DI-IPSC-82252A
Software Vulnerability Assessment Report (SVAR)
The SVAR documents the results of software assurance activities including threat assessment, attack surface analysis, testing, supply chain risk management, and vulnerability and risk assessment, concluding with plans of action and milestones to mitigate risks to an acceptable level.
Approval DateFebruary 11, 2021
AMSC Number10220
Preparing ActivityMDA
Project NumberIPSC-2021-004
OPR—
DTIC ApplicableNo
GIDEP ApplicableNo
Limitation—
Applicable FormsNone
Approval Limitation—
Form Version—
DID Formatfree_text
963C CompliantYes
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
The Software Vulnerability Assessment Report (SVAR) documents the results of software assurance activities from: threat assessment; attack surface analysis; static, dynamic, manual testing; supply chain risk management; vulnerability and risk assessment; and concludes with plans of action and milestones to mitigate risks to an acceptable level.
This DID contains the format, content, and intended use information for the data deliverable resulting from the work task described in the contract. This DID supersedes DI-IPSC-82252.
Preparation Instructions
1Reference Documents.The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as specified in the contract.
1.1DoD Developer's Guidebook for Software Assurance,Carnegie Mellon University, Software Engineering Institute (SEI), federally funded research and development center (FFRDC). https://resources.sei.cmu.edu/library/asset-view.cfm?assetid=539177
1.2Program Manager's Guidebook for Software Assurance,Carnegie Mellon University, Software Engineering Institute (SEI), federally funded research and development center (FFRDC). https://resources.sei.cmu.edu/library/asset-view.cfm?assetid=538771
1.3Software Assurance Evaluation Report (SAER),DID Number DI-IPSC-82249, https://assist.dla.mil
1.4DoD Risk Management Framework (RMF) Knowledge Service,https://rmfks.osd.mil/rmf/Pages/default.aspx
2Format.The report shall be in contractor format unless tailored out in the Contract Data Requirements List (CDRL) (DD 1423).
3Content.This section shall be divided into paragraphs, as needed, to establish the context for the content described in later sections. "The term 'document' in this DID shall mean a collection of data regardless of its medium. The terms "section" and "paragraph" in this DID shall mean their equivalents in a digital format that fulfill the section or paragraph's requirements."
3.1Reference DocumentsThis section shall list the number, title, revision, and date of all documents referenced in the report. This section shall also identify the source for all documents not available through normal Government stocking activities.
3.2Document Management and Configuration ControlThis section shall identify the version, release date, and other relevant management and configuration control information associated with the current version of the document. A change history highlighting significant changes from version to version, shall be included.
3.3Table of ContentsThis section shall index all sections, major paragraphs, subparagraphs and appendices with page numbers.
3.4Document ScopeThis section shall be divided into paragraphs covering system and software or Computer Software Configuration Item (CSCI) identification, system overview and document overview.
3.4.1System and Software or Computer Software Configuration Item (CSCI) IdentificationThis section shall contain a full identification of the system and the software or Computer Software Configuration Item (CSCI), to which this document applies, including, as applicable, identification number(s), title(s), abbreviation(s), version number(s), and release number(s).
3.4.2System Overview.This section shall briefly state the purpose of the system to which the report applies. It shall describe the general nature of the system and software or CSCI; summarize the history of system development, operation, and maintenance; identify the project sponsor, acquirer, user, developer, and support agencies; identify current and planned operating sites; and list other relevant documents.
3.4.3Document OverviewThis section shall summarize the purpose and contents of the report and shall describe any security or privacy considerations associated with its use.
3.5Software OverviewThis section shall provide an overview description of the software or Computer Software Configuration Item (CSCI) pertaining to the vulnerability analysis.
3.6Risk Management Framework (RMF)This section shall document the RMF categorization, data types, and include a RMF control matrix showing compliance status for each RMF control, Reference d.
3.7Software Operational EnvironmentThis section shall identify the software operational environment (e.g., Defense System component, Research, Test, Development, Maintenance, Training & Planning, or Enterprise Business).
3.8Software ArchitectureThis section shall provide an overview the software architecture including system, software, or Computer Software Configuration Item (CSCI) boundaries and interfaces.
3.9Cybersecurity Functional PropertiesThis section shall provide a description of the cybersecurity functional properties of the software or firmware to be employed (e.g., identification, authorization, access controls, encryption, logging, data marking, fail-over and recovery, etc.).
3.10Non Developmental Item (NDI) SoftwareThis section shall identify all NDI software, including Bill-of-Materials of the 3rd party Commercial-off-the-Shelf(COTS), Government-off-the-Shelf (GOTS), and Open Source Software (OSS) used within the software.
3.11Methods and ProcessThis section shall be divided into paragraphs, as needed, to establish the engineering methods, development processes, testing and evaluation techniques, quality control process, and program roadmap described in later sections.
3.11.1Software Security Engineering MethodsThis section shall provide a brief description of the software security engineering methods associated with the system software under vulnerability assessment.
3.11.2Software Development ProcessThis section shall provide a brief description of the software development process for the developed software under vulnerability assessment.
3.11.3Testing and Evaluation TechniquesThis section shall provide a brief description of the software or Computer Software Configuration Item (CSCI) test, evaluation and validation techniques associated with the system software under vulnerability assessment.
3.11.4Quality Control ProcessesThis section shall provide a brief description of the quality control processes associated with the system software under vulnerability assessment.
3.11.5Program RoadmapThis section shall provide a brief description of the program roadmap associated with the vulnerability assessment of the system software.
3.12Software Assurance Residual Risk AssessmentThis section shall be divided into paragraphs, as needed, to establish the software assurance residual risk assessment described in later sections.
3.12.1SAERs for Developed SoftwareThis section shall provide a consolidated summary of Software Assurance Evaluation Reports (SAER) associated with results of static, dynamic, and manual software analyses of all developed software.
3.12.2SAERs for NDI SoftwareThis section shall provide a consolidation summary of NDI software SAERs on all applicable 3rd party COTS, GOTS, and OSS SAERs.
3.12.3SAER and RMFThis section shall provide a system level residual risk assessment from all SAER, Reference c, results into an RMF Control Matrix, Reference d showing compliance status for each RMF control.
3.12.4Plan of Actions and Milestones (POAM)This section shall include in an appendix to the report a POAM addressing all non-compliant RMF Controls. Each item in the POAM shall have a description of the residual risk, the mitigation, the resources needed and timeline to be completion.
3.13Notes.This section shall contain any general information that aids in understanding the report (e.g., background information, glossary, rationale). This section shall include an alphabetical listing of all acronyms, abbreviations, and their meanings as used in the report and a list of any terms and definitions needed to understand the report.
3.14AppendicesAppendices shall provide information published separately for convenience in document maintenance (e.g., charts, classified data, etc.), as necessary. As applicable, each appendix shall be referenced in the main body of the report where the data would normally have been provided. Appendices shall be lettered alphabetically (A, B, etc.).
3.14.1Requirements ConflictsDocument any contractor proprietary components that were excluded from this report in an appendix, including proposed resolution thereof.
Schema v3.0Community-maintained · Verify against ASSIST