Title: CID Classified Electronic Media Inventory Database
1CID(Classified Electronic Media) Inventory
Database
- Presented to participants of
- NLIT Summit 2007 by
- Heather Robideau, Sandia National Laboratories
2Outline
- What is CID?
- Why was it created?
- Why is it important?
- How does it improve existing manual processes?
- High-level system architecture
- Getting started with CID
- Process demonstration
- Discrepancy notification, escalation, and
resolution procedures - Conclusion Questions
3CID is an Application . . .
- used to track all active classified electronic
media (system hard drives, backup tapes, SAN/RAID
storage disks, etc.) - that automatically, securely, and consistently
transfers inventory data to a central server - that creates a permanent audit trail for all
media introduced into classified systems - that detects inventory discrepancies and alerts
appropriate personnel as they are discovered - that was built by system administrators for
system administrators - that is currently not meant to actively detect
the removal or insertion of classified media on a
real-time basis
4CID Creation Trail - 1
CREM Classified Removable Electronic Media
- CREM Stand-down on July 23rd 2004
5CID Creation Trail - 2
- CREM Restart September 1st 2004
ACREM Accountable CREM
6CID Creation Trail - 3
CMPC Classified Matter Protection Control
- Guidance from CMPC on Mitigating Factors
- . . . Organizations that use electronic disk
farms, multimedia backup units, or similar
electronic mass storage devices with system
software and/or system device registries capable
of verifying the presence of their classified
media must use this capability as a tracking
system for these media.
7CID Creation Trail - 4
- Sandia National Laboratories Classified Removable
Electronic Media (CREM) Handling Procedures
September 10th 2004 - . . . must be entered into an automatic or
manual monitoring/tracking activity.
8CID is Important Because it . . .
- meets DOE and, consequently, SNL requirements for
regular inventories - provides an automated, easy to use, centralized,
and standard application and process - offers a new capability to easily track and view
all in-use classified media (type, location,
quantity, etc.) - eliminates opportunities for data entry mistakes,
with automation and tight integration with other
corporate utilities, databases, applications,
processes
9Improving Existing Manual Processes
- Existing processes can be cumbersome,
inconsistent, and may have manual steps that have
potential to introduce errors.
10High-level System Architecture
Data Source system or group of systems entered
into CID consisting of a machine name, media,
description
CID Driver script run on the data source to
extract display electronic serial numbers
CID Handler program (java) that collects the
driver output and sends it to the CID server
11Getting Started with CID
- CID user (view data, create data sources,
describe sources, explain discrepancies, certify
inventories, etc.) - CID account
- Terminal/workstation connected to the classified
network with a modern web browser (gt IE 5.5,
Firefox 1.0, etc.) - Group created for access control
- Machine acting as a CID data source
- Java Runtime Environment gt v1.4.2
- CID Driver(s)
12Demo Add Data Source
Group created for access control
13Demo View New Data Source
Unique identifier generated by CID
14Demo Inventories
Overdue inventories indicate this fact
15Demo Inventories that do not Match
Column indicates inventory discrepancies
16Demo View Inventory Differences
Option to remove the most recent inventory
17Demo Explaining the Difference
LADS is the Sandia database used for accountable
media documents
18Demo Explained Approved Differences
19Demo Certify Inventory
Responsible parties verify inventory completion
accuracy
20Notification Escalation Information
Sandia Labs specific terms CEM, SCN, ISSOs,
SIMP
21Conclusion
- Most important points
- DOE/Sandia policy that CREM can not be handled
without regular inventories - CID provides an automated, consistent process to
conduct weekly inventories that should reduce the
amount of work required of classified system
administrators - CID provides new important functionality that
hasnt existed before now Always know the
current state of our in play CREM, with a
birth-to-death audit trail. - For more information (on the Sandia internal
network) - http//cid-qual.sandia.gov/docs/
- https//cid-help.sandia.gov
- We have attempted to clarify what CID is, why we
need it, and how it can help you and the
Laboratories, but wed like some feedback and
discussion . . .
22Questions?