快速评估和整合软件工程 2.0备忘录2022年

VIP文档

ID:19925

大小:0.56 MB

页数:2页

时间:2022-11-23

金币:5

上传者:战必胜
DEPARTMENT OF THE NAVY
USMC, US NAVY, DEPARTMENT OF THE NAVY
1000 NAVY PENTAGON
WASHINGTON DC 20350-1000
JOINT MEMORANDUM FOR DISTRIBUTION
Subj: Rapid Assess and Incorporate Software Engineering 2.0
Ref: (a) Department of Defense Instruction (DoDI) 8510.01, Risk
Management Framework (RMF) for DoD Information
Technology (IT), Jul 17, change 3, Dec 2020
(b) Department of Defense (DoD) Enterprise DevSecOps
Strategy Guide 2.0, Oct 2021
(c) Department of Navy Strategic Intent for Software
Modernization, Aug 2021
(d) Rapid Assess and Incorporate Software Engineering
(RAISE) 2.0 Implementation Guide, Oct 2022
1. This memorandum announces the Rapid Assess and Incorporate
Software Engineering (RAISE) 2.0 Implementation Guide in
accordance with references (a) through (d). RAISE 2.0 supports
direction from reference (c) to maximize practices that
prioritize security throughout the software development
lifecycle. Effective immediately, all programs with new software
starts and/or upgrades using containerized technologies must use
the RAISE 2.0 Implementation Guide.
2. RAISE 2.0 incorporates Agile and DevSecOps principles to
streamline and accelerate the RMF process using automation,
cyber verification tools, and certified Continuous Integration /
Continuous Delivery (CI/CD) pipelines to ensure containerized
software applications are built, tested, and deployed secure.
3. Using RAISE 2.0, containerized software applications will be
assessed and incorporated into an existing RAISE Platform of
Choice (RPOC) Authority to Operate (ATO) and are not required to
have a separate ATO.
4. The RAISE 2.0 Implementation Guide has been developed with
input from both the US Navy and US Marine Corps. The Services
may maintain internal guidance aligned with this policy sharing
any updates within the DON
5. Any programs with new software starts and/or upgrades using
containerized technologies that require an exception to this
policy must be escalated through respective Service chains of
command to the appropriate Deputy DON Senior Information
Security Officer as required to resolve in a timely manner.
资源描述:

当前文档最多预览五页,下载文档查看全文

此文档下载收益归作者所有

当前文档最多预览五页,下载文档查看全文
温馨提示:
1. 部分包含数学公式或PPT动画的文件,查看预览时可能会显示错乱或异常,文件下载后无此问题,请放心下载。
2. 本文档由用户上传,版权归属用户,天天文库负责整理代发布。如果您对本文档版权有争议请及时联系客服。
3. 下载前请仔细阅读文档内容,确认文档内容符合您的需求后进行下载,若出现内容与标题不符可向本站投诉处理。
4. 下载文档时可能由于网络波动等原因无法下载或下载错误,付费完成后未能成功下载的用户请联系客服处理。
关闭