29. DRAFT - Template-DHA RMF System Enterprise and Information Security Architecture.pdf
PDF 1 MB Posted
- Attached to
- Charleston Consolidated Storage Distribution Center Federal contract opportunity
- Solicitation number
- Not on record
About this file
This document provides a template for a Detailed Architecture Diagram and Network Topology for a DHA RMF system. The template outlines minimum requirements for the diagram including delineating accreditation boundaries, identifying connection details, equipment inventory with IP addresses and hostnames, servers with functions, wireless and remote access details, and flow of information. Device icons, a legend, and labeling are specified. The template is intended to clearly show the system boundary and components to be tested per the DISN Connection Process Guide.
The second document is a Special Notice for an upcoming solicitation by the USACE Little Rock District. The requirement is for an initial outfitting project for the Charleston Consolidated Storage and Distribution Center with an estimated value between $1.5-2 million. The acquisition will use FAR Part 12 and 13 procedures and be a total small business set-aside under NAICS code 337127. The Special Notice informs potential contractors in advance of a request for quote solicitation to be issued with a tentative proposal due date of September 2, 2022 and site visit planned for August 23, 2022. Questions may be asked until August 25, 2022 regarding the draft documents provided. Potential award and start dates are also included.
View the file
Other files for this federal contract opportunity
Show all 37
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DHA RMF SYSTEM ENTERPRISE AND INFORMATION SECURITY ARCHITECTURE REQUIREMENTS
Per the DISN Connection Process Guide (CPG), section 3.8 - Customer Network Enclave Topology Diagram Requirements, the Architecture Diagram(s) must clearly show the boundary and the systems to be tested.
Minimum requirements for Detailed Architecture Diagram/Network Topology (If bullets are not applicable to your System, identify the System that it is inherited from):
Revision history page be populated with the latest date of change.
eMASS System Name & eMASS ID
Clearly delineate accreditation boundaries
Identify the CCSDs of all connections to the DISN
Identify the city and state where the component are located and building names and numbers (if applicable)
Identify equipment inventory (to include the most recent configuration including any enclave boundary firewalls, Intrusion Detection Systems (IDS), premise router, routers, switches, backside connections, Internet Protocol
(IP) addresses, encryption devices, Cross Domain Solutions (CDS)
Identify any connections to other systems/networks/enclaves
Identification of other connected enclaves must include:
The name of the organization that owns the enclave
The connection type (e.g., wireless, dedicated point-to-point, etc.)
The organization type (e.g., DOD, federal agency, contractor, etc.)
Identify Internetworking Operating System (IOS) version
Each hardware component shown on the diagram must include an IP address and host name (traceable to the Detailed Hardware Inventory list)
Each server component shown on the diagram must include the type of server (e.g. Database, Web, File, etc.)
Workstation subnets can be represented using a range of IP addresses, icons for individual workstations are not required
Printer subnets can be represented using a range of IP addresses, icons for individual printers are not required
Perimeter devices within the authorization boundary that control inbound and outbound access must be clearly identified
Components within the authorization boundary supporting remote access must be clearly identified
Wireless devices within the authorization boundary must be clearly identified.
All components with IP addresses must be represented on the Detailed Architecture Diagram.
The IP addresses on the diagram should be traceable to the Detailed Hardware Inventory and the IP addresses on the Detailed Hardware Inventory should be traceable to the diagram.
The Architecture Diagram(s) shall depict the interconnected ISs. Each interconnected IS should have an Interconnection Agreement or Service Level Agreement (SLA).
Diagram(s) must have a legend and be legible. The flow of information to, from, and through all connections, host IP addresses, and CCSD number, if known must be shown
Rev. # Description Date Drawn By 1 Creation 3/25/2021 Carmeshia Miller
REVISIONS
REVISIONS
ZONE REV DESCRIPTION DATE APPROVED
Symbol Count Description
Legend Subtitle
Legend
1 Print server
1 Server
1 Email server
1 Database server
1 Web server
Application server
1 File server
1 Firewall
1 Printer
1 Switch
1 Router
1 PC
1 Laptop computer
Multi-function device
1 Bridge
Wireless access point
Content management server
1 Proxy server
1 Router.132
1 ATM switch.134
Communications Link
Ethernet
ACCREDITATION BOUNDARY
(Shaded in Red)
DRAWN BY
CARMESHIA MILLER
REVISED
4/14/2021
TITLE
System Name (Acronym)
DATE
12/10/2018
File Server
Exchange/Email Server
Server
Web Server
Database Server
Print Server
Application Server
DEVICE ICONS - SERVER DEVICE ICONS - NETWORK
DEVICE ICONS – WORKSTATION
& PRINTERS
Firewall
Printer
SwitchRouter
PC/Workstation
Laptop
Multi-Function Device
Bridge
Wireless Access Point
Content Manager Server
Proxy Server
NOTE: You may add or remove devices as applicable.
NIPRNet
Router
Switch
Room # XXX
443: HTTPS, TLS v1.0
North Beach Pavilion, JBSA Ft Sam Houston, TX
Frontend Servers X.X.X.X
XXXXX Internal Database Servers / Backups Server
XXXXX-OSB
Oracle S7 – Backups Srvr
Solaris 11.4
IP: X.X.X.X
[System Name] System Enterprise and Information Security Architecture
XXXXX Web Application
XXXXX Server Application
MHS, .MIL,
MJAD, NIPR
System Acronym
1521; TCP (Oracle) 22; SSH (Secure File Transfer)
123; NTP (Network Time Protocol
System Acronym Accreditation Boundary -
Overview
22; SSH
111; TCP
123; NTP
(System Acronym) – Lackland AFB, TX
XXXXX-DB01
Database/Web Srvr
SPARC T4-1
Solaris 11.4
IP: X.X.X.X
XXXXX-DB02
Database/Web Srvr
SPARC T4-1
Solaris 11.4
IP: X.X.X.X
123; NTP
22; SSH
1521; TCP
System Acronym (In Accreditation Boundary)
22: SSH
Oracle Sun ZFS 7120-Disk-Array
Connected Directly to DB01/02/OSB
XXXXX-OSB
Oracle S7
Backups Srvr Solaris 11.4
IP: X.X.X.X
XXXXX-SL150
StorageTek Tape Library
IP: X.X.X.X
F5 Load Balancer
For Official Use Only (FOUO)
For Official Use Only (FOUO) text
TITLE
System Name (Acronym)
DESCRIPTION
This is the Approved Baseline
XXXXX-IDM
Identity Management Srvr
Virtual Solaris 11.4
IP: X.X.X.X
Virtual
XXXXX-DIDM1
Identity Management Srvr Solaris 10 1/13
X.X.X.X
Wilford Hall, JBSA (San Antonio)
1433: TCP
Database
Virtual – File Srvr
XXXXX-PWC01
Solaris 10 1/13
X.X.X.X
Virtual Web Srvr
XXXXX-DAPP1
Solaris 10 1/13
X.X.X.X
XXXXXDATA
Database Srvr
SPARC T4-1
Solaris 11.4
IP: X.X.X.X
XXXXXDATA02
Database Srvr
SPARC T4-1
Solaris 11.4
IP: X.X.X.X
SQL Instance / Cluster Database Srvr
Windows Server 2016
IP: X.X.X.X
IIS Portal Web Srvr
Windows Server 2016
IP: X.X.X.X IIS Portal Web Srvr
Windows Server 2016
IP: X.X.X.X
IIS Portal Web Srvr
Windows Server 2016
IP: X.X.X.X
SYSTEM NAME
CITY
STREET ADDRESS, BLDG. XXX
CITY, STATE, ZIP CODE
X.X.X.X
Navy Drug Screening Laboratory* Naval Air Station Jacksonville
CITY
STREET ADDRESS, BLDG. XXX
CITY, STATE, ZIP CODE
External X.X.X.X Internal X.X.X.X
Navy Drug Screening Laboratory*
CITY
STREET ADDRESS, BLDG. XXX
CITY, STATE, ZIP CODE
External X.X.X.X Internal X.X.X.X
U.S. Army Forensic Toxicology Drug* Testing Laboratory
CITY
STREET ADDRESS, BLDG. XXX
CITY, STATE, ZIP CODE
X.X.X.X
XXXXX-IDM
Identity Management Srvr
VirtualSolaris 11.4
Oracle Sun ZFS Storage Appliance* 7120-Disk-Array
Direct Connect to DB01/DB02/OSB
XXXX-SL150*
StorageTek Tape Library
XXXXX-DB01 –
Database/Web Srvr
SPARC T4-1
Solaris 11.4
XXXXX-DB02 –
Database/Web Srvr
SPARC T4-1
Solaris 11.4
SL150 Tape Library
XXXXX-OSB – Backups Server Oracle S7
Solaris 11.4
Oracle Sun ZFS
XXXXX-DB03 – Backups Server
SPARC V440
Solaris 10
NOTE:
ALL ITEMS IN RED SHOULD BE MODIFIED
TO BE SPECIFIC TO YOUR BOUNDARY. IF
THE ITEM.DEVICE DOES NOT APPLY,
DELETE IT.
Firewall
Firewall
Firewall
Firewall
Firewall
Firewall
Firewall eMASS ID#: XXXX
Command Communications Service Designator Number (CCSD)#:
Symbol Count Description
Legend Subtitle
Legend
Management server
Database server
4 Web server
Application server
1 File server
7 Firewall
1 Router.132
ATM
switch.134
CISCO 3850
iOS
IP ADDRESS: 192.168.x.x Switch
| DHA Sys Enterprise and Info Sec Architecture -Template.vsdx |
| Network Topology Requirements |
| Revison History |
| Devices & Key |
| DHA RMF Network Diagram/Boundary Template |
File details come from the government source that posted it. Updated .