DI-SESS-82409
Software Assurance Case
Specifies the format and content for a Software Assurance Case, a structured argument supported by evidence that justifies a software/system is acceptably assured relative to a concern such as safety or security.
Approval DateJune 8, 2023
AMSC NumberN10393
Preparing ActivityAS
Project NumberSESS-2023-011
OPR—
DTIC Applicable—
GIDEP Applicable—
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatfree_text
963C CompliantYes
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
The Software Assurance Case is a structured argument, supported by evidence, intended to justify that the software/system is acceptably assured relative to a concern (such as safety or security) in the intended operating environment.
This Data Item Description (DID) contains the format, content, and intended use for the data product resulting from the work task described in the contract Statement of Work/Performance Work Statement.
Preparation Instructions
1Referenced documentsThe applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as specified in the contract.
1.1National Institute of Standards and Technology IR 7608 - Software Assurance Using Structured Assurance Case Modelshttps://www.nist.gov/publications/software-assurance-using-structuredassurance-case-models
1.2DoD Developer's Guidebook for Software AssuranceCarnegie Mellon University, Software Engineering Institute (SEI), Federally Funded Research and Development Center (FFRDC). https://resources.sei.cmu.edu/library/asset-view.cfm?assetid=539177
1.3Program Manager's Guidebook for Software AssuranceCarnegie Mellon University, Software Engineering Institute (SEI), Federally Funded Research and Development Center (FFRDC). https://resources.sei.cmu.edu/library/asset-view.cfm?assetid=538771
1.4Program Protection Plan (PPP)
1.5ISO/IEC/IEEE 12207, Systems and Software Engineering (or equivalent)
2FormatContractor Format.
3ContentThe documented evidence shall provide a convincing and valid argument that a specified set of critical claims regarding a software's/system's properties are adequately justified for a given application in a given environment. The Software Assurance Case shall be organized into the following sections:
3.1Reference DocumentsThis section shall list the number, title, revision, and date of all documents referenced in this deliverable. This section shall also identify the source for all documents not available through normal Government stocking activities.
3.2Document ManagementThis section shall identify the version, release date, and other relevant management and configuration control information associated with the current version of the deliverable. A change history, highlighting significant changes from version to version shall be included.
3.3Table of ContentsThis section shall index all sections, major paragraphs, subparagraphs and appendices with page numbers.
3.4ScopeThis section shall be divided into paragraphs covering system and software identification, system overview and document overview.
3.4.1System and Software IdentificationThis section shall contain a full identification of the system and the software to which this deliverable applies, including, as applicable, identification number(s), title(s), abbreviation(s), version number(s), and release number(s).
3.4.2System OverviewThis section shall briefly state the purpose of the system to which this deliverable applies. It shall describe the general nature of the system and software; summarize the history of system development, operation, and maintenance; identify the project sponsor, acquirer, user, developer, and support agencies; identify current and planned operating sites; and list other relevant documents.
3.4.3Document OverviewThis section shall summarize the purpose and contents of the deliverable and shall describe any security or privacy considerations associated with its use.
3.5Software Assurance Case ModelThe structured assurance case model is represented as a directed graph whose nodes consist of claims, arguments, and evidence elements.
3.5.1Claims and Sub-ClaimsA claim is a statement asserting some characteristic, property, or behavior of the software or system that can be evaluated for truthfulness, is demonstrable, and is supported by arguments based on objective evidence. A claim may be further decomposed into subclaims, and expressed either as a positive or negative statement.
3.5.1.1Claims and Sub-ClaimsClaims and Sub-Claims should be pre-reviewed to ensure non-duplication.
3.5.2ArgumentsArguments are logical propositions intended to support a claim through reasoning or logic that links evidence to a claim. An argument is the explanation of how the evidence can be interpreted as supporting a claim or sub-claim.
3.5.3EvidenceEvidence is information used to support a claim. Evidence should be objective, reproducible, repeatable, and non-disputable.
Schema v3.0Community-maintained · Verify against ASSIST