DI-MGMT-82145A
Naval Aviation Cyber Analysis of Commercial Off-The-Shelf and Non-Developmental Items
This DID specifies the format and content for an analysis demonstrating that COTS and non-developmental items are properly configured, integrated, controlled, and that their unique cyber risks are mitigated.
Approval DateJuly 28, 2022
AMSC NumberN10334
Preparing ActivityAS
Project NumberMGMT-2022-018
OPR—
DTIC Applicable—
GIDEP Applicable—
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatfree_text
963C CompliantYes
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
This Data Item Description (DID) contains the format and content for the analysis that demonstrates commercial off-the-shelf (COTS) and non-developmental items (NDI) are appropriately configured, integrated, software / hardware / firmware is controlled, and any unique risks they pose are mitigated as tailored in the system spec.
This DID contains the format, content, and intended use information for the data product resulting from the work task described in the contract Statement of Work (SOW).
This DID supersedes DI-MGMT-82145.
Preparation Instructions
1Referenced DocumentsThe applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as specified in the contract.
2FormatContractor format is acceptable.
3ContentThe analysis shall contain the following:
3.1Provide a description of the COTS/NDI item and the functions/tasks the item will perform with in the system.
3.2The as-built configuration of the COTS/NDI item as delivered prior to incorporation into the system.This shall include hardware, software, and firmware. Identified cyber risks prior to modification shall also be included.
3.3Provide information on how the COTS/NDI item has been modified and/or configured to meet the needs of the system.Include how these modifications/configuration updates address cyber risks identified in the previous paragraph.
3.3.1Include a recommended future support concept of the COTS/NDI based on modification(s) made.
3.4Include a list and description of unmitigated cyber risks that modifications/configuration updates do not address.
Schema v3.0Community-maintained · Verify against ASSIST