Site selection is a key factor in the establishment and maintenance of a secure operating environment. Ideally, any location selected to house an automated system would support an effective physical security system. Architectural design is an equally important aspect of the site selection and security relationship. Physical provisions for restricting access should be incorporated into the initial design. While it is not practical to establish firm Army-wide standards governing the location of such systems, the factors below will be considered and will be implemented in the site selection process when appropriate and feasible.

All personnel who manage, design, develop, maintain, or operate AIS will undergo a training and awareness program consisting of-

The Computer Security Technical Vulnerability Reporting Program (CSTVRP) provides for the collection, consolidation, analysis, reporting, or notification of generic technical vulnerabilities and corrective measures in support of the DOD computer security requirements. The program focuses on technical vulnerabilities in commercially available hardware, firmware, and software products acquired by the DOD and those altered commercial products supporting standard military applications. Research prototypes, preproduction commercial products, and site-specific vulnerabilities are specifically excluded from this program.

INSCOM manages and implements the AISSAP. This program includes teams available to visit Army and selected DOD and contractor-operated facilities to provide technical advice and assistance on AIS security as well as an AIS Security Testing, Analysis, and Support Center.