Attachment_14_CSWF_Certification_Matrix_N0016721R0004.xlsx
XLSX spreadsheet 27 KB Posted
- Attached to
- Environmental and Ship Motion Forecasting (ESMF) system Federal contract opportunity
- Solicitation number
- N0016721R0004
View the file
Other files for this federal contract opportunity
Show all 31
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Reference Directions:
1. Column A: Using the contract, put the labor categories or titles for positions delivering cyber capability.
2. Column B: List the task area numbers from the SOW that define what they'll be doing.
3. Column C: Based on the duties and the work role descriptions on this reference page, choose the appropriate work role name and code.
4. Column D: Provide a brief description of the cyber duties the individual(s) will be performing.
5. Column E: If the position is primarily management choose IAM, if it is technical choose IAT. Based on the years of IT experience for this cyber duty needed to fill the position, choose level I, II or III.
6. Column F: Copy the approved baseline certifications for the IAT/IAM level chosen. (Only one is needed, and a higher-level certification will count for a lower.)
7. Column G: If the position requires additional cyber training before being engaged, it should be stated here *The words in red on the Table are examples and are not comprehensive. Please delete and replace with info from your contract. Once complete you can save the worksheet as a PDF to be included in your SOW.
| IASE Summary of IA Workforce Qualification Requirements | |||
| IAT/IAM Level | Experience | Approved Baseline Certifications | |
| IAT I | Apprentice | 0-5 years | A+ CE, CCNA-Security, CND, Network+ CE, SSCP |
| IAT II | Journeyman | at least 3 years | CCNA Security, CySA+ **, GICSP, GSEC, Security+ CE, CND, SSCP |
| IAT III | Master | at least 7 years | CASP+ CE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH |
| IAM I | Apprentice | 0-5 years | CAP, CND, Cloud+, GSLC, Security+ CE |
| IAM II | Journeyman | at least 5 years | CAP, CASP+ CE, CISM, CISSP (or Associate), GSLC, CCISO |
| IAM III | Master | at least 10 years | CISM, CISSP (or Associate), GSLC, CCISO |
| Glossary | ||
| Core Users/Members | All contractors who provide cyber capability (including coding/software development/web development) are core Cyber IT/CSWF members and are required to have an appropriate baseline certification that cannot be education, regardless if it is a secondary duty or closed enclave. | |
| IAM | Information Assurance Management | 51% or more of duties are management |
| IAT | Information Assurance Technical | 51% or more of duties are technical |
| OS/CE | Operating System/Computing Environment | Can be obtained within 6 months of start date |
| Baseline Certification | As an extension of Appendix 3 to the DoD 8570.01-Manual, the above certifications have been approved as IA baseline certifications for the IA Workforce. Personnel performing IA functions must obtain one of the certifications required for their position category or specialty and level. Refer to Appendix 3 of 8570.01-M for further implementation guidance. | |
| Cyber IT/CSWF | Includes IAM/IAT for Cyber IT/CS Workforce. | |
| CSWF | Cybersecurity workforce | Personnel who secure, defend, and preserve data, networks, net-centric capabilities, and other designated systems by ensuring appropriate security controls and measures are in place, and taking internal defense actions. This includes access to system controls, monitoring, administration, and integration of cybersecurity into all aspects of engineering and acquisition of cyberspace capabilities. |
| Cyber IT | Cyberspace Information Technology workforce | Personnel who design, build (e.g., software development), configure, operate, and maintain IT, networks, and capabilities. This includes actions to prioritize portfolio investments; architect, engineer, acquire, implement, evaluate, and dispose of IT as well as information resource management; and the management, storage, transmission, and display of data and information. |
| References | |||
| DoD 8570.01-M | Information Assurance Workforce Improvement Program Incorporating Change 4 | 10-Nov-15 | |
| DODD 8140.01 | Cyberspace Workforce Management | 31-Jul-17 | |
| SECNAV M-5239.2 | DoN Cyberspace Information Technology and Cybersecurity Workforce Management and Qualification Manual | 1-Jun-16 | |
| DoD Approved 8570 Baseline Certifications (IASE Summary of IA Workforce Qualification Requirements) | https://cyber.mil/cw/cwmp/dod-approved-8570-baseline-certifications/ | ||
| Security and Privacy for Computer Systems | DFARS clause subpart 239.71 | https://www.acq.osd.mil/dpap/dars/dfars/html/current/239_71.htm | |
| Information Assurance Contractor Training and Certification | DFARS clause subpart 239.7102-3 | https://www.acq.osd.mil/dpap/dars/dfars/html/current/239_71.htm | |
| Work Roles | |||
| Code and Name | Description | Reminders: | |
| (211) Cyber Defense Forensics Analyst | Analyzes digital evidence and investigates computer security incidents to derive useful information in support of system/network vulnerability mitigation. | 1. Education does NOT count for a cyber BASELINE certification for contractors. | |
| (411) Technical Support Specialist | Provides technical support to customers who need assistance utilizing client level hardware and software in accordance with established or approved organizational process components. (i.e., Master Incident Management Plan, when applicable). | 2. A T5 investigation is required for those requiring IT privileged access according to the SecNavInst 5510.30C, 5. b. (2). | |
| (421) Database Administrator | Administers databases and/or data management systems that allow for the storage, query, and utilization of data. | 3. DOD 8570.01-M "C2.3.9. Contractor personnel supporting IA functions in Chapters 3, 4, 10, and 11 shall obtain the appropriate DoD-approved IA baseline certification prior to being engaged." | |
| (422) Data Analyst | Examines data from multiple disparate sources with the goal of providing new insight. Designs and implements custom algorithms, flow processes and layouts for complex, enterprise-scale data sets used for modeling, data mining, and research purposes. | ||
| (431) Knowledge Manager | Responsible for the management and administration of processes and tools that enable the organization to identify, document, and access intellectual capital and information content. | ||
| (441) Network Operations Specialist | Plans, implements, and operates network services/systems, to include hardware and virtual environments. | ||
| (451) System Administrator | Installs, configures, troubleshoots, and maintains hardware, software, and administers system accounts. | ||
| (461) Systems Security Analyst | Responsible for the analysis and development of the integration, testing, operations, and maintenance of systems security. | ||
| (632) Systems Developer | Designs, develops, tests, and evaluates information systems throughout the systems development life cycle. | ||
| (612) Security Control Assessor | Conducts independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controls (as defined in NIST 800-37). | ||
| (621) Software Developer | Develops, creates, maintains, and writes/codes new (or modifies existing) computer applications, software, or specialized utility programs. | ||
| (622) Secure Software Assessor | Analyzes the security of new or existing computer applications, software, or specialized utility programs and provides actionable results. | ||
| (631) Information Systems Security Developer | Designs, develops, tests, and evaluates information system security throughout the systems development lifecycle. | ||
| (641) Requirements Planner | Consults with customers to evaluate functional requirements and translate functional requirements into technical solutions. | ||
| (651) Enterprise Architect | Develops and maintains business, systems, and information processes to support enterprise mission needs; develops information technology (IT) rules and requirements that describe baseline and target architectures. | ||
| (652) Security Architect | Designs enterprise and systems security throughout the development lifecycle; translates technology and environmental conditions (e.g., law and regulation) into security designs and processes. | ||
| (661) Research & Development Specialist | Conducts software and systems engineering and software systems research in order to develop new capabilities, ensuring cybersecurity is fully integrated. Conducts comprehensive technology research to evaluate potential vulnerabilities in cyberspace systems. | ||
| (671) Testing and Evaluation Specialist | Plans, prepares, and executes tests of systems to evaluate results against specifications and requirements as well as analyze/report test results. | ||
| (722) Information Systems Security Manager | Responsible for the cybersecurity of a program, organization, system, or enclave. (Can only be a civilian in code 1043. 461 would work for ISSOs and others who do similar duties.) | ||
| (723) COMSEC Manager | Manages the Communications Security (COMSEC) resources of an organization (CNSSI No. 4009). | ||
| (731) Legal Advisor | Provides legal advice and recommendations on relevant topics related to cyber law. | ||
| (751) Cyberspace Workforce Developer and Manager | Develop cyberspace workforce plans, strategies and guidance to support cyberspace workforce manpower, personnel, training and education requirements and to address changes to cyberspace policy, doctrine, materiel, force structure, and education and training requirements. | ||
| (752) Cyberspace Policy and Strategy Planner | Develops cyberspace plans, strategy and policy to support and align with organizational cyberspace missions and initiatives. | ||
| (801) Program Manager | Leads, coordinates, communicates, integrates and is accountable for the overall success of the program, ensuring alignment with critical agency priorities. | ||
| (802) IT Project Manager | Directly manages information technology projects. | ||
| (803) Product Support Manager | Manages the package of support functions required to field and maintain the readiness and operational capability of systems and components. | ||
| (804) IT Investment/ Portfolio Manager | Manages a portfolio of IT capabilities that align with the overall needs of mission and business enterprise priorities. | ||
| (805) IT Program Auditor | Conducts evaluations of an IT program or its individual components, to determine compliance with published standards. |
&"Times New Roman,Bold"&24References for Cyber IT/CSWF Certification Matrix
Table 1
| DoDD 8140.01 & DoD 8570.01-M | ||||||
| Labor Category | SOW Task Area | Primary Work Role | ||||
| Code & Name | IT/CS Duties | IAM/IAT Level | Approved Baseline Certifications** | OS/CE Training Required Prior to Being Engaged | ||
| Program Manager* | 3.1, 3.2, 3.3, 3.4, 3.5 | (801) Program Manager | Serves as lead on-site manager . Assigns tasks, monitors progress, ensures deliverables are met, and reports status to the government representative. Ensures team development efforts meet IA compliance standards before deployment to ships. | IAM I | CAP, CND, Cloud+, GSLC, Security+ CE | |
| Principal Engineer (Programmer)* | 3.1, 3.2 | (621) Software Developer | Serves as lead programmer, develops software, performs hydrodynamic analysis of ship models, develops system architecture, utilizes publication standards for print | IAT II | CCNA Security, CySA+ **, GICSP, GSEC, Security+ CE, CND, SSCP | |
| Sr. Scientist* | 3.1, 3.2 | (632) Systems Developer | Performs hydrodynamic analysis of ship models, develops system architecture, develops software, utilizes Computer Aided Design and Drafting (CADD) technology and publication standards for print | IAT II | CCNA Security, CySA+ **, GICSP, GSEC, Security+ CE, CND, SSCP | |
| Principal Scientist* | 3.1, 3.2 | (671) Testing and Evaluation Specialist | Develops system architecture, software, utilizes publication standards for print | IAT II | CCNA Security, CySA+ **, GICSP, GSEC, Security+ CE, CND, SSCP | |
| Sr. Engineer (Software) | 3.1, 3.2 | (621) Software Developer | Develops software life cycle, performs test and evaluation of hardware/software, utilizes publication standards for print | IAT I | A+ CE, CCNA-Security, CND, Network+ CE, SSCP | |
| Jr. Engineer (Software) | 3.1, 3.2, | (621) Software Developer | Performs hardware/software development and documentation. Prepares test plans, user manuals, and reports. Participates in test and evaluation of system at sea and at land based test facility. | IAT I | A+ CE, CCNA-Security, CND, Network+ CE, SSCP | |
| *Denotes Key Personnel | ||||||
| **All contractor personnel performing functions under this TO requiring privileged access, as defined in DoD 8570.01-M, shall obtain one of the appropriate DoD-approved IA baseline certifications prior to being engaged. |
&"Palatino Linotype,Regular"&18Information Assurance Workforce Certification Matrix &K01+000ITPR/Contract Number:&KFF0000 283100/N0016721R0004, &K01+000NSWCCD Department(s): 80
File details come from the government source that posted it. Updated .