Att 14 - 7.2 FRCS Responsibility Matrix.pdf
PDF 101 KB Posted
- Attached to
- Long-Term Capabilities Requirements Document Development Support (LT-CRDS) Federal contract opportunity
- Solicitation number
- HT001124R0064
- Issued by
- Defense Health Agency
About this file
The document is a responsibility matrix outlining roles for cybersecurity requirements on federal construction projects. It assigns responsibility for key cybersecurity tasks, such as identifying required systems, establishing cybersecurity requirements in statements of work, conducting scans and patching vulnerabilities, developing security plans and assessments, authorizing systems, and applying continuous monitoring strategies. Responsible parties include the system owner, authorizing official, contractor, construction manager, and USACE project delivery team. The related federal contract opportunity is a solicitation from the Defense Health Agency for long-term capabilities requirements document development support.
View the file
Other files for this federal contract opportunity
Show all 21
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment 4
FRCS Responsibility Matrix
Approval (A) [Final Approval Authority] Consulted (C) [In coordination with or makes recommendations]
1391 Concept, Planning & Development Identify the facility control systems required under the project R, A C I I X I I X Review Parametric Design via PDRS R, A I I I X I I X Preliminary categorize the systems/identify the CIA impact level C R A I X C C X Identify the System Owner and Authorizing Official C R A I X C C X Include budgetary line item for Cybersecurity $250 k/per system R, A C I I X I I X
Establish RMF Team, including USACE responsibility and assignments C R, A I I X C C X Include cybersecurity requirements in A/E SOW & include cybersecurity in contract evaluation R C,A I I X C C X Request Funds for Final Design R C,A I I X I I X
Design Determine if system is stand-alone or networked C C, A I R X C C X Prepare design in compliance with UFC 4-010-06 C, A I I R X I I X Develop list of relevant security controls C I I R X C C X Develop initial Sysytem Security Plan C C, A I R X C C X Provide final basis of design for inclusion into System Security Plan C, A I I R X I I X
Construction RFP Identify eMASS responsibilities of construction contractor R, A C I X I C C X Identify tasks/responsibilities/submittals of contractor R, A C I X I C C X
Construction Implement controls IAW Final Design C, A C I X R C C X Develop required submittals for approval C, A C I X R C C X Review contractor submittals and approve/disapprove/provide comments R, A C I X I C C X Conduct Nessus/SCAP scans, patch vulnerabilities, document remaining STIG deviations C C, A I X R C C X Submit request to NETCOM BidTracker website & select SCA-V (Army Only) C R, A I X C C C I Schedule SCA-V (*Needs to occur 12 Months out from OP need date) C R, A I X C C C I Develop continious monitoring strategy C R,C, A C X C C C I Complete controls self assessment C C I, A X R C C I Resolve issues identified in the self-assessment C C I, A X R C C I Complete eMASS requirements C R, A I X R C C I Assess security controls C C I X C C C R, A Track status of reviews, returns for rework and approval/disapprovals in eMASS C R,C, A I X R,C C C I Provide Security Assessment Report in eMASS I I I X I I I R, A Perform functional testing of the systems (*Full end-to-end testing will require limited duration ATO) C, A C I X R I I X
Re-Confirm RMF Team, including USACE responsibility and assignments C R, A I X I C C X Deliver all cybersecurity documentation and verify SO can log into their applications C, A C I X R C C X Verify the SA can login C, A C I X R C C X SA change all passwords on devices and in applications C R, A I X C C C X Request authority to connect C R C X C A C X Resolve issues identify by Network Provider C R I X C C, A C X
Authorize System Attend collaboration meeting with AODR C R C X X C C C Receive Decision from AO I I R,A X X I I C Perform full system acceptance testing C, A C I X R I I X
Monitor Security Controls Apply Continious Monitoring Strategy to system C R I, A X C C C X Updates and Patching C R,A I, A X X* C C X Decommission I R A X X* C C X
Post Construction and Warranty
MILCON Initiation & Development Phase
Roles-Responsibilities Matrix
Responsible (R) [Party responsible for task]
Le ge nd
NotesSC A-
V
De sig ne r o f R ec or d
Au th or izi ng O ff ici al
Sy st em O w ne r
U
SA
CE
P
DT
G6 /N
EC
/D
O
IM
Co ns tr uc to r C on tr ac to r
Informed (I) [Be informed of decision or status] IS
SM
/I
SS
O
SRM (O&M) RACI:
Approval (A) [Final Approval Authority] Consulted (C) [In coordination with or makes recommendations]
Manage Task Order Ensure Contractor provides required deliverables R C C C X Modify Task Order when required R C C C X Task Manager R C C C X Provide funding required to execute tasks C X R X X
System Design Determine if stand-alone or networked C I R C, A X Determine if child under parent ATO or stand-alone ATO C I C R, A X Define network configurations / architecture options available C R C C, A X Determine if hard server or virtualized C I C R, A X Define network configurations / architecture "allowable" C I C R, A X Develop Network Diagram C R I C, A X Develop Data Flow Diagram C R I C, A X
Cybersecurity Requirements Register System APMS C I R C, A X Register System eMASS C I R C, A X Categorize System (Requires Signed AO Approval Memo) C I R C, A X
Select Security Controls Apply CNNSI 1253 to determine System Classification C I R C, A X Apply DoD 800-53 Control Set I I R C, A X Apply DoD 800-53A Control Set I I R C, A X Determine Supplemental Controls I I R C, A X Import results from CSET into eMASS C C R C, A X Reach Agreed Baseline with customer / system owner C C R C, A X Determine all Data Types to be used in system, per RMF Guidance C C R C, A X Overlay Application and Selection C C R C, A X Import System Diagrams C C R C, A X Develop Monitoring Strategy C C R C, A X Finalize Control Set C C R C, A X Request Reciprocity Agreements from G6 C C R C, A X
Implement Security Controls Apply appropriate STIGs to system C R I C, A X Obtain Licensing for ACAS Server C C C R, A X Install Converged Security Scanning Server into lab environment C R C C X Gather existing system documentation from G6 C C R C X Develop Contingency Plan C C R C, A X Develop COOP Plan C C R C, A X Develop System Security Plan C C R C, A X Scan/Fix Process C R I I X Develop Security Assessment Report C R I I X Upload system documentation to eMASS C C R C X
Assess Security Controls Develop Security Assessment Plan C C C C X Submit Security Assessment Plan for approval C R C C, A X Prepare site for Validation team C C R C C Host Validation Team C C R C C Collaborate with Validation team to receive results from validation scan C R I C C Apply any necessary Scan/Fixes resulting from Validation Team C R I C C Prepare system POA&M C R I C X upload POA&M into eMASS C C R C X Prepare any final system documentation C R C C X Submit RMF Package to AODR C C R C X
Authorize System Collaboration meeting with AODR C I R C X Receive Decision from AO I I R C, A X
Monitor Security Controls Apply Monitoring Strategy to system I I R C X Updates and Patching I C R C X
Third Party Validation Documents and Reports Review I C I C R Scans & Test I C I C R Apply any necessary Scan/Fixes resulting from Validation Team I R I C C 3rd Party Recommendation to AO I I C C, A R
Request ATC I I R C, A X Authority to Connect (ATC) Process
Informed (I) [Be informed of decision or status] SC A-
V
Roles-Responsibilities Matrix
U
SA
CE
-P
DT
Co nt ra ct or
Cu st om er
Cu st om er
G6
/N
EC
/D O
IM
Notes
Responsible (R) [Party responsible for task] Le ge nd
| Attachment 4 |
| FRCS Responsibility Matrix |
| SRM (O&M) RACI: |
File details come from the government source that posted it. Updated .