DI-IPSC-82090C
Software Product Package (SPP)
The Software Product Package provides the procedures and deliverable computer software needed to install software and databases and to build and compile software on target computational devices.
Approval DateMay 11, 2020
AMSC NumberN10175
Preparing ActivityAS
Project NumberIPSC-2020-001
OPR—
DTIC ApplicableNo
GIDEP ApplicableNo
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatfree_text
963C CompliantYes
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
The Software Product Package (SPP) contains the procedures to install the software and databases on devices that stores or processes information. The SPP contains the deliverable computer software along with the associated build and compilation procedures.
This Data Item Description (DID) contains the format, content, and intended use information for the data deliverable resulting from the work task described in the contract.
This DID supersedes DI-IPSC-82090B.
Preparation Instructions
1Reference documents.None.
2Format.The SPP shall be in contractor format.
3Content.The SPP shall contain the required to be delivered computer software to reproduce, recreate, and recompile as defined in DFARS 252.227-7014 and the following information:
3.1Title page.The SPP shall contain a title page identifying the following information, as applicable:
3.1.1Document identification number.
3.1.3Version or Revision indicator.
3.1.4Security classification.
3.1.7Name of the device, computational system, or computer to which this SPP applies.
3.1.8Name of the Software Items (SIs) to which this SPP applies.
3.1.11Organization for which the document has been prepared.
3.1.12Name and address of the preparing organization.
3.1.13Distribution statement.
3.2.1The SPP shall contain a list of all changes incorporated from the prior document submission.
3.3.1The SPP shall contain a table of contents providing the number, title, and page number for each titled paragraph, figure, table, and appendix.
3.4.1Each page shall contain a page number and include the document number, document version, volume, and date.
3.5.1The language style shall be consistent throughout the SPP.Diagrams, tables, and other presentation styles may be substituted for text.
3.6Multiple paragraphs and subparagraphs.
3.6.1Any section, paragraph, or subparagraph may be written as multiple paragraphs or subparagraphs to enhance readability.
3.7.1This paragraph shall briefly state the purpose of the system and the software to which this document applies.
3.8.1This section shall identify the anticipated amount of time required to perform the SPP procedures per computational device, and the anticipated minimum personnel required to perform the procedures in the anticipated timeframe.This section shall describe any special personnel skill-sets and expertise required.
3.9Deliverable Computer Software.
3.9.1This section shall describe the required to be delivered software to include:
3.9.1.1Security Classification.
3.9.1.2Description (name, version, vendor).
3.9.1.3Software Data Rights (restrictions on the government's use, release, or disclosure of the computer software).
3.10Cold Start Procedures.
3.10.1The Cold Start Procedures shall include Installation Procedures, Software Build Procedures and Firmware Configuration Procedures for each delivered computational device that stores or processes data.
3.10.1.1Installation Procedures.
3.10.1.1.1The Installation Procedures shall include:
3.10.1.1.1.1The prerequisite tasks or procedures that must be completed prior to executing the procedures.
3.10.1.1.1.2A list of the physical software media and quantity required to perform the procedures.
3.10.1.1.1.3The procedural steps to format the storage devices(s) prior to performing the procedural steps of loading the application software.
3.10.1.1.1.4The software activation data, such as serial numbers, key codes, and hardware dongles, fobs and keys.
3.10.1.1.1.5The procedural steps to configure the Unified Extensible Firmware Interface (UEFI), Basic Input/Output System (BIOS) and other user configurable firmware from the factory default settings.
3.10.1.1.1.6The procedural steps to restore the entirety of software, such as the operating system, hardware device drivers, computer software, and computer databases to the original delivered configuration without the use of a restoration solution (e.g. use of disk images or pre-built virtual machines) for any computational device that runs noncommercial software.
3.10.1.1.1.7The procedural steps to restore the entirety of software, such as the operating system, hardware device drivers, computer software, and computer databases to the original delivered configuration for any computational device that only runs commercial software.
3.10.1.1.1.8The detailed action to be performed; the expected result(s) following each action; and areas to document abnormalities, discrepancies, errors; and the pass or fail status for each step.
3.10.1.1.1.9Discrete steps to break down and accomplish complex tasks.
3.10.1.1.1.10The procedural steps to configure device computational software with the applicable cybersecurity controls.
3.10.1.1.1.11All of the usernames and passwords.
3.10.1.1.1.12The procedural steps to change all passwords.
3.10.1.1.1.13The procedural steps or reference procedural steps to calibrate the delivered computational device, as applicable.
3.10.1.2Software Build Procedures.
3.10.1.2.1Software Build Procedures shall be included for each computational device that runs noncommercial software that was built from the required to delivered source code.The Software Build Procedures shall include:
3.10.1.2.1.1The procedural steps to build the software (turns source code into executable(s) and library files).
3.10.1.2.1.2The procedural steps for retrieving source code from a Version Control System (VCS) used for tracking source code changes on each applicable computational device, as applicable
3.10.1.3Firmware Configuration Procedures.
3.10.1.3.1Firmware Configuration Procedures shall be included for each device with read-only memories (ROMs), Programmable ROMs (PROMs), and Erasable PROMs (EPROMs).As applicable, the Firmware Configuration Procedures shall include:
3.10.1.3.1.1The prerequisite tasks or procedures that must be completed prior to executing the procedure.
3.10.1.3.1.2The manufacturer and model number of the firmware device.
3.10.1.3.1.3The list of software and files used for programming and reprogramming the firmware device.
3.10.1.3.1.4The description of the equipment to be used for programming and reprogramming the firmware device.
3.10.1.3.1.5The procedural steps to erase load and verify the firmware with the device.
3.10.1.3.1.6The procedural steps or reference procedural steps to calibrate the delivered computational device.
3.10.1.3.1.7The procedural steps to reset the firmware device back to the factory default settings prior to the configuration steps.
3.10.1.3.1.8Backup and restoration of the firmware device configuration.
3.11Warm Start Procedures.
3.11.1As applicable, this section shall include additional procedural steps after the Cold Start Procedures have been successfully performed by the Government or approved by the Government.The Warm Start Procedures shall include:
3.11.1.1The procedural steps to install commercial computer software, noncommercial computer software, and computer databases.
3.11.1.2The detailed action to be performed; the expected result(s) following each action; and areas to document discovered abnormalities, discrepancies, errors; and the pass or fail status for each step.
3.11.1.3Discrete steps to break down and accomplish complex tasks.
3.12.1The scanned results shall contain the previously performed Cold Start Procedures and Warm Start Procedures (as applicable), to include:
3.12.1.1A digital copy of the previously performed procedure with the markings to indicate any abnormalities, discrepancies, errors; and a pass or fail status for each step performed.
3.12.1.2A date and a signature of the person who performed the procedures.
3.13Restoration Solution Procedures.
3.13.1As applicable, this section shall include device specific procedural steps or reference device specific procedural steps to create and restore the entirety of software using a restoration solution (e.g. use of disk images or pre-built virtual machines)
3.14Qualification Provision.
3.14.1This section shall include a data integrity verification checksum for each SI, and procedures to verify those SIs against their respective checksums to confirm the SIs have not been modified after the build procedures were executed.
3.15Transition of Software.
3.15.1This section shall provide information that verifies that all software was registered or transferred to the government with the appropriate activation data, such as serial numbers, key codes, hardware dongles, fobs, and keys.
3.16.1This section shall contain any general information that aids in understanding this document (e.g., background information, glossary, rationale).This section shall include an alphabetical listing of acronyms, abbreviations, and their meanings as used in this document and a list of any terms and definitions needed to understand this document.
3.17.1Appendices may be used to provide information published separately for convenience in document maintenance (e.g., charts, classified data).As applicable, each appendix shall be referenced in the main body of the document where the data would normally have been provided. Appendices may be bound as separate documents for ease in handling. Appendices shall be lettered alphabetically (A, B, etc.).
Schema v3.0Community-maintained · Verify against ASSIST