DoDI5000.83_DAFI63-113 — Technology And Program Protection To Maintain Technological Advantage

DoDI5000.83_DAFI63-113 governs technology and program protection for maintaining technological advantage across acquisition efforts.

Search DoDI5000.83_DAFI63-113

  • Publication number: DoDI5000.83_DAFI63-113
  • Title: TECHNOLOGY AND PROGRAM PROTECTION TO MAINTAIN TECHNOLOGICAL ADVANTAGE
  • Date: 2024-10-17

View DoDI5000.83_DAFI63-113 on armypubs.army.mil


The publication addresses planning, requirements, design, test, operational software, and support data, along with TAPPs, PPPs, cybersecurity, and system security engineering. It requires protection of program information, security requirements in the technical baseline, and assessment of design vulnerabilities.

Topics covered

  • Technology and program protection
  • Planning and requirements data
  • Program protection plans
  • Engineering cybersecurity activities
  • Classified and controlled information
  • Technical information marking and dissemination
  • Supply chain vulnerabilities
  • System survivability and sustainment

Questions and answers

How should DoD and contractor program information supporting science and technology projects be protected?

(Added)(DAF) Program information created by DoD and non-DoD contractors supporting S&T projects, experiments, and specific research should also be protected from compromise. (paragraph 2)

What cybersecurity conditions can threat actors use to gain program and system knowledge?

Poor cybersecurity hygiene, untrained personnel, and operational security practices can be used by threat actors to gain program and system knowledge. (paragraph 2)

What system must contracting officers use to ensure DFARS compliance?

(Added)(DAF) Contracting officers will use the Supplier Performance Risk System in their contracts to ensure compliance with Defense Federal Acquisition Regulation Supplement (DFARS) 204.73, Safeguarding Covered Defense Information and Cyber Incident Reporting. (paragraph 2)

What software development security practice does the publication call for?

(Added)(DAF) Software vulnerabilities make up the majority of all system vulnerabilities. This calls for the use of DevSecOps in the integration of security at every phase of the software development lifecycle, from initial design through integration, testing, deployment, and software delivery. (paragraph 2)

What cryptographic standard must DoD Information Network and external interfaces implement?

(Added)(DAF) At a minimum, DoD Information Network and external interfaces shall implement FIPS 140-3, Security Requirements for Cryptographic Modules, standards. (paragraph 1)

Ask Reggie.Bot a question about DoDI5000.83_DAFI63-113