DI-SCRE-82143A
Cybersecurity Strategy Implementation Plan
The Cybersecurity Strategy Implementation Plan (CSIP) is used to ensure industry partners correctly implement the Government Program Office Cybersecurity Strategy for the development environment and product deliverables.
Approval DateOctober 19, 2022
AMSC NumberN10362
Preparing ActivityAS
Project NumberSCRE-2022-032
OPR—
DTIC Applicable—
GIDEP Applicable—
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatfree_text
963C CompliantYes
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
The Cybersecurity Strategy Implementation Plan (CSIP) will be used to ensure that industry partners are correctly implementing the Government Program Office Cybersecurity Strategy (CSS) for both the developmental environment and in the product deliverables.
This DID contains the format, content, and intended use information for the data product resulting from the work task.
This DID supersedes DI-MGMT-82143.
Preparation Instructions
1Reference documentsThe applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as specified in the contract.
2FormatContractor format is acceptable.
3ContentThe plan shall contain the following:
3.1The content of the CSIPThe content of the CSIP establishes the cybersecurity construct under which the contractor must operate in order to comply with the CSS. The Cybersecurity Strategy Implementation Plan shall include an introduction and the following sections to document how the contractor proposes to implement the requirements set forth in the CSS. The following is a narrative of the CSIP package content:
3.2Cybersecurity EnvironmentThis section shall contain a description addressing how cybersecurity is managed during system development. Include any examples of how the company keeps up with cybersecurity changing threats, industry trends, etc. Cover any general approaches to the protection of electronic information and overall awareness of threats and mitigations. This paragraph will also summarize the company's cybersecurity posture within their business model. The contractor will articulate:
3.2.1How PKI certificates will be utilizedHow PKI certificates will be utilized with email programs for digital signature and encryption.
3.2.2How the contractor will fulfill requirementsHow the contractor will fulfill requirements for securing data at rest.
3.2.3How the contractor will fulfill requirementsHow the contractor will fulfill requirements for securing data in transit.
3.2.4How the contractor will support various aspectsHow the contractor will support various aspects of the Assessment and Authorization (A&A) effort on corporate systems.
3.2.5Reserved for CS Work Force requirementsReserved for CS Work Force requirements to be determined later.
3.2.6An understanding of the process and requirementsAn understanding of the process and requirements associated with obtaining a CAC and access to government systems.
3.2.7How the contractor will meet cybersecurity requirementsHow the contractor will meet cybersecurity requirements when electronically transmitting classified information.
3.3Product CybersecurityThe goal of this section is for the contractor to demonstrate that cybersecurity design will be fully integrated into delivered system(s). Plan as to how will implement
3.3.1Key ManagementDescribe how your company plans on adhering to crypto key management practices. The goal of this section is to articulate how the contractor will comply with the NSA process for certification of cryptographic products.
3.3.2Cybersecurity Requirements Flow-DownThe goal of this section is to articulate how the contractor will flow down cybersecurity requirements to vendors and subcontractors.
3.4Cybersecurity AssessmentThe goal of this section is for the contractor to provide their strategy to ensure that cybersecurity design is fully assessed in delivered system(s).
3.4.1Describe cybersecurity verification methodologies anticipated for useDescribe cybersecurity verification methodologies anticipated for use during system development and the time phasing.
3.4.2How validate their infrastructure is safe forHow validate their infrastructure is safe for USG data, how flow down to subcontractor?
Schema v3.0Community-maintained · Verify against ASSIST