Activity-in-Diagram: Update MBCRA

Creator

Description

Cyber risk assessments prioritize mitigations for action to improve a system's security posture. And MBCRA/CTT conducted during Phase 3 helps PMs understand suspected mission impacts and prioritize remediations of vulnerabilities based on mission impact. Prioritization also informs funding decisions that drive redesign and remediation during system development. Cybersecurity risk assessments should include contractor T&E test data.

Owning Diagram A32: Conduct CVI Events and Document Results

Input

CVI test results

Mission-Based Cyber Risk Assessment (MBCRA)

Output

need for additional requirement

MBCRA updates

Control

Cheif Developmental Tester

Test and Evaulation Master Plan (TEMP)

Mechanism

Lead DT&E Organization