Research, Development, Test, and Evaluation Overlay
Abstract
Range RDT and E IT systems have become extremely challenging to authorize under the Risk Management Framework (RMF) due to the dynamic nature of the systems; continued configuration modification due to test capability and system under test improvements; and resources becoming more constrained. Ranges need to identify key controls applicable to common RDT and E system types to streamline the authorization process and provide guidance for addressing security controls. This RMF overlay provides security control value definitions, guidance, and tailoring justifications for RDT and E systems creating efficiencies for cybersecurity professionals. The Research, Development, Test, and Evaluation (RDT and E) overlay identifies security control specifications related to RDT and E systems. Versioning for this document is by date. The date of this overlay is June 2024. This Overlay will identify control specifications for the different types of RDT and E systems. An RDT and E system is one that performs, supports, tests, or evaluates the results of one or more of the following activities: basic research; applied research; advanced technology development; advanced component development and prototypes; system development and demonstration; RDT and E management support; operation system development.
Document Details
- Document Type
- Technical Report
- Publication Date
- Jun 01, 2024
- Accession Number
- AD1229895