Audit Remediation Sub-Tasks
22 KB Posted
- Attached to
- Audit Remediation Services Federal contract opportunity
- Solicitation number
- AG-3A75-S-12-0004
About this file
Attachment 002 Audit Remediation Sub-Tasks
Text of this file
Attachment 002:
Audit Remediation Sub-Tasks:
1. Add the following sub-tasks:
Task #9 – Property Audit Remediation
9.1 Property Audit Remediation
9.2 Property Audit Remediation
9.3 Property Audit Remediation
9.4 Property Audit Remediation
9.5 Property Audit Remediation
9.6 Property Audit Remediation
Task #10 – Accruals Audit Remediation
10.1 Accruals Audit Remediation
10.2 Accruals Audit Remediation
10.3 Accruals Audit Remediation
10.4 Accruals Audit Remediation
10.5 Accruals Audit Remediation
10.6 Accruals Audit Remediation
Task #11 – Undelivered Orders Audit Remediation
11.1 Undelivered Orders Audit Remediation
11.2 Undelivered Orders Audit Remediation
11.3 Undelivered Orders Audit Remediation
11.4 Undelivered Orders Audit Remediation
11.5 Undelivered Orders Audit Remediation
11.6 Undelivered Orders Audit Remediation
Task #12 – Unfilled Customer Orders Audit Remediation
12.1 Unfilled Customer Orders Audit Remediation
12.2 Unfilled Customer Orders Audit Remediation
12.3 Unfilled Customer Orders Audit Remediation
12.4 Unfilled Customer Orders Audit Remediation
12.5 Unfilled Customer Orders Audit Remediation
12.6 Unfilled Customer Orders Audit Remediation
Task #13 – Financial Reporting Audit Remediation
13.1 Financial Reporting Audit Remediation
13.2 Financial Reporting Audit Remediation
13.3 Financial Reporting Audit Remediation
13.4 Financial Reporting Audit Remediation
13.5 Financial Reporting Audit Remediation
13.6 Financial Reporting Audit Remediation
Task #14 – Purchase and Fleet Card Audit Remediation
14.1 Financial Reporting Audit Remediation
14.2 Financial Reporting Audit Remediation
14.3 Financial Reporting Audit Remediation
14.4 Financial Reporting Audit Remediation
14.5 Financial Reporting Audit Remediation
14.6 Financial Reporting Audit Remediation
2. Insert Section on Duty Hours Insert where appropriate:
Duty Hours A. The contractor shall not perform work at the government location unless government employees are present. The specific government employees will be designated at the time of award.
B. Contractors shall only work within the work hours of 6:00 A.M. and 6:00 P.M. EST, Mondays- Fridays. If extra and weekend hours are needed, they must be approved by the designated federal employee and the designated federal employee(s) must be present.
C. If contractors need to work hours when government employees are not available to be present, the contractor is still expected to meet the deadlines outlined in this statement of work. The contractor may have to work from home or from another location, other than the government location.
3. Remove Under Objective and Scope:
10. Provide support for the following Information Technology (IT) activities:
a. Plan of Action and Milestones (POAM) Status and Coordination
b. General and application controls assessment
c. State quality assurance review
d. IT compliance with laws and regulations, including, but not limited to the FFMIA, FISMA, Federal Information System Controls Audit Manual (FISCAM) and OMB Circular A-123
e. Financial audit requests
f. General Computing Controls (GCC) audit remediation
g. Implementation of an internal control strategy
4. Insert Under Objective and Scope:
10. Provide support for the following Information Technology (IT) activities:
A. A-123 Security Control Testing The objective of this task is to provide A-123 IT General Computing Controls (GCC) testing, develop required documentation and deliverables and remediation activities.
· The contractor shall integrate and coordinate as appropriate with other control-related activities as required for NRCS information systems.
· The contractor shall write, review and/or update A-123 documentation determine if statements to identify required inputs and outputs for each security control and security control enhancements for NRCS information systems.
· The contractor shall provide subject matter expertise regarding IT audit, IT internal controls and, compensating controls implementation.
· The contractor shall write, review and/or update IT internal control assessment reports.
· The contractor shall perform A-123 security control testing.
· The contractor shall monitor, track and maintain security remediation efforts and develop remediation plans for identified weaknesses.
· The contractor shall develop Plan of Action and Milestones (POA&M) for all vulnerabilities identified during A-123 testing.
· The Contractor shall assist NRCS in the development of Audit documentation and uploading artifacts into USDA systems such as ADTS and Cyber Security Assessment Management (CSAM).
· The Contractor shall attend weekly/bi-weekly Assessment Implementation Team( AIT) Meetings.
· The Contractor shall provide other A-123 security control support as required by NRCS.
B. Audit Remediation and POA&M Coordination:
The objective of this task is to coordinate and assist with remediation activities of all IT exceptions. This task will track, manage and coordinate all IT exceptions identified during certification and accreditation (C&A), internal controls assessments, various audit activities and other related areas of concern.
1. The contractor shall provide assistance in developing, updating, reviewing and implementing POA&M procedures for management and operational and technical security controls for NRCS information Systems.
1. The Contractor shall develop a POAM Management process and track POA&M resolution status. The contractor shall report POA&M resolution status in a format that provides a big picture view of POA&M Metrics and activities.
1. The contractor shall coordinate POA&M meetings with POA&M owners to obtain cost data, milestones, dates and any other pertinent information required for POA&M management and closure. The contractor shall assess proposed milestone to ensure that the mile stone accurately address remediation of the vulnerability.
1. The contractor shall participate on the POA&M team to provide subject matter expertise for management and operational and technical security control weaknesses.
1. The contractor shall develop, coordinate and deliver briefings to application project teams and senior management regarding POA&M metrics.
1. The contractor shall help document remediation plans and define Key Performance Indicators (KPIs) for resolution.
1. The contractor shall utilize the CSAM and ADTS system to create and update POA&Ms.
1. The contractor shall be responsible to coordinate all POA&Ms from all sources (i.e., incidents, application vulnerabilities, C&A activities, audit activities, etc.)
1. The contractor shall evaluate POA&M re-meditation evidence and test steps to ensure the remediation addressed the root cause of the POA&M.
1. The Contractor shall be responsible for coordinating and reporting on approaching POAM deadlines and late milestones
1. The Contractor shall provide monthly closure metrics to senior management.
C. Internal Control Assessment The objective of this task is to evaluate and assess the design and effectiveness of Internal Controls of IT mission areas.
1. The contractor shall perform assessment to test the design and effectiveness of IT internal controls for IT mission areas.
1. The contractor shall develop and document system map that identifies NRCS mission critical and financial systems.
1. The contractor shall develop and document a consolidated list of required controls. The Contactor shall use National Institutes of Standards and Technology (NIST), FISCAM and A-123 at a minimum for mapping.
1. The contractor shall coordinate meetings with IT stakeholders, Project Managers and system owners to assess critical processes and identify vulnerabilities and determination of controls in place.
1. The contractor shall facilitate the documentation of IT process narratives. The contractor shall maintain the IT process on the NRCS IT internal control SharePoint site.
1. The contractor shall develop and implement the NRCS IT internal control plan.
1. The contractor shall develop and document test plans, test steps, results and develop a final report encompassing Internal Control’s opinion, recommendations,
1. The contractor shall validate the design and effectiveness of Internal IT policies and procedures.
C. Audit Coordination The objective of this task is to coordinate various compliance based audits with the philosophy of utilizing one team to perform audit coordination and serve as an audit liaison between all vested parties.
1. The contractor shall track incoming audit request and coordinate timely delivery.
1. The contractor shall provide IT audit expertise and knowledge to address audit request and findings if questions arise.
1. The contractor shall coordinate IT audit meetings.
1. The contractor shall coordinate audit findings proper categorization and work points of contact to develop action plans.
1. The contractor shall validate evidence obtained for resolution of audit findings.
D. Standards and best practices development The objective of this task is to create and maintain SOPs, procedures and best practices for all internal control team activities.
1. The contractor shall develop a standard test plan that will satisfy all known IT assessments and therefore can be used to document testing once and be re-used for multiple assessments including the annual internal control assessment and all compliance audits (e.g. - OIG, FISMA, A-123).
1. The contractor shall create a federated artifact library for evidence items that are required for all types of audit, along with supporting policies and procedures to reduce the time and effort needed to satisfy audit-related requests. The Contractor shall leverage existing USDA/NRCS platform and tools.
1. The contractor shall develop, update, the requirements and procedures to follow when performing the IT GCC A-123 assessment. This document shall include the A-123 testing time line, key milestones of the A-123 assessment process, key points of contact, identification of controls to be tested, required documents that need to be maintained as a part of the assessment, and A-123 deliverables at a minimal.
1. The contractor shall assist NRCS with the development, review; update Internal Control/Audit policies, procedures and best practice and documentation.
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Audit Remediation Amendment 2.docx | DOCX document | |
| Audit Remediation -Intro to NRCS .docx | DOCX document | |
| Performance Standards 12.08.2011 R1.pdf | ||
| Final 33961WDC_NRCS_Annual Report.pdf | ||
| Audit Remediation Amendment 12082011.pdf | ||
| Financial_questionnaire_-_Responsibili_1 | — | |
| Combo Syn Sol -audit remediation FY 2012 | — | |
| SOW - audit remediation 11 21 2011.pdf | ||
| QASP - audit remediation.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
File details come from the government source that posted it. Updated .