Att 15 - 7.2 Risk Assessment Framework.pdf
PDF 167 KB Posted
- Attached to
- Long-Term Capabilities Requirements Document Development Support (LT-CRDS) Federal contract opportunity
- Solicitation number
- HT001124R0064
- Issued by
- Defense Health Agency
About this file
This document outlines the cybersecurity assessment and authorization timelines and requirements for systems developed or installed under various federal construction contract types. It specifies timeframes for Risk Management Framework activities including developing test plans and assessments, implementing security controls, obtaining Authority to Operate recommendations, completing independent verification and validation, and transitioning to continuous monitoring and maintenance. Contractors must submit security documentation and vulnerability scan reports according to templates provided by the Defense Health Agency and resolve any issues through iterative assessments. Systems must progress through assessment states and receive final Authority to Operate within 18 months of award for design-bid-build contracts and 12 months for sustainment contracts. Upon warranty expiration, contractors must continue conducting cybersecurity activities throughout the system lifecycle.
View the file
Other files for this federal contract opportunity
Show all 21
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment 5
RMF ASSESSMENT TIMEFRAMES
Design-Bid-Build (DBB) Timeframes:
Lead Requirements DBB: Document Requirements Timeline Vend Contact Gov POC and requests templates and any additional cybersecurity technical documentation through the standard RFI process N/A
Within 30 days of construction contract award
Gov Provides templates and additional technical document RFI response
FRCS-RA, DoD Nessus policy templates, other cybersecurity templates/documents as requested
Within 15 business days post request
Vend Provides FRCS-RA and Nessus vulnerability assessment/report Submittal of test/laboratory System/device
Completed FRCS-RA and fully-credentialled DoD templated Nessus scan report.
Within 30 days of RFI response
Gov Cybersecurity System/device Kickoff Meeting (Government, Contractor, and Vendors)
Network configuration, architecture options, ATO status Contractor Memorandum for Record
10 business days post receipt of completed test/laboratory FRCS-RA and Nessus scans
Gov eMASS registration, Control Selection, Implementation Plan
Tasks, Responsibilities, and Submittals required of Vendor
5 business days post Cybersecurity Kickoff Meeting
Gov
Security Assessment Plan Review Meeting (Government, Contractor, and Vendors)
Security Assessment Plan, RMF Templates, Categorization Memo, Applicable STIGs, Tasks, Responsibilities, and Submittals required of Vendor Contractor Memorandum for Record
10 business days post Cybersecurity Kickoff Meeting
Vend Provides Submittal of test/laboratory self-assessment matching the proposed System/device
Assessment boundary diagram;
data flow diagram; hardware inventory; software/firmware inventory; ports, protocols, and
Within 30 business days after Government
FRCS-RA for Government approval services (PPS); privacy assessment; completed STIG checklists; detailed fully-credentialled DoD templated Nessus scan report; SCAP scan report, POAMs, other as identified
Cybersecurity Kickoff meeting
Gov Provides test/laboratory self-assessment Submittal responses (may result in re-iterations of self-assessment Submittal until accepted)
N/A 15 business day post receipt
Gov Contracting Officer provides approval to proceed with installation
N/A
Upon approved self-assessment Submittal of test/laboratory System/device
Vend Implements Controls;
Installs, integrates, secures, and documents the System/device that matches test/laboratory approved self-assessment configuration. N/A
Upon Contracting Officer Approval
Vend
Provides self-assessment Submittal of the installed System/device matching the test/laboratory for Government Approval
Assessment boundary diagram;
detailed diagram with data flow;
hardware inventory; software and firmware inventory; ports, protocols, and services (PPS);
privacy assessment; completed STIG checklists; detailed fully-credentialled DoD templated Nessus scan report; SCAP scan report; POAMs, Continuous Monitoring plan, other as identified
Prior to any Commissioning or Acceptance Testing
Gov Provides installation self-assessment response (may result in re-iterations of self-assessment until accepted)
N/A 15 business day post receipt
Gov ATO-Conditional recommendation submitted to 3rd party validator eMASS Security Plan and associated artifacts
Upon acceptance of installation self-assessment
Vend Resolves Issues; (may result in re-iterations of self-assessment until accepted)
ATO-C Upon AO Approval
Gov Independent Verification and
Validation (IV&V) request to 3rd party validator
N/A Upon ATO- Conditional of System/device
Vend Proceeds with scheduling Commissioning and Functional Acceptance Testing N/A
Upon approval of installation System/device self-assessment Submittal
Vend Transitions to IV&V;
maintains cybersecurity posture
Vendor remediation, Nessus and SCAP scan reports, resulting mitigations, and POAMs
Monthly reports until BOD
Vend
Completes successful IV&V and achieves ATO ATO
Within 18 months of contract award or prior to BOD
Vend Performs full System Acceptance Testing N/A Upon ATO
Vend
Transitions to warranty support, maintenance, and continuous monitoring
Continuous monitoring:
IAVA vulnerability management, patching, updates, upgrades, Nessus/ACAS and SCAP reports, resulting mitigations, and POAMs Begins at BOD
Vend
Transitions to post-warranty support, maintenance, and continuous monitoring
Continuous monitoring:
IAVA vulnerability management, patching, updates, upgrades, Nessus/ACAS and SCAP reports, resulting mitigations, and POAMs;
Reauthorizations when required
Post Warranty;
System/device life cycle
Design-Build (DB) Required Timeframes:
Vend Contact Government POC requests updated templates and any additional cybersecurity technical documentation through RFI
RFI
65% Design Review
Gov Provides templates and additional technical document RFI response
FRCS-RA, DoD Nessus policy templates, other cybersecurity templates/documents as requested
Within 15 business days post request
Vend Provides FRCS-RA and
Nessus vulnerability assessment/report Submittal of test/laboratory System/device
Completed FRCS-RA and fully-credentialled DoD templated Nessus scan report as Submittal
60 days post receipt of Corrected Final Design Submittal
Gov Cybersecurity System/device Kickoff Meeting (Government, Contractor, and Vendors)
Network configuration, architecture options, ATO status Contractor Memorandum for Record
30 business days post receipt of completed test/laboratory FRCS-RA and Nessus scans
Gov eMASS registration, Control Selection, Implementation Plan
Tasks, Responsibilities, and Submittals required of Vendor
5 business days post Cybersecurity Kickoff Meeting
Gov
Security Assessment Plan Review Meeting (Government, Contractor, and Vendors)
Security Assessment Plan, RMF Templates, Categorization Memo, Applicable STIGs, Tasks, Responsibilities, and Submittals required of Vendor Contractor Memorandum for Record
10 business days post Cybersecurity Kickoff Meeting
Vend
Provides Submittal of test/laboratory self-assessment matching the proposed System/device FRCS-RA for Government approval
Assessment boundary diagram;
data flow diagram; hardware inventory; software/firmware inventory; ports, protocols, and services (PPS); privacy assessment; completed STIG checklists; detailed fully-credentialled DoD templated Nessus scan report; SCAP scan report, POAMs, other as identified
Within 30 business days after Government Cybersecurity Kickoff meeting
Gov Provides test/laboratory self-assessment Submittal responses (may result in re-iterations of self-assessment Submittal until accepted)
N/A 15 business day post receipt
Gov
Contracting Officer provides approval to proceed with installation
N/A
Upon final Government Approved of self-assessment Submittal of test/laboratory
Vend Implements Controls;
Installs, integrates, secures, and documents the System/device that matches test/laboratory approved self-assessment configuration N/A
Upon Contracting Officer Approval
Vend
Provides self-assessment Submittal of the installed System/device matching the test/laboratory for Government Approval
Assessment boundary diagram;
detailed diagram with data flow;
hardware inventory; software and firmware inventory; ports, protocols, and services (PPS);
privacy assessment; completed STIG checklists; detailed fully-credentialled DoD templated Nessus scan report; SCAP scan report; POAMs, Continuous Monitoring plan, other as identified
Prior to any Commissioning or Acceptance Testing
Gov Provides installation self-assessment response (may result in re-iterations of self-assessment until accepted)
N/A 15 business day post receipt
Gov ATO-Conditional recommendation submitted to 3rd party validator eMASS Security Plan and associated artifacts
Upon acceptance of installation self-assessment
Vend Resolves Issues; (may result in re-iterations of self-assessment until accepted)
ATO-Conditional Upon SCA/AO Approval
Gov Independent Verification and Validation (IV&V) request to 3rd party validator
N/A Upon ATO- Conditional of System/device
Vend Proceeds with scheduling Commissioning and Functional Acceptance Testing N/A
Upon approval of installation System/device self-assessment Submittal
Vend Transitions to IV&V;
maintains cybersecurity posture
Vendor remediation Nessus and SCAP scan reports, resulting mitigations, and POAMs
Monthly reports until BOD
Vend
Completes successful IV&V and achieves ATO ATO
Within 18 months of contract award or prior to BOD
Vend Performs full System Acceptance Testing N/A Upon ATO
Vend
Transitions to warranty support, maintenance, and continuous monitoring
Continuous monitoring:
IAVA vulnerability management, patching, updates, upgrades, Nessus/ACAS and SCAP reports, resulting mitigations, and POAMs Begins at BOD
Vend
Transitions to post-warranty support, maintenance, and continuous monitoring
Continuous monitoring:
IAVA vulnerability management, patching, updates, upgrades, Nessus/ACAS and SCAP reports, resulting mitigations, and POAMs;
Reauthorizations when required
Post Warranty;
Facilities Sustainment, Restoration and Modernization (SRM) Required Timeframes:
Lead Requirements SRM: Document Requirements Timeline Vend Contact Gov POC and requests templates and any additional cybersecurity technical documentation N/A
10 business days post award
Gov Provides requested templates and cybersecurity technical documentation
FRCS-RA, DoD Nessus templates, other cybersecurity documents as requested
15 business days post request
Vend Provides FRCS-RA and Nessus vulnerability report of test/laboratory System/device
Completed FRCS-RA and fully-credentialled, DoD templated Nessus scan report.
25 business days post award
Gov
Cybersecurity System/device Kickoff Meeting
Network configuration, architecture options, ATO status Contractor Memorandum for Record
5 business days post receipt of completed test/laboratory FRCS-RA and Nessus scans
Gov eMASS registration, Control Selection, Implementation Plan
Tasks, Responsibilities, and Submittals required of Vendor
5 business days post Cybersecurity Kickoff Meeting
Gov Security Assessment Plan Review Meeting
Security Assessment Plan, System Categorization, RMF Templates, Applicable STIGs. Contractor Memorandum for Record
10 business days post Cybersecurity Kickoff Meeting
Vend Provides test/laboratory self-assessment matching the
Assessment boundary diagram;
data flow diagram; hardware
60 business days post award submitted System/device FRCS-RA for Gov approval inventory; software/firmware inventory; ports, protocols, and services (PPS); privacy assessment; completed STIG checklists; detailed fully-credentialled DoD templated Nessus scan report; SCAP scan report, POAMs, other as identified
Gov Provides test/laboratory self-assessment response (may result in re-iterations of self-assessment until accepted)
N/A 15 business day post receipt
Gov Contracting Officer provides approval to proceed with installation
N/A
Upon approved self-assessment of test/laboratory System/device
Vend Implements Controls;
Installs, integrates, secures, and documents the System/device that matches test/laboratory approved self-assessment configuration N/A
Upon Contracting Officer notice to proceed
Vend
Provides self-assessment submittal of the installed System/device for Gov approval
Boundary diagram; data flow diagram; hardware inventory;
software/firmware inventory;
ports, protocols, and services (PPS); privacy assessment;
completed STIG checklists; fully-credentialled DoD templated Nessus/ACAS report; SCAP report; POAMs, Continuous Monitoring plan, other as identified
Prior to acceptance testing
Gov Provides installation self-assessment response (may result in re-iterations of self-assessment until accepted)
N/A 15 business day post receipt
Gov ATO-Conditional recommendation submitted to 3rd party validator eMASS Security Plan and associated artifacts
5 business days post approved self-assessment
Vend Resolves Issues; (may result in re-iterations of self-assessment until accepted)
ATO-Conditional Upon SCA/AO Approval
Vend Proceeds with scheduling
Functional Acceptance Testing N/A
Upon SCA/AO Approval
Gov Independent Verification and Validation (IV&V) request to 3rd party validator
N/A 5 business days post ATO-C
Vend Transitions to IV&V;
maintains cybersecurity posture
Vendor remediation Nessus and SCAP scan reports, resulting mitigations, and POAMs
Monthly reports until BOD
Vend Completes successful IV&V and achieves ATO ATO
Within 12 months of contract award
Vend Performs full System Acceptance Testing N/A Upon ATO
Vend
Transitions to warranty support, maintenance, and continuous monitoring
Continuous monitoring:
IAVA vulnerability management, patching, updates, upgrades, Nessus/ACAS and SCAP reports, resulting mitigations, and POAMs
Upon Government Acceptance
Vend Upon warranty expiration, Vendor transitions to post-warranty support, maintenance, and ATO continuous monitoring
Continuous monitoring:
IAVA vulnerability management, patching, updates, upgrades, Nessus/ACAS and SCAP reports, resulting mitigations, and POAMs;
Reauthorization when required
NOTE: If the Vendor has completed all required actions in a timely and acceptable manner while the Government experiences delays, the Vendor would be given additional time for future actions corresponding to the amount of Government delay.
Informational Overview of the RMF Process: The following diagram provides a summary overview of the entire process to obtain approval under DHA Cybersecurity requirements. These diagrams are for informational purposes only, are not contractually binding, and subject to change without notice. Above tables contain the contractual requirements that must be met.
File details come from the government source that posted it. Updated .