Attachment-G3-ACF_Configuration Management Plan.docx_V1.0.docx

DOCX document 122 KB Posted

Attached to
Legal Services for Unaccompanied Alien Children (UAC) Federal contract opportunity
Solicitation number
75P00126R00003
Issued by
Not on record

About this file

This is a Configuration Management Plan (CMP) template for an Administration for Children and Families (ACF) information system. The document serves as a template and does not address specific required products or services for the Legal Services for Unaccompanied Alien Children (UAC) solicitation. The CMP template outlines the governance structure, roles and responsibilities, change control procedures, secure configuration lifecycle management, and configuration item identification and baselining processes that would apply to an ACF system. Key roles identified include the Chief Information Officer, Chief Information Security Officer (who acts as SCM program manager), Authorizing Official, Business Owner, System Owner, System Security and Privacy Officer, System Administrator, and Security Engineer. The template covers software configuration management tools and processes, secure configuration planning and monitoring, vulnerability management procedures, maintenance schedules, and documentation retention requirements, all aligned with NIST standards (SP 800-37, 800-39, 800-53, 800-70, 800-117, 800-126) and federal compliance requirements including FISMA and OMB guidance on Federal Desktop Core Configuration standards.

View the file

Other files for this federal contract opportunity

Other files attached to Legal Services for Unaccompanied Alien Children (UAC), newest first.
File Type Posted
Amendment 15 - Attachment J - Section F Deliverables Table June 06 2026.pdf PDF
Amendment 15 - Attachment B - Section C- Performance Work Statement (PWS) UAC Legal Services June 06 2026.pdf PDF
Amendment 15 - Attachment L Questions and Answers June 06 2026.pdf PDF
Amendment 15 - Attachment K Direct Representation Case Inventory Report June 06 2026.pdf PDF
Attachment-G10-ACF_System Security Plan_V1.0.docx DOCX document
Attachment-G9-ACF_System Registration_V1.0.docx DOCX document
Attachment-G4-ACF_Contingency Plan.docx_V1.0.docx DOCX document
Attachment J - Section F Deliverables Schedules and Performance Requirements Summary Table_20260513.docx DOCX document
Attachment D - ORR Facilities by State_20260513.pdf PDF
Attachment-G8-ACF_System Categorization_V1.0.docx DOCX document
Attachment-G7-ACF_Privacy Impact Assessment_V1.0.docx DOCX document
Attachment I - Contractor Past Performance Narrative Template_20260513.docx DOCX document
Attachment C - Standard Form (SF)-1449_20260513.pdf PDF
Attachment B - Section C- Performance Work Statement (PWS) UAC Legal Services_20260515.docx DOCX document
Attachment A - Pricing Worksheet UAC Legal Services_20260513.xlsx XLSX spreadsheet
Attachment-G5-ACF_Incident Response Plan_V1.0.docx DOCX document
Attachment E - Quality Assurance Surveillance Plan (QASP) UAC Legal Services_20260515.docx DOCX document
Attachment B- Section C- PWS_2026.03.24 (Amd 0010).pdf PDF
75P00126R00003_2026.03.24 (Amd 0010).pdf PDF
Attachment J- Questions and Answers_2026.03.24 (Amd 0010).pdf PDF
Attachment C- Standard Form (SF)-1449.pdf PDF
75P00126R00003_2026.02.23.pdf PDF
Attachment D - ORR Facilities by State.xlsx XLSX spreadsheet
Attachment F- ACF External System Control Implementation Policy and Procedures.pdf PDF
Attachment I- Past Performance Questionnaire.docx DOCX document
Attachment A- Pricing Worksheet UAC Legal Services (Amd. 0007) 2026.02.23.xlsx XLSX spreadsheet
Attachment B- Section C- PWS (Amd 0007) 2026.02.23.pdf PDF
Attachment E- Quality Assurance Surveillance Plan (QASP) (Amd. 0007) 2026.02.23.pdf PDF
Attachment H- Glossary of Abbreviations and Acronyms.pdf PDF
Attachment G- ATO Templates-2025.zip ZIP file
75P00126R00003 (Rev2)(Amd 0004)(12.11.2025).pdf PDF
Attachment B-Pricing Worksheet UAC Legal Services (Rev2) (Amd 0004)(12.11.2025).xlsx XLSX spreadsheet
QA-75P00126R00003(Rev1) (Amd 0004)(12.11.2025)#Q127.pdf PDF
Attachment B-Pricing Worksheet UAC Legal Services (Rev1) (Amd 0003)(12.09.2025).xlsx XLSX spreadsheet
Attachment E- ORR Facilities by State (Amd 0003).pdf PDF
Attachment G- ACF External System Control Implementation Policy and Procedures (Amd 0003).pdf PDF
Attachment I- Selected Controls (Moderate) (Amd 0003).xlsx XLSX spreadsheet
QA-75P00126R00003(12.09.2025) (Amd 0003).pdf PDF
75P00126R00003 (Rev1)(Amd 0003)(12.09.2025).pdf PDF
Attachment J- Selected Controls (Low) (Amd 0003).xlsx XLSX spreadsheet
Attachment A- Performance Work Statement (PWS) (Rev1) (Amd 0003) (12.09.2025).pdf PDF
Attachment F- Quality Assurance Surveillance Plan (QASP)(Rev1)(Amd 0003)(12.09.2025).pdf PDF
Attachment H- ATO Templates_2025 (Amd 0003).zip ZIP file
Attachment B- Pricing Worksheet UAC Legal Services (11.25.2025).xlsx XLSX spreadsheet
Attachment F- Quality Assurance Surveillance Plan (QASP).pdf PDF
Attachment B- Pricing Worksheet UAC Legal Services.xlsx XLSX spreadsheet
Attachment C- HHS Subcontracting Plan Review Form.doc DOC document
75P00126R00003.pdf PDF
Attachment A - Performance Work Statement (PWS)_2025.11.24.pdf PDF
Attachment D- Standard Form (SF)-1449.pdf PDF
Show all 50

Legal Services for Unaccompanied Alien Children (UAC) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Enter System Name ACF

Configuration Management Plan Enter System Name

Version 1.0 Dated: 6/26/25

Table of Contents

1. Introduction and Purpose3
1.1 Introduction3
1.2 System Overview3
1.2.1 Mission Relevance3
1.2.2 Data Flow3
1.2.3 System Architecture3
2. Governance & Responsibilities4
2.1 Configuration Management Governance4
2.2 Role and Responsibilities4
2.3 Change Control5
2.3.1 The Change Control Function5
2.3.2 Schedule and Resource Requirements5
2.4 Software Configuration Management (SCM) Processes and Tools5
2.4.1 SCM Tools5
2.4.2 SCM Library6
3. Secure Configuration Lifecycle6
3.1 Planning6
3.2 Configuring to a Secure State6
3.3 Monitoring6
3.4 Maintaining a Secure State7
3.4.1 Maintenance Schedule and Update Log7
4. Configuration Items and Identification8
4.1 Types of Configuration Items8
4.2 Configuration Item Labeling8
4.3 Configuration Baselining9
4.4 Hardware Baselines9
4.5 Non-Hardware CI Baselines9
4.6 Retention, Archiving, Storage, and Disposal of CI9
5. Related Systems and CM Plans10
6. Approval and Authorization11
Appendix A. Applicable Policies, Standards, and Procedures12
Appendix B. Change Request Submission Guidelines13
Document Revision History14

1. Introduction and Purpose

1.1 Introduction

This Configuration Management Plan explains how software updates, improvements, and system maintenance will be managed for the System. This system is part of the Enter Program Office within the Administration for Children and Families (ACF). The plan should make these processes clear, consistent, and easy to follow.

1.2 System Overview

Outline the technology components of the system, including hardware and software.

Enter system overview

1.2.1 Mission Relevance

Describe how the system supports the mission of the Administration for Children and Families (ACF). Include a summary of the system’s primary function(s) and role in delivering services or supporting agency operations.

Enter mission relevance

1.2.2 Data Flow

Enter data flow

1.2.3 System Architecture

Enter system architecture (description or diagram)

1.2.4 System Administration and Management

Enter details

2. Governance & Responsibilities

2.1 Configuration Management Governance

Reference Appendix A for the complete list of applicable policies, standards, and procedures, including NIST and FISMA standards and checklists.

2.2 Role and Responsibilities

Table 1. Software Configuration Management (SCM) and Change Control Roles and Responsibilities

Title
Role
Name and Contact Info
Chief Information Officer (CIO)
The CIO approves and oversees the organizational SCM plan and policies.
Enter name and contact info
Chief Information Security Officer (CISO)
The ACF CISO acts as the SCM program manager. The CISO may allocate staff with security expertise to support change control or conduct security impact analyses. The CISO develops SCM policies and procedures, provides direction, and oversees the implementation of the SCM Program. At the system level, the CISO works with the System Owner (SO) (or someone designated by the SO) to apply SCM policies and procedures.
Enter name and contact info
Authorizing Official (AO)
The AO manages or participates in the change control process for systems the AO has authorized and may provide technical staff to conduct and review security impact analyses. The AO coordinates with the Business Owner on SCM issues and determines whether or not a given change or set of changes continues to be an acceptable security risk.
Enter name and contact info
Business Owner (BO)
The BO is an ACF senior program manager who is ultimately responsible for the system, including obtaining funding for its development and upkeep.
Enter name and contact info
System Owner (SO)
The SO identifies, defines, and ensures the implementation of SCM aspects for the information system that have not been defined by the organization of which the information system is a part. The SO also ensures the implementation of organizational-level SCM requirements.
Enter name and contact info
System Security and Privacy Officer (SSPO)
The SSPO assists the SO with implementing the system's SCM and conducts configuration monitoring activities (reporting and analysis).
Enter name and contact info
System Administrator (SA)
The SA implements secure baseline configurations, incorporates secure configuration settings for IT products, and assists with security impact analyses and configuration monitoring. The SA may also help determine the appropriate baseline configuration for each CI and may participate in the change control process. SAs are also responsible for complying with SCM policies and implementing and following SCM procedures.
Enter name and contact info
Security Engineer
The Security Engineer supports the Authority to Operate (ATO) process by conducting technical assessments of systems and applications to ensure security controls are implemented and effective. The SE does not modify systems directly but instead evaluates system architecture, configuration, and documentation to identify vulnerabilities and validate compliance with security baselines. The SE collaborates with ISSOs, System Owners, and technical staff to explain security requirements, support risk decisions, and provide remediation guidance. The SE also supports third-party assessment activities and prepares technical deliverables including scan reports, assessment results, and compliance validation artifacts.
Enter name and contact info

2.3 Change Control

Describe the management of configuration processes and the maintenance of records and backups.

Enter management of configuration processes

2.3.1 The Change Control Function

Describe the change control functions and how they are reviewed and approved.

Enter change control functions

2.3.2 Schedule and Resource Requirements

Describe the schedule and resources needed to support change control.

Enter schedule and resources

2.4 Software Configuration Management (SCM) Processes and Tools

2.4.1 SCM Tools

List the technical tools used for tasks like patching, inventory, and backups. The Office of Management and Budget (OMB) requires federal agencies to use tools that are security content automation protocol (SCAP) enabled to verify that the Federal Desktop Core Configuration (FDCC) settings for Windows-based workstations and laptops are compliant.

Table 2. SCM Tools

Tool Name
Description

2.4.2 SCM Library

Describe the media library's management, including the media's naming conventions, labeling procedures (name/version, date created, retention period, owner, date of destruction, impact or classification level), media tracking, and media archiving.

Enter media library management

3. Secure Configuration Lifecycle

3.1 Planning

Describe how policies for configuration management are incorporated into planning and scheduling.

Enter incorporation into planning and scheduling

3.2 Configuring to a Secure State

Describe the process of establishing and enforcing a secure baseline configuration, including development, review, testing, approval, and implementation of the secure state.

Enter establishing a secure state

3.3 Monitoring

Describe how continuous monitoring is conducted to detect deviations or vulnerabilities in the system per NIST 800-117.

Enter continuous monitoring details

Table 3. Tools Used for Vulnerability Scans

Tool Name
Function
Frequence of use
Directory location

3.4 Maintaining a Secure State

Please describe the plan for ongoing maintenance of a secure state. Include descriptions of the vulnerability management SOP, annual control assessments, and remediation plan. If applicable, include a bullet list of the methodology used to review and fix vulnerabilities.

Enter plan for ongoing maintenance

3.4.1 Maintenance Schedule and Update Log

3.4.1.1 Monthly Update Schedule

Provide a table or bulleted list with the schedule.

Enter schedule

3.4.1.2 Monthly Update User Notification

Provide a sample of the notification sent out to users before maintenance occurs.

Enter sample notification

3.4.1.3 Monthly Update Change Log

Describe the change log, including its location, when it is submitted to the Control Board, and what it contains.

Enter change log details

3.4.1.4 Additional Maintenance Information

Please provide any additional information if relevant.

Enter additional information

4. Configuration Items and Identification A configuration item (CI) can refer to one or more components of an information system, including documents, network diagrams, scripts, custom code, and other elements. Information systems and CIs have a one-to-many relationship; an information system may consist of multiple CIs, but each CI belongs to only one specific information system.

4.1 Types of Configuration Items

Describe the CIs that make up the system. Include the following information as applicable:

· System context:

· Parent information system

· System location (logical or physical)

· Ownership and management details

· Assets and components:

· Hardware components list

· Software inventory

· Documentation inventory

· Custom software details

· Configuration and versions:

· Software, patch, and document versions

· Security configuration standards

· Recovery and continuity:

· Rebuild/recovery information

Enter CIs

4.2 Configuration Item Labeling

Each CI should have an unambiguous identifier for reference within SCM processes. Please list identifiers for each CI.

Enter identifiers

4.3 Configuration Baselining

Describe how the system baseline configuration was defined, documented, tested, and approved.

Enter baseline configuration details

4.4 Hardware Baselines

List the hardware that comprises the baseline configuration.

Enter hardware details

4.5 Non-Hardware CI Baselines

List the software, documents, and other non-hardware items that comprise the baseline configuration.

Enter non-hardware details

4.6 Retention, Archiving, Storage, and Disposal of CI

Describe how long configuration items are maintained, archived, and stored, and how they are disposed of.

Enter description

5. Related Systems and CM Plans List interconnected systems and their corresponding CM plans.

Table 4. Related Systems and CM Plans

System
Organization
Relationship
CM Plan Location

6. Approval and Authorization

Enter System Owner name Digital Signature – Date John Talieri, CISO or Christopher Miller, Deputy CISO Appendix A. Applicable Policies, Standards, and Procedures

· E-Government Act (P.L. 107-347), December 2002

· Federal Information Security Management Act (P.L. 107-347, Title III), December 2002

· HHS-OCIO Policy for Information Systems Security and Privacy Handbook (draft)

· NIST Federal Information Processing Standards Publication 199, Standards for Security Categorization of Federal Information and Information Systems, February 2004

· NIST Special Publication 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach, February 2010

· NIST Special Publication 800-39, Managing Risk from Information Systems: An Organizational Perspective, April 2008

· NIST Special Publication 800-53 Revision 5, Recommended Security Controls for Federal Information Systems, December 2020

· NIST Special Publication 800-70 Revision 1, National Checklist Program for IT Products - Guidelines for Checklist Users and Developers, September 2009

· NIST Special Publication 800-117, Guide to Adopting and Using the Security Content Automation Protocol (SCAP), May 2009

· NIST Special Publication 800-126, The Technical Specification for the Security Content Automation Protocol (SCAP), December 2009

· Office of Management and Budget Memorandum 07-11, Implementation of Commonly Accepted Security Configurations for Windows Operating Systems, March 2007

· Office of Management and Budget Memorandum 08-22, Guidance on the Federal Desktop Core Configuration (FDCC), August 2008

· Paperwork Reduction Act (P.L. 104-13), May 1995

Appendix B. Change Request Submission Guidelines Suggested data to be included in a change request:

· Date

· Title of CR

· Person initiating the request

· Description of the change

· Reason for the change

· Urgency (Scheduled, Urgent, or Unscheduled)

· Security impact

· Functional impact

· Risk of not implementing

· Potential integration or interface issues

· Required changes to existing applications

· Personnel involved

· Funding required

· Implementation plan (timeline, deliverables, back-out plan)

Document Revision History

Date
Version
Comments

Version 1.0 Configuration Management Plan 1 image1.png image2.png

File details come from the government source that posted it. Updated .