Draft RFI CyberSecurity (1).pdf
PDF 231 KB Posted
- Attached to
- Cyber Security Support Services Federal contract opportunity
- Solicitation number
- NOF-0008
About this file
This document is a Sources Sought Synopsis from the Department of Housing and Urban Development (HUD) for Cybersecurity Support Services. HUD is seeking to acquire these services to transform, implement, operate, and maintain the OCISO Cybersecurity Program, which includes requirements for Cybersecurity Program Management, Security Architecture, Security Operations Center, Governance Risk and Compliance, Cyber Strategic Initiatives, and Vulnerability Management/Continuous Diagnostics and Mitigation. The services are required to provide HUD with sustainable, proactive, and reactive cybersecurity policies and processes to protect its operating environment against dynamic threats. HUD is conducting market research to identify interested parties with the capacity to perform these services. Responses are due by September 12, 2024. The procurement may be set aside for small businesses or procured through full and open competition, with the possibility of multiple awards. Key areas of work include security architecture and innovation, data security, identity and access management, zero trust architecture, strategic initiatives, governance risk and compliance, and security operations. Optional services include cybersecurity training and awareness, and additional GRC support.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Performance Work Statement.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Sources Sought Synopsis
The Department of Housing and Urban Development (HUD) is issuing this source sought synopsis as a means of conducting market research to identify parties having an interest in and the resources to support this requirement to acquire Cybersecurity Support Services for the transformation, implementation, operation, and maintenance of the OCISO Cybersecurity
Program. Specific requirements are Cybersecurity Program Management, Security Architecture, Security Operations Center, Governance, Risk, and Compliance (GRC), Cyber Strategic
Initiatives, and Vulnerability Management/Continuous Diagnostics and Mitigation. These services are required to provide the Department with sustainable organic proactive and reactive cybersecurity policies and processes to protect HUD’s operating environment against a dynamic threat environment.
The result of this market research will contribute to determining the method of procurement.
The applicable North American Industry Classification System (NAICS) code assigned to this procurement is 541611.
There is no solicitation at this time. This request for capability information does not constitute a request for proposals; submission of any information in response to this market survey is purely voluntary; the government assumes no financial responsibility for any costs incurred.
If your organization has the potential capacity to perform these contract services, please provide the following information: 1) organization name, address, email address, website address, telephone number, and size and type of ownership for the organization; and 2) tailored capability statements addressing the particulars of this effort, with appropriate documentation supporting claims of organizational and staff capability. If significant subcontracting or teaming is anticipated to deliver technical capability, organizations should address the administrative and management structure of such arrangements.
The government will evaluate market information to ascertain potential market capacity to 1) provide services consistent in scope and scale with those described in this notice and otherwise anticipated; 2) secure and apply the full range of corporate financial, human capital, and technical resources required to successfully perform similar requirements; 3) implement a successful project management plan that includes: compliance with program schedules; cost containment; meeting and tracking performance; hiring and retention of personnel and risk mitigation; and 4) provide services under a performance based service acquisition contract.
Based on the responses to this source sought notice/market research, this requirement may be set-aside for small businesses or procured through full and open competition, and multiple awards may be made. Telephone inquiries will not be accepted or acknowledged, and no feedback or evaluations will be provided to companies regarding their submissions.
Submission Instructions: Interested parties who consider themselves qualified to perform the above-listed services are invited to submit a response to this Sources Sought Notice by
9/12/2024. All responses under this Sources Sought Notice must be emailed to David.o.cruz-mota@hud.gov. Additional information on the required services is listed below. If you have any questions concerning this opportunity, please contact: David.o.cruz-mota@hud.gov.
Background:
The U.S. Department of Housing and Urban Development’s (HUD’s) Office of the Chief
Information Security Officer (OCISO) is seeking support in modernizing the cybersecurity program to include audit management policies and processes, capabilities, and services. OCISO is entrusted to implement, manage, and operate an enterprise cybersecurity program to protect
HUD’s information and systems, while enabling the Department’s core programs. HUD requires an enterprise-wide approach to coordinate cybersecurity oversight, reporting, management, and implementation. An enterprise-wide approach affords HUD the opportunity to become more proactive in seeking vulnerabilities/deficiencies in its information systems/assets, increasing employee/contractor cybersecurity knowledge, adjusting cybersecurity training, and enhancing reporting to internal and external stakeholders. As the cyber threat landscape evolves, presenting increasingly sophisticated cyber risks, HUD requires a mature and agile cybersecurity program equipped with the necessary strategy or roadmap with defined goals and milestone for the program, Department level support, qualified resources, and well-defined, risk-informed strategy that will enable HUD’s mission and protect U.S. citizens.
General Description of Work:
Currently OCISO lacks strategic development and planning, governance, enterprise risk management, cyber transformation, and process improvement and innovation. There is a lack of policy development, knowledge management, zero trust design and implementation, progression with logging and program plan and action development of an enterprise cybersecurity program to protect HUD's information and systems, while enabling the Department's core programs. The
Contractor shall provide all services, materials, supplies, equipment, travel, and project supervision, as required in connection with this Statement of Objective (SOO).
Below are the characteristics of the (insert short description) requirements:
1. Mandatory Assessment Period (Maximum 60 days from contract award). The contractor shall complete an assessment of the program to ensure the proposed solution is the most advantageous. After completing the assessment, the contractor can make a one-time adjustment to the proposed solution with up to 15% increase or unlimited decrease in price or tasks.
mailto:David.o.cruz-mota@hud.gov mailto:David.o.cruz-mota@hud.gov mailto:David.o.cruz-mota@hud.gov.
2. Security Architecture and Innovation:
• Establish and operate a Security Architect Review (SAR) and Security Systems
Engineering (SSE) program that will establish and enforce security controls for HUD’s
IT transformational projects to reduce risks prior to deployment and improve assessment turnarounds.
• Establish and implement a SAR capability that incorporates security into the software development life cycle (SDLC), establishes roles and responsibilities for security activities, and implements security configurations to prevent project delays and reduce vulnerabilities.
• Conduct research on security technologies, processes and procedures including exploring the latest advancements in security solutions, evaluation their effectiveness, and understanding how security solutions can be integrated into existing frameworks.
• Perform security reviews of HUD’s planned and existing architecture.
• Establish, implement, and evaluate HUD-specific security architecture and SSE principles standards, policies, procedures, and processes against industry best practices to provide perimeter security, network security, endpoint security, application security, physical security, and data security for all ~300,00 IT assets. Currently HUD OCISO doesn’t have any existing policies and procedures that we could provide from the past to provide a current listing for reference.
• Maintain security models and artifacts in HUD’s enterprise architecture and cybersecurity repositories. We currently do not have a repository or any security models and artifacts to reference our way forward from past contracts, due to unorganized turnovers within the office. There was a previous contractor (ManTech), but we don’t have all those documents at our disposal or the location of those documents to reference. Review the proposed architecture for all planned and existing cybersecurity solutions, that provide protection for the Department’s General Support Systems (GSS), Major Applications
(Mas), Minor Applications and Cloud Service Provider (CSP) Services and assess the extent to which these solutions are properly architected and engineered. HUD OCISO can provide what we can find, but we don’t have a central repository of past documentation and work done by previous customers.
• Research, analyze and recommend innovative technologies, processes, and procedures for entire cybersecurity program.
• Develop mechanisms for integration and information sharing between the SAR/SSE and other HUD stakeholders.
Data Security Program:
• Initiate and operate a Data Security Program (DSP) aimed at safeguarding the organization's sensitive information assets and ensuring compliance with data security laws, policies, and regulations.
• Develop data security policies, procedures, and standards that address identified risks and compliance requirements.
• Analyze potential data security risks and evaluate data security measures.
• Research and identify data security solutions such as data encryption, data loss prevention (DLP), cloud access security brokers (CASB), etc.
• In coordination with the Chief Data Officer and Zero Trust Program Office, identify and classify data, establish data movement monitoring, and implement data access controls defining who can access data based on attributes such as role, office, security clearance, location, etc.
• Currently HUD OCISO does not have any existing data security program policies, procedures, or artifacts that we could provide.
Identity, Credential, and Access Management (ICAM) Program:
• Establish and operate an Identity, Credential, and Access Management (ICAM) program, tailored to bolster the organization's security posture and operational efficiency by reducing security vulnerabilities and streamlining user access across all systems. This enterprise program is a federal requirement that is HUD is currently delinquent in accordance with federal regulations.
• Develop policies, procedures and standards to effectively manage digital identities, credentials, and access controls across all systems and platforms in accordance with laws, policies, and regulations.
• Create and maintain the ICAM strategic plan.
• Implement a governance structure that defines roles and responsibilities within the ICAM framework and ensures accountability.
• Analyze potential identity security risks and evaluate identity security measures.
• Research and identify security solutions such as phishing-resistant Multi Factor
Authentication, Identity Governance and Administration (IGA), Federated Identity
Management and Risk-based Authentication.
• In coordination with Enterprise Architecture, develop and maintain ICAM capabilities and technologies roadmaps.
• Develop and maintain ICAM implementation plan.
• Monitor the deployment of ICAM solutions across HUD, ensuring integration with existing IT infrastructure.
• Report on ICAM solution metrics.
• Coordinate with IT and security teams to implement ICAM technologies.
Zero Trust Architecture Program:
• Create and operate a Zero Trust Architecture (ZTA) Program, tasked with providing expert guidance, governance, and oversight for the organization's transition to a Zero
Trust security model. The program will be responsible for defining the strategic direction, policies, and standards necessary to implement a Zero Trust framework, emphasizing the core principle of "never trust, always verify."
• Create and maintain the Zero Trust strategic plan.
• Implement a governance structure that defines roles and responsibilities within the Zero
Trust framework and ensures accountability.
• Analyze Zero Trust requirements and identify and evaluate security measures to meet the requirement.
• Research and identify Zero Trust technical and procedural solutions.
• In coordination with Enterprise Architecture, develop and maintain Zero Trust capabilities and technologies roadmaps.
• Develop and maintain Zero Trust implementation plan.
• Monitor the deployment of Zero Trust solutions across HUD, ensuring integration with existing IT infrastructure.
• Develop and provide training to promote awareness of Zero Trust initiatives and processes.
• Report on Zero Trust solution metrics.
• Coordinate with IT and security teams to implement Zero Trust technologies.
3. Strategic Initiatives (SI):
• Manage and govern the cybersecurity supply chain risk management (SCRM) program.
Update existing SCRM procedure. SCRM to provide HUD with a framework to proactively manage supply chain risks from a cybersecurity perspective and to adhere to federal regulations.
• Identify and prioritize exiting supply chain vendors into risk levels based on services provided by vendors. This includes the documented process and the identifying the risk designation of each vendor in the Cyber Security Assessment Management (CSAM) toolkit.
• Conduct up to 50 security risk assessments annually against third parties to satisfy the
NIST SP 800-53 Rev. 5 Supply Chain Risk Management (SR) controls at the system-level.
• Integrate security-related, supply chain risk management (SCRM) concepts into the
Information Security Continuous Monitoring (ISCM) as part of the transition to National
Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 Rev. 5 transition to address untrustworthy suppliers, insertion of counterfeits, tampering, unauthorized production, theft, insertion of malicious code, and poor manufacturing and development practices throughout the SDLC.
• Support the implementation of OMB M-22-18 and the integration of the Secure Software
Development Form into the SDLC and ISCM.
• Support HUD to establish a Cybersecurity workforce strategy and implementation plan that can obtain and maintain industry certifications and academic credentials for the
Departments cybersecurity workforce.
• For each key role (up to 4), establish certificate pathway to include establishing training requirements, accountability, and tracking.
• Implement governance to manage the execution of the certificate pathways across roles to include coordination with
• Support Information System Security Officer (ISSO) function to include supporting ATO package development for approximately 30 major applications and General Support
Systems. Packages should be developed in accordance with NIST SP 800-53 Rev. 5
• Develop implementation plan and strategy to centralize the ISSO Support function under
OCISO.
4. Governance, Risk, and Compliance:
• Develop a new dashboard with views to support Risk Management Framework and the
Cybersecurity Framework (CSF), establish new performance metrics, and develop APIs with existing data sources to automate functionality.
• Define views and processes to leverage information from the CDM dashboard to support reporting to include training key stakeholders.
• Support automation of existing processes through development of Power Apps. Redesign
OCISO HUD@Work page and template and knowledge repositories (both internal and external).
• Provide analysis and review of new and emerging federal information security and privacy policies, directives, and mandates within the timeframes specified by HUD.
• Determine policy/procedures ownership and track the associated implementation timelines to ensure adherence to the requirements.
• Conduct market research and establish a roadmap and requirements for a modernized
Governance Risk and Compliance (GRC) tool.
• Assist in the agency-led High Value Asset (HVA) assessments in compliance with the
Cybersecurity and Infrastructure Security Agency (CISA) Assessment Evaluation and
Standardization (AES) Program.
• Update and enhance HUD’s Entity-Wise Business Impact Analysis (EWBIA).
5. Security Operations Center (SOC):
• Real-time Alert Monitoring and Triage: Monitor and triage incoming security alerts in real-time, prioritizing based on severity and potential impact.
• Incident Reporting: Promptly document and report security incidents following established procedures, ensuring accurate and comprehensive reporting for further analysis and response.
• Incident Analysis and Investigation: Conduct thorough analysis and investigation of security incidents to determine root causes, attack vectors, and potential impact on systems and data.
• Containment, Eradication, and Recovery: Implement effective containment strategies to prevent further spread of security incidents, eradicate threats from affected systems, and facilitate timely recovery of impacted assets.
• Incident Coordination: Coordinate response efforts across relevant teams and stakeholders, ensuring clear communication and collaboration to mitigate security incidents efficiently.
• Forensic Artifact Analysis, Malware Analysis: Perform in-depth forensic analysis of digital artifacts and conduct malware analysis to understand the nature of security threats and develop effective countermeasures.
• Cyber Threat Intelligence Collection, Processing, and Fusion: Collect, process, and fuse threat intelligence from various internal and external sources to gain insights into emerging threats, attacker tactics, techniques, and procedures (TTPs).
• Cyber Threat Intelligence Analysis and Production: Analyze gathered threat intelligence to identify patterns, trends, and indicators of compromise (IOCs), producing actionable intelligence reports to inform defensive strategies.
• Cyber Threat Intelligence Sharing and Distribution: Share relevant threat intelligence with peer organizations, industry groups, and government agencies to enhance collective defense and improve overall cybersecurity posture.
• Threat Hunting: Proactively search for signs of malicious activity within the network environment, utilizing advanced techniques and tools to detect and mitigate threats before they escalate.
• Sensor and Analysis Tuning: Continuously fine-tune security sensors and analytical tools to improve detection capabilities and reduce false positives, enhancing the overall effectiveness of threat detection and response.
• Custom Analytics and Detection Creation: Develop and deploy custom analytics and detection mechanisms tailored to the organization's specific threat landscape, leveraging advanced data analytics and machine learning techniques.
• Machine Learning: Explore and utilize machine learning algorithms to enhance threat detection, prediction, and response capabilities, enabling more adaptive and proactive cybersecurity defenses.
• Adversary Emulation and Red Teaming: Develop and execute sophisticated adversary emulation exercises and red team engagements to simulate realistic attack scenarios, evaluate defensive capabilities, and identify vulnerabilities across people, processes, and technologies. Through these exercises, the SOC aims to proactively enhance detection, response, and mitigation strategies while fostering a culture of continuous improvement in cybersecurity posture.
• Purple Teaming: Facilitate collaborative engagements between red and blue teams to foster knowledge sharing, mutual understanding of tactics, techniques, and procedures
(TTPs), and the iterative refinement of defensive strategies. By leveraging purple teaming exercises, the SOC seeks to strengthen detection and response capabilities, optimize security controls, and enhance overall resilience against advanced threats. The SOC will systematically assess the severity and potential impact of identified vulnerabilities, prioritize remediation efforts based on risk factors, and provide actionable insights to relevant stakeholders for timely mitigation.
• Continuous Improvement and Knowledge Sharing: Foster a culture of continuous improvement within the SOC by promoting knowledge sharing, skills development, and cross-functional collaboration. Regular debriefs, post-incident analyses, and lessons learned sessions will be conducted to identify areas for enhancement, disseminate best practices, and ensure alignment with industry standards and emerging trends.
• Integration of Threat Intelligence: Integrate actionable threat intelligence derived from internal and external sources into adversary emulation, red teaming, and vulnerability analysis workflows. By leveraging real-time insights on emerging threats, attacker TTPs, and exploit techniques, the SOC aims to enhance proactive detection, threat hunting capabilities, and strategic decision-making to stay ahead of evolving cyber threats.
• Metrics and Reporting: Define key performance indicators (KPIs) and metrics to measure the effectiveness of expanded SOC operations, including the success rate of adversary emulation exercises, vulnerability remediation timelines, and overall improvement in defensive capabilities. Regular reporting to executive leadership and stakeholders will provide visibility into the SOC's contribution to risk reduction, incident response readiness, and organizational resilience.
• Compliance and Regulatory Alignment: Ensure that expanded SOC operations adhere to relevant industry regulations, compliance requirements, and best practices. By maintaining alignment with regulatory frameworks and industry standards, such as
GDPR, HIPAA, PCI DSS, and NIST Cybersecurity Framework, the SOC will demonstrate a commitment to safeguarding sensitive information, protecting customer privacy, and mitigating legal and regulatory risks.
6. Enterprise Vulnerability Management/Continuous Diagnostics and Mitigation:
• Coordinate with HUD’s CDM Integrator, to align CDM capabilities with HUD’s cybersecurity strategy and roadmap. The Vulnerability Management and CDM program will need maturation to help reduce agency wide risks and improve alignment with
HUD’s cybersecurity goals.
• Develop and maintain SOPs to guide how HUD utilizes the existing hardware asset management (HWAM), software asset management (SWAM), Configuration Settings
Management (CSM), and Vulnerability Management (VUL) tools to reduce CDM
Agency-Wide Adaptive Risk Enumeration (AWARE) scores and improve FISMA metrics.
• Manages account/access/managed privileges (PRIV), trust determination for people granted access (TRUST), credentials and authentication (CRED), and security-related training (BEHAVE).
• Vulnerability Report Intake and Analysis: Establish streamlined processes for the intake, prioritization, and analysis of vulnerability reports from the Vulnerability Management
Team and other various sources, including automated scanning tools, security researchers, and internal assessments.
• Manages network and perimeter components, host and device components, data at rest and in transit, and user behavior and activities. This includes management of events
(MNGEVT); operate, monitor, and improve (OMI); design and build-in security (DBS);
boundary protection (BOUND); supply chain risk management (SCRM); and ongoing authorization.
• Manages the protection of data through the capabilities: data discovery/classification
(DISC), data protection (PROT), data loss prevention (DLP), data breach/spillage mitigation (MIT), and information rights management (IRM).
• Develop the CDM Operational Methodology that includes a continuous process for discovering assets and risks, monitoring environmental changes, analyzing and reporting risks to stakeholders, and to mitigate cyber risks.
• Utilize the suite of CDM tools and capabilities to identify risks to the security of the enterprise.
• Analyze HUD’s existing CDM tools, recommend additional coverage and requirements based on HUD’s cybersecurity strategy, and standardize how CDM tools are operated.
• Analyze unused or misused licenses and provide recommendations to user license management.
• Develop actionable risk reports utilizing the CDM tools from data generated by CDM tools.
7. Optional:
Depending on available funding, HUD would like to turn to the below optional support once funding is available to support the below activities. Currently our current customer is providing the services, but HUD will need more qualified and quality work to sustain the program.
SI Surge Support:
• Provide cybersecurity training, awareness, and communications support.
• Develop an annual training and awareness plan. Conduct Incident Response Exercises
(tabletop and live scenarios).
• Update existing training courses and develop new trainings (all trainings should be delivered as SCORM files unless otherwise specified by the Government).
• Execute awareness campaigns to include HUD-wide Lunch and Learns.
• Support ISSO forum, developing materials and coordinating.
• Perform an annual Enterprise Cyber Security Roles Analysis (ECRA).
• Develop and update training procedures and program charter.
• Support reporting on training completions.
GRC Surge Support:
• Draft and update information security policies, procedures, processes, standards, technical guidance, and templates, shepherd them through the appropriate review process, and provide training to key stakeholders.
• Support cybersecurity risk management to assist the Department to better understand, manage, and reduce its cybersecurity risks.
• Provide assessment support for initial ATOs, re-authorization, and ISCM. Establish automated testing mechanisms to enhance assessment support.
• Manage and evaluate POA&M closure requests.
• Support data calls to include quarterly Federal Information Security Modernization Act
(FISMA) self-reporting and ad hoc data calls from external entities such as OMB.
• Support cybersecurity audit management to include tracking, developing executive briefs, establishing Corrective Action Plans (CAPs), and supporting Prepared by Client (PBC) requests.
• Perform document compliance reviews such as Risk Based Decisions (RBDs), Memorandum of Understanding (MOU), Information Security Agreements (ISAs), etc.
• Provide tracking and monitoring of RBDs.
• Provide HVA governance support.
• Support the transition from NIST 800-53 Rev. 4 to Rev. 5. Develop reports and briefs for program offices, demonstrating compliance with HUD IT Security Policy.
• Perform annual retrospectives across all FISMA domains based on defined metrics and establish lessons learned.
8. Final Outcome. At the end of contract performance the OCISO Cybersecurity Program shall fully transform the OCISO project management and hiring process to include intern programs; make 75% progress or greater with the milestones within the EO 14028 to include implementation of Zero Trust; develop an executable cyber strategy; improve processes and complete backlog of audit recommendations; implement the Supply Chain
Risk Management Program within Strategic Initiatives and update cybersecurity training program; and provide knowledge and support to transform and develop processes and policies for the Vulnerability Management and Continuous Diagnostic and Mitigation
Program.
The tasks require a set of skill categories based on the following approximate breakdown:
Possible Labor Category Common Description
IT Cybersecurity Specialist - Dashboard PowerApps Dashboard
IT Cybersecurity Specialist - Policy Manage OCISO policies/procedures, GRC
Tool Research, BIA Analysis
IT Cybersecurity Specialist - Assessor Conduct HVA Assessments
ITC Specialist CDM Lead -Manage CDM
ITC Specialist CDM Specialist - Supports CDM/PM workstream (Audits, PPM docs, tools, etc.)
ITC Specialist VM Policy Analyst - Creates and/or updates
VM policies and procedures
ITC Specialist VM Lead - Manage VULMAN program management workstream
ITC Specialist VM Specialist - Supports vulnerability identified via Audits, BODs, CVEs, KEVs, etc.
Security Architect Experienced professional who designs and maintains the overall security architecture, ensuring it meets business needs and security requirements
Security Engineer Senior engineer responsible for integrating security measures into system designs and overseeing the implementation of security controls
Process/Knowledge Management Specialist Specialist responsible for organizing, maintaining, and optimizing the flow of information and knowledge within the organization, ensuring efficient access to and utilization of data and documentation
IT Cybersecurity Specialist Expert in securing network, applications, cloud, etc.
IT Project Manager Project Manager
Training Exercise Planner Sr. Exercise Planner
Training Exercise Planner Jr. Exercise Planner
ISSO Support Specialist ISSO Support
Cybersecurity Support Specialist Supply Chain Risk Management Support
Policy and Compliancy Specialist Specialist responsible for developing, maintaining, and updating security policies, procedures, and standards.
Security Architect
Expert designing the overall security architecture, ensuring comprehensive protection across all data systems and environments
System Administrator - DLP
Professional implementing and managing tools and processes to prevent unauthorized data exfiltration
Process/Knowledge Management Specialist
Specialist responsible for organizing, maintaining, and optimizing the flow of information and knowledge within the organization, ensuring efficient access to and utilization of data and documentation
IT Cybersecurity Specialist
Expert in securing network, applications, cloud, etc.
IT Project Manager
Tracks various IT projects and coordinates with both technical and non-technical staff.
Coordinates efforts across OCIO and
Program Office teams. Provides routine status updates to managers and stakeholders. Creates easy-to-follow resources to allow for easy reference.
System Integration Specialist
Analyzes software to ensure seamless interoperability
IT Cybersecurity Specialist - Policy Lead Manage policy management workstream
IT Cybersecurity Specialist - Policy Create and/or update OCISO policies and procedures
IT Cybersecurity Specialist - Lead Manage ATOs
IT Cybersecurity Specialist - Assessor Conduct security assessments, security impact analysis, ISCM, RBDs, MOUs, etc.
IT Cybersecurity Specialist - FISMA
Manager
Manage FISMA CIO data call
IT Cybersecurity Specialist - FISMA Support FISMA CIO quarterly data calls, MFA & Compliance data calls, and other ad hoc calls
IT Cybersecurity Specialist - Audit
Manager
Support OCISO audit management
IT Specialist ISSO Support
Contemplated performance metrics:
Performance Objective
SOO
Paragrap h
Performance Threshold Method of Surveillance
SS – 1
Performance
Metrics
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
Establish a baseline with objective criteria to measure transformation progression. This is an iterative process. Changes are expected along the transformation journey.
These metrics will be re-assed at the mid-point of the transformation. The final Performance Metrics to provide the Government with a way to clearly measure transformation success/failure and how to minimally maintain the change and/or adjust based on the performance metrics put in place.
100%
Surveillance
Contemplated report requirements:
DELIVERABLE –
Acceptance Criteria
DUE DATE SOO Paragraph DELIVERY
METHOD
Assessment Brief – acceptable when the briefing provides defendable recommendations to update/change the initial solution.
NLT 60 days after award
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
By email to COR in
PowerPoint/PDF briefing format
Performance Metrics
– acceptable when the performance measures are objective, executable, traceable, repeatable, and reliant on authoritative data.
DRAFT 1 - NLT 60
days after award
DRAFT 2 – NLT 30
days after mid-point of performance
FINAL – NLT 30
days prior to end task order period of performance
2.2.2
2.2.3
2.2.4
By email to COR in mutually agreed upon format
Program Management
Plans
60 days after award and thereafter monthly updated plans, if applicable
2.2.2
2.2.3
2.2.4
1 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
Cyber Risk
Dashboard &
Reporting
120 days after award
2.2.4 1 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
Cyber Training &
Awareness
Certification Pathway
90 days after award
2.2.3 1 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
HUD Cyber Strategy 90 days after award
2.2.2
2.2.3
2.2.4
PM, and HUD OCISO
TPOC
Procedures for M-22-
18 Compliance
90 days after award
2.2.3 1 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
Cyber Innovation
Evaluation Process
90 days after award
2.2.2 1 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
Redesigned
HUD@Work Page and Knowledge
Repositories
90 days after award
2.2.4 Electronic copy to the
following: COR, PM, and HUD OCISO
TPOC
Analysis of New and
Emerging Federal
Policies/Directives
30 after award and thereafter continuous
2.2.4 Electronic copy to the
following: COR, PM, and HUD OCISO
TPOC
Updated HUD’s
Entity-Wise Business
Impact Analysis
(EWBIA)
90 days after award 2.2.4 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
Cyber Program
Roadmap
145 days after award
2.2.2
2.2.3
2.2.4
PM, and HUD OCISO
TPOC
Cybersecurity SCRM
Reviews
145 days after award
2.2.3 1 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
ATO Packages for
ISSO Supported
Systems
145 days after award
2.2.3
2.2.4
1 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
GRC Tool Roadmap and Requirements
145 days after award
2.2.4 1 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
HVA Assessments 145 days after award
2.2.4 1 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
Power Apps and
Operational Guides
145 days after award
2.2.4 1 Electronic copy to the following: COR, SAR and SSE Charter 60 days after award 2.2.2 1 Electronic copy to
PM, and HUD OCISO
TPOC
SAR and SSE
Standard Operating
Procedure Guides
90 days after award 2.2.2 1 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
Security Architecture
Framework
120 days after award 2.2.2 1 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
Security Models and
Artifacts
Security Architecture
Review Reports
PM, and HUD OCISO
DSP Charter 60 days after award 2.2.2
PM, and HUD OCISO
DSP Guides 120 days after award 2.2.2
PM, and HUD OCISO
DSP Policy 90 days after award 2.2.2
PM, and HUD OCISO
TPOC
Data Inventory and
Classification Report
PM, and HUD OCISO
TPOC
DSP Audit Plan &
Schedule
150 days after award 2.2.2
PM, and HUD OCISO
TPOC
DSP Compliance
Assessment Report
DSP Technology
Implementation
Roadmap
150 days after award 2.2.2
PM, and HUD OCISO
TPOC
ICAM Program
Charter
60 days after award 2.2.2
PM, and HUD OCISO
TPOC
ICAM Current State
Assessment
90 days after award 2.2.2
PM, and HUD OCISO
ICAM Strategy 120 days after award 2.2.2
PM, and HUD OCISO
TPOC
ICAM Policy &
Guide
150 days after award 2.2.2 1 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
Unified Identity
Management
Framework &
Workflows
120 days after award 2.2.2
ICAM Technology
Implementation
Roadmap
PM, and HUD OCISO
Zero Trust Strategy 90 days after award 2.2.2
PM, and HUD OCISO
TPOC
Zero Trust Policy 60 days after award 2.2.2 1 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
Zero Trust Technical
Guides
120 days after award 2.2.2 1 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
Zero Trust Training &
Campaign
150 days after award 2.2.2 1 Electronic copy to the following: COR, Zero Trust
Governance
Framework
120 after award 2.2.2 1 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
Zero Trust
Technology
Implementation
Roadmap
150 days after award 2.2.2 1 Electronic copy to the following: COR, Contemplated dollar value of the project:
$38,281,142.80
Contemplated place of performance:
Location.
Remote but must be available for Senior Leader or requested onsite meetings/exercises online and/or in person (if applicable). Notification will be provided in advance
File details come from the government source that posted it. Updated .