[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-165315-en":3,"doc-seo-165315-105":30,"detail-sidebar-cat-1-en-105":90},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":11,"category_id":12,"category_name":13,"doc_title":14,"doc_description":15,"doc_content":16,"file_id":17,"file_url":18,"file_type":19,"file_size":20,"view_count":4,"is_deleted":4,"is_public":11,"is_downloadable":11,"audit_status":11,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":15,"update_tm":28,"read_time":29},165315,13056712833777,"Paura","https://ap-avatar.wpscdn.com/davatar_29158cc5080c5b710cf443261637dec0",1,18,"Letters","FY19 Requirement Justification Funding Request (RJFR) - F5 SCCA Cloud Gateway","FY19 Requirement Justification Funding Request (RJFR) outlines the rationale for deploying an F5 SCCA Cloud Gateway to support DoD organizations moving workloads to commercial public cloud providers. The request explains DISA SCCA 2017 objectives, detailing the BCAP, VDSS, VDMS, and TCCM components and how F5 BIG-IP Virtual Editions templates map to required security functions. It also addresses organizational impact, compliance goals, and provides an initial cost and funding approach for purchasing and first-year support.","FY19 Requirement Justification Funding Request (RJFR)\nF5 SCCA Cloud Gateway\nBackground:\nDISA has established a set of security standards for DoD Organization intent on moving workloads to Commercial Public Cloud Providers.  The guidance is defined as the \u0013 HYPERLINK \"https://iasecontent.disa.mil/stigs/pdf/SCCA_FRD_v2-9.pdf\" \u0014Secure Cloud Computing Architecture\u0015 (SCCA) published in 2017. SCCA describes the functional objectives for securing the Defense Information System Network’s (DISN) and Commercial Cloud Provider connection points with the end goal of providing mission owners secure cloud applications and the ability to engage public cloud providers directly.\nDescription of the Requirements:\nThere are four components to the SCCA:\nBoundary Cloud Access Point (BCAP)\nVirtual Datacenter Security Stack (VDSS)\nVirtual Datacenter Services (VDMS)\nTrusted Cloud Credential Manager (TCCM)\nCloud Service Providers (CSP’s) like Microsoft, AWS and Google are all developing solutions that enable workloads and applications to run in the cloud. These cloud-based applications must meet the security standards defined by the SCCA.  The VCAP, VDSS, and VDMS requirements are not specific to a cloud provider and can be delivered by the responsible DoD application or mission owners.  F5 BIG-IP Virtual Editions (VE) provide cloud-based applications with the security capabilities required by the SCCA. The joint architecture between F5 and CSP’s aims to develop a holistic cloud architecture that bring together and satisfy every functional objective of SCCA for DoD cloud workloads.  As a Mission Owner it is critical that we address these requirements.\nSCCA Solution Template\nF5 SCCA functionality is deployed through the use of templates.  These templates are fielded via the Cloud Service Provider and the F5 BIG-IP Virtual Edition (VE).  The template deployment is focused on the VDSS, BCAP, and VDMS components. The Mission Owner environments will not be deployed as part of these templates but there are additional scripts for deploying and attaching a Mission Owners application in IL5, IL4, etc.  Mission Owner application environments will be customized for the unique application requirements.\nThe below paragraphs describe the components of SCCA in more detail.\nBoundary Cloud Access Point (BCAP)\nThe purpose of the BCAP is to protect the DISN from attacks originating in the cloud environment. BCAP will perform intrusion detection and prevention as well as filter out unauthorized traffic. This component can be co-located with other components of the SCCA.\nVirtual Datacenter Security Stack (VDSS)\nThe purpose of the VDSS is to protect DoD Mission Owner applications that are hosted in Azure. VDSS performs the bulk of the security operations in the SCCA. It will conduct traffic inspection in order to secure the applications running in Azure. This component can be provided within your cloud environment.\nVirtual Datacenter Services (VDMS)\nThe purpose of VDMS is to provide host security as well as shared data center services. The functions of VDMS can either run in the hub of your SCCA or the Mission Owner can deploy pieces of it in their own specific Azure subscription. This component can be provided within your cloud environment.\nTrusted Cloud Credential Manager (TCCM)\nTCCM is a business role. This individual will be responsible for managing the SCCA. Their duties include establishing plans and policies for account access to the cloud environment, ensuring identity and access management is operating properly, and to maintain the Cloud Credential Management Plan. This individual is appointed by the Authorizing Official. The BCAP, VDSS, and VDMS will provide the capabilities needed for the TCCM to perform their job function.\nMapping SCCA to Cloud and F5 Capabilities\nThe following tables illustrate the mapping of native Microsoft Azure Cloud services and capabilities of F5 BIG-IP virtual appliances to the SCCA guidance for BCAP, VDSS and VDMS.  Descriptions for the","cbCaipWvH2QLQnXQ","https://ap.wps.com/l/cbCaipWvH2QLQnXQ","docx",142526,8,"English","en",105,"# FY19 Requirement Justification Funding Request (RJFR)\n## Background and Description of SCCA Requirements\n## SCCA Components and Their Purposes\n## Mapping SCCA to Cloud and F5 Capabilities\n## Impact on Organization and Cost Estimate\n## Funding Request Details","[{\"question\":\"What is the DISA SCCA and why is it important for DoD cloud adoption?\",\"answer\":\"SCCA (2017) defines functional objectives to secure Defense Information System Network connection points with commercial cloud providers. It enables mission owners to run secure cloud applications and directly engage public cloud providers while maintaining required security standards.\"},{\"question\":\"What are the four key SCCA components covered in this request?\",\"answer\":\"The document describes BCAP, VDSS, VDMS, and TCCM. BCAP protects against cloud-origin attacks, VDSS performs core security operations for applications hosted in Azure, VDMS provides host security and shared datacenter services, and TCCM is the business role responsible for managing SCCA-related account access and credentials.\"},{\"question\":\"How does F5 SCCA Cloud Gateway relate to Azure and cloud service providers?\",\"answer\":\"The request states that F5 BIG-IP Virtual Editions provide security capabilities aligned to SCCA objectives through template deployment. It emphasizes that VDSS, BCAP, and VDMS template deployment is handled via the cloud service provider and F5 VE, while mission owner environments are customized for specific application needs.\"}]","FY19 Requirement Justification Funding Request (RJFR) - F5 SCCA Cloud Gateway | DOCX",1788169639,3,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":14,"keywords":34,"description":15,"schema_data":35,"social_meta":85,"head_meta":87,"extra_data":89,"updated_unix":28},"fy19-requirement-justification-funding-request-rjfr-f5-scca-cloud-gateway","",{"@graph":36,"@context":84},[37,53,67],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,50],{"item":41,"name":42,"@type":43,"position":11},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/template/","Template",2,{"item":49,"name":13,"@type":43,"position":29},"https://docshare.wps.com/template/letters/",{"item":51,"name":14,"@type":43,"position":52},"https://docshare.wps.com/template/fy19-requirement-justification-funding-request-rjfr-f5-scca-cloud-gateway/165315/",4,{"url":51,"name":14,"@type":54,"author":55,"headline":14,"publisher":57,"fileFormat":60,"inLanguage":23,"description":15,"dateModified":61,"datePublished":61,"encodingFormat":60,"isAccessibleForFree":62,"interactionStatistic":63},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/vnd.openxmlformats-officedocument.wordprocessingml.document","2026-08-31",true,{"@type":64,"interactionType":65,"userInteractionCount":4},"InteractionCounter",{"@type":66},"ViewAction",{"@type":68,"mainEntity":69},"FAQPage",[70,76,80],{"name":71,"@type":72,"acceptedAnswer":73},"What is the DISA SCCA and why is it important for DoD cloud adoption?","Question",{"text":74,"@type":75},"SCCA (2017) defines functional objectives to secure Defense Information System Network connection points with commercial cloud providers. It enables mission owners to run secure cloud applications and directly engage public cloud providers while maintaining required security standards.","Answer",{"name":77,"@type":72,"acceptedAnswer":78},"What are the four key SCCA components covered in this request?",{"text":79,"@type":75},"The document describes BCAP, VDSS, VDMS, and TCCM. BCAP protects against cloud-origin attacks, VDSS performs core security operations for applications hosted in Azure, VDMS provides host security and shared datacenter services, and TCCM is the business role responsible for managing SCCA-related account access and credentials.",{"name":81,"@type":72,"acceptedAnswer":82},"How does F5 SCCA Cloud Gateway relate to Azure and cloud service providers?",{"text":83,"@type":75},"The request states that F5 BIG-IP Virtual Editions provide security capabilities aligned to SCCA objectives through template deployment. It emphasizes that VDSS, BCAP, and VDMS template deployment is handled via the cloud service provider and F5 VE, while mission owner environments are customized for specific application needs.","https://schema.org",{"og:url":51,"og:type":86,"og:title":14,"og:site_name":58,"og:description":15},"article",{"robots":88,"canonical":51},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":91},[92,97,102,107,112,117,122,125,130],{"id":93,"doc_module":11,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},11,"Presentations",90,"presentations",{"id":98,"doc_module":11,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},12,"Resumes",80,"resumes",{"id":103,"doc_module":11,"doc_module_name":46,"category_name":104,"show_sort_weight":105,"slug":106},14,"Invoices",70,"invoices",{"id":108,"doc_module":11,"doc_module_name":46,"category_name":109,"show_sort_weight":110,"slug":111},15,"Posters",60,"posters",{"id":113,"doc_module":11,"doc_module_name":46,"category_name":114,"show_sort_weight":115,"slug":116},16,"Social Media",50,"social-media",{"id":118,"doc_module":11,"doc_module_name":46,"category_name":119,"show_sort_weight":120,"slug":121},17,"Forms",40,"forms",{"id":12,"doc_module":11,"doc_module_name":46,"category_name":13,"show_sort_weight":123,"slug":124},30,"letters",{"id":126,"doc_module":11,"doc_module_name":46,"category_name":127,"show_sort_weight":128,"slug":129},21,"Paper Templates",5,"papers-templates",{"id":131,"doc_module":11,"doc_module_name":46,"category_name":132,"show_sort_weight":4,"slug":133},158,"General","general-158"]