DI-MGMT-82144A
Program Protection Implementation Plan
The Program Protection Implementation Plan documents the contractor's approach to implementing the Program Protection Plan by describing how Critical Program Information will be identified and protected.
Approval DateJuly 28, 2022
AMSC NumberN10335
Preparing ActivityAS
Project NumberMGMT-2022-021
OPR—
DTIC Applicable—
GIDEP Applicable—
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatfree_text
963C CompliantYes
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
This report is meant to be used in identification of the approach to Implementing the Program Protection Plan (PPP.) The Program Protection Implementation Plan (PPIP) is derived from the PPP and will not restate what is written in the PPP.
This DID contains the format, content, and intended use information for the data product resulting from the work task described in the contract SOW.
Preparation Instructions
1Reference documents.None.
2Format.The Program Protection Implementation Plan shall be in contractor's format.
3Content.The Contractor's PPIP shall contain the following:
3.1A section detailing the Contractors approach to implementing the PPP.
3.2Critical Program Information (Critical Components (CC) / Critical Program Information (CPI) / Critical Systems (CS) / Critical Technologies, (CT) hereafter identified as CPI.
3.3The Contractor's process for identifying any existing / proposed CPI during developmental and RDT&E phases, and its protection / identification in the ECP process prior to ECP acceptance by the Government.
3.4A section describing an effective and efficient protection of CPIwhich will include the following:
3.4.1The Contractor's Program Security / OPSEC Management structure, including relationships with the corporate hierarchy and program subcontractors and suppliers.
3.4.2An overview of all Contractor's activities, operations, tests, and other associated activities to be undertaken in performance of the contract; identifying those in which CPI could manifest itself; and when the CPI is embodied in the hardware, software or operations.
3.4.3Identification of the CPI physical locations under the Contractor's or its subcontractors' control and how the CPI is to be managed / tracked / secured throughout the CPIs life-cycle.
3.4.4An Assessment of the vulnerability of the CPI to intelligence collection in the following areas: Human Intelligence (HUMINT), Open Source Intelligence (OSINT), Signals Intelligence (SIGINT), Imagery Intelligence (IMINT), and Computer Network Operations (CNO).
3.4.5Identification of the planned countermeasures at each site where CPI is utilized /secured from the following security domains: Physical security; personnel security; telecom and network security, application, systems development, cryptography, and security architectures.
3.4.6All special handling procedures required for CPIAll special handling procedures required for CPI, and procedures for recovering CPI in the event of a mishap; address these procedures for all phases of the program, including: Program / System Technology Development, System Development & Demonstration, RDT&E, Production Deployment, Operations, Maintenance, Logistics, Transportation, Training, and Disposal under this contract for which the Contractor has control.
3.4.7A Description of how the Contractor will comply with procedures for ensuring compliance with U.S. Government export statutes and regulations that affect CPI in a contracted program.
3.4.8A Description of the Contractor's procedures for public release of program information.
3.4.9A Description of the Contractor's Information Security Program (ISP) as a part of their PPIP.As an integral part of the ISP, describe the Contractor procedures for identifying, reporting and resolution of Facility Security Breaches; Classified Information Compromises, and Spillages including notification of DSS, DCMA, and Government Program Security Manager within the constraints specified in the Contract.
3.4.10Describe how Security classification guidance and original classification authority (OCA) for DIB information will be developed in order to mitigate risks to critical DoD unclassified information supporting present and future DoD warfighting capabilities and residing on, or transiting, the Contractors / Subcontractors private networks.
3.4.11Describe how the contractor's Defense Industrial Base (DIB) Cyber Security is addressed in the contractor's facility and addressed in subcontracts and how incidents are addressed and reported to DSS / DCMA.Describe how Framework Agreements and contracts include DIB cyber security requirements for safeguarding DoD classified and unclassified information. DIB participants will handle classified and sensitive unclassified information, such as controlled unclassified information (CUI) (which includes For Official Use Only (FOUO) information); CPI (as described in DoDI 5200.39, as required by law and regulation, the Framework Agreement, contracts.
3.5Supply Chain Risk Management (SCRM)Only include if SCRM not addressed in separate DID.
3.5.1The Supply Chain Risk Management (SCRM) portion of the PPIPThe Supply Chain Risk Management (SCRM) portion of the PPIP will include the establishment of a SCRM program tailored to fit the contractor's acquisition program identifying how supply chain risks are addressed across the entire system lifecycle through a defense-in breadth approach to managing the risks to the integrity of information and communications technology (ICT) within covered systems.
3.5.2The PPP requires the contractor to establish policy and a defense-in-breadth strategy for managing supply chain risk to information and communications technology (ICT) within DoD critical information systems and weapons systems and describe in the PPIP.The PPIP SCRM section will address the following elements / requirements:
3.5.2.1Incorporation of all-source intelligence analysis into assessments of the supply chain for covered systems.
3.5.2.2Processes to control the quality, configuration, and security of software, hardware, and systems throughout their lifecycles, including components or subcomponents from secondary sources.
3.5.2.3Processes to detect the occurrence, reduce the likelihood of occurrence, and mitigate the consequences of products containing counterfeit components or malicious functions.
3.5.2.4Processes to ensure that the fabrication of integrated circuits that are custom-designed and / or custom-manufactured (generally referred to as "application-specific integrated circuits") for a specific DoD end use within covered systems are, as appropriate to the risk, performed by suppliers of integrated circuit-related services accredited through an authority designated by the Under Secretary of Defense for Acquisition, Technology, and Logistics (USD(AT&L)), unless expressly waived by the Milestone Decision Authority (MDA) established pursuant to DoDD 5000.01.
3.5.2.5Describe how the contractor will report via Government Industry Data Exchange Program GIDEP Counterfeit / malicious modified parts.
3.6The OPSEC portion of the PPIP will include establishment of an OPSEC support capability that provides for program development, planning, training, assessment, surveys, and readiness training.Including the results of the five-step OPSEC analysis Identifying CPI; Analyzing Threats, Analyzing Vulnerabilities, Assessing Risk, and Applying Countermeasures, including those aspects of the foreign intelligence threat that are applicable to the specific contract, only use if no separate OPSEC deliverable is required elsewhere. The following will be addressed:
3.6.1GeneralDetails of the OPSEC management concept to include contract identification, assignment of responsibilities, definition of milestones with target dates, provisions for continuous analysis, and how periodic revision as the contract activities evolve and become more specific and detailed.
3.6.2ThreatThe known threats to the contracting activity and include only that portion deemed applicable to the specific contract activities in addition to how threats will be mitigated.
3.6.3Sensitive Aspects of the ContractAn overview of all activities, operations, tests, etc. to be undertaken in performance of the contract; identifying those in which classified information will manifest itself; identify the topics of the classification guide that specify the information that is classified; determine how, where, and when the classified information is embodied in the hardware, software or operations; determine what type access (visual, physical) permits knowledge of the classified information, what tools / equipment / capability are required, and the specific national defense advantage provided by that information if it is protected. Use of electromechanical equipment is an operation that will be included, as are subcontracting, hardware-in-the-loop testing, calibration and check-out, fabrication, static tests, breadboard and brass board fabrication and testing, and laboratory experiments. A list of critical information, based on the above analysis, will include all the information considered essential to the success of the effort, and all the information that must be protected to preserve the military advantage potentially provided by the effort. Additionally, the list will include all the activities, operations, and tests that could reveal the "critical" information to foreign intelligence.
3.6.4CountermeasuresThe unacceptable risks of vulnerabilities identified above will include; the protective measures deemed appropriate to negate or reduce the potential damage to the project.
3.6.5Organizational OPSEC Communications and InterfacesA description as to how the Plan will be communicated to personnel supporting the program.
3.6.6The Plan will identify all OPSEC interfaces internal to the corporation such as Senior Corporate Leadership, OPSEC Working Group, OPSEC Coordinators, and program personnel.
3.6.7The Plan will identify all external points of contact; Contracting activity, Defense Contract Management Agency (DCMA), defense Security Service (DSS), Federal Bureau of Investigation (FBI) and local Law Enforcement.The Plan will identify the contacts primary role within the OPSEC program. Subcontractor and supplier OPSEC points of contact will be similarly identified.
3.6.8The categories of Potential Critical Information (CI) that will be protected and planned for in the PPIP as defined in the GFI PPP, or if additional CPI as defined by the contractor design.
3.6.9Describe how the contractors Defense Industrial Base (DIB) Cyber Security and Information Assurance (CS / IA) Program is addressed in the Contractors facility; and also addressed in subcontracts and how incidents are addressed and reported.Framework Agreement and contracts that contain DIB cyber security requirements, for safeguarding DoD classified and unclassified information. DIB participants will handle classified and sensitive unclassified information, such as controlled unclassified information (CUI) (which includes Unclassified//For Official Use Only (FOUO) information), CPI.
3.6.10Describe how the contractors Counterintelligence Awareness and Reporting (DoDD 5240.06) Program is addressed in the Contractors facility; and the contractors plan to comply with the training and reporting requirements of the above reference document.
3.7Describe how the contractor will protect Anti Tamper (AT) Plans and associated information as defined in the GFI ATP, or if additional requirements are identified as defined by the contractor design.
3.8Describe the contractor's approach for implementing the following System Security Engineering (SSE) processes:
3.8.1Assessment of security architecture, threats, and vulnerabilities.
3.8.2Threats, vulnerabilities, risk, and countermeasures analysis.
3.8.3Computing environment assessment.
3.8.4Security testing, disaster recovery, incident response plan/procedures.
3.8.5Ports and protocol analysis during systems upgrade/design and development.
3.9Describe contractor's system security design considerations including specific system capabilities for robust survival against possible sources of disruption.
Schema v3.0Community-maintained · Verify against ASSIST