DI-MGMT-82135A
Naval Aviation Cybersecurity Risk Management Framework (RMF) Assessment and Authorization Products, and CYBERSAFE Objective Quality Evidence, Assessment & Authorization (A&A) Products
This DID specifies the format, content, and intended use of the Cybersecurity Risk Management Framework (RMF) Assessment and Authorization (A&A) Products provided in support of a program.
Approval DateSeptember 12, 2022
AMSC NumberN10346
Preparing ActivityAS
Project NumberMGMT-2022-025
OPR—
DTIC Applicable—
GIDEP Applicable—
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatfree_text
963C CompliantYes
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
This Data Item Description (DID) contains the format, content and intended use for the Cybersecurity Risk Management Framework (RMF) Assessment & Authorization (A&A) Products to be provided in support of the (state your program name).
This DID contains the format, content, and intended use information for the data product resulting from the work task.
This DID supersedes DI-MGMT-82135.
Preparation Instructions
1Referenced documents.The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as specified in the contract.
1.1DoDI 8500.01, available at https://www.esd.whs.mil/Directives/issuances/dodi/
1.2DoDI 8510.01, available at https://www.esd.whs.mil/Directives/issuances/dodi/
2Format.Contractor's Format Acceptable.
3Content.The following products shall be provided in support of RMF A&A IAW DoDI 8500.01 and DoDI 8510.01. The provided products will be incorporated by the Government into the overall air system A&A package. Products shall be classified IAW the (Program Name) Security Classification Guide provided as Government Furnished Information (GFI).
3.1RMF System Security PlanThe Security Plan describes the security controls in place or planned for meeting cybersecurity requirements. The security plan will include expected implementation status, current implementation status, responsible entities, resources, and estimated completion dates. The Security Plan will also include a compiled list of system characteristics or qualities required for system registration (if required), key security-related documents such as a risk assessment, privacy impact assessment, system interconnection agreements, contingency plan, security configurations, configuration management plan, software lists, and hardware list.
Reference the draft System Security Plan document provided as GFI.
3.2Security Assessment PlanFor content, reference the following documents provided as GFI:
3.2.1National Institute of Standards and Technology Special Publication 800-53A"Guide for Assessing the Security Controls in Federal Information Systems and Organizations: Building Effective Security Assessment Plans"
3.2.2Security Assessment Plan TemplateThe template includes information related to test objectives; schedule; limitations; personnel; related tests; location; equipment; configurations; satisfactory/unsatisfactory criteria; entrance/exit criteria; logistics; qualifications/certifications; security considerations; and test procedures.
3.3Risk Assessment Report (RAR)The focus of a risk assessment is to determine if there is residual risk associated with the security controls found to be non-compliant during the contractor's assessment, leaving vulnerability. The Risk Assessment Report is used to capture any findings that will not be corrected prior to the control assessment in the Assess Phase and to communicate the contractor's risk assessment results to the Government to inform the final air system RMF authorization. Reference the GFI document "USN RMF RAR" for further content guidance.
3.4Plan of Action and Milestones (POA&M)The POA&M addresses all vulnerabilities identified during the contractor's security control assessment. It will include:
3.4.1Identify tasks that need to be accomplished to remediate or mitigate vulnerabilities.
3.4.2Specify resources required to accomplish the elements of the planned tasks.
3.4.3Include milestones for completing tasks and their scheduled completion dates.
3.5Security Assessment ReportThe output and end result of the security control assessment is the security assessment report, which documents the assurance case for the system and is one of three key documents in the security authorization package developed by system owners and common control providers for authorizing officials. The security assessment report to be provided per this CDRL includes the Contractor's assessment of the findings to determine the effectiveness of the security controls employed within or inherited by the system. The security assessment report will include an assessment summary from the detailed findings that are generated during the security control assessment. The assessment summary will provide an abbreviated version a of Security Assessment Report focusing on the highlights of the assessment, synopsis of key findings, and/or recommendations for addressing weaknesses and deficiencies in the security controls. The following elements are included in security assessment reports:
3.5.2Security categorization;
3.5.3Site(s) and/or systems assessed and assessment date(s);
3.5.4Assessor's name/identification;
3.5.5Previous assessment results (if reused);
3.5.6Security control or control enhancement designator;
3.5.7Selected assessment methods and objects;
3.5.8Depth and coverage attributes values;
3.5.9Assessment finding summary (indicating satisfied or other than satisfied);
3.5.10Assessor comments (weaknesses or deficiencies noted); and
3.5.11Assessor recommendations (priorities, remediation, corrective actions, or improvements).
3.6Information System Continuous Monitoring Strategy (ISCM)The ISCM Strategy describes the system including the continuous monitoring requirements, system architecture, and interfaces. The ISCM Strategy also identifies key personnel, continuous monitoring tools, supporting processes, communication plan, and the continuous improvement plan.
Schema v3.0Community-maintained · Verify against ASSIST