DI-MGMT-81845
Information Assurance (IA) Design Review Information Package (DRIP)
The IA Design Review Information Package (DRIP) is used by the government to review the Defense in-Depth (DiD) design and support the Platform Risk Assessment (PRA) of the ship.
Approval DateNovember 8, 2011
AMSC NumberN9222
Preparing Activity—
Project Number—
OPRSH/PEO IWS 1.0
DTIC Applicable—
GIDEP Applicable—
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatdd_form_1664
963C CompliantNo
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
The Information Assurance (IA) Design Review Information Package (DRIP) will be used by the government to review the Defense in-Depth (DiD) design and support the Platform Risk Assessment (PRA) of the ship.
This Data Item Description (DID) contains the format and content preparation instructions for the data product generated by the specific and discrete task requirement delineated in the contract.
Preparation Instructions
1Format.The IA DRIP shall be presented in format similar to that of Figures 1 through 7.
2Content.The IA DRIP workbook shall contain updatable tables for the each section.
2.1Executive Summary, Section 1.This section shall contain all of the information specified in figure 1 and shall also identify following:
2.1.1System description and purpose.
2.1.2Mission Assurance Category per DoDI 8500.2
2.1.3Security Classification.
2.1.4Security Mode of Operation.
2.2Information Assurance Certification and Accreditation (IA C&A) Boundary, Section 2.This section shall be presented in a format similar to that of Figure 2 and shall contain the following headings:
2.2.1Schematic Interface Diagram placed above the headings showing:
2.2.1.2Information Assurance defense points including:
2.2.2Nomenclature name of each subsystem within IA C&A Boundary
2.2.3Functional description of each subsystem within IA C&A Boundary
2.2.4Description of User Roles and Privileges of each subsystem within IA C&A Boundary
2.2.5Technical Cyber Defense Mitigation in each subsystem within IA C&A Boundary
2.2.6Critical Protected Information (CPI) of each subsystem within IA C&A Boundary(CPI provided as a classified attachment)
2.3System Requirements Verification Matrix (IA SRVM), Section 3.This section shall be presented in a format similar to that of Figure 3 and shall also contain the following headings:
2.3.1Applicable DoDI 8500.2 IA Controls
2.3.2Software Requirement Specifications (SRS)
2.3.3System Subsystem Specifications (SSS) to illustrate how the Defense in-Depth (DiD) design meets the IA Controls.
2.4The IA MNC section shall be presented in a format similar to that of Figure 4 and shall also contain the following headings:
2.4.1Date of data entry into the MNC
2.4.2Description of function provided by or supported by connection
2.4.3Reference Application Programming Interface (API) specification
2.4.5IP of the Data Source device transmitting data
2.4.8Hostname of the Data Source device transmitting data
2.4.9Classification of the Data Source device transmitting the data
2.4.10Classification of the actual data being transmitted
2.4.11Network Data Transfer Protocol used to transmit the data
2.4.12Data Delivery Type: Bi-Directional, Uni-Directional or Multicast
2.4.13IANA Port Number assigned to transmit the data
2.4.14Service daemon transmitting the data
2.4.15Is Port, Protocol and Service approved by DISA (Yes or No)
2.4.16Data encryption standard used
2.4.17Is Data Source device inside the IA C&A Boundary (Yes or No)
2.4.18IP of the Data Sink/Destination device receiving transmitted data
2.4.19Hostname of the Data Sink/Destination device receiving data
2.4.20Classification of the Data Sink/Destination device receiving data
2.4.21Is Data Sink/Destination device within IA C&A Boundary (Yes or No)
2.4.22The Information Assurance-Master Network Connection (IA MNC), Section 4.This section shall contain the basis for building Access Control Lists (ACLs) in accordance with the following DODI 8500.2 IA Controls:
2.4.22.1DCPP-1 Ports, Protocols, and Services
2.4.22.2DCFA-1 Functional Architecture for AIS Applications,
2.4.22.3DCFA-1 Functional Architecture for AIS Applications,
2.4.22.4DCID-1 Interconnection Documentation and
2.4.22.5ECIC-1 Interconnections Among DoD Systems and Enclaves.
2.4.23The IA-MNC section shall identify changes when made to the network connections in system upgrades or Engineering Change Proposals (ECPs).
2.4.24The IA-MNC section shall identify all network connections that route to, from, through and across the networked subsystems within the Information Assurance Certification and Accreditation (IA C&A) boundary.
2.4.25The IA-MNC section shall specify the network connections for capabilities and functions performed within the Information Assurance boundary "the enclave".
2.5Common Assurance System Architecture (CASA) Section 5.This section shall be presented in format similar to that of Figure 5 and shall contain the following headings:
2.5.1Incident Alert Categories
2.5.2Incident Alert Conditions
2.6Threat Model for IA C&A Boundary, Section 6.This section shall be in presented in format similar to that of Figure 6 and shall contain:
2.6.1Internal and External IA Threat Exploits
2.6.2Technical and Logical Mitigations
2.6.3Mitigation by Design, Inheritance or Procedure
2.7Applicable STIGS for IA C&A Boundary, Section 7.This section shall be in presented in format similar to that of Figure 7 and shall contain:
3Media Requirement.The electronic media for the IA DRIP package shall be Microsoft Excel, Version 2003-2007.
Figures

Figure 1. Executive Summary - Design Review Information Package

Figure 2. Information Assurance Certification and Accreditation (IA C&A) Boundary

Figure 3. Information Assurance (IA) System Requirements Verification Matrix (SRVM)

Figure 4. Information Assurance Master Network Connection Report (IA-MNCR)

Figure 5. Common Assurance System Architecture (CASA)

Figure 6. Threat Model

Figure 7. Applicable STIGS
Schema v3.0Community-maintained · Verify against ASSIST