DI-ADMN-80239
Information Systems Accreditation Documentation
This DID establishes the format and content requirements for the information systems accreditation documentation a contractor must prepare per a specific SOW task, in accordance with AR 380-380.
Approval DateSeptember 15, 1986
AMSC NumberA3963
Preparing Activity—
Project Number—
OPRA/ASBH-RMT
DTIC Applicable—
GIDEP Applicable—
Limitation—
Applicable Forms—
Approval Limitation—
Form VersionFEB 85
DID Formatdd_form_1664
963C CompliantNo
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Description & Purpose
3.1. This Data Item Description (DID) identifies the format and content requirements covered by the specific and discrete task for the contractor to prepare this data product identified in the contract Statement of Work (SOW).
3.2. This DID defines the data required to obtain information system accreditation in accordance with AR 380-380, "Automation Security." Regulation can be obtained from: Commander, USAAG Publications Center, 2800 Eastern Blvd., Baltimore, MD 21220-2896.
Application & Interrelationship
7.1. This DID contains the format and content preparation instruction for the data product generated by the specific and discrete task requirement for this data included in the contract.
7.2. This DID is applicable to all information systems as specified in AR 380-380.
7.3. This DID supersedes DI-S-1831.
Preparation Instructions
10.1Contract.This data is generated by the contract which contains a specific and discrete work task to develop this data product.
10.2Content and Format.shall be as described below:
10.2.1Section I - Executive Summary.
10.2.1.1Key Vulnerabilities.A summary of key vulnerabilities identified during the risk analysis process and exceptional circumstances pertaining to operating the system(s) in the facility at the stated level. A discussion of actions taken to minimize these risks must be included along with a description of the exceptional circumstances, if any, justifying operation in this environment.
10.2.1.2Mode of Operation.Describe options and procedures in use at the facility as follows:
10.2.1.2.1Log-on attempts.
10.2.1.2.2Procedures, if processing in a lower sensitivity level.
10.2.1.2.3Major software systems, executive, and applications.
10.2.1.2.4Use of data encryption if any.
10.2.1.2.5Security features.
10.2.1.2.6Use of local nationals.
10.2.1.3Waivers Requested.Identify title, number and date of any waivers granted or requested for the information system.
10.2.2Section II - Accreditation Objective.
10.2.2.1Background.Description of relevant events leading to and the objective of this accreditation; the essential nature of the mission and other factors motivating this accreditation. Other operational alternatives (for example, split system, procurement of separate computer) considered prior to selecting this course of action. Rationale for rejecting other operational alternatives.
10.2.2.2Proposed System Operation.Detailed information concerning features of operational and security modes to be implemented, to include description of system(s) hardware and software, significant applications, and system interfaces.
10.2.3Section III - Risk Management Review.Threat identification (all external and internal threats) will include a detailed vulnerability analysis, risk assessment, and countermeasures associated with each threat.
10.2.4Section IV - Implementation of Security Controls and Countermeasures.
10.2.4.1Security Features.Describe in detail the following in existence:
10.2.4.1.1Security Management.
10.2.4.1.5Communications.
10.2.4.1.8Physical and Environmental.
10.2.4.2Implementation Procedures.Describe recommended countermeasures and alternatives, cost and time estimates to implement these measures, milestones, task interdependencies and initial and final operational capabilities.
10.2.4.3Problem Areas.Identify problems potentially disruptive of system accreditation tasks, processes, and schedules.
10.2.5Section V - System(s) Test and Evaluation (ST&E) Plan.
10.2.5.1Test Requirements.A statement of the purpose, scope, objectives and requirements of the test.
10.2.5.2Test Methodology.Identify the following:
10.2.5.2.1Test method to be used.
10.2.5.2.2Investigative and analytical approaches to be used.
10.2.5.2.3Support requirements, if any.
10.2.6Appendices.The following appendices shall be included:
10.2.6.1Glossary containing a list of abbreviations or terms.
10.2.6.2Additional appendices shall be used to furnish examples, charts, exhibits, flow charts, and scenario(s) that provide additional supportive data.
Schema v3.0Community-maintained · Verify against ASSIST