Frequently Asked Question
CICB is not listed on the DoD Unified Capabilities Approved Products List and does not have a product-level ATO, official STIG approval, CMVP FIPS certificate, NIAP or NIAPC validation, Common Criteria certification, or DoD Impact Level authorization.
APL applicability depends on the product category and the complete system architecture. A vendor source review or self-test does not establish approval and must not be represented as proof that CICB will preserve a customer's STIG score.
Current vendor component evidence for CICB 2.9.11.162 is published at the CICB assurance summary. It records verified build and Air-gap controls as well as Open and Not Reviewed findings.
The Mission Owner and Authorizing Official must evaluate CICB inside the customer system boundary and determine the evidence required for the authorization package.