DI-MGMT-81843
Information Assurance (IA) Test Report
The IA Test Report is used by the government to manage Information Assurance testing that results in accreditation of the ship based information technology system.
Approval DateNovember 8, 2011
AMSC NumberN9220
Preparing Activity—
Project Number—
OPRSH/PEO IWS 1.0
DTIC Applicable—
GIDEP Applicable—
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatdd_form_1664
963C CompliantNo
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
The IA Test Report will be used by the government to manage Information Assurance testing that will result in accreditation of the ship based information technology system to comply with Information Assurance policies and criteria.
This Data Item Description (DID) contains the format and content preparation instructions for the data resulting from the work task specified in the contract.
Preparation Instructions
1Format.The IA Test Report shall be presented in the contractor's format.
2Content.The report shall address the following sections:
2.4A description of the system/subsystem being tested.
2.5Threat Model for System Under Test
2.5.1Internal and External IA Threat Exploits
2.5.2Mitigations by Design, Inheritance or Procedure
2.6Security Testing Boundary Diagram
2.7Bill of Materials for Security Testing Boundary
2.8Indicated Network topology with Test Points
2.9Master Network Connection Report (MNCR) for Security Testing Boundary
2.10Identify the applicable DISA approved Test Tools
2.11Assumptions regarding test procedures, test conditions and test environment
2.12Test Point Matrix which shall identify:
2.12.2DISA Approved Test Tool
2.12.3If Test Tool is installed on machine under test
2.12.4A justification for chosen Test Point and Test Tool
2.13Personnel Responsibility Matrix shall identify names, official job titles, and functions and responsibilities.
2.14Security Test Resource shall specify:
2.15Security Testing Schedule shall include:
2.15.2Test Event Activity:
2.15.2.1In-Brief to Site Lead
2.15.2.3Out-Brief to Site Lead
2.15.2.4Secure Assets and Materials
2.15.3Start and End Dates
2.15.4Lead Person for Test Event Activity
2.16Security Test Procedures shall include:
2.16.1The risks and threat levels of the existing security implementations
2.16.2Deviations from the IA Test Plan with Rationale
2.16.3Network discovery procedures via automated tools
2.16.4Operating System discovery procedures via automated tools
2.16.5Discovering ports, protocols and services via automated tools
2.16.6Vulnerability scan via automated tools
2.16.8Application Testing
2.16.9Testing done manually in accordance with the applicable Security Technical Implementation Guide (STIG) used.
2.17Justification for any false positives and the following:
2.17.1Finding Tracking Number
2.17.2Configuration Name and Nomenclature
2.17.3Affected Internet Protocol Address
2.17.5Title of STIG Reference including STIG Version
2.17.6STIG Reference Paragraph
2.17.7Applicable IA Controls specified in DoDI 8500.2
2.17.8Vulnerability Findings
2.17.9Rationale why compliance is not met
2.17.10Severity Risk Rating (Cat I, II, III)
2.17.11Consequence or Impact of vulnerability
2.17.12Recommendation for correcting the findings
2.17.13Engineering Response
2.17.14Estimated Completion Date
2.17.15Status of Fix Verification
3Media Requirement.The electronic media for the IA test report shall be Microsoft Office Word Version 2003-2007.
Figures

Figure 1. Information Assurance Findings Matrix
Schema v3.0Community-maintained · Verify against ASSIST