DI-MGMT-82191
Cybersecurity Vulnerability Report
The Cybersecurity Vulnerability Report provides information on the current state of the network security infrastructure to help understand and improve the security posture.
Approval DateMarch 22, 2018
AMSC NumberN9908
Preparing ActivitySH
Project NumberMGMT-2018-021
OPR—
DTIC Applicable—
GIDEP ApplicableNo
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatfree_text
963C CompliantYes
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
The Cybersecurity Vulnerability Report provides information on the current state of the network security infrastructure. It provides information needed to understand and improve the security posture.
This data item description (DID) contains the format and content preparation instructions for the data product generated by the specific and discrete task requirement as delineated in the contract.
Preparation Instructions
1Format.The Cybersecurity Vulnerability Report shall be in contractor's format.
2Content.The Cybersecurity Vulnerability Report shall include the following:
a) Unmitigated CAT I (High and Critical) - Total
b) Unmitigated CAT I (High and Critical) - Over 30 days
c) Unmitigated CAT II (Medium) - Total
d) Unmitigated CAT II (Medium) - Over 180 days
e) Raw CAT III (Low) - Total
f) Explanation of why remediation was not applied to 100 percent of affected assets for all outstanding open remediation actions.
g) Monthly Asset Discovery Results w/delta
h) All findings open longer than 30 days will be carried over to quarterly Information Security POAM.
2.1POC.Identify Office/Organization responsible for resolving vulnerability.
2.2Additional Resources Requireda) Purchase requirements
b) Additional or shift of manpower
Schema v3.0Community-maintained · Verify against ASSIST