DI-MGMT-82137A
Naval Aviation CYBERSAFE Objective Quality Evidence
This DID contains the format and content for the CYBERSAFE Objective Quality Evidence required by the certifying official to determine if applicable CYBERSAFE requirements have been accomplished.
Approval DateSeptember 12, 2022
AMSC NumberN10345
Preparing ActivityAS
Project NumberMGMT-2022-024
OPR—
DTIC Applicable—
GIDEP Applicable—
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatfree_text
963C CompliantYes
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
This Data Item Description (DID) contains the format and content for the CYBERSAFE Objective Quality Evidence required by the certifying official to determine if applicable CYBERSAFE requirements have been accomplished.
This DID contains the format, content, and intended use information for the data product resulting from the work task.
This DID supersedes DI-MGMT-82137.
Preparation Instructions
1Referenced Documents.The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as specified in the contract.
2Format:Contractor format is acceptable.
3Content:The report shall contain the following:
3.1Objective Quality Evidence (OQE) is required in sufficient detail to support the NAVAIR 4.0P CYBERSAFE certification assessment.Objective Quality Evidence shall include:
3.1.1Cybersecurity and system architecture diagrams, cyberattack surface mapping and analysis, and cyberattack tree analysis.
3.1.2A report, in contractor format, from a Cyber Risk Assessment (CRA) conducted IAW the NAVAIR CRA Standard Work Package (provided as GFI).
3.1.3An analysis of the system design for implementation of the requirements included in the SECNAV CYBERSAFE Instruction (November 2016).
3.1.4An analysis of the system demonstrating a cybersecurity Defense-in-Depth system architecture in accordance with SPAWAR Security Architecture Standards for Defense in Depth Functional Implementation Architecture (DFIA) and with NSA Information Assurance Technical Framework (IATF) Defense-in-Depth Standards.
3.1.5A report detailing an assessment of the system architecture for compliance with NIST SP 800-160 System Security Engineering design principles as tailored by the system requirements and/or statement of work.
3.1.6A cybersecurity risk mitigation plan and recommended countermeasures which reduces identified risks from the CRA (above analyses).
Schema v3.0Community-maintained · Verify against ASSIST