Attachment-G3-ACF_Configuration Management Plan.docx_V1.0.docx
DOCX document 122 KB Posted
- Attached to
- Legal Services for Unaccompanied Alien Children (UAC) Federal contract opportunity
- Solicitation number
- 75P00126R00003
- Issued by
- Not on record
About this file
This is a Configuration Management Plan (CMP) template for an Administration for Children and Families (ACF) information system. The document serves as a template and does not address specific required products or services for the Legal Services for Unaccompanied Alien Children (UAC) solicitation. The CMP template outlines the governance structure, roles and responsibilities, change control procedures, secure configuration lifecycle management, and configuration item identification and baselining processes that would apply to an ACF system. Key roles identified include the Chief Information Officer, Chief Information Security Officer (who acts as SCM program manager), Authorizing Official, Business Owner, System Owner, System Security and Privacy Officer, System Administrator, and Security Engineer. The template covers software configuration management tools and processes, secure configuration planning and monitoring, vulnerability management procedures, maintenance schedules, and documentation retention requirements, all aligned with NIST standards (SP 800-37, 800-39, 800-53, 800-70, 800-117, 800-126) and federal compliance requirements including FISMA and OMB guidance on Federal Desktop Core Configuration standards.
View the file
Other files for this federal contract opportunity
Show all 50
Legal Services for Unaccompanied Alien Children (UAC) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Enter System Name ACF
Configuration Management Plan Enter System Name
Version 1.0 Dated: 6/26/25
Table of Contents
| 1. Introduction and Purpose | 3 |
| 1.1 Introduction | 3 |
| 1.2 System Overview | 3 |
| 1.2.1 Mission Relevance | 3 |
| 1.2.2 Data Flow | 3 |
| 1.2.3 System Architecture | 3 |
| 2. Governance & Responsibilities | 4 |
| 2.1 Configuration Management Governance | 4 |
| 2.2 Role and Responsibilities | 4 |
| 2.3 Change Control | 5 |
| 2.3.1 The Change Control Function | 5 |
| 2.3.2 Schedule and Resource Requirements | 5 |
| 2.4 Software Configuration Management (SCM) Processes and Tools | 5 |
| 2.4.1 SCM Tools | 5 |
| 2.4.2 SCM Library | 6 |
| 3. Secure Configuration Lifecycle | 6 |
| 3.1 Planning | 6 |
| 3.2 Configuring to a Secure State | 6 |
| 3.3 Monitoring | 6 |
| 3.4 Maintaining a Secure State | 7 |
| 3.4.1 Maintenance Schedule and Update Log | 7 |
| 4. Configuration Items and Identification | 8 |
| 4.1 Types of Configuration Items | 8 |
| 4.2 Configuration Item Labeling | 8 |
| 4.3 Configuration Baselining | 9 |
| 4.4 Hardware Baselines | 9 |
| 4.5 Non-Hardware CI Baselines | 9 |
| 4.6 Retention, Archiving, Storage, and Disposal of CI | 9 |
| 5. Related Systems and CM Plans | 10 |
| 6. Approval and Authorization | 11 |
| Appendix A. Applicable Policies, Standards, and Procedures | 12 |
| Appendix B. Change Request Submission Guidelines | 13 |
| Document Revision History | 14 |
1. Introduction and Purpose
1.1 Introduction
This Configuration Management Plan explains how software updates, improvements, and system maintenance will be managed for the System. This system is part of the Enter Program Office within the Administration for Children and Families (ACF). The plan should make these processes clear, consistent, and easy to follow.
1.2 System Overview
Outline the technology components of the system, including hardware and software.
Enter system overview
1.2.1 Mission Relevance
Describe how the system supports the mission of the Administration for Children and Families (ACF). Include a summary of the system’s primary function(s) and role in delivering services or supporting agency operations.
Enter mission relevance
1.2.2 Data Flow
Enter data flow
1.2.3 System Architecture
Enter system architecture (description or diagram)
1.2.4 System Administration and Management
Enter details
2. Governance & Responsibilities
2.1 Configuration Management Governance
Reference Appendix A for the complete list of applicable policies, standards, and procedures, including NIST and FISMA standards and checklists.
2.2 Role and Responsibilities
Table 1. Software Configuration Management (SCM) and Change Control Roles and Responsibilities
| Title |
| Role |
| Name and Contact Info |
| Chief Information Officer (CIO) |
| The CIO approves and oversees the organizational SCM plan and policies. |
| Enter name and contact info |
| Chief Information Security Officer (CISO) |
| The ACF CISO acts as the SCM program manager. The CISO may allocate staff with security expertise to support change control or conduct security impact analyses. The CISO develops SCM policies and procedures, provides direction, and oversees the implementation of the SCM Program. At the system level, the CISO works with the System Owner (SO) (or someone designated by the SO) to apply SCM policies and procedures. |
| Enter name and contact info |
| Authorizing Official (AO) |
| The AO manages or participates in the change control process for systems the AO has authorized and may provide technical staff to conduct and review security impact analyses. The AO coordinates with the Business Owner on SCM issues and determines whether or not a given change or set of changes continues to be an acceptable security risk. |
| Enter name and contact info |
| Business Owner (BO) |
| The BO is an ACF senior program manager who is ultimately responsible for the system, including obtaining funding for its development and upkeep. |
| Enter name and contact info |
| System Owner (SO) |
| The SO identifies, defines, and ensures the implementation of SCM aspects for the information system that have not been defined by the organization of which the information system is a part. The SO also ensures the implementation of organizational-level SCM requirements. |
| Enter name and contact info |
| System Security and Privacy Officer (SSPO) |
| The SSPO assists the SO with implementing the system's SCM and conducts configuration monitoring activities (reporting and analysis). |
| Enter name and contact info |
| System Administrator (SA) |
| The SA implements secure baseline configurations, incorporates secure configuration settings for IT products, and assists with security impact analyses and configuration monitoring. The SA may also help determine the appropriate baseline configuration for each CI and may participate in the change control process. SAs are also responsible for complying with SCM policies and implementing and following SCM procedures. |
| Enter name and contact info |
| Security Engineer |
| The Security Engineer supports the Authority to Operate (ATO) process by conducting technical assessments of systems and applications to ensure security controls are implemented and effective. The SE does not modify systems directly but instead evaluates system architecture, configuration, and documentation to identify vulnerabilities and validate compliance with security baselines. The SE collaborates with ISSOs, System Owners, and technical staff to explain security requirements, support risk decisions, and provide remediation guidance. The SE also supports third-party assessment activities and prepares technical deliverables including scan reports, assessment results, and compliance validation artifacts. |
| Enter name and contact info |
2.3 Change Control
Describe the management of configuration processes and the maintenance of records and backups.
Enter management of configuration processes
2.3.1 The Change Control Function
Describe the change control functions and how they are reviewed and approved.
Enter change control functions
2.3.2 Schedule and Resource Requirements
Describe the schedule and resources needed to support change control.
Enter schedule and resources
2.4 Software Configuration Management (SCM) Processes and Tools
2.4.1 SCM Tools
List the technical tools used for tasks like patching, inventory, and backups. The Office of Management and Budget (OMB) requires federal agencies to use tools that are security content automation protocol (SCAP) enabled to verify that the Federal Desktop Core Configuration (FDCC) settings for Windows-based workstations and laptops are compliant.
Table 2. SCM Tools
| Tool Name |
| Description |
2.4.2 SCM Library
Describe the media library's management, including the media's naming conventions, labeling procedures (name/version, date created, retention period, owner, date of destruction, impact or classification level), media tracking, and media archiving.
Enter media library management
3. Secure Configuration Lifecycle
3.1 Planning
Describe how policies for configuration management are incorporated into planning and scheduling.
Enter incorporation into planning and scheduling
3.2 Configuring to a Secure State
Describe the process of establishing and enforcing a secure baseline configuration, including development, review, testing, approval, and implementation of the secure state.
Enter establishing a secure state
3.3 Monitoring
Describe how continuous monitoring is conducted to detect deviations or vulnerabilities in the system per NIST 800-117.
Enter continuous monitoring details
Table 3. Tools Used for Vulnerability Scans
| Tool Name |
| Function |
| Frequence of use |
| Directory location |
3.4 Maintaining a Secure State
Please describe the plan for ongoing maintenance of a secure state. Include descriptions of the vulnerability management SOP, annual control assessments, and remediation plan. If applicable, include a bullet list of the methodology used to review and fix vulnerabilities.
Enter plan for ongoing maintenance
3.4.1 Maintenance Schedule and Update Log
3.4.1.1 Monthly Update Schedule
Provide a table or bulleted list with the schedule.
Enter schedule
3.4.1.2 Monthly Update User Notification
Provide a sample of the notification sent out to users before maintenance occurs.
Enter sample notification
3.4.1.3 Monthly Update Change Log
Describe the change log, including its location, when it is submitted to the Control Board, and what it contains.
Enter change log details
3.4.1.4 Additional Maintenance Information
Please provide any additional information if relevant.
Enter additional information
4. Configuration Items and Identification A configuration item (CI) can refer to one or more components of an information system, including documents, network diagrams, scripts, custom code, and other elements. Information systems and CIs have a one-to-many relationship; an information system may consist of multiple CIs, but each CI belongs to only one specific information system.
4.1 Types of Configuration Items
Describe the CIs that make up the system. Include the following information as applicable:
· System context:
· Parent information system
· System location (logical or physical)
· Ownership and management details
· Assets and components:
· Hardware components list
· Software inventory
· Documentation inventory
· Custom software details
· Configuration and versions:
· Software, patch, and document versions
· Security configuration standards
· Recovery and continuity:
· Rebuild/recovery information
Enter CIs
4.2 Configuration Item Labeling
Each CI should have an unambiguous identifier for reference within SCM processes. Please list identifiers for each CI.
Enter identifiers
4.3 Configuration Baselining
Describe how the system baseline configuration was defined, documented, tested, and approved.
Enter baseline configuration details
4.4 Hardware Baselines
List the hardware that comprises the baseline configuration.
Enter hardware details
4.5 Non-Hardware CI Baselines
List the software, documents, and other non-hardware items that comprise the baseline configuration.
Enter non-hardware details
4.6 Retention, Archiving, Storage, and Disposal of CI
Describe how long configuration items are maintained, archived, and stored, and how they are disposed of.
Enter description
5. Related Systems and CM Plans List interconnected systems and their corresponding CM plans.
Table 4. Related Systems and CM Plans
| System |
| Organization |
| Relationship |
| CM Plan Location |
6. Approval and Authorization
Enter System Owner name Digital Signature – Date John Talieri, CISO or Christopher Miller, Deputy CISO Appendix A. Applicable Policies, Standards, and Procedures
· E-Government Act (P.L. 107-347), December 2002
· Federal Information Security Management Act (P.L. 107-347, Title III), December 2002
· HHS-OCIO Policy for Information Systems Security and Privacy Handbook (draft)
· NIST Federal Information Processing Standards Publication 199, Standards for Security Categorization of Federal Information and Information Systems, February 2004
· NIST Special Publication 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach, February 2010
· NIST Special Publication 800-39, Managing Risk from Information Systems: An Organizational Perspective, April 2008
· NIST Special Publication 800-53 Revision 5, Recommended Security Controls for Federal Information Systems, December 2020
· NIST Special Publication 800-70 Revision 1, National Checklist Program for IT Products - Guidelines for Checklist Users and Developers, September 2009
· NIST Special Publication 800-117, Guide to Adopting and Using the Security Content Automation Protocol (SCAP), May 2009
· NIST Special Publication 800-126, The Technical Specification for the Security Content Automation Protocol (SCAP), December 2009
· Office of Management and Budget Memorandum 07-11, Implementation of Commonly Accepted Security Configurations for Windows Operating Systems, March 2007
· Office of Management and Budget Memorandum 08-22, Guidance on the Federal Desktop Core Configuration (FDCC), August 2008
· Paperwork Reduction Act (P.L. 104-13), May 1995
Appendix B. Change Request Submission Guidelines Suggested data to be included in a change request:
· Date
· Title of CR
· Person initiating the request
· Description of the change
· Reason for the change
· Urgency (Scheduled, Urgent, or Unscheduled)
· Security impact
· Functional impact
· Risk of not implementing
· Potential integration or interface issues
· Required changes to existing applications
· Personnel involved
· Funding required
· Implementation plan (timeline, deliverables, back-out plan)
Document Revision History
| Date |
| Version |
| Comments |
Version 1.0 Configuration Management Plan 1 image1.png image2.png
File details come from the government source that posted it. Updated .