Activity-in-Diagram: Execute CVPA & Document Results

CreatorTim Ramey

Description

The OTA captures and reports data and findings in accordance with the approved Operational Test Plan, the TEMP, and 2018 DOT&E Memorandum on minimum data and reporting. The CVPA report should document the system configuration as observed, all test events executed (including both failed and successful events), observations, findings, and results. The OTA ensures that the authorized tools used to assess system cybersecurity are removed after testing is completed.

Owning Diagram A5: Phase 5: Assess Vulnerabilities and Penetration

Input

Mission-Based Cyber Risk Assessment (MBCRA)

Output

updates to RMF and POA&M

MBCRA updates

TEMP updates

Cooperative Vulnerability and Penetration Assessment (CVPA) reporting

POA&M for remediation of vulnerabilities

CVPA operational assessment

Control

Authorization to Operate (ATO)

operational test (OT) plans

Operational Test Agency

RMF and POA&M

Mechanism

Cybersecurity OTA Technical Experts