DI-MGMT-82142A
Naval Aviation Cybersecurity Test Report
This Data Item Description contains the format and content for the Cybersecurity (CS) Test Reports (CSTR) used to document results from CS testing.
Approval DateJune 2, 2022
AMSC NumberN10323
Preparing ActivityAS
Project NumberMGMT-2022-016
OPR—
DTIC Applicable—
GIDEP Applicable—
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatfree_text
963C CompliantYes
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
This Data Item Description contains the format and content for the Cybersecurity (CS) Test Reports (CSTR) used to document results from CS testing.
This DID contains the format, content, and intended use information for the data product resulting from the work task described in the contract statement of work (SOW).
This DID supersedes DI-MGMT-82142.
Preparation Instructions
1Referenced documents.The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as specified in the contract.
2Format.Contractor format is acceptable.
3Content.The report shall contain the following:
3.1Identification.This paragraph will contain a full identification of the system to which this document applies, including, as applicable, identification number(s), title(s), abbreviation(s), software version number(s), hardware components, and release number(s).
3.2System overview.State the purpose of the system and the hardware/software to which this document applies. It will describe the general nature of the system; summarize the history of system development, operation, and maintenance; identify the project sponsor, acquirer, user, developer, and support agencies; identify current and planned operating sites; and list other relevant documents.
3.3Document overview.This paragraph will summarize the purpose and contents of this document and will describe any security or privacy considerations associated with its use.
3.4Referenced documents.This section will list the number, title, revision, and date of all documents referenced. This section will also identify the source for all documents not available through normal Government stocking activities.
3.5Overview of test results.This section will be divided into the following paragraphs to provide an overview of test results.
3.5.1Overall assessment of the hardware/software tested.This paragraph will:
3.5.1.1Provide an overall assessment of the system as demonstrated by the test results in this report.
3.5.1.2Identify any remaining deficiencies, limitations, or constraints that were detected by the testing performed.Problem/change reports may be used to provide deficiency information.
3.5.1.3For each important finding, limitation, or constraint, describe:
3.5.1.3.1Its impact on hardware/software and system security posture, including identification of security requirements not met.
3.5.1.3.2The impact on hardware/software and system design to correct it.
3.5.1.3.3A recommended solution/approach for correcting it.
3.5.2Impact of test environment.This paragraph will provide an assessment of the manner in which the test environment may be different from the operational environment and the effect of this difference on the test results.
3.5.3Recommended improvements.This paragraph will provide any recommended improvements in the design, operation, or testing of the hardware/software tested. A discussion of each recommendation and its impact on the system security posture may be provided. If no recommended improvements are provided, this paragraph will state "None."
3.6Detailed test results.This section will be divided into the following paragraphs to describe the detailed results for each test. Note: The word "test" means a related collection of test cases.
3.6.1Project-unique identifier of a test.This paragraph will identify a test by project unique identifier and will be divided into the following subparagraphs to describe the test results.
3.6.1.1Summary of test results.This paragraph will summarize the results of the test. The summary will include, possibly in a table, the completion status of each test case associated with the test (for example, "all results as expected," "problems encountered," "deviations required"). When the completion status is not "as expected," this paragraph will reference the following paragraphs for details.
3.6.1.2Problems encountered.This paragraph will be divided into subparagraphs that identify each test case in which one or more problems occurred.
3.6.2Project-unique identifier of a test case.This paragraph will identify by project unique identifier a test case in which one or more problems occurred, and will provide:
3.6.2.1A brief description of the result(s) that occurred.
3.6.2.2Identification of the test procedure step(s) in which they occurred.
3.6.2.3Reference(s) to the associated problem/change report(s) and backup data, as applicable.
3.6.2.4The number of times the procedure or step was repeated in attempting to correct the problem(s) and the outcome of each attempt.
3.6.2.5Back-up points or test steps where tests were resume for retesting.
3.6.3Deviations from test cases/procedures.This paragraph will be divided into subparagraphs that identify each test case in which deviations from test case/test procedures occurred.
3.6.4Project-unique identifier of a test case.This paragraph will identify by project unique identifier a test case in which one or more deviations occurred, and will provide:
3.6.4.1A description of the result(s) (for example, test case run in which the deviation occurred and nature of the deviation, such as substitution of required equipment, procedural steps not followed, schedule deviations).(Red-lined test procedures may be used to show the deviations).
3.6.4.2The rationale for the deviation(s) if required.
3.6.4.3An assessment of the deviations' impact on the validity of the test case.
3.7Test log.This section will present, possibly in a figure or appendix, a chronological record of the test events covered by this report. This test log will include:
3.7.1The date(s), time(s), and location(s) of the tests performed.
3.7.2The hardware and software configurations used for each test including, as applicable, part/model/serial number, manufacturer, revision level, and calibration date of all hardware, and version number and name for the software components used.
3.7.3The date and time of each test-related activity, the identity of the individual(s) who performed the activity, and the identities of witnesses, as applicable.
3.8Red Lines, Notes and Unplanned Tests.This section will present the tester(s)'s handwritten materials, if applicable, with comments, redlines, unplanned test runs and their results as a scanned in document.
3.9Notes.This section will contain any general information that aids in understanding this document. This section will include an alphabetical listing of all acronyms, abbreviations, and their meanings as used in this document and a list of any terms and definitions needed to understand this document.
3.10Appendices.Appendices may be used to provide information published separately for convenience in document maintenance (e.g., charts, classified data). As applicable, each appendix will be referenced in the main body of the document where the data would normally have been provided. Appendixes may be bound as separate documents for ease in handling. Appendixes will be lettered alphabetically (A, B, etc.).
Schema v3.0Community-maintained · Verify against ASSIST