DI-MGMT-82148A
Naval Aviation Supply Chain Risk Management (SCRM) Subcontractor Analysis
This DID defines the format, content, and intended use of the Naval Aviation Supply Chain Risk Management (SCRM) subcontractor status report on critical component suppliers and threats.
Approval DateAugust 7, 2019
AMSC NumberN10063
Preparing ActivityAS
Project NumberMGMT-2019-021
OPR—
DTIC ApplicableNo
GIDEP ApplicableYes
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatfree_text
963C CompliantYes
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
This Data Delivery Item contains the format, content and is intended use information for the Naval Aviation Supply Chain Risk Management (SCRM) status report.
This DID contains the format, content, and intended use information for the data product resulting from the work task.
This DID supersedes DI-MGMT-82148.
Preparation Instructions
1Referenced DocumentsThe applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as specified in the contract.
1.1Individual program office program protection plan.
1.2National Institute of Standards and Technology (NIST) Special Publication (SP) 800-161, Supply Chain Risk Management (SCRM) Practices for Federal Information Systems and Organizations, April 2015.Copies of this document can be found at https://csrc.nist.gov/publications/detail/sp/800-161/final
2FormatContractor format is acceptable.
3ContentThe report shall contain the following:
3.1Explain criticality analysis process.
3.2Provide a list of critical components.
3.3Provide supplier information for all critical components.
3.4Provide assessment of any threat to critical components from suppliers and indicate countermeasures taken to mitigate the threat(s).
3.5Provide counterfeit prevention plan for protection of critical components.
3.6Specify assurance measures to ensure no malicious intent is designed into critical component.
3.7Describe SCRM security controls implementation per NIST SP 800-161.
4Objective Quality Evidence (OQE)Objective Quality Evidence (OQE) is any statement of fact, either quantitative or qualitative, pertaining to the quality of a product or service based on observations, measurements, or tests which can be verified and is required in sufficient detail to describe the data elements in the Statement of Work.
4.1Distribution Statementas appropriate, in accordance with Department of Defense Instruction (DoDI) 5230.24, Distribution Statements on Technical Documents (Copies of this document can be obtained at: https://www.esd.whs.mil/). Classification markings, as necessary, in accordance with DoD Manual (DoDM) 5200.01, Volume 2, DoD Information Security Program: Marking of Information. (Copies of this document can be obtained at: https://www.esd.whs.mil/).
Schema v3.0Community-maintained · Verify against ASSIST