Activity-in-Diagram: Document Results of Cyber-Attack Surface Analysis

CreatorTim Ramey

Description

The CyWG documents the identified cyber-attack surface list, the critical components and data (key terrain) that support MEFs, the analysis of the attack surface, any known vulnerabilities, and the recommended activities, such as attack surface testing, mitigation design, risk acceptance, and requirements, for further analysis. The resulting Cyber-Attack Surface Analysis Report specifies updates needed for the roles and responsibilities, system design, and cybersecurity, system cyber survivability, and operational resilience requirements.

Owning Diagram A23: Document Results and Update Test Planning and Artifacts

Input

prioritization of attack surface

identified risks

Output

need for additional requirement

cyber attack surface analysis report

Control

Cybersecurity Service Provider (CSSP) support plan

Information Support Plan (ISP)

Program Protection Plan (PPP)

Test and Evaulation Master Plan (TEMP)

Cheif Developmental Tester

Mechanism

Cybersecurity DT&E Technical Experts