UPDATED MARINE CORPS POLICY FOR USE OF PUBLIC KEY INFRASTRUCTURE (PKI) CERTIFICATES ON PORTABLE ELECTRONIC DEVICES (PEDS) SECURITY AND APPLICATION OF EMAIL SIGNATURE AND ENCRYPTION POLICY
Date Signed: 7/12/2017 | MARADMINS Number: 367/17
MARADMINS : 367/17
R 121426Z JUL 17
MARADMIN 367/17
MSGID/GENADMIN/CMC WASHINGTON DC C4//
SUBJ/UPDATED MARINE CORPS POLICY FOR USE OF PUBLIC KEY INFRASTRUCTURE (PKI) CERTIFICATES ON PORTABLE ELECTRONIC DEVICES (PEDS) SECURITY AND APPLICATION OF EMAIL SIGNATURE AND ENCRYPTION POLICY//
REF/A/MSGID/DOC/DODI 8520.02/24MAY/2011//
REF/B/MSGID/MSG/211734ZNOV08//
REF/C/MSGID/DOC/DOD CIO MEMO/06MAY2015//
REF/D/MSGID/DOC/CMC/02NOV2016//
NARR/REF A IS DODI 8520.02, PUBLIC KEY INFRASTRUCTURE (PKI) AND PUBLIC KEY (PK) ENABLING, THE DOD POLICY ON PKI.  REF B IS MARADMIN 659/08, WHICH PROVIDED ORIGINAL MARINE CORPS POLICY FOR USE OF PKI CERTIFICATES WITH PEDS.  REF C IS THE DOD INTERIM GUIDANCE FOR IMPLEMENTING DERIVED PUBLIC KEY INFRASTRUCTURE (PKI) CREDENTIALS ON UNCLASSIFIED COMMERCIAL MOBILE DEVICES.  REF D IS CMC WHITE LETTER 3-16, WHICH GOVERNS THE USE OF PEDS WITHIN THE MARINE CORPS.//
POC/DR. R. A. LETTEER/CIV/C4 CYBERSECURITY CHIEF/TEL: 703-693-3490/EMAIL: RAY.LETTEER@USMC.MIL//
POC/C. HESEMANN/CIV/C4 CYBERSECURITY/TEL: 703-693-3490/EMAIL: CHRISTINE.HESEMANN@USMC.MIL//
GENTEXT/REMARKS/1.  PURPOSE.  This MARADMIN sets forth updated policy and guidance for the use of PKI certificates with PEDS.  Acceptable use of PEDS will follow policy resulting from Ref C.  This policy is applicable to Marine Corps and Marine Corps Reserves.
2.  Policy.  All Marine Corps systems and devices (including portable electronic devices) accessing the MCEN shall be PK-enabled and support sending and receiving e-mail digitally signed and encrypted using DOD approved certificates.  E-mail shall be digitally signed and or encrypted in accordance with Marine Corps policy.
3.  Only PEDS capable of being PK-enabled with approved DOD PKI certificates in accordance with DOD PKI policy shall be authorized for use on the MCEN.
4.  All PED users shall either use an approved smartcard reader or a DOD approved derived PKI certificate issued in accordance with a DOD PKI approved process (Ref A).  Approved smartcard readers may interface with PED handhelds through either a physical connection or a secured bluetooth communications link, configured in accordance with the DISA Wireless Security Technical Implementation Guide (STIG).
5.  Commands are responsible for the acquisition, distribution, and maintenance of smartcard readers as the primary enabling capability for signing and encrypting email on a PED.
6.  All PED users will use the appropriate PKI hardware token and smartcard reader, DOD issued software certificates, or DOD approved derived PKI certificates associated with the email account.
7.  Marine Corps General Officers (GO), Senior Executive Service (SES) personnel, Chiefs Of Staff/Military Assistants/Executive Assistants (COS/MA/EA), Commanding Officers (CO), Command Executive Officers (XO), Command Sergeants Major, and other individuals approved by the Marine Corps Authorizing Official (AO) are authorized to use DOD issued software certificates on PEDS in lieu of hardware token and smartcard reader.
8.  PEDS using DOD issued software certificates or DOD derived credentials shall be treated as if it were the users Common Access Card (CAC).  Immediately report to the Registration Authority (RA) Operations Team the loss or theft of the device.
9.  Recovery, issuance, and protection measures for certificates used on a PED shall be compliant with policy and guidance outlined in Ref B.  The RA Operations Team, Local Registration Authority (LRA), and PKI Trusted Agents (TA) are authorized to load certificates as detailed in Ref B.  The RA Operations Team shall provide specific training for PKI TA authorized to perform this action.
10.  The RA Operations Team will keep a list of users and associated certificate information for those that have either software certificates or derived PKI credentials on a PED in accordance with Ref C.
11.  Request for approval to use DOD issued software certificates for users not approved by this policy may be made via letter on command letterhead to the Marine Corps AO and submitted to HQMC_C4CY_IDMGT@usmc.mil.
12.  Request for issuance of software certificates is made by individuals approved in paragraph 7 by sending a digitally signed email to the RA Operations Team at raoperations@usmc.mil.  Personnel approved by waiver must attach a copy of the AO signed letter to the email.  RA Operations will complete action on the request within 5 working days of receipt.
13.  Marines are reminded to adhere to Ref D when using PEDs in the Marine Corps.
14.  This policy supersedes and cancels Ref B and will remain be in force until cancelled or superseded.
15.  Release authorized by BGen D. A. Crall, Director, Command, Control, Communications and Computers (C4) Department/Chief Information Officer of the Marine Corps.//