DI-IPSC-82251A
Software Threat Assessment Report (STAR)
The Software Threat Assessment Report (STAR) documents the results of software threat assessment activities, used as input to risk assessments in the SVAR and SAER.
Approval DateFebruary 11, 2021
AMSC Number10219
Preparing ActivityMDA
Project NumberIPSC-2021-003
OPR—
DTIC ApplicableNo
GIDEP ApplicableNo
Limitation—
Applicable FormsNone
Approval Limitation—
Form Version—
DID Formatfree_text
963C CompliantYes
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Related
DI-IPSC-82252ADI-IPSC-82249ADI-IPSC-82252DI-IPSC-82249DI-IPSC-82250
Application & Interrelationship
—
Use & Relationship
The Software Threat Assessment Report (STAR) documents the results of the threat assessment activities. The STAR is used as input to the risk assessments completed and documented in the Software Vulnerability Assessment Report (SVAR), DI-IPSC-82252A, and the Software Assurance Evaluation Report (SAER), DI-IPSC-82249A.
This DID contains the format, content, and intended use information for the data deliverable resulting from the work task described in the contract. This DID can be used in conjunction with DI-IPSC-82252 and DI-IPSC-82249. This DID supersedes DI-IPSC-82251.
Preparation Instructions
1Reference Documents.The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as specified in the contract.
1.1"(DRAFT) GUIDE TO DATA-CENTRIC SYSTEM THREAT MODELING,"National Institute of Standards and Technology (NIST) Special Publication (SP) 800-154, https://csrc.nist.gov/CSRC/media/Publications/sp/800-154/draft/documents/sp800_154_draft.pdf
1.2"The STRIDE Threat Model,"Microsoft, https://docs.microsoft.com/en-us/previous-versions/commerce-server/ee823878(v=cs.20)?redirectedfrom=MSDN
1.3"Risk Centric Threat Modeling: Process for Attack Simulation and Threat Analysis (PASTA)",Tony UcedaVelez, Marco M. Morana, ISBN: 978-0-470-50096-5, May 2015.
1.4"Threat Modeling: 12 Available Methods,"Software Engineering Institute, Nataliya Shevchenko, https://insights.sei.cmu.edu/sei_blog/2018/12/threat-modeling-12-available-methods.html
1.5"DoD Developer's Guidebook for Software Assurance,"Carnegie Mellon University, Software Engineering Institute (SEI), federally funded research and development center (FFRDC). https://resources.sei.cmu.edu/library/asset-view.cfm?assetid=539177
1.6"Program Manager's Guidebook for Software Assurance,"Carnegie Mellon University, Software Engineering Institute (SEI), federally funded research and development center (FFRDC). https://resources.sei.cmu.edu/library/asset-view.cfm?assetid=538771
1.7"Software Attack Surfaces Analysis Report (SASAR),"DID Number DI-IPSC-82250, https://assist.dla.mil
1.8"Software Assurance Evaluation Report (SAER),"DID Number DI-IPSC-82249, https://assist.dla.mil
1.9"Software Vulnerability Assessment Report (SVAR),"DID Number DI-IPSC-82252, https://assist.dla.mil
1.10"A Threat-Driven Approach to Cyber Security,"(c) 2019 Lockheed Martin Corporation, https://www.lockheedmartin.com/content/dam/lockheedmartin/rms/documents/cyber/LM-White-Paper-Threat-Driven-Approach.pdf
2Format.The report shall be in contractor format unless tailored out in the Contract Data Requirements List (CDRL) (DD 1423).
3.1Reference DocumentsThis section shall list the number, title, revision, and date of all documents referenced in the report. This section shall also identify the source for all documents not available through normal Government stocking activities. The term 'document' in this DID shall mean a collection of data regardless of its medium. The terms "section" and "paragraph" in this DID shall mean their equivalents in a digital format that fulfill the section or paragraph's requirements.
3.2Document Management and Configuration ControlThis section shall identify the version, release date, and other relevant management and configuration control information associated with the current version of the document. A change history, highlighting significant changes from version to version, shall be included.
3.3Table of ContentsThis section shall index all sections, major paragraphs, subparagraphs and appendices with page numbers.
3.4Document ScopeThis section shall be divided into paragraphs covering system and software or Computer Software Configuration Item (CSCI) identification, system overview and document overview.
3.4.1System and Software IdentificationThis section shall contain a full identification of the system and the software or CSCI to which this document applies, including, as applicable, identification number(s), title(s), abbreviation(s), version number(s), and release number(s).
3.4.2System Overview.This section shall briefly state the purpose of the system to which the report applies. It shall describe the general nature of the system and software or CSCI; summarize the history of system development, operation, and maintenance; identify the project sponsor, acquirer, user, developer, and support agencies; identify current and planned operating sites; and list other relevant documents.
3.4.3Document OverviewThis section shall summarize the purpose and contents of the report and shall describe any security or privacy considerations associated with its use.
3.5Software and Firmware Threat Assessment Information SourcesThis section shall identify all sources of information used to support the software threat assessment. Provide a background summary for each information source along with its relevance to the assessment. Leverage all available and relevant public and Gov't information sources to provide the most robust and thorough threat assessment product. Identify the use of threat information sources to account for threats early in the Software Development Lifecycle.
3.5.1Identification of Attack SurfacesThis section shall document or reference all attack surfaces identified and enumerated in the Software Attack Surface Analysis Report (SASAR), DI-IPSC-82250.
3.6Software and Firmware Threat ModelingThis section shall document or reference the threat modeling and associated processes used to decompose the software and firmware, determine and rank threats, and determine countermeasures and mitigations. Common threat models are; Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privileges (STRIDE) Reference b, Process for Attack Simulation and Threat Analysis (PASTA) Reference c, and others outlined in Reference d.
3.7Software and Firmware Threat Analysis ResultsThis section shall document all Software and Firmware Threat Analysis Results, to include the following:
3.7.1All security-relevant information associated with identified software threats, to include threat models, where applicable.
3.7.2Categorization of the threats according to the goals and purposes of the attack based on the employed threat model
3.8Notes.This section shall contain any general information that aids in understanding the report (e.g., background information, glossary, rationale). This section shall include an alphabetical listing of all acronyms, abbreviations, and their meanings as used in the report and a list of any terms and definitions needed to understand the report.
3.9AppendicesAppendices shall provide information published separately for convenience in document maintenance (e.g., charts, classified data, etc.), as necessary. As applicable, each appendix shall be referenced in the report where the data would normally have been provided. Appendices shall be lettered alphabetically (A, B, etc.).
3.9.1Requirements ConflictsDocument any contractor proprietary components that were excluded from this report in an appendix, including proposed resolution thereof.
Schema v3.0Community-maintained · Verify against ASSIST