DI-MGMT-82139A
Naval Aviation Cyber Table Top (CTT) Report Template
This Data Item Description contains the format and content for the contractor to report results of the Cyber Table Top (CTT) analysis.
Approval DateJuly 28, 2022
AMSC NumberN10337
Preparing ActivityAS
Project NumberMGMT-2022-023
OPR—
DTIC Applicable—
GIDEP Applicable—
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatfree_text
963C CompliantYes
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
This Data Item Description contains the format and content for the contractor to report results of the Cyber Table Top (CTT) analysis.
This DID contains the format, content, and intended use information for the data product resulting from the work task.
This DID supersedes DI-MGMT-82139.
Preparation Instructions
1Referenced Documents.The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as specified in the contract.
1.1NAVAIR Standard Work Package for Cyber Tabletop Assessment Process SWP 51L012 Rev 7 dtd 19 Sep 2016.
1.2NAVAIR Cyber Table Top Handbook Draft Version 1.0 Sep 2016.
2Format.Contractor Format Acceptable.
3Content.The report shall contain the following information and be submitted in the format specified below. This will allow ease of integration with other cyber table top assessments performed in relation to this effort. Each paragraph includes a description of the expected content associated with that particular paragraph. The contractor shall pay close attention to the classification of this analysis and mark the deliverable in accordance with the security marking requirements of the contract.
3.1Executive Summary.Summarize the entire study. Include the purpose for the study, the team members and their roles, the scope of the study, and the study timeframe. Include any rationale for approved (Specify Government POC) tailoring or deviations from the SWP and Table Top Assessment Process. The major findings of the study will likely be classified at the SECRET or higher level, so the findings should only be included if the report is appropriately classified. Also include any considerations, difficulties, compromises, or assumptions that may have significantly impacted the output of the assessment. Finally, include a high-level discussion on the recommendations and mitigation strategies. Ensure portion markings are maintained, especially if an UNCLASSIFIED subset of the Executive Summary is needed for communications at that level. This summary should not be longer than two pages in length.
3.2System Information.This is the formal introduction to the Cyber Table Top (CTT) task at hand. The introduction should contain the following information:
3.2.1A description of the system under review.
3.2.2The system's current position in the acquisition lifecycle.
3.2.3The overall reasons behind conducting a CTT in general.
3.2.4System boundaries included with the scope of the CTT.
3.2.5Results from previous cyber security assessments (if any) that were used to inform this assessment.
3.2.6Recommendations or lessons learned specific to the system under study that will inform upcoming system CTT/Cyber Risk Assessment (CRA), or SETR events.
3.2.7Specific threats included in the CTT and those that are deemed out of scope for the effort
3.3CTT Report information.The output of the CTT should be reported as defined in the two spreadsheets below. See figure 1 and figure 2.
Figures

Figure 1. Cyber Risk Table.xlsx

Figure 2. Cyber Risk Table (cont'd).xlsx
Schema v3.0Community-maintained · Verify against ASSIST