Software Assurance During Acquisition - A Phased Approach

8 slides · 4 min read · Domain 8

Software Assurance During Acquisition: A Phased Approach

Four basic phases of activity shape the ways in which organizations acquire software systems via thirdparty systems providers, integrators, or consultants.

There are many different development methodologies that such efforts may use, and different methodologies need or support differing interactions between purchasing stakeholders, their operational users, the developer organization, and the developer's software design, development, test, and integration specialists.

These broader phases can be outlined as follows:

Planning Phase

As with any software project, this phase begins with an initial identification of a possible need. New business opportunities, new security threats, or other changes to the organization's operational environment often dictate the need to change business processes and the software systems that support them.

Several steps are usually required to get to the point where the decision between in-house development vs. contracting with a third party can be made in confidence.

Depending upon the scope of the desired

  • Developing software requirements to be included in the statements) of

system and the security posture it must satisfy, these steps normally include:

work (SOWs) to be incorporated in the contracts).

  • Initial statements of need are expressed in more depth and detail, usually
  • Identifying the total list of deliverable identifying existing business processes products, including information assets, that may need to be changed as a result of documentation, test data, software this decision. assurance records, configuration management and control data, or
  • Initial sizing, scoping, or other estimates

anything else that the organization may are done to identify a rough order of need to use to validate that the as-built magnitude of the effort required to system meets their needs, is sustainable, complete the project.

and can meet their own software assurance standards.

  • Risk assessments are completed, both to identify the risks of not doing the project
  • Creating an acquisition strategy

as well as risks involved in its development, and/or plan that includes identifying acceptance, and ongoing operational use.

risks associated with various software acquisition strategies. This usually

  • Alternative implementations - including

includes identifying criteria used to alternative expressions of higher-level screen bidders or possible sources (so needs into specific systems requirements

as not to waste time on ones who clearly

  • may be competed against each other in

cannot perform well enough to meet the terms of cost, schedule, risk, and other organization's acquisition plan.

factors needed for the decision process.

  • Developing bid evaluation criteria and an
  • A return on investment (ROI) estimate

evaluation plan.

is made, which is typically compared to an internal break-even or hurdle rate

Almost every step in that list above is an (projects that do not return more than opportunity for the security professional the hurdle rate must have some other to advise and influence the process. overriding to be approved).

Contracting Phase

At the end of the planning phase the organization makes the decision to move forward and seek competent, qualified suppliers, which typically involves:

  • Creating and issuing the solicitation or request for proposal (RFP) with a statement of work, instructions to potential respondents of RFP, terms and conditions, including conditions for acceptance, prequalification considerations, and certifications.
  • Evaluating supplier proposals submitted in response to the solicitation or RFP.
  • Finalizing contract negotiation to include changes in terms and conditions and awarding the contract.

Software risks should be addressed and mitigated through terms and conditions, certifications, evaluation factors for award, and risk mitigation requirements in the SOW.

Monitoring, Acceptance and Deployment Phase

This phase involves monitoring the supplier's work and accepting the final service or product delivered under a contract.

The SOW may or may not include having the supplier/developer involved in the actual installation, checkout and turnover of the new systems at end-user locations (or in the servers or clouds that support those users).

This phase includes three major activities as well:

  • Establishing and consenting to the contract work schedule
  • Implementing change or configuration control procedures
  • Reviewing and accepting software deliverables

During the monitoring and acceptance phase, software risk management and assurance case deliverables must be evaluated to determine compliance in accepted risk mitigation strategies as stated in the requirements of the contract.

Ongoing Use and Support Phase

This phase involves maintaining the software. This process is sometimes called sustainment.

This phase includes two major activities:

  • Sustainment, which includes risk management, assurance case management, and change management
  • Disposal or decommissioning

During the follow-on phase, software risks must be managed through continued analysis of the assurance case and should be adjusted to mitigate changing risks.

Test this domain