Att 15 - 7.2 Risk Assessment Framework.pdf

PDF 167 KB Posted

Attached to
Long-Term Capabilities Requirements Document Development Support (LT-CRDS) Federal contract opportunity
Solicitation number
HT001124R0064
Issued by
Defense Health Agency

About this file

This document outlines the cybersecurity assessment and authorization timelines and requirements for systems developed or installed under various federal construction contract types. It specifies timeframes for Risk Management Framework activities including developing test plans and assessments, implementing security controls, obtaining Authority to Operate recommendations, completing independent verification and validation, and transitioning to continuous monitoring and maintenance. Contractors must submit security documentation and vulnerability scan reports according to templates provided by the Defense Health Agency and resolve any issues through iterative assessments. Systems must progress through assessment states and receive final Authority to Operate within 18 months of award for design-bid-build contracts and 12 months for sustainment contracts. Upon warranty expiration, contractors must continue conducting cybersecurity activities throughout the system lifecycle.

View the file

Other files for this federal contract opportunity

Other files attached to Long-Term Capabilities Requirements Document Development Support (LT-CRDS), newest first.
File Type Posted
HT001124R0064-0002.pdf PDF
HT001124R0064-0001 LT-CRDS Amend 0001.pdf PDF
Att 18 - LT-CRDS RFP Q and A Sheet Final.pdf PDF
Att 16 - 7.2 DHA_Form_49_DHA KTR.pdf PDF
Att 13 - 7.2 Cybersecurity Regulations.pdf PDF
Att 8 - LT-CRDS DD Form 254.pdf PDF
Att 6 - LT-CRDS CDRL Portfolio.pdf PDF
Att 2 - LT-CRDS Pricing Sheet.xlsx XLSX spreadsheet
Att 14 - 7.2 FRCS Responsibility Matrix.pdf PDF
Att 11 - 7.1.2_DHA Mandatory Training List 2023.pdf PDF
Att 9 - 7.1.1_DHA CAC Request Process.pdf PDF
Att 7 - LT-CRDS QASP Draft.doc DOC document
Att 4 - LT-CRDS Sample Consent Letter.docx DOCX document
Att 3 - LT-CRDS Past Performance Questionnaire.docx DOCX document
Att 1 - LT-CRDS PWS.pdf PDF
Att 17 - WD 2015-4281 Rev 27.pdf PDF
Att 10 - 7.1.1_DMDC TASS Application.xlsx XLSX spreadsheet
Att 5 - LT-CRDS OCI Contract List.xlsx XLSX spreadsheet
Att 8 - LT-CRDS DD Form 254 scanned pdf.pdf PDF
HT001124R0064 LT-CRDS RFP.pdf PDF
Att 12 - 7.1.3 DHA New Employee Handbook.pdf PDF
Show all 21

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Attachment 5

RMF ASSESSMENT TIMEFRAMES

Design-Bid-Build (DBB) Timeframes:

Lead Requirements DBB: Document Requirements Timeline Vend Contact Gov POC and requests templates and any additional cybersecurity technical documentation through the standard RFI process N/A

Within 30 days of construction contract award

Gov Provides templates and additional technical document RFI response

FRCS-RA, DoD Nessus policy templates, other cybersecurity templates/documents as requested

Within 15 business days post request

Vend Provides FRCS-RA and Nessus vulnerability assessment/report Submittal of test/laboratory System/device

Completed FRCS-RA and fully-credentialled DoD templated Nessus scan report.

Within 30 days of RFI response

Gov Cybersecurity System/device Kickoff Meeting (Government, Contractor, and Vendors)

Network configuration, architecture options, ATO status Contractor Memorandum for Record

10 business days post receipt of completed test/laboratory FRCS-RA and Nessus scans

Gov eMASS registration, Control Selection, Implementation Plan

Tasks, Responsibilities, and Submittals required of Vendor

5 business days post Cybersecurity Kickoff Meeting

Gov

Security Assessment Plan Review Meeting (Government, Contractor, and Vendors)

Security Assessment Plan, RMF Templates, Categorization Memo, Applicable STIGs, Tasks, Responsibilities, and Submittals required of Vendor Contractor Memorandum for Record

10 business days post Cybersecurity Kickoff Meeting

Vend Provides Submittal of test/laboratory self-assessment matching the proposed System/device

Assessment boundary diagram;

data flow diagram; hardware inventory; software/firmware inventory; ports, protocols, and

Within 30 business days after Government

FRCS-RA for Government approval services (PPS); privacy assessment; completed STIG checklists; detailed fully-credentialled DoD templated Nessus scan report; SCAP scan report, POAMs, other as identified

Cybersecurity Kickoff meeting

Gov Provides test/laboratory self-assessment Submittal responses (may result in re-iterations of self-assessment Submittal until accepted)

N/A 15 business day post receipt

Gov Contracting Officer provides approval to proceed with installation

N/A

Upon approved self-assessment Submittal of test/laboratory System/device

Vend Implements Controls;

Installs, integrates, secures, and documents the System/device that matches test/laboratory approved self-assessment configuration. N/A

Upon Contracting Officer Approval

Vend

Provides self-assessment Submittal of the installed System/device matching the test/laboratory for Government Approval

Assessment boundary diagram;

detailed diagram with data flow;

hardware inventory; software and firmware inventory; ports, protocols, and services (PPS);

privacy assessment; completed STIG checklists; detailed fully-credentialled DoD templated Nessus scan report; SCAP scan report; POAMs, Continuous Monitoring plan, other as identified

Prior to any Commissioning or Acceptance Testing

Gov Provides installation self-assessment response (may result in re-iterations of self-assessment until accepted)

N/A 15 business day post receipt

Gov ATO-Conditional recommendation submitted to 3rd party validator eMASS Security Plan and associated artifacts

Upon acceptance of installation self-assessment

Vend Resolves Issues; (may result in re-iterations of self-assessment until accepted)

ATO-C Upon AO Approval

Gov Independent Verification and

Validation (IV&V) request to 3rd party validator

N/A Upon ATO- Conditional of System/device

Vend Proceeds with scheduling Commissioning and Functional Acceptance Testing N/A

Upon approval of installation System/device self-assessment Submittal

Vend Transitions to IV&V;

maintains cybersecurity posture

Vendor remediation, Nessus and SCAP scan reports, resulting mitigations, and POAMs

Monthly reports until BOD

Vend

Completes successful IV&V and achieves ATO ATO

Within 18 months of contract award or prior to BOD

Vend Performs full System Acceptance Testing N/A Upon ATO

Vend

Transitions to warranty support, maintenance, and continuous monitoring

Continuous monitoring:

IAVA vulnerability management, patching, updates, upgrades, Nessus/ACAS and SCAP reports, resulting mitigations, and POAMs Begins at BOD

Vend

Transitions to post-warranty support, maintenance, and continuous monitoring

Continuous monitoring:

IAVA vulnerability management, patching, updates, upgrades, Nessus/ACAS and SCAP reports, resulting mitigations, and POAMs;

Reauthorizations when required

Post Warranty;

System/device life cycle

Design-Build (DB) Required Timeframes:

Vend Contact Government POC requests updated templates and any additional cybersecurity technical documentation through RFI

RFI

65% Design Review

Gov Provides templates and additional technical document RFI response

FRCS-RA, DoD Nessus policy templates, other cybersecurity templates/documents as requested

Within 15 business days post request

Vend Provides FRCS-RA and

Nessus vulnerability assessment/report Submittal of test/laboratory System/device

Completed FRCS-RA and fully-credentialled DoD templated Nessus scan report as Submittal

60 days post receipt of Corrected Final Design Submittal

Gov Cybersecurity System/device Kickoff Meeting (Government, Contractor, and Vendors)

Network configuration, architecture options, ATO status Contractor Memorandum for Record

30 business days post receipt of completed test/laboratory FRCS-RA and Nessus scans

Gov eMASS registration, Control Selection, Implementation Plan

Tasks, Responsibilities, and Submittals required of Vendor

5 business days post Cybersecurity Kickoff Meeting

Gov

Security Assessment Plan Review Meeting (Government, Contractor, and Vendors)

Security Assessment Plan, RMF Templates, Categorization Memo, Applicable STIGs, Tasks, Responsibilities, and Submittals required of Vendor Contractor Memorandum for Record

10 business days post Cybersecurity Kickoff Meeting

Vend

Provides Submittal of test/laboratory self-assessment matching the proposed System/device FRCS-RA for Government approval

Assessment boundary diagram;

data flow diagram; hardware inventory; software/firmware inventory; ports, protocols, and services (PPS); privacy assessment; completed STIG checklists; detailed fully-credentialled DoD templated Nessus scan report; SCAP scan report, POAMs, other as identified

Within 30 business days after Government Cybersecurity Kickoff meeting

Gov Provides test/laboratory self-assessment Submittal responses (may result in re-iterations of self-assessment Submittal until accepted)

N/A 15 business day post receipt

Gov

Contracting Officer provides approval to proceed with installation

N/A

Upon final Government Approved of self-assessment Submittal of test/laboratory

Vend Implements Controls;

Installs, integrates, secures, and documents the System/device that matches test/laboratory approved self-assessment configuration N/A

Upon Contracting Officer Approval

Vend

Provides self-assessment Submittal of the installed System/device matching the test/laboratory for Government Approval

Assessment boundary diagram;

detailed diagram with data flow;

hardware inventory; software and firmware inventory; ports, protocols, and services (PPS);

privacy assessment; completed STIG checklists; detailed fully-credentialled DoD templated Nessus scan report; SCAP scan report; POAMs, Continuous Monitoring plan, other as identified

Prior to any Commissioning or Acceptance Testing

Gov Provides installation self-assessment response (may result in re-iterations of self-assessment until accepted)

N/A 15 business day post receipt

Gov ATO-Conditional recommendation submitted to 3rd party validator eMASS Security Plan and associated artifacts

Upon acceptance of installation self-assessment

Vend Resolves Issues; (may result in re-iterations of self-assessment until accepted)

ATO-Conditional Upon SCA/AO Approval

Gov Independent Verification and Validation (IV&V) request to 3rd party validator

N/A Upon ATO- Conditional of System/device

Vend Proceeds with scheduling Commissioning and Functional Acceptance Testing N/A

Upon approval of installation System/device self-assessment Submittal

Vend Transitions to IV&V;

maintains cybersecurity posture

Vendor remediation Nessus and SCAP scan reports, resulting mitigations, and POAMs

Monthly reports until BOD

Vend

Completes successful IV&V and achieves ATO ATO

Within 18 months of contract award or prior to BOD

Vend Performs full System Acceptance Testing N/A Upon ATO

Vend

Transitions to warranty support, maintenance, and continuous monitoring

Continuous monitoring:

IAVA vulnerability management, patching, updates, upgrades, Nessus/ACAS and SCAP reports, resulting mitigations, and POAMs Begins at BOD

Vend

Transitions to post-warranty support, maintenance, and continuous monitoring

Continuous monitoring:

IAVA vulnerability management, patching, updates, upgrades, Nessus/ACAS and SCAP reports, resulting mitigations, and POAMs;

Reauthorizations when required

Post Warranty;

Facilities Sustainment, Restoration and Modernization (SRM) Required Timeframes:

Lead Requirements SRM: Document Requirements Timeline Vend Contact Gov POC and requests templates and any additional cybersecurity technical documentation N/A

10 business days post award

Gov Provides requested templates and cybersecurity technical documentation

FRCS-RA, DoD Nessus templates, other cybersecurity documents as requested

15 business days post request

Vend Provides FRCS-RA and Nessus vulnerability report of test/laboratory System/device

Completed FRCS-RA and fully-credentialled, DoD templated Nessus scan report.

25 business days post award

Gov

Cybersecurity System/device Kickoff Meeting

Network configuration, architecture options, ATO status Contractor Memorandum for Record

5 business days post receipt of completed test/laboratory FRCS-RA and Nessus scans

Gov eMASS registration, Control Selection, Implementation Plan

Tasks, Responsibilities, and Submittals required of Vendor

5 business days post Cybersecurity Kickoff Meeting

Gov Security Assessment Plan Review Meeting

Security Assessment Plan, System Categorization, RMF Templates, Applicable STIGs. Contractor Memorandum for Record

10 business days post Cybersecurity Kickoff Meeting

Vend Provides test/laboratory self-assessment matching the

Assessment boundary diagram;

data flow diagram; hardware

60 business days post award submitted System/device FRCS-RA for Gov approval inventory; software/firmware inventory; ports, protocols, and services (PPS); privacy assessment; completed STIG checklists; detailed fully-credentialled DoD templated Nessus scan report; SCAP scan report, POAMs, other as identified

Gov Provides test/laboratory self-assessment response (may result in re-iterations of self-assessment until accepted)

N/A 15 business day post receipt

Gov Contracting Officer provides approval to proceed with installation

N/A

Upon approved self-assessment of test/laboratory System/device

Vend Implements Controls;

Installs, integrates, secures, and documents the System/device that matches test/laboratory approved self-assessment configuration N/A

Upon Contracting Officer notice to proceed

Vend

Provides self-assessment submittal of the installed System/device for Gov approval

Boundary diagram; data flow diagram; hardware inventory;

software/firmware inventory;

ports, protocols, and services (PPS); privacy assessment;

completed STIG checklists; fully-credentialled DoD templated Nessus/ACAS report; SCAP report; POAMs, Continuous Monitoring plan, other as identified

Prior to acceptance testing

Gov Provides installation self-assessment response (may result in re-iterations of self-assessment until accepted)

N/A 15 business day post receipt

Gov ATO-Conditional recommendation submitted to 3rd party validator eMASS Security Plan and associated artifacts

5 business days post approved self-assessment

Vend Resolves Issues; (may result in re-iterations of self-assessment until accepted)

ATO-Conditional Upon SCA/AO Approval

Vend Proceeds with scheduling

Functional Acceptance Testing N/A

Upon SCA/AO Approval

Gov Independent Verification and Validation (IV&V) request to 3rd party validator

N/A 5 business days post ATO-C

Vend Transitions to IV&V;

maintains cybersecurity posture

Vendor remediation Nessus and SCAP scan reports, resulting mitigations, and POAMs

Monthly reports until BOD

Vend Completes successful IV&V and achieves ATO ATO

Within 12 months of contract award

Vend Performs full System Acceptance Testing N/A Upon ATO

Vend

Transitions to warranty support, maintenance, and continuous monitoring

Continuous monitoring:

IAVA vulnerability management, patching, updates, upgrades, Nessus/ACAS and SCAP reports, resulting mitigations, and POAMs

Upon Government Acceptance

Vend Upon warranty expiration, Vendor transitions to post-warranty support, maintenance, and ATO continuous monitoring

Continuous monitoring:

IAVA vulnerability management, patching, updates, upgrades, Nessus/ACAS and SCAP reports, resulting mitigations, and POAMs;

Reauthorization when required

NOTE: If the Vendor has completed all required actions in a timely and acceptable manner while the Government experiences delays, the Vendor would be given additional time for future actions corresponding to the amount of Government delay.

Informational Overview of the RMF Process: The following diagram provides a summary overview of the entire process to obtain approval under DHA Cybersecurity requirements. These diagrams are for informational purposes only, are not contractually binding, and subject to change without notice. Above tables contain the contractual requirements that must be met.

File details come from the government source that posted it. Updated .