ATTACHMENT_10_AFMAN_63-119.xls

XLS spreadsheet 186 KB Posted

Attached to
T-38A/B and A-10 Automatic Dependent Surveillance-Broadcast (ADS-B) Federal contract opportunity
Solicitation number
FA822017R0001
Issued by
Department of the Air Force Materiel Command Lifecycle Management Center Hill Air Force Base

About this file

AFMAN 63-119

View the file

Other files for this federal contract opportunity

Other files attached to T-38A/B and A-10 Automatic Dependent Surveillance-Broadcast (ADS-B), newest first.
File Type Posted
Narrative_of_Electrical_Loads_Spreadsheets.docx DOCX document
ATTACHMENT_11_Florida_Wage_Determination.pdf PDF
FA822017R0001.pdf PDF
FA822017R0001_______0002.pdf PDF
Materiel_Fielding_Plan_Template.docx DOCX document
Item__20_ELA-AT-38B_DC_load_Analysis_ECM_Pod.xlsx XLSX spreadsheet
ATTACHMENT_12_Indiana_Wage_Determination.pdf PDF
ATTACHMENT_03_CDRLs_R01.pdf PDF
Item__20_ELA-T-38_AC_Loading_TO_data-ECM_Pod.xlsx XLSX spreadsheet
ATTACHMENT_03_CDRLs.pdf PDF
ATTACHMENT_01_Pricing_Matrix_R01.xlsx XLSX spreadsheet
ATTACHMENT_09_Reserved.pdf PDF
ATTACHMENT_13_Maryland_Wage_Determination.pdf PDF
T-38_A_and_B_Fleet_12_7_16.xlsx XLSX spreadsheet
Electrical_Loads.xlsx XLSX spreadsheet
ATTACHMENT_05_Technical_Manual_Contract_Requirements.pdf PDF
ATTACHMENT_04_GFP_List.pdf PDF
ATTACHMENT_14_Warranty_Information.pdf PDF
FA822017R0001_______0001.pdf PDF
ATTACHMENT_08_A-10_DD254.pdf PDF
ATTACHMENT_15_Source_of_Repair.pdf PDF
ATTACHMENT_02_T-38_A-10_APX-119_GPS_PWS_R01.pdf PDF
ATTACHMENT_02_T-38_A-10_APX-119_GPS_PWS.pdf PDF
ATTACHMENT_06_AFMC_Form_158.pdf PDF
ATTACHMENT_07_DD_Form_1653.pdf PDF
Synopsis_of_FA8220-17-R-0001_ADS-B_-_Presolicitation.docx DOCX document
Show all 26

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Index

AFMAN 63-119 OT&E Template Index
How to use 63-119 templates: In the appropriate block under service designation type G, Y, or R (blocks defaulted to red "R"). The block will turn that color to reflect the current status. Typing N/A or a Question Mark will turn the block white. The blocks are not case sensitive. Clicking on the template designation in the index will take you to that template. Before using, save the file to your hard drive.
Attachment 2:

ACQUISITION STRATEGY AND SCHEDULE

Attachment 3 ANALYSIS OF ALTERNATIVES (AoA) Attachment 4

CAPABILITIES BASED REQUIREMENTS DOCUMENTS (CBRD)

Attachment 5

THREAT & INTELLIGENCE DOCUMENTS

Attachment 6

INTEGRATED TEST TEAM (ITT) STANDUP AND ITT CHARTER

Attachment 7

AIR FORCE CONCEPTS

Attachment 8

LIFE CYCLE SUSTAINMENT PLAN (LCSP)

Attachment 9

INFORMATION TECHNOLOGY (IT) AND NATIONAL SECURITY SYSTEMS (NSS)

Attachment 10

TEMP (MS B AND BEYOND)

Attachment 11

INTEGRATED PLANNING

Attachment 12

PROGRAM PROTECTION AND SECURITY

Attachment 13

CONTRACTOR TESTING

Attachment 14

DEVELOPMENTAL TEST AND EVALUATION (DT&E)

ATTACHMENT 15

SOFTWARE DEVELOPMENT AND MATURITY

Attachment 16

LIVE FIRE TEST AND EVALUATION (LFT&E)

Attachment 17

MODELING AND SIMULATION (M&S)

Attachment 18

CONFIGURATION MANAGEMANT PLAN (CMP)

Attachment 19

DEFICIENCY IDENTIFICATION AND RESOLUTION PROCESS

Attachment 20

PRODUCTION REPRESENTATIVE TEST ARTICLES

Attachment 21

SYSTEM PERFORMANCE

Attachment 22

OPERATIONAL TEST AND EVALUATION PLAN

Attachment 23

PROGRAMMATIC ENVIRONMENT, SAFETY, AND OCCUPATIONAL HEALTH EVALUATION (PESHE)

Attachment 24

OPERATIONAL TEST TEAM TRAINING

Attachment 25

SUPPORT EQUIPMENT (SE)

Attachment 26

SUFFICIENCY OF SPARES

Attachment 27

SUPPORT AGREEMENTS

Attachment 28

PACKAGING, HANDLING, AND TRANSPORTATION

Attachment 29

PERSONNEL

Attachment 30

CONTRACTOR SUPPORT

Attachment 31

TECHNICAL DATA

Attachment 32

TEST AND EVALUATION RESOURCES

Attachment 2:

ACQUISITION STRATEGY AND SCHEDULE

Attachment 3 ANALYSIS OF ALTERNATIVES (AoA) Attachment 4

CAPABILITIES BASED REQUIREMENTS DOCUMENTS (CBRD)

Attachment 6

INTEGRATED TEST TEAM (ITT) STANDUP AND ITT CHARTER

Attachment 7

AIR FORCE CONCEPTS

Attachment 8

LIFE CYCLE SUSTAINMENT PLAN (LCSP)

Attachment 9

INFORMATION TECHNOLOGY (IT) AND NATIONAL SECURITY SYSTEMS (NSS)

Attachment 10

TEMP (MS B AND BEYOND)

Attachment 11

INTEGRATED PLANNING

Attachment 12

PROGRAM PROTECTION AND SECURITY

Attachment 13

CONTRACTOR TESTING

Attachment 14

DEVELOPMENTAL TEST AND EVALUATION (DT&E)

Attachment 16

LIVE FIRE TEST AND EVALUATION (LFT&E)

Attachment 17

MODELING AND SIMULATION (M&S)

Attachment 18

CONFIGURATION MANAGEMANT PLAN (CMP)

Attachment 19

DEFICIENCY IDENTIFICATION AND RESOLUTION PROCESS

Attachment 20

PRODUCTION REPRESENTATIVE TEST ARTICLES

Attachment 21

SYSTEM PERFORMANCE

Attachment 22

OPERATIONAL TEST AND EVALUATION PLAN

Attachment 23

PROGRAMMATIC ENVIRONMENT, SAFETY, AND OCCUPATIONAL HEALTH EVALUATION (PESHE)

Attachment 24

OPERATIONAL TEST TEAM TRAINING

Attachment 25

SUPPORT EQUIPMENT (SE)

Attachment 26

SUFFICIENCY OF SPARES

Attachment 27

SUPPORT AGREEMENTS

Attachment 28

PACKAGING, HANDLING, AND TRANSPORTATION

Attachment 29

PERSONNEL

Attachment 30

CONTRACTOR SUPPORT

Attachment 31

TECHNICAL DATA

Attachment 5

THREAT & INTELLIGENCE DOCUMENTS

Attachment 32

TEST AND EVALUATION RESOURCES

ATTACHMENT 15

SOFTWARE DEVELOPMENT AND MATURITY

AFMAN 63-119

Compiled From: AFMAN 63-119,V4.3, 6 Oct 2015
Attachment 2:
ACQUISITION STRATEGY AND SCHEDULEUSAFResponsible PartyComments
A2.1.Ensure early operational tester (AFOTEC or MAJCOM) involvement when developing the acquisition strategy to ensure the strategy for T&E provides needed support.RPM
A2.2.Develop realistic, achievable, event-driven acquisition and test schedules and ensure they are harmonized throughout all program documents. Avoid success-oriented schedules.RPM
A2.3.Congressional and PPBE schedule constraints are incorporated into the acquisition schedule.RPM
A2.4.Ensure sufficient and timely RDT&E funding and procurement appropriations are programmed during each budget cycle to keep the program in technical balance.RPM, OTO
A2.5.Schedule sufficient numbers of certification reviews over the program’s projected life cycle. Frequency of reviews should increase as the program nears the start of dedicated OT&E.RPM
A2.6.Resolve open issues, particularly with requirements, sufficiently early to permit orderly planning and transition to dedicated OT&E.RPM
A2.7.If an incremental strategy is used, a clear distinction must exist between each increment for determining what will be tested, produced and/or fielded.RPM, User
A2.7.1.Operational capabilities are clearly assigned to specific increments.RPM
A2.7.2.Provisions exist for developing and operationally testing subsequent increments after the initial increment is complete.RPM
A2.8.Ensure contract(s) capture the content of the most recent CBRD or appropriate requirement document.RPM
A2.9.A CDT has been identified (if an ACAT I or MAIS program), or a Test Manager (or CDT) for other than MDAP and MAIS programs.RPM
Attachment 3
ANALYSIS OF ALTERNATIVES (AoA)USAFResponsible PartyComments
A3.1.The AoA (if required) may require updating, re-validation, and approval at the appropriate level prior to each milestone.RUser
A3.2.All reasonable alternatives must be objectively described. The military value of the final alternatives must be clearly identified.RUser
A3.2.1.All relevant costs must be identified, preferably using objective engineering and business estimates derived from accepted Air Force cost analysis principles and processes.RPM
A3.2.2.All assumptions and constraints must be explicitly identified and supported by the latest CBRD, AoA guidance documents, or reasonable basis determined by the AoA sponsoring agency.RUser
A3.2.3.Acceptable ranges of performance must be established using rigorous cost-benefit, trade-off, and sensitivity analyses to show decision makers when and where certain degradations in system cost or performance yield outcomes that no longer satisfy the mission need.RUser
A3.3.Measures of Effectiveness (MOE) and Measures of Suitability (MOS) must reflect operational utility and show how they were derived from the requirements documents.ROTO
A3.3.1.MOEs and MOSs at the operational task level must be "testable" in order to develop DT&E and OT&E plans and concepts. MOEs must be developed as early as possible and agreed to between user and tester.ROTO
A3.3.2.The AoA’s MOEs, MOSs, Measures of Performance (MOP), and other criteria must be linked to system performance thresholds stated in the latest threat and requirements documents and "track" throughout the program's development.ROTO
Attachment 4
CAPABILITY BASED REQUIREMENTS DOCUMENTS (CBRD)USAFResponsible PartyComments
A4.1.The appropriate CBRD (i.e., Initial Capability Document (ICD), Draft Capability Development Document (CDD), or Capability Production Document (CPD)), and CONOPS must be coordinated and approved at appropriate levels prior to each milestone, after major program changes, and early enough to develop the TEMP and OT&E test concept and OT&E plan.RUser
A4.1.1.AF Form 1067s issued for modification programs that introduce new capability must include a Table of Performance Parameters/Attributes (KPP, KSA, other or attributes) with minimum Threshold/Objective values similar to the format for a CDD/CPD.RUser
A4.1.2.AF Form 1067s issued for permanent sustainment modifications should identify CDD/CPD requirements the modification is intended to sustain.RUser
A4.2.The CBRD must be based on the JPG, Joint Vision, Air Force Vision, and long-range planning inputs from Joint and Air Force concepts.RUser
A4.3.The CBRD’s capabilities must accurately flow down through the AoA, acquisition strategy, and TEMP to the OT&E concept and OT&E plan.RUser
A4.4.The proposed system design must satisfy projected operational requirements in the CBRD and SPG.RPM
A4.5.The system must provide the needed capabilities against the most current validated threat described in the system’s threat documents.RPM
A4.5.1.Ensure Modeling and Simulation (M&S) requirements are identified early to enable programmed funding.RPM
A4.5.2.Cyberspace threats, attack surfaces, and security requirements must be current. (See Figure 2.3)RUser
A4.6.Joint, multi-national, multi-departmental, or multi-service uses described in the CBRD must be addressed during the system's development.RPM
A4.7.All thresholds and objectives must be stated in operational terms and defined in measurable, beneficial increments of capability.RUser
A4.7.1Ensure measureable and testable criteria for how the system supports military operations, is entered and managed on the network and how effectively it exchanges information is specified with threshold and objective values IAW the Joint Capabilities Integration and Development System (JCIDS) Net-Ready KPP requirement.RUser
A4.7.2Cyber resiliency must be addressed through the JCIDS Survivability KPP.RPM
A4.8.CBRDs must be stated in such a manner that testable MOEs, MOSs, and MOPs are quantitatively measurable through analytically-based evaluation methods when possible.RUser
A4.9.All CTPs, KPPs, MOEs, MOSs, MOPs, threats, definitions, and other criteria must be consistent (harmonized) across the most current support documents (e.g., CBRD, system threat assessment, AoA, Air Force concepts, APB, TEMP).RUser
A4.10.If increments of operational capability are planned, the CPD must be updated to describe the next increment prior to development of the OT&E concept and OT&E plan.RUser
A4.10.1Use Joint Requirements Oversight Council (JROC)-approved “IT Box” strategy for future increments if specified.RUser
A4.11.Changes must be finalized and open issues resolved early enough to ensure no adverse impacts on the successful completion of dedicated OT&E.RUser
A4.12.The CBRD must contain a complete audit trail documenting rationale for all requirements changes, including changes from the APB.RUser
A4.13.Only systems with requirements to “protect users in combat” according to USC 10 § 2366 must be listed as “covered systems.”RUser
A4.14.The CBRD must state the appropriate cybersecurity impact values (High, Moderate, and Low) for Confidentiality, Integrity and Availability as well as listing the appropriate security overlays as described in DoDI 8510.01, Risk Management Framework (RMF) for DoD IT.RUser
A4.14.1.Cybersecurity capabilities must also include the requirement to register the system in the Enterprise Information Technology Data Repository (EITDR), assignment of qualified personnel to RMF roles as well as an initial security control baseline.RUser
Attachment 5
THREAT & INTELLIGENCE DOCUMENTSUSAFResponsible PartyComments
A5.1.Threat assessment document(s) must remain valid and current with updates made prior to each milestone.RUser
A5.1.1Address program impacts of testing against emerging threats which may not be stated in the current validated CBRD including cyberspace threats and impacts.ROTO, PM
A5.2.The system threat assessment document must be approved by AF/A2. For ACAT I programs, the System Threat Assessment Report (STAR) must be validated by DIA.RUser
A5.3.The system’s threat assessment document(s) must be consistent with current DoD threat projections and accurately reflected in the CBRD and AoA.RUser
A5.4.Sufficient threat detail must be provided to support system R&D and the development of realistic operational mission scenarios in support of the ITC, OT&E plan, and schedules.RPM
A5.4.1.All threats must be described in system-specific terms and include system-to-system interfaces.RPM
A5.4.2.Threat shot doctrine and employment tactics must be described.RPM
A5.4.3.The reactive threat and potential countermeasures must be described.RPM
A5.4.4.Sources for projections and areas of uncertainty must be cited.RPM
A5.4.5Adversarial cyber capabilities and tactics must be understood and described.RPM
A5.5.Life-cycle mission data plans (LMDPs) shall be established by the program office, or its predecessor organization, for each Intelligence Mission Data (IMD)-dependent acquisition program and effort beginning at MS A.RPM
Attachment 6
INTEGRATED TEST TEAM (ITT) STANDUP, ITT CHARTERUSAFResponsible PartyComments
A6.1.New-start programs direct establishment of an ITT in the initial ADM as soon as possible after the MDD. (Every program requires an ITT regardless of how long the program has been in existence.)RPM
A6.2.A current ITT Charter describes ITT activities, membership, goals, products, responsibilities, and operating procedures.RPM
A6.2.1.A CDT is identified for MDAP and MAIS programs, or a Test Manager (or CDT) for all other programs. This person and the OTO representative co-chair the ITT.RPM
A6.2.2.The charter covers the entire life cycle of the program.RPM
A6.2.3.If the system comes under an overarching ITT of related systems, the ITT Charter includes provisions for managing multiple systems.RPM
A6.2.4.All program stakeholders are represented (e.g., other Services, interoperable systems, and organizations supporting all types of T&E activities).RPM
A6.2.5.The ITT has sufficient membership participation to be effective.RPM
A6.3.The ITT directs formation of sub-groups to address specific tasks and responsibilities.RITT
A6.4.Research is completed to identify and nominate an LDTO to the PEO or decision review authority, in coordination with AFMC/A3 or AFSPC/A5, as appropriate.RITT
Attachment 7
AIR FORCE CONCEPTSUSAFResponsible PartyComments
A7.1.The Air Force concepts must describe expected system employment and operating concepts, strategies, methods, and tactics in concert with the latest CBRD.RUser
A7.1.1.Sufficient detail must permit early development of operationally realistic test scenarios and tactics for the OT&E test concept and test plans.RUser
A7.2.Operational effectiveness and suitability requirements, criteria, thresholds, objectives, and definitions in the CBRD must accurately flow down (be linked) to the Air Force concepts, which must in turn be linked to the OT&E test concept and OT&E plan.RUser
A7.2.1.Changes in the CBRD, system threat assessment document, AoA, logistics support concepts (LSC), and TEMP must be analyzed for potential impacts on Air Force concepts, which in turn affect T&E plans.RUser
A7.2.2.Changes in the Air Force concepts must be finalized and open issues resolved early enough to ensure no adverse impacts on the successful completion of DT&E, Integrated Testing, Cybersecurity T&E, and dedicated OT&E.RUser
A7.3.Air Force concepts must be available to support development of operationally relevant DT&E and OT&E scenarios.RUser
Attachment 8
LIFE CYCLE SUSTAINMENT PLAN (LCSP)USAFResponsible PartyComments
A8.1.The LCSP must describe the optimal system maintenance strategies, concepts, and methods based on the CBRD’s requirements.RUser
A8.1.1.The system must use an acceptable inter-Service, organic, and/or contractor mix.RPM
A8.1.2.The LCSP must identify potential high-risk and problem areas (such as long lead items, TOs, system reliability, support equipment, training).RUser
A8.2.Logistics and readiness criteria, thresholds, objectives, and definitions in the CBRD must accurately flow down (be linked) to the LCSP, which must in turn be linked to the MOEs and MOPs in the OT&E concept and plan.RUser
A8.3.LCSP strategies and plans must be sufficiently detailed to support early development of the OT&E concept and OT&E plan.RUser
A8.4.Realistic operational and suitability test scenarios that support the integrated test plan must be developed from the LCSP and other Air Force concepts.ROTO
A8.5.The system must be supportable in dedicated OT&E using the LCSP's strategies and plans.RPM
A8.6.The system's design must successfully address the quantitative and qualitative constraints identified in the LCSP.RPM
A8.7.The Doctrine, organization, training, materiel, leadership and education, personnel, and facilities (DOTMLPF) elements must be sufficient to support the LCSP and maintenance plan during dedicated OT&E.ROTO
A8.8.The Depot Source of Repair (DSOR) decision has determined the optimal maintenance posturing decisions needed to support warfighter operational requirements.RPM
A8.9.Reliability and maintainability (R&M) growth plans are developed, coordinated, and documented in the Systems Engineering Plan (SEP) and TEMP.RPM
A8.10.The LCSP integrates the acquisition and product support strategies throughout the system’s life cycle. The LCSP must support Milestone B and follow-on decisions. Note: Space systems are exempt from this requirement.RPM
Attachment 9
INFORMATION TECHNOLOGY (IT) AND NATIONAL SECURITY SYSTEMS (NSS)USAFResponsible PartyComments
A9.1.The NR-KPP defined in the CBRD, consists of testable characteristics, and contains performance measures required for the timely, accurate, and complete exchange and use of information.RUser
A9.1.1.Architecture products (e.g., OV-5, OV-6, and SV-1 to SV-7) are developed and available to the test community.RUser
A9.1.2.Key interface profiles are identified and complied with as applicable.RUser
A9.1.3.Cybersecurity capabilities are planned and designed into system specifications and configurations using the latest threat estimates.RPM
A9.1.3.1.An AO and Information System Security Manager (ISSM) are formally assigned in writing.RPM
A9.1.3.2.Impact values for Confidentiality, Integrity and Availability as well as a listing of the security overlays are in requirements documents and the TEMP.RUser
A9.1.3.3.The cybersecurity strategy, as an appendix to the Program Protection Plan (PPP), is complete and available to the T&E community.RPM
A9.1.3.4.RMF is implemented and the T&E community invited to observe and participate in process activities.RPM, LDTO
A9.1.4.The High Performance Team’s (HPT) architecture expert has ensured compliance with the DoD Information Enterprise Architecture, Version 1.1 and provided a compliance statement to the program office.RUser
A9.2.The Information Support Plan (ISP), Security Classification Guide (SCG), and all RMF –related documents (including a compiled list of system characteristics or qualities required for system registration, key security-related documents such as a risk assessment, privacy impact assessment, system interconnection agreements, contingency plan, security configurations, configuration management plan, and incident response plan) are complete and available to the T&E community as early as possible.RPM
A9.2.1.ISP, SCG, RMF documentation, and PPP are consistent with the TEMP, strategy for T&E, and support T&E execution activities.RPM
A9.3.System cybersecurity training for AOs, ISSMs, security systems administrators, and users is available and completed.RPM
A9.3.1.Trained teams are used to conduct passive and active scans to reveal system/network vulnerabilities, verify system protection and detection capabilities, and complete a NetRA or equivalent as outlined in the TEMP and ISP.RLDTO
A9.3.2.Trained and certified teams are used as opposition forces to conduct penetration testing for assessing the cybersecurity posture of the system/network as part of a vulnerability analysis assessment or equivalent as outlined in the TEMP and ISP.RLDTO
A9.4.NetRA and other interoperability or net-ready certification activities are complete.RPM, LDTO, JITC
A9.4.1.All developer/test passwords, password scripts, and accounts in use during system development are deleted prior to operational testing.RPM
A9.4.2.Compliance with cybersecurity vulnerability alerts will not impact any other type of system certification or potentially invalidate test data.RPM, LDTO
A9.4.3.Data passed to and from other interoperable systems must be compatible.RPM
A9.4.4.JITC has provided an OTRR Interoperability Statement as required.RPM
A9.4.5.The AO has obtained an Interim Authority to Test (IATT) or Authorization to Operate (ATO) memo (as appropriate) prior to test efforts.RPM
A9.5.Systems and subsystems comply with the USAF Electromagnetic Compatibility Program and Radio Frequency Spectrum Management guidelines.RPM
A9.6.Other systems and subsystems required to interoperate with the test articles (including external systems) are available.RPM, OTO
Attachment 10
TEMPUSAFResponsible PartyComments
A10.1.The TEMP must be updated, coordinated, and approved at appropriate levels prior to each milestone and after major program changes.RPM
A10.1.1.Open issues must be addressed and resolved before submission to HQ USAF. Changes required by OSD or other decision authorities must be incorporated as agreed.RPM
A10.1.2.Coordination must be timely and efficiently planned to minimize chances of late rejection and negative impacts on dedicated OT&E.RPM
A10.2.Level of detail must be appropriate for the stage of development, and “TBDs” eliminated as much as possible. MOEs, MOSs, CTPs, COIs, and Decision Support Questions (DSC) are included in the Developmental Evaluation Framework (DEF) Matrix.RPM
A10.3.The TEMP must accurately reflect the most recent CBRD, system threat assessment documents, LSC, Air Force concepts, and AoA.RPM
A10.4.The TEMP must clearly summarize relationships between: 1) the strategy for T&E, program schedule, and required resources; 2) CBRD parameters, COIs, CTPs, MOEs, MOSs, and 3) DEF, KPPs, CTPs, KSAs, Failure Modes, Effects and Criticality Analysis (FMECA), interoperability requirements, cyber-security requirements, reliability growth, maintainability attributes and developmental test objectives, other evaluation criteria, and decisions supported.RPM, OTO
A10.4.1.The OT&E concept and plan must be executable in terms of structure, schedule, and resources.RPM
A10.4.2.The requirements strategy (as reflected in the ICD and draft CDD) and acquisition strategy are fully supported (manpower, funding, test infrastructure, articles including M&S, and agencies).RPM
A10.4.3.T&E test resource shortfalls or limitations potentially impacting dedicated OT&E must be identified.RPM
A10.4.4.Describe the M&S assets needed for dedicated OT&E.RPM
A10.4.5.Ensure the VV&A process and agency responsibilities are described for each M&S capability, to include expected products and approvals.RPM, OTO
A10.4.6.If LFT&E is required, include the LFT&E strategy in the TEMP.RPM
A10.4.7.Appropriate cyber test measures included to evaluate operational capability to protect, detect, react, and restore to sustain continuity of operation.RPM
A10.4.8.Ensure Cost Capability Analysis has been completed.RPM
A10.5.The TEMP must describe what DT&E, OT&E, or integrated test has done or will do to ensure the system has the potential to meet operational requirements in dedicated OT&E, including assessing schedule and product risks with requisite margins, and assessing mitigation plans of above.RPM
A10.5.1.Show how all COIs and MOEs and MOSs will be addressed in dedicated OT&E.ROTO
A10.5.2.Contractor-conducted vs Government-conducted DT and OT are clearly distinguished and mutually supportive.RITT
A10.6.Rationale and provision must be made for any planned OT&E deferred beyond dedicated OT&E into Follow-On Test and Evaluation (FOT&E) or follow-on increments.RPM
A10.7.Links to required detailed information cited in the TEMP must be functional and the linked information complete. Sufficient detail is available for:RPM
A10.7.1.Reliability growth curves and planning.RPM
A10.7.2.STAT calculations and analyses.RPM, OTA
A10.7.3.Allocation of reliability among key components.RPM
A10.7.4.Anticipated development and test problem areas.RPM, LDTO
A10.7.5.Resolution of past deficiencies.RPM
A10.7.6.Cyber T&E strategy and resources and includes specified cyber content: architecture, operational environment, evaluation structure, ATO, time and resources, cooperative vulnerability and penetration assessment, and adversarial assessment.RLDTO, OTO
A10.7.6.1.Cyber test (cooperative vulnerability and penetration assessment, and adversarial assessment) events for DT&E, OT&E, and Integrated Test.RLDTO, OTO
A10.7.6.2.RMF planning is described.RPM
A10.8.The requirements strategy (as reflected in the ICD and draft CDD) and acquisition strategy are fully supported (manpower, funding, test infrastructure, articles including M&S, and agencies).RPM
A10.9.Ensure the TEMP includes applicable test scenarios, appropriate data collection (established T&E database), and performance evaluation over the life cycle of the system.RPM
Attachment 11
INTEGRATED TEST PLANNINGUSAFResponsible PartyComments
A11.1.Ensure integrated test planning starts as early as practical to make T&E schedules and resource expenditures more efficient and eliminate duplication of effort.RPM
A11.1.1.A rigorous SEP identifies how T&E will be used to achieve program goals and technical results.RPM
A11.1.2.A rigorous TEMP specifies how T&E will be planned and used to verify and validate program requirements are met to ensure the system is operationally effective and suitable.RPM
A11.1.3.DT&E and OT&E plans and concepts are structured so that OT can capture and apply DT&E data to reduce OT&E timelines and requirements.RITT
A11.1.4.OAs are planned at strategic points in the development program. OAs and early user inputs influence system design and function.RPM, OTO
A11.1.5.Other types of T&E (e.g., cybersecurity, LFT&E, contractor) are incorporated as much as practical in the integrated test design.RPM
A11.1.6Dedicated operational test and developmental test objectives are not compromised.RITT
A11.1.7.STAT process employed to ensure T&E is effective, efficient, and appropriate factors and conditions selected to produce the data required to characterize system capabilities.RPM
A11.1.8.Ensure the Integrated Test Concept (ITC) and TEMP reflect the most current program direction.RPM
A11.2.Definitions, formulas, and evaluation criteria used to determine operational effectiveness and suitability must be consistent between all individual test plans and T&E documents.RITT
A11.3.A common T&E database is used to archive all T&E data from all test organizations.RPM
A11.3.1.Parameters and formats are agreed upon between all test teams.RITT
A11.3.2.Test item configurations are rigorously controlled.RPM
A11.4.Integrated test matrices are addressed in the TEMP and depicts all T&E events and who will accomplish them.RITT
A11.4.1.Duplication and voids in testing are minimized.RITT
A11.4.2.A prudent number of backup resources (e.g., test assets, funds) are available to supplement all testing if planned integrated DT&E/OT&E data is unusable or unavailableRPM
ATTACHMENT 12
CYBER RESILIENCYUSAFResponsible PartyComments
A12.1.Cyber resiliency goes beyond “cybersecurity” to include cyber detection and response. Ensure cybersecurity phases shown in Figure 2.3 are reviewed to ensure currency of the strategies for operational requirements, acquisition, T&E, and cybersecurity. Use Figure 2.3 for the rest of this template.RITT
A12.1.1.System's Cybersecurity Strategy, Security Plan (SP), SCG, and PPP are current.RPM
A12.1.2.Cyber resiliency assessments are integrated into DT&E and OT&E.RITT
A12.1.2.1.OT plan addresses required DOT&E cybersecurity content: TEMP linkage, architecture, intelligence community-validated cyber threat, operational environment, evaluation structure, time and resources, cooperative vulnerability and penetration assessment, and adversarial assessment. Plan should also address cybersecurity software assurance considerations.RITT
A12.1.3.Six-step RMF process (1. Categorize System, 2. Select Security Controls, 3. Implement Security Controls, 4. Assess Security Controls, 5. Authorize System, 6. Monitor Security Controls) is followed. Establish an ITT sub-group to monitor and control, if necessary.RPM
A12.1.4.Confidentiality, Integrity, and Availability ratings as well as a listing of security overlays are properly assigned.RPM
A12.1.5.Applicable overlays are applied so that appropriate security controls are selected and updated.RPM
A12.1.6.Cyber-attack surfaces, threats, etc. are properly characterized and updated.RPM
A12.1.7.Cyber kill chain is correctly understood, analyzed, and updated.RPM
A12.1.8.System's Functional Hazard Analysis is current for cooperative vulnerability, penetration assessment and adversarial team baseline, and determining safety and real-world operations considerations.RPM
A12.2.Cyber test infrastructure (with appropriate architecture, level of realism, and security) and documentation is available and described in the TEMP.RPM
A12.2.1.System owners agree on rules of engagement for all teams.RPM
A12.2.2.Reciprocity agreements are in place between teams and other Services.RPM
A12.2.3.Test plans with refined cyber T&E scenarios, operational capability requirements, potential test venues, mission threads, and simulated scenarios are developed and approved.RITT
A12.2.4.Funding is available to complete cooperative vulnerability, penetration assessment, and adversarial assessment test events.RPM
A12.2.5.The IATT and ATO are available at the appropriate times.RPM
A12.2.6.SAR is prepared, recommended corrective actions and system weaknesses are addressed and prepared for.RPM
A12.2.7.All cyber testing planned to be conducted on a cyber range is identified and all events integrated with OT&E and assessment activities.RPM
A12.2.8.All necessary linkages between the cyber range and operational networks are developed.RPM
A12.2.9.Integration plan established for system operators, network defenders, and threat emulations on planned Cyber Range if conducting cyber range testing.RPM
A12.3.Cooperative vulnerability, penetration assessment and adversarial teams are available and scheduled.RPM
A12.3.1.Testability of cyberspace requirements are determined and additional clarified.RPM, OTO
A12.3.2.Applicability of network defender participation in adversarial assessment team OT&E events is determined.ROTO
A12.3.3.Limitations of generating operational effects during cybersecurity adversarial assessment OT&E events due to safety and real-world operations considerations are identified and documented.ROTO
A12.3.4.Quantitative cyber resiliency factors, descriptors and tailored measures are identified.ROTO
A12.3.5.The threat basis on which vulnerability/penetration testing scenarios will be built is identified and documented in the test concept and scenarios.ROTO
A12.3.6The Test Resource Plan (TRP) includes updated resources and costs associated with cooperative vulnerability, penetration assessment and adversarial test events.ROTO, PM
A12.4.Identify security constraints and their impacts on dedicated OT&E.RPM, LDTO
A12.4.1.Receipt of permissions and rules of engagement before DT&E cooperative vulnerability, penetration assessment and adversarial events.RPM, LDTO
A12.4.2.Cyber anti-tamper testing is integrated into DT&E and OT&E to the extent warranted and permissible.RPM, LDTO
A12.5.System OPSEC plan is current.RPM
A12.6.If NSA certification is required for classified/controlled cryptographic items, the program’s security verification test approach must be included in the TEMP.RPM, ITT
ATTACHMENT 13
CONTRACTOR TESTINGUSAFResponsible PartyComments
A13.1.Ensure all system specifications and contractor requirements support the latest CBRD.RPM
A13.2.Ensure comprehensive contractor test plans for development, qualification, and production acceptance testing are in place.RC
A13.2.1.Requirements and specifications must flow down accurately and clearly from prime contractors to subcontractors.RC
A13.2.2.Contractor test strategies and methods must determine if all aspects of the specification and the CBRD can be met.RPM, LDTO
A13.2.3.Test events should be performed with operationally relevant components/elements and under operationally relevant conditions and scenarios as much as possible with exceptions agreed to by all stakeholders and/or limitations cited.RC
A13.2.4.Sub-system and system pass/fail specification thresholds must be directly traceable to the most current CBRD.RPM
A13.2.5.A realistic, attainable, event-driven test schedule must be proposed and funded.RC
A13.2.6.Known risks are reasonably and appropriately managed.RC
A13.2.7.All contractor test data must be available in the system’s common T&E data baseRPM
A13.2.8.Ensure contractor testing is included in the ITC and described in the TEMP.RPM
A13.2.9Ensure the contractor is capable to plan and conduct special and formal multi-segment and system of system testing, including test support, handling, calibration, and transportation.RPM
A13.3.Contractor testing must demonstrate the system and/or components are meeting the CTPs at prescribed threshold levels and within defined time frames at each step in development.RC
A13.3.1.Government systems engineering analysis should determine if test results support achievement of the spec and if the system is projected to meet operational requirements.RLDTO
A13.3.2.Fault tree analysis must be performed on the operational system and its external and internal interfaces to identify potential operational contributors to mission failure.RC
A13.4.Available government facilities are used in contractor testing wherever cost-effective, available, and feasible.RPM
A13.5.A deficiency resolution system must be in place and accessible to all test organizations to identify, track, and resolve test failures.RC
A13.5.1The contractor’s DR process must be compatible with the Government’s DR process.RPM
A13.5.2.All test failures and resultant system design changes must be documented and analyzed for effectiveness. Tests must be repeated as necessary to certify specification compliance.RC
A13.5.3Document all changes to specification threshold (pass/fail) values and rationale.RPM
A13.6.Contractor T&E data and information must be available in the required formats for Government review for impacts on DT&E and dedicated OT&E.RC
A13.7.Planned contractor testing must be completed according to the contract before government acceptance and dedicated OT&E.RC
A13.7.1.Contractor testing deferred beyond government acceptance of the system is documented for final certification of system readiness.RPM
ATTACHMENT 14
GOVT DEVELOPMENTAL TEST AND EVALUATION (DT&E)USAFResponsible PartyComments
A14.1.CBRD requirements must be accurately reflected in Government DT&E plans and be demonstrated during contractor and government DT&E.RPM
A14.2.When design-cost-performance trade-offs are made that may impact CBRD requirements, user concurrence must be obtained and documented where appropriate.RPM
A14.3.The DT&E schedule and testing must be planned and executed to allow sufficient time to certify system OT&E readiness, start and complete dedicated OT&E before FRP or fielding.RPM
A14.3.1.DT&E, with inputs from LDTO, must validate contractor testing is complete, or a plan exists to finish testing.RPM
A14.3.2.Sufficient suitability testing must be conducted to permit credible predictions about system Reliability, Maintainability, and Availability (RM&A).RLDTO
A14.3.3.All CTPs must demonstrate satisfactory performance, or be supported by reliability growth plans and/or curves that show threshold attainment.RPM
A14.4.A government-run DR system must be in place in support of DT&E and OT&E for identifying, tracking, reporting, and resolving DRs.RPM
A14.4.1.Correction of all CAT I deficiencies including cybersecurity vulnerabilities identified during DT blue team/red team events are implemented before start of dedicated OT&E.RPM
A14.5.A formal process is in place to control and track system configuration during DT&E that will support dedicated OT&ERPM
A14.5.1.The system design must be stabilized sufficiently early with no major changes implemented in the OT&E test articles.RPM
A14.6.Sufficient operationally relevant DT&E must be accomplished, culminating in a "dress rehearsal" in the final phase, to determine if CBRD requirements can be met before dedicated OT&E.RLDTO
A14.6.1.Cooperative vulnerability and penetration assessment, and adversarial assessment tests of cyber resiliency are complete.RPM, OTO
A14.6.2.Sufficient testing must be accomplished with other systems to support end-to-end cybersecurity and interoperability certifications.RPM
A14.6.3.Required levels of performance must be demonstrated in the intended operational environment based on the CBRD, Air Force concepts, strategies, and plans.RPM
A14.6.4.Sufficient workarounds acceptable to the OTO are identified for CAT II vulnerabilities deficiencies.RPM
A14.6.5.If there are interoperability requirements, DT&E must take place at the system-of-systems level.RPM
A14.7.LFT&E results (if required) must be available before start of dedicated OT&E.RPM
A14.8.Formal certifications may be required from the following sources (among others). Ensure clearances and certifications are available for use in dedicated OT&E.RPM
A14.8.1.Non-nuclear Munitions Safety BoardRPM
A14.8.2Directed Energy Weapons Safety BoardRPM
A14.8.3Flight Safety BoardRPM
A14.8.4Airworthiness, Spaceflight WorthinessRPM
A14.8.5Range SafetyRPM
A14.8.6Nuclear Weapons CenterRPM
A14.8.7Institutional Review Board for Protection of Human Subjects in TestingRPM
A14.8.8SEEK EAGLE certification completed for threshold systems as a minimumRPM
A14.8.9AF Spectrum Management OfficeRPM
A14.8.10Authorization to Operate (ATO)RPM
A14.9.For integrated testing, minimize duplication and voids in testing and the excessive use of facilities.ROTO
A14.9.1.DT&E data formats and parameters are compatible with other tests to maximize data availability in the common database and usability for OT&E.ROTO
A14.10.An agreed-upon plan and rationale must exist (e.g., in the TEMP) for testing any areas or capabilities deferred past the start of dedicated OT&E.RPM
A14.10.1If there are any incomplete test areas, explain why and give impacts on dedicated OT&E with inputs from the OTO.RLDTO
A14.11.Ensure sufficient interim DT&E results and evaluations are available to support certification of readiness for operational testing.RLDTO
ATTACHMENT 15
SOFTWARE DEVELOPMENT AND MATURITYUSAFResponsible PartyComments
A15.1.System software functionality, performance, and maturity must be assessed throughout the systems engineering technical reviews from SRR through OTRR and developmentally tested at the full system level (suitable for that increment) prior to starting dedicated OT&E.RPM
A15.2.Define software-related exit criteria for MS B. These criteria may be modified and/or criteria added/deleted in response to CBRD changes during system development.RPM
A15.3.Develop and implement a "requirements traceability" metric to measure adherence of software products (to include architecture, design, and code) to the CBRD.RPM
A15.4.Operational databases are complete and sufficient for operational test and contain actual operational data.RPM
A15.5.System level integration testing of software and hardware-software-firmware interfaces must be monitored, documented, and completed.RPM
A15.6.Effective software configuration management and control procedures are in place.RPM
A15.7.Software manuals and documentation must be validated and up-to-date with the current software baseline in support of dedicated OT&E.RPM
A15.8.Software and firmware configurations must be fully documented and frozen before starting dedicated OT&E. Changes must not be implemented during dedicated OT&E that would impact the configuration being fielded or produced.RPM
A15.8.1.Incrementally deployed software releases address specific capabilities and testable performance requirements and must be assessed ready for test. Each release must undergo dedicated OT&E. Software builds or increments that are not deployed individually (release) must still support full deployment system OT&E.RPM
A15.9.The software must be stable (i.e., operate error free for a reasonable length of time prior to dedicated OT&E).RPM
A15.10.Facilities, tools, and manpower must be sufficiently representative to support the OT&E plan and schedule, and fielding of the software.RPM
A15.11.Required Software Assurance (SwA) Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG) and CNSSI 1253 controls and protection mechanisms are identified, implemented, and tested to prevent system compromise, maintain integrity and availability, and prevent unauthorized access to systems and data.RPM
A15.11.1.Require the use of automated vulnerability analysis tools & techniques throughout the lifecycle. Determine appropriate remediation strategies for all identified SwA vulnerabilities.RPM
A15.12.For critical software, employ independent SwA Verification & Validation (V&V) organizations through DT.RPM
A15.13.Known software and firmware vulnerabilities, exploitability levels, and discrepancies affecting system performance or the dedicated OT&E must be properly documented and appropriate corrective action(s) taken.RPM
A15.13.1The software must be analyzed for safety critical functions and determined acceptable for operational use.RPM
A15.14.Sufficient regression testing must be accomplished at the unit, integration, and system-of-systems level to ensure changes do not introduce operationally critical faults and/or result in additional defects.RPM
Attachment 16
LIVE FIRE TEST AND EVALUATION (LFT&E)USAFResponsible PartyComments
A16.1.Review the most current threats and operational scenarios in the CBRD, threat documents, Air Force concepts, and AoA to assess whether or not a "covered system”.RPM
A16.1.1.Consult AF/TEP, users, and OSD/DOT&E (in that order) for concurrence with the determination of covered system status.RPM
A16.2.If the system is a covered system, determine LFT&E scope and complete a cost-benefit analysis.RPM
A16.3.If full-up LFT&E is determined to be cost-effective and practical, develop an LFT&E strategy, to include the level of funding, and submit to OSD/DOT&E for approvalRPM
A16.3.1.Describe the LFT&E strategy in the TEMP and submit individual plans for “full-up system level” LFT&E to OSD/DOT&E for approval.RPM
A16.3.2.Fully integrate the LFT&E strategy and plans into the overall strategy for T&E, TEMP, and integrated test plans.RPM
A16.3.3.Plan for and fund LFT&E to be completed before start of dedicated OT&ERPM
A16.4.If full-up LFT&E is determined not to be cost-effective and practical, prepare an LFT&E waiver request and an alternate LFT&E plan for the decision review authority or PEO and OSD/DOT&E approval before MS B.RPM
A16.4.1.Describe the alternate vulnerability/lethality strategy in the TEMP.RPM
A16.4.2.Plan for and fund “alternate” LFT&E to be completed before start of dedicated OT&E.RPM
A16.5.Deficiencies identified during LFT&E that are to be corrected must be tracked and retested prior to certification for dedicated OT&E.RPM
A16.6.Fully comply with all system-specific congressional direction regarding LFT&E.RPM
A16.7.With regard to threat systems for LFT&E:R
A16.7.1.Threat "shot doctrine" and employment tactics must reflect the contents in the CBRD, Air Force concepts, and threat documents.RPM
A16.7.2.Threat systems and threat models are VV&A’ed before use in LFT&E.RPM
A16.7.3.Identify limitations in the test threats and voids in covering the threat spectrum. Describe proposed fixes.RPM
A16.7.4.Where limitations exist in test threat systems, obtain approval to fill gaps with M&S and alternative systems.RPM
A16.8.Develop a data reduction and common database for using all validated threat test data throughout the integrated test plan.RPM
ATTACHMENT 17
MODELING AND SIMULATION (M&S)USAFResponsible PartyComments
A17.1.Ensure M&S requirements are identified in CBRDs to obtain funding and support for their development or reuseRUser
A17.2.Develop a Modeling and Simulation Support Plan (MSSP) that links M&S requirements to the capabilities being developed and tested throughout the program (from the AoA through the MS C decision). The MSSP can be part of existing program, engineering or technical plans.RPM
A17.2.1.Identify as early as possible the M&S support requirements, to include funding, over the entire system life cycle.RPM
A17.2.2.The MSSP must address continuing ownership and maintenance of M&S assets after system fielding.RPM
A17.2.3.Identify M&S linkages with planned interfacing and interoperable systemsRPM
A17.2.4.Check for archived M&S tools (e.g., with Air Force Modeling and Simulation Resource Repository (AFMSRR)) before building new M&S resources.RPM
A17.2.5.Ensure programs obtain data and models for M&S from the required authoritative sources when available and feasible.
A17.3.Ensure M&S assets, test tools, and analysis tools will be available and usable for T&E as required. Testers must receive adequate training as required.RPM
A17.4.Ensure M&S V&V plan and comprehensive schedule supports the integrated test plan and the dedicated OT&E plan and schedule.RPM
A17.4.1.Scenarios, test tools, and analysis tools required for DT&E must be adequately documented.RPM
A17.4.2.The design engineering data must be reviewed. Physics models can be V&V'd, whereas operations analyses are subjectively V&V'd. Empirical test data should be used to establish model credibility.RPM
A17.4.3.Any M&S used to support dedicated OT&E must be accredited.ROTO
A17.5.If M&S will generate results used to support a fielding and/or FRP decision on an OSD T&E Oversight program, OSD/DOT&E must approve its use in dedicated OT&E.ROTO
ATTACHMENT 18
CONFIGURATION MANAGEMANT PLAN (CMP)USAFResponsible PartyComments
A18.1.Configuration management must be a key element of a rigorous systems engineering process.RPM
A18.1.1.The systems engineering process must be used for all system components and support items (e.g., hardware, software, support equipment, spares, Government Furnished Equipment (GFE)).RPM
A18.2.A configuration control mechanism must be used to ensure the orderly transition from one decision review to the next, and from development to production.RPM
A18.2.1.The Government must have sufficient control or oversight over the configuration to ensure changes do not invalidate the results of dedicated OT&ERPM
A18.2.2.The exact system configuration must be traceable throughout the program.RPM
A18.3.If known deficiencies remain in test articles before start of dedicated OT&E, the SEP must describe strategies for managing the following areas:RPM
A18.3.1.System form, fit, and function must not be adversely affected as a result of each deficiency correction.RPM
A18.3.2.The impacts of fixing before versus after dedicated OT&E must be assessed.RPM
A18.3.3.All changes are documented and under configuration control.RPM
A18.4.The system configuration and configuration of interfacing systems must be stable and production representative before the start of dedicated OT&E.RPM
ATTACHMENT 19
DEFICIENCY IDENTIFICATION AND RESOLUTION PROCESSUSAFResponsible PartyComments
A19.1.A contractor-operated DR process, if established, will augment the Joint Deficiency Reporting System (JDRS) process.RC
A19.2.JDRS incorporated and open to all stakeholders for promptly identifying, reporting, tracking, and resolving system deficiencies.RPM
A19.3.A MIPRB must ensure resolution of all DRs and list the impacts to dedicated OT&E.RPM
A19.4.A Deficiency Review Board (DRB) will periodically review, validate, and prioritize all open DRs.RPM
A19.4.1.DRs should be rank-ordered, and the most critical worked first or as agreed by the user(s), operational tester, and LDTO.RPM
A19.5.Open DRs from DT&E must not preclude successful conduct of dedicated operational testing and the achievement of operational requirements.RPM
A19.5.1.Dedicated operational test results will not be invalidated due to deferred DR resolution.RPM
A19.5.2.The DR analysis process must be complete and coordinated with users and testers prior to the start of dedicated OT&E.RPM
A19.6.Known DRs or capabilities deferred beyond the start of dedicated OT&E must be reviewed and prioritized by a T&E DRB and an impact analysis performed.RPM
A19.6.1.Category I DRs must be fixed and closure verified according to an agreed upon plan.RPM
A19.6.2.Category II DRs must be fixed and closure verified, or suitable work-arounds provided.RPM
A19.7.For DRs that cannot be resolved prior to start of dedicated OT&E, a plan exists for testing deferred capabilities and fixes after dedicated OT&E is accomplished.RPM
A19.7.1.The plan addresses how open DRs are tracked from increment to increment after OT&E is complete.RPM
A19.8.A Joint Reliability and Maintainability Evaluation Team (JRMET) and a Test Data Scoring Board (TDSB) must be established to review all Reliability, Availability, and Maintainability (RAM) data.RITT
A19.9.Plan of Action and Milestones (POA&M) shows how cybersecurity DRs and vulnerabilities will be resolved.RPM
ATTACHMENT 20
PRODUCTION REPRESENTATIVE TEST ARTICLESUSAFResponsible PartyComments

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .