Att 14 - 7.2 FRCS Responsibility Matrix.pdf

PDF 101 KB Posted

Attached to
Long-Term Capabilities Requirements Document Development Support (LT-CRDS) Federal contract opportunity
Solicitation number
HT001124R0064
Issued by
Defense Health Agency

About this file

The document is a responsibility matrix outlining roles for cybersecurity requirements on federal construction projects. It assigns responsibility for key cybersecurity tasks, such as identifying required systems, establishing cybersecurity requirements in statements of work, conducting scans and patching vulnerabilities, developing security plans and assessments, authorizing systems, and applying continuous monitoring strategies. Responsible parties include the system owner, authorizing official, contractor, construction manager, and USACE project delivery team. The related federal contract opportunity is a solicitation from the Defense Health Agency for long-term capabilities requirements document development support.

View the file

Other files for this federal contract opportunity

Other files attached to Long-Term Capabilities Requirements Document Development Support (LT-CRDS), newest first.
File Type Posted
HT001124R0064-0002.pdf PDF
HT001124R0064-0001 LT-CRDS Amend 0001.pdf PDF
Att 18 - LT-CRDS RFP Q and A Sheet Final.pdf PDF
Att 11 - 7.1.2_DHA Mandatory Training List 2023.pdf PDF
Att 9 - 7.1.1_DHA CAC Request Process.pdf PDF
Att 7 - LT-CRDS QASP Draft.doc DOC document
Att 4 - LT-CRDS Sample Consent Letter.docx DOCX document
Att 3 - LT-CRDS Past Performance Questionnaire.docx DOCX document
Att 1 - LT-CRDS PWS.pdf PDF
Att 17 - WD 2015-4281 Rev 27.pdf PDF
Att 15 - 7.2 Risk Assessment Framework.pdf PDF
Att 10 - 7.1.1_DMDC TASS Application.xlsx XLSX spreadsheet
Att 5 - LT-CRDS OCI Contract List.xlsx XLSX spreadsheet
Att 16 - 7.2 DHA_Form_49_DHA KTR.pdf PDF
Att 13 - 7.2 Cybersecurity Regulations.pdf PDF
Att 8 - LT-CRDS DD Form 254.pdf PDF
Att 6 - LT-CRDS CDRL Portfolio.pdf PDF
Att 2 - LT-CRDS Pricing Sheet.xlsx XLSX spreadsheet
Att 8 - LT-CRDS DD Form 254 scanned pdf.pdf PDF
HT001124R0064 LT-CRDS RFP.pdf PDF
Att 12 - 7.1.3 DHA New Employee Handbook.pdf PDF
Show all 21

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Attachment 4

FRCS Responsibility Matrix

Approval (A) [Final Approval Authority] Consulted (C) [In coordination with or makes recommendations]

1391 Concept, Planning & Development Identify the facility control systems required under the project R, A C I I X I I X Review Parametric Design via PDRS R, A I I I X I I X Preliminary categorize the systems/identify the CIA impact level C R A I X C C X Identify the System Owner and Authorizing Official C R A I X C C X Include budgetary line item for Cybersecurity $250 k/per system R, A C I I X I I X

Establish RMF Team, including USACE responsibility and assignments C R, A I I X C C X Include cybersecurity requirements in A/E SOW & include cybersecurity in contract evaluation R C,A I I X C C X Request Funds for Final Design R C,A I I X I I X

Design Determine if system is stand-alone or networked C C, A I R X C C X Prepare design in compliance with UFC 4-010-06 C, A I I R X I I X Develop list of relevant security controls C I I R X C C X Develop initial Sysytem Security Plan C C, A I R X C C X Provide final basis of design for inclusion into System Security Plan C, A I I R X I I X

Construction RFP Identify eMASS responsibilities of construction contractor R, A C I X I C C X Identify tasks/responsibilities/submittals of contractor R, A C I X I C C X

Construction Implement controls IAW Final Design C, A C I X R C C X Develop required submittals for approval C, A C I X R C C X Review contractor submittals and approve/disapprove/provide comments R, A C I X I C C X Conduct Nessus/SCAP scans, patch vulnerabilities, document remaining STIG deviations C C, A I X R C C X Submit request to NETCOM BidTracker website & select SCA-V (Army Only) C R, A I X C C C I Schedule SCA-V (*Needs to occur 12 Months out from OP need date) C R, A I X C C C I Develop continious monitoring strategy C R,C, A C X C C C I Complete controls self assessment C C I, A X R C C I Resolve issues identified in the self-assessment C C I, A X R C C I Complete eMASS requirements C R, A I X R C C I Assess security controls C C I X C C C R, A Track status of reviews, returns for rework and approval/disapprovals in eMASS C R,C, A I X R,C C C I Provide Security Assessment Report in eMASS I I I X I I I R, A Perform functional testing of the systems (*Full end-to-end testing will require limited duration ATO) C, A C I X R I I X

Re-Confirm RMF Team, including USACE responsibility and assignments C R, A I X I C C X Deliver all cybersecurity documentation and verify SO can log into their applications C, A C I X R C C X Verify the SA can login C, A C I X R C C X SA change all passwords on devices and in applications C R, A I X C C C X Request authority to connect C R C X C A C X Resolve issues identify by Network Provider C R I X C C, A C X

Authorize System Attend collaboration meeting with AODR C R C X X C C C Receive Decision from AO I I R,A X X I I C Perform full system acceptance testing C, A C I X R I I X

Monitor Security Controls Apply Continious Monitoring Strategy to system C R I, A X C C C X Updates and Patching C R,A I, A X X* C C X Decommission I R A X X* C C X

Post Construction and Warranty

MILCON Initiation & Development Phase

Roles-Responsibilities Matrix

Responsible (R) [Party responsible for task]

Le ge nd

NotesSC A-

V

De sig ne r o f R ec or d

Au th or izi ng O ff ici al

Sy st em O w ne r

U

SA

CE

P

DT

G6 /N

EC

/D

O

IM

Co ns tr uc to r C on tr ac to r

Informed (I) [Be informed of decision or status] IS

SM

/I

SS

O

SRM (O&M) RACI:

Approval (A) [Final Approval Authority] Consulted (C) [In coordination with or makes recommendations]

Manage Task Order Ensure Contractor provides required deliverables R C C C X Modify Task Order when required R C C C X Task Manager R C C C X Provide funding required to execute tasks C X R X X

System Design Determine if stand-alone or networked C I R C, A X Determine if child under parent ATO or stand-alone ATO C I C R, A X Define network configurations / architecture options available C R C C, A X Determine if hard server or virtualized C I C R, A X Define network configurations / architecture "allowable" C I C R, A X Develop Network Diagram C R I C, A X Develop Data Flow Diagram C R I C, A X

Cybersecurity Requirements Register System APMS C I R C, A X Register System eMASS C I R C, A X Categorize System (Requires Signed AO Approval Memo) C I R C, A X

Select Security Controls Apply CNNSI 1253 to determine System Classification C I R C, A X Apply DoD 800-53 Control Set I I R C, A X Apply DoD 800-53A Control Set I I R C, A X Determine Supplemental Controls I I R C, A X Import results from CSET into eMASS C C R C, A X Reach Agreed Baseline with customer / system owner C C R C, A X Determine all Data Types to be used in system, per RMF Guidance C C R C, A X Overlay Application and Selection C C R C, A X Import System Diagrams C C R C, A X Develop Monitoring Strategy C C R C, A X Finalize Control Set C C R C, A X Request Reciprocity Agreements from G6 C C R C, A X

Implement Security Controls Apply appropriate STIGs to system C R I C, A X Obtain Licensing for ACAS Server C C C R, A X Install Converged Security Scanning Server into lab environment C R C C X Gather existing system documentation from G6 C C R C X Develop Contingency Plan C C R C, A X Develop COOP Plan C C R C, A X Develop System Security Plan C C R C, A X Scan/Fix Process C R I I X Develop Security Assessment Report C R I I X Upload system documentation to eMASS C C R C X

Assess Security Controls Develop Security Assessment Plan C C C C X Submit Security Assessment Plan for approval C R C C, A X Prepare site for Validation team C C R C C Host Validation Team C C R C C Collaborate with Validation team to receive results from validation scan C R I C C Apply any necessary Scan/Fixes resulting from Validation Team C R I C C Prepare system POA&M C R I C X upload POA&M into eMASS C C R C X Prepare any final system documentation C R C C X Submit RMF Package to AODR C C R C X

Authorize System Collaboration meeting with AODR C I R C X Receive Decision from AO I I R C, A X

Monitor Security Controls Apply Monitoring Strategy to system I I R C X Updates and Patching I C R C X

Third Party Validation Documents and Reports Review I C I C R Scans & Test I C I C R Apply any necessary Scan/Fixes resulting from Validation Team I R I C C 3rd Party Recommendation to AO I I C C, A R

Request ATC I I R C, A X Authority to Connect (ATC) Process

Informed (I) [Be informed of decision or status] SC A-

V

Roles-Responsibilities Matrix

U

SA

CE

-P

DT

Co nt ra ct or

Cu st om er

Cu st om er

G6

/N

EC

/D O

IM

Notes

Responsible (R) [Party responsible for task] Le ge nd

Attachment 4
FRCS Responsibility Matrix
SRM (O&M) RACI:

File details come from the government source that posted it. Updated .