Activity-in-Diagram: Plan and Schedule Test Events

CreatorTim Ramey

Description

The CDT plans and proritizes cybersecurity testing based on test events and test data needed to resolve test objectives and verify the system capabilities. The attack surface informs the analysis to ensure key cyber terrain is thoroughly tested throughout cybersecurity T&E. The CDT also plans CVI test events to ensure that the vulnerability assessment teams have all the levels of system access required to assess for common exploitable vulnerabilities. The CDT identifies common vulnerabilities that can arise in systems, configurations, and across interfaces that system developers or the PM were not aware existed. In addition, as software updates are applied to the system, the CDT plans to evaluate for newly introduced vulnerabilities, default configuration impacts, and other complexities that can result from updates.

Owning Diagram A31: Plan CVI Test Activities

Decomposition

A312: Plan and Schedule Test Events

Input

RMF security plan assessement

Output

test events plan

test infrastructure plan

Control

ACD test objectives and metrics

Cheif Developmental Tester

Test and Evaulation Master Plan (TEMP)

Mechanism

Lead DT&E Organization