Click here
      Home    DAG Tutorial    Search    Available Downloads     Feedback
 
The DAG does not reflect the changes in the DoDI5000.02. Work is in progress to update the content and will be completed as soon as possible.
 
.

4.3.18.24. System Security Engineering

Topic

Previous and Next Page arrows

DEFENSE ACQUISITION GUIDEBOOK
Chapter 4 -- Systems Engineering

4.3.18.24. System Security Engineering

4.3.18.24. System Security Engineering

System Security Engineering (SSE) activities allow for identification and incorporation of security design and process requirements into risk identification and management in the requirements trade space.

SSE is the integrating process for mitigating and managing risks to advanced technology and mission-critical system functionality from foreign collection, design vulnerability or supply chain exploit/insertion, battlefield loss, and unauthorized or inadvertent disclosure throughout the acquisition life cycle. The SSE process captures SSE analysis in the system requirements and design documents, and SSE verification in the test plans, procedures, and results documents. The Program Protection Plan (see DAG Chapter 13 Program Protection) documents the comprehensive approach to system security engineering analysis and the associated results.

SSE is the functional discipline within systems engineering that ensures security requirements are included in the engineering analysis with the results being captured in the Program Protection Plan (PPP), provided at each Systems Engineering (SE) technical review (SETR) event (see DAG Chapter 13 Program Protection) and incorporated into the SETR-related SE requirements and the functional, allocated, and product baselines. The PPP is approved by the Milestone Decision Authority (MDA) at each milestone decision review and at the Full-Rate Production/Full-Deployment (FRP/FD) decision, with an approvable draft at the pre–Engineering and Manufacturing Development (EMD) review. The analysis should be used to update the SE baselines prior to each SETR and key knowledge point throughout the life cycle.

The Program Manager is responsible for developing a PPP that ensures the program complies with program protection policy and system requirements. The Systems Engineer and/or System Security Engineer is responsible for ensuring a balanced set of security requirements, designs, testing, and risk management are incorporated and addressed in the their respective trade spaces.

The Systems Engineer and/or System Security Engineer is responsible for facilitating cross-discipline system security working groups and is typically responsible for leading the SSE analysis necessary for development of the PPP. The cross-discipline interactions reach beyond the SSE community to the test and logistics communities. The Test Lead is responsible for incorporating sufficient system security test requirements into the Test and Evaluation Strategy (TES) and Test and Evaluation Master Plan (TEMP). The logistics community is responsible for continuing the protections and risk management activities initiated in acquisition throughout the Operations and Support (O&S) phase.

SSE processes inform the development and release of each request for proposal (RFP) (see DAG Chapter 13 Program Protection) by incorporating SSE process requirements into the Statement of Work (SOW) and the system security requirements into the Requests for Proposal (RFP) requirements document. Contractor responsibilities include developing plans to ensure that the system security protections are implemented in the development environments, system designs, and supply chains. The early and frequent consideration of SSE principles reduces rework and expense resulting from late-to-need security requirements (e.g., anti-tamper, exportability features, supply chain risk management, secure design, defense-in-depth, and information assurance implementation).

Previous and Next Page arrows

Previous Page Next Page

List of All Contributions at This Location

No items found.

Popular Tags

Browse

https://acc.dau.mil/UI/img/bo/minus.gifWelcome to the Defense Acquisition...
https://acc.dau.mil/UI/img/bo/plus.gifForeword
https://acc.dau.mil/UI/img/bo/plus.gifChapter 1 -- Department of Defense...
https://acc.dau.mil/UI/img/bo/plus.gifChapter 2 -- Program Strategies
https://acc.dau.mil/UI/img/bo/plus.gifChapter 3 -- Affordability and...
https://acc.dau.mil/UI/img/bo/minus.gifChapter 4 -- Systems Engineering
https://acc.dau.mil/UI/img/bo/plus.gif4.0. Overview
https://acc.dau.mil/UI/img/bo/plus.gif4.1. Introduction
https://acc.dau.mil/UI/img/bo/plus.gif4.2. Systems Engineering Activities in...
https://acc.dau.mil/UI/img/bo/minus.gif4.3. Systems Engineering Processes
https://acc.dau.mil/UI/img/bo/plus.gif4.3.2. Technical Planning Process
https://acc.dau.mil/UI/img/bo/plus.gif4.3.3. Decision Analysis Process
https://acc.dau.mil/UI/img/bo/plus.gif4.3.4. Technical Assessment Process
https://acc.dau.mil/UI/img/bo/plus.gif4.3.5. Requirements Management Process
https://acc.dau.mil/UI/img/bo/plus.gif4.3.6. Risk Management Process
https://acc.dau.mil/UI/img/bo/plus.gif4.3.7. Configuration Management Process
https://acc.dau.mil/UI/img/bo/plus.gif4.3.8. Technical Data Management Process
https://acc.dau.mil/UI/img/bo/plus.gif4.3.9. Interface Management Process
https://acc.dau.mil/UI/img/bo/plus.gif4.3.10. Stakeholder Requirements...
https://acc.dau.mil/UI/img/bo/plus.gif4.3.11. Requirements Analysis Process
https://acc.dau.mil/UI/img/bo/plus.gif4.3.12. Architecture Design Process
https://acc.dau.mil/UI/img/bo/plus.gif4.3.13. Implementation Process
https://acc.dau.mil/UI/img/bo/plus.gif4.3.14. Integration Process
https://acc.dau.mil/UI/img/bo/plus.gif4.3.15. Verification Process
https://acc.dau.mil/UI/img/bo/plus.gif4.3.16. Validation Process
https://acc.dau.mil/UI/img/bo/plus.gif4.3.17. Transition Process
https://acc.dau.mil/UI/img/bo/minus.gif4.3.18. Design Considerations
https://acc.dau.mil/UI/img/bo/plus.gif4.3.18.1. Accessibility (Section 508...
https://acc.dau.mil/UI/img/bo/plus.gif4.3.18.2. Affordability – Systems...
https://acc.dau.mil/UI/img/bo/plus.gif4.3.18.3. Anti-Counterfeiting
https://acc.dau.mil/UI/img/bo/plus.gif4.3.18.4. Commercial-Off-the-Shelf
https://acc.dau.mil/UI/img/bo/plus.gif4.3.18.5. Corrosion Prevention and...
https://acc.dau.mil/UI/img/bo/plus.gif4.3.18.6. Critical Safety Item
https://acc.dau.mil/UI/img/bo/plus.gif4.3.18.7. Demilitarization and Disposal
https://acc.dau.mil/UI/img/bo/plus.gif4.3.18.8. Diminishing Manufacturing...
https://acc.dau.mil/UI/img/bo/plus.gif4.3.18.9. Environment Safety and...
https://acc.dau.mil/UI/img/bo/plus.gif4.3.18.10. Human Systems Integration
https://acc.dau.mil/UI/img/bo/plus.gif4.3.18.11. Insensitive Munitions
https://acc.dau.mil/UI/img/bo/plus.gif4.3.18.12. Intelligence (Life-Cycle...
https://acc.dau.mil/UI/img/bo/plus.gif4.3.18.13. Interoperability and...
https://acc.dau.mil/UI/img/bo/plus.gif4.3.18.14. Item Unique Identification
https://acc.dau.mil/UI/img/bo/plus.gif4.3.18.15. Open Systems Architecture
https://acc.dau.mil/UI/img/bo/plus.gif4.3.18.16. Operational Energy
https://acc.dau.mil/UI/img/bo/plus.gif4.3.18.17. Packaging Handling Storage...
https://acc.dau.mil/UI/img/bo/plus.gif4.3.18.18. Producibility Quality and...
https://acc.dau.mil/UI/img/bo/plus.gif4.3.18.19. Reliability and...
https://acc.dau.mil/UI/img/bo/plus.gif4.3.18.20. Spectrum Management
https://acc.dau.mil/UI/img/bo/plus.gif4.3.18.21. Standardization
https://acc.dau.mil/UI/img/bo/plus.gif4.3.18.22. Supportability
https://acc.dau.mil/UI/img/bo/plus.gif4.3.18.23. Survivability and...
https://acc.dau.mil/UI/img/bo/minus.gif4.3.18.24. System Security Engineering
https://acc.dau.mil/UI/img/bo/plus.gif4.3.19. Tools Techniques and Lessons...
https://acc.dau.mil/UI/img/bo/plus.gifChapter 5 -- Life-Cycle Logistics
https://acc.dau.mil/UI/img/bo/plus.gifChapter 6 -- Human Systems Integration...
https://acc.dau.mil/UI/img/bo/plus.gifChapter 7 -- Acquiring Information...
https://acc.dau.mil/UI/img/bo/plus.gifChapter 8 -- Intelligence Analysis...
https://acc.dau.mil/UI/img/bo/plus.gifChapter 9 -- Test and Evaluation (T&E)
https://acc.dau.mil/UI/img/bo/plus.gifChapter 10 -- Decisions Assessments and...
https://acc.dau.mil/UI/img/bo/plus.gifChapter 11 -- Program Management...
https://acc.dau.mil/UI/img/bo/plus.gifChapter 12 - Defense Business System...
https://acc.dau.mil/UI/img/bo/plus.gifChapter 13 -- Program Protection
https://acc.dau.mil/UI/img/bo/plus.gifChapter 14 -- Acquisition of Services
https://acc.dau.mil/UI/img/bo/plus.gifDoD Directive 5000.01
https://acc.dau.mil/UI/img/bo/plus.gifDoD Instruction 5000.02
https://acc.dau.mil/UI/img/bo/plus.gifRecent Policy and Guidance
https://acc.dau.mil/UI/img/bo/plus.gifCurrent JCIDS Manual and CJCSI 3170.01 I
https://acc.dau.mil/UI/img/bo/plus.gifDefense Acquisition Guidebook Key...
ACC Practice Center Version 3.2
  • Application Build 3.2.9
  • Database Version 3.2.9