DI-MGMT-82146A
Naval Aviation Government Furnished Property (GFP) and Government Furnished Information (GFI) Cyber Vulnerability Report
This DID provides the format and content for contractors to report newly identified cybersecurity vulnerabilities in Government Furnished Property/Information and recommend remediation.
Approval DateMay 11, 2020
AMSC NumberN10176
Preparing ActivityAS
Project NumberMGMT-2020-013
OPR—
DTIC Applicable—
GIDEP Applicable—
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatfree_text
963C CompliantYes
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
This Data Delivery Item contains the format and content for the contractor to report new cybersecurity vulnerabilities identified in GFP/GFI during execution of the contract. This report also contains a section for contractors to provide recommended hardware/software/firmware changes or methods to remediate found vulnerabilities.
This Data Item Description (DID) contains the format, content, and intended use information for the data product resulting from the work task described in the contract.
Preparation Instructions
1Referenced Documents.The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as specified in the contract.
2Format.Contractor format acceptable.
3Content.The report shall contain the following information:
3.1Government Furnished Property.
3.1.1Provide a description of the GFP item and the functions/tasks the item will perform within the system.
3.1.2Provide a detailed description of the vulnerabilities and the operating conditions that drive the vulnerabilities.Include in the analysis potential cyber risks to the system.
3.1.2.1Provide a top-level description of recommended solution to resolve vulnerability.Include estimated cyber risk after implementation of the proposed solution.
3.1.2.2Include the pros/cons of the recommendation.
3.1.2.3Include other options considered but not chosen and reason for exclusion.
3.1.2.4Include a high/medium/low estimate of time and schedule to implement recommended solution.
3.2Government Furnished Information.
3.2.1Provide a description of the GFI item and the systems/functions impacted.
3.2.2Provide a detailed description of the vulnerabilities and the operating conditions that drive the vulnerabilities.Include in the analysis potential cyber risks to the system.
3.2.2.1Provide a top-level description of recommended solution to resolve vulnerability.Include estimated cyber risk after implementation of the proposed solution.
3.2.2.2Include the pros/cons of the recommendation.
3.2.2.3Include other options considered but not chosen and reason for exclusion.
3.2.2.4Include a high/medium/low estimate of time and schedule to implement recommended solution.
Schema v3.0Community-maintained · Verify against ASSIST