DI-MISC-80840B
Preliminary System Security Concept (PSSC)
This DID outlines the format and content of the Preliminary System Security Concept, a contractor-prepared document citing security concepts and requirements for a particular system.
Approval DateMarch 29, 2021
AMSC NumberN10226
Preparing ActivityAS
Project NumberMISC-2021-011
OPR—
DTIC ApplicableYes
GIDEP ApplicableNo
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatfree_text
963C CompliantYes
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
This Data Item Description (DID) outlines the format and content of the Preliminary System Security Concept (PSSC). The PSSC is a document that cites security concepts and requirements relative to a particular system. It is prepared by the contractor to provide the Government with preliminary descriptions of security requirements and resources.
This Data Item Description contains the format and content preparation instructions for data resulting from the work task described by 5.3.1.3 of MIL-HDBK-1785 Department of Defense Handbook: System Security Engineering Program Management Requirements. (Copies of these documents are available online at http://quicksearch.dla.mil.)
This DID supersedes DI-MISC-80840A
Preparation Instructions
1Reference Documents.The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as specified in the contract.
2Format.The PSSC shall be in the contractor's format.
3Content.The Preliminary System Security Concept (PSSC) shall include the following:
3.1.1Title.Include the complete PSSC title.
3.1.2Submitting agency.List the name and address of the contract agency submitting the report and the name and telephone number of a project officer or point of contact.
3.1.3Contract citation.Identify the contract number and date as listed by the Government.
3.1.4Security tasks.Briefly describe major security tasks cited in the statement of work and related contract documents.
3.1.5Distribution.List the name and address of Government and contract agencies receiving copies of the concept. If necessary list them in an appendix and make reference to it.
3.2.1Description.Briefly describe the system and its major components. Cite separate configurations for initial operational capability (IOC) and full operational capability (FOC), if different.
3.2.2Performance requirements.Cite the major performance and deployment criteria listed in the applicable statements of work and other related contract documents which affect security.
3.2.3Reliability and maintainability.Identify security issues affecting system reliability, logistics reliability, availability, and maintainability.
3.2.4System survivability.Show self-protection capabilities or subsystem designs which may enhance security (examples include devices against tampering and spoofing, chemical or biological radiation hardness, nuclear hardness, nuclear and non-nuclear electromagnetic pulse hardness, and use of passive detection technology).
3.2.5Preplanned Product Improvements (P3I).Indicate provisions or security implications for subsystem growth or improvements such as modifications and upgrades.
3.3Security Subsystem Employment Data.
3.3.1General employment description.Indicate how, where, when and what security subsystems will be used and how they will be integrated with the system(s) they support.
3.3.2Command and control structure.Indicate the command and control data that must be exchanged. Explain how security subsystems will be integrated into the command and control structure projected to exist when it is deployed.
3.3.3Information systems.Identify other information that must be exchanged between this subsystem and other systems, subsystems or components. Cite the expected length of each communications link, anticipate flow rate across each link, required availability of each link, etc.
3.3.4Security subsystem standardization, interoperability, and commonality.Indicate requirements for joint service interface, North American Treaty Organization (NATO) cross-servicing and interoperability with existing systems or subsystems. Identify procedural and technical interface standards incorporated in subsystem design.
3.3.5Operational environment.Indicate climatic and atmospheric environmental effects and considerations. If applicable, define the chemical and biological environment in which equipment must function.
3.4Security subsystem support.
3.4.1Maintenance planning.Outline the actions, support and documentation necessary to establish maintenance concepts and requirements. Include maintenance tasks to be accomplished for on- and off-equipment maintenance; interservice, organic and contractor mix, workloads, and time phasing for depot maintenance. Specify the management strategies for selecting and integrating contractor and Government Furnished Equipment (GFE).
3.4.2Manpower and personnel.Outline the projected manpower requirements envisioned to support this subsystem(s). Include type of specialty codes and skill levels required, time phased reporting, etc.
3.4.3Supply support.Show the proposed approach for provisioning initial support and acquiring, distributing, and replenishing spares and repair parts.
3.4.4Support equipment.Identify equipment required to support this subsystem(s). Include ground handling and maintenance equipment, tools, metrology and calibration equipment and related computer hardware and software.
3.4.5Training and training devices.Indicate the training support concept from security subsystem design through deployment. Identify the major command responsible for developing and conducting each phase of training. Show inventory items and training devices by projected type, number, use and locations required. Outline initial and recurring training requirements by location, type, specialty, and fiscal year.
3.4.6Computer resources support.Define special computer program documentation, related software, source data, facilities, hardware, etc. required for subsystem support.
3.4.7Facilities.Specify facility, shelter and housing external to system-designed survivability features.
3.4.8Packaging, handling, storage and transportation.Indicate the requirements, resources, processes, procedures, design considerations, and methods to ensure security subsystems are properly preserved, packaged, handled, and transported.
3.4.9Related support factors.Indicate those pertinent support factors, considerations or requirements not covered elsewhere, but deemed important to the effectiveness of the security subsystem.
3.5General provisions for system security.Address the following security issues relative to overall system deployment and operation.
3.5.1Threat assessment.Address security threats to the system for design, development, production, at IOC and throughout its projected life. Include foreign government capabilities, peace and wartime ground threats, and system-unique vulnerabilities. The threat assessment shall be based on authoritative, government Intelligence Community threat information. Make reference to Government threat documents. In addition, cite requirements for threat analysis and security vulnerability assessments.
3.5.2Procedural requirements.Cite security force and procedural requirements which apply to pre-, trans-, and post-attack operations in support of the Air Force Physical Security Program.
3.5.3Security resources.Cite security manpower, facility and equipment requirements in the quantities, type, and configuration necessary to support the system when deployed.
3.5.4Security response planning.Address emergency security response planning, which reflects the general design of the security force posture calculated to mitigate the greatest vulnerability to terrorism, sabotage, overt and covert attack. It shall be supported by the threat and vulnerability assessments cited in 3.5.1. In addition, indicate how a security reporting and alerting system will be implemented.
3.5.5Security priorities for all applicable systems and components.Include security priorities for all operational phases, including maintenance. For example, aircraft system priorities would include nuclear alert, nonnuclear alert, mission capable, and nonalert. In addition, explain how waivers, exceptions and variances to security criteria will be identified, submitted, approved, and corrected.
3.5.6Security requirements from related security disciplines.Include applicable information security, physical security, computer security, personnel security, product security, industrial security, operations security, communications security, electronic security, survivability, antiterrorism and counter-intelligence aspects.
3.5.7Facility and equipment requirements.Indicate facility and equipment requirements which are incorporated into the system to support system security requirements. These requirements shall include:
3.5.7.1The Central Security Control Facility, Master Surveillance and Control Facility, Security Force Response Facility, entry control facilities, etc.
3.5.7.2Barrier systems and warning signs.
3.5.7.3Alarm communication and display equipment.
3.5.7.4Security force armament and duty equipment.
3.5.7.5Security force communications.Include fixed, portable and landline requirements by type and number.
3.5.7.6Interior and exterior intrusion detection systems.
3.5.8Manpower standard.Identify security force post and patrol requirements for normal operations.
3.5.9Security force logistics.Cite security force logistics and material requirements including vehicles and associated equipment, special purpose equipment, training aids, tool kits, new armament, etc.
3.5.10Entry access controls.Include system entry control requirements for all restricted areas including:
3.5.10.1General criteria and unique requirements for entry control.Include the rate at which individuals must be processed during normal operations, alert operations, and periods of advanced readiness.
3.5.10.2Qualification requirements for the various categories of people who must enter the facility.
3.5.10.3Personnel clearance and investigative requirements.
3.5.10.4Special training or briefing and debriefing requirements.
3.5.10.5Authentication and duress code techniques and procedures.
3.5.10.6Dispatch control procedures for unattended or minimally staffed sites.
3.5.10.7Description of the badge system, emergency procedures, and personnel escort requirements.Include the number of individual names maintained in entry data files.
Schema v3.0Community-maintained · Verify against ASSIST