The file's text, extracted by GovTribe without its formatting.
RFP Question & Answer – FISMA, Audit (7/29/2016)
RFP CSOSA16R0021
| Question Reference |
| Government Response: |
| 1 |
| Is there an incumbent contractor? |
| N/A |
| No, there is no incumbent. |
| 2 |
| What is the anticipated award date? |
| N/A |
| September 2, 2016 |
| 3 |
| Will contractor have access to previous audits and has a FISMA audit been conducted before? |
| N/A |
| Yes |
| 4 |
| Can the Government confirm that submission should be both through FBO and email? |
| 5 |
| Is there a desired pricing template the Government wishes to use? |
| N/A |
| 6 |
| 6. Can the Government confirm that only the PM's resume is required? |
| N/A |
| Refer to Section 5.2 Personnel Requirements |
| 7 |
| Can the Government revise the Past Performance Questionnaire to reflect the correct email address for submission? |
| 8 |
| How many existing technical test result packages conducted by other independent assessors are available or in the scope of this SOW? |
| N/A |
| Prior assessment results and output from the the Information Security Continuous Monitoring (ISCM) |
| 9 |
| How many distinct System Security Plan (SSP), System Assessment Plan (SAP), and System Assessment Report (SAR) are available or in the scope of this SOW? |
| N/A |
| Refer to Section 4.0 for Scope of Work |
| 10 |
| Does the scope of assessment cover the data center/infrastructure, platform and software layers? For example, does CSOSA own/operate data centers that need to be assessed as part of the scope of this SOW? |
| N/A |
| Refer to Section 4.0 for Scope of Work |
| 11 |
| How many assets (router, server, VM,...) are in the scope of the assessment? |
| N/A |
| Refer to Section 4.0 for Scope of Work |
| 12 |
| How many separate applications/system are in the scope of this SOW? |
| N/A |
| Refer to Section 4.0 for Scope of Work |
| 13 |
| Has NIST 800-53A Revsion 4 be rolled out and conformance evaluated to-date. If not, which is the last revision to which conformance has been evaluated? |
| N/A |
| Refer to Section 4.0 for Scope of Work |
| 14 |
| Is CSOSA currently using the Cyberscope FISMA reporting system to populate the FISMA IG reporting metrics via the OMB Max Portal or is this the first time? |
| N/A |
| Refer to Section 4.0 for Scope of Work |
| 15 |
| Are there any current outstanding Key FISMA Metrics (KFM) issues yet to be addressed? If so, is there a POA&M available that can be reviewed? |
| N/A |
| Yes, Upon Award |
| 16 |
| Will the government clarify the scope for this audit support? How many IT systems or services are within scope? |
| N/A |
| Refer to Section 4.0 for Scope of Work |
| 17 |
| What is the size of the cybersecurity program? What is the size of systems or infrastructure involved (Large, Med, Small, etc.)? |
| N/A |
| Refer to Section 4.0 for Scope of Work |
| 18 |
| Does the government expect any scans or hands on technical evaluation? |
| N/A |
| Refer to Section 4.0 for Scope of Work |
| 19 |
| What is do the existing audit reports consists of in terms of testing conducted? |
| N/A |
| Refer to Section 4.0 for Scope of Work. |