DoDI5000.83_DAFI63-113 governs technology and program protection for maintaining technological advantage across acquisition efforts.
View DoDI5000.83_DAFI63-113 on armypubs.army.mil
The publication addresses planning, requirements, design, test, operational software, and support data, along with TAPPs, PPPs, cybersecurity, and system security engineering. It requires protection of program information, security requirements in the technical baseline, and assessment of design vulnerabilities.
(Added)(DAF) Program information created by DoD and non-DoD contractors supporting S&T projects, experiments, and specific research should also be protected from compromise. (paragraph 2)
Poor cybersecurity hygiene, untrained personnel, and operational security practices can be used by threat actors to gain program and system knowledge. (paragraph 2)
(Added)(DAF) Contracting officers will use the Supplier Performance Risk System in their contracts to ensure compliance with Defense Federal Acquisition Regulation Supplement (DFARS) 204.73, Safeguarding Covered Defense Information and Cyber Incident Reporting. (paragraph 2)
(Added)(DAF) Software vulnerabilities make up the majority of all system vulnerabilities. This calls for the use of DevSecOps in the integration of security at every phase of the software development lifecycle, from initial design through integration, testing, deployment, and software delivery. (paragraph 2)
(Added)(DAF) At a minimum, DoD Information Network and external interfaces shall implement FIPS 140-3, Security Requirements for Cryptographic Modules, standards. (paragraph 1)