Information Assurance and Security Policy Development Levels

Phase 1
The ASSC is working with the MoD to form an Information Assurance and Security Working Group from interested parties. The aim will be to review JSP440 and its supplements in order to create a database of CIS Security user requirements extracted from the standard. The output of this phase of work will be a requirements database providing traceability back to JSP 440. The database will be used to ensure compliance with JSP 440 during the procurement of CIS equipment.

The MoD have identified a need to improve the application of techniques and assessments for system maturity measurements within avionics procurement programs when utilising the System Readiness Level (SRL) airworthiness metrics. The ASSC, with its links both within the MoD and Industry, have been tasked by the MoD to undertake this work.

Phase 2
Under the guidance of the Working Group, a study of the acquisition lifecycle will be made in conjunction with JSP440.The aim will be to create a top level CIS Security Lifecycle Process (against the CADMID cycle) outlining activities, milestones and key deliverables for IPTs at different stages of the acquisition process and establishing a means of assessing the maturity of IPT project teams when using the FBG System Readiness Level (SRL) Tool.

Point of contact : Cobham Technical Services, Tel: +44 (0)1372 367141, era.assc@cobham.com