{"title":"Security considerations in the acquisition of computer systems","authors":"Captain Charles R. Pierce","doi":"10.1109/CSAC.1991.213002","DOIUrl":null,"url":null,"abstract":"The paper describes Air Force System Security Memorandum (AFSSM) 5024, security considerations in the acquisition of computer systems, and how to go about a multidisciplinary approach for including security in any system development or acquisition. The AFSSM is a handbook for program managers providing guidance on developing security specifications for requests for proposals (RFP), including contract data requirements list (CDRL) and data items descriptions (DID). It also provides the delivery timing of resulting deliverables in the development life cycle. In addition to discussing the document, the paper describes some lessons learned from using the AFSSM's draft versions, the status of its development and its future use.<<ETX>>","PeriodicalId":108621,"journal":{"name":"Proceedings Seventh Annual Computer Security Applications Conference","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1991-12-02","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings Seventh Annual Computer Security Applications Conference","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CSAC.1991.213002","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
The paper describes Air Force System Security Memorandum (AFSSM) 5024, security considerations in the acquisition of computer systems, and how to go about a multidisciplinary approach for including security in any system development or acquisition. The AFSSM is a handbook for program managers providing guidance on developing security specifications for requests for proposals (RFP), including contract data requirements list (CDRL) and data items descriptions (DID). It also provides the delivery timing of resulting deliverables in the development life cycle. In addition to discussing the document, the paper describes some lessons learned from using the AFSSM's draft versions, the status of its development and its future use.<>