Citation
DoDI 8500.01 - Cybersecurity
DoD Chief Information Officer (DoD CIO)
- Effective
- 2014-03-14
- Publisher
- DoD Chief Information Officer (DoD CIO)
- Pages citing
- 6
Scope
DoDI 8500.01 establishes DoD cybersecurity policy. The instruction reissues and cancels DoD Directive 8500.1 (Information Assurance) and DoD Directive 8500.2 (Information Assurance Implementation), transitioning DoD from an Information Assurance (IA) framework to a cybersecurity framework aligned with the NIST Risk Management Framework (RMF). The instruction assigns responsibilities to the DoD CIO, commanders, information system owners, authorizing officials, and users for protecting DoD information systems and networks.
Note on Designation
Portal content references this instruction as "DOD 8500.01E." The "E" suffix was the designation on the former DoD Directive 8500.2 and does not apply to DoDI 8500.01. Both "DOD 8500.01E" and "DoDI 8500.01" resolve to this entry.
Audience
DoD information system owners and program managers applying the Risk Management Framework (RMF) for system authorization. Marine Corps ISSO and ISSM personnel managing cybersecurity risk for unit information systems. Commanders accountable for cybersecurity posture of assigned systems. Unit cybersecurity officers routing incident reports. S-1 admin specialists operating in MCTFS, UD-MIPS, MOL, and other DoD information systems.
Key Provisions
- Risk Management Framework (RMF). DoD adopts the NIST RMF (SP 800-37) as the overarching framework for managing cybersecurity risk across all DoD information systems. All systems require authorization before operation.
- Cybersecurity program responsibilities. DoD CIO establishes DoD-wide policy. Commanders are responsible for cybersecurity within their area of responsibility. Information system owners implement security controls.
- Incident reporting. Cybersecurity incidents are reported through established DoD incident response channels. Unit cybersecurity officers route incident reports to the appropriate CERT/CC.
- Access control and identity management. Access to DoD systems requires Common Access Card (CAC) authentication for all users. Privileged access requires additional controls and agreements.
- Continuous monitoring. Authorized information systems require continuous monitoring of security controls to maintain authorization to operate (ATO).
- Supply chain risk management. DoD acquisition programs apply supply chain risk management to hardware and software components.
Connection to Marine Corps Policy
- MCO 5239.2B Marine Corps Cybersecurity Program. Marine Corps implementation of DoDI 8500.01 policy.
- SECNAVINST 5239.3C Department of the Navy Cybersecurity Policy. SECNAV-level implementation above MCO 5239.2B.
- 5 USC 552a Privacy Act of 1974. PII protection requirements implemented through RMF security controls.
Status
Active. Effective 14 March 2014, incorporating Change 1 (23 October 2019). Issued by DoD CIO. Distribution Statement A.
Aliases the resolver matches
- DoDI 8500.01
- DODI 8500.01
- DOD INSTRUCTION 8500.01
- DoD Instruction 8500.01
- DODI 8500.01 Cybersecurity
- DoDI 8500.01 Cybersecurity
- DOD 8500.01E Cybersecurity
- DOD 8500.01E
- DoDD 8500.1
- DoD Cybersecurity