DI-SESS-82432
Product Assessment Provenance Report
Documents the vendor's progress toward contract objectives by evaluating hardware and software components of equipment and identifying risks related to obsolescence, vulnerabilities, non-conformances, counterfeits, and foreign adversarial alerts.
Approval DateJanuary 19, 2024
AMSC NumberN10451
Preparing ActivityAS
Project NumberSESS-2024-003
OPR—
DTIC Applicable—
GIDEP Applicable—
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatfree_text
963C CompliantYes
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
The Product Assessment Provenance Report documents the status of the vendor's effort towards achieving contract objectives. It evaluates and illuminates the hardware and software components of specific equipment. The report will provide visibility on potential risks related to granular product components based on obsolescence, vulnerability, non-conformances, counterfeit alerts, and foreign adversarial alerts.
This Data Item Description (DID) contains the format, content, and intended use information for the deliverable resulting from the work task described in the contract.
Preparation Instructions
1Reference documentsNone.
2FormatThe Product Assessment Provenance Report shall be in Adobe Portable Document Format (PDF).
3ContentThe Product Assessment Provenance Report shall include the following:
3.1Overall Provenance Scorethat is based on the following categories:
3.1.1Manufacturer foreign presence
3.1.2Hardware component alerts
3.1.3Software Component alerts (CVE)
3.1.4Fourth Party Foreign Presence
3.1.5Related Entity Discovery Alert (Informational and is not in overall score)
3.2.2Assessment Results Overview
3.5Product FIPS Compliance
3.6DOD Approved Product List
3.8Manufacturer Description
3.8.1A table that shows information in rows for manufacturer headquarters, manufacturing locations, foreign owners, mergers and acquisition, physical location, corporate families, and cyber presenceThe table shall also show corresponding column information for level of risk.
3.10Hardware Component Alerts
3.11Software Component Alerts (CVE)
3.12.1Hardware Fourth Parties
3.12.2Software Fourth Parties
3.12.3A table that shows information in rows for company, headquarters, foreign owners, mergers & acquisitions, physical presence, corporate families, cyber presence, manufacturing, and Foreign Presence level
3.13Related Entity Discovery
3.13.1A table that shows information in rows for manufacturer, banned company, relationship, relationship alerts, evidence details and URL, evidence pictures
Schema v3.0Community-maintained · Verify against ASSIST