DI-QCIC-81690
Security Verification Report
The Security Verification Report documents test results verifying that cryptographic principles and protective alarms in equipment meet contract requirements, supporting Government decisions on item acceptance or further development.
Approval DateAugust 14, 2006
AMSC Number7605
Preparing Activity—
Project Number—
OPRNS/I312
DTIC ApplicableNo
GIDEP ApplicableNo
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatdd_form_1664
963C CompliantNo
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
The report contains the results of tests to verify that cryptographic principles and protective alarms embodied in equipment agree with those stipulated in the contract. It describes the tests performed and compares the results with contract performance requirements. It is used by the Government to support decisions on item acceptance or future developmental and testing requirements.
This Data Item Description (DID) contains the format and content preparation instructions for the data product generated by the specific and discrete task requirement as delineated in the contract.
This DID is applicable to systems and equipment acquisitions involving cryptographic capabilities.
This DID is related to DI-QCIC-81689, Security Verification Plan and Procedures and to the Tailored Security Design and Analysis Requirements Specification that is supplied with the contract.
Preparation Instructions
1Reference Documents.None.
2Format.The report shall be in the contractor's format with the following exceptions:
2.1Page size.The size of each finished page shall be on 8 1/2" x 11" paper (metric size A4). Drawing and illustration foldouts may be used, but must not exceed the 8 1/2" x 11" limits when folded. Photo-reduction of over-sized pages is preferred, provided such reductions are easily readable and reproducible.
2.2Binding.The plan shall be bound in such a manner that pages can be removed without damage or mutilation.
2.3Change/revision identification.Changes shall be by replacement change pages with revision changes and additions from earlier versions being identified by a solid vertical bar and applicable revision number/letter on the outside page margin. Revision deletions shall be identified by an asterisk and revision code in the outside margin.
3Content.The report shall contain the following:
3.1.1Cover and title page.The following information shall be included on the cover and title page:
3.1.1.2Report document number/revision number or letter.
3.1.1.4Contractor name and address.
3.1.1.7Program title, including program name and Telecommunications Security (TSEC) Joint Electronic Type Designation System (JETDS) number as applicable.
3.1.1.8Security classification, if classified.
3.1.1.9Distribution statement.
3.1.2Revision control page.The revision control page shall list the following information:
3.1.2.1Each revision number or letter.
3.1.2.2Date of each revision.
3.1.2.3Pages affected by each revision.
3.1.3Table of contents.The table of contents shall identify the following:
3.1.3.1Title and starting page of each major section and paragraph of the report.
3.1.3.2Page, identifying number, and title of each drawing, illustration, and figure.
3.2Introduction.The introduction shall include the following:
3.2.1Purpose of test (as specified in the contract tasking document).
3.2.2Item tested.The items tested section shall include the following:
3.2.2.1The equipment nomenclature, including TSEC JTEDS number, if applicable.
3.2.2.2Functional description of the equipment.This includes a detailed description of critical Information Assurance (IA) circuitry using flow charts, networks, and narrative as appropriate to depict time-referenced signals.
3.2.3Test requirements.The test requirements shall include the following, relating each to the prescribing contract requirement paragraph (specification, standard, plan, or work statement).
3.2.3.1Required tests and parameters to be measured.
3.2.3.2Performance requirements, acceptance or compliance limits, and environmental criteria.
3.3References.The references shall include identification of the following, as applicable:
3.3.1Prior test reports on the same item.
3.3.2Test plan and procedure documents.
3.3.3Requirement specifications and standards.
3.4Body of report.The body of the report shall include the following:
3.4.1Test equipment identification.The following shall be included for each item of the test equipment used:
3.4.1.4Software Version number.
3.4.1.6Calibration status.
3.4.2Test installation and setup.This section shall include a description of the physical setup for conducting the tests. Drawings and photographs may be used for clarification. The following shall be identified:
3.4.2.1Settings of equipments and instrumentation.
3.4.2.2Location of sensors and probes.
3.4.2.3Interconnections and hook-ups.
3.4.2.4Input parameters used.
3.4.2.5Trigger mechanism or signal and appropriate timing information (sample period, etc.)
3.4.3Test procedures.This section shall include an outline of the procedures followed in conducting the test. If these procedures are contained in a previously delivered document, reference that document in lieu of repeating its contents. These procedures shall address:
3.4.3.1Summarized sequence of testing steps, including a description of how the test item was operated during test, and any control conditions imposed.
3.4.3.2Data reduction techniques employed.
3.4.4Test results and analysis.
3.4.4.1Recorded data.Copies of actual recorded data (i.e., log book entries, oscillographs, instrument readings, plotter graphs). If these are extensive, provide in an appendix.
3.4.4.2Test results.The test results shall include the following:
3.4.4.2.1A complete description of the data provided.
3.4.4.2.2Matrices, tables, graphs comparing results achieved against performance objectives or requirements.Includes a discussion of these as to their significance, and how they compare to any prior tests. Explain how and where the trigger signal is relative to the desired data.
3.4.4.2.3Calculation examples with all associated assumptions and parameters.
3.4.4.3Tabulations of reduced data from 4.a, identified to the related test procedure generating the data.
3.4.4.4Discussion of anomalies, deviations, discrepancies or failures; their impact, causes, and proposed corrective actions.
3.4.5Conclusions.The conclusions shall include statements addressing the following (distinguish between opinion and subjective):
3.4.5.1Effectiveness of the test in measuring tests item performance.
3.4.5.2Success or failure of the test item to meet required performance objectives.
3.4.5.3The need for repeat, additional, or alternative testing.
3.4.5.4The need for test item re-design or further development.
3.4.6Recommendations.The recommendations shall refer to the appropriate test results and conclusions drawn. These could address such actions as:
3.4.6.1Acceptability of the tested item.
3.4.6.2Additional testing required.
3.4.6.3Redesign required.
3.4.6.4Problem resolution.
Schema v3.0Community-maintained · Verify against ASSIST