DI-MGMT-82002B
Cybersecurity Implementation Plan
The Cybersecurity Implementation Plan (CSIP) is used to ensure industry partners are protecting government data as set forth by the Cybersecurity Plan (CSP).
Approval DateFebruary 18, 2021
AMSC NumberN10222
Preparing ActivityAS
Project NumberMGMT-2021-004
OPR—
DTIC ApplicableNo
GIDEP Applicable—
LimitationNone
Applicable FormsCSIP Template
Approval Limitation—
Form Version—
DID Formatfree_text
963C CompliantYes
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
The Cybersecurity Implementation Plan (CSIP) will be used to ensure that industry partners are protecting government data set forth by the Cybersecurity Plan (CSP).
This Data Item Description (DID) contains the format, content, and intended use information for the data product resulting from the work task described by the contract.
This DID supersedes DI-MGMT-82002A.
Preparation Instructions
1Reference Documents.None.
2Format.Contractor's format acceptable.
3Content.The content of the CSIP shall contain the necessary artifacts required by the Authorizing Official (AO), Functional Authorization Official (FAO), or Program Information System Security Manager (ISSM) to successfully assess that industry partners are protecting Government data at the required level set forth by the CSP.
3.1Introduction.This section shall contain a narrative summary of the CSIP.
3.2The content of this Cybersecurity Implementation Planis to document how the contractor proposes to implement the requirements set forth in the Cybersecurity Plan (CSP).
3.3Section "G" Assessment & Authorization and section "Q" Softwaremay require additional documentation to validate the requirements set forth in the "G" and "Q" sections of the CSP per CDRL YYY, Subtitle: Cyber Security System/Software Assurance Report.
3.4.1CYBERSECURITY.Describe how your company plans on addressing Cyber Security (CS) based on Section "A" of the CSP. Address all statements in this section.
3.5.1ARCHITECTURE.Describe how your company plans on addressing Cyber Security based on Section "B" of the CSP. Address all statements in this section.
3.6.1CYBERSECURITY PRACTICES.Describe how your company plans on adhering to Cyber Security practices based on Section "C" of the CSP. Address all statements in this section.
3.7.1PUBLIC KEY INFRASTRUCTURE (PKI).Describe how your company plans on adhering to Cyber Security practices based on Section "D" of the CSP. Address all statements in this section.
3.8.1ELECTRONIC MAIL (E-MAIL).Describe how your company plans on adhering to Cyber Security practices based on Section "E" of the CSP. Address all statements in this section. The goal of this section is to articulate how PKI certificates will be utilized with email programs for digital signature and encryption.
3.9.1DATA AT REST.Describe how your company plans on adhering to Cyber Security practices based on Section "F" of the CSP. Address all statements in this section. List the encryption tools and the encryption methods utilized.
3.10.1ASSESSMENT & AUTHORIZATION (A&A).Describe how your company plans on adhering to CS practices based on Section "G" of the CSP. Address all statements in this section. If an Information Technology (IT) system that includes Platform Information Technology (PIT) systems or a system deemed as a "Control System" is NOT being delivered to the Government, state that fact and mark the section "not applicable".
3.11.1CYBER SECURITY (CS) POINT OF CONTACT (POC)/CYBER SECURITY WORKFORCE (CSWF).Describe how your company plans on adhering to Cyber Security practices based on Section "H" of the CSP. Address all statements in this section. Each CSIP is required to include a CS POC.
3.12.1WEB SITES, ELECTRONIC ROOMS (E-ROOMS), COLLABORATION TOOLS & CLOUD SERVICES.Describe how your company plans on adhering to Cyber Security practices based on Section "I" of the CSP. Address all statements in this section. Web Sites, E-Rooms and other collaboration tools must utilize token based PKI certificates for the authentication of all users. Describe how this will be accomplished. The utilization of "Cloud Services" must contain the following information: cloud service provider, types of data being stored, sensitivity level of data being stored, off-premises connectivity, cloud service model, NIST defined cloud deployment model, security objectives level (categorization), security control baseline applied, physical location of cloud service center, personnel requirements, FEDRAMP information impact level, and any current authorizations. There should also be a network diagram and a cloud configuration diagram. Storage of CUI must utilize Impact Level (IL) 4 NSS data must utilize IL5.
3.13.1COMMON ACCESS CARDS (CAC) & SAAR-N FORMS.Describe how your company plans on adhering to Cyber Security practices based on Section "J" of the CSP. Address all statements in this section.
3.14.1CONTRACTOR OWNED UNCLASSIFIED NETWORK SECURITY.Describe how your company plans on adhering to Cyber Security practices based on Section "K" of the CSP. Address all statements in this section.
3.15.1INFORMATION SECURITY REQUIREMENTS FOR PROTECTION OF UNCLASSIFIED DOD INFORMATION ON NON-DOD SYSTEMS.Describe how your company plans on adhering to Cyber Security practices based on Section "L" of the CSP. Address all statements in this section. Include any company specific policies and SOP's currently in place for achieving this goal.
3.16.1CLASSIFIED SYSTEMS.Describe how your company plans on adhering to Cyber Security practices based on Section "M" of the CSP. Address all statements in this section electronically transmitting classified information. If access to classified information is not a requirement in this contract state that fact and make the section "not applicable".
3.17.1CLASSIFIED SPILLAGES & INFORMATION LEAKAGE.Describe how your company plans on adhering to Cyber Security practices based on Section "N" of the CSP. Address all statements in this section.
3.18.1CLASSIFIED RADIOS & TEMPEST CONTROLS.Describe how your company plans on adhering to Cyber Security practices based on Section "O" of the CSP. Address all statements in this section. If classified radios with TEMPEST controls are NOT being delivered to the Government; state that fact and mark the section "not applicable".
3.19.1PROCUREMENT OF CELLULAR TELEPHONES, PDA'S, AIR CARDS AND CALLING CARDS.Describe how your company plans on adhering to Cyber Security practices based on Section "P" of the CSP. Address all statements in this section.
3.20.1SOFTWARE.Describe in detail how your company plans on adhering to software deliverables based on Section "Q" of the CSP. Address all statements in this section. Ensure that each of the subsections are sufficiently explained to determine a software security posture and baseline.
3.20.1.1Data Input Validation.
3.20.1.2Integrity Checking.
3.20.1.3Software Quality Assurance.
3.20.1.4Supply Chain Management and Software Assurance.
3.21.1MISC.Describe how your company plans to adhere to requirements in Section "R" Misc. of the CSP.
Schema v3.0Community-maintained · Verify against ASSIST