DI-MGMT-81844
Information Assurance (IA) Test Plan
The IA Test Plan is used by the government to manage Information Assurance testing that results in accreditation of the ship-based information technology system to comply with IA policies and criteria.
Approval DateNovember 8, 2011
AMSC NumberN9221
Preparing Activity—
Project Number—
OPRSH/PEO IWS1.0
DTIC Applicable—
GIDEP Applicable—
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatdd_form_1664
963C CompliantNo
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
The IA Test Plan will be used by the government to manage Information Assurance testing that will result in accreditation of the ship based information technology system to comply with Information Assurance policies and criteria.
This Data Item Description (DID) contains the format and content preparation instructions for the data resulting from the work task specified in the contract.
Preparation Instructions
1Format.The IA Test Plan shall be presented in a format similar to that of Figure 1.
2Content.The plan shall contain the following Sections:
2.4A description of the system/subsystem being tested
2.5Threat Model for System Under Test as it relates;
2.5.1Internal and External IA Threat Exploits
2.5.2Mitigations by Design, Inheritance or Procedure
2.6Security Testing Boundary Diagram
2.7Bill of Materials for Security Testing Boundary
2.8Indicated Network topology with Test Points
2.9Master Network Connection Report (MNCR) for Security Testing Boundary
2.10Identify the applicable DISA approved Test Tools
2.11Assumptions regarding test procedures, test conditions and test environment
2.12Test Point Matrix shall also identify:
2.12.2DISA Approved Test Tool
2.12.3If Test Tool is installed on machine under test
2.12.4A justification for chosen Test Point and Test Tool.
2.13Personnel Responsibility Matrixwhich identifies names, official job titles, and functions and responsibilities.
2.14Security Test Resource that indicates:
2.15Security Testing Schedule that address:
2.15.2Test Event Activity:
2.15.2.1In-Brief to Site Lead
2.15.2.3Out-Brief to Site Lead
2.15.2.4Secure Assets and Materials
2.15.4Start and End Dates
2.15.5Lead Person for Test Event Activity
2.16The Security Test Procedures that address:
2.16.1Determining the risks and threat levels of the existing security implementations
2.16.2Network discovery procedures via automated tools
2.16.3Operating System discovery procedures via automated tools
2.16.4Discovering ports, protocols and services via automated tools
2.16.5Conduct vulnerability scan via automated tools
2.16.7Application Testing
2.16.8Manual testing via applicable Security Technical Implementation Guide (STIG)
2.17Justification for any False Positives
2.18Findings Matrix shall be included in the plan in a format similar of Figure 1and shall also identify the following:
2.18.1Finding Tracking Number
2.18.2Configuration Name and Nomenclature
2.18.3Affected Internet Protocol Address
2.18.5Title of STIG Reference including STIG Version
2.18.6STIG Reference Paragraph
2.18.7Applicable IA Controls from DoDI 8500.2
2.18.8Vulnerability Findings
2.18.9Rationale why compliance is not met
2.18.10Severity Risk Rating (Cat I, II, III)
2.18.11Consequence or Impact of vulnerability
2.18.12Recommendation for correcting the findings
2.18.13Engineering Response
2.18.14Estimated Completion Date
2.18.15Status of Fix Verification
3Media Requirement.The IA Test Plan electronic media shall be Microsoft Office Word Version 2003-2007.
Figures

Figure 1. INFORMATION ASSURANCE FINDINGS MATRIX
Schema v3.0Community-maintained · Verify against ASSIST