DI-QCIC-81689
Security Verification Plan and Procedures
The Security Verification Plan and Procedures describes tests verifying that cryptographic principles and protective alarms in equipment agree with contract requirements, covering Information Assurance circuitry, verification techniques, and test data parameters.
Approval DateAugust 14, 2006
AMSC Number7604
Preparing Activity—
Project Number—
OPRNS/I312
DTIC Applicable—
GIDEP ApplicableNo
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatdd_form_1664
963C CompliantNo
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
The plan describes a series of tests to verify that cryptographic principles and protective alarms embodied in equipment agree with those stipulated in the contract. It describes the Information Assurance (IA) circuitry and functions incorporated, outlines the proposed verification techniques and procedures to be employed, and identifies the test data parameters to be measured.
This Data Item Description (DID) contains the format and content preparation instructions for the data product generated by the specific and discrete task requirement as delineated in the contract.
This DID is applicable to systems and equipment acquisitions involving cryptographic capabilities.
This DID is related to: DI-QCIC-81690, Security Verification Report; and the Tailored Security Design and Analysis Requirements Specification supplied with the contract.
Preparation Instructions
1Reference DocumentsNone.
2FormatThe plan shall be in contractor's format with the following exceptions:
2.1Page sizeThe size of each finished page shall be on 8 1/2" x 11" paper (metric size A4). Drawing and illustration fold-outs may be used, but must not exceed the 8 1/2" x 11" limits when folded. Photo-reduction of oversized pages is preferred, provided such reductions are easily readable and reproducible.
2.2BindingThe plan shall be bound in such a manner that pages can be removed without damage or mutilation.
2.2.1Change/revision identificationChanges shall be by replacement change pages with revision changes and additions from earlier versions being identified by a solid vertical bar and applicable revision number/letter on the outside page margin. Revision deletions shall be identified by an asterisk and revision code in the outside margin.
3ContentThe plan shall contain front matter and four sections as follows:
3.1.1Cover and Title PageThe following information shall be included on the cover and Title page:
3.1.1.1Plan and Procedures date of issue
3.1.1.2Plan and Procedures document number/revision number or letter
3.1.1.4Contractor name and address
3.1.1.6Program title, including program name and Telecommunications Security (TSEC) Joint Electronic Type Designation (JETDS) number as applicable
3.1.1.7Security classification, if classified
3.1.1.8Distribution statement
3.1.2Revision Control PageThe revision control page shall list the following information:
3.1.2.1Each revision number or letter
3.1.2.2Date of each revision
3.1.2.3Pages affected by each revision
3.1.3Table of ContentsThe table of contents shall identify the following:
3.1.3.1The title and starting page of each major section and paragraph of the plan
3.1.3.2The page, identifying number, and title of each drawing, illustration, figure, and table
3.2Section I, Functional descriptionThe functional description includes a detailed description of critical Information Assurance (IA) circuitry using flow charts, networks, and narrative as appropriate to depict time-referenced signals. The descriptions shall address, as a minimum, the following listed functions, and any others specified in the Functional Security Requirements Specification supplied with the contract. Each description shall be in a context suitable to allow a functional computer simulation specifying as necessary, time-referenced functional signals.
3.2.5Variable load/change/generate
3.2.6Parity check/generate
3.2.11Access Control Mechanisms
3.2.12Digital Signature Verification
3.2.13Integrity Mechanisms
3.2.14Cryptographic Algorithms
3.3Section II, Verification technique descriptionThis section shall describe precisely each proposed test, operation, or technique, which is intended to verify the embodiment, as described, for each specified function contained in Section I. The description shall include, if appropriate:
3.3.1The level of verification (chip, board, box, etc.)
3.3.2Time-referenced functional signals
3.3.4Expected signal response
3.4Section III, Data DescriptionThis section shall include a description of the data, type, format, and signal names to be provided as a result of the verification tests.
3.5Section IV, ProceduresThis section shall include the detailed steps of how each test will be conducted. Each step shall be limited to one simple operation. The procedures should be detailed enough so that a person who is familiar with the test equipment could easily perform the test with these procedures.
Schema v3.0Community-maintained · Verify against ASSIST