Attachment 2 - Information Assurance Sample Task Order.doc
DOC document 374 KB Posted
- Attached to
- Defense Information Systems Agency Information Technology Enterprise Support Services Federal contract opportunity
- Solicitation number
- HC1047-12-R-4013
- Issued by
- Defense Information Systems Agency
View the file
Other files for this federal contract opportunity
Show all 17
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Defense Information Systems Agency
Chief Information Officer
DISA Information Technology Enterprise Support Services (DESS)
HC1047-12-D-XXXX
Task Order (TO) 0002 (Version 1.0)
31 January 2012 Table of Contents
11.
Task Order CORs (TO/CORs)
11.1 Primary TO/COR.
11.2 Alternate TO/COR
12.
Task Order Title:
23.
Background
34.
Objectives
55.
Scope
65.1 Risk Management Support.
75.2 Cyber Assurance Support.
75.3 Public Key Implementation (PKE/I)/Public Key Enabling (PKE) Engineering Support .
86.
Specific Tasks
86.1 Task 1 – Project Management
86.1.1 DSS Program Management Plan (PMP)
86.1.2 DSS Concept of Operations (CONOPS)
86.1.3 Progress Reviews
96.1.4 Quality Assurance Surveillance Plan (QASP)
96.1.5 Cooperation/Coordination with Other Contractors
96.1.6 Staffing Requirements
106.1.7 Program Support
116.2.1 Accreditations.
116.2.2 Provide Routine System Accrediation Coordination Support.
146.2.3 Provide Circuits (NIPR/SIPR/DVS/DSN) Support for the C&A Process
156.2.4 Provide Cross Domain and Cross Domain Boards/Working Groups Support
176.2.5 Provide Ports/Protocol/Services Management (PPSM) Support.
186.2.6 eMASS Administration
196.2.7 Network Vulnerability Assessment Scans
206.2.8 Federal Information Systems Management Act (FISMA)
206.2.9 Meeting Support (DISN Security Accreditation Working Group (DSAWG)/GIG Waiver/DISN/Flag Panel/DISN/Flag Panel/TAG/eMASS CCB/HPT)
216.2.10 Information Assurance Workforce Professional and Certification
236.3 Task 3 – Cyber Assurance
236.3.1 Host Based Security System (HBSS) Program
246.3.2 CYBERCON Program
246.3.3 USCYBERCOM Directive Compliancy
266.3.4 Cyber Command Readiness Inspections Site Assist Visits (CCRI/SAV) Program
276.3.5 White List
276.3.6 Information Assurance/Computer Net Defense (IA/CND) Inspections
286.3.7 Secure Configuration Vulnerability Management (SCVM)
316.3.8 Continuous Monitoring Program
336.3.9 Sensor Compliance and Enclave Security
346.3.10 Cyber Drills
356.3.11 Information Assurance Knowledge Services
356.4 Task 4 - Public Key Encryption/Infrastructure (PKE/I) Engineering Support Services.
356.4.1 Provide SIPRNet Token Issuance Support
356.4.2 Maintain Departure Reporting
356.4.3 Maintain RA/LRA Certificate Practice Statement (CPS)
366.4.4 Provide Alternate Token Support
366.4.5 Provide PKE/I Engineering Support
366.4.6 Provide Mobile Code Support
366.4.7 Provide PKE/I Help Desk Support
366.4.8 Provide Registration Authority (RA)/Local Registration Authority (LRA) Support
376.4.9 Provide PKE/I Knowledge Management Support
376.4.10 Establish Processes and Procedures for Implementing PKE/I DISA-wide
387.
Place of Performance
387.1 Primary Place of Performance
387.2 Alternate Place of Performance
388.
Travel Requirements
389.
Period of Performance
3910.
Delivery Schedule
4311.
Performance Metrics
4512.
Security Requirements
4512.1 The VAR/VAL should be sent via one of two methods.
4512.1.1 Method One
4512.1.2 Method Two
4713.
Government-Furnished Equipment (GFE)/Government-Furnished Information (GFI)
4714.
Other Pertinent Information or Special Considerations
4714.1 Identification of Potential Conflicts of Interest (COI).
4814.2 Identification of Non-Disclosure Requirements.
4814.3 Inspection and Acceptance Criteria.
4815.
Section 508 Accessibility Standards
| Task Order Number: |
| HC1028-13-R-XXXX-0002 |
1. Task Order Contracting Officer’s Representatives (TO/CORs) Primary TO/COR.
| Name: |
| John Doe |
| Organization: |
| DISA/CIO/CI31 |
Department of Defense Activity
Address Code (DODAAC):
HC1047
| Address: |
| 6910 Cooper Road, Fort George G. Meade, MD 20755 |
| Phone Number: |
| 301-225-XXXX |
| Fax Number: |
| 301-225-XXXX |
| E-Mail Address: |
| John.Doe@disa.mil |
Alternate TO/COR.
| Name: |
| Jane Doe |
| Organization: |
| DISA/CIO/CI32 |
Department of Defense Activity
Address Code (DODAAC):
HC1047
| Address: |
| 6910 Cooper Road, Fort George G. Meade, MD 20755 |
| Phone Number: |
| 301-225-XXXX |
| Fax Number: |
| 301-225-XXXX |
| E-Mail Address: |
| Jane.Doe@disa.mil |
2. Task Order Title:
Defense Information Systems Agency’s (DISA’s) Information Assurance (IA) Support Services
3. Background The Defense Information Systems Agency is a Combat Support Agency responsible for connecting US Forces and their coalition partners to the DoD’s Global Information Technology (IT) Enterprise. DISA provides IT networks, computing infrastructure, and enterprise services in direct support of US Warfighters to facilitate the seamless exchange of information on a global scale.
The mission of DISA’s Chief Information Officer (CIO) is to, “Lead and govern the delivery and operation of secure world-wide enterprise IT services enabling the efficient and effective execution of DISA’s global combat support missions.” In order to accomplish this mission, the DISA CIO must:
· Provide an efficient and effective IT infrastructure and services to support the Agency’s warfighting mission.
· Achieve a Mission Assurance posture that ensures the security and continuity of the Agency’s internal IT Enterprise’s infrastructure and services against an ever evolving spectrum of threats.
· Maintain compliance with all DOD information governance policies and legislation.
· Govern a common architecture and service delivery framework to drive efficiencies in business system investments and portfolio and knowledge management capabilities.
A key component of this mission is the Information Assurance (IA) to include Risk Management, IA Training, and Cyber Assurance. The CIO designated the Information Assurance Division (IA) Division to serve as the DISA Designated Approving Authority (DAA) Representative to perform the IA function and all it components including the development, execution and oversight of the Agency’s IA program. As such, the division’s mission is to assure DISA’s information systems, assets, and enclaves possess the necessary security measures to ensure their availability, protection, integrity, authentication, confidentiality, and non-repudiation to include monitoring, detection, discover and reaction capabilities of internal and external adversaries; and ensure a trained and effective information assurance workforce.
Contractor support services is necessary to ensure DISA’s information infrastructure and systems satisfy all applicable law, government and DoD mandates, regulations, and directives. Contractor support shall provide technical security expertise in planning, preparing, oversight and executing DISA’s Information Assurance program. Also, to ensure DISA’s information infrastructure and systems are compliant with all mandated DoD, National Institute of Standards and Technology (NIST), Office of Management and Budget (OMB), Chairman of the Joint Chiefs of Staff (CJCS), U.S. Strategic Command (USSTRATCOM), U.S. Cyber Command (USCYBERCOM) and DISA tasking orders, directives, instructions, standards, and requirements. The Contractor must be able to apply these mandates, regulations, and directives and analyze DISA’s information infrastructure or systems to determine and mitigate any security discrepancies, risks, vulnerabilities or non-compliance. The Contractor must stay abreast of any new or changes to the above references, as well as emerging DoD and Industry technologies to ensure the DISA’s information infrastructure and systems are secure as possible. Additionally, the Contractor shall conduct IA training classes to train or update DISA Information Assurance Managers (IAM) and/or system administers (SA) pertaining to DoD systems certification and accreditation policies and procedures in accordance with Defense Information Assurance Certification and Accreditation Package (DIACAP), entire DoD 8500 series IA policies and procedures. The overarching vital goal of IA and Computer Network Defense (CND) Directive program is to protect, defend, and secure DISA’s Information infrastructure to ensure data assets and information are visible, accessible, understandable and trusted by all authorized users even in the face of a cyber attack. To take deliberate actions to assure DISA’s Information Infrastructure is properly configured, protected, and monitored against vulnerabilities or threats. The contractor must be knowledgeable and adapt to the changing DoD and DISA policies and procedures in executing DISA’s. The contractor must be flexible and adapt to changing DoD Policies and Procedures that impact certification and accreditation, and applicable functional IA and CND areas addressed in this SOW.
4. Objectives The Defense Information Systems Agency’s (DISA’s) authority to operate networks / systems / applications / services in compliance with Federal and Department of Defense (DoD) policies is the responsibility of DISA’s CIO and the Designated Approving Authority (DAA). Currently, DISA has designated the same individual to serve as the CIO and DAA (hereinafter, the CIO). CIO’s mission is to lead and govern the delivery and operation of secure world-wide enterprise IT services enabling the efficient and effective execution of DISA’s global combat support missions. A key component of this mission is the Information Assurance (IA) to include Risk Management, and IA Training, Cyber Assurance. The CIO designated CI3 to serve as the DISA DAA Representative to perform the IA function and all it components including the development, execution and oversight of the Agency’s IA program. As such, CI3’s mission is to assure DISA’s information systems, assets, and enclaves possess the necessary security measures to ensure their availability, protection, integrity, authentication, confidentiality, and non-repudiation to include monitoring, detection, discover and reaction capabilities of internal and external adversaries; and ensure a trained and effective information assurance workforce.
Contractor support services is necessary to ensure DISA’s information infrastructure and systems satisfy all applicable law, government and DoD mandates, regulations, and directives. Contractor support shall provide technical security expertise in planning, preparing, oversight and executing DISA’s Information Assurance program. Also, to ensure DISA’s information infrastructure and systems are compliant with all mandated DoD, National Institute of Standards and Technology (NIST), Office of Management and Budget (OMB), Chairman of the Joint Chiefs of Staff (CJCS), U.S. Strategic Command (USSTRATCOM), U.S. Cyber Command (USCYBERCOM) and DISA tasking orders, directives, instructions, standards, and requirements. The Contractor must be able to apply these mandates, regulations, and directives and analyze DISA’s information infrastructure or systems to determine and mitigate any security discrepancies, risks, vulnerabilities or non-compliance. The Contractor must stay abreast of any new or changes to the above references, as well as emerging DoD and Industry technologies to ensure the DISA’s information infrastructure and systems are secure as possible. Additionally, the Contractor shall conduct IA training classes to train or update DISA Information Assurance Managers (IAM) and/or system administers (SA) pertaining to DoD systems certification and accreditation policies and procedures in accordance with Defense Information Assurance Certification and Accreditation Package (DIACAP), entire DoD 8500 series IA policies and procedures. The overarching vital goal of IA and Computer Network Defense (CND) Directive program is to protect, defend, and secure DISA’s Information infrastructure to ensure data assets and information are visible, accessible, understandable and trusted by all authorized users even in the face of a cyber attack. To take deliberate actions to assure DISA’s Information Infrastructure is properly configured, protected, and monitored against vulnerabilities or threats. The contractor must be knowledgeable and adapt to the changing DoD and DISA policies and procedures in executing DISA’s Information Assurance Vulnerability Management (IAVM) program, CND Directive program, Command Cyber Readiness Inspection (CCRI) program, Host Based Security System (HBSS) program, CND Operations, and IA/CND Readiness Posture to respond and recover against adversary events. The overarching critical goal of PKE/I is to enhance the business processes and improve the IA posture of the DoD through widespread use of PK-Enabled applications. The contractor must be flexible and adapt to changing DoD Policies and Procedures that impact certification and accreditation, and applicable functional IA and CND areas addressed in this PWS.
The contractor shall comply with the appropriate DOD and DISA approved architectures, programs, standards and guidelines, such as:
· Clinger-Cohen Act
· Federal Information Security Management Act
· Homeland security Presidential Directive-12
· DoD Directive 0-8530.1, Computer Network Defense (CND)
· DoD Instruction 0-8530.2, Support to Computer Network Defense (CND)
· DoD Manual 0-8530.-1M, DoD Computer Network Defense (CND) Service Provider Certification and Accreditation Process
· FSO Evaluator’s Scoring Metrics: Certification and Accreditation of Computer Network Defense Service Providers
· DoD Directive 8570.1, Information Assurance Training, Certification, and Workforce Management
· DoD 8570.01M, DoD Information Assurance Workforce Improvement Program
· DoD Directive, 8500.1, Information Assurance
· DoD Instruction 8500.2, Information Assurance Implementation
· DoD Instruction 8510.01, DoD Information Assurance Certification and Accreditation Process (DIACAP)
· DoD 5200.2-R DoD Personnel Security Program
· DoD 5220.22-M, National Industrial Security Program Operating Manual
· DoD 5220.22-R, Industrial Security Regulation
· DoD 5230.20, Visits, Assignments and Exchanges of Foreign Nationals
· CJCS Manual 6510.01, Defense-In-Depth, Information Assurance (IA) and Computer Network Defense (CND)
· CJCSI Instruction 6211.02C, Defense Information System Network (DISN): Policy, Responsibilities and Processes
· DISA Instruction 630-230-19, Information Assurance
· DISA's Information Assurance Manual
· DISA Computing Services Directorate (CSD) Security Handbook
· Global Information Grid (GIG) IA Technical Framework
· DII Common Operating Environment (COE)
· DII Standard Operating Environment (SOE)
· DoD Security Technical Implementation Guides (STIGs)
· FSO Enhanced Compliance Validation Guide
· FSO Process Guide(s)
· FSO Vulnerability Scanning Procedures
· FSO Security Features User Guide (SFUG)
· FSO Security Review Methodology
· FSO Risk Assessment Guide
· National Security Agency (NSA) Security Guides
· Net centric Enterprise Services (NCES) Framework
· NetOps Policy and Checklists
· NSTISSP No. 11, National Information Assurance Protection (NIAP)
· USCYBERCOM / Communications Tasking Orders (CTOs)
· DISA Tasking Orders (DTO’s)
· DISA Operations Orders (OPORDs)
Joint Security (System Administrator) Checklist (Available on the DoD IASE/IA Portal, under STIGS
Security Checklists http://iase.disa.mil/stigs/checklist/index.html
5. Scope This Task Order encompasses the full range of mission support capabilities that are needed by the Information and Mission Assurance Support. The functional scope of the tasks associated with this effort is detailed below. The work is focused in the following areas:
- Providing IA Support in the areas of accreditation, IA workforce Professionalization and certification, Ports/Protocol/Services Management (PPSM), Cross Domain Solutions (CDS) management, DoD PKE/I engineering, computer network defense support.
- Analyzing and developing operationally effective process enhancements that will improve DISA's information assurance security posture.
- Provide technical security expertise in DoD and coalition (to include NATO) security policy, directives, and instructions.
- Ensuring compliance with the various security policies, assessing impacts of integrated, interdependent, and interconnected DoD, coalition, and NATO local subscriber environments’ security posture and topology, reviewing security relevant documentation, and preparing technical papers discussing the results of this analysis.
- Participation in DoD efforts, ensuring compliance with policies and directives, participation in technical meetings, and the preparation of technical papers and reports.
- Through insights gained and lessons learned provide analytical input for DISA IA Support Services improvements.
- Providing IA and CND Support in the areas of DISA’s CND Directives, IAVMs, Command Cyber Readiness Inspections (CCRIs), enterprise compliance tools, security incidents, Host Based Security System (HBSS), CND operations, and IA/CND readiness posture.
Risk Management Support.
The contractor shall provide on-site support to the DAA's formal accreditation reviews, PPSM, Circuits Management, Cross Domain Solution (CDS), Network Scanning, Penetration Testing, FISMA Compliancy, and IA Training Programs.
This will include the analysis of specific threats, vulnerabilities, and when process or policy is found to be out of date or requires an amendment or change, recommendations for policy and process improvements will be gathered, archived, and prepared for presentation to that system’s working group, and assess the security posture for DISA. Approximately 700 ISs are currently registered under the DISA DAA's area of responsibility, and approximately one-third may come due for review and accreditation/re-accreditation to include any number of new systems during this period of performance.
Cyber Assurance Support.
Review and evaluate each accreditation package for compliance with all of the following where applicable: DoD IA vulnerabilities notices (alerts, bulletins and technical advisories); communication tasking orders (CTOs); Warning Orders (WARNORDs); operational orders (OPORDs); security technical implementation guides (STIGs); security readiness review (SRR) findings.
Public Key Implementation (PKE/I)/Public Key Enabling (PKE) Engineering Support .
The contractor's specific support for DISA (internal) DoD PKE Engineering support services shall include:
- Issue SIPR Tokens to DISA worldwide. Issuance includes formatting tokens, adding certifications and issuance
. Identify the resources and develop a POA&M to implement cryptographic network log-on using the SIPRNet token including need for support for thin client workstations
- Identify additional equipment and licenses to support use of SIPRNet PKI
- Provide the Government with the development of a detailed implementation plan for fielding tokens to Components' SIPRNet users
- Approve of server certificates
- Generate Certificate Registration Instructions (CRI) for subscriber certificates
- Generate alternate tokens
- Process revocation request
- Preform as Registration Authority customer support
- Manage and archive paperwork associated with the registration authority program
- Process departure reports – Monthly. Create personnel departure list and check entries against PKI directory (NIPR & SIPR). Revoke any current software certificates found. Remove and outdate entries from the directory.
6. Specific Tasks
Task 1 – Project Management In order to provide the foundation for effective communication and execution of the DESS Task Orders, within 30 days of contract award the Contractor(s) shall provide the Government with the following:
6.1.1 DESS Program Management Plan (PMP)
The Contractor(s) shall submit to the Government for final approval a PMP, in MS Office formats, that addresses the contractor(s) plan for completing all assigned tasks identified in the Task Order. The PMP shall include a list of all deliverables that will be provided to the Government and an Integrated Master Schedule (IMS) detailing the contractor(s) plan for accomplish the work identified in the Task Order. The contractor shall prepare a TO management plan describing the technical approach, organizational resources and management controls to be employed to meet the cost, performance and schedule requirements throughout TO execution. The contractor shall provide a monthly status report (MSR) monitoring the quality assurance, progress/status reporting, and program reviews applied to the TO (as appropriate to the specific nature of the SOW).
6.1.2 DESS Concept of Operations (CONOPS)
The Contractor(s) shall submit, and request formal approval of, a Concept of Operations (CONOPS) in MS Office format, that details the contractor(s) approach to managing their professional relationship with the Government’s DESS management Team. The CONOPS shall include a detailed description of the contractor(s) functional and administrative roles and responsibilities and contact information for each functional and administrative Point of Contact.
6.1.3 Progress Reviews
The contractor shall conduct a formal In Progress Review within 90 days of task award and quarterly thereafter. The contractor’s Technical Task Leader (TTL) and appropriate members of the technical team will meet no less frequently than every 90 days with the appointed Government TO/COR, either in person or via teleconference or a combination of both. The purpose of these meetings will be to informally discuss progress, request assistance as required, and deal with issues raised during the execution of the task. The contractor shall provide a read ahead copy of the Quarterly Progress Review (QPR) briefing to be provided not less than five (5) working days prior to the briefing. The contractor shall include in the Quarterly Progress Review presentation, a list of newly hired personnel, as well as a list of personnel who have left the contract since the last Quarterly Progress Review, with corresponding dates of arrival/departure. Also include a list of personnel 8570 certifications, task order financials and invoice history. The contractor shall document these meetings in Quarterly Review Notes and report the occurrence of these and any other meetings in the MSRs.
6.1.4 Quality Control Plan (QCP)
Establish a Quality Control Plan (QCP) that adequately addresses metrics associated with (at a minimum) quality and efficiency of the product & service, schedule adherence/timeliness, and customer satisfaction. Establish a customer survey process to ensure adequate feedback on support is received.
6.1.5 Cooperation/Coordination with Other Contractors
There may be multiple contractors (i.e., from more than one contract vehicle and/or company) supporting CIO and other DoD activities, tasked to work on the same or related activities. The contractor shall work with these other contractors as required to accomplish Government requirements, goals, and objectives as efficiently and effectively as possible. This may include sharing or coordinating information resulting from the work required by this SOW or previous Government efforts, and/or working as a team to perform tasks in concert.
6.1.6 Staffing Requirements
The contract team shall provide the optimum mix of personnel of various labor categories and technical expertise to perform the tasks specified in the technical environments specified in this SOW. The contractor must provide 90% of personnel meeting the DoD 8570.01-M IA certification requirements within 30 days of contract start date. New personnel joining the contractor after award of the task order shall meet IA certification requirements within 90 days of assignment of the individual to perform IA work or must be removed from the task order until certification is met or a waiver from the Government is obtained. IA certification programs are intended to produce IA personnel with the demonstrated ability to perform the functions of their assigned position. Each category and skill level has specific training and certification requirements. Meeting these requirements will require a combination of formal training, experiential activities such as on-the-job training, and continuing education. The table below represents the DoD approved baseline certifications for Information Assurance Technical (IAT) and Information Assurance Manager (IAM) personnel. As new categories are added to DoD policy guidance for IA certifications, contractor must comply with established timeframes identified.
IAT Level 1
IAT Level II
IAT Level III
A +
Network +
SSCP
GSEC
Security +
SCNP
SSCP
CISA
CISSP
GSE
SCNA
| IAM Level 1 |
| IAM Level II |
| IAM Level III |
GISF
GSLC
Security+
GSLC
CISM
CISSP
GSLC
CISM
CISSP
The contractor shall ensure all senior level IA positions must meet the IA certification requirements of an IAM Level III as identified in the above table.
The contractor shall ensure site personnel working PKE/I RA and LRA responsibilities will be trained and certified to perform tasks.
Any new personnel not possessing the training and/or certification required for a proposed duty position and/or labor category shall be proposed by the contractor at a discounted/lower rate until the training and certifications are completed. Upon completion of the required training and certifications for the position being filled, the individual shall be billable by the contractor at the full rate for the appropriate labor category after concurrence by the Government.
Any contractor personnel who fail to comply with any of the above certifications shall be removed from this task order. The contractor shall be responsible for any retraining expenses required by the individual to meet these requirements. A revised resume showing in detail the retraining actions must be submitted and approved by the Government before an individual can be reinstated.
6.1.7 Program Support
The contractor shall perform information system security programmatic support to the DISA Designated Approving Authority. To perform such support, as determined in writing by the Task Order COR, the contractor shall be required to prepare position or point papers regarding specific information systems security topics as needed/requested by the TO/COR. The contractor shall be expected to prepare a maximum of ten position papers.
The TO/COR will define in writing the scope, specify the format, and due date for the effort prior to issuing the requirement to the contractor.
In accordance with the PWS and at the request of the TO/COR, research and prepare accreditation point/position papers no more than ten (10) pages in length single-spaced.
6.2 Task 2 – Risk Management
In order to provide the foundation for effective communication and execution of the DESS Task Orders, within 30 days of contract award the Contractor(s) shall provide the Government with the following:
6.2.1 Accreditations.
6.2.1.1 The contractor shall assist in the development, implementation, and management processes that support the accreditation of all DISA sites, circuits, networks, enclaves, ISs, applications, and services worldwide. This task is to achieve full accreditation and re-accreditation for all unaccredited or currently accredited DISA sites, networks, enclaves, ISs, applications and services. This will provide support to the DISA DAA, to ensure DISA systems and applicable GIG information systems are accredited in accordance with that respective system’s lifecycle, based upon DoD regulations. The contractor shall assist in the development, implementation, and management processes that support the accreditation of all DISA sites, circuits, networks, enclaves, ISs, applications, and services worldwide.
6.2.1.2 The contractors shall function as the system administrator (SA) for eMASS. SA shall manage all DISA CIO databases (VMS, DITPR, DIACAP archive, SGS, eMASS, PPSM, etc.)
6.2.1.3 The contractor shall track and document actions within the office to include capturing of sufficient data to support periodic reporting requirements as detailed below. Specific data will include, but is not limited to, date documentation is received, date package is begun, Contractor (AO) working the package, date package is completed, date package begins staffing for signature, date package is delivered to Front Office for signature, date package is signed, date package is provided to necessary elements such as program/Directorate Information Assurance Manager (IAM) and Connection Approval Office (CAO) if applicable. Data will also include those fields captured in applicable systems or tools used for Certification and Accreditation (C&A) purposes such as Vulnerability Management System (VMS), Enterprise Mission Assurance Support Service (eMASS), SIPRNet GIAP System (SGS), Ports, Protocols and Services Management (PPSM) system, IASE, Defense Information Technology Portfolio Repository (DITPR), WWOLS-R and Systems Network Approval Process (SNAP).
6.2.2 Provide Routine System Accrediation Coordination Support.
6.2.2.1 Contractor shall conduct a pre-coordination meeting with the Directorate and the System Information Assurance Manager.
6.2.2.2 Contractor shall review all pertinent data repositories (i.e. VMS, SNAP, GIAP, eMASS, DITPR) for current compliance status for each accreditation package.
6.2.2.3 Contractor shall review and evaluate each accreditation package for compliance with all of the following where applicable: DoD Information Assurance Vulnerability Management (IAVM) vulnerabilities notices (alerts, bulletins and technical advisories); Cross-Domain solutions; Ports, Protocols and Services Management (PPSM); communication tasking orders (CTOs); FRAG Operational Orders, Warning Orders (WARNORDs); operational orders (OPORDs); security technical implementation guides (STIGs); security readiness review (SRR) findings, USCYBERCOM Directives
6.2.2.4 Contractor shall review and evaluate all DIACAP packages to include the DIACAP Implementation Plan (DIP), System Information Profile (SIP), DIACAP Scorecard, and Plan of Action and Milestones (POA&Ms) as they apply to a final accreditation review.
6.2.2.5 Contractor shall review and evaluation of Certification Recommendation from Field Security Operation (FSO).
6.2.2.6 Contractor shall review and evaluation for acceptance of risk.
6.2.2.7 Contractor shall execute a draft of risk acceptance, if required.
6.2.2.8 Contractor shall prepare accreditation package (to include COMSATCOMs, change requests and amendments) and letter for the DAA.
6.2.2.9 Contractor shall prepare accreditation packages for Senior Information Assurance Officer (SIAO) and/or Designated Accrediting Authority (DAA) decision, which shall include but is not limited to, Acceptance of Risk, Interim Authorization to Test (IATT), Interim Authorization to Operate (IATO), Authorization to Operate (ATO), Denial Authorization to Operate (DATO), COMSATCOM Packages, Change Approval Requests, Amendments, Connection Approval Process (CAP) packages, policy write/review and approval, policy letters and/or memorandums, Memorandums of Agreement or Understanding (MOA/MOU), documentation review and End of Life (EOL) packages.
6.2.2.10 The Contractor shall prepare, maintain and provide, on a daily basis, an action tracking log of all actions ongoing and completed by the C&A team. Monitor and maintain the CIO-IA-Security mailbox. Specific data will include, but is not limited to, date documentation is received, date package processing has begun, Contractor (AO) working the package, date package is completed, date package begins staffing for signature, date package is delivered to Front Office for signature, date package is signed, date package is provided to necessary elements such as program/Directorate Information Assurance Manager (IAM), Connection Approval Office (CAO), Cross Domain Services (CDSs), Internet Service Providers (ISPs), Non-DOD Cross-Component Computing Environments, and Commercial Satellite Communications, if applicable.
6.2.2.11 Contractor shall maintain the CI31 Accreditation Status Board on a daily basis to include, system name, AO working the package, expiration date, circuits assigned (if applicable), current status (i.e., SIAO or Front Office).
6.2.2.12 Contractor shall develop a database to track current and upcoming accreditation packages.
6.2.2.13 Contractor shall perform all duties as the Enterprise Mission Assurance Support Service (eMASS) System Administrator for all DISA systems, and prepare and provide a monthly report depicting number of users having accounts by organization.
6.2.2.14 Contractor shall prepare, provide and maintain a Policy/CIO Accreditation Support Standard Operating Procedures (SOP) document detailing all internal processes. Internal policies/processes will include procedures for documenting specific actions in eMASS/Circuits/ PPSM/CDS/C&A.
6.2.2.15 Contractor shall participate in C&A/eMASS meetings, Working Groups and conferences as directed, and complete a Memorandum for Record (MFR) and/or Trip Report in accordance with TO/COR requirements.
6.2.2.16 Contractor shall prepare and present, as required, training for DISA personnel on DISA's C&A/eMASS processes. Specific audiences will be determined by the TO/COR and may include internal or external IA Conferences, Symposiums, Working Groups, or periodic training for IAMs, IAOs or PMs.
6.2.2.17 Contractor shall prepare and provide weekly and monthly progress reports on the number of C&A packages submitted for SIAO/DAA signature. This data will be used to compile weekly, monthly, quarterly, and annual accomplishment reports.
Accreditation Packages -
Possible Maximum Weekly Reviews - 12 to 15 (new and/or amended packages)
Possible Maximum Monthly Reviews – 50 to 60 (new and/or amended packages)
DISA Accreditation review Timeframe:
| Type of Review |
| Requirements |
| Time required (is actual time spent on specific tasks if all information is readily available; it does not include time spent researching/looking for information or in coordination). |
| Accreditation review |
| Pre-review coordination meeting stakeholders |
| 0.25 working days |
| Review and adjudication for close out of activities to prepare draft package |
| 5 working days |
| Prepare final draft package submit to IAM for coordination |
| 1 working days |
| Prepare final package for coordination and submit to DAA for decision |
| 1 working days |
| Team Composition (Historically) |
| 1 Team Lead (overseer) |
and 1 Junior IA reviewer
| Accreditation review (update) |
| Review and adjudication for close out of activities to prepare draft updated package |
| 2 working days |
| Prepare final draft updated package submit to IAM for coordination |
| 1 working days |
| Prepare final package for coordination and submit to DAA for decision |
| 1 working days |
| Team Composition (Historically) |
| 1 Team Lead (overseer) |
and 1 Junior IA reviewer
6.2.3 Provide Circuits (NIPR/SIPR/DVS/DSN) Support for the C&A Process
6.2.3.1 The contractor shall provide on-site circuit/CAP package support and verify the following items have been checked prior to submission of the CAP package to the CAO: SIP is correct/current, scorecard, POA&M, Network/Enclave Topology Diagram/SIPRNet Connection Questionnaire (SCQ), and Consent to monitor memo
6.2.3.2 The contractor shall submit CAP package to the CAO immediately upon validation.
6.2.3.3 The contractor shall update the Circuit Slides to be included in the Cyber Assurance Slides (weekly).
6.2.3.4 The contractor shall track status of all DISA owned and DISA sponsored circuit connections.
6.2.4 Provide Cross Domain and Cross Domain Boards/Working Groups Support
6.2.4.1 The CDSE/O contractor support shall provide a comprehensive review of all Cross Domain implementation documentation each month to support internal and external DISA customers.
6.2.4.2 The CDSE/O contractor shall track all DISA Cross Domain implementation and status.
6.2.4.3 The CDSE/O contractor shall provide feedback to the CDS PMs to improve documentation and implementation effectiveness.
6.2.4.4 Manage the internal DISA CDS process.
6.2.4.5 Provide input, coordination, and socialization for process improvement at the CDSAP/CDTAB/DSAWG levels.
6.2.4.6 Track changes required to the SIPRNet GIAP System database. Issue requirements to the CDS --PMs for update documentation to close records that have become non-operative or have been superseded by other implementations or revisions.
6.2.4.7 Coordinate as needed interactions between the Computer Services Directorate (CSD) DECCs and the CDS PMs, to ensure smooth delivery of SCQ and topology changes to the DISA C&A team.
6.2.4.8 Be the focal point for and manage all cross domain related activities in their respective organizations to include but not limited to keeping the UCDMO informed of new requirements, customer needs, and capability gaps.
6.2.4.9 Maintain proficiency in the cross domain capabilities provided by Enterprise Services (ES) and the UCDMO CD baseline list.
6.2.4.10 Endorse ES as a preferred method of addressing cross domain requirements. As mission dictates, recommend baseline solutions when an ES is not appropriate.
6.2.4.11 Ensure that any new cross domain developments:
· Are fully coordinated with the UCDMO;
· Are in line with the goals and objectives of the Cross Domain Community Roadmap and;
· Fill identified capability gaps
6.2.4.12 Provide coordination and support for the organizations cross domain related risk management framework activities.
6.2.4.13 Review, validate, and prioritize cross domain requirements throughout the implementing organization’s acquisition and SDLC.
6.2.4.14 Ensure that information assurance requirements for cross domain related activities are properly addressed throughout the SDLC.
6.2.4.15 Maintain knowledge of all cross domain related expenditures throughout the organization’s planning and procurement processes and send an annual progress report of these expenditures to the UCDMO.
6.2.4.16 Actively participate in applicable cross domain community forums [e.g. Cross Domain Resolution Board (CDRB), Community Security Test Group (CSTG), Requirements Security Engineering Group (RSEG), tiger teams, working groups, etc.] to represent its organizational cross domain needs.
6.2.4.17 Maintain organizational access to information regarding cross domain requirements, implementations, installations, and configurations within the supported organization’s jurisdiction for periodic reporting to the UCDMO.
6.2.4.18 Enter and update, as required, all cross domain technology and operational data to include updates and patches for technologies in the UCDMO managed cross domain community repository.
6.2.4.19 Coordinate all pertinent cross domain issues with the UCDMO.
6.2.4.20 Cross Domain Boards/Working Groups Support
6.2.4.21 Contractor shall support DISA CIO for the Cross Domain Security Assessment Panel (CDSAP), Cross Domain Technical Advisory Board (CDTAB), and Defense Security Information Assurance Working Group (DSAWG) .
6.2.4.22 Review all DISA briefings prior to submission to the board or working group. Provide assessment of the briefing to the briefer, e.g., changes to improve success and or clarity.
6.2.4.23 Represent the CDS PM as an advocate at CDSAP/CDTAB/DSAWG.
6.2.4.24 Represent DISA for non-CDS briefings (decision or information) and provide comment as required. Vote as required and appropriate.
6.2.4.25 Provide the DISA DAA/CIO with decision/position papers as required supporting DISA position on DSAWG, DISN/GIG Flag Panel, and GIG Waiver Panel topics.
6.2.4.26 Provide after action reports for meeting attended ( i.e., DSAWG, DISN/GIG Flag Panel, and GIG Waiver Panel)
6.2.5 Provide Ports/Protocol/Services Management (PPSM) Support.
6.2.5.1 Support CIO in the daily tracking of all DISA PPSM entries for compliance using all required information source and provide pre-coordination meeting with Directorate and system information assurance managers
6.2.5.2 Review all pertinent data repositories (i.e., VMS, SNAP, GIAP, eMASS, DITPR) for current compliance status of each accreditation package
6.2.5.3 Review and evaluate each accreditation package for compliance with all of the following where applicable: DoD IA vulnerabilities notices (alerts, bulletins and technical advisories); Cross-Domain solutions; Ports, Protocols and Services Management (PPSM); communication tasking orders (CTOs); Warning Orders (WARNORDs); operational orders (OPORDs); security technical implementation guides (STIGs); security readiness review (SRR) findings
6.2.5.4 Review and evaluation of test and evaluation plan and procedures
6.2.5.5 Review and evaluation of Certification recommendation
6.2.5.6 Review and evaluation for acceptance of risk
6.2.5.7 Execute draft risk acceptance documentation including a statement of residual risks
6.2.5.8 Evaluate all applicable current plans of actions and milestones (POA&Ms) as they apply to a final accreditation review
6.2.5.9 Prepare accreditation package and letter for the DAA or prepare updated accreditation amendment package and recommendation letter progress report and balance scorecard for DISA Directorates report to the Government.
6.2.5.10 Participate in PPSM Technical Assessment Group (TAG) meetings, conferences, workshops, forums and provide a memorandum for record trip report as required by the TO/COR
6.2.5.11 Support CIO to assist DISA system managers to register ports and protocols to the PPSM Database.
6.2.5.12 Participate in the PPSM Technical Assessment Group to perform interoperability vulnerability assessment on DoD/DISA ports and protocols.
6.2.5.13 Provide monthly updated PPSM Category Assignment List (CAL) to the Government.
6.2.5.14 Develop and support implementing DISA PPSM process model.
6.2.6 eMASS Administration
6.2.6.1 The contractor must complete an eMASS training course whether it be online Computer Based Training (CBT) located at the Knowledge Service (KM) site, or hands on course.
6.2.6.2 The contractor shall act as eMASS System Administrator. Within eMASS, the contractor shall approve new NIPR and SIPR accounts and create new user accounts by processing valid DD Form 2875s. The contractor shall manage Organizations, Lookup Tables and eMASS Communication (including external inheritance relationships and eMASS E-mail). The contractor shall submit and track trouble tickets related to eMASS performance.
6.2.6.3 The contractor shall receive and process eMASS Task Notifications and perform workload tasks as assigned. This includes but is not limited to the following package management tasks of control review, POA&M review of all control and system level weaknesses and associated milestones, and package approval or return for rework
6.2.6.4 Contractor shall update and maintain the eMASS playbook. The Contractor shall update the DISA component Workspace folder on the DIACAP Knowledge Service (KS).
6.2.7 Network Vulnerability Assessment Scans
6.2.7.1 Perform IA controls and IAVM validations against network infrastructure devices, Servers(Windows/UNIX), Domain Name Systems, Wireless 802.11 and BlackBerry security, Host-Based Security System (HBSS), and Traditional/Physical Security.
6.2.7.2 Perform daily, weekly, monthly, and periodic network vulnerability scans as needed.
6.2.7.3 Perform inventory, compliance, verification, and vulnerability identification scans.
6.2.7.4 Monitor the Passive Vulnerability Scanner (PVS).
6.2.7.5 Periodically validate and update the network scanner configuration settings.
6.2.7.6 Provide network vulnerability scanning support for Certification & Accreditation (C&A), Site Assist Visits (SAV), and Command Cyber Readiness Inspection (CCRI) efforts.
6.2.7.7 Provide scanning support in validation of patch management.
6.2.7.8 Perform and provide weekly, monthly and periodic network vulnerability scanning reports. An in-depth technical review of all identified vulnerabilities and technical fix or mitigation options.
6.2.7.9 Upload scan results into the Vulnerability Management System (VMS).
6.2.7.10 Troubleshoot and document scanning, false positive and reporting issues.
6.2.7.11 Prepare, provide, and maintain a scanning Policy and Standard Operating Procedures (SOP) detailing the internal policy and processes for IA Control validation activities, network vulnerability scanning and reporting.
6.2.7.12 Provide ACAS architecture support.
6.2.7.13 Participate in IA meetings.
6.2.8 Federal Information Systems Management Act (FISMA)
6.2.8.1 Perform monthly C & A Status Check, quarterly and yearly data calls/reporting mandated by DoD. Monitor DoD Cyberscope Tool and DITPR to support the FISMA compliance process.
6.2.8.2 Ensure that the DISA IAMs are aware of any systems not in compliance with FISMA.
6.2.8.3 Use DITPR to run the FISMA Metrics Report daily using the SOP for pulling reports from DITPR.
6.2.8.4 Alert IAMs via email with compliance issues.
6.2.8.5 Respond to any questions concerning the FISMA Data Quality in DITPR.
6.2.8.6 Work with the DISA Sub-Components (Directorates) POCs to update CyberScope (DCS) for Quarterly and FY FISMA reports.
6.2.8.7 Update the Compliance Tab in DITPR with newly issued ATO/IATO accreditation dates.
6.2.9 Meeting Support (DISN Security Accreditation Working Group (DSAWG)/GIG Waiver/DISN/Flag Panel/DISN/Flag Panel/TAG/eMASS CCB/HPT)
6.2.9.1 Performs analysis on all GIG waiver and appeal requests to determine compliance with all appropriate IA policies.
6.2.9.2 Develop recommendations on the acceptability of the waiver/appeal in meeting IA policy and whether any IA policy waiver should be granted.
6.2.9.3 Provide the recommendations to DISA as a part of the assessment of the waiver/appeal and to the GIG Waiver Panel Chair.
6.2.9.4 Attend all scheduled DSAWG meetings or ensure a designated alternate is present according to subject meeting’s schedule.
6.2.9.5 Provide the DISA SIAO with status updates, recommendations and prepare for briefing the DISA DAA.
6.2.9.6 Perform as a support element to the DISA office requesting the waiver.
6.2.9.7 Attend the Flag Panel meetings or ensure a designated alternate is present according to subject meeting’s schedule.
6.2.9.8 Maintain awareness of DISN/GIG Flag Panel IA activities and decisions to advise, inform, and support the DISA SIAO and the Risk Management Branch Chief.
6.2.9.9 Provide Configuration Control Management (CCM) of the DIACAP through interfacing with the DoD Component IA programs, IA COIs, and other entities (e.g., the GIG IA Program Office, DSAWG) to address issues that are common across all entities.
6.2.9.10 Provide detailed analysis and authoring support for the enterprise portion of the DIACAP Knowledge Service (KS) content.
6.2.9.11 Recommend changes to the baseline IA controls to the DISN/GIG Flag Panel.
6.2.9.12 Recommend changes to the C&A process to the DoD SIAO.
6.2.9.13 Advise the IA Senior Leadership (IASL) and other IA advisory forums identified by the DoD SIAO to resolve C&A priorities and cross-cutting issues.
6.2.9.14 Develop and manage DoD enterprise-level C&A automation requirements.
6.2.9.15 Attend DIACAP TAG meetings or ensure a designated alternate is present according to subject meeting’s schedule.
6.2.9.16 Attend eMASS CCB meetings or ensure a designated alternate is present according to subject meeting’s schedule.
6.2.9.17 Provide IA position to DISA CIO on all matters under consideration.
6.2.9.18 Participate in CCB to recommend changes and improvements that promote current issue.
6.2.9.19 Participate in discussions to report and resolve issues impeding the successful implementation and use of eMASS.
6.2.10 Information Assurance Workforce Professional and Certification
6.2.10.1 Maintain, update and provide the CIO a report. This report is developed and delivered weekly, monthly and periodic. It shall include the name of individual that have not completed their annual training.
6.2.10.2 T rack and notify the government when all the annual training is completed.
6.2.10.3 Develop and support the cybersecurity workforce framework for awareness, education training and professional development.
6.2.10.4 Rreview and provide recommendations for process improvements to improve execution and compliance with DISA management.
6.2.10.5 Participate in meetings, conferences, workshops, working groups as CIO SME and provide course of action recommendations to the CIO.
6.2.10.6 Develop briefings, coordination meetings, and coordinate documents reviews for technical input to policy definition. The contractor may also be required to travel to various locations.
6.2.10.7 The Contractor shall serve as central point of contact for all service delivery issues.
6.2.10.8 Review the DoD 8570 and provide their recommended changes to improve the policy, guidelines, and procedures regarding the documents.
6.2.10.9 Attend meetings, conferences, workshops, and working groups as CIO SME to discuss updates a nd changes to the 8570.
6.2.10.10 Provide input to the weekly compliance slides for training.
6.2.10.11 Update the Information Assurance Managers (IAM) list and ensure that the DISA IAMs are aware of any training requirements.
6.2.10.12 Develop briefings, coordination meetings, and coordinate documents reviews for technical input to policy definition. The contractor may also be required to travel to various locations.
DISA (internal) IA Workforce Professionalization and Certification Support Timeframe:
| Type of Support |
| Requirements |
| Time required (is actual time spent on specific tasks if all information is readily available; it does not include time spent researching/looking for information or in coordination). |
| IA Awareness Day |
| Pre-session coordination meeting to include researching and contacting guests speakers, logistical arrangements for DISA conference facilities, set up of tele-conference and DCO connectivity as well as recording of session and minutes. |
| 30 working days |
Team Composition
(Historically) 1 Team Lead (overseer) and
1 Intermediate IA
| 1/2 Day IA session |
| Pre-session coordination meeting to include researching and contacting guests speakers, logistical arrangements for DISA conference facilities, set up of tele-conference and DCO connectivity as well as recording of session and minutes. |
| 10 working days/ session |
Team Composition
(Historically) 1 Team Lead (overseer) and
1 Intermediate IA
Task 3 – Cyber Assurance
6.2.11 Host Based Security System (HBSS) Program
6.2.11.1 Provide trained and certified Global administrators able to manage and assume all HBSS Global Administrator responsibilities.
6.2.11.2 Monitor DISA HBSS Tier 2 and Tier 3 consoles daily for situational awareness of the environment.
6.2.11.3 The monitor and ensure any and all configuration changes to the ePO environment have been reviewed and approved by the DISA Designated Accrediting Authority.
6.2.11.4 Consolidate aggregated data from ePO consoles,…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .