data is protected from unauthorized use and manipulation.
- Data-centricity
- The path to treating data as a strategic asset in the DoD Data Strategy. Another way of thinking about it is that the data itself is the interface between different systems, locations and branches.
- Digital exhaust
- The thing the Army is trying to stop treating data as. Success is defined as Army leaders at echelon treating data not as digital exhaust but as a strategic asset.
- Data ownership
- Possession and accountability for information. Those who own the data possess the authority to access it and to grant access to others.
- Data quality
- The evaluation of how effectively a dataset fulfills standards for precision, completeness, legitimacy, coherence and distinctiveness.
- Data security (governance principle)
- The systematic approach of upholding the confidentiality, reliability and accessibility of an organization's data in alignment with its risk management plan.
- Data privacy
- An individual's capacity to control the sharing of personal information, including name, location and contact details.
- Data compliance
- Effectively managing and handling personal and sensitive data while ensuring adherence to regulatory requirements.
- Data steward
- One of three roles obligated to make their data visible to authorized users, alongside data custodians and functional data managers. The April 2024 memorandum formalizes the role.
- Enterprise Data Analytics Strategy (EDAS)
- The strategy whose objective is to establish formalized governance for the Army and develop overarching policy for enterprise-wide decision analytics capabilities. It is framed in DOTMLPF-P terms.
- Army Data Plan (February 2022)
- One of the seven governing documents. It frames the Army's data foundation as having both materiel and non-materiel components.
- Decision-Driven Data CONOPS (July 2023)
- One of the seven governing documents and the source of the DoD data literacy definition used in the previous lesson.
- Army Data Stewardship Roles and Responsibilities Memorandum (April 2024)
- The most recent of the seven governing documents, issued by Army CIO Leonel Garciga. Its central principle is establishing a better feedback loop between those who produce data and those who consume it. Much of it formalizes and institutionalizes work people were already doing informally.
- ADP 3-13 Information
- The Army's foundational doctrine for information. It codifies the Army's approach to the military uses of data and information and recognizes that all activities generate information.
- Chief Digital and AI Officer (CDAO)
- The DoD role held by Craig Martell in the lesson's citations. Distinct from the Army CDAO, Chief Data and Analytics Officer, held by Dr. David Markowitz.
Testable points
- Data governance is how an organization manages the availability, usability, integrity, and security of data. Those four nouns are the definition's core.
- For the Army, governance adds processes, policies, standards, and responsibilities that ensure data is managed properly.
- Data governance is a systematic method for overseeing data across its entire life cycle, starting from the point of acquisition - it is continuous rather than a gate.
- VAULTIS stands for Visible, Accessible, Understandable, Linked, Trusted, Interoperable, Secure - seven goals, in that order.
- VAULTIS is described as a tool for organizing and monitoring data management plans, and as something that must be achieved to become a data-centric DoD.
- Visible means consumers can locate the needed data; accessible means they can retrieve it. Locating and retrieving are two separate goals, and that separation is the point.
- Understandable is the ability to recognize context, content and applicability - not merely to read the file.
- Linked is the ability to exploit data elements through their innate relationships, which is what makes datasets more valuable together than separately.
- Trusted is the ability to be confident in all aspects of the data for decision making. Interoperable is a common representation and comprehension of data. Secure is protection from unauthorized use and manipulation.
- In the DoD Data Strategy, the path to treating data as a strategic asset is data-centricity.
- Data-centricity means the data itself is the interface between different systems, locations and branches - rather than each system defining its own.
- The Army will achieve success when leaders at echelon treat data not as digital exhaust but as a strategic asset. Digital exhaust is the phrase for what data is currently treated as.
- The Army's data foundation has both materiel and non-materiel components - it is not purely a technology program.
- The five general principles of data governance are data ownership, data quality, data security, data privacy, and compliance.
- Data ownership carries both possession and accountability, and owners hold the authority to access data and to grant access to others.
- Data quality is measured against precision, completeness, legitimacy, coherence and distinctiveness.
- Data security in the governance sense is explicitly aligned to the organization's risk management plan, which links this lesson to the Risk Management Framework.
- The core principles named in the notes add accountability, standardized rules and regulations, data stewardship, and data quality standards.
- Seven documents inform the key tenets of Army data governance, and they form a chronological stack from September 2020 to April 2024.
- The seven are: the DoD Data Strategy (September 2020), the Army Digital Transformation Strategy (October 2021), the Army Unified Network Plan (October 2021), the Army Data Plan (February 2022), the Decision-Driven Data CONOPS (July 2023), the DoD Data, Analytics and Artificial Intelligence Adoption Strategy (June 2023), and the Army Data Stewardship Roles and Responsibilities Memorandum (April 2024).
- The stewardship memorandum's central principle is establishing a better feedback loop between those who produce data and those who consume it.
- Much of the stewardship memorandum simply formalizes and institutionalizes jobs Army officers and officials had already been doing informally - which is why the roles may feel familiar.
- Three roles are obligated to make their data visible to authorized users: data stewards, data custodians, and functional data managers.
- To make data effective and useful, the Army must design, generate, quality check, inventory, distribute, store, use, and dispose of it - eight verbs covering the whole life cycle including disposal.
- The objective of the Enterprise Data Analytics Strategy is to establish formalized governance for the Army and develop overarching policy for enterprise-wide decision analytics capabilities.
- EDAS is expressed in DOTMLPF-P terms - doctrine, organization, training, materiel, leadership and education, personnel, facilities and policy - so it is not framed as a technology purchase.
- ADP 3-13 Information is the Army's foundational doctrine for information, codifying the military uses of data and information and recognizing that all activities generate information.
- Two different CDAO roles appear in the data block and they are not the same: the DoD Chief Digital and AI Officer, and the Army Chief Data and Analytics Officer.
- The stated benefits of governance are making consistent, confident decisions based on trustworthy data, and meeting regulatory requirements by documenting data lineage and access controls.
References
DoD Data Strategy (September 2020)Army Data Plan (February 2022)Army Digital Transformation Strategy (October 2021)Decision-Driven Data CONOPS (July 2023)Army Data Stewardship Roles and Responsibilities (April 2024)The Army Unified Network Plan (October 2021)ADP 3-13
Database Fundamentals 113-SCCCD10
Learning objective and standard
Learning objectiveDefine database fundamentals, components, and design considerations
StandardDefine the types of data. Define the main functions of a database management system. Identify the main components of a database system. Communicate the importance of database design. Identify the types of databases.
Day 7's second half, and the most conventionally technical lesson in the data block - it draws on CompTIA Data+ material rather than on Army doctrine. Three closed lists carry it. The data type taxonomy divides twice: quantitative into discrete and continuous, qualitative into nominal and ordinal, and both splits are exam-ready. The database system has nine components and it is worth learning which are storage-facing and which are user-facing. And the structured, semi-structured, unstructured trichotomy is the one that most often appears with examples rather than definitions, so learn an example of each.
Doctrinal sets to know cold
The components of a database system
- DBMS - the software that manages the database
- Database - the organized collection of data
- Database schema - defines the structure: tables, fields and so on
- Query processor - interprets and executes queries
- Storage engine - handles reading and writing to disk
- Transaction management - ensures transactions are processed reliably and consistently
- Concurrency control - handles simultaneous operations while preserving data integrity
- Backup and recovery system - ensures restoration to reduce data loss
- Security management - security compliance and controlled user access
- Database utilities and tools - import and export, performance monitoring and tuning, database design
The data type taxonomy
- Quantitative - expressed through numbers; assignable a value like price or measurable like weight
- Discrete - counted, only specific values. Price, inventory
- Continuous - measured, any value. Height, weight, temperature
- Qualitative (categorical) - categorized by characteristics
- Nominal - no natural order. Colors
- Ordinal - follows a natural order. Grade level
Miscellaneous data types
- Primary data - gathered directly by the researcher for their own project or objective
- Secondary data - collected and published by others for a different purpose, then reused
- Time-series data - collected over a period and organized chronologically
- Spatial data - associated with specific geographic locations or coordinates
- String - sequences of characters, for text and alphanumeric fields
- Date/time - dates, times or both; crucial to data manipulation and analysis
The three database structure types, with examples
- Structured - columns, rows and data fields; relational tables, CSV, relational databases
- Semi-structured - clickstream from web services, financial transactions; NoSQL and transactional systems; JSON, XML, Avro, Parquet
- Unstructured - correspondence, voice, video and pictures, sticky notes
ETL versus ELT
- Data pipeline - a series of processing steps that extract, transform and load data into a destination system
- ETL - extract from sources, transform into a suitable format, then load into the destination
- ELT - extract from sources, immediately load into the destination, then transform there
- The only difference is where the transformation happens - before the load or after it
The ten flaws of ordinary file system data management
- Fragmentation - files stored in non-contiguous blocks over time, slowing reads and writes
- Limited scalability
- Increased data redundancy
- Metadata corruption
- Inefficient data retrieval
- Lack of file permissions and access controls
- Security vulnerabilities
- Poor error handling
- Inconsistent file naming conventions
- Lack of version control
The five database design considerations
- Data integrity and accuracy - reduce data redundancy and ensure data consistency by avoiding anomalies
- Performance optimization - design for optimal query performance
- Scalability - ensure an evolving database can scale for future growth
- Maintainability - a well-structured database is easier to maintain, troubleshoot and update
- Security - govern the database efficiently through access control and encryption where applicable
Key terms
- Database
- An organized collection of data stored electronically or physically in a structured format that allows for efficient retrieval.
- Database management system (DBMS)
- The software that manages the database. It is distinct from the database itself, which is the organized collection of data.
- Database schema
- Defines the structure of the database - tables, fields and so on. The schema is the design; the database is what fills it.
- Query processor
- Interprets and executes querying on a database.
- Storage engine
- Handles reading and writing to the disk - the component closest to the hardware.
- Transaction management
- Ensures database transactions are processed reliably and consistently.
- Concurrency control
- Handles simultaneous tasking and operations on the database, ensuring data integrity when more than one thing happens at once.
- Backup and recovery system
- Ensures data restoration in order to reduce data loss.
- Security management (database component)
- Ensuring security compliance and controlled user access.
- Database utilities and tools
- Tools such as import and export, performance monitoring and tuning, and database design.
- Quantitative data
- Information expressed through numbers - it can be assigned a numerical value such as price, or measured such as weight.
- Discrete data
- Quantitative data that can be counted and can only take on specific values. Examples: price, inventory.
- Continuous data
- Quantitative data that can be measured and can take on any value. Examples: height, weight, temperature.
- Qualitative data
- Information categorized based on its characteristics. Also known as categorical data.
- Nominal data
- Qualitative information without a natural order. The lesson's example is colors.
- Ordinal data
- Qualitative information that follows a natural order. The lesson's example is grade level.
- Primary data
- Information gathered directly by the researcher specifically for their own research project or objective.
- Secondary data
- Information collected and published by others for a different purpose, which can then be used for research or analysis.
- Time-series data
- Information collected over a period and organized in chronological sequence.
- Spatial data
- Information associated with specific geographic locations or coordinates.
- String
- A specialized data type representing sequences of characters, used for text and alphanumeric fields.
- Date/time
- A specialized data type representing dates, times, or both. It is a crucial component in data manipulation and analysis, because it is what makes time-series work possible.
- Structured data
- Data organized in columns, rows and data fields - relational tables, CSV files, relational databases.
- Semi-structured data
- Data with some organizing structure but not a fixed relational schema. Examples include clickstream data from web services and financial transactions, stored in NoSQL or transactional systems using formats such as JSON, XML, Avro and Parquet.
- Unstructured data
- Data with no organizing structure - correspondence, voice, video and pictures, and sticky notes.
- Data pipeline
- A series of data processing steps that extract data from sources, transform it, and load it into a destination system.
- ETL (Extract, Transform, Load)
- Extracting data from various sources, transforming it into a suitable format, then loading it into the destination. Transformation happens before loading.
- ELT (Extract, Load, Transform)
- Extracting data from various sources, then immediately loading it into the destination, and transforming it there. The difference from ETL is purely where the transformation happens.
- Fragmentation
- A file system flaw where files become stored in non-contiguous blocks over time, leading to slower read and write performance.
- Data redundancy
- The same data stored in more than one place. Increased redundancy is a listed flaw of ordinary file system data management, and reducing it is a database design objective.
Testable points
- A database is an organized collection of data stored electronically or physically in a structured format allowing efficient retrieval.
- The DBMS is the software that manages the database. The database is the data. Keeping those two apart is the most basic distinction in the lesson.
- The nine components of a database system are the DBMS, the database, the database schema, the query processor, the storage engine, transaction management, concurrency control, the backup and recovery system, and security management - plus database utilities and tools.
- The database schema defines the structure - tables, fields and so on. It is the design rather than the content.
- The query processor interprets and executes queries; the storage engine handles reading and writing to disk. One faces the user, the other faces the hardware.
- Concurrency control exists specifically to maintain data integrity when simultaneous operations happen on the database.
- Quantitative data is expressed through numbers - assignable a numerical value like price, or measurable like weight.
- Quantitative data splits into discrete, which can be counted and takes only specific values, and continuous, which is measured and can take any value.
- Discrete examples are price and inventory. Continuous examples are height, weight and temperature.
- Qualitative data is categorized based on characteristics and is also known as categorical data.
- Qualitative data splits into nominal, without natural order, and ordinal, which follows a natural order. Colors are nominal; grade level is ordinal.
- Primary data is gathered by the researcher for their own project. Secondary data was collected and published by others for a different purpose.
- Time-series data is collected over a period and organized chronologically. Spatial data is associated with geographic locations or coordinates.
- The two specialized data types named are string, for sequences of characters in text and alphanumeric fields, and date/time.
- The date/time type is called crucial for both data manipulation and data analysis, because it is what makes chronological ordering and time-series analysis possible.
- Databases divide by data structure into three kinds: structured, semi-structured, and unstructured.
- Structured data means columns, rows and data fields - relational tables, CSV, relational databases.
- Semi-structured examples are clickstream data from web services and financial transactions, held in NoSQL or transactional systems, in formats such as JSON, XML, Avro and Parquet.
- Unstructured examples are correspondence, voice, video and pictures, and sticky notes.
- A data pipeline is a series of processing steps that extract, transform, and load data into a destination system.
- ETL transforms before loading; ELT loads first and transforms in the destination. The only difference is where the transformation happens, and that is the whole exam point.
- Ordinary file systems have ten listed flaws, beginning with fragmentation and running through limited scalability, increased data redundancy, metadata corruption and inefficient data retrieval.
- The file system flaw list includes governance failures as well as technical ones: lack of file permissions and access controls, security vulnerabilities, poor error handling, inconsistent file naming conventions, and lack of version control.
- The file system flaw list is the argument for using a database at all - each flaw corresponds to something a DBMS provides.
- There are five database design considerations: data integrity and accuracy, performance optimization, scalability, maintainability, and security.
- Data integrity and accuracy means reducing data redundancy and ensuring data consistency by avoiding anomalies.
- Maintainability is justified simply: a well-structured database is easier to maintain, troubleshoot and update.
- Scalability in database design is conditional - ensure the database can scale for future growth if it is an evolving one.
- The lesson's sources are Professor Mike Chapple of Notre Dame University and CompTIA Data+ exam DA0-001 test preparation material - it is commercial curriculum rather than Army doctrine, which is why its vocabulary differs slightly from the data literacy lesson's.
References
CompTIA Data+ DA0-001Army Data Plan (February 2022)Decision-Driven Data CONOPSArmy Data Management and Analytics Lexicon
The Power of Data and Telling a Story with Data 113-SCCCD10
Learning objective and standard
Learning objectiveApply data literacy to decision-making, and implement storytelling with data
StandardReview data and analytics terms. Define the act of telling a story in the world of data. Identify different approaches to storytelling. Apply the four levels of data analytics to decision-making. Identify data ethics considerations for the Army.
Day 8, and the close of the data block. Two lessons taught back to back and treated here as one, because they answer two halves of the same question: what data is for, and how you get a decision out of it. The first half is a six-part framework of data literacy applied to command - introducing, managing, innovating, leading, interacting and standardizing. The second half is about communication, and it carries the block's most quotable fact: the goal of a data story is to make complex data comprehensible and actionable, which means a chart nobody acts on has failed regardless of how accurate it is. The five Army data ethics considerations are the highest-value list in the lesson.
Doctrinal sets to know cold
The six parts of applying data literacy to command
- Introducing data - integrating new data into the existing ecosystem to maximize usefulness; classifying data, creating value, boosting usability
- Managing change and mitigating risk - smooth transitions without internal or external harm; governing access, measuring success, working ethically
- Innovating with data - new products, services and processes plus enhancing existing ones; designing services, achieving sustainability
- Leading change - guiding a command through evolution that enhances efficiency and sustainability; developing strategy, developing policy, prioritizing action
- Interacting with data - engaging with data to facilitate understanding, analysis and decisions; visualizing data, trend analysis, making data intelligent
- Standardizing data - consistency, accuracy and uniformity across sources and formats; using platforms, linking data, cleaning data
The five Army data ethics considerations
- Responsible
- Equitable - avoiding bias
- Traceable
- Reliable
- Governable
What telling a story with data means
- Presenting data in a way that is engaging, informative and easy to understand
- Built from a combination of visuals and narrative - neither alone
- The goal is to communicate insights effectively
- The test is whether complex data becomes comprehensible and actionable for the audience
Pie chart pros and cons
- Pro - simplicity: for example, the proportion of the different branches in the military
- Pro - parts to a whole: illustrating the share of mission types
- Pro - immediate impact: showing at a glance how budget is allocated among projects
- Con - limited number of slices: tanks, helicopters, jets, ships and drones on one chart becomes unreadable
- Con - misleading perception of slices, and difficulty comparing similar proportions such as two similar programs' resource allocation
- Con - lack of detail
Data and analytics terms reviewed in this lesson
- Data - raw facts and figures without inherent context or meaning; the foundation for analysis and decision making
- Information - data processed and organized meaningfully; provides context to data
- Data governance - the overall management of data availability, usability, integrity and security within an organization
- Data quality - the condition of data based on accuracy, completeness, reliability and relevance
- Data mining - discovering patterns and relationships in large datasets using statistical and computational techniques
- Data visualization - the graphical representation or communication of data to help people understand and gain insightful meaning
Why data literacy is a command competency
- Warfare at higher echelons requires decision making from a system of systems perspective
- There is a principal need for data literacy at the battalion level
- Commanders at all levels must emphasize data literacy throughout
- Source: Decision-Driven Data CONOPS, section 3.3.8, Leader Development
Key terms
- Introducing data
- The process of integrating new data into an organization's existing data ecosystem or warehouse in a way that maximizes its usefulness. Its activities are classifying data, creating value, and boosting usability - all forms of data profiling.
- Data profiling
- The activity underlying introducing data - examining new data to classify it, establish its value, and improve its usability before it enters the ecosystem.
- Managing change and mitigating risk
- Ensuring smooth transitions and evolving command practices without causing internal or external harm. Its activities are governing access, measuring success, and working ethically.
- Innovating with data
- Leveraging data to develop new products, services and processes, as well as enhancing existing ones. Its activities are designing services and achieving sustainability, through data enrichment.
- Data enrichment
- The activity underlying innovating with data - adding to or improving existing data so it supports new services and capabilities.
- Leading change
- Guiding a command through evolution that enhances efficiency and sustainability. Its activities are developing strategy, developing policy, and prioritizing action.
- Interacting with data
- Engaging with data in ways that facilitate understanding, analysis and decision-making. Its activities are visualizing data, trend analysis using historical data, and making data intelligent.
- Standardizing data
- Ensuring consistency, accuracy and uniformity in data across various sources and formats. Its activities are using platforms such as SQL and NoSQL, linking data through data mapping, and cleaning data through standardization and normalization.
- Responsible (data ethics)
- The first of the five Army data ethics considerations - personnel exercise appropriate judgment and remain accountable for the development, deployment and use of data capabilities.
- Equitable (data ethics)
- The second consideration, glossed in the lesson as avoiding bias - deliberate steps to minimize unintended bias in data and the capabilities built on it.
- Traceable (data ethics)
- The third consideration - the methods, data sources and design procedures are documented and auditable, so how a conclusion was reached can be reconstructed.
- Reliable (data ethics)
- The fourth consideration - capabilities have an explicit, well-defined use, and their safety, security and effectiveness are tested against that use.
- Governable (data ethics)
- The fifth consideration - capabilities can be disengaged or deactivated if they demonstrate unintended behavior. It is the ethics consideration with an off switch.
- Data storytelling
- Presenting data in a way that is engaging, informative, and easy to understand, through a combination of visuals and narrative. The goal is to communicate insights effectively and make complex data comprehensible and actionable for the audience.
- Data mining
- The process of discovering patterns and relationships in large datasets using statistical and computational techniques.
- Data visualization
- The graphical representation or communication of data to help people understand and gain insightful meaning from it.
- Data quality (analytics sense)
- The condition of data based on factors such as accuracy, completeness, reliability and relevance.
- Data (storytelling review definition)
- Raw facts and figures without inherent context or meaning. It forms the foundation for further analysis and decision making.
- Information (storytelling review definition)
- Data that has been processed and organized in a meaningful way. Information provides context to data.
Testable points
- Data literacy applied to command has six parts: introducing data, managing change and mitigating risk, innovating with data, leading change, interacting with data, and standardizing data.
- Introducing data means integrating new data into the existing ecosystem in a way that maximizes its usefulness - the activities are classifying data, creating value and boosting usability.
- Managing change and mitigating risk covers governing access, measuring success, and working ethically. Ethics appears here as a management activity, not only as a separate list.
- Innovating with data is about developing new products, services and processes as well as enhancing existing ones, through data enrichment.
- Leading change means guiding a command through evolution that enhances efficiency and sustainability, through developing strategy, developing policy, and prioritizing action.
- Interacting with data covers visualizing data, trend analysis on historical data, and making data intelligent.
- Standardizing data ensures consistency, accuracy and uniformity across sources and formats, through using platforms such as SQL and NoSQL, linking data by data mapping, and cleaning by standardization and normalization.
- The five Army data ethics considerations are responsible, equitable, traceable, reliable, and governable.
- Equitable is explicitly glossed in the lesson as avoiding bias.
- Governable is the consideration with an off switch - a capability showing unintended behavior can be disengaged or deactivated.
- The Decision-Driven Data CONOPS states there is a principal need for data literacy at the battalion level, and that commanders at all levels must emphasize data literacy throughout.
- Warfare at higher echelons requires decision making from a system of systems perspective - the argument the CONOPS gives for why data literacy is a command competency rather than a staff skill.
- Data is raw facts and figures without inherent context or meaning, forming the foundation for further analysis and decision making. Information is data processed and organized meaningfully, providing context to data.
- Data governance in the storytelling review is defined identically to the governance lesson: the overall management of data availability, usability, integrity and security within an organization.
- Data quality is the condition of data based on accuracy, completeness, reliability and relevance.
- Data mining discovers patterns and relationships in large datasets using statistical and computational techniques.
- Data visualization is the graphical representation or communication of data to help people understand and gain insightful meaning from it.
- Telling a story with data means presenting it in a way that is engaging, informative and easy to understand.
- A data story is built from a combination of visuals and narrative. Neither alone is the method.
- The stated goal of data storytelling is to communicate insights effectively and make complex data comprehensible and actionable for the audience. Actionable is the operative word - a chart nobody can act on has failed no matter how accurate it is.
- The lesson's argument for visuals is a learning-to-read analogy: children are shown a picture of an apple alongside the letter A, and the same principle lets a reader digest thousands or millions of records at a glance.
- Even basic visuals can support understanding of thousands or millions of records, and are commonly used for exactly that.
- A pie chart's three pros are simplicity, showing parts to a whole, and immediate impact.
- A pie chart's three cons are a limited number of slices, misleading perception of slices, and lack of detail.
- The pie chart limitation named as a worked example is comparing similar proportions - slight differences in resource allocation between two similar programs are hard to see as wedges.
- The pie chart example given for too many slices is trying to represent the distribution of tanks, helicopters, jets, ships and drones on one chart.
- This lesson repeats definitions from the data literacy and governance lessons deliberately, as a comprehensive review of data and analytics terminology - so the terminology is worth over-learning once rather than three times.
References
Decision-Driven Data CONOPS (July 2023)Army Data Plan (February 2022)DOD Data StrategyArmy Data Management and Analytics LexiconCompTIA Data+ DA0-001
S6 management techniques - the scenarios S6 MGMT
Learning objective and standard
Learning objectiveGiven a set of battalion S6 scenarios drawn from real units, apply the management techniques, battle drills and reporting requirements a battalion S6 is expected to have ready before the situation happens.
StandardRecognise the correct action for each scenario - encryption on issued machines, bench stock management, knowledge concentration in the section, loss of commercial power, the IMO programme, classified spillage, account prerequisites, insider concerns and lost COMSEC - and know which of them carry a reporting timeline.
This is the class that is not about the network. `Network Essentials Class 9.pptx` puts it on the weekly schedule at Thursday 0830, and it is nine scenarios a battalion S6 is actually likely to meet, each with the answer given. It is the most practical block in Module D and it is written from a real S6's experience - the Fort Irwin power outages, the Fort Polk COMSEC filling station, the obfuscated BitLocker code - rather than from doctrine. Two of the nine turn on a reporting clock, which is the part worth memorising: a suspected classified spillage and a missing SKL both have a next-higher notification that gets worse the longer it waits.
Doctrinal sets to know cold
The nine scenarios in this class
- The BitLocker code on a sticker on every monitor
- Bench stock - what it is, examples, why it matters, what drives the inventory
- Knowledge concentrated in one or two Soldiers
- Loss of commercial power at a FOB
- The IMO / commo representative programme
- Classified spillage forwarded to a dozen leaders
- A new Soldier who thinks he needs a Secret clearance for NIPR
- A disgruntled Soldier who says he will destroy the network
- A missing SKL after a COMSEC filling mission
What expeditionary signal units can provide after a disaster (FM 6-02, 2-130)
- Emergency restoral of first responder communications
- Command post communications - voice, data and video teleconferencing
- Network connectivity to disseminate the common operational picture
- Communications to coordinate logistical support
- Connection to civilian communications infrastructure, to interoperate with emergency responders and non-governmental organizations
- Communications to areas outside the disaster zone
IMO tasks at company level
- Managing the ATOE
- Ten-level operator fixes
- IMO patches
- Transferring inventory of equipment to the S6
- Managing company issues
- Submitting S6 tickets
- Filling radios
What drives your bench stock inventory
- The unit's equipment
- The unit's primary mission
- The commander's intent
- The unit's PACE plan
- Projected equipment
- The tech refresh cycle
Key terms
- Bench stock
- Low-cost, high-use, consumable items used at an unpredictable rate - supply classes II (clothing and equipment), IIIP (packaged petroleum, oils and lubricants), IV (construction materials) and IX (repair parts), less components. For an S6 that means CD/DVDs, Cat 5e, external drives, paper, ink cartridges, projector bulbs, CAC readers, monitors, keyboards and power supplies.
- IMO / commo representative programme
- A programme that establishes Information Management Officers at company level to carry out S6-related tasks: managing the ATOE, ten-level operator fixes, IMO patches, transferring inventory of equipment to the S6, managing company issues, submitting S6 tickets and filling radios. It is the S6's equivalent of the representative every other staff section has at company.
- ATOE
- Automations Table of Organizational Equipment. A non-doctrinal term - the same idea as an MTOE, except computers are assigned to slots rather than people. Its value is in lifecycle management: you cannot conduct a tech refresh without knowing what is assigned where.
- BitLocker
- Full-volume drive encryption. The Army now encrypts the entire hard drive at volume level, so no user-entered BitLocker code is required. Users can still encrypt individual files: right-click the folder, Properties, Advanced, tick "Encrypt contents to secure data".
- Classified spillage
- Information from a higher classification transmitted to a lower one - typically a forwarded email. It triggers an NEC alert. Every recipient must delete the message, empty it from trash and empty it from the recoverable-items folder; any machine on which it was opened must be wiped.
- NACLC / background investigation
- The investigation actually required for a NIPR account, verified by the S2 when they sign off the DA Form 2875. A Secret clearance is not a prerequisite for NIPR access. The deck writes it "NACLAC"; the investigation tiers have since been renamed, but the teaching point is the distinction, not the acronym.
- DA Form 2875
- System Authorization Access Request. The form on which the S2 verifies a user's background investigation before a network account is granted.
- SKL
- Simple Key Loader. The fill device used at a COMSEC filling station. A missing SKL is lost COMSEC and carries a reporting timeline.
- Orange 1 report
- The report submitted for lost COMSEC equipment, alongside notification of next higher. The guidance is roughly thirty minutes of thorough rechecking before the call - and that reports of this kind have a suspense, so delay makes the consequences worse rather than better.
- Obfuscation
- The old workaround for BitLocker codes, offered here as a technique rather than a recommendation: the S6 duty phone number was used as the code, so the sticker on the machine read "S6: 706-706-7060" and meant nothing to anyone else. It is no longer needed - full-volume encryption removed the user-entered code.
Testable points
- This class is on the weekly schedule. `Network Essentials Class 9.pptx` lists S6 Management Techniques at Thursday 0830.
- BitLocker: the Army encrypts the entire hard drive at volume level, so no BitLocker code is necessary and a code written on a sticker is answering a problem that no longer exists.
- File-level encryption is still available to users: right-click the folder, Properties, Advanced button, tick "Encrypt contents to secure data". The same dialog offers "Compress contents to save disk space".
- Bench stock is defined per army.mil as low-cost, high-use consumable classes II, IIIP, IV and IX items, less components, used by maintenance personnel at an unpredictable rate.
- Four factors drive what your bench stock should hold: the unit's equipment, its primary mission, the commander's intent, the unit's PACE plan, its projected equipment and the tech refresh cycle.
- The consequence of not managing bench stock is stated plainly: it becomes harder to provide reliable IT support to the BN CDR, CSM, XO and S3 - the people whose outages become your problem fastest.
- Knowledge concentrated in one or two Soldiers is an NCOIC problem first. The remedy given is end-of-day briefs to capture who did what and how; if those are already running and the problem persists, pair the Soldiers.
- Loss of commercial power at a FOB is a battle-drill problem, not an improvisation problem. The plan of action: obtain a 3K generator from the S3, run power to the UPS and switches, and have the NCOs coordinate fuel.
- That scenario is real and recurring - Fort Irwin lost power to storms three times in two years.
- Cooling is part of the same drill. Other units had to set up blowers or fans on their communications equipment in the absence of a working air conditioner.
- FM 6-02 (September 2019), paragraph 2-130, is the doctrinal backing: signal units have organic power generation and can establish communications before the commercial grid is restored, given fuel and logistical support.
- Every other staff section has a company-level counterpart - S1, S2, S3, S4 all do. The S6's is the IMO, and the IMO programme is what creates that counterpart.
- An IMO or commo representative programme must be bought off by Command. It is not something the S6 can institute alone.
- Spillage response: contact the NEC and take their guidance. Every recipient deletes the email, empties trash, and empties the recoverable-items folder. Any machine where it was opened must be wiped, and the NEC may direct that all of them are.
- If the spillage reaches the battalion commander, the turnaround of a few days is the problem - getting a replacement machine is highly advisable rather than waiting on the wipe.
- A Secret clearance is not required for a NIPR account. What is required is a background investigation, verified by the S2 when they sign the DA Form 2875.
- A missing SKL: get the team, re-verify every location thoroughly - roughly thirty minutes - then submit an Orange 1 report and notify next higher. Check hard before the call, but do not let checking run past the suspense.
- The reporting principle behind both the spillage and the SKL scenarios: these reports have timeline suspenses, and the longer the wait, the more likely there are consequences for whoever failed to report.
- Build rapport with the commo team of each general officer or senior staff section, so that when something breaks you already know who is affected and how critical it actually is.
- Have COMSEC ready in advance, or a clear understanding with the COMSEC custodian that these events happen without warning. The USANEC-A commander and NETOPS OIC should hold cell numbers for two COMSEC custodians and the commo team.
- Know which users sit on which ports, so that net technicians do not need a toner to work out whose line goes where.
References
S6 Management Techniques.pptxNetwork Essentials Class 9.pptxFM 6-02 (12 September 2019), paragraph 2-130DA Form 2875