SOW_-_Attachment_B_-_IT_Security_References.pdf

PDF 21 KB Posted

Attached to
FCC Auction Bidding System Replacement Federal contract opportunity
Solicitation number
FCC13R0006
Issued by
Federal Communications Commission

About this file

FCC ISAS - Statement of Work - Atttachment B

View the file

Other files for this federal contract opportunity

Show all 17

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ATTACHMENT B - IT SECURITY REFERENCES

The following list of resources provides additional information that may be helpful to Offerors in preparing their responses to this solicitation. The successful Offeror shall provide details as to how their services, systems and the surrounding processes will adhere to the relevant security standards and Government regulations.

FCC Cybersecurity Program Cybersecurity Policy, Version 3.1.1, July 31, 2012

Available upon request

NIST Special Publication 800-27 Rev A Engineering Principles for Information Technology Security (A Baseline for Achieving Security), Revision A http://csrc.nist.gov/publications/nistpubs/800-27A/SP800-27-RevA.pdf

Office of Management and Budget (OMB) Circular No.A-130, Management of Federal Information Resources. Documents may be found at:

http://www.whitehouse.gov/omb/circulars/a130/a130trans4.html.

Office of Management and Budget (OMB) guidelines on The E-Government Act of 2002, Sec.

208 on Privacy Provisions (see Privacy Impact Assessment requirements). Information available at:

http://www.whitehouse.gov/omb/memoranda/m03-22.html.

National Institute of Standards and Technology (NIST) Special Publication 800-18, Guide for Developing Security Plans for Information Technology Systems. This document is available at:

http://csrc.nist.gov/publications/nistpubs/800-18-Rev1/sp800-18-Rev1-final.pdf.

National Institute of Standards and Technology (NIST) Special Publication 800-37, Guide for the Security Certification and Accreditation of Federal Information Systems. This document can be found at:

http://csrc.nist.gov/publications/nistpubs/800-37/SP800-37-final.pdf.

Draft NIST Special Publication 800-53, Revision 3, and Recommended Security Controls for Federal Information Systems. This document can be found at:

http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/sp800-53-rev3-final_updated-errata_05-01-2010.pdf

Draft NIST Special Publication 800-53A, Revision 1, Guide for Assessing the Security Controls for Federal Information Systems. This document can be found at:

http://csrc.nist.gov/publications/drafts.html#sp800-53A http://csrc.nist.gov/publications/nistpubs/800-27A/SP800-27-RevA.pdf http://www.whitehouse.gov/omb/circulars/a130/a130trans4.html http://www.whitehouse.gov/omb/memoranda/m03-22.html http://csrc.nist.gov/publications/nistpubs/800-18-Rev1/sp800-18-Rev1-final.pdf http://csrc.nist.gov/publications/nistpubs/800-37/SP800-37-final.pdf http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/sp800-53-rev3-final_updated-errata_05-01-2010.pdf http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/sp800-53-rev3-final_updated-errata_05-01-2010.pdf http://csrc.nist.gov/publications/drafts.html#sp800-53A

NIST Cryptographic Toolkit. Information regarding encryption standards approved for use by Government organizations may be found at:

http://csrc.nist.gov/groups/ST/toolkit/index.html

NIST Special Publication 800-12, An Introduction to Computer Security. Documents may be found at:

http://csrc.nist.gov/publications/nistpubs/800-12/.

NIST Special Publication 800-14, Generally Accepted Principles and Practices for Securing Information Technology Systems. Documents may be found at:

http://csrc.nist.gov/publications/nistpubs/800-14/800-14.pdf.

NIST SP 800-16, Information Technology Security Training Requirements. Documents may be found at:

http://csrc.nist.gov/publications/nistpubs/800-16/800-16.pdf.

http://csrc.nist.gov/publications/nistpubs/800-16/AppendixA-D.pdf.

http://csrc.nist.gov/publications/nistpubs/800-16/Appendix_E.pdf.

NIST SP 800-47, Security Guide for Interconnecting Information Technology Systems. This document can be found at:

http://csrc.nist.gov/publications/nistpubs/800-47/sp800-47.pdf

The National Institute of Standards and Technology (NIST) Special Publication (SP) 800-64, Security Considerations in the System Development Life Cycle http://csrc.nist.gov/publications/nistpubs/800-64-Rev2/SP800-64-Revision2.pdf

NIST Special Publication 800-40 Revision 3 PRE-PUBLICATION Guide to Enterprise Patch Management Technologies http://csrc.nist.gov/publications/nistpubs/800-40-rev3/sp800_40_r3_pre_publication.pdf

Validated FIPS 140-1 and FIPS 140-2 Cryptographic Modules http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140val-all.htm

Federal Information Security Management Act (FISMA). This document is available at:

http://www.cio.gov/archive/e_gov_act_2002.pdf.

http://csrc.nist.gov/groups/ST/toolkit/index.html http://csrc.nist.gov/publications/nistpubs/800-12/ http://csrc.nist.gov/publications/nistpubs/800-14/800-14.pdf http://csrc.nist.gov/publications/nistpubs/800-16/800-16.pdf http://csrc.nist.gov/publications/nistpubs/800-16/AppendixA-D.pdf http://csrc.nist.gov/publications/nistpubs/800-16/Appendix_E.pdf http://csrc.nist.gov/publications/nistpubs/800-47/sp800-47.pdf http://csrc.nist.gov/publications/nistpubs/800-64-Rev2/SP800-64-Revision2.pdf http://csrc.nist.gov/publications/nistpubs/800-40-rev3/sp800_40_r3_pre_publication.pdf http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140val-all.htm http://www.cio.gov/archive/e_gov_act_2002.pdf

The following list of resources provides additional information that may be helpful to Offerors in preparing their responses to this solicitation. The successful Offeror shall provide details as to how their services, systems and the surrounding processes will adhere to the relevant security standards and Government regulations.
FCC Cybersecurity Program Cybersecurity Policy, Version 3.1.1, July 31, 2012
Available upon request
NIST Special Publication 800-27 Rev A Engineering Principles for Information Technology Security (A Baseline for Achieving Security), Revision A
http://csrc.nist.gov/publications/nistpubs/800-27A/SP800-27-RevA.pdf
Office of Management and Budget (OMB) Circular No.A-130, Management of Federal Information Resources. Documents may be found at:
http://www.whitehouse.gov/omb/circulars/a130/a130trans4.html.
Office of Management and Budget (OMB) guidelines on The E-Government Act of 2002, Sec. 208 on Privacy Provisions (see Privacy Impact Assessment requirements). Information available at:
http://www.whitehouse.gov/omb/memoranda/m03-22.html.
National Institute of Standards and Technology (NIST) Special Publication 800-18, Guide for Developing Security Plans for Information Technology Systems. This document is available at:
http://csrc.nist.gov/publications/nistpubs/800-18-Rev1/sp800-18-Rev1-final.pdf.
National Institute of Standards and Technology (NIST) Special Publication 800-37, Guide for the Security Certification and Accreditation of Federal Information Systems. This document can be found at:
http://csrc.nist.gov/publications/nistpubs/800-37/SP800-37-final.pdf.
Draft NIST Special Publication 800-53, Revision 3, and Recommended Security Controls for Federal Information Systems. This document can be found at:
http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/sp800-53-rev3-final_updated-errata_05-01-2010.pdf
Draft NIST Special Publication 800-53A, Revision 1, Guide for Assessing the Security Controls for Federal Information Systems. This document can be found at:
http://csrc.nist.gov/publications/drafts.html#sp800-53A
NIST Cryptographic Toolkit. Information regarding encryption standards approved for use by Government organizations may be found at:
NIST Special Publication 800-12, An Introduction to Computer Security. Documents may be found at:
http://csrc.nist.gov/publications/nistpubs/800-12/.
NIST Special Publication 800-14, Generally Accepted Principles and Practices for Securing Information Technology Systems. Documents may be found at:
http://csrc.nist.gov/publications/nistpubs/800-14/800-14.pdf.
NIST SP 800-16, Information Technology Security Training Requirements. Documents may be found at:
http://csrc.nist.gov/publications/nistpubs/800-16/800-16.pdf. http://csrc.nist.gov/publications/nistpubs/800-16/AppendixA-D.pdf.
http://csrc.nist.gov/publications/nistpubs/800-16/Appendix_E.pdf.
NIST SP 800-47, Security Guide for Interconnecting Information Technology Systems. This document can be found at:
http://csrc.nist.gov/publications/nistpubs/800-47/sp800-47.pdf
Federal Information Security Management Act (FISMA). This document is available at:
http://www.cio.gov/archive/e_gov_act_2002.pdf.

File details come from the government source that posted it. Updated .