Cybersecurity Operational T and E Concept for Software Factories
Abstract
This test and evaluation concept highlights the critical role of Department of Defense-owned software factories as key components in the software supply chain of major acquisition systems and provides a structure by which to design operational cyber testing of a software factory to inform the supply chain evaluation of the program that consumes its software. This briefing describes a conceptual software factory. Actual factory architectures will likely be more complex, and will require open discussions from all stakeholders (program office, test community, oversight, operational users, etc.) during test planning and execution. The concept includes a test design example using a notional SF that contains features of currently operating DOD SFs. This document describes the process and outlines the steps to create a test design for the notional SF. This design methodology is broadly applicable and tailorable to meet the testing needs of any SF. This document can help facilitate those conversations and provide a framework for stakeholders to both plan operational tests and also keep an account of what data was collected during test execution.
Document Details
- Document Type
- Technical Report
- Publication Date
- Jul 01, 2022
- Accession Number
- AD1205219
Entities
People
- Brandon A. Shapiro
- Eliza M. Johannes
- Erick D. Mccroskey
- Jason P. Sheldon
- Kathleen Falcon
- Peter M. Mancini
- Troy W. Lowry
- William J. Robbins
Organizations
- Institute for Defense Analyses