The DoD Defense Industrial Base (DIB) Collaborative Information Sharing Environment (DCISE) serves as the single DoD focal point for receiving all cyber incident reporting affecting unclassified networks of DoD contractors to safeguard DoD information.
DCISE Overview

DoD-Defense Industrial Base Collaborative Information Sharing Environment (DCISE)—DCISE is the operational hub of DoD’s Defense Industrial Base (DIB) Cybersecurity Program, focused on protecting intellectual property and safeguarding DoD content residing on or transiting through, contractor unclassified networks. The public-private cybersecurity partnership provides: a collaborative environment for crowd-sourced threat sharing at both unclassified and classified levels, CDC cyber resilience analyses, and Cybersecurity-as-a-Service pilot offerings. DCISE performs cyber threat analysis and diagnostics, offers mitigation and remediation strategies, provides best practices, and conducts analyst-to-analyst exchanges with DIB participants ranging in size from small to enterprise-sized companies.

DC3/DCISE is the reporting and analysis hub for implementation of 10 USC Sections 391 and 393 regarding the reporting of certain types of cyber incidents by Cleared Defense Contractors (CDCs), and the related Defense Federal Acquisition Regulation Supplement (DFARS 252.204- 7012). Cyber incidents outlined in the DFARS are submitted to DC3/ DCISE as mandatory reports; however, all other cyber activity can be reported voluntarily.

• Rated as Capability Maturity Model Integration for Services (CMMISVC) Maturity Level 3
• Collaborative partnership with over 850 CDCs and U.S. Government (USG) agencies
• Shared over 507,000+ actionable, non-attributable (to submitting source) indicators
• Provided over 77,000+ hours of no-cost forensics and malware analysis for DIB Partners
• Disseminated 12,500+ cyber threat reports for both DIB and USG consumption (DIB partners may access DCISE reporting via their DIBNET accounts and USG members can access via SIPR Intelshare)
• Operates 24/7/365 DCISE support hotline (1-877-838-2174) to assist submitters and DIB & USG Partners


 

  




If you are a Cleared Defense Contractor and interested in joining the DIB CS Programclick here to go to the DIB Cyber Incident Reporting & Cyber Threat Information Sharing portal to apply.
 

DIBNet Portal

DoD’s gateway for defense contractor reporting and voluntary participation in DoD’s DIB Cybersecurity Program.
 

DIB Tech Talks
DCISE Capabilities
Analytics Division (AD): AD conducts analysis on cyber activity submitted by DIB Partners, DoD, and other USG agencies to develop a complete understanding of known or potential threats to unclassified DoD information on or transiting DIB systems and networks. AD also analyzes aggregate data from DIB Partner incident reports to produce technical analysis products, presentations, and other threat mitigation resources. The Division collaborates with liaison officers from USG agencies to create and maintain technical and multi-source threat profiles. The Analytics Division is comprised of two branches:

1. Tactical Operations: Conducts daily processing of voluntary and mandatory incident reports, as well as malware analysis, Customer Response Forms (CRFs), CRF Supplements, and partner engagement.
2. Applied Research: Handles mid- to long-term analysis, resulting in the following threat products: Threat Activity Reports (TARs), Cyber Targeting Analysis Reports (CTARs), Alerts, Warnings, Threat Information Products (TIPs), and other threat-based analyses. To share valuable information with the DIB, this branch requests the downgrade and release of classified information derived from USG sources. Such information is shared via DCISE’s Cyber Threat Bulletins (CTBs) and Advisories.
 

Expanded Offerings and Projects (XOP) Division: XOP researches services that support DIB Partners in protecting DoD information. These services are offered as pilots to the DIB Partnership. The pilots range from services to technologies and are intended to encompass all concepts, technologies and processes within cybersecurity. XOP was created because of the need for evolving solutions based on the ever changing cybersecurity environment and the diverse composition of the DIB partnership. Three branches constitute XOP:

1. Assess Branch: Performs analysis of cybersecurity processes of DIB partners through the Cyber Resilience Analysis (CRA) tool. This branch also evaluates other vulnerability and pen testing assessment procedures and provides them as a service to the DIB Partnership.

2. Assist Branch: Evaluates different cybersecurity technologies that can be provided to the DIB partnership as a pilot. Once the pilot is offered to the DIB, the information gathered from the capability is passed on to AD to determine if the information is applicable. Once the pilot is completed, and if it is determined to be successful, it may be considered as a permanent service offering for the Partnership.

3. Architect Branch: Researches and identifies the most effective ways to communicate with the DIB partnership. Their research discovers technologies that can best support transmitting cyber threat information from AD to the Partnership.
 

Mission Support Division (MSD): MSD executes functional areas including internal/external customer services, outreach, operational metrics, process improvement, quality assurance, quality control and organizational training. MSD builds and manages relationships with a wide range of DIB companies and USG stakeholders, and drives special projects that improve the overall customer experience. MSD is comprised of two branches:

1. Customer Engagement: Primarily responsible for customer relationships; DIB Partner on-boarding and outreach campaigns to promote DIB participation, DIBNET coordination with the DIB CS Program Office and DISA; as well as event planning for Technical Exchanges, Regional Partner Exchanges, and Virtual Partner Exchanges; and facilitating Analyst-to-Analyst and Business-to-Business Exchanges.

2. Organizational Readiness: A team of knowledge managers, business and process analysts; quality control analysts; quality assurance analysts, training manager, process owners and support staff to drive continual process improvement. Systematically coordinates and aligns resources and functions with the DCISE vision, mission, goals and objectives through the DCISE Performance Management Plan.
DCISE Services
 
 

Technical Exchanges

DCISE personnel are available to meet with industry partners and government stakeholders to share insight on handling intrusion-related activity.

 

DIB Technical Teleconferences

DIB partners and DCISE analysts have unclassified discussions on adversary techniques and targeted networks.

 

DIB Network

DIBNet is the DoD's network for on-line incident reporting and access to DCISE threat products.

 

Analyst-to-Analyst Meetings

Private DIB Analyst-to-Analyst (A2A) meetings are hosted by DCISE at DC3. These meetings are partner-driven to discuss tactics, techniques, and procedures (TTPs) used by advanced persistent threat (APT) actors targeting networks of that specific DIB Partner. Local on-site A2As can be arranged in special circumstances.

 

Threat Products

DCISE cyber threat products assist government and industry partners in strengthening security and protecting controlled unclassified information on DIB computer networks. DCISE products, advisories, and administrative notifications are disseminated to USG Stakeholders and DIB Partners.