Attachment_6_Software_Vendor_Integrity_Statement_Guidelines_Application_Software.docx
DOCX document 15 KB Posted
- Attached to
- Advanced Joint Terminal Attack Controller Training System (AAJTS) Federal contract opportunity
- Solicitation number
- ID07170051
- Issued by
- GSA Federal Acquisition Service
About this file
Attachment 6 Software Vendor Integrity Statement Guideline Application Software
View the file
Other files for this federal contract opportunity
Show all 17
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SECTION J
Attachment 6 Software Vendor Integrity Statement Guidelines: Application Software
DESCRIPTION
The Vendor Integrity Statement for software shall be a written and signed Contractor certification that assures that each trainer application software delivered to the Government has been examined according to DoD and Air Force policies and procedures. The results of the examinations must indicate that the software has no elements that might be detrimental to the secure operation of the resource operating system. Elements detrimental to the secure operation include:
1. Malicious code
1. Trojans, worms, logic bombs, and other computer viruses
1. Backdoors
1. Ad-ware, Spy-ware, or web bugs that have the ability to track user behavior
1. Code that permits functions that are beyond the actual publicized intent of application capability
1. Software that will not function properly with the operating system configured securely
BACKGROUND
DoDI 8500.01, Cybersecurity, requires that IA-enabled products (such as operating systems) comply with the evaluation and validation requirements of DoDI 8510.01 Risk Management Framework for DoD Information Technology. Paragraph 9.b.11 of DoDI 8500.01 requires that IA-enabled IT products incorporated into DoD information systems be configured in accordance with DoD-approved security configuration guidelines.
CONTENT AND FORMAT
The Vendor Integrity Statements for trainer application software shall consist of the following certification, dated and signed by an authorized representative of the Contractor, on company letterhead. A sample follows:
Software Vendor Integrity Statement: Application Software Sample
TO: USAF GPO
RE: Vendor Integrity Statement for Software for Device XXXXX, under Contract XX-X-XXXX
I certify that for xxxx software, version xx, there are no elements that might be detrimental to the secure operation of the resource operating system. The software runs with the operating system configured according to DODI 8500.01, Cybersecurity, paragraph 9.b.11, and DoDI 8510.01 Risk Management Framework.
Signed
Company Representative
File details come from the government source that posted it.